Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Attestation in Cybersecurity: Types, Uses & Best Practices

Attestation is a security process that enables one system or entity to prove its state or characteristics to another. This typically involves generating verifiable evidence about the software, hardware, or configuration of a device or environment. The primary goal is to ensure that systems are operating as expected and have not been tampered with. Attestation is important for building trust in distributed environments, where direct oversight and control are not always possible.

Automating Identity and Access for FedRAMP 20x KSIs with Teleport

Cloud service providers preparing for FedRAMP 20x are encountering a fundamentally different authorization model than the one their compliance programs were built around. The traditional FedRAMP path produced lengthy System Security Plans, point-in-time assessments, and human-readable narrative evidence.

Your AI Agent Needs to Know Who You Are

When your AI agent calls an MCP tool, that tool has no idea who actually triggered the request. It sees the agent, not you. This post explains why that matters and how to fix it with Teleport JWTs. In part two of this post, we will explain how to extend this to AWS to carry your identity through Amazon Bedrock AgentCore all the way into CloudTrail.

GitGuardian Smart Notifiers: Filter Incident Alerts by Risk, Severity, and More

Every secret leak matters, but not every incident needs the same level of alerting. GitGuardian’s new Smart Notifiers let teams define per-channel rules so notifications are only sent for the incidents that matter most, using filters like severity, ML risk score, validity, secret type, and GitGuardian tags. This is available now for custom webhooks, Slack, and Microsoft Teams. We will be adding support for ServiceNow, Jira, Splunk, PagerDuty, Discord, and broader email filtering coming next.

What's New in ggshield 1.52.x - honeytoken plant, ARM Linux support, and one line install scripts

ggshield 1.52.0 and 1.52.2 bring several practical updates for teams securing AI-assisted development workflows. This release adds honeytoken plant, a command for adding local decoy AWS credential profiles Also, GitGuardian AI hooks installation will guide you through any issues you might encounter. As well as better macOS Keychain handling before hooks run in non-interactive agent sessions. The release also adds standalone Linux ARM builds and new one-line install and uninstall scripts for Linux, macOS, and Windows.

How to Setup AI Rules, Skills, Hooks and MCPs

In this video, we break down how to properly set up and use AI extension points - specifically MCP (Model Context Protocol) servers, Rules, Skills, and Hooks - to supercharge your development workflow. Using practical, security-flavored examples with Claude Code and Snyk, you'll learn how to configure a local project environment that automatically catches vulnerabilities before they ever hit your codebase. Whether you use the Claude CLI, VS Code extensions, or alternate AI ecosystems like Cursor or Gemini, you can use these exact steps as a blueprint to automate any workflow in your project.

AI changed what you ship. It also changed what you have to secure.

Two years ago, your teams shipped software. Today they ship two different things. They ship software that AI mostly wrote. And they ship AI systems they built themselves: models, agents, features that reason and act. Most security programs are still scoped for the first and blind to the second. That gap is not a tooling problem. It is a category problem. And the way the industry is drawing the categories is making it worse.

The Most Targeted Industries: What DevOps Teams Can Learn from Recent Incidents

Which industries are attracting the most attention from cybercriminals today? According to the DevOps Threats Unwrapped Report 2026, Technology and Software organizations remained the most targeted sector. This finding is consistent with our previous research in the 2024 CISO’s Guide to DevOps Threats, showing that attackers continue to focus heavily on organizations that build, manage, and distribute software. What changed, however, was the composition of the industries that followed close behind.