Quantcast
Channel: CSO Online
Browsing index pages (3329 articles)
↧

Rolling the cyber dice with open-source and open-weight AI models

With typical cybersecurity exposure, I can conduct pen testing with deterministic tools. I am able to predict how a piece of software is going to respond. I even stand a decent chance of finding...

View Article


EU Cyber Resilience Act ‘completely kills’ manual vulnerability triage

Independent security experts see the EU Cyber Resilience Act (CRA) reshaping international technology markets to emphasize cyber resilience from the ground up, thereby testing the operational...

View Article


Google makes Gemini 4 AI model available to a trusted few

Google has unveiled a new frontier AI model after months of delay. Gemini 4 Argon is designed to handle complex, long-horizon workloads spanning software engineering, enterprise knowledge work such as...

View Article

Cisco SD-WAN Manager hit by zero-day admin access attack

Cisco’s SD-WAN management software has been letting some attackers walk through an authentication check without having to prove who they are. The company says it has now fixed the flaw that was...

View Article

Why AI agents are like the dog that pushed kids into the Seine

There is an interesting story about a French dog on the banks of the Seine river that helps us understand misbehaving AI agents. The dog is trained to save children from drowning. He succeeds and is...

View Article


Unsloth’s model picker had a code-execution problem

True to its name, AI-model-training tool Unsloth would do more work than it was asked to when developers checked out a model: It would also allow arbitrary code to execute on their machines. Pillar...

View Article

Image may be NSFW.
Clik here to view.

The MFA you have isn’t the MFA you think you have

For nearly a decade, multi-factor authentication has been the control every security leader points to when asked how they’ve reduced account takeover risk. It sits on almost every compliance checklist...

View Article

Image may be NSFW.
Clik here to view.

Can we jail a superintelligence?

AI containment is essential, but security leaders should assume every boundary can fail once an agent can communicate, use tools, and act on real systems. On September 17, podcaster Steven Bartlett...

View Article


Whatever happened to the 36-month IT security roadmap?

Insight Global’s John Dickson had a problem familiar to many CISOs today. Employees were embracing AI tools faster than his security team could track them, and new AI agents and service integrations...

View Article


OpenAI pulls the plug on GPT 6.1 Astra as agents keep crossing lines

OpenAI has scrapped the planned October release of GPT-6.1 Astra after internal testing found the model did not meet the company’s safety and alignment standards. GPT-6.1 Astra was being developed as...

View Article

Nvidia releases Open Agent Safety Platform to monitor and govern agentic AI

Nvidia on Monday rolled out an agentic governance system called the Open Agent Safety Platform that combines software with out-of-band DPU-based silicon in a reference system design that it says will...

View Article

OpenAI pauses AI model training after another agent bypasses network...

OpenAI has paused training, evaluation, and inference involving tool use for its most-capable AI models after an agent bypassed network restrictions to communicate with an external chatbot during...

View Article

Autonomous agents attack Azure using compromised identities, destroying...

Jadepuffer, an autonomous AI attacker first identified in July, has expanded into Azure environments, using compromised digital identities to enumerate resources, delete cloud assets and collect other...

View Article


NetScaler admins told to patch critical zero-days in ADC and Gateway now

Citrix NetScaler ADC and NetScaler Gateway users should take their systems offline and patch them immediately, they were told over the weekend, as news emerged of two critical unauthenticated remote...

View Article

Stolen AI credentials feed growing LLM proxy economy

Cyber threat groups have increasingly targeted enterprise AI assets, such as credentials, cloud environments, and research, as a means for operationalizing their own use of AI. Now, another...

View Article


AI tools help hacker break in for $25 per target

It’s cheap to set yourself up as a hacker these days using AI. Someone attacked 105 online retailers over a period of five days, compromising 27 of them — all for an average of $25 per attack,...

View Article

Documentation placeholder domain used in ClickFix attacks

The domain name third-party[.]com is being used to serve malware to users — bad news for those following a little too literally online documentation that uses it as a placeholder for any third-party...

View Article


GitLab issue email’s only security is obscurity

It was meant to make life simpler: a secret email address to which developers can send a message and create an issue in their GitLab project. But poor security defaults and a long-lived token embedded...

View Article

Fixing Flock: The controls needed now that misuse patterns are clear

Flock Safety has stirred widespread debate of late. Flock builds interconnected networks of automated license-plate readers and other public safety cameras. Those systems can help police solve serious...

View Article

WordPress patches a critical severity security vulnerability

WordPress has patched what it described as a critical severity security vulnerability that would allow an unauthenticated attacker full remote code execution (RCE) capabilities. There have already...

View Article
Browsing index pages (3329 articles)


Latest Images