Active Exploitation of 7-Zip RCE Vulnerability Shows Why Manual Patching is No Longer an Option

A critical remote code execution (RCE) vulnerability in 7-Zip (CVE-2025-11001) is now being actively exploited. The issue stems from improper handling of symbolic links within crafted ZIP files. When a malicious archive is extracted, 7-Zip may write files outside the intended directory, allowing an attacker to overwrite system files or execute arbitrary code with the…

Read More

Delivering securely on data and AI strategy 

That’s getting more challenging, says Nithin Ramachandran, who is global vice president for data and AI at industrial and consumer products manufacturer 3M. “Our experience with generative AI has shown that we need to be looking at security differently than before,” he says. “With every tool we deploy, we look not just at its functionality but…

Read More

From Policy to Practice: Why Cyber Resilience Needs a Reboot

In cybersecurity today, regulation is everywhere, but resilience isn’t keeping pace. In this episode of Experts on Experts: Commanding Perspectives, Craig Adams chats with Sabeen Malik, VP of Public Policy & Government Affairs at Rapid7, about what’s broken (and what’s promising) in today’s regulatory landscape. Sabeen pulls from her experience across diplomacy, operations, and government…

Read More

2025 KFF Marketplace Enrollees Survey

Key Takeaways Marketplace enrollees largely see health insurance as very important to their ability to access care, to their financial well-being, and to their peace of mind; however, if the enhanced premium tax credits are not extended, many of the twenty-four million adults in the U.S. who currently buy their own insurance through the ACA…

Read More