<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>FortaRisks Blog</title>
    <link>https://www.fortarisks.com/en/blog</link>
    <description>Cybersecurity risk analysis correlating your security posture with live threat intelligence.</description>
    <language>en</language>
    <atom:link href="https://www.fortarisks.com/en/blog/rss.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>This week in cyber: SD-WAN under attack, and ransomware comes for energy and manufacturing</title>
      <link>https://www.fortarisks.com/en/blog/sd-wan-under-attack-ransomware-energy-manufacturing</link>
      <guid isPermaLink="true">https://www.fortarisks.com/en/blog/sd-wan-under-attack-ransomware-energy-manufacturing</guid>
      <pubDate>Mon, 08 Jun 2026 00:00:00 GMT</pubDate>
      <description>A CVSS 10 SD-WAN flaw with rogue peers in the wild, a fresh Cisco zero-day, and ransomware crews hitting a Canadian energy services firm and a UK machinery maker. The week&apos;s signal for critical-infrastructure teams, minus the noise.</description>
    </item>
    <item>
      <title>Radiology, Oncology, DocketWise: Three Breaches in One Week That Reshape Your Healthcare and Legal Third-Party Risk</title>
      <link>https://www.fortarisks.com/en/blog/radiology-oncology-docketwise-three-breaches-in-one-week-healthcare-legal-third-party-risk</link>
      <guid isPermaLink="true">https://www.fortarisks.com/en/blog/radiology-oncology-docketwise-three-breaches-in-one-week-healthcare-legal-third-party-risk</guid>
      <pubDate>Fri, 29 May 2026 00:00:00 GMT</pubDate>
      <description>Three US healthcare and legal breaches in one week prove your real exposure runs through your vendors&apos; vendors. A 30-day third-party risk loop.</description>
    </item>
    <item>
      <title>Defender and Apex One Under Fire: When the Antivirus Becomes the Attacker&apos;s Weapon</title>
      <link>https://www.fortarisks.com/en/blog/defender-and-apex-one-under-fire-when-the-antivirus-becomes-the-attackers-weapon</link>
      <guid isPermaLink="true">https://www.fortarisks.com/en/blog/defender-and-apex-one-under-fire-when-the-antivirus-becomes-the-attackers-weapon</guid>
      <pubDate>Tue, 26 May 2026 00:00:00 GMT</pubDate>
      <description>CISA added three endpoint-security zero-days to KEV in 72 hours. Why defense tools are now prime targets, plus a 6-step EDR remediation loop.</description>
    </item>
    <item>
      <title>Canvas, 275 Million Records: What This Breach Forces You to Rethink in Third-Party Risk</title>
      <link>https://www.fortarisks.com/en/blog/canvas-275-million-records-what-this-breach-forces-you-to-rethink-in-third-party-risk</link>
      <guid isPermaLink="true">https://www.fortarisks.com/en/blog/canvas-275-million-records-what-this-breach-forces-you-to-rethink-in-third-party-risk</guid>
      <pubDate>Tue, 19 May 2026 00:00:00 GMT</pubDate>
      <description>The ShinyHunters attack on Canvas exposes a SaaS concentration problem, not just a vendor one. Three board questions and a 6-step third-party loop.</description>
    </item>
    <item>
      <title>AI vs AI: Why Your Cyber Defense Must Also Be AI-Augmented</title>
      <link>https://www.fortarisks.com/en/blog/ai-vs-ai-why-your-cyber-defense-must-also-be-ai-augmented</link>
      <guid isPermaLink="true">https://www.fortarisks.com/en/blog/ai-vs-ai-why-your-cyber-defense-must-also-be-ai-augmented</guid>
      <pubDate>Fri, 15 May 2026 00:00:00 GMT</pubDate>
      <description>Attackers now wield AI like Mythos, so defense must be AI-augmented too. Five defensive use cases that work in 2026, and what AI should never do.</description>
    </item>
    <item>
      <title>Mythos Explained to the Board: 5 Strategic Questions Before Your Next Committee</title>
      <link>https://www.fortarisks.com/en/blog/mythos-explained-to-the-board-5-strategic-questions-before-your-next-committee</link>
