Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

No Link to Click: How a Text and a Phone Call Defeated MFA

No link was clicked. No malware was installed. No email gateway was crossed. A software development director lost her account in under two minutes. This is the full chain, in real time: a text message that offers to prevent a problem rather than asking for anything, a phone number she dials herself, a calm voice that explains what she is about to see before she sees it, and six digits read out loud.

AI Agent Security: Detecting Risky Behavior (Live Demo)

Watch five AI agents tackle a CTF and start coordinating with one another. Learn how to detect risky agent behavior using @goteleport graphs, risk scoring, and custom classifiers. Ben Arent explores lessons from the Hugging Face incident, then demonstrates how agent identity, scoped access, and activity monitoring help secure AI agents running against infrastructure.

What is ISMS-P and how it aligns with ISO 27001 and ISO 27701

Accelerating security solutions for small businesses‍ Tagore offers strategic services to small businesses. A partnership that can scale‍ Tagore prioritized finding a managed compliance partner with an established product, dedicated support team, and rapid release rate. Standing out from competitors‍ Tagore's partnership with Vanta enhances its strategic focus and deepens client value, creating differentiation in a competitive market.

What PCI DSS 4.0 Requires for Infrastructure Identity and Access Evidence

Most conversations about PCI DSS 4.0 start with the requirements, but I’d rather start with a habit. As a GRC & Cybersecurity Consultant advising organizations preparing for PCI DSS 4.0 assessments, I’ve developed a habit of observing how findings move from identification to ownership, remediation, and documented closure. That’s often where accountability gaps and unresolved findings surface first.

Corelight Agent Builder Library: AI Investigation Demo

What happens when you ask a generic SIEM AI assistant and a Corelight-powered threat hunter agent the exact same question about a suspicious IP? The difference is not the model. It is the investigation expertise. In this demo, we walk through a side-by-side comparison using Elastic's agent builder. A default AI assistant returns a surface-level summary. An agent built with the Corelight Agent Builder Library identifies lateral movement, flags potential ransomware and data exfiltration, surfaces IDS alerts, maps involved hosts, and recommends next steps.

How To Eliminate Secrets Configuration Drift Between Your Vault and the Cloud

You might treat a centralized vault as the authoritative source for every secret, but secrets can quietly fall out of sync as they get copied into cloud secret stores, CI/CD pipelines and running workloads. This is referred to as secrets configuration drift, and it can leave outdated or standing credentials, API keys and other secrets active for longer than intended.

Recognizing and detecting data exfiltration

Every breach that lands a CISO in front of the board has a common final act: Data leaving the building. Attackers don't get paid for breaking in. They get paid for what they take out. And by the time stolen data appears on an extortion site or in a regulator's inbox, the window to stop the damage has already closed. That is what makes exfiltration so dangerous. It rarely looks like an emergency.