Global coverage highlighting Mitiga’s role in moving security beyond prevention and defining Zero-Impact Breach Prevention as the new standard.
Security leaders are increasingly measured by their ability to answer the board’s first questions with confidence: What happened? What did it touch? How long did it last? What was the business impact?
April 13, 2026
Brian Contos is the Field CISO at Mitiga with 30+ years of experience building successful companies and evangelizing cybersecurity.
April 2, 2026
At RSAC 2026, Brian Contos warned AI is recreating cloud's identity mess at machine speed, as agents, copilots and non-human identities outpace governance and leave enterprises exposed to breaches, compliance failures and opaque decisions.
April 1, 2026
At this time last year, the cybersecurity world appeared to be successfully balancing the use of artificial intelligence to prevent attacks and defending against adoption of the same tools by hostile nation-states and malicious actors. The story is different now.
March 30, 2026
As enterprises increasing depend on cloud services, living off the land has evolved into living off the cloud.
March 13, 2026
Attackers are already ahead in the AI race. The only durable posture is resilience: the ability to detect threats early and respond before they escalate.
February 20, 2026
The biggest security incidents in 2026 will stem from compromised identities within supposedly zero trust environments.
January 30, 2026
"Next-generation threat hunters will rely on anomaly-based AI systems trained on historical baselines and user behavior patterns," says Ariel Parnes.
January 26, 2026
Ariel Parnes talks to Security Week about new API layers, like those from AI infrastructure, exposing sensitive systems in unpredictable ways in 2026.
January 21, 2026
The most successful breaches in 2026 are likely to exploit trust, not vulnerabilities. All courtesy of artificial intelligence (AI).
January 16, 2026
Roei Sherman, Head of Research, highlights a class of attack we'll see more in 2026 at Cyber Defense Magazine.
January 12, 2026
Today’s most damaging incidents aren’t hitting clinical systems directly. They’re triggered by compromised identities – often a single stolen login.
January 6, 2026
Ariel Parnes predicts that cybersecurity will become an AI-driven battleground in 2026.
December 23, 2025
Mitiga Labs head of research Roei Sherman predicts 2026 to be the Year of SaaS Breaches.
Modern threats move fast, but detection has to move faster, combining AI precision and human intuition to stop attacks before they spread.
December 16, 2025
Salesforce failed to address the massive wave of OAuth breaches at its Dreamforce conference, but securing third-party authentication is paramount for the agentic future it seeks.
October 22, 2025
As AI reshapes the cyber threat landscape, organizations need to keep up with the evolving nature of these threats.
October 21, 2025
In a revelation that should concern every security leader, the U.S. Justice Department (DOJ) recently disclosed that over 300 companies, including tech giants and at least one defense contractor, unknowingly hired North Korean operatives posing as remote IT workers.
August 18, 2025
Why AI is the Key to Cloud Cybersecurity: A Conversation with Ofer Maor, CTO of MITIGA
June 19, 2025
As the US Department of Homeland Security (DHS) warns of retaliatory cyberattacks against the US after bombing Iran’s nuclear infrastructure this weekend, a former Colonel of the IDF’s 8200 Cyber Unit talks cyberwarfare, Iranian hacker groups, and what the US can anticipate as the Israel-Iran conflict continues to evolve.
June 27, 2025
These collectives carry out not just traditional espionage activities, but also sabotage and disinformation operations targeting the U.S., Israel, and their allies in sectors such as finance, healthcare, energy, and water.
June 25, 2025
Cloud incident response company Mitiga Security Inc. today launched Helios AI, an artificial intelligence-powered security operations center assistant that helps security operations teams with triage, augmented investigation and accelerated threat remediation across multicloud environments.
Operation Midnight Hammer, the ultra-secret U.S. precision air attack on Iran’s nuclear sites this weekend, was stunning in its sweep and ambition. It was not only the largest strike using B-2 bombers in history but entailed the longest flight involving the fleet since 2001.
June 22, 2025
Security researchers uncovered multiple flaws in large language models developed by Chinese artificial intelligence company DeepSeek, including in its flagship R1 reasoning application.
