AI Agents Disrupt Security Playbook
AI agents have broken the traditional security playbook, requiring a new approach that assumes environments are dynamic and unpredictable, with security teams needing to own the operational layer.
Attackers exploit identity verification processes, particularly during onboarding and account recovery, to gain unauthorized access to corporate systems.
AI agents have broken the traditional security playbook, requiring a new approach that assumes environments are dynamic and unpredictable, with security teams needing to own the operational layer.
The security of operational technology (OT) systems is a growing concern, with legacy systems and real-world impacts making it a complex issue to address. OT security issues are distinct from IT security issues, with a greater emphasis on preventing denial of service (DoS) attacks that can have catastrophic consequences.
A flaw in the Claude Chrome extension allows malicious extensions to trigger predefined AI actions, potentially abusing access to connected services like Gmail and Salesforce.
Attackers are exploiting two zero-day vulnerabilities, CVE-2026-15409 and CVE-2026-15410, in SonicWall SMA1000 appliances, with the goal of ransomware attacks.
Microsoft releases Windows 10 KB5099539 extended security update, fixing 570 vulnerabilities, including two exploited and one publicly disclosed zero-day flaws.
Democratic senators pressed Jay Clayton, President Trump's pick for director of national intelligence, on election security and integrity, but left unsatisfied with his answers.
A Russian-speaking threat actor used Google's Gemini CLI AI tool to operate a small-scale botnet and deploy malware, with the AI agent responding to prompts and proposing operational improvements.
Cyberstalkers are exploiting Google Chrome's sync feature to spy on device owners' browsing history and gain access to stored passwords, according to researchers at Certo Software.
New research shows that a