How a global investment firm reduced security surprises
Most security teams don’t suffer from a lack of data. They suffer from a lack of certainty.
20 articles
Most security teams don’t suffer from a lack of data. They suffer from a lack of certainty.
Meta has become the third frontier AI developer in recent weeks to disclose a security incident involving one of its advanced AI models during cyber capabili...
Meta has become the third frontier AI developer in recent weeks to disclose a security incident involving one of its advanced AI models during cyber capabili...
The updated Cybersecurity Maturity Model Certification (CMMC) represents a critical evolution in the Department of War (DoW) strategy to secure the Defense I...
For decades, cybersecurity has been built around one assumption: defenders had enough time to: Discover vulnerabilities. Assess exposure.
AI is accelerating vulnerability discovery, exploit development, and attacker weaponization faster than most organizations can adapt. Security teams are inun...
Cybersecurity is full of frameworks, regulations, and directives that tell organizations what they should do. Zero Trust, NIST, CIS Controls, CMMC, DORA, NIS...
After more than 300,000 production penetration tests (pentests), our company has learned something that may surprise people watching the recent wave of auton...
Huntress has documented a case where the Oracle database itself became the malware host. The security firm disclosed a campaign in which threat actors exploi...
Most organizations assume remediation reduces risk. It’s a reasonable assumption.
Shortly after OpenAI publicly acknowledged the Hugging Face breach on July 21, Reuters journalist Raphael Satter called me for comment on a story which would...
When I first started working on enterprise AI security initiatives, I expected the biggest challenges to be technical. I assumed we’d spend most of our time ...
More evidence is emerging about how AI is becoming part of the day-to-day workflow for cybercriminals, from building and refining tools to managing infrastru...
Given the widespread enterprise adoption of passkeys to replace passwords, a Palo Alto Networks Unit 42 report disclosing ways attackers are getting around p...
Given the widespread enterprise adoption of passkeys to replace passwords, a Palo Alto Networks Unit 42 report disclosing ways attackers are getting around p...
Modern attacks increasingly begin with the web application. Customer portals, partner platforms, APIs, external business applications, and AI-powered service...
For years organizations have strengthened their security posture by investing in specialized tools for applications, identities, endpoints, networks, and clo...
Security researchers are warning against trust assumptions in AI security with newly detailed flaws affecting the open-source AI agent platform Paperclip tha...
OpenAI’s GPT-5.6 Sol and Anthropic’s Mythos 5 have been implicated in another series of AI security incidents after the models created fake online identities...
I was mapping the command-and-control infrastructure behind a state-linked intrusion set when the query came back and effectively ended the exercise I though...