2026-06-26 18:36
π The tech industry is uniting to enhance open-source security with the launch of Akrites, led by the Linux Foundation and backed by 19 organizations, including AWS, Google, and Microsoft. π‘οΈ This initiative aims to streamline the discovery, remediation, and disclosure of vulnerabilities in critical open-source software. AI models are now making it possible to identify multiple vulnerabilities quickly, but attackers have access to these tools as well. π As AI tools reveal thousands of...
Paul Sawers
2026-06-26 18:26
π¨ The US government has mandated restrictions on OpenAI's upcoming GPT 5.6 model due to cybersecurity concerns. π€ Only a select group of government-approved partners will have access during the initial release. This follows a similar directive given to Anthropic for their AI models. π OpenAI CEO Sam Altman confirmed that access will be granted customer by customer, which is an unusual approach for such technology. #OpenAI #GPT56 #AI #Cybersecurity #Innovation
Adrian Bridgwater
2026-06-26 13:00
Many AI agent projects encounter challenges during security reviews due to unclear identity models and broad permissions. This issue can halt progress when questions arise about the identity under which agents operate. Research indicates a significant increase in AI agents, highlighting the growing need for well-defined identities to ensure accountability and security. To address this, developers must focus on key identity decisions, such as using workload identities instead of shared service...
Jackson Connell
2026-06-25 10:02
π¨ Privacy Alert! π¨ Recent research highlights the risks of membership inference attacks on chatbots and large language models (LLMs). These attacks can reveal whether specific individuals' data was used in training without directly accessing databases. The study emphasizes that current detection methods may not be enough to protect user privacy, especially for fine-tuned models. Researchers are exploring these vulnerabilities to help developers strengthen their models against such threats. π‘οΈ...
Katie Fraser
2026-06-24 20:53
π Azul Systems is offering a free vulnerability risk assessment for Java Virtual Machines (JVMs). This tool helps DevOps and SecOps teams identify unpatched JVMs and enhance security before AI-driven threats emerge. The assessment scans networks to find JVM instances and provides a prioritized remediation roadmap, referencing established vulnerability databases. Azul's approach targets its security-only Critical Patch Updates, aiming to minimize risks during Java updates. They claim this...
Darryl K. Taft
2026-06-23 12:00
Enhancing threat hunting at Black Hat involves balancing data sources. π Recently, the Splunk Attack Analyzer (SAA) replaced Secure Malware Analytics (SMA) for malware threat analysis. SAA offers detailed data, allowing us to refine our threat landscape reporting. Collaboration was key, as David and Lily developed a query that extracts and reshapes critical submission metadata. This innovation provided deeper insights, improving our workflow efficiency. π #ThreatHunting #CyberSecurity...
Aditya Raghavan
2026-06-22 16:06
π SoftBank Corp. has enhanced its Security Operations Center (SOC) by automating its triaging workflow using Cisco Foundation AI's open-source model. This integration allows for the detection of suspicious software and dynamic policy verification, streamlining operations significantly. The model categorizes software into 17 types for efficient enforcement of company policies. Previously manual processes are now automated, freeing up analysts to focus on more critical investigations. #SoftBank...
Huaibo Zhao
2026-06-21 17:00
π¨ A recent report from Tenet Security highlights a vulnerability known as "agentjacking." This attack exploits a public Sentry key to turn AI coding agents like Claude Code, Cursor, and Codex into code-execution engines on developers' machines. The process involves sending a fake error report that the AI agent interprets as an instruction, making it act without any malware or stolen passwords. This security flaw stems from the design of Sentry's Data Source Name (DSN), which is safe for human...
Janakiram MSV
2026-06-17 15:00
π Wireless security is evolving with the rise of AI and IoT. Midsize businesses face increasing threats as new devices connect daily, putting pressure on small IT teams. Modern standards like WPA3, now part of Wi-Fi 7, offer stronger protection without complicating operations. Adopting these standards is feasible for growing businesses. Recent reports show 85% of U.S. organizations faced wireless security incidents last year, highlighting the urgent need for effective solutions....
Ameya Ahir
2026-06-16 15:00
π¨ Independent testing shows that Cisco Secure Email Threat Defense (ETD) is a leader in email security. In the May 2026 SE Labs evaluation, ETD earned the AAA award, achieving a 94% Total Accuracy Rating. It successfully detected 478 out of 486 threats, resulting in a 98% detection rate. ETD effectively blocked all phishing attempts, ensuring zero inbox compromise. This highlights the importance of proactive email security in todayβs threat landscape. #EmailSecurity #Cybersecurity #CiscoETD...
