Tag: risk
-
OpenAI Pauses Frontier RL Training as It Tightens Defenses Against Unsafe AI Behavior
OpenAI on Tuesday revealed that it paused reinforcement learning (RL) training for its latest artificial intelligence (AI) models for two weeks while it shored up additional defenses and increased the scope of its monitoring to avert another Hugging Face-like incident.”As models become more capable, the risks associated with developing and testing them internally also grow,”…
-
Quantum-Safe Isn’t Cyber-Safe
Tags: access, ai, api, breach, communications, compliance, computer, computing, credentials, cryptography, cyber, data, defense, encryption, exploit, flaw, google, group, ml, openai, password, radius, risk, threat, update<div cla In the same week federal agencies began scoping migrations under the White House’s new Post-Quantum Cryptography Executive Order, a group of academic researchers published a paper that, on its face, had nothing to do with quantum computing at all. It described a flaw in how three of the most security-conscious engineering organizations on…
-
SOC 2 + AI Controls: Strengthen Reports with Risk Audits
In 2026, organizations integrating artificial intelligence into core operations face a critical gap: traditional SOC 2 audits often overlook the unique risks introduced by AI systems, leaving reports incomplete and compliance efforts vulnerable to regulatory scrutiny. By expanding SOC 2 assessments with dedicated AI controls and integrated risk audits, firms can produce stronger, more defensible”¦…
-
NIST Frameworks and SOC 2 Reporting via Continuum GRC Services
As organizations navigate an increasingly complex regulatory environment in 2026, integrating NIST frameworks with SOC 2 reporting offers a strategic advantage that reduces audit fatigue while strengthening overall governance, risk, and compliance postures. Continuum GRC enables this interoperability through unified control mapping that aligns NIST SP 800-53, NIST SP 800-171 Rev 3, and CMMC 2.0″¦…
-
Ransomware disproportionately targets medium-sized firms, straining customer relationships
These companies often have the hardest time balancing their roles as suppliers and customers, according to the risk management firm Black Kite. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/ransomware-mid-market-firms-black-kite/828257/
-
Supply chain attack modelling using MITRE ATTCK
Supply chain risk is often discussed as a supplier problem, but for security teams it is better treated as an attack path problem. The practical question is not simply whether a supplier is trustworthy. It is how a compromise of that supplier, their software, their credentials, or their support channels could be used to reach……
-
OpenAI Tightens AI Safeguards Following Hugging Face Incident
OpenAI is strengthening safeguards for its most advanced AI models, citing growing risks as frontier systems gain more powerful cyber capabilities First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/openai-tightens-ai-safeguards/
-
OpenAI puts major frontier AI training run on hold over cyber risks
OpenAI temporarily paused reinforcement learning (RL) training on its latest models intended for deployment for two weeks while it hardened and red-teamed research … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/19/openai-model-safety-updates/
-
Wenn KI Schwachstellen schneller findet als Unternehmen sie schließen können Die Mobilisierung der Cybersicherheits-Branche
Mit Project QuiltWorks will CrowdStrike eine branchenweite Antwort auf die neue Dynamik KI-gestützter Cyberrisiken geben. Daniel Bernard, Chief Business Officer bei CrowdStrike erklärt, warum klassische Schwachstellenpriorisierung nicht mehr ausreicht und wie Technologiepartner, Integratoren und Cyberversicherer gemeinsam helfen sollen, Risiken schneller zu erkennen, zu bewerten und zu reduzieren. First seen on ap-verlag.de Jump to article: ap-verlag.de/wenn-ki-schwachstellen-schneller-findet-als-unternehmen-sie-schliessen-koennen-die-mobilisierung-der-cybersicherheits-branche/107009/
-
Control Plane Gaps Create Invisible Cloud Risk
First seen on scworld.com Jump to article: www.scworld.com/risk-advisory/risk-advisory-control-plane-gaps-create-invisible-cloud-risk
-
Identity Is the New Perimeter, AI Is Blowing It Wide Open
CyberEdBoard Webinar Panel to Explore Non-Human Identity Risks, AI Governance. Enterprises have never been able to fully secure human identities, but now CISOs are responsible for securing millions of non-human identities including AI agents, APIs, service accounts. Join this CyberEdBoard panel for perspectives on shadow AI, zero trust, legal issues and governance. First seen on…
