Tag: risk
-
IQVIA fined $7.8 million for failing to properly anonymize health data
Italy’s Data Protection Authority (GPDP) has fined IQVIA Euro7 million ($7.8M) over poor data-processing practices that the agency says could have put roughly one million patients at risk of data exposure and de-anonymization. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/iqvia-fined-78-million-for-failing-to-properly-anonymize-health-data/
-
Apple Strengthens macOS Privacy Controls as AI Agents Become More Autonomous
Apple has announced plans to strengthen macOS controls for Full Disk Access, citing concerns that increasingly autonomous AI agents could raise privacy and security risks by giving applications extensive access to users’ devices. In a developer update on October 2, Apple stated it will introduce additional controls for macOS Full Disk Access, a powerful permission…
-
Apple Plans Tighter macOS Full Disk Access Controls Over AI Agent Data Access
Apple has announced that it’s taking steps to tighten controls around a macOS setting called Full Disk Access (FDA) due to security risks posed by artificial intelligence (AI) agents.”Some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems”, including files, mail, messages, and even browsing…
-
Apple tightens macOS disk access as AI agents become more powerful
Apple plans to introduce additional controls for Full Disk Access in macOS, citing growing privacy risks as AI agents become more capable and autonomous. Users will need to … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/10/05/macos-full-disk-access-updates/
-
Von der Risikoerkennung zum aktiven Datenschutz: Thales stärkt DSPM für das KI-Zeitalter
Thales erweitert CipherTrust DSPM, um sensible Daten in Cloud-, On-Premises- und Hybridumgebungen vor neuen Risiken durch KI und autonome Agenten zu schützen. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/von-der-risikoerkennung-zum-aktiven-datenschutz-thales-staerkt-dspm-fuer-das-ki-zeitalter/a46601/
-
Unsichtbare Zugänge, reales Risiko: So gelingt Governance für Maschinenidentitäten
Service Accounts, API-Schlüssel, Cloud-Workloads und KI-Agenten handeln längst in einer Größenordnung, die klassische IAM-Prozesse überfordert. Die Studie »2026 Identity Security Landscape« beschreibt eine Identitätswelt, in der Maschinen menschliche Nutzer zahlenmäßig weit übertreffen und fragmentierte Kontrollen die Reaktion auf Vorfälle verlangsamen. Der Praxisleitfaden zeigt, wie Unternehmen in 90 Tagen Transparenz schaffen, Verantwortlichkeiten festlegen, langlebige Secrets abbauen……
-
Apple verschärft Full Disk Access wegen KI-Agenten
Apple plant strengere Kontrollen für Full Disk Access. Grund sind laut Apple wachsende Risiken durch KI-Agenten. First seen on golem.de Jump to article: www.golem.de/news/macos-apple-verschaerft-full-disk-access-wegen-ki-agenten-2610-213673.html
-
Cyberangriff auf die LMU: Wenn 50 Jahre Studierendendaten zum Risiko werden
Der Angriff zeigt, wie technische Schwachstellen und jahrzehntealte Datenbestände zu einem langfristigen Risiko für Hochschulen und Betroffene werden. Der Angriff auf das Zulassungssystem der Ludwig-Maximilians-Universität München macht aus einem IT-Vorfall ein langfristiges Datenschutzproblem: Rund 600.000 Datensätze aus fünf Jahrzehnten können betroffen sein. Während die forensische Aufklärung weiterläuft, verschiebt sich der Schwerpunkt von der akuten Abwehr……
-
UK and Europe at risk from Chinese tech, says security think tank
Although the UK and Europe have laws to restrict Chinese technology from critical infrastructure, implementation is patchy First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366651406/UK-and-Europe-at-risk-from-Chinese-tech-says-security-think-tank
-
Apple says it’s tightening macOS ‘Full Disk Access’ controls due to new risks from AI agents
Apple says it will add new controls around macOS’s Full Disk Access permission, warning that increasingly capable AI agents make broad access to users’ files, messages, mail, and browsing history riskier. First seen on techcrunch.com Jump to article: techcrunch.com/2026/10/02/apple-says-its-tightening-macos-full-disk-access-controls-due-to-new-risks-from-ai-agents/
-
Is It Fair to Blame ‘Rogue’ AI for Security Failures?
