Tag: risk
-
HR must have a say in AI policy to forestall legal risks
In this Q&A, employment attorney Deepa Menon explains the legal risks of using AI for workforce decisions and why lawyers, HR and IT must agree on a framework before implementing AI. First seen on techtarget.com Jump to article: www.techtarget.com/searchhrsoftware/news/366644954/HR-must-have-a-say-in-AI-policy-to-forestall-legal-risks
-
DifyTap Flaws Expose AI Data Across Tenants on Platform Powering 1M+ Apps
A series of critical vulnerabilities in the widely used open-source LLMOps platform Dify, which powers over one million AI applications. These vulnerabilities, collectively referred to as “DifyTap,” include four flaws, two rated as critical and two that require no authentication. They expose cross-tenant data leakage risks, allowing attackers to access private AI conversations, preview sensitive…
-
The Evolution of iGaming Fraud: What Security Teams Should Expect in 2027
Learn how AI, deepfakes, synthetic identities and fraud-as-a-service may reshape iGaming risk, and what security teams can do to detect future threats in 2027. First seen on hackread.com Jump to article: hackread.com/igaming-fraud-security-teams-expect-in-2027/
-
Cybercrime Atlas Cosmos: Open-Source-Plattform kartiert das Ökosystem der Cyberkriminalität
Management Summary Eine neue offene Plattform macht Strukturen der Cyberkriminalität sichtbar, indem sie Akteure, Werkzeuge, Marktplätze und Geldflüsse in einem gemeinsamen Wissensgraphen verknüpft. Die Lösung adressiert ein wachsendes wirtschaftliches Risiko: Cyberangriffe verursachen hohe Schäden, betreffen einen Großteil der Unternehmen und werden zunehmend arbeitsteilig organisiert. Für Unternehmen und Behörden entsteht ein praktischer Nutzen durch einheitliche Begriffe,……
-
AI-powered cyber attacks may be just months away, warn Five Eyes
Frontier AI models will pose a greater cyber security risk to government and businesses than previously thought, putting businesses and governments at risk within months First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366644997/AI-powered-cyber-attacks-may-be-just-months-away-warn-Five-Eyes
-
New AI Model Aims to Transform Behavioral Health
Nick Allen of Ksana Health on ARPA-H-Funded Effort to Predict Mental Health Risk. A new AI-powered large health behavior model could help detect mental health and substance use risks before crises occur, said Nick Allen of Ksana Health, which is leading the ARPA-H funded effort to combine wearable, smartphone and health record data for earlier…
-
Diese zehn CTI-Irrtümer machen Unternehmen angreifbarer, als sie glauben
Tags: riskDazu kommt ein strukturelles Risiko: CTI-Analysten gehören zu den gefragtesten und zugleich am stärksten belasteten Fachkräften in der Cybersecurity. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/diese-zehn-cti-irrtuemer-machen-unternehmen-angreifbarer-als-sie-glauben/a45556/
-
Novo Nordisk Breach Highlights Software Development Pipeline Risk
A leaked GitHub token underscores what most organizations get wrong: Treating secrets management as a tooling problem rather than an identity problem. First seen on darkreading.com Jump to article: www.darkreading.com/cyber-risk/novo-nordisk-breach-exposes-dev-pipeline-risk
-
Stop Your Legacy Infrastructure from Hijacking Your AI Agents
Earlier this month, I spoke at the Gartner Security & Risk Management Summit about a blind spot most security programs are still not accounting for – how attackers are circumventing AI security programs by using legacy infrastructure to hijack AI agents.AI adoption is moving faster than security programs can account for. Roughly 71% of organizations…
-
Novo Nordisk Breach Highlights Software Development Pipeline Risk
A leaked GitHub token underscores what most organizations get wrong: Treating secrets management as a tooling problem rather than an identity problem. First seen on darkreading.com Jump to article: www.darkreading.com/cyber-risk/novo-nordisk-breach-exposes-dev-pipeline-risk
-
usbliter8 Brings Unpatchable BootROM Exploit to Apple A12 and A13 Devices
usbliter8 is an unpatchable BootROM exploit affecting A12/A13 devices, enabling code execution and extending checkm8-like risks to newer iPhones. Security researchers at Paradigm Shift published a working exploit on June 18, 2026, called usbliter8, that achieves arbitrary code execution inside the SecureROM of Apple’s A12 and A13 chips. SecureROM is the first code that runs…
-
Cyberangriffe gegen die Zivilgesellschaft Muster, Eskalation und strukturelle Risiken
Der aktuelle Report on Cyberattacks against Civil Society 2026 zeigt mit ungewöhnlicher Klarheit, wie stark zivilgesellschaftliche Organisationen weltweit unter digitalem Beschuss stehen [1]. Die Daten aus dem Project”‘Galileo”‘Programm, das mehr als 3.400 Domains in 120 Ländern schützt, belegen eine deutliche Verschärfung der Bedrohungslage: Angriffe sind häufiger, länger, gezielter und technisch ausgereifter als in den Vorjahren….…
-
Wer nutzt wirklich Ihre Internetverbindung zu Hause?
