Operations | Monitoring | ITSM | DevOps | Cloud

The latest News and Information on CyberSecurity for Applications, Services and Infrastructure, and related technologies.

Certificate Authority Explained: How Short-Lived Certs Are Replacing Passwords and Keys

For decades, digital security has leaned on two familiar tools: passwords that people memorize and long-lived keys that sit quietly on servers until someone remembers to rotate them. Both approaches share the same flaw. They are static. Once a password or key is stolen, it often stays valid until someone notices the breach, which research from IBM's Cost of a Data Breach reports shows takes an average of over 200 days. That gap between compromise and detection is where a lot of damage happens.

Account Takeover Prevention: Assume Compromise, Limit the Blast Radius

Account takeover has quietly become one of the most consequential threats facing organizations of every size. Unlike a smash-and-grab breach that trips alarms immediately, a compromised account often looks like normal activity. The attacker logs in with valid credentials, moves through systems a legitimate user would touch, and causes material damage long before anyone notices something is wrong. This is why security teams are shifting away from prevention-only strategies and toward a posture that assumes compromise will happen and focuses instead on containing its impact.

5 Zero Day Attack Myths That Could Leave You Exposed

Zero day vulnerabilities remain one of the most misunderstood threats in cybersecurity. The term gets thrown around in headlines, vendor reports, and boardroom conversations, often accompanied by more confusion than clarity. Security researchers at firms including Mimecast have repeatedly noted that misconceptions about zero day attacks can be just as dangerous as the exploits themselves, because they lead organizations to underinvest in the right defenses while overspending on the wrong ones.

A new way to SIEM

For years, security teams have been sold the same bargain: send in more data, buy more tools, tune more rules, and you'll be better protected. In practice, a lot of teams have ended up with the opposite. They're carrying more cost and more complexity, and they still don't have much confidence that their detections are actually working the way they should. That's the backdrop for why Cribl is acquiring CardinalOps.

Compliance Without Complexity: Introducing Harness Rego Policy Packs | Harness Blog

In the fast-paced world of modern software delivery, compliance is often a bottleneck. While our existing OPA-based Policy as Code feature has long empowered teams to encode complex authorization checks and enforce granular governance across their DevOps workflows, we know that starting from a blank page can be daunting. Security and governance teams struggle to keep up with the volume of releases, while developers often find the initial setup of these policies to be time-consuming.

Why the Netherlands Is a Strategic Hosting Location for EU-Focused Businesses

Selecting the optimal physical server location is one of the most critical infrastructure decisions for an expanding enterprise. For digital businesses serving European users, the Netherlands has firmly established itself as the digital gateway to the continent. Situated at the very core of Europe's telecommunication crossroads, Dutch infrastructure offers unprecedented network connectivity, stringent legal data protections, and low-latency throughput.

How the TLS handshake works, and why half of it is gone

Every HTTPS connection starts with a TLS handshake. It’s the security check, answering “are you who you say you are?” and “how are we going to keep this conversation secret?”. There’s a lot going on during the handshake, and there used to be even more before it all got hacked and removed. And that’s useful to understand, the modern TLS 1.3 handshake is short because everything else got compromised.

99% of database professionals are seeing AI benefits. So why are the security challenges increasing?

The numbers from the 2026 State of the Database Landscape: AI Edition are striking. 99% percent of respondents using AI report at least one measurable benefit for their database work. Automation is up, performance is improving, and three-quarters report significant cost savings. By almost any measure, AI is delivering. However, sitting alongside that near-universal positivity in the same dataset, security and privacy concerns have climbed to 64%. Regulatory compliance anxiety has risen to 40%.

How We Secured AI Worker Agents in Harness | Harness Blog

When we launched Autonomous Worker Agents, the message we led with was simple: governance is inherited, not integrated. Agents don't get security bolted on after the fact. They inherit the OPA policies, RBAC, and audit trails already running your production pipelines. This post is about the layer underneath that promise: isolation. We let an Autonomous Worker Agent run shell commands and call APIs inside our pipelines.