Microsoft 365 makes sharing files easy, but access can remain long after its original purpose has ended, leaving organizations with little visibility into who can still reach sensitive data. tenfold Software explains how centralized access governance and owner-driven reviews can help identify and remove unnecessary access. [...]
Fast-growing companies face countless recommendations for securing Google Workspace, but not every control provides the same value. This webinar examines real-world breaches to explore which security controls matter most, which may be overrated, and where lean security teams should focus their resources. [...]
Analysis of how default configurations in AWS AgentCore Harness allow prompt injection to exfiltrate credentials, and key steps to secure your agents. The post A Vault with a Heap-View: The Uncomfortable Space Between AgentCore Harness and Identity appeared first on Unit 42.
Run security operations for more than one team, region, or customer, and you inherit a familiar tradeoff. One giant deployment gives you a single view but costs you tenant isolation, while separate environments preserve isolation and scatter your analysts across contexts, with detection rules drifting into 12 slightly different copies along the way. Cross-project search (CPS) on Elastic Cloud Serverless is built to end that tradeoff. One Elastic Security project runs detection and triage, along…
Key Takeaways Periodic audits provide a point-in-time assessment, but they cannot demonstrate whether controls remain effective between audit cycles. Qualys platform data shows 10.5 billion configuration findings across customer environments but only 1.6% represent meaningful exposure and under 1% are prioritized, business-critical findings. Verizon’s 2026 DBIR found the median time to resolve weak passwords and misconfigured permissions is about 8 months. Across 1 billion misconfiguration…
Cross-environment attacks demand a new approach to security operations. Learn how Unit 42 Managed XSIAM helps SOC teams investigate complete attack paths. The post Inside the Modern SOC: Defending the Cross-Environment Pivot appeared first on Unit 42.
AI has already made fundamental changes to the operating environment for cybersecurity. Cyberattackers are testing more paths, adapting their techniques, and moving across digital environments with greater speed and persistence. The weaknesses they exploit remain familiar: excessive permissions, unprotected authentication flows, unpatched systems, exposed execution paths, and gaps between controls. What has changed is how quickly these weaknesses can combine into attack paths that cross…
AI is making credential theft faster and easier to scale, giving attackers more opportunities to abuse valid identities. Specops explains why identity security must go beyond successful authentication by verifying that both the user and the device requesting access can be trusted. [...]
Most fraud platforms only see a threat once it becomes a transaction. This guide compares the top 5 fraud prevention platforms for banks and fintechs in 2026, including Group-IB, Feedzai, Sift, DataVisor, and Kount, and what actually separates them.
The ransom itself can be only a fraction of the total cost of a ransomware attack, with downtime, recovery, remediation, and legal obligations adding millions to the bill. Datto explains how a mature BCDR strategy can reduce downtime and provide a faster, more predictable path to recovery. [...]
Dne 11. září 2026 začaly platit ohlašovací povinnosti podle článku 14 aktu o kybernetické odolnosti CRA, které se týkají hlášení aktivně zneužívaných zranitelností a závažných incidentů. Povinnost se vztahuje na výrobce produktů s digitálními prvky uváděných na trh Evropské unie. V souvislosti s tím byly na Portálu NÚKIB v sekci Chci vyřídit zveřejněny nové rozcestníky určené pro hlášení aktivně zneužívaných zranitelností a závažných incidentů podle CRA. Uživatelé zde naleznou také související…
The first hours after discovering a Google Workspace breach can determine how an incident unfolds. This webinar examines real-world breaches to show which early response decisions can limit the impact and which can make matters worse. [...]
