Growing PQC at the edge belies deeper quantum-readiness challenges
The quantum threat is becoming an increasing concern for security leaders, but many may be mistaking protection at their website’s front door for quantum rea...
20 articles
The quantum threat is becoming an increasing concern for security leaders, but many may be mistaking protection at their website’s front door for quantum rea...
Throughout this year, Amazon Web Services (AWS) has repeatedly had to patch autonomous agent security holes, which have then reemerged in slightly different ...
Details from an FBI investigation into the ongoing FortiBleed attacks reveal that victims could be locked out of their own firewall even as attackers remain ...
Amazon Web Services (AWS) has introduced an open-source sandbox for AI agents that allows developers to restrict their actions based on previous behavior, se...
I timed an attacker once. From registering a domain to having it delegated, certificated and serving a live credential-harvesting page took under 24 minutes,...
SonicWall has disclosed yet another critical flaw in one of its core products. CVE-2026-102255, rated 10 in severity, the highest possible on the Common Vuln...
Anthropic is expanding its Cyber Verification Program to give more security teams access to advanced cyber capabilities with reduced safeguards on its most a...
Denmark is reviewing security controls around its national citizen registry after unauthorized parties exploited a company’s access credentials to harvest re...
GitHub Copilot CLI can be made to read sensitive files from a developer’s machine and send their contents to an attacker from a single web page. Security res...
In infrastructure and security programs, I have watched visibility projects follow a familiar path. The first dashboard feels like progress.
The rise of AI has CISOs facing even more vulnerabilities than ever, resulting in increasingly difficult decisions around what fixes to prioritize. “When I w...
A newly-disclosed critical flaw in Atlassian’s data center software has a remarkably wide reach, affecting eight core products across the company’s enterpris...
The US Federal Bureau of Investigation has removed an Accenture contractor working on its PeopleSoft installation over their role in a data breach that expos...
A new Linux backdoor is turning vulnerable internet-facing devices into remotely controlled proxy nodes, while using the public Session Traversal Utilities f...
When Anthropic CEO Dario Amodei urged other leading AI labs to “pace the frontier” last week, his calls for caution were echoed by other prominent voices in ...
AI is accelerating the discovery of software vulnerabilities, but it is also creating a new bottleneck for defenders: deciding which machine-generated findin...
The fastest-growing category of enterprise software right now is also the least scrutinized from a security standpoint. AI application platforms — tools that...
Gartner recently released a new category of security tools: the Integrated Security Operations Center (ISOC). This new category acknowledges the need to expa...
Attackers are increasingly weaponizing already-disclosed flaws rather than new zero-days, and AI tools may be accelerating how quickly they do it. According ...
Dell’s security team has had a busy week. The company has announced a slew of Common Vulnerabilities and Exposures (CVEs) impacting its Dell Container Storag...