DevOps Security

DevOps Security

⚠

Mapping the Unknown: Introducing Pius for Organizational Asset Discovery

Asset discovery is an essential part of Praetorian’s service delivery process. When we are engaged to carry out continuous external penetration testing, one key action is to build and maintain a thorough ...
Anton Chuvakin Interviews D3's Gordon Benoit about Morpheus AI

Your SOC Doesn’t Need More Tools. It Needs Fewer.

The average SOC manages 83 security tools from nearly 30 vendors. Why the smartest CISOs are consolidating their security operations, and how D3 Morpheus makes it possible without compromising coverage. The post ...
Lumma, infostealer RATs Reliaquest

Latest OpenClaw Security Risk: Fake GitHub Repositories Used to Deploy Infostealers

Huntress researchers said actors used a malicious repository on GitHub to lure victims into downloading a bogus OpenClaw installer that delivered infostealer malware and the GhostSocks proxy. The fake installer was given ...
Security Boulevard
A graphic visualization of Morpheus AI SOC's architecture

6 Minutes and a Prayer: The Math Your SOC Doesn’t Want You to See

Your SOC can't triage every alert — the math proves it. See why 75% of alerts go uninvestigated and how AI-autonomous triage closes the gap. The post 6 Minutes and a Prayer: ...
The Evolution of OSS Index in the Age of AI

The Evolution of OSS Index in the Age of AI

In the past 12 months, enterprise software development has changed faster than at any other point in our lifetime ...
medusa, Snowflake data breach hacker arrested

Latest OpenClaw Flaw Can Let Malicious Websites Hijack Local AI Agents

Oasis Security researchers find another security problem with the OpenClaw autonomous AI agent, uncovering a vulnerability dubbed "ClawJacked" that allows malicious websites to silently take full control of a developer's system and ...
Security Boulevard
Modern Vulnerability Management in the Age of AI

Modern Vulnerability Management in the Age of AI

Vulnerability management today is not failing because teams stopped scanning. It's failing because the ground underneath it shifted. The approach we've relied on — complete advisory data, upstream fixes on demand, and ...
A graphic visualization of Morpheus AI SOC's architecture

SOAR Is Costing More Than You Think

SOAR's real cost isn't license plus runtime. It's integration maintenance, playbook engineering, and analyst time. Here's how to find the number you're actually paying. The post SOAR Is Costing More Than You ...
Titus Burp Suite extension showing detected secrets in HTTP proxy traffic

There’s Always Something: Secrets Detection at Engagement Scale with Titus

TL;DR: Titus is an open source secret scanner from Praetorian that detects and validates leaked credentials across source code, binary files, and HTTP traffic. It ships with 450+ detection rules and runs ...
]