Why you need BAS and autonomous pentesting together

Most security teams know the drill: A new autonomous penetration testing tool gets deployed, and the first run is genuinely impressive. The dashboard surfaces critical findings, maps lateral movement paths nobody had documented before, and exposes a le… Continue reading Why you need BAS and autonomous pentesting together

Week in review: Infostealer dropped via FortiClient EMS flaw, exploited Trend Micro Apex One flaw

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Coinflow CISO on crypto payments security under AI pressure Crypto payment firms sit near the top of the target list for advanced persistent threat groups… Continue reading Week in review: Infostealer dropped via FortiClient EMS flaw, exploited Trend Micro Apex One flaw

Building a risk-based vulnerability management program that scales

In this Help Net Security video, Shankar Somasundaram, CEO at Asimily, explains how to build a risk-based vulnerability program. He notes that vulnerabilities are exploding by an order of magnitude in the age of AI-driven attacks, with one customer fin… Continue reading Building a risk-based vulnerability management program that scales

The alert economy is driving security analyst burnout

In this Help Net Security video, Ido Livneh, CEO of Jazz, explains why security analysts burn out and what leaders can do about it. The cause, he argues, is not long hours but meaningless work. Analysts spend their days closing repetitive tickets while… Continue reading The alert economy is driving security analyst burnout

Manage machine identities: The hidden privileged access layer you need to manage

Why are machine identities becoming the majority of “things with access”? Every automation, integration, and workload needs a way to authenticate and the right permissions to act. That quiet requirement has created a massive population of machine ident… Continue reading Manage machine identities: The hidden privileged access layer you need to manage

Lessons for organizations from the Verizon 2026 Data Breach Investigations Report

This is my favourite time of the year, not just because spring is here and the promise of summer is on the way. But also, because one of my must reads each year gets published. There are a few must read reports that I have on my reading list for each y… Continue reading Lessons for organizations from the Verizon 2026 Data Breach Investigations Report

Boards want cyber risk in dollars, not CVE counts

In this Help Net Security video, Ziv Levi, SVP of Technology at CYE, explains why translating cyber risk into dollars is one of the most pressing tasks for security leaders. Boards and executives want cyber exposure described in business terms, not tec… Continue reading Boards want cyber risk in dollars, not CVE counts

Week in review: GitHub breached via poisoned VS Code extension, critical NGINX flaw exploited

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: TeamPCP breached GitHub’s internal codebase via poisoned VS Code extension Following TeamPCP’s claim that they’ve breached GitHub’s own private code repos… Continue reading Week in review: GitHub breached via poisoned VS Code extension, critical NGINX flaw exploited

Keepnet contributes voice and SMS phishing data to the 2026 Verizon DBIR

Keepnet, an Extended Human Risk Management (xHRM) platform, today announced that its voice and SMS phishing simulation data contributed to the 2026 Verizon Data Breach Investigations Report (DBIR). The 2026 edition is the first to include voice and SMS… Continue reading Keepnet contributes voice and SMS phishing data to the 2026 Verizon DBIR