Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Simplifying Global Connectivity: How 11:11 Circuit Management Transforms IT Operations

Managing global connectivity is a lot like trying to assemble a puzzle, where the pieces come from different manufacturers, each with its own shapes, colors, and instructions. You might eventually fit them together, but not without significant time, effort, and potential gaps. For IT teams tasked with navigating the complexities of global connectivity, these obstacles can slow progress and create inefficiencies that ripple across an organization.

GitGuardian's VS Code Extension Just Made It Even Easier To Fight Secrets Sprawl

We are excited to announce the release of the GitGuardian Visual Studio Code Extension version 0.23.0! Aside from updating the tool to use the latest version of ggshield, it now can show all findings in a convenient list view int he primary sidebar.

How BlueVoyant's ASIM-First Strategy Simplifies Threat Detection in Microsoft Sentinel

Earlier this year, BlueVoyant adopted a new detection strategy built on the Advanced Security Information Model (ASIM). For those unfamiliar, ASIM is Microsoft's normalisation layer that standardises log data across products into consistent schemas. Our approach is simple: The result? Dramatically faster use case development and cleaner, more maintainable detection logic.

MCP vs. Traditional API Security: Why Your Existing Controls Don't Protect MCP-Powered AI Agents

Traditional API security protects deterministic systems with known endpoints and explicit actions, while MCP-powered AI agents operate through inferred intent, dynamic tool chaining, and natural language interactions. This requires MCP-specific security controls such as tool governance, behavioral monitoring, and semantic anomaly detection.

PCI DSS Compliance in Houston: The Complete 2026 Guide for Texas Businesses

Houston is one of America’s most commercially active cities — a Fortune 500 corridor, a booming technology sector, and tens of thousands of small and mid-size businesses processing credit and debit card payments around the clock. Every one of those businesses is legally bound by a set of security standards that most owners know surprisingly little about: the Payment Card Industry Data Security Standard, universally referred to as PCI DSS.

Apple doesn't care who signed your certificate

The pitch for private PKI gets more compelling every year. Public certificate lifetimes are down to 200 days, dropping to 47 by 2029. If you run your own private certificate authority, you make your own rules. Issue certificates for as long as you want, skip the renewal churn. Let’s Encrypt and DigiCert don’t get to tell you what to do. Apple does though.

When Cosine Similarity Works Great, and When It Does Not

In my last post, I explained the math behind cosine similarity. Cosine similarity is a powerful search technique. When you are dealing with thousands or millions of chunks, it provides a fast, scalable way to find content conceptually similar to the user’s question. That is a major breakthrough. Without vector search, modern RAG would be much harder to build. But the mistake is pushing every retrieval problem into vector search. That is where practical retrieval starts breaking down.

Miasma supply chain attack: malicious code found in @redhat-cloud-services npm packages

On June 1, 2026, researchers identified malicious code embedded in at least 32 package releases published under the @redhat-cloud-services npm namespace, a set of frontend components and API clients that power the Red Hat Hybrid Cloud Console. The compromised releases carry a preinstall script that runs an obfuscated payload the moment a package is installed, harvesting developer and cloud credentials and attempting to spread itself to other packages the victim can publish.