# Cybersecurity

Cybersecurity is the practice of protecting computers, communications systems, and information from attacks and unauthorized use.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Регистрация на CTF-соревнования, запланированные на GISDAYS 2026, открыта

DevFeed: [Регистрация на CTF-соревнования, запланированные на GISDAYS 2026, открыта](<https://devfeed.tech/articles/ctf-gisdays-2026-42731.md>)

Original publisher: [Read original article](<https://habr.com/ru/companies/gaz-is/news/1083660/>)

Author: Gazinformservice (Газинформсервис)

Published: 2026-09-18T06:54:27Z

Content type: news

Language: ru

Sources: [Tagir Valeev](<https://devfeed.tech/sources/tagir-valeev.md>)

Topics: [ctf](<https://devfeed.tech/topics/ctf.md>), [Security](<https://devfeed.tech/topics/security.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Cryptography](<https://devfeed.tech/topics/cryptography.md>)

Tags: [2026](<https://devfeed.tech/tags/2026.md>), [ctf](<https://devfeed.tech/tags/ctf.md>), [gis-days](<https://devfeed.tech/tags/gis-days.md>), [information-security](<https://devfeed.tech/tags/information-security.md>), [security](<https://devfeed.tech/tags/security.md>), [tag-546e7fc04851](<https://devfeed.tech/tags/tag-546e7fc04851.md>), [tag-5a06c087f682](<https://devfeed.tech/tags/tag-5a06c087f682.md>), [tag-62532a8d2a27](<https://devfeed.tech/tags/tag-62532a8d2a27.md>), [tag-85443682aea4](<https://devfeed.tech/tags/tag-85443682aea4.md>)

### AI overview

GISDAYS 2026 will host online CTF competitions on October 1 as part of its Student Day. The event will offer more than 20 tasks across web penetration testing, forensics, reverse engineering, cryptography, and combined categories, with participation available online and in person.

### Source excerpt

В рамках форума по ИТ и ИБ GISDAYS* 1 октября состоятся онлайн-CTF-соревнования. Их участниками могут стать молодые специалисты, которым интересна тема информационной безопасности. Соревнования пройдут в рамках Студенческого дня форума GISDAYS 2026 онлайн и офлайн, на площадке мероприятия в "МТС Live Холл". Офлайн-участники смогут сразу обменять баллы за решённые задачи на ценные призы, а онлайн-победителям будут отдельно отправлены подарки. Для участия необходимо зарегистрироваться на платформе, а 1 октября с 11:00 мск начать выполнять задания. Читать далее

## Plugin4Shell RCE flaw reportedly affects major AI coding agents

DevFeed: [Plugin4Shell RCE flaw reportedly affects major AI coding agents](<https://devfeed.tech/articles/ai-coding-agents-0-click-rce-flaw-could-hand-attackers-keys-to-the-kingdom-42149.md>)

Original publisher: [Read original article](<https://www.theregister.com/security/2026/09/17/ai-coding-agents-0-click-rce-flaw-could-hand-attackers-keys-to-the-kingdom/5297335>)

Author: Jessica Lyons

Published: 2026-09-17T22:42:29Z

Content type: news

Language: en

Sources: [www.theregister.com - Articles](<https://devfeed.tech/sources/www-theregister-com-articles.md>)

Topics: [AI-assisted coding](<https://devfeed.tech/topics/ai-assisted-coding.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [coding](<https://devfeed.tech/topics/coding.md>)

Tags: [ai-and-ml](<https://devfeed.tech/tags/ai-and-ml.md>), [ai-coding-agents](<https://devfeed.tech/tags/ai-coding-agents.md>), [ai-coding-tools](<https://devfeed.tech/tags/ai-coding-tools.md>), [coding-agents](<https://devfeed.tech/tags/coding-agents.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [rce](<https://devfeed.tech/tags/rce.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

Researchers say the Plugin4Shell attack affects all major AI coding agents and could enable remote code execution without user interaction.

### Source excerpt

Plugin4Shell attack affects all the major coding agents, researchers say

## China's Salt Typhoon backdoors Latin American orgs with new snooping malware

DevFeed: [China's Salt Typhoon backdoors Latin American orgs with new snooping malware](<https://devfeed.tech/articles/china-s-salt-typhoon-backdoors-latin-american-orgs-with-new-snooping-malware-42150.md>)

Original publisher: [Read original article](<https://www.theregister.com/security/2026/09/17/chinas-salt-typhoon-backdoors-latin-american-orgs-with-new-snooping-malware/5297286>)

Author: Jessica Lyons

Published: 2026-09-17T18:00:17Z

Content type: news

Language: en

Sources: [www.theregister.com - Articles](<https://devfeed.tech/sources/www-theregister-com-articles.md>)

Topics: [backdoor](<https://devfeed.tech/topics/backdoor.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [infosec](<https://devfeed.tech/topics/infosec.md>)

Tags: [backdoor](<https://devfeed.tech/tags/backdoor.md>), [backdoor-malware](<https://devfeed.tech/tags/backdoor-malware.md>), [china](<https://devfeed.tech/tags/china.md>), [cyber](<https://devfeed.tech/tags/cyber.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [malware](<https://devfeed.tech/tags/malware.md>), [salt-typhoon](<https://devfeed.tech/tags/salt-typhoon.md>), [security](<https://devfeed.tech/tags/security.md>), [sparrowocky](<https://devfeed.tech/tags/sparrowocky.md>)

### AI overview

A news report about Salt Typhoon using new snooping backdoors and malware against organizations in Latin America.

### Source excerpt

Beware the SparroWocky, my son! The backdoor that bites...

