Website profile

Cso Online

CSO delivers the critical information about trends, practices, and products enterprise security leaders need to defend against criminal cyberattacks and other threats.

  • 1,703articles · 365d
  • 2+ day agolatest article
  • Sep 15, 2025earliest in window
  • 91%with images
  • 355avg words
articles per day
Categories
  • Science & Technology 1,156
  • Computers & Electronics 880
  • Software 623
  • News 355
  • Software Dev. 328
  • Crime & Law 240
  • Conflict, War & Peace 237
  • Science & Nature 237

Please confirm you are human

This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.

A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.

Hold with a pointer, or hold Space or Enter.

News

CSO Online
csoonline.com > article > 4220702 > ai-workflows-may-be-creating-a-dangerous-new-authorization-blind-spot.html

AI workflows may be creating a dangerous new authorization blind spot

2+ day, 19+ hour ago   (735+ words) A newly identified AI attack technique can let unauthenticated users trigger privileged workflows and access enterprise systems, highlighting a gap in how identity and access controls apply to AI agents, according to research from Noma Labs. The report, authored by…...

CSO Online
csoonline.com > article > 4220259 > getting-ahead-of-harvest-now-decrypt-later-post-quantum-cryptography-planning.html

Getting ahead of ‘harvest-now-decrypt-later’: Post-quantum cryptography planning

2+ day, 22+ hour ago   (339+ words) None of this belongs in the “future planning” bucket anymore. A 2030 deprecation deadline sounds distant until you map it against how long your organization takes to touch every system running cryptography. I’ve run cryptographic discovery projects that stretched past a…...

CSO Online
csoonline.com > article > 4219801 > when-the-prompt-becomes-the-payload-a-practical-pen-testing-guide-for-genai-llm-and-rag-applications.html

When the prompt becomes the payload: A practical pen-testing guide for GenAI, LLM and RAG applications

3+ day, 21+ hour ago   (674+ words) That makes an LLM application closer to an attack graph than a single endpoint. Prompts, retrieval services, vector databases, identities, plug-ins, model gateways and downstream APIs all influence the final result. A conventional web test still matters, but it will…...

CSO Online
csoonline.com > article > 4218440 > securing-ai-agents-key-controls-and-best-practices.html

Securing AI agents: Key controls and best practices

4+ day, 23+ hour ago   (1142+ words) The closest threat model the security industry has for misaligned AI agents are rogue employees, but enterprises already struggle to contain the potential blast radius of malicious insiders, and AI agents add machine speed, autonomy, and specialized expertise to that…...

CSO Online
csoonline.com > article > 4218373 > openai-targets-small-utilities-with-1-billion-cyber-defense-initiative.html

OpenAI targets small utilities with $1 billion cyber defense initiative

1+ week, 2+ day ago   (413+ words) In a keynote speech during a summit at OpenAI’s headquarters attended by 300 enterprise security leaders and CISOs from Fortune 1000 companies, OpenAI President Greg Brockman announced Daybreak for Frontline Defenders, a new global initiative to help frontline defenders use frontier cyber…...

CSO Online
csoonline.com > article > 4218101 > decade-old-postgresql-flaw-turns-backup-account-into-a-backdoor.html

Decade-old PostgreSQL flaw turns backup account into a backdoor

1+ week, 2+ day ago   (520+ words) A critical vulnerability in PostgreSQL had remained hidden for more than a decade, potentially turning a routine backup account into a path to full database and server compromise. The issue, dubbed PostGREShell by Cyera Research, exists in the database’s replication…...

CSO Online
csoonline.com > article > 4218075 > counterfeit-installers-turn-routine-software-downloads-into-enterprise-breaches.html

Counterfeit installers turn routine software downloads into enterprise breaches

1+ week, 2+ day ago   (589+ words) The attackers are using a network of spoofed websites mimicking legitimate vendors, from browsers and security tools to utilities such as Baidu Netdisk, draw.io, and Sejda PDF, to trick users into downloading malicious installers, the blog added. Microsoft said…...

CSO Online
csoonline.com > article > 4215449 > zero-trust-has-a-big-ai-agent-problem-ahead.html

Zero trust has a big AI agent problem ahead

1+ week, 2+ day ago   (756+ words) Despite singing the praises of zero trust for many years, many CISOs have struggled to implement the framework in full. And now comes what could be the final nail: agentic AI. Can zero trust coexist with autonomous agents in typical…...