Threat analysis, guidance and product news
Practical reads on cyber risk, compliance and threat intelligence from the FortaRisks team.
RSS feed- Third-Party Risk
The 5 questions to ask any vendor at a cyber trade show
Three hours in the aisles, fifteen business cards, and back at the office nothing tells them apart. Five questions that flip the conversation, what a real answer contains, and the three lines that should worry you.
September 22, 2026 · 6 min read - Threat Intelligence
The cyber week, risk lens: the code you run is not the code you approved
Week of 14 September 2026. CrowdSec discovers that 170 of its private repositories were copied back in May, through the account of a departed employee that was never revoked. Plugin4Shell defeats commit pinning across all four major AI coding agents. An abandoned CDN domain was re-registered, and thousands of sites still call it. On the infrastructure side, two Cisco products exploited in three days, vCenter picked up by ransomware crews, and five Canadian organizations claimed in one week.
September 18, 2026 · 14 min read - AI
AI security (4/8): your vendors are using AI, and nobody asked you
Every SaaS product in your stack added an AI assistant in eighteen months. Your data now flows through models and subprocessors you never assessed. The three risks that creates, the ten questions to add to your vendor questionnaire, and the clauses that hold.
September 17, 2026 · 6 min read - Threat Intelligence
CCQ: fifteen days without services for an entire industry, and what the recovery teaches
Intrusion on 24 August, website back on 2 September, data theft confirmed on the 4th, full restoration on the 8th. Qilin claims the data of 350,000 people. Five continuity and governance lessons from a cyberattack the whole Quebec construction industry lived through, and five actions for this week.
September 14, 2026 · 5 min read - Compliance
Cyber Resilience Act: as of this morning, you have 24 hours to report an exploited flaw
On 11 September 2026, Article 14 of the EU regulation enters into application. Twenty-four hours for the early warning, 72 hours for the notification, and a transitional clause that pulls your entire catalogue into scope, including products you sold ten years ago. What it changes for a Canadian manufacturer, and for the buyer you also are.
September 11, 2026 · 10 min read - Threat Intelligence
The cyber week, risk lens: the patch now arrives after the attacker
Week of 7 September 2026. Twelve actively exploited flaws added to KEV in one week, including a Cisco firewall console exploited by Qilin affiliates and a Sandworm-adjacent actor, MikroTik routers hijacked the day before the patch, a Magento zero-day exploited four days before the hotfix, and 966 Microsoft fixes in a single Tuesday. In Quebec, Qilin claims 350,000 records from the CCQ. And 8.8 million travellers exposed by an API key left in a website's code for four years.
September 11, 2026 · 11 min read - AI
AI security (3/8): the risks specific to large language models
Direct and indirect prompt injection, data leakage through the context window, hallucinations in production. Why your usual application controls see none of it, and the four controls that actually hold.
September 10, 2026 · 8 min read - Threat Intelligence
The cyber week, risk lens: your AI toolchain is now a target
Week of 31 August 2026. CISA adds seven actively exploited flaws and the pattern is impossible to miss: AI gateway, workflow orchestrator, artifact repository. Then two chained SonicWall zero-days, an OpenAI model that finds zero-days, 153 million driver's licences for sale and a fake acquisition worth 626,000 euros.
September 4, 2026 · 8 min read - AI
AI security (2/8): who answers for AI in front of leadership?
Roles, committee and a one-page usage policy. The minimum viable governance model for AI: who decides, who approves, who answers, and the four decisions to settle before writing anything.
September 3, 2026 · 6 min read
30 minutes to know what to fix first.
A member of our team walks you through FortaRisks on threats relevant to your sector, and you leave with your priorities. No chatbot.