DEFENCE
Security
EDR, Zero Trust, MFA, patching, IR, what actually works against modern threats.
Defensive coverage for people who have to hold the line: the controls that actually move the needle, the vulnerabilities worth patching first, and the attacks they are meant to stop. Cornerstones include the state of endpoint defence, zero trust beyond the buzzword, phishing-resistant MFA and defending Active Directory.
Check your own exposure with the free website security check and the FortiBleed checker.
Start here
- EDR, XDR, MDR: the state of endpoint defence
- Zero trust architecture: beyond the buzzword
- Phishing-resistant MFA that actually works
- Identity is the new perimeter: defending Active Directory
- Incident response: the first hour of a breach
- Patch management: why so many get it wrong
Latest security coverage
- Best VirusTotal alternatives 2026: what threat hunters runThe VirusTotal alternatives threat hunters run in 2026: MetaDefender, ANY.RUN, CAPE, Intezer and MalwareBazaar, compared by job, upload privacy and API.
- SOAR vs SIEM 2026: tune before you automateSOAR vs SIEM in 2026: they were never alternatives. Gartner marked standalone SOAR obsolete, and the automation now ships inside your SIEM or XDR.
- SIEM vs XDR 2026: retention is the deciding factorSIEM vs XDR in 2026: XDR wins on detection speed, SIEM wins on retention and audit. Which one you can drop comes down to your compliance obligations.
- wp2shell: pre-auth RCE in WordPress core (CVE-2026-63030)wp2shell chains a REST batch-route bypass and a SQL injection into pre-auth RCE on WordPress core. WordPress shipped forced auto-updates in 7.0.2, 6.9.5 and 6.8.6.
- GodDamn ransomware blinds EDR with a Microsoft-signed driverSymantec detailed GodDamn ransomware using PoisonX, a kernel driver with a valid Microsoft signature, to terminate EDR before it encrypts.
- macOS.Gaslight: malware that prompt-injects your SOCSentinelLABS found macOS.Gaslight, a DPRK-linked Rust backdoor that embeds 38 fake system messages to make AI malware-triage agents abort. It is the first implant built to attack the analyst’s LLM, not the sandbox.
- 292 fake GitHub repos push a hash-dodging infostealerArctic Wolf found 292+ fake GitHub repositories impersonating security and fintech brands to deliver a BoryptGrab-lineage infostealer, with payloads that rotate every 60 seconds.
- 570 flaws, 2 exploited: July Patch Tuesday hits identityMicrosoft’s July 2026 Patch Tuesday fixed a record 570 flaws and three zero-days, two already exploited in AD FS and SharePoint identity infrastructure.
- The Gentlemen weaponised a Kontron driver to kill EDRThe Gentlemen ransomware weaponised a zero-day in Kontron’s ktapi.sys driver to gain kernel access and kill EDR from Microsoft, ESET, Palo Alto, and SentinelOne, researchers found.
- FortiBleed: 75,000 cracked Fortinet firewalls, no zero-day neededFortiBleed exposed cracked admin passwords for around 75,000 Fortinet firewalls across 194 countries, roughly half the internet-facing fleet. There is no new zero-day. It is config exports, weak hashing, and recycled credentials, packaged as a sales catalog.
- Registrų centras breach: 600,000 records exposedLithuania’s Centre of Registers (Registrų centras) disclosed a May 2026 breach exposing roughly 600,000 records. Attackers reused credentials of authorised institutions, queried from abroad. Alerts.bar data shows 117 stealer-log accounts tied to the agency and 60+ live infected staff endpoints across the wider Lithuanian institutional ecosystem.
- RDP attacks 2026: ransomware’s #1 entry vectorRemote Desktop Protocol remains the single most-abused initial-access vector for ransomware operators in 2026. We break down the current attack patterns (credential stuffing, broker-sold access, BlueKeep-era CVE echoes, and weaponised RDS misconfigurations) and the controls that actually move the needle.
- Alerts.bar review 2026: dark-web monitoring testedAlerts.bar is a continuously-updated dark-web monitoring and stealer-log intelligence platform. We’ve used it in production to power Ransomnews’s free Stealercheck tool. Here’s our independent review: features, pricing, real-world testing, and how it stacks up against HIBP, SpyCloud, Constella, and Hudson Rock.
- SEC 4-day cyber rule: 2.5 years in, what CISOs learnedA 2026 retrospective on Item 1.05 of Form 8-K, the SEC’s four-day cyber-incident disclosure rule. How filings have actually played out, what the enforcement signals look like, and the practical playbook the better-prepared CISOs now run.
- MSPs: ransomware’s #1 target of 2026 [Field Report]Managed service providers entered 2026 as the single highest-leverage target class in the ransomware economy. Why the channel is now the front line, which TTPs operators are running against MSPs specifically, and what the better-run shops have already changed.
- LockBit, 2 years after Operation Cronos: where are they now?A 2026 retrospective on the international takedown that displaced LockBit at the top of the ransomware ecosystem: what stuck, what reverted, where the affiliate workforce migrated, and what the next coordinated action should learn from the playbook.
- MFA bypass via cookie theft: the #1 breach vector of 2026Through 2024 and 2025 a quiet rebalancing happened: password-phishing fell, session-cookie theft via infostealers surged, and “we have MFA” stopped meaning what defenders thought it meant. A 2026 field guide to the technique and the controls that actually answer it.
- 2026 ransomware victim toll: countries, sectors, operatorsA data-led snapshot of who’s actually being ransomed in 2026: which sectors are losing ground, which operators are pulling away from the pack, and which national-level patterns the leak-site economy reveals.
- What’s inside an infostealer log? A 2026 walkthroughA 2026 walkthrough of the typical infostealer-log archive: what files it contains, what each one means, and how defenders parse them with Python and jq for downstream incident response.
