access ai android api apple attack authentication backdoor breach business ceo china cisa cisco ciso cloud compliance control credentials crypto cve cyber cyberattack cybercrime cybersecurity data data-breach defense detection email endpoint exploit finance flaw framework fraud google governance government group hacker hacking healthcare identity infrastructure intelligence Internet jobs law leak linux malicious malware microsoft monitoring network open-source password phishing privacy ransomware remote-code-execution resilience risk russia scam service software strategy supply-chain technology theft threat tool unclassified update usa vulnerability windows zero-day
-
Why Vulnerability Management Must Move Beyond CVSS
Learn why vulnerability management must move beyond CVSS to prioritize real risk using exploitability, asset context, attack paths, and AI-driven analysis. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-why-vulnerability-management-moves-past-cvss/ also interesting: How Top CISOs Approach Exposure Management in the Context of Managing Cyber Risk How to Take Vulnerability Management to the Next Level and Supercharge…
-
Microsoft Finds ASCII Smuggling Repurposed for Phishing Campaign
Attackers have adapted a technique popularized in AI prompt injection research for a high-volume phishing campaign, using invisible Unicode characters to evade email filtering, Microsoft researchers reported Thursday. The finding came from Microsoft Defender for Office 365 prompt injection protection research. A hunting signature built to detect ASCII smuggling in email recorded a surge beginning..…
-
Cyber Resilience Starts With a Unified Recovery Strategy
Learn why cyber resilience requires a unified recovery strategy that restores data, configurations, identities, cloud systems, and critical dependencies. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-cyber-resilience-strategy/ also interesting: Cybersecurity Snapshot: CSA Outlines Data Security Challenges and Best Practices, While ISACA Offers Tips To Retain IT Pros Improve Your Cyber Resilience with Data Security Platformization…
-
How Recent Cyber Earnings Show Growth Alone No Longer Pays
Faster Hiring Coincided With Weaker Stock Performance Across Most Security Vendors Seven of eight major cyber and technology vendors posted at least 25% annual year-over-year sales growth, but five stocks fell after earnings as investors favored profitability while CEOs outlined how AI agents will reshape security, identity and enterprise infrastructure. First seen on govinfosecurity.com Jump…
-
OpenAI’s German Wiki Hack Is Less About “Rogue AI” Than Failed Agent Containment
OpenAI’s latest foul-up was not a Hollywood-style AI “escape.” Instead, researchers say a swarm of OpenAI agents apparently found a way to turn web read access into write access on DseWiki, a collaboratively editable German programming wiki. The takeover of a German programming wiki, DseWiki, by agents linked to OpenAI is not evidence that AI..…
-
Insurers Search for Answers to Rein in Rogue AI
As incidents of unintended harm caused by rogue AI agents mount, CISOs and insurance firms are figuring out how to handle the fallout. First seen on darkreading.com Jump to article: www.darkreading.com/cyber-risk/insurers-search-answers-rogue-ai also interesting: Top challenges holding back CISOs’ agendas 10 things you should include in your AI policy CISO vs CFO: why are the conversations…
-
Why ‘Digital Asbestos’ Is Driving Up Risk Debt
Financial Services Risk Advisor Alex Golbin on Spotting Hidden Risk Debt. Alex Golbin, a senior financial services technology and data risk executive, said risk programs can look modern while resting on legacy workarounds underneath. He said accountability for that hidden risk debt, or digital asbestos, often falls on no one in the enterprise. First seen…
-
Europe Tiptoes to Legalizing Bulk Collection of ISP Metadata
CJEU Advocate-General Maciej Szpunar Says Oversight Could Mitigate Rights Harms. The most senior adviser at Europe’s highest court recommended striking down a Belgian data retention law largely intended to fight cybercrime, because it violates privacy rights. Advocate-general Maciej Szpunar also said it may be time for the EU to move past its old conception of…
-
AI Labs Pause Frontier Model Work, But to What Effect?
