Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Protecting Vulnerable and Poorly Configured Network Devices

On July 13, 2026, NSA, CISA, the FBI, and co-sealing partners from twelve other countries published AA26-194A, a joint Cybersecurity Advisory (CSA) warning that Center 16 of Russia's Federal Security Service (FSB) continues to exploit vulnerable and poorly configured network devices across the defense industrial base, communications, energy, financial services, government facilities, and healthcare sectors. The advisory does not reference new exploits.

What the Black Hat NOC taught me about MCP & agentic SOCs (Chapter 3 of 4)

The first time an MCP (Model Context Protocol) server felt real to me, it wasn't because of a clean demo. It was because of the noise. TL;DR: The harness matters more than the protocol, and the evidence matters more than both. MCP earns its keep when it shortens the path from a good security question to trustworthy evidence, and almost everything interesting about making that work happens in the harness wrapped around the model. In this series, I will cover how to build an MCP for an AI SOC.

Who's Winning the AI Security Race: Attackers or Defenders?

Defenders have gained early access to powerful AI tools, creating an opportunity to improve security outcomes and strengthen cyber resilience. But as these capabilities become more widely available, that advantage may not last. Rik Ferguson, VP of Security Intelligence at Forescout, shares his perspective on what security teams should be doing now to prepare.

Where Security Breaks First in the AI Era

Most security programs were built for a slower clock. But as AI-assisted and autonomous attackers accelerate the pace of attacks, manual approval gates can become the point where defenders fall behind. This short video explores why security teams need to reexamine the processes, decision points, and response workflows that may slow them down when speed matters most.

The First Hour of a Zero-Day: Why Preparation Must Start Before Disclosure

The window between vulnerability disclosure and exploitation is shrinking. As exploit development accelerates, organizations can no longer afford to wait for a vulnerability to be disclosed or a patch to become available before taking action. Daniel dos Santos, VP of Research, explains why effective zero-day response depends on preparation that happens before an incident occurs.

Why Residential IP Addresses Are Becoming Popular for Remote Desktop Services

Why does a perfectly working remote desktop still trigger security checks or display the wrong regional content? In many cases, the issue isn't the desktop itself; it's the IP address behind the connection. As businesses, developers, marketers and remote teams increasingly rely on location-sensitive online services, residential IP addresses are becoming popular for remote desktop services because they offer a connection profile that better matches real-world internet usage.
Featured Post

Organisations Don't Need a Cloud-Native Network to Adopt SASE

In a perfect world, every business would design its network from day one with the need for scalability, connectivity from anywhere and zero-trust security in mind. In the real world, of course, few organisations have this luxury. Most have entrenched technology investments in place, and overhauling them to conform with modern network access and security paradigms isn't always feasible.

A Guide to Firewall Management: How to Set Up Proper Firewall Rules

Firewalls remain one of the most foundational controls in any security program. Nearly every organization has at least one, and in many cases, hundreds. Despite widespread deployment, firewalls are frequently a source of unintended exposure rather than protection. The reason is almost always in how firewall rules are maintained over time, not the technology itself.