After spending billions, OpenAI still has gaps in its cybersecurity
Two separate reports of security flaws in OpenAI systems highlight how even a company spending billions […]
New npm malware finds a way around install script defenses
Blocking suspicious install scripts may no longer be enough to mitigate threats from malicious JavaScript dependencies […]
Orchid Security Introduces AI Agent Readiness Controls Featuring Continuous Identity Monitoring and Kill-Switch Capabilities
Readiness tagging for AI, always-on observability, and coordinated kill switches at the application layer give enterprises […]
Revoking the token didn’t kill the backdoor
Every identity-compromise runbook I have written, read or inherited has the same step near the top: […]
5 ways AI is reshaping the cybersecurity job market
Mario Platt spent part of last year eliminating a team. As CISO for online password management […]
CISA is ending its monthly vulnerability bulletin
The rise in AI-generated security threats may just have generated one casualty: the death of the […]
A zero-click RCE flaw in AI coding agents could have exposed enterprise systems
Popular AI coding agents such as OpenAI’s Codex, Anthropic’s Claude Code, Google’s Gemini CLI, and Microsoft-owned […]
GhostCode attackers abuse device codes to take over Microsoft 365 accounts
Microsoft 365 users are being tricked into handing over access to their accounts by a new […]
OpenAI Discloses 6 AI Misalignment Cases — What They Reveal About Agent Controls
OpenAI disclosed six AI misalignment cases that highlight new risks around agent permissions, network access, and […]
Strong fundamentals make next-gen security possible
Risk management has always been a difficult job, but the current threat landscape has taken the […]