Browse all articles

Threat Intelligence
Actionable Threat Intelligence: Driving Real Decisions

The Number That Should Make Every Vendor Uncomfortable A recent industry survey found that 91% of CISOs say threat intelligence is valuable. That sounds like a win for the threat intel market. Then you read the second stat: only 26% say that intelligence actually influences their decisions. Think about that for a moment. Nine out of ten security leaders believe in the concept of threat intelligence. But fewer than three in ten find what they are getting actionable enough to change what they do. That’s not a ringing endorsement, and it seems like a polite way of saying most threat...

Justin Fimlaid August 18, 2026 ∙ 6 min read
Industry Insights
Third-Party Risk Management in Cybersecurity

Your organization's cybersecurity posture is only as strong as the weakest link in your vendor ecosystem. For state and local governments, higher education institutions, financial organizations, and compliance-driven businesses, that statement carries significant weight. Implementing effective third-party risk management is essential because most organizations today rely heavily on third-party vendors and contractors to deliver core business functions. With that dependency comes risk that many security programs aren’t fully equipped to manage. After conducting hundreds of third-party risk assessments annually, our team at nuHarbor has developed a clear picture of the risks that show up time and again across industries, organization...

Brianna Blanchard August 4, 2026 ∙ 7 min read
Advisory & Planning
AI is Accelerating Exploits in 2026

In April 2026, Anthropic built a model it chose not to release. Claude Mythos Preview discovered and weaponized software vulnerabilities at machine speed, so the Anthropic team held it back and gave controlled access to roughly 50 organizations it trusted to harden their own code, among them AWS, Apple, Cisco, CrowdStrike, Google, Microsoft, NVIDIA, and the Linux Foundation. This unprecedented development marked a turning point in the field of AI Vulnerability Discovery. The program, called Project Glasswing, was created to provide a headstart to defenders, in hopes they could be enabled before attackers developed this capability independently. The window to...

nuHarbor June 16, 2026 ∙ 5 min read
Advisory & Planning
Two Ransomware Campaigns Your Team Needs to Know About

What Happened Two ransomware stories broke this week that deserve your attention at the same time, because together they paint a picture of where ransomware is headed. These incidents highlight a trend of increasingly sophisticated ransomware campaigns. Neither of these are new. Rather, we’re seeing an uptick in activity from both actors. The first is The Gentlemen, a newly identified ransomware family written in Go that combines fast, robust file encryption with self-propagating lateral movement across networks. Microsoft published a detailed technical breakdown on May 28 showing that The Gentlemen can spread without any human interaction once it’s inside a network,...

Justin Fimlaid June 2, 2026 ∙ 5 min read
Advisory & Planning
Public Sector Cyber Resilience: Beyond Just Security

Most public sector security teams are trying to build something that doesn't exist: an environment where nothing goes wrong. The challenge of public sector cyber resilience is to be prepared for and adapt to evolving threats rather than just aiming for perfect security. They invest in the latest tools, pass compliance audits, block thousands of threats a month, and report the numbers up the chain. Leadership hears exactly what they want to hear, “we are protected.” But that's the problem. Cybersecurity vs. Cyber Resilience: Two Different Goals Cybersecurity and cyber resilience are not the same thing. Most organizations treat them...

Kyle Smith May 19, 2026 ∙ 5 min read