
28 September 2026
The most common critical vulnerability in web applications has remained unchanged for years. We find it in every third test, and no firewall can stop it because the attacker uses exactly what the application is permitted to do.

16 September 2026
71% of the infrastructure projects we tested contained at least one critical vulnerability. Most of these vulnerabilities were hidden in systems that companies considered secure simply because they were “not publicly accessible.

11 September 2026
The greatest cybersecurity risk in 2026 is no longer limited to your internet-facing infrastructure. It is everything you already consider secure. In the first part of this series, we examine where critical risks are now emerging and what CISOs can do about them.

17 August 2026
For an actively exploited vulnerability, you have 24 hours to file the first report.

14 August 2026
Product security used to be a commercial decision. The Cyber Resilience Act turns it into a condition for market access in the EU. Here is who the regulation covers, what it requires, which deadlines apply, and where to start.

9 July 2026
Even today, many organizations are still asking the same questions about NIS2.