Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Latest posts

GitProtect: Beyond Jira Cloud migration: how to gain total visibility, reporting & data resilience

The clock is ticking on Data Center support, making the move to Jira Cloud a priority for many organizations. But migration is only the beginning. Once you're on Jira Cloud, how do you maintain visibility and control in an environment that works very differently from Data Center? For years, Jira Data Center admins could customize Velocity templates, use scripting tools, and build highly tailored workflows and reporting mechanisms with deep control over the environment. Jira Cloud changes that equation.

Passkeys vs. passwords: The authentication cage match nobody asked for

First things first, let’s be honest about one thing: passwords are terrible. Yet, here we are in 2026, still filling up our password fields with trivial stuff like P@ssw0rd123! and pretending we're being secure. And of course, we reuse the same password everywhere: We scribble it on a sticky note and display it on our cubicle wall for the world to see. But even then, we still forget what it was. So we smash that Forgot Password link so often, we might as well have it bookmarked.

When Vulnerability Databases Are No Longer Enough

The NIST’s changes in how the National Vulnerability Database (NVD) operates have fundamentally shifted how organizations interpret the vulnerabilities published in this go-to registry. In the past, the NVD provided vulnerability enrichment data, such as CVSS scores, affected products, CWE classifications, and reference links.

What Is SIEM? How It Works With DLP to Detect Data Threats

Most security teams don’t lose the fight against data breaches because they lack tools. They lose because their tools don’t talk to each other. This is exactly the loophole that SIEM and DLP were built to close, together. Security information and event management gives you visibility into what’s happening across your entire environment. At the same time, data loss prevention gives you the control to stop sensitive information from leaving in the first place.

What is Identity Governance and Administration (IGA)?

Enterprises today manage thousands of identities across employees, contractors, applications, APIs, and machine-driven systems. In most environments, identities have become the primary security boundary, yet access remains fragmented, overprovisioned, and difficult to track. According to IBM's X-Force Threat Intelligence Index, identity-based attacks now account for nearly one-third of all intrusions, highlighting how identity has become one of the most targeted layers in modern cybersecurity.

How to Reduce Payment Fraud Risk Without Adding Customer Friction

Reducing payment fraud risk requires giving existing fraud controls enough context to distinguish higher-risk interactions from routine activity, rather than applying more checks to every customer. That distinction matters. UK Finance reported that criminals stole almost £1.3 billion through authorized and unauthorized fraud in the UK during 2025. Authorized push payment fraud alone accounted for £576.4 million, up 19% year over year.

Becoming a trusted business partner: 5 partnership strategies for Australian MSPs

A reliable service desk earns confidence. A trusted business partner earns a place in decisions about risk, growth and continuity. For Australian MSPs, that distinction matters because clients increasingly need more than a list of tools. They need clear advice about which risks to address, which outcomes to prioritise and how technology supports the business. Australian Cyber Security Centre guidance encourages organizations to scrutinize the cybersecurity measures used in outsourced ICT services.

Vulnerability Assessments in an Agentic World: Step-by-Step Guide

An old package or a misconfigured cloud storage bucket can be identified by a legacy scanner, but it does not account for the unique risk profile of autonomous systems. It cannot confirm that an AI agent with access to your production environment can chain together a CRM read, an email send and a production write using inherited credentials. Your agents are dynamic: they plan, call tools, and act across multiple environments, and some may retain context or long-term memory beyond the original request.

Skynet Comes Online - The 443 Podcast - Episode 386

This week, dive into OpenAI's and METR's analysis of the rogue OpenAI agents that hacked Hugging Face back in July. We go over the full attack timeline discussing the multiple message boards the agents created and the ultimate goal of their attack against Hugging Face and trust us, its as crazy as it gets. Before that, we discuss a recent dark web service that popped up selling 153 million stolen drivers licenses before discussing a research post into a malware implant discovered in inexpensive Chinese routers.