Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

The Consent Compliance Paradox: Why Having a CMP Isn't the Same as Having Consent

Here’s a question I’ve started asking privacy and security leaders in almost every conversation: if I asked you right now to list every script collecting data on your website, could you do it? If I then asked how many of those scripts are overwriting consent preferences, would you know? Most people pause. Some laugh. A few say yes with real confidence. But when we run the audit, the answer is almost always more complicated than they expected.

Feroot Expands DXComply with Code-Free Consent Auditing for Native Mobile Apps

New DXComply release enables privacy, GRC and security teams to verify whether native apps honor user consent choices without SDK integration or code changes. Toronto, Canada, September 23, 2026: Feroot Security Inc. today announced expanded native mobile application consent auditing capabilities in DXComply, enabling enterprises to verify whether iOS and Android apps honor users’ consent choices without requiring SDK integration or changes to application code.

Why Critical Infrastructure Needs Zero-Trust Security

Malicious cyber activity targeted remote monitoring and control technology at over 30 community water systems across Minnesota in late July 2026, and water cyber attacks were subsequently reported across at least 12 states. However, the underlying OT security weaknesses are not exclusive to the water sector.

AI Has Entered the SOC. Governance Has to Catch Up.

ISO/IEC 42001 is the international standard for Artificial Intelligence Management Systems. For CISOs, the bigger question is whether governance reaches all the way into the security workflows where AI is beginning to act. Beth Dannemiller, Senior Director, Product Marketing For the last several years, CISOs have been asked a familiar question by boards: What are we doing with AI? That question is changing.

CT alerts: know when someone gets a certificate for your domains

A couple days ago, I told you how a spammer got a certificate for dev-docs.trackjs.com, and that we only found out because Google emailed us. Google knew because the spammer claimed the hostname in Search Console. An attacker running a phishing page wouldn’t have done that, but they would still need a certificate. Every publicly trusted certificate gets written to a public log, and we track that log in our database. We just weren’t watching it. Now we are, and you can too.

Egnyte Named a Leader in the IDC MarketScape: Worldwide Intelligent Content Services 2026

We’re thrilled to let you know that Egnyte has been named a Leader in the IDC MarketScape: Worldwide Intelligent Content Services 2026 Vendor Assessment (#US54137426, September 2026). IDC’s report evaluates vendors on the strategies and capabilities that matter as content platforms become the foundation for enterprise AI.

Stop Chasing Tabs: Bringing Threat Research Home to the Browser

We all know the routine. You’re deep into a new threat report or a breaking blog post, and the tab management anxiety starts to kick in. You find a suspicious indicator, copy it, pivot to your internal tools to see if you’ve seen it before, paste it into a notepad, and then—maybe—try to get it into an actual investigation. By the time you’ve validated the intel, you’ve lost the trail. Threat research happens in the browser. Its time your workflow did too.

ISO/IEC 42001 and the Governance Gap Between Pilot and Production

In July 2025, a Replit coding agent deleted data from an application’s production database during a public experiment. The data was recovered, and Replit responded by separating development and production databases, limiting the agent’s access to the development environment, and strengthening the recovery experience. It later introduced a planning mode that allowed users to work with the agent without changing code or data.

How to Evaluate and Choose the Best GRC Software in 2026

Evaluating GRC software in 2026? Every platform says it covers governance, risk, and compliance. What a demo will not show you is whether it runs on one connected system or a stack of separate tools sharing a single login, and that difference decides whether you can answer leadership on the spot or spend a week rebuilding the picture. This video walks through five criteria for judging any GRC platform, and the question to ask a vendor on each one.