Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

The Industrialized Fraud Hiding in Plain Sight

To read more on this story and the significance of Business Email Compromise (BEC), visit The Wall Street Journal where Dave Burg was interviewed (subscription required). A few months ago, scammers hijacked a routine infrastructure project in Surfside Beach, South Carolina, costing the small town $545,000. The scheme stemmed from a single spoofed email sent from a lookalike domain, instructing the town to switch payment from check to ACH.

Black Hat Proved AI Agents Are Already the Attack Surface

Enterprise AI agents stopped being a pilot project a while ago. They read email, touch source code, operate browsers, and increasingly make decisions inside production systems, which means the security model built for chatbots and prompts no longer covers what is actually happening inside the enterprise. Black Hat USA 2026 turned out to be the week that gap became impossible to ignore.

Coding Agent Risk for CISOs: Blast Radius, Governance, and Where to Start

Claude Code, Cursor, GitHub Copilot, and Gemini CLI are running on developer machines across your enterprise right now. They're browsing the web, writing to your filesystem, committing code to your repositories, and calling external APIs under the identity of your engineers. Most security teams have no visibility into any of it. This isn't a future problem.

Navigating SAMA, ADGM & DFSA Requirements with Teleport

The Middle East, especially the UAE and Saudi Arabia, has become a priority market for cloud service providers (CSPs) as governments accelerate digital transformation across public and private sectors. The opportunity is real, but so is the complexity. In our work with clients and regulators, Coalfire has seen that market entry often hinges less on commercial certifications and more on meeting strict data sovereignty and cybersecurity requirements.

Is your AI system secure enough? MITRE ATLAS Is Now Law.

For the first time anywhere, the MITRE ATLAS framework and the OWASP Top 10 for LLM applications are written into binding law. Article 15 names data poisoning, model poisoning, adversarial examples, model evasion and confidentiality attacks as threat classes you must have technical measures against—and must be able to evidence to a regulator. The question is no longer whether you have thought about AI security. It is whether you can prove your AI system holds.

Ep. 73 - EU AI Act-What Actually Lands on August 2nd, and What Slipped to 2027

The EU AI Act's August 2nd, 2026 deadline just changed shape. Host Tova Dvorin and offensive security engineer Adrian Cully separate what actually lands—Article 50 transparency duties and GPAI enforcement powers—from the high-risk obligations that slipped to December 2027. Inside: Article 15 writes MITRE ATLAS and the OWASP LLM Top 10 into binding law, the DORA / NIS2 / AI Act overlap that makes one incident reportable three times, penalties up to 7% of global turnover, and the five things a CISO should do this week. Part 1 of 2.

AI Security Posture Management: What It Covers and What It Misses

AI Security Posture Management arrived as a term before it arrived as a definition. Vendors announced products under the label through 2025 and in volume at RSA Conference 2026, each describing a somewhat different scope, and buyers now evaluate a category whose boundaries depend on who is selling. The lineage is evident, since AI-SPM follows cloud and data security posture management, and the inherited assumptions are where the difficulty starts.

Building a Security Budget Case With Return on Security Investment

Security budget requests fail on arithmetic rather than on argument. A finance function asked to approve spending wants the same information it requires from every other proposal, being what it costs, what it returns and over what period. Most security cases supply the first, describe the second qualitatively, and omit the third. ‍ Return on security investment closes that by expressing the benefit as reduced modeled loss rather than as reduced likelihood of an unspecified bad outcome.

What Are Syslogs and How They Power Modern SIEM Detection

You're in the middle of a noisy SOC shift, and a firewall alert lands late. The device was supposed to send logs over syslog, but the path was UDP-based and the network dropped the messages under stress. By the time an auditor asks for proof, the team has an investigation, a gap in the timeline, and no clean evidence trail to show what happened.

Insurance Is Still in the Crosshairs: What Recent Dark Web Chatter Says About Sector Targeting

Insurance has always been a data-rich industry. But recent threat intelligence makes it clear that attackers are not only going after insurers because they are large organizations. They’re going after them because insurance touches some of a threat actor’s favorite things: money, identity, healthcare, legal claims, third-party relationships, and highly sensitive customer records.