Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Cyber Resilience Act is here! Myth busting and first impressions

The first deadline of the Cyber Resilience Act went live last week. The Cyber Resilience Act (CRA) is the new EU regulation that defines minimum cybersecurity requirements for all products with digital elements, including their building blocks (hardware and software). It applies to anyone placing products on the EU market, not just companies based there. The full requirements won’t go into effect until the end of next year.

The Agent Will See You Now: Why Healthcare's AI Agent Boom Needs Visibility and Control

Ask AI to Choose a prompt Write a TLDR of this post Explain the security risk Summarize what CISOs should know Healthcare, as an industry vertical, is moving faster on agentic AI than it has in past technology evolutions. Some reports say it is outpacing other regulated industries. Ambient scribes are documenting patient visits in real time. Prior-authorization and revenue-cycle agents are handling payer workflows that used to require staff to log into multiple systems manually.

What It Takes to Say an AI Control Reduces Loss by a Number

Saying a control reduces exposure is easy and almost always true. Saying it reduces exposure by a specific amount is a different claim, and the machinery for producing one is well established. Set a baseline from frequency and magnitude ranges, simulate, re-estimate the ranges with the control in place, simulate again, and report the difference. ‍ The method is sound. Applied to AI controls it runs into two problems, one about which term the control touches and one about what the estimate rests on.

The Blind Spot in Brand Protection: Why App Stores Slip Past Standard Monitoring

Most brand protection solutions rely on one assumption: scam activity happens on the open web. Security teams focus on catching fake domains, social profiles, marketplace listings, paste sites, and dark web forums. While that covers a lot of ground, it leaves out a major risk: the official app stores.

The Human Side of Cyber Resilience: What's Often Overlooked Before a Crisis

Organizations spend considerable time preparing for the technical realities of a cyber incident. Detection capabilities, containment procedures, recovery plans and governance structures are all essential. Yet many of the factors that shape the success of a response have little to do with technology. The most effective incident response programs recognize that cyber resilience is shaped as much by people as technology.

Remote Work Security & Endpoint DLP: How to Prevent Exfiltration on Distributed Laptops

The corporate security perimeter has changed. An employee’s company laptop could easily arrive at work on a Monday morning connected to a home Wi-Fi network, then land in a hotel or workspace at noon on a Tuesday and work away from a hotspot on Wednesday. That leaves corporate data outside the reach of traditional IT and security controls.

What Is Cybersecurity? Types, Threats, and Best Practices

As more businesses are becoming dependent on technology, the role of cybersecurity is more crucial than ever. With so many systems and applications in use, it is difficult to manage and protect devices and data against cyberattacks and unauthorized access. No single tool or team can secure an organization alone. Businesses today use cloud platforms, third-party applications, and remote endpoints, which increase the attack surface.

Graphalgo campaign spreads to Terraform providers and Go Modules

We’ve identified Go malware distributed via at least two Terraform providers and at least two Go Modules. This is the first time we’ve observed malware distributed via Terraform providers. The following packages contain the malware: The malware overlaps with the Graphalgo NPM malware campaign, first reported by ReversingLabs in February 2026, and also reported on in the last week by Safedep, CheckMarx, and JFrog.