Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Ep. 2: The Cell - Accessing the Hidden Discord Ecosystem Behind the North Korea IT Worker Scandal

For the first time ever, host and former lead cybersecurity and digital espionage reporter for The New York Times Nicole Perlroth partners with a team of private investigators as they infiltrate a North Korean worker cell.

What is Application Threat Detection and How Does it Work?

Security threats don’t announce themselves. They can slip in through vulnerabilities in your code, hide in third-party libraries, and exploit gaps that your team hasn’t had time to patch yet. That’s why application threat detection isn’t just a nice-to-have; it’s the foundation of a modern security program.

GitGuardian Developer Endpoint Protection: Secret Scanning For Your Laptops

GitGuardian Developer Endpoint Protection helps security teams find secrets across any of your organization's laptops. In this walkthrough, Dwayne shows how to install ggshield, enable the machine scan plugin, run a local workstation scan, and review findings in the local dashboard.

Agentic IAM: The Complete Guide to Identity Security for Autonomous AI Agents

If you’ve deployed your first AI agent, then you must have given it access to your CRMs, ticketing systems, and your cloud storage. This AI agent is programmed to run 24/7, make decisions, call external APIs, and trigger actions (without a human in the loop). Now, answer these questions: If you cannot answer these questions, then you have an agentic AI identity issue. Traditional Identity and Access Management (IAM) was built for service accounts with static API keys and users with usernames.

Automate or Amplify: How to Scale a SOC Without Adding Headcount

Artificial intelligence is rapidly transforming how organizations approach cybersecurity. However, much of the debate still centers on the same old question: will AI eventually replace security analysts? In reality, the question is no longer whether AI will replace analysts, but how it can amplify their performance and redefine their role within the SOC.

A Forgotten Contributor Account Compromised the Entire Mastra npm Package Scope

An attacker republished the entire @mastra npm scope on June 17, 2026, slipping a single malicious dependency into 143 packages and counting, including @mastra/core, which pulls roughly 4 million downloads a month and has hundreds of dependent projects. The injected dependency, easy-day-js, is a dayjs lookalike whose install hook disables TLS verification, downloads a second-stage payload from a raw IP address, and runs a cross-platform cryptocurrency stealer in the background.

Build a Custom Security Training Course in Seconds | KnowBe4 AIDA Content Creation Agent

What if you could build a complete, personalized security awareness course from a single prompt — in seconds? KnowBe4's AIDA Content Creation Agent does exactly that. Powered by our decade of AI innovation, it generates e-learning modules instantly — and goes far beyond basic content generation: Deepfake Face Injection — Insert real members of your team into training visuals using safe, consensual deepfake synthesis. Your people, your culture, your training.