Tag: risk
-
KI-Governance auf mobilen Endgeräten: Die alten Regeln gelten nicht mehr
KI-Funktionen wandern zunehmend vom Chatfenster in Apps, Agenten und mobile Endgeräte. Für Unternehmen bedeutet das: Klassische KI-Governance greift zu kurz, wenn sie mobile Nutzung, App-Updates, Netzwerkwechsel und rollenbasierte Risiken nicht gezielt berücksichtigt. Management Summary Klassische KI-Governance reicht für mobile Endgeräte nicht mehr aus: KI steckt heute zunehmend in nativen Apps, Updates und Agenten statt nur……
-
A Reported Log4j RCE Is More Complicated Than It Looks
<div cla TL;DR A recently circulated Log4j finding demonstrates a reproducible bypass of a defense-in-depth deserialization control involving FilteredObjectInputStream. Sonatype does not currently consider this a clear-cut Log4j vulnerability. Apache explicitly warns that deserializing untrusted data is unsafe and treats these filters as hardening measures rather than complete security boundaries. Exploitation requires uncommon, legacy-style application…
-
A Reported Log4j RCE Is More Complicated Than It Looks
<div cla TL;DR A recently circulated Log4j finding demonstrates a reproducible bypass of a defense-in-depth deserialization control involving FilteredObjectInputStream. Sonatype does not currently consider this a clear-cut Log4j vulnerability. Apache explicitly warns that deserializing untrusted data is unsafe and treats these filters as hardening measures rather than complete security boundaries. Exploitation requires uncommon, legacy-style application…
-
A Reported Log4j RCE Is More Complicated Than It Looks
<div cla TL;DR A recently circulated Log4j finding demonstrates a reproducible bypass of a defense-in-depth deserialization control involving FilteredObjectInputStream. Sonatype does not currently consider this a clear-cut Log4j vulnerability. Apache explicitly warns that deserializing untrusted data is unsafe and treats these filters as hardening measures rather than complete security boundaries. Exploitation requires uncommon, legacy-style application…
-
A Reported Log4j RCE Is More Complicated Than It Looks
<div cla TL;DR A recently circulated Log4j finding demonstrates a reproducible bypass of a defense-in-depth deserialization control involving FilteredObjectInputStream. Sonatype does not currently consider this a clear-cut Log4j vulnerability. Apache explicitly warns that deserializing untrusted data is unsafe and treats these filters as hardening measures rather than complete security boundaries. Exploitation requires uncommon, legacy-style application…
-
Unified vision: An executive playbook for data risk management
First seen on scworld.com Jump to article: www.scworld.com/resource/unified-vision-an-executive-playbook-for-data-risk-management
-
OWASP updates top 10 security risks for LLM applications
First seen on scworld.com Jump to article: www.scworld.com/analysis/owasp-updates-top-10-security-risks-for-llm-applications
-
Why mission risk should drive cyber operations strategies
First seen on scworld.com Jump to article: www.scworld.com/perspective/why-mission-risk-should-drive-cyber-operations-strategies
-
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
The order says any foreign-produced equipment deemed to pose national security risks can’t be purchased or installed. First seen on cyberscoop.com Jump to article: cyberscoop.com/energy-department-cybersecurity-executive-order-rules/
-
Stop Building a 2003 SOC with AI: Local Context, Failure Modes and Your Path (Part 3)
In Part 1 of this series, we dumped a pile of uncomfortable questions on you and promised answers. In Part 2 of the series, we talked about why 1990s-2000s alert triage must die. The core thesis, if you recall: if you add AI agents into a legacy, swivel-chair SOC structure, you are essentially building a robotic…
-
North Korean Hackers Target Healthcare: What You Need to Know
North Korean cyberattacks reveal how trusted identities and workflows create healthcare cybersecurity risk, and how security teams can test them. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/north-korean-hackers-target-healthcare-what-you-need-to-know/
-
Your Coding Assistant Is Shipping Security Vulnerabilities
Tags: access, ai, api, application-security, authentication, compliance, credentials, email, endpoint, framework, github, governance, LLM, programming, risk, service, tool, vulnerabilityYour Coding Assistant Is Shipping Security Vulnerabilities. Here’s How to Fix That. AI coding assistants have gotten remarkably good at writing functional code. Syntax correctness rates are approaching 100%. Developers are more productive than ever. And yet the security picture tells a very different story. Veracode recently evaluated over 150 large language models across vendors…
-
How to Fix Enterprise Cyber Risk Platform Adoption
<div cla You’ve invested in an enterprise cyber risk management platform. Your security team completed training, your compliance officers signed off, and your board approved the budget. Six months later, adoption has stalled. Assessments still live in spreadsheets. Risk data remains fragmented across departments. Executive reports take days to compile manually. First seen on securityboulevard.com…
-
88 ID Verification Breaches Show the Cost of Collecting Identity Data
88 ID-verification breaches exposed billions of records, highlighting the growing risks of collecting sensitive identity and biometric data. A new report from Mysterium VPN compiles 88 documented incidents since 2011 where data collected specifically to verify someone’s identity or age got breached, exposed, or sold. The confirmed and researcher-verified total sits at 2.15 billion records,…
-
AI vulnerability discovery scores the highest impact of 20 emerging risks
