
All articles/Topic
Cyber Security
When AI must not act alone: human-in-the-loop patterns for security automation
Most of the AI security work we do for clients ends up hinging on one question: what is this thing allowed to do on its own at 3am on a Sunday? Everything else follows from the answer. Model choice, prompt design, which…
#human-in-the-loop#security-automation#ai-governance#audit-trail#soc-operations
Cloud posture on autopilot: continuously auditing AWS, Azure and Microsoft 365
Most of the cloud security incidents we get called into have nothing to do with a novel exploit. Someone opened a security group to 0.0.0.0/0 for a vendor's remote session and never closed it. A storage account got…
#cloud-security#microsoft-365#azure#aws#configuration-drift#continuous-compliance
Supply-chain attacks: package cooldowns and policy checks for npm, PyPI and NuGet
On 4 August 2026, a self-propagating worm called ChainDrop tore through npm. BleepingComputer reported more than 1,300 compromised packages with about two billion monthly downloads between them, including keyv,…
#supply-chain-security#npm#dependency-management#devsecops#ci-cd
Cutting vulnerability noise: using AI and public data to demote CVEs that don't matter
A container image scan finishes and hands back a few hundred findings. A dozen are critical. Most of the rest are base image packages with a CVE ID, a CVSS score, and no patched version anywhere in the world. The team…
#vulnerability-management#cve#patch-management#devsecops#osv
Ransomware early warning: watching leak sites for your name, your clients and your suppliers
On 13 August the Clop ransomware group posted claims naming Shell and Philips, and both companies confirmed they had experienced a security incident once the claims were reported (NL Times). Philips called it an…
#ransomware#threat-intelligence#incident-response#supply-chain#notifiable-data-breaches