Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Featured Post

AI Risk Is a Significant Security Operations Challenge

AI has quickly become a boardroom priority. Organisations are investing heavily in governance frameworks, usage policies and risk controls as employees adopt AI technologies across the business. Yet as boards look to understand AI risk, many are overlooking a more immediate frontline challenge: the impact AI is having on the threat landscape and the ability of security operations teams to keep pace.

What Is Used to Test for Hydrogen Gas? Methods for Detecting and Measuring H in Industry

Hydrogen is colourless and odourless, burns with a pale flame that is almost invisible in daylight, and forms flammable mixtures with air over a wide concentration range of roughly 4 to 75 vol.%. Its presence cannot be noticed without an instrument, so the question "is there hydrogen in the system, and how much?" is always answered by measurement.

A Win for Defenders: CrowdStrike and NVIDIA Extend Security Across the AI Stack

AI agents are already operating across the enterprise. As they become more autonomous in accessing data, using credentials, executing code, and acting across critical systems, the security boundary is changing with them. The question is no longer whether enterprises will adopt agents. It's how they give agents greater autonomy without giving up control.

AI data security: protecting sensitive information across AI tools

An employee uploads a spreadsheet to find a sales trend. Another pastes a support conversation into a chatbot to draft a reply. Neither intends to expose business information. Even so, both may send sensitive material outside the systems where your business normally controls it. SMB IT decision-makers need to know what employees share and decide which interactions are acceptable, without building a specialist AI security team.

Oops, OpenAI Hacked Australia's Health System - The 443 Podcast - Episode 389

This week on the podcast, we cover yet another rogue AI security incident that Australia's Prime Minister disclosed in front of the United Nations last week. Before that, we discuss an FBI alert on WaterPlum, a North Korean threat actor targeting IT professionals. Then, we cover the FBI themselves becoming a victim of cyberattack, this time by ShinyHunters.

Your Clients Already Deployed AI. Nobody Sold Them the Security for It.

Every vendor this year says the same thing: AI is transforming cybersecurity. True, and not useful. Here is the useful version. AI is doing two things at once. It is compressing the time between a vulnerability being found and being exploited, which is the part everyone talks about. And it is quietly installing a brand new attack surface inside your clients' businesses, which is the part nobody is selling against yet.

The AI Act Duty That Applies Regardless of Risk Tier

Almost every obligation in the AI Act is keyed to a risk classification. Work out which tier a system falls into and the duties follow. ‍ Article 4 is not. It applies to providers and deployers of any AI system whatever it does, its subject is people rather than systems, and national authorities began supervising and enforcing it from 2 August 2026 while the high-risk regime moved to December 2027. It is the live one, and it sits outside the structure most governance programs are built on. ‍

AI Review of Privileged Material and the Waiver Question

Sending privileged material through an external AI service is a disclosure to a third party, and voluntary disclosure to a third party waives privilege. The reasoning is straightforward and a federal court has now applied it. ‍ A second federal court reached the opposite conclusion on the same question within days, on a distinction the first did not draw. The position is genuinely unsettled, and the parts that are settled point at configuration choices rather than at a prohibition. ‍