- Active Directory hardening 2026: Tier 0, DSRM, PRT theftA 2026 practitioner walkthrough of Active Directory hardening against the lateral-movement, credential-theft, and persistence techniques that modern ransomware operators rely on: Tier 0 isolation, DSRM rotation, PRT theft mitigation, and AD audit baselines.
- Ransomware IR runbook 2026: NIST 800-61 r3 + CISA templatesA practitioner walkthrough of building a ransomware-specific incident response runbook in 2026, combining NIST SP 800-61 r3, CISA’s #StopRansomware playbook, and the lessons from named incidents on the Ransomtracker leak feed.
- Attack-surface mapping 2026: Shodan, Censys, FOFA, NucleiA 2026 OSINT workflow for mapping the external attack surface of any organisation using only public data: internet-scan engines, certificate transparency, and authenticated vulnerability templates.
- Detecting AI-generated phishing in 2026: a header-forensics, classifier, and DKIM workflowA 2026 workflow for telling AI-generated phishing apart from real correspondence, combining email-header forensics, public LLM-detection classifiers, and DKIM/SPF replay analysis.
- How to set up YubiKey on every account that matters: a 2026 step-by-step tutorialA practitioner’s step-by-step tutorial for hardware-key MFA in 2026. Which YubiKey to buy, how to enroll it on Google, Microsoft, GitHub, AWS, and your password manager, plus the recovery-key gotcha that locks people out.
Every security article
Every article we have published in this section, newest first.
- Best VirusTotal alternatives 2026: what threat hunters run
- SOAR vs SIEM 2026: tune before you automate
- SIEM vs XDR 2026: retention is the deciding factor
- wp2shell: pre-auth RCE in WordPress core (CVE-2026-63030)
- GodDamn ransomware blinds EDR with a Microsoft-signed driver
- macOS.Gaslight: malware that prompt-injects your SOC
- 292 fake GitHub repos push a hash-dodging infostealer
- 570 flaws, 2 exploited: July Patch Tuesday hits identity
- The Gentlemen weaponised a Kontron driver to kill EDR
- FortiBleed: 75,000 cracked Fortinet firewalls, no zero-day needed
- Registrų centras breach: 600,000 records exposed
- RDP attacks 2026: ransomware’s #1 entry vector
- Alerts.bar review 2026: dark-web monitoring tested
- SEC 4-day cyber rule: 2.5 years in, what CISOs learned
- MSPs: ransomware’s #1 target of 2026 [Field Report]
- LockBit, 2 years after Operation Cronos: where are they now?
- MFA bypass via cookie theft: the #1 breach vector of 2026
- 2026 ransomware victim toll: countries, sectors, operators
- What’s inside an infostealer log? A 2026 walkthrough
- Active Directory hardening 2026: Tier 0, DSRM, PRT theft
- Ransomware IR runbook 2026: NIST 800-61 r3 + CISA templates
- Attack-surface mapping 2026: Shodan, Censys, FOFA, Nuclei
- Detecting AI-generated phishing in 2026: a header-forensics, classifier, and DKIM workflow
- How to set up YubiKey on every account that matters: a 2026 step-by-step tutorial
- Build a home SOC with Wazuh and Suricata: a 2026 indie security tutorial
- How to host Llama 3 70B locally with Ollama and Open WebUI: a 2026 tutorial
- How to red-team your own LLM app: tutorial with Garak, PyRIT, and Promptfoo
- How to investigate a phishing kit: tutorial with urlscan.io, PhishTank, and Sublime Security
- How to set up a malware analysis sandbox at home: FlareVM, REMnux, and Cuckoo tutorial
- How to build a threat actor profile from public sources: MITRE ATT&CK + Mandiant + Malpedia tutorial
- Defending against infostealers: tutorial with Defender for Endpoint, CrowdStrike, and browser hardening
- How session-cookie theft replaced password theft in 2026
- Stealer log forensics: tracing infections back to the user
- Scattered Spider in 2026: still the SIM-swap kings
- Why hospital ransomware attacks keep getting worse
- Bulletproof hosting in 2026: where attackers actually run their infrastructure
- MFA fatigue attacks are still working in 2026: here’s why and how to stop them
- The 5 most exploited CVEs of Q1 2026 and how to patch them first
- The browser extensions stealing your data right now (and how to spot them)
- How attackers are using AI agents to automate reconnaissance in 2026
- Hardening your home lab: the OPSEC checklist for indie security researchers
- EDR vs XDR vs MDR: a buyer’s tiebreaker in plain English (2026 edition)
- Prompt injection attacks: a 2026 field manual
- How shadow AI is leaking your company’s secrets, and how to find it
- Local AI vs cloud AI: the real security trade-offs in 2026
- AI in the SOC: where it’s actually working in 2026
- Learning OpenClaw: exposing dangerous defaults
- OPSEC for OSINT investigators: not contaminating what you research
- Detecting and responding to infostealer infections before they become breaches
- Session cookie theft: why MFA stops logins, not replays
- Identity is the new perimeter: defending Active Directory in 2026
- CVSS, EPSS, and the real-world risk of a vulnerability
- The software supply chain: from SolarWinds to XZ Utils
- Incident response: what the first hour of a breach should look like
- Cloud security posture: the top misconfigurations that cause breaches
- Patch management: why so many organizations get it wrong
- Anatomy of a modern phishing campaign
- Phishing-resistant MFA: which authentication methods actually work in 2026
- Zero trust architecture: beyond the buzzword
- EDR, XDR, MDR: the state of endpoint defence in 2026
- The different types of ransomware: from crypto-lockers to triple extortion
- How ransomware works: the full attack lifecycle, step by step
- What is ransomware? A plain-English guide to how it works, who it hits and what it costs