January 31, 2025
It comes as no surprise, sadly, that cybercriminals will attack anyone and any organization as long as there its a profit in it for them, regardless of the impact on human life.
February 1, 2025
The New York Blood Center (NYBC) experienced a ransomware attack, discovered when suspicious activity was identified on IT systems. In response, the NYBC took specific systems offline and is currently working to restore them.
February 4, 2025
The New York Blood Center has suffered from a significant ransomware attack, on January 26, 2025. The non-profit blood centre collects donated blood (red cells, platelets and plasma) and uses these to create live saving products for distribution through hospitals and clinics. Read more: https://www.digitaljournal.com/world/new-york-blood-center-and-the-lessons-from-the-cyberattack/article#ixzz90u20a83I
The New York Blood Center (NYBC) said it suffered a ransomware attack that disrupted operations and forced it to reschedule some operations.
February 9, 2025
February 7, 2025
In a playbook move reminiscent of the early days of TikTok’s rise to fame in the US and its backlash from Washington lawmakers, New York state has banned government employees from using the Chinese-owned DeepSeek app over security concerns.
February 10, 2025
As Microsoft users recover from the news that three zero-day Windows vulnerabilities have been actively exploited, and there has been a surge in Russian cyber espionage attacks against Windows users, there’s more bad news for Microsoft 365 account holders.
January 16, 2025
Google is always in the news and, sadly, not always for positive reasons as far as security issues are concerned.
Security experts have shared their predictions and insights for the cybersecurity landscape in 2025, highlighting the persistence of existing threats and the emergence of new challenges as technology continues to evolve.
November 14, 2024
Here are the predictions of cybersecurity experts for 2025. These opinions will allow you to better prepare for this year which will see many challenges to overcome.
November 21, 2024
IE has so many Predictions for 2025 that there will be a series of features throughout the month. Kicking off with this one which rounds up some insights on cyber risks, data and more. Here we go.
December 2, 2024
Google's AI-powered fuzzing and augmenting SAST with AI, new OSINT/recon service for public AWS identifiers, finding EDR vulns with fuzzing
December 5, 2024
Startups offering tools for protecting cloud environments — including security for cloud data, identities and AI systems — are among those that have stood out during the year.
December 9, 2024
As we unveil the third edition of Information Security Buzz’s 2025 predictions, we are thrilled by the incredible response.
December 10, 2024
Security isn't just about tools — it's about understanding how the enemy thinks and why they make certain choices.
December 12, 2024
To wrap up our 2024 year-end roundtable, we turn our attention to new technologies and trends that are emerging to help bridge the gaps.
December 19, 2024
This collection of predictions offers some promising solutions to increasingly complex cyber challenges.
Each week, we’ll be providing a look back at the articles we posted and why they’re important to the healthcare IT community.
October 5, 2024
In an ideal world, healthcare systems would be fortified against cyberattacks, safeguarding patient data and protecting critical, life-saving operations. Yet, the reality is far from ideal.
October 3, 2024
Dell has launched an employee data breach investigation after a threat actor identified as “Grep” leaked the company’s stolen information on the dark web marketplace BreachForums.
October 1, 2024
The group claimed they accessed Disney’s system via a team member’s Slack cookies, using him as an entry point.
August 31, 2024
Disney leak included data from internal Slack messaging app about customers, staff
September 5, 2024
Mitiga unveiled its Cloud Managed Detection and Response (MDR) service, designed to provide 24/7 protection against the increasingly complex threats targeting cloud and SaaS environments.
September 11, 2024
Security Program Controls/Technologies
August 29, 2024
Need to secure non-human entities, leaky clouds, and complex environments? The companies included in our network security startups to watch series have bold ideas.
August 1, 2024
Need to secure non-human entities, leaky clouds, and complex environments? These 7 network security startups have bold ideas.
Cloud environments, including software-as-a-service tools, could be easily compromised by threat actors due to defense challenges brought upon by the shared responsibility model, as well as inadequate visibility and overall client control, according to SC Media.
