Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Cloud Transition Challenges: From On-Prem to Multi-Cloud Security #shorts

Organizations are fully onboarded in multi-cloud environments (AWS, Azure, GCP), but transitioning from traditional on-prem security to the cloud poses a significant challenge. Cloud security teams now need to collaborate with traditional network engineering teams, each with different objectives, to bridge the gap.

Your Firewall Rules Are Drifting Right Now. You Just Can't See It

Firewalls are the single most common source of misconfiguration-related breaches, yet they get changed a hundred times a week and audited once a quarter. This is the network security gap AI attackers exploit first. Endpoint gets the budget. Identity gets the roadmap. The firewall gets changed constantly and reviewed rarely. It is also the control most tied to breaches: 42% of security teams pinned a firewall misconfiguration to a breach or near miss last year, ahead of EDR at 40% and identity at 39%.

Unmasking BitRAT's C2 over HTTPS

BitRAT is a potent and versatile Remote Access Trojan (RAT) commonly sold on underground forums. Its popularity stems from a robust feature set and an emphasis on stealth, allowing it to evade detection by hiding command-and-control (C2) communications over seemingly benign protocols. This makes traditional detection methods more challenging. By examining the subtle artifacts it leaves behind, even in encrypted traffic, defenders can expose these elusive threats.

WireGuard vs OpenVPN: What Actually Matters for Everyday VPN Security?

Many people look at the protocol first when choosing a VPN. WireGuard sounds newer and faster. OpenVPN sounds mature and dependable. The question quickly becomes: which one is safer? It is a useful question, but it is not complete. VPN protocols do matter. They help decide how the encrypted tunnel is created, how the connection is verified, and how data moves between your device and the VPN server. But in real use, a VPN is not trustworthy just because it supports a certain protocol.

5 Best SD-WAN Products With Centralized Network Policy Management

Managing network policy across a distributed enterprise has always been complex. Each branch office, remote location, and cloud connection point represents a potential gap between policy and enforcement. In traditional WAN environments, that gap often meant shipping preconfigured devices to each location, maintaining separate management platforms for different network functions, and accepting that configuration drift across dozens or hundreds of sites was largely inevitable.

WatchGuard Appoints Vincent Hwang as Chief Product Officer to Accelerate Platform Strategy and AI-Driven Innovation

Former Fortinet, Cisco, and Bitdefender leader brings proven track record in scaling cybersecurity platforms, strengthening partner-driven growth, and shaping category-defining product narratives.

From days of training to three better rules in a minute

A few years ago, I was part of a team responding to a high-profile security incident. After the incident was resolved, I was given a list of NDR rules to add to my firewalls. The issue was that the rules were not made for Suricata, the IDS I was using in this position at that time, so they generated false positives. With all that extra noise, I made it my goal to eliminate that excess noise.

What the Black Hat NOC taught me about MCP & agentic SOCs (Chapter 2 of 4)

The first time an MCP (Model Context Protocol) server felt real to me, it wasn't because of a clean demo. It was because of the noise. TL;DR: The harness matters more than the protocol, and the evidence matters more than both. MCP earns its keep when it shortens the path from a good security question to trustworthy evidence, and almost everything interesting about making that work happens in the harness wrapped around the model. In this series, I will cover how to build an MCP for an AI SOC.