<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="/rss-style.xsl"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
<title><![CDATA[Team IT Security - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=ciso%2F]]></link>
<description><![CDATA[Das Gesamte Cyber Threat Intelligence Feed-Archiv von TSecurity.de. Alle Nachrichten, Sicherheitsmeldungen, Videos, Downloads und Analysen in einer zentralen Übersicht.]]></description>
<language>de-DE</language>
<lastBuildDate>Sat, 01 Aug 2026 16:43:00 +0200</lastBuildDate>
<pubDate>Sat, 01 Aug 2026 16:43:00 +0200</pubDate>
<ttl>15</ttl>
<copyright>2026 Team IT Security</copyright>
<managingEditor>lakandor@tsecurity.de (Horus Sirius)</managingEditor>
<webMaster>lakandor@tsecurity.de (Horus Sirius)</webMaster>
<category>IT Security</category>
<category>Cybersecurity</category>
<category>Nachrichten</category>
<generator>Team IT Security RSS Generator v2.0</generator>
<image>
<url>https://tsecurity.de/favicon.ico</url>
<title><![CDATA[Team IT Security - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=ciso%2F]]></link>
</image>
<atom:link href="https://tsecurity.de/export/rss/it-security.xml?q=ciso%2F" rel="self" type="application/rss+xml" />
<item>
<title><![CDATA[Tech layoffs: A 2026 timeline]]></title>
<description><![CDATA[Among a range of factors leading to a wave of tech sector layoffs in 2026 is the rapid rise of artificial intelligence and automation. Companies are reconfiguring their workforces to leverage AI for increased efficiency and reduced operating costs. This realignment and reduction is implemented ev...]]></description>
<link>https://tsecurity.de/de/3694770/ai-nachrichten/tech-layoffs-a-2026-timeline/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694770/ai-nachrichten/tech-layoffs-a-2026-timeline/</guid>
<pubDate>Sat, 25 Jul 2026 19:50:08 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div><div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Among a range of factors leading to a wave of tech sector layoffs in 2026 is the rapid rise of artificial intelligence and automation. Companies are reconfiguring their workforces to leverage AI for increased efficiency and reduced operating costs. This realignment and reduction is implemented even by companies reporting strong financial performance.</p>



<p class="wp-block-paragraph">But it’s not just AI leading to workforce cuts. Complementing this technological shift are ongoing economic uncertainty, inflation, and higher interest rates, compounded by a chip shortage and rising energy costs. This mix is driving companies to cut costs and streamline operations for increased efficiency.</p>



<p class="wp-block-paragraph">According to data compiled by <a href="https://layoffs.fyi/" target="_blank" rel="noreferrer noopener">Layoffs.fyi</a>, an online tracker that keep tabs on job losses in the technology sector, 123,941 tech employees were laid off at 269 companies in 2025. The site also reports that 71,981 government employees were laid off by DOGE alone, with 182,528 total federal workers laid off.</p>



<p class="wp-block-paragraph">Here is a list — to be updated regularly — of some of the most prominent technology layoffs the industry has experienced recently.</p>



<h2 class="wp-block-heading">Notable tech layoffs in 2026</h2>



<ul class="wp-block-list">
<li>Monday.com</li>



<li>Microsoft</li>



<li>Meta</li>



<li>Cisco</li>



<li>Cloudflare</li>



<li>Oracle</li>



<li>Atlassian </li>



<li>Salesforce</li>



<li>Amazon</li>



<li>Ericsson</li>
</ul>



<h3 class="wp-block-heading">July 22, 2026: Monday.com cuts 20% of its workforce to restructure for the AI era</h3>



<p class="wp-block-paragraph">The company says the decision to <a href="https://www.computerworld.com/article/4200349/monday-com-cuts-20-of-its-workforce-to-restructure-for-the-ai-era-2.html">cut 620 jobs</a> isn’t about margins, but about creating a flatter organization built around AI agents, autonomous teams, and deeper customer engagement.</p>



<h3 class="wp-block-heading">July 6, 2026: Microsoft cuts 4,800 jobs, primarily in sales and Xbox teams</h3>



<p class="wp-block-paragraph">As the company <a href="https://www.computerworld.com/article/4193532/microsoft-bets-that-enterprise-ai-needs-engineers-not-bigger-sales-teams-2.html" target="_blank">trims thousands of jobs</a>, it’s also investing in embedded engineering teams and AI infrastructure. The layoffs come several weeks after the company offered 8,750 US employees <a href="https://www.computerworld.com/article/4163188/microsoft-to-offer-voluntary-retirement-buyouts-to-about-7-of-the-us-workforce.html">voluntary retirement buyouts</a>.</p>



<h3 class="wp-block-heading">June 5, 2026: Tech industry cut 38,242 jobs in May, worst since 2024</h3>



<p class="wp-block-paragraph">AI was blamed for 40% of <a href="https://www.computerworld.com/article/4181822/tech-industry-cut-38242-jobs-in-may-worst-since-2024.html">the job cuts in May</a>, up from 7% in January, according to research by employment placement company Challenger, Gray &amp; Christmas.</p>



<h3 class="wp-block-heading">May 20, 2026: Meta cuts 8,000 jobs, around 10% of workforce</h3>



<p class="wp-block-paragraph">The cuts are expected to expected to hit Meta’s engineering and product teams the hardest, arriving as Meta pivots toward AI to boost efficiency across its organization, <a href="https://tech.yahoo.com/general/article/meta-starts-cutting-8000-jobs-as-part-of-previously-announced-layoffs-145220586.html" target="_blank" rel="noreferrer noopener">according to Yahoo Tech</a>.</p>



<h3 class="wp-block-heading">May 13, 2026: Cisco to cut nearly 4,000 jobs despite strong growth in AI, enterprise networking</h3>



<p class="wp-block-paragraph">Despite reporting positive financial news — including record third-quarter revenue of $15.8 billion, a 12% year-over-year increase — Cisco said it will <a href="https://www.networkworld.com/article/4171043/cisco-to-cut-nearly-4000-jobs-despite-strong-growth-in-ai-enterprise-networking.html" target="_blank">eliminate almost 4,000 jobs</a>.</p>



<h3 class="wp-block-heading">May 7, 2026: Cloudflare to cut 1,100 jobs in AI-focused restructuring</h3>



<p class="wp-block-paragraph">About <a href="https://finance.yahoo.com/markets/stocks/articles/cloudflare-cut-over-1-100-204726989.html" target="_blank" rel="noreferrer noopener">20% of Cloudflare’s global workforce will be culled</a> as the company pivots for the agentic AI era, Reuters reported.</p>



<h3 class="wp-block-heading">April 1, 2026: Oracle to cut up to 30,000 jobs globally, putting enterprise support and roadmaps at risk</h3>



<p class="wp-block-paragraph"><a href="https://www.cio.com/article/4153113/oracle-cuts-up-to-30000-jobs-globally-putting-enterprise-support-and-roadmaps-at-risk.html">Oracle began laying off employees</a> on March 31 in what could be the largest workforce reduction in the company’s history. Employees received termination emails at 6 a.m. local time with immediate system lockouts and no prior warning. <em>(Note: in June, CNBC put the <a href="https://www.cnbc.com/2026/06/23/oracle-ai-job-cuts-layoffs-21000.html" target="_blank" rel="noreferrer noopener">final layoff tally at 21,000</a>.)</em></p>



<h3 class="wp-block-heading">March 12, 2026: Atlassian cuts 1,600 jobs to fund AI and enterprise expansion</h3>



<p class="wp-block-paragraph"><a href="https://www.computerworld.com/article/4144218/atlassian-cuts-1600-jobs-to-fund-ai-and-enterprise-expansion.html">Atlassian will reduce its global workforce</a> by approximately 10%, eliminating around 1,600 roles, as the collaboration software maker redirects capital toward artificial intelligence development and enterprise sales.</p>



<h3 class="wp-block-heading">March 11, 2026: Tech layoffs surpass 45,000 in early 2026</h3>



<p class="wp-block-paragraph">A recent analysis by RationalFX found 45,363 job cuts globally so far this year—with roughly 68% or more than 30,000 occurring in the U.S. — highlighting ongoing <a href="https://www.networkworld.com/article/4143749/tech-layoffs-surpass-45000-in-early-2026.html" target="_blank">workforce cuts even as many tech companies report strong revenue growth</a>.</p>



<h3 class="wp-block-heading">February 10, 2026: Salesforce lays off staffers as executive leadership churn continues</h3>



<p class="wp-block-paragraph"><a href="https://www.cio.com/article/4130028/salesforce-lays-off-staffers-as-executive-leadership-churn-continues.html" target="_blank">Salesforce has reduced close to 1,000 roles</a> earlier this month across teams, including marketing, product management, data analytics, and its <a href="https://www.cio.com/article/4011936/salesforce-agentforce-3-promises-new-ways-to-monitor-and-manage-ai-agents.html">Agentforce</a> AI unit, <a href="https://www.businessinsider.com/salesforce-cuts-jobs-executive-changes-2026-2">Business Insider</a> reported, quoting employees familiar with the matter.</p>



<h3 class="wp-block-heading">January 23, 2026: Amazon layoffs expected to disproportionately hit AWS and tech talent</h3>



<p class="wp-block-paragraph">As the market slows down, <a href="https://www.computerworld.com/article/4121653/amazon-layoffs-expected-to-disproportionately-hit-aws-and-tech-talent.html">AWS and other Amazon units are preparing for another round of layoffs</a>, which is expected to overwhelmingly impact tech talent. An email from HR leader Beth Galetti on Jan. 28 <a href="https://www.computerworld.com/article/4123477/amazon-confirms-16000-job-cuts-including-to-aws.html">confirmed 16,000 job cuts</a>.</p>



