Tag: risk
-
Proton brings Microsoft 365 to Easy Switch for Business as security leaders weigh US ‘kill switch’ risk
Proton has extended Easy Switch for Business, its guided migration tool, to Microsoft 365. Organisations can now move email, calendars and contacts from Outlook or Google Workspace to Proton’s end-to-end encrypted platform without taking their teams offline. The tool first launched for Google Workspace in June. Adding Microsoft 365 opens it up to the platform…
-
A four-week plan to tackle vendor concentration risk
In this Help Net Security video, Guilliano Molaire, founder of Skycloak, explains how to map vendor concentration risk. A company may pay 30 vendors and think its tools are … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/29/vendor-concentration-risk-video/
-
Niche AI tools pose major cybersecurity risk to infrastructure operators
Security vetting tools and processes weren’t designed with obscure AI services in mind, according to TrendAI. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/ai-apps-niche-cybersecurity-risk-trendai/831486/
-
ShinyHunters trades financial extortion for a reckless war of ego with the FBI
Cybercrime experts are stunned as ShinyHunters risks agent safety and intense federal heat in a bizarre attempt to force the retraction of an agency advisory. First seen on cyberscoop.com Jump to article: cyberscoop.com/fbi-data-breach-shinyhunters-agent-safety-risk/
-
ShinyHunters trades financial extortion for a reckless war of ego with the FBI
Cybercrime experts are stunned as ShinyHunters risks agent safety and intense federal heat in a bizarre attempt to force the retraction of an agency advisory. First seen on cyberscoop.com Jump to article: cyberscoop.com/fbi-data-breach-shinyhunters-agent-safety-risk/
-
80,000+ Organizations Had AI Logins Stolen: From Shadow AI to LLMjacking
Infostealer logs exposed AI account credentials and sessions tied to more than 80,000 corporate domains, creating risks ranging from stolen conversations to LLMjacking. SOCRadar examines the growing market for stolen AI logins and how organizations can identify their exposure. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/80-000-plus-organizations-had-ai-logins-stolen-from-shadow-ai-to-llmjacking/
-
Why the CISO-CFO Relationship Is a Key to Cybersecurity Success
Organizations where CISOs and CFOs align on cybersecurity strategy to protect assets, manage risk, and enable business growth are better prepared to face today’s threat landscape. First seen on darkreading.com Jump to article: www.darkreading.com/cyber-risk/how-to-manage-ciso-cfo-relationship-cybersecurity-success
-
How the CISO-CFO Relationship Is a Key to Cybersecurity Success
Organizations where CISOs and CFOs align on cybersecurity strategy to protect assets, manage risk, and enable business growth are better prepared to face today’s threat landscape. First seen on darkreading.com Jump to article: www.darkreading.com/cyber-risk/how-to-manage-ciso-cfo-relationship-cybersecurity-success
-
Beyond Account-Level Risk: An Evidence-to-Action Pipeline for Detecting Fraud Rings
Linkage analysis connects accounts, devices and infrastructure to detect coordinated fraud rings that traditional account-level risk controls may fail to identify. First seen on hackread.com Jump to article: hackread.com/account-level-risk-pipeline-detecting-fraud-rings/
-
Entwicklung soll sich verlangsamen – Firmenchefs warnen erstmals bei UN-Sicherheitsrat vor Risiken von KI
First seen on security-insider.de Jump to article: www.security-insider.de/openai-anthropic-un-sicherheitsrat-ki-risiken-a-788312a89575c858b709d797966a5d13/
-
KnowBe4 adressiert Shadow AI mit Echtzeitkontrolle im Browser
KnowBe4 erweitert den Agent Risk Manager: Eine Browser-Erweiterung erkennt Shadow AI in Echtzeit und kann KI-Dienste zulassen, warnen oder blockieren. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/knowbe4-adressiert-shadow-ai-mit-echtzeitkontrolle-im-browser/a46534/
