Topic
Tanium Blog

Copy Fail (CVE-2026-31431): What Linux administrators need to know now
Copy Fail, or CVE-2026-31431, is a Linux kernel local privilege escalation vulnerability that can let an unprivileged local user corrupt page-cache-backed file data under specific conditions and potentially escalate privileges. Exposure depends on the running vendor kernel and backported fixes. Installing a vendor-provided kernel fix is the primary remediation, with temporary mitigations available in some environments if patching is delayed.

Types of AI agents: From simple reflex to autonomous systems
AI agents fall into five foundational categories: simple reflex, model-based reflex, goal-based, utility-based, and learning agents. Each is defined by how much environmental awareness and decision-making complexity the system can handle, from fixed condition-action rules to feedback-driven self-improvement.

How to create a patch management policy in 5 steps
A patch management policy is a formal organizational document that defines how software updates are identified, prioritized, tested, and deployed across an organization's systems to address security vulnerabilities that attackers commonly exploit to gain initial access.

Patch management best practices: An enterprise guide
Effective patch management requires a structured process of inventorying assets, prioritizing vulnerabilities by risk, testing fixes before broad deployment, and automating rollout: steps that collectively help narrow the window between a vendor's patch release and active exploitation across enterprise systems.

Tanium at ServiceNow Knowledge26: Endpoint management for the AI age
Together, Tanium and ServiceNow help organizations build a more secure, resilient, and confident future. Join us at Knowledge26.

VibeScamming: Why AI-built scams are changing phishing risk
VibeScamming refers to AI-assisted phishing operations where attackers use natural-language tools to rapidly generate and modify phishing content and web pages, lowering (but not eliminating) the technical skill required. One of the primary enterprise impacts is faster phishing iteration and reconstitution after blocks or takedowns, with identity compromise remaining a major risk alongside malware and other payload-based attacks.

Vercel security incident: What the breach reveals about OAuth trust, supply chain risk, and response speed
Public reporting suggests the incident involved abuse of a third-party application that had been granted OAuth access to a Vercel employee account, enabling unauthorized access to some internal resources. Certain customer‑related tokens, environment variables, or other access artifacts may have been exposed, though Vercel has not stated that password theft was part of the initial access path. The breach illustrates how trusted SaaS integrations and delegated access have become a significant attack surface for enterprises with interconnected developer workflows, even when no software vulnerability in production infrastructure is exploited.

Understanding shadow AI in your endpoint environment
Learn how shadow AI appears on endpoints, from local models to MCP servers, and why visibility, governance, and secure configuration matter now.

Claude Mythos security risks: What the Anthropic System Card tells us
Anthropic's Claude Mythos Preview demonstrated significant acceleration in capabilities for autonomously identifying vulnerabilities and exploit chains across major software and operating systems. Government and industry leaders are focused on understanding the real risks the model presents, and how to leverage these advanced technologies to protect and defend against adversarial use.

Why most patch management processes break down before deployment
Learn why the patch management process is an end‑to‑end operating discipline, not a one‑time task.

Axios npm package compromise: What happened, what matters, and how to respond
Learn what happened with the Axios npm package vulnerability, how to confirm exposure to malicious versions, and how Tanium Guardian can help investigate.

Claude Code source exposure: What enterprises should do next
Inside the npm packaging mistake that exposed half a million lines of Claude Code.