Topic: ai in cybersecurity

  • AI Slashes Attacker Breakout Time to 4 Minutes

    AI Slashes Attacker Breakout Time to 4 Minutes

    AI is dramatically accelerating cyberattacks, with threat actors using automation to reduce the average breakout time to just 34 minutes, enabling lateral movement in as little as four minutes. Attackers are using AI to enhance reconnaissance and social engineering, while defenders struggle due t...

    Read More »
  • AI-Proof Your Tech Career: Essential Protection Tips

    AI-Proof Your Tech Career: Essential Protection Tips

    Cybersecurity professional Keith Jones used AI tools like Anthropic's Claude to automate routine tasks, freeing him to focus on strategic work and boosting his team's productivity without additional hires. The tech industry is shifting toward AI-powered workflows, making it essential for professi...

    Read More »
  • Cybersecurity 'Doomed to Fail' Without AI, Experts Say

    Cybersecurity 'Doomed to Fail' Without AI, Experts Say

    Organizations relying solely on human-focused Security Operations Centers are "doomed to fail" against cyber threats, as attackers using AI, machine learning, and LLMs now exploit vulnerabilities within hours or days, compressing response times beyond human capability. Defenders must fundamentall...

    Read More »
  • AI's Impact on Attack Path Analysis: A New Era

    AI's Impact on Attack Path Analysis: A New Era

    Cybersecurity defenders must adopt AI to match the speed and scale of AI-powered attackers, as they struggle to find actionable insights within overwhelming data. AI transforms frameworks like MITRE ATT&CK from static references into dynamic tools that identify security gaps and model attack path...

    Read More »
  • Google’s AI helped fix more Chrome bugs in June than in the past two years

    Google’s AI helped fix more Chrome bugs in June than in the past two years

    Google fixed 1,072 security bugs in Chrome last month, more than in the previous two years combined, using internal AI tools. Google’s engineering director says LLMs have automated vulnerability discovery, allowing the company to preemptively fix flaws at an industrial scale. Microsoft also patch...

    Read More »
  • AI SOCs Will Still Need Human Analysts, Say Security Vendors

    AI SOCs Will Still Need Human Analysts, Say Security Vendors

    AI in cybersecurity will primarily automate routine tasks like ticket-taking and triage, not replace human analysts who handle deeper investigative work. Human intuition and contextual judgment remain irreplaceable for nuanced incidents, while AI reduces cognitive load by filtering false positive...

    Read More »
  • Defenders in Meetings, Attackers at Machine Speed

    Defenders in Meetings, Attackers at Machine Speed

    The cybersecurity threat landscape is intensifying, but a significant and widening gap exists between the level of threat activity and organizations' defensive preparedness, particularly for sophisticated attacks. Adversaries are leveraging artificial intelligence more rapidly than defenders, usi...

    Read More »
  • AI Skills Key to Solving Cybersecurity Skills Gap: Fortinet

    AI Skills Key to Solving Cybersecurity Skills Gap: Fortinet

    Mastering AI skills is critical for closing the cybersecurity skills gap, but organizations struggle with implementation due to insufficient expertise among teams. Insufficient cybersecurity awareness and training is the primary cause of security breaches, with 86% of organizations experiencing a...

    Read More »
  • Windows Zero-Day Leaked Ahead of Patch Tuesday

    Windows Zero-Day Leaked Ahead of Patch Tuesday

    The first quarter of 2026 highlights escalating AI-driven security risks, including the exploitation of zero-day vulnerabilities and the critical need for human oversight in automated systems. A significant development is the demonstration by Anthropic's Claude Mythos Preview of autonomously buil...

    Read More »
  • NIST Seeks Feedback on Modernizing NVD for AI Era

    NIST Seeks Feedback on Modernizing NVD for AI Era

    NIST has launched an initiative to modernize its National Vulnerability Database (NVD), publishing a request for information on August 12 to gather stakeholder input on adapting the system for an AI-driven cybersecurity landscape. The current NVD model of periodic scanning, static prioritization,...

