Quantcast
Channel: CSO Online
Browsing index pages (3304 articles)

F5 fixes actively exploited zero-day flaw in BIG-IP APM

Technology company F5 fixed a critical remote code execution vulnerability in its BIG-IP Access Policy Manager (APM) platform on Tuesday. The flaw impacts deployments configured as OAuth authorization...

View Article


GitHub App keys can still enable takeovers long after they are forgotten

GitHub allows organizations to install GitHub Apps that automate and extend certain functionality on the platform and have access to selected repositories and permissions. But the private keys these...

View Article


Okta bets on identity to control AI agents, but is identity enough?

Concerns over agentic risks are rising, and identity and access management (IAM) giant Okta believes it’s making the moves of a would-be leader in this emerging cyber market. “Identity is the primary...

View Article

AI malware just removed the human from the attack loop

Attackers using AI have greatly benefited when it comes to speed and scale, and now, says Cisco Talos, the technology has evolved to execute large portions of the attack chain entirely without human...

View Article

Microsoft’s EvilTokens takedown sheds light on state of AI-powered cybercrime

Microsoft has hailed its success in disrupting EvilTokens, an AI-powered a phishing-as-a-service (PhaaS) platform linked to more than 12,000 compromised Microsoft 365 inboxes across more than 10,000...

View Article


Z.ai disables coding assistant feature after flaw exposed enterprise code...

Chinese artificial intelligence company Z.ai had to disable several features of its ZCode coding assistant this week after a default setting was caught sending users’ local code repositories to...

View Article

Beware these fake websites selling subscriptions to AI assistants

Websites offering fake subscriptions to AI transcription tools, image generators, and other digital assistants could be putting enterprise data at risk, according to researchers at Malwarebytes. The...

View Article

The cyber AI parity window now has a deadline

In April, I wrote about what I called the Cyber AI Parity Window. This is the rare period in which defenders and adversaries gained access to the same transformative technology at roughly the same...

View Article


CISOs can no longer ignore the nation-state threat

Flare-ups between US intelligence agencies and private-sector defenders have long been a characteristic of the cybersecurity landscape, with the balance swinging between deep collaboration and...

View Article


Gemini broke into 3 companies, but Google kept it quiet because ‘no damage...

A Google Gemini AI agent broke into three companies in May, guessing the credentials for one and discovering the credentials for the second two in a public repository, Google confirmed on Monday. But...

View Article

After spending billions, OpenAI still has gaps in its cybersecurity

Two separate reports of security flaws in OpenAI systems highlight how even a company spending billions on developing its own AI-powered cybersecurity testing tools remains vulnerable. In one...

View Article

New npm malware finds a way around install script defenses

Blocking suspicious install scripts may no longer be enough to mitigate threats from malicious JavaScript dependencies used in software supply-chain attacks. Security researchers at Checkmarx are...

View Article

Orchid Security Introduces AI Agent Readiness Controls Featuring Continuous...

Readiness tagging for AI, always-on observability, and coordinated kill switches at the application layer give enterprises a defensible route to scaling agents while keeping authority in human hands....

View Article


Revoking the token didn’t kill the backdoor

Every identity-compromise runbook I have written, read or inherited has the same step near the top: revoke the tokens. Reset the password, kill the sessions, invalidate the refresh tokens, then go...

View Article

5 ways AI is reshaping the cybersecurity job market

Mario Platt spent part of last year eliminating a team. As CISO for online password management service LastPass, he shut down the company’s dedicated vulnerability management function in late 2025,...

View Article


CISA is ending its monthly vulnerability bulletin

The rise in AI-generated security threats may just have generated one casualty: the death of the weekly bulletin of security threats from the US Cybersecurity Infrastructure and Security Agency...

View Article

A zero-click RCE flaw in AI coding agents could have exposed enterprise systems

Popular AI coding agents such as OpenAI’s Codex, Anthropic’s Claude Code, Google’s Gemini CLI, and Microsoft-owned GitHub Copilot were vulnerable to a zero-click attack that enabled attackers to...

View Article


GhostCode attackers abuse device codes to take over Microsoft 365 accounts

Microsoft 365 users are being tricked into handing over access to their accounts by a new phishing kit, GhostCode, that exploits a weakness in a legitimate device authorization flow. Researchers in...

View Article

Strong fundamentals make next-gen security possible

Risk management has always been a difficult job, but the current threat landscape has taken the challenge to a new level. I’ve spent years leading cybersecurity efforts at large enterprises, including...

View Article

Cisco patches max-severity ISE flaw, the second critical zero-day this week

Cisco released patches for an actively exploited authentication bypass vulnerability in its Cisco Identity Services Engine (ISE) platform, which is used for enterprise network access control and...

View Article
Browsing index pages (3304 articles)


Latest Images