Zero Trust for AI Agents Starts With Fixing Zero Visibility
The way we talk about AI agents is shifting, and the way we implement them requires an even more fundamental shift.
The way we talk about AI agents is shifting, and the way we implement them requires an even more fundamental shift.
AI exposes old access problems faster, turning leaked credentials and standing trust into bigger risks.
Attackers hijacked Ukrainian websites to deliver a fake Cloudflare CAPTCHA that installs Psychedelic Stealer and steals browser and crypto credentials. Psych...
Three vulnerabilities in Salesforce Agentforce allowed hackers to hijack trusted agents, steal data, and launch phishing attacks. The post ‘SalesBleed’ Flaws...
The TrustSink attack exploits the trust Microsoft Entra places in configured external MFA providers. An attacker with a compromised privileged Entra account ...
This month's updates help you discover and control local AI agents, extend Zero Trust to agent traffic, and strengthen SOC foundations. The post What...
ClickFix has become the most common way attackers get into enterprise networks, and it does it without an exploit, an attachment, or a file on disk. Our new ...
A store in Auckland vibe-coded itself a new website. Within hours, its inventory had somehow expanded to include a pair of crusty socks, an $850 banana, and ...
Attackers are increasingly targeting the management systems used to control enterprise infrastructure, with several critical vulnerabilities actively exploit...
Cisco Duo is the best MFA for most buyers comparing on price and speed published per-user tiers, a free small-team floor, and device trust included while Mic...
The boundary between conventional conflict and cyber sabotage is narrowing as adversaries adopt artificial intelligence to industrialize deception, reconnais...
Two newly disclosed incidents involving rogue AI agents are raising questions about what happens when autonomous software operates through apparently legitim...
A third Chinese threat actor has been linked to phishing campaigns that cloned trusted websites and chained Chrome and Windows zero-day exploits to deploy a ...
Threat actors have compromised at least 65 public GitHub repositories in a software supply-chain campaign that abused npm trusted publishing to distribute a ...
In the age of AI, the new customer of intelligence is an agent. Every agent needs an intelligence layer it can trust to make good decisions and take confiden...
A Pakistan-aligned threat group, known as Transparent Tribe or APT36, has been linked to a new wave of cyberattacks targeting government and defense organiza...
CloudSEK linked GHAPPIER to a compromised npm package with valid trusted-publishing provenance
Attackers are targeting members of the Rust Project and maintainers of widely used crates (Rust code libraries), dangling attractive opportunities to comprom...
It’s unclear if the attacks are part of previous campaigns against Rust, but the techniques used by the attackers match those used by North Korea. The post R...