Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Cyber Loss When the Company Is Someone Else's Fourth Party

Third-party risk content is written from the customer's side. Assess your provider, tier your vendors, understand your concentration. ‍ A technology provider is on the other end of every one of those assessments, and its own incident propagates outward through contract rather than inward through remediation. The instinct is that the contracts therefore determine the loss. They determine the smaller half of it. ‍

The AI Act Duty That Applies Regardless of Risk Tier

Almost every obligation in the AI Act is keyed to a risk classification. Work out which tier a system falls into and the duties follow. ‍ Article 4 is not. It applies to providers and deployers of any AI system whatever it does, its subject is people rather than systems, and national authorities began supervising and enforcing it from 2 August 2026 while the high-risk regime moved to December 2027. It is the live one, and it sits outside the structure most governance programs are built on. ‍

AI Review of Privileged Material and the Waiver Question

Sending privileged material through an external AI service is a disclosure to a third party, and voluntary disclosure to a third party waives privilege. The reasoning is straightforward and a federal court has now applied it. ‍ A second federal court reached the opposite conclusion on the same question within days, on a distinction the first did not draw. The position is genuinely unsettled, and the parts that are settled point at configuration choices rather than at a prohibition. ‍

The Cybersecurity Directive That Reached Ten Times More Entities

The headline change in Europe's network security directive is scope. Directive (EU) 2022/2555 reaches an estimated hundred and sixty thousand entities across eighteen sectors, roughly ten times what its predecessor covered. ‍ The more consequential change is who decides. Under the previous regime a member state identified operators of essential services individually, through an assessment of criticality and dependency.

1Password for NVIDIA OpenShell: Give Agents Access Without Giving Them the Keys

Connect a 1Password Environment to the OpenShell runtime and let your agents work with the systems it needs without exposing real credentials to the model. Developers define their environment in 1Password and use the UI to provision an OpenShell credential provider. Secrets are mapped to OpenShell profiles, restricted to specific targets, and given an expiration date.

What Google Gemini's Sandbox Escape Reveals About Securing APIs Against AI Agents

Recently, Gemini was running a capture-the-flag exercise in a sandbox operated by the AI testing firm Irregular. Its task was to steal data from a fictional company. On three occasions, the fictional target shared a name with a real business. Gemini slipped past the test’s containment, reached the open internet, and broke into the real company’s systems. In one case it guessed the password. In the other two, it pulled working credentials from a public database of leaked passwords.

10 Cyber Security Tips to Follow in 2026

As businesses use more cloud services and connected devices, cyber threats have also become more sophisticated and more dangerous. The use of AI-based tools in organizations has also given attackers new ways to carry out phishing, social engineering, and other techniques used to gain access to business systems and sensitive data. At the same time, phishing, ransomware, account compromise, and data theft remain common security threats.

Detect, Remediate, and Prevent Credential Layer Secrets Sprawl | GitGuardian Overview

Your security stack does its job. But credentials move between your tools: into pipelines, container images, Slack threads, Jira tickets, and local machines. Together they form a credential layer that no single tool was built to see. GitGuardian is the Credential Layer Security platform that helps teams detect, remediate, and prevent secrets sprawl. In this overview, you'll see how GitGuardian: Trusted by 600K+ developers and the most-installed security app on the GitHub Marketplace.

The Great Infrastructure Reset eBook

When infrastructure pressures converge, partners need the right insight to help customers move forward. As rising costs, capacity constraints, changing infrastructure economics, and cyber resilience demands converge, customers need help understanding how each decision could affect their broader business strategy. Our Great Infrastructure Reset eBook explores the four forces reshaping infrastructure and the considerations that help guide smarter business decisions.

Attack Surface Management Vendors Compared

Most attack surface management (ASM) evaluations start with a name already on the table: a vendor from a G2 grid, an analyst shortlist, an inbound email, or a renewal conversation. Before you commit to a proof of concept (POC), you need to know how it compares. This page provides a capability matrix across 10 ASM vendors, followed by an honest section on each. UpGuard makes one of the platforms on this list, so every section, ours included, covers where the product isn't the right fit.