Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

The AI Incident Reporting Duty Nobody Can Date

Compliance content answers the question of when an obligation starts. For the serious incident reporting duty in the AI Act, the honest answer is that it is disputed, and the dispute is not a failure of research. ‍ Two readings of the text point in different directions, neither is obviously wrong, and no authority has resolved it. What follows is the reasoning on both sides and what to do without picking one. ‍

Announcing LimaCharlie Email Security: Natively Integrated Into Your SecOps Stack

Co-founder & CCO LimaCharlie Email Security is generally available today. It protects Microsoft 365 and Google Workspace mailboxes from inside the same tenant, permission model, and data lake as the rest of LimaCharlie. A phishing email and the endpoint activity it causes can now be detected, investigated, and remediated in one place.

How to Automate Repository Backups to Minimize Data Loss and Downtime

In modern CI/CD pipelines, source code moves fast, and repository state changes constantly. Manual backups are inherently fragmented, error-prone, and incapable of capturing platform metadata at scale. To prevent critical data loss and ensure rapid failover, engineering teams must automate their repository backups.

Threat Actors Abuse Trusted Accounts and Internal Tools to Launch Convincing BEC Attacks

Attackers are continually finding new ways to refine business email compromise (BEC) attacks, according to Douglas McKee, Director of Vulnerability Intelligence at Rapid7. When attackers compromise trusted tools and accounts, they can manipulate victims’ view of reality. One way attackers can achieve this is through what McKee calls “calendar warfare,” in which attackers use calendar meetings to trick users into falling for attacks.

[Cybersecurity Awareness Month] Cyber Espionage: When the Attacker's Best Asset Is You

Spies have always relied on technology, disguises, secret communications and clever gadgets, at least if the movies are to be believed. But some of the most effective tools in the espionage business have always been people. Convince the right person to open a door, reveal a secret or trust someone they should not, and suddenly bypassing the sophisticated security system becomes unnecessary.

The Egnyte + Procore Integration: Connecting Project Execution with Construction Knowledge

Construction firms rely on purpose-built platforms like Procore to coordinate RFIs and submittals, document field activity, track progress, and keep projects on schedule. But managing project execution is only one part of the information lifecycle—teams need a way to capture and connect project information across departments, applications, partners, and project phases.

Convergence of ITDR, PAM and IGA. Which of the three is standing there when the attack lands?

Our 2026 Identity and Data Security Report put compromised identity ahead of misconfigured permissions as the leading route to unauthorized access, 41.8% against 33.9%. If identity is the way in, the controls around identity belong together, and that's the reasoning behind most of the consolidation we've seen over the past few years. But how is the work split up?

Insider risk starts with who can read the data

Insider risk is often framed as an external attacker problem, but a real blind spot sits closer to home: who inside your own security stack can open sensitive files they never needed to see. Classification tools that require broad scanning access often hand that same access to every admin who configures them, turning the tool meant to reduce exposure into another path to it. The people with the least oversight, your own admins, can end up with the most unchecked visibility into regulated data.

Citrix NetScaler vulnerability (CVE-2026-88779) in active exploitation

On October 4, 2026, Citrix disclosed a high-severity (CVSS score of 8.7) memory overflow vulnerability (CVE-2026-88779) affecting Citrix NetScaler ADC and Citrix NetScaler Gateway deployments that are configured as either a SAML Service Provider (SP) or SAML Identity Provider (IdP). Successful exploitation can cause a denial of service (DoS) condition, potentially disrupting authentication services and remote access functionality.

Rethinking identity security in the agentic AI age

Identity security conversations often arrive at the same unfortunate scenario: a stolen token and breach only discovered once major damage is done. Experts Rob Kraczek, global strategist at One Identity, and Chris Ray, field CTO of security and risk at GigaOm, recently unpacked why 3 a.m. token theft has become less exception, more routine — among other things.