Paragon Graphite on iPhone: Lessons From a Reported Zero-Click Spyware Case
Review Citizen Lab's reported Paragon Graphite iPhone findings, Apple's CVE-2025-43200 advisory, the evidence limits, and lessons for high-risk users.
Read articleFind exposure, strengthen essential controls, and build practical resilience around the systems your organization depends on.
Explore cybersecurity services →Evaluate controls independently, document defensible findings, and focus remediation on the risks with the greatest operational impact.
Explore security audits →Translate security obligations into clear evidence, accountable remediation, and a practical path toward audit or customer readiness.
Explore compliance services →Bring security governance, risk decisions, leadership communication, and improvement planning into one accountable executive program.
Explore vCISO services →Review Citizen Lab's reported Paragon Graphite iPhone findings, Apple's CVE-2025-43200 advisory, the evidence limits, and lessons for high-risk users.
Read articleSTRATeBEN reported a phishing-related incident involving unauthorized access to an employee’s Microsoft 365 account at various times between August 14 and November 9, 2025. The account contained files shared to help manage an employee benefit plan.
Read articleRisk Strategies reported unauthorized access to a Microsoft 365 account belonging to one employee on January 15 and 16, 2026. Its public notice says certain emails and files were accessed and that a review later confirmed some material contained personal information.
Read articleConifer Value Based Care reported that an unauthorized third party accessed an employee’s Microsoft Office 365 hosted business email account on August 28 and 29, 2025. The company’s notice says the email account was separate from its internal network and systems, which were not affected by the incident.
Read articleiRhythm Holdings reported a material cybersecurity incident involving data in certain third party hosted business applications. Its June 2026 Form 8 K provides an unusually useful distinction: the company reported data exfiltration from business applications while stating that it had not identified an impact to product
Read articleA sourced analysis of Stryker’s March 2026 cybersecurity disruption, confirmed operational impact, remaining unknowns, and resilience lessons.
Read articleThis website uses essential cookies for security and operation. Optional analytics and advertising cookies help measure site use and outreach. Choose Allow or Deny. You can change your choice at any time.