Topic: access controls

  • Secure Active Directory with UserLock IAM: Product Showcase

    Secure Active Directory with UserLock IAM: Product Showcase

    UserLock is a modern IAM layer for Microsoft Active Directory that enhances security with granular MFA, contextual access rules, and real-time session monitoring without requiring a disruptive identity overhaul. It provides comprehensive visibility and control by aggregating AD entities into dash...

    Read More »
  • C1 strengthens identity governance with shadow AI detection

    C1 strengthens identity governance with shadow AI detection

    C1's shadow AI discovery automatically detects unauthorized AI agents, tools, and credentials across cloud and endpoint surfaces, integrating them into the existing identity governance platform to address security blind spots. The feature maps MCP servers, APIs, data stores, and local configurati...

    Read More »
  • AI Agents Mimic Users, But Play by Different Rules

    AI Agents Mimic Users, But Play by Different Rules

    The rapid proliferation of autonomous AI agents in production environments is outpacing the development of robust governance and identity management frameworks, creating significant security and compliance risks. A critical vulnerability stems from using outdated credentialing methods like static...

    Read More »
  • How to Build a Defense in Depth Strategy for Sensitive Data

    How to Build a Defense in Depth Strategy for Sensitive Data

    A defense in depth strategy for sensitive data requires multiple interconnected layers,classification, tokenization, DLP policy tuning, and access controls,rather than relying on a single safeguard like disk encryption or DLP alone. These layers operate across the data life cycle, with each layer...

    Read More »
  • Perplexity Faces Lawsuit Over Reddit Data Scraping

    Perplexity Faces Lawsuit Over Reddit Data Scraping

    Reddit has sued Perplexity and three data-scraping firms in federal court, accusing them of bypassing access controls to harvest Reddit content on a large scale, including through Google search results. Perplexity defends its actions by stating it only summarizes and cites Reddit discussions with...

    Read More »
  • Insider Threats, Malware & AI: The Rising File Security Crisis

    Insider Threats, Malware & AI: The Rising File Security Crisis

    File security breaches are escalating, causing significant financial losses, stolen data, and intellectual property exposure across organizations. Insider threats, weak access controls, and evolving malware like ransomware and zero-day threats are major vulnerabilities, with many companies lackin...

    Read More »
  • NCSC Urges Immediate Action to Build Cyber Resilience Amid Uncertainty

    NCSC Urges Immediate Action to Build Cyber Resilience Amid Uncertainty

    Paul Chichester, NCSC director, warns that unprecedented uncertainty from rapid technological change, geopolitical instability, and a shifting threat landscape makes cybersecurity "harder than they've ever been," urging stronger collaboration and cyber resilience. He highlights key challenges inc...

    Read More »
  • Why Ransomware Still Succeeds When Backups Are in Place

    Why Ransomware Still Succeeds When Backups Are in Place

    Ransomware attackers now deliberately target and destroy backup systems before deploying encryption, making traditional backup strategies a single point of failure when backup infrastructure is not isolated or protected. Common backup failures include lack of isolation between production and back...

    Read More »
  • CISA and Partners Release Zero Trust Guidance for OT Security

    CISA and Partners Release Zero Trust Guidance for OT Security

    A new cross-government guide from CISA and federal partners titled "Adapting Zero Trust Principles to Operational Technology" provides actionable steps for protecting critical infrastructure, emphasizing that IT-centric zero-trust models cannot be directly applied to OT due to legacy systems and ...

    Read More »
  • ChatGPT Expands Group Chats to Japan, New Zealand, South Korea & Taiwan

    ChatGPT Expands Group Chats to Japan, New Zealand, South Korea & Taiwan

    OpenAI has launched a group chat feature for ChatGPT in Japan, New Zealand, South Korea, and Taiwan, enabling real-time collaboration across multiple subscription tiers on mobile and web. The feature prioritizes privacy with invitation-only access, individual conversation confidentiality, and enh...