CISA developed this guidance to help defensive teams at varying levels of cybersecurity maturity plan and implement cyber decoy strategies that strengthen their detection and response capabilities. Many organizations struggle to detect adversaries who use legitimate credentials, native tools, and living off the land (LOTL) techniques to conduct discovery, move laterally, and access data. Cyber decoys are assets that appear to be legitimate systems, accounts, or data, but are designed to…
AI is accelerating vulnerability discovery, leaving unpatchable operational technology (OT) systems at risk. Hoping for the best is not a viable anti-exploitation strategy. Deploying next-generation firewalls directly upstream allows for virtual patching through deep packet inspection. These systems scan incoming traffic to detect and block exploit attempts before they can impact the vulnerable device.The predictability of legitimate network connections to OT systems can be used to protect…
Modern macOS malware uses deceptive setup guides to steal credentials and sensitive user data. Learn how to identify and block these threats. The post Atomic macOS (AMOS) Stealer Activity appeared first on Unit 42.
Executive Summary Microsoft’s September 2026 security updates, KB5124008 and KB5124012, have been linked to USB audio failures on some Windows systems, highlighting the operational risk that can accompany security patching. Qualys TruRisk Eliminate classified both updates as Low Reliability, signaling the need for additional validation before production deployment. Patch Reliability helps IT and security teams focus on deeper testing where needed while allowing high-confidence patches to move…
The tech journalists at 404 Media learned that OpenAI is hiring hundreds of contractors to read and review a massive stream of real users’ ChatGPT prompts and responses. “Project Lily” is reportedly a program that asks contractors to score or critique ChatGPT’s answers to improve the chatbot’s quality and behavior. The fact that prompts may sometimes be reviewed by humans should not come as a complete surprise. AI companies also monitor conversations for safety reasons. Anthropic, for example,…
Executive Summary Remediation deadlines slip for reasons outside your control: a patch does not exist yet, a patch is delayed, or a remediation attempt fails. The outcome is the same either way: the host stays unpatched and stays on the network. TruRisk Eliminate closes that window by isolating the host automatically the moment your deadline passes, executed natively through the Qualys Cloud Agent with no EDR integration required. This post covers the trigger criteria, the QQL query behind a…
AI is shrinking the time between vulnerability disclosure and exploitation, leaving defenders less time to wait for patches or public exploits. Picus Security explains how exploitability validation, security control testing, and autonomous pentesting can help teams close exposure gaps before attackers arrive. [...]
Australia’s move from the Essential Eight to an outcomes-based cybersecurity model will push organizations from conducting periodic point-in-time, checklist compliance assessments to having continuous evidence of a solid security posture.Key takeawaysThe Australian Signals Directorate (ASD) is moving from the Essential Eight cybersecurity framework to a new outcomes-focused Essentials series covering enterprise IT, cloud, operational technology (OT), and potentially agentic AI.The Essential…
Developed by the National Institute of Standards and Technology (NIST) and CISA, this interagency report provides federal agencies and cloud service providers with guidelines to protect the identity assertions, access tokens, and cryptographic mechanisms that support modern authentication and authorization. As agencies adopt hybrid and multi-cloud environments, single sign-on, federation, and application programming interface (API)-based access increasingly depend on signed tokens and…
If you’re still OK with posting pictures of your kids on social media, take a minute to hear from mother of two Kalie Robins. At the start of September, she did something that hundreds of thousands of parents do every day. She posted a video of her young daughter on Facebook. Under the video of Robins and her daughter singing in a car, Facebook’s Meta AI system displayed a suggested question: “Who is the child passenger?” Robins was shocked that Facebook would ask this question about a minor,…
Upozorňujeme na phishingovou kampaň zneužívající autentizační mechanismus Device Code Flow. Útočník pod záminkou připojení ke schůzce nebo videohovoru přes legitimní nástroje přiměje uživatele k autorizaci a přes kontrolovanou relaci dochází ke krádeži přístupového tokenu a následné kompromitaci uživatele.Device Code FlowDevice Code Flow je autentizační mechanismus navržený pro případy, kdy se uživatel přihlašuje na zařízení s omezenými možnostmi zadávání přihlašovacích údajů, například na…
Patch automation can help IT teams keep pace with growing update volumes, but deploying faster also means bad updates can spread faster. Action1 explains how update rings, predefined success criteria, and human oversight can make automated patching faster without sacrificing control. [...]