## From guidance to action: Security fundamentals that materially reduce risk

DevFeed: [From guidance to action: Security fundamentals that materially reduce risk](<https://devfeed.tech/articles/from-guidance-to-action-security-fundamentals-that-materially-reduce-risk-42107.md>)

Original publisher: [Read original article](<https://www.microsoft.com/en-us/security/blog/2026/09/17/from-guidance-to-action-security-fundamentals-that-materially-reduce-risk/>)

Author: Ron Pessner

Published: 2026-09-17T17:00:00Z

Content type: article

Language: en

Sources: [Microsoft Security Blog](<https://devfeed.tech/sources/microsoft-security-blog.md>)

Topics: [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Exposure Management](<https://devfeed.tech/topics/exposure-management.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Hacking](<https://devfeed.tech/topics/hacking.md>), [incident](<https://devfeed.tech/topics/incident.md>)

Tags: [agentic-security](<https://devfeed.tech/tags/agentic-security.md>), [ai](<https://devfeed.tech/tags/ai.md>), [exposure-management](<https://devfeed.tech/tags/exposure-management.md>), [passwords](<https://devfeed.tech/tags/passwords.md>), [permissions](<https://devfeed.tech/tags/permissions.md>), [pypi](<https://devfeed.tech/tags/pypi.md>), [security](<https://devfeed.tech/tags/security.md>), [speed](<https://devfeed.tech/tags/speed.md>), [sql](<https://devfeed.tech/tags/sql.md>)

### AI overview

Microsoft describes how AI is changing the cybersecurity threat landscape and argues that foundational controls remain essential. The article highlights excessive permissions, weak authentication, unpatched systems, exposed execution paths, and gaps between controls, along with guidance for governing agent identities and tools, isolating execution, restricting connectivity, monitoring behavior, and reducing exposure.

### Source excerpt

AI has made fundamental changes to the operating environment for cybersecurity. Explore exposure management guidance on recommended controls and take action and stay ahead of cyberthreats. The post From guidance to action: Security fundamentals that materially reduce risk appeared first on Microsoft Security Blog.

## Linux Foundation Newsletter: September 2026

DevFeed: [Linux Foundation Newsletter: September 2026](<https://devfeed.tech/articles/linux-foundation-newsletter-september-2026-41418.md>)

Original publisher: [Read original article](<https://www.linuxfoundation.org/blog/linux-foundation-newsletter-september-2026>)

Author: andrewb@proximabiz.com (The Linux Foundation)

Published: 2026-09-17T14:49:43Z

Content type: news

Language: en

Sources: [Linux Foundation - Blog](<https://devfeed.tech/sources/linux-foundation-blog.md>)

Topics: [linux foundation](<https://devfeed.tech/topics/linux-foundation.md>), [MCP](<https://devfeed.tech/topics/mcp.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Xen](<https://devfeed.tech/topics/xen.md>), [opensearch](<https://devfeed.tech/topics/opensearch.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>)

Tags: [2026](<https://devfeed.tech/tags/2026.md>), [blog](<https://devfeed.tech/tags/blog.md>), [careers](<https://devfeed.tech/tags/careers.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [education](<https://devfeed.tech/tags/education.md>), [lf-europe](<https://devfeed.tech/tags/lf-europe.md>), [lf-events](<https://devfeed.tech/tags/lf-events.md>), [lf-research](<https://devfeed.tech/tags/lf-research.md>), [linux](<https://devfeed.tech/tags/linux.md>), [linux-blog](<https://devfeed.tech/tags/linux-blog.md>), [linux-foundation](<https://devfeed.tech/tags/linux-foundation.md>), [mcp](<https://devfeed.tech/tags/mcp.md>), [newsletter](<https://devfeed.tech/tags/newsletter.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [open-source-summit](<https://devfeed.tech/tags/open-source-summit.md>), [opensearch](<https://devfeed.tech/tags/opensearch.md>), [project-news](<https://devfeed.tech/tags/project-news.md>), [projects](<https://devfeed.tech/tags/projects.md>), [september-2026](<https://devfeed.tech/tags/september-2026.md>), [tech-talent](<https://devfeed.tech/tags/tech-talent.md>)

### AI overview

The September 2026 Linux Foundation Newsletter highlights upcoming AGNTCon and MCPCon North America, developments in agentic AI and AI-agent infrastructure, Xen safety and security work, OpenSearch recognition, and LF Energy research, projects, and community updates.

### Source excerpt

Welcome to the September 2026 edition of the Linux Foundation Newsletter The open agentic AI community is coming together in San Jose for AGNTCon + MCPCon North America, October 22-23. More than 3,500 developers, researchers, maintainers and technical leaders will gather for 150 sessions across 11 tracks focused on MCP, agent infrastructure, security, interoperability and production agent systems. Register by October 8 to save. Beyond the event, six developments stand out this month. TheAgentic AI Foundation welcomed the Gates Foundation as its first philanthropic member, bringing the perspectives of underserved communities into the development of agentic AI and supporting broader participation in the firstMCP Dev Summit Nairobi. The Linux Foundation welcomed TRACE, an open specification developed with AMD, Anthropic, Intel, Microsoft, NVIDIA, OPAQUE and TII to provide portable, verifiable runtime and compliance evidence for AI agents and confidential workloads. TheXen Project launched the Xen Safety Committee to develop shared engineering artifacts for functional safety certification and extended security coverage for Xen releases to five years.OpenSearch won the Analytics & Data Intelligence Solutions category in SiliconANGLE's2026 TechForward Awards as the project celebrates five years of community growth. NewLF Energy research found that open source software can deliver two to five times greater net value for grid operators and introduced a standardized framework for evaluating those investments. LF Energy also welcomed three new members and three new projects, advanced Power Grid Model to Early Adoption after more than 10 million downloads, and documented how TenneT achieved a tenfold improvement in grid security analysis performance with PowSyBl. You'll also find new Linux Foundation research, training and certification opportunities, registration for upcoming events, and project news spanning cloud native, AI, energy, cybersecurity, automotive, telecommunicat

## GPT-6 Astra Is the First Model OpenAI Classifies as Critical for Cybersecurity

DevFeed: [GPT-6 Astra Is the First Model OpenAI Classifies as Critical for Cybersecurity](<https://devfeed.tech/articles/gpt-6-astra-is-the-first-model-openai-classifies-as-critical-for-cybersecurity-41296.md>)

Original publisher: [Read original article](<https://www.infoq.com/news/2026/09/gpt-6-astra-critical-cyber/>)

Author: Steef-Jan Wiggers

Published: 2026-09-17T04:59:00Z

Content type: news

Language: en

Sources: [InfoQ](<https://devfeed.tech/sources/infoq.md>)

Topics: [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [gpt-6-astra](<https://devfeed.tech/topics/gpt-6-astra.md>), [OpenAI](<https://devfeed.tech/topics/openai.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Exploit](<https://devfeed.tech/topics/exploit.md>), [browser](<https://devfeed.tech/topics/browser.md>), [Kernel](<https://devfeed.tech/topics/kernel.md>), [Chain-of-thought](<https://devfeed.tech/topics/chain-of-thought.md>)