-
As AI Evolves, Security Risks Remain Familiar
Since ChatGPT brought generative AI into the mainstream in 2022, organizations have rapidly embedded AI into everyday workflows. What began as chatbots has evolved into copilots, embedded AI features, and increasingly autonomous AI agents connected to enterprise systems. Despite this rapid evolution, the underlying security challenges remain familiar. AI risk is less about exotic threats..…
-
When AI Risk Becomes a Board Liability
CIOs Can Strengthen Oversight Through Reporting, Records and Insurance Reviews. AI failures can trigger financial, regulatory and reputational exposure that reaches the boardroom. Reed Smith partners Carolyn Rosenberg and Andy Moss explain how CIOs can document oversight, validate corporate claims and test insurance for coverage gaps. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/when-ai-risk-becomes-board-liability-a-32594
-
FDA Weighing Possible Regs for GenAI Medical Devices
Agency Seeks Public Input on Risk-Based Oversight Approach Across Product Life Cycle. The U.S. Food and Drug Administration is seeking public feedback on the varying risks and other considerations involving generative artificial intelligence-enabled medical devices to inform the agency as it contemplates how to advance a regulatory approach for these evolving products. First seen on…
-
‘Living Off the Plant’ OT Attacks Pose Physical Safety Risk
Beware Abuse of Native OT Functionality, Says Orange Cyberdefense’s Ric Derbyshire. Attackers can employ living off the plant tactics to stealthily access and move laterally inside industrial networks, abusing native functionality to conduct cyberespionage or disruption campaigns. Orange Cyberdefense’s Ric Derbyshire details essential defenses against this threat. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/living-off-plant-ot-attacks-pose-physical-safety-risk-a-32591
-
Every Company Now Needs An AI Risk Officer: Accenture Expert
For most companies, it has now become essential to clearly designate a single executive responsible for ensuring that the drive to deploy AI does not outpace cybersecurity and safety, according to Accenture cyber intelligence leader Ryan Whelan. First seen on crn.com Jump to article: www.crn.com/news/security/2026/every-company-now-needs-an-ai-risk-officer-accenture-expert
-
Where Cybersecurity GRC Programs Break Down – Kovrr
Articles related to cyber risk quantification, cyber risk management, and cyber resilience. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/where-cybersecurity-grc-programs-break-down-kovrr/
-
Where Cybersecurity GRC Programs Break Down – Kovrr
Articles related to cyber risk quantification, cyber risk management, and cyber resilience. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/where-cybersecurity-grc-programs-break-down-kovrr/
-
10 Integrated Risk Management Strategies with Continuum GRC in 2026
Tags: business, ciso, compliance, control, cybersecurity, governance, grc, risk, risk-management, strategy, threatIn 2026, organizations face an increasingly complex threat landscape where siloed risk management approaches fail to address the interoperability demands of modern regulatory frameworks. Integrated Risk Management has emerged as the essential discipline for CISOs and compliance officers seeking to unify cybersecurity controls, audit processes, and business objectives under a single governance model. Continuum GRC”¦…
-
LLMs and Contextual Integrity
I have been thinking a lot about AI and integrity. Part of that is contextual integrity. I recently found two papers on the topic. “CIMemories: A Compositional Benchmark for Contextual Integrity of Persistent Memory in LLMs”: Abstract: Large Language Models (LLMs) increasingly use persistent memory from past interactions to enhance personalization and task performance. However,…
-
Download: 2026 Credential Risk Report
85% of cybersecurity professionals consider compromised credentials a primary attack path, yet only 19% continuously monitor active credentials and automatically remediate … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/18/download-enzoic-2026-credential-risk-report/
-
EU AI Act Standards: What to Do Before Citation – Kovrr
Articles related to cyber risk quantification, cyber risk management, and cyber resilience. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/eu-ai-act-standards-what-to-do-before-citation-kovrr/

