Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

The practical checklist for defending against supply chain attacks

Supply chain attacks are having a moment. Open-source malware detections jumped 73% in 2025. In the past year, the debug and chalk packages were backdoored, the tj-actions GitHub Action was compromised and pulled malicious code into thousands of pipelines, and the axios maintainer account was hijacked and used to distribute a RAT. Malicious releases also hit Zapier, ENS Domains, PostHog, and Bitwarden CLI. Every one of these attacks was preventable with controls that were available at the time.

The best AI lesson this summer came from watching our interns challenge AI

Unknown block type "undefined", specify a component for it in the `components.types` option Every conversation about AI and early-career employees seems to start in the same place: will it weaken foundational skills by doing too much of the work? That's a reasonable concern. It's also not the question that ended up mattering most this summer.

Managed IT services for health care: What MSPs need to deliver in 2026

Heath care organizations are under attack. That's not news. But how serious is the threat? Consider these numbers from the IBM Cost of a Data Breach Report 2025: Health care organizations need help, and managed service providers (MSPs) can drive revenue and grow their businesses by providing it. But working in health care isn't like working in other industries.

The tokenmaxxing bill is due: Take control of AI spend with SaaS Manager

A nasty shock is hitting finance leaders across every industry right now: AI token bills that run ten, twenty, even a hundred times over what they forecasted, blowing holes straight through quarterly budgets. These leaders are all asking the same questions: How could this happen if they didn't approve it? Why didn't any of their systems alert them to the spike? And most importantly, what can they do now?

Connecting the Office and Field: A Better Approach to Construction Data Management

Construction projects depend on timely decisions. When a superintendent needs the latest drawing set, a project engineer must review submittals, or a project manager wants to reference lessons learned from a past project, access to accurate information directly impacts project outcomes. Yet many construction firms still struggle with information scattered across jobsite photos, RFIs, specifications, BIM models, emails, and project management systems.

How to Prevent AI Agents from Exfiltrating Sensitive Data

An AI agent on a developer's laptop has read access to a code repository, a set of internal documents, and an external model. Nobody approved that specific combination, and nobody is watching what the agent does with it session to session. The agent is not malicious, however, it is doing exactly what it was configured to do. But, that configuration is the exposure, and most security teams do not have a way to see it, let alone stop it before sensitive data leaves the environment.

Suricata IDS/IPS Data in Graylog

If you’re running Suricata to watch your network, you already know how much signal lives in its logs. Graylog provides a purpose-built way to make that signal immediately actionable. The Suricata IDS/IPS Content Pack, available with an Illuminate license and Graylog Enterprise or Graylog Security, delivers ready-to-use parsing rules, streams, GIM categorization, and a dashboard so you can turn raw Suricata EVE JSON events into structured, searchable security intelligence.

Finding Just Got Free: That's Why Fixing Is the Only Game That Matters

When Anthropic revealed Claude Mythos and Project Glasswing, the industry did what the industry always does with a frontier-AI story: it reached for the alarm. The headlines, Reddit threads, and back-channel conversations all focused on the same things: All of that is real, and none of it is the part that should keep a security leader up at night. Here is the part that should.

France's ANSSI Sets New Post-Quantum Cryptography Milestones: What It Means for Your Security Strategy

Quantum computers capable of breaking today’s encryption may still be years away, but France’s National Cybersecurity Agency (ANSSI) believes organisations shouldn’t wait to prepare. At the France Quantum Conference on June 16, 2026, ANSSI announced new milestones for the adoption of Post-Quantum Cryptography (PQC). ANSSI recommends that organisations prioritise purchasing quantum-safe security products by 2030. The most important message, however, isn’t about 2030.

The Top 5 Questions Security Leaders Are Asking About Coding Agents

The discussion during our recent webinar made one thing clear. Security teams aren't asking whether coding agents will become part of the enterprise. They're asking how to adopt them safely. The audience questions focused on practical concerns that many organizations are facing today, from autonomous execution to supply chain risk and governance. Here are the five questions that generated the most discussion.