The Fastest Layer in Your Stack Is Part of Your Biggest Security Risk The fastest part of your application may also be the least inspected. CDN caches are designed to reduce latency by serving cached content closer to users while significantly reducing the load on origin servers. Suraja Behura |September 16, 2026
NIS2 Compliance Guide for IT, Application, and API Teams In Part 1 of this NIS2 Compliance series, we reviewed the core requirements of the EU NIS2 Directive, including risk management, incident detection and response, business continuity, supply-chain security, and governance. Jitesh Sharma |September 10, 2026
The AI Is the Phisher: How Prompt Injection Turns Trusted Assistants into Personalized Social Engineers Traditional phishing begins with an unsolicited message. An attacker sends an email or text message and hopes that the recipient will open it, trust it, and take the requested action. Most phishing campaigns are therefore a numbers game: send enough messages, and eventually someone will click. Zvika Babo & Gabi Nakibly |September 03, 2026
NIS2 Compliance: Understanding the Core Requirements for IT and Security Teams Cybersecurity regulations are increasingly moving beyond policies and documentation to focus on how organizations actually manage cyber risk. Jitesh Sharma |August 25, 2026
Part 1: Visibility Isn't the Problem Anymore. Understanding Is. It's Monday morning. You sit down with your coffee, glance at your monitoring dashboard, and everything looks healthy. CPU utilization is normal. Memory usage is well within limits. Throughput hasn't changed much overnight. Dalit Bar |August 18, 2026
AI-Powered Attackers Are Here: Lessons from JADEPUFFER for Application and API Security The attack is not the story – Much of the industry discussion around JADEPUFFER has focused on a simple question: this the first fully autonomous AI-powered cyberattack? Uri Dorot |July 20, 2026
The White House Just Accelerated the PQC Clock Last week, a U.S. Presidential Executive Order, Securing the Nation Against Advanced Cryptographic Attacks – The White House, mandated that federal agencies complete their transition to Post-Quantum Cryptography (PQC) by the end of 2030. Prakash Sinha |July 16, 2026
Blocking Handshake Abuse Early: How TLS Enforcement Reduces HTTPS Attack Surface Encrypted traffic is now the default for most digital services, but encryption also changes how abuse appears on the wire. Boris Melnik |July 14, 2026
AI Crawlers Surge in FSI: Who’s Accessing Financial Data and Why It Matters In Part 1 of this series, we explored the evolving bot threat landscape in financial services, trends in ATO attacks, and how bot traffic continues to expand the attack surface. Dhanesh Ramachandran |July 09, 2026
When Bad Bots Nearly Outnumber Human Shoppers: Inside the 2026 E‑Commerce Bot Threat Report For years, the story of holiday web traffic was one of total bot traffic steadily claiming a larger share. In last year’s research we found that it crossed into the majority when total bot traffic outpaced human shopping traffic for the first time. Dhanesh Ramachandran |June 24, 2026
Security Policy: Full Control Over Your Application Security Configuration Security teams often need to update protections, validate changes, and roll those updates out across multiple applications without disrupting legitimate traffic. Etai Mandelbaum |June 23, 2026
AI Agents Create a New API Attack Surface For years, API security was mostly about discovery. Find the APIs, classify them, build the inventory, and understand what is exposed. Tzvika Shneider |June 11, 2026