Topic: security posture

  • ConnectSecure automates M365 security fixes for MSPs

    ConnectSecure automates M365 security fixes for MSPs

    ConnectSecure launched M365 Auto Remediation and AI-powered Training Assessments, enabling MSPs to directly address Microsoft 365 security findings and create, assign, and track training assessments within a single console. M365 Auto Remediation allows MSPs to fix supported findings (e.g., missin...

    Read More »
  • 6 Overlooked Okta Security Settings You Must Check Now

    6 Overlooked Okta Security Settings You Must Check Now

    Securing identity providers like Okta is critical as they act as central gatekeepers for digital access, with risks arising from misconfigurations and evolving threats. The article outlines six essential Okta security practices, including robust password policies, phishing-resistant MFA, and feat...

    Read More »
  • Cloudflare Balances Data Security with AI Access

    Cloudflare Balances Data Security with AI Access

    Cloudflare One has been enhanced to help businesses securely integrate and manage generative AI tools while maintaining data protection and compliance standards. New features include AI Security Posture Management (AI-SPM), offering discovery of AI usage patterns, protection against unapproved AI...

    Read More »
  • Ransomware's Relentless Spread: A Growing Threat

    Ransomware's Relentless Spread: A Growing Threat

    Ransomware is expanding globally into new regions and sectors, with attackers increasingly targeting areas with less mature security defenses. The public sector is a high-risk target due to uneven security practices, with a concerning segment showing both high exposure and weak controls. Future r...

    Read More »
  • Secure Your Data and AI Strategy for Success

    Secure Your Data and AI Strategy for Success

    AI security is now a primary business priority, with every new tool being evaluated for its security posture before its functional capabilities. Organizations struggle to balance innovation with robust security, requiring a proactive strategy that embeds security into AI projects from the start. ...

    Read More »
  • Mondoo Secures $17.5M to Expand Vulnerability Management Platform

    Mondoo Secures $17.5M to Expand Vulnerability Management Platform

    Mondoo raised $17.5 million in a Series A extension, bringing total funding to over $32 million, with HV Capital leading the investment to support platform enhancements and regional expansion. The company offers an agentic vulnerability management platform that identifies, categorizes, and priori...

    Read More »
  • Discern AI Deploys Six Agents to Automate Security Analysis

    Discern AI Deploys Six Agents to Automate Security Analysis

    Discern Security has launched a suite of six specialized AI agents to address challenges like tool sprawl and alert overload, aiming to improve security posture and operational efficiency. The platform's agents automate key security workflows, including intelligence gathering (Scout), data analys...

    Read More »
  • Prioritize Security, Not Just Access, for Field Workers

    Prioritize Security, Not Just Access, for Field Workers

    Modern mobile workforce security requires individual accounts with mandatory multifactor authentication (MFA), moving beyond outdated shared credentials to protect sensitive data from sophisticated threats. Implementing the principle of least privilege through role-based access and streamlined re...

    Read More »
  • Zero Trust: Slash Cyber Risk and Insurance Claims

    Zero Trust: Slash Cyber Risk and Insurance Claims

    Businesses in Australia and Oceania are facing a sharp rise in sophisticated cyberattacks, and adopting a Zero Trust security architecture can significantly reduce both the frequency and financial impact of these incidents. Research shows that implementing Zero Trust could have prevented up to 42...

    Read More »
  • Salesloft Links Drift Data Theft to March GitHub Hack

    Salesloft Links Drift Data Theft to March GitHub Hack

    A data breach at Salesloft originated from a March intrusion into its GitHub account, allowing attackers to steal authentication tokens and target major tech clients over several months. The attackers used stolen OAuth tokens to infiltrate companies like Google and Cloudflare via Salesloft's AWS ...

