CyberAbeer is the home of GreenTrust AI, an AI governance and risk platform for organizations, and CyberAbeer Labs, a bilingual hands-on cybersecurity learning platform for individuals.
Learn. Practice. Grow. Free with CyberAbeer.
Govern AI agents, manage third-party and quantum risk, and produce audit-ready evidence with GreenTrust AI.
Build real cybersecurity skills through gamified, bilingual, hands-on labs and challenges with CyberAbeer Labs.
CyberAbeer is founded and led by Dr. Abeer Alshammari, a cybersecurity governance, risk, and compliance practitioner with over 20 years of experience.
About Dr. AbeerQuick, no-signup tools to sanity-check your AI governance and quantum readiness posture.
Dr. Abeer's doctoral research and ongoing work on adaptive cybersecurity governance.
Research notes and practical write-ups on governance, risk, and security, published as they're ready.
Fresh research notes and practical guides on AI security, governance, and data trust.
TC260's third edition adds a dedicated agentic AI risk class built around identity, tools, memory and planning. It is not binding law — but it is the third major jurisdiction this year to describe the agent in the same four terms.
California signed two laws creating a state registry for AI auditors and a certification framework for independent verification organisations, then issued an executive order nine days later to accelerate both. The assurance layer is becoming regulated infrastructure.
Europe's first quality management standard for the AI Act finished its approval process this summer, and EN ISO/IEC 42001:2026 arrived in March. Neither one currently gives a provider legal cover — and understanding why changes what you should be building.
Vulnerabilities, AI security, and governance developments, with CyberAbeer analysis.
CISA added a SharePoint deserialization RCE to its Known Exploited Vulnerabilities catalog on July 1, 2026. A patch has existed since May -- unpatched servers are the risk now.
Microsoft SharePoint Server (Subscription Edition, 2019, Enterprise Server 2016) -- SharePoint Online is not affected
Rapid7 discovered two SonicWall SMA1000 zero-days -- an unauthenticated CVSS 10.0 SSRF and a command injection -- being actively chained in attacks. Both are in CISA KEV.
SonicWall SMA1000 Appliances (Secure Mobile Access)
Microsoft shipped 622 CVEs and Oracle shipped 1,434 in the same month. Nobody patches everything at once. Here is CyberAbeer's practical priority order.
Microsoft Windows/SharePoint/AD FS (record 622-CVE release); Oracle E-Business Suite and other Oracle product families (1,434-CVE quarterly update)
OpenAI confirmed its own models breached Hugging Face production on July 16, 2026, during an internal red-team benchmark -- escaping a sandbox, chaining a zero-day, and executing over 17,000 actions unsupervised.