Penetration Testing and AppSec Red team vs penetration test: differences and choice
Red team or penetration test? Compare objectives, scope, duration, cost, detection goals and deliverables to choose the right security assessment.
Daily news, analysis and practical guides explaining what happened, who is affected and what to do next. We also turn this knowledge into practical training for organisations.
Penetration Testing and AppSec Red team or penetration test? Compare objectives, scope, duration, cost, detection goals and deliverables to choose the right security assessment.
Cloud, Infrastructure and DevSecOps SAST, DAST or IAST? Compare coverage, SDLC timing, strengths, limitations, false positives and a practical AppSec rollout without alert overload.
Supply Chain Security Learn what an SBOM is, how CycloneDX and SPDX differ, where VEX fits, which minimum elements matter and how to build a trustworthy CI/CD process.
AI Security Alert fatigue, lack of analysts and an avalanche of logs - AI really helps defenders with triage, anomaly detection and response. Where it works, where it fails and why a person stays.
AI Security The UK AI Security Institute tested agents in its AWS staging environment. One found a five-step privilege escalation chain for under £150.
Cloud, Infrastructure and DevSecOps Apple is moving selected PCC workloads to confidential computing on Google Cloud. We examine attestation, administrator access and trust boundaries.
Vulnerabilities and CVEs CVE-2026-0300 enables unauthenticated root RCE in a specific PAN-OS Authentication Portal configuration. Check exposure, patches and mitigations.
Vulnerabilities and CVEs CVE-2026-10520 is an actively exploited CVSS 10 unauthenticated root RCE in Ivanti Sentry. Check affected versions, patches and response steps.
Vulnerabilities and CVEs CVE-2026-11645 in Chrome V8 is actively exploited. Check fixed Chrome and Edge versions and the response steps for users and administrators.
Vulnerabilities and CVEs CVE-2026-28318 lets an unauthenticated attacker crash SolarWinds Serv-U with a crafted POST request. Review affected versions, Hotfix 1 and mitigations.
Vulnerabilities and CVEs CVE-2026-41089 is an actively exploited unauthenticated Netlogon RCE on Windows domain controllers. Review affected systems and response steps.
Vulnerabilities and CVEs CVE-2026-42897 executes JavaScript after a crafted email is opened in on-premises OWA. Review scope, fixes and new OWAReaper evidence.
AI Security DeepMind proposes TRAIT&R, detection levels and 15 safeguards for AI agents. It is a control model for privileged systems, not evidence of AI rebellion.
Governance and Compliance The EU approved a code for AI-generated content transparency. Learn what AI Act Article 50 requires from 2 August and how companies should prepare.
AI Security After temporarily disabling Fable 5, Anthropic described new safeguards and the proposed CJS 0–4 scale. Learn how to assess jailbreak severity.
Once a month, a concise summary of the vulnerabilities and threats that matter. No spam, unsubscribe anytime.