Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Endpoint protection for industrial systems: securing HMIs and SCADA servers

Why generic IT endpoint tools fail on the plant floor, what HMI and SCADA workstations actually need and how to build OT-appropriate endpoint protection. For plant security leads, OT engineers and industrial CISOs. OT endpoint protection combines anti-ransomware, antivirus, EDR, vulnerability assessment and patch management deployed on the PC-class endpoints inside an industrial environment, primarily HMI workstations, SCADA servers, engineering workstations and historians.

Acronis extends Microsoft 365 protection with Entra ID Backup

Attackers have long focused on email and endpoints, but now they are increasingly targeting the identity layer that controls access to those resources. The new approach is subversive and highly effective: By compromising identities, threat actors can gain access to Microsoft 365, SaaS applications, devices and administrative functions without tripping the same alarms that traditional attacks trigger.

Introducing Apex Discovery to secure every domain you actually own

Most tools will only test the domains you already know about. We’ve decided that’s not enough. TLDR: Detectify’s new Apex Discovery automatically identifies root domains likely to belong to your organization (from M&A, subsidiaries, and shadow IT) for complete security coverage. Review and confirm our curated suggestions in a click, and instantly start protecting them with the same continuous discovery and vulnerability assessment as the rest of your attack surface.

When AI agents look like attackers: what behavioral telemetry tells us

An X-Ops analysis of how AI coding agents trigger endpoint detection rules designed for adversaries AI coding agents (Claude Code, Cursor, Codex, and others built on skill packs such as GStack) are showing up in customer environments. They write code, install dependencies, automate browser tasks, and troubleshoot failures by trying alternative approaches.

Static DLP Is Leaving You in the Dark: Why It's Time for Intelligent, Self-Serve Outbound DLP and Misdirected Content Analysis

When we think about email security, our minds almost always jump to the inbound threats: the sophisticated phishing lures, the AI-generated business email compromise (BEC) attacks, and the malicious attachments knocking at the perimeter. But there is a silent, internal crisis happening on the way out of your organization. And chances are, you’re flying completely blind to it.

2026 Phishing by Industry Benchmarking Report: Findings on Human Risk

Every year, KnowBe4 analyzes millions of simulated phishing tests to measure one thing: how likely is your workforce to fall for a phishing attack? The results, published in the 2026 Phishing by Industry Benchmarking Report, paint a clear picture of where human risk concentrates — and what organizations can do about it. Here are the key findings security leaders need to know.

Enable Jira 2FA for Customers and skip for Employees

Credential abuse is the common vector in 13% of data breaches. Cybercriminals can gain access to sensitive organizational data through weak, stolen, or reused passwords belonging to employees or customers. Single sign-on (SSO) and Multi-Factor Authentication (MFA) are industry-standard solutions for addressing these issues, and they can help to mitigate security threats. But external Jira Service Management (JSM) customers often authenticate differently.

Access to Your Systems No Longer Has Borders: Take Control of Who Gets In

It's 4 p.m. and a client calls. It's an employee's last day, and you need to make sure they no longer have access to company environments, applications, systems, sensitive information—or even the corporate laptop. You remove VPN access. Then remote desktop access. Then access to applications and internal systems. Multiple locations, multiple consoles, and it only takes missing one of them to leave a door open. Now multiply that by the number of clients you manage.

Zero Trust for AI Agents Starts After Login

Zero Trust was built to fix an older assumption: if you were inside the network, you were trusted. Then, Cloud, SaaS and remote work broke that, so security moved toward identity, device checks, MFA, least privilege, and continuous verification. But now, with agents, the messy bit starts after access. The agent reads a prompt, pulls context, chooses a tool, calls an API, and may trigger a workflow. The login tells you the agent is “trusted”.