Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

From Blame Culture to Reasonable Challenge in 2025

The 2025 review highlights how blame culture still drives incident hiding in cybersecurity, even as risk grows. A simple “reasonable challenge” guide, with set phrases for raising and receiving concerns, offers a practical way in 2025 to support psychological safety, early reporting and better security governance.

No Snow Days for Security: How Reach Uses AI Agents to Find and Fix Hidden Risk

Security exposure doesn’t take a day off. Rain, snow or shine, environments keep changing. Controls drift. Configs break. Risk quietly piles up. Reach was founded to help organizations find and fix hidden risk and exposure. Traditional approaches surface issues — dashboards, alerts, findings — but stop short of actually fixing them.

Scan secrets in CI with ggshield (GitHub Actions example)

Next up is ggshield secret scan ci, the mode built for continuous integration, not your local machine. In this section, we’ll show how CI scanning works and why it’s different. Instead of scanning your whole repo, it scans the set of commits that triggered your pipeline, whether that build came from a direct push or a pull request. That means you catch secrets at the exact moment they’re introduced, before they get merged or released.

A New Model You Haven't Heard About (GitHub Raptor Mini)

Can an under-the-radar AI tool actually build a secure, functional CRUD note-taking app from scratch? In this video, I put GitHub Raptor Mini to the test to see if it can design, implement, and reason through a real-world CRUD application — including authentication, data handling, and basic security considerations.

Breaking Chain of Command in 2025 Security Decisions

The Razorwire Christmas Party 2025 episode looks at how decision culture shapes security outcomes across the year. Frontline staff need room to break the chain of command when something feels wrong, so protection in 2025 depends on people lower in the hierarchy raising hard questions and taking timely action. cybersecurity podcast, razorwire podcast, razorwire christmas party, razorthorn, 2025 cybersecurity review, decision making in security, breaking chain of command, frontline empowerment, zero trust culture, organisational trust, incident response decisions, helpdesk security, security leadership.

APT Teens, AI Voices and 2025 Helpdesk Attacks

The 2025 year in review episode shows how advanced threat groups rely on simple steps, from infostealer credentials to AI voice tools, to work through helpdesks. Native language, fake confusion and social engineering still unlock password resets in 2025, opening the door to ransomware and double extortion across networks.

Secret scanning with ggshield (repo, files, changes, commits, archives, Docker, and PyPI)

Now we’re getting to the heart of ggshield: secret scanning. In this section, we jump into ggshield secret and its two subcommands, ignore and scan. Ignore makes a lot more sense once you’ve seen scan in action, so we start by learning what ggshield can scan and why it’s so flexible across the development lifecycle. We’ll open the help menu so you can see every scan target available: ggshield secret scan -h.

AI Automation Dreams in the 2025 Security Budget Squeeze

The Razorwire Christmas Party 2025 review looks at rising expectations for AI and automation while security budgets stall in real terms. Automation in 2025 sits in a tug of war between cost cutting targets and the reality that attackers also use AI, so defensive upgrades have to match a live, adaptive threat.

When to Contact Your Bank About a Suspicious Charge

Fraud doesn’t start big. It starts quiet. Those small, unfamiliar charges (even $1) are often “test” charges scammers use to see what they can get away with. Contact your bank if: You see a charge you don’t recognize (even a small one) Your card suddenly declines mid-purchase You get alerts or texts about “unusual activity” Always verify through your bank’s official app or by calling the number on the back of your card.

miniTalks Podcast | DPDP, Digital Identity, and Real-World Compliance Gaps

India’s Digital Personal Data Protection Act is not just another compliance checkbox. It changes how identities, access, and data must be handled every single day. In this episode of miniTalks by miniOrange, host Puja More speaks with Gaurav Bansod, Director of Strategic Partnerships and Alliances at miniOrange and a PhD in Cybersecurity, to unpack what DPDP really means in practice.