#zero-trust
17 stories taggedzero-trust.

CISA Wants You to Leave a Trap Out for Hackers
America's cyber-defence agency has published detailed guidance on using decoys, fake password files, and tripwire accounts to catch attackers who have already slipped inside a network.

CISA Tells Defenders to Plant Fake Systems and Wait
New federal guidance walks security teams through using decoys, tripwires and fake credentials to spot attackers who look like legitimate users.

ShinyHunters Claimed It Broke Into ReliaQuest. The Reality Is More Complicated.
A cybersecurity company's own employee fell for a fake login page, handing criminals limited access. What happened next is actually a story about defences holding.

AI Agents Are Breaking the Security Model Enterprises Spent a Decade Building
Zero trust was supposed to be the answer to modern cyber risk. Agentic AI may have quietly made it obsolete.

Why 'Identity Fabric' Is the Phrase Every Security Team Will Hear in 2026
As passwords fade and machine accounts outnumber humans, a new architecture promises to watch every login, token and API call in one place. What it actually means.

Microsoft says the patching window is shrinking fast. Here is what that means for ordinary people.
Software flaws are being turned into working attacks within hours of being made public. Microsoft says companies can no longer patch their way out fast enough, and is pushing a network-level defensive layer to buy time.

Passwords Are Getting Easier to Fake. Device Trust Is the Fix Companies Are Reaching For.
AI is turbocharging phishing and credential theft, and the old signals that told a company a login was fine are quietly failing. Here is what is replacing them.

ThreatLocker Raises $190 Million to Expand Its Block-Everything-First Security Model
The Florida firm now counts more than 70,000 business customers and is opening a UK office on the back of its latest funding haul.

What is zero trust? A plain-English guide
Zero trust means your network stops assuming anyone inside it is safe, and checks every user and device every single time.

Why Stolen Logins Keep Opening the Door to Power Grids and Water Plants
Attackers rarely need fancy exploits when a valid password and an unchecked laptop will do. A look at why device trust is the missing half of Zero Trust in critical infrastructure.

A Hidden Command in a GitHub Issue Can Silently Steal a Company's Private Code
Researchers found a flaw in GitHub's AI automation tool that lets an outsider read an organisation's private repositories by hiding plain-English instructions inside a public bug report.

Cisco Spends Around $400 Million to Plug a Growing Security Blind Spot: AI Agents
Two rapid-fire acquisitions, Astrix Security and WideField Security, are Cisco's answer to a question most companies haven't thought to ask: who's watching the bots?

CISA's New Playbook Nudges Agencies Toward Zero Trust — and Everyone Else Can Read Along
The agency's updated TIC 3.0 guidance folds Secure Access Service Edge into federal network modernisation, and the advice travels well beyond government.

Zero Trust in OT: A Pragmatic 90-Day Action Plan
Applying zero trust to operational technology environments without breaking operations or losing the room.

Zero Trust as the AI Control Plane: What Zscaler's Vienna Pitch Means for APAC CISOs
AI agents are joining the workforce whether security teams are ready or not. At Zenith Live 2026, Zscaler made its case for why zero trust should govern them the same way it governs humans.