Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

The EU Cyber Resilience Act Has Global Implications - Who Needs to Prepare and How?

The European Union has made great strides to enhance cybersecurity over the past few years, with a comprehensive framework of core legislative acts designed to protect critical infrastructure. The EU Cyber Resilience Act, originally published as Regulation (EU) 2024/2847 on 20 November 2024, and entered into force on 10 December 2024, shifts the burden of proof so that manufacturers must now show their software is secure, not just claim it.

Keeper Security Named a Leader in the 2026 GigaOm Radar Report for Enterprise Password Management

GigaOm has recognized Keeper Security in the Enduring Innovators quadrant of its 2026 Radar Report for Enterprise Password Management. This marks the fifth consecutive year that Keeper has been named a Leader in GigaOm’s evaluation of the enterprise password management market. The report recognizes Keeper’s continued innovation, architectural depth and ability to help organizations secure more than just passwords.

Australian Privacy Principles: A compliance guide for small businesses

Accelerating security solutions for small businesses‍ Tagore offers strategic services to small businesses. A partnership that can scale‍ Tagore prioritized finding a managed compliance partner with an established product, dedicated support team, and rapid release rate. Standing out from competitors‍ Tagore's partnership with Vanta enhances its strategic focus and deepens client value, creating differentiation in a competitive market.

Noodle RAT: A Recipe for Cross Platform Espionage

Noodle RAT—also known as ANGRYREBEL or Nood RAT—is a modular remote access trojan (RAT) with dual versions for Windows and Linux, actively used by Chinese-speaking threat actors since at least mid-2016. It was previously misclassified as variants of Gh0st RAT or Rekoobe but is now recognized as a unique backdoor family.

Introducing Guardian Agents: Meet Blue Agent, Your AI Security Analyst

AI agents are moving into production faster than security teams can govern them. And unlike traditional applications, agents continuously make decisions, invoke tools, access data, and take actions. Every one of those interactions creates security context that needs to be understood. At enterprise scale, asking analysts to manually evaluate every finding becomes impossible.

Social Engineering Campaign Uses Phony NDAs to Avoid Detection

Researchers at Gen Digital are tracking a sophisticated social engineering campaign that’s using phony NDA documents to trick employees into moving the conversation to WhatsApp and personal email accounts. The attackers targeted an employee at Gen itself, but the employee recognized that it was a scam and played along to see what the attackers would do. The threat actors first impersonated a real Gen executive based in Dublin, who introduced a second impersonated person who claimed to work at PwC.

Warning: "Slop Squatting" Directs AI Users to Phishing Pages

Threat actors are increasingly leveraging AI hallucinations to plant phishing links and other malicious content in AI output, IEEE Spectrum reports. Large language models (LLMs) sometimes fabricate information, including web domains, when answering users’ questions. Attackers are registering these hallucinated web domains to host phishing pages.

Device inventory is not privileged account discovery

A device inventory tells you where the machines are, while a privilege inventory tells you where an attacker can go. An endpoint record can show that a machine exists, who owns it, and whether a management agent has checked in. It does not show who can administer that machine. That distinction matters because an attacker doesn't need a complete asset inventory. A valid privileged path to one useful endpoint may be enough.

What Is ML-KEM? Guide to NIST's Post-Quantum Key Encapsulation Mechanism

Quantum computers are likely to render the current public-key cryptography used for protecting modern internet traffic, digital signatures, and encryption useless. In response, NIST has developed ML-KEM as the main post-quantum key encapsulation method. The guide below will introduce the concept of ML-KEM, how it functions, in which projects it is used, and how organisations can implement it.