A highly critical vulnerability has been disclosed in Drupal core affecting sites running a PostgreSQL database backend. Tracked as CVE-2026-9082, this flaw requires no authentication and allows remote attackers to potentially extract administrator credentials or gain full site control.
Threat intelligence tracks already show over 15,000 exploitation attempts globally.
In our latest blog post, Dr. Yunfei Ge breaks down the two independent attack vectors and details immediate remediation protocols. RidgeBot users can already automatically detect this vulnerability without manual configuration.
๐ Read more: https://t.co/YJtRjlXXAa
#Cybersecurity #ThreatIntel #Drupal #PostgreSQL #ApplicationSecurity
We're proud to see our president and co-founder, @linglingsan, featured by @blrmagazine, sharing her journey and perspective on the future of cybersecurity leadership. ๐ https://t.co/bXr4dmtZuJ
Cybersecurity leadership is about more than defending against threats โ itโs about driving innovation, resilience, and business outcomes.
#RidgeSecurity #Cybersecurity #Leadership #CyberResilience
We're live at Gartner Security & Risk Management Summit, Day 1. Come find us at Booth 251. Our experts are onsite all day โ stop by, ask the hard questions, and let's talk through what's actually going on in your environment and how we can help.
#GartnerSEC #RidgeSecurity #Cybersecurity
We will be at the @Gartner_inc Security & Risk Management Summit this year! Stop by Booth 251 for a live demo. Weโll show you how RidgeBot cuts through the noise to instantly prioritize threats and deliver clear remediation steps.
Want to make sure we connect? Comment below and we'll set aside dedicated time for you.
And if you haven't registered yet, save $450 on your ticket. ๐ Use code SEC32EDC
Hope to see you there! #GartnerSEC
For years, annual pentests have been treated as a compliance checkbox. Run the test, file the report, move on. But the environments we're defending today look nothing like they did when that model was designed.
Cloud infrastructure spins up overnight. APIs multiply. Dependencies shift. Every change is a potential new exposure, and most organizations won't know about it until next year's test.
The more important shift happening now isn't just about frequency. It's about how we think about risk.
@eSecurityPlanet captured this shift well in a recent piece featuring Ridge Security's @linglingsan. If you're responsible for your organization's security posture, it's worth 4 minutes of your time.
๐ Read the full article
https://t.co/mVjNTkxS4d
๐The 2026 Data Breach Investigations Report from Verizon reflects a threat environment that is not only growing in volume but shifting in character. Here are the findings that matter most for security teams: https://t.co/p5yWhBEZqr
#Cybersecurity#DBIR#VerizonDBIR#Infosec #SecurityTeams
Join Dan Mrvos and Eric Bowerman next Thursday 10 AM PT ยท LinkedIn Live ๐ Register: https://t.co/lKpwq73N0n
Eric Bowerman, CISO at DFW Airport, will tell you straight: they got off to a rough start with AI adoption.
People were bringing tools in, and they had to start backing out of things.
Figuring out which LLMs are safe, what data can go where, and how to actually make it useful for the team.
#Cybersecurity #CISO #SecurityLeadership #CISOCommunity
The 2026 Verizon DBIR analyzed 22,000+ confirmed breaches across 145 countries. Here are the numbers:
๐ 31% โ breaches starting with vulnerability exploitation (now #1, up from #2)
๐ 13% โ breaches via stolen credentials (used to be #1)
๐ 43 days โ median time to fully patch (up from 32 last year)
๐ 26% โ share of critical CVEs actually remediated (down from 38%)
๐ 48% โ breaches involving ransomware
๐ 69% โ ransomware victims who did NOT pay
๐ 60% โ increase in third-party involved breaches
๐ 40% โ higher click rate on mobile phishing vs. email
๐ 45% โ employees using AI on corporate devices (up from 15% last year)
๐ 15 โ median number of attack techniques where threat actors used GenAI
The theme of this year's report: "keeping a strong foundation in the face of change."
AI is accelerating attacks. Patch windows are shrinking. Third-party exposure is exploding. And shadow AI is quietly leaking source code to unauthorized tools.
The fix is unglamorous: patch faster, enforce MFA, manage your vendors, govern AI use.
Attackers are getting faster. The fundamentals can't wait.
๐ Full report: https://t.co/idXyh5m0Bc
#Cybersecurity #DBIR2026 #InfoSec #DataBreach #CyberRisk #AI
๐๏ธ Join us live next Thursday at 10:00 AM Pacific to hear the full conversation: https://t.co/6puPFm0ii0 | Most security metrics mean nothing to your board. Eric Bowerman, CISO at Dallas Fort Worth Airport, figured out how to change that.
#Cybersecurity#CISO#InfoSec #SecurityLeadership #CriticalInfrastructure #CISOCommunity
What does it actually take to secure one of the busiest airports in the world? Register for the premiere to catch the full conversation โ https://t.co/6puPFm0Q7y | In this episode in partnership with @thedaniwoolf, Dan Mrvos sits down with Eric Bowerman, CISO at Dallas Fort Worth Airport, to unpack what it's really like to run security for an organization that is, quite literally, its own city.
