Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Detect insider threats using Tines audit logs and AI

Automatically detect suspicious story deletions and insider threats in Tines before they become a bigger problem. This five-minute flow monitors your Tines audit logs on a schedule, checks for both soft and hard story deletions, and flags unusual user behaviour. When something looks off, an LLM summarizes the user's recent activity and a Case is automatically created for your team to investigate.

How Organizations Can Assess and Manage AI-Related Risks

Organizations assess and manage AI-related risks by establishing a cross-functional governance framework, mapping risks based on impact and financial likelihood, and instituting continuous monitoring that connects AI asset discovery to risk quantification, compliance, and enforcement. The most effective programs treat AI risk management not as a one-time assessment but as a continuous, data-driven discipline that evolves alongside the AI systems it governs. ‍

Why Human Behavior Has Become Cybersecurity's Fastest-Changing Attack Surface

For years, cybersecurity has largely focused on strengthening technology. Organizations invested in better endpoint protection, stronger identity controls, advanced threat detection, and AI-powered security operations. Those investments remain essential, but they're no longer enough. The next major cybersecurity challenge isn't simply keeping pace with attackers. It's keeping pace with how people work.

Sophos Firewall v22 MR2 is now available

Sophos Firewall v22 MR2 is now available AI app control, PQC detection, enhanced Chromebook support, and more. Sophos Firewall v22 bolstered Secure by Design, taking it to a whole new level with major updates to the architecture and new features like the Health Check to help identify high-risk configurations. Sophos Firewall v22 MR1 added several enhancements, including a new set of NDR detections for active threats.

How to Protect R&D Data During M&A

Mergers and acquisitions (M&A) concentrate risk into a narrow window. The moment a deal is announced, employees with access to proprietary research, source code, and unreleased product plans face pressure and opportunity at the same time. Some update their resumes. A smaller number decide to take something with them: a research file, a pricing model, or a customer list before the transition is final. For compliance and security teams, the challenge goes beyond stopping data exfiltration.

They Infiltrated the Infiltrators - And What They Found Was Unprecedented

Investigators have turned the tables on one of the world’s most elusive regimes. After a security firm hired a man calling himself "Joseph," a team of private investigators did what no one had done before: they infiltrated a North Korean remote worker cell from the inside. Head to our YouTube channel and watch the full episode of To Catch a Thief, Season 2.

Lessons from a CISA Security Incident - The 443 Podcast - Episode 378

This week on the podcast, we review an after action report from CISA on a security incident they responded to back in May. After that, we cover a vulnerability in Amazon's Q Extension for VSCode before covering a research post from Microsoft on Giga Wiper.

Why You Must Still Review AI Code

In this video, we break down why skipping code reviews is a massive mistake that will ultimately slow you down, leave you vulnerable, and compromise your system's accountability. We dive into three concrete reasons why reviewing AI-generated pull requests actually makes you a faster, safer developer, including a real-world story of a production bug caught in under 90 seconds. Resources Chapters.