AWS Bedrock’s Sandbox Gets Pwned, Is RSAC Over Yet, and Google Closes B Wiz Deal

The Cybersecurity Pulse newsletter by Darwin Salazar summarizes major security news, notable breaches and disclosures, product launches, and industry funding rounds, including an AWS Bedrock AgentCore sandbox escape and Google’s acquisition of Wiz. It also highlights the rising risks from autonomous AI agents and the emergence of AI-driven detection and remediation tools across the security stack. #AWSBedrockAgentCore #Wiz

Read More
25 Million Alerts. One Year of Real SOC Data.

Intezer’s 2026 AI SOC Report analyzes 25 million operational alerts and shows that SOCs routinely miss real threats hidden in low-severity alerts and that EDRs frequently report “mitigated” while endpoints remain compromised. The write-up recommends AI-augmented forensic triage, reassessing phishing defenses for browser-based attacks, and cleaning cloud misconfigurations to close these coverage gaps. #Intezer #S3 #CloudflareTurnstile #Vercel

Read More
The Curated Catalog: The Biggest Defense Against Shai-Hulud 3.0

Shai-Hulud 2.0 revealed that pre-install execution hooks and hijacked CI/CD runners can weaponize package installs to harvest cloud credentials and persist by enrolling self-hosted GitHub runners. Preventing a Shai-Hulud 3.0 requires moving control away from individual developers to a curated, built-from-source catalog with SLSA-hardened provenance and cryptographic pinning for reliable, organization-wide open-source consumption. #ShaiHulud2 #ActiveState

Read More
The AppSec Model Was Built for a World That’s Disappearing.

Clover Security embeds AI agents into the design and architecture phase to catch business logic and architecture risks that traditional downstream AppSec tooling misses. The platform’s Memory Agent, Feature Context Graph, and agent fleet automate design reviews, detect implementation drift and AI-generated code risks, and have delivered measurable coverage and speed gains for customers. #CloverSecurity #Neo4j

Read More
Cybersecurity Club Mentorship Program – Find a Mentor or Become a Mentor

The Cybersecurity Club runs a six-week Discord mentorship program that pairs learners with experienced practitioners to build hands-on skills, earn certifications, and advance careers. Participants follow a structured weekly check-in routine and can join as mentees or mentors across topics like penetration testing, Red Team work, SOC skills, and certification preparation. #CISSP #Wireshark

Read More
PostgreSQL Penetration Testing

This guide walks through a real-world PostgreSQL penetration testing workflow from reconnaissance to post-exploitation, demonstrating scanning, authentication attacks, file reads, command execution, and reverse shells using practical examples. It also outlines Metasploit and client-based techniques, credential attacks, and actionable hardening and remediation steps to secure PostgreSQL deployments. #PostgreSQL #Metasploit

Read More
A Unified Identity Defense Layer: Why PAM with ITDR Is the Foundation for 2026 Security

Identity-based attacks increasingly begin with valid credentials, making a unified identity defense layer that combines privileged access management (PAM) and identity threat detection and response (ITDR) essential for organizational resilience by 2026. This integrated approach detects anomalous identity behavior, enables automated remediation, and supports Zero Trust and compliance frameworks—illustrated by incidents like the FICOBA breach and solutions such as Syteca. #FICOBA #Syteca

Read More
How to Find the Gaps in Your Security Program Before an Attacker Does

Most security programs are uneven after years of reactive, compliance-driven purchasing, leaving unmapped gaps that represent the highest business risk. This workshop teaches how to map controls across the NIST Cybersecurity Framework and apply the TaSM (Threat and Safeguard Matrix) to identify critical gaps and prioritize remediation. #NISTCybersecurityFramework #TaSM

Read More
TCP #124: Security’s Biggest Founders Return, AI Is Guarding Its Own Henhouse, and A Wiper Hits Healthcare

The Cybersecurity Pulse highlights a global Microsoft Intune-based attack that Handala says wiped devices and exfiltrated vast data from Stryker, causing widespread operational disruption. It also reviews AI-driven security innovations, major startup funding, and shrinking time-to-exploit trends that pressure teams to prioritize patching and attack surface reduction. #Handala #Stryker #MicrosoftIntune #VoidManticore

Read More
Learn How to Use Linux for Cybersecurity

Linux is presented as the foundation for cybersecurity work because most servers, cloud infrastructure, containers, and many devices run on Linux, making a practical understanding of the OS essential for testing, hardening, monitoring, and forensics. The guide then lays out a three-phase roadmap—from beginner-friendly GUI distributions to command-line mastery and security-focused…

Read More
Learn Ethical Hacking Skills With

Hack The Box (HTB) Academy provides hands-on, real-world labs and structured learning paths that let beginners grow into skilled ethical hackers. Modules are unlocked with cubes—the platform’s currency—with a 50-cube starter bonus via Cybersecurity Club, plus job-role and skill paths and a deep offensive security catalog that progresses from free Tier…

Read More
Top 5 Most Important Network Protocols

This article helps cybersecurity beginners focus on the five most important network protocols and understand why they matter in real-world security, starting with the TCP/IP model and HTTP basics. It explains the differences between TCP and UDP, the role of SMTP/IMAP/POP3 and FTP in secure communications, and why mastering these basics…

Read More