What's happening in security
Breaches, credential dumps, actively exploited bugs and AI incidents — pulled from 3,022 items across public feeds, Have I Been Pwned and CISA KEV.
Biggest this week
- Cisco alerts customers to second actively exploited zero-day in as many days — CyberScoop, 1d ago
- Unauthenticated attackers are bypassing Cisco ISE’s management interface (CVE-2026-76460) — Help Net Security, 1d ago
- Google fixes actively exploited Android zero-day on Pixel devices — BleepingComputer, 2d ago
- Cisco warns customers of actively exploited zero-day in email gateways — CyberScoop, 3d ago
- Cisco patches actively exploited email gateway zero-day (CVE-2026-76461) — Help Net Security, 3d ago
-
Debating the Morality of Dario Amodei
https://www.youtube.com/watch?v=0FxXr3enprE My discussion with @ZackKormanhttps://x.com/ZackKorman on whether Dario and Anthropic are good or bad for the world. Some quick post-debate thoughts: I think Zach is very wrong about the…
-
The Ultimate Prompt For Businesses Being Pushed Into Using AI
Companies with money but no AI vision burn down while the disciplined few pull away/images/ultimate-ai-prompt-for-businesses.webp/images/ultimate-ai-prompt-for-businesses.webp Absolutely insane to me the damage that multiple compa…
-
Prompts to Run When a New Pinnacle Model Drops
A runner coiled in the starting blocks, looking down a glowing purple lane/images/things-to-do-when-fable-comes-back.webp/images/things-to-do-when-fable-comes-back.webp I originally wrote this for Claude's Fable 5, but the list ap…
-
‘Fighting Back’ Against AI Audits
If you think AI tools alone can take over managing your ISMS, read on. Jenny Odell, the artist, writer and lecturer at Stanford University, once described the concept of context collapse. This is a modern phenomenon where, thanks …
-
A Unified Theory For How AI Will Affect Jobs
The K-shaped bifurcation: thriving behaviors climbing above a rising Employability Line, struggling behaviors sinking below it/images/unified-theory-ai-jobs-k.webp/images/unified-theory-ai-jobs-k.webp Tyler Cowen recently made the…
-
AI Autopsy: South Staffordshire Water’s £1m Lesson in Visibility
An ICO incident post-mortem has some useful takeaways for CISOs Carly Page finds out how attackers managed to stay hidden inside the company’s network for two years Read the rest of AI Autopsy: South Staffordshire Water s £1m Less…
-
Onyxia Accepted into Anthropic’s Cyber Verification Program
We're excited to announce that Onyxia Cyber has been accepted into Anthropic's Cyber Verification Program (CVP) — a designation reserved for security organizations using advanced AI capabilities strictly for defensive purposes.
-
Boss Magazine Profiles Cybersecurity Expert Joseph Steinberg
Boss magazine this week features a profile of CyberSecurity Expert Joseph Steinberg, and discusses Steinberg s prowess for determining if evidence produced in lawsuits has been modified or misrepresented, and how Steinberg has hel…
-
14 Tips For Browsing The Web Securely
Modern web browsers are incredibly powerful, but their features — including security-related features such as saving passwords or keeping you logged in to a particular site or sites — can become vulnerabilities if not properly uti…
-
People, Psychology, and Privacy Principles: Cybercrime, Scams, and AI Through a Human Lens
Cybercrime and data protection might be technical disciplines, but people and psychology are key to a deeper understanding. From the gangs responsible for cybercrime, to their victims, and to everyone whose right to privacy and di…
-
Agentic Threats: How to Manage a Problem Like OpenClaw
OpenClaw promises productivity gains, but its autonomy, access and growing shadow AI footprint could make it a security team s next major challenge OpenClaw has rapidly emerged as one of the most popular agentic AI tools in the wo…
-
Gartner Security Summit 2026: Huntress 5 Key Takeaways
Resilience, identity, and practical AI led the conversation at Gartner Security & Risk Management Summit 2026. Here are five key takeaways security leaders should act on.
