<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[FortaRisks CyberSecurity Inc]]></title><description><![CDATA[FortaRisks relie votre posture, les menaces actives et votre contexte pour produire une priorisation actionnable : quoi corriger, et avec quel impact.]]></description><link>https://www.fortarisks.com/blog</link><generator>RSS for Node</generator><lastBuildDate>Wed, 17 Jun 2026 15:57:02 GMT</lastBuildDate><atom:link href="https://www.fortarisk.com/en/blog-feed.xml" rel="self" type="application/rss+xml"/><item><title><![CDATA[Radiology, Oncology, DocketWise: Three Breaches in One Week That Reshape Your Healthcare and Legal Third-Party Risk]]></title><description><![CDATA[In seven days, three US data breaches confirmed what many CISOs already know but hesitate to formalize: your real exposure doesn't run through your perimeter, it runs through your healthcare and legal vendors. Radiology Associates of Richmond, The Oncology Institute (via TriZetto) and DocketWise notified close to 4 million individuals in just a few days.]]></description><link>https://www.fortarisks.com/en/post/radiology-oncology-docketwise-three-breaches-in-one-week-that-reshape-your-healthcare-and-legal-t</link><guid isPermaLink="false">6a158799b3f40ff4eeeba5bc</guid><pubDate>Fri, 29 May 2026 10:00:22 GMT</pubDate><dc:creator>FortaRisks Team</dc:creator></item><item><title><![CDATA[Radiology, Oncology, DocketWise : trois fuites en une semaine qui redessinent votre risque tiers santé et legal]]></title><description><![CDATA[En sept jours, trois fuites de données aux États-Unis ont confirmé ce que beaucoup de RSSI savent déjà mais hésitent à formaliser : votre exposition réelle ne passe pas par votre périmètre, elle passe par vos fournisseurs santé et legal. Radiology Associates of Richmond, The Oncology Institute (via TriZetto) et DocketWise ont notifié au total près de 4 millions d'individus en quelques jours.]]></description><link>https://www.fortarisks.com/post/radiology-oncology-docketwise-trois-fuites-en-une-semaine-qui-redessinent-votre-risque-tiers-san</link><guid isPermaLink="false">6a158799b3f40ff4eeeba5bd</guid><pubDate>Fri, 29 May 2026 10:00:17 GMT</pubDate><dc:creator>FortaRisks Team</dc:creator></item><item><title><![CDATA[Defender et Apex One sous le feu : quand l'antivirus devient l'arme de l'attaquant]]></title><description><![CDATA[En 72 heures, la CISA a inscrit trois zero-days majeurs dans son catalogue KEV — tous dans des outils de sécurité endpoint. RedSun et UnDefend dans Microsoft Defender, traversée de répertoire dans Trend Micro Apex One : trois failles activement exploitées qui transforment vos outils de défense en levier d'attaque. Deadlines fédérales : 3 et 4 juin.]]></description><link>https://www.fortarisks.com/post/defender-et-apex-one-sous-le-feu-quand-l-antivirus-devient-l-arme-de-l-attaquant</link><guid isPermaLink="false">6a158798f3bc0136e51d5a38</guid><pubDate>Tue, 26 May 2026 11:44:24 GMT</pubDate><dc:creator>FortaRisks Team</dc:creator></item><item><title><![CDATA[Defender and Apex One Under Fire: When the Antivirus Becomes the Attacker's Weapon]]></title><description><![CDATA[In 72 hours, CISA added three major zero-days to its KEV catalog — all in endpoint security tools. RedSun and UnDefend in Microsoft Defender, directory traversal in Trend Micro Apex One: three actively exploited flaws that turn your defense tools into the attacker's leverage. US federal deadlines: June 3 and 4.]]