Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Vanta's The Tabletop: Ep. 2 with Jason Chan

The attacker didn't break in. They logged in. In episode 2 of The Tabletop, Jason Chan (former VP of Security at Netflix) has 26 minutes to investigate an MFA fatigue attack that leads to a forgotten production script with hard-coded credentials... and no owner. His reaction says it all: "Archeology is part of our jobs… figuring out what this thing does.".

Streamline Exposure Management Responses with Atlas

When 115+ new CVEs are released — Firefox, OpenSSL, WolfSSL, and more — figuring out your exposure used to mean hours of manual work: querying the CMDB, pulling reports, chasing tickets. In this video, we show a faster way with Tanium Atlas. We paste in the full list of CVEs and ask one question: are we affected, and can we get a report ready for the board? In under a minute, Atlas returns a full exposure report across thousands of endpoints, prioritized by what needs attention first. A follow-up question generates a remediation plan. The result.

Why Your Healthcare RAG Pipeline Is Leaking PHI (And How to Fix It)

Why Your Healthcare RAG Pipeline Is Leaking PHI Most healthcare organizations believe their AI assistant is secure once they restrict who can log in. Unfortunately, that's only part of the story. Modern healthcare AI applications rely on Retrieval-Augmented Generation (RAG), where patient records, physician notes, insurance claims, and medical documents are embedded into vector databases to power intelligent search.

The Missing Layer in Network Security: Continuous Assurance

Some of the most serious network security weaknesses develop gradually through routine operational changes. Firewall rules are adjusted to support business needs, exceptions remain in place longer than planned, and controls are modified during troubleshooting. Over time, those decisions can push the live environment away from the security posture the organization believes it has.

Protecting the Corporate Nervous System: Why Network Security Assurance Is Becoming a Security Imperative

Modern enterprises depend on a complex network of interconnected systems, applications, identities, and security controls. This infrastructure has become the nervous system of the business, enabling critical operations, supporting applications, and enforcing the boundaries that protect sensitive data. When these systems function correctly, they become invisible.

199 RubyGems, two techniques, zero working payloads: Inside a cryptomining campaign that never ran

Mend.io’s research team caught this campaign before most of the open source community ever saw it. Continuous monitoring of RubyGems flagged a batch of gems that looked, at a glance, like an ordinary cryptomining squat, and Mend.io reported the full batch to RubyGems for takedown. Every gem was pulled within hours. Mend.io’s team also pulled two of the samples apart in full, because knowing a campaign exists isn’t the same as knowing how it works.

What the OpenAI-Hugging Face Incident Really Tells Us

For years, the conversation about AI in cybersecurity has been mostly hypothetical. What happens when a model can plan and execute an attack on its own? How far away is that, really? This week, OpenAI gave us a concrete answer, and it arrived earlier than many expected. The incident is a genuine milestone, and it deserves the attention it is getting. But the most useful response is disciplined execution on the fundamentals, at a pace that matches the moment.