Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Cleartext is all fun and games

One of the many interesting things we stumble across in the Black Hat NOC (Network Operations Center) is the various applications exhibiting poor security hygiene. Usually it’s something in the clear that makes us chuckle before we move on to more serious matters. Sometimes it’s something more serious that requires letting an attendee know they’re leaking sensitive information.

9 Web App Pentesting Service Providers (2026)

Shopping for a web app pentest is confusing on purpose. Every vendor on your shortlist says the same things (“manual testing,” “OWASP coverage,” “audit-ready report”), yet what you get back ranges from a deep, exploit-driven engagement to a scanner export with a logo on it. If you are a CTO, founder, or security lead trying to compare web application penetration testing companies without a security background to lean on, the hard part is not finding providers.

How Teleport Operationalizes the EU Cyber Resilience Act's Secure-by-Design Mandate

The EU Cyber Resilience Act (CRA) enters its enforcement window in 2027, but preparations should start now. ENISA's Secure by Design and Default Playbook (v0.4, March 2026) translates the CRA's legal text into 22 actionable security playbooks, structured around architectural foundations, operational integrity, default hardening, and guided protection. Together, they represent the most prescriptive infrastructure security framework the EU has ever published.

Taming the Unstructured Data Beast: Why Life Sciences Needs a New Playbook

In the world of life sciences, data is the lifeblood of discovery. But today, that lifeblood is more like a tidal wave. We’ve moved far beyond simple spreadsheets—there’s now an explosion of unstructured data with variety, velocity, and volume that’s daunting, even for large companies. According to some estimates, unstructured data now accounts for nearly 80% of all data generated by organizations.

Access Governance vs. Access Management: What's the Difference?

Most organizations deploy access management tools and believe they have identity security covered. They do not. What they have is a way to let users in, but no systematic way to ask whether those users should still have that access at all. Access governance and access management are related but distinct disciplines.

Trust, Verify, Protect: Modernizing Email Security for the Cloud

Picture this: Your company just fell victim to a massive data breach. The culprit wasn't a sophisticated malware strain, a zero-day exploit, or a compromised firewall. It was a perfectly legitimate-looking login from a VP’s account, originating from an unrecognized IP address, requesting an urgent wire transfer via a spotless, text-only email. In the modern threat landscape, attackers have realized something crucial: Why break in when you can just log in?

TeamPCP Profile: Why Developer Tools Are Becoming the Attack Path

TeamPCP is a financially motivated ransomware group tied to software supply chain compromise, credential theft, extortion, and abuse of developer infrastructure. The group is also tracked through aliases including ShellForce, PCPcat, TeamPCP, DeadCatx3, Altered Spider, and PersyPCP. The group has also claimed ownership of CipherForce, which it describes as its private locker.

Building AI agents in Tines Stories: tips and tricks for advanced builders

This is the second in a two-part series on AI agents in Tines Stories. Part one covers the foundations: when to use agents, how to configure them, how to write prompts that work, and how to build securely. This post goes deeper on the patterns that separate robust, well-built agents from just good enough ones.

Building AI agents in Tines Stories: tips and tricks for getting started

AI agents are powerful, but they're not magic. Left unconstrained, they'll burn through credits, hallucinate confidently, and make decisions you can't explain to your team. The fix isn't a smarter model, it's a smarter workflow. This guide focuses on the foundations of building an agent: when to use agents, how to configure them, how to write prompts that work, and how to build securely from day one.

The Internet Knows More About You Than Your Neighbors Do

A few years ago, online privacy felt like something reserved for tech experts, conspiracy theorists, and people who covered their laptop cameras with tape. Today, it feels a lot more personal. Every online purchase, every account sign-up, every late-night search, and every public Wi-Fi connection- there are little digital footprints left. All by themselves, they are not that dangerous. They form an amazingly comprehensive profile of yourself.