Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

The PAM problem no vault can solve

You can stand up a vault in two weeks. The team at One Identity says that’s about how long it takes to get the basics running, from discovery scans to approval workflows. Two to four weeks of work, and a respectable PAM foundation is in place. That’s not the hard part. The hard part starts the next morning, when actual users start working around the system.

CISO Executive Briefing: Supply Chain Front-End Compromises and Sustained Third-Party Risk Elevation

This CISO Executive Briefing analyzes material developments over two horizons: the past week (July 1–7, 2026) and the past month (June 8–July 7, 2026). Analysis draws exclusively from verified public disclosures, regulatory filings, threat intelligence platforms, and incident reporting. Focus areas include AppSec posture, software supply chain integrity, identity and contractor risk, cloud/IaC exposure, and the accelerating integration of AI into attacker TTPs.

Continuous Assurance Across Every Network Security Control

Every security leader can describe their network security architecture in confident detail: how traffic should flow, where segmentation boundaries sit, which access should never be permitted. What almost none can tell me with certainty is whether their live controls are actually enforcing that design right now, at this very hour. That gap between what we intend and what is actually running in production is where modern breaches live, and it widens with every change we make.

How to Build a Red Team Exercise for AI Workflows

AI agents now retrieve data, generate recommendations, and trigger actions across enterprise systems with little human review in between. That speed is the point, and it is also the problem. A single manipulated prompt or a poisoned data source can push an AI system toward a decision no one signed off on, and most security teams have never tested for it. Building a red team exercise for AI workflows is how you find that gap before an attacker does.

The ECB just gave banks four months to fix AI vulnerability gaps. Most of the work starts in the software supply chain.

On July 7, 2026, the European Central Bank sent a letter to the CEO of every bank it directly supervises with an unambiguous instruction: build a formal action plan against AI-enabled cyberattacks, and submit it to your supervisory team by October 31.

Falcon Secure Access Sets the Standard for Zero Trust Browser Security

The browser has become the enterprise workspace. Employees, contractors, partners, and third parties use browsers to access SaaS applications, internal web apps, admin consoles, collaboration tools, and AI services from anywhere, often across a mix of managed, unmanaged, and personally owned devices. As they do, adversaries are increasingly targeting the browser session itself.

What Tools Help Build and Maintain an AI Asset Inventory?

Managing an artificial intelligence (AI) footprint has emerged as one of the most complex challenges for modern enterprise security and risk teams. As shadow AI, autonomous agents, and embedded third-party models infiltrate corporate environments, traditional methods of software tracking have broken down. Organizations are quickly realizing that maintaining an accurate inventory is not just an IT best practice.

Let's Talk Security: The Control Gap

In this conversation, Forescout CEO Barry Mainz will be joined by Karsten Abata, tech evangelist at Forescout, former cybersecurity practitioner, and co-author of The Control Gap, to discuss how to close the Control Gap: the widening space between seeing cyber risk and having the ability to control it before it becomes operational impact.

Ep. 67 - The Axis of Disruption: APT41, Volt Typhoon, and the China-Russia Cyber Alliance

For years, Beijing and Moscow kept their cyber tools apart. Not anymore. Hosts Tova Dvorin and Adrian Culley unpack the "no limits" partnership gone operational—the ESA/Galileo satellite attack where a Chinese Volt Typhoon cell opened the door and Russian AcidRain wiper code did the damage. We cover: APT41 running Russian exploit kits, Salt Typhoon pre-positioned in US telecom, China's 72-hour zero-day disclosure law feeding vulnerabilities to Russia, and the CVSS-10 Grimbolt flaw. Why continuous validation and a CTEM program are your best defense against the axis of disruption.

TITAN AI Demo Series: Build Custom Assessment Templates in Minutes with TITAN Agent

Building a strong vendor assessment template used to take hours. With our TITAN Agent, it takes minutes. In this installment of SecurityScorecard's TITAN demo series, see how our TITAN Agent builds customized, comprehensive assessment templates — so your team gets to evaluation faster and with more consistency across every vendor engagement.