Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Why Human Behavior Has Become Cybersecurity's Fastest-Changing Attack Surface

For years, cybersecurity has largely focused on strengthening technology. Organizations invested in better endpoint protection, stronger identity controls, advanced threat detection, and AI-powered security operations. Those investments remain essential, but they're no longer enough. The next major cybersecurity challenge isn't simply keeping pace with attackers. It's keeping pace with how people work.

Sophos Firewall v22 MR2 is now available

Sophos Firewall v22 MR2 is now available AI app control, PQC detection, enhanced Chromebook support, and more. Sophos Firewall v22 bolstered Secure by Design, taking it to a whole new level with major updates to the architecture and new features like the Health Check to help identify high-risk configurations. Sophos Firewall v22 MR1 added several enhancements, including a new set of NDR detections for active threats.

How to Protect R&D Data During M&A

Mergers and acquisitions (M&A) concentrate risk into a narrow window. The moment a deal is announced, employees with access to proprietary research, source code, and unreleased product plans face pressure and opportunity at the same time. Some update their resumes. A smaller number decide to take something with them: a research file, a pricing model, or a customer list before the transition is final. For compliance and security teams, the challenge goes beyond stopping data exfiltration.

They Infiltrated the Infiltrators - And What They Found Was Unprecedented

Investigators have turned the tables on one of the world’s most elusive regimes. After a security firm hired a man calling himself "Joseph," a team of private investigators did what no one had done before: they infiltrated a North Korean remote worker cell from the inside. Head to our YouTube channel and watch the full episode of To Catch a Thief, Season 2.

Lessons from a CISA Security Incident - The 443 Podcast - Episode 378

This week on the podcast, we review an after action report from CISA on a security incident they responded to back in May. After that, we cover a vulnerability in Amazon's Q Extension for VSCode before covering a research post from Microsoft on Giga Wiper.

Why You Must Still Review AI Code

In this video, we break down why skipping code reviews is a massive mistake that will ultimately slow you down, leave you vulnerable, and compromise your system's accountability. We dive into three concrete reasons why reviewing AI-generated pull requests actually makes you a faster, safer developer, including a real-world story of a production bug caught in under 90 seconds. Resources Chapters.

AI Governance on AWS: Discover, Observe, and Control AI in Production

AI adoption within AWS environments is accelerating faster than most security and governance programs. AI agents, APIs, MCP servers, and model integrations are entering production across cloud environments, often without centralized visibility or runtime controls. In this webinar, you’ll see how teams can discover AI workloads across AWS accounts, understand what AI systems are actually doing at runtime, enforce policy in real time, and generate continuous governance evidence without slowing engineering teams down. The session focuses on practical operational capabilities for AI systems already running in production.

What Is Firewall Configuration and Why Is It So Important?

Firewall configuration is the set of rules, policies, and settings that define how a firewall behaves. Without configuration, a firewall is hardware and software waiting for instructions. With configuration, it becomes a control that determines what traffic is permitted, what is blocked, and what gets inspected before a decision is made. Get the configuration right, and the firewall does its job. Let it drift, and you have the appearance of protection without the substance of it. This is not an edge case.