Operations | Monitoring | ITSM | DevOps | Cloud

The latest News and Information on CyberSecurity for Applications, Services and Infrastructure, and related technologies.

How Technology Leadership Is Changing the Future of Cybersecurity

In an increasingly interconnected world, digital security is no longer just a technical issue handled behind closed doors. Threat actors are increasingly sophisticated and attack organizations in complex networks, software supply chains, and by targeting human behavior. Consequently, the way the corporate world approaches risk is quickly moving from merely being defensive to risk governance. Modern technology leadership is key to leading this critical organizational change effort.

TLS 1.2 isn't end of life, but it will be soon

You’re probably running a TLS configuration that the IETF says is “non-conformant”. But you didn’t do anything wrong. In July, the IETF published a pair of RFCs that took away three of TLS 1.2’s key exchange methods and froze the rest of it. The phrase they used is MUST NOT, the strongest thing a specification is allowed to say. Nginx, Apache, and Windows Server all ship with those key exchanges turned on by default. Nothing breaks tomorrow.

The Future of Third-Party Risk Management and Vendor Security

Your supply chain is only as secure as its weakest vendor. You may have world-class security inside your own walls, but the moment an attacker compromises one of your third-party suppliers, they can walk straight into your systems through a trusted connection. That's the reality businesses face today, and that's why choosing the right platform is essential. Black Kite for cyber supply chain risk has emerged as one of the most comprehensive solutions available for organizations that need real, continuous visibility into their vendor ecosystems, not just a one-time compliance checkbox.

12 Top SD-WAN Solutions for Growing Enterprises (2026)

Adding branches, cloud applications, contractors, and connected equipment changes the WAN problem. The network must steer traffic intelligently, preserve application quality during poor link conditions, and apply consistent controls without creating a separate operational stack at every location.

Mapping the NCSC cloud security principles to a sovereign deployment

The 14 Cloud Security Principles from the UK's National Cyber Security Centre form the primary framework for UK public sector cloud procurement and, increasingly, for private sector regulated workloads. Any credible cloud security case in the UK context has to address these principles explicitly. For organizations placing workloads on sovereign cloud specifically, the mapping matters more than for general cloud procurement.

Do Growing Tech Teams Need a Virtual CISO?

Scaling a modern software startup often demands massive focus on feature delivery and market expansion. Technical teams push updates fast, so internal defense often drops down the priority list. Founders handle operational risk on their own until compliance demands appear during client negotiations. Bringing in experienced guidance helps prevent operational downtime before major security issues surface.

Change in behavior: Storage promise

CFEngine 3.29.0 changes how storage promises treat a filesystem that is already mounted. A promise for an unmounted filesystem now mounts only that filesystem instead of all unmounted filesystems, edit_fstab actively maintains the file system table entry to keep it aligned with the promise even when the filesystem is already mounted, and an unmount promise acts only on the explicitly promised filesystem.

Redirection Fraud

You may be familiar with web card skimming, where a fraudster replaces the payment iframe on an ecommerce site with a fake version designed to intercept payment details or divert a transaction. However, there’s another variation that, while not new, is something we encounter far less often. It was highlighted this week during a call from an ecommerce vendor: redirection fraud. In this scenario, the attack starts much earlier in the customer journey.

Building an End-to-End Drone Ecosystem: The Technologies That Need to Work Together

Commercial drone technology is rarely a single application running alongside an aircraft. A complete solution may include flight software, onboard sensors, telemetry, cloud infrastructure, web and mobile interfaces, data processing pipelines, analytics tools, and integrations with existing business systems.