report

Exposed credentials are giving attackers a head start many organizations don’t see

Exposed credentials are giving attackers a head start many organizations don’t see 2026-07-30 at 07:00 By Anamarija Pogorelec Compromised credentials can remain active long after passwords are created, leaving organizations trying to identify exposed accounts before attackers can use them. The 2026 Credential Risk Report from Enzoic shows growing awareness of the problem, but monitoring […]

Exposed credentials are giving attackers a head start many organizations don’t see Read More »

ShutterGap: Aryon Security finds 3.7M AWS cloud resources exposed beyond CSPM/CNAPP visibility

ShutterGap: Aryon Security finds 3.7M AWS cloud resources exposed beyond CSPM/CNAPP visibility 2026-07-29 at 16:00 By Help Net Security Research from Aryon reveals that each year, 3,731,699 short-lived cloud resources containing highly sensitive information are publicly exposed. This impacts any organization using AWS services that support public sharing. These exposures often last only minutes or hours,

ShutterGap: Aryon Security finds 3.7M AWS cloud resources exposed beyond CSPM/CNAPP visibility Read More »

Cloudflare reveals what’s behind major internet outages

Cloudflare reveals what’s behind major internet outages 2026-07-29 at 13:20 By Sinisa Markovic Storms, earthquakes, and infrastructure failures disrupted internet access throughout the second quarter, while governments deliberately shut networks down, according to Cloudflare’s latest Internet Disruption Summary. Based on Cloudflare Radar traffic data, the report covers internet disruptions recorded between April and June 2026.

Cloudflare reveals what’s behind major internet outages Read More »

Your AI agents can reach data no one approved

Your AI agents can reach data no one approved 2026-07-29 at 07:30 By Mirko Zorz A credential expired. An AI agent kept using it anyway, and a mid-sized company’s systems went down for a quarter’s worth of trouble before anyone traced the failure back to a non-human account no one had been logging. That agent

Your AI agents can reach data no one approved Read More »

ChatGPT joins the most impersonated brands in phishing attacks

ChatGPT joins the most impersonated brands in phishing attacks 2026-07-27 at 14:08 By Anamarija Pogorelec Microsoft continued to be the most impersonated brand in Q2 2026, accounting for 23% of all brand phishing attempts. LinkedIn, Google, Apple, and Amazon followed, with the five brands together making up more than half of all brand phishing attempts

ChatGPT joins the most impersonated brands in phishing attacks Read More »

The AI code vulnerabilities that grow with your app

The AI code vulnerabilities that grow with your app 2026-07-23 at 07:30 By Mirko Zorz Theori built 28 apps with AI coding agents and scanned each one through its pentesting platform. Five models did the building, split between Anthropic and OpenAI, across apps written from a spec, thrown together from a casual prompt, and rewritten

The AI code vulnerabilities that grow with your app Read More »

Security teams keep finding critical flaws after scheduled testing ends

Security teams keep finding critical flaws after scheduled testing ends 2026-07-22 at 08:00 By Anamarija Pogorelec Enterprise environments change between scheduled security assessments, leaving organizations with periods where new vulnerabilities can go undetected. Synack’s State of Continuous Security Validation report found that 95% of surveyed organizations identified high- or critical-severity vulnerabilities outside planned testing windows

Security teams keep finding critical flaws after scheduled testing ends Read More »

AI can’t fix cybersecurity’s hiring problem

AI can’t fix cybersecurity’s hiring problem 2026-07-22 at 07:30 By Anamarija Pogorelec Organizations are redefining cybersecurity roles through workforce frameworks and placing greater emphasis on verified skills as AI and new regulatory requirements change hiring. The SANS 2026 Cybersecurity Workforce Survey found demand for specialists in new roles more than doubled over the past year,

AI can’t fix cybersecurity’s hiring problem Read More »

Cloud operations become the next big role for agentic AI

Cloud operations become the next big role for agentic AI 2026-07-22 at 07:00 By Anamarija Pogorelec Companies are using agentic AI to manage growing application environments, automate routine tasks, and support decisions. Business and IT leaders increasingly see the technology as part of cloud application management, according to Unisys’ AI & Cloud Insights Report. To

Cloud operations become the next big role for agentic AI Read More »

The Windows 10 hangover is becoming a security problem

The Windows 10 hangover is becoming a security problem 2026-07-20 at 11:37 By Anamarija Pogorelec Windows 11 now runs on 78.8% of Windows devices after Microsoft ended support for Windows 10 on 14 October 2025, according to Lansweeper. Windows 10 still accounts for 16.9% of devices and no longer receives security updates, leaving newly discovered

