AI Agents Are a New Kind of Identity — and Most Organizations Aren't Ready
If you're handling AI agents like a service account or API token, consider yourself behind. AI agents need a fundamentally different approach.
Aggregated from vendor advisories, security research, and industry publications.
If you're handling AI agents like a service account or API token, consider yourself behind. AI agents need a fundamentally different approach.
Datadog Security Labs is warning of "several overlapping campaigns" that are systematically enumerating corporate GitHub organizations, repositories, and user accounts through the …
Microsoft has taken apart a destructive Windows backdoor it calls GigaWiper. What stands out is how it is built: not one tool but three older destructive programs bolted into one, …
Searching for work sucks; AI combs the internet and sucks it all up. Combine the two and let 'er rip with this Python project
Linux distro accuses former contributor of deleting years of work and pushing a package that could have broken installs
A new data-extortion group called Helix is using identity-focused tactics such as voice phishing (vishing), device code phishing, and multi-factor authentication (MFA) abuse to ste…
Microsoft says Windows users should expect to see an increase in security updates as the company increasingly relies on artificial intelligence to discover vulnerabilities in its c…
GitHub has officially announced the release of npm version 12 with install scripts disabled by default, along with deprecating granular access tokens (GATs) designed to bypass two-…
Vendor drops reinstatement fees and caps back-maintenance charges ahead of the ECC support cliff
Monospaced code snippets among the reported casualties
Opponents won the count but missed the 360-seat threshold needed to stop the interim CSAM-scanning rule
Most security mess starts as admin work. A link gets clicked. A tool gets trusted. A bucket name gets reused. A setting stays loose because nobody wants to touch it. This week is …
The Israeli company has developed a cryptographic posture and post-quantum cryptography management platform. The post QIZ Security Raises $17 Million for Cryptographic Governance P…
6.7 is now current, and in 6.8 you're getting Wayland whether you like it or not
PARTNER CONTENT: Why platform teams are swapping DIY Kubeflow for Canonical's managed service
A new phishing-as-a-service (PhaaS) operation called Forg365 focuses on stealing Microsoft 365 accounts by combining adversary-in-the-middle (AiTM) and device code methods with AI-…
The fate of a Ukrainian tax software company shows how modern cyber warfare can claim casualties far beyond the battlefield, and how businesses across the ocean still need to prote…
Take-home midterm row sharpens fears that the tools are dulling minds and easing cheating
Two announcements on July 7, 2026, demonstrate the government’s determination to improve the level of cybersecurity within the UK. The post UK Government Rolls Out Agentic AI Defen…
Security operations don't slow down when IT teams take vacation, but staffing levels often do. Kaseya explains how AI-driven automation can help organizations maintain consistent s…
After CEO promised 'flagship use-case' for AI, retired scheme members still struggling to make ends meet, MPs hear
Buffer overflow, DoS, command injection, SSRF, authentication bypass, and other types of vulnerabilities have been found in PAN-OS software. The post Palo Alto Networks Patches 13 …
Weeks after the exploit code dropped, Redmond has finally ships a fix for the Defender zero-day
Quantum computers are still two to five years away from full-scale production, but early users like the Cleveland Clinic and Mitsubishi Chemical are already seeing benefits, partic…
10X faster build times could force Slack developers back to their keyboards
A cryptomining incident highlights how AI gateways can provide access to AI models, cloud infrastructure, and identity and access management (IAM) data.
24-hour outage in key AWS region could leave UK firms nursing massive losses, researchers claim
AI has changed how fast attacks move. Work that once took an attacker days now takes minutes. Using models like Mythos, attackers write tailored bait, pick targets, test what lands…
Hackers exploited a zero-day vulnerability in a third-party system to access a KDDI email system for ISPs. The post 12 Million Impacted by Data Breach at Japanese Telco KDDI appear…
Nobody needs a simple web client for Exchange, do they?