Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Mini Shai-Hulud Hits keyv: Trojanized Release Exfiltrates CI Secrets via GitHub

On August 4, 2026, a malicious version of keyv was published to npm as keyv@6.0.0, one of a number of npm packages affected across the Keyv and Cacheable ecosystem. The release follows the Mini Shai-Hulud pattern: a trojanized version of a heavily depended-on package, with an install-time hook that reaches cloud and CI credentials. It leaves the compiled library untouched and instead adds a preinstall hook and two files.

Patch faster isn't the answer. Patch smarter is.

The 30-day patch cycle is dead. Most security teams already know this. What they haven’t fully reckoned with is why it died, and what has to replace it. SC Media recently gathered a range of security leaders on exactly this shift, and the picture they described is stark. AI didn’t just add more vulnerabilities to the pile. It collapsed the time between disclosure and exploitation from weeks to hours.

The AI agent working for you probably has more access than you do

Say a sales rep uses an AI assistant to help manage their pipeline. The rep has role-based access to Salesforce, scoped to their territory and their accounts. The assistant, wired in through an API integration, often doesn't have that same scoping. It authenticates as a service account with broad read and write access across the org, because that was faster to set up than a permission model that matches what the actual user is allowed to see.

What engineering leaders can learn from stoicism

“A man’s worth is no greater than the worth of his ambitions.” Marcus Aurelius wrote that almost two thousand years ago, in a private journal he never intended anyone to read. Coming from a man who held every title Rome could give, it’s a telling way to measure worth: not by what you hold, but by what you aim at. It has stuck with me, because everything I’ve seen in my career backs it up. Deep technical knowledge is where great engineering starts.

How To Encrypt A File: A Detailed Guide to Securing Your Data and Privacy

Encrypting files has become the new norm for the digital services we use online, from VPN, email, and cloud storage. Without it, our data is openly available for anyone to read, compromising our confidentiality, privacy, and security and potentially costing businesses millions in compliance fines. This comprehensive guide therefore offers you a comprehensive guide on how to encrypt files to ensure your data remains protected by covering the following topics.

PowerShell Execute .Exe: Safe Guide for 2026

You're staring at a deployment script, the vendor wants a clean setup.exe launch, and half the fleet needs the same binary with the same arguments. At the same time, your SIEM is already full of PowerShell activity that looks harmless until it isn't, because the exact same process-launch primitive is one of the most common ways attackers move from code execution to real impact. That's why PowerShell execute.exe isn't just a scripting question, it's an operational and detection question.

Departing Employees Are the Insider Threat You Are Missing

Departing users sit on your most valuable data with active access, and that makes them a heightened risk. Point existing technology at that behavior and you surface quick wins fast, which spurs the wider discussion across the business. Security leaders explain why departing users are the clearest place to start. From The Insider Risk Authority Series by Teramind. Subscribe for more conversations with security leaders on managing insider risk. Learn more at teramind.co.

Building a Separate SOC for Insider Risk?

Standing up a whole new entity for insider risk creates friction with the teams you already have. The smarter path is to ramp up with the right expertise, then transition insider risk into standard operating process inside your existing operations center. Security leaders break down why a "second SOC" rarely survives contact with reality. From The Insider Risk Authority Series by Teramind. Subscribe for more conversations with security leaders on managing insider risk. Learn more at teramind.co.

Why Cyber Resilience Is Business Critical | ITPro Podcast

Cyber attacks can create serious financial, operational, and reputational consequences for businesses. That’s why cyber resilience has become a business-critical priority—not just an IT concern. In this special edition of the ITPro Podcast, Rory is joined by Sean Tilley, Senior Director of Sales EMEA at 11:11 Systems, and Sam Woodcock, Senior Director of Solutions Architecture EMEA at 11:11 Systems.