Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

How To Eliminate Secrets Configuration Drift Between Your Vault and the Cloud

You might treat a centralized vault as the authoritative source for every secret, but secrets can quietly fall out of sync as they get copied into cloud secret stores, CI/CD pipelines and running workloads. This is referred to as secrets configuration drift, and it can leave outdated or standing credentials, API keys and other secrets active for longer than intended.

Recognizing and detecting data exfiltration

Every breach that lands a CISO in front of the board has a common final act: Data leaving the building. Attackers don't get paid for breaking in. They get paid for what they take out. And by the time stolen data appears on an extortion site or in a regulator's inbox, the window to stop the damage has already closed. That is what makes exfiltration so dangerous. It rarely looks like an emergency.

OT: The Other Technology Evolution

Written by Bill Moore, CEO & Founder TL;DR In Part 1 of this series, I looked at how computing and telecommunications gradually became what we now call Enterprise IT. That change did not happen because someone decided to merge two departments. It happened because the technologies, the systems, and the work they supported became too interconnected to describe separately.

Enforce custom rules in Datadog IaC Security scanning

Infrastructure-as-code (IaC) security scanning can catch common misconfigurations before deployment, but every organization also has internal requirements that a default rule catalog cannot cover. For example, teams may need to enforce required tags, approved instance types, or naming conventions. With custom rules for Datadog IaC Security, security and platform teams can define these requirements as Rego policies and run them alongside Datadog’s default rules during IaC scans.

PQC Post Quantum Cryptography Explained: Why Today's Encryption Has an Expiration Date

The encryption protecting today’s data isn’t broken, but it does have a timeline. This video breaks down why current systems like TLS, PKI, and RSA remain secure today, and how quantum computing will change that. As progress accelerates toward large-scale quantum machines, organizations must prepare for a new era of security. Learn how PQC (post-quantum cryptography) helps address emerging risks like “harvest now, decrypt later,” and why tracking adoption of quantum-safe encryption is critical now, not later.

CVSS Scores Alone Can Mislead Vulnerability Prioritization

Not every high-severity vulnerability represents the highest risk. Learn why effective prioritization requires more than a CVSS score and how factors such as reachability, exploitability, active exploitation, and asset criticality provide the context needed to focus remediation efforts where they matter most.

Cineworld Glitch Purportedly Allows Users To See Member Card Details

On 17 September 2026, users on X (formerly Twitter) posted that payment details belonging to other individuals had appeared on the Cineworld app under their personal accounts. On 17 September 2026, users on X (formerly Twitter) posted that payment details belonging to other individuals had appeared on the Cineworld app under their personal accounts.