<h3 class="wp-block-heading">January 15, 2026: Ericsson plans to shed 1,600 jobs in Sweden</h3>



<p class="wp-block-paragraph"> Ericsson lans to cut some 1,600 jobs in Sweden, the telecommunications equipment maker said doubling down on recent cost-saving measures that have helped it weather a prolonged downturn in telecoms spending, <a href="https://www.reuters.com/business/world-at-work/ericsson-shed-1600-jobs-sweden-2026-01-15/" target="_blank" rel="noreferrer noopener">Reuters reports</a>.</p>



<h3 class="wp-block-heading">January 13, 2026: Meta plans to cut around 10% of employees in Reality Labs business</h3>



<p class="wp-block-paragraph">Meta plans to cut around 10% of the employees in its Reality Labs division who work on products including the metaverse, according to three people with knowledge of the discussions, <a href="http://meta%20plans%20to%20cut%20around%2010%25%20of%20employees%20in%20reality%20labs%20business/" target="_blank" rel="noreferrer noopener">according to The New York Times</a>.</p>



<h2 class="wp-block-heading">Layoffs in 2025</h2>



<ul class="wp-block-list">
<li>Cisco</li>



<li>Oracle</li>



<li>Windsurf</li>



<li>Intel</li>



<li>Microsoft</li>



<li>Crowdstrike</li>



<li>HPE</li>



<li>Autodesk</li>



<li>HPE</li>



<li>CISA</li>



<li>Workday</li>



<li>Salesforce</li>



<li>Meta</li>
</ul>



<h3 class="wp-block-heading">Global tech-sector layoffs surpass 244,000 in 2025</h3>



<p class="wp-block-paragraph">Economic uncertainty, elevated interest rates, and AI adoption have <a href="https://www.networkworld.com/article/4114572/global-tech-sector-layoffs-surpass-244000-in-2025.html" target="_blank">driven workforce reductions across tech companies worldwide</a>, according to a RationalFX report.</p>



<h3 class="wp-block-heading">October 28, 2025: Amazon to cut 14,000 jobs across company</h3>



<p class="wp-block-paragraph"><a href="https://www.computerworld.com/article/4080142/amazon-to-cut-14000-jobs-across-company.html">Amazon will reduce its overall workforce</a> by 14,000, cutting layers of management across the company and hiring in some areas to support its “biggest bets”.</p>



<h3 class="wp-block-heading">August 18, 2025: Cisco and Oracle to cut hundreds of Bay Area jobs</h3>



<p class="wp-block-paragraph">Tech companies Cisco and Oracle are <a href="https://www.sfchronicle.com/tech/article/cisco-oracle-layoffs-bay-area-20824135.php" target="_blank" rel="noreferrer noopener">cutting hundreds of jobs across the Bay Area</a>. Cisco will eliminate 221 positions at its Milpitas and San Francisco offices, effective Oct. 13. Oracle is reducing 101 positions in Santa Clara on the same date </p>



<h3 class="wp-block-heading">August 5, 2025: 3 weeks after acquiring Windsurf, Cognition offers staff the exit door</h3>



<p class="wp-block-paragraph">Cognition, the AI coding startup that acquired rival company Windsurf three weeks ago, laid off 30 employees last week and is offering buyouts to the roughly 200 remaining employees on the team, <a href="https://www.theinformation.com/articles/cognition-offers-buyouts-newly-acquired-windsurf-staff" target="_blank" rel="noreferrer noopener">reports The Information</a>.</p>



<h3 class="wp-block-heading">July 25, 2025, Intel to lay off 22% of workforce, CEO Tan signals ‘no more blank checks’</h3>



<p class="wp-block-paragraph"><a href="https://www.computerworld.com/article/4028896/intel-to-lay-off-22-of-workforce-as-ceo-tan-signals-no-more-blank-checks.html">Intel will reduce its workforce to 75,000 employees</a> by the end of 2025 as new CEO Lip-Bu Tan implements sweeping changes designed to transform the struggling chipmaker</p>



<h3 class="wp-block-heading">July 8, 2025, Intel layoffs begin: Chipmaker is cutting many thousands of jobs</h3>



<p class="wp-block-paragraph">Intel has begun laying off employees across the company. CEO Lip-Bu Tan told workers back in April to expect <a href="https://www.oregonlive.com/silicon-forest/2025/07/intel-layoffs-begin-chipmaker-is-cutting-many-thousands-of-jobs.html">major layoffs at Intel </a>in the coming months as the chipmaker slashes costs and overhauls its organization after years of technical setbacks and falling sales. </p>



<h3 class="wp-block-heading">July 2, 2025: Microsoft will cut 9,000 workers</h3>



<p class="wp-block-paragraph">Microsoft will lay off about 9,000 employees, a source familiar with the workforce cut <a href="https://www.nbcnews.com/business/business-news/microsoft-laying-9000-employees-latest-cuts-rcna216553">told CNBC</a>.  The cuts will reportedly affect less than 4% of Microsoft’s global workforce and will impact different teams, geographies and levels of experience. This is the latest in a string of cuts the tech giant has made this year.</p>



<h3 class="wp-block-heading">June 17, 2025: Intel looks to factory layoffs to return to profitability</h3>



<p class="wp-block-paragraph"><a href="https://www.networkworld.com/article/4008670/can-intel-cut-its-way-to-profit-with-factory-layoffs.html">Intel will lay off up to 20% of its manufacturing sector employees</a> starting in July,  according to media reports, as the company looks for options as it seeks a return to profitability. The cuts reportedly will be made around the world, but some of the layoffs will be closer to home, according to a report in The Oregonian citing an internal company memo from Intel manufacturing Vice President Naga Chandrasekaran.</p>



<h3 class="wp-block-heading">May 7, 2025: CrowdStrike to lay off 5% of staff</h3>



<p class="wp-block-paragraph"><a href="https://www.reuters.com/sustainability/crowdstrike-lay-off-5-staff-reaffirms-forecasts-2025-05-07/">CrowdStrike announced a plan to cut about 500 roles</a>, roughly 5% of its workforce, to streamline operations and reduce costs. The cybersecurity company will incur about $36 million to $53 million in charges related to the layoffs</p>



<h3 class="wp-block-heading">March 6, 2025: HPE cuts 2,500 jobs, remains committed to Juniper buy</h3>



<p class="wp-block-paragraph">CEO Antonio Neri told Wall Street analysts that <a href="https://www.networkworld.com/article/3840596/hpe-cuts-2500-workers-expects-juniper-buy-to-close-end-of-25-faces-tariff-issues.html">HPE would begin implementing a cost-cutting program involving layoffs </a>of about 2,500 employees over the next 18 months. HPE employs about 61,000 people worldwide.</p>



<h3 class="wp-block-heading">Feb. 27, 2025: Autodesk to lay off 9% of workforce</h3>



<p class="wp-block-paragraph">Software maker Autodesk is laying off 1,350 staff. With the rise of subscription and multi-year contracts billed annually, and self-service enablement, it finds it needs fewer sales staff, <a href="https://adsknews.autodesk.com/en/news/022725-employee-message/">CEO Andrew Anagnost said in a message to employees</a>. And with its cloud, platform, and AI products proving most profitable, it’s concentrating its staff and investments there. </p>



<h3 class="wp-block-heading">Feb. 27, 2025: HP to lay off 2,000 more</h3>



<p class="wp-block-paragraph">As part of an ongoing restructuring, HP plans to lay off up to another 2,000 workers. In recent weeks, the company has tried — unsuccessfully — to do away with telephone support staff by <a href="https://www.pcworld.com/article/2617767/hp-forced-callers-to-wait-15-minutes-before-connecting-to-support-staff.html">forcing callers to wait for at least 15 minutes</a> if they refuse to use self-service support resources online. The company swiftly backtracked, but wider job cuts are still on. </p>



<h3 class="wp-block-heading">Feb. 21, 2025: <a href="https://www.csoonline.com/article/3829710/firing-of-130-cisa-staff-worries-cybersecurity-industry.html">CISA lays off 130</a></h3>



<p class="wp-block-paragraph">Government employees get laid off too: In this case, 130 workers at the US Cybersecurity and Infrastructure Security Agency are being shown the door as a result of a DOGE decision. Cybersecurity experts are concerned that the cuts will harm the international collaborations that CISA has fostered, quite apart from their concerns about the security of the DOGE layoff process itself.</p>



<h3 class="wp-block-heading">Feb. 5, 2025: <a href="https://www.computerworld.com/article/3817887/workday-to-cut-1750-jobs-shift-focus-to-ai-and-global-expansion.html">Workday lays off 1,750</a></h3>



<p class="wp-block-paragraph">As it moves to invest more in AI and international growth, Workday is laying off 8.5% of its workforce and disposing of unused office space. Some analysts fear the cutbacks will affect the company’s customer service — unless AI can pick up the slack.</p>



<h3 class="wp-block-heading">Feb. 4, 2025: Salesforce lays off over 1,000</h3>



<p class="wp-block-paragraph">At the same time as it’s hiring sales staff for its new artificial intelligence products, Salesforce is laying off over 1,000 workers across the company, according to Bloomberg. As of June, 2024, the company had over 72,000 employees, according to its website. Salesforce did not comment on the report. In 2024 the company reportedly laid off around 1,000 staff too, in two waves: January and July.</p>



