Latest from todayGoogle makes Gemini 4 AI model available to a trusted fewGoogle’s latest frontier model will offer expanded token capacity for complex enterprise workloads when it is eventually released — but for now, its benchmark results are mixed.By Nidhi SingalOct 1, 20265 minsArtificial IntelligenceSecurity Cisco SD-WAN Manager hit by zero-day admin access attackBy Shweta SharmaOct 1, 20264 minsNetwork SecurityVulnerabilitiesZero-Day Vulnerabilities Unsloth’s model picker had a code-execution problemBy Shweta SharmaSep 30, 20264 minsArtificial IntelligenceCode SecurityDevelopment ToolsOpenAI pulls the plug on GPT 6.1 Astra as agents keep crossing linesBy Shweta Sharma Sep 29, 20265 minsArtificial IntelligenceIT GovernanceIT Leadership Nvidia releases Open Agent Safety Platform to monitor and govern agentic AIBy Evan Schuman Sep 28, 20268 minsBusinessEnterpriseMarkets OpenAI pauses AI model training after another agent bypasses network restrictionsBy Anirban Ghoshal Sep 28, 20265 minsArtificial IntelligenceIT GovernanceNetwork Security Autonomous agents attack Azure using compromised identities, destroying resourcesBy Gyana Swain Sep 28, 20266 minsArtificial IntelligenceCloud SecurityIdentity and Access Management NetScaler admins told to patch critical zero-days in ADC and Gateway nowBy Shweta Sharma Sep 28, 20264 minsNetwork SecurityRemote Access SecuritySecurity Stolen AI credentials feed growing LLM proxy economyBy Lucian Constantin Sep 28, 20266 minsAPIsAccess ControlCybercrime AI tools help hacker break in for $25 per target Major retailers were hit by sophisticated attacks performed on the cheap. By Maxwell Cooter Sep 25, 2026 2 mins Cyberattacks Cybercrime Retail Industry Documentation placeholder domain used in ClickFix attacks Following instructions can lead to bad things, as this increasingly common attack method can bypass Windows protections. By Maxwell Cooter Sep 25, 2026 2 mins Cybercrime Malware Security GitLab issue email’s only security is obscurity A long-lived token embedded in GitLab’s issue-creating email address means anyone with the address, not just the project owner, can push code and trigger CI/CD jobs subject to the account’s existing permissions. By Shweta Sharma Sep 25, 2026 5 mins Code Security Communications Security Email Security WordPress patches a critical severity security vulnerability The hole, which allows an unauthenticated attacker to perform remote code execution, is especially dangerous because many enterprises are not aware of all of their WordPress sites. By Evan Schuman Sep 24, 2026 7 mins Internet Security Network Security Vulnerabilities Microsoft integrates SOC capabilities with Defender for enterprises The preview hands E5 and E7 customers SOC tools that once cost extra, and puts a price on everything else. By Gyana Swain Sep 24, 2026 5 mins Endpoint Protection Security Operations Center Windows Security On-prem VeloCloud Orchestrator under attack, only some versions patched Attackers are actively exploiting a critical VeloCloud Orchestrator flaw that exposes the SD-WAN management system and edge devices it controls, while fixes for some affected versions remain pending. By Shweta Sharma Sep 24, 2026 4 mins Network Security Security Check Point hacked: The security software protecting your network has become a prime attack target Two CVSS 9.8 flaws, including a newly disclosed zero-day in Check Point’s Security Management service, gave attackers a path into some of the most trusted systems on the enterprise perimeter. By Taryn Plumb Sep 23, 2026 7 mins Network Security Security Vulnerabilities F5 fixes actively exploited zero-day flaw in BIG-IP APM The critical remote code execution vulnerability was added to CISA’s KEV, with more than 15,000 deployments potentially at risk. By Lucian Constantin Sep 23, 2026 3 mins Network Security Vulnerabilities Zero-Day Vulnerabilities GitHub App keys can still enable takeovers long after they are forgotten GitGuardian found 474 still-valid GitHub App private keys among thousands of exposed credentials, with some carrying permissions for account takeover. By Shweta Sharma Sep 23, 2026 5 mins Code Security Identity and Access Management Security Okta bets on identity to control AI agents, but is identity enough? Identity provider Okta is investing heavily to secure the agents enterprise, but even