Attackers can combine social engineering with malicious OAuth applications to gain access to Google Workspace data without relying solely on stolen passwords. This webinar examines two attacks to show how these breaches unfold and which security controls can help stop them. [...]
Local privilege escalation (LPE) is the step that turns a foothold into full control of a host. An attacker who lands as an unprivileged user rarely stops there. They want root, and Linux keeps offering new ways to get it.In this edition of our "Linux Detection Engineering" series, we’ll cover:The default flow that a Linux LPE produces on the host and the general rules that detect it.The recurring LPE patterns behind the most recent LPEs and how each works, along with how each looks through the…
Learn what credential theft is, how attackers steal credentials, and how to prevent credential-based attacks with identity-focused defenses from Huntress.
Scammers are abusing Meta’s copyright-reporting system to suspend people’s Instagram accounts and then hold them for ransom, according to the BBC. Criminals file fake copyright complaints with Instagram, claiming that an account is using material it doesn’t own. Repeated complaints can trigger a temporary account suspension from the platform, locking out the victim even though they haven’t done anything wrong. The criminal then moves the conversation to another platform, such as Telegram, and…
Key Takeaways Identity Security Posture Management (ISPM) is the continuous risk and posture layer of the identity stack not a replacement for Identity and Access Management (IAM), Privileged Access Management (PAM), Identity Governance and Administration (IGA), or Identity-as-a-Service (IDaaS), but the layer that continuously assesses the exposure those systems create. IAM authenticates and authorizes, PAM secures privileged access, IGA governs the identity lifecycle, and IDaaS delivers…
In this article OverviewTechnique CatalogPrivilege EscalationMitigation and protection guidanceReferencesLearn more Microsoft introduces the cloud web applications threat matrix, a MITRE ATT&CK-aligned framework that helps defenders understand, prioritize, and mitigate threats to cloud-hosted web apps and serverless platforms. Cloud-hosted web applications and serverless platforms create attack paths that can cross application code, managed runtimes, workload identities, deployment pipelines,…
If your scan engine already holds credentials for a host, it can ask that host which ports are open instead of probing for them.Every scan begins with the same question: which ports on this host are open? Everything after it, from identifying services to checking for vulnerabilities to evaluating policy, depends on the answer being right. The traditional answer comes from the outside: the scan engine sends traffic to a range of ports and infers each port's state from how the host responds. That…
MFA makes account takeover harder, but attackers are increasingly targeting the recovery processes used to reset passwords and authentication methods. Specops explains why stronger identity verification at the service desk is critical to preventing social engineering attacks from turning account recovery into account takeover. [...]
The shift from AI-assisted tooling to agentic, AI-native security operations is no longer theoretical. It is entering production at scale, and 2026 represents the practical inflection point for enterprise SOCs. Agent frameworks are stabilizing, defenses against agent-specific attacks are maturing, and executive stakeholders increasingly demand AI-driven outcomes that are transparent, explainable, and auditable.[1]Nearly two-thirds of organizations are already experimenting with AI agents, yet…
The EU Cyber Resilience Act's vulnerability reporting requirements take effect September 11, giving software vendors as little as 24 hours to report actively exploited flaws. ActiveState explains why knowing exactly what shipped and when vulnerabilities were discovered will be critical to meeting the new requirements. [...]
Jason Haddix on why manual pentesting can't keep up, what disappears first, and why human methodology is what makes AI pentesting work Category: Guides & Best Practices
Jason Haddix on why manual pentesting can't keep up, what disappears first, and why human methodology is what makes AI pentesting work Category: Guides & Best Practices
Executive Summary Exposure management platforms are increasingly evaluated based on post-detection actions rather than detection itself. This piece sets out four questions to ask when evaluating one: whether it narrows vulnerabilities to the exploitable using environment context rather than severity scores; whether it validates exploitability continuously rather than just discovering assets; whether it remediates beyond patching, including patchless mitigation; and whether it lets security and…
Grindr has reportedly agreed to pay £26 million (around $35 million) to settle a UK privacy lawsuit alleging that it shared sensitive user data, including some users’ HIV status, with advertisers. The claim was brought by London law firm Austen Hays on behalf of roughly 12,000 UK Grindr users. It alleges that the dating app breached privacy and data-protection laws during a period ending in early 2020. The claimants allege that Grindr shared personal and highly sensitive information with…
Third-party applications connected to Google Workspace can retain access long after their original purpose is forgotten. This webinar examines how overly permissive integrations contribute to breaches and which security controls can help fast-growing companies reduce their exposure. [...]
