Aug 
19, 
2026

There Is No “Left” Left

Shift left was a good idea for a world that no longer exists. It assumed a human wrote the code, a human reviewed it, and security could nudge itself a little earlier into that human rhythm. That rhythm is gone. When an agent can turn one sentence into a running feature...
Aug 
4, 
2026

Containers and Security – Is Your Software Pipeline Leaky?

As containers become a standard component of modern software delivery, security teams and developers face a growing challenge: ensuring that convenience and speed do not introduce hidden risk into the CI/CD pipeline. This article examines how malicious container images can enter development workflows through public registries, the warning signs that...
Jun 
29, 
2026

5 Types of Impersonation Attacks and Ways to Prevent Them

Technology is a double-edged sword. When used correctly, it can result in cutting-edge solutions and digitization. Its misuse, on the other hand, can wreak havoc. As people and organizations become increasingly dependent on technology, it is crucial to be aware of cybercrime trends and potential risks. Only then can we...
May 
19, 
2026

Threat Modeling for Infrastructure as Code

Infrastructure as Code (IaC) frameworks are powerful tools, but they come with their own security risks. Misconfigurations, insecure defaults, or insufficient access controls can be exploited by attackers. Threat modeling helps identify weaknesses early and creates transparency around potential attack vectors before critical flaws ever reach production. This article introduces...
May 
6, 
2026

Balancing Security and Agility with a Chief Trust Officer

As digital transformation takes shape, we’re all hearing about the accelerating pace of change. But through it all, one thing that hasn’t changed is the need for trust in our transactions and relationships. Trust is fundamental to every interaction, and it has become increasingly critical in a complex, dynamic world....
Apr 
9, 
2026

The Dark Side of npm: Detecting and Mitigating Supply Chain Attacks

In 2022 alone, npm saw multiple high-profile breaches, from cryptominers hidden in ua-parser-js to the deliberate sabotage of colors.js. With over 2 million packages and minimal publishing oversight, npm has become both the backbone of modern JavaScript development and a prime target for attackers. From typosquatting to dependency hijacking, malicious...
Mar 
31, 
2026

Modernizing Threat Modeling: Embracing Zero Trust for Cloud-Native Securit

This article explores how adopting a Zero Trust security model can modernize threat modeling, enabling continuous verification, least-privilege access, and proactive defense across dynamic systems. By integrating Zero Trust principles into DevSecOps and CI/CD pipelines, organizations can build adaptive threat models that strengthen cloud security, risk management, and resilience.

Enjoying the content?

Get the most out of IT Security Summit by becoming a free community member — curated resources, weekly newsletter, and member-only perks.

Weekly
Articles + tutorials

The reads you'd find if you had time

2× / mo
Live webinars

Experts you can actually ask

Monthly
Magazine + whitepapers

Deep dives worth your weekend

On-demand
Recordings + courses

Past conferences, ready when you are

AI-Powered Security
Harness AI for security automation, threat detection, and integrating AI-driven solutions into DevSecOps.

Cloud, API Security & Identity
Safeguard your cloud environments, APIs, and identities with advanced strategies.

DevSecOps
Integrate security into your DevOps processes with precision.

Pentesting, Vulnerability Management & Forensics
Advance your offensive security skills with cutting-edge penetration testing techniques.

Secure Coding & Software Development Lifecycle
Create secure software from the ground up by mastering secure coding practices and embedding security throughout the Software Development Lifecycle (SDLC).