Website profile

Cso Online

CSO delivers the critical information about trends, practices, and products enterprise security leaders need to defend against criminal cyberattacks and other threats.

  • 1,703articles · 365d
  • 2+ day agolatest article
  • Sep 15, 2025earliest in window
  • 91%with images
  • 355avg words
articles per day
Categories
  • Science & Technology 1,156
  • Computers & Electronics 880
  • Software 623
  • News 355
  • Software Dev. 328
  • Crime & Law 240
  • Conflict, War & Peace 237
  • Science & Nature 237

Please confirm you are human

This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.

A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.

Hold with a pointer, or hold Space or Enter.

News

CSO Online
csoonline.com > article > 4220203 > chatgpt-flaw-lets-attackers-pull-gmail-data-across-accounts-via-a-hidden-channel.html

ChatGPT flaw lets attackers pull Gmail data across accounts via a hidden channel

3+ day, 17+ hour ago   (669+ words) A flaw in OpenAI’s ChatGPT allowed attackers to extract data from a victim’s connected Gmail account by passing hidden instructions between separate user sessions, according to research from Check Point. In a proof-of-concept, Check Point demonstrated that a victim’s ChatGPT…...

CSO Online
csoonline.com > article > 4219801 > when-the-prompt-becomes-the-payload-a-practical-pen-testing-guide-for-genai-llm-and-rag-applications.html

When the prompt becomes the payload: A practical pen-testing guide for GenAI, LLM and RAG applications

3+ day, 19+ hour ago   (674+ words) That makes an LLM application closer to an attack graph than a single endpoint. Prompts, retrieval services, vector databases, identities, plug-ins, model gateways and downstream APIs all influence the final result. A conventional web test still matters, but it will…...

CSO Online
csoonline.com > article > 4219765 > cisa-tells-operators-to-harden-siemens-s7-plcs-heres-how-to-do-it-without-disrupting-production.html

CISA tells operators to harden Siemens S7 PLCs. Here’s how to do it without disrupting production

4+ day, 12+ hour ago   (751+ words) On a conventional server, disabling an unused service is usually a routine hardening task. On a Siemens S7 controller, the supposedly unused service may carry remote I/O traffic, supply process values to an HMI or provide the maintenance team’s only…...

CSO Online
csoonline.com > article > 4219249 > sam-altman-calls-gpt-6-astra-rollout-messy-as-enterprise-users-wait-for-access.html

Sam Altman calls GPT-6 Astra rollout ‘messy’ as enterprise users wait for access

5+ day, 17+ hour ago   (714+ words) OpenAI’s rollout of its GPT-6 Astra model ran into early access issues after paying ChatGPT users were unable to use the system shortly after launch, prompting CEO Sam Altman to apologize and say the release had been “messy.” “First, sorry…...

CSO Online
csoonline.com > article > 4218075 > counterfeit-installers-turn-routine-software-downloads-into-enterprise-breaches.html

Counterfeit installers turn routine software downloads into enterprise breaches

1+ week, 2+ day ago   (589+ words) The attackers are using a network of spoofed websites mimicking legitimate vendors, from browsers and security tools to utilities such as Baidu Netdisk, draw.io, and Sejda PDF, to trick users into downloading malicious installers, the blog added. Microsoft said…...

CSO Online
csoonline.com > article > 4217976 > ai-agents-help-compress-ransomware-intrusion-to-under-10-hours-raising-stakes-for-cisos.html

AI agents help compress ransomware intrusion to under 10 hours, raising stakes for CISOs

1+ week, 2+ day ago   (703+ words) A ransomware attacker used AI agents to move through an enterprise network in less than 10 hours, according to Palo Alto Networks researchers, who estimated that similar work could have taken human operators about two weeks. The incident involved more than…...

CSO Online
csoonline.com > article > 4215449 > zero-trust-has-a-big-ai-agent-problem-ahead.html

Zero trust has a big AI agent problem ahead

1+ week, 2+ day ago   (756+ words) Despite singing the praises of zero trust for many years, many CISOs have struggled to implement the framework in full. And now comes what could be the final nail: agentic AI. Can zero trust coexist with autonomous agents in typical…...

CSO Online
csoonline.com > article > 4217274 > how-china-industrialized-the-infrastructure-behind-state-hacking.html

How China industrialized the infrastructure behind state hacking

1+ week, 3+ day ago   (930+ words) Last week, the US Justice Department and FBI announced court-authorized seizures of domains hard-coded into two complementary hacking platforms known as “QScan” and “QTRouter,” used by Chinese state-sponsored hackers to target US critical infrastructure and other sensitive networks. A People’s…...

CSO Online
csoonline.com > article > 4216927 > fake-cloudflare-captcha-tricks-victims-into-opening-a-tunnel-for-attackers.html

Fake Cloudflare CAPTCHA tricks victims into opening a tunnel for attackers

1+ week, 4+ day ago   (379+ words) Attackers are using fake CAPTCHA prompts to trick victims into running malicious PowerShell commands as part of a multi-stage intrusion campaign that can establish persistence, conduct network reconnaissance and potentially give operators a path to deeper access within an organization....