Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

FedRAMP Without an Agency Sponsor: Program Certification

FedRAMP as a program has been through a lot over the years it has existed. Different authorization paths, different requirements and standards, multiple rounds of streamlining and changes; it's been a rocky road. Things are starting to smooth out now that FedRAMP 20x is broadly available, but there's still a lot to learn or to question before you can be fully up to speed. So, let's talk about authorization and where we stand today.

Acronis Cyber Protect Cloud earns maximum score in AV-TEST Advanced Threat Protection test

Author: Alexander Ivanyuk Advanced attacks often use trusted Windows components and legitimate-looking files to conceal malicious activity. A manipulated DLL can run through a signed executable, while a scheduled task can launch PowerShell to load harmful code. These techniques make independent testing valuable because a security product must recognize the attack chain, not only a suspicious file.

The Year the Vulnerability Backlog Changed Shape

As we enter the AI era, few among us have found themselves so entrenched in the throes of the shifting landscape as CISOs. With the threat landscape shifting, they are up against increasing rates of vulnerabilities and exploits alongside rapidly scaling demands for ever more secure environments. As CISOs, with our role as the protectors of an organization, we are expected to deliver guidance and security visibility. This is not a vision of the future, it’s today’s reality.

Cyber Loss in Rail and Signalling

Cyber risk in transport is usually framed around a collision. Signals manipulated, a train sent onto occupied track, an accident caused deliberately. ‍ Signalling is built to make that outcome unavailable. Any failure forces the system into its most restrictive state, so a compromise produces a halt rather than a crash. The loss is the halt, and rail is unusual in already having a published price for one. ‍

Reading AI Use From the Browser When the Network Sees Nothing

A session to a sanctioned AI provider looks the same on the network whichever account it ran under and whatever was in it. Transport encryption means a proxy sees a connection to an approved domain and a payload size. ‍ Which is fine until somebody asks whether an exposure is reportable. The question turns on three facts the network never held, and none of them can be reconstructed from a log afterward. ‍

Why academic selfie fraud benchmarks fail in the real world

Academic deepfake datasets rarely static: generate an image, label it real or fake, done. Real-world fraud doesn't hold still. Zhaofeng Si, a PhD student at University at Buffalo and research scientist intern at Persona, breaks down the gap. Public academic datasets are mostly typical face swaps and diffusion-model-generated images with a fixed label. In the real world, there's an attack-and-defense loop. Fraudsters actively probe for ways to bypass detection, so defenses have to keep adapting instead of training against a static benchmark.

Sophos Named a Leader in the IDC MarketScape for Worldwide Modern Endpoint Security for Enterprises 2026

Sophos has been named a Leader in the IDC MarketScape for Worldwide Modern Endpoint Security for Enterprises 2026, recognizing the strength of our prevention-first approach and stopping AI-era threats as early as possible. Attackers using frontier AI models can now find vulnerabilities and generate exploits faster than organizations can patch them. And when malicious code is already running before an alert fires, detection alone is too late.