AI governance needs to become part of the CISO’s GRC program
Here's why CISOs must include Ai in the company's GRC program.
20 articles
Here's why CISOs must include Ai in the company's GRC program.
There are four kinds of AI agents, and each must be handled differently, Ping executives said.
Coding agents expand application risk beyond AI models to the tools, context and systems around them.
A harmless-looking sentence can influence an agent's choices once it enters a model's context.
Ransomware gangs are exploiting a WatchGuard Firebox flaw that CISA flagged nine months ago.
The five layers of securing AI agent harnesses.
Cushman & Wakefield leaders share five practices for building an effective CIO-CISO partnership.
Here’s why defenders today have to take apart and analyze code the way a hacker would.
The AI-assisted campaign enabled attackers to gain domain admin in as little as 5 minutes.
The vulnerability, tracked as CVE-2025-20701, affects firmware version 1.0.
Researchers at Group-IB have identified that Gigabud is now being paired with Vwork, a modified version of the Shelter app, attributed to the GoldFactory thr...
The unpatched Plex Media Server instances are running versions 1.43.
Democratic senators Ron Wyden and Sheldon Whitehouse, along with Republican congressman Pat Harrigan, sent a letter to U.S.
The CMMC program, particularly its Phase 2 requirements, faced criticism for being overly burdensome and costly for small and medium-sized businesses.
The new capabilities address the challenge of AI agents inheriting access through existing vulnerabilities like hard-coded credentials and dormant accounts, ...
The Radware H1 2026 Global Threat Analysis Report indicates a significant shift in attack methods, with direct-path volumetric floods, particularly stateless...
Researchers at Aikido Security discovered four packages containing the Shai-Hulud worm, which had the same malicious payload hash as the original attack from...
The system measures spending agent by agent across cloud, code, and endpoints, offering a more comprehensive view than gateway-centric tools.
The BlueMoon exploit kit targeted U.S.