search

Sections

Cyber Security

2432 articles

How AI Governance and Data Governance Are Converging in the Cloud
cybersecurity

How AI Governance and Data Governance Are Converging in the Cloud

Businesses of all sizes are increasingly recognizing the importance of data and AI governance as they scale their operations. Many companies prefer cloud-based ecosystems for their data management instead of investing in onsite equipment and software. This shift allows for better oversight and protocols while ensuring data protection and availability. Overall, the convergence of data and AI governance in the cloud is proving effective for enhancing compliance and operational efficiency.

Cloud Security Alliance ·
Threat tactic spotlight: Subdomain takeover
cybersecurity

Threat tactic spotlight: Subdomain takeover

In this blog post you’ll learn how to detect and prevent subdomain takeover – a tactic where threat actors exploit dangling DNS records to redirect traffic to attacker-controlled resources. We’ll explain the issue, how the situation arises, and how you can use various AWS features and services to help mitigate the impact of this tactic.

AWS Security Blog ·
15th June – Threat Intelligence Report
cybersecurity

15th June – Threat Intelligence Report

The Threat Intelligence Bulletin for the week of June 15 reports significant findings in cyber research. Notably, the University of Nottingham experienced a data breach when the hacking group ShinyHunters infiltrated its student records system. This breach compromised the personal information of approximately 454,600 current and former students, revealing their contact details and other sensitive data. For a comprehensive overview of recent threats and attacks, downloading the bulletin is recommended.

Check Point Research ·
From SQLi to RCE – Exploiting LangGraph’s Checkpointer
cybersecurity

From SQLi to RCE – Exploiting LangGraph’s Checkpointer

Yarden Porat discusses the necessity of memory in AI agents, specifically through frameworks like LangGraph, which includes checkpointers for maintaining execution state. However, vulnerabilities can arise if the persistence layer is not secure. LangGraph, an open-source tool for creating multi-agent AI systems with state management, is an extension of LangChain. The article delves into the potential exploitation of its checkpointer feature, a topic of concern highlighted by Check Point Research.

Check Point Research ·
Faster than the advisory
cybersecurity

Faster than the advisory

Chainguard often ships security fixes before advisories reach scanners. Learn why upstream speed matters in the era of AI-driven exploits.

Chainguard: Unchained ·
How Do You Measure FAIR Risk in the Mythos Era?
cybersecurity

How Do You Measure FAIR Risk in the Mythos Era?

TL;DR: Frontier AI models are discovering zero day vulnerabilities and weaponizing them in hours. Boards, regulators and underwriters have noticed, and they are asking a question most CISOs cannot answer: “What does our exposure cost in dollars?” Reporting in CVE counts and CVSS scores made sense when the threat timeline gave security teams room to

Aqua ·
Agentic AI Red Teaming: Tool Misuse is the Test That Matters
cybersecurity

Agentic AI Red Teaming: Tool Misuse is the Test That Matters

Agentic AI shifts the dynamics of red teaming, moving beyond the assessment of harmful text generation to consider the implications of AI systems that can plan, reason, and engage with various tools and workflows. This new approach highlights the necessity of red teaming specifically tailored for agentic AI. A recent research publication by CSA evaluates Microsoft’s Python Risk Identification Toolkit (PyRIT) as a means of effectively assessing risks associated with agentic AI.

Cloud Security Alliance ·
Proof is the Application Security Bottleneck
cybersecurity

Proof is the Application Security Bottleneck

A new survey report from the Cloud Security Alliance and Miggo Security reveals that despite extensive investments in shift-left security, application security teams are struggling to manage vulnerabilities effectively in production. The report highlights that the challenge now goes beyond just visibility; security teams face an overwhelming number of threat intelligence findings and alerts, indicating a need for improved strategies to address the complexity and volume of security issues.

Cloud Security Alliance ·
Securing the Swarm: Governance, Attack Surfaces, and Zero-Trust Architectures in Multi-Agent AI Environments
cybersecurity

Securing the Swarm: Governance, Attack Surfaces, and Zero-Trust Architectures in Multi-Agent AI Environments

Enterprise artificial intelligence has evolved from simple Large Language Model prompts to sophisticated multi-agent systems with significant operational autonomy. These advancements enhance software development, supply chain coordination, and threat responses. However, they also create new security vulnerabilities, making traditional methods of identity, data protection, and boundary defense less effective. Organizations must adapt to address these emerging risks effectively.

Cloud Security Alliance ·