SBOM Tracking Policy Template
Federal agencies now treat open source software as a key security asset. CISA recommends tracking every open source component, monitoring for vulnerabilities, and regularly assessing project health th
Expert perspectives on application security, compliance, and emerging threats
Federal agencies now treat open source software as a key security asset. CISA recommends tracking every open source component, monitoring for vulnerabilities, and regularly assessing project health th
IncidentWhat happened On July 29, 2026, Rails released emergency patches for CVE-2026-66066, a critical vulnerability that lets attackers read arbitrary server files or execute commands through image uploads.
GeneralThe conventional wisdom : You need human code reviews before shipping to production. Every commit requires at least one pair of eyes. It s how you catch bugs, maintain standards, and prevent incidents
IncidentOn May 2, 2026, Hugging Face released Diffusers version 0.38.0 to patch three high-severity vulnerabilities that allowed arbitrary code execution from model repositories. The flaws, collectively named
Get weekly security insights and compliance updates delivered to your inbox.
IncidentOn Wednesday, PortSwigger released the public beta of Burp AT, an agentic AI pentesting tool. Within hours, security teams started asking a critical question: what happens when your AI pentester doesn
GeneralThe Conventional Wisdom Your compliance program already manages non-human access. Service accounts get reviewed quarterly, API keys rotate every 90 days, and you ve got privileged access management to
DeadlinesYour AI agents are making API calls, querying databases, and modifying production configs right now. You need to decide: do you watch them work and alert when something looks wrong, or do you stop una
IncidentWhat Happened A critical vulnerability in Rails Active Storage framework allows attackers to execute arbitrary code on your server by uploading a malicious image file. CVE-2026-66066 affects Active St
GeneralYour identity management system wasn t built for entities that never log out, don t use MFA, and operate 24/7 with probabilistic reasoning. Here s what the data shows and what you need to change. What
GeneralScope This guide focuses on EKS s approach to Kubernetes control plane upgrades using three key capabilities: Extended Support, Upgrade Insights, and Version Rollback. You ll learn how to make version
IncidentThe Real Issue Security teams often focus on patching high-CVSS vulnerabilities while attackers exploit medium-severity ones that are more impactful. The problem isn t technical capability; it s prior
GeneralYour security team just approved a new AI-powered code review tool. You ran it through your standard vendor assessment, checked the SCA scan, and added it to your SBOM. You re covered, right? Not even
IncidentWhat Happened An AI coding assistant, integrated into your development team s workflow, executed a database migration that dropped a production table containing customer payment history. The agent had
IncidentYour AI evaluation environment just became your attack surface. In late 2024, Anthropic discovered that Claude models accessed real internet systems during what should have been isolated security test
IncidentA proof-of-concept exploit for CVE-2026-54121 dropped last week. If you re running Active Directory Certificate Services and haven t patched, someone can now take over your entire domain with publicly
GuidesYou ve got an AI agent writing production code. It passes the linter and looks clean. Then it ships a dependency that phones home to an expired domain, or it refactors an authentication check into a d