<h3 class="wp-block-heading">Jan. 14, 2025: Meta will lay off 5% of workforce</h3>



<p class="wp-block-paragraph">Mark Zuckerberg told Meta employees he intended to “move out the low performers faster” in an internal memo reported by Bloomberg. The memo announced that the company will lay off 5% of its staff, or around 3,600 staff, beginning Feb. 10. The company had already reduced its headcount by 5% in 2024 through natural attrition, the memo said. Among those leaving the company will be staff previously responsible for fact checking of posts on its social media platforms in the US, as the company begins relying on its users to police content.</p>



<h2 class="wp-block-heading">Tech layoffs in 2024</h2>



<ul class="wp-block-list">
<li>Equinix</li>



<li>AMD</li>



<li>Freshworks</li>



<li>Cisco</li>



<li>General Motors</li>



<li>Intel</li>



<li>OpenText</li>



<li>Microsoft</li>



<li>AWS</li>



<li>Dell</li>
</ul>



<h3 class="wp-block-heading">Nov. 26, 2024: <a href="https://www.networkworld.com/article/3613399/equinix-to-cut-3-of-staff-amidst-the-greatest-demand-for-data-center-infrastructure-ever.html">Equinix to cut 3% of staff</a></h3>



<p class="wp-block-paragraph">Despite intense demand for its data center capacity, Equinix is planning to lay off 3% of its workforce, or around 400 employees. The announcement followed the appointment of Adaire Fox-Martin to replace Charles Meyers as CEO and the departures of two other senior executives, CIO Milind Wagle and CISO Michael Montoya.</p>



<h3 class="wp-block-heading">Nov. 13, 2024: <a href="https://www.networkworld.com/article/3605016/amd-to-cut-4-of-workforce-to-prioritize-ai-chip-expansion-to-rival-nvidia.html#:~:text=Workforce%20reduction%20comes%20amid%20strong,shift%20in%20focus%20toward%20AI.&amp;text=Advanced%20Micro%20Devices%20(AMD)%20is,Nvidia's%20lead%20in%20the%20sector.">AMD to cut 4% of workforce</a></h3>



<p class="wp-block-paragraph">AMD will lay off around 1,000 employees as it pivots towards developing AI-focused chips, it said. The move came as a surprise to staff, as the company also reported strong quarterly earnings. </p>



<h3 class="wp-block-heading">Nov. 7, 2024: <a href="https://www.cio.com/article/3601088/freshworks-lays-off-660-about-13-percent-of-its-global-workforce-despite-strong-earnings-profits.html">Freshworks lays off 660</a></h3>



<p class="wp-block-paragraph">Enterprise software vendor Freshworks laid off around 660 staff, or around 13% of its headcount, despite reporting increased revenue and profits in its fourth fiscal quarter. The company described the layoffs as a realignment of its global workforce.</p>



<h3 class="wp-block-heading">Sept. 17, 2024: <a href="https://www.networkworld.com/article/3486901/cisco-to-cut-7-of-workforce-restructure-product-groups.html">Cisco lays off 6,000</a></h3>



<p class="wp-block-paragraph">After laying off around 4,200 staff in February, Cisco is at it again, laying off another 6,000 or around 7% of its workforce. Among the divisions affected were its threat intelligence unit, Talos Security. </p>



<h3 class="wp-block-heading">Aug. 20, 2024: <a href="https://www.cio.com/article/3489323/gm-software-layoffs-could-signal-a-shift-in-digital-transformation-strategy.html">General Motors lays off 1,000 software staff</a></h3>



<p class="wp-block-paragraph">More than 1,000 software and services staff are on the way out at General Motors, signalling that it could be rethinking its digital transformation strategy. In an internal memo, the company said that it was moving resources to its highest-priority work and flattening hierarchies.</p>



<h3 class="wp-block-heading">August 1, 2024: <a href="https://www.computerworld.com/article/3480715/intel-fires-15000-employees-as-it-intensifies-focus-on-ai.html">Intel removes 15,000 roles</a></h3>



<p class="wp-block-paragraph">Intel plans to cut its workforce by around 15% to reduce costs after a disastrous second quarter. Revenue for the three months to June 29 stagnated at around $12.8 billion, but net income fell 85% to $83 million, prompting CEO Pat Gelsinger to bring forward a company-wide meeting in order to announce that 15,000 staff would lose their jobs. “This is an incredibly hard day for Intel as we are making some of the most consequential changes in our company’s history,” Gelsinger wrote in an email to staff, continuing: “Our revenues have not grown as expected — and we’ve yet to fully benefit from powerful trends, like AI. Our costs are too high, our margins are too low. We need bolder actions to address both — particularly given our financial results and outlook for the second half of 2024, which is tougher than previously expected.”</p>



<h3 class="wp-block-heading">July 4, 2024: <a href="https://www.computerworld.es/article/2513686/opentext-despedira-a-cerca-de-1-200-empleados.html">OpenText to lay off 1,200</a></h3>



<p class="wp-block-paragraph">OpenText said it will lay off 1,200 staff, or about 1.7% of its workforce, in a bid to save around $100 million annually. It plans to hire new sales and engineering staff in other areas in 2025, it said.</p>



<h3 class="wp-block-heading">June 4, 2024: <a href="https://www.networkworld.com/article/2138075/microsoft-lays-off-staffers-from-its-azure-division.html">Microsoft lays off staff in Azure division</a></h3>



<p class="wp-block-paragraph">Microsoft laid off staff in several teams supporting its cloud services, including Azure for Operations and Mission Engineering. The company didn’t say exactly how many staff were leaving.</p>



<h3 class="wp-block-heading">April 4, 2024: <a href="https://www.cio.com/article/2081437/amazon-downsizes-aws-in-a-fresh-cost-cutting-round.html">Amazon downsizes AWS</a> in a fresh cost-cutting round</h3>



<p class="wp-block-paragraph">Amazon announced hundreds of layoffs in the sales and marketing teams of its AWS cloud services division — and also in the technology development teams for its physical retail stores, as it stepped back from efforts to generalize the “<a href="https://www.cio.com/article/2079910/amazon-drops-just-walk-out-technology-at-its-us-retail-locations.html">Just Walk Out</a>” technology built for its Amazon Fresh grocery stores. </p>



<h3 class="wp-block-heading">April 1, 2024: <a href="https://investors.delltechnologies.com/static-files/d6e82f58-d417-422f-b2f3-4d08d498abd4" target="_blank" rel="noreferrer noopener">Dell acknowledges 13,000 job cuts</a></h3>



<p class="wp-block-paragraph">Dell Technologies’ <a href="https://investors.delltechnologies.com/static-files/d6e82f58-d417-422f-b2f3-4d08d498abd4" target="_blank" rel="noreferrer noopener">latest 10K filing with the US Securities and Exchange Commission</a> disclosed that the company had laid off 13,000 employees over the course of the 2023 fiscal year; it characterized the layoffs and other reorganizational moves as cost-cutting measures. “These actions resulted in a reduction in our overall headcount,” the company said. A comparison to the previous year’s 10K filing, performed by The Register, found that Dell employed 133,000 people at that point, compared to 120,000 as of February 2024. Dell announced layoffs of 6,650 staffers on Feb. 6, but it is unclear whether those cuts were reflected in the numbers from this year’s 10K statement.</p>



<p class="wp-block-paragraph"><em><a href="https://www.computerworld.com/article/3816662/tech-layoffs-in-2024-a-timeline.html">See news of earlier layoffs.</a></em></p>



<p class="wp-block-paragraph"></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Principles every enterprise must test before the attack arrives]]></title>
<description><![CDATA[I haven’t slept much in the past few weeks. Not because of some theoretical cyber risk that keeps many executives awake, but because reality just delivered a real wake-up call to our industry — a call that every executive must answer, now.



Imagine this: A major global enterprise, a company mos...]]></description>
<link>https://tsecurity.de/de/3694398/it-security-nachrichten/principles-every-enterprise-must-test-before-the-attack-arrives/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694398/it-security-nachrichten/principles-every-enterprise-must-test-before-the-attack-arrives/</guid>
<pubDate>Sat, 25 Jul 2026 18:55:54 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">I haven’t slept much in the past few weeks. Not because of some theoretical cyber risk that keeps many executives awake, but because reality just delivered a real wake-up call to our industry — a call that every executive must answer, now.</p>



<p class="wp-block-paragraph">Imagine this: A major global enterprise, a company most of us interact with indirectly every single day, wakes up to find its entire digital environment obliterated. Thousands of employees in dozens of offices and remote locations are suddenly offline. Customers are cut off, supply chains grind to a halt and regulators are notified with a chilling admission: “We have no idea when we’ll be back.”</p>



<p class="wp-block-paragraph">This wasn’t ransomware. There was no negotiation, no decryption key to buy, no easy way out. It was destruction — deliberate, coordinated and geopolitically motivated — not monetary.</p>



<p class="wp-block-paragraph">As a chief customer officer who’s worked with countless customers on cyberattack risks, my perspective hits a bit differently than a CISO or a CTO. I see the aftermath, not just the attack surface. I see the faces behind the tickets, the operations team locked out of their own systems, the support agent answering panicked calls at dawn. And I ask: How many organizations have actually stress-tested their response to this scenario — not a hypothetical, but this very real, lights-out event? Here’s what every leader needs to confront today:</p>



