Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

NIST SSDF: 4 core practices for secure software development

The NIST Secure Software Development Framework (SSDF) is a set of fundamental, outcome-based practices that integrate security throughout the software development lifecycle (SDLC). Documented in NIST SP 800-218, it helps organizations reduce vulnerabilities, prevent recurrences, and establish a common language for secure development. The SSDF outlines dozens of tasks grouped into four high-level categories.

A Quiet Shift In Security Every Healthcare Compliance Team Should Read

Change Healthcare took down a third of US claims processing. Ascension spent weeks on the papers. OCR settlements keep citing “risk analysis failure,” and HITRUST r2 assessors are asking harder questions about what actually got tested versus what got scanned. The math on pentesting shifted in the middle of all that. In 2024, 1 in 40 findings was Critical. In 2025, it’s 1 in 10.

How Do I Save My Photos in the Cloud Securely and Privately?

Your phone holds years of memories, and it only takes one lost device, one failed backup or one hacked account to lose them. So if you are asking "how do I save my photos in the cloud?", you are already ahead of most people. The harder question is how to do it securely and privately. Internxt Drive and Photos make uploading and backing up your photos easy, with the added benefits of zero-knowledge encryption, open source software, and data sovereignty.

How to Reduce Overprivileged Kubernetes Service Accounts

Overprivileged Kubernetes ServiceAccounts persist when broad RBAC, cloud IAM permissions, and long-lived credentials outlive their intended use. Reduce overprivileged access with least privileged RBAC, scoped cloud permissions, and short-lived certificates that eliminate static credentials. I spent two days last quarter tracking down why a developer could delete production secrets. The RBAC looked fine. The ClusterRoleBinding said edit, not cluster-admin.

The keys to the Internet change on October 11. Are you ready?

On October 11, 2026, the DNS root is scheduled to change its key-signing key (KSK) for only the second time ever. This key anchors DNSSEC’s chain of trust, which lets DNS resolvers authenticate answers using cryptographic signatures. The change is called a KSK rollover. Validating resolvers need to trust the new key before the switch, as otherwise healthy websites could become unreachable.

A One-in-Hundred-Year Cyber Loss Is Not a Schedule

A quantification exercise reports a one-in-hundred-year loss and the figure travels well. It sounds precise, it sounds severe, and everybody in the room believes they understand it. ‍ Most of them do not. The phrasing describes an annual probability and it reads as a statement about timing, and the two produce different decisions from the same number. ‍

What an AI Correlation Rule Cannot See

A correlation rule can be tuned. The window can be widened, the join key improved, a source promoted from optional to required. Each of those is a parameter with a defensible setting. ‍ What remains after all of it is the residual, meaning the events that would produce a finding if a source existed for them, which is a form of residual risk expressed in detection terms. Naming it is the question an auditor asks after being shown a detection, and the answer is not a tuning exercise. ‍

AI Governance Evidence That Costs Nothing to Produce

The usual case for governance return is that it speeds up enterprise sales, because buyers ask security questions and a prepared answer closes faster. It is true and it is the weaker argument. ‍ The stronger one is loss avoidance, and almost nobody makes it, because it needs a loss figure that most governance programs do not have. What makes it affordable is a distinction between two kinds of evidence. ‍

Warning: Tech Support Scams Are Abusing Google Ads

Researchers at Netskope are tracking a phishing kit that hijacks users’ browser windows to display fake security alerts. The malicious websites are distributed via Google Ads, and pose as normal online stores. Once a user clicks a link on the page, however, the site will present them with an urgent-looking security warning.