Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

RubyGems supply chain attack: malware used as a credential exfiltration dead drop

Package registries have a well-known abuse pattern: attackers upload malicious packages, and unsuspecting developers install them. Our researchers just found the pattern working in reverse, in a RubyGems supply chain attack that turns the registry into a place to stash stolen data rather than deliver it.

Selling to the Government? Here's What CMMC Means for You

CMMC Phase 2 enforcement lands in November 2026, and C3PAOs are already warning about assessment capacity. If your configuration management domain isn't audit-ready, this is the walkthrough to fix that. Roy Ludmir breaks down what changed in enforced CMMC as of November 2025, what auditors actually test versus what they just ask about, and where most organizations get stuck below full compliance — plus which security baselines to standardize on and how to build an evidence package that holds up under a real assessment.

Top AI Governance Tools for Shadow & Agentic Risks

AI governance platforms are evolving rapidly to manage new challenges such as shadow AI and agentic AI. These complexities arise as AI systems grow beyond traditional boundaries, operating autonomously and often without clear oversight. This article explores how leading AI governance solutions, especially Kovrr’s integrated platform, address these challenges through comprehensive visibility, risk quantification, compliance automation, and active enforcement.

Evaluating AI Security Posture Management Tools: 7 Key Criteria

Evaluating AI Security Posture Management (AI-SPM) tools is a critical process for organizations integrating AI, specifically Generative AI (GenAI) and Large Language Models (LLMs), into their workflows. Unlike traditional security tools, AI-SPM focuses on the unique risks of AI, including Shadow AI, prompt injection, data poisoning, model theft, and improper model configuration. When assessing AI-SPM tools, security leaders should prioritize the following capabilities.

Where Severity Scores Go Wrong: "Just Add Prototype Pollution"

At JFrog, our Security Research team continuously monitors and analyzes newly disclosed CVEs across the open-source ecosystem. Throughout our research, we have repeatedly observed cases where the assigned severity score does not accurately reflect a vulnerability’s real-world impact or exploitability. In fact, during 2025, JFrog researchers reassessed NVD critical-severity vulnerabilities and concluded that 96% warranted a lower severity rating.

June Release Rollup: Building Code Analyst, AI Assistant, and More

June's release brings a range of updates across Egnyte's platform, with the most notable addition being the Building Code Analyst, an AI-powered tool that helps AEC teams quickly surface relevant code requirements across jurisdictions. The release also includes Adaptive Block Caching (now generally available), expanded AI Assistant capabilities like agent mode and multi-file spreadsheet analysis, and several mobile improvements across iOS and Android.

CISO Executive Briefing: This Week's Threats, Priorities, Foresight & Execution

Cyber risk remains at an elevated baseline. Ransomware holds at “new normal” highs, state actors exploit supply chains and zero-days, and AI accelerates attacks. Last week’s signals confirm active exploitation of known vulnerabilities and credential/ICS exposure. Winning CISOs reduce attack surface at first principles, assume breach, and enforce continuous validation with measurable business outcomes.

Why Your Asset Counts Are Wrong (And What to Do About It)

If you've ever pulled an asset count from one tool and compared it to another, you've probably noticed they don't match. The discrepancy isn’t minor, either. The difference is likely to be substantial. One scanner says you have 4,200 assets. Your CMDB says 3,800. Your cloud inventory says 1,100. None of them agree, and none of them are right. That's not a data hygiene problem you can solve with a spreadsheet cleanup.