Tags: [agents](<https://devfeed.tech/tags/agents.md>), [ai](<https://devfeed.tech/tags/ai.md>), [ai-ml-data-engineering](<https://devfeed.tech/tags/ai-ml-data-engineering.md>), [architecture](<https://devfeed.tech/tags/architecture.md>), [architecture-design](<https://devfeed.tech/tags/architecture-design.md>), [azure](<https://devfeed.tech/tags/azure.md>), [browser](<https://devfeed.tech/tags/browser.md>), [chain-of-thought](<https://devfeed.tech/tags/chain-of-thought.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [development](<https://devfeed.tech/tags/development.md>), [devops](<https://devfeed.tech/tags/devops.md>), [exploit](<https://devfeed.tech/tags/exploit.md>), [generative-ai](<https://devfeed.tech/tags/generative-ai.md>), [governance](<https://devfeed.tech/tags/governance.md>), [gpt-6-astra](<https://devfeed.tech/tags/gpt-6-astra.md>), [gpt-6-astra-critical-cyber](<https://devfeed.tech/tags/gpt-6-astra-critical-cyber.md>), [kernel](<https://devfeed.tech/tags/kernel.md>), [machine-learning](<https://devfeed.tech/tags/machine-learning.md>), [ml-data-engineering](<https://devfeed.tech/tags/ml-data-engineering.md>), [news](<https://devfeed.tech/tags/news.md>), [openai](<https://devfeed.tech/tags/openai.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [zero-day](<https://devfeed.tech/tags/zero-day.md>)

### AI overview

OpenAI classified GPT-6 Astra as the first model to reach its Critical cybersecurity threshold. Expert-led evaluations reported previously unknown vulnerabilities in a browser and an operating-system kernel, along with working exploit chains. The system card also reported a substantial decline in chain-of-thought monitorability.

### Source excerpt

OpenAI has classified GPT-6 Astra at the Critical cybersecurity threshold under its Preparedness Framework, a first. In expert-led testing the model found previously unknown vulnerabilities in a browser and an OS kernel and built working exploits. The same system card reports a substantial decline in chain-of-thought monitorability. By Steef-Jan Wiggers

## "Regex for Rows": Simplifying Pattern Detection in SQL with MATCH\_RECOGNIZE

DevFeed: ["Regex for Rows": Simplifying Pattern Detection in SQL with MATCH\_RECOGNIZE](<https://devfeed.tech/articles/regex-for-rows-simplifying-pattern-detection-in-sql-with-match-recognize-31401.md>)

Original publisher: [Read original article](<https://www.databricks.com/blog/regex-rows-simplifying-pattern-detection-sql-matchrecognize>)

Author: Kent Marten; Sergei Fedorov

Published: 2026-09-16T17:14:05Z

Content type: tutorial

Language: en

Sources: [Databricks](<https://devfeed.tech/sources/databricks.md>)

Topics: [SQL](<https://devfeed.tech/topics/sql.md>), [databricks](<https://devfeed.tech/topics/databricks.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Security & Privacy](<https://devfeed.tech/topics/security-privacy.md>)

Tags: [count](<https://devfeed.tech/tags/count.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [databricks](<https://devfeed.tech/tags/databricks.md>), [failed](<https://devfeed.tech/tags/failed.md>), [false-positives](<https://devfeed.tech/tags/false-positives.md>), [functions](<https://devfeed.tech/tags/functions.md>), [login](<https://devfeed.tech/tags/login.md>), [partition](<https://devfeed.tech/tags/partition.md>), [product](<https://devfeed.tech/tags/product.md>), [real-time](<https://devfeed.tech/tags/real-time.md>), [regex](<https://devfeed.tech/tags/regex.md>), [sql](<https://devfeed.tech/tags/sql.md>), [window-functions](<https://devfeed.tech/tags/window-functions.md>)

### AI overview

This tutorial explains how Databricks supports SQL MATCH_RECOGNIZE for detecting ordered event patterns. It shows how the clause can simplify sequence detection, including identifying repeated login failures followed by a successful login, compared with complex SQL queries and window functions.

### Source excerpt

Imagine you work in cybersecurity and you have a table that tracks login attempts...

## Spain gets its first taste of AI-aided cyber attack

DevFeed: [Spain gets its first taste of AI-aided cyber attack](<https://devfeed.tech/articles/spain-gets-its-first-taste-of-ai-aided-cyber-attack-30924.md>)

Original publisher: [Read original article](<https://www.theregister.com/cyber-crime/2026/09/16/spain-gets-its-first-taste-of-ai-aided-cyber-attack/5296844>)

Author: Connor Jones

Published: 2026-09-16T11:56:55Z

Content type: news

Language: en

Sources: [www.theregister.com - Articles](<https://devfeed.tech/sources/www-theregister-com-articles.md>)

Topics: [Security Attacks](<https://devfeed.tech/topics/security-attacks.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [cyber-crime](<https://devfeed.tech/tags/cyber-crime.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [data-protection](<https://devfeed.tech/tags/data-protection.md>), [security](<https://devfeed.tech/tags/security.md>), [spain](<https://devfeed.tech/tags/spain.md>)

### AI overview

The article reports that Spain has experienced its first AI-aided cyber attack. It also reports that data protection chiefs are calling for an immediate review of data protection models.

### Source excerpt

Data protection chiefs call for 'immediate review' of data protection models

## Iranian spies hit Windows machines with Chosen Brick data-stealing malware

DevFeed: [Iranian spies hit Windows machines with Chosen Brick data-stealing malware](<https://devfeed.tech/articles/iranian-spies-hit-windows-machines-with-chosen-brick-data-stealing-malware-26961.md>)

Original publisher: [Read original article](<https://www.theregister.com/security/2026/09/15/iranian-spies-hit-windows-machines-with-chosen-brick-data-stealing-malware/5296646>)

Author: Jessica Lyons

Published: 2026-09-15T18:01:57Z

Content type: news

Language: en

Sources: [www.theregister.com - Articles](<https://devfeed.tech/sources/www-theregister-com-articles.md>)

Topics: [Malware](<https://devfeed.tech/topics/malware.md>), [Windows](<https://devfeed.tech/topics/windows.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>)

Tags: [cyber-crime](<https://devfeed.tech/tags/cyber-crime.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [iran](<https://devfeed.tech/tags/iran.md>), [malware](<https://devfeed.tech/tags/malware.md>), [microsoft](<https://devfeed.tech/tags/microsoft.md>), [security](<https://devfeed.tech/tags/security.md>), [windows](<https://devfeed.tech/tags/windows.md>)

### AI overview

The article reports that Iranian spies targeted Windows machines with Chosen Brick, a data-stealing malware.

