Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Exploitability Without Exploitation: When Attention Is the Signal

Nucleus Insights flagged 14 vulnerabilities with real-world exploitation activity that looked risky before CISA added them to KEV. The key takeaway: all 14 were later listed in KEV. Acting on those signals would have been the right call every time, just earlier.

Ten Years, Two Photos, and One Bet That Got Much Bigger

These two photos were taken almost ten years apart. The first is from 2016, with Sam Altman at Y Combinator. The second came from an unexpected encounter in Silicon Valley almost a decade later. I’ll come back to it at the end. With Sam Altman at Y Combinator in 2016. I was 22 when I arrived in Silicon Valley on a one-way ticket, with a little bit of cash that was barely enough for one month of living there, and a thesis I wanted to prove.

From Hotspots to Lookalike Domains: 3 Phishing Tactics to Watch

In our previous “ABC’s of ‘ishing” posts, we explored how attackers use social media, calendar invites, fake CAPTCHA challenges, and other trusted tools to deceive users. This next installment looks at three phishing techniques that continue to put organizations and individuals at risk: evil twin phishing, domain spoofing, and email phishing.

What a Cyber Risk Number Cannot Tell You

Arguments for quantifying cyber risk are abundant and mostly sound. What gets published far less often is a plain account of what a modeled figure does not tell you, which is unfortunate, because stating the limits is more persuasive to a skeptical audience than another argument for the method. ‍ We build these models. What follows is what they cannot do, written plainly, followed by what remains useful once those limits are accepted. ‍

Evidence on Demand, and Why Most Programs Cannot

A governance program looks complete until somebody asks it to prove something on a deadline it did not set. A supervisor sends an information request. An underwriter asks for control coverage before binding. A prospect's security team asks how a specific control operated last quarter, and the deal waits on the answer. ‍ Most programs can describe what they do accurately and cannot evidence it inside the window. The difference is not a documentation problem.

Four Functions, One Obligation, No Owner

The standard answer to fragmented AI compliance is a responsibility matrix mapped across the lifecycle. Procurement accountable at intake, legal responsible for regulatory vetting, engineering accountable at implementation, security accountable for monitoring. Every stage has an owner and every function knows its part. ‍ Read that arrangement carefully and the problem is visible inside the solution.

Keeper Security Named Exemplary in 2026 ISG Buyers Guide for IAM

Keeper Security has been named an Exemplary provider in the 2026 ISG Buyers Guide for Identity and Access Management (IAM) platforms — ISG’s highest classification. ISG Research evaluated 31 software providers across authentication, authorization, identity lifecycle management and access governance. Keeper earned an A- grade in every category ISG measures and an overall performance score of 83.0%.

AI Governance Framework: How to Build One That Works

An AI governance framework proves itself the first time somebody asks for proof. The gap that sinks most programs sits under the policy, in the layer where nobody can say which identities reach sensitive data through an AI tool. Ownership, approval paths, control mapping, and live access visibility are what separate a working framework from a well-formatted document, and right now most organizations are missing at least one of the four. AI reaches most organizations through several doors at once.

The Active Directory Tiered Administration Model Explained

The Active Directory tiered administration model blocks a common path from credential exposure on a compromised workstation to Domain Admin. It separates privileged accounts and systems by scope of control, then enforces logon boundaries so a privileged credential can authenticate only from an approved system. Dedicated accounts and hardened administrative workstations carry most of the weight. A domain admin signs in to a user's laptop to fix a printer problem.