Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

MFA for Retail: Smarter Authentication for Stores, E-commerce & Employees

A refund is an authentication event, so are a POS login, a loyalty-account change, and a technician connecting to a store remotely. Retailers have traditionally treated these moments as separate access problems, but they share the same underlying question: how much confidence should the business require before allowing an action to proceed?

How to Audit Data Access for HIPAA, PCI, and GDPR

When an auditor asks who can access protected health information, cardholder data, or EU personal data, and why, most security teams cannot answer with confidence right away. Access sprawls across cloud storage, SaaS applications, shared drives, and generative AI tools faster than manual reviews can track it. Permissions get granted for a single project and never revoked. A spreadsheet gets shared broadly and forgotten.

CVE-2026-76461: Active Exploitation of Cisco Secure Email Gateway Critical Zero-Day Vulnerability Immediate Mitigation Required

CVE-2026-76461 is a pre-authentication SQL injection vulnerability in the email parsing logic of Cisco Secure Email Gateway (AsyncOS). This vulnerability enables unauthenticated remote threat actors to execute arbitrary code as root by sending crafted, malicious emails. This grants threat actors full control over the operating system, allowing data exfiltration, email surveillance, persistent access, and potential network pivoting, all without user interaction or credentials.

PhantomRaven: An LLM-Generated Information Stealer Developed for Bug Bounty Hunting

CrowdStrike Counter Adversary Operations identified a financially motivated threat actor who works as a bug bounty hunter and who developed and distributed the JavaScript (JS)-based information stealer PhantomRaven via npm, a platform on which developers can access open-source packages to build applications and software.

ISO 42001 Readiness Checklist: 15 Questions to Ask Before Certification

Getting an AI policy approved is not the same as being ready for ISO/IEC 42001 certification. Your organization may already have risk registers, information security controls, model documentation, supplier assessments and responsible AI principles. The more important question is whether these elements operate together as an Artificial Intelligence Management System (AIMS) — and whether you can demonstrate that with evidence. Before asking: “How quickly can we get ISO 42001 certified?”

AI Agents Are Forcing Us to Rethink Identity

Since joining BlueVoyant in May, I’ve spent my first 100 days listening. I've had conversations with nearly 50 customers and partners across industries and geographies, as well as the broader security industry, engaging with leaders at Black Hat last month. What I heard reinforced something I believe strongly: the security challenges organizations face today are changing faster than the traditional enterprise security model was designed to handle.

Never Join AI Telemetry on Byte Counts

A browser sensor reports that somebody pasted 18,000 characters into an AI tool. A network sensor reports a 24 kilobyte upload to the same destination. Joining those two records on size looks reasonable and is the wrong instinct. ‍ The two numbers describe different objects with several transformations between them, and the transformations do not all run in the same direction. The error cannot even be signed, which rules out a tolerance as well as an equality. ‍

Post-Quantum Cryptography: You Cannot Migrate What You Cannot See

On June 22, 2026, President Trump signed Executive Order 14412, accelerating the federal government’s transition to post-quantum cryptography. The order brings key migration deadlines forward from 2035 to 2030-2031 for high-value and high-impact systems. The Department of War followed with its own Post-Quantum Cryptography (PQC) Strategy, which sets additional deadlines and warns that a cryptographically relevant quantum computer is an existential threat to military missions.

AI Autonomy: How to Find the Autonomy Your Agents Already Have

AI agents are only as autonomous as the credentials behind them. This article talks about the Cloud Security Alliance's autonomy framework, why an agent's intended boundaries rarely match its actual access, and how GitGuardian helps close that gap through detection, remediation, and prevention.