Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Featured Post

The AI Data Centre Buildout Has a Security Problem

In recent months, there has been plenty of speculation about whether the industry is in the middle of an "AI bubble," often fuelled by questions about whether massive infrastructure investments are matched by real demand. Yet current developments suggest this is not the case: the ecosystem around AI continues to expand at a pace that indicates longterm structural change rather than shortterm hype.

Mastra npm Scope Takeover: 140+ Packages Compromised via easy-day-js Dropper

An attacker republished more than 140 packages in the @mastra npm scope, each carrying a single malicious dependency, easy-day-js. The malicious versions were observed on 2026-06-17. easy-day-js is a typosquat of the dayjs date library: version 1.11.21 is the clean prior release with no install hook, while version 1.11.22 adds an obfuscated postinstall dropper.

CloudCasa DR for HPE Alletra with Red Hat OpenShift - PART 2: Failback

CloudCasa completes the disaster recovery cycle by failing a file server application back from Site B (HPE Alletra MP B10000) to its original primary on Site A (HPE Alletra 9060), both running Red Hat OpenShift. In this demo, we create a reverse DR plan, scale down the workload for a clean shutdown, and let CloudCasa orchestrate the two-phase failback: an HPE recover/restore operation that reverses replication at the storage layer, followed by progressive Kubernetes resource restoration, before the file server comes back online on Site A with its data intact.

CloudCasa DR for HPE Alletra with Red Hat OpenShift - PART 1: Failover

CloudCasa orchestrates disaster recovery failover for stateful workloads across two HPE Alletra arrays running Red Hat OpenShift. In this demo, we fail over a file server application from Site A (HPE Alletra 9060) to Site B (HPE Alletra MP B10000), with CloudCasa installing its agent via a single kubectl apply, discovering both clusters and storage systems, mapping the pre-configured HPE replication relationship, and triggering consistency group failover so the workload comes back up on Site B with all data intact.

We wrote the docs

Most security vendors hide their documentation behind a login. Some don’t write it at all. You get a sales page, a demo, and a request to install an agent on your servers, and you’re expected to trust that the thing does what the marketing says. That’s backwards. So we wrote the docs, and we put all of them at certkit.io/docs. No login, no account gate, no “contact us for details.” You can read every page before you create an account.

Teleport Debuts Delegated Agentic Identity and LLM Proxy in Beams Public Beta, for Containing Agents in Production Infrastructure

Two foundational identity concepts - controlling the scope of agent roles and constraining what they can access - now have a production implementation in Beams, Teleport's trusted, ephemeral agent runtime.

Why AI Can't Verify Its Own Code and What That Means for Enterprise AppSec

AI models that generate code are also the best at exploiting it. Here’s why independent verification, not the model itself, is the only trustworthy answer. This month, the US government ordered Anthropic to suspend access to its most capable models, Mythos 5 and the newly released Fable 5, for all foreign nationals, citing national security. The trigger was a single reported jailbreak that let one of those models slip past its own guardrails on cybersecurity tasks.

GitGuardian Developer Endpoint Protection: Secret Scanning For Your Laptops

GitGuardian Developer Endpoint Protection helps security teams find secrets across any of your organization's laptops. In this walkthrough, Dwayne shows how to install ggshield, enable the machine scan plugin, run a local workstation scan, and review findings in the local dashboard.

Top 7 Claude Skills for Developers

Over 78% of developers are using Claude for coding, but almost everyone is leaving its single most powerful feature switched off: Claude Skills. In this video, we break down what Claude Skills are, how they use "progressive disclosure" to keep your context window light, and the 7 best engineering skills you can install this week to completely supercharge your workflow.