Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

CMMC Due Diligence in M&A: Successor Liability

Let's posit a hypothetical situation for you to think about. Let's say that you're a large company already CMMC-compliant and working with the DoD. You've identified a smaller company that offers a service complementary to your own, and you've decided to acquire that company. That smaller company claims to be CMMC-compliant, and you move forward with the acquisition.

Shopify Activity Monitoring: How to Detect Anomalies & Risk Before It Impacts Your Business

Every Shopify store runs on access. Staff update products, agencies manage campaigns, apps sync data, and AI tools are starting to act on behalf of teams. That flexibility is useful, but it also creates blind spots. A single unreviewed change can affect pricing, inventory, order accuracy, customer data, or storefront availability. For merchants, the real issue is not whether activity exists. It is whether that activity is visible, explainable, and monitored before it does damage.

What Is Identity Management: A Know-How for Scaling Enterprises

Whether a business runs 50 employees or 5000, it faces the same quiet risk every day: too many logins, too many devices, and not enough clarity on who can access what. This article has answers to it. This guide breaks down what identity management actually means, how it works under the hood, and how it differs from related concepts like access management and identity governance.

Agent Containment Lessons From OpenAI-Hugging Face Breach

An OpenAI model evaluation, run with safety guardrails deliberately reduced to stress test raw capability, broke out of its test environment and reached Hugging Face's production servers weekend of July 11–12, 2026, with disclosure occurring July 16. No human attacker, no jailbreak, just a model chasing a goal past a boundary that was supposed to hold. Most of the response to this incident has focused on the network boundary that failed: the sandbox, the proxy, or the zero-day.

Why Flipping Cyber Defense Backwards Works

Standard incident response is failing to keep pace with long-term threat campaigns. Adam Karcher from the FBI explains why the most effective security teams run their operations as an inverted offensive strategy, leveraging continuous adversary emulation to stop intrusions before they begin. Watch the full video on our channel.

How to Publish Multiple Policy Types in One Request: A Step-by-Step Guide

In this comprehensive guide, we will explain how to efficiently publish multiple policy types in a single request using the Fireblocks Policy Engine. This streamlined process allows you to update various policy types—such as transfer policies and typed message policies—simultaneously, ensuring that all changes are coordinated and compliant. Key Benefits of Multi-Type Policy Publishing.

How to Export Fireblocks Transaction Policies as CSV or JSON: A Step-by-Step Guide

In this comprehensive guide, learn how to export your Fireblocks transaction policies in both CSV and JSON formats. This video walks you through the process of selecting your policies, choosing the appropriate format, and securely downloading your data. Key Topics Covered: Exporting Policies: Understand how to access the active policy section from the Policy Overview screen. Choosing Formats: Discover the differences between CSV and JSON exports.

How to Use Policy Inspector to Diagnose Transaction Failures in Fireblocks

In this comprehensive guide, learn how to effectively use the Policy Inspector tool within Fireblocks to diagnose and resolve transaction failures. The Policy Inspector provides clear insights into which policy rules blocked a transaction and the reasons behind it, eliminating guesswork and streamlining communication with your security team. Key Features of Policy Inspector: Transaction Simulation: Test any transaction against your active policies directly in the console. Detailed Insights.

When the 'Attacker' Was an AI Agent: Lessons from the OpenAI-Hugging Face Breach

In this episode of Sophos Cyber Shorts, host Susie Evershed is joined by Ross McKerchar, Sophos CISO, to discuss the recent OpenAI and Hugging Face incident and what it reveals about the future of AI security. From containment failures and over-privileged AI workflows to faster AI-driven attacks, Ross shares practical advice for security leaders on how to strengthen resilience, response, and recovery.