Living Off the Pipeline: Defending Against CI/CD Subversion
The software supply chain has become one of the most attractive targets for modern adversaries, but the attacks seen in 2025 did not focus solely on poisoning dependencies or hijacking…
The software supply chain has become one of the most attractive targets for modern adversaries, but the attacks seen in 2025 did not focus solely on poisoning dependencies or hijacking…
AI governance is a key enterprise concern. Organizations are assembling councils, publishing principles, rolling out “approved AI tools” lists, and asking employees to opt in to acceptable use policies. In…
At Varonis, our customers are central to everything we do. That’s why we are exceptionally proud to have Varonis named as a Customers’ Choice in the 2026 Gartner® Peer Insights…
An overwhelming share of the user credentials that are later abused in identity-based attacks arise from the compromise of unmanaged user devices. “Infostealers” are the generic name given to the…
In this article In October 2025, Microsoft Threat Intelligence identified destructive wiping activity and uncovered a sophisticated Go programming language (Golang)-based backdoor we now track as GigaWiper, a versatile implant…
RSA and ECC, cryptographic algorithms that we’ve all relied on for decades, are vulnerable to the attack of sufficiently advanced quantum computers. Such quantum computers do not exist yet, but…
For years, organizations treated operational technology (OT), Internet of Things (IoT), and embedded devices differently from traditional IT assets. Many of these systems were designed to operate for decades with…
A representative finding from current engagements: human identity governance at Stage 4 — central IAM, MFA, lifecycle managed — and agent governance at Stage 1, with agents recently inventoried but…
Fran Hutchings | Thursday, 9 July 2026 at 09:20 UTC PortSwigger is heading to Las Vegas for one of the biggest weeks in the cybersecurity calendar. Across Black Hat USA,…
In order to understand what is Kali Purple, it’s important to recognize it as a defensive-oriented cyber security distribution designed to help organizations build, test, and improve their security operations. …