Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

CertKit Private PKI: A private certificate authority without running one yourself

In May I wrote that you probably don’t need private PKI for internal infrastructure, because DNS validation gets a publicly trusted certificate onto hosts that never touch the internet. In June I pointed out that Apple enforces an 825-day cap on private certificates, so your own CA doesn’t even free you from the browser vendors. Two days ago I told you that public client certificates stop renewing in October, and that the replacement is a private certificate authority.

The Fuyao Enterprise: Building an Ad-Fraud Empire with AI and Kids' Coding Blocks

In this post, we will uncover the “Fuyao Enterprise,” a previously unknown, sophisticated and highly modular botnet operating within Android TV boxes. This operation marks a shift in modern ad-fraud, where automated bots fake both clicks and views to defraud advertisers and ad-networks. While deploying novel tactics and techniques, Fuyao managed to escape public research for several years. Now, its operators openly advertise their network of over 120,000 “AI digital humans.".

Emerging Threat: (July 2026 Release) Apache Traffic Server Denial of Service and Access Control Bypass

The July 2026 Apache Traffic Server security release addresses a large batch of vulnerabilities across the proxy core and its plugin ecosystem, disclosed on July 29, 2026 and fixed in versions 9.2.15 and 10.1.4. Published counts of the batch differ. The Apache Traffic Server project describes the release as addressing 34 CVEs, while Belgium’s Centre for Cybersecurity puts the figure at 38 vulnerabilities.

The 14-Hour Recovery: Rethinking Healthcare Cyber Resilience

Ransomware recovery for healthcare IT depends on isolated recovery environments (IRE) and the ability to find clean data for patient safety. Jeremy Cathey shares insights on building cyber resilience by moving away from traditional disaster recovery toward a model that handles systemic cyberattacks. He details the three essential zones of an IRE: the clean room for forensics, the staging zone for validation, and the standby production environment where clinicians resume work.

From 10 Days to Unlimited Retention: How o9 Runs SecOps on Elastic Security

Somesh Agarwal, Senior Director of Security Operations at o9 Solutions, explains how the AI planning platform behind many of the world's largest supply chains consolidated security operations and observability on Elastic Security to gain unlimited threat-hunting retention, accelerate detection engineering, and simplify multicloud security operations.

Falcon AIDR Now Protects Copilot Studio Agents and Claude Code

Employees are already using AI at work. They build agents in Microsoft Copilot Studio, write code with Claude Code, and paste sensitive data into chatbots in the browser. Each of these actions can expose sensitive information outside of approved workflows, and most of it happens where traditional endpoint, network, and data loss prevention (DLP) security controls can't see the prompt or the tool call.