71% of CISOs spend 10+ hours on board reports

Boards want evidence that security controls and architecture reduce business risk, expressed in terms of resilience, consequence, and decision relevance. Translating technical findings into business language remains a major time burden for CISOs, who a… Continue reading 71% of CISOs spend 10+ hours on board reports

Week in review: Cisco fixes IMC bug, Patch Tuesday forecast, Black Hat USA 2026

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Mapping the malware blast radius a single alert won’t show you In this interview with Help Net Security, Mike Wiacek, founder and CTO of Stairwell, explai… Continue reading Week in review: Cisco fixes IMC bug, Patch Tuesday forecast, Black Hat USA 2026

US fuel gauge exposure fell by more than half in three months

Every month for the better part of a year, about 4,800 US internet addresses answered a query in the protocol that fuel tank gauges speak. In June the number was 2,354. The count fell across April, May, and June, all three months sit below the previous… Continue reading US fuel gauge exposure fell by more than half in three months

Gut feeling does nothing against AI spear phishing texts

A banker at a credit union sat down at a table with a dozen printed text messages, all of them written for that banker personally, and put them in order from the one most likely to get a click down to the one least likely. One of them stopped the sorti… Continue reading Gut feeling does nothing against AI spear phishing texts

Microsoft extends zero trust deeper into enterprise AI

Microsoft expanded its Zero Trust for AI strategy with updates to the Zero Trust Assessment tool and the Zero Trust Workshop. The additions help organizations assess security posture, prioritize remediation, and apply zero trust principles to AI agents… Continue reading Microsoft extends zero trust deeper into enterprise AI

Suppliers, logins, and AI tools are all becoming attack paths

Cybercriminals and state-backed hacking groups are abusing trusted identities, cloud services, AI tools, and software supply chains to gain access while avoiding detection, according to CrowdStrike’s 2026 Threat Hunting Report. Intrusion activity… Continue reading Suppliers, logins, and AI tools are all becoming attack paths

Suppliers, logins, and AI tools are all becoming attack paths

Cybercriminals and state-backed hacking groups are abusing trusted identities, cloud services, AI tools, and software supply chains to gain access while avoiding detection, according to CrowdStrike’s 2026 Threat Hunting Report. Intrusion activity… Continue reading Suppliers, logins, and AI tools are all becoming attack paths

Non-human identities are 91% of everything active in production

A backup job fires at two in the morning. A scanner walks the same AWS account an hour later, a deployment pipeline assumes a role at four, and a logging agent runs straight through the night. Each of those actions carries a credential issued to a mach… Continue reading Non-human identities are 91% of everything active in production

Non-human identities are 91% of everything active in production

A backup job fires at two in the morning. A scanner walks the same AWS account an hour later, a deployment pipeline assumes a role at four, and a logging agent runs straight through the night. Each of those actions carries a credential issued to a mach… Continue reading Non-human identities are 91% of everything active in production

Top product launches at Black Hat USA 2026

Black Hat USA 2026 is underway in Las Vegas, and vendors are using the moment to unveil what they hope will define the next year of defense. Here are the announcements drawing the most attention on the ground, and why they matter for teams weighing new… Continue reading Top product launches at Black Hat USA 2026