Identity and Access Post-Quantum Cryptography: Why Migration Needs to Start Now
A quantum computer will break RSA and ECC, and the "collect now, decrypt later" attack is underway today. We discuss ML-KEM, ML-DSA, hybrid modes and migration plan.
Daily news, analysis and practical guides explaining what happened, who is affected and what to do next. We also turn this knowledge into practical training for organisations.
Identity and Access A quantum computer will break RSA and ECC, and the "collect now, decrypt later" attack is underway today. We discuss ML-KEM, ML-DSA, hybrid modes and migration plan.
Penetration Testing and AppSec eBPF allows you to run programs in the Linux kernel without modules - it powers modern monitoring and networking, but can also be a rootkit tool. Technically and about hardening.
Threats and Incidents Black Kite reports disclosed ransomware in Europe rose 55% in 2026, with manufacturing the top target. What it means for companies across the EU.
Penetration Testing and AppSec A well-prepared penetration test delivers more value for the same money. How the process works, what to agree up front and how to read the report.
AI Security RAG connects LLMs to documents but adds prompt injection, data leakage and poisoning. Secure ingestion, retrieval, vector stores and model output.
AI Security AI agents carry out tasks, not just answer questions. Where agentic automation pays off, how to roll it out in stages and how to keep control.
AI Security AI incidents need evidence beyond classic breaches. Prepare response playbooks for prompt injection, data leaks, poisoning and agent tool abuse.
Cybersecurity History Kevin Mitnick was the world's most wanted hacker - and his weapons weren't exploits, but phones and psychology. A story of social engineering, an FBI chase and a second life.
Supply Chain Security Signing without key management (Sigstore) and verifiable build provenance (SLSA) are the new supply chain defense. We translate Fulcio, Rekor, cosign and SLSA levels.
Vulnerabilities and CVEs 2026 confirms a worrying trend: vulnerabilities are exploited faster than vendors ship patches. What it means for defence and how to keep up.
Threats and Incidents Improvising during an incident costs the most. We show NIST's six phases of response, ready-made playbooks, and what to prepare before the phone rings.
Penetration Testing and AppSec A regular domain account is enough to download a Kerberos ticket and crack the password of an offline service account. We explain TGS-REP, RC4 vs AES and effective defense.
AI Security An AI model registry connects owners, data, risk and deployments. Learn which fields, gates, evidence and lifecycle metrics governance needs.
Penetration Testing and AppSec DNS rebinding bypasses the same-origin policy and allows a website in the browser to reach the router, IoT or LAN admin panel. Mechanism and effective defense.
Cybersecurity History In May 2000, an email with the subject line "ILOVEYOU" infected millions of computers in a few hours and caused billions of dollars in damage. The story of a worm that exploited human curiosity.
Once a month, a concise summary of the vulnerabilities and threats that matter. No spam, unsubscribe anytime.