Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

What is SLH-DSA? Hash-Based Post-Quantum Digital Signature Guide

SLH-DSA is NIST’s standardised post-quantum digital signature algorithm (hash-based). It generates quantum-resistant signatures, ensuring signatures are not changeable and that they will not be forged, even when later superseded by schemes like RSA and ECDSA, which are susceptible to attacks by quantum computers. Organisations are studying it today because large-scale quantum computers could, in the future, crack the algorithms that currently underpin most digital trust.

PQC Post Quantum Cryptography Explained: Why Today's Encryption Has an Expiration Date

The encryption protecting today’s data isn’t broken, but it does have a timeline. This video breaks down why current systems like TLS, PKI, and RSA remain secure today, and how quantum computing will change that. As progress accelerates toward large-scale quantum machines, organizations must prepare for a new era of security. Learn how PQC (post-quantum cryptography) helps address emerging risks like “harvest now, decrypt later,” and why tracking adoption of quantum-safe encryption is critical now, not later.

Cryptography is negotiated, not configured: Why PQC readiness needs network data

Post-quantum cryptography (PQC), and the many ways it intersects with IT and cybersecurity, is becoming increasingly important to organizations of every size. While it seemed like an esoteric concept a few years ago, relegated to cryptographers' conference talks, it’s now something that comes up in many of our customer conversations.

From Encrypted Mobile Traffic to Payment Manipulation

How KomodoSec’s AigentX Penetration Tester reverse engineered client-side encryption, turned the bypass into reusable Burp tooling, and used that access to validate a real business-logic flaw in a production mobile application. Client-side secrecy failed. Server-side trust became the real vulnerability. THE CHALLENGE A mobile app with TLS, certificate pinning, and a second encryption layer.

Why Network Privacy is Becoming a Critical Layer of Modern Cybersecurity

In 2026, network privacy has become a critical layer of modern cybersecurity. With cyber threats becoming increasingly advanced and businesses embracing hybrid work, cloud platforms, and interconnected systems, network security can protect data moving across networks and reduce exposure to cybercrime. This article will explore why network security is so important in 2026, the risks associated with unsecured connections, and how businesses can strengthen their posture. Read on to find out more.

Security by Design: Incorporating Cybersecurity into Early-Stage Software

In today's hyper-connected digital economy, launching a new software application requires balancing speed, innovation, and technological resilience. Early-stage founders and product teams naturally focus on building compelling user interfaces, refining core value propositions, and validating market demand as quickly as possible. However, treating information security as an afterthought or a secondary milestone to address post-launch creates massive operational vulnerabilities that bad actors can easily exploit.

TLS 1.2 isn't end of life, but it will be soon

You’re probably running a TLS configuration that the IETF says is “non-conformant”. But you didn’t do anything wrong. In July, the IETF published a pair of RFCs that took away three of TLS 1.2’s key exchange methods and froze the rest of it. The phrase they used is MUST NOT, the strongest thing a specification is allowed to say. Nginx, Apache, and Windows Server all ship with those key exchanges turned on by default. Nothing breaks tomorrow.

What is FileVault Disk Encryption?

If your organization uses a Mac, you’ve probably heard of FileVault. But what is it, exactly? And more importantly, do you actually need it? A lost Mac can become much more than an expensive replacement if you have sensitive business data in it. FileVault is one of the simplest ways to protect it. Apple provides it by default with macOS. It encrypts your startup disk, so your files stay unreadable if someone gets access to your Mac without your login.
Featured Post

The first short-lifespan TLS renewal wave is closer than it looks

If your organization runs anything on the public internet, a mandate that changes how often you renew TLS certificates is already in effect. In March 2026, the maximum validity of public TLS certificates dropped from 398 days to 200. What fewer teams have worked out is that the first certificates issued under the 200-day cap start expiring at the end of September. That makes this autumn the first real test of whether your renewal workflows are ready for what the next three years will ask of them.