SecurityScorecard Weekly Brief: The Driftnet Edition on the Health of the Internet - Brandon Torio

In this week's Weekly Brief: The Driftnet Edition, Brandon Torio explains why internet scanning is a lot like modern healthcare. Just as blood tests help doctors identify hidden health risks before they become serious problems, internet scanning helps organizations uncover unseen cyber risks across their attack surface and third-party ecosystem. "The internet has evolved past any one person's understanding.".

Threat Actors to Watch: Three Groups Targeting Organisations Right Now

From a fast-growing ransomware affiliate network to a politically motivated DDoS collective and a prolific data extortion group, these three threat actors represent distinct but pressing risks across sectors and regions. CYJAX breaks down what each group does, why they matter, and what security teams should know.

Are Multi-Agent Systems the Next Frontier for Identity Security?

Security teams have spent years securing human logins, service accounts, and machine identities. Agentic AI introduces a more autonomous class of software actor: systems that can plan, call tools, delegate tasks, and act across environments. This is a concern because most access models were built around static roles and pre-approved permissions. Multi-agent systems put a new spin on those assumptions.

AI-assisted SOC training with Carlo Anez

Join us for this week's Defender Fridays as Carlo Anez, Founder & Lead Instructor at IgniteCyber Academy and DEFCON Training Instructor, breaks down how to build practical blue team skills using open-source labs, MITRE ATTACK, and real-world defender workflows, and where AI fits into the picture without replacing the analyst.

It's Not If Attackers Get In. It's What Happens Next | Insurity CISO Jay Wilson

"Usually it's not a question of if the bad guys get in. It's a question of what happens when they do." Jay Wilson, CISO and CIO at Insurity, and Garrett Hamilton, CEO of Reach, joined Shubhangi Dua on The Security Strategist from EM360Tech to talk about why the controls you already own are where exposure quietly builds up. That's Jay's line, and one every security leader has lived. Defense in depth only holds if every inner layer is configured the way you think it is. The outer door gets the attention. The inner doors are where incidents actually get stopped, or don't.

Scaling Security Insights: how we achieved a 10x increase in global scanning capacity

Security Insights provides actionable security recommendations for every Cloudflare account. To find these insights, we perform regular scans for all accounts, zones, and DNS records, looking for potential security risks and misconfigurations. However, two key issues emerged. First, our scans were too infrequent. Scans were only being performed every week or two, and therefore newly introduced security risks could remain undetected for up to two weeks.

Why know your transaction (KYT) is the AML capability financial institutions cannot afford to miss

The June arrests of Chilean bank workers accused of ties to an international criminal organization has again underscored the need for anti-money laundering (AML) detection to embrace real-time transaction intelligence. Authorities allege that a rogue Santander Chile employee was a key player in an $85-million USD money-laundering operation that channelled funds through accounts at almost every major bank in the country.

Do You Know How Many MCP Servers Are Running in Your Environment Right Now?

Most organizations have no idea how many MCP servers are running in their environment—and attackers are counting on that. In this clip, Adrian Culley breaks down the exact steps security teams need to take now: run the network scan, apply stringent code review to every MCP server project you find, and mandate authentication. Authorization may be optional in the MCP spec—but it doesn't have to be optional in your deployment.

ThreatSpike Product Updates: May 2026

A lot moved in May. ThreatSpike product updates this month spanned almost every corner of the platform, and a good few the community has been asking for. From port scanning in automated recon, to PDF imports into the Knowledge Base – the list covers a lot of ground. Below is everything that shipped, what it does, and what’s been fixed.