Vue normale

Il y a de nouveaux articles disponibles, cliquez pour rafraîchir la page.
Aujourd’hui — 3 août 2026Flux principal
À partir d’avant-hierFlux principal

ESET tracks rise in malicious AI skills and adaptable malware

31 juillet 2026 à 16:01
Attackers are adapting established techniques to AI platforms, emerging technologies, and changing user behavior. ESET's new threat report examines the rise of malicious AI skills, AI-assisted malware, ClickFix attacks, record quishing activity, and ransomware tools designed to disable security software. [...]

After the Break-In: What Attackers Do Once They're Already Inside

30 juillet 2026 à 16:01
Attackers rarely stop after gaining initial access. Huntress analyzes a real-world intrusion to show how threat actors establish persistence, disable defenses, and reshape compromised systems, and why defenders must investigate the original entry point rather than simply remove the malware. [...]

Is Your SSO Protected Against Modern Credential Attacks?

28 juillet 2026 à 16:00
A compromised SSO login can provide attackers with access to multiple enterprise applications and services. Specops Software explains how stronger passwords, phishing-resistant MFA, and identity hardening help secure modern SSO environments and the applications they protect. [...]

Shadow AI agents are multiplying. Here's how to find and secure them.

27 juillet 2026 à 16:01
Shadow AI agents are rapidly spreading across enterprise platforms, often without IT or security visibility. Nudge Security explains how organizations can discover, assess, and govern AI agents before unmanaged permissions and autonomous actions create security risks. [...]

Slopsquatting, Phantom Domains, and HalluSquatting Are the Same AI Attack

24 juillet 2026 à 16:01
Slopsquatting, phantom squatting, and HalluSquatting all exploit the same late-binding attack pattern, where AI coding agents trust hallucinated package, repo, or domain names. ActiveState explains how pre-fetch verification and governed dependency management can help stop these attacks before malicious code enters the pipeline. [...]

FedRAMP Rev5 Is Ending: What the 20x Transition Really Requires

23 juillet 2026 à 16:00
FedRAMP 20X replaces point-in-time assessments with continuous, machine-readable evidence that demonstrates security controls are working. Anecdotes explains what the transition from Rev5 to FedRAMP 20X means and how organizations can prepare for continuous, evidence-based assurance. [...]

How enterprise GenAI can amplify ransomware risk — and how to contain it

22 juillet 2026 à 17:30
Enterprise AI can accelerate ransomware attacks when AI assistants and agents inherit excessive permissions or compromised identities. Acronis explains how identity controls, governance, and least-privilege access help reduce AI-enabled ransomware risk while supporting secure AI adoption. [...]

An AI SOC Evaluation Guide for Security Leaders

20 juillet 2026 à 16:01
Choosing an AI SOC platform requires understanding how it will perform in your own environment, not just during an evaluation. Prophet Security shares a practical framework for assessing AI SOC solutions, including how to validate accuracy, operating models, long-term reliability, and production readiness. [...]

The Future of Age Verification: Your Face Never Leaves Your Device

18 juillet 2026 à 15:15
As age verification laws expand worldwide, organizations face growing pressure to protect users' privacy while meeting regulatory requirements. Incode explains how on-device age estimation verifies age without transmitting or storing facial images, reducing biometric privacy risks while supporting compliance. [...]

Inside the Search for "Clean" Residential Proxies for Carding

17 juillet 2026 à 16:00
Residential proxies are no longer the silver bullet they once were for carding. Flare explains why cybercriminals increasingly seek "clean" residential proxies and combine them with browser fingerprints, device profiles, and other identity signals to evade modern fraud detection. [...]

AI Agents Broke the Security Playbook. Here's What Replaces It.

16 juillet 2026 à 16:00
Traditional security workflows were built for environments that changed at human speed. Token Security explains why AI agents require a new approach: building on a live identity foundation while giving security teams the flexibility to create workflows tailored to their own environments. [...]

We built a vulnerability vending machine: AI tokens in, zero-days out

15 juillet 2026 à 16:01
Intruder built an AI-powered "vulnerability vending machine" that combines code slicing with LLMs to automatically discover complex software vulnerabilities. The company explains how the system found and exploited a previously unknown WordPress plugin zero-day, with additional discoveries already under responsible disclosure. [...]

You Don't Have to Run an Exploit to Know If You're Vulnerable

14 juillet 2026 à 16:00
Many vulnerabilities cannot be safely validated with live exploits, either because no exploit exists or the affected systems are too critical to test. Picus explains how TTP chaining helps organizations determine exploitability by validating the attack techniques an exploit depends on, without launching the exploit itself. [...]

The Replicant in Your Directory: AI Agents and the Identity Security Gap

10 juillet 2026 à 16:00
AI agents are accelerating the growth of non-human identities, making it harder for organizations to understand what exists, who owns it, and what it can access. Netwrix explains why stronger visibility and identity governance are essential as AI expands the enterprise attack surface. [...]
❌
❌