❌

Normal view

There are new articles available, click to refresh the page.
Before yesterdayInformation Security Buzz

Architectural intent is the cornerstone for the future of software security

2 September 2026 at 07:58
With agentic AI further boosting productivity, human code review becomes a serious bottleneck. Developers need to move upstream, establishing the ground rules to ensure that AI plays by the rules. No matter how drastically artificial intelligence has changed the way software is created, human developers are still indispensable to the software development process. But the [...]

There is no Zero Trust in Zero Trust

2 September 2026 at 04:27
In January, the Cloud Security Alliance asked security professionals how they handle the identities on which their AI systems run. Fewer than a quarter of organizations had a documented, formally adopted policy for creating or removing one. More than 16% do not track when a new identity is created at all. Those identities hold tokens [...]

A reverse image search platform exposed more than 9 million facial images

24 August 2026 at 03:43
A publicly accessible database linked to reverse image search service ClarityCheck exposed more than nine million images, including photographs of adults, teenagers, and children. Cybersecurity researcher Jeremiah Fowler discovered the database, which was neither password-protected nor encrypted. It contained approximately 9,042,977 image files, amounting to 450.2GB of data. Most were stored in folders labeled β€œfaces” [...]

Post-DEF CON phishing campaign delivered AMOS and NetSupport malware

24 August 2026 at 03:42
A phishing campaign targeting attendees of Black Hat and DEF CON conferences involved distributing information-stealing malware and remote access malware via a malicious Google Doc and fake DocSend installers for macOS and Windows. The Huntress team learned about the phishing attack after one of its researchers received a direct message on X on August 9. [...]

AI agents taking unsanctioned action during cyber testing

24 August 2026 at 03:41
The UK’s AI Security Institute (AISI) has disclosed a security incident in which frontier AI agents took unsanctioned actions against real people and organisations during a controlled cybersecurity evaluation.Β  This included attempts to socially engineer software maintainers and insert malicious code into an open-source project.Β  The incident happened during routine cyber capability testing between 25 [...]

Walking the AI Security and ROI Tightrope

By: Joe Logan
17 August 2026 at 11:26
Organisations across every sector are accelerating their adoption of generative AI, driven by board-level expectations for rapid innovation and measurable business value. Yet the same boards are equally insistent that AI initiatives must not compromise security, privacy, or regulatory compliance, and not lead to runaway cost.Β  This dual mandate has placed CIOs and security leaders [...]

Fake evidence: How generative AI is changing fraud capabilities

14 August 2026 at 09:17
Scams are evolving with technology. Generative AI is a game changer for scammers and has been blamed for the rise in increasingly sophisticated phishing campaigns. It is also enabling scammers to add credibility to their schemes by providing a quick, cheap, and easy way to create fake websites, videos, documents, and photographs. Tasks that once [...]

10th Annual Security Serious Unsung Heroes Awards Open for Nominations

Cybersecurity PR agency Eskenzi PRΒ  has opened nominations for its tenth annual Security Serious Unsung Heroes Awards. The awards celebrate the UK’s most extraordinary cybersecurity professionals who work to make the industry not only more secure, but also more diverse, healthier and better informed about current events. Key sponsors include CultureAI, OneAdvanced and The Zensory. [...]

Expert panel: AI is writing the code. Who is defending it?

31 July 2026 at 05:56
AI is changing the way software is being developed. From generating code, helping developers make sense of new frameworks, reviewing pull requests, and even suggesting solutions for existing vulnerabilities, AI is playing an increasingly active role in the software development process. There is an upside here, too. AI is speeding up development, eliminating redundant efforts, [...]

One-click Claude Desktop flaw could enable hidden prompt injection and code execution

28 July 2026 at 07:12
Security researchers at Oasis Security have disclosed a vulnerability in Claude Desktop that could allow attackers to execute hidden prompts, access local files, exfiltrate conversation history, or execute code with a single click on a malicious link. The vulnerability, dubbed PromptFiction, affects the way Claude Desktop handled claude:// links.Β  According to the researchers, clicking one [...]

Russian state attackers exploiting misconfigured routers, new multi-nation advisory warns

28 July 2026 at 06:53
Russian state-sponsored actors are compromising poorly secured routers and networking devices around the world, with critical infrastructure organisations among the primary targets, reveals a new joint cybersecurity advisory from 20 government agencies.Β  The advisory attributes the activity to cyber actors associated with the Russian Federal Security Service (FSB) Center 16, saying the group continues to [...]

Americans are ignoring scam calls, but phishing emails still fool many

15 July 2026 at 02:28
Americans are becoming more effective at avoiding spam calls and texts, but new research suggests that the strategy comes with an unexpected cost. A new survey of 1,000 Americans from privacy company Cloaked, revealed that two-thirds of respondents have missed an important phone call because they ignored an unknown number. One in three have missed [...]

Sysdig uncovers first documented agentic ransomware operation

10 July 2026 at 03:36
Security researchers at Sysdig have documented what they believe is the first documented case of an AI agent running a ransomware operation from end to end. Dubbed JADEPUFFER, the operation used a large language model (LLM) to automate an attack that began with the exploitation of an internet-facing Langflow instance and ended in destructive database [...]

AI-assisted software engineering is creating a new delivery paradox

10 July 2026 at 03:35
AI can generate code faster than most software organizations can absorb it. This should be a productivity breakthrough, but it also exposes a larger problem: many of the processes surrounding software delivery still happen at human speed. A new white paper from code4thought looks at what happens when AI changes how quickly teams write software, [...]

Filigran report: Organisations can see their threats but can’t act fast enough

Fragmented tools and manual processes are widening the gap between threat awareness and effective CTEM. Only 41% of organisations have a fully consolidated view of cyber risk exposure, and security teams spend 42% of their time investigating risks that turn out to be low priority or non-exploitable At the same time, AI-driven CTEM processes expected [...]
❌
❌