Recent Posts

Week 31 – CertiGhost: The Certificate That Shouldn’t Exist

27 July – 02 Aug 2026 This week’s CVE of the Week is CVE-2026-54121, also known as CertiGhost, a critical vulnerability affecting Microsoft Active Directory Certificate Services (AD CS). The flaw allows a low-privileged authenticated domain user to obtain a certificate for a Domain Controller, 

Governing Security When the CISO Advises but Doesn’t Command – by Kamran Israr Mirza (Kim)

Governing Security When the CISO Advises but Doesn’t Command – by Kamran Israr Mirza (Kim)

When the SOC reports to the CTO and the CISO’s role is advisory only, accountability and authority quietly split apart; this white paper makes the case for elevating the CISO’s reporting line to the CEO or Board and giving the function its own budget.

Week 30 – A PDF Extension with a WhatsApp Obsession

20 -26 July 2026 In this week’s CVE of the Week, we’re examining a recently patched vulnerability chain in the Adobe Acrobat PDF Chrome extension, which is used by more than 314 million users worldwide. Tracked as CVE-2026-48294 (CVSS score: 8.2) and dubbed HermeticReader by 

Cyber (In)Security — Issue #206

In this issue: Want your content featured? Tag @Cybersecurity Advisors Network in your LinkedIn post — articles, presentations, awards, new roles, or external events — and we’ll pick it up for the next issue.

Australia’s Horizon Cyber Security Initiative: What it Means for Industry – by David Gaul

Australia’s Horizon Cyber Security Initiative: What it Means for Industry – by David Gaul

Few people ask about the implications of Australia’s cyber security reform on businesses – this paper addresses important aspects of the initiative.

Cyber Risk Is in the Boardroom. Are Boards Ready to Govern It? – By Sanchay Joshi

Cyber Risk Is in the Boardroom. Are Boards Ready to Govern It? – By Sanchay Joshi

Sanchay Joshi explores improved approaches for boards to ensure oversight of cybersecurity and resilience, and how this makes organisations stronger

Week 29 – Next Stop: SYSTEM

13 -19 July 2026 This week our CVE of the Week is CVE-2026-56164, a zero-day Elevation of Privilege vulnerability affecting Microsoft SharePoint Server that Microsoft confirmed is being actively exploited in the wild. SharePoint is a critical business platform used for document management, collaboration, and 

Week 28 – A perfect 10 in UniFi Connect

06 -12 July 2026 In this week’s CVE of the Week, we’re looking at CVE-2026-50746, a critical vulnerability affecting the Ubiquiti UniFi Connect Application, with a CVSS score of 10.0. The vulnerability is caused by Improper Access Control (CWE-284) and allows an attacker with network 

Week 27 – Impact Zone: RoguePlanet Crashes into Microsoft Defender

29 June – 05 July 2026 One of the most discussed security issues in weeks is CVE-2026-50656, also known as RoguePlanet, an Elevation of Privilege (EoP) vulnerability affecting the Microsoft Malware Protection Engine used by Microsoft Defender. It was eventually assigned a CVE ID, so