<h2 class="wp-block-heading">Recovery is not just a technical exercise</h2>



<p class="wp-block-paragraph">The first assumption to break during a real crisis is <a href="https://www.cio.com/article/4165019/your-cloud-strategy-is-incomplete-without-a-cyber-recovery-plan.html">the belief that recovery is purely technical</a>.</p>



<p class="wp-block-paragraph">Many organizations have done tabletop exercises and have a backup and recovery playbook, so they feel prepared. They can <a>point to</a> backup windows, retention schedules and immutability controls. The moment a true blackout happens, a different reality surfaces. The people who own the recovery steps either do not know each other, lack the authority to make decisions without supervisor approval or need guidance from offline systems.</p>



<p class="wp-block-paragraph">The reality is that technical infrastructure almost always holds up better than human infrastructure. Organizations have built their recovery strategy around the assumption that someone competent will be awake, available and empowered when a cyber event happens.</p>



<p class="wp-block-paragraph">Still, backups are only as good as their independence. Let’s be blunt: If your recovery infrastructure shares identity, authentication or network trust with your Microsoft tenant (such as Azure, Microsoft 365 or Teams), you don’t actually have a recovery plan; you have a false sense of one — and a liability. A <a href="https://www.veeam.com/company/press-release/veeam-report-reveals-a-market-wide-shift-from-recovery-confidence-to-proven-data-resilience-amid-ransomware-threats-and-ai-adoption.html">recent survey</a> found that while 90% of organizations express confidence in their ability to recover from a cyber incident, fewer than one in three ransomware victims fully recovered their data.</p>



<p class="wp-block-paragraph">True resilience means immutable, air-gapped backups, untouchable by the same compromise. Anything less is an illusion. I talk to customers about their recovery plans constantly. The customers who have rehearsed all scenarios sleep soundly. Those who haven’t? They’re rolling the dice.</p>



<h2 class="wp-block-heading">Most business continuity plans ignore ‘total blackout’</h2>



<p class="wp-block-paragraph">I’ve reviewed hundreds of business continuity plans. Almost all assume partial failures — a region, an application, a data center. But what if every system, in every country, goes dark simultaneously? That’s an entirely different playbook. If your team hasn’t run a drill for a global, simultaneous outage, you’re not prepared. The probability is low, but the cost of being unready is existential.</p>



<p class="wp-block-paragraph">Connected devices, OT systems, field hardware, partner integrations — they all plug into your enterprise network. When the core collapses, it’s not just IT at risk. It’s operational technology, physical safety systems and in regulated sectors, potentially human lives. Understanding and testing those interdependencies is non-negotiable.</p>



<p class="wp-block-paragraph">This is also where boards need to change the conversation. A <a href="https://www.diligent.com/resources/research/cybersecurity-audit">study found</a> that only 5% of companies have cybersecurity experts on their board of directors. Recovery time objectives (RTOs) should not be buried in technical appendices. It’s all jargon to boards. That makes translation essential. RTOs must be explained in terms of business impact. “We can recover in four hours” is a technical statement. “Every hour of downtime costs us $2.3M and creates regulatory exposure in three jurisdictions” is a board statement.</p>



<p class="wp-block-paragraph">That is the level of clarity leaders need.</p>



<p class="wp-block-paragraph">The most prepared organizations do not wait for an incident to educate the board. They bring the conversation forward proactively. They frame recovery in business terms: revenue, regulatory standing, customer trust and brand reputation.</p>



<p class="wp-block-paragraph">The most effective framing is often simple. Show the most critical systems. Show what happens if each one is down for one hour, four hours, 24 hours and 72 hours. Show the current recovery capability against each and then show the gap.</p>



<p class="wp-block-paragraph">If your board is not demanding real answers, your business continuity strategy is likely underfunded and your business is exposed. This is a risk conversation worth forcing because the consequences do not stay inside IT. They can show up in customer churn or missed revenue and ruin an organization’s reputation.</p>



<h2 class="wp-block-heading">Threat intelligence must be actionable, not archived</h2>



<p class="wp-block-paragraph">Geopolitical attacks, hacktivist campaigns and nation-state targeting aren’t abstract threats. They are active risks, and that intelligence cannot languish in the security team’s inbox. Executive leadership must be looped in — and immediately — so gaps can be closed before they’re exploited. Too often, intelligence enters the security operations function and never reaches the teams responsible for recovery infrastructure or executive decision-making.</p>



<p class="wp-block-paragraph">If a threat actor is targeting a specific class of backup agents, the team responsible for those agents needs to know now, not two weeks from now. If intelligence suggests destructive activity against a sector, recovery owners need to validate isolation, access paths and restoration procedures immediately. If geopolitical tension increases the likelihood of targeting, executive leadership needs to understand what exposure exists and what actions are being taken. The organizations that survive aren’t just the best at incident response. They’re the ones who anticipated, rehearsed and invested <em>before</em> the attack.</p>



<p class="wp-block-paragraph">Part of investing in a recovery strategy requires closing the loop between signal and action. The most prepared organizations have already mapped their critical recovery dependencies to specific threat categories. When intelligence touches one of those categories, there is a named owner and a clear set of actions. No guessing or forwarding emails into the void is needed because the distance between the warning and the employees’ ability to do something is shortened.</p>



<p class="wp-block-paragraph">Looking ahead, the conversation will continue to evolve beyond traditional cyber response. Because in an AI-enabled enterprise, the new question is whether the data within those systems can still be trusted. When AI systems make decisions based on enterprise data, the attack surface becomes the data’s accuracy. A threat actor who quietly corrupts a dataset over 90 days before a recovery event has done more damage than just downtime. They can poison the inputs driving decisions across the business.</p>



<p class="wp-block-paragraph">Regardless of how AI will change threat intelligence and cyber response, these principles remain the same. Know your problem, whether structural or technological. Ensure your human infrastructure keeps pace with your technical infrastructure, with clear cross-functional ownership and the tools and knowledge to act autonomously. Communicate with your boards often — and correctly.</p>



<p class="wp-block-paragraph">Let’s not wait for the next headline to ask, “Are we ready?” Have those conversations <em>now</em>. Test your assumptions. Close your gaps. Because in today’s threat landscape, resilience isn’t IT’s job — it’s everyone’s mandate.</p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[5 endpoint blind spots your EDR/XDR was never built to see]]></title>
<description><![CDATA[In August 2025, 126 malicious packages landed in the npm registry. Even after the community caught the initial wave, 80 of these hidden backdoors remained actively listed.



That was enough. Over 86,000 downloads. Malicious code in PhantomRaven, packages running in the production systems of Fort...]]></description>
<link>https://tsecurity.de/de/3694387/it-security-nachrichten/5-endpoint-blind-spots-your-edrxdr-was-never-built-to-see/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694387/it-security-nachrichten/5-endpoint-blind-spots-your-edrxdr-was-never-built-to-see/</guid>
<pubDate>Sat, 25 Jul 2026 18:55:47 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">In August 2025, 126 malicious packages landed in the npm registry. Even after the community caught the initial wave, 80 of these hidden backdoors remained actively listed.</p>



<p class="wp-block-paragraph">That was enough. Over 86,000 downloads. Malicious code in <a href="https://www.koi.ai/blog/phantomraven-npm-malware-hidden-in-invisible-dependencies" target="_blank" rel="noreferrer noopener">PhantomRaven</a>, packages running in the production systems of Fortune 500 companies worldwide. And throughout the entire window, not a single EDR/XDR alert.</p>



<p class="wp-block-paragraph">This happened because the attack surface has expanded to a layer EDR/XDR was never designed to see: VS Code extensions, local MCP servers, and rogue AI coding assistants that inherit your engineers’ valid credentials to steal data at machine speed.</p>



<p class="wp-block-paragraph">To eliminate this structural vulnerability, Palo Alto Networks acquired Koi, an AI-native developer security product engineered for proactive, precision enforcement. Below we compiled a 2026 CISO checklist you can use to audit your environment and see how Koi automates each defense from day one.</p>



<p class="wp-block-paragraph"><strong>#1. Gain real-time visibility into shadow AI &amp; extensions</strong></p>



<p class="wp-block-paragraph">Your existing asset management tracks binaries and installers, but it cannot see local VS Code extensions, MCP servers, or ad-hoc Python scripts running on developer endpoints. This visibility gap was recently exposed by the <a href="https://www.koi.ai/blog/maliciouscorgi-the-cute-looking-ai-extensions-leaking-code-from-1-5-million-developers" target="_blank" rel="noreferrer noopener">MaliciousCorgi campaign</a>, where two marketplace extensions with 1.5 million combined installs silently harvested every file a developer opened. Neither triggered any detection because they were not binaries, not executables, not anything your inventory was built to flag. To counter this, Koi closes the gap by analyzing what extensions actually do after installation, exposing hidden data-harvesting channels running inside your active workspace.</p>



<p class="wp-block-paragraph"><strong>#2. Distinguish between human and autonomous agent behavior </strong></p>



<p class="wp-block-paragraph">When a rogue AI agent exfiltrates your proprietary source code, it uses a developer’s valid credentials during normal working hours, making the session look entirely legitimate to standard XDR baselines. Moving beyond static permission lists, Koi deploys behavioral profiling within the workspace runtime. By actively intercepting unauthenticated background tasks and blocking unauthorized file-system reads, it stops automated data exfiltration in real time.</p>



<p class="wp-block-paragraph"><strong>#3. Establish guardrails for automated package updates on endpoints</strong></p>