></description><link>https://www.fortarisks.com/en/post/defender-and-apex-one-under-fire-when-the-antivirus-becomes-the-attacker-s-weapon</link><guid isPermaLink="false">6a158798f3bc0136e51d5a37</guid><pubDate>Tue, 26 May 2026 11:44:24 GMT</pubDate><dc:creator>FortaRisks Team</dc:creator></item><item><title><![CDATA[Canvas, 275 millions de dossiers : ce que la brèche vous oblige à revoir dans votre risque tiers]]></title><description><![CDATA[Le 7 mai 2026, la plateforme Canvas (Instructure) utilisée par environ la moitié des établissements d'enseignement supérieur d'Amérique du Nord, a été paralysée par une attaque revendiquée par le groupe ShinyHunters. Les attaquants affirment avoir exfiltré 275 millions de dossiers liés aux étudiants, enseignants et personnels. La page de connexion a été remplacée par un message de rançon, avec une date butoir au 12 mai. L'incident n'a pas frappé un éditeur de niche. Il a frappé un fournisseur...]]></description><link>https://www.fortarisks.com/post/canvas-275-millions-de-dossiers-ce-que-la-br%C3%A8che-vous-oblige-%C3%A0-revoir-dans-votre-risque-tiers</link><guid isPermaLink="false">6a0926940b9e4f37fd28f1ed</guid><pubDate>Tue, 19 May 2026 10:00:00 GMT</pubDate><enclosure url="https://static.wixstatic.com/media/8341b8_e64671164cd042b98fcf9d63535a5b94~mv2.jpg/v1/fit/w_1000,h_768,al_c,q_80/file.png" length="0" type="image/png"/><dc:creator>FortaRisks Team</dc:creator></item><item><title><![CDATA[Canvas, 275 Million Records: What This Breach Forces You to Rethink in Third-Party Risk]]></title><description><![CDATA[On May 7, 2026, the Canvas platform (Instructure) — used by roughly half of North America's higher-education institutions — was paralyzed by an attack claimed by the ShinyHunters group. Attackers say they exfiltrated 275 million records tied to students, faculty, and staff. The login page was replaced with a ransom message, with a May 12 deadline. The hit didn't land on a niche vendor. It landed on a provider that thousands of institutions no longer even thought of as a "third party" — a...]]></description><link>https://www.fortarisks.com/en/post/canvas-275-million-records-what-this-breach-forces-you-to-rethink-in-third-party-risk</link><guid isPermaLink="false">6a092ba2bdbdace814c10a76</guid><pubDate>Tue, 19 May 2026 04:47:02 GMT</pubDate><enclosure url="https://static.wixstatic.com/media/8341b8_e64671164cd042b98fcf9d63535a5b94~mv2.jpg/v1/fit/w_1000,h_768,al_c,q_80/file.png" length="0" type="image/png"/><dc:creator>FortaRisks Team</dc:creator></item><item><title><![CDATA[AI vs AI: Why Your Cyber Defense Must Also Be AI-Augmented]]></title><description><![CDATA[Over the past two weeks, we broke down Anthropic's Mythos and its implications for boards of directors. The conclusion was clear: attackers now have AI capable of discovering and exploiting vulnerabilities at scale. The natural follow-up question: how do you defend? Short answer: with AI, you too. But not just any way. The myth to dismiss first "Defensive AI will replace my SOC analysts." False. Defensive AI doesn't replace humans, it augments, accelerates, and amplifies them. The right model...]]></description><link>https://www.fortarisks.com/en/post/ai-vs-ai-why-your-cyber-defense-must-also-be-ai-augmented</link><guid isPermaLink="false">6a09260adf43effc8ce0e96f</guid><pubDate>Sun, 17 May 2026 02:21:22 GMT</pubDate><enclosure url="https://static.wixstatic.com/media/8341b8_d4434e18030b43338cabaab7294bd002~mv2.jpg/v1/fit/w_1000,h_768,al_c,q_80/file.png" length="0" type="image/png"/><dc:creator>FortaRisks Team</dc:creator></item><item><title><![CDATA[AI vs AI : pourquoi votre cyber-défense doit elle aussi être augmentée par l'IA]]></title><description><![CDATA[Les deux dernières semaines, nous avons décortiqué Mythos d'Anthropic (https://www.fortarisks.com/post/mythos-tempete-ai-vulnerabilites-agir-maintenant) et son implication pour les conseils d'administration (https://www.fortarisks.com/post/mythos-conseil-administration-5-questions-strategiques). La conclusion était claire : les attaquants disposent désormais d'IA capables de découvrir et exploiter des failles à grande échelle. La question naturelle qui suit : comment se défendre ? Réponse...]]