Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Find and Fix Risky Firewall Rules | Reach Security Demo

A firewall rule set to allow any source to any destination can stay live for months. It cancels out the rules beneath it and lets traffic pass unchecked. That kind of drift sets off no alarm. It builds up between quarterly reviews, while small teams govern 50 or more firewalls and hundreds of rule changes a week. Reach Network Security Assurance finds these controls, shows how long each has been open, ties the finding to real exposure, and guides the fix.

Migrate from Protegrity AI Developer Edition to Team Edition

See how developers can move from Protegrity AI Developer Edition to Team Edition while preserving existing application workflows. This walkthrough shows a usage-driven migration designed to minimize friction and avoid unnecessary code changes. Developers can connect their environment, validate compatibility, configure Team Edition services, and confirm that existing protection workflows continue to operate successfully.

AI is moving fast. Exploits are right behind.

Chris Luft and Matt Bromiley cover four stories in this week's Intel Chat that all point to the same trend: attackers are keeping pace with how fast AI tools are being built and deployed. They break down a chatbot pipeline vulnerability in Google Dialogflow CX, a phishing technique that hides malicious content until it renders in the browser, four newly exploited vulnerabilities added to CISA's KEV catalog, and an attack that exploits AI coding assistants' tendency to hallucinate fake repository names.

AI Traffic Security: The Hidden Risk of Unstructured Data Leakage #aisecurity

Understanding the nuances of AI Traffic Security is critical because traditional firewalls and API gateways are fundamentally ill-equipped to inspect unstructured natural language. In the past, enterprise data remained safely within the corporate perimeter. Today, employees are pasting highly sensitive information directly into external models, creating a massive vulnerability where the risk lies in the meaning and content, rather than syntax or connections.

ISO 27001 vs ISO 42001 Do You Need Both

Already certified to ISO 27001 but wondering if your organization also needs ISO 42001? In this video, we explain the difference between ISO 27001 (Information Security Management) and ISO 42001 (AI Management Systems). If your organization uses AI tools like ChatGPT, Microsoft Copilot, Gemini, or develops AI-powered products, understanding AI governance is becoming increasingly important. Learn when ISO 42001 complements ISO 27001 and how both standards help organizations strengthen security, governance, and compliance.

How to Patch Vulnerabilities and Reduce Risk with Aurora Vulnerability Management and Resolve

Learn how to identify, prioritize, and remediate vulnerabilities using Aurora Vulnerability Management and the Resolve integration. This demo walks through filtering and targeting high-risk vulnerabilities, deploying patches across assets, and tracking patch jobs to reduce risk more efficiently.

See It, Fix It: Comply to Deploy/Patch in Action: Tanium Tech Talks #165

Finding a vulnerability is easy. Closing the loop from finding to fixing is where programs stall. That gap — identify, prioritize, deploy a fix safely, then confirm it's actually gone — is what closed-loop remediation solves. Today we're walking through how to take Tanium's vulnerability findings and turn them not just into vulnerability remediations — but also as ways to identify and fix gaps in your OS & 3rd party patching programs.

Ep. 68 - Why OWASP's AIVSS Scores Agentic AI at Maximum Risk

OWASP just shipped AIVSS — an entirely new vulnerability scoring methodology built for autonomous AI agents, where a compromised orchestrator can score a perfect 10. Host Tova Dvorin and Adrian break down the "amplification principle": why a 2.1 CVSS finding becomes a 7.1 in the wrong agent, how persistent memory and broad tool access expand every blast radius, and what EchoLeak-style attacks already mean for real deployments. Plus where adversarial exposure validation and SafeBreach's agentic AI coverage fit in.