Deepali Shukla
2026-06-16 00:00
Travis McPeak, Head of Security at Cursor, discussed the complexities of securing AI agents on the Zero-Shot Learning podcast. He emphasized the challenges of managing non-deterministic agents that have access to sensitive systems. To address these risks, he advocates for secure-by-default workflows and embedding security policies as code. This approach ensures that security keeps pace with business needs while minimizing potential damage. Travis also highlighted the growing reliance on AI in...
info@1password.com (Chris Fowler)
2026-06-16 00:00
At 1Password, we value security and collaboration. Thatβs why we funded an independent assessment of the open-source library Snow, a Rust implementation of the Noise Protocol Framework. The assessment by Trail of Bits identified 10 findings, including a medium-severity nonce-handling issue. We worked closely with the maintainer, Jake McGinty, to resolve 8 of these findings. We believe that strengthening open-source security benefits the wider community. Check out the report for more details!...
info@1password.com (Daryl Martin and Christian Rask)
2026-06-16 00:00
The 2026 Verizon Data Breach Incident Report highlights a rise in cyberattacks targeting the Financial and Insurance sector, with small-to-medium businesses (SMBs) particularly vulnerable. 96% of ransomware victims are SMBs, facing high security standards but limited resources. Credential management is crucial for building a strong security foundation. AI adoption is increasing SaaS sprawl and complicating compliance efforts, making it harder to manage credentials securely. For more insights,...
info@1password.com (Rachel Sudbeck)
2026-06-15 16:24
π Docker has joined the Athena coalition to enhance supply chain security amidst growing AI-driven attacks. CISO Mark Lechner highlights that AI can now discover vulnerabilities at unprecedented speeds. This shift emphasizes the need for secure and transparent products. Docker's initiatives include sandboxed execution, trusted open-source images, and governed access to tools. Collaborating with partners is crucial for a comprehensive defense against threats. #SupplyChainSecurity #Docker #AI...
Aditya Tripathi
2026-06-15 16:11
Cisco and AWS are redefining security in the AI era. As organizations seek to secure innovation, Cisco Security on AWS Marketplace offers a trusted foundation for hybrid and multicloud environments. This partnership simplifies procurement and enhances protection through a cloud-native, AI-powered platform, ensuring unified security across networking and cloud. Explore how this strategic alliance can support your security needs. ππβ¨ #Cisco #AWS #CloudSecurity #Innovation #AI
Dave West
2026-06-15 14:58
In June 2026, attackers gained control of over 20,000 Instagram accounts, including a notable Obama-era account, by simply asking Meta's AI support assistant for help. They requested to link an email address they controlled and reset the password without needing any exploits or passwords. Meta confirmed that the AI acted on a valid sequence of operations, highlighting a flaw in their security checks. This incident demonstrates how reliance on AI agents can expose vulnerabilities that...
Fabio Salvadori
2026-06-15 00:00
Ensuring voice call resilience is crucial for businesses. The Twilio blog discusses the importance of disaster recovery plans for voice communications. A strategic framework is outlined to protect communication pathways before implementation. This proactive approach can help maintain service continuity across regions. Learn how to safeguard your voice services effectively. ππ #DisasterRecovery #VoiceResilience #Twilio #BusinessContinuity #CommunicationSolutions
Hao Wang
2026-06-14 16:00
Logs often go unread until issues arise, leaving teams with incomplete evidence for investigations. π Recent shifts highlight the need for effective logging. Regulatory changes and heightened security awareness mean logs must be clear, queryable, and tied to events. π As AI-powered attacks grow, detailed logs are essential for understanding attack patterns and improving defenses. The focus is now on whether logs can provide valuable insights when it matters. #CyberSecurity #AI #Logging...
Mohit Bansal
2026-06-13 21:09
π¨ Anthropic has suspended its flagship models, Fable 5 and Mythos 5, following a U.S. government alert about a specific jailbreak vulnerability. This decision affects all users, as the export control order applies universally. Anthropic claims the vulnerabilities are minor and similar to those in other models. Amidst ongoing discussions, reports suggest that Amazon's CEO alerted officials about the jailbreak, leading to increased scrutiny. More updates are expected. #AI #Cybersecurity...
