AI Agents Are a New Kind of Identity & Most Organizations Aren’t Ready

As AI-powered agents increasingly become integrated into organizational workflows, many companies are struggling to keep pace with the unique security risks they pose. These autonomous entities, designed to automate tasks and make decisions on their own, are fundamentally different from traditional non-human identities such as service accounts or API tokens. If organizations continue to treat … Read more

European Organizations Have a Collaboration Security Confidence Gap

European Organizations’ Collaboration Security Confidence Gap Exposed by New Survey A recent survey conducted by communications provider Wire has revealed a stark contrast between the security confidence of European IT professionals and the reality of their collaboration environments. Despite an impressive 84% of respondents expressing confidence in the security of their collaboration tools, the survey’s … Read more

AI Gateways Offer Attackers the Keys to the Kingdom

As a growing number of organizations deploy AI gateways to manage access to foundation models, they are inadvertently creating a new surface for attackers to exploit. A recent incident highlights how a threat actor gained access to an EC2 server hosting an AI gateway connected to Amazon Bedrock services, using the access for cryptomining but … Read more

As Global Conflicts Go Digital, Businesses Need Wartime Gameplans

As Global Conflicts Go Digital, Businesses Need Wartime Gameplans The world of modern warfare has taken a drastic turn with the increasing involvement of cyberattacks. A recent incident involving a Ukrainian tax software company highlights the devastating impact that can occur when global conflicts go digital. Intellect Services, a mid-sized family-owned business in Ukraine, was … Read more

Microsoft Reins in RoguePlanet Zero-Day Threat

Microsoft has tackled another zero-day vulnerability published by a disgruntled security researcher, issuing an out-of-band patch for RoguePlanet, an elevation-of-privilege flaw in Windows Defender. The high-severity vulnerability could have allowed an attacker to escalate privileges on a Windows device from a basic user to the highest SYSTEM-level access, effectively granting them complete control over the … Read more

Microsoft Reins in RoguePlanet Zero-Day Threat

Microsoft has issued an emergency patch for a critical zero-day vulnerability in Windows Defender, dubbed RoguePlanet, which was made public by a disgruntled security researcher known as “Nightmare-Eclipse” just last month. The flaw, tracked as CVE-2026-50656, allows an attacker to escalate privileges on a Windows device from a basic user to the highest SYSTEM-level access, … Read more

Iran’s Cyber Crosshairs Focus Beyond Critical Infrastructure

Iran’s Cyber Crosshairs Focus Beyond Critical Infrastructure, Warning to All Organizations A recent spate of cyberattacks linked to Iran has sparked a false sense of security among companies that don’t operate in critical infrastructure sectors. These organizations assume they’re not at risk because they’re not high-profile targets like power grids or water utilities. However, the … Read more

Microsoft expects more Windows security updates from AI-discovered flaws

As AI-powers its vulnerability discovery capabilities, Microsoft is bracing users for an influx of Windows security updates. In a recent blog post, the tech giant revealed that advances in artificial intelligence have significantly accelerated the pace of vulnerability discovery, allowing engineers to identify more security issues before they can be exploited in zero-day attacks. This … Read more

New Helix vishing group emerges in SharePoint data theft attacks

A new and highly effective data-extortion group has emerged, targeting organizations through a combination of identity-focused tactics and social engineering. The group, known as Helix, has already been linked to several high-profile attacks against companies such as Medtronic, Nissan, and Kodak. Helix’s modus operandi involves initial contact with employees via voice phishing (vishing) calls, where … Read more