Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Latest posts

"Speaking the Same Language" Tanium Atlas MCP Server: Tanium Tech Talks #169

Want to point your own AI at Tanium? The Atlas MCP Server makes that possible — governed, scoped, and available today. In this episode we cover: Tanium MCP - Available now (read-only) How to set up OAuth clients and how RBAC applies How to scope a single-purpose agent to one module, like Asset, using path-based tool filtering How to tell which tools consume Atlas AI credits - and which don't!

Autonomous Patch Management: Continuous, Closed-Loop Remediation

A critical vulnerability is discovered. Minutes later, it's patched — approved, scheduled, and deployed, with no one bouncing between systems to make it happen. In this video, Steven Payne shows how Tanium and ServiceNow close the gap between finding a problem and fixing it, turning a vulnerability into a governed change request and an executed patch deployment without a single manual hand-off. It's change management and endpoint remediation working as one motion instead of two disconnected jobs. If patch cycles have ever felt like a race against the clock, watch how much faster — and safer — that race can be.

CISO Risk Intel Brief: Edge Zero-Days, Artifact-Repository Takeover, and Identity-Pivoted Extortion

This CISO application risk intelligence briefing covers two distinct horizons: the past seven days (Wednesday, 26 August 2026 through Wednesday, 2 September 2026) and the preceding thirty days (Sunday, 3 August 2026 through Wednesday, 2 September 2026). It is written for board risk committees and operating CISOs.

Cross-Border Data Transfer Under India's DPDPA

Businesses operating across countries routinely move personal data between India and overseas systems. Customer information may be stored by a global cloud provider, employee records may be accessed by an international headquarters, or an Indian business may use SaaS platforms whose infrastructure is located outside the country.

Zlatko Unger has 35 minutes to stop AI from obeying poisoned emails (Live Tabletop Exercise)

You're the CISO at Larkfield Health, a 9,500-person health tech company. A little after 9:00 AM on a Tuesday, your Head of Detection forwards you a message from a security researcher you've never heard of. They say they've found a way to make Wingman—the AI assistant you rolled out company-wide six months ago—hand internal data to an outsider, and that a collection server that isn't theirs is already receiving it. Nothing in your own stack has made a sound.

Give access only when it's needed: Configuring Just-In-Time Application Allowlisting in MSP Central

Standing exceptions to your application control policy are exactly that—standing. Once you allow an app or lift a restriction, it usually stays open indefinitely, whether or not it's still needed. In this tutorial, we cover how to configure just-in-time (JIT) application access in MSP Central. Learn how to grant temporary, rule-based access to specific applications so users get what they need for a limited window, without leaving permanent access behind.

AI Governance Auditing for Security and IT Teams

AI governance auditing distinguishes between a documented policy and a working control. The audit traces one AI output back through the identity that invoked it, the data it reached, the guardrail that applied, and the record retained afterward. Most programs fail because access is ineffective: nobody can say which identities access sensitive data through an AI assistant, let alone prove the limit is held.

Microsoft Entra ID monitoring: Detecting suspicious activity

Entra ID monitoring correlates sign-in, audit, and privileged-role activity to expose suspicious identity changes while evidence still exists. Native controls leave gaps in retention, licensing, and correlation, so resilient teams export data, baseline admin behavior, and connect to Entra ID, Privileged Identity Management (PIM), OAuth, Conditional Access, and on-premises Active Directory events in a single workflow.