### Source excerpt

'Enemies of the regime' on notice

## Critical Cisco email security flaw is being exploited by attackers

DevFeed: [Critical Cisco email security flaw is being exploited by attackers](<https://devfeed.tech/articles/cisco-email-security-boxes-can-be-rooted-by-an-email-26960.md>)

Original publisher: [Read original article](<https://www.theregister.com/security/2026/09/15/cisco-email-security-boxes-can-be-rooted-by-an-email/5296604>)

Author: Carly Page

Published: 2026-09-15T16:01:00Z

Content type: news

Language: en

Sources: [www.theregister.com - Articles](<https://devfeed.tech/sources/www-theregister-com-articles.md>)

Topics: [Cisco](<https://devfeed.tech/topics/cisco.md>), [Security](<https://devfeed.tech/topics/security.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>)

Tags: [cisco](<https://devfeed.tech/tags/cisco.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [email](<https://devfeed.tech/tags/email.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

Attackers are exploiting a critical vulnerability in Cisco email security appliances. Cisco warns that attackers may be able to conceal their activity after gaining access.

### Source excerpt

Attackers already exploiting the critical flaw, and Cisco warns they may be able to cover their tracks once they're in

## CenterPoint Energy confirms intruder helped themselves to customer information

DevFeed: [CenterPoint Energy confirms intruder helped themselves to customer information](<https://devfeed.tech/articles/centerpoint-energy-confirms-intruder-helped-themselves-to-customer-information-26955.md>)

Original publisher: [Read original article](<https://www.theregister.com/cyber-crime/2026/09/15/centerpoint-energy-confirms-intruder-helped-themselves-to-customer-information/5296523>)

Author: Connor Jones

Published: 2026-09-15T14:14:00Z

Content type: news

Language: en

Sources: [www.theregister.com - Articles](<https://devfeed.tech/sources/www-theregister-com-articles.md>)

Topics: [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [data](<https://devfeed.tech/topics/data.md>)

Tags: [breach](<https://devfeed.tech/tags/breach.md>), [cyber-crime](<https://devfeed.tech/tags/cyber-crime.md>), [data](<https://devfeed.tech/tags/data.md>)

### AI overview

CenterPoint Energy confirmed that an intruder accessed customer information while the Texas utility investigates a breach. A forum post claims that 7.49 million files may be available.

### Source excerpt

Forum post claims 7.49 million files up for grabs as Texas utility investigates breach

## Australia's Essential Eight replacement shifts cybersecurity compliance toward continuous exposure management

DevFeed: [Australia's Essential Eight replacement shifts cybersecurity compliance toward continuous exposure management](<https://devfeed.tech/articles/australia-is-replacing-the-essential-eight-with-a-new-cyber-framework-here-s-how-exposure-management-can-help-you-get-ahead-of-it-26585.md>)

Original publisher: [Read original article](<https://www.tenable.com/blog/australia-essential-eight-replacement-compliance-exposure-management>)

Author: Ben Mudie

Published: 2026-09-15T13:32:00Z

Content type: article

Language: en

Sources: [Tenable Blog](<https://devfeed.tech/sources/tenable-blog.md>)

Topics: [Exposure Management](<https://devfeed.tech/topics/exposure-management.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Security](<https://devfeed.tech/topics/security.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>), [App](<https://devfeed.tech/topics/app.md>)

Tags: [australia](<https://devfeed.tech/tags/australia.md>), [ciso](<https://devfeed.tech/tags/ciso.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [enterprise](<https://devfeed.tech/tags/enterprise.md>), [essential-eight](<https://devfeed.tech/tags/essential-eight.md>), [exposure-management](<https://devfeed.tech/tags/exposure-management.md>), [identity](<https://devfeed.tech/tags/identity.md>), [operational](<https://devfeed.tech/tags/operational.md>), [organization](<https://devfeed.tech/tags/organization.md>)

### AI overview

The article describes Australia's replacement of the Essential Eight with an outcomes-focused cybersecurity framework covering enterprise IT, cloud, operational technology, and potentially agentic AI. It argues that organizations will need continuous evidence of their security posture, and presents exposure management as a way to identify and prioritize weaknesses and support current posture validation.

### Source excerpt

Australia's move from the Essential Eight to an outcomes-based cybersecurity model will push organizations from conducting periodic point-in-time, checklist compliance assessments to having continuous evidence of a solid security posture. Key takeaways The Australian Signals Directorate (ASD) is moving from the Essential Eight cybersecurity framework to a new outcomes-focused Essentials series covering enterprise IT, cloud, operational technology (OT), and potentially agentic AI. The Essential Eight itself only ever covered on-premises enterprise IT, built around eight named technical controls, such as application control and patching. It never extended to the security of cloud, identity, or OT. The shift challenges the traditional checklist approach to cybersecurity, where organizations demonstrate compliance through periodic assessments and point-in-time reports. In dynamic environments spanning IT, cloud, identity, and OT, security posture can change quickly and repeatedly between assessments. Exposure management can help organizations continuously understand where they are exposed, prioritize the most critical weaknesses, and provide evidence of their current security posture. ASD's strategic shift to active security posture validation Can you prove your security posture is solid, right now, on demand? That's the question the Australian Signals Directorate (ASD) has effectively put in front of every Australian organization's board, CISO, and C-suite. ASD's decision to retire the Essential Eight signals a fundamental move away from point-in-time, checklist-based security toward an outcomes-focused model where organizations will need to demonstrate continuous compliance. It's no longer enough to show that your organization had a control in place at the time of the last assessment. In a technology environment that changes continuously across IT, cloud, identity, and operational technology (OT), organizations must be able to answer a much more immediate question: Ho

## Rail Network Modernization: FRMCS, Sovereignty and the AI Edge

DevFeed: [Rail Network Modernization: FRMCS, Sovereignty and the AI Edge](<https://devfeed.tech/articles/rail-network-modernization-frmcs-sovereignty-and-the-ai-edge-26717.md>)

