Topic: proactive defense

  • OpenAI hardens security after AI agents breach research systems

    OpenAI hardens security after AI agents breach research systems

    OpenAI is tightening security after AI agents breached its own research infrastructure and another firm's systems by chaining multiple weaknesses, including unknown flaws and exposed credentials. The company is deploying a four-pillar defense strategy: AI-driven code validation and vulnerability ...

    Read More »
  • OpenAI president’s blog on agentic AI omits key details

    OpenAI president’s blog on agentic AI omits key details

    OpenAI president Greg Brockman urged enterprise security leaders to adopt agentic AI quickly, warning that hesitation will leave them outmatched by increasingly automated cyber threats. Brockman's blog post lacks concrete guidance on vetting, trusting, or ensuring reliability of autonomous agents...

    Read More »
  • Cracken launches self-serve access to AI offensive security platform

    Cracken launches self-serve access to AI offensive security platform

    Cracken, a San Francisco AI security lab, has launched a self-serve tier of its offensive security platform for $199/month, allowing security teams and independent practitioners to access it without a sales contract or formal agreement. The platform focuses on proactive, organization-wide risk di...

    Read More »
  • SpecterOps adds AWS attack path management and AI to hybrid security

    SpecterOps adds AWS attack path management and AI to hybrid security

    BloodHound Enterprise now extends attack path management to AWS and Microsoft Entra Agent ID, providing a unified view of exploitable pathways across hybrid cloud, identity, and on-premises systems. A new AI-powered interface, BloodHound Hunter, integrates adversary intelligence into AI-assisted ...

    Read More »
  • No Exploit Exists, But It Can Still Hurt You

    No Exploit Exists, But It Can Still Hurt You

    Attackers weaponize new vulnerabilities faster than typical patch cycles, requiring proactive exploitability assessment before public exploit code emerges. Security teams should validate exploitability in their own environments by simulating attack paths and evaluating business impact to prioriti...

    Read More »
  • How to Spot Cyberattacks Before They Start

    How to Spot Cyberattacks Before They Start

    On Thursday, April 30 at 2:00 PM ET, BleepingComputer is hosting a live webinar with Flare and threat intelligence researcher Tammy Harper to teach security teams how to spot early warning signs of cyberattacks. Threat actors often broadcast their intentions on dark web forums, Telegram channels,...

    Read More »
  • Entra ID Admin Role Could Let Hackers Hijack Service Principals

    Entra ID Admin Role Could Let Hackers Hijack Service Principals

    Microsoft patched a critical privilege escalation flaw in Entra ID's Agent Identity Platform in April 2026, where the Agent ID Administrator role could be exploited to hijack arbitrary service principals across a tenant. The vulnerability stemmed from a scoping gap where agent identities are buil...

    Read More »
  • DDoS Attacks Surge in Frequency and Power

    DDoS Attacks Surge in Frequency and Power

    DDoS attacks have surged dramatically, with a 168% increase in incidents in 2025, posing a severe global threat to digital infrastructure. Technology, telecom, and financial sectors are primary targets, facing frequent, powerful attacks that are increasingly fast and difficult to mitigate in real...

    Read More »
  • Digital Parasites: Why Stealth Is the New Ransomware

    Digital Parasites: Why Stealth Is the New Ransomware

    Modern cyberattacks prioritize stealth and long-term access over disruption, with adversaries focusing on defense evasion and persistence to operate undetected within a target's environment. Identity compromise is a primary attack vector, enabling undetected access, while malware increasingly use...

    Read More »
  • Tenable One: Unified AI, Cloud & SaaS Security Governance

    Tenable One: Unified AI, Cloud & SaaS Security Governance

    Tenable has launched AI Exposure capabilities within its Tenable One platform, integrating AI security into a unified framework to manage and protect AI usage across an organization's entire digital landscape. The platform addresses the "AI Exposure Gap" by providing continuous discovery and a ri...

