The cyber AI parity window now has a deadline
In April, I wrote about what I called the Cyber AI Parity Window. This is the […]
CISOs can no longer ignore the nation-state threat
Flare-ups between US intelligence agencies and private-sector defenders have long been a characteristic of the cybersecurity […]
Gemini broke into 3 companies, but Google kept it quiet because ‘no damage was done’
A Google Gemini AI agent broke into three companies in July, guessing the credentials for one […]
After spending billions, OpenAI still has gaps in its cybersecurity
Two separate reports of security flaws in OpenAI systems highlight how even a company spending billions […]
New npm malware finds a way around install script defenses
Blocking suspicious install scripts may no longer be enough to mitigate threats from malicious JavaScript dependencies […]
Orchid Security Introduces AI Agent Readiness Controls Featuring Continuous Identity Monitoring and Kill-Switch Capabilities
Readiness tagging for AI, always-on observability, and coordinated kill switches at the application layer give enterprises […]
Revoking the token didn’t kill the backdoor
Every identity-compromise runbook I have written, read or inherited has the same step near the top: […]
5 ways AI is reshaping the cybersecurity job market
Mario Platt spent part of last year eliminating a team. As CISO for online password management […]
CISA is ending its monthly vulnerability bulletin
The rise in AI-generated security threats may just have generated one casualty: the death of the […]
A zero-click RCE flaw in AI coding agents could have exposed enterprise systems
Popular AI coding agents such as OpenAI’s Codex, Anthropic’s Claude Code, Google’s Gemini CLI, and Microsoft-owned […]