Original publisher: [Read original article](<https://blogs.cisco.com/industries/rail-network-modernization-frmcs-sovereignty-and-the-ai-edge>)

Author: Steve Payne

Published: 2026-09-15T13:31:46Z

Content type: article

Language: en

Sources: [Cisco Blogs](<https://devfeed.tech/sources/cisco-blogs.md>)

Topics: [Network](<https://devfeed.tech/topics/network.md>), [Critical Infrastructure](<https://devfeed.tech/topics/critical-infrastructure.md>), [digital sovereignty](<https://devfeed.tech/topics/digital-sovereignty.md>), [Resilience](<https://devfeed.tech/topics/resilience.md>), [Availability](<https://devfeed.tech/topics/availability.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>)

Tags: [2026](<https://devfeed.tech/tags/2026.md>), [availability](<https://devfeed.tech/tags/availability.md>), [cisco](<https://devfeed.tech/tags/cisco.md>), [cisco-industrial-iot-iiot](<https://devfeed.tech/tags/cisco-industrial-iot-iiot.md>), [critical-infrastructure](<https://devfeed.tech/tags/critical-infrastructure.md>), [digital-sovereignty](<https://devfeed.tech/tags/digital-sovereignty.md>), [end-of-life](<https://devfeed.tech/tags/end-of-life.md>), [eu](<https://devfeed.tech/tags/eu.md>), [europe](<https://devfeed.tech/tags/europe.md>), [industries](<https://devfeed.tech/tags/industries.md>), [infrastructure](<https://devfeed.tech/tags/infrastructure.md>), [internet-of-things-iot](<https://devfeed.tech/tags/internet-of-things-iot.md>), [latency](<https://devfeed.tech/tags/latency.md>), [modernization](<https://devfeed.tech/tags/modernization.md>), [network](<https://devfeed.tech/tags/network.md>), [networks](<https://devfeed.tech/tags/networks.md>), [nis2](<https://devfeed.tech/tags/nis2.md>), [resilience](<https://devfeed.tech/tags/resilience.md>), [systems](<https://devfeed.tech/tags/systems.md>), [transportation](<https://devfeed.tech/tags/transportation.md>), [unified-edge](<https://devfeed.tech/tags/unified-edge.md>)

### AI overview

Cisco's pre-InnoTrans 2026 perspective examines the modernization of European rail communications from GSM-R to FRMCS. It argues that the transition requires changes to the underlying IP network, including high availability, deterministic latency, cybersecurity, and large-scale automation, while operators address resilience, digital sovereignty, investment, and regulatory requirements.

### Source excerpt

Join Cisco at InnoTrans 2026 to explore the next generation of rail networks. Discover how FRMCS, AI edge computing, and digital sovereignty are transforming critical infrastructure into secure, automated systems.

## Cisco and the DISA STIG: Turning Zero Trust Policy into Repeatable Practice - Part 2: Cisco SNA

DevFeed: [Cisco and the DISA STIG: Turning Zero Trust Policy into Repeatable Practice - Part 2: Cisco SNA](<https://devfeed.tech/articles/cisco-and-the-disa-stig-turning-zero-trust-policy-into-repeatable-practice-part-2-cisco-sna-26716.md>)

Original publisher: [Read original article](<https://blogs.cisco.com/industries/cisco-and-the-disa-stig-turning-zero-trust-policy-into-repeatable-practice-part-2-cisco-sna>)

Author: Norman St. Laurent

Published: 2026-09-15T13:13:53Z

Content type: article

Language: en

Sources: [Cisco Blogs](<https://devfeed.tech/sources/cisco-blogs.md>)

Topics: [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Cisco](<https://devfeed.tech/topics/cisco.md>), [telemetry](<https://devfeed.tech/topics/telemetry.md>), [Zero Trust](<https://devfeed.tech/topics/zero-trust.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [Network](<https://devfeed.tech/topics/network.md>)

Tags: [benchmark](<https://devfeed.tech/tags/benchmark.md>), [cisco](<https://devfeed.tech/tags/cisco.md>), [cisco-secure-network-analytics-sna](<https://devfeed.tech/tags/cisco-secure-network-analytics-sna.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [department-of-defense-dod](<https://devfeed.tech/tags/department-of-defense-dod.md>), [government](<https://devfeed.tech/tags/government.md>), [hardening](<https://devfeed.tech/tags/hardening.md>), [industries](<https://devfeed.tech/tags/industries.md>), [nist](<https://devfeed.tech/tags/nist.md>), [public-sector](<https://devfeed.tech/tags/public-sector.md>), [stig](<https://devfeed.tech/tags/stig.md>), [visibility](<https://devfeed.tech/tags/visibility.md>)

### AI overview

The article explains how the DISA Security Technical Implementation Guide for Cisco Secure Network Analytics turns Zero Trust policy into testable configuration requirements. The STIG provides a shared hardening baseline for the platform and its management functions, with 31 requirements derived from NIST SP 800-53 and related requirements.

### Source excerpt

Discover how the new DISA STIG for Cisco Secure Network Analytics helps defense organizations securely configure and harden their analytics platform, ensuring trusted network visibility for Zero Trust operations.

## Safeguarding LLM-Assisted Dev at Guardsquare | Guardsquare

DevFeed: [Safeguarding LLM-Assisted Dev at Guardsquare | Guardsquare](<https://devfeed.tech/articles/safeguarding-llm-assisted-dev-at-guardsquare-guardsquare-26891.md>)

Original publisher: [Read original article](<https://www.guardsquare.com/blog/llms-for-software-development>)

Author: Noah Fraiture - Backend Engineer

Published: 2026-09-15T13:03:38Z

Content type: article

Language: en

Sources: [Guardsquare Blog](<https://devfeed.tech/sources/guardsquare-blog.md>)

Topics: [Development](<https://devfeed.tech/topics/development.md>), [Large Language Model](<https://devfeed.tech/topics/llm.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Security & Privacy](<https://devfeed.tech/topics/security-privacy.md>), [agent observability](<https://devfeed.tech/topics/agent-observability.md>)

Tags: [ai-agents](<https://devfeed.tech/tags/ai-agents.md>), [android](<https://devfeed.tech/tags/android.md>), [containers](<https://devfeed.tech/tags/containers.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [data](<https://devfeed.tech/tags/data.md>), [dev](<https://devfeed.tech/tags/dev.md>), [developer](<https://devfeed.tech/tags/developer.md>), [development](<https://devfeed.tech/tags/development.md>), [ios](<https://devfeed.tech/tags/ios.md>), [llm](<https://devfeed.tech/tags/llm.md>), [llm-gateway](<https://devfeed.tech/tags/llm-gateway.md>), [thought-leadership](<https://devfeed.tech/tags/thought-leadership.md>)

### AI overview

Guardsquare explains why it adopted LLM-assisted software development despite risks involving sensitive intellectual property, personally identifiable information, and agent access to developer infrastructure. The post describes safeguards including separating sensitive code, isolating agent execution, and controlling model access and outbound data through an LLM gateway and guardrail service.