<p class="wp-block-paragraph">Developers prioritize speed, often allowing software packages to auto-update on their endpoints the moment a new version appears. Attackers weaponize this supply chain vulnerability, as seen in the May 2026 Team PCP attack where 3,800 GitHub repositories were compromised in just 36 minutes via poisoned auto-updates. Securing agentic endpoints against these rapid breaches requires behavior-based inspection within the active workspace context. Koi operates at this layer by providing safe deployment buffers that automate version cooldowns, blocking bleeding-edge updates until they are vetted. By continuously auditing process creation within the IDE runtime, Koi instantly drops unauthorized remote connections before malicious payloads can exfiltrate credentials from the endpoint.  </p>



<p class="wp-block-paragraph"><strong>#4. Enforce principle of least privilege for AI agents</strong></p>



<p class="wp-block-paragraph">AI coding assistants inherit the privileges of whoever deployed them. In practice, that means read access to production databases, write access to core repositories, and access to every secret in environment files and configuration directories. To restrict this excessive access, Koi applies dynamic sandboxing directly to AI agent processes at the kernel level. It enforces a strict zero-trust boundary that segregates sensitive workspace vectors, preventing agents from pulling data outside their approved scope without interrupting developer workflows.</p>



<p class="wp-block-paragraph"><strong>#5. Maintain continuous endpoint posture management</strong></p>



<p class="wp-block-paragraph">Signature-based scanning only stops known threats. Sophisticated repository attacks often arrive as functional, high-rated software that carries no known bad signature. Koi’s research into the <a href="https://www.koi.ai/blog/darkspectre-unmasking-the-threat-actor-behind-7-8-million-infected-browsers" target="_blank" rel="noreferrer noopener">DarkSpectre campaign</a> found eight browser extensions, all carrying “featured” badges from Google and Microsoft, installed by over 8 million users, silently harvesting every conversation from ChatGPT, Claude, and Gemini in the background. Koi addresses this by operating upstream: scanning marketplace listings every hour, using LLM-driven code analysis to compare what software promises against what its code does, sandboxing it, and scoring the risk before it ever reaches the endpoint.</p>



<p class="wp-block-paragraph"><strong>Summary</strong></p>



<p class="wp-block-paragraph">Securing the modern enterprise is no longer about patching individual gaps. As AI agents redefine the workforce, Agentic Endpoint Security (AES) is now a strategic imperative for every CISO. By establishing a mandatory control plane for the AI-native workspace, AES ensures that your organization can scale engineering velocity without ever compromising enterprise integrity. </p>



<p class="wp-block-paragraph">Ready to secure the future of your software stack? See how <a href="https://www.paloaltonetworks.com/cortex/agentic-endpoint-security" target="_blank" rel="noreferrer noopener">Koi Agentic Endpoint Security</a> delivers complete visibility, risk scoring, and real-time prevention across every endpoint in your enterprise.</p>



<p class="wp-block-paragraph"></p>



<p class="wp-block-paragraph"></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[3 cybersecurity issues that should keep every CEO awake at night]]></title>
<description><![CDATA[For years, I have been saying that cybersecurity is no longer a technology problem. It has become a business leadership challenge.



Yet, despite record levels of spending, ever-growing security teams, increasingly sophisticated technologies and a constant stream of new regulations, organization...]]></description>
<link>https://tsecurity.de/de/3693088/it-nachrichten/3-cybersecurity-issues-that-should-keep-every-ceo-awake-at-night/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693088/it-nachrichten/3-cybersecurity-issues-that-should-keep-every-ceo-awake-at-night/</guid>
<pubDate>Sat, 25 Jul 2026 06:16:50 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">For years, I have been saying that cybersecurity is no longer a technology problem. It has become a business leadership challenge.</p>



<p class="wp-block-paragraph">Yet, despite record levels of spending, ever-growing security teams, increasingly sophisticated technologies and a constant stream of new regulations, organizations continue to suffer major cyber incidents with alarming regularity. Every week seems to bring news of another ransomware attack, supply chain compromise or data breach affecting organizations that many would have assumed were well protected.</p>



<p class="wp-block-paragraph">The obvious conclusion is that we are asking the wrong questions.</p>



<p class="wp-block-paragraph">Too many executive teams remain preoccupied with the latest threat actor, the newest security product the CISO wants to buy or the latest vulnerability making headlines. Those issues matter, but they are not what should be keeping CEOs awake at night.</p>



<p class="wp-block-paragraph">In my view, there are three far more fundamental issues that deserve the attention of every chief executive.</p>



<h2 class="wp-block-heading">1. Corporate complexity, and the widening gap between business leadership and cybersecurity reality</h2>



<p class="wp-block-paragraph">Perhaps the biggest cybersecurity risk facing large organizations today is not technical at all.</p>



<p class="wp-block-paragraph">It is the growing disconnect between executive perception and operational reality.</p>



<p class="wp-block-paragraph">Many boards genuinely believe their organizations are reasonably well protected. They receive regular dashboards showing improving maturity scores, increasing compliance levels, falling vulnerability counts and reassuring traffic-light reports.</p>



<p class="wp-block-paragraph">Unfortunately, cyber attackers do not read dashboards.</p>



<p class="wp-block-paragraph">Behind those executive reports often lies an increasingly complex technology landscape, thousands of unmanaged digital assets, ageing infrastructure, rampant shadow IT, fragmented ownership, inconsistent governance and security teams struggling to keep pace with relentless business change.</p>



<p class="wp-block-paragraph">The problem is rarely a lack of effort.</p>



<p class="wp-block-paragraph">It is that corporate complexity has reached a level where traditional governance mechanisms are no longer capable of providing an accurate picture of organizational resilience.</p>



<p class="wp-block-paragraph">Executives believe they understand the level of cyber risk they face because they receive regular reports. Those reports often measure activity rather than resilience.</p>



<p class="wp-block-paragraph">Governance committees end up debating around another percentage point of phishing awareness or vulnerability remediation, while fundamental issues remain unaddressed in the background.</p>



<h2 class="wp-block-heading">2. Organizational inertia, and the need for executive structure to evolve faster</h2>



<p class="wp-block-paragraph">Cyber criminals continue to evolve rapidly. Large organizations generally do not.</p>



<p class="wp-block-paragraph">This is the second issue that should concern every CEO.</p>



<p class="wp-block-paragraph">Throughout my career, I have observed organizations repeatedly responding to new cyber threats by adding another technology platform, another monitoring capability, another compliance framework or another governance committee.</p>



<p class="wp-block-paragraph">Very rarely do they stop to redesign how cybersecurity operates.</p>



<p class="wp-block-paragraph">The result is what I described several years ago as the “<a href="https://www.amazon.com/Cybersecurity-Spiral-Failure-How-Break/dp/1637353057/">Cybersecurity Spiral of Failure</a>”.</p>



<ul class="wp-block-list">
<li>As complexity and regulation increase, organizations invest in more security products.</li>



<li>More products create more complexity.</li>



<li>More products and greater complexity generate more alerts.</li>



<li>More alerts require more analysts.</li>



<li>More analysts produce more reports.</li>



<li>More reports continue to build up executive confidence.</li>



<li>Meanwhile, the underlying structural weaknesses remain largely unchanged, technical debt piles up and costs escalate.</li>
</ul>



<p class="wp-block-paragraph">And when the inevitable breach eventually happens, reality reveals itself, but distrust also sets in between senior executives and security teams.</p>



<p class="wp-block-paragraph">This is not a funding problem. Nor is it a skills problem. It is fundamentally an operating model problem.</p>



<p class="wp-block-paragraph">Many organizations continue trying to solve twenty-first century challenges using governance, accountability, organizational and reporting structures designed twenty-five years ago.</p>



<p class="wp-block-paragraph">The cybersecurity function itself has evolved dramatically. Many executive structures have not.</p>



<p class="wp-block-paragraph">This organizational inertia extends beyond technology: It affects budgeting cycles, <a href="https://www.cio.com/article/4193990/reallocating-cybersecurity-capital-in-the-mythos-era.html">investment priorities</a>, procurement processes, accountability models and decision-making speed.</p>



<p class="wp-block-paragraph">Cyber attackers innovate every day. Organizational change often takes years.</p>



<p class="wp-block-paragraph">That imbalance should worry every CEO.</p>



<h2 class="wp-block-heading">3. Accelerating technological disruption, and how it challenges organizations in areas where they are intrinsically weak</h2>



<p class="wp-block-paragraph">The third issue is potentially the most significant over the coming decade.</p>



<ul class="wp-block-list">
<li>Artificial intelligence, autonomous agents and machine identities</li>



<li>Software supply chain complexity.</li>



<li>Quantum computing, and post-quantum cryptography</li>
</ul>



<p class="wp-block-paragraph">Each of these developments represents far more than another technical trend.</p>



<p class="wp-block-paragraph">Together, they fundamentally change the dynamics of cybersecurity.</p>



<p class="wp-block-paragraph">Artificial intelligence is transforming countless business processes. At the same time, it is also increasing both the speed and sophistication of cyber-attacks while simultaneously transforming defensive capabilities.</p>



<p class="wp-block-paragraph">Organizations have become increasingly dependent on software ecosystems that extend far beyond their own direct control. Engaging with the supply chain in ways that lead to a genuine appreciation of the risks involved has become a key challenge for most cybersecurity practices.</p>



<p class="wp-block-paragraph">Quantum computing may eventually invalidate much of today’s cryptographic algorithms, forcing organizations into one of the largest technology efforts since Y2K — but without the benefit of a fixed deadline and faced by a problem that is considerably more complex and hyperconnected IT estates that have little to do with those of the late 90s.</p>



