AI Security Implementing AI in your company: a practical guide
How to implement AI in your company without chaos or risk — from use case selection through data and security to pilots, ROI and scaling. A practical guide.
Daily news, analysis and practical guides explaining what happened, who is affected and what to do next. We also turn this knowledge into practical training for organisations.
AI Security How to implement AI in your company without chaos or risk — from use case selection through data and security to pilots, ROI and scaling. A practical guide.
Cybersecurity History In 2017, NotPetya exited a Ukrainian accounting program and paralyzed global corporations, causing $10 billion in losses. The story of a weapon that only pretended to be a ransom.
Penetration Testing and AppSec Secure by Design puts security outcomes on manufacturers. Apply CISA principles through safe defaults, transparent metrics and product governance.
Threats and Incidents A SQL injection reached guest data held for thousands of Polish hotels. Learn what reportedly leaked, why authenticated access is no defence and how guests, hotels and SaaS providers should respond.
Identity and Access PAM reduces risks from administrator accounts, secrets and sessions. Learn how to deploy JIT access, session control and meaningful metrics.
Threats and Incidents Purple teaming turns adversary techniques into measurable detection tests. Scope exercises safely, improve controls and prove the gaps are closed.
Cybersecurity History In 2021, ransomware stopped the largest fuel pipeline on the US East Coast. The input was one password without MFA. The story of an attack that showed the fragility of infrastructure.
Penetration Testing and AppSec A free website security scanner: HTTPS, headers, cookies, SPF/DMARC, library versions checked against OSV and more. Get a report under its own shareable link.
Penetration Testing and AppSec You scanned your site and see a grade and a list of issues — now what? We explain every finding type and show how to fix it, concretely.
Penetration Testing and AppSec HSTS, CSP, X-Frame-Options, Permissions-Policy, CORS and cookie flags - which security headers to implement, how to set them correctly and how to verify them.
Penetration Testing and AppSec Rapid Reset (CVE-2023-44487) leverages HTTP/2 multiplexing for record-breaking L7 attacks. We explain the stream mechanism, RST_STREAM and defense.
Penetration Testing and AppSec Pentest, audit and vulnerability scan are three different things, often confused. We explain how they differ, how much they cost and which service to choose for your situation.
Cloud, Infrastructure and DevSecOps Secure container images from Dockerfile and CI through signing, registries and runtime. Use this practical checklist for dependencies and deployment.
Cybersecurity History In 2014, a bug in OpenSSL allowed passwords and keys to be stolen from servers' memory - silently, without a trace. The story of Heartbleed, the era of "branded" vulnerabilities, and lessons about open source.
Penetration Testing and AppSec Before an attack lands, a criminal does reconnaissance. We show what OSINT reveals about your company and how to shrink your digital footprint.
Once a month, a concise summary of the vulnerabilities and threats that matter. No spam, unsubscribe anytime.