    Read More »
  • Microsoft extends zero trust across enterprise AI

    Microsoft extends zero trust across enterprise AI

    Microsoft expanded its Zero Trust Assessment tool with a new AI pillar, adding targeted security checks and enhanced reporting that produce prioritized recommendations and executive summaries for securing AI deployments. The Zero Trust Workshop now includes a DevSecOps pillar with 15 control grou...

    Read More »
  • Secure Your Code with DefectDojo: Open-Source DevSecOps

    Secure Your Code with DefectDojo: Open-Source DevSecOps

    DefectDojo is an open-source platform that centralizes application security management, vulnerability tracking, and DevSecOps workflows by consolidating findings from multiple sources and eliminating duplicates. It enables organizations to track vulnerabilities, manage risk acceptance procedures,...

    Read More »
  • Box Shield Pro: Secure AI Workflows & Protect Sensitive Data

    Box Shield Pro: Secure AI Workflows & Protect Sensitive Data

    Box has launched Box Shield Pro, an AI-enhanced security suite that builds on its existing platform to better protect enterprise data and improve threat response against risks like ransomware and accidental exposure. The new solution includes AI-driven agents for automated content classification,...

    Read More »
  • Intel 471 expands Verity471 with AI agent and MCP support

    Intel 471 expands Verity471 with AI agent and MCP support

    Intel 471 launched MCP471 and Agent471 as AI-driven enhancements to its Verity471 platform, helping security teams counter AI-powered cyberattacks by making threat intelligence more actionable and integrated with internal telemetry. MCP471 is a connector that integrates Verity471 intelligence int...

    Read More »
  • Multi-Extortion Ransomware: The New Attack Evolution

    Multi-Extortion Ransomware: The New Attack Evolution

    Ransomware attacks are a pervasive daily reality, severely disrupting operations across critical sectors like healthcare, finance, and manufacturing, as evidenced by a 49% increase in publicly reported attacks in 2025. The threat has escalated due to a shift from simple encryption to aggressive "...

    Read More »
  • Singulr AI Agent Pulse: Enforce Runtime Governance for AI Agents

    Singulr AI Agent Pulse: Enforce Runtime Governance for AI Agents

    Singulr AI launched Agent Pulse, a platform providing real-time governance and oversight for autonomous AI agents to manage security risks and ensure policy compliance within enterprises. The platform offers four core functions: discovering all organizational AI agents, assessing their risk postu...

    Read More »
  • QuProtect R3: Unlock Full Encryption Visibility Across All Systems

    QuProtect R3: Unlock Full Encryption Visibility Across All Systems

    QuSecure has launched QuProtect R3, a production-ready platform to simplify the transition to post-quantum cryptography for organizations, offering a streamlined path without operational disruption. The platform includes a free Reconnaissance module that quickly maps cryptographic vulnerabilities...

    Read More »
  • Boost Cyber Resilience: Proactive Wazuh Strategies

    Boost Cyber Resilience: Proactive Wazuh Strategies

    Cyber resilience is a proactive strategy that enables organizations to anticipate, withstand, respond to, and recover from attacks with minimal operational impact, moving beyond traditional reactive security models. The Wazuh security platform provides unified visibility, early threat detection, ...

    Read More »
  • CISA Flags Spyware Zero-Day in Urgent Security Alert

    CISA Flags Spyware Zero-Day in Urgent Security Alert

    US authorities issued a critical security alert for a high-risk vulnerability in Samsung mobile devices, exploited since mid-2024 to install spyware via malicious files on WhatsApp. The vulnerability, CVE-2025-21042 with a CVSS score of 9.8, enables attackers to use LandFall spyware for surveilla...

    Read More »
  • DefectDojo Launches Sensei: AI Cybersecurity Advisor

    DefectDojo Launches Sensei: AI Cybersecurity Advisor

    DefectDojo has launched Sensei, an autonomous AI cybersecurity advisor that operates independently without external AI services, eliminating vulnerabilities from third-party integrations. The cybersecurity industry is increasingly adopting AI, with many professionals using or testing AI tools to ...

    Read More »