AI Security Shadow AI: discover and govern unsanctioned AI use
Shadow AI can expose data and create uncontrolled workflows. Discover tools, assess use-case risk and give employees secure, practical alternatives.
Daily news, analysis and practical guides explaining what happened, who is affected and what to do next. We also turn this knowledge into practical training for organisations.
AI Security Shadow AI can expose data and create uncontrolled workflows. Discover tools, assess use-case risk and give employees secure, practical alternatives.
AI Security LLM evaluation should measure quality, safety, cost and drift on real tasks. Build representative test suites and evidence-based production gates.
Governance and Compliance The amended KSC act implements NIS2 and applies from 3 April 2026. We explain who it covers, the deadlines and what you need to do.
Cloud, Infrastructure and DevSecOps BGP does not have built-in authentication, so routes can be hijacked and traffic redirected. We explain hijacking, route leaks and RPKI, ROA and ROV validation.
Cybersecurity History In 2014, hackers wiped Sony Pictures, leaked internal emails and threatened theaters — all because of a comedy about North Korea. The story of an attack that combined politics and censorship.
AI Security AI agents create a new class of non-human identity. Secure tokens, delegation, tools, audit and lifecycle without long-lived API credentials.
Careers and Certifications OSCP+ is a hands-on pentest and Active Directory exam. Learn its current format, scoring, evidence rules, report requirements and 70-point strategy.
Penetration Testing and AppSec Threat modeling is the cheapest way to detect design errors before they become code. We explain the STRIDE method, data flow diagrams and a practical approach.
Cybersecurity History In 1989, 20,000 floppy disks sent by mail ushered in the era of ransomware. The story of an AIDS Trojan, an eccentric biologist, and a ransom paid to a safe deposit box in Panama.
Careers and Certifications OSCE3 requires OSEP, OSWE and OSED. Compare technical scope, practical exams, prerequisite skills and the best order for three OffSec certifications.
Careers and Certifications This 12-week OSCP+ plan combines PEN-200, labs, Active Directory, privilege escalation and reporting. Build a repeatable exam-ready workflow.
Careers and Certifications An OSCP+ report protects points as much as an exploit. Capture valid proof, describe reproducible steps and submit the required archive correctly.
AI Security Claude Sonnet 5 expands agentic planning and tool use. Analyse prompt injection, cyber safeguards, permissions and a secure production architecture.
Careers and Certifications OSWE requires white-box analysis and exploit development. Build a code review workflow for data tracing, debugging and WEB-300 preparation.
Identity and Access Passkeys remove passwords and are phishing-resistant. We explain how they work, how they differ from MFA and how to start rolling them out.
Once a month, a concise summary of the vulnerabilities and threats that matter. No spam, unsubscribe anytime.