Operations | Monitoring | ITSM | DevOps | Cloud

Managing Claude Code Sessions Through Lynx

At Tigera, we spend a lot of time thinking about agent security: identity, policy, runtime controls, and the record left behind after an agent acts. Coding agents create an interesting problem because, in most organizations, they didn’t arrive through the front door. Few companies ran a platform evaluation and rolled Claude Code out to 500 developers. Developers installed it themselves.

SAST vs SCA vs DAST vs IAST: choosing the right scan for the right stage

SAST vs SCA vs DAST vs IAST: a clear breakdown of what each scan finds, when to run it, and how to combine them across your SDLC. Most AppSec teams don't run one type of scan - they run several, at different points in the pipeline, because no single tool sees the whole picture. This article breaks down SAST vs SCA vs DAST vs IAST: what each one actually tests, where it fits in the software development lifecycle (SDLC), and how to combine them without duplicating effort or drowning developers in findings.

What is Interactive Application Security Testing (IAST)?

Interactive Application Security Testing (IAST) finds vulnerabilities in running applications by monitoring code from the inside. Learn how it works and where it fits. Interactive Application Security Testing (IAST) is a method for finding security vulnerabilities in an application while it's running, by instrumenting the code and observing how it behaves during normal use or testing.

Does a TLS Certificate Need a Common Name?

Technically: no. In practice: maybe. Lot’s of teams are experimenting with shorter duration certificates from Let’s Encrypt to get ready for the 47-day mandate. Those certs come with a big gotcha: no more Common Name. A modern browser is perfectly happy with a TLS certificate that has no Common Name. Your VPN or mail server might have other opinions. And since those are probably things you’d like to keep working, there’s a little more nuance to the answer.

From SOCI Compliance to Continuous Infrastructure: How Puppet Helps Protect Critical Infrastructure

Australia’s critical infrastructure landscape has changed significantly. The Security of Critical Infrastructure Act 2018 (SOCI Act) has evolved from a framework focused primarily on identifying critical assets and reporting incidents into a broader risk-management and operational-resilience regime. The 2024 reforms reinforced that direction, increasing the focus on the systems, data, and technology dependencies that underpin Australia’s essential services.

CT alerts: know when someone gets a certificate for your domains

A couple days ago, I told you how a spammer got a certificate for dev-docs.trackjs.com, and that we only found out because Google emailed us. Google knew because the spammer claimed the hostname in Search Console. An attacker running a phishing page wouldn’t have done that, but they would still need a certificate. Every publicly trusted certificate gets written to a public log, and we track that log in our database. We just weren’t watching it. Now we are, and you can too.

The Clearinghouse For AI Agents Has A Blind Spot

Jamin Ball’s recent piece, “Systems of Record Won the SaaS Era — Clearinghouses Will Win the Agents Era,” is the cleanest articulation I’ve seen of where the durable moat goes next. His argument is simple and, I think, correct: the SaaS era rewarded whoever owned the system of record, and the agent era will reward whoever owns the clearinghouse.

How Harness orchestrates LLM security scanning

Large language models are effective at security review for the same reason they are effective at many other tasks: they reason rather than pattern match. In plain terms, a traditional scanner checks code against a list of known bad patterns, the way a spell checker flags a misspelled word, regardless of what the sentence means. An LLM can instead follow the program's logic: trace a piece of attacker-controlled input through several layers of application code to determine whether it is reachable.

Why FIPS Mode Is Not Enough: What Federal Teams Should Expect Their Vendors to Prove

Federal teams need more than a system setting. They need defensible evidence that the cryptography protecting federal information is validated, correctly configured, and actually used. For platforms such as ScienceLogic, that product-level evidence should come from the vendor, not be reconstructed by the customer.

SOC automation solution guide 2026 with examples

SOC automation can be a confusing category as there is no single type of SOC automation solution or tool, and most security teams use several different approaches at the same time. However, the need for SOC automation is much clearer with recent data on SOC automation showing that 93% of organizations are using or planning to use automation in their security workflows.

Creating Secure and Reliable Digital Signing Processes

Digital signing works best when it is designed as part of a complete business process. Organizations building signing into their own software can evaluate an esignature API from Blueink, a provider focused on developer-led document workflows with REST API tools, SDK resources, embedded signing, webhooks, tracking, and identity-verification options. Its services are relevant to integrated workflows in areas including government, insurance, education, and healthcare. A signature request is only one moment in a longer journey.

How are folks managing CVEs at scale? #itsecurity #opensource #vulnerability #sbom

Dog-walk thoughts on vulnerabilities at scale More CVEs are being found, disclosed and weaponised faster than ever. For a small team with one product, that's manageable: a CVE lands, you fix it. But if you're running thousands of applications across tens of thousands of repos, "the teams will handle it" stops working. It becomes a governance problem.

Why Security and Observability Must Work Together in 2026

Modern IT environments generate more data than ever. Every application request, user login, network connection, cloud workload and endpoint action produces signals that can help teams understand what is happening across the business. Yet having more data has not necessarily made organizations more secure, more reliable, or easier to operate.

