Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Avoid Azure secret rotation with secretless authentication

Many observability platforms authenticate to Microsoft Azure by using client secrets. Teams must create, store, and periodically rotate these secrets to keep receiving the telemetry data that they need. This recurring maintenance adds operational overhead and increases the risk of ingestion outages that occur when secrets expire.

The Agent Baseline: 35 controls, but where should you start?

Two weeks ago, we published the Agent Baseline alongside Docker and Keycard. In it, we describe six security outcomes, 35 controls, and an open reference architecture for running AI agents at the enterprise level. Last week, we stress-tested it: we took it to a panel at Black Hat and spent about one hour being asked hard questions about it. Play Video: Snyk x Docker x Keycard | Agent Baseline Panel @ Black Hat 2026 The most useful question came from someone who had actually already read it.

Reflections from Black Hat: Speed Is Table Stakes. Resilience Is the Win.

Black Hat 2026 came just weeks after the Five Eyes cybersecurity agencies — CISA, the UK’s NCSC, Australia’s ACSC, Canada’s CCCS, and New Zealand’s NCSC-NZ — issued a joint statement to boards and executives with the blunt message that AI is rewriting the rules of cyber risk, the window between vulnerability and exploitation is shrinking, and organizations have a matter of months to adapt.

Microsoft Defender Patch Bypass: High Severity Zero-Day Privilege Escalation (CVE-2026-50656/RoguePlanet, ShieldBreak)

A critical zero-day vulnerability (CVE-2026-50656/“RoguePlanet”) in Microsoft Defender’s Malware Protection Engine (mpengine.dll) enables local users, including standard, low-privilege accounts, to escalate privileges to NT AUTHORITY\SYSTEM using a race condition and improper link resolution. Microsoft initially issued a patch (Engine v1.1.26060.3008) in July 2026.

The Industrialized Fraud Hiding in Plain Sight

To read more on this story and the significance of Business Email Compromise (BEC), visit The Wall Street Journal where Dave Burg was interviewed (subscription required). A few months ago, scammers hijacked a routine infrastructure project in Surfside Beach, South Carolina, costing the small town $545,000. The scheme stemmed from a single spoofed email sent from a lookalike domain, instructing the town to switch payment from check to ACH.

Black Hat Proved AI Agents Are Already the Attack Surface

Enterprise AI agents stopped being a pilot project a while ago. They read email, touch source code, operate browsers, and increasingly make decisions inside production systems, which means the security model built for chatbots and prompts no longer covers what is actually happening inside the enterprise. Black Hat USA 2026 turned out to be the week that gap became impossible to ignore.

Coding Agent Risk for CISOs: Blast Radius, Governance, and Where to Start

Claude Code, Cursor, GitHub Copilot, and Gemini CLI are running on developer machines across your enterprise right now. They're browsing the web, writing to your filesystem, committing code to your repositories, and calling external APIs under the identity of your engineers. Most security teams have no visibility into any of it. This isn't a future problem.

Navigating SAMA, ADGM & DFSA Requirements with Teleport

The Middle East, especially the UAE and Saudi Arabia, has become a priority market for cloud service providers (CSPs) as governments accelerate digital transformation across public and private sectors. The opportunity is real, but so is the complexity. In our work with clients and regulators, Coalfire has seen that market entry often hinges less on commercial certifications and more on meeting strict data sovereignty and cybersecurity requirements.

AI Security Posture Management: What It Covers and What It Misses

AI Security Posture Management arrived as a term before it arrived as a definition. Vendors announced products under the label through 2025 and in volume at RSA Conference 2026, each describing a somewhat different scope, and buyers now evaluate a category whose boundaries depend on who is selling. The lineage is evident, since AI-SPM follows cloud and data security posture management, and the inherited assumptions are where the difficulty starts.

Building a Security Budget Case With Return on Security Investment

Security budget requests fail on arithmetic rather than on argument. A finance function asked to approve spending wants the same information it requires from every other proposal, being what it costs, what it returns and over what period. Most security cases supply the first, describe the second qualitatively, and omit the third. ‍ Return on security investment closes that by expressing the benefit as reduced modeled loss rather than as reduced likelihood of an unspecified bad outcome.