Skip to main content

Author

Melissa Bischoping

Featured image for GitHub breach: What the incident really tells security teams about extension hygiene blog post
May 20, 2026

On May 20, 2026, GitHub disclosed that an employee device was compromised through a malicious VS Code extension, with attackers claiming to have exfiltrated roughly 3,800 internal repositories.

Featured image for Mini Shai-Hulud supply chain attack blog post
May 13, 2026

The Mini Shai-Hulud supply chain attack compromised more than 170 packages across npm and PyPI, including packages from TanStack, Mistral AI, and Guardrails AI, by hijacking legitimate CI/CD publishing workflows to distribute malicious versions that still carried apparently valid provenance signals.

Ranks of cute little robots in dim light.
May 11, 2026

As AI agents multiply at machine speed across the enterprise, governance must evolve to match their autonomy, scale, and risk.

Featured blog image for Understanding shadow AI in your endpoint environment
Apr 14, 2026

Learn how shadow AI appears on endpoints, from local models to MCP servers, and why visibility, governance, and secure configuration matter now.

Tanium Guardian Spotlight - IDE Extensions
Jan 12, 2026

User-installable extensions for Visual Studio Code, Cursor, and other Integrated Development Environments are an increasingly exploited attack vector, with new malicious extensions discovered almost weekly. Do you have visibility and control?

A photo of the head and shoulders of a knight in silver armor with a helmet bearing thin slits over the eyes.
Jan 26, 2024

As hackers get more sophisticated and software more complex, CISOs must improve their ability to identify, isolate, and mitigate malicious software attacks.

Featured image: Develop a Cybersecurity Action Plan: Understanding IT Risk Management
Apr 21, 2022

Part two in this series on how to create and deploy an action plan that strengthens your organization’s cyber defenses.

Develop a Cybersecurity Action Plan: Focusing on Visibility and Breaking Down Silos
Apr 13, 2022

A cybersecurity action plan that prioritizes visibility and breaks down IT silos is essential for protecting your organization.

Endpoint hardening and preparedness in a changing threat landscape
Mar 8, 2022

With the conflict between Russia and Ukraine impacting the cyber threat landscape, organizations must close any gaps in patching workflows.

Best Practices for Responding to the Log4j Vulnerability and Preparing for the Next
Jan 19, 2022

Learn how to respond to the Log4j vulnerability and prepare for the future with tools for detecting vulnerable software components.