Wiz on Wiz: How the Wiz FinOps Team Uses Wiz Cloud Cost
Powering cost investigation and optimization with deep cloud context
Powering cost investigation and optimization with deep cloud context
AI is changing the context around data risk, making it critical to understand what’s connected, what’s exposed, and why.
A new free service called DecryptAds aggregates publicly available adtech data to help users identify who is tracking them across websites and mobile apps. The tool addresses the longstanding challenge of determining which advertising platforms and data brokers are responsible for targeted ads and data collection, information that was previously difficult for consumers to access and understand. DecryptAds simplifies this process by scraping and correlating adtech data, making transparency in digital tracking more accessible to the general public.
Recent cybersecurity incidents spanning corporate networks, supply chains, and personal accounts reveal an expanding threat landscape where attackers exploit social engineering, software vulnerabilities, and AI-powered reconnaissance alongside traditional attack methods. Notable breaches include a social engineering attack on Levi Strauss resulting in corporate file access, a CEVA Logistics cyberattack disrupting eight European warehouses, and cybercriminals targeting explicit content from social media accounts for extortion and harassment. Microsoft's August 2026 Patch Tuesday addressed over 400 vulnerabilities including three zero-days, while security experts increasingly view AI as a tool to automate repetitive defensive tasks rather than replace security professionals.
From the panels to the villages, Huntress researchers and SOC analysts were all over Hacker Summer Camp this year. Here’s what stood out at Black Hat and DEF CON.
'Computer History' records clicks and typing to build ChatGPT memories
Hidden API Estate And AI-speed Recon Are Reshaping Modern Application Risk Key Takeaways Unknown APIs create unattributed exposure, and such exposure rarely gets tested. Attackers build their own inventory through live reconnaissance; they do not wait for your spreadsheet. API discovery must pull from gateways, cloud, specs, traffic paths, scanners, and external exposure signals. OWASP […]
The incident involving OpenAI models shows that autonomous hacks make human oversight more important, not less
Kaspersky researchers have identified a new campaign by Armored Likho that masquerades as fundraising efforts to deliver an updated Still Toolkit designed to extract Telegram data and conduct surveillance on infected systems. The expanded toolkit represents an evolution in the threat actor's cyber-espionage capabilities, enabling more sophisticated data theft and eavesdropping operations against targeted victims.
Former Google Threat Intelligence leader joins GreyNoise as SVP of Adversary Operations to advance proactive discovery and disruption of cyber threats.
Qualys has launched a real-time Cloud Security Posture Management solution designed to detect cloud configuration risks as they occur rather than waiting for periodic scans, reducing the window of exposure in dynamic cloud environments. The platform maintains support for traditional periodic scanning while correlating posture findings with vulnerability data to contextualize risk assessment across cloud infrastructure.
Walmart is leveraging a collaborative purple teaming approach by colocating red and blue teams to strengthen its security posture through shared exercises and mutual trust-building. This integrated model combines offensive and defensive perspectives to identify vulnerabilities and improve overall defensive capabilities more effectively than siloed team structures.
The big-box giant has scaled its defenses by encouraging trust and innovation. Good communications, transparency, and team spirit are key factors.
Criminal organizations are escalating cargo theft tactics to unprecedented levels of violence in California, specifically targeting high-value AI hardware and data center equipment. Security experts point to at least two recent incidents as evidence that theft rings view these server shipments as lucrative enough to employ increasingly dangerous methods to intercept them.
The Agent Baseline defines 35 controls across six security outcomes—but the right starting point depends on how your organization uses agents. Learn how to sequence controls for coding, internal, and production agents.
One big caveat, though: You need your contact's phone number
This is why we can't have nice things, people
Elastic Security Labs released an analysis of 13 million tool calls from AI coding agents, demonstrating how Cursor hooks and Elastic Agent can capture and log every action including shell commands, file reads, and MCP requests as structured events. This capability enables security teams to hunt through AI agent activities using ES|QL, providing visibility into potentially risky automated actions in development environments. The research highlights the growing need for detailed auditing and threat hunting capabilities as AI coding tools become more prevalent in enterprise workflows.
New research shows how attackers can use security alerts and blocked events to manipulate and hijack AI agents.
Microsoft has been recognized as a Leader in the 2026 IDC MarketScape for managed detection and response services, reflecting competitive positioning in the enterprise MDR/MXDR market. The company's Defender Experts MDR offering integrates artificial intelligence, threat intelligence, and human security expertise to deliver detection and response capabilities.