Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Fine-Tuning Is Not What Reclassifies an AI Deployer

The concern about fine-tuning is that it quietly converts a deployer into a provider, pulling in conformity assessment, technical documentation and a quality management system nobody budgeted for. ‍ The concern is misdirected. Fine-tuning is among the least likely routes to reclassification, and the route almost nobody worries about requires no training compute at all. ‍

China's 15th Five-Year Plan: What You Need to Know

Over the past several decades, China’s five-year plan has provided a roadmap to the country's innovation and economic growth. It details what China is interested in, where technology is evolving, and what it plans to target, including the highest-priority verticals. “It’s their shopping list,” as Adam puts it. His team does a deep analysis on these plans, including information published adjacent to it and the discrepancies across various languages.

Streamlining Access Control with Brivo

Still relying on physical clickers, fobs, and windshield stickers for your parking garage? Gate delays don't just annoy residents—they back up traffic onto main roads. Brivo turns vehicle license plates into secure credentials using cloud-integrated License Plate Recognition (LPR). Residents simply pull up, the camera reads the plate, and the gate opens automatically—no fumbling for clickers required.

AI Revolutionizing Property Management

AI isn't just a buzzword—it’s changing how property managers secure their buildings. An access log only shows who scanned a door, but Brivo Video shows you what actually happened. Learn how intelligent AI analytics turns endless video feeds into a searchable database and helps you stop property issues before they start. Key Highlights.

How attackers use AI models to find code vulnerabilities

AI models accelerate software development, but attackers use those same capabilities to hunt for pipeline vulnerabilities. Asaf Saar (EVP and Chief Product Officer, Mend.io) and Christian Jensen (VP Engineering, Tricentis) break down why full visibility is required to secure AI-native software.

Why Reach Security Solves Problems That Aren't Sexy | Garrett Hamilton

"The problems we solve are not sexy." But they are hyper-relevant and important. Garrett Hamilton joined Moudy Elbayadi, Ph.D. on Inflection Point: Digital Intelligence Podcast. He explains why Reach goes after problems that have been around for decades, that matter, and that nobody wants to own. He covers why these problems have lasted so long and why they are now possible to fix at scale.

Uncovering indirect attack paths to virtualized domain controllers in Azure

Within Netwrix Security Research, we were helping a customer with an Entra ID assessment and knew they'd already done AD tiering on-prem. We also knew they had domain controllers virtualized in Azure, but it was hard to tell which Windows Server was actually a DC. We figured out that Azure Run Command lets you run commands as SYSTEM, so we used that to do reconnaissance and identify the DCs.

Copilot broke your insider threat detection, and MITRE wrote the proof

MITRE ATT&CK's detection analytic for adversaries mining SharePoint describes bulk access to files and metadata in a short window by privileged or rarely used accounts. That is also a description of Microsoft 365 Copilot answering a question. The technique hasn't changed, but the baseline has, and the exposure now happens with no vulnerability, no compromised credential, and no malicious intent anywhere in the chain.

The water system attacks were simple. Securing OT isn't.

Recent cyberattacks against U.S. water and wastewater systems have put some familiar operational technology (OT) security problems back in the headlines. Federal agencies have warned about malicious actors targeting internet-facing programmable logic controllers (PLCs), changing device configurations, and disrupting operations at utilities across multiple states.