Risk managers, auditors and senior executives at 316 companies spent April and May ranking 20 threats they have not yet felt. AI discovery of cyber vulnerabilities came back … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/26/ai-vulnerability-discovery-emerging-risks/
-
False Positive Elimination: How Runtime Context Saves Developer Time
<div cla TL;DR Traditional application security tools generate false-positive vulnerability findings because they analyze code patterns without execution context, flagging vulnerabilities in code that never runs with untrusted data. Runtime instrumentation solves this by observing actual production behavior, revealing that only a small percentage of flagged vulnerabilities are truly exploitable. Reducing application security false positives…
-
Network Compliance Is Failing 50% of Enterprises. Here’s Why and How to Fix It
According to Hyperproof’s 2026 IT Risk and Compliance Benchmark Report, 50% of organizations managing compliance ad hoc suffered a data breach in 2025. Organizations using an integrated, automated approach cut that number nearly in half. That gap does not happen by accident. The breached organizations were not ignoring compliance. Most had policies, scheduled checks, and..…
-
When the Algorithm Fires You: Uber Faces Euro825M Fine
Uber faces an Euro825M GDPR fine for automatically suspending drivers without human review, highlighting the risks of AI decisions affecting workers. The Dutch Data Protection Authority handed Uber its largest privacy fine yet, and this one isn’t about data transfers or cookie consent. The regulator imposed an 825 million euro penalty, roughly $964 million, over…
-
MDR May Be Splitting Into Three Managed Services
I have argued for a while that MDR has to move beyond alert triage and become a cyber risk reduction service. A recent conversation with an experienced MDR operator added another piece to that thesis. The future may not be one ever-expanding MDR bundle. We may be forcing three different jobs into one category: The……
-
Most Organizations Declare Victory Over a Breach Too Early
Why Bringing Systems Back Online Is Not the Same as Breach Recovery Getting systems back online may end the outage, but it doesn’t end the breach. Organizations that equate service restoration with recovery risk leaving attackers’ footholds, persistence mechanisms and governance failures untouched – and vulnerable to compromise again. First seen on govinfosecurity.com Jump to…
-
District Administration – K12’s biggest cybersecurity risk isn’t devices. It’s everything beyond.
This article was originally published in District Administration on 8/18/26 by Charlie Sander. Recent conversations about technology in schools have centered around one main question: Are students spending too much time on screens? Now, this debate has expanded to include issues like AI, a ban on cellphones and/or tablets, and the broader role of digital learning.…
-
Vektorisierung und Abliteration als KI-Risiken
Die Zahl der Kompromittierungsversuche auf öffentlich zugängliche KI-Modelle und eigenentwickelte LLMs nimmt zu. Laut den Ergebnissen des aktuellen Cost of a Data-Breach-Reports von IBM stieg die Zahl der KI-gestützten Angriffe im Vergleich zum Vorjahr um 56 Prozent. Die finanziellen Folgen waren nicht unerheblich. KI-gestützte Angriffe verursachten pro Sicherheitsvorfall durchschnittlich 1 Million US-Dollar an Kosten, da Angreifer…
-
AI supply chain risk is showing up in developer workflows first
In this Help Net Security interview, Dr. Jaushin Lee, CEO of Zentera Systems, discusses where AI supply chain risk shows up. He says most incidents still hit developer … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/25/jaushin-lee-ai-zentera-systems-supply-chain-risk/
-
How ‘Subtractive’ Security Erases Attack Paths
Chris Frenz, Rectangle Health CISO, on Reducing Risk From Attackers in Healthcare. Healthcare security teams can reduce cyber risk by removing attacker options before an incident occurs rather than relying primarily on detection and response, said Chris Frenz, CISO at Rectangle Health, describing a new subtractive-hardening architecture standard he developed for OWSAP. First seen on…
-
New Zealand to pursue social media ban for children under 16
The legislation would mandate that high-risk social media platforms such as Instagram, TikTok, Snapchat and Facebook take “reasonable steps” to ensure users are over age 16 by using tools like facial age estimation, digital ID services, formal IDs and existing account information for verification. First seen on therecord.media Jump to article: therecord.media/new-zealand-to-pursue-social-media-ban-for-children
-
After Mythos: When the Attacker Doesn’t Need to Log In
AI Agents Are Rewriting Attack Economics, CISO Risk and Enterprise Defense For years, the attacker’s problem was access. Steal a credential, find an open port and wait. Today, increasingly, the attacker’s problem is simply asking an AI model the right question. That change was the real topic at a recent roundtable of CISOs and Microsoft…
-
After Mythos: When the Attacker Doesn’t Need to Log In
AI Agents Are Rewriting Attack Economics, CISO Risk and Enterprise Defense For years, the attacker’s problem was access. Steal a credential, find an open port and wait. Today, increasingly, the attacker’s problem is simply asking an AI model the right question. That change was the real topic at a recent roundtable of CISOs and Microsoft…
-
Map What Your Agent Can Reach Before It Deletes It FireTail Blog
Tags: access, ai, control, credentials, data, group, intelligence, jobs, leak, risk, threat, tool, vulnerabilityAug 24, 2026 – Ayush Sethi – What your workforce’s AI prompts reveal in aggregate Most AI security controls judge one prompt at a time. We built Topics to read the layer above them, where a workforce’s prompts add up into a pattern that no single message shows.Someone in your legal team pastes a contract…