      <guid isPermaLink="true">https://www.fortarisks.com/en/blog/mythos-explained-to-the-board-5-strategic-questions-before-your-next-committee</guid>
      <pubDate>Fri, 08 May 2026 00:00:00 GMT</pubDate>
      <description>Anthropic&apos;s Mythos finds and exploits software flaws in hours. Why that makes AI risk a board topic, and 5 questions to ask your CISO this week.</description>
    </item>
    <item>
      <title>Mythos and the AI Storm: Why Your Cyber Program Must Change Now</title>
      <link>https://www.fortarisks.com/en/blog/mythos-and-the-ai-storm-why-your-cyber-program-must-change-now</link>
      <guid isPermaLink="true">https://www.fortarisks.com/en/blog/mythos-and-the-ai-storm-why-your-cyber-program-must-change-now</guid>
      <pubDate>Fri, 01 May 2026 00:00:00 GMT</pubDate>
      <description>The Cloud Security Alliance&apos;s emergency briefing on a Mythos-ready program: the attacker/defender asymmetry and 5 actions to launch this week.</description>
    </item>
    <item>
      <title>Two US Banks, One Vendor: 11 Third-Party Vulnerabilities Invisible to Questionnaires</title>
      <link>https://www.fortarisks.com/en/blog/two-us-banks-one-vendor-11-third-party-vulnerabilities-invisible-to-questionnaires</link>
      <guid isPermaLink="true">https://www.fortarisks.com/en/blog/two-us-banks-one-vendor-11-third-party-vulnerabilities-invisible-to-questionnaires</guid>
      <pubDate>Fri, 24 Apr 2026 00:00:00 GMT</pubDate>
      <description>Everest ransomware hit two US banks through one shared vendor. The 11 third-party vulnerabilities annual questionnaires never see, and how to fix them.</description>
    </item>
    <item>
      <title>Cyber Insurance 2026: 7 Criteria Insurers Check Before Covering You</title>
      <link>https://www.fortarisks.com/en/blog/cyber-insurance-2026-7-criteria-insurers-check-before-covering-you</link>
      <guid isPermaLink="true">https://www.fortarisks.com/en/blog/cyber-insurance-2026-7-criteria-insurers-check-before-covering-you</guid>
      <pubDate>Fri, 17 Apr 2026 00:00:00 GMT</pubDate>
      <description>Cyber insurance is now a security-posture audit. The 7 criteria insurers check, what raises or lowers your premium, and how to pass first time.</description>
    </item>
    <item>
      <title>Chaos ransomware: 36 victims in March, and your OT sector is next</title>
      <link>https://www.fortarisks.com/en/blog/chaos-ransomware-36-victims-in-march-and-your-ot-sector-is-next</link>
      <guid isPermaLink="true">https://www.fortarisks.com/en/blog/chaos-ransomware-36-victims-in-march-and-your-ot-sector-is-next</guid>
      <pubDate>Fri, 10 Apr 2026 00:00:00 GMT</pubDate>
      <description>Chaos ransomware claimed 36 victims in March, mostly construction and manufacturing. How victimology turns that signal into an early-warning window.</description>
    </item>
    <item>
      <title>Living off the Land: Your Legitimate Tools Have Become Your Worst Attackers</title>
      <link>https://www.fortarisks.com/en/blog/living-off-the-land-your-legitimate-tools-have-become-your-worst-attackers</link>
      <guid isPermaLink="true">https://www.fortarisks.com/en/blog/living-off-the-land-your-legitimate-tools-have-become-your-worst-attackers</guid>
      <pubDate>Fri, 03 Apr 2026 00:00:00 GMT</pubDate>
      <description>In 2026 sophisticated attacks drop no malware. They abuse admin consoles, OAuth and signed installers. Why EDRs miss them, and five fixes this week.</description>
    </item>
    <item>
      <title>Critical CVE in 2026: 20 Hours to React, Not 54 Days</title>
      <link>https://www.fortarisks.com/en/blog/critical-cve-in-2026-20-hours-to-react-not-54-days</link>
      <guid isPermaLink="true">https://www.fortarisks.com/en/blog/critical-cve-in-2026-20-hours-to-react-not-54-days</guid>
