Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Non-human identities (NHIs) explained and how to secure them

Non-human identities are the fastest-growing and least-governed identity population in most environments. Service accounts, API keys, and AI agents run without MFA, without owners, and without expiration. Traditional identity and access management (IAM) wasn't built to manage them. Without governance for discovery, ownership, and lifecycle management, stale machine credentials become attacker footholds that persist for months.

The new AI access problem: Why machine identities now drive trust in banking

In my experience working inside banks, identity security can be like plumbing: when it’s working, no one wants to talk about it. When there’s an incident, an audit, or a regulator—suddenly everyone wants to understand how it works. Artificial intelligence (AI) brings the same “no one cares until everyone does” energy, but with face-melting velocity. Today, AI is embedded across large parts of the financial services industry, and it has been around for more than 25 years.

Post-incident review: Source map exposure on non-production subdomain

Update (February 24, 2026): @vmfunc has published part two of their series about Persona. You can read it here. We will update this post with part three when it is released. On February 16, 2026, security researchers @vmfunc, @MDLcsgo, and @DziurwaF published a blog post identifying exposed frontend source maps on a non-production subdomain under withpersona-gov.com.

Difference between Network DLP vs Endpoint DLP vs Cloud DLP

When it comes to protecting business-sensitive data, understanding the difference and the scope of Network DLP, Endpoint DLP, and Cloud DLP is essential. Each of these Data Loss Prevention solutions (DLP) plays a unique role in securing data across various environments, whether it is on the Network, on individual devices, or in the Cloud. Knowing how each solution works can help you determine the best approach to safeguard your organization's sensitive information.

What is Data Loss Prevention (DLP)?

Data Loss Prevention (DLP), also called data leakage protection, is a cybersecurity approach designed to detect, prevent, and manage unauthorized access, sharing, or transfer of sensitive information. In simple terms, DLP helps organizations keep control of critical data such as personally identifiable information (PII), financial records, credentials, and intellectual property (IP).

How to detect the new wave of document fraud

Supplemental document checks are often required for businesses that conduct Know Your Customer (KYC) or Know Your Business (KYB) checks. Even when compliance isn’t required, organizations often collect supplemental documents for their own business purposes, such as risk assessments. In business contexts, a supplemental document is a non-government-issued document that you collect to support a risk assessment.

3 fraud vectors to watch: synthetic identities, deepfakes, and identity mules

Audiences around the world may be captivated by dramatic stories of con men like the Tinder Swindler. But this type of fraud is the exception rather than the rule. Most criminals go to great lengths to stay hidden and minimize the risk of getting caught. Sometimes, though, a criminal needs to show their face — or at least, a face — to pass identity checks.

Simplifying how businesses pay creators and contractors worldwide with Trolley - S2E10

In this episode, we're excited to introduce Barnett Klane, VP of Product at Trolley, the leading payouts platform powering the internet economy. Trolley enables businesses to automate global payments to creators, freelancers, and contractors across 210+ countries and territories, serving major companies. Barnett previously founded MyManual and held product roles at Bugcrowd, bringing deep expertise in building products at the intersection of payments, compliance, and creator platforms.

miniOrange, Securing the SDLC End-to-End | Podcast with Rakesh Falke

Security can’t be an afterthought. In this podcast, Puja More in discussion with miniOrange Engineering Manager Rakesh Falke on embedding security across the SDLC-from architecture (DFDs, sensitive data, GDPR) to secure coding, secrets management, and production hardening. Learn common developer pitfalls, app vs infra security, IaC (Terraform), and how AI tools (Cursor) plus Burp Suite speed up vulnerability detection.

Why a global identity strategy requires local governance

For years, identity has been treated as a supporting function, authenticating users, gating access, and satisfying audit requirements. Important, but rarely foundational. That era is over. In modern enterprises, identity has become the infrastructure on which critical systems depend. Every workload, certificate, API, automated process, and AI-driven action must rely on identity to operate safely and predictably. When identity fails, those systems become exposed—and often stop behaving as expected.