Operations | Monitoring | ITSM | DevOps | Cloud

Account Takeover Prevention: Assume Compromise, Limit the Blast Radius

Account takeover has quietly become one of the most consequential threats facing organizations of every size. Unlike a smash-and-grab breach that trips alarms immediately, a compromised account often looks like normal activity. The attacker logs in with valid credentials, moves through systems a legitimate user would touch, and causes material damage long before anyone notices something is wrong. This is why security teams are shifting away from prevention-only strategies and toward a posture that assumes compromise will happen and focuses instead on containing its impact.

5 Zero Day Attack Myths That Could Leave You Exposed

Zero day vulnerabilities remain one of the most misunderstood threats in cybersecurity. The term gets thrown around in headlines, vendor reports, and boardroom conversations, often accompanied by more confusion than clarity. Security researchers at firms including Mimecast have repeatedly noted that misconceptions about zero day attacks can be just as dangerous as the exploits themselves, because they lead organizations to underinvest in the right defenses while overspending on the wrong ones.

Poisoning The Pipeline: How The Mastra AI Ecosystem Was Poisoned At The Registry Level | Harness Blog

The open-source landscape has witnessed another highly automated, ecosystem-level subversion. On June 17, 2026, a critical software supply chain attack struck the Mastra AI framework - a popular open-source TypeScript ecosystem used widely to build AI agents, workflows and RAG pipelines. By exploiting a compromised contributor account, threat actors successfully mass-published 144 malicious packages under the official @mastra npm scope.

Lessons From a CI/CD Supply Chain Attack at Grafana Labs

When a compromised GitHub Actions workflow targets your CI/CD pipeline, how do you respond — and what do you change so it never happens again? Nick and David from Grafana Security walk through a real supply chain incident triggered by a pull_request_target misconfiguration, showing exactly what broke, what tools caught it, and what the team rebuilt afterward.

Improvements to our status pages as we tackle a DDoS

The uptime & availability of our status pages hasn't been great these past few days. The root cause is a persistent and pretty aggressive DDoS attack targeted at our own status page, status.ohdear.app. As a result, the overload on our systems also affected all other status pages we host for clients. We're not yet at Github or Claude levels of uptime sadness, but this isn't acceptable to us. In this post, I'll share what's happening and what steps we've already taken.

Introducing Megaport DDoS Protection: Built-In Network Resilience for Megaport Internet

This fabric-native shield delivers private, professional-grade resilience that is easily added via the Megaport Portal in under 60 seconds. Megaport is evolving the connection. With the launch of Megaport DDoS Protection, we are securing the mission-critical Megaport Internet connection by filtering out malicious traffic before it ever reaches your platform.

AI Supply Chain Attacks Are Here. And Most Organizations Aren't Ready

When I read about the Vercel breach tied to a Context AI compromise, I wasn’t surprised. I’ve been talking with customers for a while now about how AI was going to introduce a new kind of supply chain risk. This is exactly what that looks like. What stands out to me is how familiar the pattern is. We saw it with open source, then again with SaaS, and again with cloud.

How AI-Powered Phishing Is Changing What 'Suspicious Email' Looks Like

For years, spotting a phishing email was almost a checklist exercise. Look for typos, watch for broken grammar, be suspicious of generic greetings like "Dear user," and check if the sender's address looks strange. That mental model worked because phishing emails actually looked bad. Which is no longer true. With the rise of AI, attackers can generate emails that are grammatically perfect, context-aware, and indistinguishable from legitimate business communication. The obvious red flags are gone. What used to look suspicious now looks completely normal.

npm axios attack - What happened and how to protect your supply chain

100M+ weekly downloads. One compromised maintainer account. A remote access trojan in two active release branches. This is a 30-minute breakdown of the Axios npm supply chain attack – how it happened, why it was hard to detect, and what any engineering team can do right now to reduce exposure. Nigel Douglas, Head of Developer Relations at Cloudsmith, is joined by Jenn Gile, co-founder of Open Source Malware, a community-driven threat intelligence platform focused on malicious open source packages.

Emerging Cyber Threats Every Organization Should Know

Cyber threats in 2026 are evolving faster than most organizations can comfortably manage. Attackers are using automation, artificial intelligence, and scalable attack models to target businesses of every size. What used to be handled in isolation by IT teams is now a boardroom concern. A single breach can disrupt operations, damage trust, and create long-term financial consequences. Leaders are starting to recognize that cybersecurity is not just about tools but about strategy, governance, and accountability across the organization.