Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Secure Agent Harness Execution: Preventing Escape

At CrowdStrike, we conduct extensive red-team testing of agentic systems using diverse models, tools, and adversarial evaluation harnesses designed to probe for containment failures. To date, none of our offensive agents have escaped their intended sandbox boundaries.

How to Prevent Insider Threats Without Hurting Productivity

Security teams that tighten insider threat controls usually hear about it fast, and not from attackers. Sales reps complain they cannot share a deck with a prospect. Engineers say a blocked upload cost them an afternoon. The business assumes that stopping data loss and staying productive are opposing goals, and every blanket policy that blocks first and asks questions later reinforces that assumption. They do not have to be opposing goals.

Modern Authentication for Legacy Applications Explained

Your ERP system doesn't know what a SAML assertion is. Neither does that 15-year-old internal tool running your warehouse floor. But your identity team just rolled out Microsoft Entra ID with conditional access, MFA, and zero trust policies everywhere. That gap is what modern authentication for legacy applications closes.

Smart Card Authentication: A Complete Guide To Secure Enterprise Access

If you're evaluating multi-factor authentication for a bank, a hospital network, a defense contractor, or a government agency, you've probably already run into smart card authentication. It's the method behind the CAC (Common Access Card) and PIV (Personal Identity Verification) cards federal employees badge in with every day. It's also becoming the default authentication method that regulated industries reach for, once passwords and OTP codes stop being good enough.

Mini Shai-Hulud Hits keyv: Trojanized Release Exfiltrates CI Secrets via GitHub

On August 4, 2026, a malicious version of keyv was published to npm as keyv@6.0.0, one of a number of npm packages affected across the Keyv and Cacheable ecosystem. The release follows the Mini Shai-Hulud pattern: a trojanized version of a heavily depended-on package, with an install-time hook that reaches cloud and CI credentials. It leaves the compiled library untouched and instead adds a preinstall hook and two files.

Patch faster isn't the answer. Patch smarter is.

The 30-day patch cycle is dead. Most security teams already know this. What they haven’t fully reckoned with is why it died, and what has to replace it. SC Media recently gathered a range of security leaders on exactly this shift, and the picture they described is stark. AI didn’t just add more vulnerabilities to the pile. It collapsed the time between disclosure and exploitation from weeks to hours.

The AI agent working for you probably has more access than you do

Say a sales rep uses an AI assistant to help manage their pipeline. The rep has role-based access to Salesforce, scoped to their territory and their accounts. The assistant, wired in through an API integration, often doesn't have that same scoping. It authenticates as a service account with broad read and write access across the org, because that was faster to set up than a permission model that matches what the actual user is allowed to see.

What engineering leaders can learn from stoicism

“A man’s worth is no greater than the worth of his ambitions.” Marcus Aurelius wrote that almost two thousand years ago, in a private journal he never intended anyone to read. Coming from a man who held every title Rome could give, it’s a telling way to measure worth: not by what you hold, but by what you aim at. It has stuck with me, because everything I’ve seen in my career backs it up. Deep technical knowledge is where great engineering starts.

How To Encrypt A File: A Detailed Guide to Securing Your Data and Privacy

Encrypting files has become the new norm for the digital services we use online, from VPN, email, and cloud storage. Without it, our data is openly available for anyone to read, compromising our confidentiality, privacy, and security and potentially costing businesses millions in compliance fines. This comprehensive guide therefore offers you a comprehensive guide on how to encrypt files to ensure your data remains protected by covering the following topics.