Expert analysis
September 2026 Patch Tuesday forecast: All we need is more time
The Patch Apocalypse is continuing unabated. We are seeing record numbers of patches being released and reported CVEs continue to grow as well. August 2026 Patch Tuesday was …
Your threat feed is someone else’s database: What ingesting malware intel at scale takes
The advice is to consume shared threat intelligence. Join the ISAC. Wire the community feeds into your pipeline. This looks like a fine advice and I agree to it. What nobody …
NIS2 compliance: Fixing IAM and access control before the 2026 audit
The NIS2 Directive places direct obligations on organizations across supply chain risk management, incident reporting, and board-level accountability. October brings a new …
A hollowed out data layer is making CISOs fly blind into AI attacks
The security industry is currently transitioning to an era where both offense and defense are AI-led, and every SOC operates at machine speed. However, what most CISOs have …
338 million attack simulations reveal the state of enterprise defense
First, a bit of good news: Enterprise defenses are recovering. However, it’s a narrow recovery, with a twist. Today, organizations are better at stopping loud attacks but have …
Who will be the Stanislav Petrov in your organization?
The recent news coverage of “rogue AI” systems hacking innocent companies reminded me of one of the world’s most unsung heroes and genuinely someone who may well have saved …
August 2026 Patch Tuesday forecast: How do we deal with the patch apocalypse?
July 2026 Patch Tuesday was record-setting in so many ways. The sheer volume of security patches for almost every product in the Microsoft portfolio was the highest ever and, …
Shadow AI is becoming enterprise security’s biggest blind spot
Artificial intelligence has moved from experimentation to everyday business operations with remarkable speed. Employees are using it to summarize documents, draft …
The MDR renewal question: What changes when AI can handle the alerts
For most of the past decade, the managed detection and response (MDR) decision was a simple one: teams that couldn’t staff a 24/7 SOC outsourced detection and response …
Why SBOMs, signing, and provenance still don’t tell you if software is safe
We have made real progress in software supply chain security, improving visibility into software components, authenticity and build integrity. Much of this progress traces …
July 2026 Patch Tuesday forecast: Is CVE tracking still practical?
I was off by a month in my forecast of record-setting CVE releases from Microsoft. In June, we saw the deluge of over 200 reported CVEs that I expected in May. There were 116 …
How to implement a continuous offensive security testing program
The hard part was never finding the exposure. It was deciding what to do about it: whether to patch, mitigate, monitor, or accept, and banking that that decision would still …
Featured news
Resources
Don't miss
- Thomson Reuters reveals breach that exposed U.S. and Canadian court records
- Your threat feed is someone else’s database: What ingesting malware intel at scale takes
- When AI quietly breaks things, who pays?
- Download: The Agentic Software Development Guide
- Exploitation of Sangoma Switchvox flaw is underway (CVE-2026-9586)