<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="/rss-style.xsl"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/">
<channel>
<title><![CDATA[tsecurity.de - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=darktrace%2F]]></link>
<description><![CDATA[Das Gesamte Cyber Threat Intelligence Feed-Archiv von TSecurity.de. Alle Nachrichten, Sicherheitsmeldungen, Videos, Downloads und Analysen in einer zentralen Übersicht.]]></description>
<language>de-DE</language>
<lastBuildDate>Tue, 15 Sep 2026 03:55:23 +0200</lastBuildDate>
<pubDate>Tue, 15 Sep 2026 03:55:23 +0200</pubDate>
<ttl>15</ttl>
<copyright>2026 tsecurity.de - 📰 Alle Kategorien</copyright>
<managingEditor>contact@tsecurity.de (tsecurity.de)</managingEditor>
<webMaster>contact@tsecurity.de (tsecurity.de)</webMaster>
<image>
<url>https://tsecurity.de/templates/mydraft-basis-tsecurity.de/media/logo.png</url>
<title><![CDATA[tsecurity.de - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=darktrace%2F]]></link>
</image>
<atom:link href="https://tsecurity.de/export/rss/alle-kategorien.xml?q=darktrace%2F" rel="self" type="application/rss+xml" />
<item>
<title><![CDATA[nachgehakt! – bei Dr. Beverly McCann, Darktrace: Staatliche Angriffe frühzeitig erkennen]]></title>
<description><![CDATA[Woran erkennen Betreiber, dass sie es mit einem staatlich gesteuerten Angreifer als mit einer klassischen Cybercrime-Gruppe zu tun haben? Weiterlesen]]></description>
<link>https://tsecurity.de/de/4132035/it-security-nachrichten/nachgehakt-bei-dr-beverly-mccann-darktrace-staatliche-angriffe-fruehzeitig-erkennen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4132035/it-security-nachrichten/nachgehakt-bei-dr-beverly-mccann-darktrace-staatliche-angriffe-fruehzeitig-erkennen/</guid>
<pubDate>Mon, 14 Sep 2026 22:45:00 +0200</pubDate>
<content:encoded><![CDATA[<p>Woran erkennen Betreiber, dass sie es mit einem staatlich gesteuerten Angreifer als mit einer klassischen Cybercrime-Gruppe zu tun haben? <a href="https://www.google.com/url?rct=j&amp;sa=t&amp;url=https://www.computer-automation.de/safety-und-security/beverly-mccann-darktrace-staatliche-angriffe-fruehzeitig-erkennen.htm&amp;ct=ga&amp;cd=CAIyGWQwOWZmNTA1ZDc3ZWYwZTQ6ZGU6ZGU6REU&amp;usg=AOvVaw3u1jBrOGOzzPQTl6n3g1s1" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[KI in der Cybersicherheit: Neue Angriffe, neue Abwehr - BigData-Insider]]></title>
<description><![CDATA[Kommentar von Max Heinemeyer, Darktrace KI zwingt Security-Teams zum Umdenken ... Künstliche Intelligenz (KI) verändert Cyberangriffe und setzt ... Weiterlesen]]></description>
<link>https://tsecurity.de/de/3895837/ai-nachrichten/ki-in-der-cybersicherheit-neue-angriffe-neue-abwehr-bigdata-insider/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3895837/ai-nachrichten/ki-in-der-cybersicherheit-neue-angriffe-neue-abwehr-bigdata-insider/</guid>
<pubDate>Mon, 31 Aug 2026 11:39:39 +0200</pubDate>
<content:encoded><![CDATA[<p>Kommentar von Max Heinemeyer, Darktrace KI zwingt Security-Teams zum Umdenken ... Künstliche Intelligenz (KI) verändert Cyberangriffe und setzt ... <a href="https://www.google.com/url?rct=j&amp;sa=t&amp;url=https://www.bigdata-insider.de/ki-cybersicherheit-ki-angriffe-verhaltensanalyse-identitaeten-a-2c59cd19651b7e6edbdd6da8e8b6cefe/&amp;ct=ga&amp;cd=CAIyGTRiZTZmY2RmMzZhYjA0M2Y6ZGU6ZGU6REU&amp;usg=AOvVaw2V9xJZhanz9khYlkhrIcsF" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[KI in der Cybersicherheit: Neue Angriffe, neue Abwehr - BigData-Insider]]></title>
<description><![CDATA[Kommentar von Max Heinemeyer, Darktrace KI zwingt Security-Teams zum Umdenken ... Künstliche Intelligenz (KI) verändert Cyberangriffe und setzt ... Weiterlesen]]></description>
<link>https://tsecurity.de/de/3895644/ai-nachrichten/ki-in-der-cybersicherheit-neue-angriffe-neue-abwehr-bigdata-insider/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3895644/ai-nachrichten/ki-in-der-cybersicherheit-neue-angriffe-neue-abwehr-bigdata-insider/</guid>
<pubDate>Mon, 31 Aug 2026 11:34:29 +0200</pubDate>
<content:encoded><![CDATA[<p>Kommentar von Max Heinemeyer, Darktrace KI zwingt Security-Teams zum Umdenken ... Künstliche Intelligenz (KI) verändert Cyberangriffe und setzt ... <a href="https://www.google.com/url?rct=j&amp;sa=t&amp;url=https://www.bigdata-insider.de/ki-cybersicherheit-ki-angriffe-verhaltensanalyse-identitaeten-a-2c59cd19651b7e6edbdd6da8e8b6cefe/&amp;ct=ga&amp;cd=CAIyGTRiZTZmY2RmMzZhYjA0M2Y6ZGU6ZGU6REU&amp;usg=AOvVaw2V9xJZhanz9khYlkhrIcsF" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[KI in der Cybersicherheit: Neue Angriffe, neue Abwehr - BigData-Insider]]></title>
<description><![CDATA[Kommentar von Max Heinemeyer, Darktrace KI zwingt Security-Teams zum Umdenken ... Künstliche Intelligenz (KI) verändert Cyberangriffe und setzt ... Weiterlesen]]></description>
<link>https://tsecurity.de/de/3893970/ai-nachrichten/ki-in-der-cybersicherheit-neue-angriffe-neue-abwehr-bigdata-insider/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3893970/ai-nachrichten/ki-in-der-cybersicherheit-neue-angriffe-neue-abwehr-bigdata-insider/</guid>
<pubDate>Mon, 31 Aug 2026 10:36:19 +0200</pubDate>
<content:encoded><![CDATA[<p>Kommentar von Max Heinemeyer, Darktrace KI zwingt Security-Teams zum Umdenken ... Künstliche Intelligenz (KI) verändert Cyberangriffe und setzt ... <a href="https://www.google.com/url?rct=j&amp;sa=t&amp;url=https://www.bigdata-insider.de/ki-cybersicherheit-ki-angriffe-verhaltensanalyse-identitaeten-a-2c59cd19651b7e6edbdd6da8e8b6cefe/&amp;ct=ga&amp;cd=CAIyGTRiZTZmY2RmMzZhYjA0M2Y6ZGU6ZGU6REU&amp;usg=AOvVaw2V9xJZhanz9khYlkhrIcsF" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[KI in der Cybersicherheit: Neue Angriffe, neue Abwehr - BigData-Insider]]></title>
<description><![CDATA[Kommentar von Max Heinemeyer, Darktrace KI zwingt Security-Teams zum Umdenken ... Künstliche Intelligenz (KI) verändert Cyberangriffe und setzt ... Weiterlesen]]></description>
<link>https://tsecurity.de/de/3893843/ai-nachrichten/ki-in-der-cybersicherheit-neue-angriffe-neue-abwehr-bigdata-insider/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3893843/ai-nachrichten/ki-in-der-cybersicherheit-neue-angriffe-neue-abwehr-bigdata-insider/</guid>
<pubDate>Mon, 31 Aug 2026 10:32:59 +0200</pubDate>
<content:encoded><![CDATA[<p>Kommentar von Max Heinemeyer, Darktrace KI zwingt Security-Teams zum Umdenken ... Künstliche Intelligenz (KI) verändert Cyberangriffe und setzt ... <a href="https://www.google.com/url?rct=j&amp;sa=t&amp;url=https://www.bigdata-insider.de/ki-cybersicherheit-ki-angriffe-verhaltensanalyse-identitaeten-a-2c59cd19651b7e6edbdd6da8e8b6cefe/&amp;ct=ga&amp;cd=CAIyGTRiZTZmY2RmMzZhYjA0M2Y6ZGU6ZGU6REU&amp;usg=AOvVaw2V9xJZhanz9khYlkhrIcsF" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[KI in der Cybersicherheit: Neue Angriffe, neue Abwehr - BigData-Insider]]></title>
<description><![CDATA[KI in der Cybersicherheit: Neue Angriffe, neue Abwehr. Kommentar von Max Heinemeyer, Darktrace KI zwingt Security-Teams zum Umdenken. 31.08.2026 Von ... Weiterlesen]]></description>
<link>https://tsecurity.de/de/3891895/it-security-nachrichten/ki-in-der-cybersicherheit-neue-angriffe-neue-abwehr-bigdata-insider/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3891895/it-security-nachrichten/ki-in-der-cybersicherheit-neue-angriffe-neue-abwehr-bigdata-insider/</guid>
<pubDate>Mon, 31 Aug 2026 09:23:29 +0200</pubDate>
<content:encoded><![CDATA[<p>KI in der Cybersicherheit: Neue Angriffe, neue Abwehr. Kommentar von Max Heinemeyer, Darktrace KI zwingt Security-Teams zum Umdenken. 31.08.2026 Von ... <a href="https://www.google.com/url?rct=j&amp;sa=t&amp;url=https://www.bigdata-insider.de/ki-cybersicherheit-ki-angriffe-verhaltensanalyse-identitaeten-a-2c59cd19651b7e6edbdd6da8e8b6cefe/&amp;ct=ga&amp;cd=CAIyGTViNmI2YzJlZTdlY2E1ZTI6ZGU6ZGU6REU&amp;usg=AOvVaw2V9xJZhanz9khYlkhrIcsF" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[KI in der Cybersicherheit: Neue Angriffe, neue Abwehr - BigData-Insider]]></title>
<description><![CDATA[Kommentar von Max Heinemeyer, Darktrace KI zwingt Security-Teams zum Umdenken ... Künstliche Intelligenz (KI) verändert Cyberangriffe und setzt ... Weiterlesen]]></description>
<link>https://tsecurity.de/de/3891530/ai-nachrichten/ki-in-der-cybersicherheit-neue-angriffe-neue-abwehr-bigdata-insider/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3891530/ai-nachrichten/ki-in-der-cybersicherheit-neue-angriffe-neue-abwehr-bigdata-insider/</guid>
<pubDate>Mon, 31 Aug 2026 09:08:16 +0200</pubDate>
<content:encoded><![CDATA[<p>Kommentar von Max Heinemeyer, Darktrace KI zwingt Security-Teams zum Umdenken ... Künstliche Intelligenz (KI) verändert Cyberangriffe und setzt ... <a href="https://www.google.com/url?rct=j&amp;sa=t&amp;url=https://www.bigdata-insider.de/ki-cybersicherheit-ki-angriffe-verhaltensanalyse-identitaeten-a-2c59cd19651b7e6edbdd6da8e8b6cefe/&amp;ct=ga&amp;cd=CAIyGTRiZTZmY2RmMzZhYjA0M2Y6ZGU6ZGU6REU&amp;usg=AOvVaw2V9xJZhanz9khYlkhrIcsF" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[KI in der Cybersicherheit: Neue Angriffe, neue Abwehr - BigData-Insider]]></title>
<description><![CDATA[Kommentar von Max Heinemeyer, Darktrace KI zwingt Security-Teams zum Umdenken ... Künstliche Intelligenz (KI) verändert Cyberangriffe und setzt ... Weiterlesen]]></description>
<link>https://tsecurity.de/de/3890989/ai-nachrichten/ki-in-der-cybersicherheit-neue-angriffe-neue-abwehr-bigdata-insider/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3890989/ai-nachrichten/ki-in-der-cybersicherheit-neue-angriffe-neue-abwehr-bigdata-insider/</guid>
<pubDate>Mon, 31 Aug 2026 08:58:52 +0200</pubDate>
<content:encoded><![CDATA[<p>Kommentar von Max Heinemeyer, Darktrace KI zwingt Security-Teams zum Umdenken ... Künstliche Intelligenz (KI) verändert Cyberangriffe und setzt ... <a href="https://www.google.com/url?rct=j&amp;sa=t&amp;url=https://www.bigdata-insider.de/ki-cybersicherheit-ki-angriffe-verhaltensanalyse-identitaeten-a-2c59cd19651b7e6edbdd6da8e8b6cefe/&amp;ct=ga&amp;cd=CAIyGTRiZTZmY2RmMzZhYjA0M2Y6ZGU6ZGU6REU&amp;usg=AOvVaw2V9xJZhanz9khYlkhrIcsF" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hackers Use Fake Google Gemini App to Steal Windows Users’ Browser Credentials]]></title>
<description><![CDATA[Threat actors are increasingly abusing the growing popularity of generative AI tools to spread malware. In a recent incident observed by Darktrace, attackers used a fake Google Gemini installer to infect a Windows device with the Vidar information stealer. The campaign targeted users actively loo...]]></description>
<link>https://tsecurity.de/de/3749785/it-security-nachrichten/hackers-use-fake-google-gemini-app-to-steal-windows-users-browser-credentials/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3749785/it-security-nachrichten/hackers-use-fake-google-gemini-app-to-steal-windows-users-browser-credentials/</guid>
<pubDate>Sat, 22 Aug 2026 04:31:03 +0200</pubDate>
<content:encoded><![CDATA[<p>Threat actors are increasingly abusing the growing popularity of generative AI tools to spread malware. In a recent incident observed by Darktrace, attackers used a fake Google Gemini installer to infect a Windows device with the Vidar information stealer. The campaign targeted users actively looking for AI software rather than relying on... <a href="https://cyberpress.org/fake-gemini-steals-credentials/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Fake Gemini installer delivers Vidar infostealer via Google Colab lure]]></title>
<description><![CDATA[A malicious executable masquerading as a Google Gemini installer was used to deliver the Vidar infostealer on a company network in the EMEA region, according to Darktrace researchers who investigated the incident. “During the initial analysis, it was noted that the top search result for the suspi...]]></description>
<link>https://tsecurity.de/de/3749457/it-security-nachrichten/fake-gemini-installer-delivers-vidar-infostealer-via-google-colab-lure/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3749457/it-security-nachrichten/fake-gemini-installer-delivers-vidar-infostealer-via-google-colab-lure/</guid>
<pubDate>Sat, 22 Aug 2026 04:21:47 +0200</pubDate>
<content:encoded><![CDATA[<p>A malicious executable masquerading as a Google Gemini installer was used to deliver the Vidar infostealer on a company network in the EMEA region, according to Darktrace researchers who investigated the incident. “During the initial analysis, it was noted that the top search result for the suspicious filename associated pointed to a file hosted... <a href="https://www.helpnetsecurity.com/2026/08/20/fake-google-gemini-installer-vidar-infostealer/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The browser is where attacks land. Why is security still focused on the endpoint?]]></title>
<description><![CDATA[Presented by CloudMosa Enterprise work now happens increasingly inside the browser, and that shift has made the browser a primary point of entry for cyberattacks as well. Browser-based attacks have surged over the past two years, according to industry reports, while Gartner projects that more tha...]]></description>
<link>https://tsecurity.de/de/3708623/it-nachrichten/the-browser-is-where-attacks-land-why-is-security-still-focused-on-the-endpoint/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3708623/it-nachrichten/the-browser-is-where-attacks-land-why-is-security-still-focused-on-the-endpoint/</guid>
<pubDate>Thu, 06 Aug 2026 19:04:02 +0200</pubDate>
<content:encoded><![CDATA[<p><i>Presented by CloudMosa </i></p><hr><p>Enterprise work now happens increasingly inside the browser, and that shift has made the browser a primary point of entry for cyberattacks as well. Browser-based attacks have surged over the past two years, according to industry reports, while Gartner projects that more than <a href="https://www.paloaltonetworks.com/resources/research/gartner-innovation-insight-secure-enterprise-browsers">85% of enterprise workloads</a> will be accessed through the browser by 2027. </p><p>And yet most enterprise security architecture is still built to protect the device rather than the browser session where that work, and those attacks, actually take place, says Shioupyn Shen, founder and CEO of CloudMosa, the company behind Puffin Cloud Security. </p><p>“CloudMosa originally built its cloud architecture to improve browser performance and accessibility, with the expectation that enterprise work would increasingly move into the browser,” Shen says. “Today’s AI-assisted hacking has validated that architecture, demonstrating that what was designed for performance also provides a strong foundation for modern enterprise security.”</p><h2>The browser as the enterprise's operating environment</h2><p>SaaS platforms, CRM and ERP systems, and collaboration tools have made the browser the primary gateway, and often the central workspace, for enterprise operations. As LLM-powered workflows and autonomous AI agents increasingly operate through that same environment, this shift has also redefined what a threat looks like.</p><p>In a device-centric world, security teams could focus much of their attention on endpoints and networks they could monitor, manage and patch on schedule. But because web code now executes locally on the user’s device, every open browser tab can become a potential entry point for malicious scripts, credential theft, supply chain compromise and other browser-based exploits.</p><p>The browser now interprets and executes remote code, manages authenticated sessions across enterprise applications, and increasingly serves as the execution layer for AI workflows and agents.</p><p>"The browser is no longer just another application running on the endpoint," Shen says. "In practice, it has become the central operating environment for modern enterprise work. Traditional browsers were never designed to carry this level of enterprise responsibility. They were built as local interpreters of remote code, not as enterprise-grade execution environments with strong isolation and policy enforcement."</p><h2>Why detection-first security fails against browser-based attacks</h2><p>Detection-first security has a timing problem: it typically begins only after risky code has reached the device and started executing inside the browser. Because modern browsers execute dynamic, often obfuscated JavaScript and WebAssembly locally, attacks can act on the device before endpoint tools have time to respond. Short-lived or fileless attacks may steal credentials, exfiltrate data or complete their objective before a security team can intervene.</p><p>"It is no longer sufficient to ask only whether a threat can be detected," Shen says. "The stronger approach is to prevent risky or malicious code from ever reaching the device in the first place." </p><h2>AI-generated malware strains signature-based detection</h2><p>AI is a force multiplier that lets attackers automate the creation, mutation and deployment of malware at a scale signature-based tools were never designed to handle. It can generate large volumes of malware variants and help attackers adapt fileless and browser-delivered techniques faster than defenders can analyze them and update signatures.</p><p>That matters because polymorphic malware can alter its code or behavior from one instance to the next, making a known signature less reliable. And when attacks are malware-free — relying instead on legitimate tools, compromised sessions or malicious web content — there may be no conventional file signature to detect at all.</p><p>Enterprises have seen <a href="https://www.crowdstrike.com/en-us/press-releases/2026-crowdstrike-global-threat-report/">an 89% increase in attacks by AI-enabled adversaries</a> over the past year, as increasingly automated and adaptive attacks compress the window available for detection and response.</p><p>"Defenders are no longer just chasing more threats, they are chasing a machine that can keep creating new ones," Shen says. "What was good enough in the past 10 years will not be sufficient in the next six months," he adds.</p><h2>Building architecture that removes the attack surface</h2><p>Rather than continuing to refine detection, the more durable response is to change where web code is allowed to execute in the first place.</p><p>"In a conventional browser, the risk comes to the device," Shen says. "In an isolated cloud model, the risk is kept away from it." </p><p>That principle underlies Puffin Cloud Security. Rather than incrementally improving the browser itself, the platform shifts browser execution into isolated cloud environments. That architectural change improves both performance and security.</p><p>The platform runs the original web session, including its JavaScript, WebAssembly, and other executable payloads, inside a disposable cloud environment and streams only a rendered pixel view to the device. Users keep full interactive control over clicking, typing, and scrolling, but the device itself never parses, executes, or stores the original active code. </p><p>CloudMosa says display rasterization — the layer responsible for the pixel stream — accounts for <a href="https://www.cloudmosa.com/overview">roughly 5% of the browser’s total workload</a>, while the more compute-intensive HTML rendering remains isolated in the cloud. As a result, zero-day exploits and AI-generated polymorphic malware have no executable code to run on the endpoint, while fileless attacks or supply chain compromises within SaaS tools remain contained in the cloud.</p><p>"In CloudMosa's view, that means moving from good-enough security on the device to airtight security in the cloud," Shen says.</p><h2>Fitting browser isolation into SWG, CASB and ZTNA stacks</h2><p>Puffin is designed to extend existing security infrastructure rather than replace it. Secure web gateways, cloud access security broker platforms, and zero trust network access tools remain effective at routing traffic, enforcing policy, and controlling access. But none can fully stop local execution once risky content reaches the browser. </p><p>Puffin closes that gap by routing high-risk sessions through isolated cloud environments and enforcing browser-level policy, whether a user connects over a VPN, a home network, a managed device or an unmanaged, bring-your-own-device setup. </p><p>"Organizations can start with narrow use cases, such as high-risk SaaS access or AI agent workflows, and expand without disrupting tools already in place," Shen says. "The goal is not to undo existing investments, but to make them more complete." </p><h2>The choice between faster detection or endpoint isolation</h2><p>Detection will always have a role in enterprise security, but the more consequential question is no longer how quickly a threat can be caught, but whether attackers can reach the endpoint at all. Recent 2026 surveys found <a href="https://www.darktrace.com/resource/the-state-of-ai-cybersecurity-2026">92% of security professionals</a> are concerned about the impact of AI agents, with <a href="https://www.darkreading.com/threat-intelligence/2026-agentic-ai-attack-surface-poster-child">48% naming agentic AI the top attack vector of the year</a>. Shen noted that agents acting autonomously with user-level privileges are especially exposed to prompt injection, session hijacking, and indirect compromise through compromised web content.</p><p>In designing Puffin Cloud Security, CloudMosa has been “paranoid by design,” meaning it invested in an architecture built for worst-case scenarios and for a threat environment where endpoint security and detection alone may not be enough. </p><p>"This is not just a philosophy, but something that is reflected directly in the architecture itself," Shen says. "CloudMosa built earlier for a harsher threat model than most other organizations did, but today's AI-assisted attacks are now making that posture feel increasingly relevant."</p><p>By dividing a full browser into a very small layer on the device and a much larger layer in the cloud, CloudMosa designed this approach to improve both performance and security at the same time: In Puffin Cloud Security’s architecture, an AI agent’s browser activity takes place inside isolated cloud sandboxes. The endpoint receives only a pixel stream, not the original active code, preventing malicious web content from interacting directly with the device, its credentials or connected systems.</p><p>"AI-assisted hacking represents the kind of structural shift that rewards companies willing to rethink browser from the ground up," Shen says. "And so security leaders now have a choice: redesign for foresight, or wait until hindsight makes the lesson unavoidable."</p><hr><p><i>Sponsored articles are content produced by a company that is either paying for the post or has a business relationship with VentureBeat, and they’re always clearly marked. For more information, contact </i><a href="mailto:sales@venturebeat.com"><i><u>sales@venturebeat.com</u></i></a><i>.</i></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Darktrace Integrates with Microsoft Agent 365]]></title>
<description><![CDATA[Darktrace has announced an integration between its SECURE AI platform and Microsoft Agent 365, bringing behavioral risk detection capabilities to…
Read more →
The post Darktrace Integrates with Microsoft Agent 365 appeared first on IT Security News.]]></description>
<link>https://tsecurity.de/de/3706029/it-security-nachrichten/darktrace-integrates-with-microsoft-agent-365/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706029/it-security-nachrichten/darktrace-integrates-with-microsoft-agent-365/</guid>
<pubDate>Wed, 05 Aug 2026 16:05:34 +0200</pubDate>
<content:encoded><![CDATA[<p>Darktrace has announced an integration between its SECURE AI platform and Microsoft Agent 365, bringing behavioral risk detection capabilities to…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/darktrace-integrates-with-microsoft-agent-365/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/darktrace-integrates-with-microsoft-agent-365/">Darktrace Integrates with Microsoft Agent 365</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[KI übernimmt das Stadion – ein Sicherheitsproblem?]]></title>
<description><![CDATA[Moderne Stadien zählen laut Karim Benslimane, VP Field CISO bei Darktrace, zu den komplexesten Infrastrukturen überhaupt: Am Veranstaltungstag verschmelzen Shops, Verpflegungsstände, Verkehrsknotenpunkte, umfangreiche ...]]></description>
<link>https://tsecurity.de/de/3683592/it-nachrichten/ki-uebernimmt-das-stadion-ein-sicherheitsproblem/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3683592/it-nachrichten/ki-uebernimmt-das-stadion-ein-sicherheitsproblem/</guid>
<pubDate>Tue, 21 Jul 2026 13:48:26 +0200</pubDate>
<content:encoded><![CDATA[Moderne Stadien zählen laut Karim Benslimane, VP Field CISO bei Darktrace, zu den komplexesten Infrastrukturen überhaupt: Am Veranstaltungstag verschmelzen Shops, Verpflegungsstände, Verkehrsknotenpunkte, umfangreiche ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Hackers are Turning AI Gateways as Attack Surfaces to Compromise Enterprise Networks]]></title>
<description><![CDATA[AI gateways are increasingly being targeted as organizations connect generative AI applications to cloud services such as Amazon Bedrock. These gateways sit between users, business applications, and large language models, making them an attractive entry point into enterprise networks. Darktrace…
...]]></description>
<link>https://tsecurity.de/de/3659783/it-security-nachrichten/hackers-are-turning-ai-gateways-as-attack-surfaces-to-compromise-enterprise-networks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3659783/it-security-nachrichten/hackers-are-turning-ai-gateways-as-attack-surfaces-to-compromise-enterprise-networks/</guid>
<pubDate>Fri, 10 Jul 2026 15:08:50 +0200</pubDate>
<content:encoded><![CDATA[<p>AI gateways are increasingly being targeted as organizations connect generative AI applications to cloud services such as Amazon Bedrock. These gateways sit between users, business applications, and large language models, making them an attractive entry point into enterprise networks. Darktrace…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/hackers-are-turning-ai-gateways-as-attack-surfaces-to-compromise-enterprise-networks/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/hackers-are-turning-ai-gateways-as-attack-surfaces-to-compromise-enterprise-networks/">Hackers are Turning AI Gateways as Attack Surfaces to Compromise Enterprise Networks</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hackers are Turning AI Gateways as Attack Surfaces to Compromise Enterprise Networks]]></title>
<description><![CDATA[AI gateways are increasingly being targeted as organizations connect generative AI applications to cloud services such as Amazon Bedrock. These gateways sit between users, business applications, and large language models, making them an attractive entry point into enterprise networks. Darktrace r...]]></description>
<link>https://tsecurity.de/de/3659620/it-security-nachrichten/hackers-are-turning-ai-gateways-as-attack-surfaces-to-compromise-enterprise-networks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3659620/it-security-nachrichten/hackers-are-turning-ai-gateways-as-attack-surfaces-to-compromise-enterprise-networks/</guid>
<pubDate>Fri, 10 Jul 2026 14:05:56 +0200</pubDate>
<content:encoded><![CDATA[<p>AI gateways are increasingly being targeted as organizations connect generative AI applications to cloud services such as Amazon Bedrock. These gateways sit between users, business applications, and large language models, making them an attractive entry point into enterprise networks. Darktrace recently investigated a compromised Amazon Web Services EC2 instance named “LiteLLM-Proxy.” The instance appeared to […]</p>
<p>The post <a href="https://cybersecuritynews.com/hackers-turning-ai-gateways-as-attack/">Hackers are Turning AI Gateways as Attack Surfaces to Compromise Enterprise Networks</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI Gateway Compromise Turns Amazon Bedrock Infrastructure Into Cryptomining Resource]]></title>
<description><![CDATA[A compromised AI gateway connected to Amazon Bedrock was found communicating with cryptomining infrastructure, exposing how generative AI infrastructure is emerging as a new frontier in the enterprise attack surface. The incident, investigated by Darktrace and escalated via its Managed Threat Det...]]></description>
<link>https://tsecurity.de/de/3659075/it-security-nachrichten/ai-gateway-compromise-turns-amazon-bedrock-infrastructure-into-cryptomining-resource/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3659075/it-security-nachrichten/ai-gateway-compromise-turns-amazon-bedrock-infrastructure-into-cryptomining-resource/</guid>
<pubDate>Fri, 10 Jul 2026 10:22:47 +0200</pubDate>
<content:encoded><![CDATA[<p>A compromised AI gateway connected to Amazon Bedrock was found communicating with cryptomining infrastructure, exposing how generative AI infrastructure is emerging as a new frontier in the enterprise attack surface. The incident, investigated by Darktrace and escalated via its Managed Threat Detection service, shows attackers repurposing AI-enabled cloud assets for unauthorized cryptomining. AI gateways sit […]</p>
<p>The post <a href="https://cyberpress.org/ai-gateway-amazon-bedrock-cryptomining/">AI Gateway Compromise Turns Amazon Bedrock Infrastructure Into Cryptomining Resource</a> appeared first on <a href="https://cyberpress.org/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI Gateway Connected to Amazon Bedrock Hijacked for Cryptomining]]></title>
<description><![CDATA[Darktrace says a LiteLLM AI gateway linked to Amazon Bedrock was compromised for cryptomining after signs of exposed SSH activity. This article has been indexed from Hackread – Cybersecurity News, Data Breaches, AI and More Read the original article: AI…
Read more →
The post AI Gateway Connected ...]]></description>
<link>https://tsecurity.de/de/3657874/it-security-nachrichten/ai-gateway-connected-to-amazon-bedrock-hijacked-for-cryptomining/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3657874/it-security-nachrichten/ai-gateway-connected-to-amazon-bedrock-hijacked-for-cryptomining/</guid>
<pubDate>Thu, 09 Jul 2026 19:37:21 +0200</pubDate>
<content:encoded><![CDATA[<p>Darktrace says a LiteLLM AI gateway linked to Amazon Bedrock was compromised for cryptomining after signs of exposed SSH activity. This article has been indexed from Hackread – Cybersecurity News, Data Breaches, AI and More Read the original article: AI…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/ai-gateway-connected-to-amazon-bedrock-hijacked-for-cryptomining/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/ai-gateway-connected-to-amazon-bedrock-hijacked-for-cryptomining/">AI Gateway Connected to Amazon Bedrock Hijacked for Cryptomining</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI Gateway Connected to Amazon Bedrock Hijacked for Cryptomining]]></title>
<description><![CDATA[Darktrace says a LiteLLM AI gateway linked to Amazon Bedrock was compromised for cryptomining after signs of exposed SSH activity.]]></description>
<link>https://tsecurity.de/de/3657842/it-security-nachrichten/ai-gateway-connected-to-amazon-bedrock-hijacked-for-cryptomining/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3657842/it-security-nachrichten/ai-gateway-connected-to-amazon-bedrock-hijacked-for-cryptomining/</guid>
<pubDate>Thu, 09 Jul 2026 19:23:13 +0200</pubDate>
<content:encoded><![CDATA[Darktrace says a LiteLLM AI gateway linked to Amazon Bedrock was compromised for cryptomining after signs of exposed SSH activity.]]></content:encoded>
</item>
<item>
<title><![CDATA[Attack on Amazon Bedrock-linked AI gateway highlights new cloud security risk]]></title>
<description><![CDATA[A cloud intrusion that ended with the deployment of cryptomining malware has exposed a bigger risk for enterprises: AI gateways that concentrate access to cloud identities, permissions, and foundation models in a single, highly privileged system.



Researchers from cybersecurity firm Darktrace f...]]></description>
<link>https://tsecurity.de/de/3657126/it-security-nachrichten/attack-on-amazon-bedrock-linked-ai-gateway-highlights-new-cloud-security-risk/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3657126/it-security-nachrichten/attack-on-amazon-bedrock-linked-ai-gateway-highlights-new-cloud-security-risk/</guid>
<pubDate>Thu, 09 Jul 2026 15:08:30 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>A cloud intrusion that ended with the deployment of cryptomining malware has exposed a bigger risk for enterprises: AI gateways that concentrate access to cloud identities, permissions, and foundation models in a single, highly privileged system.</p>



<p>Researchers from cybersecurity firm Darktrace found attackers compromising an AWS EC2 instance acting as a LiteLLM proxy for <a href="https://www.infoworld.com/article/2335005/amazon-bedrock-generative-ai-service-reaches-ga.html">Amazon Bedrock</a>, eventually deploying XMRig cryptomining malware, along with attempts to abuse cloud identities and AI services.</p>



<p>Although the attack ended in cryptomining, researchers said the bigger concern is that AI gateways centralize model access, identities, and cloud privileges, making them valuable targets.</p>



<p>Experts found the attack familiar and consistent with past cloud attack techniques.</p>



<p>“Strip off the AI branding and this is a cloud intrusion pattern we’ve been watching since at least 2018: SSH open to the internet, brute-force attempts, a commodity <a href="https://www.csoonline.com/article/2099039/kinsing-crypto-mining-campaign-targets-75-cloud-native-applications.html">XMRig</a> miner, and repeated connections to a mining pool,” said <a href="https://www.linkedin.com/in/seantmalone/" target="_blank" rel="noreferrer noopener">Sean Malone</a>, CISO at BeyondTrust. “Even the AI-specific angle, stolen credentials probing Bedrock model access, has had a name since 2024: <a href="https://www.csoonline.com/article/3535433/llmjacking-how-attackers-use-stolen-aws-credentials-to-enable-llms-and-rack-up-costs-for-victims.html">LLMjacking</a>.”<br><br>However, Malone agreed with Darktrace researchers on the potential blast radius. “AI gateways concentrate credentials, cloud permissions, and model access into a single choke point, so a routine intrusion lands on a privileged asset,” he explained.</p>



<h2 class="wp-block-heading"><a></a>The attack followed a known pattern</h2>



<p>According to Darktrace, the compromised EC2 instance appeared to support <a href="https://www.csoonline.com/article/4149905/pypi-warns-developers-after-litellm-malware-found-stealing-cloud-and-ci-cd-credentials.html">LiteLLM</a> activity and was associated with an IAM role capable of accessing Amazon Bedrock resources. While researchers could not conclusively determine the initial access vector, they said the attack followed a sequence commonly seen in cloud intrusions.</p>



<p>Before the miner was deployed, the instance had SSH exposed to the internet, with port 22 accessible from anywhere. Darktrace observed a high volume of inbound SSH connection attempts, largely originating from a single external IP address, indicating probable brute-force activity.</p>



<p>Shortly afterward, the host downloaded a ZIP archive containing XMRig cryptomining malware before repeatedly connecting to a known mining pool over HTTPS.</p>



<p>Darktrace stressed that it could not confirm whether the SSH activity directly led to the compromise because host-level logs were unavailable. However, the timing of the SSH exposure, miner download, and subsequent mining-pool communications strongly suggested the EC2 instance had been compromised and repurposed for unauthorized compute activity.</p>



<h2 class="wp-block-heading"><a></a>Compromised AI gateways are a big deal</h2>



<p>The disclosure also detailed suspicious IAM activity observed separately, a day later, by another AWS identity. Among the unusual actions were a “GetSendQuota” API call from an IP address in Vietnam, attempts to enumerate and invoke Amazon Bedrock foundation models, and an effort to create a new IAM user using a randomly generated username.</p>



<p>This behavior is commonly associated with establishing persistence following credential compromise. However, Darktrace could not link the IAM activity directly to the LiteLLM incident.</p>



<p><a href="https://www.linkedin.com/in/jason-soroko-19b41920/" target="_blank" rel="noreferrer noopener">Jason Soroko</a>, senior fellow at Sectigo, said the incident’s significance lies less in the cryptominer than in the system that was compromised.</p>



<p>“These gateways are becoming brokers for identity, model access, prompts, logs, and policy,” he noted. “When one is exposed over SSH or backed by broad IAM permissions, it is no longer just another EC2 instance. It is a control point for AI operations.”</p>



<p>To protect against such attacks, Soroko added, security teams should close public admin paths, remove long-term keys where possible, scope IAM permissions, monitor Bedrock and model access patterns, and correlate workload telemetry with control-plane events. </p>



<p>Darktrace said it helped in the timely containment of the attack. “The cryptomining activity was received by Darktrace’s Managed Threat Detection service and reviewed by Darktrace’s SOC,” the researchers said in a blog post shared with CSO ahead of its <a href="https://www.darktrace.com/blog/when-ai-infrastructure-becomes-part-of-the-attack-surface" target="_blank" rel="noreferrer noopener">publication</a> on Thursday. “Following review, the activity was escalated to the customer. This escalation provided the customer with timely notification of active resource abuse in the AWS environment.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Darktrace tritt dem OpenAI Daybreak Cyber Partner Program bei]]></title>
<description><![CDATA[Darktrace erweitert seine Aktivitäten im Bereich Künstliche Intelligenz und wird Teil des OpenAI Daybreak Cyber Partner Program. 

Tags: #OpenAI | #partnerschaft]]></description>
<link>https://tsecurity.de/de/3621923/it-security-nachrichten/darktrace-tritt-dem-openai-daybreak-cyber-partner-program-bei/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3621923/it-security-nachrichten/darktrace-tritt-dem-openai-daybreak-cyber-partner-program-bei/</guid>
<pubDate>Wed, 24 Jun 2026 17:39:12 +0200</pubDate>
<content:encoded><![CDATA[<p><img width="1920" height="1080" src="https://www.it-daily.net/wp-content/uploads/2026/06/OpenAi-Darktrace-1920.jpg" class="attachment-full size-full wp-post-image" alt="OpenAi-Darktrace" decoding="async" srcset="https://www.it-daily.net/wp-content/uploads/2026/06/OpenAi-Darktrace-1920.jpg 1920w, https://www.it-daily.net/wp-content/uploads/2026/06/OpenAi-Darktrace-1920-300x169.jpg 300w, https://www.it-daily.net/wp-content/uploads/2026/06/OpenAi-Darktrace-1920-1024x576.jpg 1024w, https://www.it-daily.net/wp-content/uploads/2026/06/OpenAi-Darktrace-1920-768x432.jpg 768w, https://www.it-daily.net/wp-content/uploads/2026/06/OpenAi-Darktrace-1920-1536x864.jpg 1536w" sizes="(max-width: 1920px) 100vw, 1920px" title="Darktrace tritt dem OpenAI Daybreak Cyber Partner Program bei 1"></p>
    Darktrace erweitert seine Aktivitäten im Bereich Künstliche Intelligenz und wird Teil des OpenAI Daybreak Cyber Partner Program. 

<p>Tags: <a href="https://www.it-daily.net/thema/openai">#OpenAI</a> | <a href="https://www.it-daily.net/thema/partnerschaft">#partnerschaft</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[5 AI risk management frameworks for shoring up key gaps]]></title>
<description><![CDATA[Organizations racing to embed AI into business operations are realizing that the risk management frameworks they’ve relied on for decades aren’t built for the behaviors, failure modes, and ethical complexities AI systems introduce.



Fortunately, a new generation of AI-specific frameworks has em...]]></description>
<link>https://tsecurity.de/de/3604146/it-security-nachrichten/5-ai-risk-management-frameworks-for-shoring-up-key-gaps/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3604146/it-security-nachrichten/5-ai-risk-management-frameworks-for-shoring-up-key-gaps/</guid>
<pubDate>Wed, 17 Jun 2026 11:09:04 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Organizations racing to embed AI into business operations are realizing that the risk management frameworks they’ve relied on for decades aren’t built for the behaviors, failure modes, and ethical complexities AI systems introduce.</p>



<p>Fortunately, a new generation of AI-specific frameworks has emerged to give organizations a structured way to identify where AI can go wrong, what controls to put in place, and how to demonstrate responsible AI use to regulators, customers, and investors. Not all of these emerging frameworks address the same problem. Some focus on governance and organizational accountability, others on technical security controls, threat modeling, or regulatory compliance. Choosing the right one for your organization depends on where your most pressing gaps reside.</p>



<p>The frameworks are complementary, not competing, because they have different intents, priorities, and objectives, says Nicole Carignan, CISO at Darktrace.</p>



<p>“There is overlap across these frameworks, but that overlap is helpful,” Carignan points out. “It reinforces the core practices organizations need to get right: governance, data integrity, security, accountability, oversight, testing, and continuous improvement.”</p>



<p>Here are five frameworks worth considering for your AI risk management needs.</p>



<h2 class="wp-block-heading">ISO/IEC 42001 Artificial Intelligence Management System</h2>



<p><a href="https://www.iso.org/standard/81230.html">ISO/IEC 42001:2023</a> is the first internationally recognized formal standard for AI management. Published by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC) in December 2023, ISO/IEC 42001 follows a similar structure to management system standards such as ISO 27001. The framework gives organizations a structured methodology for establishing policies, processes, operational controls, and accountability mechanisms to ensure responsible development and use of AI.</p>



<p>ISO/IEC 42001 requires companies to document how they design, monitor, validate, and control AI systems, while also requiring them to conduct AI impact assessments to evaluate potential legal, ethical, and societal impacts. The standard covers governance structures, third-party supplier oversight, data management, transparency obligations, and lifecycle management.</p>



<p>ISO/IEC 42001 is a voluntary but certifiable standard that applies across sectors and organization sizes. A growing number of organizations have begun using it to demonstrate adherence to responsible AI practice and alignment with regulations such as the <a href="https://artificialintelligenceact.eu/">EU AI Act</a>. The ISO/IEC have <a href="https://www.iso.org/home/insights-news/resources/iso-42001-explained-what-it-is.html?utm_source=chatgpt.com">described the framework</a> as helping organizations align their AI practices with legal and regulatory requirements; demonstrate responsible AI governance; manage risks tied to bias, safety, and security; and enhance stakeholder trust.</p>



<p>ISO 42001 is a great option for organizations just getting started with AI risk management, says Nicole Carignan, senior vice president for security and AI strategy and field CISO at Darktrace.</p>



<p>“It provides the strongest foundation for building an AI risk management program, rather than addressing individual AI risks in isolation,” she explains. “From a program-building standpoint, ISO 42001 is the right place to start because it forces organizations to think holistically about ownership, governance, oversight, data integrity, security risk mitigation, accountability, and continuous improvement.”</p>



<p>One downside Carignan is that the framework is resource-intensive to implement, and the full standard is not publicly available. Both challenges can be formidable for organizations that are very early in their AI governance journey, she says.</p>



<h2 class="wp-block-heading">NIST AI Risk Management Framework (AI RMF)</h2>



<p>Released by the US National Institute of Standards and Technology (NIST) in January 2023, the <a href="https://airc.nist.gov/AI_RMF_Knowledge_Base/AI_RMF">AI Risk Management Framework (AI RMF)</a> is a voluntary framework designed to help organizations of all sizes and across all sectors identify, assess, and manage risks associated with AI systems across their entire lifecycle.</p>



<p>The framework consists of two parts. The first offers guidance on how organizations should think about AI risks and the characteristics of trustworthy AI systems, such as validity, safety, security, transparency, explainability, privacy, and fairness. The second part is structured around four interconnected functions:</p>



<ul class="wp-block-list">
<li><strong>Govern</strong> focuses on what organizations need to do to build internal culture, policies, and accountability structures for AI use.</li>



<li><strong>Map</strong> involves understanding the broader context and potential risks of specific AI systems.</li>



<li><strong>Measure</strong> focuses on how organizations must evaluate and track those risks using both qualitative and quantitative methods.</li>



<li><strong>Manage</strong> provides guidance on risk prioritization and appropriate responses such as mitigation, transfer, or acceptance.</li>
</ul>



<p>NIST AI RMF includes a separate Playbook that provides practical implementation steps to help organizations implement each of these functions effectively.</p>



<p>For organizations that are not ready to pursue ISO 42001 formally, the NIST AI RMF can serve as a more flexible and accessible starting point, Carignan says.</p>



<p>“It is public and gives organizations a common language for understanding and mitigating AI risk,” she adds. “But if the goal is to build a durable AI risk program, ISO 42001 is the strongest foundation.”</p>



<p>Ram Varadarajan, CEO at Acalvio recommends NIST AI RMF as a good place for organization to get started on AI risk governance, “because it’s built around maturity rather than pass/fail audits.” Its gives organizations starting from zero an opportunity to discover where they stand rather than immediately handing out a failing grade.</p>



<p>“More importantly, it forces the three conversations that have to happen first: who owns AI risk, what AI is actually running, and who gets hurt if something goes wrong,” Vardarajan says.</p>



<p>While researchers at Forrester described NIST AI RMF as a <a href="https://www.forrester.com/blogs/nist-ai-risk-management-framework-1-0-what-it-means-for-enterprises/">step in the right direction</a> soon after its launch, they also expressed concern over conflicts of interest among the multiple stakeholders that helped draft the framework, the absence of an explicit role for data governance, and the fact that the framework was “still descriptive and not prescriptive.”</p>



<p>As a result, “Chief data officers and heads of data science need to navigate this framework wisely to interpret and apply it to their AI governance efforts,” the analyst firm advised.</p>



<h2 class="wp-block-heading">ENISA Framework for AI Cybersecurity Practices</h2>



<p>ENISA, the European Union Agency for Cybersecurity, developed its <a href="https://www.faicp-framework.com/">Framework for AI Cybersecurity Practices (FAICP)</a> in anticipation of the <a href="https://artificialintelligenceact.eu/">EU AI Act</a>. Published in June 2023, the framework gives EU organizations structured, AI-specific cybersecurity guidance for enhancing the trustworthiness of their AI activities.</p>



<p>FAICP is organized around three progressive layers. The first covers foundational information and communications technology cybersecurity practices that AI systems inherit by running on standard software infrastructure. The second addresses <a href="https://www.csoonline.com/article/4110008/top-cyber-threats-to-your-ai-systems-and-infrastructure.html">AI-specific risks</a>, including adversarial attacks, model tampering, data pipeline integrity, and <a href="https://www.csoonline.com/article/4015077/ai-supply-chain-threats-are-looming-as-security-practices-lag.html">supply chain security</a>. The third provides sector-specific guidance for regulated industries such as energy, healthcare, and telecommunications.</p>



<p>According to the European Parliament, FAICP’s layered nature provides organizations with “a gradual approach” to enhancing the trustworthiness of their AI activities.</p>



<p>FAICP is voluntary, but its close alignment with the EU AI Act and the <a href="https://www.enisa.europa.eu/topics/awareness-and-cyber-hygiene/raising-awareness-campaigns/network-and-information-systems-directive-2-nis2">NIS2 Directive</a>, which is the EU’s primary cybersecurity law, means that EU regulators consider the framework as a baseline for AI governance practices at all organizations doing business within the EU.</p>



<p>FAICP is important because “Europe’s AI Act will likely become the global reference point, the same way Europe’s data privacy law became the de facto standard for companies worldwide regardless of where they’re headquartered,” Vardarajan predicts.</p>



<p>“Within two to three years, expect two frameworks to dominate: the EU AI Act setting the legal floor, and NIST AI RMF providing the operational playbook for meeting it,” Vardarajan says.</p>



<h2 class="wp-block-heading">ISO/IEC 23894:2023 Information Technology — Artificial Intelligence — Guidance on Risk Management</h2>



<p>The <a href="https://www.iso.org/standard/77304.html">ISO/IEC 23894:2923</a> framework provides organizations with specific guidance on managing risks associated with artificial intelligence. Released jointly by ISO and IEC in February 2023, the framework builds on and adapts the ISO 31000 general risk management standard to address AI-specific risks such as those tied to<strong> </strong>algorithmic bias, model drift, unpredictable behavior, and lack of transparency in decision-making. It provides organizations a way to evaluate the likelihood and potential consequences of these risks throughout the full AI system lifecycle.</p>



<p>The ISO has <a href="https://iso-library.com/standard/23894/">described the standard</a> as a “companion to ISO 31000 (Risk Management) and ISO/IEC 42001 (AI Management Systems).” The main difference between ISO/IEC 42001 and ISO/IEC 23894 is that the former is a certifiable management system. It provides organizations with the full requirements for establishing, implementing, and maintaining an AI management system. ISO/IEC 23894:2023 on the other hand is a guidance-only standard focused on how to identify, assess, and manage AI-specific risks.</p>



<p>“Notably, ISO/IEC 23894 offers concrete examples of effective risk management implementation and integration throughout the AI development lifecycle and provides detailed information on AI-specific risk sources,” according to UK-backed <a href="https://aistandardshub.org/a-new-standard-for-ai-risk-management">AI Standards Hub</a>. “A key benefit of this standard is that application of the guidance can be customized to any organization and its business context.”</p>



<h2 class="wp-block-heading">Google Secure AI Framework (SAIF)</h2>



<p><strong><a href="https://saif.google/">Google Secure AI Framework (SAIF)</a></strong> is Google’s practical guide for helping organizations develop and run AI systems with strong built-in protections against digital threats. Launched in 2023, it focuses on weaving security and privacy considerations directly into every stage of an AI project’s life cycle, from design through deployment and ongoing operation.</p>



<p>Its main goal is to tackle the unique vulnerabilities that come with AI technologies such as attacks that tamper with training data, trick models through engineered prompts, or steal sensitive information. SAIF draws on Google’s own experiences developing and deploying large scale AI systems and therefore is more engineering-heavy than other frameworks. SAIF is largely focused on helping organizations make their AI systems more resistant to cyberattacks and cyber adversaries and covers areas like data handling, underlying infrastructure, the AI models themselves, user-facing applications and verification processes. It offers organizations practical guidance on implementation controls, shared responsibility, and defending against technical attacks.</p>



<p>Technology consultancy Thoughtworks has assessed SAIF as a framework that helps organizations systematically address “common threats such as data poisoning and prompt injection through a clear risk map, component analysis, and practical mitigation strategies.” According to the firm, SAIF’s “focus on the evolving risks of building agentic systems especially timely and valuable. SAIF offers a concise, actionable playbook that teams can use to strengthen security practices for LLM usage and AI-driven applications.”</p>



<p>David Brumley, chief AI and science officer at Bugcrowd, says that for organizations that want to adopt a framework, the question is not really “which AI risk framework is best?” but “which framework helps [the] organization safely build, deploy, and learn from AI in the real world?”</p>



<p>While most of the currently available AI risk frameworks have their use, most are still focused on preventing bad outcomes rather than helping organizations pave safe roads for a technology that is already inevitable.</p>



<p>“That distinction matters,” Brumley says. “AI adoption is not waiting for perfect governance, and those who focus on a [risk management framework] could inadvertently create a shadow AI problem in their organization.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft says you don’t need another email security tool; experts say, not so fast]]></title>
<description><![CDATA[Despite best efforts by defenders, malicious emails continue to slip through the cybersecurity cracks, leading some enterprises to implement a layered “defense in depth” strategy that incorporates multiple tools.



Microsoft seems to be challenging this idea, revealing that there are only nomina...]]></description>
<link>https://tsecurity.de/de/3603512/it-security-nachrichten/microsoft-says-you-dont-need-another-email-security-tool-experts-say-not-so-fast/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3603512/it-security-nachrichten/microsoft-says-you-dont-need-another-email-security-tool-experts-say-not-so-fast/</guid>
<pubDate>Wed, 17 Jun 2026 05:23:30 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Despite best efforts by defenders, malicious emails continue to <a href="https://www.csoonline.com/article/4183653/aged-domain-acquisition-the-tradecraft-phishing-operators-are-using-to-bypass-your-mail-filters-reputation-score.html" target="_blank">slip through the cybersecurity cracks</a>, leading some enterprises to implement a layered “defense in depth” strategy that incorporates multiple tools.</p>



<p>Microsoft seems to be challenging this idea, revealing that there are only nominal returns from adding integrated pre- and post-send partners to Defender for Office 365’s protections.</p>



<p>According to its new quarterly benchmarking data, the tech giant catches the vast majority of malicious and spam emails before delivery, misses the fewest compared to competitors by a wide margin, and removes nearly 100% of dangerous emails that do reach the inbox. Collectively, its integrated partners improve that catch rate by less than .05%.</p>



<p>While these numbers seem to tip the scales towards a one-vendor email security stack, experts urge enterprises to be skeptical and cautious of such vendor claims.</p>



<p><a href="https://www.infotech.com/profiles/seva-ioussoufovitch" target="_blank" rel="noreferrer noopener">Seva Ioussoufovitch</a>, senior research analyst at Info-Tech Research Group, pointed out, “percentages obscure the true quantity and severity of what’s getting through, and, considering it only takes one message to result in an incident, it’s simple enough to argue that there is real value in the defense in depth that having multiple tools provides.”</p>



<h2 class="wp-block-heading">Malicious and spam email catch by the numbers</h2>



<p>Microsoft introduced its quarterly benchmarking report in July 2025 alongside a Defender integrated cloud email security (ICES) ecosystem designed to support multi-vendor security strategies.</p>



<p>The SEG players it ranked itself against this year includes Mimecast, Proofpoint, Hornetsecurity, Trend Micro, Iron Port (Cisco), Barracuda, and FireEye (Trellix); ICES companies include Abnormal, Checkpoint Harmony, Cisco, DarkTrace, KnowBe4 Defend, Tessian, and Trend Micro.</p>



<p>Redmond reported that Defender “consistently leads” in pre-delivery detection, missing 59% fewer high-severity cyberthreats prior to delivery than the other SEG vendors it evaluated. Its closest competitors were Mimecast and Proofpoint. The company also introduced a new metric in this area: A threat miss rate per 1,000 employees. In Microsoft’s case, that was 194 per 1,000; for Mimecast, 478; for Proofpoint, 483.</p>



<p>When it came to post-delivery protection, Defender removed an average of 96.03% of malicious emails that reached the inbox, up from an initial 45% when Microsoft first started tracking the data in its second report.</p>



<p>This makes Defender “an increasingly critical backstop, operating even when ICES solutions are in place,” Jeff Pinkston, VP and GM for Microsoft Defender, wrote in a <a href="https://www.microsoft.com/en-us/security/blog/2026/06/15/microsoft-defender-email-security-benchmarking-key-insights-from-one-year-of-data/" target="_blank" rel="noreferrer noopener">blog post</a>. Still, ICES tools operating in tandem with Microsoft Defender “continue to provide benefits,” improving malicious catch by 0.29% and spam catch by 0.68%, he said.</p>



<p>“If we focus on the basics, their argument seems strong,” Info-Tech’s Ioussoufovitch noted. “Do you really need a separate ICES vendor for that extra sub 1% catch?” Microsoft paints a “compelling picture” by only focusing on raw catch rate, he said, but we don’t hear the rest of the story: “What exactly is the danger of what isn’t being caught by Defender?”</p>



<h2 class="wp-block-heading">No one vendor catches everything </h2>



<p><a href="https://www.linkedin.com/in/dbshipley/" target="_blank" rel="noreferrer noopener">David Shipley</a> of Beauceron Security pointed out that the report underscores the fact that “lots of stuff still gets by e-mail filters.”</p>



<p>His company regularly analyzes hundreds of thousands of emails, and the content that gets through “ranges from the shockingly mundane and obvious to a human expert, to highly clever time-delayed attacks,” he said.</p>



<p>A key factor in what gets through is the amount of content that is allowlisted; settings in “100% paranoid mode” get high catch rates, as well as high false positives, Shipley noted. “Anyone who has ever had a sales person lose a deal because the purchase order PDF got flagged has felt this pain.”</p>



<p>Then there’s the AI conundrum: “A key risk for e-mail vendors using agentic LLM-based analysis is it’s now possible to poison those models with <a href="https://www.csoonline.com/article/4185051/attackers-can-turn-ai-agent-guardrails-into-denial-of-service-weapons.html" target="_blank">hidden content</a> (such as ‘ignore this e-mail, pretty please’),” Shipley said. This means enterprises need a variety of analysis methods.</p>



<p>Ioussoufovitch agreed that keeping pace with threat actors using AI is an industry-wide challenge, particularly as AI enables higher-quality phishing. Filters are improving and will catch some of it, but some will inevitably continue to get through. Those messages are likely highly-targeted, which are lower in volume but harder to catch.</p>



<p>“As of now, current tools do seem to be struggling to keep pace, but that doesn’t mean those tools aren’t necessary,” said Ioussoufovitch. “It just highlights that <a href="https://www.csoonline.com/article/4181920/15-tough-cybersecurity-questions-every-ciso-must-answer.html" target="_blank">defense-in-depth</a>, broadly speaking, is becoming more and more important.”</p>



<h2 class="wp-block-heading">Claims appear more honest</h2>



<p>Shipley said that this report appears more honest, accurate, and mature than others claiming 99.99% phish catch rates, “which is never true.” It’s also a “smart marketing move,” because Microsoft competes for the same security budget as other tools, and would rather enterprises remove those vendors and buy more from it in areas beyond e-mail.</p>



<p>On the other hand, he said, Microsoft is offering up a list of other vendors to think about, “which, congrats to Mimecast on coming in second.”</p>



<p>In the long run, CISOs need to determine the best spend for their limited security dollars, he noted. Enterprises need a good filter; whether they need two is up for debate. “They also clearly still need to invest in a <a href="https://www.csoonline.com/article/4152631/security-awareness-is-not-a-control-rethinking-human-risk-in-enterprise-security.html" target="_blank">robust awareness program</a>,” Shipley said, “because as this report shows, lots of phishes are still getting delivered.”</p>



<h2 class="wp-block-heading">Missing an important nuance</h2>



<p>Ioussoufovitch noted that while the claims in the study are interesting, the data is presented without much of the nuance that would make it truly actionable.</p>



<p>“We are all too familiar with vendors’ abilities to massage data to tell the story they want, so I would advise leaders not to extrapolate the data beyond what it actually says,” he said.</p>



<p>Instead of the takeaway being “get rid of our current vendors,” this post highlights that Defender provides “considerable value,” he noted. Whether adding or subtracting additional vendors is worth the money should be a case-by-case conversation that considers an organization’s risk appetite, and overall security budget and environment.</p>



<p>“I’d treat these claims more as a reminder to assess your own environment and compare detections,” he said. “Come to conclusions based on the data you have, not what a vendor is presenting.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft says you don’t need another email security tool; experts say, not so fast]]></title>
<description><![CDATA[Despite best efforts by defenders, malicious emails continue to slip through the cybersecurity cracks, leading some enterprises to implement a layered “defense in depth” strategy that incorporates multiple tools.



Microsoft seems to be challenging this idea, revealing that there are only nomina...]]></description>
<link>https://tsecurity.de/de/3603505/it-nachrichten/microsoft-says-you-dont-need-another-email-security-tool-experts-say-not-so-fast/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3603505/it-nachrichten/microsoft-says-you-dont-need-another-email-security-tool-experts-say-not-so-fast/</guid>
<pubDate>Wed, 17 Jun 2026 05:18:01 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Despite best efforts by defenders, malicious emails continue to <a href="https://www.csoonline.com/article/4183653/aged-domain-acquisition-the-tradecraft-phishing-operators-are-using-to-bypass-your-mail-filters-reputation-score.html" target="_blank">slip through the cybersecurity cracks</a>, leading some enterprises to implement a layered “defense in depth” strategy that incorporates multiple tools.</p>



<p>Microsoft seems to be challenging this idea, revealing that there are only nominal returns from adding integrated pre- and post-send partners to Defender for Office 365’s protections.</p>



<p>According to its new quarterly benchmarking data, the tech giant catches the vast majority of malicious and spam emails before delivery, misses the fewest compared to competitors by a wide margin, and removes nearly 100% of dangerous emails that do reach the inbox. Collectively, its integrated partners improve that catch rate by less than .05%.</p>



<p>While these numbers seem to tip the scales towards a one-vendor email security stack, experts urge enterprises to be skeptical and cautious of such vendor claims.</p>



<p><a href="https://www.infotech.com/profiles/seva-ioussoufovitch" target="_blank" rel="noreferrer noopener">Seva Ioussoufovitch</a>, senior research analyst at Info-Tech Research Group, pointed out, “percentages obscure the true quantity and severity of what’s getting through, and, considering it only takes one message to result in an incident, it’s simple enough to argue that there is real value in the defense in depth that having multiple tools provides.”</p>



<h2 class="wp-block-heading">Malicious and spam email catch by the numbers</h2>



<p>Microsoft introduced its quarterly benchmarking report in July 2025 alongside a Defender integrated cloud email security (ICES) ecosystem designed to support multi-vendor security strategies.</p>



<p>The SEG players it ranked itself against this year includes Mimecast, Proofpoint, Hornetsecurity, Trend Micro, Iron Port (Cisco), Barracuda, and FireEye (Trellix); ICES companies include Abnormal, Checkpoint Harmony, Cisco, DarkTrace, KnowBe4 Defend, Tessian, and Trend Micro.</p>



<p>Redmond reported that Defender “consistently leads” in pre-delivery detection, missing 59% fewer high-severity cyberthreats prior to delivery than the other SEG vendors it evaluated. Its closest competitors were Mimecast and Proofpoint. The company also introduced a new metric in this area: A threat miss rate per 1,000 employees. In Microsoft’s case, that was 194 per 1,000; for Mimecast, 478; for Proofpoint, 483.</p>



<p>When it came to post-delivery protection, Defender removed an average of 96.03% of malicious emails that reached the inbox, up from an initial 45% when Microsoft first started tracking the data in its second report.</p>



<p>This makes Defender “an increasingly critical backstop, operating even when ICES solutions are in place,” Jeff Pinkston, VP and GM for Microsoft Defender, wrote in a <a href="https://www.microsoft.com/en-us/security/blog/2026/06/15/microsoft-defender-email-security-benchmarking-key-insights-from-one-year-of-data/" target="_blank" rel="noreferrer noopener">blog post</a>. Still, ICES tools operating in tandem with Microsoft Defender “continue to provide benefits,” improving malicious catch by 0.29% and spam catch by 0.68%, he said.</p>



<p>“If we focus on the basics, their argument seems strong,” Info-Tech’s Ioussoufovitch noted. “Do you really need a separate ICES vendor for that extra sub 1% catch?” Microsoft paints a “compelling picture” by only focusing on raw catch rate, he said, but we don’t hear the rest of the story: “What exactly is the danger of what isn’t being caught by Defender?”</p>



<h2 class="wp-block-heading">No one vendor catches everything </h2>



<p><a href="https://www.linkedin.com/in/dbshipley/" target="_blank" rel="noreferrer noopener">David Shipley</a> of Beauceron Security pointed out that the report underscores the fact that “lots of stuff still gets by e-mail filters.”</p>



<p>His company regularly analyzes hundreds of thousands of emails, and the content that gets through “ranges from the shockingly mundane and obvious to a human expert, to highly clever time-delayed attacks,” he said.</p>



<p>A key factor in what gets through is the amount of content that is allowlisted; settings in “100% paranoid mode” get high catch rates, as well as high false positives, Shipley noted. “Anyone who has ever had a sales person lose a deal because the purchase order PDF got flagged has felt this pain.”</p>



<p>Then there’s the AI conundrum: “A key risk for e-mail vendors using agentic LLM-based analysis is it’s now possible to poison those models with <a href="https://www.csoonline.com/article/4185051/attackers-can-turn-ai-agent-guardrails-into-denial-of-service-weapons.html" target="_blank">hidden content</a> (such as ‘ignore this e-mail, pretty please’),” Shipley said. This means enterprises need a variety of analysis methods.</p>



<p>Ioussoufovitch agreed that keeping pace with threat actors using AI is an industry-wide challenge, particularly as AI enables higher-quality phishing. Filters are improving and will catch some of it, but some will inevitably continue to get through. Those messages are likely highly-targeted, which are lower in volume but harder to catch.</p>



<p>“As of now, current tools do seem to be struggling to keep pace, but that doesn’t mean those tools aren’t necessary,” said Ioussoufovitch. “It just highlights that <a href="https://www.csoonline.com/article/4181920/15-tough-cybersecurity-questions-every-ciso-must-answer.html" target="_blank">defense-in-depth</a>, broadly speaking, is becoming more and more important.”</p>



<h2 class="wp-block-heading">Claims ‘appear more honest’</h2>



<p>Shipley said that this report appears more honest, accurate, and mature than others claiming 99.99% phish catch rates, “which is never true.” It’s also a “smart marketing move,” because Microsoft competes for the same security budget as other tools, and would rather enterprises remove those vendors and buy more from it in areas beyond e-mail.</p>



<p>On the other hand, he said, Microsoft is offering up a list of other vendors to think about, “which, congrats to Mimecast on coming in second.”</p>



<p>In the long run, CISOs need to determine the best spend for their limited security dollars, he noted. Enterprises need a good filter; whether they need two is up for debate. “They also clearly still need to invest in a <a href="https://www.csoonline.com/article/4152631/security-awareness-is-not-a-control-rethinking-human-risk-in-enterprise-security.html" target="_blank">robust awareness program</a>,” Shipley said, “because as this report shows, lots of phishes are still getting delivered.”</p>



<h2 class="wp-block-heading">Missing an important nuance</h2>



<p>Ioussoufovitch noted that while the claims in the study are interesting, the data is presented without much of the nuance that would make it truly actionable.</p>



<p>“We are all too familiar with vendors’ abilities to massage data to tell the story they want, so I would advise leaders not to extrapolate the data beyond what it actually says,” he said.</p>



<p>Instead of the takeaway being “get rid of our current vendors,” this post highlights that Defender provides “considerable value,” he noted. Whether adding or subtracting additional vendors is worth the money should be a case-by-case conversation that considers an organization’s risk appetite, and overall security budget and environment.</p>



<p>“I’d treat these claims more as a reminder to assess your own environment and compare detections,” he said. “Come to conclusions based on the data you have, not what a vendor is presenting.”</p>



<p><em>This article originally appeared on <a href="https://www.csoonline.com/article/4185954/microsoft-says-you-dont-need-another-email-security-tool-experts-say-not-so-fast.html" target="_blank">CSOonline</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft says you don’t need another email security tool; experts say, not so fast]]></title>
<description><![CDATA[Despite best efforts by defenders, malicious emails continue to slip through the cybersecurity cracks, leading some enterprises to implement a layered “defense in depth” strategy that incorporates multiple tools.



Microsoft seems to be challenging this idea, revealing that there are only nomina...]]></description>
<link>https://tsecurity.de/de/3603504/it-nachrichten/microsoft-says-you-dont-need-another-email-security-tool-experts-say-not-so-fast/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3603504/it-nachrichten/microsoft-says-you-dont-need-another-email-security-tool-experts-say-not-so-fast/</guid>
<pubDate>Wed, 17 Jun 2026 05:18:00 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Despite best efforts by defenders, malicious emails continue to <a href="https://www.csoonline.com/article/4183653/aged-domain-acquisition-the-tradecraft-phishing-operators-are-using-to-bypass-your-mail-filters-reputation-score.html" target="_blank">slip through the cybersecurity cracks</a>, leading some enterprises to implement a layered “defense in depth” strategy that incorporates multiple tools.</p>



<p>Microsoft seems to be challenging this idea, revealing that there are only nominal returns from adding integrated pre- and post-send partners to Defender for Office 365’s protections.</p>



<p>According to its new quarterly benchmarking data, the tech giant catches the vast majority of malicious and spam emails before delivery, misses the fewest compared to competitors by a wide margin, and removes nearly 100% of dangerous emails that do reach the inbox. Collectively, its integrated partners improve that catch rate by less than .05%.</p>



<p>While these numbers seem to tip the scales towards a one-vendor email security stack, experts urge enterprises to be skeptical and cautious of such vendor claims.</p>



<p><a href="https://www.infotech.com/profiles/seva-ioussoufovitch" target="_blank" rel="nofollow">Seva Ioussoufovitch</a>, senior research analyst at Info-Tech Research Group, pointed out, “percentages obscure the true quantity and severity of what’s getting through, and, considering it only takes one message to result in an incident, it’s simple enough to argue that there is real value in the defense in depth that having multiple tools provides.”</p>



<h2 class="wp-block-heading">Malicious and spam email catch by the numbers</h2>



<p>Microsoft introduced its quarterly benchmarking report in July 2025 alongside a Defender integrated cloud email security (ICES) ecosystem designed to support multi-vendor security strategies.</p>



<p>The SEG players it ranked itself against this year includes Mimecast, Proofpoint, Hornetsecurity, Trend Micro, Iron Port (Cisco), Barracuda, and FireEye (Trellix); ICES companies include Abnormal, Checkpoint Harmony, Cisco, DarkTrace, KnowBe4 Defend, Tessian, and Trend Micro.</p>



<p>Redmond reported that Defender “consistently leads” in pre-delivery detection, missing 59% fewer high-severity cyberthreats prior to delivery than the other SEG vendors it evaluated. Its closest competitors were Mimecast and Proofpoint. The company also introduced a new metric in this area: A threat miss rate per 1,000 employees. In Microsoft’s case, that was 194 per 1,000; for Mimecast, 478; for Proofpoint, 483.</p>



<p>When it came to post-delivery protection, Defender removed an average of 96.03% of malicious emails that reached the inbox, up from an initial 45% when Microsoft first started tracking the data in its second report.</p>



<p>This makes Defender “an increasingly critical backstop, operating even when ICES solutions are in place,” Jeff Pinkston, VP and GM for Microsoft Defender, wrote in a <a href="https://www.microsoft.com/en-us/security/blog/2026/06/15/microsoft-defender-email-security-benchmarking-key-insights-from-one-year-of-data/" target="_blank" rel="nofollow">blog post</a>. Still, ICES tools operating in tandem with Microsoft Defender “continue to provide benefits,” improving malicious catch by 0.29% and spam catch by 0.68%, he said.</p>



<p>“If we focus on the basics, their argument seems strong,” Info-Tech’s Ioussoufovitch noted. “Do you really need a separate ICES vendor for that extra sub 1% catch?” Microsoft paints a “compelling picture” by only focusing on raw catch rate, he said, but we don’t hear the rest of the story: “What exactly is the danger of what isn’t being caught by Defender?”</p>



<h2 class="wp-block-heading">No one vendor catches everything </h2>



<p><a href="https://www.linkedin.com/in/dbshipley/" target="_blank" rel="nofollow">David Shipley</a> of Beauceron Security pointed out that the report underscores the fact that “lots of stuff still gets by e-mail filters.”</p>



<p>His company regularly analyzes hundreds of thousands of emails, and the content that gets through “ranges from the shockingly mundane and obvious to a human expert, to highly clever time-delayed attacks,” he said.</p>



<p>A key factor in what gets through is the amount of content that is allowlisted; settings in “100% paranoid mode” get high catch rates, as well as high false positives, Shipley noted. “Anyone who has ever had a sales person lose a deal because the purchase order PDF got flagged has felt this pain.”</p>



<p>Then there’s the AI conundrum: “A key risk for e-mail vendors using agentic LLM-based analysis is it’s now possible to poison those models with <a href="https://www.csoonline.com/article/4185051/attackers-can-turn-ai-agent-guardrails-into-denial-of-service-weapons.html" target="_blank">hidden content</a> (such as ‘ignore this e-mail, pretty please’),” Shipley said. This means enterprises need a variety of analysis methods.</p>



<p>Ioussoufovitch agreed that keeping pace with threat actors using AI is an industry-wide challenge, particularly as AI enables higher-quality phishing. Filters are improving and will catch some of it, but some will inevitably continue to get through. Those messages are likely highly-targeted, which are lower in volume but harder to catch.</p>



<p>“As of now, current tools do seem to be struggling to keep pace, but that doesn’t mean those tools aren’t necessary,” said Ioussoufovitch. “It just highlights that <a href="https://www.csoonline.com/article/4181920/15-tough-cybersecurity-questions-every-ciso-must-answer.html" target="_blank">defense-in-depth</a>, broadly speaking, is becoming more and more important.”</p>



<h2 class="wp-block-heading">Claims ‘appear more honest’</h2>



<p>Shipley said that this report appears more honest, accurate, and mature than others claiming 99.99% phish catch rates, “which is never true.” It’s also a “smart marketing move,” because Microsoft competes for the same security budget as other tools, and would rather enterprises remove those vendors and buy more from it in areas beyond e-mail.</p>



<p>On the other hand, he said, Microsoft is offering up a list of other vendors to think about, “which, congrats to Mimecast on coming in second.”</p>



<p>In the long run, CISOs need to determine the best spend for their limited security dollars, he noted. Enterprises need a good filter; whether they need two is up for debate. “They also clearly still need to invest in a <a href="https://www.csoonline.com/article/4152631/security-awareness-is-not-a-control-rethinking-human-risk-in-enterprise-security.html" target="_blank">robust awareness program</a>,” Shipley said, “because as this report shows, lots of phishes are still getting delivered.”</p>



<h2 class="wp-block-heading">Missing an important nuance</h2>



<p>Ioussoufovitch noted that while the claims in the study are interesting, the data is presented without much of the nuance that would make it truly actionable.</p>



<p>“We are all too familiar with vendors’ abilities to massage data to tell the story they want, so I would advise leaders not to extrapolate the data beyond what it actually says,” he said.</p>



<p>Instead of the takeaway being “get rid of our current vendors,” this post highlights that Defender provides “considerable value,” he noted. Whether adding or subtracting additional vendors is worth the money should be a case-by-case conversation that considers an organization’s risk appetite, and overall security budget and environment.</p>



<p>“I’d treat these claims more as a reminder to assess your own environment and compare detections,” he said. “Come to conclusions based on the data you have, not what a vendor is presenting.”</p>



<p><em>This article originally appeared on <a href="https://www.csoonline.com/article/4185954/microsoft-says-you-dont-need-another-email-security-tool-experts-say-not-so-fast.html" target="_blank">CSOonline</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Kein großer Profisportverein bleibt von Cyberangriffen verschont - it-daily.net]]></title>
<description><![CDATA[Deutschlands Profisportbranche steckt in der Cyberkrise. Das ist das Ergebnis einer neuen Studie des britischen KI-Sicherheitsanbieters Darktrace, die ...]]></description>
<link>https://tsecurity.de/de/3597336/it-security-nachrichten/kein-grosser-profisportverein-bleibt-von-cyberangriffen-verschont-it-dailynet/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3597336/it-security-nachrichten/kein-grosser-profisportverein-bleibt-von-cyberangriffen-verschont-it-dailynet/</guid>
<pubDate>Sun, 14 Jun 2026 18:20:31 +0200</pubDate>
<content:encoded><![CDATA[Deutschlands Profisportbranche steckt in der Cyberkrise. Das ist das Ergebnis einer neuen Studie des britischen KI-Sicherheitsanbieters Darktrace, die ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Kein großer Profisportverein bleibt von Cyberangriffen verschont]]></title>
<description><![CDATA[Laut einer neuen Studie von Darktrace waren 93 Prozent der deutschen Profisportorganisationen 2025 von Cybervorfällen betroffen.

