Please confirm you are human

This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.

A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.

Hold with a pointer, or hold Space or Enter.

News

CSO Online
csoonline.com > article > 4206750 > 4-million-fake-applications-and-one-blind-spot-a-soc-playbook-for-oauth-client-id-spoofing.html

How to detect OAuth client ID spoofing in Microsoft Entra ID before account takeover

27+ min ago   (390+ words) The technique abuses the OAuth 2.0 Resource Owner Password Credentials (ROPC) flow, in which a single token request bundles a username, password, and client ID. Three Entra ID response codes carry the signal that matters. UNK_pyreq2323. Proofpoint tracked this campaign running from AWS…...

CSO Online
csoonline.com > article > 4206851 > trojanized-ai-skills-gain-1-7m-installs-in-agent-targeted-attack.html

Trojanized AI skills gain 1.7M installs in agent-targeted attack

2+ day, 15+ hour ago   (613+ words) Researchers have uncovered an extremely effective attack campaign that involved AI agent skills trojanized to deploy a credential stealer. The incident is part of a growing trend in which attackers are targeting the AI software supply chain by poisoning sharable…...

CSO Online
csoonline.com > article > 4206782 > moonshots-kimi-ai-model-has-also-escaped-from-a-test-environment.html

Moonshot’s Kimi AI model has also escaped from a test environment

2+ day, 18+ hour ago   (140+ words) Yet another AI model has escaped from a cybersecurity test lab: This time, it’s the Chinese company Moonshot’s Kimi K3 model on the run. Frontier Security spotted that Kimi K3 had found a loophole in the UK AI Safety Institute’s test environment…...

CSO Online
csoonline.com > article > 4206739 > snowflake-attacker-pleads-guilty-to-hack-of-165-companies-data.html

Snowflake attacker pleads guilty to hack of 165 companies’ data

2+ day, 20+ hour ago   (217+ words) A Canadian hacker has admitted being part of a group responsible for several major cyberattacks. Connor Riley Moucka pleaded guilty to being part of a coterie of hackers that hit 165 organizations, resulting in the theft of customer records and the…...

CSO Online
csoonline.com > article > 4206245 > python-package-security-in-2026.html

Python package security in 2026

3+ day, 27+ min ago   (204+ words) That is not the exception anymore. It is the pattern. ReversingLabs reports that malicious open-source packages rose by 73% in 2026. The LiteLLM attack was part of a broader campaign by TeamPCP that systematically compromised widely trusted open-source security tools — including Aqua…...

CSO Online
csoonline.com > article > 4206598 > human-oversight-is-still-critical-as-ai-patching-tools-miss-security-risks.html

Human oversight is still critical as AI patching tools miss security risks

3+ day, 36+ min ago   (406+ words) “We studied what happens when Large Language Models (LLMs) generate vulnerability patches for recently disclosed, complex vulnerabilities,” said 1Password researcher Keith Hoodlet in a blog post. “Our data shows that LLMs produce Fix-Like Artifacts with Embedded Defects (FLAWED) 53.9% of the time…...

CSO Online
csoonline.com > article > 4206354 > why-exposure-management-is-replacing-vulnerability-management.html

Why exposure management is replacing vulnerability management

3+ day, 11+ hour ago   (702+ words) Vulnerability management isn’t failing because security teams lack visibility. Most organizations already have more findings than they can reasonably address. Yet despite all those findings, many CISOs still struggle to answer a deceptively simple question: Are we actually becoming harder…...

CSO Online
csoonline.com > article > 4206116 > meta-joins-openai-anthropic-in-latest-ai-test-breach.html

Meta, OpenAI, and Anthropic AI agents went rogue during Irregular testing

4+ day, 2+ hour ago   (619+ words) Meta has become the third frontier AI developer in recent weeks to disclose a security incident involving one of its advanced AI models during cyber capability testing conducted by AI safety startup, Irregular, placing the independent evaluator at the center…...

CSO Online
csoonline.com > article > 4206204 > how-a-global-investment-firm-reduced-security-surprises.html

How a global investment firm reduced security surprises

3+ day, 19+ hour ago   (484+ words) Most security teams don’t suffer from a lack of data. They suffer from a lack of certainty. Vulnerability scanners, annual penetration tests, and compliance assessments can generate thousands of findings. Yet they often fail to answer a simple question: Which…...

CSO Online
csoonline.com > article > 4206219 > how-a-software-provider-closed-unknown-paths-to-cloud-compromise.html

How a software provider closed unknown paths to cloud compromise

3+ day, 19+ hour ago   (466+ words) “It owned our network in a matter of minutes,” said the company’s IT operations leader. That result changed the conversation immediately. This was not simply a healthcare organization protecting endpoints and servers. The provider was operating in a position of…...