OpenAI and Anthropic Tighten Guardrails as Experts Question Whether Brief Pauses Are Enough. There’s been a renewed focus on the safety and security processes of frontier AI labs after mainstays spotted their agents escaping sandboxes to hack into real-life targets. The result of these pauses is not vetted by an independent party, so it is…
-
OpenAI agents discussed ways to escape their sandbox on public wiki
Tags: openaiIn all, 3,700 internal agents posted 18,000 messages discussing cheating on a test. First seen on arstechnica.com Jump to article: arstechnica.com/security/2026/09/openai-agents-discussed-ways-to-escape-their-sandbox-on-public-wiki/ also interesting: SweetSpecter hatte OpenAI im Visier OpenAI says there are 5 ‘levels’ for AI to reach human intelligence, it’s already almost at level 2 OpenAI, Anthropic to give model access to NIST’s AI…
-
European parliament members call for slowdown of Serbia’s EU entry over spyware use
Tags: spywareThe letter follows revelations about Serbian student activists being infected with Pegasus and NoviSpy, and coincides with other pressures on Belgrade. First seen on cyberscoop.com Jump to article: cyberscoop.com/eu-parliament-serbia-accession-spyware-demands/ also interesting: Apple warns of mercenary spyware attacks on iPhone users in 92 countries NSO-Group für WhatsApp-Angriff mit Pegasus-Spyware schuldig gesprochen NSO Group owes $168M in…
-
CVE-2026-19949 Leaves Millions of WordPress Sites Running Vulnerable Plugin Versions
A high-severity flaw in All-in-One WP Migration leaves 3.25 million WordPress sites exposed, with vulnerable versions potentially leading to site compromise. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-all-in-one-wp-migration-cve-2026-19949/ also interesting: 200,000 WordPress Sites Exposed to Cyber Attack, Following Plugin Vulnerability Over 100,000 WordPress Sites Exposed to Privilege Escalation via MCP AI Engine 70,000 WordPress…
-
Dropbox Says Lenovo ID Flaw Compromised 5,000 Accounts
Tags: flawA Lenovo ID verification flaw let attackers compromise 5,000 Dropbox accounts without passwords. Learn what happened and how users can stay protected. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-dropbox-lenovo-id-flaw-5000-accounts/ also interesting: Palo Alto Networks Patches Authentication Bypass Exploit in PAN-OS Software Hackers Exploit Craft CMS Vulnerability to Inject Cryptocurrency Miner Malware Critical Vulnerability in…
-
Google’s Chrome Update Patches Sixth Zero-Day Exploited in 2026
Google patched CVE-2026-85046, the sixth Chrome zero-day exploited in the wild in 2026. Here’s how to update your browser and stay protected. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-google-chrome-cve-2026-85046-zero-day/ also interesting: Google Releases Eighth Zero-Day Patch of 2023 for Chrome Google Patches Chrome Zero-Day: Type Confusion in V8 JavaScript Google Patches Critical Zero-Day Flaw…
-
Why Security Teams are Becoming Builders of Agentic AI, not just Buyers
Security teams are building custom AI agents to improve defense, close tooling gaps, and automate workflows, but strong governance remains critical. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-agentic-ai-buyers-and-builders/ also interesting: Security for AI: How Shadow AI, Platform Risks, and Data Leakage Leave Your Organization Exposed CTO New Year’s Resolutions for a More Secure 2026…
-
Attack Surface Reduction Is the Only Scalable Defense Strategy Left
Learn how attack surface reduction helps organizations eliminate unnecessary exposure, reduce security noise, and strengthen defenses through automation. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-attack-surface-reduction-scalable-defense/ also interesting: Reimagining Incident Response: Unleashing Proactive Defense with Nuspire’s Cybersecurity Experience Building an Effective DDoS Mitigation Strategy That Works 6 strategies for building a high-performance cybersecurity team Bolster…
-
Hospitals Lag in Race to Quantum-Safe Encryption
Security Leaders Say Legacy Devices and Vendor Dependence Are in the Way. Hospital security leaders say aging medical devices, incomplete asset inventories and dependence on third-party vendors could make healthcare’s transition to post-quantum cryptography slower and more difficult than in other critical sectors. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/hospitals-lag-in-race-to-quantum-safe-encryption-a-32752 also interesting: 8 Cyber…
-
Digital twins bill to be debated in Parliament
