A large-scale attack affects at least 74,000 Fortinet firewalls and compromises administrative access to security appliances at the core of enterprise networks.
Ransomware group DragonForce disguises its command-and-control traffic via Microsoft Teams’ TURN protocol and exploits multiple CVEs and kernel exploits to bypass security software.
Approximately 30,000 German companies under NIS2 must establish whistleblower reporting channels and must meet standards for confidentiality, protection against retaliation, and documentation.
A publicly accessible Elasticsearch server stored 24 billion credentials from infostealer malware collections, placing millions of accounts without MFA at acute risk.
SAE-based safety measures are vulnerable to post-intervention recovery: models can restore suppressed behaviors even when targeted features are controlled.
AI agents as active system participants with data access require new security approaches beyond classical governance, as their risks stem from gradual behavioral changes and Shadow AI, not from obvious violations.
Zero-trust architectures are converging with IAM systems to transform authentication from a one-time event into an ongoing process that evaluates contextual signals such as device security status, geographic location, and behavioral patterns.
LLMs can significantly accelerate the exploit development process for known vulnerabilities, weakening the patch gap as a traditional time buffer for defenders.