Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

A Practical Guide to Attack Surface Management

Attack surface management (ASM) is the discipline of continuously discovering, inventorying, assessing, and prioritizing every asset, control, and exposure across your environment. It gives you an always-on picture of what you actually have, rather than a point-in-time scan. Done right, it answers the three questions every security leader is really asking: What do I have? Where am I exposed? What do I fix first?

Peer Pressure: Inside the Sality Botnet Disruption Operation

On August 31, 2026, CrowdStrike's Counter Adversary Operations team, in collaboration with international law enforcement and industry partners, executed a coordinated disruption of the Sality peer-to-peer (P2P) botnet, a criminal infrastructure that has operated with seeming impunity for more than two decades. The botnet enabled the operator to distribute malicious payloads to over 15,000 infected machines worldwide.

Common Zero Standing Privilege Challenges and How To Solve Them

One of the most exploitable parts of modern attack surfaces is standing privileges: the persistent access rights that linger on accounts long after they’re needed. With standing privilege, static credentials are easier to steal, and overprovisioned accounts give attackers far more reach than they should have. Zero Standing Privilege (ZSP) solves these issues by granting access only when necessary and revoking it as soon as the task is finished, leaving behind no lingering access.

CrowdStrike Falcon Guardian Defines the Next Generation of AI Security

AI has rapidly evolved into a technology that takes action. AI agents can reason, access enterprise systems, and execute tasks autonomously at machine speed, often with the full permissions of the users they serve. As these agents proliferate across the enterprise, organizations need to understand where they operate, what they do, what they can access, and how to stop threats before they become breaches. This shift demands a new approach to AI security.

How Keeper Privileged Cloud Delivers Zero Standing Privilege

Keeper Privileged Cloud delivers Zero Standing Privilege (ZSP) by extending KeeperPAM’s Just-In-Time (JIT) access framework to cloud identity platforms. A user gets elevated permissions only after a request is approved; those permissions last for a set time window, and Keeper removes them automatically once the window ends. No permanent privilege is left in place.

The dark figure of supply chain detection

During World War II, Abraham Wald was asked where to add armor to bomber planes. The military's instinct was to study the planes that came back and reinforce wherever the bullet holes were clustered. Wald said to do the opposite. The planes in front of him had already survived hits to those spots. That's exactly why he could study them. The planes that took hits to the engine or the cockpit never made it back to be studied at all.

OpenStack Backup And Recovery Frequently Asked Questions

My name is Kevin Jackson. I have been working with OpenStack since the first releases in various capacities — as an operator, author, architect, and currently at Trilio, where I assist organisations with cloud backup and recovery strategies. Over the years, I have watched OpenStack mature from an early-stage project into the core infrastructure underpinning demanding private and public clouds across telecoms, financial services, and the public sector.