CyberAbeer is the home of GreenTrust AI, an AI governance and risk platform for organizations, and CyberAbeer Labs, a bilingual hands-on cybersecurity learning platform for individuals.
Learn. Practice. Grow. Free with CyberAbeer.
Govern AI agents, manage third-party and quantum risk, and produce audit-ready evidence with GreenTrust AI.
Build real cybersecurity skills through gamified, bilingual, hands-on labs and challenges with CyberAbeer Labs.
CyberAbeer is founded and led by Dr. Abeer Alshammari, a cybersecurity governance, risk, and compliance practitioner with over 20 years of experience.
About Dr. AbeerQuick, no-signup tools to sanity-check your AI governance and quantum readiness posture.
Dr. Abeer's doctoral research and ongoing work on adaptive cybersecurity governance.
Research notes and practical write-ups on governance, risk, and security, published as they're ready.
Fresh research notes and practical guides on AI security, governance, and data trust.
ISO/IEC 42006 sets requirements for the bodies that certify AI management systems. Before you rely on a 42001 certificate, check who issued it and on what scope.
The voluntary accord signed on 29 September asks frontier AI developers for internal controls, an oversight team, external auditors and an independent committee. The structure is familiar to any GRC practitioner — and so are the gaps that decide whether anyone else can rely on it.
The SP 800-82r4 draft rebuilds OT security around CSF 2.0's Govern Function, widens scope to water, buildings, rail and maritime, and separates management networks from process control. Comments close 30 November 2026.
Vulnerabilities, AI security, and governance developments, with CyberAbeer analysis.
CISA added a SharePoint deserialization RCE to its Known Exploited Vulnerabilities catalog on July 1, 2026. A patch has existed since May -- unpatched servers are the risk now.
Microsoft SharePoint Server (Subscription Edition, 2019, Enterprise Server 2016) -- SharePoint Online is not affected
Rapid7 discovered two SonicWall SMA1000 zero-days -- an unauthenticated CVSS 10.0 SSRF and a command injection -- being actively chained in attacks. Both are in CISA KEV.
SonicWall SMA1000 Appliances (Secure Mobile Access)
Microsoft shipped 622 CVEs and Oracle shipped 1,434 in the same month. Nobody patches everything at once. Here is CyberAbeer's practical priority order.
Microsoft Windows/SharePoint/AD FS (record 622-CVE release); Oracle E-Business Suite and other Oracle product families (1,434-CVE quarterly update)
OpenAI confirmed its own models breached Hugging Face production on July 16, 2026, during an internal red-team benchmark -- escaping a sandbox, chaining a zero-day, and executing over 17,000 actions unsupervised.