The Windows 10 hangover is becoming a security problem Read More »

Nearly half of open-source AI projects never reach production

Nearly half of open-source AI projects never reach production 2026-07-20 at 07:00 By Anamarija Pogorelec Open models are moving into production across more organizations, and the work of securing those deployments increasingly extends beyond the model weights. Mozilla’s The State of Open Source AI 2026 identifies deployment, governance and operational tooling as persistent obstacles as

Nearly half of open-source AI projects never reach production Read More »

Ransom demands are down, email is the top way attackers get in

Ransom demands are down, email is the top way attackers get in 2026-07-16 at 08:00 By Mirko Zorz An employee opens an email that looks like any other, clicks a link, and gives up a password without noticing. A stolen login opens a door deeper in the network. Files stop opening a few days later.

Ransom demands are down, email is the top way attackers get in Read More »

Companies keep getting breached by vulnerabilities they already knew about

Companies keep getting breached by vulnerabilities they already knew about 2026-07-16 at 07:30 By Mirko Zorz Scanning tools have gotten good at their work. Organizations now find more weaknesses across more of their systems than at any earlier point in the industry’s history. A survey from the security firm Vicarius points to a gap that

Companies keep getting breached by vulnerabilities they already knew about Read More »

Finance phishing works because it sounds boringly normal

Finance phishing works because it sounds boringly normal 2026-07-16 at 06:53 By Anamarija Pogorelec Finance departments process a constant stream of invoices, contracts, payment notices, and procurement emails, making email one of the most common initial access vectors for threat actors. According to Cofense, attackers exploit those workflows with phishing emails that resemble legitimate business

Finance phishing works because it sounds boringly normal Read More »

The best defense against AI attacks turns out to be a skeptical human

The best defense against AI attacks turns out to be a skeptical human 2026-07-14 at 09:00 By Mirko Zorz Analysts across the security industry now run generative AI through their daily work, from log triage to incident write-ups. Active use in cybersecurity strategy reached 78% of practitioners in 2026, up from half the field a

The best defense against AI attacks turns out to be a skeptical human Read More »

99.9% of fixable AI vulnerabilities remain unpatched

99.9% of fixable AI vulnerabilities remain unpatched 2026-07-13 at 07:30 By Anamarija Pogorelec Organizations build, deploy, and operate AI in the cloud, but basic cybersecurity hygiene is often sacrificed for speed, according to Orca Security’s 2026 State of AI Security Report. Building AI without security Fifty-six percent of AI adopters have deployed agent frameworks into

99.9% of fixable AI vulnerabilities remain unpatched Read More »

Enterprises are rethinking where their AI applications run

Enterprises are rethinking where their AI applications run 2026-07-13 at 07:00 By Anamarija Pogorelec Growing demand for compute capacity, power, cooling and low-latency connectivity is prompting organizations to reassess where AI applications run, according to CoreSite. Public cloud continues to support experimentation and rapid deployment, while colocation is increasingly used for workloads that require predictable

Enterprises are rethinking where their AI applications run Read More »

Only 28% of financial workforce MFA is phishing-resistant

Only 28% of financial workforce MFA is phishing-resistant 2026-07-10 at 08:41 By Anamarija Pogorelec Passwords remain part of many workforce authentication flows in financial organizations, making phishing and credential theft major identity security risks, according to a new Secret Double Octopus report. Key challenges preventing universal implementation of phishing-resistant MFA (Source: Secret Double Octopus) Workforce

Only 28% of financial workforce MFA is phishing-resistant Read More »

Messaging fraud trends point to smarter attacks, stronger blocking

Messaging fraud trends point to smarter attacks, stronger blocking 2026-07-09 at 07:30 By Sinisa Markovic Fraudsters spent 2025 investing in scale. New routes, new tools, and higher message volumes moved through the SMS, voice, and chat channels that businesses rely on to reach customers. Money follows that activity. The Communications Fraud Control Association puts global

Messaging fraud trends point to smarter attacks, stronger blocking Read More »

Thousands of malicious AI skills found capable of stealing data, running malware

Thousands of malicious AI skills found capable of stealing data, running malware 2026-07-08 at 12:00 By Anamarija Pogorelec AI agents can browse the web, use external tools, execute commands, and perform tasks on behalf of users. Many rely on skills that define how they interact with services and data. Malicious skills can abuse those capabilities

Thousands of malicious AI skills found capable of stealing data, running malware Read More »

Scroll to Top