🇳🇴 TNN has signed an MOU with iQ Global — bringing structured abuse reporting to a platform already doing serious work in DNS security. iQ Global is an Oslo-based domain security and intelligence company whose product suite helps registries and registrars detect, manage, and resolve abuse at scale. We're talking 200 million scans per day, 3 million active abuse reports, and tools built for the people handling DNS abuse day to day. What this MOU adds is structure around the reporting relationship itself. Operational capacity matters — but so does having a clear, accountable framework for how abuse reports flow between Trusted Notifiers and Internet intermediaries. That's what TNN brings to the table. The more of the ecosystem that operates on shared standards, the harder it becomes for abuse to find a quiet corner to sit in. If your organisation works in domain security and wants to explore what structured abuse reporting looks like in practice, let's talk. #DNSAbuse #TrustedNotifier #InternetGovernance #TNN #iQGlobal
TNN Partners with iQ Global for Structured Abuse Reporting
More Relevant Posts
-
Welcome to Sigimora v0.2.0 The BFT Network for Accountable Threshold Signatures (ATS)Sigimora is a Byzantine Fault Tolerant (BFT) network purpose-built to solve a critical dilemma in enterprise multi-party authorization: the trade-off between signer privacy and regulatory accountability. Traditional multi-signature schemes compromise privacy by revealing exactly who signed a transaction. Conversely, standard threshold signatures hide individual identities entirely, making internal auditing and compliance impossible.Sigimora bridges this gap. Powered by cutting-edge cryptographic primitives implemented entirely in Rust, Sigimora allows a decentralized group of $n$ organizations to collectively authorize transactions via BLS12-381 threshold signatures. While the public sees only a single, compact group signature, a designated tracking key holder retains the unique ability to cryptographically trace and identify the exact participants behind any given signature. https://lnkd.in/dNHWHvNG
To view or add a comment, sign in
-
For the second consecutive year, Kite has been independently attested as SOC 2 Type II compliant, in accordance with AICPA standards (SSAE 18) for SOC for Service Organizations. Renewing this certification year over year is what we believe security should look like: not a one-time milestone, but a continuous standard that holds up across every observation window. The third-party audit validates the security, availability, and confidentiality controls we have built into the Kite platform, and confirms they have operated effectively throughout the full audit period. Trust is the foundation of the agent economy. Every autonomous Agent we power touches data, identities, and transactions on behalf of users, and that bar has to be set externally, not just internally. To our users and partners: this is the standard you should be able to expect from any infrastructure powering autonomous agents, and we will continue to hold ourselves to it. Thank you to Prescient Security for the audit.
To view or add a comment, sign in
-
-
Much of security analysis still begins with the question, “Is this event malicious?” That framing keeps teams locked in indicator-level reasoning. A more effective approach asks, “What is this behavior trying to achieve?” This shift from indicators to intent, and from isolated events to progression and objectives, marks the next defensive inflection point. It is how organizations move from alerting to understanding adversary logic. Post-quantum cryptography migration faces the same limitation today. Most PQC scanners still operate at the indicator level. RSA‑2048 appears. Flag it. ECDSA appears. Flag it. That approach mirrors signature-based EDR and misses the actual risk. Exposure depends on what the cryptographic behavior is designed to protect, where it sits in a dependency chain, how long the data must remain confidential, and the harvest‑now‑decrypt‑later profile of the system. With NIST FIPS 203, 204, and 205 finalized and a 2030 federal mandate for National Security Systems in place, PQC migration is no longer theoretical. Inventory, assessment, and migration sequencing are now operational requirements. This is the case being made at Secure360. Understanding adversary logic is the next defensive inflection point, and PQC migration is the cryptographic instantiation of that same shift. ArcQubit is positioned at both layers. At the behavioral layer, grounded in real CISO experience. At the cryptographic logic layer, through QuantumDrift. QuantumDrift sits above CBOM tools, SAST scanners, and certificate managers. It interprets what cryptographic implementations are trying to achieve, where they align with NIST PQC standards, and how they fit into a defensible migration sequence. That is why QuantumDrift is a decision intelligence platform. How is your organization evaluating cryptographic risk today? #Sec360 #ArcQubit #PQC #HNDL #QuantumDrift
To view or add a comment, sign in
-
-
RSA-2048 is not protection. It is a timestamp on your data’s usable life. Most organizations track certificates, not timelines. Harvest Now, Decrypt Later turns today’s encrypted traffic into a ten-year liability tied directly to the lifespan of regulated data. The failure is observational. Cryptography is treated as static configuration while algorithms decay and data retains value long after its defensive half-life has passed. ArcQubit fixes observation first. A 10-second browser-based scan replaces point-in-time assessments and exposes what is actually deployed, right now, before infrastructure debt compounds.
