
U.S. businesses are facing a growing list of cybersecurity threats as federal officials continue to identify software flaws that attackers are actively exploiting, adding pressure on organizations to strengthen security across their operations, from network defenses to the handling and destruction of retired hardware.
The Cybersecurity and Infrastructure Security Agency, or CISA, last week added three vulnerabilities to its Known Exploited Vulnerabilities, or KEV, Catalog after confirming evidence of active exploitation. The additions include two command injection vulnerabilities affecting Fortinet FortiSandbox products, tracked as CVE 2026 25089 and CVE 2026 39808, along with a Microsoft SharePoint deserialization vulnerability, tracked as CVE 2026 58644.
CISA said these vulnerabilities represent common attack paths used by cybercriminals and other threat actors and pose significant risks to government networks. Under Binding Operational Directive 26 04, federal civilian agencies must prioritize remediation of high risk vulnerabilities listed in the KEV Catalog and determine whether systems were compromised before security updates were applied. While the directive applies only to federal agencies, CISA is encouraging private sector organizations to adopt the same risk based approach to vulnerability management.
The latest advisories arrive as businesses continue to contend with ransomware, data theft, supply chain attacks and increasingly sophisticated intrusion techniques targeting cloud infrastructure, collaboration platforms and enterprise applications.
Major technology companies have invested heavily in layered cybersecurity programs designed to reduce those risks. Microsoft has expanded its Secure Future Initiative following several high profile security incidents, increasing engineering investments, identity protections, cloud security controls and secure by design software development practices. The company has also strengthened threat intelligence capabilities and expanded default security settings across its enterprise products.
Cloud infrastructure provider CoreWeave has similarly emphasized security as demand for artificial intelligence infrastructure continues to accelerate. The company employs a defense in depth approach that includes continuous monitoring, identity and access management, encryption, infrastructure segmentation and compliance with widely recognized security standards to protect customer workloads hosted in its data center environment.
Cybersecurity professionals say technical safeguards represent only one part of an effective security strategy. Organizations are increasingly extending security controls beyond active systems by addressing how sensitive information is handled when storage devices reach the end of their operational life.
Frameworks aligned with the National Institute of Standards and Technology, including guidance contained within the NIST Cybersecurity Framework and NIST Special Publication 800 88 on media sanitization, encourage organizations to protect data throughout its entire lifecycle. That includes maintaining inventories of storage assets, documenting chain of custody, selecting appropriate sanitization methods and verifying that confidential information cannot be recovered after equipment is retired.
For many organizations handling highly sensitive or regulated information, those controls now extend to on site physical destruction of storage media at the end of life. Rather than transporting drives to an off site facility, businesses are increasingly choosing to destroy hard drives, solid state drives and other storage devices within their own facilities under documented procedures that support compliance, reduce transportation risks and strengthen audit trails.
Companies specializing in end of life data destruction have seen growing demand as organizations seek to close potential security gaps that exist after equipment leaves production environments. Verity Systems develops equipment that enables businesses, government agencies and data centers to physically destroy hard drives, solid state drives, magnetic tapes and other storage media on-site, helping organizations support media sanitization requirements while maintaining custody of sensitive assets through the destruction process.
Security experts say organizations that combine rapid vulnerability remediation, strong identity protections, continuous monitoring and disciplined end of life media destruction are better positioned to reduce the likelihood of data exposure. As cyber threats continue to evolve, businesses are increasingly treating cybersecurity as a lifecycle discipline that extends from software development and cloud operations through the final destruction of storage devices containing sensitive information.
