December 18, 2025
Real-World Lessons
TruffleNet and Cloud Abuse at Scale: An Identity Architecture Failure
The recent TruffleNet campaign, first documented by Fortinet, highlights a familiar and uncomfortable truth for security leaders: some of the most damaging cloud attacks aren’t exploiting zero-day vulnerabilities. They’re exploiting identity models that were never designed for the scale and automation of modern cloud environments. Nothing about this attack was novel. That’s precisely the problem. …
April 15, 2025
AI
Agentic AI Without Secrets, Part 3 – Making it Real
April 7, 2025
AI
Securing AI Agents in the Real World: A Case Study – Part 2 of 3
March 26, 2025
Standards
Workload Identity – Key Takeaways from IETF 122
March 14, 2025
Secret Sprawl
It’s 2025. Let’s Talk About Secrets Sprawl
March 14, 2025
Standards
Join us at IETF Bangkok
March 12, 2025
Identity
Defakto Wins Best CyberSecurity Startup in 2025 Cybersecurity Excellence Awards
March 4, 2025
Real-World Lessons
Lessons from the Snowflake Breach: Moving Past the Age of Secrets
February 24, 2025
Secret Sprawl
“Don’t break prod,” and why your secrets are future outages
February 19, 2025
AI
AI Security Begins with Workload Identity
January 16, 2025
Secret Sprawl
Non-Human Identity Misconceptions: Secrets are not Identities
November 22, 2024
Identity