Tag: information security
65 articles

Tech Giants Warn of AI-Driven Cyber Threats, Push for AI-Powered Defenses
The world's top tech and security companies are sounding the alarm: AI-driven cyber threats are on the rise and we only have a small window of time to boost our defenses before attacks become more widespread and sophisticated. Over 100 industry giants, including OpenAI, Google, and Microsoft, are urging for AI-powered defenses to protect critical infrastructure like hospitals and water treatment plants.

NIST Seeks Overhaul of Vulnerability Database for AI-Driven Era
The National Institute for Standards and Technology is calling for a major revamp of its National Vulnerability Database to better tackle software vulnerabilities in the AI-driven era. It's seeking public input on how to modernize the database and its processes to stay ahead of emerging threats.

USENIX Security Symposium Tackles AI-Driven Paper Surge
The USENIX Security Symposium has seen a record-breaking surge in submissions, with approximately 3,030 valid papers pouring in - a significant jump from last year's 2,400. To keep pace, the conference expanded its Program Committee to handle the influx of innovative research in the security community.

Zero-Knowledge Proofs Offer Secure Path for Cyber Risk Disclosure
ZKPs offer a game-changing solution, allowing companies to securely share proof of vulnerabilities without exposing sensitive data that could be exploited by attackers. By using ZKPs, organizations can demonstrate the truth of a statement, such as confirming a specific vulnerability exists, without revealing confidential details.

AI Platforms Shine in SOCs with Clear Roles
Discover how AI platforms are revolutionizing Security Operations Centers (SOCs) by taking on high-level roles and freeing teams to focus on critical threats. By integrating with existing security tools, these platforms enable teams to efficiently sift through millions of alerts and catch potential threats that might otherwise fly under the radar.

UK Government Investments Exposes Official Contact Data in 40-Hour Breach
A simple mistake by a staff member at UK Government Investments left sensitive contact information of 51 government officials exposed to the public for a staggering 40 hours. The breach, revealed in the organization's annual report, highlights the importance of following basic security protocols to protect official data.

Botnets Persist Despite Takedowns, Fueled by Residential Proxy Networks
Botnets just won't quit, and it's no surprise why - there's a thriving market for access to millions of IPs, making it easy for them to keep growing and snaring more victims. Residential proxy networks are fueling this expansion, with nearly 60 million victim IP addresses globally and a significant chunk of them right here in the US.

Evaluating AI in Security Operations Requires New Framework
When evaluating AI in security operations, it's crucial to determine if it can deliver accurate verdicts across various scenarios and attack surfaces - and surprisingly, verdict quality only improves dramatically once a certain threshold of relevant data, such as identity and context, is reached. Below that threshold, no amount of fine-tuning can compensate.

Staffing Shortages Plague Security Operations Centers
The 2026 SANS SOC Survey reveals a disconnect: while 79% of respondents use AI or machine learning tools, only 36% have integrated them into a defined workflow, highlighting a key challenge in Security Operations Centers. Practitioners cite staffing shortages as their top operational challenge, but leaders seem less concerned.

OWASP Unveils Framework to Gauge Agentic AI Security Maturity
As organizations rapidly deploy AI agents, governance often lags behind - but a new framework from OWASP aims to change that. The Enterprise Adoption Maturity Model provides a practical roadmap for gauging and improving agentic AI security maturity.

AI Transforms SOCs, But Human Analysts Remain Vital
AI is revolutionizing Security Operations Centers, but not by replacing human analysts - instead, it's freeing them from tedious tasks to focus on high-stakes decision-making. By automating routine work, AI is augmenting human capabilities, not replacing them.

NIST's Vulnerability Database Plagued by Duplication, Inefficiency
The National Vulnerability Database is facing a massive backlog crisis, with unprocessed security flaws doubling from 13,000 in June 2024 to over 27,000 by the end of 2025, and officials admit they lack a long-term plan to tackle the problem. Despite promising to clear the backlog by September 2024, the database continues to struggle with inefficiencies and a lapsed contract.

