Website profile

Cso Online

CSO delivers the critical information about trends, practices, and products enterprise security leaders need to defend against criminal cyberattacks and other threats.

  • 1,703articles · 365d
  • 2+ day agolatest article
  • Sep 15, 2025earliest in window
  • 91%with images
  • 355avg words
articles per day
Categories
  • Science & Technology 1,156
  • Computers & Electronics 880
  • Software 623
  • News 355
  • Software Dev. 328
  • Crime & Law 240
  • Conflict, War & Peace 237
  • Science & Nature 237

Please confirm you are human

This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.

A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.

Hold with a pointer, or hold Space or Enter.

News

CSO Online
csoonline.com > article > 4220203 > chatgpt-flaw-lets-attackers-pull-gmail-data-across-accounts-via-a-hidden-channel.html

ChatGPT flaw lets attackers pull Gmail data across accounts via a hidden channel

3+ day, 17+ hour ago   (669+ words) A flaw in OpenAI’s ChatGPT allowed attackers to extract data from a victim’s connected Gmail account by passing hidden instructions between separate user sessions, according to research from Check Point. In a proof-of-concept, Check Point demonstrated that a victim’s ChatGPT…...

CSO Online
csoonline.com > article > 4218759 > security-leaders-must-prepare-for-likely-threats-not-sensationalized-agentic-attacks.html

Security leaders must prepare for likely threats, not sensationalized agentic attacks

4+ day, 20+ hour ago   (1293+ words) A malicious dataset exploits code-execution paths in a remote-code dataset loader and a dataset configuration before compromising access credentials to move laterally through the target network. A frontier AI model publishes a malicious Python package to a public PyPI registry…...

CSO Online
csoonline.com > article > 4218075 > counterfeit-installers-turn-routine-software-downloads-into-enterprise-breaches.html

Counterfeit installers turn routine software downloads into enterprise breaches

1+ week, 2+ day ago   (589+ words) The attackers are using a network of spoofed websites mimicking legitimate vendors, from browsers and security tools to utilities such as Baidu Netdisk, draw.io, and Sejda PDF, to trick users into downloading malicious installers, the blog added. Microsoft said…...

CSO Online
csoonline.com > article > 4214135 > microsoft-warns-patch-window-is-collapsing-urges-shift-to-network-level-containment.html

Microsoft warns patch window is collapsing, urges shift to network-level containment

2+ week, 3+ day ago   (720+ words) Microsoft is warning that the window for patching vulnerabilities is rapidly shrinking, as attackers move from disclosure to exploitation faster than enterprises can safely deploy fixes, and is urging organizations to adopt network-level controls to limit exposure during that gap....

CSO Online
csoonline.com > article > 4213632 > new-attack-lets-hackers-plant-hidden-instructions-in-ai-memory-with-a-single-prompt.html

New attack lets hackers plant hidden instructions in AI memory with a single prompt

2+ week, 4+ day ago   (662+ words) A newly demonstrated attack technique allows hackers to plant hidden instructions inside an AI agent’s memory with a single prompt, enabling them to influence how the system responds to future queries. The technique, called InjecMEM, is described in a research…...

CSO Online
csoonline.com > article > 4212929 > windows-defenders-own-driver-can-leave-systems-defenseless.html

Windows Defender’s own driver can leave systems defenseless

2+ week, 5+ day ago   (426+ words) A Microsoft-signed Windows Defender remediation driver can be repurposed into a kernel-level “operation engine” capable of deleting files, modifying the registry and neutralizing security controls, according to new research from Check Point Research (CPR). The technique does not exploit a…...

Google News
csoonline.com > article > 4212381 > backdoored-rust-packages-hit-crates-io-exposing-developers-to-malware-at-build-time.html

Backdoored Rust packages hit crates.io, exposing developers to malware at build time | CSO Online

3+ week, 1+ day ago   (486+ words) Malicious versions of three Rust packages, including the widely used arrayref, were published to the crates.io registry on August 20, carrying a backdoor that executed automatically when affected projects were compiled. Security researchers at Wiz said the attack also shares…...

CSO Online
csoonline.com > article > 4211501 > snowflake-flaw-slips-past-ai-checks-gets-exploited-by-another-ai.html

Snowflake flaw slips past AI checks, gets exploited by another AI

3+ week, 3+ day ago   (405+ words) An autonomous AI security agent developed by cloud security firm Wiz identified and exploited a critical vulnerability in Snowflake’s GitHub Actions pipeline, while GitHub Copilot had previously reviewed the code change without flagging the flaw. The vulnerable code was part…...

CSO Online
csoonline.com > article > 4211140 > critical-gitlab-flaw-allows-attackers-to-delete-and-modify-public-repos.html

Critical GitLab flaw allows attackers to delete and modify public repos

3+ week, 4+ day ago   (304+ words) GitLab has fixed a critical vulnerability that could allow unauthenticated attackers to perform unauthorized modifications inside code repositories or to completely delete them with a single HTTP request. The patched releases also address a second high-risk cross-site request forgery (CSRF)…...