Install
CSO delivers the critical information about trends, practices, and products enterprise security leaders need to defend against criminal cyberattacks and other threats.
- 1,703articles · 365d
- 2+ day agolatest article
- Sep 15, 2025earliest in window
- 91%with images
- 355avg words
- security 1,533
- cybersecurity 1,443
- artificial intelligence 940
- technology 876
- ai 680
- software 516
- malware 506
- cybercrime 429
- cyber security news 395
- coding 390
- development 370
- engineering 342
- vulnerability 342
- cyber security 334
- cyberattacks 332
- inclusive 313
- community 297
- vulnerabilities 250
- business 237
- ransomware 223
- Science & Technology 1,156
- Computers & Electronics 880
- Software 623
- News 355
- Software Dev. 328
- Crime & Law 240
- Conflict, War & Peace 237
- Science & Nature 237
Please confirm you are human
This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.
A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.
News
Stealth rootkit targeting F5 BIG-IP could expose enterprise identity gateways
3+ day, 10+ hour ago (544+ words) Sophos said the malware, found in compromised BIG-IP APM environments using Apache and PHP components, uses custom ELF loading, function hooking, and runtime code patching to establish persistent access. The implant, it said in a blog post, appears to be…...
Getting ahead of ‘harvest-now-decrypt-later’: Post-quantum cryptography planning
3+ day, 13+ hour ago (339+ words) None of this belongs in the “future planning” bucket anymore. A 2030 deprecation deadline sounds distant until you map it against how long your organization takes to touch every system running cryptography. I’ve run cryptographic discovery projects that stretched past a…...
Post-quantum cryptography adoption and the national security implications
4+ day, 13+ hour ago (390+ words) Organizations that are already targets of nation-state actors, such as governments, tech companies, large financial companies and nuclear facilities, will be the first to adopt PQC technology, while thinner-margin companies will likely push it to the back burner due to…...
September 2026 Patch Tuesday roundup: Plugs for two zero day holes among almost 1,000 fixes in Windows
4+ day, 19+ hour ago (437+ words) Possibly wormable bugs and two zero-day holes highlight the almost 1,000 fixes issued today by Microsoft in its September Patch Tuesday release. The 964 vulnerabilities, another record since Microsoft began using AI in the middle of the year to find holes, require…...
CISA tells operators to harden Siemens S7 PLCs. Here’s how to do it without disrupting production
5+ day, 5+ hour ago (751+ words) On a conventional server, disabling an unused service is usually a routine hardening task. On a Siemens S7 controller, the supposedly unused service may carry remote I/O traffic, supply process values to an HMI or provide the maintenance team’s only…...
BigBear 2.0 phishing campaign hijacks Microsoft 365 sessions after MFA
5+ day, 11+ hour ago (700+ words) A phishing-as-a-service operation targeting Microsoft 365 users has harvested thousands of session cookies that could be used to hijack authenticated sessions after victims complete multifactor authentication, CloudSEK said. The cybersecurity firm said in a report that it uncovered the operation, known…...
Back-to-back N-able bugs send admins on a patching spree
6+ day, 10+ hour ago (499+ words) A max-severity zero-day bug could be affecting cybersecurity firm N-able’s N-central remote monitoring and management platform, the company said, even as administrators were applying a hotfix for two vulnerabilities disclosed just a day earlier. The latest flaw, tracked as CVE…...
The democratization of cyber warfare — and what it means for CISOs
1+ week, 2+ day ago (1637+ words) For most of modern history, sophisticated and costly warfare had a high barrier to entry. In order to maintain a significant tactical advantage, you needed money, infrastructure and highly trained human resources. In the physical realm, you needed trained and…...
AI agents help compress ransomware intrusion to under 10 hours, raising stakes for CISOs
1+ week, 3+ day ago (703+ words) A ransomware attacker used AI agents to move through an enterprise network in less than 10 hours, according to Palo Alto Networks researchers, who estimated that similar work could have taken human operators about two weeks. The incident involved more than…...
When the patch tsunami meets the maintenance window
1+ week, 4+ day ago (570+ words) Sabine Frömling, MBA, is an independent cybersecurity, OT security and governance consultant and the author of "ISMS für die Industrie – Der Praxisratgeber", with an English-language edition forthcoming in fall 2026. Since 2008, she has advised companies in the energy, manufacturing, pharmaceutical and…...