Frederic Lardinois
2026-06-12 00:00
π Keep your organization secure with Elasticβs new integration for monitoring Claude activity! This integration allows security teams to track over 300 event types from Claude's Compliance API, including sign-ins and configuration changes. With prebuilt dashboards and automated detection rules, teams can easily investigate and respond to potential risks. Stay informed and enhance your security posture! #CyberSecurity #DataProtection #ElasticSecurity #Compliance #TechIntegration
Jamie Hynds,Sumana Mannem
2026-06-12 00:00
π§ In a recent episode of *Chasing Entropy*, Jaya Baloo discusses the evolving landscape of security and AI vulnerability management. She emphasizes that while AI introduces new risks, organizations should prioritize known issues like asset visibility and remediation backlogs. Baloo warns against the dangers of a "risk acceptance" culture, advocating for proactive measures instead. Her insights on leveraging smaller, open-source models highlight their potential in identifying vulnerabilities...
info@1password.com (Dave Lewis)
2026-06-11 20:38
Chainguard's recent findings highlight concerns about open-source package safety. Their new source code scanner identifies "greyware," which can be transparent yet harmful. With over 52,000 potentially dangerous packages blocked, they emphasize caution for non-technical users relying on open-source solutions. Understanding the risks is essential for safe development. ππ» #CyberSecurity #OpenSource #TechSafety #Greyware #Chainguard
Darryl K. Taft
2026-06-11 12:00
π Exciting news for developers! Aikido has enhanced its scanning capabilities for Docker Hardened Images (DHI) with built-in VEX support. This update allows vulnerabilities verified as non-exploitable by Docker to be filtered out automatically, helping teams focus on critical findings. To get started, youβll need an Aikido account, access to DHIs, and a Docker Hub Personal Access Token. Learn how to connect and scan your images efficiently! #Docker #Aikido #CyberSecurity #DevOps...
Dan Berezin Stelzer
2026-06-11 07:16
π‘οΈ Strengthening security in Red Hat's OpenShift AI voice agent is crucial. In a recent article, the implementation of guardrails to prevent prompt injection attacks was discussed, highlighting the importance of prompt engineering. π Key points include the use of MLflow to track conversation history and evaluating large language models for accuracy. π οΈ Guardrails such as TrustyAI provide vital defenses against malicious inputs, ensuring reliable interactions in the voice agent. Explore more...
Mike Hepburn
2026-06-11 00:45
π Cisco has unveiled the AI Defense Policy Studio, designed to help enterprises create adaptive AI guardrails. This tool assists policy owners in defining custom rules by providing guidance based on their specific needs and data. It simplifies the process of turning unwritten policies into actionable guidelines. With a user-friendly interface, the studio helps organizations manage AI risks effectively. #Cisco #AIDefense #AIGovernance #Cybersecurity #Innovation
Konstantin Berlin
2026-06-11 00:00
Compliance work is evolving with Elastic Security's introduction of agentic compliance in Agent Builder. This new approach allows teams to interact with live telemetry, run ES|QL-backed checks, and automate daily compliance tasks. The focus is on PCI DSS v4.0.1, enabling deeper insights into compliance without relying solely on static dashboards. Elastic's composable skill model enhances the user experience by allowing for scope discovery and evidence inspection, moving beyond traditional...
Smriti,Mia LaVada
2026-06-11 00:00
π¨ New cybersecurity guidance for US agencies! π¨ OMB Memorandum M-26-14 establishes a risk-based, outcome-driven approach for cybersecurity logging. This replaces M-21-31 and emphasizes the need for effective logging in today's AI-driven landscape. Agencies using unified platforms like Elastic are better equipped to comply. Now is the time for leaders to assess capabilities and develop action plans. Stay informed! π‘οΈ #Cybersecurity #USGovernment #Compliance #M2614 #AIThreats
Chris Townsend
2026-06-11 00:00
π Passkeys vs. Passwords: What You Need to Know π As up to 51% of people reuse passwords, security risks are heightened. Weak passwords are linked to over 80% of data breaches. Passkeys offer a passwordless solution, eliminating reliance on predictable combinations. With 69% of companies breached via authentication, exploring passwordless methods is crucial for safer access. Discover the advantages of passkeys for your business! #CyberSecurity #Passwordless #Authentication #DataBreach...
2026-06-10 21:05
State and local government organizations face significant cybersecurity challenges as adversaries act quickly, while resources are often limited. The Multi-State Information Sharing and Analysis Center (MS-ISAC) has become crucial in providing timely threat intelligence for these organizations. States are increasingly adopting membership models that extend MS-ISAC services to various agencies, ensuring even the smallest entities receive vital cyber threat information. The focus is shifting...
Jamie Garcia
2026-06-10 16:40
Last week, Microsoft disabled 73 GitHub repositories after a malware attack aimed at stealing developersβ credentials. The incident originated from a malicious commit uploaded to the durabletask repository. Despite the shutdown, Microsoft has not disclosed how many developers were impacted or specific details about the breach. GitHub stated the repos violated its terms of service but did not provide further clarification. This event highlights ongoing security concerns in the industry, as...