></description><link>https://www.fortarisks.com/post/ai-vs-ai-defense-cyber-augmentee-intelligence-artificielle</link><guid isPermaLink="false">69ff67494f7ebdc9f6ad7605</guid><pubDate>Fri, 15 May 2026 10:00:00 GMT</pubDate><enclosure url="https://static.wixstatic.com/media/8341b8_d4434e18030b43338cabaab7294bd002~mv2.jpg/v1/fit/w_1000,h_768,al_c,q_80/file.png" length="0" type="image/png"/><dc:creator>FortaRisks Team</dc:creator></item><item><title><![CDATA[Mythos expliqué au conseil d'administration : 5 questions stratégiques avant votre prochain comité]]></title><description><![CDATA[Vous avez peut-être vu passer le terme « Mythos » dans la presse ces dernières semaines, ou entendu votre CISO l'évoquer en réunion. Voici ce que ça signifie vraiment pour votre entreprise — sans jargon technique. Mythos en 30 secondes Mythos est une intelligence artificielle développée par Anthropic qui a démontré, en avril 2026, une capacité inédite : trouver et exploiter des failles informatiques complexes en quelques heures, là où il fallait auparavant des semaines à des chercheurs...]]></description><link>https://www.fortarisks.com/post/mythos-conseil-administration-5-questions-strategiques</link><guid isPermaLink="false">69ff60ea4f7ebdc9f6ad681c</guid><pubDate>Fri, 08 May 2026 10:00:00 GMT</pubDate><dc:creator>FortaRisks Team</dc:creator></item><item><title><![CDATA[Mythos Explained to the Board: 5 Strategic Questions Before Your Next Committee]]></title><description><![CDATA[You may have seen the term "Mythos" in the press recently, or heard your CISO mention it in a meeting. Here's what it really means for your business — without technical jargon. Mythos in 30 seconds Mythos is an artificial intelligence developed by Anthropic that demonstrated, in April 2026, an unprecedented capability: finding and exploiting complex software flaws in a matter of hours — where it previously took specialized researchers weeks.  Think of it as an era change: attackers now have a...]]></description><link>https://www.fortarisks.com/en/post/mythos-explained-to-the-board-5-strategic-questions-before-your-next-committee</link><guid isPermaLink="false">69ff61004f7ebdc9f6ad6845</guid><pubDate>Fri, 08 May 2026 10:00:00 GMT</pubDate><dc:creator>FortaRisks Team</dc:creator></item><item><title><![CDATA[Mythos and the AI Storm: Why Your Cyber Program Must Change Now]]></title><description><![CDATA[On April 13, 2026, the Cloud Security Alliance published an emergency executive briefing co-signed by the biggest names in global cybersecurity (Jen Easterly, Bruce Schneier, Heather Adkins of Google, Rob Joyce former NSA, Phil Venables…). The title: "The AI Vulnerability Storm: Building a Mythos-ready Security Program". The message holds in one sentence: your cyber program must prepare for a structural change — not a passing trend, a structural change. What is Mythos and why everyone is...]]></description><link>https://www.fortarisks.com/en/post/mythos-and-the-ai-storm-why-your-cyber-program-must-change-now</link><guid isPermaLink="false">69ff4afd4f7ebdc9f6ad3943</guid><pubDate>Fri, 01 May 2026 10:00:00 GMT</pubDate><dc:creator>FortaRisks Team</dc:creator></item><item><title><![CDATA[Mythos et la tempête IA : pourquoi votre programme cyber doit changer maintenant]]></title><description><![CDATA[Le 13 avril 2026, la Cloud Security Alliance a publié un briefing exécutif d'urgence, co-signé par les plus grands noms de la cybersécurité mondiale (Jen Easterly, Bruce Schneier, Heather Adkins de Google, Rob Joyce ex-NSA, Phil Venables…). Le titre : « The AI Vulnerability Storm: Building a Mythos-ready Security Program ». Le message tient en une phrase : votre programme cyber doit se préparer à un changement structurel — pas un trend passager, un changement structurel. Qu'est-ce que Mythos...]]