How to prioritize AI agent security by business impact

Your CEO calls about an AI agent security incident in finance. He wants to know whether money moved, whether financial data was exposed, who owned the agent and why it had this level of access. The agent was connected to a spend management application … Continue reading How to prioritize AI agent security by business impact

How to prioritize AI agent security by business impact

Your CEO calls about an AI agent security incident in finance. He wants to know whether money moved, whether financial data was exposed, who owned the agent and why it had this level of access. The agent was connected to a spend management application … Continue reading How to prioritize AI agent security by business impact

Week in review: SimpleHelp vulnerability exploited, Oracle EBS Payments flaw under attack

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Companies keep bolting AI onto their products, and the security bill is coming due Companies keep bolting AI and LLM features onto their products, and the… Continue reading Week in review: SimpleHelp vulnerability exploited, Oracle EBS Payments flaw under attack

Geopolitical cyber threats are turning HR into a security front line

In this Help Net Security video, Roman Sannikov, Global Research Coordinator at iCOUNTER, explains why geopolitics belongs in every security team’s threat model. With open and simmering conflicts around the world, attacks can come from actors tha… Continue reading Geopolitical cyber threats are turning HR into a security front line

What a financial planner taught me about cybersecurity

When I spoke at a recent cybersecurity awareness event for financial planners and tax advisors, the audience really engaged with the subject. As happens at conferences the world over, people often come up to speakers to ask follow-up questions, or just… Continue reading What a financial planner taught me about cybersecurity

Getting boards to fund ERM means speaking their currency

In this Help Net Security video, Greg Young, VP Cybersecurity and Corporate Development at TrendAI, explains how to build Enterprise Risk Management that a board will pay for. Drawing on nearly four decades in cybersecurity, including time as a CISO an… Continue reading Getting boards to fund ERM means speaking their currency

Week in review: Fortibleed campaign’s impact on orgs, Cisco Unified CM flaw exploited

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Encrypted DNS still tells an eavesdropper where to look Encrypted DNS runs across much of the Internet. DNS over TLS, HTTPS, and QUIC keep the contents of… Continue reading Week in review: Fortibleed campaign’s impact on orgs, Cisco Unified CM flaw exploited

Product showcase: How to evaluate AI SOC platforms and where Prophet AI leads

The Agentic SOC market is loud. Dozens of vendors promise to take alert triage, investigation, and response off your analysts’ plates, but most claims have never been tested in production. The hard part is separating operational improvement from … Continue reading Product showcase: How to evaluate AI SOC platforms and where Prophet AI leads

23 ClawHub plugins squatting official scopes expose AI registry security gaps

Plugin registries for AI agents use npm-style scopes like @openclaw/ and @clawhub/ to signal who published a package. But on ClawHub, a registry whose plugins run with Claude, OpenClaw, and other agents, those official scopes weren’t reserved to … Continue reading 23 ClawHub plugins squatting official scopes expose AI registry security gaps