It takes a hacker 48 hours to exploit a vulnerability. Why does it take 43 days to patch it?

It is not always possible to patch vulnerabilities as quickly as hackers exploit them, but recent figures show just how much this gap has widened. FortiGuard Labs estimates that the time between the disclosure of a critical vulnerability and its active exploitation has dropped sharply to between 24 and 48 hours. By contrast, Verizon’s 2026 Data Breach Investigations Report shows that organizations take a median of 43 days to complete vulnerability remediation.

HITL for autonomous agents: Where does the human go?

Human approval is easy when you are sitting in front of the agent. For an agent running by itself in a cluster, almost none of that holds. You’re in a meeting and your agent is running in a cluster. It has a service account, it has been asked to keep a service healthy, and it has just worked out that the right fix is to roll back a database migration. Nobody is watching it. That was rather the point of deploying it. You want to get notified to approve such an important action.

Installing CFEngine with Ansible

You started with Ansible, and for a long time it was the only thing you needed. With a handful of playbooks and an inventory file, you got the job done. However, as the fleet grew, runs went from taking minutes to hours, and parts of the inventory were unreachable at any given moment. This is not an Ansible flaw. Push-based configuration and continuous state enforcement are simply two different jobs. This blog post is all about getting you started with a hybrid system.

Are SOC 2's days numbered? #SOC2 #CodeReview #AICoding #DevOps #SoftwareDevelopment #LLM #SpeedScale

As companies adopt AI coding tools, code review processes are breaking down. Traditional compliance methods are slowing teams down, but human engineers aren't going to spend hours reading AI-generated low-level code forever. How will SOC 2 adapt to the era of AI-driven development? Drop your thoughts in the comments and subscribe for more tech insights! Learn more: speedscale.com.

Harness Named a Leader in SecureIQLab's Cloud WAAP v5.0 CyberRisk Validation Report

In the August 2026 SecureIQLab Cloud WAAP v5.0 CyberRisk Validation Comparative Report, Harness Web Application & API Protection (WAAP) was named a Leader. The analysis involves actual lab testing across 12 leading Cloud WAAP vendors and shows scores for each criterion evaluated — and we're thrilled to be one of just six vendors to earn Leader status, and one of only five to meet both of SecureIQLab's "Secure by Design" and "Secure by Default" criteria.

SIEM Pricing 2026: Major Providers Compared (& How to Lower Your Bill)

Every major security information and event management (SIEM) platform prices on the volume of data you send it. Microsoft Sentinel meters per gigabyte across two tiers. Splunk charges per gigabyte indexed or per compute unit. Google SecOps draws down a prepaid gigabyte credit balance. Elastic Security bills ingest plus retention, or the resources your cluster consumes. Three of the four keep their real rates quote-only. Budgeting starts with the meter.

Redact PII at the edge - and still be able to search for it

Ask a platform team why their application logs aren't in their observability backend and you'll often get a one-sentence answer: And, that's where the conversation ends. The logs stay in a silo. Or, they don't get collected at all. The team loses the troubleshooting signal, and nobody revisits the decision because the alternative looks like a compliance violation. Application logs in healthcare, aviation, insurance, and retail are full of personal information that should not be stored in plain text.

Run More Internal Hackathons

Internal hackathons are a powerful way to let your teams explore ideas and work together on something fun besides the same old stuff for work. Maybe they want to build something brand new, maybe they want to knock out things that are on the backlog that never get prioritized, or maybe they want to work on something fun but completely unrelated to work.

The Essential Eight: Patching Applications and Operating Systems at Maturity Level Two

Why do so many patching programs pass every internal check and still come back from an Essential Eight assessment rated at Maturity Level One? The answer is rarely speed. Teams that miss the mark are usually patching their servers, browsers, and office suites on schedule, then losing the rating on the fifty applications nobody put on a list. Maturity Level Two is where the Essential Eight stops asking how fast you patch and starts asking how much you can see.

SBOMs are easy for one project, monumental at scale

Think of an SBOM as your ingredient list. A common language describing everything that goes into a piece of software, every dependency and version, in one place. This video covers why SBOMs have gone from niche to mandatory, and why they're harder to pull off than the concept suggests: The concept is simple. Operationalizing it across a large, diverse tech stack is where it gets hard.

PCI DSS Requirement 10: Logging and Monitoring in v4.0.1

Version 4.0 renumbered PCI DSS Requirement 10 from end to end, and the Council retired v3.2.1 on 31 March 2024. Sub-requirement numbers written before then mostly point somewhere else now. Four more Requirement 10 rules changed status on 31 March 2025, automated log review among them. Checking your numbering against v4.0.1 costs an afternoon and saves a finding. In this blog, you will: PCI DSS Requirement 10 covers audit logging and monitoring across the cardholder data environment.

