We are fighting phishing at the wrong layer
I timed an attacker once. From registering a domain to having it delegated, certificated and serving […]
SonicWall’s latest critical flaw indicates a security pattern, not another one-off bug
SonicWall has disclosed yet another critical flaw in one of its core products. CVE-2026-102255, rated 10 […]
Agentless vs. Agent-Based Deception: The Case for Faster Deployment
Key Takeaways Agentless deception skips per-endpoint installation, agent compatibility testing, and endpoint-management dependencies, which shortens time-to-value […]
Anthropic widens access to AI cyber capabilities for vetted security teams
Anthropic is expanding its Cyber Verification Program to give more security teams access to advanced cyber […]
Denmark’s national ID system breach exposes personal data of 8.8M
Denmark is reviewing security controls around its national citizen registry after unauthorized parties exploited a company’s […]
Encrypted instructions trick Copilot CLI into spilling developer secrets
GitHub Copilot CLI can be made to read sensitive files from a developer’s machine and send […]
Your enterprise doesn’t need six BOM programs. It needs one evidence graph
In infrastructure and security programs, I have watched visibility projects follow a familiar path. The first […]
AI is turning offensive security into a continuous necessity
The rise of AI has CISOs facing even more vulnerabilities than ever, resulting in increasingly difficult […]
Atlassian’s critical flaw turns eight enterprise products into one big security problem
A newly-disclosed critical flaw in Atlassian’s data center software has a remarkably wide reach, affecting eight […]
FBI removes contractor working with its PeopleSoft system after data breach, says report
The US Federal Bureau of Investigation has removed an Accenture contractor working on its PeopleSoft installation […]