Ihre Heimverbindung könnte den Verkehr für Fremde leiten. So funktionieren Wohn-Proxy-Netzwerke, wie Geräte registriert werden und was unsere Telemetrie über die Risiken für Verbraucher aufzeigt. Management Summary Kernaussage: Wohn-Proxy-Netzwerke machen private Haushaltsanschlüsse zur kommerziellen Infrastruktur für Dritte. Was für Marktforschung, Werbeprüfung oder Sicherheitstests legitim genutzt werden kann, wird zunehmend auch für Phishing, Malware-Verteilung, Betrug, Scraping……
-
Quantensouveräne KI vom kritischen Risiko zur vertrauenswürdigen Lösung
KEEQuant, Collaider und noris network demonstrieren ein souveränes KI-Modell, das quantengesicherte Kommunikation, vertrauenswürdige deutsche Infrastruktur und anwendungsbereite KI für vertraulichkeitssensible Anwendungsfälle kombiniert. Viele Organisationen möchten KI für ihre eigentliche Arbeit nutzen, schrecken jedoch davor zurück, wenn sensible Informationen unter einem herkömmlichen Cloud-Modell ihre Umgebung verlassen müssen. Fragen rund um Vertraulichkeit, Governance und langfristige Datenexposition… First…
-
The Cyber Express Weekly Roundup: Cybersecurity Weekly Round on Emerging Threats, Data Breaches, and Global Policy Shifts
This week’s weekly roundup of cybersecurity developments highlights an expanding intersection of cyber risk, regulatory action, and enterprise vulnerability. Across healthcare, technology platforms, gaming companies, and government policy, organizations continue to confront a rapidly evolving cybersecurity landscape where data exposure, advanced intrusion tactics, and platform security failures are interconnected. First seen on thecyberexpress.com Jump to article: thecyberexpress.com/tce-weekly-roundup-global-threats/
-
CVE-2026-48907 and LiteSpeed cPanel Plugin Flaws Come Under Active Attack
Security researchers and software vendors warn that attackers are actively exploiting vulnerabilities in both Joomla and the LiteSpeed cPanel plugin, posing significant risks to website administrators and shared hosting environments. First seen on thecyberexpress.com Jump to article: thecyberexpress.com/cve-2026-48907-joomla-jce-litespeed-cpanel/
-
Meteor 3.0 Migration Helped Rocket.Chat Move Off EndLife Node.js Runtime
Meteor 3.0 helped Rocket.Chat move from Node.js 14 to Node.js 20, cutting runtime debt after Fibers removal and reducing supply-chain risk across federal users. First seen on hackread.com Jump to article: hackread.com/meteor-3-0-migration-rocket-chat-node-js-runtime/
-
New OpenAI Method Forecasts AI Risks Before Deployment
New Evaluation Method Predicts Harmful AI Behavior Before Launch. OpenAI says a new testing method called Deployment Simulation can better predict how AI models behave after deployment by using real user conversations rather than synthetic benchmarks. But researchers found models often detect when they are being tested, raising questions about the reliability of traditional safety…
-
24B Records Exposed in Massive Leak of Emails, Passwords, and Login Data
Cybernews researchers found an exposed database with 24 billion credential records, raising fresh risks from password reuse and credential stuffing. The post 24B Records Exposed in Massive Leak of Emails, Passwords, and Login Data appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-24-billion-credential-records-exposed-database/
-
Critical Chrome Extension Vulnerabilities Let Attackers Easily Compromise Browsers
