The Latest
-
Companies are failing to keep up with AI’s identity sprawl, creating entry points for hackers
Three-quarters of organizations say they aren’t fully overseeing the activities of user accounts belonging to agents and other AI tools.
-
CISA, researchers warn of escalating attacks using Cisco Catalyst SD-WAN flaws
Multiple vulnerabilities are being chained together to gain additional access to systems.
-
Check Point warns of zero-day flaw targeted by ransomware affiliate
A vulnerability in the company’s VPN deployments has faced exploitation since early May.
-
Deep Dive
Cyber insurance policyholders facing heavier scrutiny in underwriting, claims
A multiyear lull in insurance rates and insurers’ over-dependence on large U.S. policyholders have led to more restrictions and exclusions in coverage.
-
IT sector faces growing threats from IP-hungry China, AI-enabled cybercriminals
Businesses also need to watch out for North Korean remote IT worker schemes, according to a new CrowdStrike report.
-
Companies aren’t prepared for how AI is accelerating impersonation attacks
Businesses generally aren’t taking a proactive enough approach to blocking schemes that spoof their leaders’ identities, according to a new report.
-
Sprawling new House AI bill includes frontier model oversight, open-source security grants
The legislation has already drawn widespread criticism for its proposal to preempt state AI laws.
-
Cisco warns zero-day flaw in SD-WAN is being exploited
The company cautioned that no current patches are available and the flaw could allow an attacker to conduct command injection attacks.
-
CISA chief says Trump AI executive order implementation will start soon
The agency, depleted after several rounds of cuts imposed by the White House, insists it can handle its new AI security responsibilities.
-
CrowdStrike, Palo Alto Networks defy estimates as AI fuels cyber demand
The cybersecurity sector has been under perceived pressure due to accelerating deployment of AI tools.
-
‘Don’t panic’: AI reality checks dominate major cybersecurity conference
CISOs and their colleagues should focus on network security basics, not overhyped AI promises, analysts said at a Gartner cybersecurity event.
-
CISA, FBI warn that hackers are targeting systems used to monitor industrial fluids
Automatic tank gauge systems are widely used across multiple industries, including energy, agriculture and transportation.
-
Trump signs EO seeking early government access to powerful AI models
The directive represents an about-face for an administration that previously repudiated government AI reviews.
Updated June 2, 2026 -
Anthropic shares Mythos with 150 more organizations, including critical infrastructure operators
The AI firm also said it’s exploring how to help open-source developers deal with a flood of vulnerability reports.
-
Dozens of Red Hat npm packages targeted in supply chain attack
Researchers said a variant of the Mini Shai-Hulud is involved in the compromise.
-
Opinion
Turning tension into collaboration: How CIOs and CISOs can lead together
If properly managed and channeled, age-old friction between IT and cybersecurity can create a more resilient organization.
-
CISA adds critical Palo Alto Networks firewall flaw to KEV as company, researchers warn of exploitation
The vulnerability in a vital defensive technology creates serious risks for federal networks, CISA said.
-
Without strong governance, companies put credit ratings at risk in AI era
A new report from S&P Global provides a blueprint for how companies can adapt to the changing threat environment.
-
CISA urges security teams to check for software development compromises
The agency warned about a wave of attacks targeting credentials and other secrets across critical supply chains.
-
IBM’s new $5B initiative will help enterprises rapidly patch open-source vulnerabilities
The tech giant’s project could make it easier for businesses to safely use open-source packages.
-
Opinion
How CISOs can manage sovereign-cloud security risks
Selecting and adopting cloud services from non-U.S. regional providers requires solid cyber risk and security assessment.
-
Coordinated operation takes down Glassworm botnet
The botnet began in early 2025, targeting software developers across the open-source supply chain.
-
Enterprise data is creeping its way into shadow AI tools
Executives and employees are clashing over usage policies as AI security concerns rise, an Okta report found.
-
Leading AI models are more vulnerable to malicious prompts than vendors claim
Hackers could subvert frontier models with attacks that their developers overlook, Cisco said.
-
FBI warns about PhaaS platform used to access Microsoft 365 environments
Device code phishing enabled hackers to bypass multifactor authentication without credentials.