We share our expertise to make the world a safer place.
InfoSec moves at a rapid pace and sometimes it’s hard to keep up—that’s where we enter the chat.

Discover current cybersecurity insights
Get vital information straight from the experts, without all the noise.

AMA: CMMC Phase II Suspension and Beyond
Join Director of Advisory Services Chris Camejo and Compliance Practice Lead Lee Quinton for an expert breakdown of the recent CMMC changes and how to prepare…

A Vault With No Treasure - CMMC Level 2 Compliance for Subcontractors With No CUI
This blog post should not exist, but it does due to an unfortunate reality: Many large prime defense contractors are attempting to impose CMMC Level 2 audit…

The Art of Hunting Azure Cloud Secrets
The difference between a standard cloud test and a subscription takeover? Finding the right secrets. In this blog, we introduce two open-source tools for…

TLS Encryption and Compliance
Transport Layer Security: the compliance checkbox that's harder to get right than it looks. In this blog, we cover the most common TLS misconfigurations and…

Black Hat USA Training - Supply-Chain to Runtime: Attacking & Defending the Modern DevOps Stack
During our Black Hat training, go beyond network pentesting fundamentals and gain the attacker and defender perspective needed to conduct modern,…

AMA: CCPA's New Cybersecurity Audit Requirement
During this live AMA, you’ll get the chance to ask your pressing questions about the new CCPA regulations and find out how your organization can prepare for…

AI Directives and AI Strategy Development
The hardest part of AI adoption isn't the tech, it's the strategy. In this blog, we outline a practical framework covering governance, risk classification,…

CCPA Update: Cybersecurity Requirements (Part 2)
Confirmed you're in scope for CCPA? Now comes the cybersecurity audit requirement. In Part 2 of this blog series, we cover what it entails, the phased…

CCPA Update: Who’s In Scope (Part 1)
California updated CCPA... again. Before you do anything else, does it apply to you? In Part 1 of this blog series, we clarify who falls under scope, what data…

The New Hotness in Phishing: Device Code Attacks in M365
Device code phishing is quietly becoming one of the more effective techniques targeting M365 environments. In this blog, we detail how it works and the…

CMMC is (Not) Cancelled
Just because CMMC Phase II audits are paused doesn't mean compliance is. In this blog, we clarify what the suspension means for defense contractors and why…

Pandora’s Container Part 1: Unpacking Azure Container Security
Azure container services are everywhere. Their attack surface? Often overlooked. In Part 1 of this blog series, we walk through offensive techniques targeting…
Loading...
Get our best blogs, latest webinars, and podcasts sent to your inbox.
Our monthly newsletter makes it easy to stay up-to-date on the latest in security.
