
Fewer CVEs, more accurate findings: Wiz now scans Chainguard Libraries for Python and Java
Wiz now scans Chainguard Libraries for Python and Java, combining trusted, source-built dependencies with risk-based visibility and remediation.
2432 articles

Wiz now scans Chainguard Libraries for Python and Java, combining trusted, source-built dependencies with risk-based visibility and remediation.

NIST’s shift to risk-based enrichment makes one thing clear: modern security teams need more than a single public source. In the AI era, trusted vulnerability intelligence depends on multiple signals, human validation, and clear context.

Varonis Threat Labs has identified a significant vulnerability known as SearchLeak in Microsoft 365 Copilot Enterprise. This multi-stage vulnerability allows attackers to easily access and steal sensitive information, including MFA codes, emails, meeting details, and confidential organizational files, with just one click. The discovery highlights serious security risks associated with Microsoft 365 Copilot, which can be exploited for silent data exfiltration.

Amazon Web Services (AWS) recently announced support for resource-based policies and resource control policies (RCPs) for AWS Sign-In. By using resource-based policies and RCPs, you can restrict access to the AWS Management Console sign-in and aws login CLI sessions to requests from your expected networks, your on-premises data center networks, and your Amazon Virtual Private

Learn how CNAPP platforms are helping organizations prioritize exploitable risks, reduce exposure, and operationalize security across the application lifecycle. The post CNAPP evolution: How Microsoft aligns with leading cloud risk management platforms appeared first on Microsoft Security Blog.

Machine learning models are not like other software artifacts. A single fine-tuned LLM can weigh 70 GB. A model family may share 95% of its weights across dozens of variants. When hundreds of developers, training jobs, and GPU clusters all need the same model at the same time, the infrastructure underneath needs to be built

Organizations have traditionally viewed SaaS security primarily as an access management issue, focusing on implementing Single Sign-On (SSO), Multi-Factor Authentication (MFA), and efficient user provisioning processes. However, the landscape of SaaS breaches has evolved, as illustrated by the recent ADT breach linked to the ShinyHunters extortion group. Reports indicate that attackers exploited an employee’s Okta account via a voice phishing attack, highlighting the need for a more comprehensive approach to security.

The landscape for AI regulation is changing quickly, influenced by new federal policies, a surge of state-level laws, and specific industry compliance needs. Organizations recognize the necessity for AI governance but often struggle with the complexities of this evolving environment. Proactive companies are not waiting for definitive regulations; instead, they are developing governance frameworks to ensure they can adapt to and comply with emerging requirements effectively.

Claude Cowork is not just a chatbot with additional features; it operates as a local agent on employees’ machines. This allows it to access files, execute shell commands, navigate the web using stored cookies, and connect to various enterprise systems. According to Anthropic, the potential impact of an issue with Cowork hinges on its access and permissions, significantly altering the threat model. A prompt injection attack can have varied consequences based on what Claude can read and execute.

Organizations increasingly rely on complex digital ecosystems that encompass cloud services, SaaS applications, API integrations, and outsourced infrastructure. Although these technologies enhance scalability and efficiency, they raise significant security challenges. As businesses expand their vendor networks, security and procurement teams face lengthy due diligence processes, repetitive security questionnaires, and a lack of visibility into third-party risks, complicating risk management.

Quantum computing and artificial intelligence (AI) are commonly seen as distinct technologies, each poised to revolutionize their respective fields. Quantum computing expands the boundaries of computational capabilities, while AI is transforming software development, data analysis, and decision-making processes. However, a more intriguing aspect lies in the potential synergy between these two technologies. The CSA’s recent publication discusses how quantum computing could enhance AI, creating a future of Quantum Artificial Intelligence.

Security control frameworks are expanding in both scope and complexity, with the CSA AI Controls Matrix featuring 243 control objectives and the NIST CSF containing hundreds of subcategories. Organizations utilizing multiple frameworks must perform mapping for compliance, gap analysis, risk aggregation, and audit preparation. Large Language Models (LLMs) have become essential for this task, enabling rapid and structured mapping across frameworks, streamlining the compliance process significantly.