The CSO’s blind spot: Why platform engineering 2.0 is now a security imperative
Security leaders have spent the last decade building controls around people and code. Shift-left practices caught vulnerabilities earlier in the development ...
20 articles
Security leaders have spent the last decade building controls around people and code. Shift-left practices caught vulnerabilities earlier in the development ...
Arista has patched a VeloCloud Orchestrator (VCO) security hole that has been actively leveraged in the wild, one that the vendor says “may allow a remote at...
With AI compressing reconnaissance and exploit development from weeks to hours, security vendors are racing to help enterprises identify exposures long befor...
Every week, another enterprise technology vendor issues a glossy press release announcing their new autonomous AI agent architecture, complete with a SOC 2 T...
The recent breach of Hugging Face’s platform was the latest in a string of AI-assisted intrusions to come to light in recent weeks, showing that attackers ca...
Traveling enterprise employees beware: Think twice before you log onto that oh-so-convenient public Wi-Fi. Since at least June, threat actors have been compr...
Microsoft announced a new AI-powered service that enables enterprise security teams to continuously evaluate and update their organization’s security posture...
Now that Samsung has jumped into the crowded AI-powered glasses arena alongside Apple, Google, Meta, and others, CISOs and IT leaders are again having to thi...
Now that Samsung has jumped into the crowded AI-powered glasses arena alongside Apple, Google, Meta, and others, CISOs and IT leaders are having to think thr...
A vulnerability in Microsoft’s Active Directory Certificate Services (AD CS) could allow a low-privilege domain user to impersonate a Domain Controller, secu...
OpenAI is noticeably absent from the list of initial supporters of a new industry initiative to promote the creation of strong, safe, defensive AI cybersecur...
I have sat in on a version of the same incident post-mortem in three sectors over the past two years. The script does not vary much.
In cybersecurity, defenders sometimes naively assume that threat actors operate from secure, resilient infrastructures insulated from the very chaos they inf...
CISOs have quietly become their organizations’ de facto chief resilience officers as the role has evolved from its primary prevention roots to now include gr...
Enterprise software developers continue to be in danger of falling victim to slopsquatting, where AI coding tools hallucinate the existence of nonexistent li...
Traditional phishing techniques are in decline as a result of the disruption of the Tycoon2FA phishing-as-a-service (PHaaS) platform, Microsoft said in a new...
Cybercriminals are actively exploiting a recently discovered vulnerability in Palo Alto Networks firewall and VPN appliances to deploy the Qilin ransomware s...
A new attack method found by Zenity Labs reveals that AI agents are becoming persistent insiders that attackers can recruit, rather than malware they have to...
Check Point has confirmed that a critical security hole in its SmartConsole management tool, one that allows unauthenticated attackers to assume full admin p...
The cybersecurity landscape has evolved beyond human scale. Today’s adversaries have replaced predictable, manual playbooks with machine-generated attack cha...