Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

How to Prepare for a CompTIA Exam Without Paying for a Course

CompTIA certifications open real doors - Security+, A+, Network+, and CySA+ appear in job postings from entry-level IT support all the way up to federal security analyst roles. The assumption most people run into is that passing one of these exams requires spending $300 to $500 on an instructor-led course. It doesn't. Candidates who pass without dropping that money aren't cutting corners; they're just smarter about where they find the same information. Official exam objectives, free practice materials, active online communities, and a disciplined self-study schedule give you everything a paid course would - minus the price tag.

Lessons from Microsoft's September 2026 Patch Tuesday

This month's Patch Tuesday just became the largest security release in Microsoft's history (so far), and it's tempting to let that record stand as the headline. However, the volume isn't the highlight. What a cycle this size exposes is how most patching processes are built, and exactly where they buckle. Here's what this month actually taught us, and what we need to change before the next record-breaking cycle arrives.

AI Governance in healthcare: Compliance and security

AI governance in healthcare has become a question boards and auditors ask directly. They want to know which AI tools reach protected health information, who's accountable for each one, and what evidence shows the controls are holding. Most health systems have a written policy and no way to produce those three answers on request, which is precisely what an auditor tests. Healthcare organizations adopted AI faster than they built the governance to account for it.

Aligning Application Security Software with Business Growth Objectives

AppSec teams know application risk is growing, but budget conversations are often won and lost outside the security team, in rooms full of executives who speak the language of revenue and delivery velocity, not CVSS scores. The core argument: application security software is easier to fund when it is tied to growth, resilience, compliance, and delivery outcomes… not just technical findings.

Is Your OT Jump Server Giving Vendors More Access Than They Need?

A vendor can bypass MFA and sign in with an individual account while still being able to reach industrial systems unrelated to the job. Before replacing your current setup, follow one real service request from approval through completion. The exercise can reveal outdated permissions, unnecessary network connectivity, shared credentials, or records that are difficult to retrieve when you need them.

How Active Roles by One Identity supports IAM in a university environment

Managing user accounts, permissions and security access across a university environment involves significant administrative work. For institutions that rely on Microsoft Active Directory, keeping that infrastructure organized, secure and current can quickly become resource-intensive as student and staff populations shift each semester. This type of challenge grows when IT teams must handle onboarding, access changes and offboarding manually for each individual.

What Does NIST IR 8587 Mean for API Security?

On September 15, 2026, NIST published Internal Report 8587, “Protecting Tokens and Assertions from Forgery, Theft, and Misuse.” It’s built to extend NIST Special Publication 800-53 Release 5.1.1, and on paper it reads like an SSO hardening document for government agencies and their cloud vendors.

New Partnership with Entrust to Reach More Victims of Cybercrime and Fraud

Entrust, a global leader in identity-centric security solutions, today announced its partnership with The Cyber Helpline. Entrust will support our mission to help people understand, contain, and recover from cyber incidents by funding more than 3,200 hours of specialist support, which will provide assistance for approximately 1,000 individuals across the US and UK.

AI Security Has a Context Problem

The problem is not a lack of controls. It is connecting them into one attack story. The more time I spend with enterprise AI deployments, the clearer one thing becomes: AI security is incredibly fragmented. There are LLM guardrails, AI gateways, MCP security tools, API security, endpoint controls, SASE, code scanning, and runtime detection. Each solves a real problem, but agentic systems do not experience them as separate layers, and neither do attackers.