US lawmakers on Thursday introduced a bill that would require developers of advanced AI models to report major safety and security incidents…
News
Mythos is a signal, not a siren: What frontier AI should change for CISOs
When a new AI capability starts making headlines, I see the same pattern play out in boardrooms and executive staff meetings. The…
GDPR at 10: Landmark data protections, increasing business burden
Ten years have passed since the General Data Protection Regulation (GDPR) came into force, and the results are mixed. While data protection…
Rethinking the balance between AI oversight and innovation
The new CIO mandate is clear: facilitate AI adoption across the enterprise at speed. According to CIO.com’s State of the CIO survey,…
GRC is broken. FedRAMP 20x might fix it
We are auditing a curated version of history. I’ve worked in security long enough now to know something most of us don’t…
Be on the lookout for Mistic, a new backdoor used by ransomware broker
Researchers have identified a new backdoor program that has been used in enterprise intrusions since April and appears to be linked to…
Scattered Spider duo convicted over $38M Transport for London attack
Two members of the Scattered Spider cybercrime collective have admitted launching a cyberattack against Transport for London (TfL) that caused millions in…
Attackers exploit Cisco Unified CM flaw weeks after patch release
A critical Cisco Unified CM vulnerability is now under active exploitation, weeks after the company issued patches warning it could allow attackers…
How a malicious AI agent skill passed security checks and reached 26,000 users
A fake AI agent skill that passed security checks reached over 26,000 users through Instagram, highlighting new risks as enterprises rely on…
Kahneman, ‘Where’s Waldo’ and the Nexus pass: A CISO’s mental model for the AI era
Security awareness training as a defense against phishing is dead. It has been dead for a while. The industry never held a…