-
Roundcube SQL injection CVE-2026-48842 is now being exploited in the wild
Roundcube SQL injection CVE-2026-48842 is now being exploited in the wild, putting unpatched webmail servers at risk of database compromise. A Roundcube Webmail vulnerability, tracked as CVE-2026-48842 (CVSS score of 8.1) and patched four months ago, is now being exploited in the wild. The Canadian Centre for Cyber Security added the warning to its advisory…
-
From Tokenmaxxing to FDEmaxxing: The Next Enterprise AI Trap
Why Enterprise AI Needs Architecture, Not More Engineers or Tokens Enterprises have never standardized on one database, cloud or language, and AI should be no different. The real fix is a multi-model architecture with governance built in: risk profiling for every agent, guardian agents that monitor other agents and a learning loop the enterprise owns…
-
If you do one security check this quarter, make it agent memory
In this interview with Help Net Security, Chris Latimer, CEO of Vectorize, talks about the security risks hiding in AI agent memory. He found coding agents storing API keys, … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/28/chris-latimer-vectorize-agent-memory-security/
-
How the CISO CFO Relationship is a Key to Cybersecurity Success
Building a financial bridge: Organizations where CISOs and CFOs align on cybersecurity strategy to protect assets, manage risk and enable business growth are better prepared to face today’s threat landscape. First seen on darkreading.com Jump to article: www.darkreading.com/cyber-risk/how-to-manage-ciso-cfo-relationship-cybersecurity-success
-
Labcorp to overhaul data security practices, pay $2.3 million fine for cybersecurity failings
Security changes include creating an incident response plan for vendor security failings, limiting how much data Labcorp shares with vendors and building an expansive risk management team charged with tracking vendors’ compliance with data security practices. First seen on therecord.media Jump to article: therecord.media/labcorp-to-overhaul-security-practices-settlement
-
LabCorp Pays States $2.2M in Settlement Over AMCA Hack
42 States, DC Require Lab to Strengthen Security, Vendor Risk Management Practices. LabCorp has agreed to pay $2.2 million and improve its data security and vendor risk management practices to resolve multistate litigation stemming from a 2019 hack on a third-party firm that affected 10.2 million patients of the medical testing lab. First seen on…
-
With the Rise of AI Agents, SOC 2 Should Adapt or Risk Irrelevance
AI agents can operate through human credentials and take actions that existing SOC 2 controls may not distinguish from human activity. Token Security explains why SOC 2 needs to adapt to address the security gaps created by agent identities. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/with-the-rise-of-ai-agents-soc-2-should-adapt-or-risk-irrelevance/
-
With the Rise of AI Agents, SOC 2 Should Adapt or Risk Irrelevance
AI agents can operate through human credentials and take actions that existing SOC 2 controls may not distinguish from human activity. Token Security explains why SOC 2 needs to adapt to address the security gaps created by agent identities. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/with-the-rise-of-ai-agents-soc-2-should-adapt-or-risk-irrelevance/
-
KnowBe4 vermindert Shadow-AI mit Innovationen im Bereich der Agentensicherheit
KnowBe4 gibt eine Erweiterung des Agent-Risk-Manager bekannt: Mit der Einführung einer neuen nativen Browser-Erweiterung für Chrome und Edge erhalten Sicherheitsteams nun Echtzeitkontrolle über ‘Shadow-AI”. Diese neue Funktion geht über bestehende Dashboards hinaus, die eine nicht genehmigte KI-Nutzung erst dann melden, wenn der Schaden bereits entstanden ist, und bietet stattdessen eine Kontrollmöglichkeit, mit der der Zugriff von…
-
Zero-Click Vulnerabilities in Salesforce Agentforce Expose Wider AI Agent Risk