Rogue AI terminology anthropomorphizes LLMs and shifts risk responsibility from vendors. Defenders should treat agents as untrusted, nondeterministic software systems, not sentient beings with malicious intent. First seen on darkreading.com Jump to article: www.darkreading.com/insider-threats/blame-rogue-ai-security-failures
-
FTC Probes OpenAI, Anthropic as AI Agent Safety Risks Draw Scrutiny
The FTC is investigating OpenAI, Anthropic and other AI firms over potential consumer harms, safety claims and risks tied to increasingly autonomous AI systems. The post FTC Probes OpenAI, Anthropic as AI Agent Safety Risks Draw Scrutiny appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-ftc-openai-anthropic-ai-consumer-harms/
-
OpenAI’s Medicare attack has exposed Australia’s ‘tech debt’. Fixing it could bring a big bill for taxpayers
Home affairs department orders all federal government agencies to conduct review of ‘legacy technology’ amid fallout from AI agent hacks <ul><li>Get our <a href=”https://www.theguardian.com/email-newsletters?CMP=cvau_sfl”>breaking news email, <a href=”https://app.adjust.com/w4u7jx3″>free app or <a href=”https://www.theguardian.com/australia-news/series/full-story?CMP=cvau_sfl”>daily news podcast</li></ul>The Australian government faces significant “tech debt” that could bring a big bill for taxpayers after the <a href=”https://www.theguardian.com/technology/2026/sep/24/openai-agent-hacked-medicare-australia-what-we-know-so-far-ntwnfb”>OpenAI Medicare breach, as…
-
Medical records giant Epic pauses product development to fix security bugs that risk patients’ data
The healthtech software giant, which makes the widely used MyChart system for accessing medical data, will focus on fixing security bugs for the next few weeks. First seen on techcrunch.com Jump to article: techcrunch.com/2026/10/02/medical-records-giant-epic-pauses-product-development-to-fix-security-bugs-that-risk-patients-data/
-
12 Best IGA Tools Compared (2026): Features Pricing
SailPoint remains the best overall IGA platform for certification depth and AI-assisted reviews, with Saviynt the best converged alternative when ERP-grade SoD must ship cloud-native. Evaluating the broader landscape across the top Identity and Access Management (IAM) companies shows how access governance has evolved from static audit checklists into dynamic risk-control planes. The market’s real…
-
11 Best PAM Solutions Compared (2026): Features Pricing
CyberArk remains the best overall PAM platform for depth-driven enterprises, while Delinea is the best pick for usability-led deployments and Teleport the best modern choice for engineering infrastructure access. Enterprise risk teams evaluate these platforms directly alongside the Top 10 Best Privileged Access Management (PAM) Solutions for 2026 to eliminate unmanaged administrative sprawl. Privileged accounts…
-
FTC Investigates OpenAI and Anthropic Over Consumer Risks From Advanced AI Models
The U.S. Federal Trade Commission (FTC) has initiated a broad investigation into OpenAI, Anthropic, and other leading artificial intelligence developers to examine potential consumer harm arising from advanced AI systems. This inquiry will assess whether the companies’ development, deployment, safety claims, and management of agentic AI risks could violate the FTC Act’s prohibition on unfair…
-
National cyber director: Government-industry collaboration vital to managing AI risks, competition with nations
Sean Cairncross talked about regulations, China, pilot projects and more Thursday. First seen on cyberscoop.com Jump to article: cyberscoop.com/sean-cairncross-ai-security-china-industry-collaboration/
-
Sicherheitslücken durch Hybrid AI: Governance wird zur strategischen CISO-Aufgabe
Hybrid AI verspricht Unternehmen mehr Wahlfreiheit bei Modellen und Betriebsformen. Gleichzeitig wächst ein Geflecht aus Schnittstellen, Datenflüssen und Zuständigkeiten, das sich mit klassischen Kontrollen nur unzureichend steuern lässt. Für CISOs wird deshalb die Fähigkeit entscheidend, KI-Nutzung sichtbar zu machen, Risiken über den gesamten Lebenszyklus zu bewerten und Governance mit technischer Observability zu verbinden. Management Summary……
-
Sicherheitslücken durch Hybrid AI: Governance wird zur strategischen CISO-Aufgabe
