Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Turning the OWASP Agentic Top 10 Into Expected Loss

The OWASP list for agentic applications, published in December 2025, gives security teams a shared vocabulary for what goes wrong when software acts rather than answers. Ten categories covering planning, tools, identity, supply chain, code execution, memory, inter-agent communication, cascading failures, human trust and rogue behavior. ‍ Translating that into a financial figure is where programs stall, and the usual attempt makes a specific error.

The Three Questions Every AI Telemetry Claim Should Survive

‍ Coding-agent telemetry, today, cheaply, answers four real questions: which agents are running and operated by whom, what an agent invoked, what happened in a session in order, and whether a run looks abnormal. Part 1 of this series covers that case in full. ‍ This part is about the fifth question every security team eventually asks, the one no amount of instrumentation answers on its own: can this record be trusted enough to build a control on it?

Jira + UpGuard: Automating Risk Management Together

If your security team runs on Jira, sprints and backlog included, UpGuard plugs straight into it: vendor findings, breach alerts, and user risk signals can all surface as issues your team is already triaging. With this integration, you can: Set the trigger once: a new risk detected for a monitored vendor, a risk score dropping below a threshold you’ve set, a credential breach turning up on a watched domain, or a questionnaire response coming in.

How to improve your cyber maturity

Most organisations that get hit by a serious cyber attack weren’t careless: Ransomware, supply chain attacks and identity-based breaches aren’t hypothetical risks anymore. They happen to businesses and public sector organisations of every size, across every sector. And the ones that come through them best aren’t necessarily those with the biggest security budgets.

The CRA Deadline You Can't Ignore: What Every Company Needs to Fix Before September 2026

The EU Cyber Resilience Act (CRA) introduces a 24-hour reporting requirement for actively exploited vulnerabilities from September 11, 2026. For companies selling products with digital elements into the EU, meeting that deadline will require more than compliance documentation — it demands fast vulnerability identification, clear ownership, reliable SBOM visibility, and a remediation process that can move quickly.

Warning: Malicious AI Tools Are Spreading in the Criminal Underground

Criminals are now selling malicious AI tools for use in cyberattacks, according to researchers at Trellix. These tools dramatically lower the barrier for unskilled crooks to launch sophisticated attacks. “In the first half of 2026, the Trellix research team identified multiple distinct AI-related offerings across major underground forums,” the researchers write.

Voice Phishing Attacks Target Hedge Fund Employees

Google’s Threat Intelligence Group (GTIG) is tracking a voice phishing (vishing) campaign that’s targeting hedge funds and financial firms. The researchers attribute the attacks to “UNC6671,” an extortion group formerly known as “BlackFile.” The attackers pose as IT staff informing employees of urgent, mandatory migrations.

Autonomous Pentesting for SaaS Companies in 2026: The Complete Guide

You ship to production every day while your last pentest happened 11 months ago. Just say that sentence out loud, and we ought to rest our entire case of autonomous pentesting for SaaS companies right there. Everything below is just the supporting evidence. The mismatch isn’t subtle. Your engineers deploy continuously, your infrastructure reshapes itself weekly, and your security validation still runs on a calendar designed for software that shipped twice a year.
Featured Post

Why AI is becoming harder to budget for

For most business technology, the cost is relatively easy to understand. You buy a licence, agree a contract or pay for a certain level of usage, and you have a reasonable idea of what you will spend over the year. AI is making that much harder. As businesses move beyond individual AI subscriptions and start using AI across more of their operations, costs can vary considerably depending on which models are being used, how often they're being used and what they're being asked to do.

Top 7 Technology Strategies Growing Businesses Need to Stay Competitive

Growing businesses face mounting pressure to modernize their operations while competitors race ahead with emerging technologies. The gap between those who adapt and those who fall behind widens each quarter, making strategic technology adoption no longer optional but essential for survival. Seven core strategies have emerged as critical differentiators in today's market, each addressing specific operational challenges that determine whether a company scales successfully or stagnates. Understanding these approaches reveals why some organizations thrive while others struggle to keep pace.