Category index

Cyber Security

4276 articles

4276 ARTICLES

FEATURED REPORT

The Hidden Risks of the Agentic Enterprise: Bridging the AI Governance Gap

Software used to wait for permission. It executed specific instructions predictably, transparently, and only when a human initiated a process. Today, AI agents are crowding into IT environments. These autonomous entities can execute complex workflows, access critical systems and sensitive data, and even spawn additional agents to complete tasks. No humans required. New research from Okta reveals the speed and scale at which enterprises and employees are adopting AI agents. Its global sur…

BY
MIN READ 1 MIN READ
EXPLORE north_east
The Hidden Risks of the Agentic Enterprise: Bridging the AI Governance Gap
Unpacking the Salesloft Incident
CYBERSECURITY

Unpacking the Salesloft Incident

Introduction On August 26, 2025, Google Threat intelligence Group released a report detailing a widespread data theft campaign targeting the sales automation platform Salesloft, via compromised OAuth tokens used by the third-party Drift AI chat agent [1][2]. The attack has been attributed to the threat actor UNC6395 by Google Threat Intelligence and Mandiant [1]. The attack is believed to have begun in early August 2025 and continued through until mid-August 2025 [1], with…

1 MIN READ arrow_forward
ISO 42001: The Importance of Knowing Your Role Before Building Your AI System
CYBERSECURITY

ISO 42001: The Importance of Knowing Your Role Before Building Your AI System

ISO/IEC 42001:2023 is the first international standard for an Artificial Intelligence Management System (AIMS). Structured similarly to other ISO management system standards, like ISO 27001, with mandatory clauses 4 through 10 and an Annex A control set, it shares the same Plan-Do-Check-Act logic familiar to any management system practitioner. But among other AI specific considerations, it contains a requirement that sets it apart from other ISO frameworks: as part of scoping your AIMS,

1 MIN READ arrow_forward
Enforce least-privilege authorization in multi-agent AI chains using Cedar
CYBERSECURITY

Enforce least-privilege authorization in multi-agent AI chains using Cedar

If you’re building multi-agent AI systems, you need to prevent authorization scope from silently expanding as agents delegate tasks through multi-hop chains. Without proper controls, an agent can potentially act beyond what the originating user authorized, even when role-based access control (RBAC) policies are in place. The OWASP Top 10 for Agentic Applications classifies this

1 MIN READ arrow_forward
Is Your AppSec Program Built to Close the OWASP Top 10 2025 Coverage Gap?
CYBERSECURITY

Is Your AppSec Program Built to Close the OWASP Top 10 2025 Coverage Gap?

Key Takeaways Most AppSec programs treat API-layer coverage as a DAST extension, but BOLA, BFLA, and SSRF require authenticated multi-role testing that traditional scanners weren’t built to run at scale. Modern authentication flows (OAuth2, JWT validation, MFA-protected sessions) often fall outside standard scan scope, meaning the exact endpoints where account takeover occurs go untested. TotalAppSec

1 MIN READ arrow_forward
Cavern Manticore: Exposing Iran-Linked Modular C2 Framework
CYBERSECURITY

Cavern Manticore: Exposing Iran-Linked Modular C2 Framework

Key Points Introduction Since early 2026, Check Point Research (CPR) has tracked a new modular command-and-control framework used by Cavern Manticore, an Iran-nexus APT group primarily targeting Israeli organizations, with a focus on IT providers, and government sectors. Cavern Manticore is an Iran MOIS (Ministry of Intelligence and Security)-linked actor, with links to the OilRig […] The post Cavern Manticore: Exposing Iran-Linked Modular C2 Framework appeared first on Check Point Research.

1 MIN READ arrow_forward
6th July – Threat Intelligence Report
CYBERSECURITY

6th July – Threat Intelligence Report

For the latest discoveries in cyber research for the week of 6th July, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES River Bank & Trust, a US financial institution, has experienced a ransomware incident after an unauthorized actor accessed the network of parent company River Financial Corporation on June 16. The bank found […] The post 6th July – Threat Intelligence Report appeared first on Check Point Research.

1 MIN READ arrow_forward
Summer of Clearinghouses
CYBERSECURITY

Summer of Clearinghouses

Clearinghouses alone won’t secure open source. Learn why actuation, trusted builds, and secure-by-design software matter more than vulnerability data.

1 MIN READ arrow_forward