      <pubDate>Fri, 27 Mar 2026 00:00:00 GMT</pubDate>
      <description>The gap between a critical CVE going public and first exploitation fell from 54 days to under 20 hours. What it means for CISOs and how to keep up.</description>
    </item>
    <item>
      <title>SBOM: understanding and managing your software supply chain</title>
      <link>https://www.fortarisks.com/en/blog/sbom-understanding-and-managing-your-software-supply-chain</link>
      <guid isPermaLink="true">https://www.fortarisks.com/en/blog/sbom-understanding-and-managing-your-software-supply-chain</guid>
      <pubDate>Fri, 20 Mar 2026 00:00:00 GMT</pubDate>
      <description>In 2026, the SBOM has become one of cybersecurity&apos;s critical artifacts. Why it matters, its priority use cases, and how to get started in four steps.</description>
    </item>
    <item>
      <title>Cybersecurity trends for 2026: understanding the risks ahead</title>
      <link>https://www.fortarisks.com/en/blog/cybersecurity-trends-for-2026-understanding-the-risks-ahead</link>
      <guid isPermaLink="true">https://www.fortarisks.com/en/blog/cybersecurity-trends-for-2026-understanding-the-risks-ahead</guid>
      <pubDate>Fri, 13 Mar 2026 00:00:00 GMT</pubDate>
      <description>In 2026 cyber risk gets faster and more sophisticated. A clear view of the threats ahead, their impact, and concrete actions to take now.</description>
    </item>
    <item>
      <title>Cyber risk mapping: why it matters and how to do it</title>
      <link>https://www.fortarisks.com/en/blog/digital-risk-management-cyber-risk-mapping-why-it-matters-and-how-to-do-it</link>
      <guid isPermaLink="true">https://www.fortarisks.com/en/blog/digital-risk-management-cyber-risk-mapping-why-it-matters-and-how-to-do-it</guid>
      <pubDate>Sun, 01 Mar 2026 00:00:00 GMT</pubDate>
      <description>Digital risk management is now a strategic priority. How cyber risk mapping gives you the visibility and prioritization to reduce exposure effectively.</description>
    </item>
    <item>
      <title>Executive Committee Memo: The 10 Questions That Prevent a &quot;Cyber Surprise&quot; in 2026</title>
      <link>https://www.fortarisks.com/en/blog/executive-committee-memo-the-10-questions-that-prevent-a-cyber-surprise-in-2026</link>
      <guid isPermaLink="true">https://www.fortarisks.com/en/blog/executive-committee-memo-the-10-questions-that-prevent-a-cyber-surprise-in-2026</guid>
      <pubDate>Sat, 14 Feb 2026 00:00:00 GMT</pubDate>
      <description>A practical, non-technical framework of 10 questions every Executive Committee should ask to turn reassuring cyber statements into measurable proof.</description>
    </item>
    <item>
      <title>Cybersecurity Operating Model: 9 Dimensions for Resilience</title>
      <link>https://www.fortarisks.com/en/blog/cybersecurity-operating-model-9-dimensions-for-resilience</link>
      <guid isPermaLink="true">https://www.fortarisks.com/en/blog/cybersecurity-operating-model-9-dimensions-for-resilience</guid>
      <pubDate>Thu, 20 Feb 2025 00:00:00 GMT</pubDate>
      <description>The nine dimensions of a solid cybersecurity operating model, from business impact and CTI to identity and compliance, and why correlation wins.</description>
    </item>
    <item>
      <title>2025: The Turning Point That Reshaped Cyber Risk</title>
      <link>https://www.fortarisks.com/en/blog/2025-the-turning-point-that-reshaped-cyber-risk</link>
      <guid isPermaLink="true">https://www.fortarisks.com/en/blog/2025-the-turning-point-that-reshaped-cyber-risk</guid>
      <pubDate>Fri, 14 Feb 2025 00:00:00 GMT</pubDate>
      <description>How 2025 industrialized cybercrime around access and identity: record ransomware, the infostealer surge, offensive AI, and the priorities it forces.</description>
    </item>
  </channel>
</rss>