### Source excerpt

This post is not meant to tell you how to use large language models (LLMs) or to claim we've found the right approach. As a cybersecurity company working with particularly sensitive IP, our decision to use LLMs for development was never just about productivity. The broader enthusiasm around LLMs was not itself a reason for us to adopt them quickly. For some time, our position was that the risks outweighed the productivity gains, and incidents involving AI agents elsewhere in the industry reinforced that assessment.

## HBO Max Reddit account compromised to serve ClickFix attacks

DevFeed: [HBO Max Reddit account compromised to serve ClickFix attacks](<https://devfeed.tech/articles/hbo-max-reddit-account-compromised-to-serve-clickfix-attacks-21627.md>)

Original publisher: [Read original article](<https://www.theregister.com/cyber-crime/2026/09/14/hbo-max-reddit-account-compromised-to-serve-clickfix-attacks/5296408>)

Author: Jessica Lyons

Published: 2026-09-14T22:43:01Z

Content type: news

Language: en

Sources: [www.theregister.com - Articles](<https://devfeed.tech/sources/www-theregister-com-articles.md>)

Topics: [ClickFix](<https://devfeed.tech/topics/clickfix.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [Reddit](<https://devfeed.tech/topics/reddit.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [macOS](<https://devfeed.tech/topics/macos.md>), [Windows](<https://devfeed.tech/topics/windows.md>)

Tags: [clickfix](<https://devfeed.tech/tags/clickfix.md>), [cyber-crime](<https://devfeed.tech/tags/cyber-crime.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [hbo-max](<https://devfeed.tech/tags/hbo-max.md>), [macos](<https://devfeed.tech/tags/macos.md>), [malware](<https://devfeed.tech/tags/malware.md>), [reddit](<https://devfeed.tech/tags/reddit.md>), [security](<https://devfeed.tech/tags/security.md>), [windows](<https://devfeed.tech/tags/windows.md>)

### AI overview

The article reports that an HBO Max Reddit account was compromised and used to serve ClickFix attacks in a massive 48-hour malvertising campaign targeting macOS and Windows machines with malware.

### Source excerpt

Part of a 'massive 48-hour malvertising blitz' targeting macOS and Windows machines with malware

## New hardware device can RAM into encrypted memory, expose your data

DevFeed: [New hardware device can RAM into encrypted memory, expose your data](<https://devfeed.tech/articles/new-hardware-device-can-ram-into-encrypted-memory-expose-your-data-21632.md>)

Original publisher: [Read original article](<https://www.theregister.com/security/2026/09/14/new-hardware-device-can-ram-into-encrypted-memory-expose-your-data/5296377>)

Author: Thomas Claburn

Published: 2026-09-14T18:31:33Z

Content type: news

Language: en

Sources: [www.theregister.com - Articles](<https://devfeed.tech/sources/www-theregister-com-articles.md>)

Topics: [Hardware](<https://devfeed.tech/topics/hardware.md>), [Security](<https://devfeed.tech/topics/security.md>), [Server](<https://devfeed.tech/topics/server.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>)

Tags: [amd](<https://devfeed.tech/tags/amd.md>), [confidential-computing](<https://devfeed.tech/tags/confidential-computing.md>), [ddr5](<https://devfeed.tech/tags/ddr5.md>), [ddrop](<https://devfeed.tech/tags/ddrop.md>), [hardware](<https://devfeed.tech/tags/hardware.md>), [intel](<https://devfeed.tech/tags/intel.md>), [memory](<https://devfeed.tech/tags/memory.md>), [security](<https://devfeed.tech/tags/security.md>), [server](<https://devfeed.tech/tags/server.md>)

### AI overview

A new hardware attack can compromise encrypted DDR5 memory and expose data. The attack requires physical access to the server.

### Source excerpt

Attackers would need physical access to the server to pull off the DDR5 trick

## Open Secure AI Alliance Joins the Linux Foundation to Build a Shared, Open Defense Stack for the AI Era

DevFeed: [Open Secure AI Alliance Joins the Linux Foundation to Build a Shared, Open Defense Stack for the AI Era](<https://devfeed.tech/articles/open-secure-ai-alliance-joins-the-linux-foundation-to-build-a-shared-open-defense-stack-for-the-ai-era-17457.md>)

Original publisher: [Read original article](<https://www.linuxfoundation.org/blog/open-secure-ai-alliance-joins-the-linux-foundation-to-build-a-shared-open-defense-stack-for-the-ai-era>)

Author: andrewb@proximabiz.com (The Linux Foundation)

Published: 2026-09-14T16:00:00Z

Content type: news

Language: en

Sources: [Linux Foundation - Blog](<https://devfeed.tech/sources/linux-foundation-blog.md>)

Topics: [Linux](<https://devfeed.tech/topics/linux.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Securing AI](<https://devfeed.tech/topics/securing-ai.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Security](<https://devfeed.tech/topics/security.md>), [Resilience](<https://devfeed.tech/topics/resilience.md>), [Inference](<https://devfeed.tech/topics/inference.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [ai-security](<https://devfeed.tech/tags/ai-security.md>), [collaboration](<https://devfeed.tech/tags/collaboration.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [governance](<https://devfeed.tech/tags/governance.md>), [infrastructure](<https://devfeed.tech/tags/infrastructure.md>), [linux](<https://devfeed.tech/tags/linux.md>), [models](<https://devfeed.tech/tags/models.md>), [nvidia](<https://devfeed.tech/tags/nvidia.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [open-source-security](<https://devfeed.tech/tags/open-source-security.md>), [open-source-software](<https://devfeed.tech/tags/open-source-software.md>), [resilience](<https://devfeed.tech/tags/resilience.md>), [security](<https://devfeed.tech/tags/security.md>), [september-2026](<https://devfeed.tech/tags/september-2026.md>), [standards](<https://devfeed.tech/tags/standards.md>)

### AI overview

The Open Secure AI Alliance has joined the Linux Foundation under neutral governance. It aims to help organizations collaborate on open AI security tools, research, shared standards, and verifiable defenses spanning models, inference, agents, identity, policy, enforcement, containment, and infrastructure.