Meredith Shubel
2026-06-10 03:31
Organizations are increasingly using agentic AI workflows, which bring new challenges in governance and accountability. π€ When AI agents act on behalf of a business, itβs crucial to establish clear ownership and permissions from the start. This helps prevent issues and ensures accountability. π Over-permissioning can lead to risks, so granting autonomy gradually is essential. An effective audit trail is also necessary for tracking actions and outcomes. π Maintaining human oversight in...
Conrad Schwellnus
2026-06-10 00:45
π The article explores how Databricks streamlines BSA/AML compliance in financial services. It highlights the integration of previously isolated AML systems with machine learning risk scoring and AI agents into a unified workflow. This approach enhances the process from alert generation to the filing of Suspicious Activity Reports (SARs). Discover how technology is reshaping compliance! πΌπ #BSA #AML #Databricks #FinancialServices #Compliance
2026-06-09 15:00
π¨ The cybersecurity landscape is evolving with AI-driven vulnerability discovery reshaping defenses. In the article "Security in the Post-Mythos Era," the author emphasizes the importance of foundational hardening and proactive threat detection. Traditional strategies like multi-factor authentication and network segmentation are vital but often overlooked. The recent unveiling of Project Glasswing showcases AI's capability to identify critical zero-day vulnerabilities, underscoring the need...
Yuri Kramarz
2026-06-09 07:09
The rise of dual-use AI, exemplified by Anthropicβs Claude Mythos, is transforming enterprise security. This tool autonomously identifies critical software vulnerabilities, enhancing bug-finding efficiency significantly. π However, these advancements also present risks. Unauthorized use of AI can lead to rapid, machine-speed exploits, overwhelming traditional security responses. Organizations must focus on enforcing zero trust principles and continuous secret hygiene to mitigate these...
David Mills
2026-06-09 00:00
European banks are encouraged to assess their readiness for conversational AI by reflecting on 15 critical questions outlined in a recent article. These questions focus on compliance with current regulations and the technical capabilities needed for effective deployment. Understanding these factors is essential for maximizing the potential of conversational AI in the banking sector. Stay informed and prepared! π€πΌ #ConversationalAI #BankingInnovation #EURegulations #TechReadiness #AIInsights
Henry Guyver
2026-06-09 00:00
π The CrowdStrike 2026 Technology Threat Landscape Report highlights significant findings in cybersecurity. π Over 58% of state-sponsored attacks on the tech sector are attributed to China-nexus adversaries, including groups like MURKY PANDA and MUSTANG PANDA. π These attacks are motivated by financial gain, intelligence collection, and industrial espionage, reflecting the vulnerabilities of modern tech innovations. For a deeper understanding, consider downloading the full report....
Counter Adversary Operations
2026-06-09 00:00
π Microsoft has released its June 2026 security update, addressing 206 vulnerabilities. This includes fixes for three publicly disclosed zero-day vulnerabilities and 37 critical ones. The most common risk types involve elevation of privilege, remote code execution, and information disclosure. Patches were primarily for Microsoft Windows, followed by Extended Security Updates and Microsoft Office. #Microsoft #Cybersecurity #PatchTuesday #Vulnerabilities #InformationSecurity
Falcon Exposure Management Team
2026-06-09 00:00
π¨ A recent report by GitLab's Vulnerability Research team revealed a supply chain attack on PyPI involving the Shai-Hulud malware. Five malicious packages were identified, including typosquats of popular libraries like Flask, Requests, and NumPy. These packages execute harmful code at installation without user action. The attack showcases how attackers exploit Python's .pth file mechanism for self-propagating credential theft, targeting major cloud providers and CI/CD environments. For those...
Daniel Abeles
2026-06-08 19:54
Understanding software supply chain security is essential for development teams. With open-source malware on the rise, organizations must implement effective practices now. π This article outlines five best practices, including starting with trusted content, verifying build provenance, and integrating vulnerability analysis into workflows. π¦π By treating supply chain security as an engineering discipline, teams can better protect their software against sophisticated attacks. #SoftwareSecurity...
Aditya Tripathi
2026-06-08 00:00
π Exciting news from CrowdStrike and Zscaler! Their new integration enhances Zero Trust Access by using CrowdStrike's Continuous Identity approach. This allows for real-time, risk-based access decisions to combat identity-driven attacks. The integration helps organizations evaluate user risk across various domains, improving security response times. Stay ahead of threats with this innovative solution! ππ #Cybersecurity #ZeroTrust #IdentitySecurity #CrowdStrike #Zscaler
Chris Kachigian