Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

See It, Fix It: Comply to Deploy/Patch in Action: Tanium Tech Talks #165

Finding a vulnerability is easy. Closing the loop from finding to fixing is where programs stall. That gap — identify, prioritize, deploy a fix safely, then confirm it's actually gone — is what closed-loop remediation solves. Today we're walking through how to take Tanium's vulnerability findings and turn them not just into vulnerability remediations — but also as ways to identify and fix gaps in your OS & 3rd party patching programs.

IAM for DevOps: How to Secure Distributed Teams, CI/CD Pipelines, and Privileged Access

Your DevOps team doesn't log into one app from one office. They're in cloud consoles, Git repos, CI/CD pipelines, and production, often at 2 am, often from home. IAM for DevOps has to work for that reality, not the one from 2016. Traditional identity and access management was built for employees signing into a handful of business apps from a managed laptop. But the DevOps team blew past that model years ago.

Data Lineage vs. Data Provenance: What's the Difference?

Security and governance teams often use "data lineage" and "data provenance" as if they have the same definition and offer the same insights. They don't, and the gap between them shows up fast once a program tries to act on it. A provenance record can tell you where a file came from, but it cannot tell you what happened to it after an employee copied it into a new spreadsheet, renamed it, and uploaded it to a personal cloud drive.

Why Now Is the Time to Replace Your VPN

For years, the VPN has been the default answer to remote access. It solved a problem organizations faced when employees primarily worked from offices and only occasionally connected from home. That world no longer exists. Today, employees work from everywhere. Applications run across SaaS platforms, public cloud, private cloud, and on-premises environments. Security teams are expected to provide seamless access while protecting against increasingly sophisticated attacks.

How much does HIPAA compliance cost MSPs? A full breakdown

For MSPs serving health care clients, HIPAA compliance is a line item with consequences. Get it wrong and the downside is a six- or seven-figure Office for Civil Rights (OCR) settlement, a corrective action plan and a client base that loses confidence overnight. Get it right and health care becomes one of the highest-margin verticals in the channel.

The background agent that outgrew me

Accelerating security solutions for small businesses‍ Tagore offers strategic services to small businesses. A partnership that can scale‍ Tagore prioritized finding a managed compliance partner with an established product, dedicated support team, and rapid release rate. Standing out from competitors‍ Tagore's partnership with Vanta enhances its strategic focus and deepens client value, creating differentiation in a competitive market.

Ep. 68 - Why OWASP's AIVSS Scores Agentic AI at Maximum Risk

OWASP just shipped AIVSS — an entirely new vulnerability scoring methodology built for autonomous AI agents, where a compromised orchestrator can score a perfect 10. Host Tova Dvorin and Adrian break down the "amplification principle": why a 2.1 CVSS finding becomes a 7.1 in the wrong agent, how persistent memory and broad tool access expand every blast radius, and what EchoLeak-style attacks already mean for real deployments. Plus where adversarial exposure validation and SafeBreach's agentic AI coverage fit in.

Ep. 67 - The Axis of Disruption: APT41, Volt Typhoon, and the China-Russia Cyber Alliance

For years, Beijing and Moscow kept their cyber tools apart. Not anymore. Hosts Tova Dvorin and Adrian Culley unpack the "no limits" partnership gone operational — the ESA/Galileo satellite attack where a Chinese Volt Typhoon cell opened the door and Russian AcidRain wiper code did the damage. We cover: APT41 running Russian exploit kits, Salt Typhoon pre-positioned in US telecom, China's 72-hour zero-day disclosure law feeding vulnerabilities to Russia, and the CVSS-10 Grimbolt flaw. Why continuous validation and a CTEM program are your best defense against the axis of disruption.

Ep. 66 - Poisoned Pipelines: TeamPCP and the FBI Flash on Weaponized Dev Tools

A criminal crew with APT-grade patience is trojanizing the very tools defenders trust. Host Tova Dvorin sits down with Adrian Culley to break down FBI FLASH-20260702-01 (coordinated with CISA) on TeamPCP — the group compromising Trivy, KICS, LiteLLM, and the Telnyx SDK to sit inside CI/CD pipelines. Inside: the CanisterWorm and SANDCLOCK credential stealers, the self-replicating "Mini Shai-Hulud" worm across npm and PyPI, npm account takeovers via expired recovery domains, and five concrete defenses — starting with searching your GitHub org for "tpcp-docs" right now.

Ep. 65 - "Months, Not Years": The Five Eyes AI Warning and Your Security Program

On June 22, 2026, the heads of all six Five Eyes cyber agencies — GCHQ, CISA, the NSA, ASD, the Canadian Centre, and New Zealand's GCSB — signed a rare joint statement: AI has rewritten the cyber risk timeline, and it's months, not years. Host Tova Dvorin and offensive security expert Adrian Culley unpack why AI is collapsing the window between vulnerability and exploit, why "having controls" isn't the same as proven controls, and why legacy systems are now strategic liabilities for the board, not the IT team. A clear-eyed look at validation, assumed breach, and what CISOs should do Monday morning.