### Source excerpt

Originally founded by dozens of enterprise leaders and NVIDIA, the Alliance moves to neutral governance to expand industry collaboration on open AI security tools, research and shared defenses

## Cyberattack sends International Meteor Organization crashing back to Earth

DevFeed: [Cyberattack sends International Meteor Organization crashing back to Earth](<https://devfeed.tech/articles/cyberattack-sends-international-meteor-organization-crashing-back-to-earth-21626.md>)

Original publisher: [Read original article](<https://www.theregister.com/cyber-crime/2026/09/14/cyberattack-sends-international-meteor-organization-crashing-back-to-earth/5296282>)

Author: Carly Page

Published: 2026-09-14T16:00:00Z

Content type: news

Language: en

Sources: [www.theregister.com - Articles](<https://devfeed.tech/sources/www-theregister-com-articles.md>)

Topics: [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Security](<https://devfeed.tech/topics/security.md>), [datacenter](<https://devfeed.tech/topics/datacenter.md>)

Tags: [cyber-crime](<https://devfeed.tech/tags/cyber-crime.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [infrastructure](<https://devfeed.tech/tags/infrastructure.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

A cyberattack dealt a critical blow to the International Meteor Organization's aging infrastructure, with several weeks of disruption expected.

### Source excerpt

Attack dealt a 'critical blow' to aging infrastructure, with several weeks of disruption expected

## Perfect-10 GitLab bug under attack days after patch lands

DevFeed: [Perfect-10 GitLab bug under attack days after patch lands](<https://devfeed.tech/articles/perfect-10-gitlab-bug-under-attack-days-after-patch-lands-21634.md>)

Original publisher: [Read original article](<https://www.theregister.com/security/2026/09/14/perfect-10-gitlab-bug-under-attack-days-after-patch-lands/5296176>)

Author: Carly Page

Published: 2026-09-14T14:30:00Z

Content type: news

Language: en

Sources: [www.theregister.com - Articles](<https://devfeed.tech/sources/www-theregister-com-articles.md>)

Topics: [GitLab](<https://devfeed.tech/topics/gitlab.md>), [bug](<https://devfeed.tech/topics/bug.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Internet](<https://devfeed.tech/topics/internet.md>), [servers](<https://devfeed.tech/topics/servers.md>)

Tags: [bug](<https://devfeed.tech/tags/bug.md>), [cisa](<https://devfeed.tech/tags/cisa.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [cybersecurity-and-infrastructure-security-agency](<https://devfeed.tech/tags/cybersecurity-and-infrastructure-security-agency.md>), [exploit](<https://devfeed.tech/tags/exploit.md>), [gitlab](<https://devfeed.tech/tags/gitlab.md>), [internet](<https://devfeed.tech/tags/internet.md>), [security](<https://devfeed.tech/tags/security.md>), [servers](<https://devfeed.tech/tags/servers.md>)

### AI overview

CISA confirms active exploitation of a critical GitLab vulnerability shortly after a patch was released. Security researchers observed attackers probing internet-facing servers.

### Source excerpt

CISA confirms active exploitation as watchTowr spots miscreants probing internet-facing servers

## UK.gov begins killing off passwords for 23 million users

DevFeed: [UK.gov begins killing off passwords for 23 million users](<https://devfeed.tech/articles/uk-gov-begins-killing-off-passwords-for-23-million-users-17411.md>)

Original publisher: [Read original article](<https://www.theregister.com/security/2026/09/14/ukgov-begins-killing-off-passwords-for-23-million-users/5296088>)

Author: Carly Page

Published: 2026-09-14T09:16:11Z

Content type: article

Language: en

Sources: [www.theregister.com - Articles](<https://devfeed.tech/sources/www-theregister-com-articles.md>)

Topics: [Passkeys](<https://devfeed.tech/topics/passkeys.md>), [passwords](<https://devfeed.tech/topics/passwords.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>)

Tags: [government-of-the-united-kingdom](<https://devfeed.tech/tags/government-of-the-united-kingdom.md>), [password](<https://devfeed.tech/tags/password.md>), [passwords](<https://devfeed.tech/tags/passwords.md>), [phishing](<https://devfeed.tech/tags/phishing.md>), [security](<https://devfeed.tech/tags/security.md>), [uk](<https://devfeed.tech/tags/uk.md>), [whitehall](<https://devfeed.tech/tags/whitehall.md>)

### AI overview

The UK government is beginning to replace passwords with passkeys for 23 million users. The change is intended to reduce phishing problems and save Whitehall approximately GBP 600 per day in SMS costs.

### Source excerpt

Passkeys promise fewer phishing headaches - and GBP 600 a day off Whitehall's SMS bill

## A week in security (September 7 - September 13)

DevFeed: [A week in security (September 7 - September 13)](<https://devfeed.tech/articles/a-week-in-security-september-7-september-13-17400.md>)

Original publisher: [Read original article](<https://www.malwarebytes.com/blog/news/2026/09/a-week-in-security-september-7-september-13>)

Author: Malwarebytes Labs

Published: 2026-09-14T07:01:00Z

Content type: news

Language: en

Sources: [Malwarebytes](<https://devfeed.tech/sources/malwarebytes.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>)

Tags: [2026](<https://devfeed.tech/tags/2026.md>), [bluemoon](<https://devfeed.tech/tags/bluemoon.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [grindr](<https://devfeed.tech/tags/grindr.md>), [lg-tvs](<https://devfeed.tech/tags/lg-tvs.md>), [news](<https://devfeed.tech/tags/news.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

A weekly security roundup covering topics discussed from September 7 to September 13, 2026.