    Read More »
  • Secure Your Credentials: IT's Multi-System Strategy

    Secure Your Credentials: IT's Multi-System Strategy

    IT teams must securely manage credentials across systems using a comprehensive approach that combines technology, policy, and training to address escalating cyber threats. Key security measures include strong authentication like multi-factor authentication, encryption for data protection, and con...

    Read More »
  • Unlock Customer Sentiment & Risk Hidden in Your CRM Emails

    Unlock Customer Sentiment & Risk Hidden in Your CRM Emails

    Generative AI transforms inbound CRM email analysis by uncovering customer sentiment and risks, shifting focus from traditional outbound metrics to understanding actual communication content and emotional tone. Natural language processing reveals nuanced customer emotions, pain points, and buying...

    Read More »
  • Master Zero Trust & Identity at Today's Virtual Summit

    Master Zero Trust & Identity at Today's Virtual Summit

    The SecurityWeek Zero Trust & Identity Strategies Summit 2025 is a virtual event focusing on modern cybersecurity frameworks and the evolution of Zero Trust into a core strategy for protecting corporate assets. Zero Trust Network Access (ZTNA) is highlighted as essential for strengthening access ...

    Read More »
  • American Archive of Public Broadcasting Patches Security Flaw

    American Archive of Public Broadcasting Patches Security Flaw

    A security flaw in the American Archive of Public Broadcasting (AAPB) website allowed unauthorized downloads of protected media files for years, which was exploited since at least 2021 and has now been fixed. The vulnerability was an Insecure Direct Object Reference (IDOR) flaw that let users byp...

    Read More »
  • Reddit revives its unusual DMCA battle over Google results

    Reddit revives its unusual DMCA battle over Google results

    A federal judge allowed Reddit's lawsuit against SerpApi to proceed, ruling that Reddit plausibly alleged SerpApi conspired with Perplexity AI to bypass Google's access controls and harvest copyrighted Reddit content. This ruling contrasts with a recent dismissal of a similar Google case, where t...

    Read More »
  • Cisco ASA Devices Face Surge in Network Scans

    Cisco ASA Devices Face Surge in Network Scans

    A significant surge in network scanning activity targeting Cisco ASA devices has been detected, with spikes in late August involving up to 25,000 unique IP addresses, suggesting potential vulnerability exploitation. The scanning was largely driven by a Brazilian botnet and focused heavily on the ...

    Read More »
  • AI's Success Hinges on Trusted, Well-Governed Data

    AI's Success Hinges on Trusted, Well-Governed Data

    Many businesses are struggling to implement AI effectively due to a lack of trusted, well-governed data, which is essential for reliable and secure outcomes. A significant challenge is the complexity and security risks associated with unstructured data, with many organizations citing budget const...

    Read More »
  • AI Security Institute Urges Best Practices After Mythos T

    AI Security Institute Urges Best Practices After Mythos T

    The UK's AI Security Institute (AISI) has confirmed that Anthropic's Claude Mythos Preview model represents a significant advancement in autonomous cyber operations, capable of executing complex, multi-stage network attacks that would normally require days of human effort. While the AI successful...

    Read More »
  • Secure Your AI with Allama: Open-Source Automation

    Secure Your AI with Allama: Open-Source Automation

    Allama is an open-source security automation platform that uses visual workflows to integrate with over 80 tools, including SIEMs and ticketing systems, for unified threat detection and response. Its core strength lies in AI-powered agents that analyze threats, enable automated actions like conta...

    Read More »
  • The Password Problem We Still Haven't Solved

    The Password Problem We Still Haven't Solved

    Identity-related breaches persist due to basic vulnerabilities like reused passwords and insufficient verification, allowing attackers prolonged network access. Passwords remain the dominant authentication method despite intentions to go passwordless, hindered by legacy systems and diverse enviro...

    Read More »