You Won't Believe These Results from Replit

In this video, we put Replit’s AI coding tool to the test by asking it to create a secure note-taking app. While the tool shows off some seriously impressive abilities, it’s not without its flaws... Join me as I explore what Replit can (and can’t) do, and whether AI coding tools such as this one are ready to build reliable, secure apps.

Tenant Matters: Enabling Safe SaaS Adoption with CASB Tenant Awareness

Imagine your marketing team needs to share a product roadmap with a partner, so they drop it into a shared OneDrive folder. Everything looks fine — same interface, same app — but no one realizes the file was uploaded to the partner’s personal OneDrive account instead of their corporate tenant. Days later, the file is still accessible from an unmanaged device, with no audit trail, no data loss protection, and no way to revoke access.

Don't SOC-block your best engineer

Startups move fast—but nothing slows you down like pulling your best engineer off product to chase a SOC 2. In this spot, a founder’s big deal hangs on compliance, an engineer is deep in flow...and one voice of reason steps in with the answer: Vanta. Vanta automates compliance so you can get audit-ready in days, unblock deals, and keep building. Your engineer will thank you.

Trusted Access: Smuggled Secrets, SD Cards and Peanut Butter Sandwiches

Some insider threats are quiet and compulsive. Others come wrapped in a peanut butter sandwich. In 2021, U.S. Navy engineer Jonathan Toebbe was arrested for attempting to sell classified submarine technology to a foreign government. He wasn’t forced into it. He wasn’t coerced. He initiated the contact himself, asking for hundreds of thousands of dollars in cryptocurrency in exchange for nuclear secrets. This wasn’t a data dump or a careless mistake. It was premeditated.

How AI is (or should be) changing SOC workflows with Matt Bromiley

We dove into AI in the SOC with Matt Bromiley from Prophet Security! Matt broke down how AI is transforming (and should be transforming) SOC workflows. Whether you're already using AI tools or wondering where to start, this is the conversation you don't want to miss.

GitProtect 2.0.5: More Access Control and Predictability

GitProtect 2.0.5 version focuses on a more predictable recovery and access control. The console now enforces 2FA when users enter through SSO or SAML. So, access to backup and restore actions requires a second factor at the point of use. Additionally, bulk restores no longer depend on a single token’s rate limit, and Jira jobs are less brittle as well, with automatic detection of expired Personal Access Tokens. The new version is not a redesign.

LCQL Made Simple with AI #cybersecurity #ai

LimaCharlie Query Language (LCQL) enables security teams to search across their entire multi-platform fleet, from Windows Event Logs to Linux package installations to macOS volume mounts. Our MCP server allows users to generate LCQL queries from plain-text language commands. Eric Capuano, founder of Digital Defense Institute, demoed this during our webinar: "I want an LCQL query that'll go and find processes in the last twenty four hours that exhibit signs of x. I can just give it that instruction... that MCP tool will work it out and give Claude the ideal LCQL query to run.".

Intel Chat: JavaScript phishing, undersea cables cut, Contagious Interview campaign & Salty2FA [247]

In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community. Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform. This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows.