Tag: defense
-
AI Accelerates Financial Services Fraud
Coinbase’s Lunglhofer on Deepfakes, Supply-Chain Risk and Human Expertise. AI is helping criminals clone voices, exploit software flaws and guide fraud schemes in real time. Coinbase Chief Security Officer Jeff Lunglhofer explains why faster attacks demand AI-enabled defense backed by cybersecurity experts. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/ai-accelerates-financial-services-fraud-a-32450
-
Why Open-Weight AI Models Are Key to US Strategy
Rain Capital’s Chenxi Wang on Why Closed AI Models Risk US Competitiveness. Machine-scale AI attacks demand machine-scale defenses, says Rain Capital’s Chenxi Wang. She says America’s edge depends on backing open-weight models and using the world’s top AI researchers, not retreating behind closed systems that cede ground to competitors. First seen on govinfosecurity.com Jump to…
-
New Interrupt Injection Attack Can Bypass Spectre v2 Defenses on Intel and AMD CPUs
An unprivileged Linux program can time a hardware interrupt to land in the gap between a processor sanitizing its branch predictor and the kernel using it, re-poisoning the predictor after the defense has run.MIT CSAIL researchers Daniël Trujillo and Mengjia Yan named the technique INTERRUPT INJECTION. On an AMD Zen 2 machine running Linux 6.14…
-
Palo Alto Networks Introduces PAN-OS 12.2 Ceres With AI Security Features
Palo Alto Networks has introduced PAN-OS 12.2 Ceres, a firewall operating system update that adds more than 55 innovations aimed at attacks accelerated by frontier AI. The release centers on Advanced Virtual Patching, Advanced IP Defense and six AI-powered Network Security Agents. Advanced Virtual Patching uses AI to identify unknown vulnerabilities and deliver network protections..…
-
Miggo Adds DefenseDepth Mitigation to Close Patch Gaps in Minutes
Miggo Security has announced Defense-in-Depth Mitigation, a capability that coordinates protections at the network edge and inside an application while a permanent patch is being prepared. The release was issued from Black Hat USA and says Miggo is presenting the capability in Las Vegas during the event. The approach gives security teams multiple mitigation points..…
-
How AI-powered phishing killed blocklists for good
AI is helping attackers create disposable phishing infrastructure and rapidly evolving toolkits that blocklists cannot track fast enough. Push Security explains why browser-level, technique-based detection offers a more durable defense than relying on domains, signatures, and other known-bad indicators. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/how-ai-powered-phishing-killed-blocklists-for-good/
-
Zimperium Launches Deep Insights for Automated Mobile Forensics
Zimperium has announced Deep Insights, a mobile security product that combines real-time Mobile Threat Defense with automated mobile forensics. Deep Insights automates forensic analysis and reconstructs the sequence of events around a mobile incident. Zimperium said it correlates configuration changes, application activity, permission shifts and suspicious network traffic to build a step-by-step attack timeline. The..…
-
Russian Access Broker Sells Network Access to Ransomware Gangs While Spying on Ukraine
Tags: access, cyber, data-breach, defense, exploit, intelligence, network, ransomware, russia, ukraineAn exposed server linked to a Russian”‘speaking initial access broker (IAB) has revealed a sprawling operation that simultaneously fuels ransomware intrusions worldwide and supports Russian state-aligned intelligence collection against Ukrainian defense and aerospace targets. The artefacts show a mature, high”‘volume access brokerage pipeline that industrialises exploitation of internet”‘facing appliances, pivots to full Active Directory compromise,…
-
Is Securing Data A Crime? The Sam Tunick Case Tests the Limits of Digital Self-Defense
A federal prosecution involving a phone’s duress-wipe feature raises difficult questions about border searches, digital property and whether privacy protections can become obstruction. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/is-securing-data-a-crime-the-sam-tunick-case-tests-the-limits-of-digital-self-defense/
-
New York Pours $9M Into Water Cyber Defense Amid Attacks
New York Fast-Tracks Utilities Grants as Hackers Disrupt Water Systems Nationwide. New York is awarding more than $9 million in cybersecurity grants to water and wastewater systems statewide, fast-tracking the funding after a wave of cyberattacks disrupted utility operations across at least seven states and federal standards efforts remain stalled. First seen on govinfosecurity.com Jump…
-
XCSSET v40 Infects Xcode Projects to Hijack Chrome and Trojanize Telegram on Macs
XCSSET v40 marks a significant escalation in macOS-focused supply chain attacks, weaponizing poisoned Xcode projects to hijack Chrome and Trojanize Telegram while operating almost entirely from memory with aggressive polymorphism and defense evasion. After several months of apparent inactivity, the actors behind the XCSSET malware resurfaced with version 40 (v40), a major re-architecture of the…
-
CMMC 2.0 Audits: Lazarus Alliance Compliance Assessments
In 2026, defense contractors face heightened scrutiny under the CMMC 2.0 Final Rule, where compliance assessments have shifted from preparatory exercises to mandatory gatekeepers for contract eligibility. Lazarus Alliance brings first-hand audit experience to help organizations navigate this landscape with precision, integrating CMMC requirements with broader frameworks like NIST 800-171 and ISO 27001. CMMC 2.0″¦…
-
To Ban or Not Ban Chinese Open-Weight AI Models
Tags: ai, backdoor, china, control, cybersecurity, data, defense, finance, government, infrastructure, international, malicious, microsoft, military, network, nvidia, open-source, openai, regulation, risk, software, supply-chain, technology, usaShould the US ban American companies from using Chinese open-weight AI models? That is the ugly question. US officials have openly expressed concerns and a desire to implement regulations. The technology community has aggressively responded, with over 20 leading AI companies, including Microsoft, Nvidia, Meta, and Dell, urging legislators not to rush imposing restrictions on…
-
Zero Trust Stops at the AI
Your machine-learning defenses have a half-life, and the standing trust you place in them is the gap no dashboard shows. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/07/zero-trust-stops-at-the-ai/
-
What the Hugging Face breach reveals about defense in the age of agentic AI
We almost never get both sides of an intrusion. This time we did. Last month, Hugging Face disclosed a breach into part of its production infrastructure, saying an autonomous AI agent system ran the attack from start to finish. Five days later, OpenAI revealed that its own models, including GPT-5.6 Sol along with an unreleased…
-
Anthropic, Pentagon Clash Over First Amendment Claims
Judge Questions Defense Department’s Blacklisting of AI Company. A San Francisco federal judge showed skepticism Thursday over whether the Department of Defense acted lawfully when it blacklisted artificial intelligence firm Anthropic, telling federal attorneys at the onset of a roughly 90 minute hearing that the Pentagon is at odds with the First Amendment. First seen…
-
ThreatLocker Raises $190M to Counter Malicious AI Agents
Series F Funding Supports Zero Trust Controls Built for Autonomous AI Workflows. ThreatLocker raised $190 million in Series F funding to expand zero trust protections against autonomous AI agents while using AI to simplify security administration, policy management and prevention-first defenses across increasingly complex enterprise environments. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/threatlocker-raises-190m-to-counter-malicious-ai-agents-a-32379
-
NVIDIA’s Open Secure AI Alliance Is Missing Some Big Names
NVIDIA has launched a new Open Secure AI Alliance to build an “open defense stack for agents” First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/nvidia-open-security-ai-alliance/
-
Kiteworks, A-LIGN target CMMC readiness across the defense industrial base
Tags: defenseFirst seen on scworld.com Jump to article: www.scworld.com/brief/kiteworks-a-lign-target-cmmc-readiness-across-the-defense-industrial-base
-
US Space Cybersecurity: ‘No One Is in Charge’
Cyber Defense Falters Without Cabinet Agency or White House Champion for Security. No single senior official is in charge of U.S. efforts to help secure commercial satellites and their land-based infrastructure. That leadership void has hampered the ability to impose security standards on space vendors providing critical services to the U.S. government over the past…
-
Anthropic and DOD Set to Face Off Thursday Over Blacklisting
Both Sides Ask San Francisco Federal Judge for Summary Judgment. Anthropic and the U.S. Department of Defense are set to face off Thursday in San Francisco federal court before a judge who already called the Pentagon’s effort to ban the artificial intelligence firm’s models almost certainly retaliatory and Orwellian. First seen on govinfosecurity.com Jump to…
-
In the Mythos era, security belongs at runtime
Frontier AI cut time-to-exploit from years to hours. Why defense now has to happen at runtime. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/spons/in-the-mythos-era-security-belongs-at-runtime/825478/
-
GitHub, PyPI add time-based defenses against supply chain attacks
GitHub and PyPI (Python Package Index) have introduced a time-based mechanism in the Dependabot dependency management tool to protect against supply-chain attacks and to limit their impact. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/github-pypi-add-time-absed-defenses-against-supply-chain-attacks/
-
GitHub, PyPI add time-absed defenses against supply chain attacks
GitHub and PyPI (Python Package Index) have introduced a time-based mechanism in the Dependabot dependency management tool to protect against supply-chain attacks and to limit their impact. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/github-pypi-add-time-absed-defenses-against-supply-chain-attacks/
-
Rep. Bacon warns CISA cuts weaken U.S. cyber defenses
First seen on scworld.com Jump to article: www.scworld.com/analysis/rep-bacon-warns-cisa-cuts-weaken-u-s-cyber-defenses
-
US House Votes to Extend Cyber Sharing Law for 10 Years
Lawmakers Advance 10-Year Renewal of Key Cyber Law, Setting Up Looming Senate Fight. The U.S. House of Representatives passed a fiscal year 2027 defense authorization bill with a provision extending the Cybersecurity Information Sharing Act of 2015 through 2036. The decade-long renewal faces an uphill climb in the Senate. First seen on govinfosecurity.com Jump to…
-
Russian LAUNDRY BEAR Hackers Exploit Zimbra Zero-Day to Steal 90 Days of Emails
Tags: advisory, cyber, cybersecurity, defense, email, espionage, exploit, government, group, hacker, russia, technology, threat, vulnerability, zero-dayRussian state-supported threat actors, known as LAUNDRY BEAR, have exploited a zero-day vulnerability in the Zimbra Collaboration Suite to steal up to 909,090 days’ worth of emails from targeted organizations across Western countries. A joint cybersecurity advisory, AA26-204A, issued on July 23, 2026, warns that this espionage-focused group has targeted government, defense, energy, technology, education,…
-
Top 10 Best Physical Security Penetration Testing Firms 2026
In an era dominated by cyber threats, the importance of physical security penetration testing often gets overshadowed. However, a robust security posture requires a holistic approach that addresses vulnerabilities in both the digital and physical realms. A determined attacker can bypass sophisticated cyber defenses simply by walking through an unlocked door, exploiting weak physical controls,…
-
Google Unveils CodeMender AI Agent for Automated Vulnerability Detection and Remediation
Google has unveiled CodeMender, a managed AI security agent designed to identify, validate, and remediate software vulnerabilities at machine speed. Announced in preview on July 22, 2023, the tool is available through the Gemini Enterprise Agent Platform and can also function as a core component of Google’s AI Threat Defense offering. This launch comes as…

