Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Penetration Testing Options Worth Knowing

Penetration testing has turned into one of those services every business claims to offer, but the actual delivery varies wildly. Some firms hand you an automated scan with a logo slapped on the report. Others put a named, accredited tester on your network who explains exactly what they found and why it matters. For businesses, charities and schools weighing up who to call, the accreditation behind the tester matters as much as the report format. Here are eight providers worth knowing, starting with a CREST-accredited option built around direct access to the people doing the work.

Arctic Wolf President & CEO Nick Schneider on AWS Security LIVE! at Black Hat USA 2026

The volume, velocity, and sophistication of cyber threats continue to grow. Security teams need a new approach. At AWS Security LIVE! during Black Hat USA 2026, Arctic Wolf President & CEO Nick Schneider joined Amazon Web Services' Jess Kubat, Ryan Orsi and Brian Mendenhall for a discussion on security operations at Machine Speed and how organizations can combine AI-powered capabilities with security expertise to stay ahead of modern threats.

How To Build An AI Risk Management Framework

Every AI approval a security team makes feels reasonable in isolation. A security architect signs off on a generative AI writing tool for marketing. An engineering lead spins up an agent to triage support tickets. A finance team connects a copilot to its planning software. Individually, none of these decisions looks risky.

Why Employee Behavior Is The Next Big Security Opportunity for MSPs | WatchGuard Webinar

Employees are increasingly adopting AI tools, working across unsecured networks, and bypassing established security practices, often without their organization's knowledge. The result is a growing class of cybersecurity risks that traditional security controls alone cannot address.

The Complete Re-evaluation of AI Security

The OpenAI model that escaped its testing environment and compromised Hugging Face exposed a much bigger cybersecurity problem: are our existing defences actually designed for autonomous AI attacks? In this Razorwire Raw, James Rees looks beyond the original incident at what happens when AI can identify vulnerabilities, exploit them and move through systems at a speed human defenders simply can't match. From AI security and sandboxing to defensive AI and the possible return of honeypots, it may be time to reconsider what defence in depth looks like in the age of AI.

What is RAR / FedRAMP Ready and is It Worth It?

FedRAMP has long been one of the more complex certifications you can achieve, but the rewards are well worth the effort. Validating your company's information security is a huge benefit, and on top of that, working with the government on sensitive contracts is a lucrative business venture. We do our best to explain various aspects of FedRAMP in plain English, to make it easier to figure out what your goals should be and where you should place your efforts.

Attribute-Based Access Control: How ABAC Works, Examples and Use Cases

Access control has become significantly more complex as enterprises adopt cloud platforms, AI applications, and distributed workforces. A user’s identity alone is no longer enough to determine whether they should access sensitive data. Factors such as device posture, data sensitivity, location, and business context all influence the right decision. This shift is driving widespread adoption of attribute-based access control, a model that evaluates multiple attributes before granting access.

They Paid Medusa's Ransom. A Second Medusa Actor Called and Demanded Half Again.

The FBI documented a Medusa ransomware victim who paid the ransom—and was then contacted by a second, separate Medusa actor, claiming the original negotiator had stolen the payment and demanding half the ransom again for the "true" decryptor. That's triple extortion, and it's the strongest argument in the whole CISA/FBI/MS-ISAC advisory (AA25-071A) against paying at all. There is no guarantee the extortion stops when the money moves.

Ep. 75 - The Franchise Model: How Medusa Turned Ransomware Into a Business

Medusa ransomware has went from 300 victims to more than 500, and CISA, FBI, and MS-ISAC just refreshed advisory AA25-071A with new IOCs and TTPs. Tova Dvorin and Adrian Culley unpack the ransomware-as-a-service franchise behind it: the ScreenConnect and Fortinet EMS CVEs still opening doors, three tiers of PowerShell obfuscation, gaze.exe killing shadow copies before AES-256 encryption, and the triple-extortion case where one victim was made to pay twice.