Glossary
Attack Surface
The complete set of points where an unauthorized user could attempt to enter or extract data from a system, including software, hardware, network interfaces, and human users. Reducing the attack surface — by disabling unused services, closing unnecessary ports, and limiting exposed endpoints — is a core defensive strategy.
Recent coverage mentioning Attack Surface
MikroTik RouterOS Critical Flaws Chained to Hack Routers
Critical vulnerabilities in MikroTik RouterOS, including CVE-2026-67276 and CVE-2026-86060, are actively exploited to gain full control of routers. Patch immediately.
BigBear PhaaS Bypasses Microsoft 365 MFA at 258 Orgs
BigBear 2.0 PhaaS uses Evilginx2 AiTM to bypass Microsoft 365 MFA, stealing credentials and session cookies from 258 organizations.
METR Suffers API Key Credential Theft, $600,000 Loss
AI model evaluator METR experienced credential theft, leading to an API key compromise and $600,000 in public AI model credit consumption.
CVE-2026-59346: VMware Workstation & Fusion RCE Patch
Broadcom patches critical arbitrary code execution flaws (CVE-2026-59346, CVE-2026-59347) in VMware Workstation and Fusion, impacting host systems from compromised VMs.
39 Methods Compromise Passkey Authentication: Threat Analysis
Discover 39 published methods compromising passkey authentication, focusing on ecosystem flaws, UI manipulation, and enrollment abuse.
CVE-2026-19490: Citrix NetScaler Auth Bypass Under Attack
Critical Citrix NetScaler authentication bypass (CVE-2026-19490) is actively exploited in the wild, allowing remote unprivileged access.
Advertisement