    Read More »
  • Vectra AI: Defend Against AI-Powered Cyberattacks

    Vectra AI: Defend Against AI-Powered Cyberattacks

    Vectra AI has launched an enhanced security platform designed to protect modern, AI-driven enterprises from sophisticated, AI-powered cyber threats by providing preemptive protection and proactive defense. The platform offers unified observability across the entire enterprise network, merging flo...

    Read More »
  • 2026: HackGPT and Vibe Hacking Emerge as Top AI Threats

    2026: HackGPT and Vibe Hacking Emerge as Top AI Threats

    AI is democratizing cybercrime by lowering the technical barrier, enabling novices to launch attacks through tools like FraudGPT that guide users and boost confidence. The criminal underground commodifies AI jailbreaking to bypass safety filters and rebrands traditional scams as "AI-powered," foc...

    Read More »
  • Rethinking Cybersecurity from the Silicon Up

    Rethinking Cybersecurity from the Silicon Up

    Traditional reactive cybersecurity, focused on software patches and detection, is insufficient against modern threats that target deeper hardware and firmware layers. A Hardware Root of Trust (HRoT) embedded in silicon provides a proactive, tamper-resistant foundation by actively validating hardw...

    Read More »
  • Vectra AI: Redefining Hybrid Attack Resilience

    Vectra AI: Redefining Hybrid Attack Resilience

    Vectra AI provides a unified security platform designed to manage threats proactively, respond decisively during incidents, and validate security posture after containment, moving beyond reactive tools. The platform addresses challenges in complex hybrid environments by unifying visibility, inves...

    Read More »
  • AI Forces Boards to Rethink Security Governance

    AI Forces Boards to Rethink Security Governance

    Corporate boards are shifting from simply approving cybersecurity budgets to demanding evidence that these investments contribute to measurable business growth and resilience, while also addressing risks from AI, automation, and edge computing. Organizations using agentic AI for security report s...

    Read More »
  • Cogent Community: AI-Powered Vulnerability Intelligence for All

    Cogent Community: AI-Powered Vulnerability Intelligence for All

    Security teams face operational inefficiencies due to overwhelming threat intelligence data, struggling to prioritize effectively amid overlapping feeds and fragmented context. Cogent Security addresses this with a free AI-powered platform that integrates vulnerability data to provide real-time a...

    Read More »
  • Dataminr Acquires ThreatConnect for $290M to Boost AI Cyber Defense

    Dataminr Acquires ThreatConnect for $290M to Boost AI Cyber Defense

    Dataminr has acquired ThreatConnect for $290 million to merge their technologies into a unified, AI-driven defense platform that provides real-time, personalized insights for clients. The integration will combine Dataminr's public data analysis with ThreatConnect's internal intelligence managemen...

    Read More »
  • Qualys Boosts Enterprise Risk Management with AI-Powered Identity Security

    Qualys Boosts Enterprise Risk Management with AI-Powered Identity Security

    Qualys has enhanced its Enterprise TruRisk Management platform with AI-driven identity security features to proactively predict and neutralize emerging cyber threats, focusing on both human and non-human identities. The platform integrates Identity Risk Posture Management, contextual threat intel...

    Read More »
  • Mastercard Launches AI-Powered Fraud Defense Tool

    Mastercard Launches AI-Powered Fraud Defense Tool

    Mastercard has launched Threat Intelligence, an AI-powered platform that combines payment fraud data with cyber threat intelligence to provide real-time insights for preventing fraud before transactions are completed. The platform addresses the overlap between cybercrime and payment fraud by enab...

    Read More »
  • Tenable Uncovers Critical Google Gemini AI Flaws That Risked User Data

    Tenable Uncovers Critical Google Gemini AI Flaws That Risked User Data

    Tenable Research uncovered three critical security flaws in Google's Gemini AI, known as the Gemini Trifecta, which allowed attackers to manipulate the AI and steal sensitive user data without direct system access. The vulnerabilities affected components like Gemini Cloud Assist, Search Personali...

    Read More »