Lightwell project filters out 400 Java library vulnerabilities
Lightwell, the open-source security initiative set up by IBM and Red Hat, has identified more than […]
Risk-Based Vulnerability Prioritization with Fidelis Halo® CNAPP
Key Takeaways Vulnerability severity alone does not provide enough context to determine the actual risk to […]
Ransomware consultant said he would decrypt data, is accused of paying ransoms instead
The owner of a ransomware remediation company is facing trial for defrauding customers. Zohar Pinhasi, also […]
OpenAI reports three new incidents of misalignment
OpenAI continues to report incidences of “misaligned” behavior by its AI models, with three new reports […]
Citrix issues its weekly critical security patch for NetScaler ADC and NetScaler Gateway
For the third week running, Citrix has issued a critical security warning to customers managing their […]
Exposed Nvidia GPU monitors can reveal AI infrastructure secrets
A component of Nvidia’s GPU monitoring software that enterprises use to keep tabs on their AI […]
When building an AI-native security program, start with outcomes
In my last article, I described the SOC Triangle, the longstanding trade-off among quality, consistency and […]
Growing PQC at the edge belies deeper quantum-readiness challenges
The quantum threat is becoming an increasing concern for security leaders, but many may be mistaking […]
Risk Prioritization: How Security Teams Decide What to Fix First
Key Takeaways Risk prioritization helps security teams focus remediation efforts based not only on severity scores, […]
AWS’s repeated problems with AI agent controls illustrates the autonomous agent dilemma
Throughout this year, Amazon Web Services (AWS) has repeatedly had to patch autonomous agent security holes, […]