SC Media
20 articles
Why Short-Lived Workloads Create Long-Lived Identity Risk
Static Governance Cannot Keep Pace with Ephemeral Identities
How to Build a Data Access Governance Program
Can employees safely use AI agents? AI pentesting agent liabilities, and the news - Rob Allen - ESW #473
When an Agent Fails: Incident Response for AI-Initiated Access Events
How to Build a Data Discovery and Classification Program
How to Map Controls Across Frameworks Without Losing Meaning
Move Beyond Crosswalks to Control-Based Compliance
TrueConf flaws enabling attacks on meeting participants added to KEV catalog
The flaws have been used by the Head Mare APT hacktivist group to spread PhantomCore malware.
Secure AI agent identity in private cloud and hybrid environments
Ping Identity adds self-managed identity controls to secure and govern AI agents in regulated environments.
Navy warns of multi-pronged adversary campaign targeting personnel and installations
The campaign includes direct threats and harassment via social media, doxing, drone activity near Navy assets, ground-level surveillance, physical attacks, a...
Surveillance, Murder Hornets, Portmantau, TrueCONF, Siemens, N-Able and More - SWN #609
New Agent Tesla malware version uses emoji obfuscation to evade detection
The latest Agent Tesla campaign utilizes a JScript dropper that incorporates Unicode emoji characters to disrupt signature-based detection and obscure the ma...
Army seeks AI agents for cyber defense amid evolving threats
Project Griffin, also known as the Intelligent Response and Orchestration Node (IRON), is a pilot program designed to create an ecosystem of AI agents capabl...
Researchers find way to weaponize Windows Defender's own driver
Check Point Research disclosed a technique that uses Microsoft Defender's boot-time remediation driver, BTR.sys, to perform arbitrary kernel-level file and r...
Senator Wyden seeks review of federal law enforcement hacking tools
Wyden has formally requested the U.S.
New malware targets Android car head units for ad fraud and botnet creation
Kaspersky discovered the threat in June 2026, noting that the malware spreads through the built-in updaters of the head unit firmware.
Attackers use FTP banners to hide new E4del and PINHOLE RATs
The attack chain begins with a ZIP archive, likely distributed via phishing, which initiates an LNK-based infection.
Hospital for Sick Children discloses employee data breach due to third-party software flaw
SickKids confirmed that clinical systems and patient records were not affected, though its public-facing Careers website was temporarily taken offline.
Thousands of active AWS access keys remain publicly exposed
Truffle Security has been tracking this exposure for four years, finding that 817 of the exposed keys were linked to companies, with 526 being AWS root keys.
Microsoft patches flaw in Entra ID identity software
Microsoft fixed an exploited Entra ID flaw, but experts urge customers to check for compromise.