Most guidance published on AI agent security is written for enterprise organizations. It assumes dedicated AI security functions, red teams, platform engineering groups, and the budget to commission purpose-built tooling. If your security team is three people covering five hundred… Read More "Practical MCP Security: A Playbook for Mid-Market Teams"
Extension Banned for Stealing AI Chats Returns to Chrome Store, Resumes Malicious Activities
A Chrome extension that Google pulled from its store in January 2026 over conversation-theft allegations is back in circulation and reaching enterprise browsers again through Google’s own CRX distribution infrastructure, according to Netskope Threat Labs. The extension is named ‘AI… Read More "Extension Banned for Stealing AI Chats Returns to Chrome Store, Resumes Malicious Activities"
Researchers Turn USB Auto-Install Into a Full SYSTEM Takeover on Windows 11
Swati KhandelwalAug 11, 2026Vulnerability / Enterprise Security Windows Plug and Play can be abused to fetch signed vendor software for an emulated USB device and execute privileged installation components that researchers chained to SYSTEM access on a fully updated Windows… Read More "Researchers Turn USB Auto-Install Into a Full SYSTEM Takeover on Windows 11"
Logistics Giant Ceva Suffers Data Breach Impacting European Clients
A data breach at one of the world’s biggest logistics companies appears to have had a significant impact on its wider supply chain ecosystem of customers. Ceva Logistics is a subsidiary of the French CMA CGM Group, which is the world’s… Read More "Logistics Giant Ceva Suffers Data Breach Impacting European Clients"
Human Factors in Cybersecurity in 2026
Humans are often regarded as the weakest link in a cybersecurity program. Whether resulting from manipulative cybersecurity tactics or limited cybersecurity awareness, human errors remain the most prevalent attack vectors in every information security program, no matter how sophisticated your… Read More "Human Factors in Cybersecurity in 2026"
Hacker Conversations: Marcus Hutchins and the Journey From the Gray Zone to Redemption
Marcus Hutchins doesn’t personally consider himself a hacker – but he accepts the epithet because it’s a widely used term for what he once did. Born in Ascot, England, he was working as a cyber threat analyst for an LA-based… Read More "Hacker Conversations: Marcus Hutchins and the Journey From the Gray Zone to Redemption"
BdThemes Supply Chain Attack Poisons JSON to Create Rogue WordPress Admins
Ravie LakshmananAug 11, 2026Supply Chain Attack / Vulnerability Cybersecurity researchers have warned of a supply chain compromise impacting WordPress plugin vendor BdThemes, prompting the content management systems (CMS) platform’s plugins team to temporarily disable their downloads. “Unlike traditional software supply… Read More "BdThemes Supply Chain Attack Poisons JSON to Create Rogue WordPress Admins"
Security leaders’ rogue AI confidence could actually be disastrous
Part of the challenge is that an agent’s activity is spread across identities, cloud platforms, SaaS applications, APIs, and security tools that were not designed to tell a complete story, Camacho says. Security teams often have to piece together events… Read More "Security leaders’ rogue AI confidence could actually be disastrous"
OpenAI Pauses Some Development of Astra Model on Security Concerns
OpenAI has said it is temporarily halting some internal testing of a forthcoming model after assessing its cyber capabilities as “critical.” The AI firm said in a blog post on August 7 that testing of Astra had revealed “significant advancements… Read More "OpenAI Pauses Some Development of Astra Model on Security Concerns"
What’s New in Risk Automations: 4 Templates for Vendor and User Risk
Most vendor onboarding and app access work is waiting and follow-ups. Waiting for someone to notice a form came in, assign a tier, chase a questionnaire, or dig up the context behind a Slack request. Risk Automations workflows remove that… Read More "What’s New in Risk Automations: 4 Templates for Vendor and User Risk"