Install
CSO delivers the critical information about trends, practices, and products enterprise security leaders need to defend against criminal cyberattacks and other threats.
- 1,703articles · 365d
- 2+ day agolatest article
- Sep 15, 2025earliest in window
- 91%with images
- 355avg words
- security 1,533
- cybersecurity 1,443
- artificial intelligence 940
- technology 876
- ai 680
- software 516
- malware 506
- cybercrime 429
- cyber security news 395
- coding 390
- development 370
- engineering 342
- vulnerability 342
- cyber security 334
- cyberattacks 332
- inclusive 313
- community 297
- vulnerabilities 250
- business 237
- ransomware 223
- Science & Technology 1,156
- Computers & Electronics 880
- Software 623
- News 355
- Software Dev. 328
- Crime & Law 240
- Conflict, War & Peace 237
- Science & Nature 237
Please confirm you are human
This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.
A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.
News
Attackers are weaponizing the gap between Chromium fixes and Chrome patches
2+ day, 14+ hour ago (642+ words) A new exploit kit is revealing the perils of the “patch later” mentality. According to the Proofpoint Threat Research team, espionage-motivated threat actors are using a new malicious toolkit to chain together four separate Chrome browser and Microsoft Windows vulnerabilities…...
AI workflows may be creating a dangerous new authorization blind spot
3+ day, 3+ hour ago (735+ words) A newly identified AI attack technique can let unauthenticated users trigger privileged workflows and access enterprise systems, highlighting a gap in how identity and access controls apply to AI agents, according to research from Noma Labs. The report, authored by…...
Stealth rootkit targeting F5 BIG-IP could expose enterprise identity gateways
3+ day, 3+ hour ago (544+ words) Sophos said the malware, found in compromised BIG-IP APM environments using Apache and PHP components, uses custom ELF loading, function hooking, and runtime code patching to establish persistent access. The implant, it said in a blog post, appears to be…...
Getting ahead of ‘harvest-now-decrypt-later’: Post-quantum cryptography planning
3+ day, 6+ hour ago (339+ words) None of this belongs in the “future planning” bucket anymore. A 2030 deprecation deadline sounds distant until you map it against how long your organization takes to touch every system running cryptography. I’ve run cryptographic discovery projects that stretched past a…...
SpyCloud 2026 Identity Threat Report Finds Non-Human Identities Are Now the Leading Path into the Enterprise
4+ day, 3+ hour ago (5+ words) ...
ChatGPT flaw lets attackers pull Gmail data across accounts via a hidden channel
4+ day, 4+ hour ago (669+ words) A flaw in OpenAI’s ChatGPT allowed attackers to extract data from a victim’s connected Gmail account by passing hidden instructions between separate user sessions, according to research from Check Point. In a proof-of-concept, Check Point demonstrated that a victim’s ChatGPT…...
When the prompt becomes the payload: A practical pen-testing guide for GenAI, LLM and RAG applications
4+ day, 5+ hour ago (674+ words) That makes an LLM application closer to an attack graph than a single endpoint. Prompts, retrieval services, vector databases, identities, plug-ins, model gateways and downstream APIs all influence the final result. A conventional web test still matters, but it will…...
Post-quantum cryptography adoption and the national security implications
4+ day, 6+ hour ago (390+ words) Organizations that are already targets of nation-state actors, such as governments, tech companies, large financial companies and nuclear facilities, will be the first to adopt PQC technology, while thinner-margin companies will likely push it to the back burner due to…...
50% of CISOs see Mythos as a sign to exit the profession
4+ day, 7+ hour ago (1222+ words) CISOs already have it tough, but the straw that breaks the back of many IT security executives may be the rapidly advancing capabilities of frontier AI models, enterprise insistence on rapid and widespread AI experimentation, and the compounding risk responsibilities…...
Security leaders must prepare for likely threats, not sensationalized agentic attacks
5+ day, 6+ hour ago (1293+ words) A malicious dataset exploits code-execution paths in a remote-code dataset loader and a dataset configuration before compromising access credentials to move laterally through the target network. A frontier AI model publishes a malicious Python package to a public PyPI registry…...