Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

ASOS Cyber Attack: What IT Leaders Can Learn About Third-Party Risk

The ASOS cyber attack reported on 6 October 2026, has raised fresh questions about third-party access, SaaS security and how modern organisations manage an increasingly connected attack surface. The incident became public in an unusual way: customers received an unauthorised mobile push notification through the ASOS app claiming the retailer had been compromised. ASOS later confirmed that basic personal information, including names and contact details, may have been accessed.

Real-Time Data Replication: 5 Best Practices for Efficient Implementation

Data replication is primarily used when service and data availability requirements are high. There are two types of replication – real-time replication or continuous replication and traditional replication, also called periodical or snapshot replication. Real-time replication has more advantages than traditional replication but consumes more resources. For this reason, it is better to follow data replication best practices to implement real-time VM replication for disaster recovery.

Critical Security Risks in vSphere Active Directory Integration

Microsoft Active Directory is widely used for authentication, and many software solutions can integrate with it to rely on a single authentication system. VMware vSphere components, including vCenter Server and ESXi hosts, also support Active Directory integration, which simplifies account and access management. However, this convenience introduces specific security risks that administrators need to understand and mitigate.

Why a clean firewall policy isn't enough to secure your network

Your last firewall audit came back clean. Every rule documented, every exception justified, every box checked, exactly what PCI DSS and your other compliance frameworks and attestations require. None of that tells you whether a compromised laptop in marketing can actually reach your payment systems right now. The audit verifies your firewall policy. It was never built to verify your network.

Ep. 84 - ShinyHunters Leaked 5,000 Agents' Home Addresses Over One FBI Advisory

ShinyHunters breached FBIJobs.gov, leaked personal data on roughly 5,000 Bureau personnel—including 14 staffers tied to China-focused counterintelligence—and triggered arrests in Amsterdam and Jordan. We separate what the FBI confirmed from what the crew claimed: the unverified Oracle PeopleSoft zero-day, the vishing and OAuth token abuse behind 140+ breaches, and why the arrests wound the brand but not the playbook. Plus, the four controls worth validating this week, starting with FIDO2.

CrowdStrike Named a Leader in the 2026 IDC MarketScape for Worldwide Modern Endpoint Security for Enterprises Vendor Assessment

CrowdStrike has been named a Leader in the 2026 IDC MarketScape for Worldwide Modern Endpoint Security for Enterprises Vendor Assessment. We believe this recognition reflects the strength of the CrowdStrike Falcon platform and the proven endpoint capabilities CrowdStrike brings into the AI era: industry-leading protection at scale, consistent analyst recognition, measurable business value, and the trust of customers globally.

Unknown Threat Actor Uses AI-Driven ARTEX to Target South Korean Finance

CrowdStrike Intelligence identified infrastructure associated with a targeted campaign against South Korean financial organizations that resulted in exfiltrated data. The campaign was active from late September to early October 2026. Analysis of threat actor-controlled open directories uncovered Claude Code session histories, ARTEX configuration files, and Claude memory files, providing direct insight into the threat actor's operational methodology and tooling.

How we replaced our host vulnerability scanner with the Datadog Agent

A year ago, Datadog’s cloud environment had grown to support tens of thousands of users across the globe. As our host fleet expanded alongside that user growth, we saw that our original system for vulnerability scanning was becoming less effective at reaching and assessing every host.

Gemini Never Left the Sandbox. The Sandbox Had a Door.

In short, in May 2026 a Gemini model under evaluation by the AI security firm Irregular reached the systems of three real companies, and the incident has been reported as a breakout. By Google’s own account it was nothing of the kind. The test environment had internet access it was not meant to have, the fictional target shared its name with a real company, and the model found public information online, guessed one password and found two more in public code repositories.