Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Report: Vishing and Device Code Phishing Are Surging

Social engineering remains a central part of modern cyberattacks, according to a new report from CrowdStrike. Attackers are increasingly turning to voice phishing because it bypasses traditional security controls and leaves little forensic evidence, since the social engineering takes place over the phone.

Securing the Tip of the Spear: Guam's Path to Human and AI Resilience

As the Asia-Pacific and Japan (APJ) region continues its rapid digital acceleration, Guam stands at a unique strategic intersection. Serving as a critical hub for telecommunications, government services and regional defense, the island’s cybersecurity posture is no longer just a local concern, it is a cornerstone of regional stability. I have observed a proactive shift toward onboarding various agencies to a unified security framework.

GitProtect vs. Native Microsoft 365 Backup

Summary Organizations often assume their Microsoft 365 assets are fully protected by native backup tools. However, while Microsoft does offer advanced built-in backup and recovery features, relying solely on a native approach is not a substitute for an independent, enterprise-grade backup strategy. The risks of relying on a single ecosystem for backups are escalating.

AI Isn't Creating New Cyberattacks. It's Changing How They Operate

Artificial Intelligence has quickly become one of the most important conversations in cybersecurity. Much of that conversation focuses on what attackers might create next: AI-generated malware, deepfakes, autonomous attacks, or entirely new categories of threats. Those risks matter, but focusing only on new attack techniques misses a much larger transformation already taking place. The real impact of AI is not only what attackers can create. It is how efficiently they can operate.

Propagating User Identity From AI Agents to Your Tools: Amazon Bedrock AgentCore Gateway and JFrog Artifactory

Join us at swampUP New York, September 1-3, for our joint session Trusted AI Delivery at Scale: Securing Every Artifact from Curation to Cloud, where we walk the full chain of custody from the moment a package enters your organization to the moment your agent runs on Amazon Bedrock AgentCore. Register here. AI agents are becoming real users of internal systems. They open pull requests, run queries, and pull and publish artifacts in repositories like JFrog Artifactory.

AI Prompt Data Leakage: How to Secure Sensitive Data in LLMs

As generative AI adoption surges, so does a dangerous new enterprise risk: AI prompt data leakage — the unintentional exposure of confidential corporate data to third-party Large Language Models via user prompts. Why does it happen? Driven by productivity pressure and the need to speed up their work, employees routinely bypass traditional DLP controls.

How to Set up Backup and Recovery on Your Own Kubernetes Cluster in 5 Minutes

Regulation is doing more to shape backup strategy right now than almost anything else. NIS2 requires organizations to document their risk management measures, keep an incident response plan on file, and report breaches within 24 hours, with fines that can reach €10 million or 2% of global turnover. DORA goes further for financial entities, requiring documented recovery objectives, regular resilience testing, and an audit trail that holds up to a regulator’s questions.

Maturity Is a Lagging Indicator. Here's a Leading One.

A maturity score answers where a program has been. It reports the state of documented process at the moment somebody assessed it, on a cadence measured in quarters or years, using a scale that describes organization rather than outcome. Every property that makes it useful for planning makes it useless as an early warning. ‍ The interesting question is what a leading indicator would look like instead, and the answer requires separating two problems that get treated as one.

What Counts as One AI Asset? Getting the Unit Right

Two teams inventory the same organization and return different numbers. One counts forty-one AI assets, the other counts one hundred and twelve. Neither is wrong, because they counted different things, and nobody had decided what a row represents. ‍ Guidance on building an AI inventory covers which fields a row should carry and skips what a row is. That question determines the count, the risk scores, the regulatory classification and whether two inventories can ever be reconciled.

Beyond the Compliance Snapshot: Why GRC Needs Continuous Evidence

I recently had the opportunity to speak at the ISACA GRC Conference in San Diego about a challenge I see becoming increasingly important for governance, risk, and compliance teams: How do you prove your controls are actually working in digital environments that never stop changing?