APOLLOSEC

Savount

Research and analysis on cyber conflict, artificial intelligence and the powers behind them, from APOLLOSEC.

The magazine
AI

Securing New Agentic Workers

A practical hardening guide for desktop AI agents: sandboxing, allow-lists, secrets, logging, and keeping work and personal contexts apart.

APOLLOSEC research  ·   ·  8 minute read

Latest

AI

AI agents are powerful. Are they secure?

Securing agentic AI before it becomes your biggest attack surface: prompt injection, memory poisoning, tool misuse and the defences that work.

· 6 minute read
Geopolitics

Lessons From Recent Cyberattacks

M&S, Co-op and Harrods, Cartier and Coinbase: what recent attacks have in common, the techniques used, and what defenders should take from them.

· 13 minute read
Cyber

How to Secure Your DevOps Pipeline: Risks, Tools, and Best Practices

The risks in modern CI/CD pipelines, the tools that help, and the practices that keep secrets, dependencies and build systems away from attackers.

· 7 minute read
Cyber

Replacing Annual Penetration Testing with Continuous Pen Testing

Why a yearly penetration test describes a system that no longer exists, and how continuous penetration testing closes the gap.

· 9 minute read
Field notes

Emulating the Enemy – How Adversary Emulation is Elevating Offensive Security

How adversary emulation moved offensive security beyond the annual penetration test, and how to use real attacker behaviour to test your defences.

· 12 minute read
Threat actors

Lessons from Hellcat’s Jira breaches

No zero-days and no novel malware: how the Hellcat crew breached enterprise Jira with stolen credentials, and the identity defences that stop it.

· 5 minute read
Cyber

Critical Vulnerabilities Keep Coming: The Urgency of Proactive Security

The gap between disclosure and exploitation keeps shrinking. Why critical vulnerabilities demand continuous, proactive security, not a yearly test.

· 12 minute read
Cyber

The Costly Reality of Cybersecurity Gaps for SMBs

What security gaps really cost small and mid-sized businesses, from breaches and downtime to ransomware and fines, and how to build resilience on a budget.

· 10 minute read
Cyber

From Perimeter to Identity: The New SaaS Attack Frontier

Single sign-on, session tokens and MFA fatigue: why identity is now the main attack surface for SaaS, and how to defend it.

· 8 minute read
Threat actors

Threat Actors TTPs You Need to Watch in 2025

Five attacker techniques to watch: non-human identity attacks, pass-the-hash, supply chain compromise, Golden SAML and stolen remote access credentials.

· 5 minute read
Geopolitics

Navigating Supply Chain Risks

Why a supplier’s weakness becomes yours: lessons from SolarWinds, Log4Shell and Okta, and how to protect your organisation from supply chain attacks.

· 5 minute read
Geopolitics

Preparing for the Digital Operational Resilience Act (DORA): How Financial Services Can Comply with New EU IT Resilience Legislation

Who the EU Digital Operational Resilience Act applies to, what it asks of financial services firms, and how to prepare for it.

· 3 minute read
Cyber

Cyber Breach Survey Insight: The Need to Know for UK Businesses and Charities

Key findings from the UK Cyber Security Breaches Survey 2024: what breaches cost, why phishing leads, and where boards stand on cyber risk.

· 5 minute read
Cyber

Enhancing Cloud Security: A Multi-Layered Approach

How attackers exploit cloud storage, web applications and deployments, and a layered approach to securing them, from zero trust to data security.

· 5 minute read
Field notes

Living on the Edge: An Adversary Playground

A walk through an engagement: how edge devices, leaked cloud keys and an open Trello board gave an attacker a path in, one step at a time.

· 6 minute read
Cyber

The Essential Guide to Penetration Testing for SMBs

What penetration testing is, why small and mid-sized businesses are targeted, what testing gives you, and how often to do it.

· 3 minute read
Cyber

Offense is The Best Form of Defense

Why thinking like an attacker is the most effective way to defend, and the case for offensive security over checkbox compliance.

· 2 minute read
Cyber

The 2024 Cyber Landscape: Insights and Strategies

The 2024 threat landscape in brief: the attack trends that shaped the year and the strategies organisations can use to respond.

· 3 minute read
Cyber

The Key to Robust IT Security

The basics that stop most attacks: least privilege, password hygiene, patching, email controls and training, and why regular testing matters.

· 3 minute read
Cyber

SBOMs: Essential for Modern Software Security

What a software bill of materials is, why transparency in software matters, and how SBOMs help secure the software supply chain.

· 2 minute read

The magazine

A quarterly collection of the best research, interviews and field notes, written to be read at length. Join the list to receive the first issue.

We will only email you about Savount. Unsubscribe at any time. Privacy.