></description><link>https://www.fortarisks.com/post/mythos-tempete-ai-vulnerabilites-agir-maintenant</link><guid isPermaLink="false">69ff4adcb1ac8cd94fa3e636</guid><pubDate>Fri, 01 May 2026 10:00:00 GMT</pubDate><dc:creator>FortaRisks Team</dc:creator></item><item><title><![CDATA[Deux banques américaines, un seul fournisseur : les 11 vulnérabilités tierces invisibles aux questionnaires]]></title><description><![CDATA[Le 20 avril 2026, le groupe ransomware Everest a publié sur son site de leak deux banques américaines majeures. Toutes les deux ont confirmé : la brèche n'est pas venue de leur réseau interne, mais d'un fournisseur tiers commun. Une chaîne de quelques minutes, un seul vendor compromis, deux institutions financières exposées. Le TPRM — Third Party Risk Management — n'est plus un sujet de conformité. C'est devenu un sujet de continuité business. Et pourtant, la plupart des programmes TPRM en...]]></description><link>https://www.fortarisks.com/post/tprm-11-vulnerabilites-tierces-invisibles-questionnaires</link><guid isPermaLink="false">69ff43c257c1b4d98769ee45</guid><pubDate>Fri, 24 Apr 2026 10:00:00 GMT</pubDate><dc:creator>FortaRisks Team</dc:creator></item><item><title><![CDATA[Two US Banks, One Vendor: 11 Third-Party Vulnerabilities Invisible to Questionnaires]]></title><description><![CDATA[On April 20, 2026, the Everest ransomware group published two major US banks on its leak site. Both confirmed: the breach didn't come from their internal network but from a common third-party vendor. A chain of a few minutes, a single compromised vendor, two financial institutions exposed. TPRM — Third Party Risk Management — is no longer a compliance topic. It has become a business continuity topic. And yet, most TPRM programs in 2026 still rely on a static annual questionnaire. Here's what...]]></description><link>https://www.fortarisks.com/en/post/two-us-banks-one-vendor-11-third-party-vulnerabilities-invisible-to-questionnaires</link><guid isPermaLink="false">69ff43df38e3e83040eb99b4</guid><pubDate>Fri, 24 Apr 2026 10:00:00 GMT</pubDate><dc:creator>FortaRisks Team</dc:creator></item><item><title><![CDATA[Cyber Insurance 2026: 7 Criteria Insurers Check Before Covering You]]></title><description><![CDATA[The cyber insurance market has hardened dramatically. Premiums tripled between 2021 and 2024, terms tightened, and exclusions multiplied. In 2026, obtaining or renewing a cyber policy is no longer an administrative formality — it's an audit of your security posture. Here's what your insurers now check, and how to pass the audit on the first try. Why insurers have become so demanding Three shocks reshaped the market:  • The 2020-2024 ransomware explosion: claims exceeded premiums collected for...]]></description><link>https://www.fortarisks.com/en/post/cyber-insurance-2026-7-criteria-insurers-check-before-covering-you</link><guid isPermaLink="false">69ff43134f7ebdc9f6ad27c4</guid><pubDate>Fri, 17 Apr 2026 10:00:00 GMT</pubDate><dc:creator>FortaRisks Team</dc:creator></item><item><title><![CDATA[Cyber-assurance 2026 : 7 critères que les assureurs vérifient avant de vous couvrir]]></title><description><![CDATA[Le marché de la cyber-assurance s'est radicalement durci. Les primes ont triplé entre 2021 et 2024, les conditions se sont resserrées, et les exclusions se sont multipliées. En 2026, obtenir ou renouveler une cyber-police n'est plus une formalité administrative — c'est un audit de votre posture de sécurité. Voici ce que vos assureurs vérifient désormais, et comment passer l'audit du premier coup. Pourquoi les assureurs sont devenus si exigeants Trois chocs ont bouleversé le marché :  •...]]