433 Central Ave., 4th Floor, St. Petersburg, FL 33701 | info@poseidon-us.com | Office: (813) 786-3120

AWS gives DevOps teams an AI investigator for firewall incidents

AWS DevOps Agent helps administrators inspect logs, review firewall rules and network paths, identify configuration changes that caused AWS Network Firewall to block traffic, and restore connectivity. The service is an AI-powered operations assistant for DevOps and SRE teams that investigates and troubleshoots application and infrastructure issues. It connects to monitoring tools, logs, code repositories, and deployment pipelines, analyses incidents, pinpoints likely root causes, and recommends fixes or preventive improvements. It works across AWS, multicloud, … More → The post AWS gives DevOps teams an AI investigator for firewall incidents appeared first on Help Net Security.
http://news.poseidon-us.com/TTk9hb

Marathon Petroleum’s CISO on OT security automation, supply chain risk

In this interview with Help Net Security, Mary Rose Martinez, CISO at Marathon Petroleum, talks about what happens to security when automation reaches deep into refineries, pipelines, and terminals. She explains why the old idea of air-gapped operational technology has faded, how the Purdue model helps her team apply controls without stopping production, and where supply chain risk sits when vendors and their vendors hold the keys. She also covers cross-skilling the workforce and working … More → The post Marathon Petroleum’s CISO on OT security automation, supply chain risk appeared first on Help Net Security.
http://news.poseidon-us.com/TTk1g4

Nono: Open-source sandbox for AI agents

An AI coding agent opens a terminal, reads a config file, and finds a live cloud key sitting in plaintext. It runs with the permissions of the person who launched it. Every file that person can read, the agent reads. Every credential in the environment, the agent can use. That reach is where the damage starts. A prompt injection, a mistyped command, or a hallucinated path points that access at the company’s own credentials and … More → The post Nono: Open-source sandbox for AI agents appeared first on Help Net Security.
http://news.poseidon-us.com/TTk1fx

What the identity attack surface looks like when trust becomes the target

In this Help Net Security video, Joel Moses, VP, Strategic Engineering at F5, explains how attackers use identity instead of breaking through it. He walks through MFA fatigue, session token theft, and consent given to malicious applications, using the 2022 Uber breach as an example. He also covers how cloud and on-premises trust relationships give attackers a path between environments. Moses suggests number matching, FIDO2 keys, periodic reviews of third party application access, and watching … More → The post What the identity attack surface looks like when trust becomes the target appeared first on Help Net Security.
http://news.poseidon-us.com/TTk1fT

Product showcase: LastPass Authenticator brings Face ID, Apple Watch, and cloud backup to 2FA

LastPass Authenticator is a free app that provides two-factor authentication (2FA) for accounts and any service that supports time-based one-time passwords (TOTP). It supports push notifications for one-tap approvals and generates six-digit verification codes for online accounts. The app is available for iPhone, iPad, Apple Watch, and Android devices. Getting started Adding a new account takes only a few steps. Users can scan a QR code, import one from an image saved in Photos, or … More → The post Product showcase: LastPass Authenticator brings Face ID, Apple Watch, and cloud backup to 2FA appeared first on Help Net Security.
http://news.poseidon-us.com/TTjzww

GitHub delays version updates so malware gets caught first

An automated update tool watches a package registry, catches a new release the moment it publishes, and opens a pull request for your team. That is the job it was built to do. In September 2025, that speed cut the wrong way. An attacker phished one npm maintainer’s credentials and shipped poisoned versions of chalk, debug, and about a dozen other packages. Together those packages are downloaded more than 2 billion times a week, and … More → The post GitHub delays version updates so malware gets caught first appeared first on Help Net Security.
http://news.poseidon-us.com/TTjzwm