(Adobe Stock) Was the Australia health portal incident a misconfiguration error?Steve ZurierSeptember 25, 2026Questions emerge over whether a reported AI hack was actually a basic government portal misconfiguration.
Gemini hacked three companies. The AI isn’t the part that should scare you.Neha DuggalSeptember 25, 2026
The four AI questions CISOs will hear from the board the next time they meet Sravish SridharSeptember 25, 2026
The government must designate AI as critical infrastructure sooner rather than laterTravis Rosiek September 23, 2026
Senate leaders introduce bill for voluntary telecom cybersecurity practicesSC StaffSeptember 25, 2026
From autonomous agent to trusted worker: Building identity and accountability for AI agentsPaul WagenseilSeptember 17, 2026
Security OperationsKiteworks warns customers to shut down servers due to possible imminent attackLaura FrenchSeptember 25, 2026Kiteworks’ CISO cited “credible threat intelligence from law enforcement” for the urgent alert.
Vulnerability ManagementCISA publishes framework for improving CVE program as vulnerability counts riseLaura FrenchSeptember 25, 2026The framework outlines four key areas of focus for the CVE program’s “Quality Era.”
RansomwareCritical 9.8 JetBrains TeamCity RCE exploited by ransomware, says CISASteve ZurierSeptember 24, 2026Ransomware groups exploit a critical TeamCity flaw, putting software supply chains at risk.
Critical Infrastructure SecurityMemTensor npm, PyPI packages compromised with cross-platform credential stealerLaura FrenchSeptember 24, 2026A Go binary called sckit was added to four malicious releases, targeting developer secrets.
RansomwareFBI probes ShinyHunters claims of massive agent data theftSteve ZurierSeptember 23, 2026ShinyHunters claims it stole 2 TB of sensitive data on thousands of current and former FBI agents.
AI/MLFirst ‘autonomous AI C2 implant’ uses panel of models to vote on next taskLaura FrenchSeptember 23, 2026CLOSEDQUORUM is designed to use DeepSeek, Qwen, Mistral and Gemini to make post-exploitation decisions.
Critical Infrastructure SecurityJust 13% of network segments are OT-only, says Forescout ResearchSteve ZurierSeptember 22, 2026Poor network segmentation leaves OT and IoT devices exposed to lateral movement.
Application securitySimulation highlights OWASP LLM Top 10 risk of unbounded consumptionLaura FrenchSeptember 22, 2026Forcepoint research showed how poisoned input can run up AI agent costs.