How Organisations Can Prevent Phishing and Stop Modern Attacks

Phishing continues to be the most common way attackers gain initial access. If you want to prevent phishing in your organisation, it starts with understanding how these campaigns suceed and why they continue to bypass traditional controls. Drawing on insights from our recent webinar Red Team Insights: What We’ve Learned from Breaching the Best, this article explores the tactics attackers rely on and the steps security teams can take to strengthen their defences.

CVE-2025-55752: Apache Tomcat Path Traversal Vulnerability

Apache Tomcat continues to play a central role in hosting Java-based web applications across enterprises, cloud services, and government systems. Its reliability and lightweight architecture make it a go-to choice for developers, but its ubiquity also means that a single vulnerability can have widespread security implications. CVE-2025-55752, disclosed in late 2025, highlights how a subtle processing regression can evolve into a high-impact vulnerability under the right conditions.

Off the Blocks | Ep. 4: What Stage Are We In With Stablecoin Adoption?

We asked industry leaders a simple but powerful question: What stage of the game are we in when it comes to stablecoin adoption? In this finale of Off the Blocks, our guests share sharp, honest perspectives on the evolution of stablecoins and the infrastructure surrounding them. From pilot projects to real-world utility Institutional use cases fueling global settlement Regulatory clarity driving momentum What’s still missing for mass adoption.

Racing and Fuzzing HTTP/3: Open-sourcing QuicDraw(H3)

This blog post provides a dive into HTTP/3’s evolution for security engineers, an overview of our research journey, and what led us to develop the open-source tool QuicDraw, which can be used for fuzzing and racing HTTP/3 applications. QuicDraw implements “Quic-Fin-Sync” our implementation of the last-byte-sync with the single packet attack on HTTP/3. We conclude by evaluating QuicDraw’s performance against a real-world target and comparing its results to other tools.

Comparing Best NER Models for PII Identification

Identifying and redacting personally identifiable information (PII) is a critical need for enterprises handling sensitive data. Over 1000 NLP models and tools claim to solve this problem, but an infinite number of options opens a paradox of choice. We compiled this comprehensive comparison that examines notable PII detection solutions – their features, use cases, pros/cons, and reported success rates.

FedRAMP Penetration Testing Companies: Complete Buyer's Guide & Top Providers (2025)

With the arrival of cloud-conscious threat actors that are falling head over heels for LLM jacking and valid account abuse as cloud intrusions rose over 26% in 2024 vs 2023, being a Cloud Service Provider (CSP) you know that FedRAMP authorization is no longer about achieving a said compliance, you need to walk the extra mile to make sure you survive the ruthless competition in this space.

From Blind Spots to Resilience: Why Visibility Is the Foundation of OT Security

In today’s industrial environments, the single biggest barrier to securing operations is not technology, not budget, not even talent–it’s visibility. You cannot protect what you cannot see. In Operational Technology (OT), visibility has two dimensions: Without this combined view, organizations are left guessing where their crown jewels sit, how traffic flows across the environment and where vulnerabilities or attack paths may hide.

2025 Security Predictions Recap - The 443 Podcast - Episode 349

This week on the podcast, we review our 2025 security predictions and grade ourselves on our accuracy. We recap all 6 predictions for 2025 from multi-modal AI being used to create entire attack chains to the CISO role becoming the least desirable role in business, and follow up on this year's news to see if they hit or not.

Why access management needs a challenger mindset

Cybersecurity never stands still. Every login, session, and connection shifts the balance between freedom and control. Effective access management today isn’t about restriction—it’s about enabling trust at the speed of innovation. Modern enterprises achieve this by evolving their controls to be seamless, adaptive, and invisible to the user.

Endpoint Management for Operational Technology - Tanium Tech Talks #148

Tanium Endpoint Management for Operational Technology… "OT" Today see how Tanium now offers visibility for OT and ICS devices in manufacturing and industrial environments. Tanium full stack visibility at speed and scale on the OT shop floor Using native device protocols from a Tanium client satellite Query & report on devices & vulnerabilities using a familiar Tanium experience IT & OT global visibility converged into a single solution.