Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Ep. 65 - "Months, Not Years": The Five Eyes AI Warning and Your Security Program

On June 22, 2026, the heads of all six Five Eyes cyber agencies — GCHQ, CISA, the NSA, ASD, the Canadian Centre, and New Zealand's GCSB — signed a rare joint statement: AI has rewritten the cyber risk timeline, and it's months, not years. Host Tova Dvorin and offensive security expert Adrian Culley unpack why AI is collapsing the window between vulnerability and exploit, why "having controls" isn't the same as proven controls, and why legacy systems are now strategic liabilities for the board, not the IT team. A clear-eyed look at validation, assumed breach, and what CISOs should do Monday morning.

Why Continuous Attestation Is Critical in the AI Coding Era

In the age of AI coding, annual audits and snapshots are no longer enough. Discover **Continuous Attestation** — the practice of producing ongoing, verifiable evidence that your applications and pipelines are always running in a trusted, policy-conformant state. In this video, Anthony Barkley, Chief Strategy Officer at Veracode, explains why independence in attestation is critical for earning trust from regulators, customers, and boards — especially when AI agents are writing code.

Oracle Just Shipped 1,449 Security Patches in One Quarter. We Checked How Much of It Is Actually New.

Oracle's July 2026 Critical Patch Update (CPU) is nearly three times larger than any release in the company's history. To understand it, we parsed all 23 of Oracle's quarterly advisories going back to 2021, matched them against the official CVE record, and compared Oracle against eight other major vendors. We set out to answer three questions: How much of this is genuinely new? Does it really reflect AI-accelerated patching? And how unusual is it?

What Are Auditors Looking for During a DORA Assessment

Are you prepared for a DORA assessment — and can you actually prove your organization is operationally resilient? Under the Digital Operational Resilience Act (DORA), having cybersecurity policies on paper isn't enough. Financial entities need to demonstrate how ICT risks are governed, monitored, tested, and managed in practice. In this video, we cover the key areas that assessors and regulators may review.

Finding eight high-severity vulnerabilities in NodeBB in six hours

TL;DR While improving our AI Pentest, we ran a whitebox assessment on NodeBB, a forum software powered by NodeJS. The result? Eight high-severity vulnerabilities that would all be exploitable on default instances of NodeBB. This includes Cross-Site Scripting (XSS), two of which require interaction with a custom Federation server that the AI agent had to set up itself. Another affects practically every input on NodeBB due to a template injection.

The New Face of AI Risk

Cybercrime used to have a ‘"tell." It was the digital equivalent of a villain stroking their cat - clunky grammar, misspelt links and suspicious attachments that screamed ‘phishing’. But the arrival of AI has changed everything. Typos have been replaced by perfect prose. Generic lures have evolved into highly personalized attacks that mimic your internal language and align with your project timelines.

Enabling Massive-File Collaboration in the Cloud With Adaptive Block Caching

When it comes to massive files, many organizations still rely on old-fashioned, on-premises file servers and filers. They’re hesitant to work on these projects in the cloud because the inherent network latency makes working with massive files difficult. So they stick to an on-premises approach—even though it typically requires wired access and stable VPN connections, which makes sharing and collaborating especially challenging for people working from home, in the field, or on the road.

How to Convert OST To PST When The Outlook Profile Is Deleted

Outlook profiles are extremely important part of Outlook. It not only contains the account configuration but also mailbox settings. Also, it includes the data file associations required for mailbox content access. Now the question arises what if something went wrong with this Outlook profile? What if the profile is deleted? In such a scenario, Outlook loses its connection to the associated OST file. It means OST file can become orphaned. In such a case, users are unable to access the mailbox folders. What's next? The solution is to convert this encrypted OST to any portable data file format like PST.

How Professional IT Services Help Businesses Improve Efficiency, Security, and Long-Term Growth

Technology has become essential to daily business operations. From communication and collaboration to customer service and data management, organizations depend on reliable systems to keep work moving forward. Partnering with experienced Managed IT Services professionals allows businesses to take a proactive approach to technology management instead of constantly responding to unexpected technical issues. Professional IT Services help improve efficiency, reduce downtime, strengthen Cybersecurity, and create a stronger foundation for sustainable growth.