Website profile

Cso Online

CSO delivers the critical information about trends, practices, and products enterprise security leaders need to defend against criminal cyberattacks and other threats.

  • 1,703articles · 365d
  • 2+ day agolatest article
  • Sep 15, 2025earliest in window
  • 91%with images
  • 355avg words
articles per day
Categories
  • Science & Technology 1,156
  • Computers & Electronics 880
  • Software 623
  • News 355
  • Software Dev. 328
  • Crime & Law 240
  • Conflict, War & Peace 237
  • Science & Nature 237

Please confirm you are human

This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.

A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.

Hold with a pointer, or hold Space or Enter.

News

CSO Online
csoonline.com > article > 4084478 > crowdstrike-cybersecurity-report-highlights-a-spike-in-physical-attacks-on-privileged-users.html

Crowdstrike cybersecurity report highlights a spike in physical attacks on privileged users

10+ mon, 1+ week ago   (273+ words) While tracking cyberattacks since last year, a Crowdstrike report also found that physical attacks and kidnappings have increased dramatically, particularly in Europe. “In January 2025, threat actors kidnapped and attempted to extort the co-founder of Ledger, a prolific cryptocurrency wallet vendor,…...

CSO Online
csoonline.com > article > 4220939 > attackers-are-weaponizing-the-gap-between-chromium-fixes-and-chrome-patches.html

Attackers are weaponizing the gap between Chromium fixes and Chrome patches

2+ day, 19+ hour ago   (642+ words) A new exploit kit is revealing the perils of the “patch later” mentality. According to the Proofpoint Threat Research team, espionage-motivated threat actors are using a new malicious toolkit to chain together four separate Chrome browser and Microsoft Windows vulnerabilities…...

CSO Online
csoonline.com > article > 4220702 > ai-workflows-may-be-creating-a-dangerous-new-authorization-blind-spot.html

AI workflows may be creating a dangerous new authorization blind spot

3+ day, 8+ hour ago   (735+ words) A newly identified AI attack technique can let unauthenticated users trigger privileged workflows and access enterprise systems, highlighting a gap in how identity and access controls apply to AI agents, according to research from Noma Labs. The report, authored by…...

CSO Online
csoonline.com > article > 4220693 > stealth-rootkit-targeting-f5-big-ip-could-expose-enterprise-identity-gateways.html

Stealth rootkit targeting F5 BIG-IP could expose enterprise identity gateways

3+ day, 9+ hour ago   (544+ words) Sophos said the malware, found in compromised BIG-IP APM environments using Apache and PHP components, uses custom ELF loading, function hooking, and runtime code patching to establish persistent access. The implant, it said in a blog post, appears to be…...

CSO Online
csoonline.com > article > 4220259 > getting-ahead-of-harvest-now-decrypt-later-post-quantum-cryptography-planning.html

Getting ahead of ‘harvest-now-decrypt-later’: Post-quantum cryptography planning

3+ day, 11+ hour ago   (339+ words) None of this belongs in the “future planning” bucket anymore. A 2030 deprecation deadline sounds distant until you map it against how long your organization takes to touch every system running cryptography. I’ve run cryptographic discovery projects that stretched past a…...

CSO Online
csoonline.com > article > 4220390 > mikrotik-patches-flaws-currently-being-exploited-to-take-over-routers.html

MikroTik patches flaws currently being exploited to take over routers

4+ day, 52+ min ago   (649+ words) Networking gear manufacturer MikroTik has released patches for six vulnerabilities in its RouterOS firmware, two of which can be chained together to take over devices without authentication over SSH. The exploit chain, dubbed MikroTrick, is already being used by attackers…...

CSO Online
csoonline.com > article > 4220203 > chatgpt-flaw-lets-attackers-pull-gmail-data-across-accounts-via-a-hidden-channel.html

ChatGPT flaw lets attackers pull Gmail data across accounts via a hidden channel

4+ day, 9+ hour ago   (669+ words) A flaw in OpenAI’s ChatGPT allowed attackers to extract data from a victim’s connected Gmail account by passing hidden instructions between separate user sessions, according to research from Check Point. In a proof-of-concept, Check Point demonstrated that a victim’s ChatGPT…...

CSO Online
csoonline.com > article > 4220193 > shinyhunters-claims-florida-dmv-breach-puts-data-on-the-clock.html

ShinyHunters claims Florida DMV breach, puts data on the clock

4+ day, 9+ hour ago   (439+ words) ShinyHunters is claiming to have broken into a Florida government database containing sensitive information on the state’s drivers. The notorious extortion group said it has breached the Florida Department of Highway Safety and Motor Vehicles’ Driver and Vehicle Information Database…...

CSO Online
csoonline.com > article > 4219801 > when-the-prompt-becomes-the-payload-a-practical-pen-testing-guide-for-genai-llm-and-rag-applications.html

When the prompt becomes the payload: A practical pen-testing guide for GenAI, LLM and RAG applications

4+ day, 10+ hour ago   (674+ words) That makes an LLM application closer to an attack graph than a single endpoint. Prompts, retrieval services, vector databases, identities, plug-ins, model gateways and downstream APIs all influence the final result. A conventional web test still matters, but it will…...