Topic: audit logs

  • Credential Management as a Financial Risk Control in DORA

    Credential Management as a Financial Risk Control in DORA

    DORA's Article 9 mandates that financial institutions implement least-privilege policies and strong authentication mechanisms (like FIDO2/WebAuthn), making credential security a legal requirement with supervisory consequences. Stolen credentials are the leading initial attack vector in 2025, acco...

    Read More »
  • Conjur: Open-Source Secrets Management for Secure Apps

    Conjur: Open-Source Secrets Management for Secure Apps

    Conjur is an open-source secrets management solution that provides a centralized, policy-driven system to securely control access to credentials like passwords and API keys, eliminating the risks of hardcoding them in code or config files. It operates on a core philosophy of identity and policy, ...

    Read More »
  • Secure Active Directory with UserLock IAM: Product Showcase

    Secure Active Directory with UserLock IAM: Product Showcase

    UserLock is a modern IAM layer for Microsoft Active Directory that enhances security with granular MFA, contextual access rules, and real-time session monitoring without requiring a disruptive identity overhaul. It provides comprehensive visibility and control by aggregating AD entities into dash...

    Read More »
  • VulnRisk: Open-Source Vulnerability Risk Assessment

    VulnRisk: Open-Source Vulnerability Risk Assessment

    VulnRisk is a free, open-source platform for vulnerability risk assessment that uses context-aware analysis to provide more relevant security insights than traditional CVSS scoring. It reduces alert fatigue by filtering out up to 90% of irrelevant noise through contextual factors like exploit lik...

    Read More »
  • Breach at the Beach: Master the Ultimate Entra ID CTF

    Breach at the Beach: Master the Ultimate Entra ID CTF

    Varonis researchers created "Breach at the Beach," a free Capture the Flag (CTF) training tool that immerses cybersecurity professionals in real-world data exfiltration tactics targeting Microsoft Entra ID, where non-human identities like AI agents have expanded the attack surface. The CTF teache...

    Read More »
  • Microsoft Empowers Security Teams with AI Investigations

    Microsoft Empowers Security Teams with AI Investigations

    Microsoft has launched **Purview Data Security Investigations**, a new AI-powered tool that dramatically speeds up complex data investigations, turning processes that took weeks into operations completed in hours. The platform aggregates and analyzes data from across Microsoft 365 (including emai...

    Read More »
  • Jozu Agent Guard Stops AI Agents Bypassing Security

    Jozu Agent Guard Stops AI Agents Bypassing Security

    Jozu has launched Agent Guard, a zero-trust AI runtime that securely executes AI components with built-in policy enforcement to address security gaps in enterprise AI adoption. The solution was developed in response to a critical vulnerability where AI agents can logically bypass and disable trad...

    Read More »
  • IronCurtain: Open-Source Security for Autonomous AI

    IronCurtain: Open-Source Security for Autonomous AI

    IronCurtain is a new open-source security framework designed to prevent unauthorized actions by autonomous AI agents, creating a secure barrier between an AI's intentions and a user's system to vet every action before execution. It operates by forcing all agent activity through a trusted review p...

    Read More »