Steven Bowcut


As AI systems gain the ability to exploit vulnerabilities and follow attack paths, human oversight must remain more than a ceremonial checkpoint. There is a meaningful difference between asking artificial intelligence to identify a vulnerability and authorizing it to exploit one. The first is an extension of what automated security […]

The Guardrails That Make Autonomous Pentesting Safe



Agentic AI may help security teams identify which weaknesses attackers could actually exploit—but continuous offensive testing requires evidence, boundaries, and human oversight. Security teams seldom suffer from a shortage of findings. The more constant problem is determining which findings describe a genuine path to compromise—and which will consume remediation time […]

From Vulnerability Counts to Proven Attack Paths



Salesforce is strengthening authentication for privileged users. Token argues that enterprises should go further by verifying the person behind the credential. Salesforce administrators hold the keys to an extraordinary amount of sensitive information. Depending on the organization, that may include customer records, sales projections, financial histories, donor information, support cases, […]

Beyond Phishing Resistance: Proving Who Is Accessing Salesforce


BlackGirlsHack is taking a different approach to SquadCon this year. Instead of staging its annual in-person cybersecurity conference during Hacker Summer Camp in Las Vegas, BlackGirlsHack is launching SquadCon 2026: Squad Support Edition, a combination of virtual programming, career assistance, financial support, and community networking scheduled for August 4–6. The […]

SquadCon 2026 Puts Resources Directly Into Community Hands


Approov’s new chairman brings decades of financial, legal, and operational experience as the company prepares for growing mobile app, API, and AI-agent security challenges. Approov has appointed Silicon Valley technology executive Rex S. Jackson as independent chairman of its Board of Directors, positioning the mobile app and API security company […]

Approov Names Rex S. Jackson Chairman as Mobile API Risks ...



Mobile applications have become a primary gateway to some of an organization’s most sensitive systems. Banking apps process financial transactions. Healthcare apps provide access to medical information. Retail apps store payment details and purchasing histories. Connected vehicle apps can even control physical functions. Behind each of these applications is a […]

Agentic AI Raises the Stakes for Mobile API Security


Automatic tank gauge systems may appear to be relatively simple monitoring devices. They measure the contents of storage tanks and provide operators with information needed to manage fuel, chemicals, water-treatment materials, and other liquids. But when these systems are exposed to the public internet, protected by default credentials, or connected […]

Internet-Exposed Tank Gauges Reveal a Persistent Critical Infrastructure Risk





In Episode S8E7 of the Brilliance Security Magazine Podcast, host Steven Bowcut speaks with Phuong “Kenny” Nguyen, Chief Technology Officer at KhaiCode, about the growing challenge of understanding what is actually inside the software organizations rely on every day. KhaiCode focuses on what it calls binary exploit intelligence: the process […]

Why Binary Exploit Intelligence Matters in Software Supply Chain Security


As financial institutions accelerate their adoption of AI, automation, and cloud-native software delivery, a critical part of the enterprise technology stack may still be operating with outdated controls: database change. Liquibase, a provider of database change governance solutions used by many leading financial services organizations, has released The Financial Services […]

AI Raises the Stakes for Database Governance