-
How to Rate the AI We're All Chasing
A three-axis rating gauge: the customization spoke longest, integration medium, competence shortest/images/customization-beats-competence.webp/images/customization-beats-competence.webp I'm increasingly rating the AI we're all cha…
-
Investigating suspicious AI workflows in Microsoft Entra Agent ID: Assistive agents
Assistive AI agents aren't always helpful—it all depends on who they're working on behalf of.
-
Finding the Middle in AI Narratives
A pendulum swung from a collapsing clock tower to an immovable monolith, its heavy bob now resting at center/images/finding-the-middle-in-ai-narratives.webp/images/finding-the-middle-in-ai-narratives.webp Another major AI vibe shi…
-
AI Predicts the Text of Answers
A stream of text reasoning its way through a locked room, landing on the one glowing stone/images/ai-predicts-answers.webp/images/ai-predicts-answers.webp There's a common argument about AI that says it doesn't understand anything…
-
Thoughts on AI Adoption Speed
A human figure reaching upward, lifted by rising machinery — magnified, not replaced, by AI/images/ai-adoption-speed.webp/images/ai-adoption-speed.webp One of the most talked about AI topics is the speed of AI adoption in companie…
-
How I'm Thinking About the Anthropic and OpenAI IPOs
A charcoal architectural sketch: a lone figure steps out of a broken, tangled sienna structure on the left—current state—into a clean purple architectural corridor that races toward bright open light on the right—ideal state/image…
-
Investigating suspicious AI workflows in Microsoft Entra Agent ID: Agent’s user account
Entra ID agent users can send malicious content to human users via Microsoft Teams. Here’s what to look out for.
-
The Top 11 Cybersecurity Risks to Small Businesses
I frequently am asked what the biggest cybersecurity risks are for small businesses. While every business is unique, and, as a result, is vulnerable to somewhat different dangers than every other business, there are certain common…
-
Après-climb: the Security + Privacy Weekend Magazine for May 30–31, 2026
Your weekend magazine for Information Security Data Privacy! InfoSecSherpa Sherpa Intelligence : Your Guides Up a Mountain of Information! Tools Resources ⚙️ 200+ Review Questions for Getting Started in Industrial (ICS/OT) Cyber S…
-
The Top CISO Stories from Around the Web: May 2026
From the Pentagon overhauling its paper-heavy compliance process to hackers poisoning AI coding assistants with the new "TrapDoor" malware, CISOs are fighting on entirely new battlegrounds. Let’s dive into the major shifts, high-s…
-
My local grocer recently upgraded their self-checkout lanes with some kind of AI loss prevention system, using…
My local grocer recently upgraded their self-checkout lanes with some kind of AI loss prevention system, using overhead cameras to track purchases. So far it's 0-2 for me. The last two times I've gone through the checkout it's err…
-
Investigating suspicious AI workflows in Microsoft Entra Agent ID: Autonomous agents
Read our primer on how to detect and respond to an autonomous agent escalating privileges and persisting in your Entra ID tenant
-
Post-AI Jobs Will Go to a Tiny Sliver
A small elite stands on an elevated platform under cold purple light while a vast crowd in warm sienna looks up from below/images/ai-jobs-tiny-sliver.webp/images/ai-jobs-tiny-sliver.webp I think people are missing the point on the…
-
Calling in to my doctor’s office to schedule my annual physical, and noticed the AI assistant has fake keyboar…
Calling in to my doctor’s office to schedule my annual physical, and noticed the AI assistant has fake keyboard clicking sounds to support the illusion.
-
Could Suddenly-Great Open Source AI Crash the US Economy?
A charcoal architectural sketch: a colossal monolithic tower cracked at the base, washed in deep purple, while a horizontal current of small distributed structures in burnt sienna flows beneath the fracture/images/could-open-sourc…
-
AI Autopsy: Axios Campaign Charts an Evolution in Social Engineering
For CISOs, there are two points of concern. The use of new social engineering tactics and the continued challenges presented by Trojanised open source packages Maintainers have long been perceived as one of the weakest links in th…
Last fetch 17m ago · 0 new · 2 source error(s)