August 8, 2024
Cloud Security, Incident Response, Network Security, Black Hat
August 7, 2024
Small businesses are increasingly being targeted by cyberattackers. Why, then, are security features priced at a premium?
July 25, 2024
Hackers have stolen records of virtually every call made by AT&T's customers during a six-month period in 2022, after compromising the US telco's Snowflake data environment
July 12, 2024
Mitiga – an AWS validated software path partner that offers cloud threat detection, investigation and response experts for cloud and SaaS- appointed Amir Gabrieli has been appointed as VP of product. Gabrieli’s career spanning over two decades in cloud and cybersecurity; he will lead Mitiga’s product development roadmap and implementation.
June 17, 2024
EPAM, a Belarusian software company, said an investigation found no evidence that it was connected to recent attacks against Snowflake customer databases.
June 18, 2024
Ticketmaster, Santander Bank, and other large firms have suffered data leaks from a large cloud-based service, underscoring that companies need to pay attention to authentication.
June 25, 2024
June 22, 2024
Early-stage vendors focused on protecting data and GenAI usage in the cloud are among the year’s most notable cloud security startups.
July 3, 2024
Let log analysis be the guide for your Kubernetes security safari.
July 8, 2024
A massive cyberattack against AT&T exposed data from "nearly all" of its customers and downloaded it to a third-party cloud platform, AT&T said in a press release.
The best strategy to defend against ransomware attacks is a proactive one. So, the more you understand the stages of an attack, the more capable you will be at preventing them.
February 1, 2023
A hacker group called “NullBulge” says it stole more than a terabyte of Disney’s internal Slack messages and files from nearly 10,000 channels in an apparent protest over AI-generated art.
July 15, 2024
Protesting Disney’s use of crypto, pushing AI-generated art and/or stealing from artists.
July 17, 2024
After a ransomware strike on a national sales management network cost U.S. car dealerships $1 billion, hackers published data stolen from Disney's messaging channels on Slack--without even seeking a payout.
July 16, 2024
'Phishing hole' attacks are particularly dangerous during Prime Day, experts warned
Assigning responsibility for missing security controls is tricky. The burden is collective but cloud providers need to raise minimum standards, experts say.
June 13, 2024
This podcast episode discusses the recent attacks against Snowflake customers and a controversial report that claimed the cloud storage and analytics giant had been breached.
June 5, 2024
According to new threat research, Mandiant is reporting that UNC5537 conducted attacks against Snowflake database customers at least as early as April 14.
June 10, 2024
The recent Snowflake debacle highlights the need for more stringent enterprise MFA practices
June 7, 2024
Last week, the notorious hacker gang, ShinyHunters, sent shockwaves across the globe by allegedly plundering 1.3 terabytes of data from 560 million users.
June 12, 2024
“We are confident that Amir's leadership and industry knowledge will be instrumental in meeting customer demands in today’s ever-evolving cyber landscape,” said Co-Founder and CTO Ofer Maor.
Multi-factor authentication is a gold standard for cybersecurity that organizations can use to better shield users from threats. Cybersecurity experts say Snowflake's lack of MFA enforcement leaves a gap.
Snowflake is disputing claims made by a threat actor who stole data belonging to Santander and Ticketmaster, and maintains that the theft of customer data was the result of stolen customer login credentials.
June 1, 2024
Snowflake denies breach, Santander and Ticketmaster confirm data theft, Hudson Rock deletes report
A threat actor tracked as UNC5537 is using stolen credentials against Snowflake database customers to conduct data theft and extortion attacks, cloud security firm Mitiga said.
May 31, 2024
Hackers are targeting cloud storage platform Snowflake to steal data from enterprise customers.
Data breaches at Ticketmaster and financial services company Santander have been linked to attacks against cloud provider Snowflake. Researchers fear more breaches will soon be uncovered.
Cyber authorities and researchers warn many major companies could be compromised by the targeted attacks against Snowflake customer environments.