Tags: unclassifiedA Ten-Minute Rule Bill curbing the creation of digital twins of individual people is to be debated in Parliament. First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366650120/Digital-twins-bill-to-be-debated-in-Parliament also interesting: Forrester: Webentwickler vernachlässigen Sicherheit Lascher Umgang mit Datenträgern: Erhebliche Sicherheitslücken beim FBI aufgedeckt Massive Störung: E-Rezepte waren zeitweise nicht einlösbar Will Smaller Companies Buckle Under the…
-
Digital twins bill to be debated in Parliament
Tags: unclassifiedA Ten-Minute Rule Bill curbing the creation of digital twins of individual people is to be debated in Parliament. First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366650120/Digital-twins-bill-to-be-debated-in-Parliament also interesting: How Dark Patterns Trick Users into Unintended Actions? Asus VivoTab RT: Das Tablet, das ein Notebook ist… Check Point sieht Konsolidierung als Erfolgsschlüssel für robuste Cyberabwehr…
-
White House Acts to Shut Out China From US Bulk Power Market
Trump Executive Order Declares National Emergency, Citing Potential Backdoors. A broad Trump administration plan to shut adversary nations, including China, out of the equipment supply chain for the U.S. bulk electric power market has left the industry in regulatory uncertainty, just as demand for electricity is spiking nationwide due the ballooning power demands of data…
-
White House Acts to Shut Out China From US Bulk Power Market
Trump Executive Order Declares National Emergency, Citing Potential Backdoors. A broad Trump administration plan to shut adversary nations, including China, out of the equipment supply chain for the U.S. bulk electric power market has left the industry in regulatory uncertainty, just as demand for electricity is spiking nationwide due the ballooning power demands of data…
-
White House Acts to Shut Out China From US Bulk Power Market
Trump Executive Order Declares National Emergency, Citing Potential Backdoors. A broad Trump administration plan to shut adversary nations, including China, out of the equipment supply chain for the U.S. bulk electric power market has left the industry in regulatory uncertainty, just as demand for electricity is spiking nationwide due the ballooning power demands of data…
-
Crooks Behind Manchester Airports Group Hack Leaked Data of 8.8 Million People
Manchester Airports Group (MAG) data allegedly leaked by FulcrumSec exposes emails and phone numbers of 8.8 million people. Manchester Airports Group, which operates Manchester, London Stansted and East Midlands airports, has confirmed a data breach involving customer information held in a third-party database. The company says airport operations, passenger safety and aviation security were not…
-
US offers $10 million for info on Iranian allegedly behind cyberattacks on critical infrastructure
Amir Yaryab is the leader of the IRGC’s cyber unit and oversees hacker groups such as the CyberAv3ngers, the State Department said in posting a reward for information about him. First seen on therecord.media Jump to article: therecord.media/us-reward-amir-yaryab-iran-irgc-cyberattacks also interesting: Iranian cyber threats overhyped, but CISOs can’t afford to let down their guard Iranian APT…
-
Security Operations To See A ‘Renaissance’ In Next 24 Months: Cyderes CEO
Security operations is poised to see an “absolute renaissance” over the next two years, with AI and agentic capabilities eliminating much of the repetitive work facing security analysts”, while also potentially leading to a surge in threat actor activity that must be protected against, Cyderes CEO Chris Schueler tells CRN. First seen on crn.com Jump…
-
How Keeper Helps Enforce Zero Standing Privilege
Privileged accounts are standing invitations for attackers, with credentials to steal and permissions to misuse. When administrative rights are persistently active, whether or not they’re being used, privileged accounts significantly expand the attack surface. Zero Standing Privilege (ZSP) shrinks that… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/how-keeper-helps-enforce-zero-standing-privilege/ also interesting: 7 biggest cybersecurity stories of…
-
Why Hiring More Analysts Won’t Solve an Infinite Automation Attack
Conventional wisdom states that if the alert queue is too long, you just need to hire more Tier-1 analysts to clear the backlog. It’s a comforting thought, suggesting that with a slightly larger budget and a few more resumes, an… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/why-hiring-more-analysts-wont-solve-an-infinite-automation-attack/ also interesting: How to Chart an Exposure…
-
Dissecting Attacks Is Only Valuable If It Informs Controls: What the Unit 42 agentic AI investigation should change in your control set, stage by stage.
