Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

The Cyber Risk Inputs That Move the Answer Most

A cyber loss model has dozens of inputs and every one of them can be argued about. Record counts, downtime costs, control effectiveness, secondary loss factors, event likelihoods. ‍ A few of them determine the answer and the rest barely move it. Knowing which is which tells you where estimation effort belongs, and more usefully which disagreements about the model are not worth having. ‍

PCI DSS Continuous Compliance: How to Keep Payment-Page Controls Working Between Audits

At the 2026 PCI SSC North America Community Meeting in Vancouver, continuous compliance was a recurring theme: how do organizations move beyond point-in-time validation and keep security controls working as their environments change? For payment-page security, that question is especially practical. Your last assessment captured your environment at a point in time. Since then, a release may have added a checkout dependency. A vendor may have updated its JavaScript. Marketing may have changed a tag.

Building for the Future: Why We're Doubling Down on Customer Experience at Brivo

One of the earliest business lessons I learned is the importance of taking exceptional care of customers. Focusing on a positive customer experience is a commitment and a business success strategy I’ve followed at Barracuda Networks, Eagle Eye Networks and now here at Brivo. Customers value a real person answering the phone, knowledgeable technical support, and professionals with regional and vertical market expertise.

Emerging Threat: (CVE-2026-86858) ServiceNow AI Platform Unauthenticated Privilege Escalation via GraphQL

CVE-2026-86858 is an improper access control flaw in the ServiceNow AI Platform, classified as CWE-284. ServiceNow describes it as an unauthenticated privilege escalation reachable through GraphQL. In certain circumstances an unauthenticated user can create, modify, or delete instance data beyond what was intended. The vulnerability carries a CVSS v4.0 base score of 8.7 (High). Attack vector is network, attack complexity is low, and neither privileges nor user interaction are required.

The Agentic SOC Isn't Coming for Analysts' Jobs. It's Coming for Their Tabs.

An agentic SOC uses AI-powered investigation, analysis, and automation to gather data, connect activity, and handle repetitive investigative work. Analysts remain in control and focus on judgment, prioritization, and response. This addresses the need for machine-speed security operations as AI agents gain autonomy and Tier 1 access to systems. Spend five minutes watching a security analyst at work and the “AI will replace analysts” headline starts to sound out of touch.

What's New in LogRhythm SIEM for October 2026

The October 2026 LogRhythm SIEM release modernizes self-hosted security operations with an in-place migration from Elasticsearch to OpenSearch, a next-generation self-service reporting engine, generative AI collectors, and a community Model Context Protocol (MCP) server. The release also includes backend and API updates that improve event drilldown, rule administration, network routing, and telemetry quality while helping organizations maintain control of sensitive security data.

AI Security in DevOps: Best Practices to Follow

SUMMARY Attacking a CI/CD pipeline used to require a specialist who understood Git internals, cloud identity, and the way build runners handle secrets. That is no longer true. The barrier to entry for an advanced attack has dropped to the level of writing prompts in English. Automation itself is not new to DevOps, but AI has raised its ceiling on both sides of the fence.

Block malicious packages across your organization with Supply Chain Firewall and Datadog Code Security

Campaigns such as Shai-Hulud 2.0 have demonstrated how quickly package malware can propagate through npm and then harvest credentials. Traditional dependency scanning can identify known risks in code once a package is added to the code, but security teams also need a check before installation.

AI Threats Are Evolving Fast. Your Employees Are Still the Last Line of Defense.

New training on using AI safely and spotting AI-powered threats arrives this Cybersecurity Awareness Month Attackers are moving faster than ever, weaponizing newly discovered vulnerabilities before defenders can patch them and building new types of malware that signature-based defenses can’t catch.