Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

The Invisible Expansion of the Attack Surface: Shadow AI, MCP, and Third-Party Risk

AI adoption is moving faster than most of us anticipated and, more importantly, faster than most organizations can govern it. Organizations are implementing the use of AI-enabled applications, browser extensions, coding assistants, and automated agents to enable employees to work faster. In many cases, these tools are adopted without security review, procurement approval, or a clear understanding of where organizational data is being sent.

What Is the Cyber Kill Chain: A 2026 Guide

You open an inbox and spot the kind of email every SOC team knows too well, a message that looks routine, lands with a harmless subject line, and asks someone to click, open, or approve something they shouldn't. That's where what is the cyber kill chain stops being an abstract term and starts being a practical way to think about intrusion, because the attack usually isn't one event, it's a sequence of choices an adversary makes before the damage shows up.

From standard sales user to AWS root in 5 minutes: An AigentX Case Study - Agentic AI Penetration Testing

A recent grey-box Salesforce assessment began with a low-privileged standard user account. From that starting point, AigentX mapped native Salesforce APIs and custom objects, identified cloud credentials exposed through misconfigured Field-Level Security, and demonstrated a path beyond Salesforce into the organization’s connected cloud infrastructure.

NGAV vs EDR vs XDR vs MDR: how to choose the right detection and response approach

NGAV (next-generation antivirus), EDR (endpoint detection and response), XDR (extended detection and response), and MDR (managed detection and response) are not four separate products bought independently — they are overlapping capabilities and delivery models. NGAV is a prevention capability, normally built into an endpoint protection platform or an EDR solution, that uses AI and behavioral analysis to block known and unknown threats.

Java Source Code Scanning that Works the Way You Do

Many tools fail to adapt to diverse developer use cases, leading to workflow interruptions in IDEs and CI pipelines. Managing dependencies for multi-module projects can be complex and time-consuming, often causing delays. And developers frequently work across varied environments – whether it’s IDEs, CI pipelines, or repositories, each with unique requirements. These challenges create friction and slow down the development process, making it harder to deliver secure applications on time.

What Is DSAR? Understanding Data Subject Access Requests Under the DPDP Act

A Data Subject Access Request (DSAR) gives individuals the right to ask these questions and gain greater visibility into how their personal data is being used. Under privacy laws such as India's Digital Personal Data Protection (DPDP) Act, Data Principals can request access to their information and exercise other privacy rights. Every time you shop online, sign up for a service, or submit your details on a website, organizations collect and process personal data about you.

ClickFix campaign abuses Deno runtime for infostealer delivery

Counter Threat Unit (CTU) researchers investigated a June 2026 campaign in which threat actors used the Deno JavaScript runtime as a core execution mechanism within a ClickFix-driven intrusion chain. On June 3 and June 4, compromised WordPress sites served Cloudflare-themed ClickFix lures that prompted users to execute a clipboard-delivered PowerShell command. This command initiated an MSI-based staging process that installed Deno and enabled retrieval and execution of remote JavaScript.

EU AI Act: risk tiers, timeline, and compliance requirements

The EU AI Act is a regulatory framework governing the development, deployment, and use of artificial intelligence within the European Union. The European Commission proposed it to keep AI systems placed on the EU market safe and transparent and to make sure they respect fundamental rights. The Act sets obligations for AI providers, users, and other stakeholders to address risks associated with AI while still supporting innovation and investment in the sector.

The Rise of Rogue AI Agents. What Recent Incidents Tell Us About the Modern World of AI

AI! It's in everything, everywhere, all at once! It’s reading emails, summarising meetings, drafting documents, and writing code, and it’s no longer just giving us answers. We now also have agents that act on their own, access other systems, and make decisions with little to no human oversight.

5 Reasons a Security Guard Cannot Legally Replace a Fire Watch Guard

With a malfunction in a fire alarm system, the main fire line breaks, or life safety control panels become non-functional due to maintenance work, there will be a requirement for compliance immediately. In order to save time and money, facility directors usually rely on the security guards who perform their duties in the building to "watch out for any fires.".