The volume of published incident research involving agentic AI is increasing, and the analysis that follows each report tends to concentrate on the same attribute: speed. The recent investigation from Unit 42, the threat intelligence and incident response group at… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/dissecting-attacks-is-only-valuable-if-it-informs-controls-what-the-unit-42-agentic-ai-investigation-should-change-in-your-control-set-stage-by-stage/ also interesting: Threat-informed defense for operational technology:…
-
The Braid: Rethinking Trust, Continuity and Human-AI Systems
What one AI-generated image taught me about trust, continuity, and why I am building QuietWire. There is a problem with AI logos. A good friend in the cybersecurity industry pointed it out to me last year, and once he did I could not unsee it. Since then I have watched the observation turn into something..…
-
How Differential Privacy Will Transform Enterprise Data Strategy
For sixteen years I’ve watched enterprise data privacy evolve through three eras: access controls and encryption at rest, then de-identification, and now a third era defined by a mathematical framework most executives have heard of but few truly understand: differential privacy. The shift matters because the previous eras have quietly failed. De-identified datasets have been..…
-
How Differential Privacy Will Transform Enterprise Data Strategy
For sixteen years I’ve watched enterprise data privacy evolve through three eras: access controls and encryption at rest, then de-identification, and now a third era defined by a mathematical framework most executives have heard of but few truly understand: differential privacy. The shift matters because the previous eras have quietly failed. De-identified datasets have been..…
-
153 Million Reasons to Rethink Identity Data Retention
An ID verification company is suspected of being responsible for a data breach involving 153 million identity cards that were put up for sale to criminals! The cache includes drivers licenses, travel documents, medical cards, and other government issued IDs… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/153-million-reasons-to-rethink-identity-data-retention/ also interesting: Rhode Island suffers major cyberattack,…
-
What the AI Warning Letter Completely Missed
Tags: aiThe recent AI warning letter is right about the window, but it omits naming who is coming through it or, critically, who will close it. First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/ai-warning-letter-missed-people also interesting: Amazon, Google, Microsoft, Other Tech Firms, Form Consortium for Improved AI Cybersecurity From Deepfakes to Malware: AI’s Expanding Role in…
-
Companies Have 6 Months to Prepare for Automated Attacks
Frontier AI models have already demonstrated they can autonomously, and in some cases, inadvertently, conduct end-to-end compromises, but the situation will become more urgent very soon. First seen on darkreading.com Jump to article: www.darkreading.com/cybersecurity-operations/companies-six-months-prepare-automated-attacks also interesting: Snowflake Clients Targeted With Credential Attacks Meet ShadowLeak: ‘Impossible to detect’ data theft using AI CometJacking: One Click Can…
-
AI is finding vulnerabilities faster. Who is funding the people expected to fix them?
Artificial intelligence is changing vulnerability discovery. At OpenSSL, we are seeing that change first-hand. A year ago, our security address received around nine separate reports and enquiries a month. It now receives around 70. AI tools can examine source code and identify potential security issues at a scale that would previously have required significant human…
-
AI is finding vulnerabilities faster. Who is funding the people expected to fix them?
Artificial intelligence is changing vulnerability discovery. At OpenSSL, we are seeing that change first-hand. A year ago, our security address received around nine separate reports and enquiries a month. It now receives around 70. AI tools can examine source code and identify potential security issues at a scale that would previously have required significant human…
-
AI is finding vulnerabilities faster. Who is funding the people expected to fix them?
Artificial intelligence is changing vulnerability discovery. At OpenSSL, we are seeing that change first-hand. A year ago, our security address received around nine separate reports and enquiries a month. It now receives around 70. AI tools can examine source code and identify potential security issues at a scale that would previously have required significant human…
-
QA: Viasat Tests Satellite Resilience With AI as Cyber Expert Warns an Attack Could ‘Hurt an Entire Country’
Tags: ai, attack, communications, country, cyber, data-breach, network, resilience, russia, ukraine, vulnerabilityAn AI-assisted platform has been used to test whether Viasat’s satellite communications links can meet operational thresholds under interference and adversarial jamming. Announced this month, the work with Atalanta has renewed scrutiny of the vulnerabilities exposed by Russia’s 2022 attack on Viasat’s KA-SAT network, which disrupted communications across Ukraine and several European countries. Gil Baram,…
-
Data dive: Mapping NHS hyperscaler dependence
Mapping NHS DNS data reveals a heavy reliance on US hyperscalers, with Microsoft 365 routing email and infrastructure for the vast majority of trusts in a tangled web of connections First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366649921/Data-dive-Mapping-NHS-hyperscaler-dependence also interesting: 11 ways cybercriminals are making phishing more potent than ever APT Attacks Target Indian Government…