Cybersecurity Pros Prefer CISOs With Live Attack Response Experience
When it comes to cybersecurity leadership, professionals trust those who have been battle-tested, with 75% believing that experience in live attack response boosts a leader's credibility. Hands-on experience navigating high-pressure incidents gives leaders a unique perspective, composure, and trustworthiness.

Infosecurity Europe Spotlights Cyber Startups
Get ready to witness the future of cybersecurity as five innovative startups take the stage at Infosecurity Europe 2026 to pitch their game-changing ideas and compete for a coveted prize package. The event will also feature a dedicated Cyber Startups Zone, where you can discover the latest solutions and meet the minds behind them.

Global Agencies Unveil AI Supply Chain Risk Guidance with SBOMs
Global agencies have joined forces to release groundbreaking guidance on AI supply chain risk, outlining minimum elements for Software Bill of Materials (SBOMs) to enhance security and transparency. This crucial step forward aims to tackle the complex challenges of measuring and defining AI risks across organizations.

CISA Taps AI Automation to Bolster Threat Analysis Capabilities
With AI automation, CISA analysts can quickly sift through threats, cutting through the noise to focus on what matters most. This tech boost has supercharged their Security Operations Unit, enabling rapid, real-time assessments that help prevent threats from unfolding.

CISOs Confront Growing Skills Gap in Cybersecurity Teams
A growing concern for CISOs is the widening skills gap in their cybersecurity teams, with 60% citing a lack of skilled staff as a bigger challenge than filling vacant positions. The right people with the right skills are proving harder to find than more bodies to fill open roles.

NCSC Warns of Flawed SOC Metrics
The National Cyber Security Centre is warning that common security operations center metrics are fundamentally flawed, and that the only metric that truly matters is whether attacks are detected and responded to in a timely manner. By focusing on easily quantifiable but misleading metrics, organizations may inadvertently be encouraging their teams to prioritize speed over substance.

Cybersecurity Salaries Stagnate Amid Rising Threats and Workloads
Despite the rising demand for cybersecurity experts, a shocking 71% of infosec pros worldwide - and 77% in the UK - have seen their salaries stagnate over the past year, leaving them lagging behind their peers in other tech fields.

Education Sector Grapples with 63% Surge in Cyber-Attacks
The education sector is facing a daunting reality: a 63% surge in cyber-attacks is putting institutions at risk, threatening the very openness and collaboration that define higher education. Can schools and universities keep pace with the growing threat?

NIST Scales Back Vulnerability Ratings Amid Surge in Submissions
The National Institute of Standards and Technology is overhauling its vulnerability rating system, scaling back severity scores for lower-priority flaws as submissions surge. This change means some software flaws will no longer get a severity score, shifting focus to the most critical vulnerabilities.

Anthropic's Claude Mythos Preview Bolsters Cybersecurity Leaders
Anthropic's Claude Mythos Preview is giving select cybersecurity giants a powerful edge, and we're exploring what this exclusive rollout means for the industry. By granting early access to this cutting-edge AI model, Project Glasswing is poised to reshape the cybersecurity landscape.

Vendor Breaches Spotlight Healthcare's Cyber Vulnerability
Recent vendor breaches have exposed healthcare's alarming cyber vulnerability, raising critical questions about who bears the cost - and the consequences - when a vendor's systems fail. As the threat landscape evolves, one thing is clear: the healthcare industry must rethink its approach to cybersecurity and vendor risk management.

Risk Management Takes Critical Turn with NIST SP 800-39 Insights
In today's high-risk digital landscape, effective risk management is no longer a choice - it's a necessity for protecting your organization's information systems and sensitive data. By adopting a comprehensive risk management approach, you can ensure the confidentiality, integrity, and availability of your data and stay ahead of evolving cyber threats.