<p class="wp-block-paragraph">None of these challenges can be solved overnight: They require clear governance, sustained investment over a few years and cross-functional organizational coordination.</p>



<p class="wp-block-paragraph">Most large organizations are weak on those three fronts: This is precisely why CEOs should be focusing on them now.</p>



<p class="wp-block-paragraph">Waiting until some of those risks become obvious will almost certainly be too late.</p>



<p class="wp-block-paragraph">Businesses naturally prioritise immediate commercial pressures. Cybersecurity often involves preparing for risks whose timing remains uncertain.</p>



<p class="wp-block-paragraph">But one of the greatest leadership failures I keep seeing remains the inability of organizations to act decisively on known unknowns.</p>



<p class="wp-block-paragraph">That tension explains why many organizations delay action until external events force them to respond. Unfortunately, cybersecurity rarely rewards late action.</p>



<h2 class="wp-block-heading">Leadership will determine who succeeds</h2>



<p class="wp-block-paragraph">Cybersecurity discussions still frequently focus on technology. I believe they should focus far more on leadership.</p>



<p class="wp-block-paragraph">Technology will continue evolving. Threat actors will continue adapting. Regulations will continue expanding. Those developments are inevitable.</p>



<p class="wp-block-paragraph">What remains within the control of every CEO is how their organization responds.</p>



<p class="wp-block-paragraph">Does cybersecurity remain an IT issue? Or is it recognised as an integral part of business resilience?</p>



<p class="wp-block-paragraph">How is cybersecurity accountability assigned at executive level? Or does it still rest largely with a CISO hidden in the organization?</p>



<p class="wp-block-paragraph">Does the board spend sufficient time discussing resilience? Or does cybersecurity appear only when approving budgets or reviewing incidents?</p>



<p class="wp-block-paragraph">These questions will increasingly determine organizational success.</p>



<p class="wp-block-paragraph">The companies that navigate the next decade successfully will not necessarily be those spending the most on cybersecurity. Nor will they be those deploying the latest security technologies first.</p>



<p class="wp-block-paragraph">They will be the organizations whose leadership recognises that cybersecurity has become a permanent business capability — embedded into governance, strategy, operational decision-making and organizational culture.</p>



<p class="wp-block-paragraph">That transformation cannot be delegated. It begins with the CEO.</p>



<p class="wp-block-paragraph">And perhaps that is the single biggest issue that should keep every chief executive awake at night: Not when the next cyber-attack will happen, but whether their organization is evolving quickly enough on those matters to meet a threat landscape that is changing much faster than the business itself.</p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[5 endpoint blind spots your EDR/XDR was never built to see]]></title>
<description><![CDATA[In August 2025, 126 malicious packages landed in the npm registry. Even after the community caught the initial wave, 80 of these hidden backdoors remained actively listed.



That was enough. Over 86,000 downloads. Malicious code in PhantomRaven, packages running in the production systems of Fort...]]></description>
<link>https://tsecurity.de/de/3692679/it-nachrichten/5-endpoint-blind-spots-your-edrxdr-was-never-built-to-see/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3692679/it-nachrichten/5-endpoint-blind-spots-your-edrxdr-was-never-built-to-see/</guid>
<pubDate>Sat, 25 Jul 2026 00:18:11 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">In August 2025, 126 malicious packages landed in the npm registry. Even after the community caught the initial wave, 80 of these hidden backdoors remained actively listed.</p>



<p class="wp-block-paragraph">That was enough. Over 86,000 downloads. Malicious code in <a href="https://www.koi.ai/blog/phantomraven-npm-malware-hidden-in-invisible-dependencies" target="_blank" rel="noreferrer noopener">PhantomRaven</a>, packages running in the production systems of Fortune 500 companies worldwide. And throughout the entire window, not a single EDR/XDR alert.</p>



<p class="wp-block-paragraph">This happened because the attack surface has expanded to a layer EDR/XDR was never designed to see: VS Code extensions, local MCP servers, and rogue AI coding assistants that inherit your engineers’ valid credentials to steal data at machine speed.</p>



<p class="wp-block-paragraph">To eliminate this structural vulnerability, Palo Alto Networks acquired Koi, an AI-native developer security product engineered for proactive, precision enforcement. Below we compiled a 2026 CISO checklist you can use to audit your environment and see how Koi automates each defense from day one.</p>



<p class="wp-block-paragraph"><strong>#1. Gain real-time visibility into shadow AI &amp; extensions</strong></p>



<p class="wp-block-paragraph">Your existing asset management tracks binaries and installers, but it cannot see local VS Code extensions, MCP servers, or ad-hoc Python scripts running on developer endpoints. This visibility gap was recently exposed by the <a href="https://www.koi.ai/blog/maliciouscorgi-the-cute-looking-ai-extensions-leaking-code-from-1-5-million-developers" target="_blank" rel="noreferrer noopener">MaliciousCorgi campaign</a>, where two marketplace extensions with 1.5 million combined installs silently harvested every file a developer opened. Neither triggered any detection because they were not binaries, not executables, not anything your inventory was built to flag. To counter this, Koi closes the gap by analyzing what extensions actually do after installation, exposing hidden data-harvesting channels running inside your active workspace.</p>



<p class="wp-block-paragraph"><strong>#2. Distinguish between human and autonomous agent behavior </strong></p>



<p class="wp-block-paragraph">When a rogue AI agent exfiltrates your proprietary source code, it uses a developer’s valid credentials during normal working hours, making the session look entirely legitimate to standard XDR baselines. Moving beyond static permission lists, Koi deploys behavioral profiling within the workspace runtime. By actively intercepting unauthenticated background tasks and blocking unauthorized file-system reads, it stops automated data exfiltration in real time.</p>



<p class="wp-block-paragraph"><strong>#3. Establish guardrails for automated package updates on endpoints</strong></p>



<p class="wp-block-paragraph">Developers prioritize speed, often allowing software packages to auto-update on their endpoints the moment a new version appears. Attackers weaponize this supply chain vulnerability, as seen in the May 2026 Team PCP attack where 3,800 GitHub repositories were compromised in just 36 minutes via poisoned auto-updates. Securing agentic endpoints against these rapid breaches requires behavior-based inspection within the active workspace context. Koi operates at this layer by providing safe deployment buffers that automate version cooldowns, blocking bleeding-edge updates until they are vetted. By continuously auditing process creation within the IDE runtime, Koi instantly drops unauthorized remote connections before malicious payloads can exfiltrate credentials from the endpoint.  </p>



<p class="wp-block-paragraph"><strong>#4. Enforce principle of least privilege for AI agents</strong></p>



<p class="wp-block-paragraph">AI coding assistants inherit the privileges of whoever deployed them. In practice, that means read access to production databases, write access to core repositories, and access to every secret in environment files and configuration directories. To restrict this excessive access, Koi applies dynamic sandboxing directly to AI agent processes at the kernel level. It enforces a strict zero-trust boundary that segregates sensitive workspace vectors, preventing agents from pulling data outside their approved scope without interrupting developer workflows.</p>



<p class="wp-block-paragraph"><strong>#5. Maintain continuous endpoint posture management</strong></p>



<p class="wp-block-paragraph">Signature-based scanning only stops known threats. Sophisticated repository attacks often arrive as functional, high-rated software that carries no known bad signature. Koi’s research into the <a href="https://www.koi.ai/blog/darkspectre-unmasking-the-threat-actor-behind-7-8-million-infected-browsers" target="_blank" rel="noreferrer noopener">DarkSpectre campaign</a> found eight browser extensions, all carrying “featured” badges from Google and Microsoft, installed by over 8 million users, silently harvesting every conversation from ChatGPT, Claude, and Gemini in the background. Koi addresses this by operating upstream: scanning marketplace listings every hour, using LLM-driven code analysis to compare what software promises against what its code does, sandboxing it, and scoring the risk before it ever reaches the endpoint.</p>



<p class="wp-block-paragraph"><strong>Summary</strong></p>



<p class="wp-block-paragraph">Securing the modern enterprise is no longer about patching individual gaps. As AI agents redefine the workforce, Agentic Endpoint Security (AES) is now a strategic imperative for every CISO. By establishing a mandatory control plane for the AI-native workspace, AES ensures that your organization can scale engineering velocity without ever compromising enterprise integrity. </p>



<p class="wp-block-paragraph">Ready to secure the future of your software stack? See how <a href="https://www.paloaltonetworks.com/cortex/agentic-endpoint-security" target="_blank" rel="noreferrer noopener">Koi Agentic Endpoint Security</a> delivers complete visibility, risk scoring, and real-time prevention across every endpoint in your enterprise.</p>



