Check the
Latest News.

Secrets Sprawl: 6 Patterns to Stop CI/CD Credential Leaks

Secrets sprawl isn't a public-GitHub problem anymore - it lives inside the CI/CD pipelines teams depend on every day. This piece breaks down six operational patterns that separate teams whose pipelines quietly accumulate leaked credentials from teams that actually close the gap.
Secrets Sprawl

Vendor Risk: 5 Signals Your AI Supply Chain Is Exposed

Traditional vendor risk management assumes software is static. AI vendors aren't — models drift, sub-processors multiply, and shadow AI slips in through tools you already approved. Here are five signals your due diligence process is behind.
Vendor Risk: 5 Signals Your AI Supply Chain Is Exposed

Non-Human Identity: 5 Gaps AI Agents Expose in IAM

This piece breaks down five places IAM architecture still assumes a human is on the other end of the request, and what happens when that assumption fails.
Non-human Identity

SBOM and the CRA: 3 Deadlines Your Team Can’t Miss

The EU Cyber Resilience Act has a September 2026 deadline most teams don't know about. This guide covers the three CRA deadlines that actually matter and how to build an SBOM readiness plan before the clock runs out.
Software Bill of Materials SBOM

Open Archives at Fyld: A New Chapter Begins

Fyld officially opened the doors to its new office through Open Archives at Fyld — an inauguration experience inspired by the idea of a living archive. Through memories, installations, and shared moments, the event celebrated the journey, culture, and people that continue to shape Fyld’s story.
Fyld Office

DevSecOps Pipeline: From Code Scanning to Runtime Protection in 2026

A DevSecOps Pipeline is not a sequence of tools, but a system of enforced guarantees that governs how software moves from code to runtime. This article explains how to design, scale, and operationalize it as a control system.
DevSecOps Pipeline