Skip to main content

Topic

Emerging Issue

Featured image for Governing AI-driven infrastructure: When AI handles 80% of the work, who governs the other 20% blog post
Jun 10, 2026

AI is reshaping DevOps and platform engineering by automating routine implementation work such as pipeline generation, container configuration, and assisting with Kubernetes issue resolution that once required deep hands-on expertise. The critical question for enterprise teams isn't whether AI can support this work, but whether humans still understand what actually occurred and have the right controls in place to catch problems before they propagate.

Featured image for Latest agentic AI developments and industry trends blog post
Jun 5, 2026

A practitioner's guide to the capability shifts, framework changes, and regulatory developments reshaping how enterprise IT and cybersecurity teams govern, deploy, and defend against autonomous agents.

CTI blog image
Jun 3, 2026

A critical, unauthenticated remote code execution vulnerability in Windows Netlogon (CVE-2026-41089, CVSS 9.8) lets a remote attacker run code as SYSTEM on a domain controller. Patch all domain controllers in the same maintenance window with the May 2026 security updates.

Featured image for Locked Shields and the OSI Model: Stop blaming the firewall blog post
Jun 3, 2026

A back-to-basics walk through what blue teams actually defend at each layer, and why the unglamorous stuff (Layer 2, BGP) keeps deciding the scoreboard.

Featured image for GitHub breach: What the incident really tells security teams about extension hygiene blog post
May 20, 2026

On May 20, 2026, GitHub disclosed that an employee device was compromised through a malicious VS Code extension, with attackers claiming to have exfiltrated roughly 3,800 internal repositories.

Featured image for Mini Shai-Hulud supply chain attack blog post
May 13, 2026

The Mini Shai-Hulud supply chain attack compromised more than 170 packages across npm and PyPI, including packages from TanStack, Mistral AI, and Guardrails AI, by hijacking legitimate CI/CD publishing workflows to distribute malicious versions that still carried apparently valid provenance signals.

Featured image for s Windows Autopatch ready for enterprise use, or does it trade too much control for convenience blog post
May 13, 2026

Windows Autopatch is a Microsoft service, included with Windows Enterprise E3 and above, that automates the scheduling and deployment of Windows quality updates, driver updates, and Microsoft 365 app updates across Intune-managed devices. It reduces the manual overhead of patch scheduling by managing update rings and cadence on your behalf, but it does so by abstracting away the granular controls that enterprise patch management workflows typically depend on.

Featured image for Copy Fail (CVE-2026-31431): What Linux administrators need to know now blog post
Apr 30, 2026

Copy Fail, or CVE-2026-31431, is a Linux kernel local privilege escalation vulnerability that can let an unprivileged local user corrupt page-cache-backed file data under specific conditions and potentially escalate privileges. Exposure depends on the running vendor kernel and backported fixes. Installing a vendor-provided kernel fix is the primary remediation, with temporary mitigations available in some environments if patching is delayed.

How Mythos is reshaping enterprise security posture video thumbnail
Apr 28, 2026

Tanium CRO Pedro Diaz and Sr. Director of Solution Engineering Mark Liu break down why Anthropic's Mythos model is fundamentally changing the threat landscape, and what enterprise security teams must do right now to keep pace with machine-speed attacks.

Featured image for Vercel security incident blog post
Apr 20, 2026

Public reporting suggests the incident involved abuse of a third-party application that had been granted OAuth access to a Vercel employee account, enabling unauthorized access to some internal resources. Certain customer‑related tokens, environment variables, or other access artifacts may have been exposed, though Vercel has not stated that password theft was part of the initial access path. The breach illustrates how trusted SaaS integrations and delegated access have become a significant attack surface for enterprises with interconnected developer workflows, even when no software vulnerability in production infrastructure is exploited.

Featured blog image for Understanding shadow AI in your endpoint environment
Apr 14, 2026

Learn how shadow AI appears on endpoints, from local models to MCP servers, and why visibility, governance, and secure configuration matter now.

Blog image for Claude Mythos security risks
Apr 13, 2026

Anthropic's Claude Mythos Preview demonstrated significant acceleration in capabilities for autonomously identifying vulnerabilities and exploit chains across major software and operating systems. Government and industry leaders are focused on understanding the real risks the model presents, and how to leverage these advanced technologies to protect and defend against adversarial use.