Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Hunting the Undead: Accelerating NetNTLMv1 Lookups Without GPUs

Outdated protocols, forgotten configurations, and legacy dependencies continue to create opportunities for attackers in modern environments. This research explores how NetNTLMv1 can still be leveraged today and how improvements in attack tooling are reducing the cost and complexity of exploiting it.

Cyber Resilience Act Compliance Checklist: 15 Steps to Prepare Before 2027

The EU Cyber Resilience Act makes cybersecurity a condition of market access. A product with digital elements sold in the EU must demonstrate security by design, secure defaults and working vulnerability management — or it does not get a CE mark. This Cyber Resilience Act compliance checklist turns Regulation (EU) 2024/2847 into 15 steps, in execution order.

How to stop sensitive data leaking into ChatGPT, Copilot and other GenAI tools

AI productivity tools are creating a prompt-level data leakage problem: 77% of employees paste data into generative AI tools, and 82% of that activity comes from unmanaged accounts, according to the LayerX Enterprise AI and SaaS Data Security Report 2025. Every paste into ChatGPT, Copilot or another GenAI tool is a potential exposure of sensitive data that traditional file-focused controls were never built to see.

OT vs IT: The Key Differences Between Operational Technology and Information Technology

Information technology and operational technology are increasingly connected, but they are not interchangeable. IT is built around information and business services; OT is built around physical processes, equipment and safe operation. That difference shapes their security priorities, asset lifecycles, maintenance practices, network architecture and recovery requirements.

Antivirus and Firewall: Building Layered Defense with SIEM

“Install antivirus and enable the firewall” is still common security advice. It's also incomplete. Those controls can block malicious code and unwanted traffic, but they don't automatically connect an endpoint detection to the firewall event that preceded it, identify a compromised identity, or tell an analyst whether a policy change was legitimate.

Cybersecurity Challenges Facing the EMEA Travel and Tourism Industry

Like many, the travel and tourism industry has undergone a radical digital transformation over the last few years. From AI-curated itineraries and biometric check-ins to interconnected booking engines and smart room tech, the modern “Digital Guest Journey” is more seamless than ever before. However, this rapid innovation has come at a steep price.

Evaluating AI systems at Corelight

AI system evaluation is the process of continuously assessing AI system capabilities, limitations, and performance through quantitative and qualitative measures. Across the system lifecycle, evals provide continuous assurance: Validating system behavior before deployment and detecting drift, bias, and reliability issues in production.

Developer secrets management that keeps delivery moving

In March 2025, attackers compromised a GitHub Action used in the development pipelines of more than 23,000 repositories. The malicious code exposed API keys, cloud credentials, SSH keys, and other tokens in workflow logs. Affected teams were advised to review their workflow runs and rotate any credentials the logs exposed.

Real-Time AI Security Monitoring: Why One Assessment Expires

A penetration test on a web application stays broadly valid until someone changes the application. An assessment of an AI system starts expiring immediately, because the system changes without anyone at your organization touching it. The same prompt can return a different answer tomorrow, and the provider can revise the model underneath you without notice. ‍