Quantcast
Channel: CSO Online
Browsing index pages (3346 articles)
↧

Anthropic widens access to AI cyber capabilities for vetted security teams

Anthropic is expanding its Cyber Verification Program to give more security teams access to advanced cyber capabilities with reduced safeguards on its most advanced AI models. The expanded program has...

View Article


Denmark’s national ID system breach exposes personal data of 8.8M

Denmark is reviewing security controls around its national citizen registry after unauthorized parties exploited a company’s access credentials to harvest records on approximately 8.8 million people...

View Article


Encrypted instructions trick Copilot CLI into spilling developer secrets

GitHub Copilot CLI can be made to read sensitive files from a developer’s machine and send their contents to an attacker from a single web page. Security researchers at Adversa AI said the new attack...

View Article

Your enterprise doesn’t need six BOM programs. It needs one evidence graph

In infrastructure and security programs, I have watched visibility projects follow a familiar path. The first dashboard feels like progress. Then the data grows, ownership blurs and the team discovers...

View Article

AI is turning offensive security into a continuous necessity

The rise of AI has CISOs facing even more vulnerabilities than ever, resulting in increasingly difficult decisions around what fixes to prioritize. “When I was a CIO, the hardest part of my job was...

View Article


Atlassian’s critical flaw turns eight enterprise products into one big...

A newly-disclosed critical flaw in Atlassian’s data center software has a remarkably wide reach, affecting eight core products across the company’s enterprise portfolio. CVE-2026-21589, rated 9.3...

View Article

FBI removes contractor working with its PeopleSoft system after data breach,...

The US Federal Bureau of Investigation has removed an Accenture contractor working on its PeopleSoft installation over their role in a data breach that exposed personal details of FBI employees,...

View Article

New Linux malware turns vulnerable IoT devices into proxy nodes

A new Linux backdoor is turning vulnerable internet-facing devices into remotely controlled proxy nodes, while using the public Session Traversal Utilities for NAT (STUN) infrastructure to blend into...

View Article


Pacing the AI frontier won’t solve agentic cybersecurity’s most urgent problems

When Anthropic CEO Dario Amodei urged other leading AI labs to “pace the frontier” last week, his calls for caution were echoed by other prominent voices in tech. Both Sam Altman and Elon Musk agreed...

View Article


Google’s bug bounty pause highlights growing AI vulnerability triage challenge

AI is accelerating the discovery of software vulnerabilities, but it is also creating a new bottleneck for defenders: deciding which machine-generated findings warrant investigation. Google has...

View Article

The AI app builder your team trusts has a root-level backdoor

The fastest-growing category of enterprise software right now is also the least scrutinized from a security standpoint. AI application platforms — tools that let teams build, connect and automate...

View Article

What exactly is ISOC? And what does it mean for you?

Gartner recently released a new category of security tools: the Integrated Security Operations Center (ISOC). This new category acknowledges the need to expand beyond traditional SIEM tools in the...

View Article

AI accelerates n-day attacks, as flaw disclosures and exploits double

Attackers are increasingly weaponizing already-disclosed flaws rather than new zero-days, and AI tools may be accelerating how quickly they do it. According to a report from Google’s Threat...

View Article


Dell patches 18 critical flaws that could hand attackers the keys to storage...

Dell’s security team has had a busy week. The company has announced a slew of Common Vulnerabilities and Exposures (CVEs) impacting its Dell Container Storage Modules (CSM) and Dell System Update...

View Article

Despite ShinyHunters arrests after FBI jobs data breach, enterprises still...

The theft of FBI employee data by hacking group ShinyHunters, and the subsequent shutdown of the FBI’s Peoplesoft-based jobs portal, is causing concern for enterprise users of the Oracle product, with...

View Article


Citrix warns of actively exploited NetScaler flaw days after zero-day patch rush

Citrix has warned customers about another high-severity vulnerability in its NetScaler ADC and NetScaler Gateway products, just days after the company urged them to fix a separate batch of flaws that...

View Article

Should the CISO role be split in two?

In its roughly 30-year history, the CISO role has been reshaped by waves of new technology and rising cyber threats. In many organizations, CISOs now own risk reporting, information risk management,...

View Article


Rolling the cyber dice with open-source and open-weight AI models

With typical cybersecurity exposure, I can conduct pen testing with deterministic tools. I am able to predict how a piece of software is going to respond. I even stand a decent chance of finding...

View Article

EU Cyber Resilience Act ‘completely kills’ manual vulnerability triage

Independent security experts see the EU Cyber Resilience Act (CRA) reshaping international technology markets to emphasize cyber resilience from the ground up, thereby testing the operational...

View Article

Google makes Gemini 4 AI model available to a trusted few

Google has unveiled a new frontier AI model after months of delay. Gemini 4 Argon is designed to handle complex, long-horizon workloads spanning software engineering, enterprise knowledge work such as...

View Article
Browsing index pages (3346 articles)


Latest Images