Reading view

There are new articles available, click to refresh the page.

Shadow AI: The New Frontier of Shadow IT

As a CISO advisor, I am observing a familiar pattern gaining a new, critical dimension. What we historically identified as "Shadow IT", the use of unapproved SaaS and tools, is rapidly evolving into "Shadow AI."

Employees are increasingly leveraging AI bots for drafting, analysis, code generation and strategic decision-making. While the intention is often to drive efficiency, the lack of governance creates a dangerous risk surface: sensitive data leakage, compliance violations and the potential for operational decisions based on unverified, AI-generated content.

The Blind Spot: How “Bulletproof” Phishing Redirectors Slip Past SEGs

By Shikhar Dalela and Jeewan Singh Jalal

The operators named the kit themselves.

Buried inside compromised legitimate websites, the hidden staging directory is sometimes literally called “/.bulletproof”, and the PHP session cookie the kit sets on every visitor is named “bp_redir_sess.” The “bp” stands for bulletproof, which is an unusual degree of candor from a threat actor whose entire design philosophy is concealment.

❌