Blog

Posts

  1. Engineering

    Introducing DOM-0.8B DOM-0.8B and VAKT bring code-security review to your machine, helping you prioritise what to investigate before production.
  2. Threat Brief

    Securing Agentic AI: Evaluating the Muse Spark 1.1 Sandbox Incident Recent unauthorized access incidents involving frontier AI models emphasize the necessity of rigorous testing environment isolation. By implementing strict configuration controls and continuous monitoring, organizations can safely evaluate agentic models without exposing external systems.
  3. Threat Brief

    Evaluating the Efficacy of AI-Generated Security Patches Recent data indicates that AI-generated patches successfully resolve vulnerabilities less than half the time, often introducing new defects. Security teams can maintain the productivity benefits of AI by pairing generation tools with rigorous human validation and formal verification.
  4. Threat Brief

    Addressing the coordination gap: Enhancing law enforcement and industry collaboration Security experts at Black Hat USA 2026 outlined how AI and affiliate models are enabling threat actors to scale their operations, requiring a more cohesive, structural response from law enforcement and the security community.
  5. Threat Brief

    Building a Security-First Culture: Methodologies From the Democratic National Committee Former and current security leaders from the Democratic National Committee share how they established a resilient security culture, focusing on hardware keys, cloud infrastructure, and executive co-ownership.
  6. Threat Brief

    Security evaluation demonstrates cross-tenant data transfer in ChatGPT sandbox Security researchers presented a proof-of-concept methodology at Black Hat USA 2026 for bypassing ChatGPT's large language model supervisor. The findings outline a sequence for executing background processes and transferring data between isolated sandboxes, prompting architectural updates by OpenAI.
  7. Threat Brief

    AI Browsers Susceptible to 'PleaseFix' Zero-Click Agent Redirection Security researchers have identified a new class of vulnerabilities in AI browsers that allows everyday content to manipulate agent actions. Protecting users requires a shift in how organizations configure trust boundaries and limit agent permissions.
  8. Signal Shorts

    Aligning Organizational Structure with Security Strategy An analysis of the eighth annual Omdia and ISSA study, examining how organizational design, leadership models, and technology consolidation directly impact security team resilience and effectiveness.
  9. Threat Brief

    Aligning security leadership: Structural solutions to CISO fatigue Recent industry data indicates that elevated stress among cybersecurity professionals stems from organizational design rather than purely staffing shortages. By aligning accountability with authority and integrating technology stacks, organizations can improve operational resilience and better support their security leaders.
  10. Engineering

    Vakttårn A vulnerability-identification and solution model for scans that need resolution.
  11. Engineering

    Minisøk A fast vulnerability-identification model for scans that need findings without generated solutions.
  12. Signal Shorts

    Addressing the intersection of legacy OT exposure and autonomous AI software As organizations work to secure legacy physical infrastructure, security researchers are observing the development of autonomous software agents capable of reasoning and lateral movement. This convergence requires security teams to adopt foundational defenses and increase remediation velocity to protect both operational technology and cloud environments.
  13. Threat Brief

    Federal Executive Order Outlines Voluntary Frontier AI Evaluation and Cybersecurity Mandates A new executive order establishes a voluntary early-access framework for frontier AI models and directs federal agencies to support civilian and national security cybersecurity programs. For security practitioners, the directive signals an upcoming influx of vulnerability data and emphasizes the need to reinforce defensive fundamentals and integrate AI tools into existing workflows.
  14. Threat Brief

    Preparing for Adaptive AI Worms in Enterprise Environments Security researchers have demonstrated proof-of-concept AI worms capable of autonomous propagation and reasoning. By understanding these emerging methods, organizations can implement foundational safeguards like zero-trust architecture and micro-segmentation to protect their infrastructure.
  15. Threat Brief

    Securing Internet-Exposed Automatic Tank Gauges Against Unauthorized Access Following a joint advisory from US federal agencies, we review the operational risks associated with internet-facing automatic tank gauge (ATG) systems and provide actionable remediation steps to safeguard critical industrial environments.
  16. Threat Brief

    Analysis of SideCopy Threat Actor Surveillance Against the Afghan Finance Ministry Security researchers have detailed an ongoing espionage campaign by the SideCopy threat group targeting Afghanistan's Ministry of Finance. This assessment outlines the threat actor's methodology, including their use of localized decoys and compromised sovereign infrastructure to deploy remote access tools.
  17. Threat Brief

    Evaluating four critical threat vectors identified at the 2026 Gartner Security Summit Analysts at the 2026 Gartner Security & Risk Management Summit identified deepfakes, software supply chain risks, prompt injections, and AI application compromises as pressing areas where threat actors currently hold an advantage. By implementing layered authentication, strict access controls, and regular security assessments, organizations can effectively safeguard their systems against these vectors.
  18. Threat Brief

    Rust-written IronWorm malware impacts npm supply chain Security researchers have identified IronWorm, a custom Rust-based malware sample designed to compromise npm publishing workflows and harvest developer secrets. By understanding its evasion techniques and targeting methods, security teams can better protect continuous integration environments and software supply chains.
  19. Threat Brief

    Unauthorized Email Access Campaign Targets Global Stock Exchange Executive Security researchers recently identified a prolonged unauthorized access campaign targeting a senior executive at a global stock exchange. By analyzing the threat actor's methodology, organizations can better understand how to protect their cloud environments and implement effective detection strategies.
  20. Threat Brief

    Security Researchers Identify Indirect Prompt Injection Risk in Google Gemini Notifications SafeBreach researchers demonstrated how untrusted input in messaging notifications could allow unauthorized parties to bypass Google Gemini’s guardrails. Following responsible disclosure, Google has issued content classifier updates to block these indirect prompt injections.
  21. Threat Brief

    Debug configuration vulnerability in Microsoft 365 Android applications enables unauthorized token access A debug setting left enabled in a shared Microsoft Android SDK bypassed authentication checks, allowing unauthorized applications to request sensitive FOCI tokens. Microsoft has patched the affected applications, and organizations should ensure their mobile fleets are updated.
  22. Threat Brief

    Cyber insurance rates stabilize as coverage exclusions expand While cyber insurance premiums are becoming more affordable, carriers are simultaneously introducing strict coverage exclusions and sub-limits. Organizations must carefully review their policies to ensure continuous protection against social engineering, state-backed incidents, and mass outages.
  23. Threat Brief

    Analyzing State-Sponsored Cyber Operations in Latin America and the Caribbean A review of recent cyber operations targeting government and critical infrastructure sectors in the Americas, driven by geopolitical shifts. This analysis outlines the observed access methods, including identity-based vectors and edge device targeting, alongside prioritized remediation steps for security teams.
  24. Threat Brief

    Threat actors use AI models to automate EDR bypass testing Recent findings show threat actors using AI tools to iteratively test unauthorized software against common endpoint detection and response (EDR) agents. While this automated methodology increases the speed of adversary research, organizations can protect their environments by maintaining foundational security practices like defense-in-depth and modern authentication.
enes