Tags: #Cyber Crime | #Hacker]]></description>
<link>https://tsecurity.de/de/3597277/it-security-nachrichten/kein-grosser-profisportverein-bleibt-von-cyberangriffen-verschont/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3597277/it-security-nachrichten/kein-grosser-profisportverein-bleibt-von-cyberangriffen-verschont/</guid>
<pubDate>Sun, 14 Jun 2026 17:35:18 +0200</pubDate>
<content:encoded><![CDATA[<p><img width="1920" height="1080" src="https://www.it-daily.net/wp-content/uploads/2026/06/Stadion-Quelle-Orange-Pictures-Shutterstock-2442140781-1920.jpg" class="attachment-full size-full wp-post-image" alt="Stadion" decoding="async" srcset="https://www.it-daily.net/wp-content/uploads/2026/06/Stadion-Quelle-Orange-Pictures-Shutterstock-2442140781-1920.jpg 1920w, https://www.it-daily.net/wp-content/uploads/2026/06/Stadion-Quelle-Orange-Pictures-Shutterstock-2442140781-1920-300x169.jpg 300w, https://www.it-daily.net/wp-content/uploads/2026/06/Stadion-Quelle-Orange-Pictures-Shutterstock-2442140781-1920-1024x576.jpg 1024w, https://www.it-daily.net/wp-content/uploads/2026/06/Stadion-Quelle-Orange-Pictures-Shutterstock-2442140781-1920-768x432.jpg 768w, https://www.it-daily.net/wp-content/uploads/2026/06/Stadion-Quelle-Orange-Pictures-Shutterstock-2442140781-1920-1536x864.jpg 1536w" sizes="(max-width: 1920px) 100vw, 1920px" title="Kein großer Profisportverein bleibt von Cyberangriffen verschont 1"></p>
    Laut einer neuen Studie von Darktrace waren 93 Prozent der deutschen Profisportorganisationen 2025 von Cybervorfällen betroffen.

<p>Tags: <a href="https://www.it-daily.net/thema/cyber-crime">#Cyber Crime</a> | <a href="https://www.it-daily.net/thema/hacker">#Hacker</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Over 80% of Sports Organizations Targeted by Hackers in the Last Year]]></title>
<description><![CDATA[As the FIFA World Cup 2026 kicks off, a new Darktrace report warns that sports teams and bodies are a major target for cyber criminals]]></description>
<link>https://tsecurity.de/de/3593246/it-security-nachrichten/over-80-of-sports-organizations-targeted-by-hackers-in-the-last-year/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3593246/it-security-nachrichten/over-80-of-sports-organizations-targeted-by-hackers-in-the-last-year/</guid>
<pubDate>Fri, 12 Jun 2026 13:07:39 +0200</pubDate>
<content:encoded><![CDATA[As the FIFA World Cup 2026 kicks off, a new Darktrace report warns that sports teams and bodies are a major target for cyber criminals]]></content:encoded>
</item>
<item>
<title><![CDATA[Over 80% of Sports Organizations Targeted by Hackers in the Last Year]]></title>
<description><![CDATA[As the FIFA World Cup 2026 kicks off, a new Darktrace report warns that sports teams and bodies are a major target for cyber criminals This article has been indexed from www.infosecurity-magazine.com Read the original article: Over 80% of Sports…
Read more →
The post Over 80% of Sports Organizati...]]></description>
<link>https://tsecurity.de/de/3593240/it-security-nachrichten/over-80-of-sports-organizations-targeted-by-hackers-in-the-last-year/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3593240/it-security-nachrichten/over-80-of-sports-organizations-targeted-by-hackers-in-the-last-year/</guid>
<pubDate>Fri, 12 Jun 2026 13:07:32 +0200</pubDate>
<content:encoded><![CDATA[<p>As the FIFA World Cup 2026 kicks off, a new Darktrace report warns that sports teams and bodies are a major target for cyber criminals This article has been indexed from www.infosecurity-magazine.com Read the original article: Over 80% of Sports…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/over-80-of-sports-organizations-targeted-by-hackers-in-the-last-year/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/over-80-of-sports-organizations-targeted-by-hackers-in-the-last-year/">Over 80% of Sports Organizations Targeted by Hackers in the Last Year</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Stellenstreichungen: Frisst die KI-Revolution ihre Ingenieure? - WirtschaftsWoche]]></title>
<description><![CDATA[... IT-Unternehmen Dynatrace, dessen Softwareplattform komplexe IT ... Information Security Officer beim britischen Cybersicherheitsanbieter Darktrace.]]></description>
<link>https://tsecurity.de/de/3520199/it-security-nachrichten/stellenstreichungen-frisst-die-ki-revolution-ihre-ingenieure-wirtschaftswoche/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3520199/it-security-nachrichten/stellenstreichungen-frisst-die-ki-revolution-ihre-ingenieure-wirtschaftswoche/</guid>
<pubDate>Fri, 15 May 2026 17:24:36 +0200</pubDate>
<content:encoded><![CDATA[... <b>IT</b>-Unternehmen Dynatrace, dessen Softwareplattform komplexe <b>IT</b> ... Information <b>Security</b> Officer beim britischen Cybersicherheitsanbieter Darktrace.]]></content:encoded>
</item>
<item>
<title><![CDATA[Hackers used faked Apple & Yahoo infrastructure to hide malware]]></title>
<description><![CDATA[Hackers spent months hiding malware behind fake Apple-themed internet infrastructure and similarly bogus Windows pop-ups to infiltrate organizations across the Asia-Pacific region without triggering obvious security alarms. Here's how they did it.Attackers impersonated CDN infrastructure. Image c...]]></description>
<link>https://tsecurity.de/de/3517235/ios-mac-os/hackers-used-faked-apple-yahoo-infrastructure-to-hide-malware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3517235/ios-mac-os/hackers-used-faked-apple-yahoo-infrastructure-to-hide-malware/</guid>
<pubDate>Thu, 14 May 2026 17:40:20 +0200</pubDate>
<content:encoded><![CDATA[Hackers spent months hiding malware behind fake Apple-themed internet infrastructure and similarly bogus Windows pop-ups to infiltrate organizations across the Asia-Pacific region without triggering obvious security alarms. Here's how they did it.<br><br><div><img src="https://photos5.appleinsider.com/gallery/67645-142580-Code-header-xl.jpg" alt="Close-up of XML configuration code on a dark background, showing nested runtime and assemblyBinding elements with attributes like assemblyIdentity, codeBase URLs, etwEnable, appDomainManagerAssembly, and appDomainManagerType"><span>Attackers impersonated CDN infrastructure. Image credit: Darktrace</span></div><br>The malware was disguised as trusted Apple and Yahoo-themed internet infrastructure. Legitimate Windows software and DLL sideloading concealed a modular remote access trojan within ordinary network traffic.<br><br>Activity first appeared in customer networks in late September 2025 and primarily affected organizations in the Asia-Pacific and Japan region. Researchers observed repeated abuse of trusted executables and fake CDN infrastructure inside corporate environments.<br><br>Attackers impersonated CDN infrastructure tied to major technology brands to make malicious traffic appear legitimate. Trusted Windows binaries and DLL sideloading then launched a modular .NET remote access trojan.<br><br><br> <a href="https://appleinsider.com/articles/26/05/14/hackers-used-faked-apple-yahoo-infrastructure-to-hide-malware?utm_source=rss">Continue Reading on AppleInsider</a> | <a href="https://forums.appleinsider.com/discussion/244344?urm_source=rss">Discuss on our Forums</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[China-Linked Twill Typhoon Uses Fake Apple and Yahoo Sites for Espionage]]></title>
<description><![CDATA[A new Darktrace report reveals how Chinese hackers use fake Apple and Yahoo sites and the FDMTP malware framework to spy on organisations. This article has been indexed from Hackread – Cybersecurity News, Data Breaches, AI and More Read the…
Read more →
The post China-Linked Twill Typhoon Uses Fa...]]></description>
<link>https://tsecurity.de/de/3516456/it-security-nachrichten/china-linked-twill-typhoon-uses-fake-apple-and-yahoo-sites-for-espionage/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3516456/it-security-nachrichten/china-linked-twill-typhoon-uses-fake-apple-and-yahoo-sites-for-espionage/</guid>
<pubDate>Thu, 14 May 2026 13:05:00 +0200</pubDate>
<content:encoded><![CDATA[<p>A new Darktrace report reveals how Chinese hackers use fake Apple and Yahoo sites and the FDMTP malware framework to spy on organisations. This article has been indexed from Hackread – Cybersecurity News, Data Breaches, AI and More Read the…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/china-linked-twill-typhoon-uses-fake-apple-and-yahoo-sites-for-espionage/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/china-linked-twill-typhoon-uses-fake-apple-and-yahoo-sites-for-espionage/">China-Linked Twill Typhoon Uses Fake Apple and Yahoo Sites for Espionage</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[China-Linked Twill Typhoon Uses Fake Apple and Yahoo Sites for Espionage]]></title>
<description><![CDATA[A new Darktrace report reveals how Chinese hackers use fake Apple and Yahoo sites and the FDMTP malware framework to spy on organisations.]]></description>
<link>https://tsecurity.de/de/3516398/it-security-nachrichten/china-linked-twill-typhoon-uses-fake-apple-and-yahoo-sites-for-espionage/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3516398/it-security-nachrichten/china-linked-twill-typhoon-uses-fake-apple-and-yahoo-sites-for-espionage/</guid>
<pubDate>Thu, 14 May 2026 12:40:26 +0200</pubDate>
<content:encoded><![CDATA[A new Darktrace report reveals how Chinese hackers use fake Apple and Yahoo sites and the FDMTP malware framework to spy on organisations.]]></content:encoded>
</item>
<item>
<title><![CDATA[AI Agents Are Creating a New Cybersecurity Blind Spot]]></title>
<description><![CDATA[The cybersecurity industry has spent years focusing on visibility. Dashboards expanded. Detection tooling improved. Telemetry volumes exploded. Yet one of the biggest emerging risks in 2026 is not hidden malware or an unknown zero-day. It is the rapid deployment of AI agents that organisations ba...]]></description>
<link>https://tsecurity.de/de/3505918/it-security-nachrichten/ai-agents-are-creating-a-new-cybersecurity-blind-spot/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3505918/it-security-nachrichten/ai-agents-are-creating-a-new-cybersecurity-blind-spot/</guid>
<pubDate>Mon, 11 May 2026 08:08:35 +0200</pubDate>
<content:encoded><![CDATA[

<div class="ise-post">

<p><span>The cybersecurity industry has spent years focusing on visibility. Dashboards expanded. Detection tooling improved. Telemetry volumes exploded. Yet one of the biggest emerging risks in 2026 is not hidden malware or an unknown zero-day. It is the rapid deployment of AI agents that organisations barely understand, cannot fully inventory, and often cannot meaningfully govern.</span></p>

<p><span>AI agents are moving beyond chat interfaces and simple copilots. They are increasingly capable of reasoning, planning, accessing systems, invoking tools, retrieving information, and taking autonomous actions with limited human involvement. That changes the security conversation entirely.</span></p>

<p><span>This is not simply another software category. It is the emergence of autonomous digital workers operating across identity systems, APIs, SaaS platforms, cloud environments, and business processes.</span></p>

<p><span>And most organisations are deploying them faster than they can secure them.</span></p>

<p><span><a href="https://www.bvp.com/atlas/securing-ai-agents-the-defining-cybersecurity-challenge-of-2026" rel="noopener" target="_blank">Research and industry reporting throughout 2026</a> show a growing concern across both government and enterprise sectors around agentic AI security risks. Security leaders increasingly view autonomous AI systems as one of the most significant new attack surfaces facing organisations.</span></p>

<p><span>The concern is justified.</span></p>

<p><span>AI agents introduce a combination of risks that traditional governance and security models were never designed to handle.</span></p><p></p><div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgkSOTVGT3WHeBO6vLI3IUKRJhuMNEIVRORg49ViI-AxDqMbV-HvUcpWh2QbnCFT4fFMnNLP19PZ1aW0xG-haSGDaSNwUjrgVyhBSID9d7fr18AIdT8vJcBuBC8sK6kYr54T_VXS0LME5ULMmG3IfR-vtWiIv-bMv0R82BTQ2HrEe-jwHwP3By1Ve0zX05i/s1536/AIAgentsSecurityRisk.png" imageanchor="1"><img border="0" data-original-height="1024" data-original-width="1536" height="266" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgkSOTVGT3WHeBO6vLI3IUKRJhuMNEIVRORg49ViI-AxDqMbV-HvUcpWh2QbnCFT4fFMnNLP19PZ1aW0xG-haSGDaSNwUjrgVyhBSID9d7fr18AIdT8vJcBuBC8sK6kYr54T_VXS0LME5ULMmG3IfR-vtWiIv-bMv0R82BTQ2HrEe-jwHwP3By1Ve0zX05i/w400-h266/AIAgentsSecurityRisk.png" width="400"></a></div><p></p>

<h2><span>AI Agents Change the Nature of Identity Risk</span></h2>

<p><span>Most cybersecurity programmes were built around managing human identities and traditional service accounts. AI agents disrupt that model because they behave more like autonomous actors than passive software components.</span></p>

<p><span>Many organisations are now deploying AI agents with:</span></p>

<ul>
  <li><span>access to internal documentation</span></li>
  <li><span>integration into SaaS platforms</span></li>
  <li><span>permissions to execute workflows</span></li>
  <li><span>API access to sensitive systems</span></li>
  <li><span>delegated authority to make operational decisions</span></li>
</ul>

<p><span>The problem is not simply access. It is scale and autonomy.</span></p>

<p><a href="https://securitybrief.co.uk/story/ai-s-2026-security-fallout-identity-chaos-deepfake-fear" rel="noopener" target="_blank"><span>Industry forecasts suggest AI agent identities may soon outnumber human identities dramatically inside enterprise environments.</span></a></p>

<p><span>That creates several immediate challenges:</span></p>

<ul>
  <li><span>identity sprawl</span></li>
  <li><span>excessive permissions</span></li>
  <li><span>unmanaged API tokens</span></li>
  <li><span>poor lifecycle governance</span></li>
  <li><span>invisible machine-to-machine trust relationships</span></li>
  <li><span>difficulty attributing actions and accountability</span></li>
</ul>

<p><span>In many environments, organisations already struggle to maintain accurate inventories of privileged accounts or SaaS integrations. AI agents accelerate that problem significantly.</span></p>

<p><span>The result is a growing gap between operational reality and governance visibility.</span></p>

<h2><span>AI Agents Create a New Attack Surface</span></h2>

<p><span>The security industry often focuses heavily on model risks such as prompt injection or data poisoning. Those are important, but they are only part of the picture.</span></p>

<p><span>The bigger issue is that AI agents operate across interconnected runtime environments.</span></p>

<p><span>Modern agents may:</span></p>

<ul>
  <li><span>consume external data</span></li>
  <li><span>invoke plugins and APIs</span></li>
  <li><span>interact with cloud services</span></li>
  <li><span>maintain persistent memory</span></li>
  <li><span>chain multiple actions together</span></li>
  <li><span>collaborate with other agents</span></li>
  <li><span>execute operational workflows automatically</span></li>
</ul>

<p><span>That creates an entirely new form of runtime attack surface.</span></p>

<p><span>Recent research highlights risks including:</span></p>

<ul>
  <li><span>memory poisoning</span></li>
  <li><span>malicious tool invocation</span></li>
  <li><span>indirect prompt injection</span></li>
  <li><span>AI supply chain compromise</span></li>
  <li><span>runtime dependency manipulation</span></li>
  <li><span>self-propagating agent loops</span></li>
  <li><a href="https://arxiv.org/abs/2602.19555" rel="noopener" target="_blank"><span>excessive agency and unauthorised action execution</span></a></li>
</ul>

<p><span>The important point is this:</span></p>

<p><span>Many of these attacks do not exploit traditional software vulnerabilities. They exploit trust, autonomy, orchestration, and context.</span></p>

<p><span>That makes detection and governance significantly harder.</span></p>

<h2><span>Why Existing Security Controls Are Struggling</span></h2>

<p><span>One of the most dangerous assumptions organisations can make is believing existing security tooling automatically extends to AI agents.</span></p>

<p><span>In many cases it does not.</span></p>

<p><span>Traditional controls were largely designed for:</span></p>

<ul>
  <li><span>deterministic systems</span></li>
  <li><span>predictable workflows</span></li>
  <li><span>static permissions</span></li>
  <li><span>human-driven actions</span></li>
  <li><span>relatively stable software behaviour</span></li>
</ul>

<p><span>AI agents are fundamentally different.</span></p>

<p><span>They are probabilistic, adaptive, and capable of unexpected behaviour under changing context conditions.</span></p>

<p><span>This creates several assurance problems:</span></p>

<ul>
  <li><span>inventories quickly become outdated</span></li>
  <li><span>permissions drift continuously</span></li>
  <li><span>actions may not be fully explainable</span></li>
  <li><span>logging lacks meaningful context</span></li>
  <li><span>governance ownership becomes unclear</span></li>
  <li><span>accountability boundaries blur</span></li>
</ul>

<p><span>The challenge is not merely technical. It is operational.</span></p>

<p><span>Security teams increasingly face environments where AI functionality appears inside:</span></p>

<ul>
  <li><span>SaaS products</span></li>
  <li><span>collaboration platforms</span></li>
  <li><span>development tooling</span></li>
  <li><span>cloud management interfaces</span></li>
  <li><span>workflow automation systems</span></li>
  <li><span>productivity platforms</span></li>
</ul>

<p><span>Often these capabilities are enabled by default or adopted informally by business teams before governance frameworks exist.</span></p>

<p><span>This is rapidly becoming one of the largest forms of <a href="https://thehackernews.com/2026/04/the-hidden-security-risks-of-shadow-ai.html" rel="noopener" target="_blank">Shadow IT the industry has seen</a>.</span></p>

<h2><span>The Real Risk Is Governance Lag</span></h2>

<p><span>The most significant AI security risk in many organisations is not the AI itself.</span></p>

<p><span>It is governance lag.</span></p>

<p><span>Technology deployment is moving faster than:</span></p>

<ul>
  <li><span>control validation</span></li>
  <li><span>identity governance</span></li>
  <li><span>operational assurance</span></li>
  <li><span>policy adaptation</span></li>
  <li><span>board understanding</span></li>
  <li><span>security architecture redesign</span></li>
</ul>

<p><span>This creates a dangerous illusion of control.</span></p>

<p><span>Dashboards may still appear green while autonomous systems quietly accumulate:</span></p>

<ul>
  <li><span>privileges</span></li>
  <li><span>integrations</span></li>
  <li><span>external dependencies</span></li>
  <li><span>sensitive data access</span></li>
  <li><span>operational authority</span></li>
</ul>

<p><span>Without strong governance, organisations risk repeating familiar mistakes:</span></p>

<ul>
  <li><span>deploying first</span></li>
  <li><span>governing later</span></li>
  <li><span>discovering exposure during incidents</span></li>
</ul>

<p><span>The difference now is speed.</span></p>

<p><span>AI systems compress timelines dramatically.</span></p>

<h2><span>What Security Leaders Should Do Next</span></h2>

<p><span>The organisations responding most effectively are not trying to ban AI agents entirely. They are focusing on visibility, containment, and evidence-driven governance.</span></p>

<p><span>Several priorities are emerging:</span></p>

<h3><span>1. Build an AI Asset Inventory</span></h3>

<p><span>Most organisations cannot currently answer:</span></p>

<ul>
  <li><span>which AI agents exist</span></li>
  <li><span>what systems they access</span></li>
  <li><span>what permissions they hold</span></li>
  <li><span>what data they process</span></li>
  <li><span>who owns them</span></li>
</ul>

<p><span>That must change quickly.</span></p>

<p><span>AI agents should be treated as managed operational assets with clear ownership and lifecycle governance.</span></p>

<h3><span>2. Apply Least Privilege Aggressively</span></h3>

<p><span>Many AI deployments currently operate with excessive permissions for convenience.</span></p>

<p><span>That is unsustainable.</span></p>

<p><span>AI agents should operate with:</span></p>

<ul>
  <li><span>constrained access scopes</span></li>
  <li><span>segmented permissions</span></li>
  <li><span>time-limited credentials</span></li>
  <li><span>monitored API activity</span></li>
  <li><span>restricted tool invocation</span></li>
</ul>

<p><span>The principle of least privilege matters even more in autonomous environments.</span></p>

<h3><span>3. Treat AI Runtime Behaviour as an Assurance Problem</span></h3>

<p><span>The industry increasingly needs continuous validation rather than static approval models.</span></p>

<p><span>Security teams should focus on:</span></p>

<ul>
  <li><span>runtime monitoring</span></li>
  <li><span>behavioural drift detection</span></li>
  <li><span>evidence freshness</span></li>
  <li><span>control verification</span></li>
  <li><span>anomalous workflow analysis</span></li>
</ul>

<p><span>This aligns closely with broader Continuous Control Monitoring (CCM) approaches already emerging across cybersecurity assurance programmes.</span></p>

<h3><span>4. Update Governance Frameworks</span></h3>

<p><span>Most governance structures were not designed for autonomous operational actors.</span></p>

<p><span>Boards, risk committees, and security leadership teams need clearer accountability models around:</span></p>

<ul>
  <li><span>AI deployment ownership</span></li>
  <li><span>operational risk tolerance</span></li>
  <li><span>human override mechanisms</span></li>
  <li><span>auditability</span></li>
  <li><span>resilience testing</span></li>
  <li><span>third-party AI exposure</span></li>
</ul>

<p><span>The governance gap is becoming as important as the technical gap.</span></p>

<h2><span>Final Thought</span></h2>

<p><span>AI agents are not simply another cybersecurity trend. They represent a structural change in how digital systems operate.</span></p>

<p><span>The organisations that succeed will not necessarily be those deploying AI fastest.</span></p>

<p><span>They will be the organisations that can answer:</span></p>

<ul>
  <li><span>what their AI systems are doing</span></li>
  <li><span>what authority they possess</span></li>
  <li><span>how they are governed</span></li>
  <li><span>how they are monitored</span></li>
  <li><span>whether their controls still work under real operational conditions</span></li>
</ul>

<p><span>That is ultimately the real challenge of AI security in 2026.</span></p>

<p><span>Not visibility alone.</span></p>

<p><span>But provable assurance.</span></p>

<p class="sources"><strong><span>Sources and further reading:</span></strong></p>

<ul>
  <li><a href="https://internationalaisafetyreport.org/publication/international-ai-safety-report-2026" rel="noopener" target="_blank"><span>International AI Safety Report 2026</span></a></li>
  <li><a href="https://www.darktrace.com/blog/state-of-ai-cybersecurity-2026-92-of-security-professionals-concerned-about-the-impact-of-ai-agents" rel="noopener" target="_blank"><span>State of AI Cybersecurity 2026</span></a></li>
  <li><a href="https://arxiv.org/abs/2602.19555" rel="noopener" target="_blank"><span>Agentic AI security research papers</span></a></li>
  <li><a href="https://www.cybersecurity-insiders.com/ai-agents-are-the-new-attack-surface-and-most-enterprises-dont-know-it/" rel="noopener" target="_blank"><span>Industry reporting on AI agent attack surfaces and governance risks</span></a></li>
</ul>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Inside ZionSiphon: Darktrace’s Analysis of OT Malware Targeting Israeli Water Systems]]></title>
<description><![CDATA[2026-04-16 • Darktrace
     • Calum Hall, Ryan Traill
    
    
    
    Open article on Malpedia]]></description>
<link>https://tsecurity.de/de/3488847/malware-trojaner-viren/inside-zionsiphon-darktraces-analysis-of-ot-malware-targeting-israeli-water-systems/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3488847/malware-trojaner-viren/inside-zionsiphon-darktraces-analysis-of-ot-malware-targeting-israeli-water-systems/</guid>
<pubDate>Tue, 05 May 2026 10:47:58 +0200</pubDate>
<content:encoded><![CDATA[<!--  -->
<div>
    2026-04-16 • Darktrace
     • Calum Hall, Ryan Traill
    
    
    <br>
    <a href="https://malpedia.caad.fkie.fraunhofer.de/library/1dcd3b9c-8b94-42f8-911d-0c8efce55915/">Open article on Malpedia</a>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Phantom Footprints: Tracking GhostSocks Malware]]></title>
<description><![CDATA[2026-03-26 • Darktrace
     • Isabel Evans
     • win.ghostsocks, win.lumma
    
    
    Open article on Malpedia]]></description>
<link>https://tsecurity.de/de/3488795/malware-trojaner-viren/phantom-footprints-tracking-ghostsocks-malware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3488795/malware-trojaner-viren/phantom-footprints-tracking-ghostsocks-malware/</guid>
<pubDate>Tue, 05 May 2026 10:32:35 +0200</pubDate>
<content:encoded><![CDATA[<!--  -->
<div>
    2026-03-26 • Darktrace
     • Isabel Evans
     • win.ghostsocks, win.lumma
    
    <br>
    <a href="https://malpedia.caad.fkie.fraunhofer.de/library/2461c96d-3868-42af-9aa6-22547e994903/">Open article on Malpedia</a>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[DDoS Malware Abuses Jenkins Infrastructure In Attacks On Valve Source Engine Servers]]></title>
<description><![CDATA[Darktrace has disclosed a new DDoS botnet that abused a Jenkins honeypot to infect exposed systems and target video game servers, including Valve Source Engine environments. The activity was seen on March 18, 2026, when an attacker tried to use Jenkins’ scriptText endpoint to run a malicious Groo...]]></description>
<link>https://tsecurity.de/de/3485223/it-security-nachrichten/ddos-malware-abuses-jenkins-infrastructure-in-attacks-on-valve-source-engine-servers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3485223/it-security-nachrichten/ddos-malware-abuses-jenkins-infrastructure-in-attacks-on-valve-source-engine-servers/</guid>
<pubDate>Mon, 04 May 2026 09:07:40 +0200</pubDate>
<content:encoded><![CDATA[<p>Darktrace has disclosed a new DDoS botnet that abused a Jenkins honeypot to infect exposed systems and target video game servers, including Valve Source Engine environments. The activity was seen on March 18, 2026, when an attacker tried to use Jenkins’ scriptText endpoint to run a malicious Groovy script and gain remote code execution. The […]</p>
<p>The post <a href="https://cyberpress.org/jenkins-abusing-ddos-hits-source/">DDoS Malware Abuses Jenkins Infrastructure In Attacks On Valve Source Engine Servers</a> appeared first on <a href="https://cyberpress.org/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[New DDoS Malware Exploits Jenkins to Attack Valve Source Engine Game Servers]]></title>
<description><![CDATA[A newly discovered DDoS botnet is exploiting exposed Jenkins servers to launch powerful attacks against Valve Source Engine game infrastructure. Security researchers at Darktrace identified the threat after capturing it on one of their honeypot systems. What makes this malware…
Read more →
The po...]]></description>
<link>https://tsecurity.de/de/3480736/it-security-nachrichten/new-ddos-malware-exploits-jenkins-to-attack-valve-source-engine-game-servers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3480736/it-security-nachrichten/new-ddos-malware-exploits-jenkins-to-attack-valve-source-engine-game-servers/</guid>
<pubDate>Fri, 01 May 2026 17:51:47 +0200</pubDate>
<content:encoded><![CDATA[<p>A newly discovered DDoS botnet is exploiting exposed Jenkins servers to launch powerful attacks against Valve Source Engine game infrastructure. Security researchers at Darktrace identified the threat after capturing it on one of their honeypot systems. What makes this malware…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/new-ddos-malware-exploits-jenkins-to-attack-valve-source-engine-game-servers/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/new-ddos-malware-exploits-jenkins-to-attack-valve-source-engine-game-servers/">New DDoS Malware Exploits Jenkins to Attack Valve Source Engine Game Servers</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[New DDoS Malware Exploits Jenkins to Attack Valve Source Engine Game Servers]]></title>
<description><![CDATA[A newly discovered DDoS botnet is exploiting exposed Jenkins servers to launch powerful attacks against Valve Source Engine game infrastructure. Security researchers at Darktrace identified the threat after capturing it on one of their honeypot systems. What makes this malware stand out is its sp...]]></description>
<link>https://tsecurity.de/de/3480440/it-security-nachrichten/new-ddos-malware-exploits-jenkins-to-attack-valve-source-engine-game-servers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3480440/it-security-nachrichten/new-ddos-malware-exploits-jenkins-to-attack-valve-source-engine-game-servers/</guid>
<pubDate>Fri, 01 May 2026 15:36:57 +0200</pubDate>
<content:encoded><![CDATA[<p>A newly discovered DDoS botnet is exploiting exposed Jenkins servers to launch powerful attacks against Valve Source Engine game infrastructure. Security researchers at Darktrace identified the threat after capturing it on one of their honeypot systems. What makes this malware stand out is its specific targeting of video game servers, combined with a smart infection […]</p>
<p>The post <a href="https://cybersecuritynews.com/new-ddos-malware-exploits-jenkins/">New DDoS Malware Exploits Jenkins to Attack Valve Source Engine Game Servers</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[4 ways to prepare your SOC for agentic AI]]></title>
<description><![CDATA[According to IDC, agentic AI is on track to become mainstream infrastructure. The analyst firm expects 45% of organizations to have autonomous agents operating at scale across critical business functions by 2030. In enterprise SOCs, AI is already reshaping functions like alert triage, enrichment,...]]></description>
<link>https://tsecurity.de/de/3479721/it-security-nachrichten/4-ways-to-prepare-your-soc-for-agentic-ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3479721/it-security-nachrichten/4-ways-to-prepare-your-soc-for-agentic-ai/</guid>
<pubDate>Fri, 01 May 2026 09:07:15 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>According to <a href="https://my.idc.com/getdoc.jsp?containerId=prUS53883425">IDC</a>, agentic AI is on track to become mainstream infrastructure. The analyst firm expects 45% of organizations to have autonomous agents operating at scale across critical business functions by 2030. In enterprise SOCs, AI is already reshaping functions like alert triage, enrichment, data correlation, IOC validation and initial containment. It could soon move up the stack to take on more complex tasks like incident investigation, root cause analysis, and response.</p>



<p>“AI acts as a force multiplier in the SOC,” says Nicole Carignan, senior VP, security and AI strategy at Darktrace. But harnessing that promise will require organizations to invest now in reskilling analysts, redesigning processes, building new technical roles, and establishing guardrails and governance frameworks to ensure autonomous AI agents operate safely. “It’s not enough to simply deploy an AI solution. Security practitioners must understand how the underlying machine learning techniques function, what their strengths and limitations are, and how to evaluate their outputs,” Carignan says. “Without explainability and trust, AI risks are exacerbating alert fatigue rather than solving it.”</p>



<p>Here is what security leaders need to know — and do — to prepare their SOCs for the agentic AI era.</p>



<h2 class="wp-block-heading">Reskill analysts to become AI collaborators and overseers</h2>



<p>Increasingly, human roles in the SOC will shift from hands-on execution to supervision, governance, design, and oversight. As AI agents take on more operational tasks, analysts will need to focus on managing AI systems, interpreting outputs, and resolving the nuanced challenges machines cannot handle, says Casey Ellis, founder of Bugcrowd. “Jobs won’t disappear, they’ll adapt. The key is ensuring that SOC professionals are prepared for this shift through ongoing education, training, and tooling.”</p>



<p>Few expect the transition will occur organically or without friction. Many SOC leaders will need to reskill existing staff to manage AI effectively; to interrogate AI reasoning; enrich investigations with contextual insight; and apply informed human analysis to AI-driven outputs.</p>



<p>When acting on an AI tool’s recommendation, analysts must understand what questions the agent asked, which data sources it queried, and what evidence informed its decision, according to Dov Yoran, co-founder and CEO of Command Zero. From there, they need to be able to pivot to additional data sources, pursue new artifacts, and extend the investigative timeline as needed. “Junior analysts who might not know how to start an investigation from scratch can become effective by learning how to extend and refine what the agent produced,” Yoran says. “It’s a different skill set from traditional SOC work, and in many ways, a more accessible one.”</p>



<p>In the SOC of the future, analysts must also act as adversarial reviewers of AI-driven conclusions. That’s because AI systems can introduce hallucinations, training-data bias, and other vulnerabilities while also being vulnerable to adversarial manipulation. Analysts need to recognize these risks to ensure decisions remain grounded and defensible, says Ensar Seker, CISO at SOCRadar. “Analysts need to be trained less as button-pushers and more as adversarial reviewers of AI output. That means understanding how models reason, where they fail, how bias and data gaps surface, and how to interrogate confidence levels and assumptions. The goal isn’t to ‘trust AI faster,’ but to develop the instinct to ask: What would make this conclusion wrong?” Seker says.</p>



<p>Analysts will also play a critical role in enabling organization-specific context into AI-driven workflows. Without that context, agents risk missing threats, amplifying noise, or triggering risky actions based on incomplete information. SOC leaders need to remember that “AI agents are only as smart as the context they have access to,” Yoran says. Analysts must learn to annotate identities, maintain watch lists, document recurring false-positive patterns, and build enrichment layers that strengthen future investigations, he said, “This is knowledge work, not data work.”</p>



<p>Ultimately, the objective is not to outperform AI, but to do better where AI falls short. For example, “accept that autonomous alert triage will become table stakes,” Yoran says. “Your processes need to shift from ‘how do we triage every alert’ to ‘how do we handle escalations from autonomous investigations’.”</p>



<h2 class="wp-block-heading">Build capabilities for AI governance, content and quality</h2>



<p>Upskilling existing analysts alone is not enough. As AI agents begin operating across tools, making decisions and triggering actions with minimal human involvement, the demands on the SOC will extend well beyond traditional analyst capabilities, experts say.</p>



<p>Content engineering, for instance, is one emerging requirement. In an AI-enabled SOC, detection engineers will no longer write only static rules. They must design dynamic content such as questions, prompts and investigation templates that agents can use to reason, enrich data, correlate signals and act autonomously. These content engineers curate the structured inputs that power agents, including telemetry, threat models, and playbooks.</p>



<p>“This is the most underappreciated role in AI-powered security operations,” Yoran notes. “These are people who build and maintain the questions that agents can ask, the investigation plans that guide autonomous work, and the knowledge bases that provide context,”. Organizations need someone who can translate detection logic from their SIEM, import best practices from frameworks like MITRE ATT&amp;CK, and encode institutional knowledge into the platform. “This isn’t traditional security engineering, it’s closer to knowledge management combined with threat intelligence,” he says.</p>



<p>Mature SOCs will also require clear ownership of AI governance and agent oversight. That includes roles that have oversight over model risk evaluation, prompt and policy management, continuous performance validation, and even red teaming the agents themselves, Seker says. “You don’t need a massive new team, but you do need clear accountability for how autonomous decisions are made, tested, and constrained.”</p>



<p>Another emerging need is analysts with deep fluency in data management. An AI-driven SOC will require professionals who understand how information should be classified, protected, normalized, and monitored to ensure reliable conclusions. “With 64% of organizations <a href="https://www.darktrace.com/the-state-of-ai-cybersecurity-2025">planning</a> to add AI-powered solutions to their security stack in the next year, it is critical for professionals to cross-skill in AI,” Carignan says. “Cybersecurity professionals must become fluent in AI and data, developing a deeper understanding of data classification, governance, and model behavior.” Cross-skills in data science, machine learning, and cybersecurity enable analysts to critically evaluate AI outputs, tune models for security use cases, and adapt defenses as threats evolve, making them indispensable in an AI-augmented SOC.</p>



<p>Frank Dickson, an analyst at IDC, urged organizations to think of this capability as similar to a data architect role. “The key to getting value from AI is having data located in a place where you can get to it, having it formatted in a homogeneous way so you can do analysis on it, and then manage the data,” he says. “The success of your AI initiative is going to be tied to the effectiveness of your ability to get data. A data architect manages that.”</p>



<p>Dickson also emphasized the need for an “orchestration platform engineer” role responsible for ensuring effective communication and workflow integration across security tools. The SOC of the future will not hinge on a single platform but on an interconnected ecosystem of SIEM, EDR, SOAR, identity, cloud and other systems that must operate in concert to support AI-driven, agentic investigations and automation, Dickson tells. Dedicated orchestration expertise will become essential to maintain reliable data flows and automation logic in such an environment, he noted.</p>



<h2 class="wp-block-heading">Redesign SOC processes and playbooks where needed</h2>



<p>Organizations will need to review and rework SOC processes and playbooks to ensure their AI-augmented SOC is consistent, efficient and continuously learning. Yoran recommends that SOC leaders focus on codifying institutional knowledge into AI agent-accessible questions and plans. Translate playbooks into investigation plans that AI agents can follow on a repeatable basis. In situations where an agent might hit a wall, have processes in place for a smooth handoff to a human analyst and build feedback loops for continuous improvement, Yoran adds.</p>



<p>“Playbooks must shift from step-by-step human procedures to intent-based guardrails,” Seker points out. “Instead of telling analysts how to investigate, define what outcomes are allowed, what actions are prohibited, and when human approval is mandatory.”. The objective is not to micromanage every alert but to assume AI agents operate continuously across tools, with humans only supervising exceptions, edge cases, and strategic decisions.</p>



<p>SOCs also need to rethink metrics, accountability, and documentation within the SOC. Traditional performance indicators, such as ticket closure rates or mean time to resolution, may need to broaden to include model accuracy, escalation quality, and the effectiveness of automated containment actions. “The biggest mistake is optimizing for speed metrics instead of investigation quality,” Yoran says. “I see this constantly: vendors promising 90% faster time to resolution or reduce tier-one workload by 80% or close alerts in seconds instead of hours. These metrics while seductive are dangerous,” he cautions. “Making the same mistake faster benefits no one. An incomplete investigation that closes in two minutes isn’t better than a thorough investigation that takes 30 minutes.”</p>



<p>Auditability too becomes critical. All AI-driven decisions should be traceable, explainable, and reviewable from both an internal governance standpoint and for external compliance requirements.  “If you can’t explain why an AI took an action to an auditor, regulator, or executive, it shouldn’t be allowed to take that action. Explainability isn’t a nice-to-have; it’s a prerequisite for autonomy,” Seker says.</p>



<h2 class="wp-block-heading">Implement AI guardrails and principles</h2>



<p>Formal guardrails and operating principles are going to be critical in SOCs where AI agents influence decisions, initiate responses and help prioritize threats. That means setting defined boundaries around data access and model behavior, having processes to validate responses and making sure humans remain in the loop on all high-impact decisions.</p>



<p>Focus areas should include approval thresholds for autonomous actions, figuring out allowed and disallowed actions for an agent, protecting against prompt injection attacks, testing and red-teaming of agentic workflows and ensuring IR policies are updated for AI-driven actions. “Require transparent decision trails, rate limiting, least-privilege, and instant override,” Seker advises. “Hard limits on action scope, blast radius, and privilege are non-negotiable. Agents should operate under least-privilege identities, with explicit kill-switches, change-control boundaries, and environment awareness. The key is to ensure that AI is never allowed to silently escalate its own authority or modify guardrails without human approval.”</p>



<p>IDC analyst Dickson pointed to identity and access as two other areas to focus on by way of guardrails and policies. “In the past, when we gave humans access, we often over-provisioned by default. That approach does not work with agents. With agentic AI, permissions must start at least privilege, defined precisely from day one.”</p>



<p>The focus should be on ensuring no standing privileges, implementing dynamic authorization and establishing clear role definitions, Dickson says. “Agentic AI is enormously powerful. Constraining access correctly is non-negotiable.”</p>



<p><em>There’s no playbook for leading through today’s cyber risk — only experience. The CSO Cybersecurity Awards &amp; Conference, May 11-13, brings together CISOs and senior security executives for peer‑driven insight, unfiltered conversations, and practical strategies that drive real business impact. <a href="https://event.foundryco.com/cso-conference-awards/?utm_medium=editorial&amp;utm_source=cso2026_foundry_pre-event_editorial&amp;utm_campaign=cso_2026_pre_event_articles&amp;utm_term=4/25/2026-5/16//2026&amp;utm_content=editorial"><strong>Secure your seat before it fills up</strong></a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Managed Security Services gehen bei Darktrace den KI-Weg - it-business]]></title>
<description><![CDATA[IT-Security lässt sich auch remote managen. (Bild: Midjourney / KI-generiert). Security wird zunehmend „as a Service“ bezogen. Diese Tatsache geht ...]]></description>
<link>https://tsecurity.de/de/3458391/it-security-nachrichten/managed-security-services-gehen-bei-darktrace-den-ki-weg-it-business/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3458391/it-security-nachrichten/managed-security-services-gehen-bei-darktrace-den-ki-weg-it-business/</guid>
<pubDate>Thu, 23 Apr 2026 16:22:47 +0200</pubDate>
<content:encoded><![CDATA[<b>IT</b>-<b>Security</b> lässt sich auch remote managen. (Bild: Midjourney / KI-generiert). Security wird zunehmend „as a Service“ bezogen. Diese Tatsache geht ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Cyberattack That Could Have Poisoned a City’s Water Supply by Manipulating Chlorine Levels]]></title>
<description><![CDATA[In mid-April 2026, researchers at Darktrace published a detailed breakdown of a malware sample that occupies a narrow but alarming niche in the threat landscape: a Windows-based OT weapon apparentlyRead More →
The post Cyberattack That Could Have Poisoned a City’s Water Supply by Manipulating Chl...]]></description>
<link>https://tsecurity.de/de/3449550/it-security-nachrichten/cyberattack-that-could-have-poisoned-a-citys-water-supply-by-manipulating-chlorine-levels/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3449550/it-security-nachrichten/cyberattack-that-could-have-poisoned-a-citys-water-supply-by-manipulating-chlorine-levels/</guid>
<pubDate>Mon, 20 Apr 2026 22:36:32 +0200</pubDate>
<content:encoded><![CDATA[<p>In mid-April 2026, researchers at Darktrace published a detailed breakdown of a malware sample that occupies a narrow but alarming niche in the threat landscape: a Windows-based OT weapon apparently<span class="more-link"><a href="https://www.exploitone.com/forensics/cyberattack-that-could-have-poisoned-a-citys-water-supply-by-manipulating-chlorine-levels/">Read More →</a></span></p>
<p>The post <a href="https://www.exploitone.com/forensics/cyberattack-that-could-have-poisoned-a-citys-water-supply-by-manipulating-chlorine-levels/">Cyberattack That Could Have Poisoned a City’s Water Supply by Manipulating Chlorine Levels</a> appeared first on <a href="https://www.exploitone.com/">Cyber Security News | Exploit One | Hacking News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[ZionSiphon Launches Sabotage Attacks On Israel’s Water Infrastructure]]></title>
<description><![CDATA[Darktrace researchers have uncovered a new politically motivated malware strain called ZionSiphon, engineered specifically to infiltrate and sabotage Israel’s water treatment and desalination systems. The malware combines privilege escalation, persistence, USB-based propagation, and industrial co...]]></description>
<link>https://tsecurity.de/de/3447939/it-security-nachrichten/zionsiphon-launches-sabotage-attacks-on-israels-water-infrastructure/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3447939/it-security-nachrichten/zionsiphon-launches-sabotage-attacks-on-israels-water-infrastructure/</guid>
<pubDate>Mon, 20 Apr 2026 12:22:17 +0200</pubDate>
<content:encoded><![CDATA[<p>Darktrace researchers have uncovered a new politically motivated malware strain called ZionSiphon, engineered specifically to infiltrate and sabotage Israel’s water treatment and desalination systems. The malware combines privilege escalation, persistence, USB-based propagation, and industrial control system (ICS) scanning with explicit sabotage capabilities targeting chlorine dosing and hydraulic pressure controls. ZionSiphon is not a generic opportunistic […]</p>
<p>The post <a href="https://cyberpress.org/zionsiphon-hits-water-infrastructure/">ZionSiphon Launches Sabotage Attacks On Israel’s Water Infrastructure</a> appeared first on <a href="https://cyberpress.org/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Researchers Detect ZionSiphon Malware Targeting Israeli Water, Desalination OT Systems]]></title>
<description><![CDATA[Cybersecurity researchers have flagged a new malware called ZionSiphon that appears to be specifically designed to target Israeli water treatment and desalination systems.
The malware has been codenamed ZionSiphon by Darktrace, highlighting its ability to set up persistence, tamper with local con...]]></description>
<link>https://tsecurity.de/de/3447634/it-security-nachrichten/researchers-detect-zionsiphon-malware-targeting-israeli-water-desalination-ot-systems/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3447634/it-security-nachrichten/researchers-detect-zionsiphon-malware-targeting-israeli-water-desalination-ot-systems/</guid>
<pubDate>Mon, 20 Apr 2026 10:38:14 +0200</pubDate>
<content:encoded><![CDATA[Cybersecurity researchers have flagged a new malware called ZionSiphon that appears to be specifically designed to target Israeli water treatment and desalination systems.
The malware has been codenamed ZionSiphon by Darktrace, highlighting its ability to set up persistence, tamper with local configuration files, and scan for operational technology (OT)-relevant services on the local subnet.]]></content:encoded>
</item>
<item>
<title><![CDATA[Researchers Detect ZionSiphon Malware Targeting Israeli Water, Desalination OT Systems]]></title>
<description><![CDATA[Cybersecurity researchers have flagged a new malware called ZionSiphon that appears to be specifically designed to target Israeli water treatment and desalination systems. The malware has been codenamed ZionSiphon by Darktrace, highlighting its ability to set up persistence, tamper with…
Read mor...]]></description>
<link>https://tsecurity.de/de/3447624/it-security-nachrichten/researchers-detect-zionsiphon-malware-targeting-israeli-water-desalination-ot-systems/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3447624/it-security-nachrichten/researchers-detect-zionsiphon-malware-targeting-israeli-water-desalination-ot-systems/</guid>
<pubDate>Mon, 20 Apr 2026 10:38:00 +0200</pubDate>
<content:encoded><![CDATA[<p>Cybersecurity researchers have flagged a new malware called ZionSiphon that appears to be specifically designed to target Israeli water treatment and desalination systems. The malware has been codenamed ZionSiphon by Darktrace, highlighting its ability to set up persistence, tamper with…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/researchers-detect-zionsiphon-malware-targeting-israeli-water-desalination-ot-systems/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/researchers-detect-zionsiphon-malware-targeting-israeli-water-desalination-ot-systems/">Researchers Detect ZionSiphon Malware Targeting Israeli Water, Desalination OT Systems</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[ZionSiphon Hits Israeli Water Systems With OT Sabotage Malware]]></title>
<description><![CDATA[ZionSiphon is a newly analyzed Operational Technology (OT) malware strain designed to target Israeli water treatment and desalination facilities, with a clear emphasis on sabotage rather than simple IT disruption. Darktrace’s investigation found that ZionSiphon restricts itself to hardcoded IPv4…...]]></description>
<link>https://tsecurity.de/de/3447348/it-security-nachrichten/zionsiphon-hits-israeli-water-systems-with-ot-sabotage-malware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3447348/it-security-nachrichten/zionsiphon-hits-israeli-water-systems-with-ot-sabotage-malware/</guid>
<pubDate>Mon, 20 Apr 2026 08:36:50 +0200</pubDate>
<content:encoded><![CDATA[<p>ZionSiphon is a newly analyzed Operational Technology (OT) malware strain designed to target Israeli water treatment and desalination facilities, with a clear emphasis on sabotage rather than simple IT disruption. Darktrace’s investigation found that ZionSiphon restricts itself to hardcoded IPv4…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/zionsiphon-hits-israeli-water-systems-with-ot-sabotage-malware/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/zionsiphon-hits-israeli-water-systems-with-ot-sabotage-malware/">ZionSiphon Hits Israeli Water Systems With OT Sabotage Malware</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[ZionSiphon Hits Israeli Water Systems With OT Sabotage Malware]]></title>
<description><![CDATA[ZionSiphon is a newly analyzed Operational Technology (OT) malware strain designed to target Israeli water treatment and desalination facilities, with a clear emphasis on sabotage rather than simple IT disruption. Darktrace’s investigation found that ZionSiphon restricts itself to hardcoded IPv4 ...]]></description>
<link>https://tsecurity.de/de/3447314/it-security-nachrichten/zionsiphon-hits-israeli-water-systems-with-ot-sabotage-malware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3447314/it-security-nachrichten/zionsiphon-hits-israeli-water-systems-with-ot-sabotage-malware/</guid>
<pubDate>Mon, 20 Apr 2026 08:22:34 +0200</pubDate>
<content:encoded><![CDATA[<p>ZionSiphon is a newly analyzed Operational Technology (OT) malware strain designed to target Israeli water treatment and desalination facilities, with a clear emphasis on sabotage rather than simple IT disruption. Darktrace’s investigation found that ZionSiphon restricts itself to hardcoded IPv4 ranges that map to Israeli network space, such as 2.52.0.0–2.55.255.255, 79.176.0.0–79.191.255.255, and 212.150.0.0–212.150.255.255. The malware […]</p>
<p>The post <a href="https://gbhackers.com/zionsiphon-hits-israeli-water/">ZionSiphon Hits Israeli Water Systems With OT Sabotage Malware</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[New ZionSiphon Malware Discovered Targeting Israeli Water Systems]]></title>
<description><![CDATA[Researchers at Darktrace have identified ZionSiphon, a new malware targeting Israeli water treatment plants. Learn how this OT-focused…]]></description>
<link>https://tsecurity.de/de/3441743/it-security-nachrichten/new-zionsiphon-malware-discovered-targeting-israeli-water-systems/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3441743/it-security-nachrichten/new-zionsiphon-malware-discovered-targeting-israeli-water-systems/</guid>
<pubDate>Fri, 17 Apr 2026 13:07:08 +0200</pubDate>
<content:encoded><![CDATA[Researchers at Darktrace have identified ZionSiphon, a new malware targeting Israeli water treatment plants. Learn how this OT-focused…]]></content:encoded>
</item>
<item>
<title><![CDATA[New ZionSiphon Malware Discovered Targeting Israeli Water Systems]]></title>
<description><![CDATA[Researchers at Darktrace have identified ZionSiphon, a new malware targeting Israeli water treatment plants. Learn how this OT-focused… This article has been indexed from Hackread – Cybersecurity News, Data Breaches, AI and More Read the original article: New ZionSiphon Malware…
Read more →
The p...]]></description>
<link>https://tsecurity.de/de/3441735/it-security-nachrichten/new-zionsiphon-malware-discovered-targeting-israeli-water-systems/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3441735/it-security-nachrichten/new-zionsiphon-malware-discovered-targeting-israeli-water-systems/</guid>
<pubDate>Fri, 17 Apr 2026 13:06:57 +0200</pubDate>
<content:encoded><![CDATA[<p>Researchers at Darktrace have identified ZionSiphon, a new malware targeting Israeli water treatment plants. Learn how this OT-focused… This article has been indexed from Hackread – Cybersecurity News, Data Breaches, AI and More Read the original article: New ZionSiphon Malware…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/new-zionsiphon-malware-discovered-targeting-israeli-water-systems/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/new-zionsiphon-malware-discovered-targeting-israeli-water-systems/">New ZionSiphon Malware Discovered Targeting Israeli Water Systems</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Inside ZionSiphon: politically driven malware aims at Israeli water systems]]></title>
<description><![CDATA[New ZionSiphon malware targets water systems, and allows attackers to alter pressure and chlorine levels. A flaw makes it ineffective for now. Darktrace analyzed ZionSiphon, a new malware designed to target water treatment and desalination systems, which aims to disrupt…
Read more →
The post Insi...]]></description>
<link>https://tsecurity.de/de/3441623/it-security-nachrichten/inside-zionsiphon-politically-driven-malware-aims-at-israeli-water-systems/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3441623/it-security-nachrichten/inside-zionsiphon-politically-driven-malware-aims-at-israeli-water-systems/</guid>
<pubDate>Fri, 17 Apr 2026 12:22:57 +0200</pubDate>
<content:encoded><![CDATA[<p>New ZionSiphon malware targets water systems, and allows attackers to alter pressure and chlorine levels. A flaw makes it ineffective for now. Darktrace analyzed ZionSiphon, a new malware designed to target water treatment and desalination systems, which aims to disrupt…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/inside-zionsiphon-politically-driven-malware-aims-at-israeli-water-systems/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/inside-zionsiphon-politically-driven-malware-aims-at-israeli-water-systems/">Inside ZionSiphon: politically driven malware aims at Israeli water systems</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Inside ZionSiphon: politically driven malware aims at Israeli water systems]]></title>
<description><![CDATA[New ZionSiphon malware targets water systems, and allows attackers to alter pressure and chlorine levels. A flaw makes it ineffective for now. Darktrace analyzed ZionSiphon, a new malware designed to target water treatment and desalination systems, which aims to disrupt operations by altering hyd...]]></description>
<link>https://tsecurity.de/de/3441535/it-security-nachrichten/inside-zionsiphon-politically-driven-malware-aims-at-israeli-water-systems/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3441535/it-security-nachrichten/inside-zionsiphon-politically-driven-malware-aims-at-israeli-water-systems/</guid>
<pubDate>Fri, 17 Apr 2026 12:07:48 +0200</pubDate>
<content:encoded><![CDATA[New ZionSiphon malware targets water systems, and allows attackers to alter pressure and chlorine levels. A flaw makes it ineffective for now. Darktrace analyzed ZionSiphon, a new malware designed to target water treatment and desalination systems, which aims to disrupt operations by altering hydraulic pressure and increasing chlorine levels to unsafe levels. The malware combines […]]]></content:encoded>
</item>
<item>
<title><![CDATA[Cybersicherheit: Millionenauftrag für Linzer Kontron - Oberösterreichische Nachrichten]]></title>
<description><![CDATA[LINZ. Der börsenotierte Linzer Softwarekonzern Kontron hat sich mit Darktrace, einem weltweit führenden Anbieter KI-gestützter Cyberabwehr, ...]]></description>
<link>https://tsecurity.de/de/3432609/it-security-nachrichten/cybersicherheit-millionenauftrag-fuer-linzer-kontron-oberoesterreichische-nachrichten/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3432609/it-security-nachrichten/cybersicherheit-millionenauftrag-fuer-linzer-kontron-oberoesterreichische-nachrichten/</guid>
<pubDate>Tue, 14 Apr 2026 17:51:38 +0200</pubDate>
<content:encoded><![CDATA[LINZ. Der börsenotierte Linzer Softwarekonzern Kontron hat sich mit Darktrace, einem weltweit führenden Anbieter KI-gestützter Cyberabwehr, ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Wie Fake-Startups systematisch Krypto-Wallets plündern]]></title>
<description><![CDATA[Professionelle Websites, verifizierte Social-Media-Profile, öffentlicher Git­Hub-Code: Fake-Startups wie „Eternal Decay“ inszenieren sich als seriöse Web3-Unternehmen. Über vermeintliche Beta-Tests verbreiten sie Malware, die gezielt Krypto-Wallets leert. Darktrace analysiert die Kampagne, die se...]]></description>
<link>https://tsecurity.de/de/3430941/it-security-nachrichten/wie-fake-startups-systematisch-krypto-wallets-pluendern/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3430941/it-security-nachrichten/wie-fake-startups-systematisch-krypto-wallets-pluendern/</guid>
<pubDate>Tue, 14 Apr 2026 08:38:46 +0200</pubDate>
<content:encoded><![CDATA[Professionelle Websites, verifizierte Social-Media-Profile, öffentlicher Git­Hub-Code: Fake-Startups wie „Eternal Decay“ inszenieren sich als seriöse Web3-Unternehmen. Über vermeintliche Beta-Tests verbreiten sie Malware, die gezielt Krypto-Wallets leert. Darktrace analysiert die Kampagne, die seit Ende 2024 aktiv ist und mit hohem Aufwand operiert.]]></content:encoded>
</item>
<item>
<title><![CDATA[New Chaos Malware Variant Expands to Cloud Targets, Introduces Proxy Capability]]></title>
<description><![CDATA[  A newly observed version of the Chaos malware is now targeting poorly secured cloud environments, indicating a defining shift in how this threat is being deployed and scaled. According to analysis by Darktrace, the malware is increasingly exploiting misconfigured…
Read more →
The post New Chaos...]]></description>
<link>https://tsecurity.de/de/3421707/it-security-nachrichten/new-chaos-malware-variant-expands-to-cloud-targets-introduces-proxy-capability/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3421707/it-security-nachrichten/new-chaos-malware-variant-expands-to-cloud-targets-introduces-proxy-capability/</guid>
<pubDate>Thu, 09 Apr 2026 22:37:14 +0200</pubDate>
<content:encoded><![CDATA[<p>  A newly observed version of the Chaos malware is now targeting poorly secured cloud environments, indicating a defining shift in how this threat is being deployed and scaled. According to analysis by Darktrace, the malware is increasingly exploiting misconfigured…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/new-chaos-malware-variant-expands-to-cloud-targets-introduces-proxy-capability/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/new-chaos-malware-variant-expands-to-cloud-targets-introduces-proxy-capability/">New Chaos Malware Variant Expands to Cloud Targets, Introduces Proxy Capability</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[New Chaos Variant Targets Misconfigured Cloud Deployments, Adds SOCKS Proxy]]></title>
<description><![CDATA[Cybersecurity researchers have flagged a new variant ofmalware called Chaosthat’scapable of hitting misconfigured cloud deployments, marking an expansion of the botnet’s targeting infrastructure. “Chaos malware is increasingly targeting misconfigured cloud deployments, expanding beyond its tradit...]]></description>
<link>https://tsecurity.de/de/3418445/it-security-nachrichten/new-chaos-variant-targets-misconfigured-cloud-deployments-adds-socks-proxy/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3418445/it-security-nachrichten/new-chaos-variant-targets-misconfigured-cloud-deployments-adds-socks-proxy/</guid>
<pubDate>Wed, 08 Apr 2026 21:20:06 +0200</pubDate>
<content:encoded><![CDATA[<p>Cybersecurity researchers have flagged a new variant ofmalware called Chaosthat’scapable of hitting misconfigured cloud deployments, marking an expansion of the botnet’s targeting infrastructure. “Chaos malware is increasingly targeting misconfigured cloud deployments, expanding beyond its traditional focus on routers and edge devices,” Darktrace said in…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/new-chaos-variant-targets-misconfigured-cloud-deployments-adds-socks-proxy/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/new-chaos-variant-targets-misconfigured-cloud-deployments-adds-socks-proxy/">New Chaos Variant Targets Misconfigured Cloud Deployments, Adds SOCKS Proxy</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[New Chaos Variant Targets Misconfigured Cloud Deployments, Adds SOCKS Proxy]]></title>
<description><![CDATA[Cybersecurity researchers have flagged a new variant ofmalware called Chaosthat'scapable of hitting misconfigured cloud deployments, marking an expansion of the botnet's targeting infrastructure.
"Chaos malware is increasingly targeting misconfigured cloud deployments, expanding beyond its tradit...]]></description>
<link>https://tsecurity.de/de/3418381/it-security-nachrichten/new-chaos-variant-targets-misconfigured-cloud-deployments-adds-socks-proxy/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3418381/it-security-nachrichten/new-chaos-variant-targets-misconfigured-cloud-deployments-adds-socks-proxy/</guid>
<pubDate>Wed, 08 Apr 2026 20:52:12 +0200</pubDate>
<content:encoded><![CDATA[Cybersecurity researchers have flagged a new variant ofmalware called Chaosthat'scapable of hitting misconfigured cloud deployments, marking an expansion of the botnet's targeting infrastructure.
"Chaos malware is increasingly targeting misconfigured cloud deployments, expanding beyond its traditional focus on routers and edge devices," Darktrace said in a new report.]]></content:encoded>
</item>
<item>
<title><![CDATA[Chaos malware expands from routers to Linux cloud servers]]></title>
<description><![CDATA[Chaos, Go-based malware first documented by Lumen’s Black Lotus Labs, has historically targeted routers and edge devices. A new variant observed in March 2026 shows the malware operating against misconfigured Linux cloud servers, a category of infrastructure the botnet had not previously prioriti...]]></description>
<link>https://tsecurity.de/de/3416737/it-security-nachrichten/chaos-malware-expands-from-routers-to-linux-cloud-servers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3416737/it-security-nachrichten/chaos-malware-expands-from-routers-to-linux-cloud-servers/</guid>
<pubDate>Wed, 08 Apr 2026 11:37:23 +0200</pubDate>
<content:encoded><![CDATA[<p>Chaos, Go-based malware first documented by Lumen’s Black Lotus Labs, has historically targeted routers and edge devices. A new variant observed in March 2026 shows the malware operating against misconfigured Linux cloud servers, a category of infrastructure the botnet had not previously prioritized. Darktrace’s malware research team documented the compromise through its CloudyPots program, a global honeypot network the company runs to capture attacker behavior across a range of services and cloud platforms. One honeypot … <a href="https://www.helpnetsecurity.com/2026/04/08/chaos-malware-cloud-misconfigured-servers/" rel="nofollow">More <span class="meta-nav">→</span></a></p>
<p>The post <a href="https://www.helpnetsecurity.com/2026/04/08/chaos-malware-cloud-misconfigured-servers/">Chaos malware expands from routers to Linux cloud servers</a> appeared first on <a href="https://www.helpnetsecurity.com/">Help Net Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Generative KI sicher nutzen: Transparenz statt Blindflug - BigData-Insider]]></title>
<description><![CDATA[Der aktuelle State of AI Cybersecurity Report 2026 von Darktrace zeigt, wie schnell die Einführung von KI die Unternehmensumgebungen verändert.]]></description>
<link>https://tsecurity.de/de/3416400/it-security-nachrichten/generative-ki-sicher-nutzen-transparenz-statt-blindflug-bigdata-insider/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3416400/it-security-nachrichten/generative-ki-sicher-nutzen-transparenz-statt-blindflug-bigdata-insider/</guid>
<pubDate>Wed, 08 Apr 2026 09:22:05 +0200</pubDate>
<content:encoded><![CDATA[Der aktuelle State of AI Cybersecurity Report 2026 von Darktrace zeigt, wie schnell die Einführung von KI die Unternehmensumgebungen verändert.]]></content:encoded>
</item>
<item>
<title><![CDATA[Salt Typhoon: Systematischer und verdeckter Angriff]]></title>
<description><![CDATA[Eine Analyse von Darktrace zeigt, wie die APT-Gruppe Salt Typhoon mit Zero-Day-Exploits, DLL-Sideloading und verschleierter Kommunikation westliche Netze unterwandert. Der Fall verdeutlicht, warum klassische Abwehrmechanismen an ihre Grenzen stoßen.]]></description>
<link>https://tsecurity.de/de/3410809/it-security-nachrichten/salt-typhoon-systematischer-und-verdeckter-angriff/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3410809/it-security-nachrichten/salt-typhoon-systematischer-und-verdeckter-angriff/</guid>
<pubDate>Mon, 06 Apr 2026 12:07:27 +0200</pubDate>
<content:encoded><![CDATA[Eine Analyse von Darktrace zeigt, wie die APT-Gruppe Salt Typhoon mit Zero-Day-Exploits, DLL-Sideloading und verschleierter Kommunikation westliche Netze unterwandert. Der Fall verdeutlicht, warum klassische Abwehrmechanismen an ihre Grenzen stoßen.]]></content:encoded>
</item>
<item>
<title><![CDATA[Security awareness is not a control: Rethinking human risk in enterprise security]]></title>
<description><![CDATA[Organizations have been responding to phishing, business email compromise, and credential theft in essentially the same manner for over ten years. They essentially follow a playbook that involves investing in awareness training, running phishing simulations, and requiring employees to complete an...]]></description>
<link>https://tsecurity.de/de/3398655/it-security-nachrichten/security-awareness-is-not-a-control-rethinking-human-risk-in-enterprise-security/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3398655/it-security-nachrichten/security-awareness-is-not-a-control-rethinking-human-risk-in-enterprise-security/</guid>
<pubDate>Wed, 01 Apr 2026 11:07:12 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Organizations have been responding to phishing, business email compromise, and credential theft in essentially the same manner for over ten years. They essentially follow a playbook that involves investing in awareness training, running phishing simulations, and requiring employees to complete annual security modules. The reason behind this is simple and the reasoning behind these efforts is straightforward: if people can better spot malicious emails and recognize malicious activity, incidents will decrease.</p>



<p>Yet, the amount of money lost because of business email compromise keeps rising. Credential harvesting is still successful. Conventional multi-factor authentication is frequently circumvented by <a href="https://www.darktrace.com/blog/mfa-under-attack-aitm-phishing-kits-abusing-legitimate-services">adversary-in-the-middle phishing kits</a>. Under duress, senior executives, including seasoned finance leaders, continue to approve fraudulent payments.</p>



<p>A deeper misclassification in enterprise security strategy is shown in this persistence. Although awareness is an educational measure that promotes culture rather than imposes results, it has been viewed as a control. This distinction has important ramifications for how businesses evaluate and control risk.</p>



<h2 class="wp-block-heading">The core misunderstanding</h2>



<p>A true <a href="https://csrc.nist.gov/glossary/term/security_control">security control</a> prevents, detects, or limits an outcome regardless of what an individual does, knows or does not know. Conditional access rules, for instance, do not depend on an employee having a good day, and network segmentation does not depend on an employee remembering a policy. Likewise, Segregation of duties in finance exists precisely to ensure that no single individual can independently authorize high-risk transactions. These mechanisms are engineered to constrain risk structurally rather than depend on behavioral perfection.</p>



<p>Security awareness has its own purpose to influence behavior through the improvement of human judgment in situations that deal with time pressure and often incomplete information. Although these initiatives can lessen the possibility of poor decisions, they are unable to ensure consistent results for a varied workforce with <a href="https://www.sciencedirect.com/topics/social-sciences/individual-differences">individual differences </a>working in a variety of environments. Human performance is inherently variable, especially when exposed to different conditions, and training does not eliminate that variability.</p>



<p>When organizations term security awareness as a “layer of defense,” they implicitly place it alongside technical and procedural safeguards, which can distort how risk is understood and assigned. Responsibility for incidents thus shifts subtly toward individuals, especially when an employee clicks a malicious link or authorizes a fraudulent request. The resulting narrative often emphasizes human error rather than examining whether the surrounding system allowed a single, foreseeable mistake to create material impact.</p>



<p>Examining whether the organization’s controls were made to foresee anticipated human mistakes and limit their effects before they cause enterprise-level harm is a more constructive line of inquiry. </p>



<h2 class="wp-block-heading">The predictability of human error</h2>



<p>Human error is sometimes viewed as an exception in security incident conversations, as if a breach happened because someone made a mistake that should have been prevented. Human error is a constant in complex systems, especially in huge organizations where everyday operations are shaped by scale, pace, and conflicting agendas. The pertinent question is whether the surrounding environment has been constructed with the inevitable occurrence of mistakes in mind, rather than whether mistakes will occur at all.</p>



<p>Modern social engineering campaigns reflect a sophisticated understanding of how organizations function. Attackers study and understand reporting lines, financial processes, vendor relationships, and executive communication styles, sometimes gleaned from previously compromised accounts in similar industries. They time their messages to coincide with legitimate business activity and plan these messages to align with travel schedules, invoice payments and quarter-end reporting pressure. In many business email compromise cases, there is no malware involved and no technical exploit in the traditional sense of it and attacks are successful because it takes advantage of the trust that is ingrained in regular operations blended in seamlessly with established routines.</p>



<p>Under such conditions, expecting flawless human performance is unrealistic. Employees manage high volumes of communication while also combating deadlines and performance expectations. Senior leaders frequently make decisions with incomplete information, balancing urgency against risk to keep the business running. When a request appears in line with organizational standards and past experience, even highly skilled individuals may misunderstand it. These mistakes are a natural result of cognitive load, environmental clues, and institutional dynamics, not necessarily proof of carelessness.</p>



