Purple Red Blue

Blog — Insights from the Field

Latest Articles

The Rise of AI-Powered Phishing — What Defenders Need to Know

AI-generated phishing campaigns are becoming increasingly difficult to distinguish from legitimate communications. Here’s what organizations should be doing about it.

Read more →

Why Your Cloud Pentest Probably Isn't Testing the Right Things

Most cloud penetration tests focus on VM-level vulnerabilities while ignoring the IAM misconfigurations that actually lead to breaches.

Read more →

Lessons from a Ransomware Tabletop Exercise

We recently facilitated a ransomware tabletop exercise for a mid-size enterprise. Here are the gaps that surprised everyone in the room.

Read more →

Supply Chain Attacks Are Getting Harder to Detect — Here's Why

The latest wave of supply chain compromises targets build pipelines and package registries with techniques that evade traditional security controls.

Read more →