-
Humans have edge over AI in Dutch hacking contest
As machines become crucial for cyber security, humans wonder where they stand First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366649310/Humans-have-edge-over-AI-in-Dutch-hacking-contest also interesting: US may plan legislation to contain Chinese cyber espionage FCC creates national security council to counter cyber threats from China Cybersecurity Snapshot: Top Guidance for Improving AI Risk Management, Governance and Readiness Microsoft…
-
US senator Bernie Sanders calls for ban on AI superintelligence
Tags: aiTwo bills aimed at curbing the possibility of superintelligent AI systems, and regulating the use of agentic AI, are being introduced in the US First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366649983/US-senator-Bernie-Sanders-calls-for-ban-on-AI-superintelligence also interesting: MSSP Alert Live 2024: Why AI is a Business Opportunity for MSPs NSFOCUS ISOP Receives International Recognition: AI Drives Enterprise Security…
-
Once popular for attacking AI, ASCII smuggling is embraced by spammers
Tags: aiA once-overlooked block of unicode that’s invisible to humans is gaining ever wider use. First seen on arstechnica.com Jump to article: arstechnica.com/security/2026/09/once-popular-for-attacking-ai-ascii-smuggling-is-embraced-by-spammers/ also interesting: MSSP Alert Live 2024: Why AI is a Business Opportunity for MSPs NSFOCUS ISOP Receives International Recognition: AI Drives Enterprise Security Operations from “Complex” to “Simple” Microsoft to Add New AI-Powered…
-
Three Frontier Labs, Two Weeks: Rogue AI Agents Are Real
On July 21, 2026, OpenAI confirmed that one of its own evaluation agents had broken into Hugging Face. By August 5, Anthropic and Meta had each disclosed a similar incident. Three labs, three model families, one pattern: an agent given… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/three-frontier-labs-two-weeks-rogue-ai-agents-are-real/ also interesting: DeepSeek Deep Dive Part 1:…
-
Breach of Confidence, 04 September 2026
I’ve spent this week watching a scam artist successfully impersonate a friend on LinkedIn, complete with his job title and a slightly better headshot. It was reported four days ago. The account is still up. LinkedIn’s verification process remains slower… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/breach-of-confidence-04-september-2026/ also interesting: TDL001 – Cybersecurity Explained: Privacy,…
-
IDScan sued over alleged data breach affecting 153 million drivers
Multiple lawsuits have been filed against identity verification company IDScan after hackers allegedly breached the service and offered to sell more than 153 million driver’s licenses. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/idscan-sued-over-alleged-data-breach-affecting-153-million-drivers/ also interesting: AWS customers face massive breach amid alleged ShinyHunters regroup The biggest data breach fines, penalties, and settlements so far…
-
AI Attack Surfaces and Supply Chain Threats Define the Week
Weekly summary of Cybersecurity Insider newsletters First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/weekly-roundup/ai-attack-surfaces-and-supply-chain-threats-define-the-week/ also interesting: Data Security Predictions for 2025: Putting Protection and Resilience at Center Stage Purdue 2.0? : Rising to the Challenge to secure OT with Zero Trust Connectivity Vaillant CISO: NIS2 complexity and lack of clarity endanger its mission Why outsourced…
-
AI Attack Surfaces and Supply Chain Threats Define the Week
Weekly summary of Cybersecurity Insider newsletters First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/weekly-roundup/ai-attack-surfaces-and-supply-chain-threats-define-the-week/ also interesting: 5 trends reshaping IT security strategies today 10 promising cybersecurity startups CISOs should know about AI, Quantum, and the New Threat Frontier: What Will Define Cybersecurity in 2026? 8 things CISOs can’t afford to get wrong in 2026
-
CISA Adds 7 Exploited Flaws as Attackers Target AI Infrastructure
CISA added seven exploited flaws to its KEV catalog, including LiteLLM, Kestra, Starlette, and SonicWall vulnerabilities under active attack. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/news/news-cisa-exploited-ai-flaws/ also interesting: Operation Epic Fury: Why exposure data changes everything about Iran’s cyber-kinetic campaign Attackers exploit critical Langflow RCE within hours as CISA sounds alarm Attackers exploit critical…
-
OpenAI Pledges $1B to Arm Cyber Defenders With Frontier AI
Daybreak Expansion Targets US Public Sector and Critical Infrastructure Security. OpenAI is committing $1 billion to subsidize access to its cyber-capable models for defenders and is launching a center to train security professionals in the American public sector. Daybreak for Frontline Defenders offers security engineers and other defenders the ability to use frontier AI models.…
-
OpenAI Pledges $1B to Arm Cyber Defenders With Frontier AI
Daybreak Expansion Targets US Public Sector and Critical Infrastructure Security. OpenAI is committing $1 billion to subsidize access to its cyber-capable models for defenders and is launching a center to train security professionals in the American public sector. Daybreak for Frontline Defenders offers security engineers and other defenders the ability to use frontier AI models.…