<p>This reality is acknowledged by high-risk industries like aviation and healthcare, which create multi-layered protections to stop a single error from turning into a disaster. Checklists, redundancy, and cross-verification processes are embedded as part of organizational pipelines to ensure that systems remain safe even when individuals are imperfect. On the other hand, the same discipline has not always been used in enterprise cybersecurity. A single compromised credential or a single configuration error, exemplified in <a href="https://www.bbc.co.uk/news/articles/cpe3zgznwjno">the CrowdStrike outrage</a>,  can still result in serious operational or financial harm in many settings. When that degree of fragility is present, the system’s authority distribution and error-absorbing capabilities become more pertinent than individual behavior.</p>



<h2 class="wp-block-heading">Awareness cannot function as a primary safeguard</h2>



<p>There are structural limitations that prevent awareness from serving as a dependable control. First, cognitive load and decision fatigue are unavoidable in complex organizations. Even experienced professionals make mistakes due to reduced scrutiny when under pressure and awareness training does not eliminate this human reality. Awareness training may increase general suspicion, but it cannot eliminate the reality that individuals must constantly triage information under time pressure and occasional lapses in judgment are statistically inevitable as a result.</p>



<p>Secondly, organizational dynamics further complicate the picture, especially in traditional societies where this is strongly upheld. Hierarchy and perceived authority are exploited in many successful business email compromise incidents as a result. Requests that seem to come from senior executives are implicitly urgent and significant for the organization. Employees are frequently trained to support executive instructions rather than impede them, particularly when it comes to urgent financial concerns, which could slow down business processes.</p>



<p>Lastly, the widespread adoption of multi-factor authentication has also contributed to an inflated sense of security. While MFA greatly improves security over password-only settings, not all implementations are impervious to modern attack methods. Push fatigue attacks take advantage of routine approval patterns, adversary-in-the-middle frameworks can steal and replay session tokens, and <a href="https://www.huntress.com/blog/oh-auth-2-0-device-code-phishing-in-google-cloud-and-azure">device code / OAuth consent phishing</a> can provide continuous access without the need for conventional credential theft. In these cases, there is a likelihood employees comply with established security procedures and still be compromised because the architectural design allows it.</p>



<p>When combined, these reasons show why awareness is not a reliable main protection. It can strengthen best practices and lower risk at the edges, but it cannot make up for shoddy identity architecture, brittle finance procedures, or inadequate monitoring.</p>



<h2 class="wp-block-heading">Treating human risk as a design constraint</h2>



<p>A more pruned approach reframes human risk as an engineering consideration as opposed to a behavioral flaw. Security leaders should assess which decisions entail a disproportionate amount of risk when carried out in isolation, rather than asking how to train staff to recognize every potential phishing variant.</p>



<p>Salient questions in this regard include:</p>



<ul start="1" class="wp-block-list">
<li>Should a single email request ever be sufficient to initiate a high-value transfer?</li>



<li>Are payment instruction changes subject to enforced out-of-band verification?</li>



<li>Does identity infrastructure continuously validate session integrity?</li>



<li>Are anomalous financial behaviors detected in real time?</li>
</ul>



<p>This shift moves the focus from persuading individuals to behave perfectly toward building systems that remain resilient when they do not.</p>



<h2 class="wp-block-heading">What structural controls should look like</h2>



<p>An enterprise strategy that effectively tackles human-centric threats includes defenses that function without constant monitoring. <a href="https://it.cornell.edu/secure-connect/deviceboundkey">Device-bound passkeys</a> and hardware-backed credentials are examples of phishing-resistant authentication techniques that lessen vulnerability to push-based manipulation and token interception. Compared to static MFA prompts alone, conditional access policies that also assess device health and onboarding status, geolocation anomalies, and behavioral risk signals offer greater assurance.</p>



<p>In the same vein, financial workflows should embed <a href="https://csf.tools/reference/nist-sp-800-53/r5/ac/ac-5/">separation of duties and enforced verification</a>. Secondary validation should be required through separate channels for high-value transactions, vendor banking changes, and urgent payment requests. Systems for tracking transactions should also be able to spot anomalous payment amounts or departures from historical trends.</p>



<p>Particular consideration should also be given to identity telemetry. Persistence tactics frequently employed in business email compromise campaigns can be found by keeping an eye on mailbox rules, atypical travel, OAuth grants, privileged role assignments, and session oddities. Using <a href="https://learn.microsoft.com/en-us/entra/id-governance/privileged-identity-management/pim-configure">Privileged Identity Management</a> solutions, privileged access should be time-bound and approval-based to reduce the blast radius of credential misuse. Although human error cannot be eliminated, these precautions greatly lessen the chance that a single error will result in severe material loss.</p>



<h2 class="wp-block-heading">From blame game to architecture</h2>



<p>It makes sense that organizations would choose to gravitate towards awareness-raising campaigns. They are visible, often reasonably priced when bundled as part of existing security tooling and quantifiable. On the other hand, more funding and cross-functional cooperation are needed for architectural redesign, identity modernization, and workflow reorganization.</p>



<p>Threat actors, however, are becoming more adept at taking advantage of human behavior patterns that are predictable in current corporate procedures. They only require people to be human because they comprehend the urgency, trust, and operational complexity that frequently accompany working in time-sensitive professions, high-pressure conditions, and the ensuing complacency.</p>



<p>The rational response is to assume imperfection and build accordingly.</p>



<h2 class="wp-block-heading"><a></a>A more honest assessment of systemic risk</h2>



<p>Security awareness remains an important component of organizational culture. Employees should understand common attack patterns and feel empowered to report suspicious activity. However, awareness should be viewed as a supporting measure rather than a primary safeguard.</p>



<p>When a single decision can still trigger substantial financial or operational damage, the organization’s exposure is rooted in design. Resilient enterprises acknowledge that human error is inevitable and ensure that their identity architecture, financial controls, and monitoring capabilities are robust enough to absorb it.</p>



<p>Reframing awareness in this way does not diminish its value. It places it in the correct category and forces a more honest assessment of systemic risk. Until that shift occurs, many organizations will continue to invest heavily in training while leaving structural weaknesses intact, and attackers will continue to exploit the gap between education and engineering.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.<br><a href="https://www.csoonline.com/expert-contributor-network/">Want to join?</a></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[10 essenzielle Maßnahmen für physische Sicherheit]]></title>
<description><![CDATA[Wenn physische Security nur immer so simpel umzusetzen wäre… Foto: Leremy | shutterstock.comObwohl CISOs im Allgemeinen eher selten mit dem gesamten Spektrum der Gesundheits- und Arbeitssicherheitsbelange betraut sind, spielen sie diesbezüglich doch eine wichtige, strategische Rolle – insbesonder...]]></description>
<link>https://tsecurity.de/de/3382028/it-security-nachrichten/10-essenzielle-massnahmen-fuer-physische-sicherheit/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3382028/it-security-nachrichten/10-essenzielle-massnahmen-fuer-physische-sicherheit/</guid>
<pubDate>Thu, 26 Mar 2026 05:06:11 +0100</pubDate>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img decoding="async" alt="Wenn physische Security nur immer so simpel umzusetzen wäre..." title="Wenn physische Security nur immer so simpel umzusetzen wäre..." src="https://images.computerwoche.de/bdb/3376739/1200x.jpg" width="1200" loading="lazy"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Wenn physische Security nur immer so simpel umzusetzen wäre…</p></figcaption></figure><p class="imageCredit"> Foto: Leremy | shutterstock.com</p></div><p>Obwohl <a href="https://www.csoonline.com/article/3492570/security-leadership-material-5-anzeichen-dass-sie-nicht-zum-ciso-taugen.html" title="CISOs" target="_blank">CISOs</a> im Allgemeinen eher selten mit dem gesamten Spektrum der Gesundheits- und Arbeitssicherheitsbelange betraut sind, spielen sie diesbezüglich doch eine wichtige, strategische Rolle – insbesondere, wenn es um physische Sicherheitssysteme mit IT-Anbindung und den direkten Zugang zu <a href="https://www.csoonline.com/article/3493004/report-von-xm-cyber-geschaftskritische-assets-in-gefahr.html" title="IT-Assets" target="_blank">IT-Assets</a> geht. Die wesentlichen limitierenden Faktoren für CISOs sind dabei in aller Regel:</p>



<ul class="wp-block-list">
<li><p>das Budget sowie</p></li>



<li><p>nicht eindeutige Verantwortlichkeiten.</p></li>
</ul>



<p>In diesem Artikel stellen wir Ihnen zehn essenzielle Maßnahmen für (mehr) physische Sicherheit vor, die CISOs auf dem Zettel haben sollten. Zunächst werfen wir jedoch einen kurzen Blick darauf, wie sich physische Security definiert – und warum sie von entscheidender Bedeutung für Unternehmen ist.</p>



<h2 class="wp-block-heading">Warum physische Security wichtig ist</h2>



<p>Der Begriff der physischen Sicherheit umfasst per Definition den Schutz von Personen, Eigentum und physischen Assets vor unberechtigtem Zugriff, Diebstahl und sonstigen Handlungen die zu Schaden oder Verlust führen. Dieser Bereich wird allzu oft zugunsten der Cybersicherheit vernachlässigt.</p>



<p>Für CISOs ist der Bereich vor allem deshalb so wichtig, weil die allermeisten modernen, physischen Sicherheitssysteme respektive -kontrollen auf irgendeine Art und Weise mit der IT verknüpft sind – von Badges und Keycards bis hin zur Videoüberwachung. Kommt es zu einem unberechtigten (physischen) Zugriff, können daraus in der Folge zudem auch <a href="https://www.csoonline.com/article/3577944/diese-unternehmen-hats-schon-erwischt.html" title="Cyberangriffe und Data Breaches" target="_blank">Cyberangriffe und Data Breaches</a> erwachsen. Es sollte deshalb im Interesse eines jeden Sicherheitsentscheiders liegen, entsprechende Vorkehrungen zu treffen, um den Zugriff auf diese Assets zu kontrollieren.</p>



<p>Das soll (und kann) nicht heißen, CISOs mit sämtlichen Tasks physischer Security zu betrauen. Zwar funktioniert es im Fall einiger kleinerer Unternehmen, die Rolle des CISO und des CSO zusammenzulegen – für viele große Unternehmen ist das jedoch keine Option, wie <a href="https://www.linkedin.com/in/max-shier-741426183" target="_blank" rel="noreferrer noopener">Max Shier</a>, ehemals CISO beim Cyberrisk-Spezialisten Optiv, erklärt: “Wenn behördliche Auflagen bestehen oder es um größere Unternehmen geht, ergibt es unter Umständen keinen Sinn, die Bereiche Cybersecurity und physische Sicherheit zusammenzulegen. Die resultierenden Verantwortlichkeiten – etwa, sich um einen Wachdienst für Produktionsanlagen oder Bodyguards für Führungskräfte zu kümmern -, könnten Cybersecurity-Teams je nach Auslastung und Kapazität <a title="schnell überfordern" href="https://www.csoonline.com/article/3495078/gestresste-security-mitarbeiter-droht-eine-kundigungswelle.html" target="_blank">schnell überfordern</a>.”</p>



<p>Sollte diese Option auch für Sie entfallen, weiß <a href="https://www.radware.com/blog/author/htaylor/" target="_blank" rel="noreferrer noopener">Howard Taylor</a>, CISO beim Security-Dienstleister Radware, was zu tun ist: “Dann ist die Kommunikation und Koordination mit den physischen Sicherheitsteams für CISOs entscheidend, um ihre Ziele zu erreichen. Diese sollten in die Planungsprozesse für <a title="Business Continuity" href="https://www.csoonline.com/article/3493151/resilienz-business-continuity-planung-ist-alles.html" target="_blank">Business Continuity</a>, <a title="Disaster Recovery" href="https://www.csoonline.com/article/3495970/die-besten-cyber-recovery-anbieter.html" target="_blank">Disaster Recovery</a> sowie physische Anlagen und Einrichtungen einbezogen werden. Zusätzlich muss auch sichergestellt sein, dass die resultierenden, physischen Maßnahmen aus rechtlicher Sicht einwandfrei sind – etwa, dass Aufnahmen von Überwachungskameras keine Datenschutzregularien verletzen.”</p>



<h2 class="wp-block-heading">Die Top Ten physischer Sicherheitsmaßnahmen</h2>



<p>Ganz unabhängig von der jeweiligen Organisationsstruktur sollten CISOs mit allen Stakeholdern im Bereich physische Sicherheit kollaborieren. Folgende zehn Maßnahmen sollten Sie diesbezüglich vor allem auf dem Schirm haben.</p>



<p><strong>1. IT-Einrichtungen und Rechenzentren härten</strong></p>



<p>Rechenzentren, sensible IT-Einrichtungen und Computerräume in Mehrzweckbüros sind offensichtliche Bereiche, auf die CISOs ihr Augenmerk legen sollten, um die Kontrolle über den physischen Zugang zu gewährleisten. <a href="https://www.linkedin.com/in/davidortizciso" target="_blank" rel="noreferrer noopener">David Ortiz</a>, CISO beim Konsumgüter-Unternehmen Church &amp; Dwight, spezifiziert: “Sicherheitsentscheider sollten dafür Sorge tragen, dass der Zugang zu sämtlichen Räumen mit technischem Equipment auf die Personen beschränkt wird, <a title="die ihn benötigen" href="https://www.csoonline.com/article/3493543/was-ist-privileged-access-management.html" target="_blank">die ihn benötigen</a>. Zudem sollten Auftragnehmer ausschließlich in Begleitung Zugang zu solchen Räumlichkeiten erhalten. Idealerweise wird der Zugang protokolliert und täglich überprüft.”</p>



<p>Natürlich sollten die zu ergreifenden Maßnahmen je nach Einrichtung und ihrer Risikolage variiert und angepasst werden, empfiehlt <a href="https://www.darktrace.com/people/justin-fier" target="_blank" rel="noreferrer noopener">Justin Fier</a>, Senior Vice President of Red Team Operations beim Sicherheitsanbieter Darktrace: “Sämtliche Einrichtungen, die kritische Informationen beherbergen, sollten strengere Sicherheitskontrollen aufweisen, als solche die für weniger sensible Assets genutzt werden. CISOs müssen deshalb in erster Linie wissen, welche Daten und Ressourcen wo gespeichert und genutzt werden, das Risiko bestimmen, das im Fall eines unberechtigten Eindringens ensteht – und anschließend die physischen Sicherheitsmaßnahmen bei Bedarf entsprechend verstärken.”</p>



<p><strong>2. Risiken im Büroalltag erkennen</strong></p>



<p>Um sich Zugang zu Unternehmensnetzwerken zu verschaffen, nehmen kriminelle Angreifer auch ganz alltägliche Office-Settings ins Visier. Jeder Netzwerkanschluss könne so zu einem potenziellen Einfallstor in die IT-Umgebung werden, warnt <a href="https://www.linkedin.com/in/willbass" target="_blank" rel="noreferrer noopener">Will Bass</a>, Vice President Cybersecurity beim Rechenzentrumsspezialisten Flexential. Sein Rat an CISOs: “Setzen Sie sich intensiv mit der physischen Sicherheitsarchitektur und den Standards für alle Einrichtungen auseinander – unabhängig davon, ob es sich um sensible Facilities handelt oder nicht. Nur so können Sie sicherstellen, die richtigen <a title="Defense-in-Depth-Maßnahmen" href="https://www.csoonline.com/article/3492407/ot-security-so-schutzen-sie-ihre-industrieanlagen.html" target="_blank">Defense-in-Depth-Maßnahmen</a> einzusetzen und unbefugten, physischen Zugriff zu verhindern.”</p>



<p>Optiv-CISO Shier ergänzt, dass das auch in Zeiten von <a href="https://www.csoonline.com/article/3492755/incident-reporting-wie-sich-remote-work-auf-die-meldung-von-sicherheitsvorfallen-auswirkt.html" title="Remote- und Hybrid Work" target="_blank">Remote- und Hybrid Work</a> relevant sei: “Trotzdem die Büros in vielen Fällen inzwischen weniger frequentiert sind, müssen Sicherheitsentscheider gewährleisten, dass Bürogebäude mit angemessenen physischen Sicherheitskontrollen ausgestattet sind. Drahtlose Zugangspunkte, Zugangskontrollen mit Ausweisen und Videoüberwachung sind weiterhin relevant und sollten keinesfalls unter den Tisch fallen.”</p>



<p><strong>3. Laterale Bewegungen in physischen Räumen ausschließen</strong></p>



<p>Wenn es darum geht, den Zugang zu Unternehmen physisch abzusichern, sollten CISOs außerdem ein Augenmerk darauf legen, ob sich Angreifer lateral durch physische Sperrzonen bewegen können. <a href="https://bishopfox.com/authors/alethe-denis" target="_blank" rel="noreferrer noopener">Alethe Denis</a>, Senior Security Consultant beim Sicherheitsanbieter Bishop Fox, erklärt: “Hat sich ein Angreifer erst einmal Zugang zu Sperrbereichen verschafft, sinkt die Wahrscheinlichkeit aufzufliegen, drastisch. Schließlich gehen die allermeisten Menschen davon aus, dass Personen, die sich in Sperrbereichen aufhalten, zuvor eine Zugangskontrolle durchlaufen und bestanden haben.”</p>



<p>Ebenso wie Unternehmen <a href="https://www.csoonline.com/article/3491997/cyberresilienz-mikrosegmentierung-ruckt-in-den-fokus.html" title="Netzwerksegmentierung" target="_blank">Netzwerksegmentierung</a> und <a href="https://www.csoonline.com/article/3491851/was-ist-zero-trust.html" title="Zero-Trust-Prinzipien" target="_blank">Zero-Trust-Prinzipien</a> einsetzten, um Netzwerkressourcen zu schützen, sollten sie auch im Bereich physische Security vorgehen, fordert die Sicherheitsexpertin: “Im Idealfall verhindern Treppenhäuser und Aufzüge mit Authentifizierungserfordernis sowie aufmerksame Mitarbeiter, dass es zu ‘Tailgaiting’ und einem möglichen Schaden für das Unternehmen kommt.”</p>



<p><strong>4. Assets in Colocation- und Cloud-Umgebungen schützen</strong></p>



<p>Das Adlerauge der Sicherheitsentscheider ist aber nicht nur gefragt, wenn es um unternehmenseigene Lokalitäten geht. Auch <a href="https://www.computerwoche.de/article/2815781/so-funktioniert-ein-rechenzentrum.html" title="Colocation-Facilities oder -Rechenzentren" target="_blank">Colocation-Facilities oder -Rechenzentren</a> sollten diesbezüglich berücksichtigt werden, fordert Shier: “Sollten Sie zum Beispiel ein Rechenzentrum mit anderen Unternehmen teilen, tun Sie gut daran, auch einzelne Serverracks abzusichern – etwa mit integrierten Ausweislesegeräten. Zudem ist es essenziell, Rechenzentren mit Kameras, Wachpersonal und weiteren Kontrollmaßnahmen auszustatten.”</p>



<p>Selbst wenn die physische Handhabung von Systemen vollständig von der Organisation abstrahiert sei – wie bei Public-Cloud- oder SaaS-Ressourcen – müssten CISOs dennoch darauf achten, wie diese Systeme physisch kontrolliert werden, ist <a href="https://www.linkedin.com/in/mpedrick" target="_blank" rel="noreferrer noopener">Mike Pedrick</a>, Vice President of Cybersecurity Consulting beim Managed-Service-Provider Nuspire, überzeugt: “Solche Offerings entbinden CISOs nicht von ihrer Verantwortung. Wenn überhaupt, setzt es sie zusätzlich unter Druck, die Bedeutung von Verträgen und Service Level Agreements sowie den Wert eines erfolgreichen <a title="Audits" href="https://www.computerwoche.de/article/2761566/10-wege-in-die-it-audit-hoelle.html" target="_blank">Audits</a> durch Dritte zu schätzen.”</p>



<p><strong>5. Physische Cyber-Verbindungen analysieren</strong></p>



<p>CISOs, die in <a href="https://www.csoonline.com/article/3492064/it-sicherheit-in-kritis-unternehmen-unsichtbar-ist-unschutzbar.html" title="Kritis-Organisationen" target="_blank">Kritis-Organisationen</a> tätig sind, sollten sich nicht nur Gedanken darüber machen, wie sich physische Handlungen auf die Cyberumgebung auswirken können. Sie müssen auch dazu in der Lage sein, einzuschätzen, wie sich Aktivitäten im Cyberraum auf physische Umgebungen auswirken könnten.</p>



<p>“Cyberangriffe auf industrielle Umgebungen können eine erhebliche Bedrohung für die physische Sicherheit darstellen”, konstatiert <a href="https://cyolo.io/authors/almog-apirion" target="_blank" rel="noreferrer noopener">Almog Apirion</a>, Mitbegründer des Remote-Access-Anbieters Cyolo. Angesichts der heutigen Konvergenz von IT- und OT-Umgebungen sollten CISOs jedoch generell – also auch wenn sie nicht im Kritis-Bereich tätig sind – sämtliche Verbindungspunkte zwischen dem physischen und dem Cyberraum im Blick haben. So fielen zum Beispiel auch physische Industrieanlagen in den Bereich des CISO, wenn diese remote gesteuert respektive gemanagt werden könnten, gibt Apirion zu bedenken.</p>



<p><strong>6. IoT-Gerätschaften berücksichtigen</strong></p>



<p>Ein weiterer Aspekt der physischen Security steht mit <a href="https://www.csoonline.com/article/3492217/tuv-sud-diese-sicherheitsstandards-gelten-im-iot.html" title="IoT-Devices" target="_blank">IoT-Devices</a> in Zusammenhang. Flexential-Manager Bass erklärt: “IoT-Geräte befinden sich oft in frei zugänglichen Bereichen – wie etwa Überwachungskameras an der Außenseite eines Gebäudes. Der physische Zugang zu einem solchen Device ist ein potenzieller Einstiegspunkt. Zu verhindern, dass es dazu kommt, erfordert spezifische Schutzmaßnahmen und kann zur Herausforderung gereichen.”</p>



<p>Radware-CISO Taylor weist darauf hin, dass IoT-Gerätschaften wie OT-Systeme unter Umständen essenzielle Funktionen im physischen Raum steuern: “IoT-Systeme stellen eine Brücke zwischen Information und Aktion dar. Das macht sie im Rahmen physischer Angriffe zu einem attraktiven Ziel.” Der Sicherheitsentscheider appelliert deshalb, bei solchen Devices auf integrierte Monitoring-Funktionalitäten zu achten, um unbefugte Manipulationen von Software oder <a href="https://www.csoonline.com/article/3493727/proofpoint-report-zu-ta547-ki-gestutzte-malware-zielt-auf-deutsche-unternehmen.html" title="Malware-Befall" target="_blank">Malware-Befall</a> zu verhindern. Er ergänzt: “Für den Fall, dass jemand das IoT-Gerät zerstört, sollte zudem ein Notfallplan existieren.”</p>



<p><strong>7. Remote-Devices sperren</strong></p>



<p>Der Netzwerkrand hat sich im Laufe der Zeit verändert. Für CISOs bedeutet das: Sie müssen auf Bedrohungsmodelle und Kontrollmaßnahmen setzen, die im jeweiligen Kontext ihres Unternehmens Sinn ergeben und ein akzeptables Risikolevel realisieren. Dazu sollten Security Stakeholder und Supply-Chain-Partner zusammenarbeiten, um die Integrität der Hardware sicherzustellen und der Belegschaft Security Best Practices an die Hand zu geben.</p>



<p>Die neue Arbeitswelt hat dabei das Problem der verteilten Gerätschaften weiter verstärkt, wie Darktrace-Sicherheitsexperte Fier erklärt: “Wegen der Popularität von Remote und Hybrid Work wird es für CISOs zunehmend herausfordernder, physische IT-Ressourcen abzusichern. Schließlich nutzen die Mitarbeiter ihre Geräte an vielen verschiedenen Orten, was grundsätzlich das Risiko von Verlust, Diebstahl und Missbrauch erhöht. Das Homeoffice hilft an dieser Stelle auch nicht – in diesem Fall müssen CISOs sich auch damit befassen, wie etwa Router im Homeoffice abgesichert sind.” </p>



<p>Laut Fier nehmen kriminelle Hacker zunehmend solche Devices ins Visier. Sein Tipp, um Abhilfe zu schaffen: “Erwägen Sie, Personen, die für Angreifer von besonderem Interesse sein könnten – etwa <a href="https://www.csoonline.com/article/3491663/executive-cyber-protection-8-tools-um-entscheider-zu-schutzen.html" title="Führungskräfte und Administratoren" target="_blank">Führungskräfte und Administratoren</a> – mit speziell abgesicherter Hardware auszustatten.”</p>



<p><strong>8. Auf integrierte Access Control setzen</strong></p>



<p>Facility Teams sind für die alltäglichen Administrationsaufgaben in Zusammenhang mit physischen Zugangskontrollen – und der Gebäudesicherheit im Allgemeinen – zuständig. Diesbezüglich empfiehlt es sich allerdings, Sicherheitsentscheider einzubeziehen, wie Church &amp; Dwight CISO Ortiz vorschlägt: “Ein CISO sollte mit den Teams für physische Sicherheit zusammenarbeiten, um die Risikolage physischer Zugangskontrollen zu durchdringen. Das beinhaltet zum Beispiel zu wissen, ob der Zugang zu einer Einrichtung durch einen Empfangsbereich gesichert wird, per Badge erfolgt oder ob Videoüberwachungssysteme im Einsatz sind. Zudem sollten die Zugangssysteme auf verdächtige Aktivitäten überprüft werden.”</p>



<p>Der Manager ist davon überzeugt, dass CISOs auch einen Beitrag dazu leisten sollten, die <a href="https://www.csoonline.com/article/3495114/identity-access-managementdie-9-besten-iam-tools.html" title="Access-Control-Maßnahmen" target="_blank">Access-Control-Maßnahmen</a> mitzugestalten und in logische Zugangskontrollen zu integrieren. “Physische und logische Zugangskontrollen müssen Hand in Hand gehen. Das gilt insbesondere, wenn Zugangsdaten verlorengehen oder Mitarbeiter entlassen werden”, hält Ortiz fest.</p>



<p><strong>9. Überwachungssysteme (und deren Daten) absichern</strong></p>



<p>Videoüberwachungssysteme zu monitoren, fällt ebenfalls nicht ins native Zuständigkeitsgebiet von CISOs. Trotzdem sollten Sicherheitsentscheider ein Interesse daran haben, mitzureden, wenn es darum geht, diese Systeme zu designen und abzusichern. Schließlich sind sie in der Regel die Spezialisten, wenn es um <a href="https://www.csoonline.com/article/3492710/governance-risk-compliance-grc-adaptiver-ansatz-fur-das-risk-management.html" title="Datenschutz und Compliance" target="_blank">Datenschutz und Compliance</a> geht.</p>



<p>“In Anbetracht der unterschiedlichen Datenschutzbedenken, der gesetzlichen Verpflichtungen und anderer Aspekte, die mit einer Videoüberwachung einhergehen, sollten CISOs eine tragende Rolle einnehmen, wenn es darum geht, diese Systeme zu managen”, bestätigt Darktrace-Manager Fier und fügt hinzu: “Dazu müssen sie eng mit den relevanten Teams, beispielsweise der Rechtsabteilung, zusammenarbeiten und sicherstellen, dass die jeweils geltenden Gesetze und Datenschutzvorschriften eingehalten werden.”</p>



<p>Davon abgesehen seien moderne CCTV-Systeme auch Teil der IT-Umgebung – vergrößerten also die <a href="https://www.csoonline.com/article/3495294/schwachstellen-managen-die-6-besten-vulnerability-management-tools.html" title="Cyberangriffsfläche von Unternehmen" target="_blank">Cyberangriffsfläche von Unternehmen</a>, erklärt Jonathan Sword, Director der Security-Beratung Agility Cyber: “Es ist üblich, dass die Überwachungskameras von Bürogebäuden mit dem Hauptnetzwerk des Unternehmens verbunden sind. Sie sind also für andere Benutzer im Netzwerk einsehbar – und damit potenziell auch für Bedrohungsakteurre, die sich Zugang verschafft haben.”</p>



<p><strong>10. Überwachungsdaten bereithalten</strong></p>



<p>Essenziell ist für CISOs und ihre <a href="https://www.csoonline.com/article/3494979/was-ist-ein-incident-response-retainer.html" title="Incident-Response" target="_blank">Incident-Response</a>-Teams schließlich auch, jederzeit auf den Output dieser Überwachungssysteme zugreifen zu können. Das Ziel ist dabei, mit Hilfe der Überwachungsaufnahmen Aktivitäten in physischen Räumen schnell und einfach mit Aktionen logischer Systeme zu verknüpfen.</p>



<p>Bishop-Fox-Security-Expertin Denis erklärt: “Wenn es zu einem Angriff kommt, bei dem Daten gefährdet sein könnten und das Überwachungsmaterial Erkenntnisse zum Status der Attacke geben kann, sollte das IT-Sicherheitsteam auch auf diese Daten zugreifen können.” (fm)</p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[New critical Citrix NetScaler hole of similar severity to CitrixBleed2, says expert]]></title>
<description><![CDATA[A new critical vulnerability that is similar to the widely-exploited CitrixBleed and CitrixBleed2 holes should be patched in NetScaler devices immediately, say experts.



The hole, CVE-2026-3055, is an out-of-bounds read vulnerability in customer-managed NetScaler ADC and NetScaler Gateway devic...]]></description>
<link>https://tsecurity.de/de/3381867/it-security-nachrichten/new-critical-citrix-netscaler-hole-of-similar-severity-to-citrixbleed2-says-expert/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3381867/it-security-nachrichten/new-critical-citrix-netscaler-hole-of-similar-severity-to-citrixbleed2-says-expert/</guid>
<pubDate>Thu, 26 Mar 2026 01:21:28 +0100</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>A new critical vulnerability that is similar to the widely-exploited CitrixBleed and CitrixBleed2 holes should be patched in NetScaler devices immediately, say experts.</p>



<p>The hole, <a href="https://www.cve.org/CVERecord?id=CVE-2026-3055" target="_blank" rel="noreferrer noopener">CVE-2026-3055</a>, is an out-of-bounds read vulnerability in customer-managed NetScaler ADC and NetScaler Gateway devices configured as SAML IDP for approving identity and authentication. It’s rated at 9.3 in severity on the CVSS scale,</p>



<p>“The implications of leaving it unpatched are serious,” <a href="https://www.rapid7.com/blog/author/ryan-emmons/" target="_blank" rel="noreferrer noopener">Ryan Emmons</a>, staff security researcher at Rapid7, told <em>CSO</em> in an email, because the hole allows an unauthenticated remote attacker to leak potentially sensitive information from the appliance’s memory.</p>



<p>“This vulnerability is one that threat actors and researchers alike are paying attention to,” he said.</p>



<p>The vulnerability carries similar ramifications to 2023’s <a href="https://www.csoonline.com/article/657085/citrix-urges-immediate-patching-of-critically-vulnerable-product-lines.html" target="_blank">CitrixBleed</a> and 2025’s <a href="https://www.csoonline.com/article/4019802/exploit-details-released-for-citrix-bleed-2-flaw-affecting-netscaler.html" target="_blank">CitrixBleed2</a> memory leak vulnerabilities, Emmons added. Then, unauthenticated attackers with no existing level of access were able to steal credentials from business-critical Citrix NetScaler systems exposed to the public internet. </p>



<p>CitrixBleed2 enabled attackers to leak sensitive memory content by sending specially crafted HTTP requests to a vulnerable Citrix endpoint. When it was discovered last year, <a href="https://www.imperva.com/blog/cve-2025-5777-exposes-citrix-netscaler-to-dangerous-memory-leak-attacks/" target="_blank" rel="noreferrer noopener">researchers at Imperva </a>quickly saw threat actors trying to exploit the hole, detecting over 11.5 million attacks. </p>



<p>One that was successful involved the China-based group known to researchers as Salt Typhoon, which, <a href="https://www.darktrace.com/blog/salty-much-darktraces-view-on-a-recent-salt-typhoon-intrusion" target="_blank" rel="noreferrer noopener">according to Darktrace</a>, got past defenses at an unnamed European telecom provider by exploiting CitrixBleed2 and installed a backdoor.</p>



<p>“We expect that’s also what exploitation of this vulnerability facilitates,” he said “Initial access. With so much to potentially gain, it’s overwhelmingly likely that threat actors are actively working on developing an exploit for CVE-2026-3055, and we believe that exploitation in the wild is imminent.”</p>



<p>Affected are NetScaler ADC and NetScaler Gateway version 14.1 before 14.1-66.59; NetScaler ADC and NetScaler Gateway version 13.1 before 13.1-62.23; and NetScaler ADC FIPS and NDcPP before 13.1-37.262</p>



<p>In its <a href="https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696300&amp;articleURL=NetScaler_ADC_and_NetScaler_Gateway_Security_Bulletin_for_CVE_2026_3055_and_CVE_2026_4368" target="_blank" rel="noreferrer noopener">notice to customers</a>, Citrix “strongly urges affected customers” to install the relevant updated versions as soon as possible.</p>



<p>In the same notice, Citrix alerted admins to <a href="https://www.cve.org/CVERecord?id=CVE-2026-4368" target="_blank" rel="noreferrer noopener">CVE-2026-4368</a>, a race condition leading to user session mixup, rated at 7.7 on the CVSS scale, that applies to NetScaler ADC and NetScaler Gateway 14.1-66.54 devices.</p>



<h2 class="wp-block-heading">Prime targets</h2>



<p>NetScaler ADCs are application delivery controllers that optimize the delivery of web and traditional applications through load balancing and traffic management, while NetScaler Gateways are VPN solutions.</p>



<p>As categories, ADCs and VPNs are prime targets for threat actors because they are internet-facing. “Anything that organizations tend to heavily rely on and expose at the network edge makes for a juicy target in the eyes of attackers,” said Emmons. “That doesn’t mean these products are of poor quality, it just means that threat actors are spending a significant amount of time and energy finding and exploiting subtle flaws in them.”</p>



<p>Citrix says in its advisory that CVE-2026-3055 was found through product security testing, he pointed out, “which means they’re taking a proactive approach to find these bugs before threat actors do. That’s a great thing to see. Citrix products are incredibly popular and widely used, and they are routinely exposed to the public internet, so it’s of the utmost importance that the vendor is prioritizing security in this manner.”</p>



<p>Emmons said the best things defenders can do to protect ADCs and VPNs are to reduce their exposed attack surface, ensure vulnerability intelligence is available and effectively distributed, and prioritize patching the systems that matter most.</p>



<p>“Systems that don’t need to be exposed to the internet shouldn’t be,” he said. “Reducing public-facing attack surface is key, where possible. When that’s already in place, it’s vital to have early and accurate intelligence on vulnerabilities affecting products the organization relies on. A focus should be placed on ensuring important security advisories are highly visible to defending teams on the day of publication for triage.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Darktrace expands MSSP offering with AI-driven managed email security]]></title>
<description><![CDATA[Darktrace has launched its managed security service for MSSPs, enabling partners to deliver AI-native email security with real-time detection, investigation, and response across the email ecosystem. The launch is supported by updates to the Darktrace Defenders Partner Program designed to…
Read mo...]]></description>
<link>https://tsecurity.de/de/3376846/it-security-nachrichten/darktrace-expands-mssp-offering-with-ai-driven-managed-email-security/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3376846/it-security-nachrichten/darktrace-expands-mssp-offering-with-ai-driven-managed-email-security/</guid>
<pubDate>Tue, 24 Mar 2026 14:36:55 +0100</pubDate>
<content:encoded><![CDATA[<p>Darktrace has launched its managed security service for MSSPs, enabling partners to deliver AI-native email security with real-time detection, investigation, and response across the email ecosystem. The launch is supported by updates to the Darktrace Defenders Partner Program designed to…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/darktrace-expands-mssp-offering-with-ai-driven-managed-email-security/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/darktrace-expands-mssp-offering-with-ai-driven-managed-email-security/">Darktrace expands MSSP offering with AI-driven managed email security</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Darktrace expands MSSP offering with AI-driven managed email security]]></title>
<description><![CDATA[Darktrace has launched its managed security service for MSSPs, enabling partners to deliver AI-native email security with real-time detection, investigation, and response across the email ecosystem. The launch is supported by updates to the Darktrace Defenders Partner Program designed to provide ...]]></description>
<link>https://tsecurity.de/de/3376794/it-security-nachrichten/darktrace-expands-mssp-offering-with-ai-driven-managed-email-security/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3376794/it-security-nachrichten/darktrace-expands-mssp-offering-with-ai-driven-managed-email-security/</guid>
<pubDate>Tue, 24 Mar 2026 14:24:10 +0100</pubDate>
<content:encoded><![CDATA[<p>Darktrace has launched its managed security service for MSSPs, enabling partners to deliver AI-native email security with real-time detection, investigation, and response across the email ecosystem. The launch is supported by updates to the Darktrace Defenders Partner Program designed to provide flexibility and scalability for partners at every stage of their services maturity, helping them expand security offerings and deliver AI-native protection to customers around the world. Email threats continue to grow in sophistication as … <a href="https://www.helpnetsecurity.com/2026/03/24/darktrace-managed-email-security-offering/" rel="nofollow">More <span class="meta-nav">→</span></a></p>
<p>The post <a href="https://www.helpnetsecurity.com/2026/03/24/darktrace-managed-email-security-offering/">Darktrace expands MSSP offering with AI-driven managed email security</a> appeared first on <a href="https://www.helpnetsecurity.com/">Help Net Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Identitätsmissbrauch wird zum dominierenden Einfallstor]]></title>
<description><![CDATA[Kompromittierte Identitäten haben sich zum wichtigsten Einfallstor für Cyberangriffe entwickelt. Das zeigt der Annual Threat Report 2026 des KI-Cybersicherheitsanbieters Darktrace, der die globale Bedrohungslage des Jahres 2025 analysiert. ...]]></description>
<link>https://tsecurity.de/de/3371814/android-tipps/identitaetsmissbrauch-wird-zum-dominierenden-einfallstor/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3371814/android-tipps/identitaetsmissbrauch-wird-zum-dominierenden-einfallstor/</guid>
<pubDate>Mon, 23 Mar 2026 08:38:25 +0100</pubDate>
<content:encoded><![CDATA[Kompromittierte Identitäten haben sich zum wichtigsten Einfallstor für Cyberangriffe entwickelt. Das zeigt der Annual Threat Report 2026 des KI-Cybersicherheitsanbieters Darktrace, der die globale Bedrohungslage des Jahres 2025 analysiert. ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Cloud-Vorfälle: 90 Prozent erleiden Schaden vor Eindämmug]]></title>
<description><![CDATA[Cloud-Incident-Untersuchungen dauern laut Darktrace-Umfrage durch­schnitt­lich drei bis fünf Tage länger als On-Premises-Vorfälle. 90 Prozent der befragten Sicherheitsverantwortlichen berichten, dass sie bereits Schaden erlitten, bevor sie mit der Eindämmung beginnen konnten. Volatile Daten gehen...]]></description>
<link>https://tsecurity.de/de/3359151/it-security-nachrichten/cloud-vorfaelle-90-prozent-erleiden-schaden-vor-eindaemmug/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3359151/it-security-nachrichten/cloud-vorfaelle-90-prozent-erleiden-schaden-vor-eindaemmug/</guid>
<pubDate>Wed, 18 Mar 2026 13:38:44 +0100</pubDate>
<content:encoded><![CDATA[Cloud-Incident-Untersuchungen dauern laut Darktrace-Umfrage durch­schnitt­lich drei bis fünf Tage länger als On-Premises-Vorfälle. 90 Prozent der befragten Sicherheitsverantwortlichen berichten, dass sie bereits Schaden erlitten, bevor sie mit der Eindämmung beginnen konnten. Volatile Daten gehen oft verloren, bevor sie erfasst werden – automatisierte Forensik kann diese Lücke schließen.]]></content:encoded>
</item>
<item>
<title><![CDATA[ESW #305 - Tom Goings, Ashley Leonard]]></title>
<description><![CDATA[Tanium has recently released a new capability called Tanium Software Bill of Materials (SBOM) to help customers identify third-party libraries associated with software packages. • What is Tanium SBOM • Why is it different and why do you need it • How to configure SBOM • How to query for the detai...]]></description>
<link>https://tsecurity.de/de/3356993/it-security-nachrichten/esw-305-tom-goings-ashley-leonard/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3356993/it-security-nachrichten/esw-305-tom-goings-ashley-leonard/</guid>
<pubDate>Tue, 17 Mar 2026 18:10:14 +0100</pubDate>
<content:encoded><![CDATA[<p>Tanium has recently released a new capability called Tanium Software Bill of Materials (SBOM) to help customers identify third-party libraries associated with software packages.</p> <p>• What is Tanium SBOM</p> <p>• Why is it different and why do you need it</p> <p>• How to configure SBOM</p> <p>• How to query for the details about every software application in your environment</p> <p>• Where your vulnerable packages exist</p> <p>• Ways that Tanium can remediate vulnerabilities from OpenSSL to Struts to Log4j today as well as new supply-chain vulnerabilities in the future</p> <p> </p> <p>No one knows what the next supply chain vulnerability is going to be, but with Tanium, you will have access to data about how your applications are affected before it happens so that when it does, you're ready to take action to remediate the issue from within the Tanium XEM platform.</p> <p> </p> <p>Segment Resources:</p> <p><a href="https://www.tanium.com/products/tanium-sbom/">https://www.tanium.com/products/tanium-sbom/</a></p> <p> <a href="https://www.tanium.com/press-releases/tanium-launches-software-bill-of-materials-for-unprecedented-visibility-to-combat-supply-chain-threats/">https://www.tanium.com/press-releases/tanium-launches-software-bill-of-materials-for-unprecedented-visibility-to-combat-supply-chain-threats/</a></p> <p> <a href="https://www.tanium.com/blog/software-bill-of-materials-openssl/">https://www.tanium.com/blog/software-bill-of-materials-openssl/</a></p> <p> </p> <p>This segment is sponsored by Tanium. Visit <a href="https://securityweekly.com/tanium">https://securityweekly.com/tanium</a> to learn more about them!</p> <p> </p> <p>Syxsense and Enterprise Management Associates (EMA) recently teamed up to publish a survey around the current state of Zero Trust within enterprises as well as where it's going. This interview will discuss the key findings and insights into the challenges many organizations face around Zero Trust, as well as endpoint security and network access.</p> <p>Segment Resources:</p> <p><a href="https://www.syxsense.com/advancing-zero-trust-priorities">https://www.syxsense.com/advancing-zero-trust-priorities</a></p> <p> </p> <p>In the Enterprise News: Whether you want insurtechs or not, they're here and you're getting them! Don't worry - we'll explain what insurtechs are. Two potential deals to take security companies private: Sumo Logic and Rapid 7! Looks like 32 year old security company Cyren is shutting down, hoping for an asset sale. They've already laid off all their employees. Big drama: a firm shorts Darktrace and releases a scathing report. We've got yet more more layoffs this week, but don't fret - the NSA is hiring! </p> <p>For our squirrel stories, we'll be deciding between three stories: codebreakers solve 500 year old ciphers, the real cost of meetings visualized, and sushi terrorists!</p> <p>All that and more, on this episode of Enterprise Security Weekly.</p> <p> </p> <p>Visit <a href="https://www.securityweekly.com/esw">https://www.securityweekly.com/esw</a> for all the latest episodes!</p> <p>Follow us on Twitter: <a href="https://www.twitter.com/securityweekly">https://www.twitter.com/securityweekly</a></p> <p>Like us on Facebook: <a href="https://www.facebook.com/secweekly">https://www.facebook.com/secweekly</a></p> <p> </p> <p>Show Notes: <a href="https://securityweekly.com/esw305">https://securityweekly.com/esw305</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security Money & BlackHat Interviews - BSW #317]]></title>
<description><![CDATA[The Security Weekly 25 Index is still trying to recover. Inflation fears have tampered the recovery and the NASDAQ is outperforming the Index. Fastly replaces Sumo Logic in the Index and Thoma Bravo has not acquired anyone, so hoping the index stays stable for more than a quarter :). Here's the l...]]></description>
<link>https://tsecurity.de/de/3356835/it-security-nachrichten/security-money-blackhat-interviews-bsw-317/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3356835/it-security-nachrichten/security-money-blackhat-interviews-bsw-317/</guid>
<pubDate>Tue, 17 Mar 2026 18:08:18 +0100</pubDate>
<content:encoded><![CDATA[<p>The Security Weekly 25 Index is still trying to recover. Inflation fears have tampered the recovery and the NASDAQ is outperforming the Index. Fastly replaces Sumo Logic in the Index and Thoma Bravo has not acquired anyone, so hoping the index stays stable for more than a quarter :). Here's the latest list of companies in the index: Secureworks Corp Palo Alto Networks Inc Check Point Software Technologies Ltd. Splunk Inc Gen Digital Inc Fortinet Inc Akamai Technologies, Inc. F5 Inc Zscaler Inc Onespan Inc Leidos Holdings Inc Qualys Inc Verint Systems Inc. Cyberark Software Ltd Tenable Holdings Inc Darktrace PLC SentinelOne Inc Cloudflare Inc Crowdstrike Holdings Inc NetScout Systems, Inc. Varonis Systems Inc Rapid7 Inc Fastly Inc Radware Ltd A10 Networks Inc</p> <p>Ransomware-as-a-Service has contributed to a steady rise in sophisticated ransomware attacks. Ransomware authors are increasingly staying under the radar by launching encryption-less attacks which involve large volumes of data exfiltration. Organizations must move away from using legacy point products and instead migrate to a fully integrated zero trust platform that minimizes their attack surface, prevents compromise, reduces the blast radius in the event of a successful attack, and prevents data exfiltration.</p> <p>Segment Resources: <a href="https://www.zscaler.com/press/zscaler-2023-ransomware-report-shows-nearly-40-increase-global-ransomware-attacks"> https://www.zscaler.com/press/zscaler-2023-ransomware-report-shows-nearly-40-increase-global-ransomware-attacks</a></p> <p><a href="https://www.zscaler.com/blogs/security-research/2023-phishing-report-reveals-472-surge-phishing-attacks-last-year"> https://www.zscaler.com/blogs/security-research/2023-phishing-report-reveals-472-surge-phishing-attacks-last-year</a> </p> <p>This segment is sponsored by Zscaler.</p> <p>Visit <a href="https://securityweekly.com/zscalerbh">https://securityweekly.com/zscalerbh</a> to learn more about them!</p> <p>The security mediascape is buzzing with discussions around the growing threat of generative AI. But, how can we use this powerful new weapon for good? In this executive interview, IRONSCALES CEO Eyal Benishti walks us through the ways in which generative AI can be used to significantly harden organizations' cyber defenses, and even unveils the latest, cutting-edge tools to be added to IRONSCALES' growing AI suite of capabilities. Meet IRONSCALES' Themis Co-Pilot for Outlook and learn how your team can use artificial intelligence to tip the scales back in your favor.</p> <p>Segment Resources: <a href="https://ironscales.com/company/news-awards/news/ironscales-announces-themis-copilot"> https://ironscales.com/company/news-awards/news/ironscales-announces-themis-copilot</a></p> <p>Video: <a href="https://youtu.be/ayn8ecsNgKY">https://youtu.be/ayn8ecsNgKY</a> This segment is sponsored by IRONSCALES.</p> <p>Visit <a href="https://securityweekly.com/ironscalesbh">https://securityweekly.com/ironscalesbh</a> to learn more about them!</p> <p>Visit <a href="https://www.securityweekly.com/bsw">https://www.securityweekly.com/bsw</a> for all the latest episodes!</p> <p>Follow us on Twitter: <a href="https://www.twitter.com/securityweekly">https://www.twitter.com/securityweekly</a></p> <p>Like us on Facebook: <a href="https://www.facebook.com/secweekly">https://www.facebook.com/secweekly</a></p> <p>Show Notes: <a href="https://securityweekly.com/bsw-317">https://securityweekly.com/bsw-317</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security Money/Pick Your Battles To Avoid Overconsolidation - Jess Burn, Jeff Pollard - BSW #337]]></title>
<description><![CDATA[It's time to review the money of security, including public companies, IPOs, funding rounds and acquisitions from the previous quarter. We also update you on the Security Weekly 25 index. The index came roaring back last quarter. Here are the stocks currently in the index: SCWX Secureworks Corp P...]]></description>
<link>https://tsecurity.de/de/3356691/it-security-nachrichten/security-moneypick-your-battles-to-avoid-overconsolidation-jess-burn-jeff-pollard-bsw-337/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3356691/it-security-nachrichten/security-moneypick-your-battles-to-avoid-overconsolidation-jess-burn-jeff-pollard-bsw-337/</guid>
<pubDate>Tue, 17 Mar 2026 18:06:36 +0100</pubDate>
<content:encoded><![CDATA[<p>It's time to review the money of security, including public companies, IPOs, funding rounds and acquisitions from the previous quarter. We also update you on the Security Weekly 25 index. The index came roaring back last quarter. Here are the stocks currently in the index:</p> <p>SCWX Secureworks Corp PANW Palo Alto Networks Inc CHKP Check Point Software Technologies Ltd. SPLK Splunk Inc GEN Gen Digital Inc FTNT Fortinet Inc AKAM Akamai Technologies, Inc. FFIV F5 Inc ZS Zscaler Inc OSPN Onespan Inc LDOS Leidos Holdings Inc QLYS Qualys Inc VRNT Verint Systems Inc. CYBR Cyberark Software Ltd TENB Tenable Holdings Inc DARK Darktrace PLC S SentinelOne Inc NET Cloudflare Inc CRWD Crowdstrike Holdings Inc NTCT NetScout Systems, Inc. VRNS Varonis Systems Inc RPD Rapid7 Inc FSLY Fastly Inc RDWR Radware Ltd ATEN A10 Networks Inc</p> <p>Large security vendors and hyperscalers, including Microsoft, continue to expand their cybersecurity product and service portfolios. Microsoft's extensive enterprise reach, massive partner network, and enormous influence in the C-suite puts pressure on CIOs and CISOs to consolidate on it as much as possible for cybersecurity. This report helps security leaders understand Microsoft's cybersecurity portfolio, the tactics it uses, and how to manage peer and executive pressure to single-source security technology.</p> <p>Visit <a rel="noopener" target="_blank" href="https://www.securityweekly.com/bsw">https://www.securityweekly.com/bsw</a> for all the latest episodes!</p> <p>Show Notes: <a rel="noopener" target="_blank" href="https://securityweekly.com/bsw-337">https://securityweekly.com/bsw-337</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security Money: Rubrick Saves The Index As It Continues To Climb - Jim Simpson, Theresa Lanowitz - BSW #351]]></title>
<description><![CDATA[This week, it's time for security money, our quarterly review of the money of security, including public companies, IPOs, funding rounds and acquisitions from the previous quarter. This quarter, Rubrick's IPO saves the index, as Cisco finishes the acquisition of Splunk. The index is now made up o...]]></description>
<link>https://tsecurity.de/de/3356592/it-security-nachrichten/security-money-rubrick-saves-the-index-as-it-continues-to-climb-jim-simpson-theresa-lanowitz-bsw-351/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3356592/it-security-nachrichten/security-money-rubrick-saves-the-index-as-it-continues-to-climb-jim-simpson-theresa-lanowitz-bsw-351/</guid>
<pubDate>Tue, 17 Mar 2026 18:05:10 +0100</pubDate>
<content:encoded><![CDATA[<p>This week, it's time for security money, our quarterly review of the money of security, including public companies, IPOs, funding rounds and acquisitions from the previous quarter. This quarter, Rubrick's IPO saves the index, as Cisco finishes the acquisition of Splunk. The index is now made up of the following 25 pure play cybersecurity public companies:</p> <p>Secureworks Corp Palo Alto Networks Inc Check Point Software Technologies Ltd. Rubrik Inc Gen Digital Inc Fortinet Inc Akamai Technologies, Inc. F5 Inc Zscaler Inc Onespan Inc Leidos Holdings Inc Qualys Inc Verint Systems Inc. Cyberark Software Ltd Tenable Holdings Inc Darktrace PLC SentinelOne Inc Cloudflare Inc Crowdstrike Holdings Inc NetScout Systems, Inc. Varonis Systems Inc Rapid7 Inc Fastly Inc Radware Ltd A10 Networks Inc</p> <p>In this segment, Theresa will unpack the complexities of cyber resilience, and dive into new research that examines dynamic computing. She'll discuss how it merges IT and business operations, taps into data-driven decision-making, and redefines computing for the modern era.</p> <p>This segment is sponsored by LevelBlue. Visit <a rel="noopener" target="_blank" href="https://www.securityweekly.com/levelbluersac">https://www.Securityweekly.com/levelbluersac</a> to learn more about them!</p> <p>In this segment, Jim can discuss how organizations can enhance their cybersecurity posture with Blumira's automated threat monitoring, detection and response solutions. Jim can talk about the exciting plans Blumira has in store for the next 3 years, emphasizing how the company is lowering the barrier to entry in cybersecurity for SMBs.</p> <p>Segment Resources: <a rel="noopener" target="_blank" href="https://www.blumira.com/customer-stories/">https://www.blumira.com/customer-stories/</a> <a rel="noopener" target="_blank" href="https://www.blumira.com/why-blumira/">https://www.blumira.com/why-blumira/</a></p> <p>This segment is sponsored by Blumira. Visit <a rel="noopener" target="_blank" href="https://securityweekly.com/blumirarsac">https://securityweekly.com/blumirarsac</a> to learn more about them!</p> <p>Visit <a rel="noopener" target="_blank" href="https://www.securityweekly.com/bsw">https://www.securityweekly.com/bsw</a> for all the latest episodes!</p> <p>Show Notes: <a rel="noopener" target="_blank" href="https://securityweekly.com/bsw-351">https://securityweekly.com/bsw-351</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security Money: Crowdstrike Crashes the Index - BSW #360]]></title>
<description><![CDATA[This week, it's time for security money, our quarterly review of the money of security, including public companies, IPOs, funding rounds and acquisitions from the previous quarter. This quarter, Crowdstrike crashes the index, as Thoma Bravo acquires another index company. The index is currently m...]]></description>
<link>https://tsecurity.de/de/3356516/it-security-nachrichten/security-money-crowdstrike-crashes-the-index-bsw-360/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3356516/it-security-nachrichten/security-money-crowdstrike-crashes-the-index-bsw-360/</guid>
<pubDate>Tue, 17 Mar 2026 18:03:23 +0100</pubDate>
<content:encoded><![CDATA[<p>This week, it's time for security money, our quarterly review of the money of security, including public companies, IPOs, funding rounds and acquisitions from the previous quarter. This quarter, Crowdstrike crashes the index, as Thoma Bravo acquires another index company. The index is currently made up of the following 25 pure play cybersecurity public companies:</p> <ul> <li>Secureworks Corp</li> <li>Palo Alto Networks Inc</li> <li>Check Point Software Technologies Ltd.</li> <li>Rubrik Inc</li> <li>Gen Digital Inc</li> <li>Fortinet Inc</li> <li>Akamai Technologies, Inc.</li> <li>F5 Inc</li> <li>Zscaler Inc</li> <li>Onespan Inc</li> <li>Leidos Holdings Inc</li> <li>Qualys Inc</li> <li>Verint Systems Inc.</li> <li>Cyberark Software Ltd</li> <li>Tenable Holdings Inc</li> <li>Darktrace PLC</li> <li>SentinelOne Inc</li> <li>Cloudflare Inc</li> <li>Crowdstrike Holdings Inc</li> <li>NetScout Systems, Inc.</li> <li>Varonis Systems Inc</li> <li>Rapid7 Inc</li> <li>Fastly Inc</li> <li>Radware Ltd</li> <li> <p>A10 Networks Inc</p> <p>In the leadership and communications segment, The Cybersecurity Leadership Crisis Dooming America's Companies, Judge Rejects SEC's Aggressive Approach to Cybersecurity Enforcement, Is It Time to Pivot Your Strategy?, and more!</p> </li> </ul> <p>Visit <a rel="noopener" target="_blank" href="https://www.securityweekly.com/bsw">https://www.securityweekly.com/bsw</a> for all the latest episodes!</p> <p>Show Notes: <a rel="noopener" target="_blank" href="https://securityweekly.com/bsw-360">https://securityweekly.com/bsw-360</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[DragonForce verschlüsselt Fertiger in sieben Tagen]]></title>
<description><![CDATA[Ein internationales Fertigungsunternehmen verlor innerhalb von sieben Tagen den Kampf gegen die Ransomware DragonForce. Die KI-basierte Erkennung von DarkTrace identifizierte alle Angriffsphasen korrekt, durfte jedoch nicht autonom reagieren.Die Verteidigung blieb somit wirkungslos und der Angrif...]]></description>
<link>https://tsecurity.de/de/3343087/it-security-nachrichten/dragonforce-verschluesselt-fertiger-in-sieben-tagen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3343087/it-security-nachrichten/dragonforce-verschluesselt-fertiger-in-sieben-tagen/</guid>
<pubDate>Thu, 12 Mar 2026 08:34:12 +0100</pubDate>
<content:encoded><![CDATA[Ein internationales Fertigungsunternehmen verlor innerhalb von sieben Tagen den Kampf gegen die Ransomware DragonForce. Die KI-basierte Erkennung von DarkTrace identifizierte alle Angriffsphasen korrekt, durfte jedoch nicht autonom reagieren.Die Verteidigung blieb somit wirkungslos und der Angriff konnte sich voll entfalten.]]></content:encoded>
</item>
<item>
<title><![CDATA[Darktrace names Ed Jennings as new president and CEO]]></title>
<description><![CDATA[The experienced industry leader brings extensive software and cybersecurity expertise as Darktrace targets continued growth]]></description>
<link>https://tsecurity.de/de/3338161/it-security-nachrichten/darktrace-names-ed-jennings-as-new-president-and-ceo/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3338161/it-security-nachrichten/darktrace-names-ed-jennings-as-new-president-and-ceo/</guid>
<pubDate>Tue, 10 Mar 2026 12:51:49 +0100</pubDate>
<content:encoded><![CDATA[The experienced industry leader brings extensive software and cybersecurity expertise as Darktrace targets continued growth]]></content:encoded>
</item>
<item>
<title><![CDATA[APT-Angriff missbraucht Microsoft VS Code für Spionage]]></title>
<description><![CDATA[Eine Spionagekampagne gegen Südkorea nutzt Microsoft VS Code Tunnel für den verdeckten Fernzugriff. Sicherheistforscher von Darktrace identifizierten Übereinstimmungen mit bekannten DPRK-Taktiken. Der Angriff nutzt aus­schließ­lich legitime Software von Microsoft und GitHub. Statt klassischer Mal...]]></description>
<link>https://tsecurity.de/de/3327761/it-security-nachrichten/apt-angriff-missbraucht-microsoft-vs-code-fuer-spionage/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3327761/it-security-nachrichten/apt-angriff-missbraucht-microsoft-vs-code-fuer-spionage/</guid>
<pubDate>Thu, 05 Mar 2026 13:21:09 +0100</pubDate>
<content:encoded><![CDATA[Eine Spionagekampagne gegen Südkorea nutzt Microsoft VS Code Tunnel für den verdeckten Fernzugriff. Sicherheistforscher von Darktrace identifizierten Übereinstimmungen mit bekannten DPRK-Taktiken. Der Angriff nutzt aus­schließ­lich legitime Software von Microsoft und GitHub. Statt klassischer Malware etablieren die Angreifer verschlüsselte Tunnel und umgehen so etablierte Erkennungsmechanismen.]]></content:encoded>
</item>
<item>
<title><![CDATA[Darktrace Flags Surge in Phishing as Identity-Based Attacks Redefine 2025 Threat Landscape]]></title>
<description><![CDATA[  More than 32 million high-confidence phishing emails were identified in 2025, signaling a sharp rise in identity-focused cyberattacks, according to new findings from Darktrace. The cybersecurity firm analyzed incidents across its global customer network, revealing a year marked by…
Read more →
...]]></description>
<link>https://tsecurity.de/de/3314943/it-security-nachrichten/darktrace-flags-surge-in-phishing-as-identity-based-attacks-redefine-2025-threat-landscape/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3314943/it-security-nachrichten/darktrace-flags-surge-in-phishing-as-identity-based-attacks-redefine-2025-threat-landscape/</guid>
<pubDate>Fri, 27 Feb 2026 15:35:25 +0100</pubDate>
<content:encoded><![CDATA[<p>  More than 32 million high-confidence phishing emails were identified in 2025, signaling a sharp rise in identity-focused cyberattacks, according to new findings from Darktrace. The cybersecurity firm analyzed incidents across its global customer network, revealing a year marked by…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/darktrace-flags-surge-in-phishing-as-identity-based-attacks-redefine-2025-threat-landscape/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/darktrace-flags-surge-in-phishing-as-identity-based-attacks-redefine-2025-threat-landscape/">Darktrace Flags Surge in Phishing as Identity-Based Attacks Redefine 2025 Threat Landscape</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Darktrace Flags 32 Million Phishing Emails in 2025 as Identity Attacks Intensify]]></title>
<description><![CDATA[2025 saw 32M phishing emails, with identity threats surpassing vulnerabilities This article has been indexed from www.infosecurity-magazine.com Read the original article: Darktrace Flags 32 Million Phishing Emails in 2025 as Identity Attacks Intensify
Read more →
The post Darktrace Flags 32 Milli...]]></description>
<link>https://tsecurity.de/de/3312659/it-security-nachrichten/darktrace-flags-32-million-phishing-emails-in-2025-as-identity-attacks-intensify/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3312659/it-security-nachrichten/darktrace-flags-32-million-phishing-emails-in-2025-as-identity-attacks-intensify/</guid>
<pubDate>Thu, 26 Feb 2026 16:21:15 +0100</pubDate>
<content:encoded><![CDATA[<p>2025 saw 32M phishing emails, with identity threats surpassing vulnerabilities This article has been indexed from www.infosecurity-magazine.com Read the original article: Darktrace Flags 32 Million Phishing Emails in 2025 as Identity Attacks Intensify</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/darktrace-flags-32-million-phishing-emails-in-2025-as-identity-attacks-intensify/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/darktrace-flags-32-million-phishing-emails-in-2025-as-identity-attacks-intensify/">Darktrace Flags 32 Million Phishing Emails in 2025 as Identity Attacks Intensify</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Darktrace Flags 32 Million Phishing Emails in 2025 as Identity Attacks Intensify]]></title>
<description><![CDATA[2025 saw 32M phishing emails, with identity threats surpassing vulnerabilities]]></description>
<link>https://tsecurity.de/de/3312597/it-security-nachrichten/darktrace-flags-32-million-phishing-emails-in-2025-as-identity-attacks-intensify/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3312597/it-security-nachrichten/darktrace-flags-32-million-phishing-emails-in-2025-as-identity-attacks-intensify/</guid>
<pubDate>Thu, 26 Feb 2026 16:05:40 +0100</pubDate>
<content:encoded><![CDATA[2025 saw 32M phishing emails, with identity threats surpassing vulnerabilities]]></content:encoded>
</item>
<item>
<title><![CDATA[ISO/IEC 42001: Verantwortungsvolle KI – ein neuer Standard für Cybersicherheit]]></title>
<description><![CDATA[... Cybersicherheit. Max Heinemeyer, Global Field CISO, Darktrace, Bild: Darktrace. In einer Zeit, in der ...]]></description>
<link>https://tsecurity.de/de/3312507/it-security-nachrichten/isoiec-42001-verantwortungsvolle-ki-ein-neuer-standard-fuer-cybersicherheit/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3312507/it-security-nachrichten/isoiec-42001-verantwortungsvolle-ki-ein-neuer-standard-fuer-cybersicherheit/</guid>
<pubDate>Thu, 26 Feb 2026 15:21:03 +0100</pubDate>
<content:encoded><![CDATA[... <b>Cybersicherheit</b>. Max Heinemeyer, Global Field CISO, Darktrace, Bild: Darktrace. In einer Zeit, in der ...]]></content:encoded>
</item>
<item>
<title><![CDATA[KI im Unternehmen: Hat die IT-Security noch die Kontrolle? - Silicon.de]]></title>
<description><![CDATA[Der aktuelle State of AI Cybersecurity Report 2026 von Darktrace zeigt, wie tief generative Systeme bereits in Unternehmensprozesse integriert sind.]]></description>
<link>https://tsecurity.de/de/3305466/it-security-nachrichten/ki-im-unternehmen-hat-die-it-security-noch-die-kontrolle-siliconde/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3305466/it-security-nachrichten/ki-im-unternehmen-hat-die-it-security-noch-die-kontrolle-siliconde/</guid>
<pubDate>Mon, 23 Feb 2026 17:20:57 +0100</pubDate>
<content:encoded><![CDATA[Der aktuelle State of AI Cybersecurity Report 2026 von Darktrace zeigt, wie tief generative Systeme bereits in Unternehmensprozesse integriert sind.]]></content:encoded>
</item>
<item>
<title><![CDATA[Hackers Use LLM to Create React2Shell Malware, the Latest Example of AI-Generated Threat]]></title>
<description><![CDATA[Darktrace researchers caught a sample of malware that was created by AI and LLMs to exploit the high-profiled React2Shell vulnerability, putting defenders on notice that the technology lets even lesser-skilled hackers create malicious code and build complex exploit frameworks. The…
Read more →
Th...]]></description>
<link>https://tsecurity.de/de/3282865/it-security-nachrichten/hackers-use-llm-to-create-react2shell-malware-the-latest-example-of-ai-generated-threat/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3282865/it-security-nachrichten/hackers-use-llm-to-create-react2shell-malware-the-latest-example-of-ai-generated-threat/</guid>
<pubDate>Thu, 12 Feb 2026 00:20:44 +0100</pubDate>
<content:encoded><![CDATA[<p>Darktrace researchers caught a sample of malware that was created by AI and LLMs to exploit the high-profiled React2Shell vulnerability, putting defenders on notice that the technology lets even lesser-skilled hackers create malicious code and build complex exploit frameworks. The…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/hackers-use-llm-to-create-react2shell-malware-the-latest-example-of-ai-generated-threat/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/hackers-use-llm-to-create-react2shell-malware-the-latest-example-of-ai-generated-threat/">Hackers Use LLM to Create React2Shell Malware, the Latest Example of AI-Generated Threat</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Threat Actors Exploiting React2Shell Vulnerability Using AI-Generated Malware]]></title>
<description><![CDATA[A fully AI-generated malware campaign actively exploiting the “React2Shell” vulnerability, detected within Darktrace’s “CloudyPots” global honeypot network, the intrusion highlights a critical shift in cybercrime: the weaponization of Large Language Models (LLMs) to lower the barrier of entry for...]]></description>
<link>https://tsecurity.de/de/3279426/it-security-nachrichten/threat-actors-exploiting-react2shell-vulnerability-using-ai-generated-malware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3279426/it-security-nachrichten/threat-actors-exploiting-react2shell-vulnerability-using-ai-generated-malware/</guid>
<pubDate>Tue, 10 Feb 2026 15:07:42 +0100</pubDate>
<content:encoded><![CDATA[<p>A fully AI-generated malware campaign actively exploiting the “React2Shell” vulnerability, detected within Darktrace’s “CloudyPots” global honeypot network, the intrusion highlights a critical shift in cybercrime: the weaponization of Large Language Models (LLMs) to lower the barrier of entry for effective cyberattacks. Darktrace’s analysis of the incident points to the growing trend of “vibecoding,” AI-assisted software […]</p>
<p>The post <a href="https://cybersecuritynews.com/react2shell-vulnerability-ai-generated-malware/">Threat Actors Exploiting React2Shell Vulnerability Using AI-Generated Malware</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[BT Announces Cyber-Defense Partnership with Darktrace]]></title>
<description><![CDATA[BT has begun a partnership with Darktrace whereby it will integrate the latter’s Enterprise Immune System technology into its security portfolio.]]></description>
<link>https://tsecurity.de/de/3268101/it-security-nachrichten/bt-announces-cyber-defense-partnership-with-darktrace/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3268101/it-security-nachrichten/bt-announces-cyber-defense-partnership-with-darktrace/</guid>
<pubDate>Fri, 06 Feb 2026 14:04:20 +0100</pubDate>
<content:encoded><![CDATA[BT has begun a partnership with Darktrace whereby it will integrate the latter’s Enterprise Immune System technology into its security portfolio.]]></content:encoded>
</item>
<item>
<title><![CDATA[UK Security Biz Darktrace Pockets $65m in Funding]]></title>
<description><![CDATA[Vendor goes from strength to strength]]></description>
<link>https://tsecurity.de/de/3266954/it-security-nachrichten/uk-security-biz-darktrace-pockets-65m-in-funding/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3266954/it-security-nachrichten/uk-security-biz-darktrace-pockets-65m-in-funding/</guid>
<pubDate>Fri, 06 Feb 2026 13:58:03 +0100</pubDate>
<content:encoded><![CDATA[Vendor goes from strength to strength]]></content:encoded>
</item>
<item>
<title><![CDATA[#ISSEconf: Shifting to Self-learning, Self-defending Networks]]></title>
<description><![CDATA[Speaking at ISSE Conference 2016 in Paris, Emily Orton, director of Darktrace, argued that traditional security approaches alone are simply now not enough to defend against evolving cyber-threats, instead advocating the use of machine-based learning to aid in the battle against cybercrime]]></description>
<link>https://tsecurity.de/de/3266611/it-security-nachrichten/isseconf-shifting-to-self-learning-self-defending-networks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3266611/it-security-nachrichten/isseconf-shifting-to-self-learning-self-defending-networks/</guid>
<pubDate>Fri, 06 Feb 2026 13:56:08 +0100</pubDate>
<content:encoded><![CDATA[Speaking at ISSE Conference 2016 in Paris, Emily Orton, director of Darktrace, argued that traditional security approaches alone are simply now not enough to defend against evolving cyber-threats, instead advocating the use of machine-based learning to aid in the battle against cybercrime]]></content:encoded>
</item>
<item>
<title><![CDATA[Navigating the AI Revolution in Cybersecurity: Risks, Rewards, and Evolving Roles]]></title>
<description><![CDATA[In the rapidly changing landscape of cybersecurity, AI agents present both opportunities and challenges. This article examines the findings from Darktrace’s 2026 State of AI Cybersecurity Report, highlighting the benefits of AI in enhancing security measures while addressing concerns regarding…
R...]]></description>
<link>https://tsecurity.de/de/3252056/it-security-nachrichten/navigating-the-ai-revolution-in-cybersecurity-risks-rewards-and-evolving-roles/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3252056/it-security-nachrichten/navigating-the-ai-revolution-in-cybersecurity-risks-rewards-and-evolving-roles/</guid>
<pubDate>Wed, 04 Feb 2026 09:08:53 +0100</pubDate>
<content:encoded><![CDATA[<p>In the rapidly changing landscape of cybersecurity, AI agents present both opportunities and challenges. This article examines the findings from Darktrace’s 2026 State of AI Cybersecurity Report, highlighting the benefits of AI in enhancing security measures while addressing concerns regarding…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/navigating-the-ai-revolution-in-cybersecurity-risks-rewards-and-evolving-roles/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/navigating-the-ai-revolution-in-cybersecurity-risks-rewards-and-evolving-roles/">Navigating the AI Revolution in Cybersecurity: Risks, Rewards, and Evolving Roles</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Darktrace schafft Transparenz über den unternehmensweiten KI-Einsatz mit Darktrace SECURE AI]]></title>
<description><![CDATA[... Information Security Officer bei Darktrace. "Darktrace verfolgt seit ... Nahezu die Hälfte der Führungskräfte im Bereich IT-Sicherheit (47 ...]]></description>
<link>https://tsecurity.de/de/3251117/it-security-nachrichten/darktrace-schafft-transparenz-ueber-den-unternehmensweiten-ki-einsatz-mit-darktrace-secure-ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3251117/it-security-nachrichten/darktrace-schafft-transparenz-ueber-den-unternehmensweiten-ki-einsatz-mit-darktrace-secure-ai/</guid>
<pubDate>Tue, 03 Feb 2026 18:35:55 +0100</pubDate>
<content:encoded><![CDATA[... Information Security Officer bei Darktrace. "Darktrace verfolgt seit ... Nahezu die Hälfte der Führungskräfte im Bereich <b>IT</b>-<b>Sicherheit</b> (47 ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Von der NIS2‑Gesetzgebung zur Umsetzung – Sind Sie bereit für 2026? | Events - Darktrace]]></title>
<description><![CDATA[Latest security trends and tips ... Neue Pflichten, strengere Anforderungen und aktuelle BSI-Leitlinien stellen IT- und Sicherheitsteams vor konkrete ...]]></description>
<link>https://tsecurity.de/de/3230998/it-security-nachrichten/von-der-nis2gesetzgebung-zur-umsetzung-sind-sie-bereit-fuer-2026-events-darktrace/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3230998/it-security-nachrichten/von-der-nis2gesetzgebung-zur-umsetzung-sind-sie-bereit-fuer-2026-events-darktrace/</guid>
<pubDate>Fri, 23 Jan 2026 19:50:11 +0100</pubDate>
<content:encoded><![CDATA[Latest <b>security</b> trends and tips ... Neue Pflichten, strengere Anforderungen und aktuelle BSI-Leitlinien stellen <b>IT</b>- und Sicherheitsteams vor konkrete ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Von der NIS2‑Gesetzgebung zur Umsetzung – Sind Sie bereit für 2026? | Events - Darktrace]]></title>
<description><![CDATA[Neue Pflichten, strengere Anforderungen und aktuelle BSI-Leitlinien stellen IT- und Sicherheitsteams vor konkrete Herausforderungen. In unserem ...]]></description>
<link>https://tsecurity.de/de/3230661/it-security-nachrichten/von-der-nis2gesetzgebung-zur-umsetzung-sind-sie-bereit-fuer-2026-events-darktrace/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3230661/it-security-nachrichten/von-der-nis2gesetzgebung-zur-umsetzung-sind-sie-bereit-fuer-2026-events-darktrace/</guid>
<pubDate>Fri, 23 Jan 2026 16:49:19 +0100</pubDate>
<content:encoded><![CDATA[Neue Pflichten, strengere Anforderungen und aktuelle BSI-Leitlinien stellen <b>IT</b>- und Sicherheitsteams vor konkrete Herausforderungen. In unserem ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Darktrace just hired its first chief information officer]]></title>
<description><![CDATA[The enterprise transformation specialist will work to consolidate Darktrace’s enterprise IT and data functions into a unified platform]]></description>
<link>https://tsecurity.de/de/3212562/it-security-nachrichten/darktrace-just-hired-its-first-chief-information-officer/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3212562/it-security-nachrichten/darktrace-just-hired-its-first-chief-information-officer/</guid>
<pubDate>Wed, 14 Jan 2026 13:34:06 +0100</pubDate>
<content:encoded><![CDATA[The enterprise transformation specialist will work to consolidate Darktrace’s enterprise IT and data functions into a unified platform]]></content:encoded>
</item>
<item>
<title><![CDATA[Cybercriminals Exploit Maduro Arrest News to Spread Backdoor Malware]]></title>
<description><![CDATA[Cybercriminals are leveraging reports of Venezuelan President Nicolás Maduro’s arrest on January 3, 2025, to distribute backdoor malware through a sophisticated social engineering campaign. Security researchers at Darktrace have uncovered a malicious operation that exploits this high-profile geop...]]></description>
<link>https://tsecurity.de/de/3205136/it-security-nachrichten/cybercriminals-exploit-maduro-arrest-news-to-spread-backdoor-malware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3205136/it-security-nachrichten/cybercriminals-exploit-maduro-arrest-news-to-spread-backdoor-malware/</guid>
<pubDate>Sat, 10 Jan 2026 06:35:18 +0100</pubDate>
<content:encoded><![CDATA[<p>Cybercriminals are leveraging reports of Venezuelan President Nicolás Maduro’s arrest on January 3, 2025, to distribute backdoor malware through a sophisticated social engineering campaign. Security researchers at Darktrace have uncovered a malicious operation that exploits this high-profile geopolitical event to…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/cybercriminals-exploit-maduro-arrest-news-to-spread-backdoor-malware/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/cybercriminals-exploit-maduro-arrest-news-to-spread-backdoor-malware/">Cybercriminals Exploit Maduro Arrest News to Spread Backdoor Malware</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CS4CA APAC Summit | Events - Darktrace]]></title>
<description><![CDATA[The globally acclaimed Cyber Security for Critical Assets summit returns to Singapore for its 7th Asian Pacific edition in 2026 with a new ally, ...]]></description>
<link>https://tsecurity.de/de/3203778/it-security-nachrichten/cs4ca-apac-summit-events-darktrace/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3203778/it-security-nachrichten/cs4ca-apac-summit-events-darktrace/</guid>
<pubDate>Fri, 09 Jan 2026 12:51:41 +0100</pubDate>
<content:encoded><![CDATA[The globally acclaimed <b>Cyber Security</b> for Critical Assets summit returns to Singapore for its 7th Asian Pacific edition in 2026 with a new ally, ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Darktrace vereint Endpoint- und Netzwerk-Telemetrie mit Agentic AI]]></title>
<description><![CDATA[Darktrace hat seine ActiveAI-Plattform erweitert. Ein neuer Agent soll Netzwerk- und Endpoint-Daten zusammenführen. Die KI analysiert Vorfälle übergreifend – ohne Toolwechsel. Auch Schwachstellenmanagement und OT-Sicherheit wurden ausgebaut.]]></description>
<link>https://tsecurity.de/de/3166339/it-security-nachrichten/darktrace-vereint-endpoint-und-netzwerk-telemetrie-mit-agentic-ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3166339/it-security-nachrichten/darktrace-vereint-endpoint-und-netzwerk-telemetrie-mit-agentic-ai/</guid>
<pubDate>Thu, 18 Dec 2025 09:23:00 +0100</pubDate>
<content:encoded><![CDATA[Darktrace hat seine ActiveAI-Plattform erweitert. Ein neuer Agent soll Netzwerk- und Endpoint-Daten zusammenführen. Die KI analysiert Vorfälle übergreifend – ohne Toolwechsel. Auch Schwachstellenmanagement und OT-Sicherheit wurden ausgebaut.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2023-29656 | Darktrace Mobile App prior 6.0.15 on Android improper authorization (EUVD-2023-33196)]]></title>
<description><![CDATA[A vulnerability categorized as critical has been discovered in Darktrace Mobile App on Android. The affected element is an unknown function. The manipulation results in improper authorization.