Hybrid AI verspricht Unternehmen mehr Wahlfreiheit bei Modellen und Betriebsformen. Gleichzeitig wächst ein Geflecht aus Schnittstellen, Datenflüssen und Zuständigkeiten, das sich mit klassischen Kontrollen nur unzureichend steuern lässt. Für CISOs wird deshalb die Fähigkeit entscheidend, KI-Nutzung sichtbar zu machen, Risiken über den gesamten Lebenszyklus zu bewerten und Governance mit technischer Observability zu verbinden. Management Summary……
-
AI Finding More Medium-Risk Flaws
Exploitation Is Rising Faster Than Zero-Days as Attackers Accelerate N-Day Weaponization. A sharp uptick in artificial intelligence-spotted vulnerabilities so far hasn’t resulted in a corresponding explosion in hacking, Google says. AI is mostly identifying medium-risk flaws, the computing giant found in an analysis of disclosed vulnerabilities made over the past 18 months. First seen on…
-
Anthropic Prospectus Reveals Surging Sales, Worsening Losses
Amazon and Google Marketplaces Handled 47% of the Frontier AI Lab’s 2025 Sales. Anthropic’s prospectus shows rapid Claude revenue growth increasingly tied to Amazon and Google, while soaring compute costs, customer concentration and hundreds of billions of dollars in infrastructure commitments amplify the financial risks behind its expansion. First seen on govinfosecurity.com Jump to article:…
-
‘The Art of War’ Never Said Know Only Your Vulnerabilities
Why Threat Intelligence Must Connect Adversary Intent to Business Risk Organizations have become adept at cataloging vulnerabilities, but technical exposure alone does not reveal who will attack – and why or how. Strategic threat intelligence connects adversary behavior with business context to guide security priorities. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/blogs/the-art-war-never-said-know-only-your-vulnerabilities-p-4201
-
‘The Art of War’ Never Said Know Only Your Vulnerabilities
Why Threat Intelligence Must Connect Adversary Intent to Business Risk Organizations have become adept at cataloging vulnerabilities, but technical exposure alone does not reveal who will attack – and why or how. Strategic threat intelligence connects adversary behavior with business context to guide security priorities. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/blogs/the-art-war-never-said-know-only-your-vulnerabilities-p-4201
-
‘The Art of War’ Never Said Know Only Your Vulnerabilities
Why Threat Intelligence Must Connect Adversary Intent to Business Risk Organizations have become adept at cataloging vulnerabilities, but technical exposure alone does not reveal who will attack – and why or how. Strategic threat intelligence connects adversary behavior with business context to guide security priorities. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/blogs/the-art-war-never-said-know-only-your-vulnerabilities-p-4201
-
AI’s Third Wave: Coworkers Break the Security Model That Worked for Agents
Persistent AI coworkers may operate continuously with standing access, creating identity risks that existing security models were not designed to handle. Token Security explains why these agents need their own identities, owners, scoped permissions, and lifecycle controls. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/ais-third-wave-coworkers-break-the-security-model-that-worked-for-agents/
-
Quantum Readiness Means It’s Time To ‘Elevate’ Your Cryptography Experts: Optiv Field CISO
As businesses prepare for potentially unprecedented data security risks posed by quantum computing, a key part of the preparations should involve providing in-house cryptography specialists with greater attention and support as soon as possible, according to Optiv Field CISO Kristin Lowery. First seen on crn.com Jump to article: www.crn.com/news/security/2026/quantum-readiness-means-it-s-time-to-elevate-your-cryptography-experts-optiv-field-ciso
-
Everpure survey: 88% of executives fear data sovereignty failures
An Everpure survey of 2,100 C-suite and IT leaders across eight countries finds 90% recognise the risk, yet 64% lack a formal strategy to close ‘the sovereignty gap’ First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366651384/Everpure-survey-88-of-executives-fear-data-sovereignty-failures
-
Proton brings Microsoft 365 to Easy Switch for Business as security leaders weigh US ‘kill switch’ risk
Proton has extended Easy Switch for Business, its guided migration tool, to Microsoft 365. Organisations can now move email, calendars and contacts from Outlook or Google Workspace to Proton’s end-to-end encrypted platform without taking their teams offline. The tool first launched for Google Workspace in June. Adding Microsoft 365 opens it up to the platform…

