Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

How Regulated Data Leaks Through AI, One Paste at a Time

A support coordinator has a difficult letter to write. The customer record is open in one tab, a consumer AI assistant in another, and the deadline is this afternoon. She selects the record, copies it, pastes it into the prompt box, and asks for a polite draft. Thirty seconds later she has a good letter and a regulatory problem, and nobody in the organization knows about either. ‍ The sequence below traces that single action through to its consequences.

What Is PCI DSS Compliance? the Essential Guide

You're reviewing payment flows, the bank has asked for proof, and the audit deadline suddenly feels real. The problem isn't usually that the team has done nothing, it's that nobody has turned day-to-day security work into evidence a card brand, acquirer, or assessor can use. PCI DSS compliance is where that gap gets exposed, and it's why security teams that already run SIEM, XDR, or EDR still get pulled into a separate compliance scramble.

AI Is Changing Cyberattacks on Hotels: Here's How to Stay Protected

Peak season brings challenges to the hospitality industry every year. Thousands of guests, temporary staff, vendors, and business partners interact daily with reservation systems, management platforms, mobile apps, and loyalty programs. That operational complexity makes hotels a particularly attractive target for cybercriminals. Artificial intelligence hasn't created a new problem for hotels, it is simply accelerating an existing one: identity-based attacks.

Cyber Threat Intelligence for the Insurance Sector: A Sector Under Two Kinds of Pressure

The insurance sector faces mounting pressure from both commercial growth and a persistent, evolving cyber threat landscape. This blog examines why insurers remain key targets, where their security gaps lie, and how cyber threat intelligence helps close the gap between ambition and resilience.

CrowdStrike Threat Hunts for Shell Command Obfuscation on VMware ESX

VMware ESX systems are a recurring target in ransomware campaigns. Threat groups including SCATTERED SPIDER, BlackBasta, Royal (aka BlackSuit), Akira, and the ESX-focused ransomware as a service (RaaS) platform shinysp1d3r have demonstrated that once an adversary reaches the hypervisor layer, they can rapidly encrypt virtual machines, disable logging, and cripple an entire data center.

What Is CAC Authentication? A Complete Guide to Common Access Card Authentication

CISA calls phishing-resistant MFA the standard every organization should be working toward. For DoD components, federal agencies, defense contractors, and other organizations operating at NIST's highest authenticator assurance level (AAL3), that guidance narrows to two paths: FIDO2/WebAuthn, or PKI-based smart cards like CAC and PIV.

Your AI deployment might be out of policy

Most AI deployment policies stop at approved chat interfaces. Meanwhile, employees install browser copilots, AI extensions, and third-party plugins that never touch Microsoft's management stack. IT can't configure what it can't see, and Group Policy and Intune only govern Microsoft's world. This post covers what actually happens once AI tools show up outside policy, five things most teams miss, and how PolicyPak enforces controls directly on the apps and browser extensions themselves.