Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Your AD is a stomping ground for lateral movement

Active Directory (AD) is the backbone many enterprises lean on for their IT environments. Yet, most organizations rarely govern the directory with the scrutiny necessary. This was the throughline of a recent webinar with Nitish Deshpande, senior analyst at KuppingerCole, and Robert Kraczek, global strategist at One Identity. The pair made a strong case for mediating admin access to AD, emphasizing just how easily compromised credentials can beget full-blown incidents.

SSH Session Monitoring: How to Monitor, Record & Audit SSH Sessions

Secure Shell (SSH) gives you direct access to critical servers, databases, and cloud infrastructure. Once a privileged user connects through SSH, they hold extensive control over that system. They can alter core configurations, run terminal scripts, move files, or delete production databases in seconds. If you lack visibility into privileged actions, it can be risky. If a credential gets stolen or an insider goes rogue, traditional firewalls won’t be enough.

Scaling DevSecOps: The Role of a Comprehensive Application Security Platform

Exploitation of software vulnerabilities is now the number one cause of breaches, according to the 2026 Verizon DBIR Report. At the same time, release velocity keeps climbing and AI coding tools are now authoring roughly half of all committed code in organizations that use them. For application security and engineering teams, the math is unforgiving: more code, faster delivery, and a growing attack surface.

8 Key DLP Use Cases Every Enterprise Should Know

Most enterprise data loss prevention (DLP) programs get judged on a single metric: how many exfiltration attempts did it block last quarter. That framing undersells what a modern DLP program needs to do. Sensitive data now leaves through AI prompts, personal cloud accounts, and agent-initiated file transfers that a legacy blocking rule alone was never built to catch, while auditors and boards expect evidence that the program is working, not just alerts confirming it.

When a Cyber Loss Becomes a Recall

Cyber loss models are built around information leaving an organization. Records exposed, notification costs, regulatory penalty, litigation from affected individuals. Every category assumes the harm is informational. ‍ A compromise affecting vehicles in the field produces something the model has no term for. The vehicle can behave differently, the manufacturer may have to recall it, and the recall cost is frequently larger than anything the cyber categories would have produced. ‍

What an AI Correlation Rule Does When Sources Disagree

A correlation rule joins records from several sources to establish that one thing happened. Two of those sources return different answers about the same identity, the same session or the same action. Something has to happen next, and what most systems do is pick a winner. ‍ Picking is the wrong default. The disagreement carries information that resolving it discards, and in a few specific cases the disagreement is the most useful thing the system produced. ‍

Seeing Every MCP Connection: Zenity Joins the Cursor Marketplace

Cursor has become one of the primary AI coding environments for development teams, and its agents increasingly reach into the outside world through MCP servers: databases, ticketing systems, cloud consoles, and internal APIs. Every connection extends what an agent can do. It also extends what could go wrong if that access goes unmonitored or unchecked.

Agentic AI Security Buyer's Checklist: 15 Questions to Ask Before You Sign

Buying agentic AI security software is a fast-moving decision with high stakes. Get it wrong, and your security team ends up chasing agent activity it cannot see, while attackers exploit business logic gaps that no prompt filter was built to catch. This checklist gives security and platform leaders a structured way to evaluate vendors before signing, based on the questions that actually separate a purpose-built platform from a bolted-on feature.

Detection scaled. The loop did not.

Findings got cheap. Verified closure did not. That AppSec remediation gap is the actual problem. AppSec spent a decade winning the wrong race. We got very good at finding things. Scanners in CI. SCA on every manifest. SAST on every pull request. Container and IaC checks on the way to the cluster. Then AI arrived and did what AI does to a solved problem: it made discovery cheaper, louder, and continuous. The same model that writes the function will also enumerate the ways to break it.

Acronis denial-of-wallet protection: Managing runaway AI usage before costs spike

With most cyberattacks, the problem announces itself. A service goes down. A user cannot log in. An alert fires. Denial-of-wallet is different. The application keeps working normally while the cost of running it climbs in the background. That is what makes it a security problem and not only a budgeting one. The goal is not to take a system offline. It is to make the system do expensive work that nobody asked for.