Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Why Your Healthcare RAG Pipeline Is Leaking PHI (And How to Fix It)

Why Your Healthcare RAG Pipeline Is Leaking PHI Most healthcare organizations believe their AI assistant is secure once they restrict who can log in. Unfortunately, that's only part of the story. Modern healthcare AI applications rely on Retrieval-Augmented Generation (RAG), where patient records, physician notes, insurance claims, and medical documents are embedded into vector databases to power intelligent search.

Every laptop is a credential store: lessons from Vermeer

Your code repos aren't the only place secrets hide — your laptop is too. In this session, GitGuardian's Emanuelle Franquelin talks with CJ May, Cybersecurity Architect at Vermeer, about extending secrets detection beyond the codebase and onto developer endpoints. They dig into where credentials actually live on modern machines (think config files, shell history, and AI coding agents), why every workstation is fair game, and what to actually do once you find exposed secrets. Watch to see how one enterprise team is tackling credential sprawl to deploy AI safely.

11:11 Cloud Demo | 30 Minute Walkthrough of the 11:11 Resilient Cloud Platform

When moving on-premises applications to the cloud or establishing a hybrid cloud strategy — whether for production, data protection, or disaster recovery — 11:11 Cloud provides the right VMware-based environment to meet your needs for performance, security, and cost while also fortifying defenses, improving availability, and creating flexibility. Watch this half-hour demo to see the 11:11 Resilient Cloud Platform in action.

11:11 Object Storage Demo | 30 Minute Object Storage Walkthrough

Whether it’s backup storage, reclaiming capacity of on-premises data, or replacing an outdated tape archive, you can securely store data offsite in the cloud with 11:11 Cloud Object Storage. Managed through the Cloud Console, archive and back up short- and long-term data with S3 compatibility. Watch this half-hour demo to see 11:11 Object Storage and the 11:11 Cloud Console in action.

11:11 Systems Disaster Recovery as a Service Demo | 30 Minute DRaaS Walkthrough

Whether from cybercrime, hardware failure, or natural disasters, unplanned downtime can result in long-term damage to your organization, including revenue loss, customer churn, or the inability to continue business operations.

11:11 Systems Network as a Service Demo | 30 minute NaaS Walkthrough

As networks grow more complex, 11:11 Network as a Service (NaaS) makes it easy to connect, secure, and manage your entire environment. From SD-WAN and managed firewalls to hybrid and multi-cloud connectivity, our fully managed service improves performance, strengthens security, and reduces operational burden.

Jason Chan has 26 minutes to shut down a hacker hidden in plain sight (Live Tabletop Exercise)

What do you do when an attacker doesn’t break into your network, but simply walks in by turning your own multi-factor authentication against you? In this episode of The Tabletop, Jason Chan takes the hot seat and works the problem in real time.

Ep. 68 - Why OWASP's AIVSS Scores Agentic AI at Maximum Risk

OWASP just shipped AIVSS — an entirely new vulnerability scoring methodology built for autonomous AI agents, where a compromised orchestrator can score a perfect 10. Host Tova Dvorin and Adrian break down the "amplification principle": why a 2.1 CVSS finding becomes a 7.1 in the wrong agent, how persistent memory and broad tool access expand every blast radius, and what EchoLeak-style attacks already mean for real deployments. Plus where adversarial exposure validation and SafeBreach's agentic AI coverage fit in.

Ep. 67 - The Axis of Disruption: APT41, Volt Typhoon, and the China-Russia Cyber Alliance

For years, Beijing and Moscow kept their cyber tools apart. Not anymore. Hosts Tova Dvorin and Adrian Culley unpack the "no limits" partnership gone operational — the ESA/Galileo satellite attack where a Chinese Volt Typhoon cell opened the door and Russian AcidRain wiper code did the damage. We cover: APT41 running Russian exploit kits, Salt Typhoon pre-positioned in US telecom, China's 72-hour zero-day disclosure law feeding vulnerabilities to Russia, and the CVSS-10 Grimbolt flaw. Why continuous validation and a CTEM program are your best defense against the axis of disruption.

Ep. 66 - Poisoned Pipelines: TeamPCP and the FBI Flash on Weaponized Dev Tools

A criminal crew with APT-grade patience is trojanizing the very tools defenders trust. Host Tova Dvorin sits down with Adrian Culley to break down FBI FLASH-20260702-01 (coordinated with CISA) on TeamPCP — the group compromising Trivy, KICS, LiteLLM, and the Telnyx SDK to sit inside CI/CD pipelines. Inside: the CanisterWorm and SANDCLOCK credential stealers, the self-replicating "Mini Shai-Hulud" worm across npm and PyPI, npm account takeovers via expired recovery domains, and five concrete defenses — starting with searching your GitHub org for "tpcp-docs" right now.