Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Supabase Data Exposure | 16,000+ Open Databases and What Security Teams Can Do

We found more than 16,000 Supabase databases sitting wide open, and over half held personal data like names, phone numbers and passwords. The organizations behind them ranged from a valet service to a government consulate, and in many cases the owners never checked the settings AI wrote. What is the Supabase data exposure? Anyone visiting these sites could read the data in their databases. Many belong to vibe-coded apps, where AI coding tools often handle the database setup.

Buying an AI SOC Isn't Like Anything You've Bought Before

John White is the Field CISO for EMEA at Torq. A respected security executive with more than 20 years of leadership experience, John previously served as CISO at Virgin Atlantic, where he led a multi-year transformation deploying the Torq AI SOC Platform to modernize cyber operations. Prior to Virgin Atlantic, he built and transformed security functions for global organizations, including ASOS, Liberty Global, AEG Europe, and KPMG.

Zero Touch Patch Automation: Tanium Tech Talks #172

How do you patch faster - all while honoring your patching policies and *not* breaking things? Attackers are using AI to find and exploit vulnerabilities faster, and vendors are shipping patches faster too. Your patching processes need to keep up! In this episode we show how to automate patching on a monthly cadence, roll it out in rings, and keep control of the process the whole way through. zero-touch, ring-based patch automation with Tanium deployment plans, in Atlas or the classic console.

Frontier models found the vulnerabilities. Only the attacker found the chains.

Attackers don't read your repository; they hit your URL, and chain together whatever they find. In an era where offensive AI runs against live applications at machine speed, your security tooling needs to go beyond finding vulnerabilities to prove exploitability, including whether they can be combined into a breach.

Autonomous Attacks Are Already Here. The Defense Has to Match Their Speed.

Last week, Snyk CTO Manoj Nair sat down with Alon Krifcher, Head of Applied AI from Anthropic, for a live discussion on the coming wave of autonomous attacks. Manoj kept landing on one thing: the AI Hurricane has already arrived, and what's left is deciding whether your defense runs at the same speed as the threat.

What to Look for in a Threat Intelligence Tool

Most security teams aren't short of data. The harder problem is turning that data into intelligence they can act on. This guide sets out the seven criteria that separate an effective threat intelligence tool from another unused dashboard: dark web coverage, relevance, human analysis, speed, multi-audience outputs, integration and provider trust. It also covers the red flags to watch for during procurement and gives ten questions to ask every vendor.

The Interconnected Security Program: Managing Risk Across Cybersecurity Domains

Cybersecurity programs have become increasingly specialized and become a rather expansive enterprise responsibility. Protecting a modern organization can involve identity, endpoints, networks, applications and APIs, cloud infrastructure, data, threat intelligence, detection and response, governance, risk and compliance (GRC), incident response, and cyber resilience. Each discipline brings specialized technologies, processes, and expertise to the security program.