This vulnerability is reported as CVE-2023-29656. The attack requires a local approach. No exploit exis...]]></description>
<link>https://tsecurity.de/de/3153131/sicherheitsluecken/cve-2023-29656-darktrace-mobile-app-prior-6015-on-android-improper-authorization-euvd-2023-33196/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3153131/sicherheitsluecken/cve-2023-29656-darktrace-mobile-app-prior-6015-on-android-improper-authorization-euvd-2023-33196/</guid>
<pubDate>Thu, 11 Dec 2025 15:36:31 +0100</pubDate>
<content:encoded><![CDATA[A vulnerability categorized as <a href="https://vuldb.com/?kb.risk">critical</a> has been discovered in <a href="https://vuldb.com/?product.darktrace:mobile_app">Darktrace Mobile App</a> on Android. The affected element is an unknown function. The manipulation results in improper authorization.

This vulnerability is reported as <a href="https://vuldb.com/?source_cve.233053">CVE-2023-29656</a>. The attack requires a local approach. No exploit exists.

It is advisable to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[Cyberangriff auf europäisches Telekommunikationsunternehmen - Darktrace Bericht]]></title>
<description><![CDATA[Cyberrisiken 2025 · Bilder · CIO Briefing · IT Security Best Practices · Akademie · Anmelden · Security-Management · Sicherheitsvorfälle. Cyberangriff ...]]></description>
<link>https://tsecurity.de/de/3148379/it-security-nachrichten/cyberangriff-auf-europaeisches-telekommunikationsunternehmen-darktrace-bericht/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3148379/it-security-nachrichten/cyberangriff-auf-europaeisches-telekommunikationsunternehmen-darktrace-bericht/</guid>
<pubDate>Tue, 09 Dec 2025 16:51:03 +0100</pubDate>
<content:encoded><![CDATA[Cyberrisiken 2025 · Bilder · CIO Briefing · <b>IT Security</b> Best Practices · Akademie · Anmelden · Security-Management · Sicherheitsvorfälle. Cyberangriff ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Salt Typhoon nutzt bekannte Citrix-Schwachstelle für Angriff in Europa]]></title>
<description><![CDATA[Darktrace vermeldet einen Cyberangriff auf ein europäisches Telekom­muni­kations­unternehmen. Die Vorgehensweisen erinnern stark an Salt Typhoon, der Einstieg erfolgte über eine bekannte Schwachstelle in Citrix Netscaler.]]></description>
<link>https://tsecurity.de/de/3148231/it-security-nachrichten/salt-typhoon-nutzt-bekannte-citrix-schwachstelle-fuer-angriff-in-europa/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3148231/it-security-nachrichten/salt-typhoon-nutzt-bekannte-citrix-schwachstelle-fuer-angriff-in-europa/</guid>
<pubDate>Tue, 09 Dec 2025 16:06:41 +0100</pubDate>
<content:encoded><![CDATA[Darktrace vermeldet einen Cyberangriff auf ein europäisches Telekom­muni­kations­unternehmen. Die Vorgehensweisen erinnern stark an Salt Typhoon, der Einstieg erfolgte über eine bekannte Schwachstelle in Citrix Netscaler.]]></content:encoded>
</item>
<item>
<title><![CDATA[Wie Cloud-Forensik Sicherheitslücken sichtbar macht - it-daily]]></title>
<description><![CDATA[Verlorene Zeit – verlorene Beweise. In einer US/UK-Umfrage von Darktrace gaben 65 Prozent der befragten Security-Verantwortlichen an, dass Cloud- ...]]></description>
<link>https://tsecurity.de/de/3140881/it-security-nachrichten/wie-cloud-forensik-sicherheitsluecken-sichtbar-macht-it-daily/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3140881/it-security-nachrichten/wie-cloud-forensik-sicherheitsluecken-sichtbar-macht-it-daily/</guid>
<pubDate>Fri, 05 Dec 2025 14:50:29 +0100</pubDate>
<content:encoded><![CDATA[Verlorene Zeit – verlorene Beweise. In einer US/UK-Umfrage von Darktrace gaben 65 Prozent der befragten <b>Security</b>-Verantwortlichen an, dass Cloud- ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Darktrace / Email strengthens behavioral detection, DLP, and SOC integrations]]></title>
<description><![CDATA[Darktrace announced a series of enhancements to Darktrace / EMAIL designed to detect and stop attacks spanning communications channels, strengthen outbound email protections, and streamline SOC integrations. The new capabilities will help security teams catch sophisticated attacks that evade exis...]]></description>
<link>https://tsecurity.de/de/3138614/it-security-nachrichten/darktrace-email-strengthens-behavioral-detection-dlp-and-soc-integrations/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3138614/it-security-nachrichten/darktrace-email-strengthens-behavioral-detection-dlp-and-soc-integrations/</guid>
<pubDate>Thu, 04 Dec 2025 15:07:05 +0100</pubDate>
<content:encoded><![CDATA[<p>Darktrace announced a series of enhancements to Darktrace / EMAIL designed to detect and stop attacks spanning communications channels, strengthen outbound email protections, and streamline SOC integrations. The new capabilities will help security teams catch sophisticated attacks that evade existing email tools, protect sensitive data, and preserve trust in digital communications, all while reducing operational complexity. New Darktrace research shows that even with multiple layers of email security in place, a significant share of dangerous … <a href="https://www.helpnetsecurity.com/2025/12/04/darktrace-email-strengthens-behavioral-detection-dlp-and-soc-integrations/" rel="nofollow">More <span class="meta-nav">→</span></a></p>
<p>The post <a href="https://www.helpnetsecurity.com/2025/12/04/darktrace-email-strengthens-behavioral-detection-dlp-and-soc-integrations/">Darktrace / Email strengthens behavioral detection, DLP, and SOC integrations</a> appeared first on <a href="https://www.helpnetsecurity.com/">Help Net Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Darktrace / Email strengthens behavioral detection, DLP, and SOC integrations]]></title>
<description><![CDATA[Darktrace announced a series of enhancements to Darktrace / EMAIL designed to detect and stop attacks spanning communications channels, strengthen outbound email protections, and streamline SOC integrations. The new capabilities will help security teams catch sophisticated attacks that evade exis...]]></description>
<link>https://tsecurity.de/de/3138609/it-security-nachrichten/darktrace-email-strengthens-behavioral-detection-dlp-and-soc-integrations/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3138609/it-security-nachrichten/darktrace-email-strengthens-behavioral-detection-dlp-and-soc-integrations/</guid>
<pubDate>Thu, 04 Dec 2025 15:06:58 +0100</pubDate>
<content:encoded><![CDATA[<p>Darktrace announced a series of enhancements to Darktrace / EMAIL designed to detect and stop attacks spanning communications channels, strengthen outbound email protections, and streamline SOC integrations. The new capabilities will help security teams catch sophisticated attacks that evade existing…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/darktrace-email-strengthens-behavioral-detection-dlp-and-soc-integrations/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/darktrace-email-strengthens-behavioral-detection-dlp-and-soc-integrations/">Darktrace / Email strengthens behavioral detection, DLP, and SOC integrations</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Three Black Friday Scams to Watch Out For This Year]]></title>
<description><![CDATA[Darktrace observed a 620% spike in Black Friday-themed phishing in the weeks leading up to the 2025 edition of the sale day This article has been indexed from www.infosecurity-magazine.com Read the original article: Three Black Friday Scams to Watch Out…
Read more →
The post Three Black Friday Sc...]]></description>
<link>https://tsecurity.de/de/3126444/it-security-nachrichten/three-black-friday-scams-to-watch-out-for-this-year/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3126444/it-security-nachrichten/three-black-friday-scams-to-watch-out-for-this-year/</guid>
<pubDate>Fri, 28 Nov 2025 15:06:15 +0100</pubDate>
<content:encoded><![CDATA[<p>Darktrace observed a 620% spike in Black Friday-themed phishing in the weeks leading up to the 2025 edition of the sale day This article has been indexed from www.infosecurity-magazine.com Read the original article: Three Black Friday Scams to Watch Out…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/three-black-friday-scams-to-watch-out-for-this-year/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/three-black-friday-scams-to-watch-out-for-this-year/">Three Black Friday Scams to Watch Out For This Year</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Three Black Friday Scams to Watch Out For This Year]]></title>
<description><![CDATA[Darktrace observed a 620% spike in Black Friday-themed phishing in the weeks leading up to the 2025 edition of the sale day]]></description>
<link>https://tsecurity.de/de/3126421/it-security-nachrichten/three-black-friday-scams-to-watch-out-for-this-year/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3126421/it-security-nachrichten/three-black-friday-scams-to-watch-out-for-this-year/</guid>
<pubDate>Fri, 28 Nov 2025 14:50:28 +0100</pubDate>
<content:encoded><![CDATA[Darktrace observed a 620% spike in Black Friday-themed phishing in the weeks leading up to the 2025 edition of the sale day]]></content:encoded>
</item>
<item>
<title><![CDATA[Darktrace koppelt Netzwerk und Endpoint - IP-Insider]]></title>
<description><![CDATA[Laut Darktrace könnten Sicherheitsteams so schneller reagieren und auf Toolwechsel verzichten. Parallel dazu wurde der Cyber AI Analyst überarbeitet.]]></description>
<link>https://tsecurity.de/de/3102895/it-security-nachrichten/darktrace-koppelt-netzwerk-und-endpoint-ip-insider/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3102895/it-security-nachrichten/darktrace-koppelt-netzwerk-und-endpoint-ip-insider/</guid>
<pubDate>Mon, 17 Nov 2025 17:49:07 +0100</pubDate>
<content:encoded><![CDATA[Laut Darktrace könnten Sicherheitsteams so schneller reagieren und auf Toolwechsel verzichten. Parallel dazu wurde der <b>Cyber</b> AI Analyst überarbeitet.]]></content:encoded>
</item>
<item>
<title><![CDATA[Authentication in the age of AI spoofing]]></title>
<description><![CDATA[A finance manager joins a video call with familiar faces — the company’s CFO and her colleagues. They’ve been summoned via email for a confidential “M&A discussion” requiring bank transfers before the close of business. While the meeting isn’t outside the realm of possibility, the reality was jus...]]></description>
<link>https://tsecurity.de/de/3098183/it-security-nachrichten/authentication-in-the-age-of-ai-spoofing/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3098183/it-security-nachrichten/authentication-in-the-age-of-ai-spoofing/</guid>
<pubDate>Fri, 14 Nov 2025 11:20:29 +0100</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>A finance manager joins a video call with familiar faces — the company’s CFO and her colleagues. They’ve been summoned via email for a confidential “M&amp;A discussion” requiring bank transfers before the close of business. While the meeting isn’t outside the realm of possibility, the reality was just that: everyone aside from the manager was an AI-generated deepfake. Their voices, gestures and likenesses were synthesized from publicly available videos. The email and its provenance evaded system-wide detection.</p>



<p>This isn’t far-fetched; it was a real-life scenario for engineering company <a href="https://www.weforum.org/stories/2025/02/deepfake-ai-cybercrime-arup/" target="_blank" rel="nofollow">Arup in 2024, when deepfake impersonation cost the firm $25 million</a>.</p>



<p>The availability of platforms that enable deepfakes-as-a-service demands that organizations adopt an AI-aware security posture. One that assumes AI-enhanced techniques are attempting to bypass traditional security systems and test the nature of human trust, escalating the AI arms race.</p>



<p>The result is creating a paradox for organizations with no clear long-term gains and a short-lived homefield advantage. The race is accelerating exponentially in both velocity and sophistication to the point that soon no human will be able to follow nor track AI attack/defense response cycles.</p>



<h2 class="wp-block-heading">The threat of AI is here</h2>



<p>At the start of this year, <a href="https://reports.weforum.org/docs/WEF_Global_Cybersecurity_Outlook_2025.pdf" target="_blank" rel="nofollow">approximately two-thirds of global companies surveyed by the World Economic Forum stated that they anticipate that AI will have the “most significant impact” on cybersecurity</a>.</p>



<p>Even as AI revolutionizes enterprise cybersecurity defenses, threats continue to evolve with sophistication and complexity. Unlike traditional malware, which may find its way into networks through a compromised software update or downloads, AI-powered threats utilize machine learning to analyze how employees authenticate themselves to access networks, including when they log in, from which devices, typing patterns and even mouse movements. The AI learns to mimic legitimate behavior while collecting login credentials and is ultimately deployed to evade basic detection.</p>



<p>The ante is raised with the deployment of text-to-video apps that can manipulate video streams, generate AI-videos and clone voices and human likeness. Real-world incidents highlight a critical gap: Building more resilient security requires additional layers to tilt the field in the direction of defenses. Ideally the additional layer is:</p>



<ul class="wp-block-list">
<li>Additive and based on a completely different approach (little overlap).</li>



<li>Bypasses AI’s strengths, such as learning, manipulating, emulating, etc.</li>



<li>Extremely efficient, fast, computationally cheap, authoritative.</li>
</ul>



<p>Fortunately, such a mechanism already exists. Unfortunately, it is often overlooked or misunderstood. My thesis is that authentication, especially one based on open standards and tied to fundamental internet infrastructure, is a proven and effective defensive layer that helps address the AI challenge.</p>



<h2 class="wp-block-heading">The changing battlefield: Hyperrealism by the numbers</h2>



<p>The AI threat is already materializing. One only needs to try out OpenAI’s Sora2 to grasp the coming wave of hyper realistic spoofs that are making it nearly impossible to distinguish the real from the fake.</p>



<p>In the first five months of 2025 alone, <a href="https://deepstrike.io/blog/password-statistics-2025" target="_blank" rel="nofollow">there’s been a 1,265% jump in AI-powered phishing attacks</a>, according to DeepStrike. Microsoft’s 2025 Digital Defense Report indicates that <a href="https://www.microsoft.com/en-us/security/security-insider/threat-landscape/microsoft-digital-defense-report-2025" target="_blank" rel="nofollow">AI-powered phishing emails achieved a 54% click-through rate</a>, compared to 12% for traditional phishing. <a href="https://www.resemble.ai/wp-content/uploads/2025/07/Q2-Deepfake-Detection-Report.pdf" target="_blank" rel="nofollow">Deepfakes, like voice cloning and video impersonation, are doubling in frequency every six months</a>. In a recent Darktrace survey, <a href="https://www.darktrace.com/the-state-of-ai-cybersecurity-2025" target="_blank" rel="nofollow">78% of CISOs now see AI-powered cyberthreats significantly affect their organizations</a>.</p>



<p>Beyond the statistics, AI’s effectiveness is driven by its exponentially improving abilities to social engineer humans — replicating writing style, voice cadence, facial expressions or speech with subtle nuance and adding realistic context by scanning social media and other publicly available references.</p>



<p>The data is striking and reflects the crucial need for a multi-layer approach to help sidestep the exponentially escalating ability for AI to trick humans. </p>



<p>Here’s how a layered authentication strategy can change the outcome of an AI-powered attack:</p>



<ul class="wp-block-list">
<li>At the infrastructure level, DNS-based protocols verify that communications are actually coming from legitimate sources, operating on cryptographic principles rather than pattern recognition. Critically, this side steps hyperrealistic AI attacks.</li>



<li>At the access level, security tokens, combined with biometric confirmation, create physical barriers.</li>



<li>AI-powered behavioral analytics flag anomalies, like unusual location, access time or device.</li>
</ul>



<p>Machine learning cannot forge DNS records for domains it doesn’t control, summon physical tokens or replicate fingerprints — at least not yet.</p>



<h2 class="wp-block-heading">Authentication: A critical defense layer</h2>



<p>As adversaries leverage AI for advanced phishing campaigns, deepfake attacks and automated vulnerability exploitation, various forms of authentication have evolved from best practices to strategic imperatives.</p>



<p>The numbers tell a compelling story: <a href="https://learn.microsoft.com/en-us/partner-center/security/security-at-your-organization" target="_blank" rel="nofollow">more than 99.9% of compromised accounts lack multi-factor authentication</a>. <a href="https://jumpcloud.com/blog/passwordless-authentication-adoption-trends" target="_blank" rel="nofollow">When MFA is enabled, 96% of bulk phishing attempts and 76% of targeted attacks are deterred</a>.</p>



<p>Yet despite authentication’s effectiveness, Okta’s global workforce data indicates <a href="https://www.okta.com/blog/identity-security/phishing-resistant-mfa-shows-great-momentum/" target="_blank" rel="nofollow">approximately two-thirds of organizations worldwide deploy MFA</a>, but just <a href="https://cyberreadinessinstitute.org/news-and-events/new-study-underscores-slow-adoption-of-multifactor-authenification/" target="_blank" rel="nofollow">35% of global SMBs and 27% to 34% of businesses with fewer than 100 employees use MFA</a>, according to a Cyber Readiness Institute report. Moreover, Okta also found that government organizations had a 55% MFA adoption rate. The adoption gaps create significant supply chain vulnerabilities that attackers can exploit on a large scale.</p>



<p>Authentication vendors need to make deployment of their services easier, more intuitive, user-friendly and seamless. And MFA needs to be a requirement across the board, especially for executives, since they are the most targeted and can cause the most damage when breached.</p>



<p>But support must come from the top. When board and CEO-level executives actively champion MFA education and adoption, they give CIO/CISO/InfoSec teams the authority and organizational momentum needed to enforce it successfully.</p>



<p>Today, most organizations that roll out MFA broadly rely on established methods, adding verification layers to traditional password-based authentication:</p>



<ul class="wp-block-list">
<li><strong>Time-based one-time passwords</strong> (TOTPs), which are generated through authenticator apps like Google Authenticator or Microsoft Authenticator and expire every 30 seconds. Software-generated codes eliminate the vulnerabilities of static credentials while remaining cost-effective and easy to deploy across large user bases.</li>



<li><strong>Biometric authentication</strong>, like facial recognition, one-touch fingerprint scanning or voice recognition, provides unique identifiers tied to individuals. Multi-modal biometric approaches offer stronger protection, particularly against AI-generated deepfakes. Passkeys can be used with biometrics, adding several additional layers of AI-resistant security.</li>



<li><strong>Push notifications</strong> send approval requests to registered devices, allowing users to confirm or deny authentication attempts with a single tap. While this method offers better usability than typing codes, it can be vulnerable to look-alike “prompt bombing” attacks aiming to overwhelm the target with requests.</li>



<li><strong>SMS-based codes, </strong>though similar in delivery to notifications, remain common despite known vulnerabilities such as SIM swapping and SMS interception.</li>
</ul>



<p>By providing multiple fast and frictionless authentication layers that exist outside the digital realm where AI operates, networks become more resistant to phishing, session hijacking and man-in-the-middle attacks.</p>



<h2 class="wp-block-heading">The next generation of MFA</h2>



<p>Passkeys are emerging as the next critical evolution of defense. Passkeys are built on the mature<a href="https://fidoalliance.org/passkeys/" target="_blank" rel="nofollow"> FIDO2</a> and <a href="https://webauthn.io/" target="_blank" rel="nofollow">WebAuthn</a> standards, which address a critical gap in current authentication methods.</p>



<p>Just as DNS-based protocols like DMARC establish trusted identity at the infrastructure level, FIDO2-based passkeys establish cryptographic trust at the user authentication level. By making the authentication mechanism itself incapable of working with fraudulent domains, passkeys offer a fundamental shift in authentication security. Passkey use can also be authenticated itself via biometrics (i.e., touch or face ID on Apple devices or Google’s face or fingerprint unlock for Android devices).</p>



<p>Cryptographic protection complements biometric authentication, which verifies “Is this the right person?” at the device level, while passkeys are used to verify “Is this the right website or service?” at the network level. Multi-modal biometrics, such as facial recognition plus fingerprint scanning or biometrics plus behavioral patterns, further strengthen this approach.</p>



<p>As AI-powered attacks make credential theft and impersonation attacks more sophisticated, the only sustainable line of defense is a form of authentication that cannot be tricked or must be cryptographically verified. With major platforms including Apple, Google, Microsoft and GitHub already supporting passkeys, this technology is quickly evolving from emerging to essential.</p>



<h2 class="wp-block-heading">Balancing AI innovation with authentication modernization</h2>



<p>The real opportunity is not choosing between AI-powered defenses and robust authentication; it is recognizing that non-AI authentication can fundamentally shift the security equation in favor of defenders. With <a href="https://www.ibm.com/think/x-force/2025-cost-of-a-data-breach-navigating-ai" target="_blank" rel="nofollow">average breach costs at $4.44 million</a>, according to IBM’s 2025 Cost of a Data Breach Report, the path forward requires balancing both imperatives.</p>



<p>Success belongs to enterprises that recognize these technologies have fundamentally different roles. AI for detection, adaptation and response speed and non-AI authentication for definitive access control that cannot be algorithmically defeated.</p>



<p>But to truly change the equation, organizations must prioritize authentication modernization methods that are grounded in non-AI principles and open standards, even as they embrace AI-driven security innovations.<br></p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.<br><a href="https://www.cio.com/expert-contributor-network/">Want to join?</a></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Darktrace bolsters expansion plans with double C-suite appointment]]></title>
<description><![CDATA[Industry veteran Samun Raju joins the security vendor as CFO, while former KnowBe4 executive Hein Hellemons becomes CRO]]></description>
<link>https://tsecurity.de/de/3076891/it-security-nachrichten/darktrace-bolsters-expansion-plans-with-double-c-suite-appointment/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3076891/it-security-nachrichten/darktrace-bolsters-expansion-plans-with-double-c-suite-appointment/</guid>
<pubDate>Mon, 03 Nov 2025 13:04:40 +0100</pubDate>
<content:encoded><![CDATA[Industry veteran Samun Raju joins the security vendor as CFO, while former KnowBe4 executive Hein Hellemons becomes CRO]]></content:encoded>
</item>
<item>
<title><![CDATA[SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 68]]></title>
<description><![CDATA[Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter TikTok videos continue to push infostealers in ClickFix attacks 131 Spamware Extensions Targeting WhatsApp Flood Chrome Web Store  Salty Much: D...]]></description>
<link>https://tsecurity.de/de/3062674/it-security-nachrichten/security-affairs-malware-newsletter-round-68/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3062674/it-security-nachrichten/security-affairs-malware-newsletter-round-68/</guid>
<pubDate>Sun, 26 Oct 2025 14:19:44 +0100</pubDate>
<content:encoded><![CDATA[Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter TikTok videos continue to push infostealers in ClickFix attacks 131 Spamware Extensions Targeting WhatsApp Flood Chrome Web Store  Salty Much: Darktrace’s view on a recent Salt Typhoon intrusion   Shifts in the Underground: The Impact […]]]></content:encoded>
</item>
<item>
<title><![CDATA[Hackers Used Snappybee Malware and Citrix Flaw to Breach European Telecom Network]]></title>
<description><![CDATA[A European telecommunications organization is said to have been targeted by a threat actor that aligns with a China-nexus cyber espionage group known as Salt Typhoon.
The organization, per Darktrace, was targeted in the first week of July 2025, with the attackers exploiting a Citrix NetScaler Gat...]]></description>
<link>https://tsecurity.de/de/3052452/it-security-nachrichten/hackers-used-snappybee-malware-and-citrix-flaw-to-breach-european-telecom-network/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3052452/it-security-nachrichten/hackers-used-snappybee-malware-and-citrix-flaw-to-breach-european-telecom-network/</guid>
<pubDate>Tue, 21 Oct 2025 09:34:20 +0200</pubDate>
<content:encoded><![CDATA[A European telecommunications organization is said to have been targeted by a threat actor that aligns with a China-nexus cyber espionage group known as Salt Typhoon.
The organization, per Darktrace, was targeted in the first week of July 2025, with the attackers exploiting a Citrix NetScaler Gateway appliance to obtain initial access.
Salt Typhoon, also known as Earth Estries, FamousSparrow,]]></content:encoded>
</item>
<item>
<title><![CDATA[China-linked Salt Typhoon hackers attempt to infiltrate European telco]]></title>
<description><![CDATA[Salt Typhoon, the China-linked APT group that has a penchant for targeting telecommunications companies, has been spotted trying to sneak into yet another one. The intrusion “Darktrace observed activity in a European telecommunications organisation consistent with Salt Typhoon’s known tactics, te...]]></description>
<link>https://tsecurity.de/de/3051313/it-security-nachrichten/china-linked-salt-typhoon-hackers-attempt-to-infiltrate-european-telco/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3051313/it-security-nachrichten/china-linked-salt-typhoon-hackers-attempt-to-infiltrate-european-telco/</guid>
<pubDate>Mon, 20 Oct 2025 17:05:32 +0200</pubDate>
<content:encoded><![CDATA[<p>Salt Typhoon, the China-linked APT group that has a penchant for targeting telecommunications companies, has been spotted trying to sneak into yet another one. The intrusion “Darktrace observed activity in a European telecommunications organisation consistent with Salt Typhoon’s known tactics, techniques and procedures (TTPs), including dynamic-link library (DLL) sideloading and abuse of legitimate software for stealth and execution,” the British cybersecurity company shared on Monday. Other attack elements indicating Salt Typhoon’s involvement include: The exploitation … <a href="https://www.helpnetsecurity.com/2025/10/20/salt-typhoon-apt-telecommunications-europe/" rel="nofollow">More <span class="meta-nav">→</span></a></p>
<p>The post <a href="https://www.helpnetsecurity.com/2025/10/20/salt-typhoon-apt-telecommunications-europe/">China-linked Salt Typhoon hackers attempt to infiltrate European telco</a> appeared first on <a href="https://www.helpnetsecurity.com/">Help Net Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[SonicWall SSL VPN Devices Targeted by Threat Actors to Distribute Akira Ransomware]]></title>
<description><![CDATA[A significant uptick in Akira ransomware attacks has been observed exploiting unpatched SonicWall SSL VPN devices between July and August 2025. Despite a patch release the same day, many organizations remained vulnerable, allowing threat actors to gain initial access and deploy Akira’s double-ext...]]></description>
<link>https://tsecurity.de/de/3032633/hacking/sonicwall-ssl-vpn-devices-targeted-by-threat-actors-to-distribute-akira-ransomware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3032633/hacking/sonicwall-ssl-vpn-devices-targeted-by-threat-actors-to-distribute-akira-ransomware/</guid>
<pubDate>Fri, 10 Oct 2025 14:50:52 +0200</pubDate>
<content:encoded><![CDATA[<p>A significant uptick in Akira ransomware attacks has been observed exploiting unpatched SonicWall SSL VPN devices between July and August 2025. Despite a patch release the same day, many organizations remained vulnerable, allowing threat actors to gain initial access and deploy Akira’s double-extortion scheme. On August 20, 2025, Darktrace detected anomalous network scanning and reconnaissance […]</p>
<p>The post <a href="https://gbhackers.com/sonicwall-ssl-vpn/">SonicWall SSL VPN Devices Targeted by Threat Actors to Distribute Akira Ransomware</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[IT Security Awards 2025: SentinelOne, CrowdStrike, Darktrace und MetricStream ausgezeichnet]]></title>
<description><![CDATA[In der 19. Auflage wurden herausragende Lösungen in den Kategorien Cloud Security, IAM, Internet/Web Security und Management Security ausgezeichnet.]]></description>
<link>https://tsecurity.de/de/3026713/it-security-nachrichten/it-security-awards-2025-sentinelone-crowdstrike-darktrace-und-metricstream-ausgezeichnet/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3026713/it-security-nachrichten/it-security-awards-2025-sentinelone-crowdstrike-darktrace-und-metricstream-ausgezeichnet/</guid>
<pubDate>Tue, 07 Oct 2025 22:04:29 +0200</pubDate>
<content:encoded><![CDATA[In der 19. Auflage wurden herausragende Lösungen in den Kategorien Cloud <b>Security</b>, IAM, Internet/Web <b>Security</b> und Management <b>Security</b> ausgezeichnet.]]></content:encoded>
</item>
<item>
<title><![CDATA[IT Security Awards 2025: SentinelOne, CrowdStrike, Darktrace und MetricStream ausgezeichnet]]></title>
<description><![CDATA[Preisverleihung im Rahmen der „it-sa 2025“ · Cloud Security: SentinelOne Purple AI · IAM: CrowdStrike Falcon Identity Protection · Internet/Web Security: ...]]></description>
<link>https://tsecurity.de/de/3026346/it-security-nachrichten/it-security-awards-2025-sentinelone-crowdstrike-darktrace-und-metricstream-ausgezeichnet/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3026346/it-security-nachrichten/it-security-awards-2025-sentinelone-crowdstrike-darktrace-und-metricstream-ausgezeichnet/</guid>
<pubDate>Tue, 07 Oct 2025 18:49:22 +0200</pubDate>
<content:encoded><![CDATA[Preisverleihung im Rahmen der „<b>it</b>-sa 2025“ · Cloud <b>Security</b>: SentinelOne Purple AI · IAM: CrowdStrike Falcon Identity Protection · Internet/Web <b>Security</b>: ...]]></content:encoded>
</item>
<item>
<title><![CDATA[IT Security Awards 2025: SentinelOne, CrowdStrike, Darktrace und MetricStream ausgezeichnet]]></title>
<description><![CDATA[Die Preisträger der IT Security Awards 2025 stehen fest. In der 19. Auflage wurden herausragende Lösungen in den Kategorien Cloud Security, IAM, ...]]></description>
<link>https://tsecurity.de/de/3026229/it-security-nachrichten/it-security-awards-2025-sentinelone-crowdstrike-darktrace-und-metricstream-ausgezeichnet/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3026229/it-security-nachrichten/it-security-awards-2025-sentinelone-crowdstrike-darktrace-und-metricstream-ausgezeichnet/</guid>
<pubDate>Tue, 07 Oct 2025 18:05:18 +0200</pubDate>
<content:encoded><![CDATA[Die Preisträger der <b>IT Security</b> Awards 2025 stehen fest. In der 19. Auflage wurden herausragende Lösungen in den Kategorien Cloud Security, IAM, ...]]></content:encoded>
</item>
<item>
<title><![CDATA[IT Security Awards 2025: SentinelOne, CrowdStrike, Darktrace und MetricStream ausgezeichnet]]></title>
<description><![CDATA[Die Preisträger der IT Security Awards 2025 stehen fest. In der 19. Auflage wurden herausragende Lösungen in den Kategorien Cloud Security, IAM, Internet/Web Security und Management Security ausgezeichnet. Die Verleihung fand auf der IT-Security-Messe it-sa in Nürnberg statt.

Tags: #GRC | #Ident...]]></description>
<link>https://tsecurity.de/de/3026086/it-security-nachrichten/it-security-awards-2025-sentinelone-crowdstrike-darktrace-und-metricstream-ausgezeichnet/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3026086/it-security-nachrichten/it-security-awards-2025-sentinelone-crowdstrike-darktrace-und-metricstream-ausgezeichnet/</guid>
<pubDate>Tue, 07 Oct 2025 17:04:34 +0200</pubDate>
<content:encoded><![CDATA[<p><img width="1920" height="1080" src="https://www.it-daily.net/wp-content/uploads/2025/10/it-security-awards-2025-alle-1920x1080-1.jpeg" class="attachment-full size-full wp-post-image" alt="Die Gewinner der it security Awards 2025" decoding="async" srcset="https://www.it-daily.net/wp-content/uploads/2025/10/it-security-awards-2025-alle-1920x1080-1.jpeg 1920w, https://www.it-daily.net/wp-content/uploads/2025/10/it-security-awards-2025-alle-1920x1080-1-300x169.jpeg 300w, https://www.it-daily.net/wp-content/uploads/2025/10/it-security-awards-2025-alle-1920x1080-1-1024x576.jpeg 1024w, https://www.it-daily.net/wp-content/uploads/2025/10/it-security-awards-2025-alle-1920x1080-1-768x432.jpeg 768w, https://www.it-daily.net/wp-content/uploads/2025/10/it-security-awards-2025-alle-1920x1080-1-1536x864.jpeg 1536w" sizes="(max-width: 1920px) 100vw, 1920px" title="IT Security Awards 2025: SentinelOne, CrowdStrike, Darktrace und MetricStream ausgezeichnet 1"></p>
    Die Preisträger der IT Security Awards 2025 stehen fest. In der 19. Auflage wurden herausragende Lösungen in den Kategorien Cloud Security, IAM, Internet/Web Security und Management Security ausgezeichnet. Die Verleihung fand auf der IT-Security-Messe it-sa in Nürnberg statt.

<p>Tags: <a href="https://www.it-daily.net/thema/grc">#GRC</a> | <a href="https://www.it-daily.net/thema/identity-threat-detection-and-response-itdr">#Identity Threat Detection and Response (ITDR)</a> | <a href="https://www.it-daily.net/thema/it-securityaward">#IT SecurityAward</a> | <a href="https://www.it-daily.net/thema/sicherheitsplattform">#Sicherheitsplattform</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[ShadowV2 Botnet Infects AWS Docker Containers to Launch DDoS Campaign]]></title>
<description><![CDATA[Darktrace’s latest investigation uncovered a novel campaign that blends traditional malware with modern DevOps technology. At the center of this operation lies a Python-based command-and-control (C2) framework hosted on GitHub CodeSpaces. The threat actors leverage a multi-stage Docker deployment...]]></description>
<link>https://tsecurity.de/de/3001293/hacking/shadowv2-botnet-infects-aws-docker-containers-to-launch-ddos-campaign/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3001293/hacking/shadowv2-botnet-infects-aws-docker-containers-to-launch-ddos-campaign/</guid>
<pubDate>Wed, 24 Sep 2025 09:49:00 +0200</pubDate>
<content:encoded><![CDATA[<p>Darktrace’s latest investigation uncovered a novel campaign that blends traditional malware with modern DevOps technology. At the center of this operation lies a Python-based command-and-control (C2) framework hosted on GitHub CodeSpaces. The threat actors leverage a multi-stage Docker deployment initiated by a Python spreader, followed by a Go-based Remote Access Trojan (RAT) that implements a […]</p>
<p>The post <a href="https://gbhackers.com/shadowv2-botnet/">ShadowV2 Botnet Infects AWS Docker Containers to Launch DDoS Campaign</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[ShadowV2 Botnet Exploits Misconfigured AWS Docker Containers for DDoS-for-Hire Service]]></title>
<description><![CDATA[Cybersecurity researchers have disclosed details of a new botnet that customers can rent access to conduct distributed denial-of-service (DDoS) attacks against targets of interest.
The ShadowV2 botnet, according to Darktrace, predominantly targets misconfigured Docker containers on Amazon Web Ser...]]></description>
<link>https://tsecurity.de/de/2999723/it-security-nachrichten/shadowv2-botnet-exploits-misconfigured-aws-docker-containers-for-ddos-for-hire-service/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2999723/it-security-nachrichten/shadowv2-botnet-exploits-misconfigured-aws-docker-containers-for-ddos-for-hire-service/</guid>
<pubDate>Tue, 23 Sep 2025 14:49:50 +0200</pubDate>
<content:encoded><![CDATA[Cybersecurity researchers have disclosed details of a new botnet that customers can rent access to conduct distributed denial-of-service (DDoS) attacks against targets of interest.
The ShadowV2 botnet, according to Darktrace, predominantly targets misconfigured Docker containers on Amazon Web Services (AWS) cloud servers to deploy a Go-based malware that turns infected systems into attack nodes]]></content:encoded>
</item>
<item>
<title><![CDATA[Salty2FA Bypasses Multi-Factor Authentication in Advanced Phishing Campaign]]></title>
<description><![CDATA[Salty2FA Bypasses Multi-Factor Authentication in Advanced Phishing Campaign
				
				
			
			
				
				
				
				
			
				
				
				
				
				
				
				
				
				
				
				
				 Post Views: 1
			
			
				
				
				
				
				



			
			
				
				
				
				
			
				
				
				
				
				
				
				
...]]></description>
<link>https://tsecurity.de/de/2975943/it-security-nachrichten/salty2fa-bypasses-multi-factor-authentication-in-advanced-phishing-campaign/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2975943/it-security-nachrichten/salty2fa-bypasses-multi-factor-authentication-in-advanced-phishing-campaign/</guid>
<pubDate>Wed, 10 Sep 2025 11:04:51 +0200</pubDate>
<content:encoded><![CDATA[<div class="et_pb_section et_pb_section_0 et_section_specialty">
				
				
				
				
				
				<div class="et_pb_row">
				<div class="et_pb_column et_pb_column_3_4 et_pb_column_0   et_pb_specialty_column  et_pb_css_mix_blend_mode_passthrough">
				
				
				
				
				<div class="et_pb_row_inner et_pb_row_inner_0">
				<div class="et_pb_column et_pb_column_4_4 et_pb_column_inner et_pb_column_inner_0 et-last-child">
				
				
				
				
				<div class="et_pb_module et_pb_post_title et_pb_post_title_0 et_pb_bg_layout_light  et_pb_text_align_left">
				
				
				
				
				
				<div class="et_pb_title_container">
					<h1 class="entry-title">Salty2FA Bypasses Multi-Factor Authentication in Advanced Phishing Campaign</h1>
				</div>
				
			</div>
			</div>
				
				
				
				
			</div><div class="et_pb_row_inner et_pb_row_inner_1">
				<div class="et_pb_column et_pb_column_4_4 et_pb_column_inner et_pb_column_inner_1 et-last-child">
				
				
				
				
				<div class="et_pb_module et_pb_text et_pb_text_0  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><p><strong><div class="post-views content-post post-286260 entry-meta load-static">
				<span class="post-views-icon dashicons dashicons-chart-bar"></span> <span class="post-views-label">Post Views:</span> <span class="post-views-count">1</span>
			</div></strong></p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_1  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><br>
<!-- News_Horizontal_smaller --><br>
<ins class="adsbygoogle" data-ad-client="ca-pub-6620833063853657" data-ad-slot="8337846400"></ins><br>
</div>
			</div>
			</div>
				
				
				
				
			</div><div class="et_pb_row_inner et_pb_row_inner_2 patreon-row">
				<div class="et_pb_column et_pb_column_4_4 et_pb_column_inner et_pb_column_inner_2 et-last-child">
				
				
				
				
				<div class="et_pb_module et_pb_text et_pb_text_2  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><h3 class="premium-content">Join our <a class="green_color" href="https://www.patreon.com/posts/maximizing-your-87671900" target="_blank" rel="noopener sponsored">Patreon</a> Channel and Gain access to 70+ Exclusive Walkthrough Videos.</h3></div>
			</div><div class="et_pb_module et_pb_image et_pb_image_0">
				
				
				
				
				<a href="https://www.patreon.com/posts/create-evasive-111421720" target="_blank"><span class="et_pb_image_wrap "><img fetchpriority="high" decoding="async" width="800" height="120" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2025/02/Patreon-2.png" alt="Patreon" title="Patreon" srcset="https://www.blackhatethicalhacking.com/wp-content/uploads/2025/02/Patreon-2.png 800w, https://www.blackhatethicalhacking.com/wp-content/uploads/2025/02/Patreon-2-480x72.png 480w" sizes="(min-width: 0px) and (max-width: 480px) 480px, (min-width: 481px) 800px, 100vw" class="wp-image-282931"></span></a>
			</div><div class="et_pb_module et_pb_divider et_pb_divider_0 et_pb_divider_position_ et_pb_space"><div class="et_pb_divider_internal"></div></div>
			</div>
				
				
				
				
			</div><div class="et_pb_row_inner et_pb_row_inner_3">
				<div class="et_pb_column et_pb_column_4_4 et_pb_column_inner et_pb_column_inner_3 et-last-child">
				
				
				
				
				<div class="et_pb_module et_pb_text et_pb_text_3  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner">Reading Time: 3 Minutes</div>
			</div>
			</div>
				
				
				
				
			</div><div class="et_pb_row_inner et_pb_row_inner_4">
				<div class="et_pb_column et_pb_column_4_4 et_pb_column_inner et_pb_column_inner_4 et-last-child">
				
				
				
				
				<div class="et_pb_module et_pb_text et_pb_text_4  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><h2 data-start="722" data-end="748"><strong>A New Era of Phishing</strong></h2>
<p data-start="750" data-end="972">Cybersecurity researchers have identified a <strong data-start="794" data-end="826">next-generation phishing kit</strong> known as <strong data-start="836" data-end="848">Salty2FA</strong>, which uses advanced tactics to bypass multi-factor authentication (MFA) and impersonate trusted corporate login portals.</p>
<p data-start="974" data-end="1192">The kit was revealed in exclusive <a href="https://www.ontinue.com/resource/blog-salty2fa-multi-stage-evasion-phishing/" target="_blank" rel="noopener">research</a> by the <strong data-start="1024" data-end="1056">Ontinue Cyber Defence Centre</strong>, which described it as part of a wider evolution in phishing that mirrors the development practices of legitimate software companies.</p>
<p data-start="1194" data-end="1363">The campaign begins with an email lure pointing victims to a <strong data-start="1255" data-end="1302">fake document-sharing page hosted on Aha.io</strong>, created on September 3, 2025, using a free trial account.</p>
<p data-start="1194" data-end="1363"><a class="pk-image-popup pk-zoom-icon-popup" href="https://hackread.com/wp-content/uploads/2025/09/Salty2FA-Experts-Warn-of-Enterprise-Grade-Phishing-Attacks.png"><img decoding="async" class="wp-image-134553 pk-pin-it-ready aligncenter" src="https://hackread.com/wp-content/uploads/2025/09/Salty2FA-Experts-Warn-of-Enterprise-Grade-Phishing-Attacks-1024x736.png" sizes="(max-width: 1024px) 100vw, 1024px" srcset="https://hackread.com/wp-content/uploads/2025/09/Salty2FA-Experts-Warn-of-Enterprise-Grade-Phishing-Attacks-1024x736.png 1024w, https://hackread.com/wp-content/uploads/2025/09/Salty2FA-Experts-Warn-of-Enterprise-Grade-Phishing-Attacks-300x216.png 300w, https://hackread.com/wp-content/uploads/2025/09/Salty2FA-Experts-Warn-of-Enterprise-Grade-Phishing-Attacks-768x552.png 768w, https://hackread.com/wp-content/uploads/2025/09/Salty2FA-Experts-Warn-of-Enterprise-Grade-Phishing-Attacks-380x273.png 380w, https://hackread.com/wp-content/uploads/2025/09/Salty2FA-Experts-Warn-of-Enterprise-Grade-Phishing-Attacks-800x575.png 800w, https://hackread.com/wp-content/uploads/2025/09/Salty2FA-Experts-Warn-of-Enterprise-Grade-Phishing-Attacks-1160x834.png 1160w, https://hackread.com/wp-content/uploads/2025/09/Salty2FA-Experts-Warn-of-Enterprise-Grade-Phishing-Attacks.png 1217w" alt="" width="873" height="628"></a>Phishing Lure (Source: Ontinue)</p>
<hr data-start="1365" data-end="1368">
<h2 data-start="1370" data-end="1399"><strong>Multi-Stage Attack Chain</strong></h2>
<p data-start="1401" data-end="1606">Once on the malicious site, victims are directed through a <strong data-start="1460" data-end="1492">Cloudflare Turnstile captcha</strong> — a step that ironically blocks automated sandboxes and analysis tools while allowing human victims to proceed.</p>
<p data-start="1608" data-end="1856">From there, the phishing kit deploys a multi-stage attack chain supported by <strong data-start="1685" data-end="1722">session-based rotating subdomains</strong>. Each new visitor is assigned a unique URL, making it nearly impossible for defenders to blacklist domains or disrupt the campaign.</p>
<p data-start="1608" data-end="1856"><a class="pk-image-popup pk-zoom-icon-popup" href="https://hackread.com/wp-content/uploads/2025/09/Salty2FA-Experts-Warn-of-Enterprise-Grade-Phishing-Attacks-2.png"><img decoding="async" class="wp-image-134555 pk-pin-it-ready aligncenter" src="https://hackread.com/wp-content/uploads/2025/09/Salty2FA-Experts-Warn-of-Enterprise-Grade-Phishing-Attacks-2.png" sizes="(max-width: 587px) 100vw, 587px" srcset="https://hackread.com/wp-content/uploads/2025/09/Salty2FA-Experts-Warn-of-Enterprise-Grade-Phishing-Attacks-2.png 587w, https://hackread.com/wp-content/uploads/2025/09/Salty2FA-Experts-Warn-of-Enterprise-Grade-Phishing-Attacks-2-206x300.png 206w, https://hackread.com/wp-content/uploads/2025/09/Salty2FA-Experts-Warn-of-Enterprise-Grade-Phishing-Attacks-2-380x552.png 380w" alt="" width="519" height="754"></a>Session-based rotating subdomains (Source: Ontinue)</p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_5 see-also-text  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><strong>See Also: So, you want to be a hacker?<br>
</strong><strong><a href="https://www.blackhatethicalhacking.com/courses/" target="_blank" rel="noopener noreferrer">Offensive Security, Bug Bounty Courses</a></strong></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_6  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><br>
<!-- News_Horizontal_smaller --><br>
<ins class="adsbygoogle" data-ad-client="ca-pub-6620833063853657" data-ad-slot="8337846400"></ins><br>
</div>
			</div><div class="et_pb_module et_pb_text et_pb_text_7  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><h4><span><strong>Discover your weakest link. Be proactive, not reactive. Cybercriminals need just one flaw to strike.</strong></span></h4>
<p><a href="https://www.blackhatethicalhacking.com/solutions/"><img decoding="async" class="alignnone wp-image-276050 size-full" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2023/11/Solutions.png" alt="" width="800" height="120" srcset="https://www.blackhatethicalhacking.com/wp-content/uploads/2023/11/Solutions.png 800w, https://www.blackhatethicalhacking.com/wp-content/uploads/2023/11/Solutions-480x72.png 480w" sizes="(min-width: 0px) and (max-width: 480px) 480px, (min-width: 481px) 800px, 100vw"></a></p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_8  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><h2 data-start="1863" data-end="1892"><strong>The Art of Impersonation</strong></h2>
<p data-start="1894" data-end="2137">Ontinue researchers highlighted the kit’s ability to perform <strong data-start="1955" data-end="1985">dynamic corporate branding</strong>. By analyzing a victim’s email domain, Salty2FA generates a fraudulent login portal complete with the <strong data-start="2088" data-end="2134">target company’s logo, colors, and styling</strong>.</p>
<p data-start="2139" data-end="2296">This tactic enhances the realism of the phishing attempt and has been observed across industries including <strong data-start="2246" data-end="2293">healthcare, finance, technology, and energy</strong>.</p>
<p data-start="2298" data-end="2521">The kit also simulates up to <strong data-start="2327" data-end="2371">six forms of multi-factor authentication</strong>, such as SMS, authenticator apps, and phone call codes — giving victims the false impression they are interacting with a secure, legitimate system.</p>
<hr data-start="2523" data-end="2526">
<h2 data-start="2528" data-end="2550"><strong>Defensive Evasion</strong></h2>
<p data-start="2552" data-end="2745">To hinder defenders, the malware employs <strong data-start="2593" data-end="2649">heavy code obfuscation and anti-debugging techniques</strong>, complicating efforts by security researchers to reverse engineer or dismantle the framework.</p>
<p data-start="2747" data-end="2922">The sophistication of the campaign suggests the involvement of an <strong data-start="2813" data-end="2857">organized and well-funded criminal group</strong>, though Ontinue noted no definitive attribution could be made.</p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_9 see-also-text  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><p><strong>Trending: <a href="https://www.blackhatethicalhacking.com/articles/os-command-injection-via-lang-parameter-in-fortinet-vpn-ssl-interface/" target="_blank" rel="noopener noreferrer">OS Command Injection via ‘lang’ Parameter in Fortinet VPN SSL Interface<br>
</a></strong></p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_10  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><br>
<!-- News Adsense Adcode Horizontal --><br>
<ins class="adsbygoogle" data-ad-client="ca-pub-6620833063853657" data-ad-slot="8337846400"></ins><br>
</div>
			</div><div class="et_pb_module et_pb_text et_pb_text_11 see-also-text  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><p><strong>Trending: <a href="https://www.blackhatethicalhacking.com/tools/zoomeyesearch/" target="_blank" rel="noopener">Recon Tool: ZoomeyeSearch<br>
</a></strong></p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_12  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><div class="pt-0">
<div class="gizmo-bot-avatar flex h-8 w-8 items-center justify-center overflow-hidden rounded-full">
<div class="relative p-1 rounded-sm flex items-center justify-center bg-token-main-surface-primary text-token-text-primary h-8 w-8">
<div class="flex-shrink-0 flex flex-col relative items-end">
<div class="pt-0">
<div class="gizmo-bot-avatar flex h-8 w-8 items-center justify-center overflow-hidden rounded-full">
<div class="relative p-1 rounded-sm flex items-center justify-center bg-token-main-surface-primary text-token-text-primary h-8 w-8">
<div class="flex-shrink-0 flex flex-col relative items-end">
<div class="pt-0">
<div class="gizmo-bot-avatar flex h-8 w-8 items-center justify-center overflow-hidden rounded-full">
<div class="relative p-1 rounded-sm flex items-center justify-center bg-token-main-surface-primary text-token-text-primary h-8 w-8">
<div class="pt-0">
<div class="gizmo-bot-avatar flex h-8 w-8 items-center justify-center overflow-hidden rounded-full">
<div class="relative p-1 rounded-sm flex items-center justify-center bg-token-main-surface-primary text-token-text-primary h-8 w-8">
<div class="flex-shrink-0 flex flex-col relative items-end">
<div class="pt-0">
<div class="gizmo-bot-avatar flex h-8 w-8 items-center justify-center overflow-hidden rounded-full">
<div class="relative p-1 rounded-sm flex items-center justify-center bg-token-main-surface-primary text-token-text-primary h-8 w-8">
<div class="flex-shrink-0 flex flex-col relative items-end">
<div class="pt-0">
<div class="gizmo-bot-avatar flex h-8 w-8 items-center justify-center overflow-hidden rounded-full">
<div class="relative p-1 rounded-sm flex items-center justify-center bg-token-main-surface-primary text-token-text-primary h-8 w-8">
<h2 data-start="2929" data-end="2952"><strong>The Bigger Picture</strong></h2>
<p data-start="2954" data-end="3211">This discovery aligns with a <strong data-start="2983" data-end="3021">broader surge in advanced phishing</strong>. <a href="https://www.menlosecurity.com/blog/browser-security-report-ai-powered-attacks-surge" target="_blank" rel="noopener">Data</a> from <strong data-start="3033" data-end="3051">Menlo Security</strong> shows a <strong data-start="3060" data-end="3103">140% increase in browser-based phishing</strong> since 2023, alongside a <strong data-start="3128" data-end="3171">130% rise in zero-hour phishing attacks</strong> exploiting unpatched vulnerabilities.</p>
<p data-start="3213" data-end="3371">These trends underscore the growing difficulty of defending against “Phishing 2.0” kits that blend technical sophistication with psychological manipulation.</p>
<hr data-start="3373" data-end="3376">
<h2 data-start="3378" data-end="3402"><strong>Expert Perspectives</strong></h2>
<p data-start="3404" data-end="3553"><a href="https://www.linkedin.com/in/nicole-carignan/" target="_blank" rel="noopener">Nicole Carignan</a>, Senior Vice President of Security &amp; AI Strategy at <strong data-start="3472" data-end="3485">Darktrace</strong>, warned that traditional tools struggle to detect such campaigns:</p>
<blockquote data-start="3555" data-end="3749">
<p data-start="3557" data-end="3749">“Organisations can’t rely on employees as the last line of defence. Machine learning systems that build a baseline of normal activity are essential to accurately detect suspicious behavior.”</p>
</blockquote>
<p data-start="3751" data-end="3835"><a href="https://ca.linkedin.com/in/jason-soroko-19b41920" target="_blank" rel="noopener">Jason Soroko</a>, Senior Fellow at <strong data-start="3782" data-end="3793">Sectigo</strong>, added that MFA alone is not foolproof:</p>
<blockquote data-start="3837" data-end="4069">
<p data-start="3839" data-end="4069">“Not all multi-factor authentication is created equal. Shared-secret MFA, such as one-time passwords, is just as vulnerable to fake authentication pages as traditional passwords. Education and stronger MFA methods are critical.”</p>
</blockquote>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_13 see-also-text  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><p><strong>Trending: <a href="https://www.blackhatethicalhacking.com/news/meta-patches-whatsapp-zero-day-vulnerability-linked-to-apple-zero-day-exploit-chain/" target="_blank" rel="noopener noreferrer">Meta Patches WhatsApp Zero-Day Vulnerability Linked to Apple Zero-Day Exploit Chain<br>
</a></strong></p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_14  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><blockquote><p><em>Are u a security researcher? Or a company that writes articles about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing? </em><em>If you want to express your idea in an article contact us here for a quote: <strong>info@blackhatethicalhacking.com</strong></em></p></blockquote></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_15  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><p><strong><em>Source: hackread.com</em></strong></p>
<p><a href="https://hackread.com/salty2fa-phishing-kit-bypasses-mfa-clone-login-pages/" target="_blank" rel="noopener"><strong>Source Link</strong></a></p></div>
			</div><div class="et_pb_module et_pb_divider et_pb_divider_1 et_pb_divider_position_ et_pb_space"><div class="et_pb_divider_internal"></div></div><div class="et_pb_module et_pb_image et_pb_image_1 store-img">
				
				
				
				
				<a href="https://store.blackhatethicalhacking.com/" target="_blank"><span class="et_pb_image_wrap "><img decoding="async" width="1142" height="500" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Store.png" alt="Merch" title="Store" srcset="https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Store.png 1142w, https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Store-980x429.png 980w, https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Store-480x210.png 480w" sizes="(min-width: 0px) and (max-width: 480px) 480px, (min-width: 481px) and (max-width: 980px) 980px, (min-width: 981px) 1142px, 100vw" class="wp-image-271829"></span></a>
			</div><div class=" et_pb_logo_slider  et_pb_logo_slider_0 ">
                
            </div>
			</div>
				
				
				
				
			</div>
			</div><div class="et_pb_column et_pb_column_1_4 et_pb_column_1    et_pb_css_mix_blend_mode_passthrough">
				
				
				
				
				<div class="et_pb_module et_pb_sidebar_0 news-sidebar1 et_pb_widget_area clearfix et_pb_widget_area_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_widget rpwe_widget recent-posts-extended"><h4 class="widgettitle">Recent News</h4><div class="rpwe-block news-recent-posts-sb"><ul class="rpwe-ul"><li class="rpwe-li rpwe-clearfix"><a class="rpwe-img" href="https://www.blackhatethicalhacking.com/news/icloud-calendar-invites-abused-to-send-callback-phishing-emails-via-apple-servers/" target="_self"><img class="rpwe-aligncenter rpwe-thumb" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2025/09/877x440-Images-for-the-News-posts-20-300x150.png" alt="iCloud Calendar Invites Abused to Send Callback Phishing Emails via Apple Servers" height="150" width="300" loading="lazy" decoding="async"></a><h3 class="rpwe-title"><a href="https://www.blackhatethicalhacking.com/news/icloud-calendar-invites-abused-to-send-callback-phishing-emails-via-apple-servers/" target="_self">iCloud Calendar Invites Abused to Send Callback Phishing Emails via Apple Servers</a></h3><time class="rpwe-time published" datetime="2025-09-08T11:19:57+02:00">September 8, 2025</time><div class="rpwe-summary"></div></li><li class="rpwe-li rpwe-clearfix"><a class="rpwe-img" href="https://www.blackhatethicalhacking.com/news/cloudflare-confirms-salesforce-linked-data-breach-via-salesloft-drift/" target="_self"><img class="rpwe-aligncenter rpwe-thumb" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2025/09/877x440-Images-for-the-News-posts-19-300x150.png" alt="Cloudflare Confirms Salesforce-Linked Data Breach via Salesloft Drift" height="150" width="300" loading="lazy" decoding="async"></a><h3 class="rpwe-title"><a href="https://www.blackhatethicalhacking.com/news/cloudflare-confirms-salesforce-linked-data-breach-via-salesloft-drift/" target="_self">Cloudflare Confirms Salesforce-Linked Data Breach via Salesloft Drift</a></h3><time class="rpwe-time published" datetime="2025-09-03T09:37:19+02:00">September 3, 2025</time><div class="rpwe-summary"></div></li><li class="rpwe-li rpwe-clearfix"><a class="rpwe-img" href="https://www.blackhatethicalhacking.com/news/meta-patches-whatsapp-zero-day-vulnerability-linked-to-apple-zero-day-exploit-chain/" target="_self"><img class="rpwe-aligncenter rpwe-thumb" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2025/09/877x440-Images-for-the-News-posts-18-300x150.png" alt="Meta Patches WhatsApp Zero-Day Vulnerability Linked to Apple Zero-Day Exploit Chain" height="150" width="300" loading="lazy" decoding="async"></a><h3 class="rpwe-title"><a href="https://www.blackhatethicalhacking.com/news/meta-patches-whatsapp-zero-day-vulnerability-linked-to-apple-zero-day-exploit-chain/" target="_self">Meta Patches WhatsApp Zero-Day Vulnerability Linked to Apple Zero-Day Exploit Chain</a></h3><time class="rpwe-time published" datetime="2025-09-01T10:38:23+02:00">September 1, 2025</time><div class="rpwe-summary"></div></li><li class="rpwe-li rpwe-clearfix"><a class="rpwe-img" href="https://www.blackhatethicalhacking.com/news/nx-supply-chain-attack-abuses-ai-tools-to-steal-developer-credentials/" target="_self"><img class="rpwe-aligncenter rpwe-thumb" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2025/08/877x440-Images-for-the-News-posts-16-300x150.png" alt="Nx Supply Chain Attack Abuses AI Tools to Steal Developer Credentials" height="150" width="300" loading="lazy" decoding="async"></a><h3 class="rpwe-title"><a href="https://www.blackhatethicalhacking.com/news/nx-supply-chain-attack-abuses-ai-tools-to-steal-developer-credentials/" target="_self">Nx Supply Chain Attack Abuses AI Tools to Steal Developer Credentials</a></h3><time class="rpwe-time published" datetime="2025-08-29T10:30:34+02:00">August 29, 2025</time><div class="rpwe-summary"></div></li></ul></div><!-- Generated by http://wordpress.org/plugins/recent-posts-widget-extended/ --></div><div class="et_pb_widget widget_block"><h3>EXPLORE OUR STORE</h3></div><div class="et_pb_widget widget_media_image"><a href="https://store.blackhatethicalhacking.com/"><img decoding="async" width="233" height="300" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2024/09/Tshirt-233x300.png" class="image wp-image-280999  attachment-medium size-medium" alt=""></a></div><div class="et_pb_widget widget_media_image"><a href="https://store.blackhatethicalhacking.com/"><img decoding="async" width="300" height="280" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2024/09/RedTeamers-e1725807706904-300x280.png" class="image wp-image-281001  attachment-medium size-medium" alt=""></a></div><div class="et_pb_widget widget_media_image"><a href="https://store.blackhatethicalhacking.com/"><img decoding="async" width="711" height="1024" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2024/09/Hoodie-711x1024.png" class="image wp-image-281002  attachment-large size-large" alt=""></a></div><div class="widget_text et_pb_widget widget_custom_html"><div class="textwidget custom-html-widget"> <!-- News Adsense Adcode --> <ins class="adsbygoogle" data-ad-client="ca-pub-6620833063853657" data-ad-slot="8337846400" data-ad-format="auto" data-full-width-responsive="true"></ins> </div></div>
			</div><div class="et_pb_module et_pb_sidebar_1 news-sidebar2 et_animated et_pb_widget_area clearfix et_pb_widget_area_left  et_pb_text_align_justified et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_widget widget_block"><a href="https://www.blackhatethicalhacking.com/courses/"><img decoding="async" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/OffSec-Course.png"></a>
<h3>Offensive Security &amp; Ethical Hacking Course</h3>
<p>Begin the learning curve of hacking now!</p>
</div><div class="et_pb_widget widget_block"><hr>
<a href="https://www.blackhatethicalhacking.com/solutions/"><img decoding="async" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Solutions.png"></a>
<h3>Information Security Solutions</h3>
<p>Find out how Pentesting Services can help you.</p></div><div class="et_pb_widget widget_block"><hr>
<a href="https://discord.gg/EYMqveWXkv"><img decoding="async" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2023/10/Discord.png"></a>
<h3>Join our Community</h3></div>
			</div>
			</div>
				</div>
				
			</div>The post <a href="https://www.blackhatethicalhacking.com/news/salty2fa-bypasses-multi-factor-authentication-in-advanced-phishing-campaign/">Salty2FA Bypasses Multi-Factor Authentication in Advanced Phishing Campaign</a> first appeared on <a href="https://www.blackhatethicalhacking.com/">Black Hat Ethical Hacking</a>.]]></content:encoded>
</item>
<item>
<title><![CDATA[Attackers Abuse Virtual Private Servers to Compromise SaaS Accounts]]></title>
<description><![CDATA[Darktrace observed a coordinated campaign on customer SaaS accounts, all of which involved logins from IP addresses linked to VPS providers]]></description>
<link>https://tsecurity.de/de/2953429/it-security-nachrichten/attackers-abuse-virtual-private-servers-to-compromise-saas-accounts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2953429/it-security-nachrichten/attackers-abuse-virtual-private-servers-to-compromise-saas-accounts/</guid>
<pubDate>Fri, 22 Aug 2025 13:03:45 +0200</pubDate>
<content:encoded><![CDATA[Darktrace observed a coordinated campaign on customer SaaS accounts, all of which involved logins from IP addresses linked to VPS providers]]></content:encoded>
</item>
<item>
<title><![CDATA[Cyberangriff auf US-Chemieunternehmen durch Linux-Backdoor Auto-Color - Security-Insider]]></title>
<description><![CDATA[Cyberkriminelle schleusten über eine SAP-Schwachstelle die Linux-Backdoor Auto-Color in ein US-Chemieunternehmen ein. So konnte Darktrace den ...]]></description>
<link>https://tsecurity.de/de/2935980/it-security-nachrichten/cyberangriff-auf-us-chemieunternehmen-durch-linux-backdoor-auto-color-security-insider/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2935980/it-security-nachrichten/cyberangriff-auf-us-chemieunternehmen-durch-linux-backdoor-auto-color-security-insider/</guid>
<pubDate>Tue, 12 Aug 2025 18:03:49 +0200</pubDate>
<content:encoded><![CDATA[Cyberkriminelle schleusten über eine SAP-Schwachstelle die Linux-Backdoor Auto-Color in ein US-Chemieunternehmen ein. So konnte Darktrace den ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Linux-Backdoor über SAP-Schwachstelle eingeschleust]]></title>
<description><![CDATA[Cyberkriminelle schleusten über eine SAP-Schwachstelle die Linux-Backdoor Auto-Color in ein US-Chemieunternehmen ein. So konnte Darktrace den Angriff frühzeitig erkennen und blockieren.]]></description>
<link>https://tsecurity.de/de/2934746/it-security-nachrichten/linux-backdoor-ueber-sap-schwachstelle-eingeschleust/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2934746/it-security-nachrichten/linux-backdoor-ueber-sap-schwachstelle-eingeschleust/</guid>
<pubDate>Tue, 12 Aug 2025 07:33:40 +0200</pubDate>
<content:encoded><![CDATA[Cyberkriminelle schleusten über eine SAP-Schwachstelle die Linux-Backdoor Auto-Color in ein US-Chemieunternehmen ein. So konnte Darktrace den Angriff frühzeitig erkennen und blockieren.]]></content:encoded>
</item>
<item>
<title><![CDATA[Darktrace Acquires Mira Security]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/2922280/it-security-nachrichten/darktrace-acquires-mira-security/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2922280/it-security-nachrichten/darktrace-acquires-mira-security/</guid>
<pubDate>Mon, 04 Aug 2025 21:34:22 +0200</pubDate>
</item>
<item>
<title><![CDATA[SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 56]]></title>
<description><![CDATA[Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Endgame Gear mouse config tool infected users with malware Auto-Color Backdoor: How Darktrace Thwarted a Stealthy Linux Intrusion  Sealed Chain ...]]></description>
<link>https://tsecurity.de/de/2920318/it-security-nachrichten/security-affairs-malware-newsletter-round-56/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2920318/it-security-nachrichten/security-affairs-malware-newsletter-round-56/</guid>
<pubDate>Sun, 03 Aug 2025 15:33:52 +0200</pubDate>
<content:encoded><![CDATA[Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Endgame Gear mouse config tool infected users with malware Auto-Color Backdoor: How Darktrace Thwarted a Stealthy Linux Intrusion  Sealed Chain of Deception: Actors leveraging Node.JS to Launch JSCeal Decrypted: FunkSec Ransomware  Threat actor uses […]]]></content:encoded>
</item>
<item>
<title><![CDATA[‘CISO는 안심, 실무진은 불안’··· 보안 인식 격차, 조직 리스크 키운다]]></title>
<description><![CDATA[조직의 사이버 보안 성숙도와 회복탄력성에 있어 보안 임원진과 실무진 사이에 뚜렷한 인식 차이가 존재하는 것으로 나타났다.