authenticated agents can do harm, leaving room for debate in the hotly contested agentic AI security space. By Maria Korolov Sep 23, 2026 5 mins Identity and Access Management Markets Technology Industry AI malware just removed the human from the attack loop CLOSEDQUORUM queries multiple models, tallies their decisions and automatically executes the winning action, eliminating the need for continuous attacker commands. By Taryn Plumb Sep 22, 2026 6 mins Artificial Intelligence Cybercrime Malware Microsoft’s EvilTokens takedown sheds light on state of AI-powered cybercrime Surreptitiously gaining persistent access to compromised Microsoft 365/Entra ID accounts, the group also offered an AI-powered chatbot to facilitate BEC scams. By John Leyden Sep 22, 2026 4 mins Cybercrime Phishing Social Engineering Z.ai disables coding assistant feature after flaw exposed enterprise code upload risk Z.ai’s default-enabled workflow sent entire local repositories to cloud infrastructure, raising fresh concerns over how AI tools handle sensitive source code. By Gyana Swain Sep 22, 2026 4 mins Artificial Intelligence Data and Information Security Development Tools Beware these fake websites selling subscriptions to AI assistants Over 100 websites abusing legitimate Google sign-in processes are ripping off customers who think they are getting a great deal on reputable AI services. By Shweta Sharma Sep 22, 2026 3 mins Artificial Intelligence Cybercrime Fraud Gemini broke into 3 companies, but Google kept it quiet because ‘no damage was done’ An agentic cybersecurity incident in May impacted OpenAI, Google, Anthropic and Meta; everyone reported it except Google. By Evan Schuman Sep 21, 2026 7 mins Artificial Intelligence Cybercrime Hacking After spending billions, OpenAI still has gaps in its cybersecurity Two separate groups of researchers found holes in OpenAI’s identity systems and agent controls. By Gyana Swain Sep 21, 2026 5 mins Artificial Intelligence Development Tools Identity and Access Management New npm malware finds a way around install script defenses A malicious npm package reached over 2 million weekly downloads by hiding its payload in a routine library function rather than an install script. By Shweta Sharma Sep 21, 2026 3 mins Code Security Cybercrime Malware CISA is ending its monthly vulnerability bulletin Does its claim of conforming to BOD requirements ring true? By Maxwell Cooter Sep 18, 2026 2 mins Government Markets Vulnerabilities A zero-click RCE flaw in AI coding agents could have exposed enterprise systems By exploiting how AI coding agents retrieve and verify plugins, researchers were able to execute malicious code even when the agent was told to use a trusted, approved version. By Anirban Ghoshal Sep 18, 2026 6 mins Code Editors Development Tools Vulnerabilities GhostCode attackers abuse device codes to take over Microsoft 365 accounts A new phishing kit abuses a legitimate Microsoft device authorization flow to steal authentication tokens, register attacker-controlled devices and gain persistent access to a victim’s Microsoft 365 environments. By Shweta Sharma Sep 18, 2026 4 mins Authentication Multifactor Authentication Phishing 12345678910…433 Show me morePopularArticlesPodcastsVideos opinion Why AI agents are like the dog that pushed kids into the Seine By Etay MaorOct 1, 20266 mins Access ControlData and Information SecurityIT Governance opinion The MFA you have isn't the MFA you think you have By Ashish MishraSep 30, 20266 mins Access ControlAuthenticationMultifactor Authentication opinion Can we jail a superintelligence? By Arjun MullickSep 30, 20269 mins Application SecurityData and Information SecurityNetwork Security podcast Why Email Still Works for Attackers By Joan GoodchildSep 30, 20266 mins Email Security podcast The Evolving CISO: AI, Leadership and the Future of Cybersecurity By Joan GoodchildSep 24, 20266 mins CSO and CISO podcast Why Security Debt May Be a Bigger Risk Than Security Spend By Joan GoodchildSep 10, 202616 mins Cybercrime video Why Email Still Works for Attackers By Joan GoodchildSep 30, 20266 mins Email Security video The Evolving CISO: AI, Leadership and the Future of Cybersecurity By Joan GoodchildSep 24, 20266 mins CSO and CISO video Why Security Debt May Be a Bigger Risk Than Security Spend By Joan GoodchildSep 10, 202616 mins Cyberattacks