Articles

What Do False Positive Security Findings Actually Cost?
If even a quarter of a SOC analyst’s time goes to findings that need no action, that’s a real dollar cost on top of the burnout and missed real threats. Here’s what false positives actually drain from a security program, and how to fix it.

How Machine Identities Are Expanding the Modern Attack Surface
Certificates, API keys, service accounts, and tokens now outnumber human logins many times over in the average enterprise, and AI agents are adding to that pile faster than most security teams can govern it.

Cyber Insurance Rates Are Falling, But the Fine Print Could Leave You Exposed
Falling cyber insurance premiums sound like good news, but Gartner analysts say carriers are quietly stripping coverage for social engineering, war exclusions, and mass events, exclusions many policyholders won’t notice until they need to file a claim.

Attackers Are Weaponizing ChatGPT and Claude Share Links to Deliver Malware
A malicious ad for “chatgpt” leads not to a fake site but to a real chatgpt.com share link, one that every URL reputation checker trusts. Researchers detail how the LLMShare campaign hides malware delivery behind ChatGPT and Claude’s own domains.

5 Underestimations Security Teams Are Making About AI Adoption
Most security teams are still debating whether to allow AI, while shadow AI, ungoverned agent identities, and unvetted AI vendors are already creating exposure. Five mental models about technology risk that are leaving organizations underprepared.

Why Audit Preparation Becomes Chaotic, and the Operational Changes That Actually Fix It
Audit season doesn’t have to mean all-nighters and scrambled evidence hunts. This piece explains why audit preparation becomes chaotic and the specific operational changes, made year-round, that turn compliance from a seasonal crisis into a steady discipline.

Instructure Pays Off ShinyHunters to Contain Massive Canvas Data Breach
Instructure, the company behind the Canvas learning management system, paid the ransomware group ShinyHunters after a second breach exposed 3.6 terabytes of data and defaced login pages across its platform.

Why Security Backlogs Persist and How to Shrink Them: A Practical Playbook for Modern Teams
Vulnerability scanners, pentest reports, and compliance audits keep feeding the same backlog that never shrinks. This playbook explains why security backlogs persist and how to turn an unmanageable queue into a measurable, risk-driven program.

Two Americans Sentenced for Running ‘Laptop Farms’ That Helped North Korean IT Workers Infiltrate U.S. Companies
Two U.S. nationals were sentenced to prison for running ‘laptop farms’ that let North Korean IT workers pose as remote U.S. employees, infiltrating nearly 70 companies and funneling over $1.2 million back to the regime.

Building a CTEM Program Cost-Effectively: How to Get 90% of the Value from 10% of the Spend
You don’t need a seven-figure security stack to run Continuous Threat Exposure Management. This guide shows how organizations can capture most of CTEM’s value from a fraction of the typical spend.

North Korea Quietly Walked Off With 76% of 2026’s Stolen Crypto Using Only Two Attacks
New TRM Labs data shows North Korea-aligned hackers now control roughly 76% of all cryptocurrency stolen worldwide this year, achieved not through more attacks but through fewer, smarter, AI-assisted operations.

Why Security Is a Process Problem, Not a Technology Problem
Layering EDR on XDR on SIEM on SOAR hasn’t stopped breaches from getting worse. This article argues that security’s real weakness isn’t a lack of tools, but a lack of process discipline.