Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

CT alerts: know when someone gets a certificate for your domains

A couple days ago, I told you how a spammer got a certificate for dev-docs.trackjs.com, and that we only found out because Google emailed us. Google knew because the spammer claimed the hostname in Search Console. An attacker running a phishing page wouldn’t have done that, but they would still need a certificate. Every publicly trusted certificate gets written to a public log, and we track that log in our database. We just weren’t watching it. Now we are, and you can too.

Egnyte Named a Leader in the IDC MarketScape: Worldwide Intelligent Content Services 2026

We’re thrilled to let you know that Egnyte has been named a Leader in the IDC MarketScape: Worldwide Intelligent Content Services 2026 Vendor Assessment (#US54137426, September 2026). IDC’s report evaluates vendors on the strategies and capabilities that matter as content platforms become the foundation for enterprise AI.

Stop Chasing Tabs: Bringing Threat Research Home to the Browser

We all know the routine. You’re deep into a new threat report or a breaking blog post, and the tab management anxiety starts to kick in. You find a suspicious indicator, copy it, pivot to your internal tools to see if you’ve seen it before, paste it into a notepad, and then—maybe—try to get it into an actual investigation. By the time you’ve validated the intel, you’ve lost the trail. Threat research happens in the browser. Its time your workflow did too.

ISO/IEC 42001 and the Governance Gap Between Pilot and Production

In July 2025, a Replit coding agent deleted data from an application’s production database during a public experiment. The data was recovered, and Replit responded by separating development and production databases, limiting the agent’s access to the development environment, and strengthening the recovery experience. It later introduced a planning mode that allowed users to work with the agent without changing code or data.

3 Things CISOs Need to Know About Microsoft's ISOC Announcement

Cost pressure can decide what your security team gets to see. A useful log source gets left out. Investigation history gets shortened. Analysts work with the evidence the organization could afford to keep. That is the part of Microsoft's Integrated Security Operations Center, or ISOC, announcement I keep coming back to. Bringing SIEM capabilities into the Defender experience, using native security data, and changing the economics gives customers a reason to revisit those decisions.

Offsite Disaster Recovery: Benefits and Solutions

Most teams find the holes in their recovery plans at the worst possible time: a flooded data center, failed storage array, or ransomware note sitting on the same server as the backup catalog. Offsite disaster recovery removes that single point of failure, but only when the copy is truly separated from production by geography, network path, and access control. Distance by itself won’t save you.

How Headspace is taming wild code with Tines 3B

One of my favorite parts of my role is working closely with innovative customers like Chris Oh, Senior Director of AI Enablement at Headspace. Chris and I recently caught up to talk through how Headspace uses Tines 3B to give teams the freedom to build with AI, without the operational risk. We covered the problem Headspace set out to solve, why they chose Tines 3B, and some of their early wins with the product.

Cyber Resilience Act is here! Myth busting and first impressions

The first deadline of the Cyber Resilience Act went live last week. The Cyber Resilience Act (CRA) is the new EU regulation that defines minimum cybersecurity requirements for all products with digital elements, including their building blocks (hardware and software). It applies to anyone placing products on the EU market, not just companies based there. The full requirements won’t go into effect until the end of next year.

The Agent Will See You Now: Why Healthcare's AI Agent Boom Needs Visibility and Control

Ask AI to Choose a prompt Write a TLDR of this post Explain the security risk Summarize what CISOs should know Healthcare, as an industry vertical, is moving faster on agentic AI than it has in past technology evolutions. Some reports say it is outpacing other regulated industries. Ambient scribes are documenting patient visits in real time. Prior-authorization and revenue-cycle agents are handling payer workflows that used to require staff to log into multiple systems manually.