98% of fraudulent hires have company credentials by the time they’re caught

A 90-day period between hiring and onboarding is creating a blind spot in enterprise identity security, according to HYPR’s State of HR Identity Fraud Detection report. “Adversaries no longer need to breach a network when they can pass a remote intervi… Continue reading 98% of fraudulent hires have company credentials by the time they’re caught→

New infosec products of the week: September 18, 2026

Here’s a look at the most interesting products from the past week, featuring releases from Akuity, Bitsight, Cohesity, Dataminr, Nozomi Networks, and Tuskira. Dataminr uses agentic AI to predict and verify security threats Dataminr has announced Datami… Continue reading New infosec products of the week: September 18, 2026→

A fake ChatGPT billing email is after your OpenAI password

A fake ChatGPT billing email is steering users to a copy of the OpenAI login page that keeps whatever username and password they type. Josh Varden of Cofense’s Phishing Defense Center traced the email’s payment button through a Google redir… Continue reading A fake ChatGPT billing email is after your OpenAI password→

Google’s new agent security system detects tool misuse, loops and rogue behavior

Google’s Agent Anomaly Detection is a reasoning-based oversight and audit layer for autonomous agents deployed on Agent Runtime in the Gemini Enterprise Agent Platform and built with the Agent Development Kit (ADK) for Python 1.2 or later. Google recom… Continue reading Google’s new agent security system detects tool misuse, loops and rogue behavior→

Fake AI trading agent steals crypto wallet passwords

Attackers built a website for a fake AI crypto trading agent and used it to install Needle Stealer, malware that replaces a victim’s browser wallet with a copy that sends the wallet password to the attacker. HP caught the campaign between April a… Continue reading Fake AI trading agent steals crypto wallet passwords→

One runaway AI agent racked up a $50,000 cloud bill

Organizations are deploying autonomous AI systems that execute API calls, optimize production configurations, and analyze telemetry across hybrid cloud environments. At the same time, attacks are expanding from direct prompts to indirect prompt injecti… Continue reading One runaway AI agent racked up a $50,000 cloud bill→

NIST and CISA finalize playbook to stop token theft and forgery

NIST and CISA have finalized guidelines to help federal agencies and cloud service providers (CSPs) protect identity and access tokens from forgery, theft, and misuse. The guidance, Protecting Tokens and Assertions from Forgery, Theft, and Misuse (NIST… Continue reading NIST and CISA finalize playbook to stop token theft and forgery→

MSPs say nearly half their customers rely on them for CISO services

MSPs estimate that 46% of their customers, on average, look to them to act as CISOs, according to Sophos. Most of those providers do that job without the full set of compliance services, and many spread the work across several tools. Most providers exp… Continue reading MSPs say nearly half their customers rely on them for CISO services→

Microsoft sets security and safety rules for its AI models

Microsoft AI has published the first draft of its Humanist AI Code of Conduct, a training manual outlining how it develops AI models and intends them to behave during deployment. The draft is open for public consultation for six weeks. The company plan… Continue reading Microsoft sets security and safety rules for its AI models→