Orbia CISO Miranda Ritchie on building security into sustainable infrastructure

In this interview with Help Net Security, industrial cybersecurity, CISO at Orbia, talks about protecting industrial systems where software runs water, chemical and manufacturing processes. She explains why a cyber incident in these settings can harm p… Continue reading Orbia CISO Miranda Ritchie on building security into sustainable infrastructure

OpenAI and Anthropic are pulling in different directions

Companies are handing routine operational decisions to AI agents that plan, remember, and act on their behalf. These agents run on statistical models, and their behavior can drift across weeks and months. That drift opens a security gap outside the rea… Continue reading OpenAI and Anthropic are pulling in different directions

Researchers make the case for a cybersecurity AI scientist

Autonomous AI agents have started doing real security work. Language-model agents probe software for flaws, run penetration tests, and chain together attack steps that once needed a human operator. Research about security has stayed slower and more man… Continue reading Researchers make the case for a cybersecurity AI scientist

Securing the inbox: Where identity, brand and security meet

Getting a verified logo to appear next to your email has traditionally meant having to work with two separate entities. You have to work with a DMARC partner for setting up DMARC and BIMI, then use a trusted Certificate Authority (CA) to purchase a Mar… Continue reading Securing the inbox: Where identity, brand and security meet

The endpoint recovery gap many teams discover during an incident

In this interview with Help Net Security, IGEL CTO Matthias Haas explains why backups alone do not equal recovery. He makes the case that endpoint recovery is often overlooked, leaving organizations exposed when thousands of devices go down at once. Ha… Continue reading The endpoint recovery gap many teams discover during an incident

Nika: Open-source code analysis tool

Many serious security bugs in web applications sit across several files at once. Request data enters through a controller, moves through data objects and service layers, and turns dangerous only when it reaches a sensitive operation such as a database … Continue reading Nika: Open-source code analysis tool

AI-generated code risks reach security, legal, and compliance teams

Most engineering organizations write code with AI, and a good number of them keep that code away from customers. A Flux survey of engineering leaders and practitioners found that nearly half run AI-generated code in production. Almost every company in … Continue reading AI-generated code risks reach security, legal, and compliance teams

AirDrop and Quick Share vulnerabilities affect protocols on five billion devices as fixes begin

Phones and laptops ship with a feature that sends files to nearby devices over the air, with no cables, accounts, or prior pairing. Apple calls its version AirDrop. Google and Samsung call theirs Quick Share. Both run inside privileged background servi… Continue reading AirDrop and Quick Share vulnerabilities affect protocols on five billion devices as fixes begin

DarkMoon: Open-source AI pentesting platform

Penetration testing has long run on expert time, with specialists spending days probing a network or web application by hand. Manual engagements stretch across weeks, expert consultants run into thousands of dollars a day, and results vary with the tes… Continue reading DarkMoon: Open-source AI pentesting platform

Companies keep bolting AI onto their products, and the security bill is coming due

Companies keep bolting AI and LLM features onto their products, and the security results are starting to show a pattern. The vulnerabilities those features create get rated high risk far more often than anything else, and they get fixed slower than any… Continue reading Companies keep bolting AI onto their products, and the security bill is coming due