microsegment.io

segment all the things

The Platform Was Not Breached. The Delegated Key Was.

The BigCommerce Ribon incident shows why third-party SaaS identities need their own containment boundaries

Compromised credentials for the Ribon BigCommerce apps reportedly enabled customer-data access and storefront script injection across merchant environments. This article explains how to contain delegated SaaS identities with narrow scopes, separated permissions, independent revocation, and behavioral monitoring.

The Email Security Gateway Is Now An Attack Origin

CVE-2026-76461 turns one crafted message into a root-level containment problem

Cisco Secure Email Gateway CVE-2026-76461 is actively exploited and can provide root command execution through email parsing. This article explains how to contain the appliance across mail, management, egress, identity, and evidence paths.

Your Microsegmentation Policy Is Not Proven Until You Test The Deny

A clean rule set is not evidence that lateral movement paths are closed

Microsegmentation only reduces blast radius when denied paths are tested from real workloads. This article presents a practical method for validating policy enforcement, identity context, failure behavior, and containment over time.

When The Network Infrastructure Lies

Fire Ant shows why routers, TACACS, and telemetry systems need separate containment and evidence paths

Sygnia's Fire Ant investigation shows how compromised routers and authentication infrastructure can provide reach, steal credentials, and suppress the evidence defenders rely on. This article turns the incident into a practical microsegmentation and forensic-readiness design.

The Login Worked. The Breach Did Not.

A stolen identity session should not become access to every application behind the identity provider

ReliaQuest's August 2026 social-engineering attempt shows why authentication is only the first policy decision. This article explains how device trust, per-application authorization, session controls, and microsegmentation contain a valid but hostile login.