Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

The Cybersecurity Visibility Gap: What You Can't See Can Still Hurt You

Most security programmes are built to watch the inside of the network, but the threats that do the most damage often start outside it: leaked credentials, impersonated domains, dark web chatter, and vulnerabilities under active discussion. This post looks at why the visibility gap exists, what the data says about it, and what closing it involves.

Breach fatigue: Why your team has switched off and how to fix it

Cybersecurity continues to face continued challenges in the Australian environment. The Australian Signals Directorate’s (ASD's) Annual Cyber Threat Report 2024–25 revealed that there were more than 84,700 cybercrime incidents and over 42,500 calls to the Australian Cyber Security Hotline, representing a 16% increase in comparison to the previous reporting period. More threats. More notifications. More training events. Yet, surprisingly, employee vigilance is continually decreasing.

Seeing Every MCP Connection: Zenity Joins the Cursor Marketplace

Cursor has become one of the primary AI coding environments for development teams, and its agents increasingly reach into the outside world through MCP servers: databases, ticketing systems, cloud consoles, and internal APIs. Every connection extends what an agent can do. It also extends what could go wrong if that access goes unmonitored or unchecked.

Agentic AI Security Buyer's Checklist: 15 Questions to Ask Before You Sign

Buying agentic AI security software is a fast-moving decision with high stakes. Get it wrong, and your security team ends up chasing agent activity it cannot see, while attackers exploit business logic gaps that no prompt filter was built to catch. This checklist gives security and platform leaders a structured way to evaluate vendors before signing, based on the questions that actually separate a purpose-built platform from a bolted-on feature.

Detection scaled. The loop did not.

Findings got cheap. Verified closure did not. That AppSec remediation gap is the actual problem. AppSec spent a decade winning the wrong race. We got very good at finding things. Scanners in CI. SCA on every manifest. SAST on every pull request. Container and IaC checks on the way to the cluster. Then AI arrived and did what AI does to a solved problem: it made discovery cheaper, louder, and continuous. The same model that writes the function will also enumerate the ways to break it.

Acronis denial-of-wallet protection: Managing runaway AI usage before costs spike

With most cyberattacks, the problem announces itself. A service goes down. A user cannot log in. An alert fires. Denial-of-wallet is different. The application keeps working normally while the cost of running it climbs in the background. That is what makes it a security problem and not only a budgeting one. The goal is not to take a system offline. It is to make the system do expensive work that nobody asked for.

Ransomware's AI Adoption Curve: From Marketing Claim to Operating Model

Somewhere in the first nine months of 2026, AI stopped being a talking point in ransomware and became part of how the work actually gets done. Tracking new ransomware-as-a-service (RaaS) launches, darknet recruitment ads and public incident reporting through this period shows a three-step progression: AI as advertising, AI as an assistant, and AI built directly into ransomware.

The Workforce Has a Blind Spot, and It's Ringing

With inboxes increasingly well guarded, cybercriminals are turning to a more vulnerable front in their attacks against your digital workforce. Voice is the fastest-growing attack vector, and it’s because it’s dangerously effective. According to Verizon’s 2026 Data Breach Investigation Report, phone-centric attacks are 40% more successful than traditional email-based phishing.

Direct Send: How Attackers Weaponize Your Infrastructure Against You

An employee at your company receives an email from hr@yourcompany.com. The domain matches. There is no warning banner. The message asks them to review a payment approval document. They click. That email was never sent by your HR team. An attacker sent it, and your own Microsoft email infrastructure delivered it, with no password and no credentials required.

The Role of Agentic AI in Cybersecurity

Agentic AI has moved from experimental research to live production environments at unprecedented speed, outpacing nearly every technology security leaders have encountered in recent history. Distinguishing themselves from standard chatbots that merely respond and pause, autonomous agents architect multi-step workflows, interface with tools and APIs, maintain contextual memory, and execute operations with minimal human intervention.