To view or add a comment, sign in
-
-
This week in Dallas, I sat down with the teams from Cytactic, Crush Security, and Halcyon for a live CIRM simulation that hit closer to home than most tabletops ever do. The scenario: a regional healthcare system, compromised through third-party software. Patient data exposed. Clinical systems degraded. The clock running. The kind of incident that's stopped being hypothetical. What made this exercise different wasn't the chaos. It was watching how fast the picture sharpened when the right intelligence showed up at the right time. SecurityScorecard contributed Titan Secure intelligence to the simulation, and the moment the third-party vector surfaced, the room had answers it would have spent days chasing in a manual response: Which vendors share the same exposure. Which assets are reachable from the outside. Which threat actors are actively working that path. That's the difference between "we have a vendor list" and "we have a response plan." A few takeaways from the night: Third-party incidents don't respect your org chart. Legal, comms, IR, and the business are all in the room from minute one. Run your tabletops the same way. Inside-out attestation is not a substitute for outside-in evidence. Your vendor's last SOC 2 won't tell you they got popped yesterday. The hardest part of CIRM isn't the technical response. It's the decisions. Who do we notify, when, and with what we actually know versus what we're guessing. The teams that win these scenarios aren't the ones with the most tools. They're the ones who practiced together before the day it mattered. Big thanks to Cytactic for pulling this together, and to Crush Security and Halcyon for being in the trenches with us. This is the kind of collaboration the industry needs more of. Thanks to Nimrod Kozlovski, the great Tim Brown, and David Hannigan for partnering with me in the simulation! And thanks to Larry Slusser for getting us all organized and clicking the buttons! If you haven't run a third-party breach scenario in the last 12 months, that's your next sprint. #CyberResilience #TPRM #IncidentResponse #ThreatIntelligence #SecurityScorecard
To view or add a comment, sign in
-
-
SIEMs are a $6B market built on a primitive that cannot prove anything. Post-quantum signed attestation can. This changes what "evidence" means for every regulated security operation. In H33-Alina episode 14, Alina walks through why log-based SIEM stacks fail at the question they were built to answer ("what actually happened?") and what H33 Replay does instead. The SIEM problem in three sentences: • Logs are emitter-asserted, mutable after the fact, and unverifiable by an independent third party. • Incident reconstruction is forensic narrative, not deterministic replay. • Long-horizon audit fails the moment a regulator asks "prove this log was real at the time it was written." The H33 Replay answer: • Every operationally-meaningful event is post-quantum-signed at production time, anchored to the H33-74 substrate, and independently verifiable forever after. reconstruct what the system knew at the moment of any decision — without trusting H33, without trusting your SOC, without trusting your application logs. Verification is public. Computation proprietary. The verifier is open source: https://lnkd.in/ejBjdm-V The shift is from "trust me, here are the logs" to "here is independently verifiable cryptographic evidence." That property does not exist in any log-based SIEM, and it is what regulators are increasingly going to require for the post-quantum decade.
To view or add a comment, sign in
-
The NSA just compressed more than a thousand pages of Zero Trust guidance into an interactive implementation resource. The principles are sound and battle tested. The harder question for a bank is what happens when the identity on the other side of the policy is an autonomous agent. Zero Trust was written for humans and static services. An agent interprets goals, chains tools, delegates to other agents, and keeps context across sessions. The doctrine still holds. The implementation has to be rebuilt around it. Here is how the NSA pillars translate into agent controls a regulated institution can actually deploy: 1. Identity. Every agent receives a unique cryptographic identity, not a shared service account. Each action it takes must trace back to that exact instance, the same way a trader's every order traces to a named individual. 2. Credentials. Static API keys embedded in code no longer meet the bar. Tokens are short lived, scoped to a single task, and expire unless live telemetry proves the agent is still inside its guardrails. 3. Least privilege becomes least agency. Access defines what the agent can reach. Agency defines what it is permitted to do once inside, under which conditions, and with what oversight. The second control is the one most programmes are missing. 4. Assume breach. A high privilege orchestrator that delegates to worker agents without scoping passes its full access downstream. Privilege has to be re scoped at every hop, never inherited wholesale. 5. Monitoring at machine speed. Manual triage cannot keep pace with an agent that deviates in milliseconds. A model belongs at the front of the alert queue, and when an agent drifts beyond its authorised capability the infrastructure severs access automatically. Humans retain authority over containment and disclosure. The institutions that read this guidance as a foundation rather than a finished answer will be the ones still standing when their first agent is compromised. Access is earned. Actions are constrained. Agency is governed by design. NSA resource: https://lnkd.in/d65gc2wR #CISO #ZeroTrust #AgenticAI #NonHumanIdentities #OperationalResilience #CyberSecurity
To view or add a comment, sign in
-
Government portals have authentication built in. Under the EU eEvidence regulation, orders will arrive via systems such as e-CODEX, each with its own security mechanisms. Most organizations will treat that authentication as sufficient. But the compromise history of government systems suggests otherwise. Under the new regulation, each workflow and API connection includes additional verification checks that use agent-specific data and other signals to independently validate the authenticity of requests beyond the portal. Portal authentication is the starting point. The verification layer on top of it is what accounts for how government systems actually behave, not just how they are designed to behave. With enforcement beginning on August 18, that distinction is where the compliance risk lies. Stay ahead of the conversation: https://bit.ly/4u0cSqU
To view or add a comment, sign in
-
You wouldn’t hand over your car keys without a second thought or give your credit card to anyone who asks, so why would you allow overly broad permissions at work? In the modern enterprise, giving someone a little too much power or granting access to those who don’t need it creates a world of chaos. Today, identity has become the primary attack vector because adversaries no longer break in — they simply log in using pervasive, uncontrolled privileges. Idira™, by Palo Alto Networks, is the next-generation identity security platform built to secure every human, machine and agentic identity for the AI enterprise. By replacing static, always-on access with dynamic, zero standing privilege controls, Idira helps you discover hidden risks and automate governance at machine speed. It’s time to control the chaos and secure every identity. Learn more: paloaltonetworks.com/idira This video depicts AI-generated dramatizations. Do not attempt. https://lnkd.in/dSDkJZAS
Secure Every Identity with Idira by Palo Alto Networks
https://www.youtube.com/
To view or add a comment, sign in