U.S. Bank CISO says the security role keeps growing and no one can own all of it

In this interview with Help Net Security, Ann Barron-DiCamillo, EVP, CISO at U.S. Bank, talks about how the CISO role has grown to cover fraud, resilience, third-party risk, and AI governance. She says no single leader can own all of it, so partnership… Continue reading U.S. Bank CISO says the security role keeps growing and no one can own all of it→

RemoveMacAI turns off Apple Intelligence on macOS 27 and deletes its models

A developer has released RemoveMacAI, a free command-line tool that turns off Apple Intelligence on macOS 27 and deletes about 12 GB of downloaded AI models. It requires a Mac with Apple silicon. macOS 27 doesn’t have a switch for Apple Intellige… Continue reading RemoveMacAI turns off Apple Intelligence on macOS 27 and deletes its models→

MAKERphone 2: A DIY 4G phone with plug-in camera, speaker and prototyping board

CircuitMess, a Croatian electronics kit maker, is selling MAKERphone 2.0, a build-it-yourself 4G phone on Kickstarter that buyers program in MicroPython or Arduino C++ and extend with plug-in hardware. Insert a SIM and it makes real calls and sends rea… Continue reading MAKERphone 2: A DIY 4G phone with plug-in camera, speaker and prototyping board→

Three questions a hospital CISO should ask a healthcare fintech vendor

In this Help Net Security interview, Drew McCombs, CTO and CISO at Cylerity, explains how he balances both roles. Security work is scheduled into every sprint, and issues touching patient data or funds disbursement come first. He covers how Cylerity ke… Continue reading Three questions a hospital CISO should ask a healthcare fintech vendor→

Many expect AI in the SOC to make entry jobs harder to get

A junior analyst in a security operations center, or SOC, has usually learned the job the slow way. You work the same phishing lure dozens of times, chase the same familiar malware pattern and write up the same case note at the end of the shift. Eventu… Continue reading Many expect AI in the SOC to make entry jobs harder to get→

Google says Gemini 4 Argon can find and patch critical software flaws

Google announced Gemini 4 Argon, its new frontier AI model, and is rolling it out to a set of trusted cyber defenders through its Fairwind Program. Google says the model can locate critical software vulnerabilities, validate them, and patch them withou… Continue reading Google says Gemini 4 Argon can find and patch critical software flaws→

In this new SME cybersecurity service, the AI assists and the consultants decide

BH Consulting, the Irish cybersecurity and data protection consultancy, has launched BH Haven, an ongoing service that gives Irish small and medium-sized enterprises (SMEs) access to its specialist consultants, supported by a proprietary AI tool for an… Continue reading In this new SME cybersecurity service, the AI assists and the consultants decide→

Most open critical and high flaws are over 90 days old

Detectify analyzed exposure data from 1,293 of its customers in the US, the UK and the Nordics and found that most serious flaws still open on their internet-facing systems are months old. Of the critical and high-severity vulnerabilities open at the t… Continue reading Most open critical and high flaws are over 90 days old→

Post-quantum website certificates from Cloudflare are scheduled for early 2027

Cloudflare plans to become a public certificate authority (CA), an organization that issues the digital certificates websites use to encrypt traffic and prove who they are. The company said that its CA will issue conventional certificates and a post-qu… Continue reading Post-quantum website certificates from Cloudflare are scheduled for early 2027→

Cloudflare’s EmDash 1.0 makes sandboxed plugins ask for access first

Cloudflare released EmDash 1.0, a free, open source content management system that locks each sandboxed plugin in its own isolated runtime. A plugin starts with access to its own private storage. It cannot reach the site’s content, media, users, … Continue reading Cloudflare’s EmDash 1.0 makes sandboxed plugins ask for access first→