<p>As Anthropic’s Mythos model makes clear, AI is a cybersecurity game changer. When released in preview, Mythos proved unexpectedly effective in finding and exploiting bugs in software. Anthropic said the preview release found more than 10,000 critical vulnerabilities across every…
Category: Search Security Resources and Information from TechTarget
Behavioral biometrics: How to detect non-human threat actors
<p>As Anthropic’s Mythos model makes clear, AI is a cybersecurity game changer. When released in preview, Mythos proved unexpectedly effective in finding and exploiting bugs in software. Anthropic says the preview release found more than 10,000 critical vulnerabilities across every…
Employees’ shadow AI use is poorly monitored, survey finds
<p>Despite cybersecurity professionals’ best efforts to protect their organizations’ networks and data, employees have long been the weak link in the chain. They click malicious links in emails, reuse weak passwords, share sensitive information and make other mistakes that threat…
Industry reacts to Gold Eagle vulnerability management plan
<p>The tech industry is cautiously optimistic about the U.S. government’s announcement this week to create a centralized clearinghouse for AI-discovered vulnerabilities. The key, executives and analysts said, will be how well the new initiative executes on its mission to collect…
Why CISOs should automate SBOM management with AI
<p>Modern software runs on open source. Nearly all codebases — 98% — contain open source code, according to a 2026 <a target=”_blank” href=”https://www.blackduck.com/content/dam/black-duck/en-us/reports/rep-ossra.pdf” rel=”noopener”>report</a> from cybersecurity vendor Black Duck, which scanned 947 codebases and analyzed nearly 3,000 individual projects between…
How mapping security controls can ease the compliance burden
<p>CISOs and their teams are expected to demonstrate compliance with a range of regulations, frameworks and standards. With an alphabet soup of frameworks — NIST, ISO, PCI DSS, HIPAA, GDPR and many other country- or sector-specific mandates — there is…
Why CISOs should use zero-trust security for IoT
<p>IoT is meant to drive operational efficiency and improve decision-making, largely by automating processes and reducing overall costs. But with these benefits come escalating cybersecurity <a href=”https://www.techtarget.com/iotagenda/tip/5-IoT-security-threats-to-prioritize”>threats that target IoT devices</a>, which are notoriously vulnerable compared to traditional IT infrastructure.</p>…
Building cyber-resilient AI in the enterprise
<p>Enterprise AI deployments are scaling faster than any software category in history, now commanding 6% of the $300 SaaS market, according to venture capital firm Menlo Ventures. Meanwhile, McKinsey & Company has reported that 88% of businesses have applied AI…
Why conversational AI is redefining your security perimeter
<p>As enterprises race to deploy AI across their operations, a perfect storm is brewing: New AI-generated attack vectors are colliding with employees’ growing emotional trust in chatbots and AI assistants, creating security blind spots that traditional defenses weren’t designed to…
ClickFix and removable media lead malware delivery methods
<p>When it comes to malware delivery methods, attackers are sticking with what works — even as they rely on a rapidly revolving door of payloads.</p> <p>That’s according to a report from the ReliaQuest Threat Research Team, which tracks threat activity…
Edtech gets schooled by third-party cyberthreats
<p>In the education sector, cybersecurity controls and third-party risk management get put to the test — and frequently don’t get a passing grade.</p> <p>Academic organizations might not seem like prime targets for cyberattacks, but these data-rich — and security-insufficient —…
Common MFA mistakes — and how to fix them
<p>MFA has long been one of the most effective security controls an organization can deploy. It’s inexpensive compared to many security technologies, relatively easy to implement and capable of stopping a large percentage of credential-based attacks.</p> <p>It’s not a coincidence…
How to operationalize threat modeling with AI
<p>Effective threat modeling — where security architects review system design, enumerate threats and mitigations, validate controls and map the attack surface of a system — is critical to secure software but can be complex and time-consuming.</p> <p>This guidance explains how…
CISO’s guide to hiring for the right cybersecurity skills
<p>The cybersecurity talent crisis has moved from a simple numbers problem to a fundamental mismatch between what organizations need and what the workforce can deliver.</p> <p>While 87% of organizations plan to expand their security teams this year, according to Fortinet…
First fully agentic ransomware attack sparks readiness concerns
<p>The latest cyberattack headlines leave security leaders asking a critical question: Does an AI agent’s successful execution of an end-to-end ransomware attack signal a fundamental shift in threat response strategies, or does it simply underscore the enduring importance of cybersecurity…
Evaluating secure enterprise browsers vs. security plugins
<p>Whether hosted in-house or in the cloud, the web browser serves as the gateway to most enterprise work, making it a crucial consideration in any enterprise security strategy.</p> <p>The current AI frenzy puts an even brighter spotlight on browser security.…
The AI vulnerability storm is here: Is your security program ready?
<p>Emerging frontier AI models, such as Anthropic’s Claude Mythos, are dramatically accelerating vulnerability discovery and exploitation, shrinking the window between a software flaw’s discovery and its weaponization to mere hours.</p> <p>In just a few months, Mythos has discovered <a href=”https://www.techtarget.com/searchsecurity/news/366643606/First-month-of-Mythos-Preview-testing-exposes-10K-flaws”>thousands…
Perimeter to posture: A roadmap to zero trust maturity
<p>As cybersecurity threats intensify and perimeter-based security models continue to fail, organizations must adopt zero trust as a strategic, long-term approach to reducing risk and improving resilience surrounding cloud adoption, hybrid work and supply-chain exposure.</p> <p>CISOs and IT decision-makers need…
TLS certificate lifetime changes: What CISOs must do now
<p>Organizations that rely on manual TLS certificate lifecycle management are racing against the clock. The 200-day certificate timeline, which took effect in March 2026, means the first wave of certificate renewals will arrive within a matter of months.</p> <p>”People will…
The agentic AI ‘lethal trifecta’: What CISOs should know
<p>By now, every CISO has probably heard the phrase <i>lethal trifecta</i> tossed around in AI security discussions. The term refers to a combination of three agentic AI properties that, together, make agents vulnerable to attack and put the enterprises using…
