Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

A Short History of Crypto Customer Data Leaks, and What They Teach

In August 2026, Trezor told about 13,700 US customers that their names, email addresses, phone numbers and shipping addresses had been stolen in a breach at ShipMonk, a logistics company that had once handled its orders. Weeks later the number rose to roughly 80,700, after the company found the stolen records also covered orders placed between late 2019 and mid-2021. Customers who had bought a wallet five years earlier, and long since forgotten the delivery, were suddenly on a list in the hands of an extortion group.

Open-Source Intelligence Tools for Security Teams

Attackers rarely start with an exploit. They start with a search: which subdomains a company runs, which staff email addresses sit in breach dumps, which forgotten server still answers on the internet. MITRE ATT&CK treats this stage as a tactic of its own, Reconnaissance, and most of it runs on public data.

Cyber Loss in Rail and Signalling

Cyber risk in transport is usually framed around a collision. Signals manipulated, a train sent onto occupied track, an accident caused deliberately. ‍ Signalling is built to make that outcome unavailable. Any failure forces the system into its most restrictive state, so a compromise produces a halt rather than a crash. The loss is the halt, and rail is unusual in already having a published price for one. ‍

Reading AI Use From the Browser When the Network Sees Nothing

A session to a sanctioned AI provider looks the same on the network whichever account it ran under and whatever was in it. Transport encryption means a proxy sees a connection to an approved domain and a payload size. ‍ Which is fine until somebody asks whether an exposure is reportable. The question turns on three facts the network never held, and none of them can be reconstructed from a log afterward. ‍

Sophos Named a Leader in the IDC MarketScape for Worldwide Modern Endpoint Security for Enterprises 2026

Sophos has been named a Leader in the IDC MarketScape for Worldwide Modern Endpoint Security for Enterprises 2026, recognizing the strength of our prevention-first approach and stopping AI-era threats as early as possible. Attackers using frontier AI models can now find vulnerabilities and generate exploits faster than organizations can patch them. And when malicious code is already running before an alert fires, detection alone is too late.

Key compliance frameworks in Singapore: PDPA, MAS TRM, Cybersecurity Act, and more

Accelerating security solutions for small businesses‍ Tagore offers strategic services to small businesses. A partnership that can scale‍ Tagore prioritized finding a managed compliance partner with an established product, dedicated support team, and rapid release rate. Standing out from competitors‍ Tagore's partnership with Vanta enhances its strategic focus and deepens client value, creating differentiation in a competitive market.

Egnyte's AI Workspace: Where Organizational Knowledge Becomes Action

We've all been there. You're a few minutes from a client call, and you need one clear answer before you jump on. So, you open the project tracker then the shared drive, hunting for the latest email. Then you review a Slack thread to check if that blocker got resolved. By the time you dial in, you've burned fifteen minutes and you're still not fully sure you have the full picture. None of those tools failed you—each one had a piece of what you needed.

The Difference Between Knowing a Vendor Is Risky and Knowing Exactly Which Assets to Fix

When a vendor’s risk score changes, a TPRM team can see what issues were flagged, why they matter, and what remediation steps are recommended next. But improving a vendor’s risk posture is not always as simple as working through each risk finding one by one. Sometimes the bigger pattern sits at the asset level.

Cybersecurity Awareness Month 2026: Why Awareness Needs to Be Intelligence-Led

Cybersecurity Awareness Month has encouraged safer online behaviour every October since 2004, but AI-enabled attacks are changing what awareness needs to look like. This article looks at the campaign's history, the latest UK threat data, and why organisations should ground their awareness efforts in real threat intelligence.