Marlin AI automatically analyzes SaaS misconfigurations, investigates related activity across enterprise environments, and recommends remediation steps — while stopping short of fully autonomous corrective action.
Hi, what are you looking for?
Marlin AI automatically analyzes SaaS misconfigurations, investigates related activity across enterprise environments, and recommends remediation steps — while stopping short of fully autonomous corrective action.
Nimbus Manticore has continued its operations during and after the US military campaign against Iran.
The allegedly stolen information leaked by ShinyHunters contains email addresses, names, addresses, and dates of birth.
Notable integrations include CrowdStrike, Palo Alto Networks, Microsoft, Okta, Zscaler, Netskope, Cloudflare, Fortinet, and Wiz.
Hardcoded machineKey values in a configuration file enabled ViewState deserialization attacks leading to remote code execution.
Register to enjoy free access and explore the tools, strategies, and frameworks needed to build a resilient security program for a world where every minute counts.
DockSec, an OWASP incubator project, correlates findings from multiple container security scanners and uses AI to generate plain-English remediation guidance and exact Dockerfile fixes.
Lithuanian authorities are on high alert after a massive data leak involving more than 600,000 entries from national data registers.
The two own Dutch companies that allegedly provided bulletproof hosting services to Russia-aligned threat actors.
Sites belonging to major universities such as Harvard and Oxford, as well as DuckDuckGo, have been compromised in the attack.
The affected third-party vendor has not been named, but one possible candidate is TriZetto.
Threat actors stole files containing names and protected health information from the healthcare organization’s systems.
Many findings have been confirmed to be critical or high-severity vulnerabilities and the number will continue to increase.
Published within a 15-minute window, the malicious tags introduced backdoors to exfiltrate CI secrets.
Hackers accessed names, addresses, Social Security numbers, financial information, and medical data from third-party partner repositories.
Fake automated commits injected GitHub Actions workflows containing payloads to steal credentials, CI secrets, keys, and tokens.