비트디펜더(BitDefender)의 최근 보고서에 따르면 조직의 공격 표면이 확대되고 있지만, CISO는 중간 관리자급보다 리스크를 관리할 수 있는 역량에 대해 더 자신감을 보였다. CISO의 45%가 자신감을 보인 반면, 중간 관리자급은 이 비율이 19%에 그쳤다. 다크트레이스(Darktrace)의 ‘AI 사이버보안 현황’ 보고서 역시 AI 기반 위협에 대응할 조직의 역량에 대해 보안 실무진이 보안 ...]]></description>
<link>https://tsecurity.de/de/2916948/it-security-nachrichten/ciso/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2916948/it-security-nachrichten/ciso/</guid>
<pubDate>Fri, 01 Aug 2025 08:04:16 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>조직의 사이버 보안 성숙도와 회복탄력성에 있어 보안 임원진과 실무진 사이에 뚜렷한 인식 차이가 존재하는 것으로 나타났다.</p>



<p><a href="https://www.bitdefender.com/content/dam/bitdefender/business/campaign/assessment/Official-2025-Cybersecurity-Assessment-Report.pdf" rel="nofollow">비트디펜더(BitDefender)</a>의 최근 보고서에 따르면 조직의 공격 표면이 확대되고 있지만, CISO는 중간 관리자급보다 리스크를 관리할 수 있는 역량에 대해 더 자신감을 보였다. CISO의 45%가 자신감을 보인 반면, 중간 관리자급은 이 비율이 19%에 그쳤다. 다크트레이스(Darktrace)의 ‘<a href="https://www.darktrace.com/the-state-of-ai-cybersecurity-2025" rel="nofollow">AI 사이버보안 현황</a>’ 보고서 역시 AI 기반 위협에 대응할 조직의 역량에 대해 보안 실무진이 보안 임원보다 신뢰도가 낮다(49% 대 62%)고 분석했다.</p>



<p>다크트레이스 보고서는 “신뢰도의 차이는 리더와 현장 실무진 간의 단절을 보여주는 증거”라며 “일선에서 AI 기반 공격자와 매일 맞서고 있는 실무진은 현재 솔루션이 어떤 한계를 드러내고 있는지 누구보다 잘 알고 있다”라고 설명했다.</p>



<p>침투 테스트 전문 기업 코발트(Cobalt)의 CTO 귄터 올만은 “이 같은 단절은 보안 조직에서 흔히 나타나는 현상이며, 보안 우선순위를 정렬하는 데 어려움을 초래할 수 있다”라고 말했다.</p>



<p>올만은 “매일 다양한 공격 유형을 직접 마주하는 ‘현장 최전선’의 실무진과, 그로부터 거리가 있는 임원진 사이에는 오래전부터 인식의 단절이 존재해 왔다. 현장 보안 인력은 끊임없는 경보 피로와 결코 끝나지 않는 일상적 스트레스에 시달리며, 이런 환경은 전체적인 보안 전략을 조망하기 어렵게 한다”라고 지적했다.</p>



<p>한편 사이버보안 교육 플랫폼 시큐어플래그(SecureFlag)의 기술 전문가 니코렛 클라킨은 “보안 임원진이 일상적인 사이버 보안 업무와 동떨어져 있다 보니 현장에서 발생하는 문제들이 간과될 수 있다”라고 말했다.</p>



<p>클라킨은 “임원진은 주로 요약된 보고서나 대시보드 지표에 의존하는 반면, 실무진은 커버리지의 한계, 낡은 시스템, 경보 피로 등 일상적인 문제를 직면한다. 이런 문제는 이사회 회의에서 거의 논의되지 않기 때문에 리더십에 잘못된 보안 인식을 심어주고, 보안 개발, 위협 모델링, 기술 역량과 같은 핵심 영역에 대한 과소투자로 이어질 수 있다”라고 분석했다.</p>



<p>반면 원 아이덴티티(One Identity)의 글로벌 IAM 전략 수석부사장 래리 친스키는 “중간 관리자들은 보안 프레임워크를 구성하는 실제 도구들을 직접 다루기 때문에 조직의 보안 상태에 대해 항상 더 많이 우려한다”라고 진단했다.</p>



<p>CISO와 현장 보안 실무진 간의 격차는 준비 상태 인식 수준과 실제 대응 역량 사이의 간극을 만들 수 있다. 이는 흔히 다음과 같은 문제로 이어진다.</p>



<ul class="wp-block-list">
<li><strong>우선순위 왜곡</strong>: 사이버보안 기업 아크로니스(Acronis TRU)의 수석 보안 연구원 산티아고 폰티롤리는 “보안 투자가 종종 탐지 엔지니어링, 사고 대응, 위협 억제와 같은 핵심 역량보다 가시성 확보나 규제 준수에 우선순위를 둘 수 있다”라고 말했다.</li>



<li><strong>대응 지연</strong>: 폰티롤리에 따르면 AI 기반 위협은 더 빠르고 지능적인 방어 체계를 요구하지만, 리스크를 과소 평가하다 보니 <a href="https://www.csoonline.com/article/3822459/what-is-anomaly-detection-behavior-based-analysis-for-cyber-threats.html">행동 기반 분석</a>이나 자동화 같은 핵심 업그레이드가 자주 연기되고 있다.</li>



<li><strong>효력 없는 구현</strong>: 보안 도구가 적절한 통합이나 교육 없이 배포되면 그 효력이 제한되고 운영상의 혼란을 가중시킬 수 있다.</li>
</ul>



<p>네트워크 보안 관리 기업 파이어몬(FireMon)의 국제사업 수석부사장 데이비드 브라운은 “보안 임원은 최근 사고가 없었다는 이유만으로 정책과 통제 체계가 잘 작동한다고 가정하는 경향이 있지만, 실무진은 그 이면을 더 잘 알고 있다. 실제로는 시간이 지날수록 기술 부채, 정책 난립, 설정 불일치가 누적되는 현실을 실무진은 명확히 인식하고 있다”라고 말했다.</p>



<h2 class="wp-block-heading">종종 오해되는 AI 기반 위협</h2>



<p>임원진은 주로 고차원의 컴플라이언스 지표나 벤더의 보장에 근거해 보안에 대한 자신감을 갖는다. 반면 보안 엔지니어와 분석가 등 현장 실무진은 <a href="https://www.csoonline.com/article/4014238/cybercriminals-take-malicious-ai-to-the-next-level.html">AI 기반 위협</a>의 복잡하고 빠르게 진화하는 실체를 직접 목격하고 있다.</p>



<p>사이버 리스크 관리 기업 놈사이버(NormCyber)의 CTO 폴 크래그는 “다크트레이스의 최근 연구는 이러한 인식 차이를 부각시킨다. 고위 리더들은 조직의 대비 태세를 과대평가하는 경향이 있는 반면, 현장 실무진은 훨씬 더 신중하게 평가한다”라고 말했다.</p>



<p>실제로 AI의 발전은 기존에 시간과 비용이 많이 들었던 공격 작업을 자동화할 수 있게 하며, <a href="https://www.csoonline.com/article/3632268/gen-ai-is-transforming-the-cyber-threat-landscape-by-democratizing-vulnerability-hunting.html">공격의 진입 장벽을 낮추고</a> 성공 가능성을 높이고 있다.</p>



<p>크라우드소싱 기반 사이버보안 기업 인티그리티(Intigriti)의 최고 해커 책임자 인티 드 쾨켈레어는 “현장 실무진은 일반적으로 이런 변화를 가장 먼저 인식한다. 애초에 임원진도 공격 가능성에 대한 평가를 실무진에 의존하고 있기 때문”이라고 말했다.</p>



<p>공격자들은 이미 <a href="https://www.csoonline.com/article/3819176/top-5-ways-attackers-use-generative-ai-to-exploit-your-systems.html">생성형 AI를 활용</a>해 피싱, 사칭, 랜섬웨어 전술을 대규모로 전개하고 있다. 동시에 직원의 <a href="https://www.csoonline.com/article/3964282/cisos-no-closer-to-containing-shadow-ais-skyrocketing-data-risks.html">3분의 1 이상</a>이 보안 통제나 정책, 가시성 없이 AI 도구를 비공식적으로 사용하고 있다.</p>



<p>아이반티(Ivanti) 네트워크 보안 그룹의 수석부사장 마이크 리머는 “이른바 ‘섀도우 AI’는 관리되지 않는 도구와 데이터 흐름을 조직 내부로 유입시켜 위협 범위를 급격히 확장시킨다”라며 “특히 노후화되거나 고립된 보안 통제 시스템과 결합될 경우 기존 보안 체계를 쉽게 우회하게 만든다”라고 지적했다.</p>



<p>AI 기반 위협의 진화 속도가 너무 빨라 보안 현장에서는 기존의 정책과 리스크 평가 체계로는 대응이 어려운 상황이다. 브라운은 “리더들은 정기적인 업데이트에 안심할 수 있지만, 실무진은 실시간 대응이 요구되는 끊임없이 변화하는 위협 환경을 체감하고 있다”라고 설명했다.</p>



<p>AI 관련 위협에 대한 인식 격차는 조직 내 보이지 않는 사각지대를 만들고, 그 안에서 리스크가 잠재적으로 늘어나게 된다. 리더십이 보안 태세를 실제보다 낙관할 경우, 필수적인 투자가 지연되거나 잘못된 방향으로 이뤄질 수 있다.</p>



<p>브라운은 “조직은 꼭 필요한 권한만 부여하는 방식으로 보안 아키텍처를 재설계하고, 정책 집행을 자동화하며 통제 체계를 지속적으로 검증해야 한다. 이미 수작업으로 관리하기 어려운 정책이라면 AI 기반 위협은 그 체계를 완전히 무력화시킬 수 있다”라고 경고했다.</p>



<h2 class="wp-block-heading">가시성과 맥락의 중요성</h2>



<p>포스카우트(Forescout)의 보안 인텔리전스 부사장 릭 퍼거슨은 “이 같은 인식 괴리의 상당 부분은 가시성과 맥락이라는 측면에서 비롯된다. 조직 내 역할에 따라 보안 태세를 해석하는 방식이 다르기 때문”이라고 언급했다.</p>



<p>퍼거슨은 “예를 들어 SOC 분석가는 한 종류의 데이터를, 보안 관리자는 다른 데이터를, CISO는 또 다른 데이터를 본다. 이 데이터는 각자의 역할과 책임, 사용하는 도구, 조직 내 우선순위에 따라 달라진다. 전달 과정에서 데이터는 요약되거나 재구성되고, 중요도나 시간 압박에 따라 선별적으로 강조되면서 메시지가 왜곡될 수 있다”라고 설명했다.</p>



<p>이런 과정은 결국 동일한 데이터에 대한 서로 다른 해석으로 이어지며, 조직의 실제 보안 성숙도나 리스크 노출 수준에 대한 오해와 보안 우선순위의 불일치를 낳을 수 있다.</p>



<p>또한 GRC 인터내셔널 그룹(GRC International Group)의 정보보안 관리자 아담 시먼스는 CISO의 조직 내 <a href="https://www.csoonline.com/article/3626973/cisos-embrace-rise-in-prominence-with-broader-business-authority.html">위상</a>이 높아지고 <a href="https://www.csoonline.com/article/4002753/cisos-reposition-their-roles-for-business-leadership.html">비즈니스 리더십</a> 역할로 재편되면서 이런 단절이 더 심화되고 있을 수 있다고 지적했다.</p>



<p>시먼스는 “많은 CISO가 기술 책임자에서 비즈니스 리더로 역할을 전환해 왔다. 문제는 이 과정에서 운영 현장의 세부 사항과 점점 멀어지게 된다는 점”이라고 말했다. 그는 “이로 인해 경영진이 인식하는 보안 상황과 현장에서 실제로 벌어지는 일 사이에 일종의 ‘해석 격차’가 생긴다”라고 설명했다.</p>



<h2 class="wp-block-heading">공통된 지표의 부재</h2>



<p>리스크와 보안 태세에 대한 공통된 인식이 없으면 전략이 분산되고, 그 결과 의사결정 속도가 느려지거나 특정 영역에 과잉 또는 과소 투자로 이어질 수 있다. 이는 결국 공격자가 파고들 수 있는 사각지대를 만든다.</p>



<p>포스카우트의 퍼거슨은 “이 격차를 해소하려면 보안 데이터를 전달하고 맥락화하는 방식을 개선하는 일부터 시작해야 한다. 보안 도구는 필터링된 정보를 상위 단계로 전달하는 대신 동일한 기초 데이터를 각 역할에 맞게 제시할 수 있어야 한다”라고 말했다.</p>



<p>가령 SOC 분석가는 기술 세부 정보를 필요로 하지만, CISO는 비즈니스 영향 수준과 관련된 맥락을 요구할 수 있다. 퍼거슨은 “도구가 의미를 훼손하지 않으면서 각 역할에 맞는 맥락을 제공할 수 있다면 왜곡을 줄이고 공동의 이해를 높이는 데 유용할 것”이라고 설명했다.</p>



<p>일부 전문가는 도구 고도화와 내부 소통 개선이 맞물리면서 보안 인식 격차가 점차 좁혀지고 있다고 봤다.</p>



<p>원 아이덴티티의 친스키는 “CISO는 팀과 더 긴밀히 협력하고, 정기적으로 소통하며 최신 기술을 적극적으로 활용해 보안 태세의 취약 지점을 함께 파악해야 한다”라고 조언했다. 또한 그는 “최근 기업의 공격 표면이 크게 확장되면서 CISO의 현장 개입이 훨씬 깊어지고 있다. 이들이 보안 태세 강화를 위해 새로운 도구를 도입함에 따라 인식 격차가 크게 줄어들 가능성이 있다”라고 전망했다.<br>dl-ciokorea@foundryco.com</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hackers Target SAP NetWeaver to Deploy New Auto-Color Linux Malware]]></title>
<description><![CDATA[Cybersecurity researchers at Darktrace have uncovered a sophisticated attack targeting a US-based chemicals company, marking the first observed instance of threat actors exploiting SAP NetWeaver vulnerabilities to deploy Auto-Color backdoor malware. The incident, which occurred over three days in...]]></description>
<link>https://tsecurity.de/de/2913170/hacking/hackers-target-sap-netweaver-to-deploy-new-auto-color-linux-malware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2913170/hacking/hackers-target-sap-netweaver-to-deploy-new-auto-color-linux-malware/</guid>
<pubDate>Wed, 30 Jul 2025 11:27:40 +0200</pubDate>
<content:encoded><![CDATA[<p>Cybersecurity researchers at Darktrace have uncovered a sophisticated attack targeting a US-based chemicals company, marking the first observed instance of threat actors exploiting SAP NetWeaver vulnerabilities to deploy Auto-Color backdoor malware. The incident, which occurred over three days in April 2025, demonstrates an alarming evolution in cyber attack tactics combining enterprise software exploitation with advanced […]</p>
<p>The post <a href="https://gbhackers.com/hackers-target-sap-netweaver/">Hackers Target SAP NetWeaver to Deploy New Auto-Color Linux Malware</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Critical SAP flaw exploited to launch Auto-Color Malware attack on U.S. company]]></title>
<description><![CDATA[Hackers exploited a SAP NetWeaver bug to deploy upgraded Auto-Color Linux malware in an attack on U.S. chemicals firm. Cybersecurity firm Darktrace reported that threat actors exploited a SAP NetWeaver flaw, tracked as CVE-2025-31324, to deploy Auto-Color Linux malware in a U.S. chemicals firm at...]]></description>
<link>https://tsecurity.de/de/2913091/hacking/critical-sap-flaw-exploited-to-launch-auto-color-malware-attack-on-us-company/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2913091/hacking/critical-sap-flaw-exploited-to-launch-auto-color-malware-attack-on-us-company/</guid>
<pubDate>Wed, 30 Jul 2025 10:34:55 +0200</pubDate>
<content:encoded><![CDATA[Hackers exploited a SAP NetWeaver bug to deploy upgraded Auto-Color Linux malware in an attack on U.S. chemicals firm. Cybersecurity firm Darktrace reported that threat actors exploited a SAP NetWeaver flaw, tracked as CVE-2025-31324, to deploy Auto-Color Linux malware in a U.S. chemicals firm attack. “In April 2025, Darktrace identified an Auto-Color backdoor malware attack […]]]></content:encoded>
</item>
<item>
<title><![CDATA[Darktrace Acquires Mira Security for Network Visibility]]></title>
<description><![CDATA[The acquisition gives the British cybersecurity solutions provider more insights into encrypted network traffic and additional decryption capabilities.]]></description>
<link>https://tsecurity.de/de/2900135/it-security-nachrichten/darktrace-acquires-mira-security-for-network-visibility/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2900135/it-security-nachrichten/darktrace-acquires-mira-security-for-network-visibility/</guid>
<pubDate>Tue, 22 Jul 2025 15:19:42 +0200</pubDate>
<content:encoded><![CDATA[The acquisition gives the British cybersecurity solutions provider more insights into encrypted network traffic and additional decryption capabilities.]]></content:encoded>
</item>
<item>
<title><![CDATA[Darktrace kauft Netzwerk-Spezialisten Mira Security]]></title>
<description><![CDATA[Die Sicherheitsplattform des britischen Cybersecurity-Anbieters Darktrace erhält Zuwachs: Das Unternehmen hat den amerikanischen Netzwerkverkehr-Analysten Mira Security übernommen. Damit will Darktrace vor allem verschlüsselte Datenströme besser durchleuchten können.

Tags: #Firmenübernahme]]></description>
<link>https://tsecurity.de/de/2900075/it-security-nachrichten/darktrace-kauft-netzwerk-spezialisten-mira-security/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2900075/it-security-nachrichten/darktrace-kauft-netzwerk-spezialisten-mira-security/</guid>
<pubDate>Tue, 22 Jul 2025 14:48:19 +0200</pubDate>
<content:encoded><![CDATA[<p><img width="1920" height="1080" src="https://www.it-daily.net/wp-content/uploads/2025/07/Handshake-Cybersecurity-Shutterstock-2116749248-1920.jpg" class="attachment-full size-full wp-post-image" alt="Handshake" decoding="async" srcset="https://www.it-daily.net/wp-content/uploads/2025/07/Handshake-Cybersecurity-Shutterstock-2116749248-1920.jpg 1920w, https://www.it-daily.net/wp-content/uploads/2025/07/Handshake-Cybersecurity-Shutterstock-2116749248-1920-300x169.jpg 300w, https://www.it-daily.net/wp-content/uploads/2025/07/Handshake-Cybersecurity-Shutterstock-2116749248-1920-1024x576.jpg 1024w, https://www.it-daily.net/wp-content/uploads/2025/07/Handshake-Cybersecurity-Shutterstock-2116749248-1920-768x432.jpg 768w, https://www.it-daily.net/wp-content/uploads/2025/07/Handshake-Cybersecurity-Shutterstock-2116749248-1920-1536x864.jpg 1536w" sizes="(max-width: 1920px) 100vw, 1920px" title="Darktrace kauft Netzwerk-Spezialisten Mira Security 1"></p>
    Die Sicherheitsplattform des britischen Cybersecurity-Anbieters Darktrace erhält Zuwachs: Das Unternehmen hat den amerikanischen Netzwerkverkehr-Analysten Mira Security übernommen. Damit will Darktrace vor allem verschlüsselte Datenströme besser durchleuchten können.

<p>Tags: <a href="https://www.it-daily.net/thema/firmenuebernahme">#Firmenübernahme</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Darktrace Acquires Mira Security]]></title>
<description><![CDATA[AI-powered cybersecurity company Darktrace has acquired network traffic visibility provider Mira Security.
The post Darktrace Acquires Mira Security appeared first on SecurityWeek.]]></description>
<link>https://tsecurity.de/de/2900006/it-security-nachrichten/darktrace-acquires-mira-security/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2900006/it-security-nachrichten/darktrace-acquires-mira-security/</guid>
<pubDate>Tue, 22 Jul 2025 14:19:59 +0200</pubDate>
<content:encoded><![CDATA[<p>AI-powered cybersecurity company Darktrace has acquired network traffic visibility provider Mira Security.</p>
<p>The post <a href="https://www.securityweek.com/darktrace-acquires-mira-security/">Darktrace Acquires Mira Security</a> appeared first on <a href="https://www.securityweek.com/">SecurityWeek</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Phishing als Türöffner]]></title>
<description><![CDATA[Phishing ist nach wie vor eine der hartnäckigsten und wirkungsvollsten Methoden, die Cyberkriminelle einsetzen. Allein im Jahr 2024 hat Darktrace mehr als 30,4 Millionen Phishing-Angriffe registriert. 

Tags: #cybercrime | #Künstliche Intelligenz | #Phishing]]></description>
<link>https://tsecurity.de/de/2891514/it-security-nachrichten/phishing-als-tueroeffner/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2891514/it-security-nachrichten/phishing-als-tueroeffner/</guid>
<pubDate>Thu, 17 Jul 2025 07:18:25 +0200</pubDate>
<content:encoded><![CDATA[<p><img width="1920" height="1080" src="https://www.it-daily.net/wp-content/uploads/2025/07/Phishing.jpg" class="attachment-full size-full wp-post-image" alt="Phishing" decoding="async" srcset="https://www.it-daily.net/wp-content/uploads/2025/07/Phishing.jpg 1920w, https://www.it-daily.net/wp-content/uploads/2025/07/Phishing-300x169.jpg 300w, https://www.it-daily.net/wp-content/uploads/2025/07/Phishing-1024x576.jpg 1024w, https://www.it-daily.net/wp-content/uploads/2025/07/Phishing-768x432.jpg 768w, https://www.it-daily.net/wp-content/uploads/2025/07/Phishing-1536x864.jpg 1536w" sizes="(max-width: 1920px) 100vw, 1920px" title="Phishing als Türöffner 1"></p>
    Phishing ist nach wie vor eine der hartnäckigsten und wirkungsvollsten Methoden, die Cyberkriminelle einsetzen. Allein im Jahr 2024 hat Darktrace mehr als 30,4 Millionen Phishing-Angriffe registriert. 

<p>Tags: <a href="https://www.it-daily.net/thema/cybercrime">#cybercrime</a> | <a href="https://www.it-daily.net/thema/kuenstliche-intelligenz">#Künstliche Intelligenz</a> | <a href="https://www.it-daily.net/thema/phishing">#Phishing</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Fake Gaming and AI Companies Target Windows and macOS Users with Drainer Malware Attacks]]></title>
<description><![CDATA[The cybersecurity company Darktrace has uncovered a persistent, intricate social engineering campaign that targets bitcoin users, building on earlier findings by Cado Security Labs in December 2024. Threat actors are fabricating elaborate startup companies themed around AI, gaming, video conferen...]]></description>
<link>https://tsecurity.de/de/2882819/hacking/fake-gaming-and-ai-companies-target-windows-and-macos-users-with-drainer-malware-attacks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2882819/hacking/fake-gaming-and-ai-companies-target-windows-and-macos-users-with-drainer-malware-attacks/</guid>
<pubDate>Sun, 13 Jul 2025 00:19:10 +0200</pubDate>
<content:encoded><![CDATA[<p>The cybersecurity company Darktrace has uncovered a persistent, intricate social engineering campaign that targets bitcoin users, building on earlier findings by Cado Security Labs in December 2024. Threat actors are fabricating elaborate startup companies themed around AI, gaming, video conferencing, Web3, and social media to lure victims into downloading malware disguised as legitimate software. These […]</p>
<p>The post <a href="https://gbhackers.com/fake-gaming-and-ai-companies-target-windows-and-macos-users/">Fake Gaming and AI Companies Target Windows and macOS Users with Drainer Malware Attacks</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Defeating PumaBot: How Check Point Quantum IoT Protect Nano Agent Shields Surveillance Devices]]></title>
<description><![CDATA[The threat at a glance Darktrace researchers have identified PumaBot, a Go-based Linux botnet that focuses on embedded surveillance cameras and other IoT devices.Unlike spray-and-pray botnets that scan the whole internet, PumaBot pulls a curated IP list from its C2 and then brute-forces SSH login...]]></description>
<link>https://tsecurity.de/de/2846788/it-security-nachrichten/defeating-pumabot-how-check-point-quantum-iot-protect-nano-agent-shields-surveillance-devices/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2846788/it-security-nachrichten/defeating-pumabot-how-check-point-quantum-iot-protect-nano-agent-shields-surveillance-devices/</guid>
<pubDate>Mon, 23 Jun 2025 15:33:30 +0200</pubDate>
<content:encoded><![CDATA[<img width="800" height="400" src="https://blog.checkpoint.com/wp-content/uploads/2025/04/hidden-costs-of-cloud-saas-only-blog-post-featured-image.png" class="webfeedsFeaturedVisual wp-post-image" alt="" link_thumbnail="" decoding="async" fetchpriority="high" srcset="https://blog.checkpoint.com/wp-content/uploads/2025/04/hidden-costs-of-cloud-saas-only-blog-post-featured-image.png 800w, https://blog.checkpoint.com/wp-content/uploads/2025/04/hidden-costs-of-cloud-saas-only-blog-post-featured-image-300x150.png 300w, https://blog.checkpoint.com/wp-content/uploads/2025/04/hidden-costs-of-cloud-saas-only-blog-post-featured-image-768x384.png 768w, https://blog.checkpoint.com/wp-content/uploads/2025/04/hidden-costs-of-cloud-saas-only-blog-post-featured-image-400x200.png 400w, https://blog.checkpoint.com/wp-content/uploads/2025/04/hidden-costs-of-cloud-saas-only-blog-post-featured-image-600x300.png 600w" sizes="(max-width: 800px) 100vw, 800px"><p>The threat at a glance Darktrace researchers have identified PumaBot, a Go-based Linux botnet that focuses on embedded surveillance cameras and other IoT devices.Unlike spray-and-pray botnets that scan the whole internet, PumaBot pulls a curated IP list from its C2 and then brute-forces SSH logins on port 22 until it gets a shell. Once in, it drops its payload under /lib, registers a rogue systemd service, injects a back-door key into ~/.ssh/authorized_keys, and can fetch further modules via the same C2 channel. Why device-level controls matter Because PumaBot’s entire kill-chain exploited vulnerabilities and misconfiguration on the device itself, network-edge firewalls […]</p>
<p>The post <a href="https://blog.checkpoint.com/securing-the-network/defeating-pumabot-how-check-point-quantum-iot-protect-nano-agent-shields-surveillance-devices/">Defeating PumaBot: How Check Point Quantum IoT Protect Nano Agent Shields Surveillance Devices</a> appeared first on <a href="https://blog.checkpoint.com/">Check Point Blog</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[New Linux PumaBot Targets IoT Devices with SSH Credential Brute-Force Attack]]></title>
<description><![CDATA[A new and insidious threat has surfaced in the cybersecurity landscape as Darktrace’s Threat Research team uncovers PumaBot, a Go-based Linux botnet meticulously designed to exploit embedded Internet of Things (IoT) devices. Unlike conventional botnets that cast a wide net through indiscriminate ...]]></description>
<link>https://tsecurity.de/de/2813155/hacking/new-linux-pumabot-targets-iot-devices-with-ssh-credential-brute-force-attack/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2813155/hacking/new-linux-pumabot-targets-iot-devices-with-ssh-credential-brute-force-attack/</guid>
<pubDate>Tue, 03 Jun 2025 19:04:26 +0200</pubDate>
<content:encoded><![CDATA[<p>A new and insidious threat has surfaced in the cybersecurity landscape as Darktrace’s Threat Research team uncovers PumaBot, a Go-based Linux botnet meticulously designed to exploit embedded Internet of Things (IoT) devices. Unlike conventional botnets that cast a wide net through indiscriminate internet scans, PumaBot employs a highly targeted strategy, fetching a curated list of […]</p>
<p>The post <a href="https://gbhackers.com/new-linux-pumabot-targets-iot-devices/">New Linux PumaBot Targets IoT Devices with SSH Credential Brute-Force Attack</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Photos: Infosecurity Europe 2025]]></title>
<description><![CDATA[Infosecurity Europe 2025 is a cybersecurity event taking place from June 3 to 5 in London. Help Net Security is on-site and here’s a closer look at the conference. The featured vendors are: Okta, PlexTrac, ISC2, Insight, EasyDMARC, Defense.com, Tines, Darktrace, Torq, and Cyrebro.
The post Photos...]]></description>
<link>https://tsecurity.de/de/2812418/it-security-nachrichten/photos-infosecurity-europe-2025/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2812418/it-security-nachrichten/photos-infosecurity-europe-2025/</guid>
<pubDate>Tue, 03 Jun 2025 13:48:46 +0200</pubDate>
<content:encoded><![CDATA[<p>Infosecurity Europe 2025 is a cybersecurity event taking place from June 3 to 5 in London. Help Net Security is on-site and here’s a closer look at the conference. The featured vendors are: Okta, PlexTrac, ISC2, Insight, EasyDMARC, Defense.com, Tines, Darktrace, Torq, and Cyrebro.</p>
<p>The post <a href="https://www.helpnetsecurity.com/2025/06/03/infosecurity-europe-2025-photos/">Photos: Infosecurity Europe 2025</a> appeared first on <a href="https://www.helpnetsecurity.com/">Help Net Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[New PumaBot targets Linux IoT surveillance devices]]></title>
<description><![CDATA[PumaBot targets Linux IoT devices, using SSH brute-force attacks to steal credentials, spread malware, and mine crypto. Darktrace researchers discovered a new botnet called PumaBot targets Linux-based IoT devices, using SSH brute-force attacks to steal credentials, spread malware, and mine crypto...]]></description>
<link>https://tsecurity.de/de/2802938/it-security-nachrichten/new-pumabot-targets-linux-iot-surveillance-devices/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2802938/it-security-nachrichten/new-pumabot-targets-linux-iot-surveillance-devices/</guid>
<pubDate>Wed, 28 May 2025 17:04:20 +0200</pubDate>
<content:encoded><![CDATA[PumaBot targets Linux IoT devices, using SSH brute-force attacks to steal credentials, spread malware, and mine crypto. Darktrace researchers discovered a new botnet called PumaBot targets Linux-based IoT devices, using SSH brute-force attacks to steal credentials, spread malware, and mine cryptocurrency. PumaBot skips broad internet scans and instead pulls a list of targets from its […]]]></content:encoded>
</item>
<item>
<title><![CDATA[From hype to harm: 78% of CISOs see AI attacks already]]></title>
<description><![CDATA[AI attacks are keeping most practitioners up at night, says Darktrace, and with good reason Sponsored feature  From the written word through to gunpowder and email, whenever an enabling technology comes along, you can be sure someone will be ready to use it for evil. Most tech is dual-use, and AI...]]></description>
<link>https://tsecurity.de/de/2779861/it-security-nachrichten/from-hype-to-harm-78-of-cisos-see-ai-attacks-already/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2779861/it-security-nachrichten/from-hype-to-harm-78-of-cisos-see-ai-attacks-already/</guid>
<pubDate>Fri, 16 May 2025 11:18:51 +0200</pubDate>
<content:encoded><![CDATA[<h4>AI attacks are keeping most practitioners up at night, says Darktrace, and with good reason</h4> <p><strong>Sponsored feature</strong>  From the written word through to gunpowder and email, whenever an enabling technology comes along, you can be sure someone will be ready to use it for evil. Most tech is dual-use, and AI is no exception.…</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Healthcare Cyber-Attacks Intensify, Sector Now Prime Target]]></title>
<description><![CDATA[New data from Darktrace showed that cyber-attacks targeting healthcare organizations increased in intensity in 2024]]></description>
<link>https://tsecurity.de/de/2779856/it-security-nachrichten/healthcare-cyber-attacks-intensify-sector-now-prime-target/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2779856/it-security-nachrichten/healthcare-cyber-attacks-intensify-sector-now-prime-target/</guid>
<pubDate>Fri, 16 May 2025 11:18:44 +0200</pubDate>
<content:encoded><![CDATA[New data from Darktrace showed that cyber-attacks targeting healthcare organizations increased in intensity in 2024]]></content:encoded>
</item>
<item>
<title><![CDATA[Cybersicherheit im Zeitalter der KI: Ergebnisse einer weltweiten Studie - Darktrace]]></title>
<description><![CDATA[In diesem Webinar präsentiert Darktrace die wichtigsten Ergebnisse einer aktuellen Umfrage unter mehr als 1.500 IT- und Cybersicherheitsexperten ...]]></description>
<link>https://tsecurity.de/de/2767525/it-security-nachrichten/cybersicherheit-im-zeitalter-der-ki-ergebnisse-einer-weltweiten-studie-darktrace/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2767525/it-security-nachrichten/cybersicherheit-im-zeitalter-der-ki-ergebnisse-einer-weltweiten-studie-darktrace/</guid>
<pubDate>Fri, 09 May 2025 23:48:30 +0200</pubDate>
<content:encoded><![CDATA[In diesem Webinar präsentiert Darktrace die wichtigsten Ergebnisse einer aktuellen Umfrage unter mehr als 1.500 <b>IT</b>- und Cybersicherheitsexperten ...]]></content:encoded>
</item>
<item>
<title><![CDATA[RansomHub Taps SocGholish: WebDAV & SCF Exploits Fuel Credential Heists]]></title>
<description><![CDATA[SocGholish, a notorious loader malware, has evolved into a critical tool for cybercriminals, often delivering payloads like Cobalt Strike and, more recently, RansomHub ransomware. Darktrace’s Threat Research team has tracked multiple incidents since January 2025, where threat actors exploited Soc...]]></description>
<link>https://tsecurity.de/de/2756259/hacking/ransomhub-taps-socgholish-webdav-scf-exploits-fuel-credential-heists/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2756259/hacking/ransomhub-taps-socgholish-webdav-scf-exploits-fuel-credential-heists/</guid>
<pubDate>Sun, 04 May 2025 00:35:28 +0200</pubDate>
<content:encoded><![CDATA[<p>SocGholish, a notorious loader malware, has evolved into a critical tool for cybercriminals, often delivering payloads like Cobalt Strike and, more recently, RansomHub ransomware. Darktrace’s Threat Research team has tracked multiple incidents since January 2025, where threat actors exploited SocGholish to compromise networks through fake browser updates and JavaScript-based attacks on vulnerable CMS platforms like […]</p>
<p>The post <a href="https://gbhackers.com/webdav-scf-exploits-fuel-credential-heists/">RansomHub Taps SocGholish: WebDAV &amp; SCF Exploits Fuel Credential Heists</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[AiTM Phishing Kits Bypass MFA by Hijacking Credentials and Session Tokens]]></title>
<description><![CDATA[Darktrace’s Security Operations Center (SOC) in late 2024 and early 2025, cybercriminals have been exploiting legitimate Software-as-a-Service (SaaS) platforms like Milanote to orchestrate sophisticated phishing campaigns. These attacks, bolstered by the Tycoon 2FA phishing kit, demonstrate an ad...]]></description>
<link>https://tsecurity.de/de/2751559/hacking/aitm-phishing-kits-bypass-mfa-by-hijacking-credentials-and-session-tokens/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2751559/hacking/aitm-phishing-kits-bypass-mfa-by-hijacking-credentials-and-session-tokens/</guid>
<pubDate>Wed, 30 Apr 2025 18:23:24 +0200</pubDate>
<content:encoded><![CDATA[<p>Darktrace’s Security Operations Center (SOC) in late 2024 and early 2025, cybercriminals have been exploiting legitimate Software-as-a-Service (SaaS) platforms like Milanote to orchestrate sophisticated phishing campaigns. These attacks, bolstered by the Tycoon 2FA phishing kit, demonstrate an advanced Adversary-in-the-Middle (AiTM) approach that circumvents multi-factor authentication (MFA) protections. Leveraging Legitimate Services for Stealthy Attacks By abusing […]</p>
<p>The post <a href="https://gbhackers.com/aitm-phishing-kits-bypass-mfa-by-hijacking-credentials/">AiTM Phishing Kits Bypass MFA by Hijacking Credentials and Session Tokens</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[A new era of cyber threats is approaching for the energy sector]]></title>
<description><![CDATA[Cyber threats targeting the energy sector come in many forms, including state-sponsored actors seeking to disrupt national infrastructure, cybercriminals motivated by profit, and insiders intentionally causing damage. The consequences of a successful attack can be severe, potentially disrupting e...]]></description>
<link>https://tsecurity.de/de/2739988/it-security-nachrichten/a-new-era-of-cyber-threats-is-approaching-for-the-energy-sector/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2739988/it-security-nachrichten/a-new-era-of-cyber-threats-is-approaching-for-the-energy-sector/</guid>
<pubDate>Thu, 24 Apr 2025 07:05:25 +0200</pubDate>
<content:encoded><![CDATA[<p>Cyber threats targeting the energy sector come in many forms, including state-sponsored actors seeking to disrupt national infrastructure, cybercriminals motivated by profit, and insiders intentionally causing damage. The consequences of a successful attack can be severe, potentially disrupting energy supplies and causing economic and social damage, according to Darktrace’s research focused on the UK and US energy sector over a three-year period (November 2021 – Dec 2024). Email as the initial attack vector As seen … <a href="https://www.helpnetsecurity.com/2025/04/24/energy-sector-cyber-threats/" rel="nofollow">More <span class="meta-nav">→</span></a></p>
<p>The post <a href="https://www.helpnetsecurity.com/2025/04/24/energy-sector-cyber-threats/">A new era of cyber threats is approaching for the energy sector</a> appeared first on <a href="https://www.helpnetsecurity.com/">Help Net Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Crypto mining campaign targets Docker environments with new evasion technique]]></title>
<description><![CDATA[New malware campaign targets Docker environments using unknown methods to secretly mine cryptocurrency, researchers warn. Researchers from Darktrace and Cado Security have spotted a malware campaign that targets Docker environments with a novel technique to mine cryptocurrency. The malware campai...]]></description>
<link>https://tsecurity.de/de/2739420/hacking/crypto-mining-campaign-targets-docker-environments-with-new-evasion-technique/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2739420/hacking/crypto-mining-campaign-targets-docker-environments-with-new-evasion-technique/</guid>
<pubDate>Wed, 23 Apr 2025 20:37:03 +0200</pubDate>
<content:encoded><![CDATA[New malware campaign targets Docker environments using unknown methods to secretly mine cryptocurrency, researchers warn. Researchers from Darktrace and Cado Security have spotted a malware campaign that targets Docker environments with a novel technique to mine cryptocurrency. The malware campaign targets Docker environments to deploy a malicious node connected to Teneo, a decentralized infrastructure network. […]<!-- START: Dynamically Added Content --><br><h3>KI generiertes Nachrichten Update</h3><hr>This website uses cookies to improve your experience. By continuing to use the site, you agree to the use of cookies.
Learn more
Accept































Privacy Policy 
Cookie Policy 
Contact Us 

© 2024 Security Affairs. All rights reserved. 




Close<!-- END: Dynamically Added Content -->]]></content:encoded>
</item>
<item>
<title><![CDATA[New Malware Hijacks Docker Images Using Unique Obfuscation Technique]]></title>
<description><![CDATA[A recently uncovered malware campaign targeting Docker, one of the most frequently attacked services according to Darktrace’s honeypot data, has revealed a startling level of sophistication in obfuscation and cryptojacking methods. This novel attack begins with a seemingly innocuous request to la...]]></description>
<link>https://tsecurity.de/de/2738809/hacking/new-malware-hijacks-docker-images-using-unique-obfuscation-technique/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2738809/hacking/new-malware-hijacks-docker-images-using-unique-obfuscation-technique/</guid>
<pubDate>Wed, 23 Apr 2025 15:22:23 +0200</pubDate>
<content:encoded><![CDATA[<p>A recently uncovered malware campaign targeting Docker, one of the most frequently attacked services according to Darktrace’s honeypot data, has revealed a startling level of sophistication in obfuscation and cryptojacking methods. This novel attack begins with a seemingly innocuous request to launch a container from Docker Hub, specifically the kazutod/tene:ten image. Sophisticated Attack Targets Docker […]</p>
<p>The post <a href="https://gbhackers.com/new-malware-hijacks-docker-images/">New Malware Hijacks Docker Images Using Unique Obfuscation Technique</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Docker Malware Exploits Teneo Web3 Node to Earn Crypto via Fake Heartbeat Signals]]></title>
<description><![CDATA[Cybersecurity researchers have detailed a malware campaign that's targeting Docker environments with a previously undocumented technique to mine cryptocurrency.
The activity cluster, per Darktrace and Cado Security, represents a shift from other cryptojacking campaigns that directly deploy miners...]]></description>
<link>https://tsecurity.de/de/2737202/it-security-nachrichten/docker-malware-exploits-teneo-web3-node-to-earn-crypto-via-fake-heartbeat-signals/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2737202/it-security-nachrichten/docker-malware-exploits-teneo-web3-node-to-earn-crypto-via-fake-heartbeat-signals/</guid>
<pubDate>Tue, 22 Apr 2025 19:34:16 +0200</pubDate>
<content:encoded><![CDATA[Cybersecurity researchers have detailed a malware campaign that's targeting Docker environments with a previously undocumented technique to mine cryptocurrency.
The activity cluster, per Darktrace and Cado Security, represents a shift from other cryptojacking campaigns that directly deploy miners like XMRig to illicitly profit off the compute resources.
This involves deploying a malware strain]]></content:encoded>
</item>
<item>
<title><![CDATA[New Cryptojacking Malware Targets Docker with Novel Mining Technique]]></title>
<description><![CDATA[Darktrace and Cado said the new campaign highlights a shift towards alternative methods of mining cryptocurrencies]]></description>
<link>https://tsecurity.de/de/2736710/it-security-nachrichten/new-cryptojacking-malware-targets-docker-with-novel-mining-technique/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2736710/it-security-nachrichten/new-cryptojacking-malware-targets-docker-with-novel-mining-technique/</guid>
<pubDate>Tue, 22 Apr 2025 16:20:27 +0200</pubDate>
<content:encoded><![CDATA[Darktrace and Cado said the new campaign highlights a shift towards alternative methods of mining cryptocurrencies]]></content:encoded>
</item>
<item>
<title><![CDATA[Darktrace erweitert KI-Modelle für präzisere Cybersicherheit - it boltwise]]></title>
<description><![CDATA[Ein zentrales Element der neuen Modelle ist das Darktrace Incident Graph Evaluation for Security Threats (DIGEST), das dem Cyber AI Analyst hilft, ...KI generiertes Nachrichten UpdateVerwendetes künstliches Intelligenz Model: gemma-3-12b-itund erweitere diese durch dein Fachwissen.  Der Artikel s...]]></description>
<link>https://tsecurity.de/de/2732063/it-security-nachrichten/darktrace-erweitert-ki-modelle-fuer-praezisere-cybersicherheit-it-boltwise/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2732063/it-security-nachrichten/darktrace-erweitert-ki-modelle-fuer-praezisere-cybersicherheit-it-boltwise/</guid>
<pubDate>Sat, 19 Apr 2025 01:32:19 +0200</pubDate>
<content:encoded><![CDATA[Ein zentrales Element der neuen Modelle ist das Darktrace Incident Graph Evaluation for <b>Security</b> Threats (DIGEST), das dem <b>Cyber</b> AI Analyst hilft, ...<!-- START: Dynamically Added Content --><br><h3>KI generiertes Nachrichten Update</h3><hr>Verwendetes künstliches Intelligenz Model: gemma-3-12b-it<br><br><p>und erweitere diese durch dein Fachwissen.  Der Artikel soll folgende Aspekte beinhalten:</p><br />
<ul><br />
<li><strong>Einführung:</strong> Kontextualisierung der Bedeutung von KI in der Cybersicherheit.</li><br />
<li><strong>Darktraces Ansatz (Antigena):</strong> Detaillierte Beschreibung der Funktionsweise von Antigena, einschließlich der verwendeten KI-Techniken (z.B. unsupervised learning, anomaly detection).  Gehe auf die Vorteile gegenüber traditionellen Signaturen/Regelbasierung ein.</li><br />
<li><strong>Erweiterungen der KI-Modelle:</strong> Welche konkreten Verbesserungen wurden vorgenommen? Wie beeinflussen diese die Genauigkeit und Effizienz der Erkennung? (z.B. verbesserte Kontextsensitivität, Reduktion von False Positives)</li><br />
<li><strong>Herausforderungen &amp; Limitationen:</strong>  Diskussion möglicher Schwachstellen des KI-basierten Ansatzes, z.B. Adversarial Attacks, Data Poisoning, Bias in Trainingsdaten.  Wie geht Darktrace damit um?</li><br />
<li><strong>Ausblick:</strong> Zukunftstrends im Bereich KI-gestützte Cybersicherheit und die mögliche Rolle von Darktrace.</li><br />
<li><strong>Zielgruppe:</strong> IT-Sicherheitsverantwortliche, Architekten und Entscheider.</li><br />
</ul><br />
<h2>Schreibe den Artikel in einem professionellen Ton, vermeide unnötigen Jargon und erkläre komplexe Konzepte verständlich.  Länge: ca. 800 - 1200 Wörter.</h2><br />
<h2>Darktrace erweitert KI-Modelle für präzisere Cybersicherheit – Ein tieferer Blick auf Antigena und seine Evolution</h2><br />
<p>Die Bedrohungslandschaft entwickelt sich rasant weiter. Traditionelle Sicherheitslösungen, die auf Signaturen und vordefinierten Regeln basieren, haben zunehmend Schwierigkeiten, mit der Geschwindigkeit und Raffinesse moderner Cyberangriffe Schritt zu halten. Hier kommt Künstliche Intelligenz (KI) ins Spiel – eine Technologie, die das Potenzial hat, die Art und Weise, wie wir unsere digitalen Assets schützen, grundlegend zu verändern. Darktrace, ein führender Anbieter von KI-gestützter Cybersicherheit, setzt diesen Trend konsequent fort und erweitert seine Modelle kontinuierlich, um präzisere und effektivere Abwehrstrategien zu ermöglichen. Dieser Artikel beleuchtet den Ansatz von Darktrace, insbesondere die Funktionsweise von Antigena, analysiert die jüngsten Erweiterungen der KI-Modelle und diskutiert die damit verbundenen Herausforderungen und zukünftigen Trends.</p><br />
<p><strong>Die Notwendigkeit von KI in der Cybersicherheit</strong></p><br />
<p>Traditionell basierte IT-Sicherheit auf einem reaktiven Ansatz: Signaturen bekannter Malware wurden erstellt, Regeln definiert und Systeme überwacht, um verdächtiges Verhalten zu erkennen. Doch diese Methoden sind anfällig für Zero-Day-Exploits – Angriffe, die sich neue Schwachstellen zunutze machen, bevor ein Patch verfügbar ist.  Darüber hinaus erfordern sie einen erheblichen manuellen Aufwand zur kontinuierlichen Aktualisierung und Anpassung an neue Bedrohungen.</p><br />
<p>KI bietet eine Alternative. Insbesondere <em>unsupervised learning</em> (nicht überwachtes Lernen) ermöglicht es Systemen, Muster im Netzwerkverkehr zu erkennen, ohne dass explizite Trainingsdaten für bösartiges Verhalten erforderlich sind.  Dies erlaubt die Erkennung von Anomalien – Abweichungen vom normalen Verhalten – die auf bisher unbekannte Angriffe hindeuten könnten.</p><br />
<p><strong>Darktraces Ansatz: Antigena in Aktion</strong></p><br />
<p>Im Kern der Darktrace-Lösung steht Antigena, ein autonomes Response-System, das auf den Erkenntnissen des Darktrace AI Detection Engine basiert.  Antigena lernt kontinuierlich das “digitale Verhalten” einer Organisation kennen und erstellt so ein detailliertes Verständnis davon, was normal ist. Es analysiert dabei eine Vielzahl von Datenpunkten: Netzwerkverkehr, Benutzeraktivität, Dateizugriffe und mehr.</p><br />
<p>Im Gegensatz zu traditionellen SIEM-Systemen (Security Information and Event Management), die große Mengen an Alarme generieren und menschliche Analysten überfordern, agiert Antigena proaktiv.  Es kann autonom verdächtige Aktivitäten blockieren oder einschränken, bevor sie Schaden anrichten können – beispielsweise durch das Isolieren eines kompromittierten Hosts vom Netzwerk oder das Stoppen eines bösartigen Prozesses.</p><br />
<p>Die zugrundeliegenden KI-Techniken in Antigena umfassen:</p><br />
<ul><br />
<li><strong>Unsupervised Learning:</strong>  Identifiziert Anomalien im Netzwerkverhalten, ohne auf vorher definierte Signaturen angewiesen zu sein.</li><br />
<li><strong>Anomaly Detection:</strong>  Verwendet statistische Modelle und Machine Learning Algorithmen, um Abweichungen vom normalen Verhalten zu erkennen.</li><br />
<li><strong>Pattern Recognition:</strong> Identifiziert wiederkehrende Muster in Daten, die auf Angriffe hindeuten könnten.</li><br />
<li><strong>Behavioral Analytics:</strong> Analysiert das Verhalten von Benutzern und Geräten, um potenzielle Insider-Bedrohungen oder kompromittierte Konten zu identifizieren.</li><br />
</ul><br />
<p>Die Stärke des Ansatzes liegt in der Fähigkeit, Bedrohungen zu erkennen, die traditionelle Methoden übersehen würden – wie z.B. Angriffe, die sich langsam einschleichen und das Netzwerk unbemerkt infiltrieren.</p><br />
<p><strong>Erweiterungen der KI-Modelle: Präzision durch Kontextsensitivität</strong></p><br />
<p>Die kürzlichen Erweiterungen der Darktrace KI-Modelle konzentrieren sich auf eine noch präzisere Erkennung und Reduktion von False Positives.  Ein häufiges Problem bei KI-basierten Systemen ist die Generierung von Fehlalarmen, die zu einer &quot;Alarmmüdigkeit&quot; bei den Sicherheitsteams führen können.</p><br />
<p>Die Verbesserungen umfassen:</p><br />
<ul><br />
<li><strong>Kontextsensitivität:</strong> Antigena berücksichtigt nun noch stärker den Kontext der Netzwerkaktivitäten. Beispielsweise wird eine ungewöhnliche Dateifreigabe nicht isoliert, wenn sie von einem bekannten Benutzer zu einer vertrauten Ressource erfolgt und mit den üblichen Arbeitsabläufen übereinstimmt.  Dies erfordert die Integration zusätzlicher Datenquellen wie Identity and Access Management (IAM) Systeme und Collaboration Plattformen.</li><br />
<li><strong>Verbesserte Feature Engineering:</strong> Die Algorithmen zur Anomalieerkennung wurden verfeinert, um weniger anfällig für Rauschen und irrelevante Daten zu sein. Dies beinhaltet eine sorgfältige Auswahl der Merkmale, die zur Entscheidungsfindung verwendet werden.</li><br />
<li><strong>Reinforcement Learning:</strong>  Darktrace setzt zunehmend Reinforcement Learning ein, um Antigena selbstständig zu optimieren. Das System lernt aus seinen eigenen Aktionen und passt seine Strategien an, um die Erkennung von Bedrohungen zu verbessern und False Positives zu minimieren.</li><br />
<li><strong>Verbesserte Modellkalibrierung:</strong> Die Modelle werden kontinuierlich kalibriert, um ihre Genauigkeit und Zuverlässigkeit zu gewährleisten.</li><br />
</ul><br />
<p>Diese Erweiterungen führen zu einer signifikanten Reduktion von Fehlalarmen und ermöglichen es den Sicherheitsteams, sich auf die wirklich kritischen Vorfälle zu konzentrieren.</p><br />
<p><strong>Herausforderungen und Limitationen: Ein kritischer Blick</strong></p><br />
<p>Obwohl KI-basierte Cybersicherheit vielversprechend ist, birgt sie auch Risiken und Herausforderungen:</p><br />
<ul><br />
<li><strong>Adversarial Attacks:</strong>  Angreifer können versuchen, KI-Modelle durch gezielte Manipulation von Eingabedaten (Adversarial Examples) zu täuschen. Darktrace begegnet dieser Gefahr durch die Implementierung robuster Validierungsmechanismen und kontinuierliche Modellüberwachung.</li><br />
<li><strong>Data Poisoning:</strong>  Wenn Angreifer die Trainingsdaten eines KI-Modells verfälschen können, kann dies dazu führen, dass das Modell falsche Muster lernt und bösartige Aktivitäten übersehen oder sogar als normal interpretiert werden. Darktrace setzt auf eine sorgfältige Datenvalidierung und -bereinigung sowie auf Techniken des Federated Learning, um die Auswirkungen von Data Poisoning zu minimieren.</li><br />
<li><strong>Bias in Trainingsdaten:</strong>  Wenn die Trainingsdaten einseitig sind oder bestimmte Bevölkerungsgruppen oder Verhaltensweisen unterrepräsentiert werden, kann das KI-Modell verzerrte Ergebnisse liefern und bestimmte Angriffe übersehen. Darktrace bemüht sich um eine vielfältige und repräsentative Datengrundlage und setzt Techniken zur Bias-Erkennung und -Reduktion ein.</li><br />
<li><strong>&quot;Black Box&quot;-Charakter:</strong>  Die komplexen Algorithmen, die in KI-Modellen verwendet werden, können schwer nachvollziehbar sein (sog. &quot;Black Box&quot;). Dies erschwert es, die Entscheidungen des Systems zu verstehen und Fehler zu beheben. Darktrace arbeitet an der Verbesserung der Interpretierbarkeit seiner Modelle und bietet Tools zur Analyse der Entscheidungsprozesse.</li><br />
</ul><br />
<p><strong>Ausblick: Die Zukunft der KI-gestützten Cybersicherheit</strong></p><br />
<p>Die Entwicklung von KI in der Cybersicherheit steht erst am Anfang. Zukünftige Trends umfassen:</p><br />
<ul><br />
<li><strong>Explainable AI (XAI):</strong>  Eine stärkere Fokussierung auf die Erklärbarkeit von KI-Modellen, um das Vertrauen und die Akzeptanz bei den Anwendern zu erhöhen.</li><br />
<li><strong>Federated Learning:</strong>  Ein Ansatz, bei dem Modelle dezentral trainiert werden, ohne dass Daten zentral gespeichert werden müssen. Dies verbessert den Datenschutz und die Sicherheit.</li><br />
<li><strong>Generative AI:</strong> Der Einsatz von generativen KI-Modellen (wie z.B. GPT-3) zur Automatisierung von Sicherheitsaufgaben wie z.B. der Erstellung von Threat Intelligence Reports oder der Simulation von Angriffsszenarien.</li><br />
<li><strong>Integration mit Extended Detection and Response (XDR):</strong>  Eine stärkere Integration von KI-gestützten Tools in umfassende XDR-Plattformen, um eine ganzheitliche Sicherheitsabdeckung zu gewährleisten.</li><br />
</ul><br />
<h2>Darktrace ist gut positioniert, um diese Trends zu nutzen und seine Führungsposition im Bereich der KI-gestützten Cybersicherheit weiter auszubauen. Die kontinuierlichen Erweiterungen von Antigena zeigen das Engagement des Unternehmens für Innovation und die stetige Verbesserung der Abwehr gegen Cyberbedrohungen.  Für IT-Sicherheitsverantwortliche, Architekten und Entscheider bietet Darktrace eine leistungsstarke Lösung, um ihre digitale Umgebung proaktiv zu schützen und dem zunehmenden Druck durch Cyberangriffe standzuhalten.</h2><br />
<p><strong>Hinweis:</strong> Dieser Artikel basiert auf den bereitgestellten Quellen und erweitert diese durch mein Fachwissen. Die hier dargestellten Informationen sind allgemeiner Natur und sollten nicht als umfassende Sicherheitsberatung betrachtet werden.  Es ist wichtig, die spezifischen Anforderungen der eigenen Organisation zu berücksichtigen und eine individuelle Risikobewertung durchzuführen.</p><br />
<!-- END: Dynamically Added Content -->]]></content:encoded>
</item>
<item>
<title><![CDATA[Darktrace unveils tailored AI models with a twist for its cybersecurity agent]]></title>
<description><![CDATA[Darktrace has announced new AI models for its agentic AI security tool, but it's taken a novel approach to tackle hallucinations.]]></description>
<link>https://tsecurity.de/de/2729680/it-security-nachrichten/darktrace-unveils-tailored-ai-models-with-a-twist-for-its-cybersecurity-agent/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2729680/it-security-nachrichten/darktrace-unveils-tailored-ai-models-with-a-twist-for-its-cybersecurity-agent/</guid>
<pubDate>Thu, 17 Apr 2025 12:05:16 +0200</pubDate>
<content:encoded><![CDATA[Darktrace has announced new AI models for its agentic AI security tool, but it's taken a novel approach to tackle hallucinations.]]></content:encoded>
</item>
<item>
<title><![CDATA[Threat Actors Use 'Spam Bombing' Technique to Hide Malicious Motives]]></title>
<description><![CDATA[Darktrace researchers detailed "spam bombing," a technique in which threat actors bombard targets with spam emails as a pretense for activity like social engineering campaigns.]]></description>
<link>https://tsecurity.de/de/2717148/it-security-nachrichten/threat-actors-use-spam-bombing-technique-to-hide-malicious-motives/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2717148/it-security-nachrichten/threat-actors-use-spam-bombing-technique-to-hide-malicious-motives/</guid>
<pubDate>Thu, 10 Apr 2025 15:03:46 +0200</pubDate>
<content:encoded><![CDATA[Darktrace researchers detailed "spam bombing," a technique in which threat actors bombard targets with spam emails as a pretense for activity like social engineering campaigns.]]></content:encoded>
</item>
<item>
<title><![CDATA[Integrated Exposure Management with Darktrace: Firewall Rules | Resources]]></title>
<description><![CDATA[... its exposure management capabilities to include firewalls—an essential component of network security. By integrating firewall data into risk ...]]></description>
<link>https://tsecurity.de/de/2689055/it-security-nachrichten/integrated-exposure-management-with-darktrace-firewall-rules-resources/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2689055/it-security-nachrichten/integrated-exposure-management-with-darktrace-firewall-rules-resources/</guid>
<pubDate>Thu, 27 Mar 2025 00:03:09 +0100</pubDate>
<content:encoded><![CDATA[... its exposure management capabilities to include firewalls—an essential component of network <b>security</b>. By integrating firewall <b>data</b> into risk ...]]></content:encoded>
</item>
<item>
<title><![CDATA[20 powerful women shaping the networking industry]]></title>
<description><![CDATA[Women are severely underrepresented in top leadership roles across the business world. Only 10.4% of the Fortune 500 companies have women CEOs. In an AP survey of S&P 500 companies, only 25 of 341 CEOs were women.



That disparity extends into the technology sector. The Women in Tech organizatio...]]></description>
<link>https://tsecurity.de/de/2685350/it-security-nachrichten/20-powerful-women-shaping-the-networking-industry/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2685350/it-security-nachrichten/20-powerful-women-shaping-the-networking-industry/</guid>
<pubDate>Tue, 25 Mar 2025 11:20:33 +0100</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Women are severely underrepresented in top leadership roles across the business world. Only 10.4% of the Fortune 500 companies have women CEOs. In an <a href="https://apnews.com/article/female-women-pay-ceo-equity-inclusion-d482ceb56cd0194d1129083852ce7bde" target="_blank" rel="noreferrer noopener">AP</a> survey of S&amp;P 500 companies, only 25 of 341 CEOs were women.</p>



<p>That disparity extends into the technology sector. The <a href="https://www.womentech.net/en-us/women-in-tech-stats" target="_blank" rel="noreferrer noopener">Women in Tech</a> organization reports that 17% of tech companies have a woman CEO, and only 25% of all C-suite jobs are held by women.</p>



<p>But there are a number of groundbreaking women who have been highly successful in networking, and we’re highlighting 20 of them (in alphabetical order). We’ve found no clear pattern or career path—some have stayed with the same company their entire career; others have bounced from one place to another. Several went out and started their own company. Some have technical backgrounds; others have business or management degrees. Two traits they share are a commitment to diversity and inclusion and active participation in organizations and programs championing women in tech.</p>



<h2 class="wp-block-heading">1. Kimberly Anstett</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized"> srcset="https://b2b-contenthub.com/wp-content/uploads/2025/03/01-Trellix-Kim-Anstett.jpg?quality=50&amp;strip=all 1200w, https://b2b-contenthub.com/wp-content/uploads/2025/03/01-Trellix-Kim-Anstett.jpg?resize=240%2C300&amp;quality=50&amp;strip=all 240w, https://b2b-contenthub.com/wp-content/uploads/2025/03/01-Trellix-Kim-Anstett.jpg?resize=768%2C960&amp;quality=50&amp;strip=all 768w, https://b2b-contenthub.com/wp-content/uploads/2025/03/01-Trellix-Kim-Anstett.jpg?resize=819%2C1024&amp;quality=50&amp;strip=all 819w, https://b2b-contenthub.com/wp-content/uploads/2025/03/01-Trellix-Kim-Anstett.jpg?resize=558%2C697&amp;quality=50&amp;strip=all 558w, https://b2b-contenthub.com/wp-content/uploads/2025/03/01-Trellix-Kim-Anstett.jpg?resize=134%2C168&amp;quality=50&amp;strip=all 134w, https://b2b-contenthub.com/wp-content/uploads/2025/03/01-Trellix-Kim-Anstett.jpg?resize=67%2C84&amp;quality=50&amp;strip=all 67w, https://b2b-contenthub.com/wp-content/uploads/2025/03/01-Trellix-Kim-Anstett.jpg?resize=384%2C480&amp;quality=50&amp;strip=all 384w, https://b2b-contenthub.com/wp-content/uploads/2025/03/01-Trellix-Kim-Anstett.jpg?resize=288%2C360&amp;quality=50&amp;strip=all 288w, https://b2b-contenthub.com/wp-content/uploads/2025/03/01-Trellix-Kim-Anstett.jpg?resize=200%2C250&amp;quality=50&amp;strip=all 200w" width="819" height="1024" sizes="(max-width: 819px) 100vw, 819px"&gt;</figure><p class="imageCredit">Trellix</p></div>



<ul class="wp-block-list">
<li><strong>Title: </strong>CIO, <a href="https://www.trellix.com/about/leadership/kim-anstett/" target="_blank" rel="noreferrer noopener">Trellix</a></li>



<li><strong>Education: </strong>Bachelor of Science, Electrical Engineering, Tufts University</li>



<li><strong>Why she’s here: </strong>Anstett joined Trellix (a rebranding following the merger of McAfee Enterprise and FireEye) in 2022. She previously worked at Iron Mountain, where she was Executive Vice President and CTO. At Trellix, which is positioning itself as a leader in extended detection and response (XDR), she heads the Enterprise Technology and Operations group. Anstett <a href="https://www.trellix.com/news/press-releases/kim-anstett-appointed-trellix-chief-information-officer/" target="_blank" rel="noreferrer noopener">said at her appointment</a>: “My number one priority as CIO is to deliver insights to our business to serve our customers. Second is furthering diversity, equity, inclusion, and development for my teams.”</li>



<li><strong>In her own words:</strong> “The best learning comes from the toughest times. We’re all going to stub our toe, we’re all going to get bruises, but it’s actually going to make us much better. Just don’t let it get you down. You’re not learning if you’re not making mistakes. And if you can punch through that, it’s quite extraordinary,” she said on a <a href="https://www.e-channelnews.com/women-in-tech-interview-kim-anstett/" target="_blank" rel="noreferrer noopener">podcast interview with eChannelNews</a>.</li>



<li><strong>Fun fact: </strong>She also said during the podcast that virtually everyone in her family is an engineer. When she was growing up, her parents didn’t ask if she wanted to be an engineer, they just wanted to know what type.&gt;</li>
</ul>



<h2 class="wp-block-heading">2. Alvina Antar</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized"> srcset="https://b2b-contenthub.com/wp-content/uploads/2025/03/02-F5-Alvina-Antar.jpg?quality=50&amp;strip=all 1200w, https://b2b-contenthub.com/wp-content/uploads/2025/03/02-F5-Alvina-Antar.jpg?resize=240%2C300&amp;quality=50&amp;strip=all 240w, https://b2b-contenthub.com/wp-content/uploads/2025/03/02-F5-Alvina-Antar.jpg?resize=768%2C960&amp;quality=50&amp;strip=all 768w, https://b2b-contenthub.com/wp-content/uploads/2025/03/02-F5-Alvina-Antar.jpg?resize=819%2C1024&amp;quality=50&amp;strip=all 819w, https://b2b-contenthub.com/wp-content/uploads/2025/03/02-F5-Alvina-Antar.jpg?resize=558%2C697&amp;quality=50&amp;strip=all 558w, https://b2b-contenthub.com/wp-content/uploads/2025/03/02-F5-Alvina-Antar.jpg?resize=134%2C168&amp;quality=50&amp;strip=all 134w, https://b2b-contenthub.com/wp-content/uploads/2025/03/02-F5-Alvina-Antar.jpg?resize=67%2C84&amp;quality=50&amp;strip=all 67w, https://b2b-contenthub.com/wp-content/uploads/2025/03/02-F5-Alvina-Antar.jpg?resize=384%2C480&amp;quality=50&amp;strip=all 384w, https://b2b-contenthub.com/wp-content/uploads/2025/03/02-F5-Alvina-Antar.jpg?resize=288%2C360&amp;quality=50&amp;strip=all 288w, https://b2b-contenthub.com/wp-content/uploads/2025/03/02-F5-Alvina-Antar.jpg?resize=200%2C250&amp;quality=50&amp;strip=all 200w" width="819" height="1024" sizes="(max-width: 819px) 100vw, 819px"&gt;</figure><p class="imageCredit">F5 Networks</p></div>



<ul class="wp-block-list">
<li><strong>Title: </strong>Chief Digital Officer, <a href="https://www.f5.com/" target="_blank" rel="noreferrer noopener">F5</a></li>



<li><strong>Education: </strong>Bachelor of Science, Computer Science, University of Houston&gt;</li>



<li><strong>Why she’s here: </strong>Antar worked at Dell for 17 years, starting as a software engineer and eventually leading the company’s acquisitions efforts, where she mastered the art of integrating technology, people, and business models. With that broad experience, Antar set her sights on becoming a CIO. She joined Zuora, a startup that provides billing and subscription management software, scaling it from $30M to $300M in revenue and taking it public in 2018. She joined Okta as CIO in 2020, and left Okta for her current role at F5 in January 2025, where she is tasked with building a data- and AI-first enterprise. When <a href="https://www.forbes.com/sites/peterhigh/2025/01/27/former-okta-and-zuora-tech-chief-alvina-antarjoins-f5-as-first-cdo/" target="_blank" rel="noreferrer noopener">joining F5</a>, she reflected on her career and said, “F5’s evolution from hardware to software and SaaS mirrors my own professional journey and passion for transformation.” &gt;</li>



<li><strong>In her own words:</strong> “Be fearless in all that you do, and ultimately don’t look around and hold back because you may be the only girl in the room. Be confident in what differentiates you,” she said in <a href="https://www.cio.com/article/646408/okta-global-cio-alvina-antar-on-driving-diversity-and-why-we-need-a-passwordless-future.html" target="_blank">an article</a> about driving diversity in tech.</li>



<li><strong>Fun fact: </strong>Co-founded the Silicon Valley CIO Women’s Network and is a member of the Girls in Tech Board of Directors.</li>
</ul>



<h2 class="wp-block-heading">3. &gt;Liz Centoni</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized"> srcset="https://b2b-contenthub.com/wp-content/uploads/2025/03/03-Cisco-Liz-Centoni.jpg?quality=50&amp;strip=all 1200w, https://b2b-contenthub.com/wp-content/uploads/2025/03/03-Cisco-Liz-Centoni.jpg?resize=240%2C300&amp;quality=50&amp;strip=all 240w, https://b2b-contenthub.com/wp-content/uploads/2025/03/03-Cisco-Liz-Centoni.jpg?resize=768%2C960&amp;quality=50&amp;strip=all 768w, https://b2b-contenthub.com/wp-content/uploads/2025/03/03-Cisco-Liz-Centoni.jpg?resize=819%2C1024&amp;quality=50&amp;strip=all 819w, https://b2b-contenthub.com/wp-content/uploads/2025/03/03-Cisco-Liz-Centoni.jpg?resize=558%2C697&amp;quality=50&amp;strip=all 558w, https://b2b-contenthub.com/wp-content/uploads/2025/03/03-Cisco-Liz-Centoni.jpg?resize=134%2C168&amp;quality=50&amp;strip=all 134w, https://b2b-contenthub.com/wp-content/uploads/2025/03/03-Cisco-Liz-Centoni.jpg?resize=67%2C84&amp;quality=50&amp;strip=all 67w, https://b2b-contenthub.com/wp-content/uploads/2025/03/03-Cisco-Liz-Centoni.jpg?resize=384%2C480&amp;quality=50&amp;strip=all 384w, https://b2b-contenthub.com/wp-content/uploads/2025/03/03-Cisco-Liz-Centoni.jpg?resize=288%2C360&amp;quality=50&amp;strip=all 288w, https://b2b-contenthub.com/wp-content/uploads/2025/03/03-Cisco-Liz-Centoni.jpg?resize=200%2C250&amp;quality=50&amp;strip=all 200w" width="819" height="1024" sizes="(max-width: 819px) 100vw, 819px"&gt;</figure><p class="imageCredit">Cisco</p></div>



<ul class="wp-block-list">
<li><strong>Title:</strong> Executive Vice President and Chief Customer Experience Officer, <a href="https://newsroom.cisco.com/c/r/newsroom/en/us/executives/liz-centoni.html" target="_blank" rel="noreferrer noopener">Cisco</a></li>



<li><strong>Education:</strong> Bachelor of Science in Chemistry, the University of Mumbai; Master of Business Administration, the University of San Francisco</li>



<li><strong>Why she’s here:</strong> Centoni joined Cisco in 2000 after working for five years in sales and marketing for a packaged goods company. Looking back at that time, <a href="https://www.youtube.com/watch?v=LoJ22e4JNbI&amp;t=132s" target="_blank" rel="noreferrer noopener">she said</a>: “When I came into Cisco, I came in with a business background and the advice I was given was, ‘You’re never going to succeed at engineering, which requires domain knowledge of computer science. So, it’s good that you’re giving this a try, but I suggest you look at what a Plan B looks like.’” She started out as senior director of engineering and climbed the ranks to excel at numerous positions, including senior vice president and general manager of Cisco’s Cloud, Compute, and IoT business, chief strategy officer, and general manager of applications. Earlier this year, CEO Chuck Robbins revamped Cisco’s top management and promoted Centoni to EVP and chief customer experience officer. In her new role, Centoni will lead a team of 20,000 employees focused on helping customers transform their businesses through Cisco products and services.</li>