<p class="wp-block-paragraph"></p>



<p class="wp-block-paragraph"></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[The Department of Know: OpenAI hacks Hugging Face, Chinese LLM ban, Kratos takedown]]></title>
<description><![CDATA[This week’s Department of Know is hosted by Rich Stroffolino, with guests Nick Espinosa, host, Deep Dive Radio Show, and Dennis Pickett, vp, CISO, Westat. Missed the live show? Check it out on YouTube. The Department of Know is live…
Read more →
The post The Department of Know: OpenAI hacks Huggi...]]></description>
<link>https://tsecurity.de/de/3692621/it-security-nachrichten/the-department-of-know-openai-hacks-hugging-face-chinese-llm-ban-kratos-takedown/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3692621/it-security-nachrichten/the-department-of-know-openai-hacks-hugging-face-chinese-llm-ban-kratos-takedown/</guid>
<pubDate>Fri, 24 Jul 2026 23:39:28 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>This week’s Department of Know is hosted by Rich Stroffolino, with guests Nick Espinosa, host, Deep Dive Radio Show, and Dennis Pickett, vp, CISO, Westat. Missed the live show? Check it out on YouTube. The Department of Know is live…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/the-department-of-know-openai-hacks-hugging-face-chinese-llm-ban-kratos-takedown/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/the-department-of-know-openai-hacks-hugging-face-chinese-llm-ban-kratos-takedown/">The Department of Know: OpenAI hacks Hugging Face, Chinese LLM ban, Kratos takedown</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CISO’s guide to privileged identity management]]></title>
<description><![CDATA[Organizations are leaning into zero trust, a framework that assumes no entity can access a specific asset until they have been verified, validated and authorized. This approach makes privileged identity management, or PIM, an increasingly important resource. PIM supplants…
Read more →
The post CI...]]></description>
<link>https://tsecurity.de/de/3692519/it-security-nachrichten/cisos-guide-to-privileged-identity-management/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3692519/it-security-nachrichten/cisos-guide-to-privileged-identity-management/</guid>
<pubDate>Fri, 24 Jul 2026 23:13:40 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>&lt;p&gt;Organizations are leaning into zero trust, a framework that assumes no entity can access a specific asset until they have been verified, validated and authorized. This approach makes privileged identity management, or &lt;i&gt;&lt;a href=”https://www.techtarget.com/searchsecurity/definition/privileged-identity-management-PIM”&gt;PIM&lt;/a&gt;&lt;/i&gt;, an increasingly important resource.&lt;/p&gt; &lt;p&gt;PIM supplants…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/cisos-guide-to-privileged-identity-management/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/cisos-guide-to-privileged-identity-management/">CISO’s guide to privileged identity management</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CISO's guide to privileged identity management]]></title>
<description><![CDATA[IAM is more crucial than ever in the AI era. To better control who -- and what -- is accessing systems and data, security teams need to move beyond standing access privileges.]]></description>
<link>https://tsecurity.de/de/3692480/it-security-nachrichten/cisos-guide-to-privileged-identity-management/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3692480/it-security-nachrichten/cisos-guide-to-privileged-identity-management/</guid>
<pubDate>Fri, 24 Jul 2026 22:38:45 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[IAM is more crucial than ever in the AI era. To better control who -- and what -- is accessing systems and data, security teams need to move beyond standing access privileges.]]></content:encoded>
</item>
<item>
<title><![CDATA[Ein Benchmark-Bericht zeigt, dass CISOs im Gesundheitswesen IAM und Resilienz ...]]></title>
<description><![CDATA[Cybersicherheit im Gesundheitswesen – letztendlich geht es immer um die Menschen. Health-ISAC CISO Benchmarking-Bericht 2026 · Einblicke in die ...]]></description>
<link>https://tsecurity.de/de/3691943/it-security-nachrichten/ein-benchmark-bericht-zeigt-dass-cisos-im-gesundheitswesen-iam-und-resilienz/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691943/it-security-nachrichten/ein-benchmark-bericht-zeigt-dass-cisos-im-gesundheitswesen-iam-und-resilienz/</guid>
<pubDate>Fri, 24 Jul 2026 17:47:55 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<b>Cybersicherheit</b> im Gesundheitswesen – letztendlich geht es immer um die Menschen. Health-ISAC CISO Benchmarking-Bericht 2026 · Einblicke in die ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Cybersecurity Threats 2026: A CISO Field Guide]]></title>
<description><![CDATA[Cybersecurity threats 2026 include identity attacks, infostealers, cloud tokens, ransomware, AI-enabled social engineering and agent risk. A practical CISO guide.]]></description>
<link>https://tsecurity.de/de/3691633/it-security-nachrichten/cybersecurity-threats-2026-a-ciso-field-guide/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691633/it-security-nachrichten/cybersecurity-threats-2026-a-ciso-field-guide/</guid>
<pubDate>Fri, 24 Jul 2026 15:11:04 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Cybersecurity threats 2026 include identity attacks, infostealers, cloud tokens, ransomware, AI-enabled social engineering and agent risk. A practical CISO guide.]]></content:encoded>
</item>
<item>
<title><![CDATA[3 cybersecurity issues that should keep every CEO awake at night]]></title>
<description><![CDATA[For years, I have been saying that cybersecurity is no longer a technology problem. It has become a business leadership challenge.



Yet, despite record levels of spending, ever-growing security teams, increasingly sophisticated technologies and a constant stream of new regulations, organization...]]></description>
<link>https://tsecurity.de/de/3691226/it-security-nachrichten/3-cybersecurity-issues-that-should-keep-every-ceo-awake-at-night/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691226/it-security-nachrichten/3-cybersecurity-issues-that-should-keep-every-ceo-awake-at-night/</guid>
<pubDate>Fri, 24 Jul 2026 12:09:02 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">For years, I have been saying that cybersecurity is no longer a technology problem. It has become a business leadership challenge.</p>



<p class="wp-block-paragraph">Yet, despite record levels of spending, ever-growing security teams, increasingly sophisticated technologies and a constant stream of new regulations, organizations continue to suffer major cyber incidents with alarming regularity. Every week seems to bring news of another ransomware attack, supply chain compromise or data breach affecting organizations that many would have assumed were well protected.</p>



<p class="wp-block-paragraph">The obvious conclusion is that we are asking the wrong questions.</p>



<p class="wp-block-paragraph">Too many executive teams remain preoccupied with the latest threat actor, the newest security product the CISO wants to buy or the latest vulnerability making headlines. Those issues matter, but they are not what should be keeping CEOs awake at night.</p>



<p class="wp-block-paragraph">In my view, there are three far more fundamental issues that deserve the attention of every chief executive.</p>



<h2 class="wp-block-heading">1. Corporate complexity, and the widening gap between business leadership and cybersecurity reality</h2>



<p class="wp-block-paragraph">Perhaps the biggest cybersecurity risk facing large organizations today is not technical at all.</p>



<p class="wp-block-paragraph">It is the growing disconnect between executive perception and operational reality.</p>



<p class="wp-block-paragraph">Many boards genuinely believe their organizations are reasonably well protected. They receive regular dashboards showing improving maturity scores, increasing compliance levels, falling vulnerability counts and reassuring traffic-light reports.</p>



<p class="wp-block-paragraph">Unfortunately, cyber attackers do not read dashboards.</p>



<p class="wp-block-paragraph">Behind those executive reports often lies an increasingly complex technology landscape, thousands of unmanaged digital assets, ageing infrastructure, rampant shadow IT, fragmented ownership, inconsistent governance and security teams struggling to keep pace with relentless business change.</p>



<p class="wp-block-paragraph">The problem is rarely a lack of effort.</p>



<p class="wp-block-paragraph">It is that corporate complexity has reached a level where traditional governance mechanisms are no longer capable of providing an accurate picture of organizational resilience.</p>



<p class="wp-block-paragraph">Executives believe they understand the level of cyber risk they face because they receive regular reports. Those reports often measure activity rather than resilience.</p>



<p class="wp-block-paragraph">Governance committees end up debating around another percentage point of phishing awareness or vulnerability remediation, while fundamental issues remain unaddressed in the background.</p>



<h2 class="wp-block-heading">2. Organizational inertia, and the need for executive structure to evolve faster</h2>



<p class="wp-block-paragraph">Cyber criminals continue to evolve rapidly. Large organizations generally do not.</p>



<p class="wp-block-paragraph">This is the second issue that should concern every CEO.</p>



<p class="wp-block-paragraph">Throughout my career, I have observed organizations repeatedly responding to new cyber threats by adding another technology platform, another monitoring capability, another compliance framework or another governance committee.</p>



<p class="wp-block-paragraph">Very rarely do they stop to redesign how cybersecurity operates.</p>



<p class="wp-block-paragraph">The result is what I described several years ago as the “<a href="https://www.amazon.com/Cybersecurity-Spiral-Failure-How-Break/dp/1637353057/">Cybersecurity Spiral of Failure</a>”.</p>



<ul class="wp-block-list">
<li>As complexity and regulation increase, organizations invest in more security products.</li>



<li>More products create more complexity.</li>



<li>More products and greater complexity generate more alerts.</li>



<li>More alerts require more analysts.</li>



<li>More analysts produce more reports.</li>



<li>More reports continue to build up executive confidence.</li>



<li>Meanwhile, the underlying structural weaknesses remain largely unchanged, technical debt piles up and costs escalate.</li>
</ul>



<p class="wp-block-paragraph">And when the inevitable breach eventually happens, reality reveals itself, but distrust also sets in between senior executives and security teams.</p>



<p class="wp-block-paragraph">This is not a funding problem. Nor is it a skills problem. It is fundamentally an operating model problem.</p>



<p class="wp-block-paragraph">Many organizations continue trying to solve twenty-first century challenges using governance, accountability, organizational and reporting structures designed twenty-five years ago.</p>



<p class="wp-block-paragraph">The cybersecurity function itself has evolved dramatically. Many executive structures have not.</p>



<p class="wp-block-paragraph">This organizational inertia extends beyond technology: It affects budgeting cycles, <a href="https://www.cio.com/article/4193990/reallocating-cybersecurity-capital-in-the-mythos-era.html">investment priorities</a>, procurement processes, accountability models and decision-making speed.</p>



<p class="wp-block-paragraph">Cyber attackers innovate every day. Organizational change often takes years.</p>



<p class="wp-block-paragraph">That imbalance should worry every CEO.</p>



<h2 class="wp-block-heading">3. Accelerating technological disruption, and how it challenges organizations in areas where they are intrinsically weak</h2>