    Read More »
  • RSAC 2026: The Critical Certificate Automation Gap

    RSAC 2026: The Critical Certificate Automation Gap

    The RSA Conference 2026 saw a major resurgence in attendance and international participation, recapturing its dynamic pre-pandemic energy levels. Key topics included the transformative role of AI in cybersecurity, alongside growing interest in quantum computing and the adoption of quantum-resista...

    Read More »
  • Know If You're Vulnerable Without Running an Exploit

    Know If You're Vulnerable Without Running an Exploit

    The window between vulnerability disclosure and exploit emergence has collapsed from weeks to under a day due to an explosion in CVE volume (one every 7.4 minutes in 2026) and AI-accelerated exploitation. Traditional defenses and continuous pentesting are inadequate, as live exploits can only tes...

    Read More »
  • Cybersecurity AI Scientist: Researchers Make the Case

    Cybersecurity AI Scientist: Researchers Make the Case

    Researchers propose a Cybersecurity AI Scientist to automate the entire security research cycle, including hypothesis generation, experiment design, and result analysis, aiming to accelerate routine discovery tasks. Key challenges include ensuring the AI's outputs are reliable and reproducible th...

    Read More »
  • Empirical Security secures $25M to predict data breaches

    Empirical Security secures $25M to predict data breaches

    Empirical Security has raised a $25 million Series A to advance its data-driven vulnerability prediction technology, using two models,Foundation for global threat monitoring and Radiant for organization-specific risk forecasting. The company is a second attempt by CEO Ed Bellis and CTO Michael Ro...

    Read More »
  • Indusface SwyftComply AI automates patching for AI-found flaws

    Indusface SwyftComply AI automates patching for AI-found flaws

    AI has accelerated vulnerability discovery but not remediation, creating a bottleneck where security teams are overwhelmed by findings while engineering capacity lags behind. Indusface launched SwyftComply AI, an autonomous vulnerability remediation platform that virtually patches flaws at the ed...

    Read More »
  • Microsoft Patches Bug in Age of Empires II

    Microsoft Patches Bug in Age of Empires II

    Microsoft released its largest-ever batch of security patches, driven by the expanded use of AI in discovering vulnerabilities at an unprecedented scale. A critical remote code execution bug in the remastered Age of Empires II, tracked as CVE-2026-50663, could let attackers take full control of a...

    Read More »
  • Mythos Beats GPT5.5 on Chrome Security Exploits

    Mythos Beats GPT5.5 on Chrome Security Exploits

    Bugcrowd's ExploitBench benchmark reveals Anthropic's Claude Mythos significantly outperformed OpenAI's GPT-5.5 in exploiting real-world Chrome vulnerabilities, with Mythos scoring 9.90 out of 16 and reaching the highest exploitation tier on 21 of 41 vulnerabilities compared to GPT-5.5's 5.51 ave...

    Read More »
  • Cybercrime Group Claims It Hacked MyPillow CEO Mike Lindell

    Cybercrime Group Claims It Hacked MyPillow CEO Mike Lindell

    The Russian ransomware group Play claims to have stolen sensitive data from MyPillow, including financial and personal records, and has given the company until Friday to respond before releasing the information online, though CEO Mike Lindell denies the breach and calls it a politically motivated...

    Read More »
  • Ex-CISA Chief Jen Easterly to Lead RSA Conference

    Ex-CISA Chief Jen Easterly to Lead RSA Conference

    Jen Easterly, former head of CISA, is appointed CEO of RSA Conference, signaling a major leadership shift for the global cybersecurity event. Easterly aims to expand RSAC's year-round influence, focusing on initiatives like innovation sandboxes to nurture AI-driven cybersecurity startups. She emp...

    Read More »
  • Aikido acquires Israel's Root to apply AI to open source patching

    Aikido acquires Israel's Root to apply AI to open source patching

    Aikido Security acquired Israeli startup Root for an estimated $70-100 million, integrating Root's AI agent technology that can patch open-source vulnerabilities in 15-40 minutes without breaking applications or requiring code rebuilds. The acquisition addresses the widespread problem of vulnerab...

    Read More »