Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Ransomware Has Changed and Your Defenses Need to Change With It

For years, ransomware was treated mostly as a malware problem. A user clicked something bad, files were encrypted, a ransom note appeared and everyone had a very bad week. That version still exists, of course, because cybercriminals love recycling old hits. But ransomware has changed significantly over the last year.

Shadow IT Security and why visibility beats another approval process

A staging site is meant to last a week, but six months later, it still resolves on a company subdomain, runs an old framework, and has no clear owner. The asset never made it into the central inventory, which means that it also missed the normal cycle of testing, patching, and retirement. That is how many Shadow IT Security problems develop. The original shortcut may have been reasonable, but the risk grows when temporary infrastructure becomes part of the permanent attack surface without anyone noticing.

A revisit of remote Spectre attacks on Cloudflare Workers

In 2021, we assessed remote Spectre attacks against Cloudflare Workers. Based on the results, we shipped a production defense called Dynamic Process Isolation (DyPrIs), which identifies maliciously looking scripts and isolates them into separate processes. Since then, newer techniques in the area of stabilizing Spectre attacks have been discovered. To understand if these techniques posed a threat to our Workers production environment, we decided to internally reassess the remote Spectre attack.

What is Runtime Authorization? A Use Case-Based Guide

Static roles work until the environment changes. Authentication can confirm who or what is making a request, but it cannot determine whether that identity should perform a specific action under current conditions. As infrastructure, services, and AI agents evolve, permissions granted months ago rarely reflect what an identity actually needs to accomplish. Among companies planning to deploy agentic AI within two years, only 21% report having a mature model for agent governance.

Apono partnership brings just-in-time access to Elasticsearch and Elastic Cloud

Pull an access review on almost any Elasticsearch cluster and you’ll find the same thing: roles created for a migration two years ago, analyst accounts with broad read access to indices they queried exactly once, and service accounts nobody can quite explain. None of it was granted carelessly, and all of it is still there. That leftover access is the problem.

ChatGPT Security Risks for Enterprises: Real Incidents, Controls and Best Practices

Security teams often evaluate ChatGPT by examining its outputs. The greater risk, however, lies in the information employees submit before the model generates a single response. As generative AI becomes a big part of daily business operations, prompts increasingly contain confidential customer data, proprietary source code, legal documents, and strategic plans.

Benchmaxxing: When the Benchmark Becomes the Target

Public benchmarks in AI provide important signals and allow for regression testing, directional validation of model updates, and public discussion of capabilities and limitations. But the more attention a benchmark receives, the stronger the incentive to optimize for it. Once a score becomes the goal, teams start benchmaxxing: optimizing for the benchmark rather than the capability it is meant to measure. This is a familiar problem in the AI space.

Why Employee Behavior Is the Next Big Security Opportunity for MSPs

Employees are increasingly using AI tools, working across unsecured networks, and bypassing established security practices creating new risks that traditional security controls alone can’t address. Join WatchGuard’s Marc Laliberte, Director of Security Operations, on August 20 for an exclusive webinar exploring the findings from the 2026 Cybersecurity Hygiene Report.