Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Session Tokens Are the Real Target

For most of the past decade, security advice on credential attacks reduced to a single instruction. Turn on multi-factor authentication. That instruction was correct and it worked, which is precisely why attackers stopped attacking the thing it protects. The current generation of credential campaigns does not try to defeat MFA. It waits for the victim to complete it, then steals what the authentication produced. The password was never the prize. The session was.

ManageEngine Listed on the UK Government's G-Cloud 15 Framework

For public sector organisations, digital change is rarely just a question of new tech. It is also about finding solutions that are secure, effective, sustainable, and just as importantly, straightforward to procure. That is why we are delighted to announce that ManageEngine has been awarded a place on the UK Government’s G-Cloud 15 framework, with our cloud applications listed under Lot 2b: Software as a Service (SaaS).
Featured Post

AEBA: Why Behavioural Analytics Has to Expand Beyond Humans

For years, security teams have built behavioural models around people. We learned that valid credentials only tell so much. A user can have legitimate access to a system and still behave in a way that deserves attention, which is why User and Entity Behaviour Analytics (UEBA) became such an important part of modern security operations today - intersecting data from multiple sources over extended periods of time to build a story indicating risk has become an essential tool to identify malicious actors, both insiders and outsiders.

Agent Sprawl is the New Shadow IT

As you’re reading this, it’s possible an agent you’ve never heard of is reading your files. But where did it come from? What systems can it access? And who’s responsible for its oversight? Today, employees are using AI and agents to expand what they can accomplish and how work gets done. And the barriers to innovation have never been lower — with natural language and no-code tools, anyone in your organization can build a new agent in the span of an afternoon.

UPDATE: Active Exploitation CVE-2026-32996 of Veeam Agent

On September 14, 2026, public technical details and proof-of-concept (PoC) exploit code were released for CVE-2026-32996, increasing the likelihood of exploitation attempts against affected Veeam Agent for Microsoft Windows deployments. CVE-2026-32996 is a local privilege escalation vulnerability in Veeam Agent for Microsoft Windows version 13.0.1.2067 and affects all earlier version 13 builds.

The Linux AI blind spot: 7 exfiltration points your DLP can't see

Shadow AI now contributes to one in five data breaches, and Linux endpoints, where most developers work, largely lack DLP enforcement. That means engineers can upload code to AI tools, copy files to USB or Bluetooth devices, sync data to personal cloud storage, and move files through network shares undetected. HIPAA, PCI DSS, GDPR, and CMMC hold organizations accountable regardless of this coverage gap. Netwrix Endpoint Protector extends content-aware inspection and device control to Linux.

Sumo Logic MCP server: bringing SIEM and log data into Claude and other AI clients

More security and operations work now happens inside an AI client instead of a dedicated console. That shift creates a gap for any platform that isn’t part of the conversation. Every time an analyst needs to triage an insight or check a log, they have to leave the AI client and go open a different tool. Sumo Logic closes that gap with a Model Context Protocol (MCP) server.

Run LimaCharlie AI Sessions on the model you choose

Co-founder and COO AI Sessions in the LimaCharlie web application now run on OpenAI, Google Gemini, and OpenRouter models in addition to Claude. Connect your own credentials, pick a provider per session profile, and the session behaves the same way regardless of which model is doing the work. Sessions run on Claude by default. Beyond that, you can connect any of the following with your own credentials.

Identity Lifecycle Management: Process, Stages, Benefits, and Best Practices

Identity lifecycle management is the process of managing a user's digital identity and access from the day they join an organization to the day they leave. It covers account creation, role changes, permission updates, and deprovisioning, and it applies to employees, contractors, service accounts, and increasingly, AI agents. Get it wrong, and you end up with two failure modes: new hires waiting days for access, and former employees who still have it. Both cost money. Only one of them makes headlines.