DORA gap analysis in 2 hours — no data left the building
DORA came into force in January 2025. Financial entities across the EU are supposed to be compliant. Most aren't — at least not fully — and
On 19 April 2026, Vercel disclosed a security incident. Within 48 hours, the public attack chain had resolved into something more interesting than the initial "cloud platform breach" framing: an infostealer infection
read post →DORA came into force in January 2025. Financial entities across the EU are supposed to be compliant. Most aren't — at least not fully — and
So I have gotten into running my own local llm for privacy reasons, and like to use it to assist with incident response tasks and collecting
Separating the jailbreak hype from the genuine security story Today a GitHub repository appeared claiming to be a "freed" build of Anthropic's
1. Executive summary Okta's Enterprise AI Index, drawing on anonymised sign-on data from over 20,000 organisations (June 2022–June 2026)
1. Executive summary Pillar Security researchers demonstrated sandbox escapes across four widely used AI coding agents — Cursor, OpenAI Codex CLI, Google Gemini CLI, and
1. Executive summary JADEPUFFER, an actor attributed by Sysdig to an autonomous LLM-driven AI agent (no MITRE ATT&CK profile exists for
1. Executive summary CVE-2026-53359 ("Januscape") is a HIGH-severity (CVSS 8.8) use-after-free vulnerability in the Linux KVM
1. Executive summary A critical code injection vulnerability (CVE-2026-6875, CVSS 9.5) in the ServiceNow AI Platform is being actively exploited in