CISOs vs. Boards: Myth or Misunderstanding?
Escalating threats are forcing boards to prioritize security, but communication gaps persist. Boards and security teams each say they need m…
Appearance and language
Browse all headlines from this category in a dedicated page.
Escalating threats are forcing boards to prioritize security, but communication gaps persist. Boards and security teams each say they need m…
Lower catch this year. As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered. Blo…
The hacking of Hugging Face by a rogue OpenAI agent is significant, but unsurprising — and preventing the next AI model escape will be diffi…
This essay was written with Barath Raghavan, and originally appeared in IEEE Spectrum. Major benchmarks measure what AI can do. None measure…
A porous API endpoint exposes, names, email addresses, country, and site status, all of which can be easily gleaned by anyone with a browser…
New paper: “Encryption and Globalization 15 Years Later: End-to-End Encryption and the Third Round of the ‘Going Dark’ Debate“: Abstract: Th…
Microsoft addresses a public-by-default configuration and chain of code flaws in Azure Automation that could have let attackers seize anothe…
Harrowing story of an identity theft victim. Yes, the person made a mistake—they gave the scammer a two-factor authentication code that allo…
The AI security layer and guardrails for many AI products don't evenly protect against jailbreaking and unsafe actions in every single langu…
The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn one's television i…
A state-sponsored threat group, dubbed "Laundry Bear," sends "half-click" phishing emails that require a victim only to open or preview the …
It’s a lot: According to information obtained by The Tech, MIT is spending over $3 million on more than 500 AI surveillance cameras in acade…
Core issues that slowed down adoption of secure data vaults are being resolved by technology, but artificial intelligence poses new ones. Ex…
Portuguese businesses operate in the same native language as Brazilian hackers, making those businesses easy targets.
A cyberattack on a food and logistics firm disrupts the supply of frozen food to thousands of clients, including major franchises like Kentu…
Ahead of Black Hat USA, researchers find exploitable flaws in how Microsoft handles passkeys that could allow attackers to impersonate privi…
Sandworm_Mode is an early example of malware that exploits trusted AI tools and workflows to make malicious activity virtually indistinguish…
A malicious application delivers four-stage Android spyware via phony Google Play sites, exploiting civilian fear during Iranian missile str…
Advanced LLMs escaped their sandboxes while attempting to achieve a non-malicious benchmark test objective.
European and US banks inadvertently transmitted customer data to ad platforms via tracking pixels, raising serious compliance, security, and…
Researchers pointed to fragmentation of the ransomware ecosystem, the emergence of new attackers, and expansion of attacks on less defended …
The latest large language models have high false-positive rates and fail to take into account the context of scans, leading to more work for…
A Russian-speaking actor, "Trim," dismantled publicly available frontier models and integrated them with offensive security tools.
AI-generated code introduces 15 vulnerabilities on average per codebase, but the actual risk depends on framework pairing more than the mode…