Flock CEO Garrett Langley has said the company made its first license plate cameras in his Atlanta home, permanently scratching his dining table with drill marks. A decade later, where the company assembles its signature—and fiercely debated—product has become more… Read More "Flock Once Touted Its Cameras as ‘Made in the USA.’ Now It’s Not So Clear"
Threat Gang ‘Springs’ Vishing Attacks on Microsoft Teams Users
A coordinated operation has targeted at least 150 Microsoft Teams users across multiple companies with voice phishing (vishing) attacks aimed at installing remote monitoring and management (RMM) and malware tools onto their machines. The campaign also attempts in some instances… Read More "Threat Gang ‘Springs’ Vishing Attacks on Microsoft Teams Users"
AI Agent Carries Out Multi-Stage Data Theft Attack
Spain’s data protection agency has reported the country’s first agentic AI-powered personal data breach. Francisco Pérez Bes, president of the Agencia Espanola Proteccion Datos (AEPD), revealed the news in a post on September 14. He said that an agent using… Read More "AI Agent Carries Out Multi-Stage Data Theft Attack"
Can You Adjust Vendor Security Ratings?
Vendor security ratings cannot be adjusted without modifying the criteria for evaluating a vendor’s security posture. Ratings are one input to a TPRM program, not a substitute for the stages around them. Since the ability to make unmitigated adjustments violates… Read More "Can You Adjust Vendor Security Ratings?"
CISA Releases Guidance on Deploying Cyber Decoys
The US Cybersecurity and Infrastructure Security Agency (CISA) has released new guidance on deploying decoy systems for robust cyber defenses within critical infrastructure organizations. Cyber decoys, the agency says, complement Zero Trust models, which continuously verify all access, by assuming… Read More "CISA Releases Guidance on Deploying Cyber Decoys"
16 governance tools for securing your AI fleet
Lasso Security Taking control of AI across a large enterprise platform requires a breadth of knowledge and the tools to control it. Lasso Security begins with a comprehensive census of AI implementations driven by automated tools that can find the… Read More "16 governance tools for securing your AI fleet"
AI Gives Cybercriminals a Dangerous New Advantage
Brett Johnson has seen cybercrime from both sides. Once dubbed the “original Internet Godfather” by the US Secret Service, Johnson built and ran Shadow Crew, an early organized cybercrime community, before eventually leaving that life behind. Now, he works with… Read More "AI Gives Cybercriminals a Dangerous New Advantage"
We Researched Four AI Evidence Analysis Tools for TPRM. Here’s What We Found.
TL;DR: We researched four AI evidence-parsing tools against four criteria security teams often overlook. None nailed all four. Here’s what they got right, where they fell short, and what to ask before trusting one with a real vendor decision. Analyzing… Read More "We Researched Four AI Evidence Analysis Tools for TPRM. Here’s What We Found."
AI Agents Can Retrain Own Models Mid-Task, Leaking Secrets and Erasing Refusals
AI agents can end up retraining the model that powers them, a process that can embed recoverable secrets in the model and eliminate refusals the model had been previously trained to enforce, according to new research from AI security firm… Read More "AI Agents Can Retrain Own Models Mid-Task, Leaking Secrets and Erasing Refusals"
AI’s Vulnerability Surge May Be More Manageable Than Feared
A new study suggests that while AI is rapidly accelerating vulnerability discovery, enterprise organizations are better equipped to handle the surge than generally assumed. The key is their ability to quickly validate findings, prioritize risk, and get available fixes into… Read More "AI’s Vulnerability Surge May Be More Manageable Than Feared"