You’re only as secure as your last evaluation
The updated Cybersecurity Maturity Model Certification (CMMC) represents a critical evolution in the Department of War (DoW) st...
222 articles in this category
The updated Cybersecurity Maturity Model Certification (CMMC) represents a critical evolution in the Department of War (DoW) st...
For decades, cybersecurity has been built around one assumption: defenders had enough time to: Discover vulnerabilities....
AI is accelerating vulnerability discovery, exploit development, and attacker weaponization faster than most organizations can...
Cybersecurity is full of frameworks, regulations, and directives that tell organizations what they should do. Zero Trust, NIST,...
After more than 300,000 production penetration tests (pentests), our company has learned something that may surprise people wat...
Huntress has documented a case where the Oracle database itself became the malware host. The security firm disclosed a campa...
Most organizations assume remediation reduces risk. It’s a reasonable assumption. A vulnerability is identified, a patch is...
Shortly after OpenAI publicly acknowledged the Hugging Face breach on July 21, Reuters journalist Raphael Satter called me for...
When I first started working on enterprise AI security initiatives, I expected the biggest challenges to be technical. I assume...
More evidence is emerging about how AI is becoming part of the day-to-day workflow for cybercriminals, from building and refining...
Given the widespread enterprise adoption of passkeys to replace passwords, a Palo Alto Networks Unit 42 report disclosing ways...
Given the widespread enterprise adoption of passkeys to replace passwords, a Palo Alto Networks Unit 42 report disclosing ways...
Modern attacks increasingly begin with the web application. Customer portals, partner platforms, APIs, external business app...
For years organizations have strengthened their security posture by investing in specialized tools for applications, identities...
Security researchers are warning against trust assumptions in AI security with newly detailed flaws affecting the open-source A...
OpenAI’s GPT-5.6 Sol and Anthropic’s Mythos 5 have been implicated in another series of AI security incidents after the models...
I was mapping the command-and-control infrastructure behind a state-linked intrusion set when the query came back and effective...
Comparisons of LangChain, CrewAI and AutoGen are easy to find — dozens of guides this year cover the same ground: developer exp...
Recent high-profile rogue agent incidents involving OpenAI and Anthropic underscore the fact that organizations can’t put blind t...
Malicious AI use and threats to AI systems are requiring cyber teams to double down on security fundamentals and rethink the fu...