Multi-patch vulnerability fixes can leave open source exposed

Vulnerability management runs on a shorthand. A CVE shows a linked patch, someone applies it, and the ticket moves to closed. That shorthand covers most open source fixes. A share work in a different way, arriving as a run of two or more commits where … Continue reading Multi-patch vulnerability fixes can leave open source exposed

The AI code vulnerabilities that grow with your app

Theori built 28 apps with AI coding agents and scanned each one through its pentesting platform. Five models did the building, split between Anthropic and OpenAI, across apps written from a spec, thrown together from a casual prompt, and rewritten from… Continue reading The AI code vulnerabilities that grow with your app

Snowpick: Open-source ServiceNow exposure scanner

An employee opens a company service portal, searches the knowledge base, and drops a file onto a ticket. Someone who never signed in can send a request to that same portal and get records back. Bishop Fox ran that test across 166 ServiceNow instances d… Continue reading Snowpick: Open-source ServiceNow exposure scanner

Cisco’s open-weight Antares models make vulnerability localization cheaper

A security analyst opens an unfamiliar repository, pulls up a vulnerability advisory, and starts hunting for the file where the weakness lives. The naming conventions belong to someone else. Evidence sits in scattered corners of a codebase that runs to… Continue reading Cisco’s open-weight Antares models make vulnerability localization cheaper

The air gap is a myth and other OT security truths

Benjamin Bachmann, Director Group Information Security at Bilfinger, speaks with Help Net Security about defending industrial plants. He explains why attackers want to control operations instead of stealing data, and why the air gap is mostly a myth. B… Continue reading The air gap is a myth and other OT security truths

PR3TACK preemptive framework maps threats before attackers use them

Defensive frameworks in cybersecurity record what attackers have already done. Analysts study a breach, document the method, and build detections around confirmed activity. This cycle leaves a gap between the moment an attacker invents a technique and … Continue reading PR3TACK preemptive framework maps threats before attackers use them

AI agents are still logging in as humans

Most large companies run more than one AI platform at the same time. Developers pull up coding assistants, marketing teams lean on writing tools, and analysts query enterprise search across separate vendors. Single-provider setups keep giving way to mi… Continue reading AI agents are still logging in as humans

Reading between the lines of a cyber insurance policy

Enterprises in regulated industries often carry cyber insurance policies because contracts require it or boards ask for documented risk transfer. The global market for these policies reached about $16 billion in premiums in 2024. Coverage has become wi… Continue reading Reading between the lines of a cyber insurance policy

Ransom demands are down, email is the top way attackers get in

An employee opens an email that looks like any other, clicks a link, and gives up a password without noticing. A stolen login opens a door deeper in the network. Files stop opening a few days later. That chain now sits at the front of most ransomware c… Continue reading Ransom demands are down, email is the top way attackers get in