Quantcast
Channel: CSO Online
Browsing index pages (3294 articles)

After spending billions, OpenAI still has gaps in its cybersecurity

Two separate reports of security flaws in OpenAI systems highlight how even a company spending billions on developing its own AI-powered cybersecurity testing tools remains vulnerable. In one...

View Article


New npm malware finds a way around install script defenses

Blocking suspicious install scripts may no longer be enough to mitigate threats from malicious JavaScript dependencies used in software supply-chain attacks. Security researchers at Checkmarx are...

View Article


Orchid Security Introduces AI Agent Readiness Controls Featuring Continuous...

Readiness tagging for AI, always-on observability, and coordinated kill switches at the application layer give enterprises a defensible route to scaling agents while keeping authority in human hands....

View Article

Revoking the token didn’t kill the backdoor

Every identity-compromise runbook I have written, read or inherited has the same step near the top: revoke the tokens. Reset the password, kill the sessions, invalidate the refresh tokens, then go...

View Article

5 ways AI is reshaping the cybersecurity job market

Mario Platt spent part of last year eliminating a team. As CISO for online password management service LastPass, he shut down the company’s dedicated vulnerability management function in late 2025,...

View Article


CISA is ending its monthly vulnerability bulletin

The rise in AI-generated security threats may just have generated one casualty: the death of the weekly bulletin of security threats from the US Cybersecurity Infrastructure and Security Agency...

View Article

A zero-click RCE flaw in AI coding agents could have exposed enterprise systems

Popular AI coding agents such as OpenAI’s Codex, Anthropic’s Claude Code, Google’s Gemini CLI, and Microsoft-owned GitHub Copilot were vulnerable to a zero-click attack that enabled attackers to...

View Article

GhostCode attackers abuse device codes to take over Microsoft 365 accounts

Microsoft 365 users are being tricked into handing over access to their accounts by a new phishing kit, GhostCode, that exploits a weakness in a legitimate device authorization flow. Researchers in...

View Article


Strong fundamentals make next-gen security possible

Risk management has always been a difficult job, but the current threat landscape has taken the challenge to a new level. I’ve spent years leading cybersecurity efforts at large enterprises, including...

View Article


Cisco patches max-severity ISE flaw, the second critical zero-day this week

Cisco released patches for an actively exploited authentication bypass vulnerability in its Cisco Identity Services Engine (ISE) platform, which is used for enterprise network access control and...

View Article

OpenAI admits six new misalignment incidents under new reporting framework

OpenAI has published six new reports detailing AI model misalignment, including instances of hidden instructions, unauthorized communication, and attempts to locate exposed API keys, adding to the...

View Article

Security spending is growing — except for the typical CISO

Security budgets may be growing on paper, but for a majority of CISOs, the money isn’t moving in quite the same direction. The budgets grew by 5% on average in 2026, up from 4% last year. But that...

View Article

Self-modifying AI agents expose a blind spot in enterprise security

As debate over AI safety intensifies, new research is drawing attention to a more immediate risk for enterprises: AI agents that can alter the models they rely on while carrying out routine tasks....

View Article


16 governance tools for securing your AI fleet

Every DevOps team member knows that dealing with an AI is like being a circus lion tamer. The boss and the audience are happy when the lions sit on the pedestal and roar on cue, but there’s always the...

View Article

LinkedIn fights for the right to tell customers when the feds want their data

Microsoft’s top lawyer argued Tuesday that legislators “must make secrecy [orders] the exception” in government subpoenas demanding information about LinkedIn users. LinkedIn, which is owned by...

View Article


Big Tech’s AI safety rift signals disruption and disparity for enterprises

A growing divide among leading AI companies over how to secure increasingly powerful models is beginning to translate into challenges for enterprise IT, with implications for how organizations access,...

View Article

Oracle’s September patches put Fusion Middleware back in the hot seat

Oracle’s September 2026 Critical Security Patch Update has arrived with 673 new security patches spanning 17 Oracle product families, with Oracle E-Business Suite accounting for the largest share at...

View Article


AI agent authorization risks remain a gap in new NIST-CISA token security...

AI agents’ actions are out of scope for new guidance from US authorities on securing identity and access tokens, but there is still plenty enterprises can do to protect their systems from rogue humans...

View Article

You don’t have to join the hack-back program to inherit its risk

The obvious question about Washington’s new private offensive cyber program is which security vendors will join it. The CSO question is what happens to you when one of your vendors does. The August 12...

View Article

AI made software development unrecognizable. Is cybersecurity next?

The rapid emergence of AI has radically changed a host of professions, with software engineering and development perhaps the most transformed of all pursuits. The usual “solitary ritual” of a...

View Article
Browsing index pages (3294 articles)


Latest Images