7 skills and traits of elite security engineers
“The same generative tools that help security teams work faster are available to adversaries, and it shows,” Ahmed says. “Phishing campaigns read better and land more precisely than they did…
“The same generative tools that help security teams work faster are available to adversaries, and it shows,” Ahmed says. “Phishing campaigns read better and land more precisely than they did…
Fran Hutchings | Friday, 17 July 2026 at 13:35 UTC Back in April, we launched the Official Burp Ambassador Program: a community initiative designed to work more closely with experienced…
Malware: AMOS, Atomic macOS Stealer, Atomic Stealer, BadIIS, Broomstick, ClawdBot Agent, CleanUp, CleanUpLoader, ConnectWise Control, ConnectWise ScreenConnect, GhostChat, GORBLE, Lumma, LummaC2, Lumma Stealer, OSX.AtomicStealer, OSX.AtomStealer, OysterLoader, POWERSTAR, Redline, Redline Loader,…
The Good | Authorities Sanction Cybercriminals & Dismantle Russian Bulletproof Hosting Infrastructure The EU and the United Kingdom have jointly sanctioned multiple Russian individuals and entities for targeting government networks…
It was a quiet Monday morning until John, head of IT, opened his laptop and saw 424 new support tickets. Users across the office were reporting issues like “apps won’t…
CSO Conversations is a blog series interviewing Okta’s Regional CSOs supporting David Bradbury, Okta’s Chief Security Officer in providing the best service for our customers. Okta’s Regional CSOs are integral…
When you incorporate data from application security scanners into your exposure management platform, you can assess the threat from formerly isolated code flaws using a broader risk context, which illuminates…
In this article Across the threat landscape, in this moment, one pattern sits at the center of the story: threat actors are following trust. They are not only looking for…
Major Threats & Vulnerabilities Record Patch Releases and Actively Exploited Zero-Days Microsoft’s July 2026 Patch Tuesday addressed a record 570 vulnerabilities, including three zero-days and two under active exploitation. Of…
What gets me about this one is the timeline. That token had been sitting there since October 2021. Nearly two years, inside Microsoft, before anyone caught it. If a team…