Infosec stories
Security teams now see autonomous AI as a bigger internal danger, even as most say it is boosting productivity, a survey found.
Reduced staffing and delegated approvals during annual leave are giving fraudsters more chances to slip through corporate checks, Everywhen says.
Security teams could cut alert overload as Google ties exposed assets to live attacker activity, helping prioritise the riskiest flaws first.
Firms with manually rotated ADFS certificates could still be exposed, as attackers may recover live signing keys and forge SAML logins.
Users now have more local routing choices as ExpressVPN widens its app-selectable network to 214 locations in 113 countries.
Sensitive physics and engineering research at US and Canadian universities may have been exposed after hackers used Roundcube flaws to enter mail servers.
Vendor consolidation among managed service providers is pushing WatchGuard to sharpen its platform strategy as it appoints a new product chief.
The real risk is growing backlogs and patching delays, as AI speeds up exploit development faster than security teams can respond.
Android users and IT teams can now deploy YubiKeys as hardware-backed passkeys, following Google Play Services support for NFC security keys.
Security teams are being pushed to prioritise more than ever, as vulnerabilities now make up 42.6% of critical exposures, Check Point says.
Rising deadline pressure is leaving finance and payroll teams more exposed to sophisticated scams that can disrupt payments and damage trust.
Hidden tracking markers and a US standoff over a vulnerability-finding model are fuelling fears that AI now carries cyber and national security risks.
New safeguards will let Fable 5 block more harmful cyber prompts, as Anthropic also seeks a common scale for jailbreak risk.
Most organisations are exposed to AI security breaches, with AvePoint finding 88.4% suffered at least one incident in the past year.
Rising Mac adoption has left many security teams short of Apple-specific expertise, prompting Jamf to add dedicated threat hunting and investigations.
Security teams face a new governance gap as AI agents spread across Microsoft systems, with many lacking inventories, controls or monitoring.
UK firms face mounting attack costs as NCC Group joins a government-backed push to put cyber risk on board agendas and across supply chains.
Staff confidence masks weak cyber readiness in the public sector, where more than a quarter report no effective training in a year or ever.
The province found hidden security flaws in public sector systems in hours, a task officials say could have taken a manual review 6.5 years.
Many workers are risking disciplinary action by feeding customer data and confidential files into public AI tools, the survey found.