Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

The Cybersecurity Visibility Gap: What You Can't See Can Still Hurt You

Most security programmes are built to watch the inside of the network, but the threats that do the most damage often start outside it: leaked credentials, impersonated domains, dark web chatter, and vulnerabilities under active discussion. This post looks at why the visibility gap exists, what the data says about it, and what closing it involves.

CYJAX Joins the UK Cyber Security Council

CYJAX joins the UK's professional body for cyber security, reinforcing its commitment to developing cyber talent, upholding the highest ethical standards and helping strengthen the future of the profession. CYJAX is proud to announce that we have become a corporate member of the UK Cyber Security Council, the independent professional body dedicated to advancing the cyber security profession across the UK.

Cyber Threat Intelligence for Insurance: The Supply Chain Risk Insurers Can't Ignore

A strong internal security score means little if the brokers, claims processors, and software vendors an insurer depends on are the weak link. This blog breaks down where insurance supply chain risk sits and what to do about it.

From Social Media to Dark Web Forums: Monitoring Threats Across the Web

Cyber threats rarely start in hidden corners of the internet. Most begin in plain sight, on social media, before moving into Telegram channels and dark web forums. This blog looks at why organisations need visibility across the open and underground web, and how CYJAX connects the two into one picture of risk.

CYJAX Intelligence Now Lands Directly Inside Google SecOps and Microsoft Sentinel

CYJAX intelligence is now built directly into Google SecOps SIEM and Microsoft Sentinel, giving analysts structured, normalised threat data inside the platforms they already use. Four feeds are live in Google SecOps and eight endpoints are available in Microsoft Sentinel's Content Hub.

Domain Monitor Now Catches the Impersonation Attempts Keyword Matching Was Built to Miss

Domain Monitor's detection engine has been rebuilt to catch impersonation domains that keyword matching was never built to find. This release covers the new evidence-based matching engine, per-keyword Low, Medium and High thresholds, and what's coming next as the improvements roll out in stages. Domain Monitor's detection engine has been rebuilt from the ground up.

Threat Actors to Watch: Akira and Storm-1175

From a ransomware-as-a-service group that can move from initial access to full encryption in under four hours, to a China-linked affiliate that has quietly pivoted to its own encryptor, these two threat actors show how mature the ransomware ecosystem has become. CYJAX breaks down what each group does, why they matter, and what security teams should know.

Cyber Threat Intelligence for Fintech: A Sector Built for Speed, Targeted for the Same Reason

UK fintech is one of the country's fastest-growing sectors, but its reliance on APIs, partnerships, and real-time data makes it a prime target for cybercriminals. This blog explores why fintechs are so exposed, what the latest UK data reveals about breach costs and supply chain risk, and how cyber threat intelligence helps firms grow securely.