Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

How SAML SSO + SCIM Simplify Atlassian User Management Across Jira, Confluence, and More

Managing Atlassian Cloud access sounds simple until you’re managing hundreds of users with different IdPs across applications like Jira, Confluence, and more. You have to manually onboard users, assign groups, and revoke access at the right time. It’s very tedious, and if you miss a beat, you risk an ex-employee still having access to their Jira account, creating security concerns. Atlassian Guard provides a solid baseline for cloud security.

What is managed XDR (MXDR)? A complete guide for service providers

Security teams rarely lack alerts. The harder problem is working out which ones belong to the same attack — and doing it quickly enough to stop the damage. An endpoint tool may flag suspicious activity on a device. An identity platform may record an unusual sign-in. An email security product may spot a malicious message. When those systems operate separately, each one shows only part of the incident.

Coding Agents Just Reopened Your Software Supply Chain Blind Spot

Most organizations spent years hardening their software supply chain. The model is familiar: dependencies flow through a controlled repository, policies determine what is allowed, scanning catches what slips through, and every action is logged for auditability. It works because human developers operate within environments that enforce these rules. AI coding agents break that assumption entirely.

Threat Actors to Watch: Akira and Storm-1175

From a ransomware-as-a-service group that can move from initial access to full encryption in under four hours, to a China-linked affiliate that has quietly pivoted to its own encryptor, these two threat actors show how mature the ransomware ecosystem has become. CYJAX breaks down what each group does, why they matter, and what security teams should know.

Domain Monitor Now Catches the Impersonation Attempts Keyword Matching Was Built to Miss

Domain Monitor's detection engine has been rebuilt to catch impersonation domains that keyword matching was never built to find. This release covers the new evidence-based matching engine, per-keyword Low, Medium and High thresholds, and what's coming next as the improvements roll out in stages. Domain Monitor's detection engine has been rebuilt from the ground up.

New Bitsight Research Shows AI Abuse Is Moving Beyond the Jailbreak Prompt

Jailbreak prompts (i.e. prompts designed to remove or bypass the guardrails and rules that govern AI systems, like LLMs) prompts have been circulating for years. At first, a lot of it was pretty simple: copy a prompt, tell the model to ignore its rules, and see what happens. It was also largely noisy, unverified, and often didn’t work. But the noise was still telling us something. Threat actors were beginning to study AI systems the same way defenders were, and over time, the goal started to change.