Anthropic widens access to AI cyber capabilities for vetted security teams
Anthropic is expanding its Cyber Verification Program to give more security teams access to advanced cyber capabilities with reduced safeguards on its most advanced AI models. The expanded program has...
View ArticleDenmark’s national ID system breach exposes personal data of 8.8M
Denmark is reviewing security controls around its national citizen registry after unauthorized parties exploited a company’s access credentials to harvest records on approximately 8.8 million people...
View ArticleEncrypted instructions trick Copilot CLI into spilling developer secrets
GitHub Copilot CLI can be made to read sensitive files from a developer’s machine and send their contents to an attacker from a single web page. Security researchers at Adversa AI said the new attack...
View ArticleYour enterprise doesn’t need six BOM programs. It needs one evidence graph
In infrastructure and security programs, I have watched visibility projects follow a familiar path. The first dashboard feels like progress. Then the data grows, ownership blurs and the team discovers...
View ArticleAI is turning offensive security into a continuous necessity
The rise of AI has CISOs facing even more vulnerabilities than ever, resulting in increasingly difficult decisions around what fixes to prioritize. “When I was a CIO, the hardest part of my job was...
View ArticleAtlassian’s critical flaw turns eight enterprise products into one big...
A newly-disclosed critical flaw in Atlassian’s data center software has a remarkably wide reach, affecting eight core products across the company’s enterprise portfolio. CVE-2026-21589, rated 9.3...
View ArticleFBI removes contractor working with its PeopleSoft system after data breach,...
The US Federal Bureau of Investigation has removed an Accenture contractor working on its PeopleSoft installation over their role in a data breach that exposed personal details of FBI employees,...
View ArticleNew Linux malware turns vulnerable IoT devices into proxy nodes
A new Linux backdoor is turning vulnerable internet-facing devices into remotely controlled proxy nodes, while using the public Session Traversal Utilities for NAT (STUN) infrastructure to blend into...
View ArticlePacing the AI frontier won’t solve agentic cybersecurity’s most urgent problems
When Anthropic CEO Dario Amodei urged other leading AI labs to “pace the frontier” last week, his calls for caution were echoed by other prominent voices in tech. Both Sam Altman and Elon Musk agreed...
View ArticleGoogle’s bug bounty pause highlights growing AI vulnerability triage challenge
AI is accelerating the discovery of software vulnerabilities, but it is also creating a new bottleneck for defenders: deciding which machine-generated findings warrant investigation. Google has...
View ArticleThe AI app builder your team trusts has a root-level backdoor
The fastest-growing category of enterprise software right now is also the least scrutinized from a security standpoint. AI application platforms — tools that let teams build, connect and automate...
View ArticleWhat exactly is ISOC? And what does it mean for you?
Gartner recently released a new category of security tools: the Integrated Security Operations Center (ISOC). This new category acknowledges the need to expand beyond traditional SIEM tools in the...
View ArticleAI accelerates n-day attacks, as flaw disclosures and exploits double
Attackers are increasingly weaponizing already-disclosed flaws rather than new zero-days, and AI tools may be accelerating how quickly they do it. According to a report from Google’s Threat...
View ArticleDell patches 18 critical flaws that could hand attackers the keys to storage...
Dell’s security team has had a busy week. The company has announced a slew of Common Vulnerabilities and Exposures (CVEs) impacting its Dell Container Storage Modules (CSM) and Dell System Update...
View ArticleDespite ShinyHunters arrests after FBI jobs data breach, enterprises still...
The theft of FBI employee data by hacking group ShinyHunters, and the subsequent shutdown of the FBI’s Peoplesoft-based jobs portal, is causing concern for enterprise users of the Oracle product, with...
View ArticleCitrix warns of actively exploited NetScaler flaw days after zero-day patch rush
Citrix has warned customers about another high-severity vulnerability in its NetScaler ADC and NetScaler Gateway products, just days after the company urged them to fix a separate batch of flaws that...
View ArticleShould the CISO role be split in two?
In its roughly 30-year history, the CISO role has been reshaped by waves of new technology and rising cyber threats. In many organizations, CISOs now own risk reporting, information risk management,...
View ArticleRolling the cyber dice with open-source and open-weight AI models
With typical cybersecurity exposure, I can conduct pen testing with deterministic tools. I am able to predict how a piece of software is going to respond. I even stand a decent chance of finding...
View ArticleEU Cyber Resilience Act ‘completely kills’ manual vulnerability triage
Independent security experts see the EU Cyber Resilience Act (CRA) reshaping international technology markets to emphasize cyber resilience from the ground up, thereby testing the operational...
View ArticleGoogle makes Gemini 4 AI model available to a trusted few
Google has unveiled a new frontier AI model after months of delay. Gemini 4 Argon is designed to handle complex, long-horizon workloads spanning software engineering, enterprise knowledge work such as...
View Article