Securing AI Applications
Security teams must prepare for AI applications moving into production, leveraging data-driven discussions, agility, and future-proofing to secure them.
Attackers exploit identity verification processes, particularly during onboarding and account recovery, to gain unauthorized access to corporate systems.
Security teams must prepare for AI applications moving into production, leveraging data-driven discussions, agility, and future-proofing to secure them.
Microsoft has shared mitigations for the YellowKey Windows zero-day vulnerability, tracked as CVE-2026-45585, which grants access to protected drives.
Microsoft seized infrastructure and disrupted a cybercrime service that created and sold over 1,000 code-signing certificates used to make malware appear trusted and legitimate.
Microsoft blames a recent macOS security update for non-dismissible location prompts in the Teams app on some macOS systems, affecting users who have enabled location access in their Teams settings.
Microsoft is introducing the Driver Quality Initiative to improve Windows 11 driver quality, focusing on safer user-mode drivers and better Windows Update catalog hygiene.
A previously unknown vulnerability in Huawei enterprise router software was exploited in a zero-day attack, causing a nationwide telecoms outage in Luxembourg last year.
Microsoft has disrupted a malware-signing-as-a-service operation that abused its Artifact Signing platform to generate fraudulent code-signing certificates used by ransomware gangs and other cybercriminals.
UK regulator Ofcom will require tech firms to remove non-consensual intimate images and curb deepfakes, with new rules taking effect this autumn.
Mini Shai-Hulud malware has compromised hundreds of npm packages, with the threat actor TeamPCP embedding a self-replicating worm that installs persistent backdoors and steals sensitive data.