Aura, the consumer digital safety company known for identity protection and fraud monitoring, recently confirmed a data breach that exposed nearly 900,000 marketing contacts. What seems like a single shocking number actually reveals deeper problems: legacy data inherited through acquisitions, the continued effectiveness of social-engineering attacks, and the tricky line between marketing lists and active customer records. This incident is
Latest Articles

Attackers Exploit SharePoint Authentication Bypass After Public PoC Release
Microsoft’s SharePoint platform is facing active exploitation following the public release of a proof-of-concept (PoC) for a critical authentication bypass vulnerability tracked as CVE-2026-55040. Patched in July’s Patch Tuesday, the flaw allows unauthenticated actors to impersonate SharePoint users by forging JSON Web Tokens (JWTs). Since the PoC surfaced, security researchers and telemetry providers have observed real-world attempts that underscore the urgency for administrators to apply updates and audit their environments. What happened Microsoft disclosed CVE-2026-55040 as a high-severity authentication feature…
Continue readingTwo Words, One Deal: How “Stateful” vs “Stateless” Could Decide a $50 Billion Cloud Dispute
Last week’s reporting brought into sharp relief a narrowly technical — but potentially enormous — dispute between Microsoft, Amazon and OpenAI over a reported $50 billion commercial arrangement. At the center of the controversy are two terms engineers use every day: “stateful” and “stateless.” Depending on how those words are interpreted, Microsoft may have grounds to claim a breach of
OpenAI’s New North Star: Report Says Business and Productivity Take Center Stage
Last week, details from an internal all‑hands meeting at OpenAI were reported by the Wall Street Journal and subsequently picked up by other outlets. According to the reporting, company leaders signaled a strategic shift toward prioritizing business and productivity use cases, with executives urging teams to focus on core, revenue‑driving efforts rather than exploratory side projects. What was reported at
Stryker Confirms Massive Wiper Strike — Thousands of Devices Erased in Alleged Iran-Linked Operation
Stryker, the global medical technology company, confirmed on March 11, 2026, that it suffered a significant, destructive cyberattack that disabled large parts of its corporate Microsoft environment and resulted in the wiping of thousands of devices. The company characterized the incident as a deliberate data-destruction operation rather than a ransomware extortion scheme, and investigators and security firms have pointed to
Microsoft Plans to Disable Hands‑Free Automated Installation for Windows 11 and Server 2025 After Critical RCE Flaw
Microsoft has announced a hardening plan for Windows Deployment Services (WDS) after the discovery of a critical remote code execution vulnerability, CVE-2026-0386, that compromises hands‑free automated installations. The vulnerability exposes Unattend.xml answer files over an unauthenticated channel, allowing an attacker on the same network segment to intercept or tamper with deployment configurations. For organizations that depend on network-based provisioning to
Hotpatch Alert: Microsoft Fixes Critical RRAS Remote-Execution Flaws in Windows 11
Microsoft issued an out-of-band hotpatch on March 13, 2026, to address a set of serious vulnerabilities in the Windows Routing and Remote Access Service (RRAS) management tool that affect Windows 11. The update, tracked as KB5084597 and aimed at OS builds 26200.7982 (25H2) and 26100.7982 (24H2), patches three CVEs that can allow a remote attacker to disrupt RRAS or execute





