Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

SaaS vs. self-hosted Kubernetes backup: how to choose

SaaS or self-hosted is one of the first calls to make on Kubernetes backup and disaster recovery, and it’s worth settling before you compare features. This guide walks through what each deployment model means for a platform team, what to weigh before picking one, and where CloudCasa fits, since it offers both.

What Is Exact Data Match (EDM)? How It Works & Why It Matters

Every security team has lived through this problem: an employee books a flight with a personal credit card, and the DLP system flags the transaction, simply because the card number matches a predefined pattern. So, when multiple alerts accumulate, security teams often spend time investigating false positives rather than addressing genuine data leaks. This is precisely the problem Exact Data Match (EDM) was built to solve.

Sophos Firewall v23 is now in early access

Delivering over 30 of your top-requested features Sophos Firewall v23 brings many of your top-requested enhancements in one feature-packed release. From new AI-powered assistance and a modern REST API to streamlined rule management, stronger high-availability capabilities, expanded identity support, and simpler day-to-day administration, Sophos Firewall v23 is designed to make your firewall easier to manage, automate, and scale, while further strengthening its Secure by Design foundation.

TerminalFix and Lorem Ipsum Loader enable covert tunneling

In August 2026, Sophos analysts began investigating a series of Managed Detection and Response (MDR) cases that involved ClickFix-style lures and resulted in the deployment of a Python-based tunneling implant. Instead of a typical ClickFix lure that instructs victims to open the Run dialog box, these lures direct users to open a Windows Terminal window. This ClickFix variation is known as ‘TerminalFix’. TerminalFix is not linked to a specific threat group or a single campaign.

What Is Agentic AppSec?

Agentic AppSec (agentic application security) is the practice of using a team of AI security agents to run an organization's entire application security program: understanding the application, modeling its threats, finding the vulnerabilities that matter, deciding what is worth fixing, generating and validating fixes, and proving those fixes hold. It applies continuously to both new code and the existing backlog.

The Authorization Trap: Why "No Evidence of Manipulation" Doesn't Mean "No Incident"

Ask AI to Choose a prompt Write a TLDR of this post Explain the security risk Summarize what CISOs should know Many conversations about AI agent risk over the past year start from the same unspoken assumption: something bad happened because someone or something manipulated the agent. A hidden instruction in a document, a poisoned prompt, an adversary steering the model toward an action it shouldn't take. That's a real category of risk, and it deserves the attention it's getting.

Agentic AI Security Platforms: What Agent Logs Miss

An agent’s logs are written by the agent. Every framework log, trace span and tool-call record that an agentic AI security platform ingests comes from the process being watched, or from a gateway that sees only what that process routes through it. When a trusted prompt coerces an agent into misusing a permission it already holds, the record shows a normal tool call, because from inside the process it was one. Running more analysis on that record returns the same answer faster.