Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Connecting the Office and Field: A Better Approach to Construction Data Management

Construction projects depend on timely decisions. When a superintendent needs the latest drawing set, a project engineer must review submittals, or a project manager wants to reference lessons learned from a past project, access to accurate information directly impacts project outcomes. Yet many construction firms still struggle with information scattered across jobsite photos, RFIs, specifications, BIM models, emails, and project management systems.

How to Prevent AI Agents from Exfiltrating Sensitive Data

An AI agent on a developer's laptop has read access to a code repository, a set of internal documents, and an external model. Nobody approved that specific combination, and nobody is watching what the agent does with it session to session. The agent is not malicious, however, it is doing exactly what it was configured to do. But, that configuration is the exposure, and most security teams do not have a way to see it, let alone stop it before sensitive data leaves the environment.

AI Chat: Grok CLI data exfiltration, AI vs. patching, distillation wars & shadow AI [339]

AI Chat with Maxime Lamothe-Brassard and Chris Luft. A new segment on the podcast: AI news in cybersecurity that is less than 24 hours old, discussed while it is still hot. Joining Chris for these conversations is LimaCharlie founder and CEO Maxime Lamothe-Brassard. In this episode: Stories covered: Chapters: The Cybersecurity Defenders Podcast — a podcast about cybersecurity and the people that keep the internet safe. New episodes drop weekly.

Could your own AI agents run a ransomware attack?

Ransomware is evolving well beyond locking systems, and agentic AI is introducing a category of security risk most organizations are not yet equipped to handle. On The Cybersecurity Defenders Podcast, Behnaz Karimi, Senior Cybersecurity Analyst at Accenture and independent ransomware researcher, walks through what that shift actually looks like. The full conversation includes.

Suricata IDS/IPS Data in Graylog

If you’re running Suricata to watch your network, you already know how much signal lives in its logs. Graylog provides a purpose-built way to make that signal immediately actionable. The Suricata IDS/IPS Content Pack, available with an Illuminate license and Graylog Enterprise or Graylog Security, delivers ready-to-use parsing rules, streams, GIM categorization, and a dashboard so you can turn raw Suricata EVE JSON events into structured, searchable security intelligence.

Demo Discover Enterprise AI Workloads Running on AWS

AI workloads are appearing across AWS environments faster than most teams can inventory them. New APIs, EKS clusters, model integrations, and AI services are showing up across accounts and regions without a clear ownership trail or centralized visibility. By the time security catches up, the environment has already changed again.

Finding Just Got Free: That's Why Fixing Is the Only Game That Matters

When Anthropic revealed Claude Mythos and Project Glasswing, the industry did what the industry always does with a frontier-AI story: it reached for the alarm. The headlines, Reddit threads, and back-channel conversations all focused on the same things: All of that is real, and none of it is the part that should keep a security leader up at night. Here is the part that should.

France's ANSSI Sets New Post-Quantum Cryptography Milestones: What It Means for Your Security Strategy

Quantum computers capable of breaking today’s encryption may still be years away, but France’s National Cybersecurity Agency (ANSSI) believes organisations shouldn’t wait to prepare. At the France Quantum Conference on June 16, 2026, ANSSI announced new milestones for the adoption of Post-Quantum Cryptography (PQC). ANSSI recommends that organisations prioritise purchasing quantum-safe security products by 2030. The most important message, however, isn’t about 2030.