Passwork NIS2 efficiency guide: Save your team hours before the 2026 audit

By the second half of 2026, national competent authorities across the EU are actively reviewing NIS2 compliance documentation. Under Article 20(1) of the directive, senior management at essential and important entities can be held personally liable for… Continue reading Passwork NIS2 efficiency guide: Save your team hours before the 2026 audit→

Week in review: Cisco patches exploited email gateway 0-day, Revolut breach

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: What we know about the Revolut data breach so far Someone impersonating a government agency, using an email address on that agency’s domain, obtained sens… Continue reading Week in review: Cisco patches exploited email gateway 0-day, Revolut breach→

The modern attack chain: Rethinking Google Workspace security in the age of AI

Over the past two months, I’ve written about the Vercel breach and the Composio breach separately. Both offer lessons to learn on their own. But reading them together, I keep coming back to the same observation: these aren’t isolated incide… Continue reading The modern attack chain: Rethinking Google Workspace security in the age of AI→

Week in review: Linux rootkit deployed on F5 BIG-IP APM devices, Cisco FMC bugs exploited

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Zero trust AI agents demand a different kind of security In this interview, Chris Webber, VP, Product Marketing at Teleport, explains why zero trust princ… Continue reading Week in review: Linux rootkit deployed on F5 BIG-IP APM devices, Cisco FMC bugs exploited→

Building a ransomware decision tree before the call comes in

In this Help Net Security video, Kerri Shafer-Page, VP of Incident Response at Arctic Wolf, walks through the ransomware decision tree in this video. She covers four areas where decisions need settling in advance, starting with containment. Someone has… Continue reading Building a ransomware decision tree before the call comes in→

Product showcase: GitGuardian Honeytoken catches credential theft as it happens

Credential harvesting on developer machines has widened. Earlier infostealers worked from a short list of known targets, mostly browser stores and a few cloud credential paths. The families active now cast a much wider net. Shai-Hulud, for instance, ra… Continue reading Product showcase: GitGuardian Honeytoken catches credential theft as it happens→

Gartner: 70% of SOCs will pilot AI agents. Only 15% will see results

In the Gartner report Validate the Promises of AI SOC Agents With These Key Questions, analysts Craig Lawson and Andrew Davies posit that “By 2028, 70% of large SOCs will pilot AI agents to augment Tier 1 and Tier 2 operations, but only 15% will achiev… Continue reading Gartner: 70% of SOCs will pilot AI agents. Only 15% will see results→

What breach and attack simulation needs to become in the AI era

Breach and attack simulation (BAS) has always had a supply chain. Somebody has to read the threat report, pull out the techniques, and turn them into something that will actually run against your controls. That somebody has always been a human red team… Continue reading What breach and attack simulation needs to become in the AI era→