In a recent security assessment, we were unable to intercept the traffic originating from a WebView from an Android application. The application wasn't using certificate pinning, nor was it configured in any special way that would prevent normal interception. When testing that same application on a different device, the traffic could be intercepted directly, confirming … Continue reading Intercepting Android WebView traffic under new certificate validity requirement by Chromium
Category: Prevent
Reducing Microsoft Sentinel Costs Without Compromising Detection – Part 2: The Firewall Quest
Firewall network traffic logs are the largest driver of Microsoft Sentinel ingestion costs. Yet they remain a critical source of information for threat detection, investigations & incident response. Explore how Sentinel Summary Rules can reduce the cost of ingesting firewall traffic events while retaining the visibility SecOp teams need to detect threats & investigate incidents.
The Road to Post-Quantum Readiness Part 2 of 2: The Migration Playbook
Post-Quantum Cryptography is no longer just about understanding the threat. The real challenge now is migration: deciding where to start, how to reduce risk early, and why waiting for vendors is not a strategy. Part 2 outlines a practical, risk-driven playbook to help organizations take ownership of their quantum-readiness journey and turn urgency into action.
The Road to Post-Quantum Readiness Part 1 of 2: Understanding the Risk
Post-Quantum Cryptography is no longer a future-only concern. Standards are final, major providers have already deployed hybrid protection, and the real risk now is data captured today and decrypted later. Part 1 explains the fundamentals, the threat, and why organizations can no longer afford to wait.
Reducing Microsoft Sentinel Costs Without Compromising Detection – Part 1: The Summary Rules Quest
This blog is the first in a series exploring how Summary Rules, together with Auxiliary or Data Lake storage, can help organizations optimize SIEM costs without compromising core threat detection and monitoring capabilities.
Securing AI systems without overconfidence or fear – Part 2: Attack surfaces and the checkpoint flow
Part 1 explained how we have to bound behavior instead of asserting exact outputs. This post maps where to place those boundaries. AI systems expose attack surfaces at three runtime checkpoints (i.e., input, processing and output) and the checks differ by system type (classical ML, LLM-based, or hybrid).






