Two major AI pain points for today’s security leaders are adjusting to new requirements for cyber hygiene, and preventing unintended consequences from over-privileged agents. Team8 is a venture capital and private equity firm that invests in companies specializing in enterprise… Read More "CISOs Race to Control AI Agents Without Destroying Their Value"
Hackers Exploit Maximum Severity Flaw in GitLabs
GitLab users are being urged to patch a maximum severity vulnerability in the platform after reports of “in-the-wild” exploitation. CVE-2026-85706 is described as an “improper limitation of a pathname to a restricted directory,” or “path traversal” flaw. The DevSecOps orchestration… Read More "Hackers Exploit Maximum Severity Flaw in GitLabs"
Good Security Rating? Your Dark Web Exposure Says Otherwise
Ask a security leader how secure their company is, and most will point to a number. A rating, maybe a grade, or a score out of some maximum that a vendor calculated for them. That number only measures half the… Read More "Good Security Rating? Your Dark Web Exposure Says Otherwise"
Telus Warns Customers of Account Breaches
Telus, one of Canada’s largest telecom providers, is notifying some customers that their accounts have been breached and their personal information has been accessed. In data breach notifications sent to customers whose consumer telecom accounts were affected, Telus said the… Read More "Telus Warns Customers of Account Breaches"
What the 3M ChatGPT case reveals about AI governance
Could you reconstruct the decision a year later? One habit I have developed working around operational systems is to think backward from the future investigation. I do not assume that every process will fail, but asking what evidence would be… Read More "What the 3M ChatGPT case reveals about AI governance"
OpenAI Agent Swarm Hacks RubyGems Package Manager
A cyber-attack on a popular open source package manager in May was the work of OpenAI agents, security researchers have revealed. Starting on May 11, the agents apparently flooded the RubyGems platform with malicious packages, forcing it to suspend new… Read More "OpenAI Agent Swarm Hacks RubyGems Package Manager"
The Cloud Controls Matrix (CCM): Manual vs. AI-Assisted Vendor Assessment
Most teams that assess cloud vendors already have a general idea of the Consensus Assessment Initiative Questionnaire (CAIQ) and Cloud Controls Matrix (CCM). However, you may not have a good answer for what it takes to run that assessment. Turning… Read More "The Cloud Controls Matrix (CCM): Manual vs. AI-Assisted Vendor Assessment"
ConnectWise Patches ScreenConnect Vulnerability Exploited in Worm-Like Attacks
ConnectWise has released urgent patches for a critical-severity vulnerability in the ScreenConnect remote access and support software that has been exploited in worm-like attacks. Tracked as CVE-2026-84869 (CVSS score of 9.9/10), the security defect is described as a missing authorization… Read More "ConnectWise Patches ScreenConnect Vulnerability Exploited in Worm-Like Attacks"
Malicious Twitch Browser Extension Leaks OAuth Tokens From Nearly 31,000 Users
Ravie LakshmananSep 14, 2026Malware / Browser Security A malicious cross-store Twitch browser extension has leaked OAuth tokens associated with nearly 31,000 users to proxy servers operated by a Russian commercial bot service. The extension, named “Twitch Enhanced Viewer | JeetBot,”… Read More "Malicious Twitch Browser Extension Leaks OAuth Tokens From Nearly 31,000 Users"
How to level up from security pro to security leader
“In my career, I’ve been very successful with the following: have a positive attitude especially under stress, assume best intent from people you’re engaging with, and always take the high road, especially when trying to collaborate on solutions,” he says.… Read More "How to level up from security pro to security leader"