Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Why Flipping Cyber Defense Backwards Works

Standard incident response is failing to keep pace with long-term threat campaigns. Adam Karcher from the FBI explains why the most effective security teams run their operations as an inverted offensive strategy, leveraging continuous adversary emulation to stop intrusions before they begin. Watch the full video on our channel.

How to Publish Multiple Policy Types in One Request: A Step-by-Step Guide

In this comprehensive guide, we will explain how to efficiently publish multiple policy types in a single request using the Fireblocks Policy Engine. This streamlined process allows you to update various policy types—such as transfer policies and typed message policies—simultaneously, ensuring that all changes are coordinated and compliant. Key Benefits of Multi-Type Policy Publishing.

How to Export Fireblocks Transaction Policies as CSV or JSON: A Step-by-Step Guide

In this comprehensive guide, learn how to export your Fireblocks transaction policies in both CSV and JSON formats. This video walks you through the process of selecting your policies, choosing the appropriate format, and securely downloading your data. Key Topics Covered: Exporting Policies: Understand how to access the active policy section from the Policy Overview screen. Choosing Formats: Discover the differences between CSV and JSON exports.

How to Use Policy Inspector to Diagnose Transaction Failures in Fireblocks

In this comprehensive guide, learn how to effectively use the Policy Inspector tool within Fireblocks to diagnose and resolve transaction failures. The Policy Inspector provides clear insights into which policy rules blocked a transaction and the reasons behind it, eliminating guesswork and streamlining communication with your security team. Key Features of Policy Inspector: Transaction Simulation: Test any transaction against your active policies directly in the console. Detailed Insights.

When the 'Attacker' Was an AI Agent: Lessons from the OpenAI-Hugging Face Breach

In this episode of Sophos Cyber Shorts, host Susie Evershed is joined by Ross McKerchar, Sophos CISO, to discuss the recent OpenAI and Hugging Face incident and what it reveals about the future of AI security. From containment failures and over-privileged AI workflows to faster AI-driven attacks, Ross shares practical advice for security leaders on how to strengthen resilience, response, and recovery.

The AI governance confidence gap: Why trust in AI is running ahead of the capacity to govern it

Accelerating security solutions for small businesses‍ Tagore offers strategic services to small businesses. A partnership that can scale‍ Tagore prioritized finding a managed compliance partner with an established product, dedicated support team, and rapid release rate. Standing out from competitors‍ Tagore's partnership with Vanta enhances its strategic focus and deepens client value, creating differentiation in a competitive market.

Enterprise risk designations and multiple risk registers: when are they relevant?

Accelerating security solutions for small businesses‍ Tagore offers strategic services to small businesses. A partnership that can scale‍ Tagore prioritized finding a managed compliance partner with an established product, dedicated support team, and rapid release rate. Standing out from competitors‍ Tagore's partnership with Vanta enhances its strategic focus and deepens client value, creating differentiation in a competitive market.

Third-Party Vendor Risk Management: Lessons From the TPWD and Carnival Breaches

In June, the Texas Parks and Wildlife Department (TPWD) disclosed that a vendor running its hunting and fishing license system had been compromised, potentially exposing personal data belonging to more than three million people. Weeks earlier, Carnival Corporation confirmed that an attacker had socially engineered an employee into granting access to part of its IT environment, affecting close to six million individuals. Different sectors. Different attack paths.

BGP ORIGIN attribute manipulation and its impact on the Internet

Border Gateway Protocol (BGP) is the de facto routing protocol of the Internet. It offers built-in mechanisms to allow entities, represented by Autonomous Systems (ASes), to express how they want to send and receive traffic on the Internet. One such mechanism is path attributes, which carry essential routing information and metadata for their associated route.