Author
Melissa Bischoping

May 2026 GitHub breach: Extension hygiene is still a challenge–so what can we do about it?
On May 20, 2026, GitHub disclosed that an employee device was compromised through a malicious VS Code extension, with attackers claiming to have exfiltrated roughly 3,800 internal repositories.

Mini Shai-Hulud supply chain attack: Why this campaign changes how defenders should think about trusted software
The Mini Shai-Hulud supply chain attack compromised more than 170 packages across npm and PyPI, including packages from TanStack, Mistral AI, and Guardrails AI, by hijacking legitimate CI/CD publishing workflows to distribute malicious versions that still carried apparently valid provenance signals.

How smart governance can contain agentic sprawl
As AI agents multiply at machine speed across the enterprise, governance must evolve to match their autonomy, scale, and risk.

Understanding shadow AI in your endpoint environment
Learn how shadow AI appears on endpoints, from local models to MCP servers, and why visibility, governance, and secure configuration matter now.

IDE extensions: a new persistent risk to your organization
User-installable extensions for Visual Studio Code, Cursor, and other Integrated Development Environments are an increasingly exploited attack vector, with new malicious extensions discovered almost weekly. Do you have visibility and control?

Ep. 16: We Need to Get Proactive About Vulnerability Management
Nick Brown, a senior engineer at True Zero Technologies, explains why criticality, risk acceptance, and AI tools are key to staying ahead of common vulnerabilities and exposures (CVEs).

Ep. 15: It’s Tougher Than Ever to Be a CISO – and It’s Time to Admit It
More enterprises are now expecting the CISO role to shift from security techno brain to executive risk manager who's there to protect the business. It’s critical for chief information security officers to talk about the stress and get support.

Ep. 14: How to Lead a Threat Intelligence Team
Microsoft’s Sherrod DeGrippo, self-described “weird security voyeur,” shares her strategies for making threat intel actionable, building teams that trust their intuition, and – here’s the big one – getting your CISO totally on board.

7 Ways to Defend Your Software Supply Chain
As hackers get more sophisticated and software more complex, CISOs must improve their ability to identify, isolate, and mitigate malicious software attacks.

Ep. 3: Why It’s Time to Trust in Digital Trust, Part 2
As consumer trust plummets, an ISACA survey shows how enterprises can rebuild it—even after a cyberattack.

Ep. 2: Why It’s Time to Trust in Digital Trust, Part 1
An informative ISACA survey reveals today’s digital trust landscape. The surprising takeaway? Maximizing trust minimizes cybersecurity risk.

Develop a Cybersecurity Action Plan: Understanding IT Risk Management
Part two in this series on how to create and deploy an action plan that strengthens your organization’s cyber defenses.

Develop a Cybersecurity Action Plan: Focusing on Visibility and Breaking Down Silos
A cybersecurity action plan that prioritizes visibility and breaks down IT silos is essential for protecting your organization.

Endpoint hardening and preparedness in a changing threat landscape
With the conflict between Russia and Ukraine impacting the cyber threat landscape, organizations must close any gaps in patching workflows.

Best Practices for Responding to the Log4j Vulnerability and Preparing for the Next
Learn how to respond to the Log4j vulnerability and prepare for the future with tools for detecting vulnerable software components.