></description><link>https://www.fortarisks.com/post/cyber-assurance-2026-7-criteres-assureurs</link><guid isPermaLink="false">69ff42fbecab901137540904</guid><pubDate>Fri, 17 Apr 2026 10:00:00 GMT</pubDate><dc:creator>FortaRisks Team</dc:creator></item><item><title><![CDATA[Ransomware Chaos : 36 victimes en mars, et votre secteur OT est dans le viseur]]></title><description><![CDATA[En mars 2026, le groupe ransomware Chaos a revendiqué 36 nouvelles victimes sur son site de leak. Une statistique brute. Mais la lecture des cibles révèle une tendance lourde qui devrait alerter tout RSSI industriel : construction, manufacturier et services aux entreprises concentrent l'essentiel des attaques. Si vous opérez dans l'un de ces secteurs, votre nom est statistiquement déjà sur la liste des prochaines cibles. Pourquoi le manufacturier OT est devenu le terrain de jeu favori Quatre...]]></description><link>https://www.fortarisks.com/post/ransomware-chaos-36-victimes-en-mars-et-votre-secteur-ot-est-dans-le-viseur</link><guid isPermaLink="false">69ff41fb4f7ebdc9f6ad253c</guid><pubDate>Fri, 10 Apr 2026 10:00:00 GMT</pubDate><dc:creator>FortaRisks Team</dc:creator></item><item><title><![CDATA[Chaos Ransomware: 36 Victims in March, and Your OT Sector Is Next]]></title><description><![CDATA[In March 2026, the Chaos ransomware group claimed 36 new victims on its leak site. A raw statistic. But reading the targets reveals a heavy trend that should alert every industrial CISO: construction, manufacturing and business services concentrate the bulk of attacks. If you operate in one of these sectors, your name is statistically already on the list of next targets. Why manufacturing OT has become the favorite playground Four structural factors explain this targeting:  • Hybrid IT/OT...]]></description><link>https://www.fortarisks.com/en/post/chaos-ransomware-36-victims-in-march-and-your-ot-sector-is-next</link><guid isPermaLink="false">69ff420d38e3e83040eb95bc</guid><pubDate>Fri, 10 Apr 2026 10:00:00 GMT</pubDate><dc:creator>FortaRisks Team</dc:creator></item><item><title><![CDATA[Living off the Land : vos outils légitimes deviennent vos pires attaquants]]></title><description><![CDATA[En 2026, la majorité des attaques sophistiquées ne déposent plus aucun malware sur vos systèmes. Les attaquants utilisent vos consoles d'administration, vos OAuth, vos installeurs officiels. C'est le « Living off the Land » (LotL) — et il fait sauter les détections classiques. 4 incidents Q1 2026 qui dessinent la même tendance 1. Stryker (mars). Le groupe iranien Handala vole une seule credential, accède à Microsoft Intune (l'outil légitime de gestion des postes), et wipe 80 000 machines dans...]]></description><link>https://www.fortarisks.com/post/living-off-the-land-outils-legitimes-attaquants</link><guid isPermaLink="false">69ff40dab1ac8cd94fa3d054</guid><pubDate>Fri, 03 Apr 2026 10:00:00 GMT</pubDate><dc:creator>FortaRisks Team</dc:creator></item><item><title><![CDATA[Living off the Land: Your Legitimate Tools Have Become Your Worst Attackers]]></title><description><![CDATA[In 2026, the majority of sophisticated attacks no longer drop any malware on your systems. Attackers use your admin consoles, your OAuth flows, your official installers. This is “Living off the Land” (LotL) — and it bypasses classic detections. 4 Q1 2026 incidents that point to the same trend 1. Stryker (March). The Iranian Handala group steals a single credential, accesses Microsoft Intune (the legitimate device management tool), and wipes 80,000 machines across 79 countries. Not a single...]]></description><link>https://www.fortarisks.com/en/post/living-off-the-land-your-legitimate-tools-have-become-your-worst-attackers</link><guid isPermaLink="false">69ff40e938e3e83040eb933b</guid><pubDate>Fri, 03 Apr 2026 10:00:00 GMT</pubDate><dc:creator>FortaRisks Team</dc:creator></item></channel></rss>