Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Guide: Certificate-Based Authentication for Payment & Banking Infrastructure

Payment and banking infrastructure continues to grow. Bare-metal servers and mainframes now sit alongside Kubernetes clusters, microservice architectures, and CI/CD pipelines running across multiple clouds and on-prem data centers. Every new environment adds its own accounts, tokens, and access paths to manage. But because this infrastructure powers live transactions, there is no room for downtime or disruptions.

It Just Got Easier To Consistently Deploy And Configure ggshield Across Your Whole Fleet With v1.53

ggshield v1.53.0 introduces ggshield machine setup, a consistent way to configure ggshield no matter how it was installed. Set up AI hooks for every detected AI coding assistant, install global git pre-commit/pre-push hooks, and deploy a honeytoken on the endpoint. You have full control, and we have options to customize which features you want to skip. This release also includes ggshield machine doctor, a read-only command that checks that the machine's ggshield protections are correctly set up, letting you know what steps to take if it encounters an issue.

CertKit Private PKI: A private certificate authority without running one yourself

In May I wrote that you probably don’t need private PKI for internal infrastructure, because DNS validation gets a publicly trusted certificate onto hosts that never touch the internet. In June I pointed out that Apple enforces an 825-day cap on private certificates, so your own CA doesn’t even free you from the browser vendors. Two days ago I told you that public client certificates stop renewing in October, and that the replacement is a private certificate authority.

NIS2 and DORA Compliance for Kubernetes Backup

EU regulations are putting real pressure on how organizations protect and recover their data. If you run Kubernetes workloads in financial services, insurance, healthcare, energy, telco, and public administration, your backup strategy is no longer just an IT concern. It is something regulators and auditors can examine directly. Most Kubernetes environments were set up for operational convenience rather than compliance.

Move faster than AI-driven risk: Inside Mend.io's latest AI application security update

AI didn’t just change how fast you ship. It changed what your AI application security program has to protect. Two years ago, security teams protected code, open source, and containers. Today they also have to protect AI agents, MCP servers, models, prompts, and runtime interactions, configured or deployed faster than any team can manually review. The attack surface didn’t grow. It exploded.

Public mTLS client-auth certificates stop renewing in October

Chrome’s root program decides what certificates will be trusted by Chrome, and what they are allowed to do. Recently, Google decided that client authentication isn’t on the list. Under Chrome Root Program Policy v1.8, every certificate issued on or after March 15, 2027 can assert only one Extended Key Usage (EKU): server authentication. Let’s Encrypt moved early.

EveryOps in 1 Minute: What is GRC?

Governance, Risk, and Compliance — better known as — is an integrated approach that helps organizations align their objectives, manage risks, and meet regulatory requirements, all at the same time. In this quick explainer, we break down: Whether you're new to GRC or looking for a simple way to explain it to your team, this short video gives you the essentials without the jargon.

How to Access Internal Web Apps Without a VPN

Most organizations start with a VPN when they need to give employees access to internal web applications. The VPN places the user on the internal network, and from there, they can reach the app. This approach works when the user base is small and the number of internal apps is limited. But as teams grow, compliance requirements increase, and the mix of technical and non-technical users increases, a VPN’s network-level connectivity introduces new operational and security challenges.