Install
CSO delivers the critical information about trends, practices, and products enterprise security leaders need to defend against criminal cyberattacks and other threats.
- 1,703articles · 365d
- 2+ day agolatest article
- Sep 15, 2025earliest in window
- 91%with images
- 355avg words
- security 1,533
- cybersecurity 1,443
- artificial intelligence 940
- technology 876
- ai 680
- software 516
- malware 506
- cybercrime 429
- cyber security news 395
- coding 390
- development 370
- engineering 342
- vulnerability 342
- cyber security 334
- cyberattacks 332
- inclusive 313
- community 297
- vulnerabilities 250
- business 237
- ransomware 223
- Science & Technology 1,156
- Computers & Electronics 880
- Software 623
- News 355
- Software Dev. 328
- Crime & Law 240
- Conflict, War & Peace 237
- Science & Nature 237
Please confirm you are human
This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.
A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.
News
Counterfeit installers turn routine software downloads into enterprise breaches
1+ week, 2+ day ago (589+ words) The attackers are using a network of spoofed websites mimicking legitimate vendors, from browsers and security tools to utilities such as Baidu Netdisk, draw.io, and Sejda PDF, to trick users into downloading malicious installers, the blog added. Microsoft said…...
Anthropic introduces zero-retention AI safety monitoring for enterprises
1+ week, 3+ day ago (828+ words) Anthropic is introducing a new framework aimed at helping enterprises monitor AI misuse without ceding control over sensitive data, as organizations struggle to balance security visibility with strict compliance requirements. The company announced a new solution called Enterprise Frontier Safeguards…...
New attack lets hackers plant hidden instructions in AI memory with a single prompt
2+ week, 4+ day ago (662+ words) A newly demonstrated attack technique allows hackers to plant hidden instructions inside an AI agent’s memory with a single prompt, enabling them to influence how the system responds to future queries. The technique, called InjecMEM, is described in a research…...
Windows Defender’s own driver can leave systems defenseless
2+ week, 5+ day ago (426+ words) A Microsoft-signed Windows Defender remediation driver can be repurposed into a kernel-level “operation engine” capable of deleting files, modifying the registry and neutralizing security controls, according to new research from Check Point Research (CPR). The technique does not exploit a…...
Backdoored Rust packages hit crates.io, exposing developers to malware at build time | CSO Online
3+ week, 1+ day ago (486+ words) Malicious versions of three Rust packages, including the widely used arrayref, were published to the crates.io registry on August 20, carrying a backdoor that executed automatically when affected projects were compiled. Security researchers at Wiz said the attack also shares…...
Snowflake flaw slips past AI checks, gets exploited by another AI
3+ week, 3+ day ago (405+ words) An autonomous AI security agent developed by cloud security firm Wiz identified and exploited a critical vulnerability in Snowflake’s GitHub Actions pipeline, while GitHub Copilot had previously reviewed the code change without flagging the flaw. The vulnerable code was part…...
Most organizations aren’t ready for a Hugging Face-level event
3+ week, 3+ day ago (329+ words) Lee Rossey is a former group leader at MIT Lincoln Laboratory, where he established the Cyber System Assessments Group, which became a nationally recognized center of excellence. He led the group in cyber range development, cyber test and evaluation, cyber…...
Critical GitLab flaw allows attackers to delete and modify public repos
3+ week, 4+ day ago (304+ words) GitLab has fixed a critical vulnerability that could allow unauthenticated attackers to perform unauthorized modifications inside code repositories or to completely delete them with a single HTTP request. The patched releases also address a second high-risk cross-site request forgery (CSRF)…...
New malware turns Microsoft cloud into its control center
3+ week, 4+ day ago (413+ words) Security researchers are warning of a newly uncovered Python malware framework that routes much of its command-and-control (C2) activity through Microsoft services that defenders already expect to see. The Ontinue Cyber Defense Center discovered the implant while investigating an active campaign…...
Researcher bypasses Microsoft Defender patch, seizing control
1+ mon, 8+ hour ago (608+ words) Just weeks after Microsoft patched a critical hole in Microsoft Defender, a cybersecurity researcher has posted an apparent bypass that provides system-level control to attackers once they gain any level of access. The researcher, who goes by the name Nightmare…...