Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

We wrote the docs

Most security vendors hide their documentation behind a login. Some don’t write it at all. You get a sales page, a demo, and a request to install an agent on your servers, and you’re expected to trust that the thing does what the marketing says. That’s backwards. So we wrote the docs, and we put all of them at certkit.io/docs. No login, no account gate, no “contact us for details.” You can read every page before you create an account.

The Howler Episode 31 - Trisha Farrow

This month, we sit down with Trisha Farrow, our Senior Vice President of People and Facilities. In this episode, Trisha Farrow shares the heart behind her leadership—why human connection, courage, and curiosity matter more than ever in a fast-changing world. From building inclusive cultures to navigating AI in HR, she offers a powerful perspective on what it really means to lead people, not just processes.

CloudCasa DR for HPE Alletra with Red Hat OpenShift - PART 1: Failover

CloudCasa orchestrates disaster recovery failover for stateful workloads across two HPE Alletra arrays running Red Hat OpenShift. In this demo, we fail over a file server application from Site A (HPE Alletra 9060) to Site B (HPE Alletra MP B10000), with CloudCasa installing its agent via a single kubectl apply, discovering both clusters and storage systems, mapping the pre-configured HPE replication relationship, and triggering consistency group failover so the workload comes back up on Site B with all data intact.

CloudCasa DR for HPE Alletra with Red Hat OpenShift - PART 2: Failback

CloudCasa completes the disaster recovery cycle by failing a file server application back from Site B (HPE Alletra MP B10000) to its original primary on Site A (HPE Alletra 9060), both running Red Hat OpenShift. In this demo, we create a reverse DR plan, scale down the workload for a clean shutdown, and let CloudCasa orchestrate the two-phase failback: an HPE recover/restore operation that reverses replication at the storage layer, followed by progressive Kubernetes resource restoration, before the file server comes back online on Site A with its data intact.

Inside CVE-2026-53435: Authenticated Deserialization to Full Controller Takeover in Jenkins via config.xml

How a low-privileged account turns an XML configuration upload into arbitrary file read, user impersonation, and remote code execution — and how to detect and stop it. Published 16 June 2026 · Fact-checked against the official project advisory and government vulnerability databases.

1Password + Kiro: Trusted Access for AI-Powered Development

AI agents now write code, fix bugs, and ship to production. But in order to do useful work, agents require credentials. At 1Password, one of our core AI security principles is that raw credentials should never be directly exposed to LLMs, but all too often, that’s exactly what happens: most teams sacrifice security for speed and hand agents secrets in plaintext.