Tag: enterprise security
94 articles

Enterprises Lag in AI Agent Governance
Most enterprises are playing with fire when it comes to AI agents, with a staggering 65% admitting that their AI agents have veered off course, causing measurable impacts in nearly 3 out of 10 cases. As organizations increasingly deploy AI at scale, governance gaps are leaving them vulnerable to risk.

PaperCut Vulnerabilities Expose Enterprises to Elevated Threats
PaperCut's recent vulnerabilities, CVE-2026-82078 and CVE-2026-81578, pose a severe threat to enterprises, allowing attackers to gain remote access to sensitive information with ease - and no authentication required. This alarming weakness has security experts warning of elevated risks and potential breaches.

AI Super-Users Expose Enterprises to Growing Security Risk
A small group of power users, known as "AI super-adopters," are driving a growing security risk for enterprises, interacting with AI models at 12 times the rate of their colleagues and embedding them into core business operations. These heavy users are having lengthy conversations with AI, with some exchanges lasting 18 prompts or more.

Attackers Exploit Trusted Collaboration Platforms for Identity Abuse
Collaboration platforms like Microsoft Teams and Slack have become a prime target for attackers, who are exploiting their trusted status to launch identity abuse attacks through chat phishing operations. These attacks are thriving, with 99% of alerts generated by one study related to chat phishing, signaling a major shift away from traditional email-based attacks.

Controls Fail to Halt Quiet Attacks
A shocking revelation from the Blue Report 2026: tweaking how Mimikatz dumps credentials can drop prevention rates from 94% to just 3%, exposing a gaping hole in our security defenses. Traditional controls can lull us into a false sense of security, as attackers increasingly take quieter, sneakier routes to their targets.

MCP Servers Expose Enterprise Secrets Through Flawed Security Practices
Are your organization's secrets safe with AI? The Model Context Protocol's security flaws are exposing enterprise secrets, making it crucial to assess how well your sensitive information is protected when shared with MCP servers.

Shadow AI Runs Rampant in 74% of Organizations
Most organizations are flying blind to the sprawling presence of AI tools, with 74% discovering more AI tools than they expected, and 30% of those finding 16 or more running in their environments. This unexpected AI use poses a governance problem, as these tools can access sensitive data, run code, and connect to other services.

AI Agents Expose Enterprises to Growing Prompt Injection Risk
A recent security audit revealed a staggering 36% of AI agent skills contain critical-level security issues, including malware distribution, prompt injection attacks, and exposed secrets. This widespread risk can have serious consequences for enterprises that deploy these skills in their production workflows.

AI Agents Exposed to Ghostjacking Attacks Bypassing Firewall Defenses
Imagine a stealthy attack that turns your own AI agents against you, routing sensitive email and web traffic around your firewall defenses - and it starts with just a single, seemingly harmless fake bug report. This sneaky technique, known as Ghostjacking, can leave even the biggest companies vulnerable to devastating breaches.

AI Agent Frameworks Expose Enterprise Security Gaps
A recent study revealed a shocking truth: many AI agent frameworks used by enterprises have gaping security holes that allow attackers to exploit them, even after a year of testing, 11 vulnerabilities were still found. This weakness not only puts AI models at risk of prompt injection, but also enables malicious content to spread into trusted framework logic.

Identity Attacks Expose Gaps in APAC's Cyber Defenses
Cyberattacks are wreaking havoc in APAC, with identity infrastructure compromises capable of crippling an organisation's ability to operate, and recovery timelines often stretching to weeks. When attackers gain control of Active Directory, they can bring an entire business to a grinding halt.

AI Attacks Expose Enterprise Security Gaps
Nearly a quarter of organizations have been hit with AI-powered attacks, exposing significant security gaps in their defenses. Are your company's critical business platforms protected from the growing threat of artificial intelligence-driven exploitation?

Security Fears Stall Microsoft Copilot Rollouts
Two-thirds of organizations are hitting the brakes on Microsoft Copilot rollouts, citing fears that the AI assistant could inadvertently spill confidential data. This widespread hesitation is driven by top-level concerns that Copilot might expose sensitive information from corporate systems.

AI Agents Expose Growing Enterprise Attack Surface
The rapid proliferation of AI agents in enterprise environments - up 466.7% in just one year - has created a massive, high-value target for cybercriminals, with these AI identities often being granted privileged access to core systems. This surge in AI adoption has significantly expanded the enterprise attack surface, making it a prime time for cyber threats to exploit these new vulnerabilities.

Security Leaders Seize AI Adoption With Proactive Governance
With AI tools like writing assistants and coding copilots now used by 76% of employees, security leaders are recognizing the need for proactive governance to stay ahead of the curve. Traditional blocking methods are no match for the speed of workarounds, which often take just minutes to find, versus official approval routes that can take weeks.

AI Connectors Exacerbate Security Risks in Enterprise Deployments
As AI connectors rapidly evolve, they can dramatically expand the risk of security breaches in enterprise deployments, introducing new vulnerabilities with each added integration. In fact, a recent analysis found that 37% of connectors changed in just six weeks, with thousands of new tools and rewritten descriptions heightening the threat.

Microsoft Warns of ACR Stealer Malware Surge Targeting Enterprise Customers
Microsoft warns of a surge in ACR Stealer malware attacks targeting enterprise customers, using clever social-engineering tactics and legitimate Windows tools to steal sensitive info. The malware, described as a malicious-as-a-service operation, has seen a significant spike in attacks between late April and mid-June.

Security Teams Must Adapt as AI Agents Disrupt Traditional Playbook
The era of predictable enterprise security is over: AI agents are autonomously accessing production data, forcing security teams to rethink everything they thought they knew. With AI agents blurring the lines between sanctioned and unsanctioned activity, traditional security playbooks are no longer effective.

Windows 10 Migration Stall Leaves Enterprises Exposed to Growing Security Risks
A surprising 16.9 percent of Windows devices still run Windows 10, leaving many enterprises vulnerable to growing security risks as they stall on migration. With the easy migrations already done, only the toughest cases remain, making it crucial to reassess and accelerate Windows 10 migration plans.

Progress Disrupts ShareFile Servers Over External Security Threat
If you're a ShareFile customer, take immediate action: shut down your Storage Zone Controller servers now to protect against a critical external security threat. Progress Software has already disabled access to affected accounts, but manual shutdown is crucial for safeguarding your data.

Lumen Technologies Rebuilds Exposure Management with Trusted Asset Data
Lumen Technologies' security team transformed their exposure management by consolidating 40 disconnected systems into one trusted view, growing their asset count from 17,000 to 1.1 million devices. This overhaul empowered them to respond to incidents with confidence, knowing who owned what and taking informed risk decisions.

Enterprises Reap AI Security Risks
Most enterprises are facing a harsh reality: a majority are reporting AI-related security incidents or vulnerabilities, highlighting a growing concern that can't be ignored. This stark statistic sets the tone for a crucial conversation about the intersection of AI and security.

Avalon Malware Framework Targets Enterprise with CrownX Ransomware
Meet Avalon, a sneaky malware framework that's targeting enterprises with a potent ransomware punch, known as CrownX, and discover how it infiltrates systems through clever phishing tactics. This modular menace combines credential collection, lateral movement, and more into a single, reusable threat.

AI Agents Emerge as Unchecked Identities in Enterprise Security
The equation for enterprise security is no longer simple: with AI agents now connected to critical business services, controlling identities is no longer enough to control risk. These emerging insiders have quietly become privileged - and potentially invisible - attack paths that security and identity programs must urgently address.