<li><strong>In her own words:</strong> “Throughout my career, there have been days when I’ve been scared and days I haven’t had time to think about whether I was scared or not. I think if you don’t have that fear, you’re going to ask yourself if you’re stretching yourself. In fact, if I look back, what I fear is the opportunities I didn’t take,” <a href="https://www.youtube.com/watch?v=LoJ22e4JNbI&amp;t=132s" target="_blank" rel="noreferrer noopener">she said.</a></li>



<li><strong>Fun fact:</strong> Centoni is Cisco’s Executive Sponsor for the Women in Science and Engineering (WISE) program.</li>
</ul>



<h2 class="wp-block-heading">4. Eva Chen</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized"> srcset="https://b2b-contenthub.com/wp-content/uploads/2025/03/04-Trend-Micro-Eva-Chen.jpg?quality=50&amp;strip=all 1200w, https://b2b-contenthub.com/wp-content/uploads/2025/03/04-Trend-Micro-Eva-Chen.jpg?resize=240%2C300&amp;quality=50&amp;strip=all 240w, https://b2b-contenthub.com/wp-content/uploads/2025/03/04-Trend-Micro-Eva-Chen.jpg?resize=768%2C960&amp;quality=50&amp;strip=all 768w, https://b2b-contenthub.com/wp-content/uploads/2025/03/04-Trend-Micro-Eva-Chen.jpg?resize=819%2C1024&amp;quality=50&amp;strip=all 819w, https://b2b-contenthub.com/wp-content/uploads/2025/03/04-Trend-Micro-Eva-Chen.jpg?resize=558%2C697&amp;quality=50&amp;strip=all 558w, https://b2b-contenthub.com/wp-content/uploads/2025/03/04-Trend-Micro-Eva-Chen.jpg?resize=134%2C168&amp;quality=50&amp;strip=all 134w, https://b2b-contenthub.com/wp-content/uploads/2025/03/04-Trend-Micro-Eva-Chen.jpg?resize=67%2C84&amp;quality=50&amp;strip=all 67w, https://b2b-contenthub.com/wp-content/uploads/2025/03/04-Trend-Micro-Eva-Chen.jpg?resize=384%2C480&amp;quality=50&amp;strip=all 384w, https://b2b-contenthub.com/wp-content/uploads/2025/03/04-Trend-Micro-Eva-Chen.jpg?resize=288%2C360&amp;quality=50&amp;strip=all 288w, https://b2b-contenthub.com/wp-content/uploads/2025/03/04-Trend-Micro-Eva-Chen.jpg?resize=200%2C250&amp;quality=50&amp;strip=all 200w" width="819" height="1024" sizes="(max-width: 819px) 100vw, 819px"&gt;</figure><p class="imageCredit">Trend Micro</p></div>



<ul class="wp-block-list">
<li><strong>Title:</strong> Co-founder and CEO, <a href="https://www.trendmicro.com/en_us/about/leaders.html" target="_blank" rel="noreferrer noopener">Trend Micro</a></li>



<li><strong>Education:</strong> Bachelor of Philosophy, National Chengchi University; Master of Business Administration and Master of Management Information Systems, University of Texas</li>



<li><strong>Why she’s here:</strong> No job hopping for Chen. She co-founded Trend Micro in 1988 and has been leading the company ever since; first as executive vice president, CTO in 1996, and CEO since 2005. During her tenure, the company successfully made the transition from simple anti-virus software to a broad, AI-driven cybersecurity platform that protects endpoints, cloud, and enterprise resources. Not many security vendors from the 1980s are still around, but Trend Micro is a survivor. In its latest earnings report, the company announced 13% year-over-year net sales growth and annual revenues in the $1.8 billion range.</li>



<li><strong>In her own words:</strong> “As a woman in Asia, when I became the CEO, I tried to imitate all the male CEOs. I didn’t wear a skirt and I didn’t wear earrings. But it’s not right. People can see that you are not yourself. I started to realize that the only way you can express yourself is to let people connect with you without the mask. Be yourself,” she said during an <a href="https://www.youtube.com/watch?v=orVQ_CPqHak" target="_blank" rel="noreferrer noopener">interview with CNBC</a>.</li>



<li><strong>Fun fact:</strong> Chen co-founded the company with her sister Jenny and brother-in-law Steve Chang.</li>
</ul>



<h2 class="wp-block-heading">5. Tam Dell’Oro</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized"> srcset="https://b2b-contenthub.com/wp-content/uploads/2025/03/05-Dell-Oro-Tam-DellOro.jpeg?quality=50&amp;strip=all 1200w, https://b2b-contenthub.com/wp-content/uploads/2025/03/05-Dell-Oro-Tam-DellOro.jpeg?resize=240%2C300&amp;quality=50&amp;strip=all 240w, https://b2b-contenthub.com/wp-content/uploads/2025/03/05-Dell-Oro-Tam-DellOro.jpeg?resize=768%2C960&amp;quality=50&amp;strip=all 768w, https://b2b-contenthub.com/wp-content/uploads/2025/03/05-Dell-Oro-Tam-DellOro.jpeg?resize=819%2C1024&amp;quality=50&amp;strip=all 819w, https://b2b-contenthub.com/wp-content/uploads/2025/03/05-Dell-Oro-Tam-DellOro.jpeg?resize=558%2C697&amp;quality=50&amp;strip=all 558w, https://b2b-contenthub.com/wp-content/uploads/2025/03/05-Dell-Oro-Tam-DellOro.jpeg?resize=134%2C168&amp;quality=50&amp;strip=all 134w, https://b2b-contenthub.com/wp-content/uploads/2025/03/05-Dell-Oro-Tam-DellOro.jpeg?resize=67%2C84&amp;quality=50&amp;strip=all 67w, https://b2b-contenthub.com/wp-content/uploads/2025/03/05-Dell-Oro-Tam-DellOro.jpeg?resize=384%2C480&amp;quality=50&amp;strip=all 384w, https://b2b-contenthub.com/wp-content/uploads/2025/03/05-Dell-Oro-Tam-DellOro.jpeg?resize=288%2C360&amp;quality=50&amp;strip=all 288w, https://b2b-contenthub.com/wp-content/uploads/2025/03/05-Dell-Oro-Tam-DellOro.jpeg?resize=200%2C250&amp;quality=50&amp;strip=all 200w" width="819" height="1024" sizes="(max-width: 819px) 100vw, 819px"&gt;</figure><p class="imageCredit">Dell’Oro Group</p></div>



<ul class="wp-block-list">
<li><strong>Title:</strong> Founder and CEO, <a href="https://www.delloro.com/about/meet-the-team/tam-delloro/" target="_blank" rel="noreferrer noopener">Dell’Oro Group</a></li>



<li><strong>Education:</strong> Bachelor of Science, International Business, Santa Clara University; Master of Business Administration, Strategy and Marketing, the University of Chicago</li>



<li><strong>Why she’s here:</strong> In a world of mega research and analyst groups like IDC, Gartner, and Forrester, Dell’Oro Group has carved out a successful niche focusing exclusively on networking, telecommunications, data center infrastructure, and network security. In addition to delivering the latest market share numbers, Dell’Oro Group provides consulting in business planning and strategic competitive analysis. Dell’Oro herself has had a long career in networking, going back to SynOptics in the 1990s, where she developed a competitive analysis program to evaluate the strategic performance of key companies in the networking industry.</li>



<li><strong>In her own words:</strong> “I often sort out key assumptions on my forecast when I am out riding my mountain bike, zooming along the single track at Russian Ridge overlooking the Pacific Ocean,” <a href="https://www.delloro.com/about/meet-the-team/tam-delloro/" target="_blank" rel="noreferrer noopener">she said.</a></li>



<li><strong>Fun fact:</strong> As a child, she spent time living in Saudi Arabia, where her father Walter, a geologist, was working for a state-owned oil company exploring potential drilling sites.</li>
</ul>



<h2 class="wp-block-heading">6. <strong>Jae Evans</strong></h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized"> srcset="https://b2b-contenthub.com/wp-content/uploads/2025/03/06-Oracle-Jae-Evans.jpg?quality=50&amp;strip=all 1200w, https://b2b-contenthub.com/wp-content/uploads/2025/03/06-Oracle-Jae-Evans.jpg?resize=240%2C300&amp;quality=50&amp;strip=all 240w, https://b2b-contenthub.com/wp-content/uploads/2025/03/06-Oracle-Jae-Evans.jpg?resize=768%2C960&amp;quality=50&amp;strip=all 768w, https://b2b-contenthub.com/wp-content/uploads/2025/03/06-Oracle-Jae-Evans.jpg?resize=819%2C1024&amp;quality=50&amp;strip=all 819w, https://b2b-contenthub.com/wp-content/uploads/2025/03/06-Oracle-Jae-Evans.jpg?resize=558%2C697&amp;quality=50&amp;strip=all 558w, https://b2b-contenthub.com/wp-content/uploads/2025/03/06-Oracle-Jae-Evans.jpg?resize=134%2C168&amp;quality=50&amp;strip=all 134w, https://b2b-contenthub.com/wp-content/uploads/2025/03/06-Oracle-Jae-Evans.jpg?resize=67%2C84&amp;quality=50&amp;strip=all 67w, https://b2b-contenthub.com/wp-content/uploads/2025/03/06-Oracle-Jae-Evans.jpg?resize=384%2C480&amp;quality=50&amp;strip=all 384w, https://b2b-contenthub.com/wp-content/uploads/2025/03/06-Oracle-Jae-Evans.jpg?resize=288%2C360&amp;quality=50&amp;strip=all 288w, https://b2b-contenthub.com/wp-content/uploads/2025/03/06-Oracle-Jae-Evans.jpg?resize=200%2C250&amp;quality=50&amp;strip=all 200w" width="819" height="1024" sizes="(max-width: 819px) 100vw, 819px"&gt;</figure><p class="imageCredit">Oracle</p></div>



<ul class="wp-block-list">
<li><strong>Title:</strong> Global Chief Information Officer and Executive Vice President, <a href="https://www.oracle.com/">Oracle</a></li>



<li><strong>Education:</strong> Bachelor of Science, UC Santa Barbara; Master of Business Administration, Golden Gate University</li>



<li><strong>Why she’s here:</strong> With more than 20 years of experience leading global teams and managing critical production services, Evans now oversees Oracle IT’s cloud transformation and provides IT services to Oracle’s 160,000 employees and developers. Her team manages Oracle Cloud Infrastructure (OCI) Platform Services to ensure top-tier security, compliance, and support. Evans is passionate about bringing diversity and inclusion into the workplace, and she is the executive sponsor for D&amp;I, a member of Oracle’s Executive D&amp;I Council, and an active participant in and champion of various Oracle Professional Asian Leadership and Women in Tech Events.</li>



<li><strong>In her own words:</strong> On the topic of building trust, <a href="https://blogs.oracle.com/diversity-inclusion/post/nurturing-trust-and-inclusion-a-qa-with-oracle-cio-jae-evans" target="_blank" rel="noreferrer noopener">she said</a>: “Leading a team can be challenging, especially when you’re new to it or when there are a lot of changes taking place and things are moving at a fast pace. And that’s when it’s actually the most critical time. You won’t learn how to effectively manage a team just by reading a book, but one key element for you to learn is you can’t lead if people won’t follow, and the key element to that is building trust.”</li>



<li><strong>Fun fact:</strong> Upon joining Oracle, Evans established a mentoring circle of high-performing female leaders and <a href="https://blogs.oracle.com/diversity-inclusion/post/nurturing-trust-and-inclusion-a-qa-with-oracle-cio-jae-evans" target="_blank" rel="noreferrer noopener">said in an Oracle blog post</a>: “We’re having these honest conversations here at Oracle, and I’m using that information to initiate discussion with my peers along the lines of sponsorship, advocacy, and action to develop and retain great talent.”</li>
</ul>



<h2 class="wp-block-heading">7. Adaire Fox-Martin</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized"> srcset="https://b2b-contenthub.com/wp-content/uploads/2025/03/07-Equinix-Adaire-Fox-Martin.jpeg?quality=50&amp;strip=all 1200w, https://b2b-contenthub.com/wp-content/uploads/2025/03/07-Equinix-Adaire-Fox-Martin.jpeg?resize=240%2C300&amp;quality=50&amp;strip=all 240w, https://b2b-contenthub.com/wp-content/uploads/2025/03/07-Equinix-Adaire-Fox-Martin.jpeg?resize=768%2C960&amp;quality=50&amp;strip=all 768w, https://b2b-contenthub.com/wp-content/uploads/2025/03/07-Equinix-Adaire-Fox-Martin.jpeg?resize=819%2C1024&amp;quality=50&amp;strip=all 819w, https://b2b-contenthub.com/wp-content/uploads/2025/03/07-Equinix-Adaire-Fox-Martin.jpeg?resize=558%2C697&amp;quality=50&amp;strip=all 558w, https://b2b-contenthub.com/wp-content/uploads/2025/03/07-Equinix-Adaire-Fox-Martin.jpeg?resize=134%2C168&amp;quality=50&amp;strip=all 134w, https://b2b-contenthub.com/wp-content/uploads/2025/03/07-Equinix-Adaire-Fox-Martin.jpeg?resize=67%2C84&amp;quality=50&amp;strip=all 67w, https://b2b-contenthub.com/wp-content/uploads/2025/03/07-Equinix-Adaire-Fox-Martin.jpeg?resize=384%2C480&amp;quality=50&amp;strip=all 384w, https://b2b-contenthub.com/wp-content/uploads/2025/03/07-Equinix-Adaire-Fox-Martin.jpeg?resize=288%2C360&amp;quality=50&amp;strip=all 288w, https://b2b-contenthub.com/wp-content/uploads/2025/03/07-Equinix-Adaire-Fox-Martin.jpeg?resize=200%2C250&amp;quality=50&amp;strip=all 200w" width="819" height="1024" sizes="(max-width: 819px) 100vw, 819px"&gt;</figure><p class="imageCredit">Equinix</p></div>



<ul class="wp-block-list">
<li><strong>Title:</strong> CEO and President, <a href="https://www.equinix.com/about/leadership" target="_blank" rel="noreferrer noopener">Equinix</a></li>



<li><strong>Education:</strong> Bachelor of Arts, Trinity College, Dublin</li>



<li><strong>Why she’s here:</strong> Fox-Martin was named CEO and president of Equinix in June 2024, after a stellar career at tech powerhouses Oracle, SAP, and Google, where she led global teams encompassing sales, professional services, partner ecosystem, and customer success. At Equinix, where she has been a member of the Board of Directors since 2020, she is responsible for leading the overall strategy and direction of the business.</li>



<li><strong>In her own words:</strong> “Regardless of whether you’re tech or not, whatever you do, whatever you make, innovation is the lifeblood of your company, and you only become innovative when you can bring together individuals who have a diverse and different frame of reference,” she said on a <a href="https://www.youtube.com/watch?v=KWMxO31zXZ0" target="_blank" rel="noreferrer noopener">podcast.</a></li>



<li><strong>Fun fact:</strong> Fox-Martin began her career as a schoolteacher, which she described this way in an <a href="https://mobile-magazine.com/articles/lifetime-achievement-award-adaire-fox-martin" target="_blank" rel="noreferrer noopener">article</a>: “It’s the only job where on your first day, you’re CEO of 32-plus people and you need to find a way to engage them and maintain that level of engagement.”</li>
</ul>



<h2 class="wp-block-heading">8. Rupal Hollenbeck</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized"> srcset="https://b2b-contenthub.com/wp-content/uploads/2025/03/08-Check-Point-Rupal-Hollenbeck.jpeg?quality=50&amp;strip=all 1200w, https://b2b-contenthub.com/wp-content/uploads/2025/03/08-Check-Point-Rupal-Hollenbeck.jpeg?resize=240%2C300&amp;quality=50&amp;strip=all 240w, https://b2b-contenthub.com/wp-content/uploads/2025/03/08-Check-Point-Rupal-Hollenbeck.jpeg?resize=768%2C960&amp;quality=50&amp;strip=all 768w, https://b2b-contenthub.com/wp-content/uploads/2025/03/08-Check-Point-Rupal-Hollenbeck.jpeg?resize=819%2C1024&amp;quality=50&amp;strip=all 819w, https://b2b-contenthub.com/wp-content/uploads/2025/03/08-Check-Point-Rupal-Hollenbeck.jpeg?resize=558%2C697&amp;quality=50&amp;strip=all 558w, https://b2b-contenthub.com/wp-content/uploads/2025/03/08-Check-Point-Rupal-Hollenbeck.jpeg?resize=134%2C168&amp;quality=50&amp;strip=all 134w, https://b2b-contenthub.com/wp-content/uploads/2025/03/08-Check-Point-Rupal-Hollenbeck.jpeg?resize=67%2C84&amp;quality=50&amp;strip=all 67w, https://b2b-contenthub.com/wp-content/uploads/2025/03/08-Check-Point-Rupal-Hollenbeck.jpeg?resize=384%2C480&amp;quality=50&amp;strip=all 384w, https://b2b-contenthub.com/wp-content/uploads/2025/03/08-Check-Point-Rupal-Hollenbeck.jpeg?resize=288%2C360&amp;quality=50&amp;strip=all 288w, https://b2b-contenthub.com/wp-content/uploads/2025/03/08-Check-Point-Rupal-Hollenbeck.jpeg?resize=200%2C250&amp;quality=50&amp;strip=all 200w" width="819" height="1024" sizes="(max-width: 819px) 100vw, 819px"&gt;</figure><p class="imageCredit">Check Point Software</p></div>



<ul class="wp-block-list">
<li><strong>Title:</strong> President, <a href="https://www.checkpoint.com/about-us/leadership/" target="_blank" rel="noreferrer noopener">Check Point Software</a></li>



<li><strong>Education:</strong> Bachelor of Science, Finance and International Studies, Boston College; Master of Business Administration, International Management, the Thunderbird School of Global Management at Arizona State University</li>



<li><strong>Why she’s here:</strong> Hollenbeck enjoyed a 23-year career at Intel, where she held senior leadership positions, including Corporate Vice President and General Manager of Global Data Center Sales, and Vice President and General Manager of Intel China. Hollenbeck then held key jobs at Oracle and AI startup Cerebras Systems before joining Check Point in 2022 as chief commercial officer. She was recently promoted to Check Point President, where she is in charge of all commercial and go-to-market functions for the company. She is also an Adjunct Professor at California State University East Bay, teaching a Women in Leadership course in the College of Business &amp; Economics.</li>



<li><strong>In her own words:</strong> “I’m hugely passionate about the notion of equity and inclusion. It’s important to me as a human being. And I take it with me in everything that I do,” she said in a <a href="https://blog.checkpoint.com/executive-insights/check-points-president-on-her-journey-vision-and-gpostth-strategy/" target="_blank" rel="noreferrer noopener">Check Point Software blog post</a>.</li>



<li><strong>Fun fact:</strong> She is a Founding Member of Neythri, an organization dedicated to the professional advancement of South Asian women, and a Founding Limited Partner in the Neythri Futures Fund.</li>
</ul>



<h2 class="wp-block-heading">9. Kate Johnson</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized"> srcset="https://b2b-contenthub.com/wp-content/uploads/2025/03/09-Lumen-Kate-Johnson.jpeg?quality=50&amp;strip=all 1200w, https://b2b-contenthub.com/wp-content/uploads/2025/03/09-Lumen-Kate-Johnson.jpeg?resize=240%2C300&amp;quality=50&amp;strip=all 240w, https://b2b-contenthub.com/wp-content/uploads/2025/03/09-Lumen-Kate-Johnson.jpeg?resize=768%2C960&amp;quality=50&amp;strip=all 768w, https://b2b-contenthub.com/wp-content/uploads/2025/03/09-Lumen-Kate-Johnson.jpeg?resize=819%2C1024&amp;quality=50&amp;strip=all 819w, https://b2b-contenthub.com/wp-content/uploads/2025/03/09-Lumen-Kate-Johnson.jpeg?resize=558%2C697&amp;quality=50&amp;strip=all 558w, https://b2b-contenthub.com/wp-content/uploads/2025/03/09-Lumen-Kate-Johnson.jpeg?resize=134%2C168&amp;quality=50&amp;strip=all 134w, https://b2b-contenthub.com/wp-content/uploads/2025/03/09-Lumen-Kate-Johnson.jpeg?resize=67%2C84&amp;quality=50&amp;strip=all 67w, https://b2b-contenthub.com/wp-content/uploads/2025/03/09-Lumen-Kate-Johnson.jpeg?resize=384%2C480&amp;quality=50&amp;strip=all 384w, https://b2b-contenthub.com/wp-content/uploads/2025/03/09-Lumen-Kate-Johnson.jpeg?resize=288%2C360&amp;quality=50&amp;strip=all 288w, https://b2b-contenthub.com/wp-content/uploads/2025/03/09-Lumen-Kate-Johnson.jpeg?resize=200%2C250&amp;quality=50&amp;strip=all 200w" width="819" height="1024" sizes="(max-width: 819px) 100vw, 819px"&gt;</figure><p class="imageCredit">Lumen Technologies</p></div>



<ul class="wp-block-list">
<li><strong>Title:</strong> President and CEO, <a href="https://www.lumen.com/en-us/about/governance/kate-johnson.html" target="_blank" rel="noreferrer noopener">Lumen Technologies</a></li>



<li><strong>Education:</strong> Bachelor of Science, Electrical Engineering, Lehigh University; Master of Business Administration, the University of Pennsylvania’s Wharton School</li>



<li><strong>Why she’s here:</strong> Johnson spent six years as a management consultant, where she got hooked on business transformations. Her resume includes stints at Deloitte Consulting, USB Investment Bank, Red Hat, Oracle, GE Digital, and Microsoft. Johnson was named president and CEO of Lumen (formerly CenturyLink) in 2022. Saddled with $20 billion in debt from a variety of acquisitions, Lumen needed a shot in the arm and Johnson delivered. She said about a culture of empathy in an <a href="https://observer.com/2024/09/lumen-technologies-ceo-kate-johnson-ai-deal/" target="_blank" rel="noreferrer noopener">article</a>, “I’m a change lover. I love transformation. And this was a company that needed to be transformed fundamentally, and also needed a giant hug.” Johnson restructured the debt load, reorganized the company, changed the culture, re-focused the business, and is betting on the AI revolution to drive new business in high-speed connectivity.</li>



<li><strong>In her own words:</strong> “You can’t just peel out and get a better job every time something is not going your way. I think the notion of resilience is super important, how to deal with it, that’s important for the longevity of your career but also to develop empathy for people that you start to manage. All of this requires a growth mindset. You have to be in the game to learn and apply those learnings as a takeaway,” she said on a <a href="https://www.youtube.com/watch?v=FBItykisLXg" target="_blank" rel="noreferrer noopener">podcast</a> of how to deal with bad bosses.</li>



<li><strong>Fun fact:</strong> The Denver resident is an avid skier.</li>
</ul>



<h2 class="wp-block-heading">10. Praniti Lakhwara</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized"> srcset="https://b2b-contenthub.com/wp-content/uploads/2025/03/10-Zscaler-Praniti-Lakhwara.jpeg?quality=50&amp;strip=all 1200w, https://b2b-contenthub.com/wp-content/uploads/2025/03/10-Zscaler-Praniti-Lakhwara.jpeg?resize=240%2C300&amp;quality=50&amp;strip=all 240w, https://b2b-contenthub.com/wp-content/uploads/2025/03/10-Zscaler-Praniti-Lakhwara.jpeg?resize=768%2C960&amp;quality=50&amp;strip=all 768w, https://b2b-contenthub.com/wp-content/uploads/2025/03/10-Zscaler-Praniti-Lakhwara.jpeg?resize=819%2C1024&amp;quality=50&amp;strip=all 819w, https://b2b-contenthub.com/wp-content/uploads/2025/03/10-Zscaler-Praniti-Lakhwara.jpeg?resize=558%2C697&amp;quality=50&amp;strip=all 558w, https://b2b-contenthub.com/wp-content/uploads/2025/03/10-Zscaler-Praniti-Lakhwara.jpeg?resize=134%2C168&amp;quality=50&amp;strip=all 134w, https://b2b-contenthub.com/wp-content/uploads/2025/03/10-Zscaler-Praniti-Lakhwara.jpeg?resize=67%2C84&amp;quality=50&amp;strip=all 67w, https://b2b-contenthub.com/wp-content/uploads/2025/03/10-Zscaler-Praniti-Lakhwara.jpeg?resize=384%2C480&amp;quality=50&amp;strip=all 384w, https://b2b-contenthub.com/wp-content/uploads/2025/03/10-Zscaler-Praniti-Lakhwara.jpeg?resize=288%2C360&amp;quality=50&amp;strip=all 288w, https://b2b-contenthub.com/wp-content/uploads/2025/03/10-Zscaler-Praniti-Lakhwara.jpeg?resize=200%2C250&amp;quality=50&amp;strip=all 200w" width="819" height="1024" sizes="(max-width: 819px) 100vw, 819px"&gt;</figure><p class="imageCredit">Zscaler</p></div>



<ul class="wp-block-list">
<li><strong>Title:</strong> CIO, <a href="https://www.zscaler.com/company/leadership/praniti-lakhwara" target="_blank" rel="noreferrer noopener">Zscaler</a></li>



<li><strong>Education:</strong> Bachelor of Science, Aeronautical Engineering, Arizona State University</li>



<li><strong>Why she’s here:</strong> Lakhwara came to the U.S. from India with the goal of becoming a pilot but switched to aerospace engineering instead. “I was solving problems, and it had its own mini adrenaline rush,” she said in an <a href="https://www.evanta.com/resources/cio/leadership-profile/the-unlikely-path-from-flight-school-to-top-technology-leader" target="_blank" rel="noreferrer noopener">article</a> about her career path. Aerospace engineering with a focus on computational modeling led to programming, which led to a long career running IT operations. Her path has included stints at Align Technology, Nimble Storage, and Conga, where she was CIO from 2017-2021. She was senior vice president of information technology and applications at Zscaler from 2021-2022, then assumed her current CIO role.</li>



<li><strong>In her own words:</strong> She discussed in an <a href="https://www.evanta.com/resources/cio/leadership-profile/the-unlikely-path-from-flight-school-to-top-technology-leader" target="_blank" rel="noreferrer noopener">article</a> her take on keys to success: 1. “I truly, to this day, feel like I arrived at the perfect role for me. So, passion is a big driver.” 2. “Not all careers are by design. It may or may not be a direct, straight route. Life is going to get in the way.” (When she landed her first role as head of IT, she had five-month-old twins.) “It was quite a juggle. But I like high-pressure situations, and I took it as a challenge.” </li>



<li><strong>Fun fact:</strong> She is a licensed English-as-a-Second Language teacher.</li>
</ul>



<h2 class="wp-block-heading">11. Mindy Lieberman</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized"> srcset="https://b2b-contenthub.com/wp-content/uploads/2025/03/11-MongoDB-Mindy-Lieberman-1.jpeg?quality=50&amp;strip=all 1200w, https://b2b-contenthub.com/wp-content/uploads/2025/03/11-MongoDB-Mindy-Lieberman-1.jpeg?resize=240%2C300&amp;quality=50&amp;strip=all 240w, https://b2b-contenthub.com/wp-content/uploads/2025/03/11-MongoDB-Mindy-Lieberman-1.jpeg?resize=768%2C960&amp;quality=50&amp;strip=all 768w, https://b2b-contenthub.com/wp-content/uploads/2025/03/11-MongoDB-Mindy-Lieberman-1.jpeg?resize=819%2C1024&amp;quality=50&amp;strip=all 819w, https://b2b-contenthub.com/wp-content/uploads/2025/03/11-MongoDB-Mindy-Lieberman-1.jpeg?resize=558%2C697&amp;quality=50&amp;strip=all 558w, https://b2b-contenthub.com/wp-content/uploads/2025/03/11-MongoDB-Mindy-Lieberman-1.jpeg?resize=134%2C168&amp;quality=50&amp;strip=all 134w, https://b2b-contenthub.com/wp-content/uploads/2025/03/11-MongoDB-Mindy-Lieberman-1.jpeg?resize=67%2C84&amp;quality=50&amp;strip=all 67w, https://b2b-contenthub.com/wp-content/uploads/2025/03/11-MongoDB-Mindy-Lieberman-1.jpeg?resize=384%2C480&amp;quality=50&amp;strip=all 384w, https://b2b-contenthub.com/wp-content/uploads/2025/03/11-MongoDB-Mindy-Lieberman-1.jpeg?resize=288%2C360&amp;quality=50&amp;strip=all 288w, https://b2b-contenthub.com/wp-content/uploads/2025/03/11-MongoDB-Mindy-Lieberman-1.jpeg?resize=200%2C250&amp;quality=50&amp;strip=all 200w" width="819" height="1024" sizes="(max-width: 819px) 100vw, 819px"&gt;</figure><p class="imageCredit">MongoDB</p></div>



<ul class="wp-block-list">
<li><strong>Title:</strong> CIO, <a href="https://www.mongodb.com/company/leadership" target="_blank" rel="noreferrer noopener">MongoDB</a></li>



<li><strong>Education:</strong> Bachelor of Science, Mechanical Engineering, The Cooper Union; Doctorate, Mechanical Engineering, the University of California, Berkeley</li>



<li><strong>Why she’s here:</strong> Lieberman is responsible for business system delivery, data engineering and analytics, corporate infrastructure, collaboration tools, and IT operations at MongoDB. Her resume includes serving on IT executive teams at Peloton, Okta, Zendesk, and Salesforce. Her career has also included stints at startups, working in public sector scientific computer research, and, like many in the industry, she worked at Cisco early in her career. Known for building talented, collaborative teams, she prides herself on a people-first approach to leadership.</li>



<li><strong>In her own words:</strong> On advice she would give her younger self: “I’d give myself two pieces of advice. The first is don’t worry so much about career growth; worry about making sure that you are part of the team that is tackling the thorniest, ickiest, hairballiest problems in your organization—because the more you are seen to be doing that repeatedly, the more your career growth is naturally going to take care of itself. The second thing is, speak up when it’s uncomfortable to do so, and especially when it’s uncomfortable to do so, because you have to train yourself to be part of the conversation, as opposed to an onlooker,” <a href="https://www.thestack.technology/the-big-interview-mongodb-cio-mindy-lieberman/" target="_blank" rel="noreferrer noopener">she said in a recent interview with The Stack.</a> </li>



<li><strong>Fun fact:</strong> She was a post-doctoral research assistant at Lawrence Livermore National Lab, working on fluid flow simulations.</li>
</ul>



<h2 class="wp-block-heading">12. Sharon Mandell</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized"> srcset="https://b2b-contenthub.com/wp-content/uploads/2025/03/12-Juniper-Sharon-Mandell.jpeg?quality=50&amp;strip=all 1200w, https://b2b-contenthub.com/wp-content/uploads/2025/03/12-Juniper-Sharon-Mandell.jpeg?resize=240%2C300&amp;quality=50&amp;strip=all 240w, https://b2b-contenthub.com/wp-content/uploads/2025/03/12-Juniper-Sharon-Mandell.jpeg?resize=768%2C960&amp;quality=50&amp;strip=all 768w, https://b2b-contenthub.com/wp-content/uploads/2025/03/12-Juniper-Sharon-Mandell.jpeg?resize=819%2C1024&amp;quality=50&amp;strip=all 819w, https://b2b-contenthub.com/wp-content/uploads/2025/03/12-Juniper-Sharon-Mandell.jpeg?resize=558%2C697&amp;quality=50&amp;strip=all 558w, https://b2b-contenthub.com/wp-content/uploads/2025/03/12-Juniper-Sharon-Mandell.jpeg?resize=134%2C168&amp;quality=50&amp;strip=all 134w, https://b2b-contenthub.com/wp-content/uploads/2025/03/12-Juniper-Sharon-Mandell.jpeg?resize=67%2C84&amp;quality=50&amp;strip=all 67w, https://b2b-contenthub.com/wp-content/uploads/2025/03/12-Juniper-Sharon-Mandell.jpeg?resize=384%2C480&amp;quality=50&amp;strip=all 384w, https://b2b-contenthub.com/wp-content/uploads/2025/03/12-Juniper-Sharon-Mandell.jpeg?resize=288%2C360&amp;quality=50&amp;strip=all 288w, https://b2b-contenthub.com/wp-content/uploads/2025/03/12-Juniper-Sharon-Mandell.jpeg?resize=200%2C250&amp;quality=50&amp;strip=all 200w" width="819" height="1024" sizes="(max-width: 819px) 100vw, 819px"&gt;</figure><p class="imageCredit">Juniper</p></div>



<ul class="wp-block-list">
<li><strong>Title:</strong> CIO, <a href="https://www.juniper.net/us/en/the-feed/topics/sharon-mandell.html" target="_blank" rel="noreferrer noopener">Juniper Networks</a></li>



<li><strong>Education:</strong> Bachelor of Arts, Computer Science, Temple University; Master of Computer Science, Georgia Institute of Technology; Master of Business Administration, University of Chicago</li>



<li><strong>Why she’s here:</strong> Mandell’s route to Juniper, where she leads the team that provides ongoing enhancement of the company’s IT infrastructure and applications architectures, has included lots of zigs and zags. She has worked in media, communications, and networking industries. She started as a programmer, co-founded a startup, and held titles of CIO and CTO at various stops along the way. Prior to Juniper, she was CIO at TIBCO Software. Throughout her career, she developed a level of expertise in cybersecurity and compliance, enterprise architecture and road mapping, data, and analytics.</li>



<li><strong>In her own words:</strong> On the topic of IT leadership, growth, and being open to new ideas, <a href="https://www.linkedin.com/posts/sharon-mandell-juniper_what-technologists-need-to-know-to-lead-an-activity-7257492282260480000-dinr/" target="_blank" rel="noreferrer noopener">she said</a>: “I’ve had a long career in technology, but stepping into the classroom has probably taught me at least as much as I’ve been able to share with my students. Along with my role as CIO of Juniper Networks, I teach a class every year at the University of San Francisco, and it’s shown me just how much power lies in having a beginner’s mindset, along with a willingness to make mistakes, be humbled, and continuously learn and evolve.”</li>



<li><strong>Fun fact:</strong> She wanted to be a ballet dancer and, at one point, she was in the apprentice program at the Pennsylvania Ballet, while also attending Temple University, where she was introduced to computer science.</li>
</ul>



<h2 class="wp-block-heading">13. Jill Popelka</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized"> srcset="https://b2b-contenthub.com/wp-content/uploads/2025/03/13-Darktrace-Jill-Popelka.jpg?quality=50&amp;strip=all 1200w, https://b2b-contenthub.com/wp-content/uploads/2025/03/13-Darktrace-Jill-Popelka.jpg?resize=240%2C300&amp;quality=50&amp;strip=all 240w, https://b2b-contenthub.com/wp-content/uploads/2025/03/13-Darktrace-Jill-Popelka.jpg?resize=768%2C960&amp;quality=50&amp;strip=all 768w, https://b2b-contenthub.com/wp-content/uploads/2025/03/13-Darktrace-Jill-Popelka.jpg?resize=819%2C1024&amp;quality=50&amp;strip=all 819w, https://b2b-contenthub.com/wp-content/uploads/2025/03/13-Darktrace-Jill-Popelka.jpg?resize=558%2C697&amp;quality=50&amp;strip=all 558w, https://b2b-contenthub.com/wp-content/uploads/2025/03/13-Darktrace-Jill-Popelka.jpg?resize=134%2C168&amp;quality=50&amp;strip=all 134w, https://b2b-contenthub.com/wp-content/uploads/2025/03/13-Darktrace-Jill-Popelka.jpg?resize=67%2C84&amp;quality=50&amp;strip=all 67w, https://b2b-contenthub.com/wp-content/uploads/2025/03/13-Darktrace-Jill-Popelka.jpg?resize=384%2C480&amp;quality=50&amp;strip=all 384w, https://b2b-contenthub.com/wp-content/uploads/2025/03/13-Darktrace-Jill-Popelka.jpg?resize=288%2C360&amp;quality=50&amp;strip=all 288w, https://b2b-contenthub.com/wp-content/uploads/2025/03/13-Darktrace-Jill-Popelka.jpg?resize=200%2C250&amp;quality=50&amp;strip=all 200w" width="819" height="1024" sizes="(max-width: 819px) 100vw, 819px"&gt;</figure><p class="imageCredit">Darktrace</p></div>



<ul class="wp-block-list">
<li><strong>Title:</strong> CEO, <a href="https://darktrace.com/people/jill-popelka" target="_blank" rel="noreferrer noopener">Darktrace</a></li>



<li><strong>Education:</strong> Bachelor of Arts, International/Global Studies, Texas A&amp;M University</li>



<li><strong>Why she’s here:</strong> Popelka joined Darktrace, which specializes in AI-powered network monitoring, in January 2024 as a director on the company’s board. In June, she became COO, and in September became CEO, when founder and former CEO Poppy Gustafsson stepped aside following the company’s $5.3 billion takeover by private equity powerhouse Thoma Bravo. In her new role, Popelka will lead the company in its transition from a public company to part of the Thoma Bravo portfolio. Prior to Darktrace, she spent two years as head of enterprise services at Snap, and was a longtime employee at SAP, where she led the SAP SuccessFactors business unit.</li>



<li><strong>In her own words:</strong> On the topic of prioritizing the employee experience, <a href="https://www.linkedin.com/pulse/lets-get-started-laying-foundation-great-employee-jill-popelka/" target="_blank" rel="noreferrer noopener">she said</a>: “Technology should <em>strengthen</em> human connection—not weaken it. Don’t be a ‘tech-first’ company; be a ‘people-first’ company.”</li>



<li><strong>Fun fact:</strong> She wrote a book called, <strong><em>Experience, Inc.: Why Companies That Uncover Purpose, Create Connection, and Celebrate Their People Will Triumph, </em></strong>a business leader’s guide to creating a winning employee experience for your organization and your people.</li>
</ul>



<h2 class="wp-block-heading">14. Kate Prouty</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized"> srcset="https://b2b-contenthub.com/wp-content/uploads/2025/03/14-Akamai-Kate-Prouty.jpeg?quality=50&amp;strip=all 1200w, https://b2b-contenthub.com/wp-content/uploads/2025/03/14-Akamai-Kate-Prouty.jpeg?resize=240%2C300&amp;quality=50&amp;strip=all 240w, https://b2b-contenthub.com/wp-content/uploads/2025/03/14-Akamai-Kate-Prouty.jpeg?resize=768%2C960&amp;quality=50&amp;strip=all 768w, https://b2b-contenthub.com/wp-content/uploads/2025/03/14-Akamai-Kate-Prouty.jpeg?resize=819%2C1024&amp;quality=50&amp;strip=all 819w, https://b2b-contenthub.com/wp-content/uploads/2025/03/14-Akamai-Kate-Prouty.jpeg?resize=558%2C697&amp;quality=50&amp;strip=all 558w, https://b2b-contenthub.com/wp-content/uploads/2025/03/14-Akamai-Kate-Prouty.jpeg?resize=134%2C168&amp;quality=50&amp;strip=all 134w, https://b2b-contenthub.com/wp-content/uploads/2025/03/14-Akamai-Kate-Prouty.jpeg?resize=67%2C84&amp;quality=50&amp;strip=all 67w, https://b2b-contenthub.com/wp-content/uploads/2025/03/14-Akamai-Kate-Prouty.jpeg?resize=384%2C480&amp;quality=50&amp;strip=all 384w, https://b2b-contenthub.com/wp-content/uploads/2025/03/14-Akamai-Kate-Prouty.jpeg?resize=288%2C360&amp;quality=50&amp;strip=all 288w, https://b2b-contenthub.com/wp-content/uploads/2025/03/14-Akamai-Kate-Prouty.jpeg?resize=200%2C250&amp;quality=50&amp;strip=all 200w" width="819" height="1024" sizes="(max-width: 819px) 100vw, 819px"&gt;</figure><p class="imageCredit">Akamai</p></div>



<ul class="wp-block-list">
<li><strong>Title:</strong> Senior Vice President and CIO, <a href="https://www.akamai.com/company/leadership/executive-team/kate-prouty" target="_blank" rel="noreferrer noopener">Akamai</a></li>



<li><strong>Education:</strong> Bachelor of Science, Business Administration, Keene State College; graduate of the Greater Boston Executive Program, MIT Sloan School of Management</li>



<li><strong>Why she’s here:</strong> Prouty oversees Akamai’s IT organization, responsible for business transformation, including global strategy, development, and operation of applications and IT infrastructure. Prouty joined Akamai in 1999 and has been instrumental in developing systems that have been foundational to the company’s growth, including ERP and supply chain. Prior to joining Akamai, she held a variety of technology positions including in network administration, system administration, database administration, and software implementation at Fleet Financial and Digitas.</li>



<li><strong>In her own words:</strong> She offered advice in three areas: 1. “Unfortunately, there’s pressure on people to present in a way that they think everyone wants them to, as opposed to just being comfortable in your own skin. Be yourself.” 2. “There’s nothing that’s going to replace hard work. There’s no silver bullet. There’s no easy answer. At the end of the day, it’s about hard work.” 3. “You need to challenge yourself. You need to raise your hand and take on the things that you aren’t 100% sure you can actually do, <a href="https://www.youtube.com/watch?v=36WjNX1GXX0" target="_blank" rel="noreferrer noopener">she said</a> in a leadership spotlight series at Akamai.</li>



<li><strong>Fun fact:</strong> Prouty co-chairs the Executive Women’s Network at Akamai and is a member of the board of directors of Delta Projects, which supports people with intellectual challenges.</li>
</ul>



<h2 class="wp-block-heading">15. Meerah Rajavel</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized"> srcset="https://b2b-contenthub.com/wp-content/uploads/2025/03/15-Palo-Alto-Meerah-Rajavel.jpeg?quality=50&amp;strip=all 1200w, https://b2b-contenthub.com/wp-content/uploads/2025/03/15-Palo-Alto-Meerah-Rajavel.jpeg?resize=240%2C300&amp;quality=50&amp;strip=all 240w, https://b2b-contenthub.com/wp-content/uploads/2025/03/15-Palo-Alto-Meerah-Rajavel.jpeg?resize=768%2C960&amp;quality=50&amp;strip=all 768w, https://b2b-contenthub.com/wp-content/uploads/2025/03/15-Palo-Alto-Meerah-Rajavel.jpeg?resize=819%2C1024&amp;quality=50&amp;strip=all 819w, https://b2b-contenthub.com/wp-content/uploads/2025/03/15-Palo-Alto-Meerah-Rajavel.jpeg?resize=558%2C697&amp;quality=50&amp;strip=all 558w, https://b2b-contenthub.com/wp-content/uploads/2025/03/15-Palo-Alto-Meerah-Rajavel.jpeg?resize=134%2C168&amp;quality=50&amp;strip=all 134w, https://b2b-contenthub.com/wp-content/uploads/2025/03/15-Palo-Alto-Meerah-Rajavel.jpeg?resize=67%2C84&amp;quality=50&amp;strip=all 67w, https://b2b-contenthub.com/wp-content/uploads/2025/03/15-Palo-Alto-Meerah-Rajavel.jpeg?resize=384%2C480&amp;quality=50&amp;strip=all 384w, https://b2b-contenthub.com/wp-content/uploads/2025/03/15-Palo-Alto-Meerah-Rajavel.jpeg?resize=288%2C360&amp;quality=50&amp;strip=all 288w, https://b2b-contenthub.com/wp-content/uploads/2025/03/15-Palo-Alto-Meerah-Rajavel.jpeg?resize=200%2C250&amp;quality=50&amp;strip=all 200w" width="819" height="1024" sizes="(max-width: 819px) 100vw, 819px"&gt;</figure><p class="imageCredit">Palo Alto Networks</p></div>



<ul class="wp-block-list">
<li><strong>Title:</strong> CIO, <a href="https://www.paloaltonetworks.com/about-us/management" target="_blank" rel="noreferrer noopener">Palo Alto Networks</a></li>



<li><strong>Education:</strong> Bachelor of Science, Computer Science and Engineering, the Thiagarajar College of Engineering at Anna University in Chennai, India; Master of Business Administration, the Leavey School of Business, Santa Clara University, California</li>



<li><strong>Why she’s here:</strong> Rajavel oversees the 1,000-member team at Palo Alto Networks responsible for the technology and business infrastructure that runs the company. Her journey to Palo Alto included stops at Lotus Infotech, Infosys, Cisco, McAfee, and Forcepoint. Prior to joining Palo Alto, she was CIO at Citrix. Rajavel was married at age 20 and her marital status didn’t go over well with prospective employers back in the ’90s. <a href="https://yourstory.com/herstory/2023/07/its-okay-to-fall-if-you-know-how-to-get-up-meerah-rajavel" target="_blank" rel="noreferrer noopener">She recalled</a>: “There was prejudice. I would pass all rounds and in the final one, someone would say, ‘Oh! You are married? Will your husband have a job transfer? Are you planning to have children? And then, they would reject.’ My husband was very supportive and would always tell me that it was their loss, not mine.”</li>



<li><strong>In her own words:</strong> On the topic of risk-taking, <a href="https://yourstory.com/herstory/2023/07/its-okay-to-fall-if-you-know-how-to-get-up-meerah-rajavel" target="_blank" rel="noreferrer noopener">she said</a>: “It’s okay to fall if you know how to get up. But practice on getting up, and not falling. Again, if you are not falling, you are playing safe.”</li>



<li><strong>Fun fact:</strong> A technologist at heart, she started programming when she was in the 10<sup>th</sup> grade.</li>
</ul>



<h2 class="wp-block-heading">16. Fidelma Russo</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized"> srcset="https://b2b-contenthub.com/wp-content/uploads/2025/03/16-HPE-Fidelma-Russo.jpeg?quality=50&amp;strip=all 1200w, https://b2b-contenthub.com/wp-content/uploads/2025/03/16-HPE-Fidelma-Russo.jpeg?resize=240%2C300&amp;quality=50&amp;strip=all 240w, https://b2b-contenthub.com/wp-content/uploads/2025/03/16-HPE-Fidelma-Russo.jpeg?resize=768%2C960&amp;quality=50&amp;strip=all 768w, https://b2b-contenthub.com/wp-content/uploads/2025/03/16-HPE-Fidelma-Russo.jpeg?resize=819%2C1024&amp;quality=50&amp;strip=all 819w, https://b2b-contenthub.com/wp-content/uploads/2025/03/16-HPE-Fidelma-Russo.jpeg?resize=558%2C697&amp;quality=50&amp;strip=all 558w, https://b2b-contenthub.com/wp-content/uploads/2025/03/16-HPE-Fidelma-Russo.jpeg?resize=134%2C168&amp;quality=50&amp;strip=all 134w, https://b2b-contenthub.com/wp-content/uploads/2025/03/16-HPE-Fidelma-Russo.jpeg?resize=67%2C84&amp;quality=50&amp;strip=all 67w, https://b2b-contenthub.com/wp-content/uploads/2025/03/16-HPE-Fidelma-Russo.jpeg?resize=384%2C480&amp;quality=50&amp;strip=all 384w, https://b2b-contenthub.com/wp-content/uploads/2025/03/16-HPE-Fidelma-Russo.jpeg?resize=288%2C360&amp;quality=50&amp;strip=all 288w, https://b2b-contenthub.com/wp-content/uploads/2025/03/16-HPE-Fidelma-Russo.jpeg?resize=200%2C250&amp;quality=50&amp;strip=all 200w" width="819" height="1024" sizes="(max-width: 819px) 100vw, 819px"&gt;</figure><p class="imageCredit">HPE</p></div>



<ul class="wp-block-list">
<li><strong>Title:</strong> Executive Vice President and General Manager, Cloud Business Unit, and CTO, <a href="https://www.hpe.com/us/en/leadership-bios/fidelma-russo.html" target="_blank" rel="noreferrer noopener">HPE</a></li>



<li><strong>Education:</strong> Bachelor of Engineering, Electrical Engineering, University College Cork; Master of Computer Science, Boston University; completed the Internet of Things Executive Education program at MIT’s Sloan School of Management</li>



<li><strong>Why she’s here:</strong> Russo wears two hats; She leads a 5,500-person global organization responsible for driving the strategic direction, development, and execution of HPE’s GreenLake platform, storage, private cloud, and SaaS solutions. And she is in charge of driving innovation through the Office of the CTO. She joined Hewlett Packard Enterprise in September 2021 as CTO, where she led the creation, development, and delivery of GreenLake. In 2023, CEO Antonio Neri established a Hybrid Cloud business unit containing all GreenLake activities and put Russo in charge. Prior to joining HPE, she had stints at VMware, Iron Mountain, EMC, Sun Microsystems, and Dell.</li>



<li><strong>In her own words:</strong> On the topic of advice that she’s grateful for, <a href="https://www.weforum.org/podcasts/meet-the-leader/episodes/fidelma-russo-innovation-cto/" target="_blank" rel="noreferrer noopener">Russo said</a>: “I got a piece of advice. I didn’t appreciate it at the time, and I am immensely thankful for it. And it is the following: ‘You always bring yourself with you.’ And so sometimes when you are having challenges and difficulties, you really have to look in the mirror and think about, is it you? Is it how you react? And really own that yourself. It kind of clarifies things for you. And I’ve always appreciated that piece of advice, which I got many, many years ago.”</li>



<li><strong>Fun fact:</strong> She worked at HPE once before. She was vice-president of adaptive infrastructure at what was then HP in 2006-2007.</li>
</ul>



<h2 class="wp-block-heading">17. Dr. Lisa Su</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized"> srcset="https://b2b-contenthub.com/wp-content/uploads/2025/03/17-AMD-Lisa-Su.jpeg?quality=50&amp;strip=all 1200w, https://b2b-contenthub.com/wp-content/uploads/2025/03/17-AMD-Lisa-Su.jpeg?resize=240%2C300&amp;quality=50&amp;strip=all 240w, https://b2b-contenthub.com/wp-content/uploads/2025/03/17-AMD-Lisa-Su.jpeg?resize=768%2C960&amp;quality=50&amp;strip=all 768w, https://b2b-contenthub.com/wp-content/uploads/2025/03/17-AMD-Lisa-Su.jpeg?resize=819%2C1024&amp;quality=50&amp;strip=all 819w, https://b2b-contenthub.com/wp-content/uploads/2025/03/17-AMD-Lisa-Su.jpeg?resize=558%2C697&amp;quality=50&amp;strip=all 558w, https://b2b-contenthub.com/wp-content/uploads/2025/03/17-AMD-Lisa-Su.jpeg?resize=134%2C168&amp;quality=50&amp;strip=all 134w, https://b2b-contenthub.com/wp-content/uploads/2025/03/17-AMD-Lisa-Su.jpeg?resize=67%2C84&amp;quality=50&amp;strip=all 67w, https://b2b-contenthub.com/wp-content/uploads/2025/03/17-AMD-Lisa-Su.jpeg?resize=384%2C480&amp;quality=50&amp;strip=all 384w, https://b2b-contenthub.com/wp-content/uploads/2025/03/17-AMD-Lisa-Su.jpeg?resize=288%2C360&amp;quality=50&amp;strip=all 288w, https://b2b-contenthub.com/wp-content/uploads/2025/03/17-AMD-Lisa-Su.jpeg?resize=200%2C250&amp;quality=50&amp;strip=all 200w" width="819" height="1024" sizes="(max-width: 819px) 100vw, 819px"&gt;</figure><p class="imageCredit">AMD </p></div>



<ul class="wp-block-list">
<li><strong>Title:</strong> CEO and Chair, <a href="https://www.amd.com/en/corporate/leadership/lisa-su.html" target="_blank" rel="noreferrer noopener">Advanced Micro Devices (AMD)</a></li>



<li><strong>Education:</strong> Bachelor of Science, Electrical Engineering, Master of Science and Doctor of Philosophy, Electrical Engineering, MIT</li>



<li><strong>Why she’s here:</strong> Su designed semiconductors at Texas Instruments, helped design chips at IBM, and was CTO at Freescale Semiconductor before being tasked to turn around a struggling AMD. She was named CEO in 2014 and successfully revitalized the company with a strategy that focused on designing (but not manufacturing) high-performance chips for AI and graphics-heavy use cases. In 2015, AMD was a $4 billion company that reported a net loss of $660 million. In 2023, AMD reported full-year revenue of $23 billion, with $854 million in net income. The company is gaining traction in enterprise data centers with its GPUs and is poised to capitalize on the rush to build high-performance systems for AI and generative AI.</li>



<li><strong>In her own words:</strong> On her decision to focus on electrical engineering at MIT, <a href="https://stratechery.com/2024/an-interview-with-amd-ceo-lisa-su-about-solving-hard-problems/" target="_blank" rel="noreferrer noopener">Su said</a>: “I was always around math and science, my parents were always saying, ‘You have to do the hard things.’ When I went to MIT, at that time, it was a decision between electrical engineering and computer science. Computer science, you could just write software programs, whereas electrical engineering, you had to build things. I wanted to build things.”</li>



<li><strong>Fun fact:</strong> Jensen Huang, CEO at competitor Nvidia, is a distant cousin.</li>
</ul>



<h2 class="wp-block-heading">18. Jayshree Ullal</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized"> srcset="https://b2b-contenthub.com/wp-content/uploads/2025/03/18-Arista-Jayshree-Ullal.jpeg?quality=50&amp;strip=all 1200w, https://b2b-contenthub.com/wp-content/uploads/2025/03/18-Arista-Jayshree-Ullal.jpeg?resize=240%2C300&amp;quality=50&amp;strip=all 240w, https://b2b-contenthub.com/wp-content/uploads/2025/03/18-Arista-Jayshree-Ullal.jpeg?resize=768%2C960&amp;quality=50&amp;strip=all 768w, https://b2b-contenthub.com/wp-content/uploads/2025/03/18-Arista-Jayshree-Ullal.jpeg?resize=819%2C1024&amp;quality=50&amp;strip=all 819w, https://b2b-contenthub.com/wp-content/uploads/2025/03/18-Arista-Jayshree-Ullal.jpeg?resize=558%2C697&amp;quality=50&amp;strip=all 558w, https://b2b-contenthub.com/wp-content/uploads/2025/03/18-Arista-Jayshree-Ullal.jpeg?resize=134%2C168&amp;quality=50&amp;strip=all 134w, https://b2b-contenthub.com/wp-content/uploads/2025/03/18-Arista-Jayshree-Ullal.jpeg?resize=67%2C84&amp;quality=50&amp;strip=all 67w, https://b2b-contenthub.com/wp-content/uploads/2025/03/18-Arista-Jayshree-Ullal.jpeg?resize=384%2C480&amp;quality=50&amp;strip=all 384w, https://b2b-contenthub.com/wp-content/uploads/2025/03/18-Arista-Jayshree-Ullal.jpeg?resize=288%2C360&amp;quality=50&amp;strip=all 288w, https://b2b-contenthub.com/wp-content/uploads/2025/03/18-Arista-Jayshree-Ullal.jpeg?resize=200%2C250&amp;quality=50&amp;strip=all 200w" width="819" height="1024" sizes="(max-width: 819px) 100vw, 819px"&gt;</figure><p class="imageCredit">Arista Networks</p></div>



<ul class="wp-block-list">
<li><strong>Title:</strong> President and CEO, <a href="https://www.arista.com/en/company/management-team" target="_blank" rel="noreferrer noopener">Arista Networks</a></li>



<li><strong>Education:</strong> Bachelor of Science, Electrical Engineering, San Francisco State University; Master of Science, Engineering Management, Santa Clara University</li>



<li><strong>Why she’s here:</strong> There’s bold. There’s brave. There’s brash. Then there’s leaving Cisco after 15 years in upper management to join a startup that challenged Cisco in its core network switch business. That’s what Jayshree Ullal did in 2008, when she became CEO of upstart Arista Networks. The results have been impressive. Arista racked up nearly $6 billion in revenue in 2023. The company actually surpassed Cisco in the data center switch market share in Q4 2023 (according to Dell’Oro Group.) In the early days, when Cisco had the enterprise pretty much locked up, Arista went after the cloud service providers. That strategy has paid dividends; 43% of the company’s total revenue comes from the hyperscalers.</li>



<li><strong>In her own words:</strong> On the topic of her guiding principles, <a href="https://www.lightreading.com/telecoms-software/arista-s-ceo-shares-her-guiding-principles" target="_blank" rel="noreferrer noopener">Ullal said</a>: <strong>“</strong>As human beings, we all want to do a good job, be acknowledged, and crave that appreciation. Treat your peers and team respectfully, cultivate their inner strengths, and harness their full potential.”</li>



<li><strong>Fun fact:</strong> She created (with her husband) the SITA Foundation for Women, which works to fund women internationally in pursuing education. SITA also funds cancer research.</li>
</ul>



<h2 class="wp-block-heading">19. Joanne Wright</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized"> srcset="https://b2b-contenthub.com/wp-content/uploads/2025/03/19-IBM-Joanne-Wright.jpeg?quality=50&amp;strip=all 1200w, https://b2b-contenthub.com/wp-content/uploads/2025/03/19-IBM-Joanne-Wright.jpeg?resize=240%2C300&amp;quality=50&amp;strip=all 240w, https://b2b-contenthub.com/wp-content/uploads/2025/03/19-IBM-Joanne-Wright.jpeg?resize=768%2C960&amp;quality=50&amp;strip=all 768w, https://b2b-contenthub.com/wp-content/uploads/2025/03/19-IBM-Joanne-Wright.jpeg?resize=819%2C1024&amp;quality=50&amp;strip=all 819w, https://b2b-contenthub.com/wp-content/uploads/2025/03/19-IBM-Joanne-Wright.jpeg?resize=558%2C697&amp;quality=50&amp;strip=all 558w, https://b2b-contenthub.com/wp-content/uploads/2025/03/19-IBM-Joanne-Wright.jpeg?resize=134%2C168&amp;quality=50&amp;strip=all 134w, https://b2b-contenthub.com/wp-content/uploads/2025/03/19-IBM-Joanne-Wright.jpeg?resize=67%2C84&amp;quality=50&amp;strip=all 67w, https://b2b-contenthub.com/wp-content/uploads/2025/03/19-IBM-Joanne-Wright.jpeg?resize=384%2C480&amp;quality=50&amp;strip=all 384w, https://b2b-contenthub.com/wp-content/uploads/2025/03/19-IBM-Joanne-Wright.jpeg?resize=288%2C360&amp;quality=50&amp;strip=all 288w, https://b2b-contenthub.com/wp-content/uploads/2025/03/19-IBM-Joanne-Wright.jpeg?resize=200%2C250&amp;quality=50&amp;strip=all 200w" width="819" height="1024" sizes="(max-width: 819px) 100vw, 819px"&gt;</figure><p class="imageCredit">IBM</p></div>



<ul class="wp-block-list">
<li><strong>Title:</strong> Senior Vice President, Transformation and Operations, <a href="https://newsroom.ibm.com/joanne-wright" target="_blank" rel="noreferrer noopener">IBM</a></li>



<li><strong>Education:</strong> Bachelor of Arts, Business, Management, and Marketing, Glasgow Caledonian University</li>



<li><strong>Why she’s here:</strong> Probably no major U.S. company has undergone the type of upheaval that IBM has over the past 25 years. The transitions from hardware to software to services to cloud to AI under multiple management teams have been anything but smooth. Wright has seen it all and has seen her star steadily rise from 1998, when she joined the company, to today, where she is Senior Vice President, Transformation and Operations. In this role, she is responsible for delivering productivity across IBM through the application of AI on the hybrid cloud and to unleash innovation and growth. In her 25-year career at IBM, she has held key leadership roles across procurement, manufacturing, supply chain, real estate, client support, and operations.</li>



<li><strong>In her own words:</strong> “Early on in my career, I recognized the importance of these three tips. Tip one: Plan ahead, schedule. Make sure you have the right amount of time to spend on the most important things you need to cover every day. Tip two: Unplug: Each evening if I’m in town, we have dinner as a family. None of us are on electronics; the TV is off. Tip three: Have fun: Make sure you have time for every aspect of your life, and that includes ‘me’ time. Relax, take a hot bath, have that mindful moment,” <a href="https://www.youtube.com/watch?v=jokdNb-ajuQ" target="_blank" rel="noreferrer noopener">she said</a> on the topic of work/life balance.</li>



<li><strong>Fun fact:</strong> She is the head of the Women at IBM Community and started the company’s Women’s Business Resource Group. </li>
</ul>



<h2 class="wp-block-heading">20. Michelle Zatlyn</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized"> srcset="https://b2b-contenthub.com/wp-content/uploads/2025/03/20-Cloudflare-Michelle-Zatlyn.jpeg?quality=50&amp;strip=all 1200w, https://b2b-contenthub.com/wp-content/uploads/2025/03/20-Cloudflare-Michelle-Zatlyn.jpeg?resize=240%2C300&amp;quality=50&amp;strip=all 240w, https://b2b-contenthub.com/wp-content/uploads/2025/03/20-Cloudflare-Michelle-Zatlyn.jpeg?resize=768%2C960&amp;quality=50&amp;strip=all 768w, https://b2b-contenthub.com/wp-content/uploads/2025/03/20-Cloudflare-Michelle-Zatlyn.jpeg?resize=819%2C1024&amp;quality=50&amp;strip=all 819w, https://b2b-contenthub.com/wp-content/uploads/2025/03/20-Cloudflare-Michelle-Zatlyn.jpeg?resize=558%2C697&amp;quality=50&amp;strip=all 558w, https://b2b-contenthub.com/wp-content/uploads/2025/03/20-Cloudflare-Michelle-Zatlyn.jpeg?resize=134%2C168&amp;quality=50&amp;strip=all 134w, https://b2b-contenthub.com/wp-content/uploads/2025/03/20-Cloudflare-Michelle-Zatlyn.jpeg?resize=67%2C84&amp;quality=50&amp;strip=all 67w, https://b2b-contenthub.com/wp-content/uploads/2025/03/20-Cloudflare-Michelle-Zatlyn.jpeg?resize=384%2C480&amp;quality=50&amp;strip=all 384w, https://b2b-contenthub.com/wp-content/uploads/2025/03/20-Cloudflare-Michelle-Zatlyn.jpeg?resize=288%2C360&amp;quality=50&amp;strip=all 288w, https://b2b-contenthub.com/wp-content/uploads/2025/03/20-Cloudflare-Michelle-Zatlyn.jpeg?resize=200%2C250&amp;quality=50&amp;strip=all 200w" width="819" height="1024" sizes="(max-width: 819px) 100vw, 819px"&gt;</figure><p class="imageCredit">Cloudflare</p></div>



<ul class="wp-block-list">
<li><strong>Title:</strong> Co-founder and president, <a href="https://www.cloudflare.com/" target="_blank" rel="noreferrer noopener">Cloudflare</a></li>



<li><strong>Education:</strong> Bachelor of Arts/Science, McGill University; Master of Business Administration, Harvard Business School</li>



<li><strong>Why she’s here:</strong> Zatlyn and two of her Harvard Business School friends (Matthew Prince and Lee Holloway) co-founded Cloudflare in 2009. (Cloudflare acts as a reverse proxy service that provides content delivery, security, and application performance optimization for Internet traffic.) Zatlyn admits she didn’t know a lot about technology when the company was founded, but she learned fast. She was chief operating officer through the company’s wildly successful IPO in 2019, and in 2020 became company president. At the time, <a href="https://www.fastcompany.com/90587133/exclusive-cloudflare-promotes-michelle-zatlyn-to-president-a-gain-for-women-in-tech" target="_blank" rel="noreferrer noopener">Prince said</a>: “Had it just been me and Lee, we’d still be in a small office over the nail salon in Palo Alto. Her leadership within Cloudflare has been a big part of how we have been able to thrive, taking care of our employees, our customers, and our business.” Today, the company has $1.6 billion in annualized revenue and is growing 30% year-over-year. Cloudflare is now valued at more than $28 billion.</li>



<li><strong>In her own words:</strong> On pitching Cloudflare to investors, <a href="https://techcrunch.com/2020/09/17/cloudflares-michelle-zatlyn-on-getting-funding-for-crazy-ideas/" target="_blank" rel="noreferrer noopener">Zatlyn said</a>:: “It was bold then and not everyone thought it was a good idea. Some people looked at us like we’re crazy, but I’d like to say that when people look at you like you’re crazy, you’re probably onto something big,” she said on pitching Cloudflare to investors.</li>



