Skip to main content

Topic

Emerging Issue

Line chart of total daily vulnerability findings from Tanium Exposure Management, holding near 20 billion from August 2025 through mid-June 2026 before spiking to roughly 100 billion by August 2026

Daily vulnerability findings across Tanium customer environments jumped from 10-40 billion to as high as 101 billion after mid-June 2026. Here is what is driving the surge and how to keep up.

Featured image for Latest agentic AI developments and industry trends blog post

A practitioner's guide to the capability shifts, framework changes, and regulatory developments reshaping how enterprise IT and cybersecurity teams govern, deploy, and defend against autonomous agents.

CTI blog image

A critical, unauthenticated remote code execution vulnerability in Windows Netlogon (CVE-2026-41089, CVSS 9.8) lets a remote attacker run code as SYSTEM on a domain controller. Patch all domain controllers in the same maintenance window with the May 2026 security updates.

Featured image for Locked Shields and the OSI Model: Stop blaming the firewall blog post

A back-to-basics walk through what blue teams actually defend at each layer, and why the unglamorous stuff (Layer 2, BGP) keeps deciding the scoreboard.

Featured image for GitHub breach: What the incident really tells security teams about extension hygiene blog post

On May 20, 2026, GitHub disclosed that an employee device was compromised through a malicious VS Code extension, with attackers claiming to have exfiltrated roughly 3,800 internal repositories.

Featured image for Mini Shai-Hulud supply chain attack blog post

The Mini Shai-Hulud supply chain attack compromised more than 170 packages across npm and PyPI, including packages from TanStack, Mistral AI, and Guardrails AI, by hijacking legitimate CI/CD publishing workflows to distribute malicious versions that still carried apparently valid provenance signals.

Featured image for s Windows Autopatch ready for enterprise use, or does it trade too much control for convenience blog post

Windows Autopatch is a Microsoft service, included with Windows Enterprise E3 and above, that automates the scheduling and deployment of Windows quality updates, driver updates, and Microsoft 365 app updates across Intune-managed devices. It reduces the manual overhead of patch scheduling by managing update rings and cadence on your behalf, but it does so by abstracting away the granular controls that enterprise patch management workflows typically depend on.

Featured image for Copy Fail (CVE-2026-31431): What Linux administrators need to know now blog post

Copy Fail, or CVE-2026-31431, is a Linux kernel local privilege escalation vulnerability that can let an unprivileged local user corrupt page-cache-backed file data under specific conditions and potentially escalate privileges. Exposure depends on the running vendor kernel and backported fixes. Installing a vendor-provided kernel fix is the primary remediation, with temporary mitigations available in some environments if patching is delayed.

How Mythos is reshaping enterprise security posture video thumbnail

Tanium CRO Pedro Diaz and Sr. Director of Solution Engineering Mark Liu break down why Anthropic's Mythos model is fundamentally changing the threat landscape, and what enterprise security teams must do right now to keep pace with machine-speed attacks.

Featured image for Vercel security incident blog post

Public reporting suggests the incident involved abuse of a third-party application that had been granted OAuth access to a Vercel employee account, enabling unauthorized access to some internal resources. Certain customer‑related tokens, environment variables, or other access artifacts may have been exposed, though Vercel has not stated that password theft was part of the initial access path. The breach illustrates how trusted SaaS integrations and delegated access have become a significant attack surface for enterprises with interconnected developer workflows, even when no software vulnerability in production infrastructure is exploited.

Featured blog image for Understanding shadow AI in your endpoint environment

Learn how shadow AI appears on endpoints, from local models to MCP servers, and why visibility, governance, and secure configuration matter now.

Blog image for Claude Mythos security risks

Anthropic's Claude Mythos Preview demonstrated significant acceleration in capabilities for autonomously identifying vulnerabilities and exploit chains across major software and operating systems. Government and industry leaders are focused on understanding the real risks the model presents, and how to leverage these advanced technologies to protect and defend against adversarial use.