Cybersecurity protects your systems. Cybersecurity risk management protects your business.®

The Information Highway

The Information Highway

"The AI Did It" Is Not a Defense: What the OpenAI Lawsuit Means for Businesses Using AI Agents

img-ai-accountability
AI agents are quickly moving from experiment to everyday business tool, and a new lawsuit is a timely reminder that when an AI agent causes harm, someone is still responsible. On September 29, 2026, the nonprofit Legal Advocates for Safe Science and Technology (LASST) sued OpenAI in California, seeking to hold the company accountable for the actions of its AI agents, including their role in the July 2026 breach of Hugging Face. At the center of the case is a California law that took effect this year and says, in effect, that "the AI did it" is not a legal defense.
Continue reading
  31 Hits

Critical Citrix NetScaler Zero-Days Are Under Active Attack: What Your Business Needs to Do This Week

server-room-closeup-critical-error

A pair of critical, unauthenticated zero-day vulnerabilities in Citrix NetScaler are being actively exploited right now and with roughly 23,000 internet-exposed devices worldwide, this is a "patch today, not next sprint" moment that shows exactly why continuous vulnerability management can't be a once-a-quarter checkbox for any growing business.

Continue reading
  121 Hits

Your Backups Might Not Save You: What a New Ransomware Recovery Study Means for Small and Mid-Sized Businesses

broken-chain-link-backup-recovery
A new field study of 800+ real-world ransomware recoveries found that only four organizations hit their 24-48 hour recovery target — and the reason usually wasn't missing backups, it was an untested, incomplete recovery plan.
Continue reading
  152 Hits

Cybersecurity Threat Advisory: ZcopyReaper Linux Kernel Flaw Gives Local Users Root Access, and Exploit Code Is Public

Threat-Advisory-Banner3

Threat update

A newly detailed Linux kernel vulnerability, tracked as CVE-2026-43502 and nicknamed ZcopyReaper, allows an unprivileged local user to escalate to full root control by abusing a memory-handling error in the kernel's Reliable Datagram Sockets (RDS) component. The flaw has existed since Linux kernel 4.17, working exploit code has been published, and patched kernels are available from major distributions. Organizations running Linux servers, cloud workloads, or Linux-based appliances should confirm patch status now. 

Continue reading
  222 Hits

Cybersecurity Threat Advisory: KATARU Malware Is Turning Exposed IoT Devices into Long-Term DDoS Bots

Threat-Advisory-Banner3

Threat update

A newly documented malware family named KATARU is hijacking internet-facing Linux devices, including routers and other IoT equipment, by guessing weak or default Telnet passwords. Once inside, it takes root-level control, embeds itself so it survives reboots, and enlists the device in a Mirai-style botnet used for large-scale DDoS attacks. Any organization with connected devices that are exposed to the internet, unpatched, or protected by default credentials should review its exposure now.

Continue reading
  194 Hits

Business Continuity and Disaster Recovery: Could Your Business Keep Running Tomorrow?

business-continuity-disaster-recovery
Data BackupBackups aren't the whole recovery plan. Learn how business continuity and disaster recovery help protect your operations when technology fails.
Continue reading
  194 Hits

Cybersecurity Threat Advisory: ScreenConnect Security Alert: What Businesses Need to Know About CVE-2026-84869

Threat-Advisory-Banner3

Threat update

A newly disclosed security issue affecting ConnectWise ScreenConnect could allow files to be transferred and executed during an active remote-support session without the authorization or confirmation normally expected in certain circumstances. ConnectWise has released ScreenConnect 26.6.5 to address the vulnerability, identified as CVE-2026-84869, and recommends affected organizations update as soon as possible.  

Continue reading
  279 Hits

Urgent N-central Hotfix: What Businesses Need to Know About the September 2026 Security Update

N-able N-central Hotfix 2026.3
If your IT provider or internal technology team uses N-able N-central, there is a new security update you should know about.

N-able released N-central 2026.3 Hotfix 3 on September 5, 2026, to address two high-severity security vulnerabilities. The flaws could allow an unauthorized person to bypass authentication controls and potentially gain full access to the N-central platform.
Continue reading
  353 Hits

It Wasn't a “Hack” It Was a Mistake Anyone Could Make: What the Manchester Airports Breach Teaches SMBs About Vendor Risk

Airport-flight-checkin
A breach that exposed the data of 8.7 million people didn't require nation-state malware or a zero-day exploit, it exploited exposed login credentials sitting in plain view in website code, tied to a third-party marketing platform. That's not a sophisticated attack. That's a mistake almost any business could make, which is exactly why every small and mid-sized business should be paying attention.
Continue reading
  258 Hits

AI Phishing Attacks Are Changing Fast: What Businesses Need to Know in 2026

AI-phishingv2

AI phishing attacks are making familiar cyber scams faster, more convincing, and harder for employees to recognize. Recent 2026 threat intelligence shows attackers expanding beyond email into Microsoft Teams, voice calls, trusted cloud services, and highly personalized messages. For businesses, protecting Microsoft 365 identities and training employees to verify unusual requests has become increasingly important.

Continue reading
  632 Hits

AI Coding Tools Got Hacked Into Hacking: What It Means for Your Business

AI_cyber_attack_Main
Hackers didn't need to write new malware, they just told a trusted AI coding assistant it was "running a test," and it happily helped them break into ten companies. If a $9-billion AI tool can be talked into attacking its own users, what's stopping the AI plugins already running inside your business?
Continue reading
  386 Hits

CMMC Level 2 Is on Hold: What Defense Contractors Need to Know

Government-Manufacturing

If you've been preparing your company for a CMMC Level 2 certification assessment, you may have heard some confusing news: the federal government has put CMMC Phase II on hold.

That part is true.

What isn't true is that CMMC has disappeared.

On July 13, 2026, the Department announced the immediate suspension of CMMC Phase II, which had been scheduled to begin November 10, 2026. At the same time, officials launched a 60-day review of the program. Phase I self-assessment requirements remain in place.

Continue reading
  340 Hits

Understanding the Difference Between Cybersecurity and Cybersecurity Risk

csr

In today's digital age, the terms "cybersecurity" and "cybersecurity risk" are often used interchangeably. However, they represent different concepts that are crucial for understanding how to protect information systems effectively. Let's delve into what these terms mean and how they relate to each other. 

Continue reading
  2493 Hits

Understanding email threats: The foundation of email security

email-bec-2431571581-1300x783

In today's digital landscape, email remains a fundamental communication tool for businesses. However, its ubiquity makes it a prime target for cyber threats. Understanding these threats is the first step in fortifying your email security. In this blog post, we'll explore the technical intricacies of various email threats and how you can protect your business from these ever-evolving dangers. 

Continue reading
  2605 Hits

How company size affects the email threats targeting your business

shutterstock_1727882452-1300x867

It takes less than a minute for someone to fall for a phishing scam. According to the 2024 Data Breach Investigations Report, the median time for a recipient to click on a malicious link after opening the email is 21 seconds, followed by 28 seconds to enter the requested data.

Continue reading
  2582 Hits

Top Breaches Cost ($) of 2024

HEALTHCARE
FINANCIAL
INDUSTRIAL
TECHNOLOGY
ENERGY
Source: IBM Cost of a Data Breach Report 2024