CERT Polska warns that attackers are actively exploiting a chain of critical MikroTik RouterOS flaws to seize control of routers exposed to the internet. Although the warning comes from Poland’s national cybersecurity response team, MikroTik routers are sold worldwide, including in the US. The vulnerabilities can affect users anywhere if their router is running a vulnerable version of RouterOS and its SSH remote-management service is accessible from the internet. Attackers are exploiting two…
Group-IB's 2026 data shows ransomware accelerating across APAC. See where response plans fail, and the 5-pillar framework built to hold under pressure.
Smart TVs are internet-connected computers with microphones, app stores, advertising systems, and access to the same home networks used by your family’s phones, laptops, printers, and smart-home devices. In the past, we reported on Samsung settling a lawsuit with the Texas Attorney General over how its smart TVs collect and monetize viewing data using Automated Content Recognition (ACR). ACR technology samples what appears on or is heard through a TV, creates a digital fingerprint, and compares…
Upozorňujeme na zranitelnost ve firmware RouterOS v zařízeních MikroTik, kterou lze před autentizací zneužít k vzdálenému spuštění kódu s administrátorskými oprávněními. Aktuálně dochází k masovému zneužití této zranitelnosti. Dne 4. září 2026 byla vydána aktualizace RouterOS, v současnosti jsou však na internetu v ČR stále vystaveny tisíce zranitelných zařízení. Útočníci navíc u napadených zařízení upravují konfiguraci, aby si zajistili trvalý přístup k zařízení, který přežije jakoukoli…
Enterprises face an unmanaged crisis of AI agent and MCP server sprawl, characterized by rapid, decentralized proliferation of autonomous agents, protocol connections operating with excessive privilege, opaque execution paths, and identity blind spots. Absent agent-aware governance, modern enterprises struggle to prevent, detect, or contain multi-hop autonomous exploits, leaving environments vulnerable to lateral movement, shadow collaboration, and unauthorized data exfiltration. More…
In this article Edge AI changes the trust model for AI systemsConstrain model actions through deterministic mediationEstablish trust before releasing sensitive assetsVerify runtime before releasing sensitive assetsVerify artifacts that shape model behaviorNext steps Edge AI moves model execution, model IP, customer data, and system authority into infrastructure the customer owns and operates. That changes who must verify the stack before sensitive assets are released. Edge AI includes AI…
Dirty Frag turns low-privileged Linux access into root, and can escape containers. The affected CVEs, how to check if you're exposed, and how to fix it. Category: Vulnerabilities & Threats
In a joint advisory released Thursday, the G7 Cyber Security Working Group and the U.S. Cybersecurity and Infrastructure Security Agency, CISA, said organizations should begin moving to post-quantum cryptography now.
X says attackers may be targeting accounts because its X Money payments service is now more widely available. The company is investigating a wave of unsolicited password-reset emails sent to users. While their arrival alongside the wider X Money rollout has fueled account-takeover concerns, X says it has found no evidence of a breach or successful account takeovers so far. X users began reporting unexpected password-reset emails and codes on September 1. In a public post, X product engineer…
Dne 11. září 2026 začíná platit povinnost dle Aktu o kybernetické odolnosti (CRA) k hlášení závažných incidentů a aktivně zneužívaných zranitelností. Přečtěte si nový podpůrný materiál.
Národní úřad pro kybernetickou a informační bezpečnost (NÚKIB) upozorňuje na cílené phishingové kampaně zaměřené na uživatele komunikační aplikace Signal.