June 3, 2024
Snowflake CISO Brad Jones hit back at claims the Ticketmaster and Santander data breaches were caused by platform vulnerabilities
Snowflake on Saturday issued a joint statement with third-party investigators Mandiant and CrowdStrike denying reports that its platform had been breached.
Startups at Innovation Sandbox 2024 brought clarity to artificial intelligence, protecting data from AI, and accomplishing novel security solutions with new models.
May 23, 2024
Subtly tamper with GHA builds, repo with offense-focused Rust PoCs, how to prioritize a detection backlog
In an arena of thousands of cybersecurity vendors, there is a decent share of incremental innovation and products that are features.
May 20, 2024
Each year, RSA Conference invites cybersecurity’s boldest new innovators to compete in RSAC Innovation Sandbox, a contest that puts the spotlight on startups with potentially game-changing ideas.
May 7, 2024
Expert Insights breaks down the Innovation Sandbox finalists at RSAC 2024.
Mitiga — a finalist in this year’s RSAC Innovation Sandbox — provides capabilities for “advanced” visibility, threat detection, investigation and response in cloud and SaaS deployments. The offering ultimately enables customers to address cloud threats “70 times faster than traditional capabilities,” the company said. Mitiga has raised $45 million in total funding led ClearSky Security.
May 9, 2024
In the span of just a few years, software supply chain security has evolved from being a niche security topic to a top priority for development organizations, security practitioners and CISOs alike. That shift is evident when you take a peek at the schedule for this year’s RSA Conference in San Francisco, where talks related to software supply chain cyber risk abound.
May 1, 2024
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical flaw impacting GitLab to its Known Exploited Vulnerabilities (KEV) catalog, owing to active exploitation in the wild.
May 2, 2024
Today organizations have a large part of their environment outside of their control. They have authentication, email, data, code—some organizations have the majority of their most important assets in cloud and SaaS applications. And yet the security team does not have effective tooling to investigate across this surface.
In this conversation, we discuss: 👉 How Mitiga addresses security gaps in cloud environments 👉 The importance of simplifying complex security operations data for faster response times 👉 Emerging trends in cybersecurity threats for 2024 and how companies should prepare
May 3, 2024
In this episode, we delve into proactive cybersecurity and best practices for modern businesses with Ariel Parnes, co-founder of Mitiga and former head of the Israeli intelligence service's cyber department. With over two decades in IT and cybersecurity, Ariel brings unparalleled insights into cyber warfare and its implications for today's business environment.
May 5, 2024
The opening of the annual RSA Conference in San Francisco on Monday brought together MSSPs, MSPs, vendors and subject matter experts for a three-day event featuring new products, services and ideas representing the latest innovations and thought leadership from across the cybersecurity industry.
May 6, 2024
The practice of cybersecurity is ever-changing, marked by a continual dance between the attackers and the defenders. Each side is in a constant state of adaptation, reacting to the strategies of the other. The ongoing evolution of ransomware cybercrime is a prime illustration of this dynamic.
April 18, 2024
The Cybersecurity and Infrastructure Security Agency (CISA) urged Sisense's customers to reset passwords and other credentials that may have been exposed to or used to access Sisense's services and to report any suspicious activity.
April 12, 2024
AI, cybersecurity, digital transformation. These trends have been major themes over the past several years, but IT departments need to remain on top of what’s changing, why, and how.
April 10, 2024
Microsoft confirms that Russian state-sponsored hackers, known as Midnight Blizzard, infiltrated their systems and stole source code. Experts warn of potential zero-day vulnerabilities.
March 11, 2024
As news on an alleged Russian hack against Microsoft continues to unfold — with the latest reports revealing that Microsoft has not been yet able to shake down the Russian-linked criminal group Midnight Blizzard (also known as Nobelium), experts weigh in on the consequences of the attack.
March 15, 2024
While the medical field embraces innovation, discovering AI solutions that have the potential to enhance diagnosis, administration, and drug development, there are consistently new threats — a primary target for ransomware gangs and cybercriminals.
March 8, 2024