AI Agents on Kubernetes 101: From Laptop Script to Production Pod

In short, this is a beginner’s guide to deploying an AI agent on Kubernetes. You will containerize an agent, store its API key as a Kubernetes secret, write a deployment with health probes and resource limits, expose it with a service, and lock down its network egress, in that order, with a working manifest at every step. On a local kind cluster the whole walkthrough takes about an hour.

Why Most Security Firms Miss Their Incident Prevention Window

Security operations managers face a critical paradox: their teams are designed to respond to incidents, but the incidents that matter most are the ones that never happen. The difference between a security firm that prevents problems and one that merely responds to them comes down to a single, often-overlooked factor: whether they can see what their guards are actually doing in real time. When operators lack live visibility into patrol locations, guard status, and emerging threats, they're always one step behind.

How to Cut SIEM Ingest by 90% Without Losing Detection Coverage

Every SOC team knows the trade-off. Send everything to the SIEM platform and pay for it. Or filter aggressively and risk missing something. Filter lists are written once, during onboarding. Detection content keeps moving after that. Smart Engine, the new core of the VirtualMetric DataStream pipeline, takes the guesswork out of that decision. It reduces SIEM ingest using your registered detection rules. An event that no registered detection could match is dropped.

Microsoft Took 8 Months to Fix This Copilot Vulnerability

Microsoft finally patched a critical Copilot vulnerability nearly eight months after researchers first disclosed it — and the way the attack worked raises some unsettling questions about AI memory. The vulnerability chained together multiple flaws that could allow a malicious prompt hidden inside a webpage to be pulled into Copilot simply by asking it to summarize the page. From there, the attack could potentially access connected data from services like Gmail, Google Drive, and Google Calendar and exfiltrate that information using Copilot’s own capabilities. But the most concerning part may have been persistence.

What is IPsec?

Our Megaport technical expert, Steve Tu explains what IPsec is, how it secures network traffic, and where it’s used across VPN and cloud connectivity. About Megaport Deploying infrastructure should be fast and simple. Megaport’s software-defined platform provides private compute, network, and storage — so you can build secure, scalable infrastructure for cloud, enterprise, and global AI inference workloads. Trusted by the world’s leading enterprises, Megaport operates across 1,200+ enabled locations globally.

Headless vs. Traditional Web Architecture: What DevOps Teams Need to Consider

DevOps teams face a critical architectural decision when building modern web applications: should they stick with traditional, monolithic systems or embrace headless architecture? This choice affects everything from deployment workflows to team collaboration, performance optimization, and long-term maintenance costs. Understanding the technical and operational implications of each approach helps teams make informed decisions that align with their specific requirements.

Certificate monitoring for your intranet hosts

Certificate monitoring from the cloud only sees what the internet sees, like your public websites. But the vCenter console, the internal API, the switch management page, or that thing on db01.corp.internal are invisible to it. Those certificates expire just like public ones. They just don’t warn anybody first. This gap became very clear when we shipped Private PKI. Now CertKit can issue certificates for internal names and IP addresses, deploy them, and install the root into your trust stores.

Icinga Web SSO walkthrough

The ability to log into all corporate applications with one username and password is pretty convenient, even compared to a password manager. As a benefit, the IT department can centrally enforce one desired two-factor auth mechanism. Now we, Icinga, also provide a so-called OpenID Connect integration for single sign-on. By the end of this text you’ll know how to connect your Icinga Web instance to the ID provider of your choice.

See It, Approve It, Revoke It: Scoped OAuth for Public Apps

This blog post is part of PagerDuty’s ongoing series on how we’re helping customers navigate their journey towards autonomous operations. Read on to learn about how Scoped OAuth for Public Apps, now in Early Access, builds towards this vision. Your security team asks a simple question during a routine review: which third-party apps can reach our PagerDuty data right now, and what exactly can they do with it?

PII Redaction in Logs: Mask, Redact, Hash, or Drop?

Sensitive values reach your logs without anyone deciding they should. A debug line prints a whole request object. An error message carries the query string. A customer email address is suddenly stored in three systems. PII redaction in logs then gets treated as one setting to switch on. In practice it covers four separate treatments. The value is already inside the message before log ingestion finishes. In this blog, you will: By the end you can write a rule for each field and defend it.

Outrun the Threat Window: AI-accelerated Vulnerability and Patch Management

The gap between vulnerability disclosure and active exploitation is shrinking—often from weeks to mere hours. Traditional patching cycles no longer cut it. In this session, discover how AI-accelerated solutions can help you: Identify exposed assets faster Prioritize vulnerabilities by real-world risk Remediate across Windows, macOS, Linux, and hundreds of apps Verify success with a connected workflow Learn how our approach, powered by AI-driven insights and automation, can help you close the gap before attackers strike. Watch now and take control of your patch management.

When login systems become an ops problem

SSO usually enters a company as a convenience project. People are tired of juggling passwords, new employees need access faster, and security wants fewer loose credentials floating around the business. At first, that sounds like a clean IT improvement. Then the company grows, tools multiply, teams work across more environments, and login becomes part of the operating layer that keeps the whole business moving.