Latest stories — Page 90

Infosecurity Europe 2026: What the London Gathering Means for the Security Calendar
The industry's largest European security conference returns to London on June 2–4, 2026, and the programme signals where enterprise security investment is heading.

Operators Warn AI-Generated Traffic Is Outpacing Static DDoS Defences as Regulators Eye Disclosure Rules
Machine-learning-driven flood attacks are reshaping volumetric thresholds faster than current incident-reporting frameworks anticipated.

The 'Too Many Tools' Webinar Is a Sales Pitch. The Numbers Behind It Are Harder to Find.
Vendors keep telling network teams that consolidation and AI will fix incident response. I asked four of them for the data. None sent any.

SharePoint's latest RCE bug hands attackers the keys with no extra paperwork
CVE-2026-45659 is a deserialization flaw that doesn't ask for much — and that's exactly why Microsoft is shipping fixes across every supported SharePoint Server build.

Anthropic Wires Claude Into 28 Enterprise Security Platforms
The AI company is pushing deeper into corporate security stacks, connecting Claude to vendors including CrowdStrike, Okta, and Zscaler.

SOC Teams Are Running Out of Road Without AI, Manchester Panel Warns
Security practitioners gathered at DTX Manchester to debate machine-versus-machine warfare, alert fatigue, and why the fundamentals still matter before any AI switch gets flipped.

Microsoft Open-Sources Rampart and Clarity to Embed AI Agent Safety Into Dev Pipelines
Two new tools shift AI red-teaming left, targeting prompt injection and privilege escalation before code ships.

ChromaDB Flaw Exposes Servers to Remote Attacks
A vulnerability in ChromaDB allows attackers to execute code remotely, posing a risk to AI application servers.

Microsoft Rushes Fixes for Two Actively Exploited Defender Zero-Days as CISA Adds Both to KEV
A disgruntled researcher's GitHub exploits may be behind attacks on the Malware Protection Engine and Antimalware Platform — but Microsoft isn't saying so.

Cisco Secure Workload Flaw Demands Immediate Attention
Cisco Secure Workload vulnerability allows attackers admin-level access; patch now.

Google Repositions CodeMender within AI Ecosystem
Shift from standalone security tool to integrated AI agent marks strategy pivot.

The Perimeter Is Gone. Attackers Already Knew That.
Modern intrusions rarely crack the wall. They walk through the front door, wearing your credentials.

AI-Driven OT Security Is Only as Good as the Telemetry Feeding It
Fewer than 10 percent of OT networks have meaningful monitoring in place, according to the 2026 Dragos OT Cybersecurity Year in Review. Until that changes, layering machine-learning tools on top of industrial control systems may create more risk than it resolves.

Microsoft Wires Agentic AI Into Edge for Business — With an Audit Leash Attached
A limited preview of Edge for Business introduces Copilot-driven task automation alongside Microsoft Purview controls that log, filter, and block sensitive data before it leaves the tenant.

Authorities Shut Down First VPN Over Criminal Ties
A European crackdown takes out a VPN aiding crime, but raises wider privacy concerns.

Kali365 Phishing Kit Hijacks Microsoft OAuth Tokens to Silently Bypass MFA
The FBI has flagged a device-code phishing campaign powered by Kali365, a toolkit that steals OAuth tokens tied to Microsoft 365 accounts without ever touching a user's password.

More Than Half of CISOs Would Pay a Ransomware Demand. The Maths Are Not Flattering.
A survey of 750 CISOs in the US and UK finds 58% would hand over money to ransomware operators — despite law enforcement advice, incomplete decryption rates, and the lingering question of whether the data stays exclusive.

A Three-Year-Old Chromium Bug Can Turn Your Browser Into a Bot — And It's Still Not Fixed
An unpatched flaw in Chromium's Background Fetch API lets malicious websites keep service workers alive indefinitely, enabling crypto mining, DDoS participation, and persistent tracking across browser restarts.

Your CI Pipeline Is Already Too Late — CVE Lite CLI Disagrees With Your Entire Workflow
An OWASP-backed JavaScript dependency scanner built by Sonu Kapoor wants to catch vulnerable packages the moment a developer types the install command, not when the build breaks at 2 a.m.

Treat the Model Like a Threat: Why AI Agent Security Needs a Systems Overhaul
A paper from researchers at Google and two US universities argues that prompt-level defences and alignment tuning are structurally inadequate for securing autonomous AI agents — and that enterprises should start treating the model itself as an untrusted component.

Ten Thousand Bugs, One Model: Inside Anthropic's Project Glasswing
Claude Mythos Preview has scanned more than a thousand open-source projects and surfaced thousands of critical flaws. The bottleneck has moved — and the patch queue is not moving fast enough.