Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

The Cybersecurity Visibility Gap: What You Can't See Can Still Hurt You

Most security programmes are built to watch the inside of the network, but the threats that do the most damage often start outside it: leaked credentials, impersonated domains, dark web chatter, and vulnerabilities under active discussion. This post looks at why the visibility gap exists, what the data says about it, and what closing it involves.
Featured Post

Cyber Risk and Incident Response: A Growing Priority Across Industries

Cyber risk has become a dominant priority for organisations across nearly every sector. As the severity and velocity of the threat landscape and technological change continue to accelerate, organisations are under increasing pressure to ensure they can keep pace and recover quickly in the aftermath of a cyber event. A core focus for many organisations is strengthening their incident response capability: how effectively the business can react and recover when an attack occurs.

Astra Just Raised the Bar for AI-Enabled Attacks. Here's What That Means for Defenders

OpenAI published its assessment of its newest GPT model, Astra, and found it to be the first of their models to reach a critical level of cybersecurity capability, meaning that given the right tools and access, it could autonomously exploit previously unknown vulnerabilities. As a result, OpenAI has restricted Astra’s most advanced cybersecurity capabilities to trusted partners before a public rollout.

Why the best vendor relationships go beyond technology in Australia

Australian MSPs have no shortage of technology vendors. The difficult part is deciding which relationships will make the business stronger after the contract is signed. A product can perform well and still create friction if the commercial model is hard to explain, enablement is generic or support disappears when an opportunity becomes complicated. A strong vendor relationship connects technology, operations and go-to-market execution.

Introducing automatic remediation policies with Cloudflare CASB

Today, we’re making Cloudflare CASB more powerful than ever by introducing automatic remediation policies. This means security teams can now design event-driven logic to revoke risky file shares and dispatch custom webhooks, without manual intervention. When we launched Cloudflare CASB, a cloud access security broker, we wanted to provide security teams complete visibility into the posture of their SaaS applications before misconfigurations became incidents.

FBI Alert: OAuth Consent Phishing is Targeting Users of Messaging Apps

The U.S. Federal Bureau of Investigation (FBI) has issued an advisory warning of a wave of OAuth consent phishing attacks targeting “prominent victims, their family members, and personal acquaintances.” OAuth phishing is an increasingly popular social engineering tactic that tricks users into granting access to their accounts without handing over their passwords.

Survey: Companies Cite Phishing as their Top AI-Enabled Fraud Concern

A recent survey from Experian found that 60% of companies report fraud losses that are “somewhat or significantly higher” than in previous years, with a majority of respondents citing AI-generated phishing attacks as their top AI-related fraud concern. “Businesses identify AI-generated phishing as the most common AI-enabled fraud risk at 53%,” the report says.

13 essential cybersecurity frameworks, standards, and regulations explained

Security teams rarely work from a single rulebook. They may use the NIST Cybersecurity Framework to organize the program, ISO/IEC 27001 to build a formal management system, SOC 2 reports to assess vendors, and laws such as HIPAA, GDPR, DORA, or NIS2 to meet legal obligations. Those names are often grouped together, even though they serve different purposes. Some provide guidance. Some can be certified or independently assessed. Others are contractual requirements, laws, or mandatory sector standards.