COMMAND.EXE

> Search or run a command

Commands: home latest search topic popular sudo surprise-me dark light subtle geek full geek rss status about

Ctrl + K search · / search · D dark mode · Esc close

TOPIC

Cybersecurity

17 articles

Security changes, vulnerabilities and practical resilience without turning every update into panic or theatre.

CURATED TOPIC HUB

Start here

13 articles · authority 65/100

AI Agents in the Enterprise: The Identity Problem Nobody Should Ignore
Latest in Cybersecurity

AI Agents in the Enterprise: The Identity Problem Nobody Should Ignore

The enterprise rush to deploy AI agents is running into a familiar problem in a new form: identity. If an agent can act, call tools, move data or trigger workflows, it needs a proper identity model, not a vague service account and a hope that logs will be enough. That shifts the discussion from ‘what can the model do?’ to ‘what can this agent prove it is allowed to do, and how is that enforced?’

> MORE IN CYBERSECURITY

CybersecurityTRENDINGVERIFIED SEP 2026

Critical RCE flaw affects Silicon One-based Cisco Nexus 9000 switches

Critical unauthenticated code execution in specified Silicon One-based Cisco Nexus 9000 switches can give a reachable attacker root privileges and reload the device. Operators should urgently establish exposure, restrict access and upgrade using Cisco’s platform-specific guidance.

Microsoft Entra ID: The Security Controls I Would Enable First
Cybersecurity

Microsoft Entra ID: The Security Controls I Would Enable First

If you are tightening up Microsoft Entra ID security, the first wins are usually not exotic: they are the controls that reduce password abuse, shrink admin exposure, and stop legacy sign-in paths from becoming an easy route in. The trick is to turn on the right controls in the right order, without breaking sign-in for the people who keep the business running.

Cybersecurity

Entra ID’s move from SMS/voice MFA to passkeys: what breaks

Microsoft is steering Entra ID away from SMS and voice MFA and towards passkeys. The shift is security-led, but it’s operationally risky: recovery, Conditional Access interactions, legacy apps, and helpdesk load can all change the outcome.

Cybersecurity

Entra ID passkeys become default as SMS/voice MFA retires

Microsoft will make passkeys the default sign-in method in Entra ID from 1 September 2026 and retire Microsoft-provided SMS and voice delivery on 1 February 2027. The key risk is strand-through: recovery and helpdesk flows that still assume telecom MFA.

CybersecurityVERIFIED AUG 2026

Jersey cyber law starts in September, but OES duties begin in December

Jersey’s Cyber Security Law takes effect in two stages: the JCSC gains statutory functions on 1 September, while OES security duties and 24-hour incident reporting begin on 1 December. Potential operators should use the gap to establish scope and response readiness.

Microsoft flags exploited SharePoint Server RCE as patching priority
CybersecurityVERIFIED AUG 2026

Microsoft flags exploited SharePoint Server RCE as patching priority

Microsoft lists CVE-2026-58644 as exploited in the wild. SharePoint Server operators should verify every farm meets the June fixed-build threshold, install the latest August cumulative updates and assess any previously exposed unpatched host for compromise.

Microsoft flags active exploitation of two SharePoint Server flaws
CybersecurityVERIFIED AUG 2026

Microsoft flags active exploitation of two SharePoint Server flaws

Microsoft has marked two SharePoint Server vulnerabilities as actively exploited. Organisations with internet-facing or previously exposed farms should patch to current builds, preserve evidence and assess whether attackers gained access before remediation.