Eric shares how he thinks about nation-state threats he can't fully prevent, why resilience has become as important as protection, how he frames security metrics in a way that actually resonates with his board, and what emerging threats โ from AI chatbots to autonomous vehicles โ are flying under the radar.
๐ก๏ธThis conversation will change how you think about what it means to truly protect an organization that can never go down.
We are excited to announce our participation in this yearโs CYBR.HAK.CON in Plano, Texas. As the threat landscape evolves, staying ahead of vulnerabilities is more critical than ever. Join us on May 27!
Visit https://t.co/WGCwOCFUlb for full event details and registration.
#CyberSecurity #CYBRHAKCON #RidgeSecurity #InfoSec
Agentic AI in security is a hot topic, but itโs rarely demonstrated. On May 21, weโre changing that with a live session. Register: https://t.co/PfHKJQJzS0
Join us for a LinkedIn Live to see PurpleRidge in action. Witness exactly how an AI reasons through an application, chains exploits, and validates findings, all without a human in the loop.
โญ๏ธ Get 100 Free Credits
Want to test it yourself before the session? Sign up now to get 100 free credits. Run a full agentic AI pentest on any domain you own and see the results instantly. ๐ Claim your credits & try it free: https://t.co/WDdkhmrdIy
#CyberSecurity #AgenticAI #Pentesting #PurpleRidge #InfoSec #AI
Government and public sector teams operate in complex environments with legacy systems, rapid cloud adoption, strict compliance requirements, and an expanding attack surface.
RidgeBot helps organizations, including government agencies, identify and validate exploitable risks across hybrid environments using automated offensive security testing.
Weโre honored to be recognized by Security Today for the innovation behind RidgeBot.
Read more: https://t.co/pSbCebTVt1
#GOVIES #Cybersecurity #Pentesting #Government #AIPowered #OffensiveSecurity #RidgeBot
๐จOne JWT vulnerability. Twelve cascading findings. That's what happened when Ken Huang benchmarked RidgeGen against OWASP Juice Shop.
Full analysis โ https://t.co/TrR3QyN4iB
After confirming a JWT alg:none bypass, RidgeGen didn't log the finding and move on. It updated its model of the application's authentication surface and reprioritized everything downstream:
โ Role claims in forged tokens accepted server-side โ vertical privilege escalation
โ Admin access confirmed โ full API surface enumeration
โ /api/Users/:id โ account takeover via mass assignment
โ /api/Products/:id โ unauthenticated price and description manipulation
โ 12 IDOR vulnerabilities across basket, address, complaint, and privacy endpoints
โ Admin-level enumeration and deletion across feedback, complaints, and user records
Neither of the two competing frameworks in the benchmark found any of these. They stopped at the first layer.
Huang calls the underlying failure "belief state amnesia" โ when a system can't maintain coherent knowledge about what it's learned across a session, it can't reason about the implications of its discoveries. It logs findings sequentially instead of asking: given what I now know, what else becomes possible?
This is what we built RidgeGen to do differently. The architecture maintains a persistent, structured model of what has been tested, what has been confirmed, and what attack paths remain open โ and updates that model after every significant finding.
All three platforms in Huang's benchmark used the same LLM. The difference is entirely the system design.
Full analysis โ https://t.co/TrR3QyN4iB
#CyberSecurity #PenetrationTesting #AIpentesting #AppSec #RidgeSecurity
Ken Huang benchmarked three platforms against OWASP Juice Shop under identical conditions: same target, same URL, same LLM backend (Gemini 3 Flash), network-isolated, with anti-cheat controls in place.
His core argument: the phrase "agentic AI pentester" has been stretched so thin it no longer means anything. Glorified scanners, pre-defined payload libraries, decision trees with an LLM on the output โ all marketed with words like "AI-driven exploitation" and "autonomous reasoning."
๐ฏ The benchmark puts a number on that gap:
โข RidgeGen: 55 findings โ 0% hallucination rate
โข Shannon: 27 findings โ 63% unconfirmed (no execution evidence)
โข Strix: 6 findings โ all confirmed, but 95% of attack surface unexplored
Huang's methodology note is the most important part: all three platforms used the same model. The 55 vs. 6 finding gap isn't about which LLM you're running. It's entirely about system architecture โ how a platform plans, maintains state, validates findings, and chains discoveries.
The 63% unconfirmed rate on Shannon's findings isn't a minor quality issue. When unconfirmed findings mix with real ones in a report, every result requires a meta-level judgment from the analyst reviewing it. That overhead compounds โ and ultimately destroys trust in the platform's output.
Worth a read for anyone evaluating or building in this space: https://t.co/TrR3QyN4iB
#CyberSecurity #AIpentesting #AppSec #AgenticAI
Cisco recently disclosed several critical vulnerabilities in Catalyst SD-WAN Manager, some of which are actively being exploited in the wild. As a result, CISA has added these flaws (CVE-2026-20128, CVE-2026-20133, and CVE-2026-20122) to its Known Exploited Vulnerabilities (KEV) Catalog, highlighting the immediate risk to network infrastructure.
Learn more: https://t.co/VBc868IWtA
#CVE #KEV #RidgeBot #AgenticAI