Practical lessons from deploying AI securely at scale
When I first started working on enterprise AI security initiatives, I expected the biggest challenges to be technical. I assumed we’d spend most of our…
When I first started working on enterprise AI security initiatives, I expected the biggest challenges to be technical. I assumed we’d spend most of our…
Most organizations assume remediation reduces risk. It’s a reasonable assumption. A vulnerability is identified, a patch is applied, the scanner comes back clean, and the…
The attackers could have simply extracted or manipulated data through SQL injection, but instead, they expanded the exploit to include long-term persistence and remote command…
After more than 300,000 production penetration tests (pentests), our company has learned something that may surprise people watching the recent wave of autonomous security announcements.…
Cybersecurity is full of frameworks, regulations, and directives that tell organizations what they should do. Zero Trust, NIST, CIS Controls, CMMC, DORA, NIS2, and now…
AI is accelerating vulnerability discovery, exploit development, and attacker weaponization faster than most organizations can adapt. Security teams are inundated with vulnerability disclosures, threat intelligence…
For decades, cybersecurity has been built around one assumption: defenders had enough time to: Discover vulnerabilities. Assess exposure. Deploy patches. Verify that critical systems remained…
The updated Cybersecurity Maturity Model Certification (CMMC) represents a critical evolution in the Department of War (DoW) strategy to secure the Defense Industrial Base (DIB).…
Meta has become the third frontier AI developer in recent weeks to disclose a security incident involving one of its advanced AI models during cyber…
Severe business downtime can cost millions Business downtime can also be significantly costly for a breached organization, depending on the level and extent of the…
Fixing is not the same as securing Instead of simply checking whether the fixed code compiled or passed automated tests, 1Password said it reviewed every…
Moucka and other members of the group used stolen login credentials to compromise data belonging to at least 165 customers of a US-based software-as-a-service company.…