Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Sophos MDR Onboarding: Case workflow

Detections that generate a new MDR Case trigger the Sophos MDR Operations Team to investigate and respond to identified threats in your environment. This workflow is examined, along with the importance of adding your MDR authorized contacts, and choosing the appropriate Threat Response Mode. The detection triage process is covered in a linked video. Ask questions and get expert answers in the Sophos Community.

PhantomRaven: An LLM-Generated Information Stealer Developed for Bug Bounty Hunting

CrowdStrike Counter Adversary Operations identified a financially motivated threat actor who works as a bug bounty hunter and who developed and distributed the JavaScript (JS)-based information stealer PhantomRaven via npm, a platform on which developers can access open-source packages to build applications and software.

How to Evaluate and Choose the Best Risk Management Software in 2026

Evaluating risk management software in 2026? Here is the moment it has to survive. A board member or an auditor asks what your risk posture is today, not last quarter. You either have it ready to show, or you are rebuilding a register that went stale weeks ago. This video follows one risk through its entire life inside a platform, and uses that path to lay out five criteria for judging any tool, plus the question to put to each vendor.

Protect Sensitive Data in LibreChat with Protecto | PII Masking Demo

Most DLP tools can mask a PII value on the way into a model. Almost none of them can make that value usable again when the AI needs to call a tool with it, so the masking breaks the workflow instead of protecting it. This is Protecto Privacy Gateway for AI Chat, live in a self-hosted LibreChat deployment. Watch what happens when a masked account number needs to resolve at a tool boundary — and comes back correct.

ISO 42001 Readiness Checklist: 15 Questions to Ask Before Certification

Getting an AI policy approved is not the same as being ready for ISO/IEC 42001 certification. Your organization may already have risk registers, information security controls, model documentation, supplier assessments and responsible AI principles. The more important question is whether these elements operate together as an Artificial Intelligence Management System (AIMS) — and whether you can demonstrate that with evidence. Before asking: “How quickly can we get ISO 42001 certified?”

AI Agents Are Forcing Us to Rethink Identity

Since joining BlueVoyant in May, I’ve spent my first 100 days listening. I've had conversations with nearly 50 customers and partners across industries and geographies, as well as the broader security industry, engaging with leaders at Black Hat last month. What I heard reinforced something I believe strongly: the security challenges organizations face today are changing faster than the traditional enterprise security model was designed to handle.

Never Join AI Telemetry on Byte Counts

A browser sensor reports that somebody pasted 18,000 characters into an AI tool. A network sensor reports a 24 kilobyte upload to the same destination. Joining those two records on size looks reasonable and is the wrong instinct. ‍ The two numbers describe different objects with several transformations between them, and the transformations do not all run in the same direction. The error cannot even be signed, which rules out a tolerance as well as an equality. ‍

Post-Quantum Cryptography: You Cannot Migrate What You Cannot See

On June 22, 2026, President Trump signed Executive Order 14412, accelerating the federal government’s transition to post-quantum cryptography. The order brings key migration deadlines forward from 2035 to 2030-2031 for high-value and high-impact systems. The Department of War followed with its own Post-Quantum Cryptography (PQC) Strategy, which sets additional deadlines and warns that a cryptographically relevant quantum computer is an existential threat to military missions.

AI Autonomy: How to Find the Autonomy Your Agents Already Have

AI agents are only as autonomous as the credentials behind them. This article talks about the Cloud Security Alliance's autonomy framework, why an agent's intended boundaries rarely match its actual access, and how GitGuardian helps close that gap through detection, remediation, and prevention.