Operations | Monitoring | ITSM | DevOps | Cloud

The latest News and Information on CyberSecurity for Applications, Services and Infrastructure, and related technologies.

How are folks managing CVEs at scale? #itsecurity #opensource #vulnerability #sbom

Dog-walk thoughts on vulnerabilities at scale More CVEs are being found, disclosed and weaponised faster than ever. For a small team with one product, that's manageable: a CVE lands, you fix it. But if you're running thousands of applications across tens of thousands of repos, "the teams will handle it" stops working. It becomes a governance problem.

Why Security and Observability Must Work Together in 2026

Modern IT environments generate more data than ever. Every application request, user login, network connection, cloud workload and endpoint action produces signals that can help teams understand what is happening across the business. Yet having more data has not necessarily made organizations more secure, more reliable, or easier to operate.

It takes a hacker 48 hours to exploit a vulnerability. Why does it take 43 days to patch it?

It is not always possible to patch vulnerabilities as quickly as hackers exploit them, but recent figures show just how much this gap has widened. FortiGuard Labs estimates that the time between the disclosure of a critical vulnerability and its active exploitation has dropped sharply to between 24 and 48 hours. By contrast, Verizon’s 2026 Data Breach Investigations Report shows that organizations take a median of 43 days to complete vulnerability remediation.

HITL for autonomous agents: Where does the human go?

Human approval is easy when you are sitting in front of the agent. For an agent running by itself in a cluster, almost none of that holds. You’re in a meeting and your agent is running in a cluster. It has a service account, it has been asked to keep a service healthy, and it has just worked out that the right fix is to roll back a database migration. Nobody is watching it. That was rather the point of deploying it. You want to get notified to approve such an important action.

Installing CFEngine with Ansible

You started with Ansible, and for a long time it was the only thing you needed. With a handful of playbooks and an inventory file, you got the job done. However, as the fleet grew, runs went from taking minutes to hours, and parts of the inventory were unreachable at any given moment. This is not an Ansible flaw. Push-based configuration and continuous state enforcement are simply two different jobs. This blog post is all about getting you started with a hybrid system.

Are SOC 2's days numbered? #SOC2 #CodeReview #AICoding #DevOps #SoftwareDevelopment #LLM #SpeedScale

As companies adopt AI coding tools, code review processes are breaking down. Traditional compliance methods are slowing teams down, but human engineers aren't going to spend hours reading AI-generated low-level code forever. How will SOC 2 adapt to the era of AI-driven development? Drop your thoughts in the comments and subscribe for more tech insights! Learn more: speedscale.com.

Harness Named a Leader in SecureIQLab's Cloud WAAP v5.0 CyberRisk Validation Report

In the August 2026 SecureIQLab Cloud WAAP v5.0 CyberRisk Validation Comparative Report, Harness Web Application & API Protection (WAAP) was named a Leader. The analysis involves actual lab testing across 12 leading Cloud WAAP vendors and shows scores for each criterion evaluated — and we're thrilled to be one of just six vendors to earn Leader status, and one of only five to meet both of SecureIQLab's "Secure by Design" and "Secure by Default" criteria.

SIEM Pricing 2026: Major Providers Compared (& How to Lower Your Bill)

Every major security information and event management (SIEM) platform prices on the volume of data you send it. Microsoft Sentinel meters per gigabyte across two tiers. Splunk charges per gigabyte indexed or per compute unit. Google SecOps draws down a prepaid gigabyte credit balance. Elastic Security bills ingest plus retention, or the resources your cluster consumes. Three of the four keep their real rates quote-only. Budgeting starts with the meter.