Security teams keep finding critical flaws after scheduled testing ends

Enterprise environments change between scheduled security assessments, leaving organizations with periods where new vulnerabilities can go undetected. Synack’s State of Continuous Security Validation report found that 95% of surveyed organization… Continue reading Security teams keep finding critical flaws after scheduled testing ends

AI can’t fix cybersecurity’s hiring problem

Organizations are redefining cybersecurity roles through workforce frameworks and placing greater emphasis on verified skills as AI and new regulatory requirements change hiring. The SANS 2026 Cybersecurity Workforce Survey found demand for specialists… Continue reading AI can’t fix cybersecurity’s hiring problem

Cloud operations become the next big role for agentic AI

Companies are using agentic AI to manage growing application environments, automate routine tasks, and support decisions. Business and IT leaders increasingly see the technology as part of cloud application management, according to Unisys’ AI &#0… Continue reading Cloud operations become the next big role for agentic AI

AWS wants GuardDuty to automate the first steps of threat investigations

Amazon GuardDuty investigation agent is now in public preview. The feature provides AI-powered investigations of GuardDuty findings, AWS accounts and AWS organizations, helping security teams reduce investigation time. During the public preview, the in… Continue reading AWS wants GuardDuty to automate the first steps of threat investigations

Open-source maintainers still work underfunded as sponsorship crosses $100 million

A maintainer patches a library late at night that ships inside thousands of products, and no invoice follows. Sebastián Ramírez and Caleb Porzio spent years in that position. Ramírez, known as tiangolo, builds tools that other Python projects depend on… Continue reading Open-source maintainers still work underfunded as sponsorship crosses $100 million

Nobody was checking the drives that encrypt your laptop

A drive ships with a label promising hardware encryption. You plug it in, set a password, and trust the chip inside to handle the rest. Millions of laptops and workstations run this way, on solid-state drives built to the TCG Opal2 standard. Milan Brož… Continue reading Nobody was checking the drives that encrypt your laptop

AI-generated reports push GNOME to shorten its disclosure window

Volunteer maintainers of open source projects now receive a steady flow of security vulnerability reports produced with AI tools. Many arrive with no mention that a language model helped write them. The volume has grown enough that GNOME is revising th… Continue reading AI-generated reports push GNOME to shorten its disclosure window

The Windows 10 hangover is becoming a security problem

Windows 11 now runs on 78.8% of Windows devices after Microsoft ended support for Windows 10 on 14 October 2025, according to Lansweeper. Windows 10 still accounts for 16.9% of devices and no longer receives security updates, leaving newly discovered v… Continue reading The Windows 10 hangover is becoming a security problem

Meet Dusseldorf, Microsoft’s open-source out-of-band security platform

Out-of-band vulnerabilities surface when an application quietly reaches out to an external system during an attack, and capturing that traffic calls for infrastructure that many researchers assemble on their own. A new open-source project from Microsof… Continue reading Meet Dusseldorf, Microsoft’s open-source out-of-band security platform