SC Media
20 articles
Escalating an unassignable asset without making it someone's problem by default
Getting an owner to acknowledge an asset they did not know they had
MemTensor npm, PyPI packages compromised with cross-platform credential stealer
A Go binary called sckit was added to four malicious releases, targeting developer secrets.
Hype vs. Reality: Where is AI actually impacting the practice of cybersecurity now?
Hype vs. Reality: Where is AI impacting the practice of cybersecurity now?
Okta: Let's collaborate, not compete, on agentic AI security
Okta CEO Todd McKinnon called on the cybersecurity industry to develop common standards for agentic AI security.
Malicious bot traffic surges 124%, overwhelming website defenses
The "State of Bot & Agent Security Report" analyzed over a trillion requests, finding that scraping accounted for 70.9% of malicious bot traffic, increas...
D-Link warns of critical vulnerabilities in legacy DIR-822A routers with public exploit code
The first vulnerability, CVE-2026-86296, is a stack-based buffer overflow in the DHCP server component.
Okta enhances AI agent security with new platform features and Blueprint Alliance
Okta's new features, Agent Gateway and Shadow AI Agent Discovery for Endpoints, address the growing risks associated with AI agents gaining excessive access ...
Ransomware group PAYLOAD weaponizes Microsoft Active Directory for disruption
The PAYLOAD ransomware group targeted a manufacturing organization in the Middle East, gaining initial access via a compromised VPN account, Kaspersky reported.
SideCopy threat actor targets Indian academic institutions with new attack methods
SideCopy, an advanced persistent threat group originating from Pakistan and active since at least 2019, has historically targeted Indian defense forces and g...
Worker stress increases due to AI-driven security threats
A recent report by Object First indicates that 91% of workers feel uncomfortably stressed by IT security risks, a seven percentage-point increase from last y...
ZTE SmartLife platform vulnerabilities allow account takeover
Security researcher Mina Nageh Salama disclosed four critical vulnerabilities in the SmartLife platform, with the most severe, CVE-2026-86553, rated 8.8.
The government must designate AI as critical infrastructure sooner rather than later
Here are five policy initiatives government and industry should act on before a catastrophic incident forces our hand.
FBI probes ShinyHunters claims of massive agent data theft
ShinyHunters claims it stole 2 TB of sensitive data on thousands of current and former FBI agents.
First ‘autonomous AI C2 implant’ uses panel of models to vote on next task
CLOSEDQUORUM is designed to use DeepSeek, Qwen, Mistral and Gemini to make post-exploitation decisions.
Balancing AI Benefits and Risks as Your Next CISO Could be Artificial Intelligence - Evan McHenry - BSW #466
BigCommerce merchants impacted by third-party app data breach
The breach occurred between September 13 and September 17, 2026, when attackers gained access to shopper data via compromised credentials for the Ribon and R...
VA criticizes Baylor Genetics for delayed notification after data breach
The cybersecurity incident at Baylor Genetics, occurring around June 15, resulted in unauthorized access to sensitive information of 30,263 veterans.