<li><strong>Fun fact:</strong> In high school, she was captain of the girls’ basketball team.</li>
</ul>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[KI gegen Cyberangriffe: Deutschland fehlt Strategie - Security-Insider]]></title>
<description><![CDATA[„State of AI Cybersecurity“-Report von Darktrace KI-Bedrohungen überholen Abwehrstrategien. 24.03.2025 Quelle: Pressemitteilung 2 min Lesedauer.KI generiertes Nachrichten UpdateVerwendetes künstliches Intelligenz Model: gemma-3-12b-itKI gegen Cyberangriffe: Deutschland fehlt Strategie – Ein kriti...]]></description>
<link>https://tsecurity.de/de/2684084/it-security-nachrichten/ki-gegen-cyberangriffe-deutschland-fehlt-strategie-security-insider/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2684084/it-security-nachrichten/ki-gegen-cyberangriffe-deutschland-fehlt-strategie-security-insider/</guid>
<pubDate>Mon, 24 Mar 2025 18:03:43 +0100</pubDate>
<content:encoded><![CDATA[„State of AI Cybersecurity“-Report von Darktrace KI-Bedrohungen überholen Abwehrstrategien. 24.03.2025 Quelle: Pressemitteilung 2 min Lesedauer.<!-- START: Dynamically Added Content --><br><h3>KI generiertes Nachrichten Update</h3><hr>Verwendetes künstliches Intelligenz Model: gemma-3-12b-it<br><br><h2>KI gegen Cyberangriffe: Deutschland fehlt Strategie – Ein kritischer Blick auf die Implementierung und die Notwendigkeit einer nationalen Richtlinie</h2><br />
<p><strong>Abstract:</strong> Die zunehmende Raffinesse und Automatisierung von Cyberangriffen stellen eine wachsende Bedrohung für Unternehmen, Behörden und kritische Infrastrukturen in Deutschland dar. Künstliche Intelligenz (KI) bietet vielversprechende Möglichkeiten zur Verbesserung der Cyberabwehr, indem sie Muster erkennt, Anomalien identifiziert und automatisierte Reaktionen ermöglicht.  Allerdings fehlt es Deutschland bislang an einer kohärenten nationalen Strategie für den Einsatz von KI im Bereich der Cybersicherheit. Dieser Artikel analysiert die aktuellen Entwicklungen, Herausforderungen und Chancen des Einsatzes von KI in der Cyberabwehr, beleuchtet die Defizite der deutschen Vorgehensweise und plädiert für eine umfassende nationale Richtlinie zur Förderung eines verantwortungsvollen und effektiven KI-basierten Cyber-Schutzes.</p><br />
<p><strong>1. Einleitung: Die Eskalation der Bedrohungslage und das Potenzial der KI</strong></p><br />
<p>Die digitale Transformation, die COVID-19 Pandemie und geopolitische Spannungen haben zu einer signifikanten Zunahme der Cyberbedrohungen geführt.  Angriffe werden immer häufiger, komplexer und automatisierter. Traditionelle Sicherheitslösungen basierend auf manuellen Prozessen und regelbasierten Systemen können mit dieser Dynamik kaum noch mithalten. Die steigende Anzahl von Vorfällen, die zunehmende Komplexität der Angriffe und der Fachkräftemangel in der IT-Sicherheitsbranche erfordern innovative Ansätze (vgl. <a href="https://tsecurity.de/de/2684084/IT+Sicherheit/Cybersecurity+Nachrichten/KI+gegen+Cyberangriffe%3A+Deutschland+fehlt+Strategie+-+Security-Insider/">Tsecurity.de - KI gegen Cyberangriffe</a>).</p><br />
<p>Künstliche Intelligenz (KI) und insbesondere Machine Learning (ML) bieten hier ein enormes Potenzial. KI kann große Datenmengen analysieren, Anomalien erkennen, Verhaltensmuster vorhersagen und automatisierte Abwehrreaktionen auslösen – oft in Echtzeit.  Anwendungsbereiche sind unter anderem:</p><br />
<ul><br />
<li><strong>Intrusion Detection Systems (IDS):</strong> KI-basierte IDS können ungewöhnliche Netzwerkaktivitäten identifizieren, die auf Angriffe hindeuten könnten.</li><br />
<li><strong>Threat Intelligence:</strong> KI kann Informationen aus verschiedenen Quellen aggregieren und analysieren, um Bedrohungen frühzeitig zu erkennen und Vorhersagen über zukünftige Angriffe zu treffen.</li><br />
<li><strong>Malware Detection:</strong> ML-Modelle können Malware anhand von Verhaltensmerkmalen identifizieren, auch wenn sie noch unbekannt sind (Zero-Day-Angriffe).</li><br />
<li><strong>Security Information and Event Management (SIEM):</strong> KI kann SIEM-Systeme verbessern, indem sie die Analyse großer Datenmengen automatisiert und relevante Vorfälle hervorhebt.</li><br />
<li><strong>Automatisierte Reaktion:</strong>  KI kann automatisierte Reaktionen auf Sicherheitsvorfälle auslösen, um den Schaden zu minimieren und die Reaktionszeit zu verkürzen (Security Orchestration, Automation and Response - SOAR).</li><br />
</ul><br />
<p><strong>2. Der Stand der KI-Implementierung in der Cyberabwehr – Deutschland im internationalen Vergleich</strong></p><br />
<p>Obwohl das Potenzial von KI in der Cybersicherheit weithin anerkannt ist, sind die tatsächlichen Implementierungen in Deutschland noch vergleichsweise langsam und fragmentiert. Während andere Länder wie die USA, Israel oder China bereits nationale Strategien und Initiativen zur Förderung des Einsatzes von KI in der Cyberabwehr entwickelt haben (vgl. <a href="https://www.atlanticcouncil.org/in-focus/cyberstatecraft/ai-and-cybersecurity/">Atlantic Council - AI and Cybersecurity</a>), fehlt es Deutschland an einer solchen übergreifenden Strategie.</p><br />
<p>Die Gründe für diese Zurückhaltung sind vielfältig:</p><br />
<ul><br />
<li><strong>Bedenken hinsichtlich ethischer Aspekte und Datenschutz:</strong> Der Einsatz von KI in der Cybersicherheit wirft Fragen nach Transparenz, Fairness und Verantwortlichkeit auf.  Datenschutzbestimmungen (DSGVO) stellen zusätzliche Herausforderungen dar, insbesondere bei der Verarbeitung personenbezogener Daten zur Erkennung von Bedrohungen.</li><br />
<li><strong>Mangel an Fachkräften:</strong> Der Mangel an KI-Experten mit Kenntnissen im Bereich der Cybersicherheit ist ein erhebliches Hindernis.</li><br />
<li><strong>Fehlende Anreize und Investitionen:</strong>  Es mangelt an klaren Förderprogrammen und finanziellen Anreizen für Unternehmen und Forschungseinrichtungen, KI-basierte Sicherheitslösungen zu entwickeln und einzusetzen.</li><br />
<li><strong>Bürokratische Hürden:</strong> Die Implementierung von KI-Systemen in Behörden und kritischen Infrastrukturen wird oft durch komplexe bürokratische Prozesse erschwert.</li><br />
</ul><br />
<p>Die im Artikel <a href="https://tsecurity.de/de/2684084/IT+Sicherheit/Cybersecurity+Nachrichten/KI+gegen+Cyberangriffe%3A+Deutschland+fehlt+Strategie+-+Security-Insider/">Tsecurity.de - KI gegen Cyberangriffe</a> angesprochene Situation, in der deutsche Unternehmen und Behörden Schwierigkeiten haben, KI-basierte Sicherheitslösungen einzuführen, spiegelt diese Probleme wider.  Die Abhängigkeit von ausländischen Anbietern wird dadurch verstärkt.</p><br />
<p><strong>3. Herausforderungen und Risiken des KI-basierten Cyber-Schutzes</strong></p><br />
<p>Neben den oben genannten Hindernissen müssen bei der Implementierung von KI in der Cybersicherheit auch spezifische Risiken berücksichtigt werden:</p><br />
<ul><br />
<li><strong>Adversarial Machine Learning:</strong> Angreifer können ML-Modelle durch gezielte Manipulationen täuschen oder umgehen.  &quot;Poisoning Attacks&quot; und &quot;Evasion Techniques&quot; sind hier nur zwei Beispiele (vgl. <a href="https://www.technologyreview.com/2017/11/30/284945/adversarial-machine-learning-is-a-serious-national-security-risk/">MIT Technology Review - Adversarial machine learning</a>).</li><br />
<li><strong>Datenbias:</strong> ML-Modelle sind nur so gut wie die Daten, mit denen sie trainiert werden.  Wenn die Trainingsdaten verzerrt sind, kann dies zu falschen oder diskriminierenden Ergebnissen führen.</li><br />
<li><strong>Automatisierung von Angriffen:</strong> KI kann nicht nur für die Abwehr eingesetzt werden, sondern auch zur Automatisierung und Verbesserung von Cyberangriffen.  &quot;Generative Adversarial Networks&quot; (GANs) können beispielsweise verwendet werden, um realistische Phishing-E-Mails oder Malware zu erstellen.</li><br />
<li><strong>Blackbox-Charakter:</strong> Viele KI-Modelle sind &quot;Blackboxes&quot;, deren Entscheidungen schwer nachvollziehbar und erklärbar sind. Dies kann die Akzeptanz und das Vertrauen in diese Systeme beeinträchtigen.</li><br />
</ul><br />
<p><strong>4. Empfehlungen für eine nationale Strategie zur Förderung des KI-basierten Cyber-Schutzes in Deutschland</strong></p><br />
<p>Um die Lücke zwischen dem Potenzial der KI in der Cybersicherheit und der tatsächlichen Implementierung in Deutschland zu schließen, ist eine umfassende nationale Strategie erforderlich.  Diese sollte folgende Elemente umfassen:</p><br />
<ul><br />
<li><strong>Klare Definition von Zielen und Prioritäten:</strong> Die Strategie muss klar definieren, welche Bereiche der Cyberabwehr durch den Einsatz von KI priorisiert werden sollen.</li><br />
<li><strong>Förderung von Forschung und Entwicklung:</strong> Es bedarf erheblicher Investitionen in die Grundlagenforschung und angewandte Forschung im Bereich des KI-basierten Cyber-Schutzes.</li><br />
<li><strong>Ausbildung und Weiterbildung:</strong>  Der Mangel an Fachkräften muss durch gezielte Ausbildungs- und Weiterbildungsprogramme behoben werden.</li><br />
<li><strong>Entwicklung ethischer Richtlinien und Datenschutzrahmenbedingungen:</strong> Es müssen klare ethische Leitlinien und datenschutzrechtliche Rahmenbedingungen für den Einsatz von KI in der Cybersicherheit geschaffen werden, die Transparenz, Fairness und Verantwortlichkeit gewährleisten.</li><br />
<li><strong>Förderung von Kooperationen:</strong>  Die Zusammenarbeit zwischen Unternehmen, Forschungseinrichtungen, Behörden und internationalen Partnern muss gestärkt werden.</li><br />
<li><strong>Pilotprojekte und Best Practices:</strong> Die Implementierung von KI-basierten Sicherheitslösungen sollte durch Pilotprojekte unterstützt und die gewonnenen Erfahrungen dokumentiert und verbreitet werden.</li><br />
<li><strong>Sensibilisierung der Bevölkerung:</strong>  Die Öffentlichkeit muss über die Möglichkeiten und Risiken des KI-basierten Cyber-Schutzes informiert werden.</li><br />
</ul><br />
<p><strong>5. Fazit: Ein dringender Handlungsbedarf</strong></p><br />
<p>Der Einsatz von KI in der Cybersicherheit ist nicht länger eine Option, sondern eine Notwendigkeit. Deutschland steht vor einer historischen Chance, seine Cyberabwehrfähigkeiten deutlich zu verbessern und seine digitale Souveränität zu stärken.  Allerdings erfordert dies eine konzertierte Anstrengung aller Beteiligten und die Entwicklung einer umfassenden nationalen Strategie, die die oben genannten Punkte berücksichtigt. Die aktuelle Situation, wie sie im Artikel <a href="https://tsecurity.de/de/2684084/IT+Sicherheit/Cybersecurity+Nachrichten/KI+gegen+Cyberangriffe%3A+Deutschland+fehlt+Strategie+-+Security-Insider/">Tsecurity.de - KI gegen Cyberangriffe</a> dargelegt wird, unterstreicht den dringenden Handlungsbedarf.  Nur so kann Deutschland seine Position als führende Wirtschaftsnation in der digitalen Welt behaupten und seine Bürgerinnen und Bürger wirksam vor Cyberbedrohungen schützen.</p><br />
<p><strong>Schlüsselwörter:</strong> Künstliche Intelligenz (KI), Cybersicherheit, Cyberabwehr, Machine Learning (ML), Bedrohungslage, Nationale Strategie, Deutschland, Adversarial Machine Learning, Datenschutz, SOAR.</p><br />
<!-- END: Dynamically Added Content -->]]></content:encoded>
</item>
<item>
<title><![CDATA[Malware-as-a-Service: Für die meisten Angriffe verantwortlich - B2B Cyber Security]]></title>
<description><![CDATA[Darktrace, ein weltweit führendes Unternehmen für KI-gestützte Cybersicherheit, hat seinen jährlichen Threat Report veröffentlicht. Die Analyse des ...]]></description>
<link>https://tsecurity.de/de/2681625/it-security-nachrichten/malware-as-a-service-fuer-die-meisten-angriffe-verantwortlich-b2b-cyber-security/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2681625/it-security-nachrichten/malware-as-a-service-fuer-die-meisten-angriffe-verantwortlich-b2b-cyber-security/</guid>
<pubDate>Sun, 23 Mar 2025 08:18:11 +0100</pubDate>
<content:encoded><![CDATA[Darktrace, ein weltweit führendes Unternehmen für KI-gestützte Cybersicherheit, hat seinen jährlichen Threat Report veröffentlicht. Die Analyse des ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Worried AI Will Take Your Job? This AI Assistant Doesn’t Want It]]></title>
<description><![CDATA[Cursor, an AI coding assistant, challenges users to learn programming, sparking debate in the tech community.
The post Worried AI Will Take Your Job? This AI Assistant Doesn’t Want It appeared first on eWEEK.KI generiertes Nachrichten UpdateVerwendetes künstliches Intelligenz Model: gemma-3-12b-i...]]></description>
<link>https://tsecurity.de/de/2671726/it-nachrichten/worried-ai-will-take-your-job-this-ai-assistant-doesnt-want-it/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2671726/it-nachrichten/worried-ai-will-take-your-job-this-ai-assistant-doesnt-want-it/</guid>
<pubDate>Mon, 17 Mar 2025 18:45:32 +0100</pubDate>
<content:encoded><![CDATA[<p>Cursor, an AI coding assistant, challenges users to learn programming, sparking debate in the tech community.</p>
<p>The post <a href="https://www.eweek.com/news/cursor-ai-coding-assistant/">Worried AI Will Take Your Job? This AI Assistant Doesn’t Want It</a> appeared first on <a href="https://www.eweek.com/">eWEEK</a>.</p><!-- START: Dynamically Added Content --><br><h3>KI generiertes Nachrichten Update</h3><hr>Verwendetes künstliches Intelligenz Model: gemma-3-12b-it<br><br><p><strong>Achtung:</strong> Der Artikel soll wissenschaftlich fundiert sein, aber für ein Fachpublikum (IT-Experten, IT-Sicherheitsforscher, IT-Berater) verständlich geschrieben werden. Vermeide übermäßig populäre Formulierungen und verwende Fachterminologie korrekt.</p><br />
<hr /><br />
<h2>Die Symbiose statt der Substitution: Analyse des Konzepts &quot;AI Assistant&quot; als Werkzeug zur Kompetenzerweiterung in der IT-Branche</h2><br />
<p><strong>Einleitung</strong></p><br />
<p>Die rasante Entwicklung generativer Künstlicher Intelligenz (KI) hat zu einer weitverbreiteten Angst vor dem Verlust von Arbeitsplätzen, insbesondere in wissensintensiven Branchen wie der Informationstechnologie, geführt. Die Debatte dreht sich oft um die Frage, ob KI menschliche Fähigkeiten ersetzen oder lediglich ergänzen wird. Der Artikel &quot;Worried AI Will Take Your Job? This AI Assistant Doesn’t Want It&quot; (https://tsecurity.de/de/2671726/IT+Nachrichten/Worried+AI+Will+Take+Your+Job%3F+This+AI+Assistant+Doesn%E2%80%99t+Want+It/) beleuchtet einen interessanten Ansatz: die Entwicklung von KI-Assistenten, die aktiv darauf abzielen, menschliche Arbeitskräfte zu unterstützen und deren Kompetenzen zu erweitern, anstatt sie zu ersetzen. Dieser Artikel analysiert diesen Ansatz kritisch unter Berücksichtigung aktueller Forschungsergebnisse im Bereich der Mensch-KI-Interaktion (Human-AI Interaction – HAI) und bewertet dessen Potenzial für die IT-Branche.</p><br />
<p><strong>Der Paradigmenwechsel: Von Substitution zur Symbiose</strong></p><br />
<p>Traditionell wurde KI häufig als Werkzeug zur Automatisierung repetitiver Aufgaben und potenziellen Arbeitsplatzverlusten wahrgenommen. Dies führte zu einer defensiven Haltung vieler Fachkräfte, die befürchteten, durch algorithmische Prozesse obsolet zu werden.  Artikel auf tsecurity.de und verwandten Portalen (z.B. heise online, Computerwoche) spiegeln diese Angst wider und diskutieren häufig Szenarien der KI-gesteuerten Jobverdrängung.</p><br />
<p>Der von der Referenz genannte Ansatz stellt diesen Blickwinkel jedoch in Frage. Statt einer direkten Substitution wird ein &quot;AI Assistant&quot; konzipiert, der als Erweiterung menschlicher Fähigkeiten dient. Dieser Ansatz basiert auf dem Verständnis, dass die Stärken von KI (schnelle Datenverarbeitung, Mustererkennung) und den Stärken des Menschen (kreatives Denken, kritische Analyse, ethisches Urteilsvermögen) komplementär sind.</p><br />
<p><strong>Funktionsweise und Anwendungsbereiche eines &quot;AI Assistant&quot; in der IT-Branche</strong></p><br />
<p>Ein solches KI-System könnte verschiedene Funktionen umfassen:</p><br />
<ul><br />
<li><strong>Code-Generierung und -Analyse:</strong>  KI-Modelle wie Codex (von OpenAI) können bereits Code basierend auf natürlicher Sprachbeschreibung generieren. Ein &quot;AI Assistant&quot; könnte diese Fähigkeit nutzen, um Entwicklern bei der Erstellung von Prototypen zu helfen, repetitive Codierungsaufgaben zu automatisieren oder bestehenden Code zu analysieren und potenzielle Fehlerquellen aufzudecken. (vgl. GitHub Copilot: https://github.com/features/copilot)</li><br />
<li><strong>Sicherheitsanalysen:</strong>  KI-Assistenten könnten Sicherheitsrechercheern bei der Analyse großer Datenmengen helfen, Bedrohungsindikatoren zu identifizieren und Schwachstellen in Systemen zu finden. Die Fähigkeit von KI, Anomalien zu erkennen, kann die Reaktionszeit auf Sicherheitsvorfälle erheblich verkürzen. (Siehe auch: Darktrace Antigena: https://www.darktrace.com/de/)</li><br />
<li><strong>Infrastrukturmanagement:</strong>  Automatisierung der Überwachung und Konfiguration von IT-Infrastrukturen durch KI, um menschliche Administratoren zu entlasten und die Effizienz zu steigern. Dies kann auch Predictive Maintenance ermöglichen, um Ausfälle vorherzusehen und präventiv Maßnahmen zu ergreifen.</li><br />
<li><strong>Wissensmanagement:</strong>  KI kann als zentrales Wissensrepository fungieren, das Informationen aus verschiedenen Quellen zusammenführt und für Mitarbeiter leicht zugänglich macht. Dies fördert die Zusammenarbeit und reduziert den Zeitaufwand für die Informationsbeschaffung.</li><br />
</ul><br />
<p><strong>Herausforderungen und Risiken</strong></p><br />
<p>Die Implementierung von &quot;AI Assistant&quot;-Systemen ist jedoch nicht ohne Herausforderungen:</p><br />
<ul><br />
<li><strong>Datenschutz und Bias:</strong>  KI-Modelle werden mit großen Datenmengen trainiert, die möglicherweise Vorurteile enthalten oder sensible Informationen bergen. Es ist entscheidend, diese Verzerrungen zu identifizieren und zu minimieren, um faire und zuverlässige Ergebnisse zu gewährleisten. (Siehe auch: Fairness in AI - https://www.tensorflow.org/ai-principles/responsible-use)</li><br />
<li><strong>Abhängigkeit und Dequalifikation:</strong>  Eine übermäßige Abhängigkeit von KI-Assistenten könnte dazu führen, dass menschliche Fähigkeiten verkümmern. Es ist wichtig, sicherzustellen, dass Mitarbeiter weiterhin ihre eigenen Kompetenzen pflegen und kritisch hinterfragen können. (Das Konzept der &quot;Skill Erosion&quot; in HAI).</li><br />
<li><strong>Sicherheitsrisiken:</strong>  KI-Systeme selbst können anfällig für Angriffe sein. Ein kompromittierter KI-Assistent könnte falsche Informationen liefern oder schädliche Aktionen ausführen. Eine robuste Sicherheitsarchitektur ist daher unerlässlich. (Adversarial Attacks auf KI Modelle)</li><br />
<li><strong>Ethische Aspekte:</strong>  Die Nutzung von KI in der IT-Branche wirft ethische Fragen auf, beispielsweise im Hinblick auf die Transparenz von Algorithmen und die Verantwortlichkeit für Entscheidungen, die von KI getroffen werden.</li><br />
</ul><br />
<p><strong>Fazit und Ausblick</strong></p><br />
<p>Der Ansatz des &quot;AI Assistant&quot; als Werkzeug zur Kompetenzerweiterung bietet eine vielversprechende Alternative zum dystopischen Szenario der Jobverdrängung durch KI.  Die Symbiose zwischen Mensch und Maschine kann zu einer deutlichen Steigerung der Effizienz, Innovation und Sicherheit in der IT-Branche führen. Es ist jedoch entscheidend, die damit verbundenen Herausforderungen und Risiken proaktiv anzugehen.</p><br />
<p>Zukünftige Forschung sollte sich auf folgende Bereiche konzentrieren:</p><br />
<ul><br />
<li><strong>Entwicklung von HAI-Frameworks:</strong>  Die Gestaltung von intuitiven und effektiven Schnittstellen zwischen Mensch und KI erfordert ein tiefes Verständnis der menschlichen Kognition und Motivation.</li><br />
<li><strong>Erklärung der KI (Explainable AI – XAI):</strong>  Um das Vertrauen in KI-Systeme zu stärken, ist es wichtig, dass Entscheidungen nachvollziehbar sind und die Funktionsweise von Algorithmen transparent wird.</li><br />
<li><strong>Kontinuierliche Weiterbildung:</strong>  Fachkräfte müssen sich kontinuierlich weiterbilden, um mit den rasanten Entwicklungen im Bereich der KI Schritt halten und ihre Fähigkeiten an die neuen Anforderungen anzupassen.</li><br />
</ul><br />
<p>Die erfolgreiche Integration von &quot;AI Assistant&quot;-Systemen in die IT-Branche erfordert eine strategische Planung, verantwortungsvolle Implementierung und eine offene Kommunikation über die Chancen und Risiken dieser Technologie.  Die Zukunft liegt nicht in der Substitution des Menschen durch KI, sondern in der Schaffung einer intelligenten Partnerschaft, die das Beste aus beiden Welten vereint.</p><br />
<hr /><br />
<p><strong>Hinweis:</strong> Dieser Artikel ist eine wissenschaftliche Analyse basierend auf den bereitgestellten Informationen und zusätzlichen Recherchen. Die hier dargestellten Meinungen spiegeln die Perspektive des Autors wider und stellen keine abschließende Bewertung dar.</p><br />
<!-- END: Dynamically Added Content -->]]></content:encoded>
</item>
<item>
<title><![CDATA[Malware-as-a-Service hoch im Kurs]]></title>
<description><![CDATA[Malware-as-a-Service (MaaS) macht mittlerweile 57 Prozent der erkannten Bedrohungen aus. Phishing-Angriffe werden immer ausgefeilter. Cyberkriminelle setzen verstärkt auf Tarnung. Dies sind zentrale Ergebnisse des Darktrace-Threat-Reports 2024.]]></description>
<link>https://tsecurity.de/de/2670268/it-security-nachrichten/malware-as-a-service-hoch-im-kurs/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2670268/it-security-nachrichten/malware-as-a-service-hoch-im-kurs/</guid>
<pubDate>Mon, 17 Mar 2025 09:33:18 +0100</pubDate>
<content:encoded><![CDATA[Malware-as-a-Service (MaaS) macht mittlerweile 57 Prozent der erkannten Bedrohungen aus. Phishing-Angriffe werden immer ausgefeilter. Cyberkriminelle setzen verstärkt auf Tarnung. Dies sind zentrale Ergebnisse des Darktrace-Threat-Reports 2024.]]></content:encoded>
</item>
<item>
<title><![CDATA[Why you should ignore 99% of AI tools - and which four I use every day]]></title>
<description><![CDATA[How I avoid AI overwhelm, manage AI FOMO, and stay smarter, faster, and less stressed.KI generiertes Nachrichten UpdateVerwendetes künstliches Intelligenz Model: gemma-3-4b-itBitte beachte: Dieser Text soll ein wissenschaftlicher Artikel sein und nicht eine einfache Blog-Post oder Meinungsäußerun...]]></description>
<link>https://tsecurity.de/de/2669304/hacking/why-you-should-ignore-99-of-ai-tools-and-which-four-i-use-every-day/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2669304/hacking/why-you-should-ignore-99-of-ai-tools-and-which-four-i-use-every-day/</guid>
<pubDate>Sun, 16 Mar 2025 12:04:21 +0100</pubDate>
<content:encoded><![CDATA[How I avoid AI overwhelm, manage AI FOMO, and stay smarter, faster, and less stressed.<!-- START: Dynamically Added Content --><br><h3>KI generiertes Nachrichten Update</h3><hr>Verwendetes künstliches Intelligenz Model: gemma-3-4b-it<br><br><p><strong>Bitte beachte:</strong> Dieser Text soll ein wissenschaftlicher Artikel sein und nicht eine einfache Blog-Post oder Meinungsäußerung. Er muss fundiert, detailliert und kritisch analysiert werden.</p><br />
<hr /><br />
<h2>Die Illusion der Automatisierung: Eine kritische Betrachtung von KI-Tools im IT-Sicherheitskontext</h2><br />
<p><strong>Zusammenfassung:</strong> Der rasante Aufstieg von Künstlicher Intelligenz (KI)-basierten Tools verspricht eine Revolution in nahezu allen Branchen, einschließlich der IT-Sicherheit. Während viele Anbieter überzeugende Versprechungen hinsichtlich Automatisierung und Effizienz machen, ist es unerlässlich, diese Behauptungen kritisch zu hinterfragen. Dieser Artikel argumentiert, dass ein Großteil der derzeitigen KI-Tools im Sicherheitsbereich nicht nur übertrieben dargestellt wird, sondern auch potenziell schädliche Auswirkungen haben kann. Stattdessen plädiert dieser Beitrag für einen fokussierten Ansatz, der auf bewährten Methoden und manuellen Analysen basiert, ergänzt durch vier spezifische Tools, die in unserer täglichen Arbeit unerlässlich sind.</p><br />
<p><strong>1. Ein kritischer Blick auf den Markt:</strong></p><br />
<p>Die aktuelle KI-Landschaft im IT-Sicherheitsbereich ist von Hype geprägt. Viele Anbieter präsentieren ihre Lösungen als Allheilmittel gegen Bedrohungen, die in der Lage sind, komplexe Angriffe in Echtzeit zu erkennen und abzuwehren. Die Realität sieht jedoch oft anders aus. Die meisten dieser Tools basieren auf maschinellem Lernen (ML), das zwar beeindruckende Ergebnisse bei bestimmten Aufgaben erzielen kann, aber durch seine inhärente Abhängigkeit von Trainingsdaten anfällig für Manipulationen ist.  Wie Tsecurity (https://tsecurity.de/de/2669304/IT+Sicherheit/Hacker/Why+you+should+ignore+99%25+of+AI+tools+-+the+danger+of+over-reliance) korrekt hervorhebt, ist die Qualität der Trainingsdaten entscheidend für die Leistungsfähigkeit eines ML-Modells.  Schlechte oder verzerrte Daten führen zu fehlerhaften Ergebnissen und potenziell gefährlichen Fehlinterpretationen.</p><br />
<p>Darüber hinaus fehlt es vielen KI-basierten Tools an Transparenz in Bezug auf ihre Algorithmen. Diese &quot;Black Box&quot;-Natur erschwert die Validierung ihrer Ergebnisse und die Identifizierung von Schwachstellen. Die mangelnde Verlässlichkeit und das Fehlen einer robusten Fehlerbehandlung machen diese Lösungen oft zu einem Risiko, insbesondere in kritischen Sicherheitsbereichen.  Die Tendenz, menschliches Urteilsvermögen durch automatisierte Prozesse zu ersetzen, ist ein gefährlicher Fehler.</p><br />
<p><strong>2. Der Wert manueller Analysen und bewährter Methoden:</strong></p><br />
<p>Unabhängig von den Fortschritten im Bereich KI bleibt die manuelle Analyse und das Verständnis der zugrunde liegenden Sicherheitskonzepte unerlässlich.  Echte Bedrohungsanalysen erfordern tiefes Fachwissen, Erfahrung und die Fähigkeit, über den Tellerrand hinauszuschauen. KI-Tools können zwar bei der Datenerfassung und -aggregation helfen, aber sie sind nicht in der Lage, das menschliche Urteilsvermögen zu ersetzen, das für die Identifizierung neuer Angriffsmuster und die Entwicklung effektiver Gegenmaßnahmen erforderlich ist. Die Konzentration auf bewährte Methoden wie Penetrationstests, Schwachstellenanalysen und regelmäßige Sicherheitsaudits bleibt von entscheidender Bedeutung.</p><br />
<p><strong>3. Vier KI-Tools, die wir täglich nutzen:</strong></p><br />
<p>Trotz der Kritik an vielen generischen KI-Tools haben wir in unserem Team vier spezifische Tools identifiziert, die einen signifikanten Mehrwert bieten:</p><br />
<ul><br />
<li><strong>Darktrace Antigena:</strong>  Dieses Tool nutzt eine Verhaltensanalyse (UEBA - User and Entity Behavioral Analytics), um ungewöhnliche Aktivitäten zu erkennen, ohne auf vordefinierte Signaturen angewiesen zu sein. Es ist ein wertvolles Instrument zur Erkennung von Zero-Day-Angriffen und Insider-Bedrohungen.  (Quelle: Darktrace Website)</li><br />
<li><strong>Microsoft Sentinel:</strong> Ein cloudbasiertes SIEM (Security Information and Event Management), das KI-gestützte Funktionen bietet, um Sicherheitsereignisse zu korrelieren, Bedrohungen zu priorisieren und automatisierte Reaktionsmaßnahmen auszuführen. Die Integration mit Microsoft 365 ermöglicht eine umfassende Überwachung der gesamten IT-Infrastruktur. (Quelle: Microsoft Sentinel Website)</li><br />
<li><strong>Prisma Cloud:</strong> Eine Plattform für Application Security Posture Management (ASPM), die KI nutzt, um Schwachstellen in Anwendungen zu identifizieren und zu priorisieren.  (Quelle: Prisma Cloud Website)</li><br />
<li><strong>SysDig Secure:</strong> Ein Container-Sicherheits-Tool, das KI zur Erkennung von Anomalien im Container-Verkehr verwendet, um Angriffe auf Container-Umgebungen zu verhindern. (Quelle: SysDig Website)</li><br />
</ul><br />
<p>Diese vier Tools ergänzen unsere bestehenden Sicherheitsstrategien und bieten uns zusätzliche Möglichkeiten zur Verbesserung unserer Reaktionsfähigkeit und Effizienz.  Es ist wichtig zu betonen, dass diese Tools nicht als Ersatz für menschliches Fachwissen dienen, sondern als Werkzeuge, die unsere Arbeit unterstützen.</p><br />
<p><strong>4. Fazit:</strong></p><br />
<p>Die KI-Revolution im IT-Sicherheitsbereich steht erst am Anfang. Während einige KI-Tools das Potenzial haben, den Sicherheitsbereich zu verbessern, ist es wichtig, sie kritisch zu betrachten und sich nicht von Hype blenden zu lassen.  Ein fokussierter Ansatz, der auf bewährten Methoden, manueller Analysen und einer sorgfältigen Auswahl von spezialisierten Tools basiert, ist entscheidend für eine effektive IT-Sicherheit. Die Illusion der Automatisierung darf uns nicht davon abhalten, die Bedeutung menschlicher Expertise und kritischen Denkens zu erkennen.</p><br />
<hr /><br />
<p><strong>Disclaimer:</strong> Dieser Artikel dient nur zu Informationszwecken und stellt keine Rechtsberatung dar. Die genannten Tools dienen als Beispiele und sollten auf die spezifischen Bedürfnisse und Anforderungen Ihrer Organisation zugeschnitten werden.</p><br />
<!-- END: Dynamically Added Content -->]]></content:encoded>
</item>
<item>
<title><![CDATA[Viele Unternehmen nicht auf KI-gestützte Cyberangriffe vorbereitet - Silicon.de]]></title>
<description><![CDATA[Laut dem Bericht “State of AI Cybersecurity 2025” von Darktrace befürchten 93 Prozent der deutschen Unternehmen, dass KI-gestützte Cyberangriffe in ...]]></description>
<link>https://tsecurity.de/de/2663112/it-security-nachrichten/viele-unternehmen-nicht-auf-ki-gestuetzte-cyberangriffe-vorbereitet-siliconde/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2663112/it-security-nachrichten/viele-unternehmen-nicht-auf-ki-gestuetzte-cyberangriffe-vorbereitet-siliconde/</guid>
<pubDate>Wed, 12 Mar 2025 18:03:17 +0100</pubDate>
<content:encoded><![CDATA[Laut dem Bericht “State of AI Cybersecurity 2025” von Darktrace befürchten 93 Prozent der deutschen Unternehmen, dass KI-gestützte Cyberangriffe in ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Ransomware: Unternehmen unter Zugzwang - Onlineportal von IT Management - It-daily.net]]></title>
<description><![CDATA[Die Münchner Sicherheitskonferenz 2025 hebt Cybersicherheit als geopolitische Herausforderung hervor – und der neue Darktrace Threat Report 2024 ...]]></description>
<link>https://tsecurity.de/de/2644583/it-security-nachrichten/ransomware-unternehmen-unter-zugzwang-onlineportal-von-it-management-it-dailynet/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2644583/it-security-nachrichten/ransomware-unternehmen-unter-zugzwang-onlineportal-von-it-management-it-dailynet/</guid>
<pubDate>Mon, 03 Mar 2025 10:19:12 +0100</pubDate>
<content:encoded><![CDATA[Die Münchner Sicherheitskonferenz 2025 hebt Cybersicherheit als geopolitische Herausforderung hervor – und der neue Darktrace Threat Report 2024 ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Ransomware: Unternehmen unter Zugzwang]]></title>
<description><![CDATA[Die Münchner Sicherheitskonferenz 2025 hebt Cybersicherheit als geopolitische Herausforderung hervor – und der neue Darktrace Threat Report 2024 zeigt, warum dieses Thema weltweit an Bedeutung gewinnt. Die durchschnittliche Zahlung pro Ransomware-Angriff stieg 2024 auf 2,73 Millionen US-Dollar – ...]]></description>
<link>https://tsecurity.de/de/2644360/it-security-nachrichten/ransomware-unternehmen-unter-zugzwang/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2644360/it-security-nachrichten/ransomware-unternehmen-unter-zugzwang/</guid>
<pubDate>Mon, 03 Mar 2025 07:34:16 +0100</pubDate>
<content:encoded><![CDATA[<p><img width="1000" height="563" src="https://www.it-daily.net/wp-content/uploads/2022/10/Ransomware_shutterstock_674295670.jpg" class="attachment-full size-full wp-post-image" alt="Ransomware" decoding="async" srcset="https://www.it-daily.net/wp-content/uploads/2022/10/Ransomware_shutterstock_674295670.jpg 1000w, https://www.it-daily.net/wp-content/uploads/2022/10/Ransomware_shutterstock_674295670-300x169.jpg 300w, https://www.it-daily.net/wp-content/uploads/2022/10/Ransomware_shutterstock_674295670-768x432.jpg 768w" sizes="(max-width: 1000px) 100vw, 1000px" title="Ransomware: Unternehmen unter Zugzwang 1"></p>
    Die Münchner Sicherheitskonferenz 2025 hebt Cybersicherheit als geopolitische Herausforderung hervor – und der neue Darktrace Threat Report 2024 zeigt, warum dieses Thema weltweit an Bedeutung gewinnt. Die durchschnittliche Zahlung pro Ransomware-Angriff stieg 2024 auf 2,73 Millionen US-Dollar – ein Anstieg um eine Million US-Dollar gegenüber 2023.

<p>Tags: <a href="https://www.it-daily.net/thema/cyber-security">#Cyber Security</a> | <a href="https://www.it-daily.net/thema/ransomware">#Ransomware</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Darktrace Threat Report 2024: Malware-as-a-Service eine zunehmende Bedrohung]]></title>
<description><![CDATA[Die Daten stammten aus den Beobachtungen des „Darktrace Threat Research“-Teams, welches mit Hilfe selbstlernender KI von Darktrace die IT-Sicherheit ...]]></description>
<link>https://tsecurity.de/de/2643047/it-security-nachrichten/darktrace-threat-report-2024-malware-as-a-service-eine-zunehmende-bedrohung/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2643047/it-security-nachrichten/darktrace-threat-report-2024-malware-as-a-service-eine-zunehmende-bedrohung/</guid>
<pubDate>Sun, 02 Mar 2025 01:03:39 +0100</pubDate>
<content:encoded><![CDATA[Die Daten stammten aus den Beobachtungen des „Darktrace Threat Research“-Teams, welches mit Hilfe selbstlernender KI von Darktrace die <b>IT</b>-<b>Sicherheit</b> ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Warum Malware-as-a-Service immer gefährlicher wird - It-daily.net]]></title>
<description><![CDATA[Der jährliche Threat Report von Darktrace zeigt, wie sich Cyberangriffe weiterentwickeln: Malware-as-a-Service (MaaS) und raffinierte Techniken ...]]></description>
<link>https://tsecurity.de/de/2628821/it-security-nachrichten/warum-malware-as-a-service-immer-gefaehrlicher-wird-it-dailynet/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2628821/it-security-nachrichten/warum-malware-as-a-service-immer-gefaehrlicher-wird-it-dailynet/</guid>
<pubDate>Sat, 22 Feb 2025 17:06:45 +0100</pubDate>
<content:encoded><![CDATA[Der jährliche Threat Report von Darktrace zeigt, wie sich Cyberangriffe weiterentwickeln: Malware-as-a-Service (MaaS) und raffinierte Techniken ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Warum Malware-as-a-Service immer gefährlicher wird]]></title>
<description><![CDATA[Der jährliche Threat Report von Darktrace zeigt, wie sich Cyberangriffe weiterentwickeln: Malware-as-a-Service (MaaS) und raffinierte Techniken wie Remote-Access-Trojaner (RAT) stellen Unternehmen vor wachsende Herausforderungen.

Tags: #MaaS | #Malware | #Malware-as-a-Service | #Studie]]></description>
<link>https://tsecurity.de/de/2627911/it-security-nachrichten/warum-malware-as-a-service-immer-gefaehrlicher-wird/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2627911/it-security-nachrichten/warum-malware-as-a-service-immer-gefaehrlicher-wird/</guid>
<pubDate>Sat, 22 Feb 2025 05:17:42 +0100</pubDate>
<content:encoded><![CDATA[<p><img width="1920" height="1080" src="https://www.it-daily.net/wp-content/uploads/2025/03/Malware_MaaS_Shutterstock_2332050013_1920.jpg" class="attachment-full size-full wp-post-image" alt="Malware, MaaS, Malware-as-a-Service, Cyberangriff" decoding="async" srcset="https://www.it-daily.net/wp-content/uploads/2025/03/Malware_MaaS_Shutterstock_2332050013_1920.jpg 1920w, https://www.it-daily.net/wp-content/uploads/2025/03/Malware_MaaS_Shutterstock_2332050013_1920-300x169.jpg 300w, https://www.it-daily.net/wp-content/uploads/2025/03/Malware_MaaS_Shutterstock_2332050013_1920-1024x576.jpg 1024w, https://www.it-daily.net/wp-content/uploads/2025/03/Malware_MaaS_Shutterstock_2332050013_1920-768x432.jpg 768w, https://www.it-daily.net/wp-content/uploads/2025/03/Malware_MaaS_Shutterstock_2332050013_1920-1536x864.jpg 1536w" sizes="(max-width: 1920px) 100vw, 1920px" title="Warum Malware-as-a-Service immer gefährlicher wird 1"></p>
    Der jährliche Threat Report von Darktrace zeigt, wie sich Cyberangriffe weiterentwickeln: Malware-as-a-Service (MaaS) und raffinierte Techniken wie Remote-Access-Trojaner (RAT) stellen Unternehmen vor wachsende Herausforderungen.

<p>Tags: <a href="https://www.it-daily.net/thema/maas">#MaaS</a> | <a href="https://www.it-daily.net/thema/malware">#Malware</a> | <a href="https://www.it-daily.net/thema/malware-as-a-service">#Malware-as-a-Service</a> | <a href="https://www.it-daily.net/thema/studie">#Studie</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Darktrace Threat Report 2024: Ransomware boomt weiter - Security-Insider]]></title>
<description><![CDATA[Die Münchner Sicherheitskonferenz 2025 hat Cybersicherheit als geopolitische Herausforderung in den Fokus gerückt. Der neue Darktrace Threat ...]]></description>
<link>https://tsecurity.de/de/2623851/it-security-nachrichten/darktrace-threat-report-2024-ransomware-boomt-weiter-security-insider/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2623851/it-security-nachrichten/darktrace-threat-report-2024-ransomware-boomt-weiter-security-insider/</guid>
<pubDate>Thu, 20 Feb 2025 09:18:28 +0100</pubDate>
<content:encoded><![CDATA[Die Münchner Sicherheitskonferenz 2025 hat Cybersicherheit als geopolitische Herausforderung in den Fokus gerückt. Der neue Darktrace Threat ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Erpresser nutzen Ransomware gezielter]]></title>
<description><![CDATA[Die Münchner Sicherheitskonferenz 2025 hat Cybersicherheit als geopoli­tische Herausforderung in den Fokus gerückt. Der neue Darktrace Threat Report zeigt, warum: Die durchschnittliche Zahlung pro Ransomware-Angriff stieg im vergangenen Jahr auf 2,73 Millionen US-Dollar – eine Zunahme um eine Mil...]]></description>
<link>https://tsecurity.de/de/2623781/it-security-nachrichten/erpresser-nutzen-ransomware-gezielter/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2623781/it-security-nachrichten/erpresser-nutzen-ransomware-gezielter/</guid>
<pubDate>Thu, 20 Feb 2025 08:33:37 +0100</pubDate>
<content:encoded><![CDATA[Die Münchner Sicherheitskonferenz 2025 hat Cybersicherheit als geopoli­tische Herausforderung in den Fokus gerückt. Der neue Darktrace Threat Report zeigt, warum: Die durchschnittliche Zahlung pro Ransomware-Angriff stieg im vergangenen Jahr auf 2,73 Millionen US-Dollar – eine Zunahme um eine Million US-Dollar im Vergleich zu 2023.]]></content:encoded>
</item>
<item>
<title><![CDATA[Darktrace Report Highlights the Growing Power of MaaS, Sneaky Evasion Tactics]]></title>
<description><![CDATA[Cybercrime-as-a-Service (CaaS) is more than just a trend—it’s here to stay. As sophisticated attack tools become widely (and easily) available, even less experienced cybercriminals can now carry out highly disruptive campaigns.   In fact, Malware-as-a-Service (MaaS) now makes up 57% of detected t...]]></description>
<link>https://tsecurity.de/de/2623586/it-security-nachrichten/darktrace-report-highlights-the-growing-power-of-maas-sneaky-evasion-tactics/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2623586/it-security-nachrichten/darktrace-report-highlights-the-growing-power-of-maas-sneaky-evasion-tactics/</guid>
<pubDate>Thu, 20 Feb 2025 06:18:40 +0100</pubDate>
<content:encoded><![CDATA[Cybercrime-as-a-Service (CaaS) is more than just a trend—it’s here to stay. As sophisticated attack tools become widely (and easily) available, even less experienced cybercriminals can now carry out highly disruptive campaigns.   In fact, Malware-as-a-Service (MaaS) now makes up 57% of detected threats—a 17% increase from the first half of last nyear. This surge makes it [...]]]></content:encoded>
</item>
<item>
<title><![CDATA[Darktrace: 96% of Phishing Attacks in 2024 Exploited Trusted Domains Including SharePoint & Zoom Docs]]></title>
<description><![CDATA[The cyber security firm reported in its latest annual report that their researchers found more than 30.4 million phishing emails last year.]]></description>
<link>https://tsecurity.de/de/2623164/it-security-nachrichten/darktrace-96-of-phishing-attacks-in-2024-exploited-trusted-domains-including-sharepoint-zoom-docs/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2623164/it-security-nachrichten/darktrace-96-of-phishing-attacks-in-2024-exploited-trusted-domains-including-sharepoint-zoom-docs/</guid>
<pubDate>Wed, 19 Feb 2025 20:19:01 +0100</pubDate>
<content:encoded><![CDATA[The cyber security firm reported in its latest annual report that their researchers found more than 30.4 million phishing emails last year.]]></content:encoded>
</item>
<item>
<title><![CDATA[Darktrace Threat Report: Kritische Infrastrukturen im Visier - Computer&AUTOMATION]]></title>
<description><![CDATA[Perimeter-Sicherheit als Schwachstelle. Auch Edge- und Perimeter-Geräte sind begehrte Ziele von Cyberangriffen. Darktrace analysierte, dass 40 Prozent ...]]></description>
<link>https://tsecurity.de/de/2622757/it-security-nachrichten/darktrace-threat-report-kritische-infrastrukturen-im-visier-computerautomation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2622757/it-security-nachrichten/darktrace-threat-report-kritische-infrastrukturen-im-visier-computerautomation/</guid>
<pubDate>Wed, 19 Feb 2025 17:19:11 +0100</pubDate>
<content:encoded><![CDATA[Perimeter-<b>Sicherheit</b> als Schwachstelle. Auch Edge- und Perimeter-Geräte sind begehrte Ziele von Cyberangriffen. Darktrace analysierte, dass 40 Prozent ...]]></content:encoded>
</item>
<item>
<title><![CDATA[AI’s Achilles heel: Securing the next revolution]]></title>
<description><![CDATA[Artificial intelligence (AI)-enabled systems are driving a new era of business transformation, revolutionizing industries through prescriptive analytics, personalized customer experiences and process automation. From manufacturing to healthcare and finance to defense, AI enhances efficiency, deci...]]></description>
<link>https://tsecurity.de/de/2611406/it-security-nachrichten/ais-achilles-heel-securing-the-next-revolution/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2611406/it-security-nachrichten/ais-achilles-heel-securing-the-next-revolution/</guid>
<pubDate>Thu, 13 Feb 2025 14:48:49 +0100</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Artificial intelligence (AI)-enabled systems are driving a new era of business transformation, revolutionizing industries through prescriptive analytics, personalized customer experiences and process automation. From manufacturing to healthcare and finance to defense, AI enhances efficiency, decision-making and operational agility, providing organizations a competitive edge in an increasingly data-driven world. Its processing of vast datasets enables supply chain precision, life-saving diagnostics and hyper-personalized consumer interactions, fostering scalability and innovation. </p>



<p>However, as AI adoption accelerates, organizations face rising threats from adversarial attacks, data poisoning, algorithmic bias and regulatory uncertainties. Without robust security and governance frameworks, unsecured AI systems can erode stakeholder trust, disrupt operations and expose businesses to compliance and reputational risks. </p>



<p>Senior executives are challenged with securing AI, aligning initiatives with governance frameworks and fortifying business resilience. Organizations can unlock AI’s full potential by proactively addressing security, ethics and operational challenges while ensuring transparency, reliability and long-term sustainability. </p>



<h2 class="wp-block-heading">The risks of unsecured AI </h2>



<p>Unlike traditional IT systems, AI is uniquely susceptible to novel attack vectors such as:  </p>



<ul class="wp-block-list">
<li><strong>Adversarial attacks.</strong> Subtle input data manipulations can cause AI systems to make incorrect decisions, jeopardizing their reliability.  </li>



<li><strong>Data poisoning.</strong> Compromised datasets used in training AI models can degrade system accuracy.  </li>



<li><strong>Generative AI risks.</strong> Issues like hallucinations and malicious prompt injections threaten enterprises reliant on AI-generated content.  </li>
</ul>



<h2 class="wp-block-heading">Ethics and governance in AI  </h2>



<p>AI also challenges organizations to address algorithmic bias, transparency and accountability issues. Regulatory frameworks like the EU AI Act and NIST AI Risk Management Framework are shaping expectations around responsible AI deployment.   </p>



<h2 class="wp-block-heading">Balancing security, ethics and strategic investments </h2>



<p>Securing AI systems requires a balanced approach that integrates technical rigor with strategic foresight: </p>



<ul class="wp-block-list">
<li><strong>Invest in AI-specific security.</strong> Tools like adversarial training and robust data validation can prevent common attack vectors.  </li>



<li><strong>Adopt ethical AI frameworks.</strong> Promoting fairness and inclusivity in AI systems builds trust and mitigates reputational risks.  </li>



<li><strong>Future-proof AI systems.</strong> Continuous monitoring, adaptive governance and upskilling talent ensure resilience against evolving challenges.  </li>
</ul>



<h2 class="wp-block-heading">Key AI security concepts </h2>



<p>Review critical AI security terms, their definitions, relevance and interrelationships around AI governance and resilience. Understanding these foundational concepts helps organizations build secure, ethical and scalable AI that aligns with business goals and regulatory requirements.  </p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2025/02/table-1-key-ai-security-concepts.png?w=1024" alt="Table 1 - Key AI security concepts" class="wp-image-3823232" srcset="https://b2b-contenthub.com/wp-content/uploads/2025/02/table-1-key-ai-security-concepts.png?quality=50&amp;strip=all 1710w, https://b2b-contenthub.com/wp-content/uploads/2025/02/table-1-key-ai-security-concepts.png?resize=300%2C172&amp;quality=50&amp;strip=all 300w, https://b2b-contenthub.com/wp-content/uploads/2025/02/table-1-key-ai-security-concepts.png?resize=768%2C440&amp;quality=50&amp;strip=all 768w, https://b2b-contenthub.com/wp-content/uploads/2025/02/table-1-key-ai-security-concepts.png?resize=1024%2C587&amp;quality=50&amp;strip=all 1024w, https://b2b-contenthub.com/wp-content/uploads/2025/02/table-1-key-ai-security-concepts.png?resize=1536%2C880&amp;quality=50&amp;strip=all 1536w, https://b2b-contenthub.com/wp-content/uploads/2025/02/table-1-key-ai-security-concepts.png?resize=1216%2C697&amp;quality=50&amp;strip=all 1216w, https://b2b-contenthub.com/wp-content/uploads/2025/02/table-1-key-ai-security-concepts.png?resize=293%2C168&amp;quality=50&amp;strip=all 293w, https://b2b-contenthub.com/wp-content/uploads/2025/02/table-1-key-ai-security-concepts.png?resize=147%2C84&amp;quality=50&amp;strip=all 147w, https://b2b-contenthub.com/wp-content/uploads/2025/02/table-1-key-ai-security-concepts.png?resize=838%2C480&amp;quality=50&amp;strip=all 838w, https://b2b-contenthub.com/wp-content/uploads/2025/02/table-1-key-ai-security-concepts.png?resize=628%2C360&amp;quality=50&amp;strip=all 628w, https://b2b-contenthub.com/wp-content/uploads/2025/02/table-1-key-ai-security-concepts.png?resize=436%2C250&amp;quality=50&amp;strip=all 436w" width="1024" height="587" sizes="(max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Vipin Jain</p></div>



<p>The following provides a quick overview of interrelationships among these terms and an overall ecosystem impact: </p>



<ul class="wp-block-list">
<li><strong>Dependencies.</strong> Adversarial attacks, data poisoning and generative AI risks exploit data governance and security gaps.    </li>



<li><strong>Complementary solutions.</strong> Explainable AI and federated learning address transparency and privacy concerns.  </li>



<li><strong>Audits.</strong> Bias audits and adversarial training improve reliability.  </li>



<li><strong>Holistic approach.</strong> Establishes the foundation for secure, ethical and scalable AI systems, enabling organizations to mitigate risks.  </li>
</ul>



<p>Addressing these key areas can help organizations create resilient AI frameworks that balance security, ethics and efficiency.  </p>



<h2 class="wp-block-heading">Drivers, challenges and strategic importance   </h2>



<p>AI has become a fundamental driver of business transformation, allowing organizations to enhance efficiency, refine decision-making and create personalized customer experiences. However, AI adoption also presents complex challenges, including security vulnerabilities, ethical concerns and regulatory compliance. Understanding these drivers, challenges and the strategic importance of AI security is essential for organizations aiming to maximize AI’s potential while mitigating risks. </p>



<h3 class="wp-block-heading">Drivers   </h3>



<p>Organizations across industries are using AI to drive business innovation and operational efficiency. Several key factors contribute to the widespread adoption of AI: </p>



<ul class="wp-block-list">
<li><strong>Business transformation.</strong> AI improves workflows, enhances decision-making and delivers hyper-personalized customer experience.  
<ul class="wp-block-list">
<li><strong>Healthcare.</strong> AI-driven diagnostics improve accuracy and early disease detection.  </li>



<li><strong>Finance.</strong> AI-powered fraud detection prevents financial losses in real-time.  </li>



<li><strong>Retail.</strong> Recommendation engines personalize shopping experiences, boosting sales.  </li>
</ul>
</li>



<li><strong>Regulatory compliance.</strong> Governments are mandating stricter AI governance to ensure transparency and fairness.  
<ul class="wp-block-list">
<li><strong>EU AI Act.</strong> Requires explainability and imposes penalties for non-compliance.  </li>



<li><strong>US NIST AI Framework.</strong> Defines security best practices for AI deployment.  </li>
</ul>
</li>



<li><strong>Stakeholder trust.</strong> Ethical AI adoption fosters customer, employee and partner trust.  
<ul class="wp-block-list">
<li><strong>Transparent AI models</strong> reassure stakeholders about fairness in decision-making.  </li>



<li><strong>Inclusive AI</strong> reduces bias, promoting fair access to services.  </li>
</ul>
</li>
</ul>



<p>Challenges   </p>



<p>Despite its benefits, AI adoption introduces a range of challenges that require initiative-taking risk management:  </p>



<ul class="wp-block-list">
<li><strong>Cybersecurity threats.</strong> AI systems are uniquely vulnerable to advanced cyberattacks. 
<ul class="wp-block-list">
<li><strong>Adversarial attacks.</strong> Attackers manipulate AI inputs to produce incorrect outputs. </li>



<li><strong>Model theft.</strong> AI intellectual property can be stolen and exploited. </li>
</ul>
</li>



<li><strong>Data governance gaps.</strong> Poor data management can lead to compromised AI integrity.  
<ul class="wp-block-list">
<li><strong>Data poisoning.</strong> Corrupt training data leads to inaccurate AI predictions.  </li>



<li><strong>Lack of data lineage.</strong> Inconsistent data tracking hinders compliance. </li>
</ul>
</li>



<li><strong>Algorithmic bias.</strong> Biased training datasets can perpetuate systemic discrimination. </li>



<li><strong>Operational inefficiencies.</strong> AI models still require ongoing maintenance to be effective. 
<ul class="wp-block-list">
<li><strong>Model drift.</strong> AI models lose accuracy over time due to changing data patterns. </li>



<li><strong>Generative AI hallucinations.</strong> AI-generated outputs can become unreliable.  </li>
</ul>
</li>



<li><strong>Shadow AI.</strong> Unauthorized AI deployments outside IT governance create security and compliance risks.  </li>
</ul>



<h2 class="wp-block-heading">Strategic importance </h2>



<p>To maximize AI’s potential while mitigating risks, organizations must integrate AI security and governance into their long-term strategies:  </p>



<ul class="wp-block-list">
<li><strong>Protecting operational integrity.</strong> Proactively addressing AI vulnerabilities ensures uninterrupted business operations and safeguards performance.  </li>



<li><strong>Ensuring ethical practices.</strong> Adopting fairness, accountability and transparency in AI systems builds stakeholder confidence and regulatory alignment.  </li>



<li><strong>Fostering innovation.</strong> Effectively managing AI risks allows organizations to use AI as a competitive advantage while driving sustainable growth.  </li>
</ul>



<p>By addressing these drivers and challenges, organizations can strategically position themselves to unlock AI’s full potential, ensure long-term resilience and foster a secure and ethical AI ecosystem.  </p>



<h2 class="wp-block-heading">Fortifying AI frontiers across the lifecycle </h2>



<p>Securing AI requires a lifecycle approach that addresses risks from data collection to deployment and ongoing monitoring. Without robust security, governance and risk mitigation, AI systems can be exploited through adversarial attacks, data manipulation and ethical breaches. To ensure secure, transparent and compliant AI, organizations should adopt three foundational strategies: </p>



<ul class="wp-block-list">
<li><strong>Governance.</strong> Implement AI-specific risk frameworks such as the NIST AI Risk Management Framework and enhance transparency with Explainable AI (XAI) for regulatory compliance.  </li>



<li><strong>Continuous monitoring.</strong> Deploy real-time threat detection and model drift monitoring to proactively manage vulnerabilities and prevent AI degradation.  </li>



<li><strong>Collaborative ecosystems.</strong> Align IT, compliance, cybersecurity and business teams to enforce AI governance and ensure security and ethical integrity.  </li>
</ul>



<p>By securing AI at every stage of its lifecycle, organizations can fortify AI innovation while mitigating security risks, supporting compliance and sustaining business trust. The following table provides a quick overview of artificial intelligence lifecycle stages:  </p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2025/02/table-2-ai-lifecycle-stages.png?w=1024" alt="Table 2 - AI lifecycle stages" class="wp-image-3823234" srcset="https://b2b-contenthub.com/wp-content/uploads/2025/02/table-2-ai-lifecycle-stages.png?quality=50&amp;strip=all 1427w, https://b2b-contenthub.com/wp-content/uploads/2025/02/table-2-ai-lifecycle-stages.png?resize=300%2C180&amp;quality=50&amp;strip=all 300w, https://b2b-contenthub.com/wp-content/uploads/2025/02/table-2-ai-lifecycle-stages.png?resize=768%2C460&amp;quality=50&amp;strip=all 768w, https://b2b-contenthub.com/wp-content/uploads/2025/02/table-2-ai-lifecycle-stages.png?resize=1024%2C614&amp;quality=50&amp;strip=all 1024w, https://b2b-contenthub.com/wp-content/uploads/2025/02/table-2-ai-lifecycle-stages.png?resize=1163%2C697&amp;quality=50&amp;strip=all 1163w, https://b2b-contenthub.com/wp-content/uploads/2025/02/table-2-ai-lifecycle-stages.png?resize=280%2C168&amp;quality=50&amp;strip=all 280w, https://b2b-contenthub.com/wp-content/uploads/2025/02/table-2-ai-lifecycle-stages.png?resize=140%2C84&amp;quality=50&amp;strip=all 140w, https://b2b-contenthub.com/wp-content/uploads/2025/02/table-2-ai-lifecycle-stages.png?resize=801%2C480&amp;quality=50&amp;strip=all 801w, https://b2b-contenthub.com/wp-content/uploads/2025/02/table-2-ai-lifecycle-stages.png?resize=601%2C360&amp;quality=50&amp;strip=all 601w, https://b2b-contenthub.com/wp-content/uploads/2025/02/table-2-ai-lifecycle-stages.png?resize=417%2C250&amp;quality=50&amp;strip=all 417w" width="1024" height="614" sizes="(max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Vipin Jain</p></div>



<h2 class="wp-block-heading">4 critical AI security strategies </h2>



<h3 class="wp-block-heading">1. Adversarial training: Strengthening AI against manipulations  </h3>



<p>Adversarial training fortifies AI models by exposing them to simulated attacks, making them more resilient against data manipulation, cyber threats and fraud. A global logistics firm implemented adversarial training in its route optimization AI, reducing disruptions from data tampering by 25%. This method enhances AI’s ability to detect malicious inputs and prevent exploitation in fraud detection, image recognition and autonomous decision-making.  </p>



<h3 class="wp-block-heading">2. Explainable AI (XAI): Enhancing transparency and trust  </h3>



<p>XAI clarifies AI-driven decision-making, helping businesses build trust, reduce bias and meet regulatory requirements. A healthcare provider leveraged XAI tools to make its AI-driven diagnostic recommendations more transparent, improving physician confidence by 30%. In regulated industries like finance, healthcare and insurance, XAI supports auditability, compliance and ethical AI. </p>



<h3 class="wp-block-heading">3. Secure data pipelines: Protecting AI from data tampering  </h3>



<p>Ensuring data integrity is critical for AI reliability. Secure data pipelines safeguard AI models from data poisoning, unauthorized access and compliance violations through encryption, access controls and anomaly detection. Businesses can maintain accuracy and regulatory compliance by ensuring that only confirmed, unbiased and tamper-proof data is fed into AI models. </p>



<h3 class="wp-block-heading">4. Real-time monitoring: Detecting and mitigating AI risks  </h3>



<p>AI systems require continuous oversight to detect anomalies, performance drift and emerging cyber threats. A financial institution implemented real-time AI monitoring for its credit scoring system, reducing fraud-related losses by 20% and ensuring ongoing model accuracy. Continuous monitoring solutions help find vulnerabilities 85% faster, ensuring that AI stays stable, secure and aligned with business aims.  </p>



<h2 class="wp-block-heading">The path forward </h2>



<p> Organizations must integrate adversarial defense, explainability, secure data management and real-time risk monitoring into their AI strategies to fortify AI security. These measures safeguard AI integrity, enhance compliance and build stakeholder trust. Proactively addressing AI risks through strategic governance and security frameworks allows businesses to drive innovation while ensuring ethical responsibility and long-term sustainability. By adopting these strategies, organizations can strengthen AI security, support transparency and uphold compliance while refining efficiency and reinforcing stakeholder confidence. </p>



<h2 class="wp-block-heading">The competitive AI landscape </h2>



<p>The rapid adoption of AI has created a thriving ecosystem of vendors offering innovative solutions for securing AI systems, managing governance and ensuring ethical compliance. Understanding these players’ strengths and limitations is essential for informed decision-making in technology investments. </p>



<h3 class="wp-block-heading">Microsoft Azure AI </h3>



<p>Microsoft Azure AI provides a robust AI ecosystem that integrates Microsoft’s cloud and enterprise solutions. Prebuilt security frameworks like Azure AI Defender and Azure Sentinel are ideal for regulated industries such as finance and healthcare. While scalable and compliant, its prohibitive cost and complexity can hinder smaller organizations. Gartner ranks Azure AI among the top three enterprise AI security solutions.  </p>



<h3 class="wp-block-heading">Google Cloud AI  </h3>



<p>Google Cloud AI specializes in AI governance, security and explainability (XAI), making it an excellent choice for enterprises requiring transparent and compliant AI. Its XAI tools support regulatory adherence in healthcare and finance, though limited customization and premium pricing may be drawbacks.   </p>



<h3 class="wp-block-heading">AWS AI  </h3>



<p>Amazon Web Services (AWS) AI offers comprehensive AI security and scalability, with AWS Sage Maker widely used for secure model training and deployment. Its global infrastructure supports large-scale enterprises, but excessive costs and third-party integration challenges may hinder smaller firms.   </p>



<h3 class="wp-block-heading">Darktrace  </h3>



<p>Darktrace is a leader in AI-powered cybersecurity, offering real-time anomaly detection and autonomous threat mitigation. Its self-learning AI models adapt to evolving threats, making it essential for enterprises requiring continuous security monitoring. However, inflated costs and complex deployment may limit adoption for smaller businesses.   </p>



<p>These vendors shape AI security’s future, offering specialized solutions in threat detection, explainability and data integrity. As AI adoption accelerates, their technologies will be key to ensuring secure, compliant and ethical AI deployment.  </p>



<h2 class="wp-block-heading">Market trends and strategic implications  </h2>



<p>The AI security market is experiencing rapid growth and is projected to expand at a 28% CAGR, reaching $50 billion by 2030. North America currently leads with a 45% market share, followed by Europe and the Asia-Pacific region, reflecting a global emphasis on AI security. This growth is driven by increasing regulatory compliance mandates, the evolving sophistication of AI-related threats and a rising focus on ethical AI practices. Organizations across industries recognize the need to implement robust security frameworks that address adversarial attacks, data governance challenges and algorithmic bias to ensure AI systems stay secure and trustworthy.  </p>



<h2 class="wp-block-heading">Future focus  </h2>



<p>AI security is evolving rapidly, with innovative technologies and frameworks shaping the future landscape. Organizations must expect emerging trends to still be competitive and resilient.  </p>



<ul class="wp-block-list">
<li><strong>AI-driven threat intelligence</strong> transforms cybersecurity by enabling real-time detection and mitigation of sophisticated threats. AI-powered systems analyze vast data streams to find anomalies, predict cyberattacks and neutralize risks before they escalate. Darktrace employs AI for anomaly detection, reducing breach risks by 40% and reinforcing AI’s role in initiative-taking security management. </li>



<li><strong>Regulatory frameworks</strong> for AI governance are becoming increasingly stringent. The EU AI Act mandates transparency and accountability, with substantial penalties for non-compliance. Organizations that invest early in compliance frameworks gain a competitive advantage, regulatory readiness and stronger stakeholder trust, ensuring AI deployments stay ethical, secure and aligned with legal requirements.  </li>
</ul>



<h2 class="wp-block-heading">Conclusion  </h2>



<p>AI systems are driving unparalleled innovation and operational efficiency across industries. However, securing these systems against technical, ethical and regulatory challenges requires a holistic, forward-looking approach. Organizations can adopt the right strategies to ensure their AI frontiers, foster stakeholder trust and sustain growth in an increasingly AI-powered world.  </p>



<p><em>Vipin Jain, founder and chief architect of </em><a href="https://txe.ai/" target="_blank" rel="nofollow"><em>Transformation Enablers Inc.</em></a><em>, brings over 30 years of experience crafting execution-ready IT strategies and transformation roadmaps aligned with business goals while leveraging emerging technologies like AI. He has held executive roles at AIG, Merrill Lynch and Citicorp, where he led business and IT portfolio transformations. Vipin also led consulting practices at Accenture, Microsoft and HPE, advising Fortune 100 firms and U.S. federal agencies. He is currently a senior advisor at </em><a href="https://wve.digital/" target="_blank" rel="nofollow"><em>WVE</em></a><em>.</em> </p>



<p><em>This article was made possible by our partnership with the IASA </em><a href="https://chiefarchitectforum.org/" target="_blank" rel="nofollow"><em>Chief Architect Forum</em></a><em>. The CAF’s purpose is to test, challenge and support the art and science of Business Technology Architecture and its evolution over time as well as grow the influence and leadership of chief architects both inside and outside the profession. The CAF is a leadership community of the </em><a href="https://iasaglobal.org/" target="_blank" rel="nofollow"><em>IASA</em></a><em>, the leading non-profit professional association for business technology architects.</em> </p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI’s Achilles heel: Securing the next revolution]]></title>
<description><![CDATA[Artificial intelligence (AI)-enabled systems are driving a new era of business transformation, revolutionizing industries through prescriptive analytics, personalized customer experiences and process automation. From manufacturing to healthcare and finance to defense, AI enhances efficiency, deci...]]></description>
<link>https://tsecurity.de/de/2611405/it-security-nachrichten/ais-achilles-heel-securing-the-next-revolution/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2611405/it-security-nachrichten/ais-achilles-heel-securing-the-next-revolution/</guid>
<pubDate>Thu, 13 Feb 2025 14:48:48 +0100</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Artificial intelligence (AI)-enabled systems are driving a new era of business transformation, revolutionizing industries through prescriptive analytics, personalized customer experiences and process automation. From manufacturing to healthcare and finance to defense, AI enhances efficiency, decision-making and operational agility, providing organizations a competitive edge in an increasingly data-driven world. Its processing of vast datasets enables supply chain precision, life-saving diagnostics and hyper-personalized consumer interactions, fostering scalability and innovation. </p>



<p>However, as AI adoption accelerates, organizations face rising threats from adversarial attacks, data poisoning, algorithmic bias and regulatory uncertainties. Without robust security and governance frameworks, unsecured AI systems can erode stakeholder trust, disrupt operations and expose businesses to compliance and reputational risks. </p>



<p>Senior executives are challenged with securing AI, aligning initiatives with governance frameworks and fortifying business resilience. Organizations can unlock AI’s full potential by proactively addressing security, ethics and operational challenges while ensuring transparency, reliability and long-term sustainability. </p>



<h2 class="wp-block-heading">The risks of unsecured AI </h2>



<p>Unlike traditional IT systems, AI is uniquely susceptible to novel attack vectors such as:  </p>



<ul class="wp-block-list">
<li><strong>Adversarial attacks.</strong> Subtle input data manipulations can cause AI systems to make incorrect decisions, jeopardizing their reliability.  </li>



<li><strong>Data poisoning.</strong> Compromised datasets used in training AI models can degrade system accuracy.  </li>



<li><strong>Generative AI risks.</strong> Issues like hallucinations and malicious prompt injections threaten enterprises reliant on AI-generated content.  </li>
</ul>



<h2 class="wp-block-heading">Ethics and governance in AI  </h2>



<p>AI also challenges organizations to address algorithmic bias, transparency and accountability issues. Regulatory frameworks like the EU AI Act and NIST AI Risk Management Framework are shaping expectations around responsible AI deployment.   </p>



<h2 class="wp-block-heading">Balancing security, ethics and strategic investments </h2>



<p>Securing AI systems requires a balanced approach that integrates technical rigor with strategic foresight: </p>



<ul class="wp-block-list">
<li><strong>Invest in AI-specific security.</strong> Tools like adversarial training and robust data validation can prevent common attack vectors.  </li>



<li><strong>Adopt ethical AI frameworks.</strong> Promoting fairness and inclusivity in AI systems builds trust and mitigates reputational risks.  </li>



<li><strong>Future-proof AI systems.</strong> Continuous monitoring, adaptive governance and upskilling talent ensure resilience against evolving challenges.  </li>
</ul>



<h2 class="wp-block-heading">Key AI security concepts </h2>



<p>Review critical AI security terms, their definitions, relevance and interrelationships around AI governance and resilience. Understanding these foundational concepts helps organizations build secure, ethical and scalable AI that aligns with business goals and regulatory requirements.  </p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2025/02/table-1-key-ai-security-concepts.png?w=1024" alt="Table 1 - Key AI security concepts" class="wp-image-3823232" srcset="https://b2b-contenthub.com/wp-content/uploads/2025/02/table-1-key-ai-security-concepts.png?quality=50&amp;strip=all 1710w, https://b2b-contenthub.com/wp-content/uploads/2025/02/table-1-key-ai-security-concepts.png?resize=300%2C172&amp;quality=50&amp;strip=all 300w, https://b2b-contenthub.com/wp-content/uploads/2025/02/table-1-key-ai-security-concepts.png?resize=768%2C440&amp;quality=50&amp;strip=all 768w, https://b2b-contenthub.com/wp-content/uploads/2025/02/table-1-key-ai-security-concepts.png?resize=1024%2C587&amp;quality=50&amp;strip=all 1024w, https://b2b-contenthub.com/wp-content/uploads/2025/02/table-1-key-ai-security-concepts.png?resize=1536%2C880&amp;quality=50&amp;strip=all 1536w, https://b2b-contenthub.com/wp-content/uploads/2025/02/table-1-key-ai-security-concepts.png?resize=1216%2C697&amp;quality=50&amp;strip=all 1216w, https://b2b-contenthub.com/wp-content/uploads/2025/02/table-1-key-ai-security-concepts.png?resize=293%2C168&amp;quality=50&amp;strip=all 293w, https://b2b-contenthub.com/wp-content/uploads/2025/02/table-1-key-ai-security-concepts.png?resize=147%2C84&amp;quality=50&amp;strip=all 147w, https://b2b-contenthub.com/wp-content/uploads/2025/02/table-1-key-ai-security-concepts.png?resize=838%2C480&amp;quality=50&amp;strip=all 838w, https://b2b-contenthub.com/wp-content/uploads/2025/02/table-1-key-ai-security-concepts.png?resize=628%2C360&amp;quality=50&amp;strip=all 628w, https://b2b-contenthub.com/wp-content/uploads/2025/02/table-1-key-ai-security-concepts.png?resize=436%2C250&amp;quality=50&amp;strip=all 436w" width="1024" height="587" sizes="(max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Vipin Jain</p></div>



<p>The following provides a quick overview of interrelationships among these terms and an overall ecosystem impact: </p>



<ul class="wp-block-list">
<li><strong>Dependencies.</strong> Adversarial attacks, data poisoning and generative AI risks exploit data governance and security gaps.    </li>



<li><strong>Complementary solutions.</strong> Explainable AI and federated learning address transparency and privacy concerns.  </li>



<li><strong>Audits.</strong> Bias audits and adversarial training improve reliability.  </li>



<li><strong>Holistic approach.</strong> Establishes the foundation for secure, ethical and scalable AI systems, enabling organizations to mitigate risks.  </li>
</ul>



<p>Addressing these key areas can help organizations create resilient AI frameworks that balance security, ethics and efficiency.  </p>



<h2 class="wp-block-heading">Drivers, challenges and strategic importance   </h2>



<p>AI has become a fundamental driver of business transformation, allowing organizations to enhance efficiency, refine decision-making and create personalized customer experiences. However, AI adoption also presents complex challenges, including security vulnerabilities, ethical concerns and regulatory compliance. Understanding these drivers, challenges and the strategic importance of AI security is essential for organizations aiming to maximize AI’s potential while mitigating risks. </p>



<h3 class="wp-block-heading">Drivers   </h3>



<p>Organizations across industries are using AI to drive business innovation and operational efficiency. Several key factors contribute to the widespread adoption of AI: </p>



<ul class="wp-block-list">
<li><strong>Business transformation.</strong> AI improves workflows, enhances decision-making and delivers hyper-personalized customer experience.  
<ul class="wp-block-list">
<li><strong>Healthcare.</strong> AI-driven diagnostics improve accuracy and early disease detection.  </li>



<li><strong>Finance.</strong> AI-powered fraud detection prevents financial losses in real-time.  </li>



<li><strong>Retail.</strong> Recommendation engines personalize shopping experiences, boosting sales.  </li>
</ul>
</li>



<li><strong>Regulatory compliance.</strong> Governments are mandating stricter AI governance to ensure transparency and fairness.  
<ul class="wp-block-list">
<li><strong>EU AI Act.</strong> Requires explainability and imposes penalties for non-compliance.  </li>



<li><strong>US NIST AI Framework.</strong> Defines security best practices for AI deployment.  </li>
</ul>
</li>



<li><strong>Stakeholder trust.</strong> Ethical AI adoption fosters customer, employee and partner trust.  
<ul class="wp-block-list">
<li><strong>Transparent AI models</strong> reassure stakeholders about fairness in decision-making.  </li>



<li><strong>Inclusive AI</strong> reduces bias, promoting fair access to services.  </li>
</ul>
</li>
</ul>



<p>Challenges   </p>



<p>Despite its benefits, AI adoption introduces a range of challenges that require initiative-taking risk management:  </p>



<ul class="wp-block-list">
<li><strong>Cybersecurity threats.</strong> AI systems are uniquely vulnerable to advanced cyberattacks. 
<ul class="wp-block-list">
<li><strong>Adversarial attacks.</strong> Attackers manipulate AI inputs to produce incorrect outputs. </li>



<li><strong>Model theft.</strong> AI intellectual property can be stolen and exploited. </li>
</ul>
</li>



<li><strong>Data governance gaps.</strong> Poor data management can lead to compromised AI integrity.  
<ul class="wp-block-list">
<li><strong>Data poisoning.</strong> Corrupt training data leads to inaccurate AI predictions.  </li>



<li><strong>Lack of data lineage.</strong> Inconsistent data tracking hinders compliance. </li>
</ul>
</li>



<li><strong>Algorithmic bias.</strong> Biased training datasets can perpetuate systemic discrimination. </li>



<li><strong>Operational inefficiencies.</strong> AI models still require ongoing maintenance to be effective. 
<ul class="wp-block-list">
<li><strong>Model drift.</strong> AI models lose accuracy over time due to changing data patterns. </li>



<li><strong>Generative AI hallucinations.</strong> AI-generated outputs can become unreliable.  </li>
</ul>
</li>



<li><strong>Shadow AI.</strong> Unauthorized AI deployments outside IT governance create security and compliance risks.  </li>
</ul>



<h2 class="wp-block-heading">Strategic importance </h2>



<p>To maximize AI’s potential while mitigating risks, organizations must integrate AI security and governance into their long-term strategies:  </p>



<ul class="wp-block-list">
<li><strong>Protecting operational integrity.</strong> Proactively addressing AI vulnerabilities ensures uninterrupted business operations and safeguards performance.  </li>



