DeepSeek can generate ransomware that runs entirely in browsers, abusing legitimate browser APIs and is difficult for conventional security tools to detect.
DORA compliance is not synonymous with security – digital resilience emerges only through consistent, centrally controllable security architecture beyond checklists.
DORA compliance is necessary but insufficient for digital resilience – what is required is a consistently built and centrally controllable security architecture with a focus on identity and cryptography management.
Anthropic classifies AI cybersecurity use into four categories and establishes a severity framework for jailbreaks to enable defensive applications while preventing misuse.
The BSI clarifies reporting obligations for cyberattacks and establishes binding standards for organisations subject to reporting requirements in Germany.
The FBI has seized NetNut — a proxy network based on the Popa botnet comprising two million compromised devices — after security firms documented its connection to malware on smart TVs and streaming devices in June.
FortiBleed actors monetize their access to Fortinet firewalls through cooperation with Inc and Lynx ransomware groups while also deploying zero-day exploits against Nextcloud.
Phishing attacks using generative AI are grammatically perfect and contextually calibrated, causing traditional rule-based filters to fail — Amazon Bedrock instead relies on behavior analysis and anomaly detection.
Attackers bypassed multi-factor authentication through the non-MFA-compatible ROPC protocol because many organizations had incompletely configured their Conditional Access Policies.
A newly documented prompt-injection technique manipulates AI browsers through fictional game scenarios to disable their security filters and steal credentials; OpenAI has patched, other vendors have not.