by Matt Tankersley | Jun 30, 2026 | CYBERSECURITY
⏱ 6 min read Key Takeaways Texas cybersecurity law already requires every business, regardless of size, to protect sensitive personal information and report breaches within 60 days of discovery. SB 2610 offers a safe harbor from punitive damages — but only if you can...
by Matt Tankersley | Apr 16, 2026 | CYBERSECURITY
⏱ 3 min read Key Takeaways NIST stopped automatic CVSS scoring for most CVEs on April 15 — the patch prioritization signal most organizations relied on just changed permanently. Only CVEs on CISA's KEV list, federal software, and EO 14028 critical software receive...
by Matt Tankersley | Apr 7, 2026 | CYBERSECURITY, STOP the #CYBERinsanity
⏱ 4 min read Key Takeaways Device code phishing abuses a legitimate Microsoft OAuth flow — no passwords stolen, no MFA prompt triggered, full M365 access granted. AI-generated lures are now role-specific and hyper-personalized — standard phishing training won’t...
by Matt Tankersley | Apr 2, 2026 | CYBERSECURITY
⏱ 4 min read Key Takeaways This chrome zero day patch isn’t routine maintenance — it covers two vulnerabilities already being weaponized. CVE-2026-5289 scored a 9.6 CVSS — a full sandbox escape. If exploited, an attacker owns the endpoint. CISA added CVE-2026-5281 to...
by Matt Tankersley | Mar 31, 2026 | CYBERSECURITY, STOP the #CYBERinsanity
⏱ 4 min read Key Takeaways Newly disclosed Russian remote access toolkit called CTRL is enabling remote desktop hijacking attacks that bypass all known threat intelligence platforms — including VirusTotal CTRL is a newly disclosed Russian-origin remote access toolkit...
by Matt Tankersley | Mar 24, 2026 | CYBERSECURITY, STOP the #CYBERinsanity
⏱ 5 min read Key Takeaways 32% of the most active exploits are old vulnerabilities, more than ten years old — patches exist, they’re just not being applied. Attackers start with the low-hanging fruit: automated scans for known, unpatched flaws before deploying...