Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Mend.io upgrades 184 open source organizations to the Renovate Community (OSS) plan

Mend.io has proactively upgraded 184 open source organizations and GitHub users to the Mend Renovate Community (OSS) plan, with no request required. The upgrade covers about 3,000 repositories with roughly 4 million combined GitHub stars. Maintainers get higher resource limits, more concurrency, and access to Merge Confidence.

IT onboarding automation: building a provisioning agent with Tines 3B

New hires shouldn't spend their first week waiting on IT. But in most organizations, that's exactly what happens: a Slack account that takes three days to provision, a GitHub invite that falls through the cracks, a hiring manager who has no idea whether security has approved VPN access yet. The result is a frustrating first impression for the employee and a pile of repetitive, error-prone manual work for IT.

Proactive Security in Action Across the CrowdStrike Falcon Platform

Proactive security starts with understanding the environment before an attacker can take advantage of it. In this demo, see how the CrowdStrike Falcon platform brings together proactive telemetry and context across endpoint, cloud, identity, network, applications, SaaS, and more to build a connected view of risk.

Autonomous Pentesting: AI Agents That Test Your App 24/7

Most companies pentest their app once a year. Hackers look for new backdoors every single day. Astra Autonomous Pentesting closes that gap with AI security agents that test your web app continuously, 24/7. Traditional penetration testing gives you a giant report full of jargon that sits on a shelf. Astra works like a friendly hacker that never sleeps. When it finds a security weakness, it doesn't just send a scary alert. It explains the exact problem, with the attack story and proof, so clearly that AI coding tools can fix, test and repair the vulnerability the same day.

How Modern Threat Actors Are Changing the Defense-in-Depth Playbook - Webinar October 8, 2026

Ransomware is still growing, but payouts are shrinking. Enterprises got better at backups, so attackers moved to where defenses are thinner: SaaS, identity, and stolen credentials. Infostealers do the collecting at scale, and AI is widening the gap. Credentials for AI services were the fastest growing category of leaked secrets in 2025, up 81% year over year with 1.27 million exposed (State of Secrets Sprawl 2026). Most defense-in-depth programs were not built with this attack chain in mind.

11:11 Systems Acquires Select IBM VMware Cloud Service Provider Enterprise Customers

Brett Diamond, CEO, 11:11 Systems, shares the exciting news about our acquisition of select IBM VMware Cloud Service Provider enterprise customers. At a time of significant change across the VMware ecosystem, 11:11 Systems continues to expand its ability to give customers greater choice, continuity and control. With the acquisition of select IBM VMware Cloud Service Provider enterprise customers, 11:11 has now made eight VMware-related acquisitions and continues to strengthen its position as the largest privately held, global VMware Cloud Service Provider.

How to Tie Kubernetes Audit Logs to Individual Engineers

Kubernetes audit logs may show multiple engineers as one user and do not capture what is typed after a kubectl exec session starts. Assign each engineer a unique identity, make sure it stays consistent through proxies and cloud IAM, and use a session recorder if you need to review terminal activity.

Risk Acceptance Has a Shelf Life: Notes from the Aviation ISAC Cybersecurity Summit

The first Aviation ISAC summit, a little over a decade ago, was about forty people in a room in Miami, hosted by the Health ISAC. This year’s conference in Vancouver hosted more than five hundred: airlines, airports, OEMs, suppliers, and government, all in one place for three days. Many in the audience were new to the conference. One of the opening speakers asked first-timers to raise their hands, and a lot of hands went up around the room.

Critical Bookly IDOR Leads to Booking Disclosure and Deletion (CVE-2026-93399)

During independent security research conducted as part of the Wordfence Bug Bounty Program, we identified an unauthenticated Insecure Direct Object Reference (IDOR) vulnerability in Bookly, a WordPress appointment booking plugin used to manage online scheduling, services, staff availability and customer appointments.