GitHub App keys can still enable takeovers long after they are forgotten
GitHub allows organizations to install GitHub Apps that automate and extend certain functionality on the platform […]
Inside a Data Breach Investigation with Fidelis: Connecting Network, Endpoint, and Deception Evidence
When a breach occurs, the problem is rarely a lack of security data. The harder problem […]
Okta bets on identity to control AI agents, but is identity enough?
Concerns over agentic risks are rising, and identity and access management (IAM) giant Okta believes it’s […]
AI malware just removed the human from the attack loop
Attackers using AI have greatly benefited when it comes to speed and scale, and now, says […]
Microsoft’s EvilTokens takedown sheds light on state of AI-powered cybercrime
Microsoft has hailed its success in disrupting EvilTokens, an AI-powered a phishing-as-a-service (PhaaS) platform linked to […]
Z.ai disables coding assistant feature after flaw exposed enterprise code upload risk
Chinese artificial intelligence company Z.ai had to disable several features of its ZCode coding assistant this […]
Beware these fake websites selling subscriptions to AI assistants
Websites offering fake subscriptions to AI transcription tools, image generators, and other digital assistants could be […]
The cyber AI parity window now has a deadline
In April, I wrote about what I called the Cyber AI Parity Window. This is the […]
CISOs can no longer ignore the nation-state threat
Flare-ups between US intelligence agencies and private-sector defenders have long been a characteristic of the cybersecurity […]
Gemini broke into 3 companies, but Google kept it quiet because ‘no damage was done’
A Google Gemini AI agent broke into three companies in May, guessing the credentials for one […]