Category index

Cyber Security

4276 articles

4276 ARTICLES

SearchLeak: How We Turned M365 Copilot Into a One-Click Data Exfiltration Weapon
CYBERSECURITY

SearchLeak: How We Turned M365 Copilot Into a One-Click Data Exfiltration Weapon

Varonis Threat Labs discovered SearchLeak, a critical vulnerability chain in Microsoft 365 Copilot Enterprise that allows an attacker to steal sensitive data — MFA codes, email messages, meeting details, and private organizational files — with a single click. Varonis Threat Labs has uncovered a new three-stage vulnerability chain that turns Microsoft 365 Copilot Enterprise Search into a silent data exfiltration weapon. Dubbed SearchLeak, the chain combines a relatively new class

1 MIN READ arrow_forward
Restrict AWS Management Console access to expected networks with sign-in resource-based policies and RCPs
CYBERSECURITY

Restrict AWS Management Console access to expected networks with sign-in resource-based policies and RCPs

Amazon Web Services (AWS) recently announced support for resource-based policies and resource control policies (RCPs) for AWS Sign-In. By using resource-based policies and RCPs, you can restrict access to the AWS Management Console sign-in and aws login CLI sessions to requests from your expected networks, your on-premises data center networks, and your Amazon Virtual Private

1 MIN READ arrow_forward
The SaaS Security Problem Most Organizations Still Treat Like an IT Issue
CYBERSECURITY

The SaaS Security Problem Most Organizations Still Treat Like an IT Issue

For years, organizations approached SaaS security as an access management problem. Enable SSO. Turn on MFA. Provision users correctly. Deprovision them quickly. Audit permissions periodically. That model no longer reflects how modern SaaS breaches actually happen. The recent ADT breach attributed to the ShinyHunters extortion group demonstrates why. According to reports, attackers allegedly compromised an employee’s Okta account through a voice phishing attack and used that foothold to…

1 MIN READ arrow_forward
AI Regulation Keeps Evolving: How to Develop an AI Governance Framework That Adapts
CYBERSECURITY

AI Regulation Keeps Evolving: How to Develop an AI Governance Framework That Adapts

The regulatory landscape for AI is shifting rapidly between evolving federal policies, an explosion of state-level legislation, and the emergence of industry-specific compliance requirements. Many organizations know they need AI governance but may face uncertainty about how to navigate the evolving landscape. The most forward-thinking companies aren’t waiting for regulatory clarity, they’re building governance frameworks now that will position themselves to adapt and comply with whatev…

1 MIN READ arrow_forward
Top 6 Claude Cowork Security Risks to Watch
CYBERSECURITY

Top 6 Claude Cowork Security Risks to Watch

Most security teams evaluate Claude Cowork as if it were a chatbot with extra buttons. It isn’t. Cowork is a local agent that runs on the employee’s machine, reads their files, runs shell commands, browses the web with their logged-in cookies, and connects to the enterprise systems they can reach. As Anthropic frames it, when something goes wrong, the impact depends on what Claude can read and what Claude is allowed to do. That changes the threat model. A prompt injection against a ch…

1 MIN READ arrow_forward
The Role of CSA STAR in Vendor Security Assessments
CYBERSECURITY

The Role of CSA STAR in Vendor Security Assessments

Most organizations operate across complex digital ecosystems that include cloud providers, SaaS platforms, API integrations, and outsourced infrastructure. While these technologies enable scalability and operational efficiency, they also introduce additional security considerations. As vendor networks expand, security and procurement teams often encounter lengthy due diligence processes, repetitive security questionnaires, and limited visibility into third-party risks. Managing tra…

1 MIN READ arrow_forward