A critical security flaws in widely used Chrome extensions, exposing millions of users to the risk of full browser compromise. The vulnerabilities, named >>MaXSS<>Spyder,<< affect popular AI-powered extensions SiderAI and MaxAI, which together have more than 10 million installations across Chrome and other Chromium-based browsers. These issues transform these convenience-oriented AI helpers into […] The…
-
State Digital Surveillance Puts Foreign Travelers and Businesses at Risk Across 31 Countries
A new state-surveillance assessment finds that foreign travelers and business staff face high or very high digital risk in 31 countries, where governments increasingly use telecom interception, spyware, AI-enabled monitoring, and data aggregation with little meaningful oversight. The concern is not just espionage in the classic sense; it is the routine conversion of travel, communications,…
-
Supplier risk has become a business resilience problem
First seen on scworld.com Jump to article: www.scworld.com/perspective/supplier-risk-has-become-a-business-resilience-problem
-
Novo Nordisk Breach Exposes Software Development Pipeline Risk
A leaked GitHub token underscores what most organizations get wrong: Treating secrets management as a tooling problem rather than an identity problem. First seen on darkreading.com Jump to article: www.darkreading.com/cyber-risk/novo-nordisk-breach-exposes-dev-pipeline-risk
-
6 Ways to Contain Enterprise Risk in Model Context Protocol
Understand Agentic AI Risks and Secure All MCP Deployments MCP has rapidly become the connective tissue of the agentic AI era and the standard for connecting AI agents to enterprise systems. But it also introduces new attack vectors, from tool poisoning to prompt injection. Here are six ways to reduce the risk. First seen on…
-
Are Job Search Platforms Putting Your Data at Risk?
A new Incogni study found that many job-search platforms sell candidate data and use AI tools that raise privacy concerns. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/are-job-search-platforms-putting-your-data-at-risk/
-
Gulf CIOs shift focus from recovery to cyber resilience as regional threats intensify
Commvault’s Yahya Kassab says organisations across the Gulf are reassessing recovery strategies, AI risks and cloud investments amid growing cyber threats First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366644877/Gulf-CIOs-shift-focus-from-recovery-to-cyber-resilience-as-regional-threats-intensify
-
Digitale Souveränität ist mehr als eine Standort-Frage
Daten in Europa zu speichern macht Unternehmen noch lange nicht digital souverän. Im Gespräch mit Netzpalaver erläutert Pantelis Astenburg, Vice President of Sales DACH bei Versa, warum echte digitale Souveränität weit über den Speicherort von Daten hinausgeht, welche Rolle SASE-Architekturen für Sicherheit und Compliance spielen und weshalb Unternehmen angesichts von NIS2, DORA und geopolitischen Risiken…
-
Orphaned AI Agents: How to Find Hidden Access Risks Inside Your Network
If an autonomous AI agent interacts with your company’s core intellectual property today, can your security team instantly name the person who authorized it?For most enterprises, the answer is a simple no.The rush to adopt internal AI tools has left a massive trail of administrative debt: orphaned agents (AI tools left running after their creator…
-
The safe VMS choice may be the one creating more risk
Tags: riskFirst seen on scworld.com Jump to article: www.scworld.com/perspective/the-safe-vms-choice-may-be-the-one-creating-more-risk

