Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

UK Cybersecurity & Resilience Bill Explained | Part 1: Why It Matters

What is the UK Cybersecurity & Resilience Bill (CSRB), and why should organisations be paying attention now? In Part 1 of this 6-part series, Dean Roberts explains why the Cybersecurity & Resilience Bill is one of the biggest changes to UK cyber regulation in recent years—and why it's about much more than compliance.

Every laptop is a credential store: lessons from Vermeer

Your code repos aren't the only place secrets hide — your laptop is too. In this session, GitGuardian's Emanuelle Franquelin talks with CJ May, Cybersecurity Architect at Vermeer, about extending secrets detection beyond the codebase and onto developer endpoints. They dig into where credentials actually live on modern machines (think config files, shell history, and AI coding agents), why every workstation is fair game, and what to actually do once you find exposed secrets. Watch to see how one enterprise team is tackling credential sprawl to deploy AI safely.

199 RubyGems, two techniques, zero working payloads: Inside a cryptomining campaign that never ran

Mend.io’s research team caught this campaign before most of the open source community ever saw it. Continuous monitoring of RubyGems flagged a batch of gems that looked, at a glance, like an ordinary cryptomining squat, and Mend.io reported the full batch to RubyGems for takedown. Every gem was pulled within hours. Mend.io’s team also pulled two of the samples apart in full, because knowing a campaign exists isn’t the same as knowing how it works.

Identity Security for AI

What's scarier than an engineer with prod access? An agent with the same access that never sleeps, never asks, and runs a thousand sessions while you're at lunch. Last year we solved the problem of visibility in the Identity Chain, the concept is that identities are fragmented and it’s hard to get a view from Identity Providers to Infrastructure. Within a year, two things have changed. First, teams are using LLMs & Tools to perform actions on their behalf - fully delegating work to AI Agents.

Best 6 AI security posture management platforms (AI-SPM) in 2026

AI Security Posture Management (AI-SPM) platforms are specialized tools that discover, monitor, and secure AI models, pipelines, and data, mitigating risks like data leakage and model poisoning. They offer continuous visibility, manage misconfigurations, and enforce security policies across cloud services like Azure OpenAI and Bedrock.

OpenAI's Sol, Terra, Luna Explained: Which One Should You Use?

-OpenAI has completely overhauled its model naming system with the release of GPT-5.6, introducing three distinct tiers: Sol, Terra, and Luna. In this video, we put OpenAI's new flagship model, GPT-5.6 Sol, to the ultimate test. Using the Codex extension in VS Code, we throw our classic "Build me a secure notes app or I get fired" prompt at Sol. Watch as we break down the pricing and reasoning differences of the new tiers, run a full security audit using Snyk, and see if Sol's $5/$30 price tag is truly production-ready or if a small local CSRF bug gets us "fired" first.

Securing kubectl on Remote Kubernetes Clusters Without Static Credentials or VPNs

Fleets of robots, drones, EV chargers, and sensors now run K3s or MicroK8s on the device itself, bringing container orchestration to hardware deployed in warehouses, cell towers, and customer sites around the world. Engineers need kubectl to debug and manage containerized workloads on those devices in the field. But because each cluster requires a kubeconfig file, and every kubeconfig file is a shared static credential, risk grows with each new device added to the fleet.

How Teleport Operationalizes the EU Cyber Resilience Act's Secure-by-Design Mandate

The EU Cyber Resilience Act (CRA) enters its enforcement window in 2027, but preparations should start now. ENISA's Secure by Design and Default Playbook (v0.4, March 2026) translates the CRA's legal text into 22 actionable security playbooks, structured around architectural foundations, operational integrity, default hardening, and guided protection. Together, they represent the most prescriptive infrastructure security framework the EU has ever published.

GitProtect 2.4.0: Complete QA Protection in Azure DevOps, FIPS-Compliant Encryption, and More

The new 2.4.0 release delivers complete protection for your entire Quality Assurance (QA) workloads in Azure DevOps. Teams on platforms hosted locally in Windows can now secure them with the AES encryption compliant with the federal, enterprise-grade FIPS standards. This release also packs other notable upgrades, including seamless Active Directory integration, a smarter repository exclusion mechanism, and full German language support. Dive into the full breakdown below.