Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

How to Tie Kubernetes Audit Logs to Individual Engineers

Kubernetes audit logs may show multiple engineers as one user and do not capture what is typed after a kubectl exec session starts. Assign each engineer a unique identity, make sure it stays consistent through proxies and cloud IAM, and use a session recorder if you need to review terminal activity.

How Modern Threat Actors Are Changing the Defense-in-Depth Playbook - Webinar October 8, 2026

Ransomware is still growing, but payouts are shrinking. Enterprises got better at backups, so attackers moved to where defenses are thinner: SaaS, identity, and stolen credentials. Infostealers do the collecting at scale, and AI is widening the gap. Credentials for AI services were the fastest growing category of leaked secrets in 2025, up 81% year over year with 1.27 million exposed (State of Secrets Sprawl 2026). Most defense-in-depth programs were not built with this attack chain in mind.

Certificate monitoring with TLS, chain, and post-quantum readiness

Most customers start CertKit with SSL host monitoring. On day one, you point CertKit at the systems you already run and get every certificate and when it expires. You start with confidence that you have everything under control. Then, you automate, letting CertKit take over the certificates as they need to be renewed. Each renewal is the last time you ever have to worry about that certificate.

How to Reduce Overprivileged Kubernetes Service Accounts

Overprivileged Kubernetes ServiceAccounts persist when broad RBAC, cloud IAM permissions, and long-lived credentials outlive their intended use. Reduce overprivileged access with least privileged RBAC, scoped cloud permissions, and short-lived certificates that eliminate static credentials. I spent two days last quarter tracking down why a developer could delete production secrets. The RBAC looked fine. The ClusterRoleBinding said edit, not cluster-admin.

NIST SSDF: 4 core practices for secure software development

The NIST Secure Software Development Framework (SSDF) is a set of fundamental, outcome-based practices that integrate security throughout the software development lifecycle (SDLC). Documented in NIST SP 800-218, it helps organizations reduce vulnerabilities, prevent recurrences, and establish a common language for secure development. The SSDF outlines dozens of tasks grouped into four high-level categories.

What's taking DNS-PERSIST-01 so long?

In February, Let’s Encrypt announced that DNS-PERSIST-01 was coming, “some time in Q2 2026.” It’s October, and it’s nowhere close to ready. We’ve been waiting for DNS-PERSIST-01 since January, along with every other ACME client and lots of organizations. DNS-PERSIST-01 promised to simplify domain validation and make automation easier, but we had to wait on Let’s Encrypt. Let’s Encrypt is waiting on a redesign, a standards body, and maybe one more vote.

AI is building your software. Who's making the security decisions?

AI coding assistants are changing how software gets built. Traditional AppSec tools focus heavily on scanning the final code artifact, but as AI agents move from simple code dependencies to autonomous decision-makers and execution paths, traditional security controls enter the process too late.

What's New at GitGuardian: AI Leak Triage & Laptop Secrets Scanning

We found 15x more valid secrets on developer laptops than in code repositories. In this September edition of What's New in GitGuardian, Sr. Product Managers Léna Cuissard and Emmanuelle Franquelin walk through two updates: agents that triage public secret leaks for you, and Developer Endpoint Protection coming together as one package.

Introducing The GitGuardian Mixin Kit To Extend Docker Sandboxes for Safer AI Coding

Modern enterprise security is increasingly being tasked with keeping agents from affecting critical data and infrastructure. In this video, Dwayne, principal developer at GitGuardian, introduces how GitGuardian AI hooks extend the power of Docker Sandbox isolation. Their micoVM architecture plus the power of ggshield mean anyone can get an agent working in a secure way with very little effort. Chapters.