262 publications
Recent unauthorized access incidents involving frontier AI models emphasize the necessity of rigorous testing environment isolation. By implementing strict configuration controls and continuous monitoring, organizations can safely evaluate agentic models without exposing external systems.
Recent data indicates that AI-generated patches successfully resolve vulnerabilities less than half the time, often introducing new defects. Security teams can maintain the productivity benefits of AI by pairing generation tools with rigorous human validation and formal verification.
Security experts at Black Hat USA 2026 outlined how AI and affiliate models are enabling threat actors to scale their operations, requiring a more cohesive, structural response from law enforcement and the security community.
Former and current security leaders from the Democratic National Committee share how they established a resilient security culture, focusing on hardware keys, cloud infrastructure, and executive co-ownership.
Security researchers presented a proof-of-concept methodology at Black Hat USA 2026 for bypassing ChatGPT's large language model supervisor. The findings outline a sequence for executing background processes and transferring data between isolated sandboxes, prompting architectural updates by OpenAI.
Security researchers have identified a new class of vulnerabilities in AI browsers that allows everyday content to manipulate agent actions. Protecting users requires a shift in how organizations configure trust boundaries and limit agent permissions.
An analysis of the eighth annual Omdia and ISSA study, examining how organizational design, leadership models, and technology consolidation directly impact security team resilience and effectiveness.
Recent industry data indicates that elevated stress among cybersecurity professionals stems from organizational design rather than purely staffing shortages. By aligning accountability with authority and integrating technology stacks, organizations can improve operational resilience and better support their security leaders.
As organizations work to secure legacy physical infrastructure, security researchers are observing the development of autonomous software agents capable of reasoning and lateral movement. This convergence requires security teams to adopt foundational defenses and increase remediation velocity to protect both operational technology and cloud environments.
A new executive order establishes a voluntary early-access framework for frontier AI models and directs federal agencies to support civilian and national security cybersecurity programs. For security practitioners, the directive signals an upcoming influx of vulnerability data and emphasizes the need to reinforce defensive fundamentals and integrate AI tools into existing workflows.
Security researchers have demonstrated proof-of-concept AI worms capable of autonomous propagation and reasoning. By understanding these emerging methods, organizations can implement foundational safeguards like zero-trust architecture and micro-segmentation to protect their infrastructure.
Following a joint advisory from US federal agencies, we review the operational risks associated with internet-facing automatic tank gauge (ATG) systems and provide actionable remediation steps to safeguard critical industrial environments.
Security researchers have detailed an ongoing espionage campaign by the SideCopy threat group targeting Afghanistan's Ministry of Finance. This assessment outlines the threat actor's methodology, including their use of localized decoys and compromised sovereign infrastructure to deploy remote access tools.
Analysts at the 2026 Gartner Security & Risk Management Summit identified deepfakes, software supply chain risks, prompt injections, and AI application compromises as pressing areas where threat actors currently hold an advantage. By implementing layered authentication, strict access controls, and regular security assessments, organizations can effectively safeguard their systems against these vectors.
Security researchers have identified IronWorm, a custom Rust-based malware sample designed to compromise npm publishing workflows and harvest developer secrets. By understanding its evasion techniques and targeting methods, security teams can better protect continuous integration environments and software supply chains.
Security researchers recently identified a prolonged unauthorized access campaign targeting a senior executive at a global stock exchange. By analyzing the threat actor's methodology, organizations can better understand how to protect their cloud environments and implement effective detection strategies.
SafeBreach researchers demonstrated how untrusted input in messaging notifications could allow unauthorized parties to bypass Google Gemini’s guardrails. Following responsible disclosure, Google has issued content classifier updates to block these indirect prompt injections.
A debug setting left enabled in a shared Microsoft Android SDK bypassed authentication checks, allowing unauthorized applications to request sensitive FOCI tokens. Microsoft has patched the affected applications, and organizations should ensure their mobile fleets are updated.
While cyber insurance premiums are becoming more affordable, carriers are simultaneously introducing strict coverage exclusions and sub-limits. Organizations must carefully review their policies to ensure continuous protection against social engineering, state-backed incidents, and mass outages.
A review of recent cyber operations targeting government and critical infrastructure sectors in the Americas, driven by geopolitical shifts. This analysis outlines the observed access methods, including identity-based vectors and edge device targeting, alongside prioritized remediation steps for security teams.
Recent findings show threat actors using AI tools to iteratively test unauthorized software against common endpoint detection and response (EDR) agents. While this automated methodology increases the speed of adversary research, organizations can protect their environments by maintaining foundational security practices like defense-in-depth and modern authentication.
A technical review of emerging access methodologies, including device code phishing and traffic distribution systems, alongside updates on PAN-OS vulnerabilities and the integration of AI in security workflows. Provides actionable remediation steps for defending identity and edge infrastructure.
A vulnerability in Palo Alto Networks' PAN-OS GlobalProtect VPN allows unauthorized parties to bypass authentication using forged cookies. Organizations should apply the vendor-supplied patch or adjust certificate configurations immediately to protect their network access.
Recent friction between Microsoft and independent security researchers illustrates the complexities of vulnerability disclosure. As AI-generated reporting increases triage workloads, maintaining clear, collaborative disclosure pathways remains essential for protecting users and systems.
The European Union is finalizing an agreement with Anthropic to provide ENISA with access to the Mythos AI model for security research. The partnership aims to help defenders understand and mitigate the risks associated with AI-accelerated vulnerability discovery.
As organizations rapidly adopt agentic AI, security teams face the challenge of governing models that possess high autonomy and system access. By implementing continuous discovery, security posture management, and behavioral detection, enterprises can safely integrate AI agents while protecting critical infrastructure.
An evaluation of Operation Dragon Weave, a spear-phishing campaign that deploys Rust-based loaders and utilizes Azure Blob Storage for command-and-control. This analysis details the deployment methods and provides actionable guidance to help security teams protect their environments.
Security researchers have identified an industrialized operation known as DriveSurge that compromises legitimate websites to distribute unauthorized software. Organizations can protect their environments by monitoring outbound traffic, evaluating JavaScript configurations, and educating users on social engineering tactics.
The Kali365 phishing-as-a-service platform has evolved from its initial focus on Microsoft 365 into a broader identity threat tool targeting AWS and major messaging services. This analysis details the mechanics of OAuth device code phishing and provides actionable guidance for securing organizational environments against these techniques.
An analysis of how digital security directly influences physical safety, spanning regional risk trends in APAC, non-human identity management in cloud architectures, and the emerging challenges of embodied AI. Organizations can use these findings to strengthen identity governance and memory management.