
What a Compromised SaaS Integration Can Hand to an Extortion Group
Stolen OAuth tokens from a niche SaaS vendor were enough to exfiltrate Salesforce CRM data from nine cybersecurity firms, exposing integration ecosystem risk.
Practical tips, use cases, and news about AI for SMBs. Explore our latest articles.

Stolen OAuth tokens from a niche SaaS vendor were enough to exfiltrate Salesforce CRM data from nine cybersecurity firms, exposing integration ecosystem risk.

FortiBleed compromised over 30,000 Fortinet devices across 194 countries — no zero-days needed, just credentials left unchanged after a prior breach.

Three critical FortiSandbox vulnerabilities have been actively exploited since June 16, 2026, exposing the patch lag problem plaguing network appliances.

CVE-2026-20253 (CVSS 9.8): an unauthenticated component in Splunk Enterprise exposes AWS deployments to remote code execution — no credentials required.

A former IT tech sabotaged his ex-employer for 21 months via never-revoked credentials. What this conviction reveals about IT offboarding risk.

GreatXML, an unpatched zero-day, bypasses BitLocker through the Windows Recovery Environment. Here's what IT teams need to do right now.

One account compromised via social engineering was enough to expose 73,000 civil servants and 13.5 GB of data from a state-backed encrypted platform.

A critical flaw (CVSS 9.4) in Veeam Backup & Replication v12 allows any domain user to seize control of the backup server — no elevated privileges required.

CVE-2026-23111: a use-after-free flaw in nftables enables root escalation and container escape. Working exploits have been public since June 8.

Fake IT helpdesk calls, remote desktop takeovers, and rapid ransom demands: vishing now targets professional services firms — including through physical intrusion.

A seventh actively exploited zero-day hits Cisco Catalyst SD-WAN Manager in 2026: root-level privilege escalation, no patch available, all deployments affected.

In March 2026, 230 AWS, Azure and GCP cloud servers were silently hijacked to form a criminal email relay network — without their owners' knowledge.

Fewer than twenty encrypted vaults stolen via TOTP brute-force: the Dashlane incident exposes the transparency gaps security vendors too often hide.