Chinese AI firms are stealing proprietary capabilities belonging to US-based AI models via massive distillation campaigns, according to US government agencies. Distillation is a common machine-learning practice in which mature “teacher” AI models are used to train “student” AI models.… Read More "US Government Claims Chinese AI Firms Distilling Frontier Models"
Beyond the Red Flags: Responding to a Failed Vendor Audit
Picture this: your vendor’s latest security audit just landed in your inbox, and you spot multiple failure points. What’s your immediate action plan? Failed vendor audits are an uncomfortable but increasingly common reality as reliance on third-party vendors grows, and… Read More "Beyond the Red Flags: Responding to a Failed Vendor Audit"
Nightmare-Eclipse Strikes Again With ShieldCrash Windows Exploit
On the heels of a record-breaking Patch Tuesday, the disgruntled security researcher known as Nightmare-Eclipse dropped yet another Windows zero-day exploit, which enables privilege escalation and bypasses the fix for a previous Windows exploit released last month. The latest from… Read More "Nightmare-Eclipse Strikes Again With ShieldCrash Windows Exploit"
Ongoing TPRM Success: Continuous Security Monitoring with AI
All security professionals know third-party risk management doesn’t stop after one risk assessment. That ongoing work is the TPRM program, not a one-time assessment. What about the next vendor? Or the future risks the vendors you’ve already evaluated will inevitably… Read More "Ongoing TPRM Success: Continuous Security Monitoring with AI"
Indonesia Hit by Android Banking App-Cloning Campaign
Indonesia has emerged as an early testing ground for a new Android banking malware technique that uses Google’s Work Profile feature to help fraudsters evade banking security controls. According to Group-IB, its researchers observed roughly 1,469 compromised devices and 1,281… Read More "Indonesia Hit by Android Banking App-Cloning Campaign"
Security Bottleneck? Here’s How to Accelerate Vendor Approvals
Organizations today move fast, but slow vendor approvals can grind everything to a halt. As companies increasingly rely on third-party vendors, slow vendor approvals create a serious security bottleneck. This slowdown costs organizations valuable time and resources—and leaves them open… Read More "Security Bottleneck? Here’s How to Accelerate Vendor Approvals"
AI Governance Can’t Wait
OPINION Last week, my colleagues at ESET Labs found hackers intentionally tripping AI-safety guardrails with a nuclear weapon prompt — a novel technique named GuardBreaker that is designed to interfere with AI-assisted malware analysis. In this case, Russia-aligned UAC-0099 used… Read More "AI Governance Can’t Wait"
Remediation Made Easy: Reducing Risks and Driving Vendor Action
Managing the vendor remediation process is no small feat. While on the surface, it might seem like the bulk of the heavy lifting is done once you complete your initial assessment, you (and every other security team on the planet)… Read More "Remediation Made Easy: Reducing Risks and Driving Vendor Action"
SpiderSilk Uses AI to Scan for Cyber Threats
Dubai-based security firm SpiderSilk puts on an adversarial hat when scanning for Internet-facing threats affecting companies. SpiderSilk’s scanning technologies require only a company’s name, not a customer’s list of IP addresses and domains. Within a few hours, the tools scan… Read More "SpiderSilk Uses AI to Scan for Cyber Threats"
What is Cyber Supply Chain Risk Management?
Cyber supply chain risk management (C-SCRM) is the process of identifying, assessing, and mitigating cybersecurity risks associated with an organization’s supply chain. Supply chains comprise multiple attack vectors, ranging from procurement tools to suppliers, developers, and third-party services. The complexity… Read More "What is Cyber Supply Chain Risk Management?"