Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Red Hat OpenShift on IBM Cloud: What It Is and What's New

Running Kubernetes in production takes real work. Patching control planes, managing upgrades, and keeping clusters highly available pulls engineers away from shipping applications. Red Hat OpenShift on IBM Cloud removes that operational load. IBM runs the platform as a fully managed service, and your team keeps its attention on workloads.

Securing what your Bedrock AgentCore agents actually do

An AI agent is software that can act on your behalf. It may read documents, emails, and web pages, then use the systems you connected to complete a task. Amazon Bedrock AgentCore makes these agents faster to build and deploy. But securing them requires more than limiting which systems an agent can access. You also need to consider what the agent can read once it gets there. A document, email, or web page may contain hidden or malicious instructions designed to influence an agent’s next action.

Measuring AI Agent Coverage Against the Gateway Log

A tool gateway reads every call that crosses it and enforces policy on each one. It is blind to whatever never traverses it, which is established and not the interesting part. ‍ The useful number is what fraction of an agent's total action surface the gateway covers. Blindness of unknown size and blindness of known size are different problems, and only the second lets you state what a gateway-based claim is worth. ‍

CrowdStrike Named a Leader in The Forrester Wave: Proactive Security Platforms, Q3 2026

CrowdStrike has been named a Leader in The Forrester Wave: Proactive Security Platforms, Q3 2026. We received the highest Strategy category score in the evaluation and maximum scores in both the Innovation and Roadmap criteria. This evaluation reflects how the market is evolving. Proactive security is moving beyond traditional vulnerability management.

A Configuration Change Should Never Leave You Guessing

Security controls change constantly. Firewall rules are modified, endpoint exclusions are added, identity policies are adjusted, and temporary exceptions appear as teams respond to new business and operational requirements. Some of those changes are expected. Some turn out to be harmless. Others quietly weaken the defenses organizations depend on. Detecting that a configuration changed is really important for security teams, but it’s just the beginning of the investigation.

HTTPS Content Inspection: Give Your Firebox a Better View

HTTPS protects communications between users and the services they access by encrypting data in transit. That makes it much harder for someone to intercept and read that information. But there is a trade-off: encryption can also prevent security controls from seeing what is inside the traffic they are supposed to protect. Your Firebox may know that a user is connecting to a website or service. Without HTTPS inspection, however, it may have limited visibility into what is actually being exchanged.

MDR vs XDR: which do you need in 2026?

Quick definitionManaged detection and response (MDR) is a managed security service that provides human-led monitoring, investigation and agreed response actions through a remotely operated security operations center.Extended detection and response (XDR) is a technology platform that correlates security telemetry across multiple domains and provides investigation tools and automated response capabilities for security teams.

HMI security: protecting human-machine interfaces from cyber threats

HMI security protects the operator-facing system against unauthorized access, credential misuse, malware, lateral movement and tampering while preserving safe visibility and operational continuity. In PC-based deployments, the OEM-managed application and the Windows or Linux workstation beneath it require separate controls. This guide is for OT and automation engineers, SCADA administrators and plant leaders responsible for HMI availability.

Detectify positioned as a Major Player in the IDC MarketScape for Worldwide Dynamic Application Security Testing

When modern development teams and AI agents ship code at unprecedented speeds, the runtime security checkpoint becomes an indispensable line of defense. However, far too many AppSec teams find themselves drowning in a sea of false positives, overburdened by legacy tools that infer potential vulnerabilities rather than proving their real-world exploitability.