Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

AI Traffic Security: The Hidden Risk of Unstructured Data Leakage #aisecurity

Understanding the nuances of AI Traffic Security is critical because traditional firewalls and API gateways are fundamentally ill-equipped to inspect unstructured natural language. In the past, enterprise data remained safely within the corporate perimeter. Today, employees are pasting highly sensitive information directly into external models, creating a massive vulnerability where the risk lies in the meaning and content, rather than syntax or connections.

ISO 27001 vs ISO 42001 Do You Need Both

Already certified to ISO 27001 but wondering if your organization also needs ISO 42001? In this video, we explain the difference between ISO 27001 (Information Security Management) and ISO 42001 (AI Management Systems). If your organization uses AI tools like ChatGPT, Microsoft Copilot, Gemini, or develops AI-powered products, understanding AI governance is becoming increasingly important. Learn when ISO 42001 complements ISO 27001 and how both standards help organizations strengthen security, governance, and compliance.

The value of adding Microsoft administration and governance to your IGA environment

Most identity governance and administration (IGA) programs do a good job answering one question: who should have access to what. The platform provisions accounts, runs certifications, enforces segregation of duties and feeds compliance reporting. After the request has been approved and the account exists in Active Directory, the IGA tool typically stops looking. What happens inside the directory after that is somebody else’s problem.

The Agentic Attacker: One Objective, One Prompt, Forty Minutes, Domain Admin - Game Over

In a controlled enterprise lab, we tested how far an agentic attack stack could go by harnessing a frontier model with an agent platform, MCP-enabled tooling, operational context, and enough autonomy to execute a complete attack path.

Cyber Risk Intelligence Brief: Supply Chain Trust Erosion and Ransomware Velocity Require Preventive Control Discipline

This CISO Executive Cyber Risk Intelligence Briefing covers the Past Week (July 8–14, 2026) and the Past Month (June 15–July 14, 2026). Analysis draws exclusively from verified incident disclosures, CISA KEV activity, threat intelligence platforms, and platform telemetry. Focus remains on material risk to AppSec posture, software supply chain integrity, cloud/IaC, identity fabrics, and business enablement.

Cyber Risk Quantification Methodologies: A Practical Comparison

Cyber risk quantification methodologies translate technical exposure into structured financial estimates using mathematical, statistical, and actuarial techniques instead of ordinal ratings like high, medium, or low. The methodological landscape has matured enough that buyers now face real choices between frameworks that describe how to reason about risk, models that produce the numbers, and automated platforms that combine both.

Agentic AI vs. Generative AI: What Enterprises Need to Know

Agentic AI and generative AI both build on large language models, but they behave in fundamentally different ways once deployed. Generative AI produces content in response to a specific prompt and then stops. Agentic AI receives a goal, then autonomously plans, decides, and executes multi-step workflows to accomplish that goal, often across systems and tools the enterprise runs. That difference is the difference between an AI that helps a human do work faster and an AI that does the work itself. ‍

How to Patch Vulnerabilities and Reduce Risk with Aurora Vulnerability Management and Resolve

Learn how to identify, prioritize, and remediate vulnerabilities using Aurora Vulnerability Management and the Resolve integration. This demo walks through filtering and targeting high-risk vulnerabilities, deploying patches across assets, and tracking patch jobs to reduce risk more efficiently.

See It, Fix It: Comply to Deploy/Patch in Action: Tanium Tech Talks #165

Finding a vulnerability is easy. Closing the loop from finding to fixing is where programs stall. That gap — identify, prioritize, deploy a fix safely, then confirm it's actually gone — is what closed-loop remediation solves. Today we're walking through how to take Tanium's vulnerability findings and turn them not just into vulnerability remediations — but also as ways to identify and fix gaps in your OS & 3rd party patching programs.

IAM for DevOps: How to Secure Distributed Teams, CI/CD Pipelines, and Privileged Access

Your DevOps team doesn't log into one app from one office. They're in cloud consoles, Git repos, CI/CD pipelines, and production, often at 2 am, often from home. IAM for DevOps has to work for that reality, not the one from 2016. Traditional identity and access management was built for employees signing into a handful of business apps from a managed laptop. But the DevOps team blew past that model years ago.