Topic: security posture
-
ConnectSecure automates M365 security fixes for MSPs
ConnectSecure launched M365 Auto Remediation and AI-powered Training Assessments, enabling MSPs to directly address Microsoft 365 security findings and create, assign, and track training assessments within a single console. M365 Auto Remediation allows MSPs to fix supported findings (e.g., missin...
Read More » -
Microsoft extends zero trust across enterprise AI
Microsoft expanded its Zero Trust Assessment tool with a new AI pillar, adding targeted security checks and enhanced reporting that produce prioritized recommendations and executive summaries for securing AI deployments. The Zero Trust Workshop now includes a DevSecOps pillar with 15 control grou...
Read More » -
KT Fined $39M Over Misleading Femtocell Campaign
South Korea's PIPC fined KT approximately $39 million after hackers exploited a stolen femtocell certificate to intercept traffic and make unauthorized micropayments, defrauding 368 customers of about $175,000 and compromising data for 16,647 users. The regulator found KT's femtocell management s...
Read More » -
Intel 471 expands Verity471 with AI agent and MCP support
Intel 471 launched MCP471 and Agent471 as AI-driven enhancements to its Verity471 platform, helping security teams counter AI-powered cyberattacks by making threat intelligence more actionable and integrated with internal telemetry. MCP471 is a connector that integrates Verity471 intelligence int...
Read More » -
No Exploit Exists, But It Can Still Hurt You
Attackers weaponize new vulnerabilities faster than typical patch cycles, requiring proactive exploitability assessment before public exploit code emerges. Security teams should validate exploitability in their own environments by simulating attack paths and evaluating business impact to prioriti...
Read More » -
Multi-Extortion Ransomware: The New Attack Evolution
Ransomware attacks are a pervasive daily reality, severely disrupting operations across critical sectors like healthcare, finance, and manufacturing, as evidenced by a 49% increase in publicly reported attacks in 2025. The threat has escalated due to a shift from simple encryption to aggressive "...
Read More » -
Discern AI Deploys Six Agents to Automate Security Analysis
Discern Security has launched a suite of six specialized AI agents to address challenges like tool sprawl and alert overload, aiming to improve security posture and operational efficiency. The platform's agents automate key security workflows, including intelligence gathering (Scout), data analys...
Read More » -
Prioritize Security, Not Just Access, for Field Workers
Modern mobile workforce security requires individual accounts with mandatory multifactor authentication (MFA), moving beyond outdated shared credentials to protect sensitive data from sophisticated threats. Implementing the principle of least privilege through role-based access and streamlined re...
Read More » -
Armadin Raises $190M to Combat AI-Powered Cyberattacks
Armadin raised a record $189.9 million in early-stage funding to address the "hyperattack gap," where AI-powered cyber threats outpace traditional, human-dependent defenses. The company's platform uses an "agentic attacker swarm" of specialized AI agents that mimic and surpass human threat actors...
Read More » -
Singulr AI Agent Pulse: Enforce Runtime Governance for AI Agents
Singulr AI launched Agent Pulse, a platform providing real-time governance and oversight for autonomous AI agents to manage security risks and ensure policy compliance within enterprises. The platform offers four core functions: discovering all organizational AI agents, assessing their risk postu...
Read More » -
Boost Cyber Resilience: Proactive Wazuh Strategies
Cyber resilience is a proactive strategy that enables organizations to anticipate, withstand, respond to, and recover from attacks with minimal operational impact, moving beyond traditional reactive security models. The Wazuh security platform provides unified visibility, early threat detection, ...
Read More » -
6 Overlooked Okta Security Settings You Must Check Now
Securing identity providers like Okta is critical as they act as central gatekeepers for digital access, with risks arising from misconfigurations and evolving threats. The article outlines six essential Okta security practices, including robust password policies, phishing-resistant MFA, and feat...
Read More » -
Rubrik Launches Security Cloud Sovereign for Data Compliance
Rubrik has launched a new solution, Security Cloud Sovereign, to help global organizations meet strict data compliance and security challenges, particularly around data residency and access control. The platform gives customers definitive control over where their data is stored and who can access...
Read More » -
Ransomware's Relentless Spread: A Growing Threat
Ransomware is expanding globally into new regions and sectors, with attackers increasingly targeting areas with less mature security defenses. The public sector is a high-risk target due to uneven security practices, with a concerning segment showing both high exposure and weak controls. Future r...
Read More » -
Secure Your Data and AI Strategy for Success
AI security is now a primary business priority, with every new tool being evaluated for its security posture before its functional capabilities. Organizations struggle to balance innovation with robust security, requiring a proactive strategy that embeds security into AI projects from the start. ...
Read More » -
CISA Flags Spyware Zero-Day in Urgent Security Alert
US authorities issued a critical security alert for a high-risk vulnerability in Samsung mobile devices, exploited since mid-2024 to install spyware via malicious files on WhatsApp. The vulnerability, CVE-2025-21042 with a CVSS score of 9.8, enables attackers to use LandFall spyware for surveilla...
Read More » -
Tufin R25-2 Boosts Network & Cloud Security Automation
Tufin Orchestration Suite R25-2 enhances security by providing expanded visibility, comprehensive automation, and stronger controls across hybrid networks from a unified platform. The update introduces key advancements including improved topology accuracy, streamlined SASE policy control, and enh...
Read More » -
DefectDojo Launches Sensei: AI Cybersecurity Advisor
DefectDojo has launched Sensei, an autonomous AI cybersecurity advisor that operates independently without external AI services, eliminating vulnerabilities from third-party integrations. The cybersecurity industry is increasingly adopting AI, with many professionals using or testing AI tools to ...
Read More » -
Identity: The Leading Cloud Security Threat
Identity-related weaknesses and outdated vulnerabilities are the main causes of the rise in cloud security incidents, with attackers exploiting these gaps to access sensitive systems and data. Excessive permissions and over-privileged cloud identities, affecting 99% of cases, allow attackers to m...
Read More » -
Zero Trust: Slash Cyber Risk and Insurance Claims
Businesses in Australia and Oceania are facing a sharp rise in sophisticated cyberattacks, and adopting a Zero Trust security architecture can significantly reduce both the frequency and financial impact of these incidents. Research shows that implementing Zero Trust could have prevented up to 42...
Read More »