Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

What Campaigns Like Grandoreiro Teach Us About Threat Detection

The recent Grandoreiro campaign detected by the WatchGuard Threat Lab team is a clear example of how today’s threats combine different techniques to make detection more difficult and operate more discreetly. In this case, the attack begins with a phishing email designed to persuade the user to click a link. From there, the victim is taken through several redirects and eventually downloads a compressed file from well-known services such as Dropbox or MediaFire.

Identity Everywhere: Bringing Infrastructure Identity to Agentic IT

Cisco and Teleport are announcing a strategic partnership centered on deep technology integration, licensing, and investment. As the largest strategic investor, Cisco is reinforcing its commitment to accelerating the next phase of Teleport's evolution.

10 Shadow AI Detection Tools for Enterprise Data Security

As artificial intelligence becomes deeply woven into daily workflows, employees are adopting unapproved AI apps at an unprecedented pace. According to Teramind’s Shadow AI Behavior Report, a staggering 89% of workplace AI usage occurs outside enterprise-governed channels, leaving 86% of organizations blind as to how corporate data flows in and out of these tools.

Same Numbers, Two Audiences: Insurer and Board

The same quantification run supports two conversations that happen weeks apart. One with a board asking whether the organization is managing cyber risk sensibly. One with an underwriter deciding what to charge for it. ‍ Most guidance treats these as a formatting problem, where the board version gets charts and the submission gets detail.

State AI Laws Change Faster Than Compliance Programs

Colorado passed the first comprehensive state AI law in May 2024, and organizations spent the following year building impact assessment processes against it. Those obligations never took effect. The statute was delayed twice, blocked by a federal court, then repealed and replaced by a narrower framework before its own effective date arrived. ‍ Anyone who built a compliance program to that specific statute prepared for a regime that never existed.

Ask Why Before You Walk Away from a VMware Deal

Here is a deal that almost died for the wrong reason. The customer said, “We need Hyper-V.” The partner logged it as a technical requirement, qualified the opportunity out of any VMware conversation, and moved on. Reasonable enough. That is what a stated requirement is supposed to mean. Except it was not technical. When someone finally asked why Hyper-V, the answer had nothing to do with the hypervisor.

Get Your CTEM Initiative Moving with Seemplicity

CTEM scoping isn’t about putting everything you can scan into scope. It’s about defining what matters most to the business and keeping that definition current as your environment changes. Get scoping right, and every stage that follows—from discovery to prioritization and mobilization—becomes more focused, relevant, and effective. Continuous Threat Exposure Management breaks down into five stages: scoping, discovery, prioritization, validation, and mobilization.

Code is the easy part with Rohan Varma from OpenAI | Zero-Shot Learning

As a product leader who went from working on Cursor to OpenAI’s Codex, Rohan Varma got a personal preview of a shift most developers are just beginning to catch up to. His conversation with 1Password CTO Nancy Wang upends the idea that AI helps developers write code faster, reimagines code reviews, and explores how developer skills expand once agents take over implementation. In this episode: Zero-Shot Learning is a builder-to-builder podcast about how AI systems are designed, deployed, and secured. Subscribe for more.

Google Authenticator vs YubiKey: Which Authentication Method Is More Secure?

Compare Google Authenticator and YubiKey to understand how each authentication method works, their security strengths, phishing resistance, deployment considerations, and which option is best for your organization. Passwords alone are no longer enough. Multi-factor authentication (MFA) is now the baseline but not all MFA methods are equally secure. Two of the most commonly compared options are Google Authenticator, a free smartphone app, and YubiKey, a physical hardware security key.