Infosec stories
Healthcare providers face added pressure to secure AI systems and patient data as Rubrik joins a coalition of nearly 3,000 members.
Enterprises can now vet open-source dependencies before build time, as the catalogue adds independent malware and vulnerability checks for Python and Java.
Security teams may be able to cut false alarms as Picus says its new platform proves whether a vulnerability can actually be exploited.
Rising use of deepfakes and voice cloning is forcing firms to rethink staff training as insurers and buyers scrutinise human risk more closely.
Weak default safeguards and uneven sandboxing could leave developers exposed to command execution before workspace trust is granted.
AI-enabled scams are making it harder for UK and European businesses to win executive backing for staff-focused cyber defences.
Businesses are being urged to tighten controls as AI tools spread faster than governance, with Quorum Cyber updating assessments to cut cyber risk.
Businesses face a fresh wave of identity theft-driven extortion as Helix is linked to BlackFile and ShinyHunters through shared infrastructure.
Asia-Pacific security teams can now keep regulated data in Singapore as Conifers expands its CognitiveSOC platform across the region.
Breaches are hitting lenders harder as AI adoption speeds up, with 98 per cent of affected firms saying the impact was material.
The cybersecurity company is tightening financial control and customer support as it expands internationally and seeks to protect recurring revenue.
A live fraud campaign targeting Mexican banks, fintechs and crypto services exposed how criminals are using generative AI to draft malware.
Malicious AI skills are helping criminals steal data and run malware, while QR-code phishing climbed 146% in the latest ESET report.
Security teams now see autonomous AI as a bigger internal danger, even as most say it is boosting productivity, a survey found.
Reduced staffing and delegated approvals during annual leave are giving fraudsters more chances to slip through corporate checks, Everywhen says.
Security teams could cut alert overload as Google ties exposed assets to live attacker activity, helping prioritise the riskiest flaws first.
Firms with manually rotated ADFS certificates could still be exposed, as attackers may recover live signing keys and forge SAML logins.
It targets defence and government teams needing to handle sensitive data in disconnected environments without direct internet access.
UK firms face mounting attack costs as NCC Group joins a government-backed push to put cyber risk on board agendas and across supply chains.
Staff confidence masks weak cyber readiness in the public sector, where more than a quarter report no effective training in a year or ever.