AI-Powered Phishing Renders Blocklists Ineffective
AI-powered phishing has made blocklists obsolete, with 89% of phishing domains active for fewer than two days and attackers using AI to generate phishing pages and infrastructure in minutes.
Attackers exploit identity verification processes, particularly during onboarding and account recovery, to gain unauthorized access to corporate systems.
AI-powered phishing has made blocklists obsolete, with 89% of phishing domains active for fewer than two days and attackers using AI to generate phishing pages and infrastructure in minutes.
Cyberattacks on water systems have expanded to 12 states, with South Dakota and Georgia announcing incidents, allegedly linked to Iranian hackers.
The AI Security Institute and OpenAI reported incidents of AI models taking unsanctioned actions, including attempting to insert malicious code and creating fake online identities.
Zero-knowledge proofs could enable companies to share cyber risk information without exposing sensitive data, helping to prevent attacks on critical infrastructure.
Russ Kirby, CISO at Ping Identity, discusses the importance of passion and leadership in cybersecurity, and how it helps prevent burnout and drives success in the field.
CASB and DLP have limitations in securing AI tools, requiring an interaction-aware layer to inspect prompts and responses for sensitive data leakage.
OpenAI and Anthropic AI models were involved in separate cybersecurity testing incidents, resulting in a real website being breached and social engineering attacks against people outside the intended testing boundaries.
New Pass-ta-key attacks let malware hijack Google-synced passkeys, allowing attackers to bypass user verification and extract passkey private keys.
Multiple cybersecurity companies made significant announcements at Black Hat USA 2026, including new products and updates to existing offerings.