microsegment.io

segment all the things

The Email Security Gateway Is Now An Attack Origin

CVE-2026-76461 turns one crafted message into a root-level containment problem

Cisco Secure Email Gateway CVE-2026-76461 is actively exploited and can provide root command execution through email parsing. This article explains how to contain the appliance across mail, management, egress, identity, and evidence paths.

Your Microsegmentation Policy Is Not Proven Until You Test The Deny

A clean rule set is not evidence that lateral movement paths are closed

Microsegmentation only reduces blast radius when denied paths are tested from real workloads. This article presents a practical method for validating policy enforcement, identity context, failure behavior, and containment over time.

The 2026 Forrester Wave For Microsegmentation: Why Illumio Stands Out

A neutral reading of a competitive market, and why Illumio's position deserves attention

Forrester's Q3 2026 Microsegmentation Solutions Wave evaluates 10 vendors across 25 criteria. Here is what the results say about the market, Illumio's Leader position, and what buyers should validate next.

Your CI/CD Runner Is A Privileged Workload. Contain It.

The Snowflake GitHub Actions flaw shows how one untrusted issue title can become a path into an internal SaaS system

Wiz's Snowflake disclosure shows why CI/CD runners need microsegmentation, narrow egress, short-lived identity, and explicit trust paths. This article turns the incident into a practical containment design.

OT Segmentation Must Survive Edge Compromise

The Polish energy-sector attack showed why VLANs are not containment when one administrator can reach every control subnet

CERT Polska's investigation of the December 2025 energy-sector attack shows how compromised VPN and identity control paths can flatten OT segmentation. This article turns the incident into a practical containment design for remote sites, SCADA, RTUs, HMIs, and safety-critical systems.