The ‘SalesBleed’ set of weaknesses in Salesforce’s Agentforce agents exposed CRM data to attackers via prompt injection and DNS exfiltration First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/vulnerabilities-salesforce-ai/
-
Zero-Click Vulnerabilities in Salesforce Agentforce Expose Wider AI Agent Risk
The ‘SalesBleed’ set of weaknesses in Salesforce’s Agentforce agents exposed CRM data to attackers via prompt injection and DNS exfiltration First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/vulnerabilities-salesforce-ai/
-
Nur 5 Prozent der Unternehmen sind gegen Cyberangriffe versichert
Cyberrisiken werden teurer, professioneller und für den Mittelstand immer schwerer zu ignorieren. Dennoch besitzt in Deutschland erst jedes 20. Unternehmen eine Cyberversicherung. Entscheidend ist deshalb ein Doppelansatz: belastbare IT-Mindeststandards senken das operative Risiko, eine passende Police federt die finanziellen und organisatorischen Folgen eines Vorfalls ab. Management Summary Versicherungslücke bleibt groß: 2025 stieg die Zahl gewerblicher……
-
Rogue OpenAI agent targeted Australian government site
The prime minister rebuked the company for its slow response and warned that AI poses significant risks that need to be further addressed. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/rogue-openai-agent-targeted-australian-government-site/831263/
-
Cybersicherheit in Zahlen 2026: Wenn IT-Sicherheit zur Teamaufgabe wird
Cybersecurity ist 2026 keine isolierte Aufgabe der IT mehr. KI-gestützte Angriffe, NIS2-Pflichten, Abhängigkeiten von Technologieanbietern und fehlende Fachkräfte zwingen Unternehmen zu einer integrierten Sicherheitsstrategie. Entscheidend ist das Zusammenspiel aus belastbarer Technik, klarer Governance, digitaler Souveränität und einer Belegschaft, die Risiken erkennt und im Ernstfall handlungsfähig bleibt. Management Summary Cyberrisiko wird zum Geschäftsrisiko: Organisierte Kriminalität dominiert……
-
AI Agents Need More Than Proofs of Concept
AWS’ Sivasubramanian Says Enterprises Need Focused AI Agent Investments. Enterprises risk getting trapped in AI proof-of-concept hell when they deploy agents without clear measures of success. AWS executive Swami Sivasubramanian explains how focused investments, shared infrastructure and human oversight can help move AI agents into production. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/ai-agents-need-more-than-proofs-concept-a-32919
-
Building AI Systems With ‘Least Capability’ Cuts Agent Risk
Akamai CTO Robert Blumofe on Reliability, Visibility and AI Security. AI systems that perform well in the lab can fail at scale, drive unexpected costs and expose new attack paths in production. Robert Blumofe, executive vice president and CTO at Akamai, says enterprises need stronger visibility, reliability engineering and a least capability model for AI…
-
The Hidden Security Risks of Devices You Forgot Were Connected
IoT and OT devices can create hidden security gaps. Learn how asset visibility helps organizations find forgotten devices and reduce network security risks now. First seen on hackread.com Jump to article: hackread.com/hidden-security-risks-connected-devices/
-
Vibe-Coding schafft Risiken
Der zunehmende Einsatz von KI-Kodierungstools kurz Vibe-Coding beschleunigt zwar die Softwareentwicklung erheblich. Allerdings verändert die Nutzung dieser Tools unbemerkt die Zusammensetzung von Entwicklungsumgebungen und schafft damit ein Sicherheitsproblem, das klassische Patch- und Compliance-Prozesse übersehen können. Besonders betroffen sind Entwicklerrechner mit zahlreichen .NET-SDK- und Runtime-Versionen. Generative KI und agentenbasierte Entwicklungswerkzeuge sind inzwischen fester Bestandteil […] First…
-
Insider Research im Gespräch – Agentic AI Control: Neue Risiken, Neue Sicherheits-Strategien
First seen on security-insider.de Jump to article: www.security-insider.de/least-agency-ki-agenten-sicher-steuern-a-65afc4db2f1920070280de057b89e8e2/

