Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

The Rise of Legitimate-Service Phishing: 1 in 10 Phishing Emails Now Comes From a Platform You Trust

A legitimate sender does not mean legitimate content. Attackers have abused legitimate services such as DocuSign, SharePoint, Adobe Sign, Dropbox and Google Drive to exploit that trust for years. KnowBe4's Phishing Threat Trends Report Vol. 7, released April 2026, flagged this shift at the industry level: 22% of all phishing attacks are now sent through a legitimate platform, with attackers moving from impersonating a brand to abusing that brand's actual infrastructure.

Corelight in the Black Hat USA NOC: A playlist of attendee mistakes

When I got back from Black Hat USA, I was stunned. Of course, it’s easy to be overwhelmed by Black Hat. There is so much going on. Las Vegas casinos are loud and flashy. Going outdoors feels like standing on the surface of the sun. Everywhere you walk there are strong smells, and you hope it’s a delicious meal, but sometimes it’s not.

What is privacy management? Core components and how to build a program

Accelerating security solutions for small businesses‍ Tagore offers strategic services to small businesses. A partnership that can scale‍ Tagore prioritized finding a managed compliance partner with an established product, dedicated support team, and rapid release rate. Standing out from competitors‍ Tagore's partnership with Vanta enhances its strategic focus and deepens client value, creating differentiation in a competitive market.

Egnyte Collaborates With Microsoft to Bring Governed AI to Windows 11

AI agents are moving beyond the browser and into the desktop applications professionals use every day. Egnyte is excited to announce a new collaboration with Microsoft to bring Egnyte AI to Windows 11 through Microsoft Execution Containers (MXC), enabling AI agents to work directly alongside desktop applications while operating within enterprise security boundaries.

SOC metrics that prove your security actually works

SOC metrics are quantifiable measures of how well a security operations center detects, investigates, and contains threats. The metrics that matter most are mean time to detect (MTTD), mean time to respond (MTTR), and incident closure rate, because together they show speed, effectiveness, and reliability, not just activity.

Securonix Introduces Advanced Behavioral Analytics to Detect Human and AI-Driven Threats

New solution uses behavioural intelligence and governed Agentic AI to uncover human and AI-driven threats while keeping analysts in control, backed by new ISO/IEC 42001:2023 certification for responsible AI management.

Insignary Launches Clarity AIR to Detect Undeclared Open-Source and AI-Written Code

Insignary Launches Clarity AIR: Closing the Blind Spot Between What Your Developers Declare and What's Actually in Your Code. New snippet-level scanning shows security and compliance leaders which open-source code and which AI-written code never made it into a manifest.

The hidden cost of over-permissioned service accounts

Service accounts, app integrations, and AI agents often have more access than any person, and they get reviewed last. That gives them one of the largest blast radiuses in the environment, meaning they can reach more if they're compromised. The Uber and Cloudflare breaches and the Salesloft Drift campaign against Salesforce customers show how attackers exploit these accounts. Check them for open, stale, orphaned, and privileged access, then cut access back to what they really use.