### Source excerpt

A list of topics we covered in the week of September 7 to September 13 of 2026

## GitLab Dedicated: Compliance for a new regulatory era

DevFeed: [GitLab Dedicated: Compliance for a new regulatory era](<https://devfeed.tech/articles/gitlab-dedicated-compliance-for-a-new-regulatory-era-20785.md>)

Original publisher: [Read original article](<https://about.gitlab.com/blog/gitlab-dedicated-compliance/>)

Author: Aathira Nair

Published: 2026-09-14T00:00:00Z

Content type: article

Language: en

Sources: [GitLab](<https://devfeed.tech/sources/gitlab.md>)

Topics: [GitLab](<https://devfeed.tech/topics/gitlab.md>), [Software as a service](<https://devfeed.tech/topics/saas.md>), [Amazon Web Services](<https://devfeed.tech/topics/aws.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Security](<https://devfeed.tech/topics/security.md>), [Resilience](<https://devfeed.tech/topics/resilience.md>), [Deployment](<https://devfeed.tech/topics/deployment.md>), [Testing](<https://devfeed.tech/topics/testing.md>), [Multitenancy](<https://devfeed.tech/topics/multitenancy.md>)

Tags: [amazon-web-services-aws](<https://devfeed.tech/tags/amazon-web-services-aws.md>), [aws](<https://devfeed.tech/tags/aws.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [deployment](<https://devfeed.tech/tags/deployment.md>), [gdpr](<https://devfeed.tech/tags/gdpr.md>), [gitlab](<https://devfeed.tech/tags/gitlab.md>), [infrastructure-as-code](<https://devfeed.tech/tags/infrastructure-as-code.md>), [nis2](<https://devfeed.tech/tags/nis2.md>), [product](<https://devfeed.tech/tags/product.md>), [regulatory](<https://devfeed.tech/tags/regulatory.md>), [resilience](<https://devfeed.tech/tags/resilience.md>), [saas](<https://devfeed.tech/tags/saas.md>), [security](<https://devfeed.tech/tags/security.md>), [testing](<https://devfeed.tech/tags/testing.md>)

### AI overview

The article presents GitLab Dedicated as a fully isolated, single-tenant SaaS platform hosted and managed by GitLab in a preferred Amazon Web Services region. It explains how the service is intended to help European enterprises address compliance, data sovereignty, audit readiness, security, resilience, and operational responsibilities related to DORA, NIS2, and GDPR.

### Source excerpt

Enforcements such as NIS2 are no longer a future planning consideration. The European Union Agency for Cybersecurity's (ENISA) NIS360 report confirms that supervisory authorities are actively assessing cybersecurity maturity across critical sectors. The agency is moving from guidance and consultation into active oversight, scrutiny, and accountability. This is the regulatory environment European enterprises now operate in. Multi-tenant cloud platforms remove operational overhead but place source code and pipelines on shared infrastructure regulators now scrutinize. Self-managed solutions provide isolation but transfer responsibility for upgrade cycles, security patches, and disaster recovery (DR) tests to an already stretched platform team. Both deployment options leave gaps in risk management, data sovereignty, and furnishing audit evidence. In this article, you'll discover how GitLab Dedicated, a fully isolated, single-tenant SaaS solution deployed in your preferred Amazon Web Services (AWS) region and hosted and managed by GitLab, addresses these challenges and helps you keep pace with evolving compliance requirements. "NatWest Group is adopting GitLab Dedicated SaaS to enable our engineers to use a common cloud engineering platform; delivering new customer and colleague outcomes rapidly, frequently, and securely with high quality, automated testing, on-demand infrastructure, and straight-through deployment." -- Adam Leggett, Platform Lead for Engineering Platforms, NatWest Group Regulations are driving change In the European Union, key regulations are driving the need for a different platform approach. These regulations converge on a decision most enterprises made before they existed: a platform their developers build on. That decision now carries audit consequences it didn't before. Digital Operational Resilience Act (DORA), which came into force across EU financial services in January 2025, requires financial institutions to keep critical technology resilient,

## Benchmaxxing: When the Benchmark Becomes the Target

DevFeed: [Benchmaxxing: When the Benchmark Becomes the Target](<https://devfeed.tech/articles/benchmaxxing-when-the-benchmark-becomes-the-target-8302.md>)

Original publisher: [Read original article](<https://www.crowdstrike.com/en-us/blog/benchmaxxing-when-benchmark-becomes-the-target/>)

Author: Nathan Danneman

Published: 2026-09-12T11:17:51.295154Z

Content type: article

Language: en

Sources: [Blog](<https://devfeed.tech/sources/blog.md>)

Topics: [Benchmark](<https://devfeed.tech/topics/benchmark.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Ground truth / benchmark quality](<https://devfeed.tech/topics/ground-truth-benchmark-quality.md>), [Detection engineering](<https://devfeed.tech/topics/detection-engineering.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [ai-and-cybersecurity](<https://devfeed.tech/tags/ai-and-cybersecurity.md>), [benchmark](<https://devfeed.tech/tags/benchmark.md>), [benchmarking](<https://devfeed.tech/tags/benchmarking.md>), [benchmarks](<https://devfeed.tech/tags/benchmarks.md>), [blog](<https://devfeed.tech/tags/blog.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [leaderboards](<https://devfeed.tech/tags/leaderboards.md>), [securing-ai](<https://devfeed.tech/tags/securing-ai.md>), [security](<https://devfeed.tech/tags/security.md>), [validation](<https://devfeed.tech/tags/validation.md>)

### AI overview

The article explains how public AI and cybersecurity benchmarks can become targets for optimization, a practice it calls "benchmaxxing." It argues that gaming, ceiling effects, data leakage, binary scoring, omitted costs, and aggregate scores can make benchmark results poor proxies for real-world defensive capability. The article proposes task-coupled internal benchmarks intended to evaluate end-to-end cyber agents and support rigorous science rather than visibility-driven score optimization.

### Source excerpt

The more attention a benchmark receives, the stronger the incentive to optimize for it. In AI and cybersecurity, this can have significant consequences.

[Next page](<https://devfeed.tech/topics/cybersecurity.md?cursor=WyIyMDI2LTA5LTEyVDExOjE3OjUxLjI5NTE1NCswMDowMCIsICIyOTg3ZDA4OC05MGJjLTRlMTMtYjRkMC0zOGFhOTIzMTM0Y2MiXQ%3D%3D>)