Giving AI Freedom Without Losing Control Who’s Really in Control? AI agents are stepping into a bigger role inside the enterprise. They are not just…
58 Arrested, 263 Suspects Identified: Inside the Global Crackdown on Operation Jackal IV
The Foundation Operation Jackal INTERPOL has been spearheading a continuing, multi-year international law enforcement effort known as Operation Jackal to…
The Balance Of Healthcare Research Potential And Privacy In The Age Of AI
There’s no question that AI has transformed healthcare research and completely changed the trajectory of the healthcare industry. What would have taken…
Innovator Spotlight: Rubrik Zero Labs
When AI Breaks Out of the Sandbox What Happens When AI Escapes? AI assistants are gaining unprecedented access to the inner workings of businesses, but…
Friday Squid Blogging: Truckload of Squid Spills in Rhode Island
Ugh : A tractor-trailer rollover sent a truckload of squid spilling into a Rhode Island roadway, leaving a stench as they sat in the road for hours in the…
The Artificial Adversary
Cybersecurity has spent decades focused on the human adversary. We built models for nation-state actors, cybercriminal gangs, insiders, access brokers,…
The Department of Know: Power plant attack, NSA hacker reunion, Hugging Face hack report
Read the full stories at CISOSeries.com . This week’s Department of Know is hosted by Rich Stroffolino, with guests Jason Elrod , CISO, MultiCare Health…
White House Declares Executive Order to Protect Bulk-Power System
National Emergency Declaration for Grid Security White House released Executive Order 14420, which targets security risks within the nation’s bulk-power…
Researcher shows how Claude Code can be tricked simply by asking it to summarize a website
More prompt-injection hijinks from wunderwuzzi
Cosmos EVM Flaw Exploited After Cosmos Labs Knew Every Blockchain Running It Was Vulnerable
Cosmos Labs has warned that a critical balance-handling flaw in the shared Cosmos EVM module was exploited to drain funds from six blockchains between…
Love Electric Breach: 877,000 Driver Records Offered for $600
Love Electric’s alleged data breach exposes sensitive driver data and highlights the identity risks created by third-party salary sacrifice providers. A…
Anthropic MHS Lets AI Agents Control Machines, Raising Security Questions
Anthropic’s Model Hardware Standard lets AI agents control physical equipment, raising questions about permissions, monitoring and operational security.
The Imperfect SOC: How Security Teams Can Defend Without a Dream Team
Lean SOC teams can use explainable and agentic AI to reduce alert fatigue, scale analyst expertise, automate investigations, and improve security…
PaperCut Flaw Under Active Attack Enables Pre-Auth RCE
Attackers are exploiting a PaperCut flaw that enables pre-authentication remote code execution.
Skimming on the Blockchain: A Magecart Campaign That Uses EtherHiding, Found by Malvertising Scanning
One attacker wallet, 144 smart contracts, and 40+ compromised e-commerce checkouts quietly stealing shoppers’ card data.
Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them
Hackers are making some phishing pages harder to track by changing the code delivered to every visitor. An examined operation served a credential-stealing…
Extend your data perimeter to the AWS Management Console with Private Access
Organizations in regulated industries such as financial services, government, defense, and healthcare restrict their sensitive workloads to isolated…
Trump Targets Foreign Technology in New U.S. Power Grid Security Order
Trump targets foreign-made power grid equipment, citing cyber, sabotage and supply-chain risks to U.S. national security. Executive Order 14420, signed on…
Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft
Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for remote code execution, credential theft, and…
Attackers Chain Two PaperCut Flaws to Execute Code Without Authentication
Malicious actors are exploiting a newly patched security flaw in PaperCut NG and MF to execute arbitrary code on susceptible instances, as the company…
Microsoft Teams Has Become a Haven for Scammers in China
Fraudsters are exploiting enterprise chat apps like Teams and Webex to trick Chinese victims into transferring large sums of money, fueling a wave of…
Android 17 Adds OS-Wide ECH to Hide Website Visits From Network Providers
Google on Thursday announced new network security protections in Android 17 to bolster connection privacy, address cellular vulnerabilities, and safeguard…
Cyberattack on Three UK Airports Exposes Data of 8.7 Million Customers
A cyberattack on Manchester Airports Group exposed information belonging to about 8.7 million customers across three UK airports.
ownCloud Flaw Exploited to Steal Nuclear Records From Philippine Research Body
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a critical security flaw impacting ownCloud to its Known Exploited…