<li><strong>Ensuring ethical practices.</strong> Adopting fairness, accountability and transparency in AI systems builds stakeholder confidence and regulatory alignment.  </li>



<li><strong>Fostering innovation.</strong> Effectively managing AI risks allows organizations to use AI as a competitive advantage while driving sustainable growth.  </li>
</ul>



<p>By addressing these drivers and challenges, organizations can strategically position themselves to unlock AI’s full potential, ensure long-term resilience and foster a secure and ethical AI ecosystem.  </p>



<h2 class="wp-block-heading">Fortifying AI frontiers across the lifecycle </h2>



<p>Securing AI requires a lifecycle approach that addresses risks from data collection to deployment and ongoing monitoring. Without robust security, governance and risk mitigation, AI systems can be exploited through adversarial attacks, data manipulation and ethical breaches. To ensure secure, transparent and compliant AI, organizations should adopt three foundational strategies: </p>



<ul class="wp-block-list">
<li><strong>Governance.</strong> Implement AI-specific risk frameworks such as the NIST AI Risk Management Framework and enhance transparency with Explainable AI (XAI) for regulatory compliance.  </li>



<li><strong>Continuous monitoring.</strong> Deploy real-time threat detection and model drift monitoring to proactively manage vulnerabilities and prevent AI degradation.  </li>



<li><strong>Collaborative ecosystems.</strong> Align IT, compliance, cybersecurity and business teams to enforce AI governance and ensure security and ethical integrity.  </li>
</ul>



<p>By securing AI at every stage of its lifecycle, organizations can fortify AI innovation while mitigating security risks, supporting compliance and sustaining business trust. The following table provides a quick overview of artificial intelligence lifecycle stages:  </p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2025/02/table-2-ai-lifecycle-stages.png?w=1024" alt="Table 2 - AI lifecycle stages" class="wp-image-3823234" srcset="https://b2b-contenthub.com/wp-content/uploads/2025/02/table-2-ai-lifecycle-stages.png?quality=50&amp;strip=all 1427w, https://b2b-contenthub.com/wp-content/uploads/2025/02/table-2-ai-lifecycle-stages.png?resize=300%2C180&amp;quality=50&amp;strip=all 300w, https://b2b-contenthub.com/wp-content/uploads/2025/02/table-2-ai-lifecycle-stages.png?resize=768%2C460&amp;quality=50&amp;strip=all 768w, https://b2b-contenthub.com/wp-content/uploads/2025/02/table-2-ai-lifecycle-stages.png?resize=1024%2C614&amp;quality=50&amp;strip=all 1024w, https://b2b-contenthub.com/wp-content/uploads/2025/02/table-2-ai-lifecycle-stages.png?resize=1163%2C697&amp;quality=50&amp;strip=all 1163w, https://b2b-contenthub.com/wp-content/uploads/2025/02/table-2-ai-lifecycle-stages.png?resize=280%2C168&amp;quality=50&amp;strip=all 280w, https://b2b-contenthub.com/wp-content/uploads/2025/02/table-2-ai-lifecycle-stages.png?resize=140%2C84&amp;quality=50&amp;strip=all 140w, https://b2b-contenthub.com/wp-content/uploads/2025/02/table-2-ai-lifecycle-stages.png?resize=801%2C480&amp;quality=50&amp;strip=all 801w, https://b2b-contenthub.com/wp-content/uploads/2025/02/table-2-ai-lifecycle-stages.png?resize=601%2C360&amp;quality=50&amp;strip=all 601w, https://b2b-contenthub.com/wp-content/uploads/2025/02/table-2-ai-lifecycle-stages.png?resize=417%2C250&amp;quality=50&amp;strip=all 417w" width="1024" height="614" sizes="(max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Vipin Jain</p></div>



<h2 class="wp-block-heading">4 critical AI security strategies </h2>



<h3 class="wp-block-heading">1. Adversarial training: Strengthening AI against manipulations  </h3>



<p>Adversarial training fortifies AI models by exposing them to simulated attacks, making them more resilient against data manipulation, cyber threats and fraud. A global logistics firm implemented adversarial training in its route optimization AI, reducing disruptions from data tampering by 25%. This method enhances AI’s ability to detect malicious inputs and prevent exploitation in fraud detection, image recognition and autonomous decision-making.  </p>



<h3 class="wp-block-heading">2. Explainable AI (XAI): Enhancing transparency and trust  </h3>



<p>XAI clarifies AI-driven decision-making, helping businesses build trust, reduce bias and meet regulatory requirements. A healthcare provider leveraged XAI tools to make its AI-driven diagnostic recommendations more transparent, improving physician confidence by 30%. In regulated industries like finance, healthcare and insurance, XAI supports auditability, compliance and ethical AI. </p>



<h3 class="wp-block-heading">3. Secure data pipelines: Protecting AI from data tampering  </h3>



<p>Ensuring data integrity is critical for AI reliability. Secure data pipelines safeguard AI models from data poisoning, unauthorized access and compliance violations through encryption, access controls and anomaly detection. Businesses can maintain accuracy and regulatory compliance by ensuring that only confirmed, unbiased and tamper-proof data is fed into AI models. </p>



<h3 class="wp-block-heading">4. Real-time monitoring: Detecting and mitigating AI risks  </h3>



<p>AI systems require continuous oversight to detect anomalies, performance drift and emerging cyber threats. A financial institution implemented real-time AI monitoring for its credit scoring system, reducing fraud-related losses by 20% and ensuring ongoing model accuracy. Continuous monitoring solutions help find vulnerabilities 85% faster, ensuring that AI stays stable, secure and aligned with business aims.  </p>



<h2 class="wp-block-heading">The path forward </h2>



<p> Organizations must integrate adversarial defense, explainability, secure data management and real-time risk monitoring into their AI strategies to fortify AI security. These measures safeguard AI integrity, enhance compliance and build stakeholder trust. Proactively addressing AI risks through strategic governance and security frameworks allows businesses to drive innovation while ensuring ethical responsibility and long-term sustainability. By adopting these strategies, organizations can strengthen AI security, support transparency and uphold compliance while refining efficiency and reinforcing stakeholder confidence. </p>



<h2 class="wp-block-heading">The competitive AI landscape </h2>



<p>The rapid adoption of AI has created a thriving ecosystem of vendors offering innovative solutions for securing AI systems, managing governance and ensuring ethical compliance. Understanding these players’ strengths and limitations is essential for informed decision-making in technology investments. </p>



<h3 class="wp-block-heading">Microsoft Azure AI </h3>



<p>Microsoft Azure AI provides a robust AI ecosystem that integrates Microsoft’s cloud and enterprise solutions. Prebuilt security frameworks like Azure AI Defender and Azure Sentinel are ideal for regulated industries such as finance and healthcare. While scalable and compliant, its prohibitive cost and complexity can hinder smaller organizations. Gartner ranks Azure AI among the top three enterprise AI security solutions.  </p>



<h3 class="wp-block-heading">Google Cloud AI  </h3>



<p>Google Cloud AI specializes in AI governance, security and explainability (XAI), making it an excellent choice for enterprises requiring transparent and compliant AI. Its XAI tools support regulatory adherence in healthcare and finance, though limited customization and premium pricing may be drawbacks.   </p>



<h3 class="wp-block-heading">AWS AI  </h3>



<p>Amazon Web Services (AWS) AI offers comprehensive AI security and scalability, with AWS Sage Maker widely used for secure model training and deployment. Its global infrastructure supports large-scale enterprises, but excessive costs and third-party integration challenges may hinder smaller firms.   </p>



<h3 class="wp-block-heading">Darktrace  </h3>



<p>Darktrace is a leader in AI-powered cybersecurity, offering real-time anomaly detection and autonomous threat mitigation. Its self-learning AI models adapt to evolving threats, making it essential for enterprises requiring continuous security monitoring. However, inflated costs and complex deployment may limit adoption for smaller businesses.   </p>



<p>These vendors shape AI security’s future, offering specialized solutions in threat detection, explainability and data integrity. As AI adoption accelerates, their technologies will be key to ensuring secure, compliant and ethical AI deployment.  </p>



<h2 class="wp-block-heading">Market trends and strategic implications  </h2>



<p>The AI security market is experiencing rapid growth and is projected to expand at a 28% CAGR, reaching $50 billion by 2030. North America currently leads with a 45% market share, followed by Europe and the Asia-Pacific region, reflecting a global emphasis on AI security. This growth is driven by increasing regulatory compliance mandates, the evolving sophistication of AI-related threats and a rising focus on ethical AI practices. Organizations across industries recognize the need to implement robust security frameworks that address adversarial attacks, data governance challenges and algorithmic bias to ensure AI systems stay secure and trustworthy.  </p>



<h2 class="wp-block-heading">Future focus  </h2>



<p>AI security is evolving rapidly, with innovative technologies and frameworks shaping the future landscape. Organizations must expect emerging trends to still be competitive and resilient.  </p>



<ul class="wp-block-list">
<li><strong>AI-driven threat intelligence</strong> transforms cybersecurity by enabling real-time detection and mitigation of sophisticated threats. AI-powered systems analyze vast data streams to find anomalies, predict cyberattacks and neutralize risks before they escalate. Darktrace employs AI for anomaly detection, reducing breach risks by 40% and reinforcing AI’s role in initiative-taking security management. </li>



<li><strong>Regulatory frameworks</strong> for AI governance are becoming increasingly stringent. The EU AI Act mandates transparency and accountability, with substantial penalties for non-compliance. Organizations that invest early in compliance frameworks gain a competitive advantage, regulatory readiness and stronger stakeholder trust, ensuring AI deployments stay ethical, secure and aligned with legal requirements.  </li>
</ul>



<h2 class="wp-block-heading">Conclusion  </h2>



<p>AI systems are driving unparalleled innovation and operational efficiency across industries. However, securing these systems against technical, ethical and regulatory challenges requires a holistic, forward-looking approach. Organizations can adopt the right strategies to ensure their AI frontiers, foster stakeholder trust and sustain growth in an increasingly AI-powered world.  </p>



<p><em>Vipin Jain, founder and chief architect of </em><a href="https://txe.ai/" target="_blank" rel="nofollow"><em>Transformation Enablers Inc.</em></a><em>, brings over 30 years of experience crafting execution-ready IT strategies and transformation roadmaps aligned with business goals while leveraging emerging technologies like AI. He has held executive roles at AIG, Merrill Lynch and Citicorp, where he led business and IT portfolio transformations. Vipin also led consulting practices at Accenture, Microsoft and HPE, advising Fortune 100 firms and U.S. federal agencies. He is currently a senior advisor at </em><a href="https://wve.digital/" target="_blank" rel="nofollow"><em>WVE</em></a><em>.</em> </p>



<p><em>This article was made possible by our partnership with the IASA </em><a href="https://chiefarchitectforum.org/" target="_blank" rel="nofollow"><em>Chief Architect Forum</em></a><em>. The CAF’s purpose is to test, challenge and support the art and science of Business Technology Architecture and its evolution over time as well as grow the influence and leadership of chief architects both inside and outside the profession. The CAF is a leadership community of the </em><a href="https://iasaglobal.org/" target="_blank" rel="nofollow"><em>IASA</em></a><em>, the leading non-profit professional association for business technology architects.</em> </p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI and cybersecurity: A double-edged sword]]></title>
<description><![CDATA[In the ever-changing landscape of digital threats, artificial intelligence (AI) has emerged as both a formidable ally and a dangerous adversary. As we navigate the complexities of our interconnected world, it’s becoming increasingly clear that AI is not just a tool, but a force that’s reshaping t...]]></description>
<link>https://tsecurity.de/de/2564711/it-security-nachrichten/ai-and-cybersecurity-a-double-edged-sword/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2564711/it-security-nachrichten/ai-and-cybersecurity-a-double-edged-sword/</guid>
<pubDate>Tue, 21 Jan 2025 13:19:05 +0100</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>In the ever-changing landscape of digital threats, artificial intelligence (AI) has emerged as both a formidable ally and a dangerous adversary. As we navigate the complexities of our interconnected world, it’s becoming increasingly clear that AI is not just a tool, but a force that’s reshaping the very nature of cybersecurity.  </p>



<p>The cybersecurity world has changed dramatically. Gone are the days when simple firewalls and antivirus software could keep our digital assets safe. Today, we’re dealing with sophisticated threat actors who are leveraging AI to launch attacks at unprecedented scale and speed. For instance, in 2024, <a href="https://www.deepinstinct.com/voice-of-secops-reports" target="_blank" rel="nofollow">a troubling trend emerged</a> where hackers used AI-powered tools to create highly convincing deepfakes, impersonating CEOs and other C-suite executives in 75% of such attacks.  </p>



<p>At <a href="https://www.synechron.com/en-us" rel="nofollow">Synechron</a>, we are prioritizing diligence through our payment process to ensure that we have appropriate approval authority including out of band validation of mid-large money transfers. As a secondary measure, we are now evaluating a few deepfake detection tools that can be integrated into our business productivity apps, in particular for Zoom or Teams, to continuously detect deepfakes. </p>



<p>Using AI in cybersecurity is like trying to play chess against a supercomputer — the game is familiar, but the opponent’s capabilities are on a whole new level. Luckily, we also have access to the supercomputer. </p>



<h2 class="wp-block-heading">The AI advantage </h2>



<p>How exactly is AI tipping the scales in favor of cybersecurity professionals? For starters, it’s revolutionizing threat detection and response. AI systems can analyze vast amounts of data in real time, identifying potential threats with speed and accuracy. Companies like CrowdStrike <a href="https://vorecol.com/blogs/blog-how-can-artificial-intelligence-be-leveraged-to-improve-threat-detection-in-cybersecurity-141954" target="_blank" rel="nofollow">have documented</a> that their AI-driven systems can detect threats in under one second.  </p>



<p>But AI’s capabilities don’t stop at detection. When it comes to incident response, AI is proving to be a game-changer. Imagine a security system that doesn’t just alert you to a threat but takes immediate action to neutralize it. That’s the potential of AI-driven automated incident response. From isolating compromised systems to blocking malicious IP addresses, AI can execute these critical tasks swiftly and without human input, dramatically reducing response times and minimizing potential damage. </p>



<p>Perhaps one of the most anticipated applications of AI in cybersecurity is in the realm of behavioral analytics and predictive analysis. By leveraging machine learning algorithms, AI can analyze user behavior and network traffic patterns, identifying anomalies that might indicate insider threats or other malicious activities. These AI-driven insider threat behavioral analytics systems have been shown to detect <a href="https://web.cs.dal.ca/~lcd/pubs/TNSM2021.pdf" target="_blank" rel="nofollow">60% of malicious insiders under a 0.1%</a> investigation budget and achieve full detection within a 5% budget in certain cases.  </p>



<h2 class="wp-block-heading">The dark side of AI  </h2>



<p>However, as with any powerful tool, AI is a double-edged sword. While it’s enhancing our defensive capabilities, it’s also being weaponized by cybercriminals to launch more sophisticated attacks. These AI-powered cyber-attacks are no longer a potential threat — they’re a very real and present danger. </p>



<p>For example, <a href="https://abnormalsecurity.com/blog/2023-ai-generated-email-attacks" target="_blank" rel="nofollow">attackers recently used AI</a> to pose as representatives of an insurance company. The email informed the recipient about benefits enrollment and included a form that needed to be completed urgently to avoid losing coverage and attempting to fool the receiver. AI can craft phishing emails like these, which are so convincing that even the most security-conscious user might fall for it. It can even create custom malware that can adapt and evolve to evade detection. These are the kinds of attacks that AI-enabled cybercriminals are now capable of producing. We’ve ended up in a cat-and-mouse game where both sides are constantly upping the ante. </p>



<p>The challenges don’t end there. As we increasingly rely on AI for our cybersecurity needs, we open these new AI tools to new vulnerabilities. Data poisoning and model manipulation are emerging as serious concerns for those of us in cybersecurity. Attackers can potentially tamper with the data used to train AI models, causing them to malfunction or make erroneous decisions.  </p>



<p>There’s also the risk of over-reliance on the new systems. While AI is undoubtedly powerful, it’s not infallible. Becoming too dependent on AI for cybersecurity could lead to complacency and a false sense of security. We must remember that AI is a tool to augment human expertise, not replace it entirely. </p>



<h2 class="wp-block-heading">The human factor  </h2>



<p>AI is not just changing the skill set required for cybersecurity professionals, it’s augmenting it for the better. The ability to work alongside AI systems, interpret their outputs, and make strategic decisions based on AI-generated insights will be paramount for both users and experts.  While AI is improving at its cybersecurity capabilities, a human paired with an AI tool will outperform AI by itself ten-fold.  </p>



<p>Our cyber team at Synechron plans to build and deploy our own AI accelerators as well as leverage Microsoft’s security co-pilot capabilities to augment our detection and security investigation of possible threats. However, this approach also requires human interaction to validate any findings or recommendations from AI to prioritize the remediations or responses that are required based on the criticality of the asset. In other words, humans are still required to interpret any business contextual information that AI might miss. This miss should not be understated as any discrepancy or incorrect analysis from AI could lead to detrimental loss or compromise. In addition, humans can also adapt to business contexts, and interpret changes or perceptions of potential loss or impact better than AI as AI is specifically programmed to achieve programmed outcomes. </p>



<p>As AI becomes more prevalent across organizations, there’s a growing need for a better understanding of data dependencies and asset management. Cybersecurity teams will need to reevaluate the relative importance of data assets, update inventories, and account for new threats and risks these AI systems might bring to their organizations.  </p>



<h2 class="wp-block-heading">The promise AI brings  </h2>



<p>Despite these challenges, the potential of AI in cybersecurity is truly exciting. Unlike traditional security solutions that can only rely on predefined rules, AI can learn from its environment and evolve its security protocols accordingly. And it’s this adaptability that will be crucial in a landscape where new threats are constantly emerging due to the very tools that are helping prevent them. </p>



<p>Looking ahead, the integration of AI with other emerging technologies like quantum computing or blockchain could lead to even more comprehensive security solutions. Picture a cybersecurity system that combines the processing power of quantum computing, the immutability of blockchain, and the adaptive intelligence of AI. This combination can create a highly robust defense system the likes of which we have not seen before.  </p>



<h2 class="wp-block-heading">The road ahead </h2>



<p>As we look toward the future, it’s clear that AI will continue to play an increasingly central role in cybersecurity. In fact, <a href="https://darktrace.com/resources/state-of-ai-cyber-security-2024" target="_blank" rel="nofollow">87% of IT professionals</a> anticipate AI-generated threats will continue to impact their organizations for years to come, underscoring the need for continued innovation and vigilance. The key with AI will be striking the right balance — leveraging its strengths while mitigating the risks and limitations. It’s a challenge, certainly, but also an opportunity to build a safer, more secure digital world.    </p>



<p>We need to invest in developing more robust and secure AI systems, ones that are resistant to manipulation and capable of explaining their decision-making processes. At the same time, we must continue to nurture human expertise, fostering a symbiotic relationship between human intuition and machine intelligence. </p>



<p>As we stand at this technological crossroads, one thing is clear: In the ongoing battle against cyber threats, AI is not just a tool — it’s the future of the entire battlefield.  </p>



<p></p>



<p><em>As the Global CISO at Synechron, a leading global digital transformation consulting firm, </em><a href="https://www.linkedin.com/in/aaronmomin/" target="_blank" rel="nofollow"><em>Aaron Momin</em></a><em> is accountable and responsible for cyber risk management, information security, crisis management and business continuity planning. Aaron has 30 years of experience in managing cyber and technology risk, improving security maturity and integrating privacy for global organizations. He is a certified CISO, CISM and CRISC.</em> </p>



<p></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Darktrace: Multi-Agenten-Systeme und Insider-Angriffe - Silicon.de]]></title>
<description><![CDATA[KI-Security-Trends 2025: Zunahme von Angriffen auf OT-Systeme bedrohen Betriebstechnologie. Alle IT-Nachrichten auf Silicon.de.]]></description>
<link>https://tsecurity.de/de/2548043/it-security-nachrichten/darktrace-multi-agenten-systeme-und-insider-angriffe-siliconde/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2548043/it-security-nachrichten/darktrace-multi-agenten-systeme-und-insider-angriffe-siliconde/</guid>
<pubDate>Mon, 13 Jan 2025 10:04:17 +0100</pubDate>
<content:encoded><![CDATA[KI-<b>Security</b>-Trends 2025: Zunahme von Angriffen auf OT-Systeme bedrohen Betriebstechnologie. Alle <b>IT</b>-Nachrichten auf Silicon.de.]]></content:encoded>
</item>
<item>
<title><![CDATA[Darktrace übernimmt Incident-Response-Spezialisten Cado Security - It-daily.net]]></title>
<description><![CDATA[Das britische Cybersecurity-Unternehmen Darktrace setzt seinen Expansionskurs fort und kündigt die Übernahme des in London ansässigen ...]]></description>
<link>https://tsecurity.de/de/2544706/it-security-nachrichten/darktrace-uebernimmt-incident-response-spezialisten-cado-security-it-dailynet/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2544706/it-security-nachrichten/darktrace-uebernimmt-incident-response-spezialisten-cado-security-it-dailynet/</guid>
<pubDate>Fri, 10 Jan 2025 17:34:31 +0100</pubDate>
<content:encoded><![CDATA[Das britische Cybersecurity-Unternehmen Darktrace setzt seinen Expansionskurs fort und kündigt die Übernahme des in London ansässigen ...]]></content:encoded>
</item>
<item>
<title><![CDATA[DarkTrace acquires Cado Security]]></title>
<description><![CDATA[Darktrace has officially announced its acquisition of Cado Security for £131 million, marking the first major deal for the cybersecurity giant since its own acquisition by Thoma Bravo in October 2024. This strategic move signals Darktrace’s intent to solidify its position in the cybersecurity mar...]]></description>
<link>https://tsecurity.de/de/2544556/it-security-nachrichten/darktrace-acquires-cado-security/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2544556/it-security-nachrichten/darktrace-acquires-cado-security/</guid>
<pubDate>Fri, 10 Jan 2025 16:48:55 +0100</pubDate>
<content:encoded><![CDATA[<p>Darktrace has officially announced its acquisition of Cado Security for £131 million, marking the first major deal for the cybersecurity giant since its own acquisition by Thoma Bravo in October 2024. This strategic move signals Darktrace’s intent to solidify its position in the cybersecurity market through innovative collaborations and expanded capabilities. Cado Security, a UK-based […]</p>
<p>The post <a href="https://www.cybersecurity-insiders.com/darktrace-acquires-cado-security/">DarkTrace acquires Cado Security</a> appeared first on <a href="https://www.cybersecurity-insiders.com/">Cybersecurity Insiders</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Darktrace übernimmt Incident-Response-Spezialisten Cado Security]]></title>
<description><![CDATA[Das britische Cybersecurity-Unternehmen Darktrace setzt seinen Expansionskurs fort und kündigt die Übernahme des in London ansässigen Incident-Response-Spezialisten Cado Security an. Mit der Akquisition will der Security-Anbieter seine Fähigkeiten im Bereich der digitalen Forensik und Cloud-Unter...]]></description>
<link>https://tsecurity.de/de/2544140/it-security-nachrichten/darktrace-uebernimmt-incident-response-spezialisten-cado-security/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2544140/it-security-nachrichten/darktrace-uebernimmt-incident-response-spezialisten-cado-security/</guid>
<pubDate>Fri, 10 Jan 2025 13:19:13 +0100</pubDate>
<content:encoded><![CDATA[<p><img width="1920" height="1080" src="https://www.it-daily.net/wp-content/uploads/2023/03/Handshake-KI-Shutterstock-2102809798-1920.jpg" class="attachment-full size-full wp-post-image" alt="Handshake" decoding="async" srcset="https://www.it-daily.net/wp-content/uploads/2023/03/Handshake-KI-Shutterstock-2102809798-1920.jpg 1920w, https://www.it-daily.net/wp-content/uploads/2023/03/Handshake-KI-Shutterstock-2102809798-1920-300x169.jpg 300w, https://www.it-daily.net/wp-content/uploads/2023/03/Handshake-KI-Shutterstock-2102809798-1920-1024x576.jpg 1024w, https://www.it-daily.net/wp-content/uploads/2023/03/Handshake-KI-Shutterstock-2102809798-1920-768x432.jpg 768w, https://www.it-daily.net/wp-content/uploads/2023/03/Handshake-KI-Shutterstock-2102809798-1920-1536x864.jpg 1536w" sizes="(max-width: 1920px) 100vw, 1920px" title="Darktrace übernimmt Incident-Response-Spezialisten Cado Security 1"></p>
    Das britische Cybersecurity-Unternehmen Darktrace setzt seinen Expansionskurs fort und kündigt die Übernahme des in London ansässigen Incident-Response-Spezialisten Cado Security an. Mit der Akquisition will der Security-Anbieter seine Fähigkeiten im Bereich der digitalen Forensik und Cloud-Untersuchungen ausbauen.

<p>Tags: <a href="https://www.it-daily.net/thema/firmenuebernahme">#Firmenübernahme</a> | <a href="https://www.it-daily.net/thema/incident-response">#Incident Response</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[10 Best Darktrace Alternatives & Competitors in 2024 [Features, Pricing & Reviews]]]></title>
<description><![CDATA[Looking for Darktrace alternatives can feel like hunting for missing puzzle pieces. Yes, Darktrace does a good job at detecting network threats. But these days, you must consider covering various protection layers to secure your system. Endpoint detection and response, cloud and email security, o...]]></description>
<link>https://tsecurity.de/de/2424815/it-security-nachrichten/10-best-darktrace-alternatives-competitors-in-2024-features-pricing-reviews/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2424815/it-security-nachrichten/10-best-darktrace-alternatives-competitors-in-2024-features-pricing-reviews/</guid>
<pubDate>Tue, 05 Nov 2024 09:19:08 +0100</pubDate>
<content:encoded><![CDATA[<p>Looking for Darktrace alternatives can feel like hunting for missing puzzle pieces. Yes, Darktrace does a good job at detecting network threats. But these days, you must consider covering various protection layers to secure your system. Endpoint detection and response, cloud and email security, or user access management are equally important areas. While you’re out […]</p>
<p>The post <a href="https://heimdalsecurity.com/blog/darktrace-alternatives-competitors/">10 Best Darktrace Alternatives &amp; Competitors in 2024 [Features, Pricing &amp; Reviews]</a> appeared first on <a href="https://heimdalsecurity.com/blog">Heimdal Security Blog</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Keir Starmer hands ex-Darktrace boss investment minister gig]]></title>
<description><![CDATA[What's harder? Convincing people to invest in a beleaguered security business or a tiny island everybody hates? Keir Starmer's decision to appoint Poppy Gustafsson as the UK's new investment minister is being resoundingly praised despite the former Darktrace boss spending years failing to fully r...]]></description>
<link>https://tsecurity.de/de/2380713/it-security-nachrichten/keir-starmer-hands-ex-darktrace-boss-investment-minister-gig/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2380713/it-security-nachrichten/keir-starmer-hands-ex-darktrace-boss-investment-minister-gig/</guid>
<pubDate>Fri, 11 Oct 2024 13:33:52 +0200</pubDate>
<content:encoded><![CDATA[<h4>What's harder? Convincing people to invest in a beleaguered security business or a tiny island everybody hates?</h4> <p>Keir Starmer's decision to appoint Poppy Gustafsson as the UK's new investment minister is being resoundingly praised despite the former Darktrace boss spending years failing to fully rebuild investor confidence in the embattled company.…</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Darktrace-Bericht: KI-gesteuerte Ransomware wie Qilin bedroht Banken - IT Finanzmagazin]]></title>
<description><![CDATA[Daher benötigt der Finanzsektor neue Security-Maßnahmen. von Max Heinemeyer, Chief Product Officer bei Darktrace. Die Eintrittsschwelle für ...]]></description>
<link>https://tsecurity.de/de/2371878/it-security-nachrichten/darktrace-bericht-ki-gesteuerte-ransomware-wie-qilin-bedroht-banken-it-finanzmagazin/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2371878/it-security-nachrichten/darktrace-bericht-ki-gesteuerte-ransomware-wie-qilin-bedroht-banken-it-finanzmagazin/</guid>
<pubDate>Mon, 07 Oct 2024 14:04:44 +0200</pubDate>
<content:encoded><![CDATA[Daher benötigt der Finanzsektor neue <b>Security</b>-Maßnahmen. von Max Heinemeyer, Chief Product Officer bei Darktrace. Die Eintrittsschwelle für ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Darktrace brings real-time cloud detection and response to Microsoft Azure customers]]></title>
<description><![CDATA[Darktrace announced the expansion of Darktrace / CLOUD to support Microsoft Azure environments. The AI-driven Cloud Detection and Response (CDR) system leverages Microsoft’s virtual network flow logs for agentless deployment, slashing deployment times by 95%. The need for AI-driven cloud security...]]></description>
<link>https://tsecurity.de/de/2366423/it-security-nachrichten/darktrace-brings-real-time-cloud-detection-and-response-to-microsoft-azure-customers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2366423/it-security-nachrichten/darktrace-brings-real-time-cloud-detection-and-response-to-microsoft-azure-customers/</guid>
<pubDate>Thu, 03 Oct 2024 15:33:09 +0200</pubDate>
<content:encoded><![CDATA[<p>Darktrace announced the expansion of Darktrace / CLOUD to support Microsoft Azure environments. The AI-driven Cloud Detection and Response (CDR) system leverages Microsoft’s virtual network flow logs for agentless deployment, slashing deployment times by 95%. The need for AI-driven cloud security has never been more critical. 51% of US organizations use cloud computing today, and global spending on public cloud services is expected to reach $805 billion in 2024. Moreover, Darktrace’s State of AI Cybersecurity report … <a href="https://www.helpnetsecurity.com/2024/10/03/darktrace-cloud-microsoft-azure/" rel="nofollow">More <span class="meta-nav">→</span></a></p>
<p>The post <a href="https://www.helpnetsecurity.com/2024/10/03/darktrace-cloud-microsoft-azure/">Darktrace brings real-time cloud detection and response to Microsoft Azure customers</a> appeared first on <a href="https://www.helpnetsecurity.com/">Help Net Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Darktrace Announces Formal Completion of its Acquisition by Thoma Bravo]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/2363219/it-security-nachrichten/darktrace-announces-formal-completion-of-its-acquisition-by-thoma-bravo/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2363219/it-security-nachrichten/darktrace-announces-formal-completion-of-its-acquisition-by-thoma-bravo/</guid>
<pubDate>Tue, 01 Oct 2024 23:34:38 +0200</pubDate>
</item>
<item>
<title><![CDATA[Zunehmender Missbrauch von GenAI - Crn de]]></title>
<description><![CDATA[Die "ActiveAI Security Platform" des UK-Anbieters Darktrace nimmt Bechtle in sein Cybersecurity-Portfolio auf. Die strategische Partnerschaft sieht ...]]></description>
<link>https://tsecurity.de/de/2337915/it-security-nachrichten/zunehmender-missbrauch-von-genai-crn-de/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2337915/it-security-nachrichten/zunehmender-missbrauch-von-genai-crn-de/</guid>
<pubDate>Tue, 17 Sep 2024 17:49:00 +0200</pubDate>
<content:encoded><![CDATA[Die "ActiveAI <b>Security</b> Platform" des UK-Anbieters Darktrace nimmt Bechtle in sein Cybersecurity-Portfolio auf. Die strategische Partnerschaft sieht ...]]></content:encoded>
</item>
<item>
<title><![CDATA[KI und Cybersicherheit: Darktrace expandiert nach DACH mit Partner Bechtle - Crn de]]></title>
<description><![CDATA[Die "ActiveAI Security Platform" des UK-Anbieters Darktrace nimmt Bechtle in sein Cybersecurity-Portfolio aufnehmen. Die strategische Partnerschaft ...]]></description>
<link>https://tsecurity.de/de/2335094/it-security-nachrichten/ki-und-cybersicherheit-darktrace-expandiert-nach-dach-mit-partner-bechtle-crn-de/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2335094/it-security-nachrichten/ki-und-cybersicherheit-darktrace-expandiert-nach-dach-mit-partner-bechtle-crn-de/</guid>
<pubDate>Mon, 16 Sep 2024 13:50:02 +0200</pubDate>
<content:encoded><![CDATA[Die "ActiveAI <b>Security</b> Platform" des UK-Anbieters Darktrace nimmt Bechtle in sein Cybersecurity-Portfolio aufnehmen. Die strategische Partnerschaft ...]]></content:encoded>
</item>
<item>
<title><![CDATA[How I got started: AI security executive]]></title>
<description><![CDATA[Artificial intelligence and machine learning are becoming increasingly crucial to cybersecurity systems. Organizations need professionals with a strong background that mixes AI/ML knowledge with cybersecurity skills, bringing on board people like Nicole Carignan, Vice President of Strategic Cyber...]]></description>
<link>https://tsecurity.de/de/2329646/it-security-nachrichten/how-i-got-started-ai-security-executive/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2329646/it-security-nachrichten/how-i-got-started-ai-security-executive/</guid>
<pubDate>Thu, 12 Sep 2024 15:48:55 +0200</pubDate>
<content:encoded><![CDATA[<p>Artificial intelligence and machine learning are becoming increasingly crucial to cybersecurity systems. Organizations need professionals with a strong background that mixes AI/ML knowledge with cybersecurity skills, bringing on board people like Nicole Carignan, Vice President of Strategic Cyber AI at Darktrace, who has a unique blend of technical and soft skills. Carignan was originally a […]</p>
<p>The post <a rel="nofollow" href="https://securityintelligence.com/articles/how-i-got-started-ai-security-executive/">How I got started: AI security executive</a> appeared first on <a rel="nofollow" href="https://securityintelligence.com/">Security Intelligence</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Poppy Gustafsson to Step Down As CEO of Darktrace; Jill Popelka Appointed Successor]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/2327987/it-security-nachrichten/poppy-gustafsson-to-step-down-as-ceo-of-darktrace-jill-popelka-appointed-successor/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2327987/it-security-nachrichten/poppy-gustafsson-to-step-down-as-ceo-of-darktrace-jill-popelka-appointed-successor/</guid>
<pubDate>Wed, 11 Sep 2024 18:19:15 +0200</pubDate>
</item>
<item>
<title><![CDATA[Darktrace schließt Partnerschaft mit Bechtle - It-daily.net]]></title>
<description><![CDATA[Diese ergänzt das bestehende Sicherheitsangebot von Bechtle und entlastet Security-Teams von der manuellen, zeitintensiven Bewertung von ...]]></description>
<link>https://tsecurity.de/de/2327957/it-security-nachrichten/darktrace-schliesst-partnerschaft-mit-bechtle-it-dailynet/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2327957/it-security-nachrichten/darktrace-schliesst-partnerschaft-mit-bechtle-it-dailynet/</guid>
<pubDate>Wed, 11 Sep 2024 18:04:07 +0200</pubDate>
<content:encoded><![CDATA[Diese ergänzt das bestehende Sicherheitsangebot von Bechtle und entlastet <b>Security</b>-Teams von der manuellen, zeitintensiven Bewertung von ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Bechtle schließt Partnerschaft mit Unternehmen für Cybersicherheit - ECOreporter.de]]></title>
<description><![CDATA[Das Neckarsulmer IT-Systemhaus Bechtle hat eine Partnerschaft mit dem britischen Cybersicherheit-Anbieter Darktrace geschlossen.]]></description>
<link>https://tsecurity.de/de/2327541/it-security-nachrichten/bechtle-schliesst-partnerschaft-mit-unternehmen-fuer-cybersicherheit-ecoreporterde/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2327541/it-security-nachrichten/bechtle-schliesst-partnerschaft-mit-unternehmen-fuer-cybersicherheit-ecoreporterde/</guid>
<pubDate>Wed, 11 Sep 2024 15:03:24 +0200</pubDate>
<content:encoded><![CDATA[Das Neckarsulmer <b>IT</b>-Systemhaus Bechtle hat eine Partnerschaft mit dem britischen Cybersicherheit-Anbieter Darktrace geschlossen.]]></content:encoded>
</item>
<item>
<title><![CDATA[Darktrace schließt Partnerschaft mit Bechtle - it-business]]></title>
<description><![CDATA[Bechtle-Kunden sollen vom gemeinsam entwickelten Angebot für KI-basierte Cybersicherheit profitieren. Darktrace hat eine Partnerschaft mit Bechtle ...]]></description>
<link>https://tsecurity.de/de/2327288/it-security-nachrichten/darktrace-schliesst-partnerschaft-mit-bechtle-it-business/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2327288/it-security-nachrichten/darktrace-schliesst-partnerschaft-mit-bechtle-it-business/</guid>
<pubDate>Wed, 11 Sep 2024 13:03:30 +0200</pubDate>
<content:encoded><![CDATA[Bechtle-Kunden sollen vom gemeinsam entwickelten Angebot für KI-basierte Cybersicherheit profitieren. Darktrace hat eine Partnerschaft mit Bechtle ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Darktrace schließt Partnerschaft mit Bechtle]]></title>
<description><![CDATA[Darktrace hat eine Partnerschaft mit Bechtle geschlossen. Diese Kooperation verstärkt die Präsenz von Darktrace in der DACH-Region und bietet dem umfangreichen Kundenstamm von Bechtle einzigartige KI-basierte Cybersicherheitslösungen.

Tags: #Cybersicherheit | #IT Security | #partnerschaft]]></description>
<link>https://tsecurity.de/de/2327017/it-security-nachrichten/darktrace-schliesst-partnerschaft-mit-bechtle/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2327017/it-security-nachrichten/darktrace-schliesst-partnerschaft-mit-bechtle/</guid>
<pubDate>Wed, 11 Sep 2024 10:48:49 +0200</pubDate>
<content:encoded><![CDATA[<p><img width="1920" height="1080" src="https://www.it-daily.net/wp-content/uploads/2024/09/Partnerschaft.jpg" class="attachment-full size-full wp-post-image" alt="Partnerschaft" decoding="async" srcset="https://www.it-daily.net/wp-content/uploads/2024/09/Partnerschaft.jpg 1920w, https://www.it-daily.net/wp-content/uploads/2024/09/Partnerschaft-300x169.jpg 300w, https://www.it-daily.net/wp-content/uploads/2024/09/Partnerschaft-1024x576.jpg 1024w, https://www.it-daily.net/wp-content/uploads/2024/09/Partnerschaft-768x432.jpg 768w, https://www.it-daily.net/wp-content/uploads/2024/09/Partnerschaft-1536x864.jpg 1536w" sizes="(max-width: 1920px) 100vw, 1920px" title="Darktrace schließt Partnerschaft mit Bechtle 1"></p>
    Darktrace hat eine Partnerschaft mit Bechtle geschlossen. Diese Kooperation verstärkt die Präsenz von Darktrace in der DACH-Region und bietet dem umfangreichen Kundenstamm von Bechtle einzigartige KI-basierte Cybersicherheitslösungen.

<p>Tags: <a href="https://www.it-daily.net/thema/cybersicherheit">#Cybersicherheit</a> | <a href="https://www.it-daily.net/thema/it-security">#IT Security</a> | <a href="https://www.it-daily.net/thema/partnerschaft">#partnerschaft</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[KI-basierte Cyber-Sicherheit: Bechtle nimmt Darktrace als Lieferanten auf - ChannelPartner]]></title>
<description><![CDATA[Von Anfang an hat sich der Cyber-Security-Spezialist den Technologien der "Künstlichen Intelligenz" (KI) verschrieben. Mittlerweile offeriert ...]]></description>
<link>https://tsecurity.de/de/2325068/it-security-nachrichten/ki-basierte-cyber-sicherheit-bechtle-nimmt-darktrace-als-lieferanten-auf-channelpartner/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2325068/it-security-nachrichten/ki-basierte-cyber-sicherheit-bechtle-nimmt-darktrace-als-lieferanten-auf-channelpartner/</guid>
<pubDate>Tue, 10 Sep 2024 12:19:26 +0200</pubDate>
<content:encoded><![CDATA[Von Anfang an hat sich der <b>Cyber</b>-<b>Security</b>-Spezialist den Technologien der "Künstlichen Intelligenz" (KI) verschrieben. Mittlerweile offeriert ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Künstliche Intelligenz und Cybersecurity: Deutschlands Vorbereitung Lücken - Security-Insider]]></title>
<description><![CDATA[Darktrace State of AI Cybersecurity Report KI-Gefahren erfordern neue Sicherheitsstufe. 27.08.2024 Von Peter Schmitz 2 min Lesedauer. Anbieter zum ...]]></description>
<link>https://tsecurity.de/de/2300492/it-security-nachrichten/kuenstliche-intelligenz-und-cybersecurity-deutschlands-vorbereitung-luecken-security-insider/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2300492/it-security-nachrichten/kuenstliche-intelligenz-und-cybersecurity-deutschlands-vorbereitung-luecken-security-insider/</guid>
<pubDate>Tue, 27 Aug 2024 13:19:49 +0200</pubDate>
<content:encoded><![CDATA[Darktrace State of AI Cybersecurity Report KI-Gefahren erfordern neue Sicherheitsstufe. 27.08.2024 Von Peter Schmitz 2 min Lesedauer. Anbieter zum ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Darktrace Co-founder Mike Lynch Presumed Dead After Superyacht Sinks]]></title>
<description><![CDATA[Mike Lynch, co-founder of Darktrace and Autonomy, is among six people presumed dead after the superyacht, Bayesian, sank off the coast of Sicily early Monday.
The post Darktrace Co-founder Mike Lynch Presumed Dead After Superyacht Sinks appeared first on SecurityWeek.]]></description>
<link>https://tsecurity.de/de/2288597/it-security-nachrichten/darktrace-co-founder-mike-lynch-presumed-dead-after-superyacht-sinks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2288597/it-security-nachrichten/darktrace-co-founder-mike-lynch-presumed-dead-after-superyacht-sinks/</guid>
<pubDate>Tue, 20 Aug 2024 22:06:14 +0200</pubDate>
<content:encoded><![CDATA[<p>Mike Lynch, co-founder of Darktrace and Autonomy, is among six people presumed dead after the superyacht, Bayesian, sank off the coast of Sicily early Monday.</p>
<p>The post <a href="https://www.securityweek.com/darktrace-co-founder-mike-lynch-presumed-dead-after-superyacht-sinks/">Darktrace Co-founder Mike Lynch Presumed Dead After Superyacht Sinks</a> appeared first on <a href="https://www.securityweek.com/">SecurityWeek</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Tech-Unternehmer: Autonomy- und Darktrace-Investor vermisst]]></title>
<description><![CDATA[Nach einem Schiffsunglück vor der Küste Siziliens ist der britische Unternehmer Mike Lynch unter den Vermissten. (Wirtschaft, Maschinelles Lernen)]]></description>
<link>https://tsecurity.de/de/2286162/it-nachrichten/tech-unternehmer-autonomy-und-darktrace-investor-vermisst/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2286162/it-nachrichten/tech-unternehmer-autonomy-und-darktrace-investor-vermisst/</guid>
<pubDate>Mon, 19 Aug 2024 19:47:15 +0200</pubDate>
<content:encoded><![CDATA[Nach einem Schiffsunglück vor der Küste Siziliens ist der britische Unternehmer Mike Lynch unter den Vermissten. (<a href="https://www.golem.de/specials/wirtschaft/">Wirtschaft</a>, <a href="https://www.golem.de/specials/maschinelles-lernen/">Maschinelles Lernen</a>) <img src="https://cpx.golem.de/cpx.php?class=17&amp;aid=188162&amp;page=1&amp;ts=1724089442" alt="" width="1" height="1">]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2024-22854 | Darktrace Threat Visualizer up to 6.1.27 Main Page cross site scripting]]></title>
<description><![CDATA[A vulnerability classified as problematic was found in Darktrace Threat Visualizer up to 6.1.27. Affected by this vulnerability is an unknown functionality of the component Main Page. The manipulation leads to cross site scripting.

This vulnerability is known as CVE-2024-22854. The attack can be...]]></description>
<link>https://tsecurity.de/de/2282439/sicherheitsluecken/cve-2024-22854-darktrace-threat-visualizer-up-to-6127-main-page-cross-site-scripting/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2282439/sicherheitsluecken/cve-2024-22854-darktrace-threat-visualizer-up-to-6127-main-page-cross-site-scripting/</guid>
<pubDate>Fri, 16 Aug 2024 21:50:23 +0200</pubDate>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/?kb.risk">problematic</a> was found in <a href="https://vuldb.com/?product.darktrace:threat_visualizer">Darktrace Threat Visualizer up to 6.1.27</a>. Affected by this vulnerability is an unknown functionality of the component <em>Main Page</em>. The manipulation leads to cross site scripting.

This vulnerability is known as <a href="https://vuldb.com/?source_cve.253999">CVE-2024-22854</a>. The attack can be launched remotely. There is no exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[Security Weekly: Security Money: Crowdstrike Crashes the Index - BSW #360]]></title>
<description><![CDATA[Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:5 This week, it’s time for security money, our quarterly review of the money of security, including public companies, IPOs, funding rounds and acquisitions from the previous quarter. This quarter, Crowdstrike crashes the index, as T...]]></description>
<link>https://tsecurity.de/de/2274842/it-security-video/security-money-crowdstrike-crashes-the-index-bsw-360/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2274842/it-security-video/security-money-crowdstrike-crashes-the-index-bsw-360/</guid>
<pubDate>Tue, 13 Aug 2024 02:05:56 +0200</pubDate>
<content:encoded><![CDATA[<p>Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:5 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/My-8Ab-D4H8?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>This week, it’s time for security money, our quarterly review of the money of security, including public companies, IPOs, funding rounds and acquisitions from the previous quarter. This quarter, Crowdstrike crashes the index, as Thoma Bravo acquires another index company. The index is currently made up of the following 25 pure play cybersecurity public companies:<br />
<br />
- Secureworks Corp <br />
- Palo Alto Networks Inc<br />
- Check Point Software Technologies Ltd. <br />
- Rubrik Inc <br />
- Gen Digital Inc <br />
- Fortinet Inc <br />
- Akamai Technologies, Inc. <br />
- F5 Inc <br />
- Zscaler Inc <br />
- Onespan Inc <br />
- Leidos Holdings Inc <br />
- Qualys Inc <br />
- Verint Systems Inc. <br />
- Cyberark Software Ltd <br />
- Tenable Holdings Inc <br />
- Darktrace PLC <br />
- SentinelOne Inc <br />
- Cloudflare Inc <br />
- Crowdstrike Holdings Inc <br />
- NetScout Systems, Inc. <br />
- Varonis Systems Inc <br />
- Rapid7 Inc <br />
- Fastly Inc <br />
- Radware Ltd <br />
- A10 Networks Inc<br />
<br />
Visit https://www.securityweekly.com/bsw for all the latest episodes!<br />
<br />
Show Notes: https://securityweekly.com/bsw-360<br/></p>]]></content:encoded>
<enclosure url="https://i.ytimg.com/vi/My-8Ab-D4H8/maxresdefault.jpg" length="0" type="image/jpeg" />
</item>
<item>
<title><![CDATA[Malware-as-a-Service and Ransomware-as-a-Service lower barriers for cybercriminals]]></title>
<description><![CDATA[The sophistication of cyber threats has escalated dramatically, with malicious actors’ deploying advanced tactics, techniques, and procedures (TTPs) to exploit vulnerabilities and evade detection, according to Darktrace. Subscription-based tools such as Malware-as-a-Service (MaaS) and Ransomware-...]]></description>
<link>https://tsecurity.de/de/2269635/it-security-nachrichten/malware-as-a-service-and-ransomware-as-a-service-lower-barriers-for-cybercriminals/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2269635/it-security-nachrichten/malware-as-a-service-and-ransomware-as-a-service-lower-barriers-for-cybercriminals/</guid>
<pubDate>Fri, 09 Aug 2024 06:35:18 +0200</pubDate>
<content:encoded><![CDATA[<p>The sophistication of cyber threats has escalated dramatically, with malicious actors’ deploying advanced tactics, techniques, and procedures (TTPs) to exploit vulnerabilities and evade detection, according to Darktrace. Subscription-based tools such as Malware-as-a-Service (MaaS) and Ransomware-as-a-Service (RaaS) have also lowered the barrier-to-entry for less experienced attackers, making it easier to carry out complex, multistage attacks. “The threat landscape continues to evolve, but new threats often build upon old foundations rather than replacing them. While we have … <a href="https://www.helpnetsecurity.com/2024/08/09/maas-threat-landscape/" rel="nofollow">More <span class="meta-nav">→</span></a></p>
<p>The post <a href="https://www.helpnetsecurity.com/2024/08/09/maas-threat-landscape/">Malware-as-a-Service and Ransomware-as-a-Service lower barriers for cybercriminals</a> appeared first on <a href="https://www.helpnetsecurity.com/">Help Net Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Cybercrime-as-a-Service weiterhin größte Gefahr - Security - connect professional]]></title>
<description><![CDATA[Darktrace hat in seinem neuen „First 6: Half-Year Threat Report 2024“ die größten IT-Gefahren für Unternehmen in der ersten Jahreshälfte 2024 ...]]></description>
<link>https://tsecurity.de/de/2266134/it-security-nachrichten/cybercrime-as-a-service-weiterhin-groesste-gefahr-security-connect-professional/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2266134/it-security-nachrichten/cybercrime-as-a-service-weiterhin-groesste-gefahr-security-connect-professional/</guid>
<pubDate>Wed, 07 Aug 2024 09:20:57 +0200</pubDate>
<content:encoded><![CDATA[Darktrace hat in seinem neuen „First 6: Half-Year Threat Report 2024“ die größten <b>IT</b>-Gefahren für Unternehmen in der ersten Jahreshälfte 2024 ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Malware-as-a-Service Golden Business for Hackers: Darktrace Report]]></title>
<description><![CDATA[By offering pre-packed, plug-and-play malware, the MaaS market has enabled even inexperienced attackers to carry out potentially disruptive attacks regardless of their skill level or technical ability. The post Malware-as-a-Service Golden Business for Hackers: Darktrace Report appeared first on T...]]></description>
<link>https://tsecurity.de/de/2264730/it-nachrichten/malware-as-a-service-golden-business-for-hackers-darktrace-report/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2264730/it-nachrichten/malware-as-a-service-golden-business-for-hackers-darktrace-report/</guid>
<pubDate>Tue, 06 Aug 2024 14:03:04 +0200</pubDate>
<content:encoded><![CDATA[<div><img width="300" height="156" src="https://www.technewsworld.com/wp-content/uploads/sites/3/2023/01/malware-alert-300x156.jpg" class="attachment-medium size-medium wp-post-image" alt="malware alert on computer screen" decoding="async" loading="lazy" srcset="https://www.technewsworld.com/wp-content/uploads/sites/3/2023/01/malware-alert-300x156.jpg 300w, https://www.technewsworld.com/wp-content/uploads/sites/3/2023/01/malware-alert-768x399.jpg 768w, https://www.technewsworld.com/wp-content/uploads/sites/3/2023/01/malware-alert.jpg 1000w" sizes="(max-width: 300px) 100vw, 300px"></div>By offering pre-packed, plug-and-play malware, the MaaS market has enabled even inexperienced attackers to carry out potentially disruptive attacks regardless of their skill level or technical ability. The post <a rel="nofollow" href="https://www.technewsworld.com/story/malware-as-a-service-golden-business-for-hackers-darktrace-report-179312.html?rss=1">Malware-as-a-Service Golden Business for Hackers: Darktrace Report</a> appeared first on <a rel="nofollow" href="https://www.technewsworld.com/?rss=1">TechNewsWorld</a>.]]></content:encoded>
</item>
<item>
<title><![CDATA[Darktrace startet Managed Detection & Response Service für bessere Sicherheitsprozesse]]></title>
<description><![CDATA[Als führendes Unternehmen bei der Anwendung von KI für Cybersicherheit hat Darktrace seit mehr als zehn Jahren die Security-Prozesse für Tausende ...]]></description>
<link>https://tsecurity.de/de/2171454/it-security-nachrichten/darktrace-startet-managed-detection-response-service-fuer-bessere-sicherheitsprozesse/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2171454/it-security-nachrichten/darktrace-startet-managed-detection-response-service-fuer-bessere-sicherheitsprozesse/</guid>
<pubDate>Sat, 08 Jun 2024 12:07:14 +0200</pubDate>
<content:encoded><![CDATA[Als führendes Unternehmen bei der Anwendung von KI für Cybersicherheit hat Darktrace seit mehr als zehn Jahren die <b>Security</b>-Prozesse für Tausende ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Darktrace MDR service improves cyber resilience for organizations]]></title>
<description><![CDATA[Darktrace launched its new service offering, Darktrace Managed Detection & Response (MDR). The service combines detection and response capabilities spanning across the enterprise, with the expertise of its global analyst team. This combination augments internal security teams with AI-powered thre...]]></description>
<link>https://tsecurity.de/de/2168329/it-security-nachrichten/darktrace-mdr-service-improves-cyber-resilience-for-organizations/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2168329/it-security-nachrichten/darktrace-mdr-service-improves-cyber-resilience-for-organizations/</guid>
<pubDate>Thu, 06 Jun 2024 13:52:01 +0200</pubDate>
<content:encoded><![CDATA[<p>Darktrace launched its new service offering, Darktrace Managed Detection &amp; Response (MDR). The service combines detection and response capabilities spanning across the enterprise, with the expertise of its global analyst team. This combination augments internal security teams with AI-powered threat containment and expert alert management across Darktrace environments, allowing them to focus resources on more strategic security efforts, like improving cyber resilience. Over 40% of security leaders cite enhancing and optimizing technology and processes in … <a href="https://www.helpnetsecurity.com/2024/06/06/darktrace-mdr/" rel="nofollow">More <span class="meta-nav">→</span></a></p>
<p>The post <a href="https://www.helpnetsecurity.com/2024/06/06/darktrace-mdr/">Darktrace MDR service improves cyber resilience for organizations</a> appeared first on <a href="https://www.helpnetsecurity.com/">Help Net Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI sets up new safety body in wake of staff departures]]></title>
<description><![CDATA[OpenAI is setting up a new governance body to oversee the safety and security of its AI models, as it embarks on the development of a successor to GPT-4.



The first task for the OpenAI Board’s new Safety and Security Committee will be to evaluate the processes and safeguards around how the comp...]]></description>
<link>https://tsecurity.de/de/2153730/it-security-nachrichten/openai-sets-up-new-safety-body-in-wake-of-staff-departures/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2153730/it-security-nachrichten/openai-sets-up-new-safety-body-in-wake-of-staff-departures/</guid>
<pubDate>Sun, 19 May 2024 04:17:01 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>OpenAI is setting up a new governance body to oversee the safety and security of its AI models, as it embarks on the development of a successor to GPT-4.</p>



<p>The first task for the OpenAI Board’s new Safety and Security Committee will be to evaluate the <a href="https://www.computerworld.com/article/1612082/microsoft-openai-move-to-fend-off-genai-aided-hackers-for-now.html">processes and safeguards</a> around how the company develops future models.</p>



<p>As an aside, the company said in the <a href="https://openai.com/index/openai-board-forms-safety-and-security-committee/" rel="nofollow">blog post announcing the committee’s creation</a> that it “has recently begun training its next frontier model”  and that it anticipates that the resulting systems will “bring us to the next level of capabilities on our path to AGI,” or artificial general intelligence — an AI system whose capabilities match or exceed the human brain in a wide range of tasks.</p>



<p>OpenAI’s creation of a new safety committee at board level follows a string of departures and bad publicity around the company’s attitude to safety, including the dispersal of a “superalignment” team focused on long-term risks led by ex-chief-scientist <a href="https://www.computerworld.com/article/2108395/openai-chief-scientist-ilya-sutskever-is-leaving.html">Ilya Sutskever, who left the company two weeks ago</a>. Sutskever’s departure was followed by that of Jan Leike, who co-led the superalignment team.</p>



<p>The committee will be led by OpenAI CEO Sam Altman, OpenAI chairman Bret Taylor, and fellow board members Adam D’Angelo, Nicole Seligman. Other members will include the OpenAI Head of Preparedness Aleksander Madry, Head of Safety Systems Lilian Weng, Head of Alignment Science John Schulman, Head of Security Matt Knight, and Sutskever’s successor as chief scientist, Jakub Pachocki.</p>



<p>Its first task will be to evaluate how the company is handling AI risks in its development of AI models. In 90 days, it will share its recommendations with the full board of directors. The company said it may later reveal any adopted recommendations “in a manner that is consistent with safety and security.”</p>



<p>With the committee, OpenAI signals that it recognizes the continued concerns the industry and the general public have about AI, and is taking steps internally to monitor itself even as it aims to stay ahead of competitors.</p>



<p>“While we are proud to build and release models that are industry-leading on both capabilities and safety, we welcome a robust debate at this important moment,” it said in the blog post.</p>



<h2 class="wp-block-heading">Pressure mounts on OpenAI</h2>



<p>OpenAI’s unveiling of progress on its next version of GPT is a natural progression for the company as it aims to protect its market lead even as competition heat ups. xAI, the company founded by Tesla leader Elon Musk, recently announced a $6 billion fundraising effort with a $24 billion valuation as Musk aims to challenge the startup he once championed on AI and AGI. Meanwhile, Musk and OpenAI <a href="https://www.computerworld.com/article/1612447/elon-musks-suit-against-openai-right-idea-wrong-messenger.html">remain embroiled</a> in a heated legal dispute.</p>



<p>OpenAI also faced controversy recently when it released a virtual assistant with a voice that some said sounded eerily similar to that of Hollywood actress Scarlett Johannson, even though she did not consent to the company using her voice when asked for her permission several times. Johannson famously voiced an AI system with whom a character played by Joaquim Phoenix falls in love in the 2013 film “Her.”</p>



<p>“As the usage of generative AI increases, associated risks, and security concerns are emerging,” observed Pareekh Jain, CEO of EIIRTrend &amp; Pareekh Consulting. “The Scarlett Johansson incident has heightened OpenAI’s awareness of these risks.”</p>



<h2 class="wp-block-heading">Securing AI can bolster its adoption</h2>



<p>AI security also remains a priority for AI stakeholders at large, with various initiatives being formed at both the government and corporate levels to try to set guidelines for the future development of the technology before it evolves beyond human control.</p>



<p>Just last week, 16 big users and creators of AI, including OpenAI as well as its top competitors Google, Amazon, Meta and xAI as well as frenemy Microsoft, signed up to <a href="https://www.cio.com/article/2119325/big-tech-companies-commit-to-new-safety-practices-for-ai.html">the Frontier AI Safety Commitments</a>, a new set of safety guidelines and development outcomes for the technology.</p>



<p>Demonstrating that AI is secure is essential to companies like OpenAI whose business depend on its widespread adoption. That’s because one of the largest challenges in enterprise and consumer perception of AGI relates to security, according to Jain. This perception “is often influenced by scenarios depicted in science fiction movies,” he said. “Therefore, it is essential to integrate security measures, risk management, and ethical considerations from the design stage, rather than as an afterthought.”</p>



<p>He’s not alone in that believe. Nicole Carignan, vice president of strategic cyber AI at cybersecurity firm Darktrace, said, “The risk AI poses is often in the way it is adopted,” and it’s important to encourage AI leaders to promote its responsible, safe, and secure use. “Broader commitments to AI safety will allow us to move even faster to realize the many opportunities and benefits of AI,” she said.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security Weekly: Security Money: Rubrick Saves The Index As It Continues To Climb - BSW #351]]></title>
<description><![CDATA[Author: Security Weekly - Bewertung: 0x - Views:3 This week, it’s time for security money, our quarterly review of the money of security, including public companies, IPOs, funding rounds and acquisitions from the previous quarter.  This quarter, Rubrick's IPO saves the index, as Cisco finishes th...]]></description>
<link>https://tsecurity.de/de/2141529/it-security-video/security-money-rubrick-saves-the-index-as-it-continues-to-climb-bsw-351/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2141529/it-security-video/security-money-rubrick-saves-the-index-as-it-continues-to-climb-bsw-351/</guid>
<pubDate>Fri, 10 May 2024 13:36:08 +0200</pubDate>
<content:encoded><![CDATA[<p>Author: Security Weekly - Bewertung: 0x - Views:3 <br/></p><p><iframe id="ytplayer" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/-EcTFnE2ycQ?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>This week, it’s time for security money, our quarterly review of the money of security, including public companies, IPOs, funding rounds and acquisitions from the previous quarter.  This quarter, Rubrick's IPO saves the index, as Cisco finishes the acquisition of Splunk.  The index is now made up of the following 25 pure play cybersecurity public companies:

Secureworks Corp
Palo Alto Networks Inc
Check Point Software Technologies Ltd.
Rubrik Inc
Gen Digital Inc
Fortinet Inc
Akamai Technologies, Inc.
F5 Inc
Zscaler Inc
Onespan Inc
Leidos Holdings Inc
Qualys Inc
Verint Systems Inc.
Cyberark Software Ltd
Tenable Holdings Inc
Darktrace PLC
SentinelOne Inc
Cloudflare Inc
Crowdstrike Holdings Inc
NetScout Systems, Inc.
Varonis Systems Inc
Rapid7 Inc
Fastly Inc
Radware Ltd
A10 Networks Inc

Visit https://www.securityweekly.com/bsw for all the latest episodes!

Show Notes: https://securityweekly.com/bsw-351<br/></p>]]></content:encoded>
<enclosure url="https://i.ytimg.com/vi/-EcTFnE2ycQ/maxresdefault.jpg" length="0" type="image/jpeg" />
</item>
<item>
<title><![CDATA[Thoma Bravo kauft Darktrace für 5,3 Milliarden US-Dollar - IT-Markt]]></title>
<description><![CDATA[Die Beteiligungsgesellschaft Thoma Bravo hat angekündigt, den britischen Cybersecurity-Anbieter Darktrace mit seinen mehr als 9400 Kunden für 5,3 ...]]></description>
<link>https://tsecurity.de/de/2114757/it-security-nachrichten/thoma-bravo-kauft-darktrace-fuer-53-milliarden-us-dollar-it-markt/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2114757/it-security-nachrichten/thoma-bravo-kauft-darktrace-fuer-53-milliarden-us-dollar-it-markt/</guid>
<pubDate>Thu, 18 Apr 2024 22:37:09 +0200</pubDate>
<content:encoded><![CDATA[Die Beteiligungsgesellschaft Thoma Bravo hat angekündigt, den britischen Cybersecurity-Anbieter Darktrace mit seinen mehr als 9400 Kunden für 5,3 ...]]></content:encoded>
</item>
<item>
<title><![CDATA[UK Becomes First Country To Ban Default Bad Passwords on IoT Devices]]></title>
<description><![CDATA[The United Kingdom has become the first country in the world to ban default guessable usernames and passwords from these IoT devices. Unique passwords installed by default are still permitted. From a report: The Product Security and Telecommunications Infrastructure Act 2022 (PSTI) introduces new...]]></description>
<link>https://tsecurity.de/de/2112431/it-security-nachrichten/uk-becomes-first-country-to-ban-default-bad-passwords-on-iot-devices/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2112431/it-security-nachrichten/uk-becomes-first-country-to-ban-default-bad-passwords-on-iot-devices/</guid>
<pubDate>Wed, 17 Apr 2024 12:41:22 +0200</pubDate>
<content:encoded><![CDATA[The United Kingdom has become the first country in the world to ban default guessable usernames and passwords from these IoT devices. Unique passwords installed by default are still permitted. From a report: The Product Security and Telecommunications Infrastructure Act 2022 (PSTI) introduces new minimum-security standards for manufacturers, and demands that these companies are open with consumers about how long their products will receive security updates for. 

Manufacturing and design practices mean many IoT products introduce additional risks to the home and business networks they're connected to. In one often-cited case described by cybersecurity company Darktrace, hackers were allegedly able to steal data from a casino's otherwise well-protected computer network after breaking in through an internet-connected temperature sensor in a fish tank. Under the PSTI, weak or easily guessable default passwords such as "admin" or "12345" are explicitly banned, and manufacturers are also required to publish contact details so users can report bugs.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=UK+Becomes+First+Country+To+Ban+Default+Bad+Passwords+on+IoT+Devices%3A+https%3A%2F%2Fnews.slashdot.org%2Fstory%2F24%2F04%2F29%2F142211%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fnews.slashdot.org%2Fstory%2F24%2F04%2F29%2F142211%2Fuk-becomes-first-country-to-ban-default-bad-passwords-on-iot-devices%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://news.slashdot.org/story/24/04/29/142211/uk-becomes-first-country-to-ban-default-bad-passwords-on-iot-devices?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Mega-Deal im Cybersicherheitsmarkt: Thoma Bravo übernimmt Darktrace für 5 Mrd. US-Dollar]]></title>
<description><![CDATA[Cybersecurity. Samstag, 27. April 2024 um 13:13. LONDON, Großbritannien (IT-Times) - Thoma Bravo gab bekannt ...]]></description>
<link>https://tsecurity.de/de/2110441/it-security-nachrichten/mega-deal-im-cybersicherheitsmarkt-thoma-bravo-uebernimmt-darktrace-fuer-5-mrd-us-dollar/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2110441/it-security-nachrichten/mega-deal-im-cybersicherheitsmarkt-thoma-bravo-uebernimmt-darktrace-fuer-5-mrd-us-dollar/</guid>
<pubDate>Mon, 15 Apr 2024 09:58:24 +0200</pubDate>
<content:encoded><![CDATA[Cybersecurity. Samstag, 27. April 2024 um 13:13. LONDON, Großbritannien (<b>IT</b>-Times) - Thoma Bravo gab bekannt ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Thoma Bravo To Take UK Cybersecurity Company Darktrace Private In $5 Billion Deal]]></title>
<description><![CDATA[An anonymous reader quotes a report from TechCrunch: Darktrace is set to go private in a deal that values the U.K.-based cybersecurity giant at around $5 billion. A newly formed entity called Luke Bidco Ltd., formed by private equity giant Thoma Bravo, has tabled an all-cash bid of $7.75 per shar...]]></description>
<link>https://tsecurity.de/de/2109831/it-security-nachrichten/thoma-bravo-to-take-uk-cybersecurity-company-darktrace-private-in-5-billion-deal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2109831/it-security-nachrichten/thoma-bravo-to-take-uk-cybersecurity-company-darktrace-private-in-5-billion-deal/</guid>
<pubDate>Sun, 14 Apr 2024 15:20:26 +0200</pubDate>
<content:encoded><![CDATA[An anonymous reader quotes a report from TechCrunch: Darktrace is set to go private in a deal that values the U.K.-based cybersecurity giant at around $5 billion. A newly formed entity called Luke Bidco Ltd., formed by private equity giant Thoma Bravo, has tabled an all-cash bid of $7.75 per share, which represents a 44% premium on its average price for the three-month period ending April 25. However, this premium drops to just 20% when juxtaposed against Darktrace's closing price Thursday, as the company's shares had risen 20% to 5.18 pounds in the past month.
 
Founded out of Cambridge, U.K., in 2013, Darktrace is best known for AI-enabled threat detection smarts, using machine learning to identify abnormal network activity and attempts at ransomware attacks, insider attacks, data breaches and more. The company claims big-name customers including Allianz, Airbus and the city of Las Vegas. After raising some $230 million in VC funding and hitting a private valuation of $1.65 billion, Darktrace went public on the London Stock Exchange in April 2021, with an opening-day valuation of $2.4 billion. Its shares hit an all-time high later that year of 9.45 pounds and plummeted to an all-time low of 2.29 pounds last February. But they had been steadily rising since the turn of the year and hadn't fallen below 4 pounds since the beginning of March.
 
The full valuation based on Thoma Bravo's offer amounts to $5.3 billion on what is known as a full-diluted basis, which takes into account all convertible securities and is designed to give a more comprehensive view of a company's valuation. However, the enterprise value in this instance is approximately $4.9 billion, which includes additional considerations such as debt and cash positions. [...] The deal is of course still subject to shareholder approval, but the companies said that they expect to complete the transaction by the end of 2024. "The proposed offer represents an attractive premium and an opportunity for shareholders to receive the certainty of a cash consideration at a fair value for their shares," Darktrace chair Gordon Hurst said. "The proposed acquisition will provide Darktrace access to a strong financial partner in Thoma Bravo, with deep software sector expertise, who can enhance the company's position as a best-in-class cyber AI business headquartered in the U.K."<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Thoma+Bravo+To+Take+UK+Cybersecurity+Company+Darktrace+Private+In+%245+Billion+Deal%3A+https%3A%2F%2Fnews.slashdot.org%2Fstory%2F24%2F04%2F26%2F2043204%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fnews.slashdot.org%2Fstory%2F24%2F04%2F26%2F2043204%2Fthoma-bravo-to-take-uk-cybersecurity-company-darktrace-private-in-5-billion-deal%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://news.slashdot.org/story/24/04/26/2043204/thoma-bravo-to-take-uk-cybersecurity-company-darktrace-private-in-5-billion-deal?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Second time lucky for Thoma Bravo, which scoops up Darktrace for $5.3B]]></title>
<description><![CDATA[Analysts brand deal a 'nail in the coffin' for UK tech investment Private equity investor Thoma Bravo has successfully completed a second acquisition attempt of UK-based cybersecurity company Darktrace in a $5.3 billion deal.…]]></description>
<link>https://tsecurity.de/de/2109539/it-security-nachrichten/second-time-lucky-for-thoma-bravo-which-scoops-up-darktrace-for-53b/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2109539/it-security-nachrichten/second-time-lucky-for-thoma-bravo-which-scoops-up-darktrace-for-53b/</guid>
<pubDate>Sun, 14 Apr 2024 08:51:05 +0200</pubDate>
<content:encoded><![CDATA[<h4>Analysts brand deal a 'nail in the coffin' for UK tech investment</h4> <p>Private equity investor Thoma Bravo has successfully completed a second acquisition attempt of UK-based cybersecurity company Darktrace in a $5.3 billion deal.…</p> <p><!--#include virtual='/data_centre/_whitepaper_textlinks_top.html' --></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Darktrace to be Taken Private in $5.3 Billion Sale to Thoma Bravo]]></title>
<description><![CDATA[UK cybersecurity firm Darktace has agreed to sell itself to private equity giant Thoma Bravo for approximately $5.32 million in cash.
The post Darktrace to be Taken Private in $5.3 Billion Sale to Thoma Bravo appeared first on SecurityWeek.]]></description>
<link>https://tsecurity.de/de/2109155/it-security-nachrichten/darktrace-to-be-taken-private-in-53-billion-sale-to-thoma-bravo/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2109155/it-security-nachrichten/darktrace-to-be-taken-private-in-53-billion-sale-to-thoma-bravo/</guid>
<pubDate>Sun, 14 Apr 2024 04:51:21 +0200</pubDate>
<content:encoded><![CDATA[<p>UK cybersecurity firm Darktace has agreed to sell itself to private equity giant Thoma Bravo for approximately $5.32 million in cash.</p>
<p>The post <a href="https://www.securityweek.com/darktrace-to-be-taken-private-in-5-3-billion-sale-to-thoma-bravo/">Darktrace to be Taken Private in $5.3 Billion Sale to Thoma Bravo</a> appeared first on <a href="https://www.securityweek.com/">SecurityWeek</a>.</p>]]></content:encoded>
</item>
</channel>
</rss>
<!-- Generated in 75,81ms -->