Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Why Better Context Makes AI More Accurate, Faster, and Less Expensive

Ask an AI system a question about your business and, before it can answer, it has another problem to solve: What information actually matters? It has to find the right files. Determine which version is current. Understand how those files relate to a project, client, deal, or other piece of work. Figure out which information applies to the person asking. Then assemble enough of that information to make a useful decision. For someone who works in the business every day, much of that is obvious.

How to configure Microsoft 365 for maximum security

If someone wanted to cause serious damage to your organisation, where would they start? Not with your filing cabinets. Not with your server room. They’d probably start with your Microsoft 365 tenant, because that’s where your emails, files and customer data live, and where your entire operation runs. Thankfully, Microsoft 365 comes with powerful security capabilities built in. However, having those capabilities and being protected by them are two different things.

8 Best AI Tools for DevOps in 2026

SUMMARY Building an effective AI DevOps stack in 2026 comes down to balancing platform-native assistants for workflow speed with specialized engines for security, infrastructure, and delivery governance. This guide evaluates the 8 leading tools across both categories to help you select the right mix for your architecture and security requirements. This approach reflects a fundamental shift in engineering capabilities.

Emerging Threat: (CVE-2026-76461) Cisco Secure Email Gateway Root RCE via Email Parsing

CVE-2026-76461 is a SQL injection vulnerability in the email parsing logic of Cisco AsyncOS Software for Cisco Secure Email Gateway, caused by insufficient validation of message content before it reaches a database query. An attacker who sends a crafted email message containing SQL statements can have those statements executed by the appliance as it processes the message. The vulnerability carries a CVSS v3.1 base score of 9.8 (Critical).

Phishing Emails Use New Technique to Bypass Microsoft 365 Security Filters

Threat actors are using phishing emails with blank SMTP sender fields to bypass Microsoft 365 security filters, according to researchers at ReliaQuest. Microsoft 365 Exchange Online uses a feature called “RejectDirectSend” to block unauthenticated Direct Send emails from an organization’s trusted domain. If an attacker omits the domain field from these emails, however, RejectDirectSend will no longer block the messages.

10 MCP Security Best Practices

A natural-language decision can now trigger a real API call, query sensitive data, deploy code, or modify infrastructure. MCP expands the security boundary beyond the connection to the identities, privileges, tools, credentials, and downstream systems behind each action. That challenge is growing with adoption. Anthropic reported more than 10,000 active public MCP servers by December 2025, alongside 97M+ monthly downloads of its Python and TypeScript MCP SDKs.

The defensible AI-SOC: Redefining SOC modernization for the Mythos era

I know, I know. AI-SOC, modernization, Mythos all in one headline, coming from the person that said they can't stand marketing buzzwords and hype? Hear me out. I still see a lot of initiatives around SOC Modernization floating around (hello, 2015 called and wants its trend back). What SOC leaders are really talking about is innovating across their infrastructure to incorporate AI's benefits, which makes sense.

How AI Changes Exposure Management: From Static Findings to Continuous Risk Decisions

Every security team knows the feeling. The quarterly vulnerability scan completes. The report lands, with thousands of findings, color-coded by CVSS severity, neatly timestamped. And the moment it’s printed, it’s already out of date. That is the fundamental flaw at the heart of traditional exposure management: it is built around a point in time.

PAPERMILL: Tracking an Emerging China-Nexus Malware Factory

JUMPSEC’s DART (Detection & Response Team) raised an alert to the Threat Research team regarding a specific ticket that arrived in a clients’ inbox, passing SPF, DKIM, and DMARC. The email contained an attachment and a subject which spoke about Tax Audits, that attachment, named “Tax_Notice_45594.exe” is not actually an exe but instead an.ISO. On the surface this looks like a fairly typical phishing lure, but the delivery mechanism underneath is anything but.