Install
CSO delivers the critical information about trends, practices, and products enterprise security leaders need to defend against criminal cyberattacks and other threats.
- 76articles · 30d
- 3+ day agolatest article
- Aug 17, 2026earliest in window
- 99%with images
- 363avg words
- Science & Technology 57
- Computers & Electronics 44
- Software 28
- News 21
- Software Dev. 19
- Science & Nature 15
- Conflict, War & Peace 9
- Business & Industrial 6
Please confirm you are human
This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.
A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.
News
AI workflows may be creating a dangerous new authorization blind spot
3+ day, 23+ hour ago (735+ words) A newly identified AI attack technique can let unauthenticated users trigger privileged workflows and access enterprise systems, highlighting a gap in how identity and access controls apply to AI agents, according to research from Noma Labs. The report, authored by…...
Getting ahead of ‘harvest-now-decrypt-later’: Post-quantum cryptography planning
4+ day, 2+ hour ago (339+ words) None of this belongs in the “future planning” bucket anymore. A 2030 deprecation deadline sounds distant until you map it against how long your organization takes to touch every system running cryptography. I’ve run cryptographic discovery projects that stretched past a…...
MikroTik patches flaws currently being exploited to take over routers
4+ day, 15+ hour ago (649+ words) Networking gear manufacturer MikroTik has released patches for six vulnerabilities in its RouterOS firmware, two of which can be chained together to take over devices without authentication over SSH. The exploit chain, dubbed MikroTrick, is already being used by attackers…...
ChatGPT flaw lets attackers pull Gmail data across accounts via a hidden channel
4+ day, 23+ hour ago (669+ words) A flaw in OpenAI’s ChatGPT allowed attackers to extract data from a victim’s connected Gmail account by passing hidden instructions between separate user sessions, according to research from Check Point. In a proof-of-concept, Check Point demonstrated that a victim’s ChatGPT…...
When the prompt becomes the payload: A practical pen-testing guide for GenAI, LLM and RAG applications
5+ day, 1+ hour ago (674+ words) That makes an LLM application closer to an attack graph than a single endpoint. Prompts, retrieval services, vector databases, identities, plug-ins, model gateways and downstream APIs all influence the final result. A conventional web test still matters, but it will…...
50% of CISOs see Mythos as a sign to exit the profession
5+ day, 2+ hour ago (1222+ words) CISOs already have it tough, but the straw that breaks the back of many IT security executives may be the rapidly advancing capabilities of frontier AI models, enterprise insistence on rapid and widespread AI experimentation, and the compounding risk responsibilities…...
Reflectiz Launches Agentic Pentesting for Websites: Up to 10x Coverage vs Conventional Pentests
5+ day, 20+ hour ago (171+ words) ...
Securing AI agents: Key controls and best practices
6+ day, 2+ hour ago (1142+ words) The closest threat model the security industry has for misaligned AI agents are rogue employees, but enterprises already struggle to contain the potential blast radius of malicious insiders, and AI agents add machine speed, autonomy, and specialized expertise to that…...
Sam Altman calls GPT-6 Astra rollout ‘messy’ as enterprise users wait for access
6+ day, 23+ hour ago (714+ words) OpenAI’s rollout of its GPT-6 Astra model ran into early access issues after paying ChatGPT users were unable to use the system shortly after launch, prompting CEO Sam Altman to apologize and say the release had been “messy.” “First, sorry…...
OpenAI launches GPT-6 Astra, its first model to cross a critical cybersecurity threshold
1+ week, 3+ day ago (684+ words) OpenAI launched GPT-6 Astra on Thursday, disclosing that the new flagship model has crossed the “Critical” threshold for cybersecurity risk under its Preparedness Framework, a classification the company said triggers additional deployment restrictions. “GPT‑6 Astra is rolling out today to…...