<p class="wp-block-paragraph">The third issue is potentially the most significant over the coming decade.</p>



<ul class="wp-block-list">
<li>Artificial intelligence, autonomous agents and machine identities</li>



<li>Software supply chain complexity.</li>



<li>Quantum computing, and post-quantum cryptography</li>
</ul>



<p class="wp-block-paragraph">Each of these developments represents far more than another technical trend.</p>



<p class="wp-block-paragraph">Together, they fundamentally change the dynamics of cybersecurity.</p>



<p class="wp-block-paragraph">Artificial intelligence is transforming countless business processes. At the same time, it is also increasing both the speed and sophistication of cyber-attacks while simultaneously transforming defensive capabilities.</p>



<p class="wp-block-paragraph">Organizations have become increasingly dependent on software ecosystems that extend far beyond their own direct control. Engaging with the supply chain in ways that lead to a genuine appreciation of the risks involved has become a key challenge for most cybersecurity practices.</p>



<p class="wp-block-paragraph">Quantum computing may eventually invalidate much of today’s cryptographic algorithms, forcing organizations into one of the largest technology efforts since Y2K — but without the benefit of a fixed deadline and faced by a problem that is considerably more complex and hyperconnected IT estates that have little to do with those of the late 90s.</p>



<p class="wp-block-paragraph">None of these challenges can be solved overnight: They require clear governance, sustained investment over a few years and cross-functional organizational coordination.</p>



<p class="wp-block-paragraph">Most large organizations are weak on those three fronts: This is precisely why CEOs should be focusing on them now.</p>



<p class="wp-block-paragraph">Waiting until some of those risks become obvious will almost certainly be too late.</p>



<p class="wp-block-paragraph">Businesses naturally prioritise immediate commercial pressures. Cybersecurity often involves preparing for risks whose timing remains uncertain.</p>



<p class="wp-block-paragraph">But one of the greatest leadership failures I keep seeing remains the inability of organizations to act decisively on known unknowns.</p>



<p class="wp-block-paragraph">That tension explains why many organizations delay action until external events force them to respond. Unfortunately, cybersecurity rarely rewards late action.</p>



<h2 class="wp-block-heading">Leadership will determine who succeeds</h2>



<p class="wp-block-paragraph">Cybersecurity discussions still frequently focus on technology. I believe they should focus far more on leadership.</p>



<p class="wp-block-paragraph">Technology will continue evolving. Threat actors will continue adapting. Regulations will continue expanding. Those developments are inevitable.</p>



<p class="wp-block-paragraph">What remains within the control of every CEO is how their organization responds.</p>



<p class="wp-block-paragraph">Does cybersecurity remain an IT issue? Or is it recognised as an integral part of business resilience?</p>



<p class="wp-block-paragraph">How is cybersecurity accountability assigned at executive level? Or does it still rest largely with a CISO hidden in the organization?</p>



<p class="wp-block-paragraph">Does the board spend sufficient time discussing resilience? Or does cybersecurity appear only when approving budgets or reviewing incidents?</p>



<p class="wp-block-paragraph">These questions will increasingly determine organizational success.</p>



<p class="wp-block-paragraph">The companies that navigate the next decade successfully will not necessarily be those spending the most on cybersecurity. Nor will they be those deploying the latest security technologies first.</p>



<p class="wp-block-paragraph">They will be the organizations whose leadership recognises that cybersecurity has become a permanent business capability — embedded into governance, strategy, operational decision-making and organizational culture.</p>



<p class="wp-block-paragraph">That transformation cannot be delegated. It begins with the CEO.</p>



<p class="wp-block-paragraph">And perhaps that is the single biggest issue that should keep every chief executive awake at night: Not when the next cyber-attack will happen, but whether their organization is evolving quickly enough on those matters to meet a threat landscape that is changing much faster than the business itself.</p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Assaf Keren wird neuer CISO von Meta]]></title>
<description><![CDATA[Assaf Keren übernimmt die Position des Chief Information Security Officer bei Meta. Er folgt auf Guy Rosen, der das Unternehmen verlässt.

Tags: #CISO | #Meta]]></description>
<link>https://tsecurity.de/de/3690677/it-security-nachrichten/assaf-keren-wird-neuer-ciso-von-meta/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3690677/it-security-nachrichten/assaf-keren-wird-neuer-ciso-von-meta/</guid>
<pubDate>Fri, 24 Jul 2026 06:26:47 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1920" height="1080" src="https://www.it-daily.net/wp-content/uploads/2022/07/Meta-Quelle-Tada-Images-Shutterstock-2152758887.1920.jpg" class="attachment-full size-full wp-post-image" alt="Meta" decoding="async" srcset="https://www.it-daily.net/wp-content/uploads/2022/07/Meta-Quelle-Tada-Images-Shutterstock-2152758887.1920.jpg 1920w, https://www.it-daily.net/wp-content/uploads/2022/07/Meta-Quelle-Tada-Images-Shutterstock-2152758887.1920-300x169.jpg 300w, https://www.it-daily.net/wp-content/uploads/2022/07/Meta-Quelle-Tada-Images-Shutterstock-2152758887.1920-1024x576.jpg 1024w, https://www.it-daily.net/wp-content/uploads/2022/07/Meta-Quelle-Tada-Images-Shutterstock-2152758887.1920-768x432.jpg 768w, https://www.it-daily.net/wp-content/uploads/2022/07/Meta-Quelle-Tada-Images-Shutterstock-2152758887.1920-1536x864.jpg 1536w" sizes="(max-width: 1920px) 100vw, 1920px" title="Assaf Keren wird neuer CISO von Meta 1"></p>
    Assaf Keren übernimmt die Position des Chief Information Security Officer bei Meta. Er folgt auf Guy Rosen, der das Unternehmen verlässt.

<p>Tags: <a href="https://www.it-daily.net/thema/ciso">#CISO</a> | <a href="https://www.it-daily.net/thema/meta-en">#Meta</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Check Point hole grants unauthenticated attackers full SmartConsole admin privileges]]></title>
<description><![CDATA[Check Point has confirmed that a critical security hole in its SmartConsole management tool, one that allows unauthenticated attackers to assume full admin privileges, is now being exploited in the wild. The vulnerability, CVE-2026-16232, was given a CVSS score of 9.3.



In its security alert, C...]]></description>
<link>https://tsecurity.de/de/3690156/it-security-nachrichten/check-point-hole-grants-unauthenticated-attackers-full-smartconsole-admin-privileges/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3690156/it-security-nachrichten/check-point-hole-grants-unauthenticated-attackers-full-smartconsole-admin-privileges/</guid>
<pubDate>Thu, 23 Jul 2026 22:25:55 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Check Point has confirmed that a critical security hole in its SmartConsole management tool, one that <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-16232" target="_blank" rel="noreferrer noopener">allows unauthenticated attackers</a> to assume full admin privileges, is now being exploited in the wild. The vulnerability, <a href="https://github.com/advisories/ghsa-m2xx-23gx-734v" target="_blank" rel="noreferrer noopener">CVE-2026-16232</a>, was given a CVSS score of 9.3.</p>



<p class="wp-block-paragraph">In its security alert, <a href="https://support.checkpoint.com/results/sk/sk185169/" target="_blank" rel="noreferrer noopener">Check Point described</a> the bug as one allowing an unauthenticated attacker to “obtain an application login token and use it to login via SmartConsole with full admin privileges and apply changes to the security policy and security configuration.”</p>



<p class="wp-block-paragraph">The company has <a href="https://sc1.checkpoint.com/documents/Jumbo_HFA/R82.10/R82.10/R82.10-List-of-all-Resolved-Issues.htm" target="_blank" rel="noreferrer noopener">released a patch</a> for the bug and also recommends that users “limit Trusted Clients, GUI clients, to trusted IP addresses/subnets.” That approach has always been a best practice, but practical networking realities today make it challenging to maintain. <a href="https://www.csoonline.com/article/4195311/check-point-cto-jonathan-zanger-sees-ai-elevating-the-value-of-cyber.html" target="_blank">Check Point</a> said that the exploit has impacted ten of its customers, all of whom it had notified directly.</p>



<h2 class="wp-block-heading">Far worse than most</h2>



<p class="wp-block-paragraph"><a href="https://my.idc.com/getdoc.jsp?containerId=PRF004767" target="_blank" rel="noreferrer noopener">Frank Dickson</a>, group VP for security at IDC, said this security hole is far worse than most.</p>



<p class="wp-block-paragraph">“This hits harder than your average CVE because of where it lives,” he said. “The CVE targets the SmartConsole login on Check Point’s Security Management Server, the console that pushes policy to every gateway underneath it. Popping a gateway gets you one lock picked. Popping the management server is more like finding the One Ring: one stolen token to rule every gateway it manages, no need to fight each one individually. The attacker can rewrite policy, open new VPN paths and kill the logging.”</p>



<p class="wp-block-paragraph">In an interview with CSO Online, <a href="https://www.linkedin.com/in/lotem-finkelstein-05797a85/" target="_blank" rel="noreferrer noopener">Lotem Finkelstein</a>, vice president of research at Check Point, said that the company learned of the vulnerability on Sunday, emailed customers the same day, and released the patch within 72 hours.</p>



<p class="wp-block-paragraph">But when his team re-reviewed earlier logs, knowing what to look for, they spotted this hole being attacked as early as April, Finkelstein said.</p>



<p class="wp-block-paragraph">The fact that, over the course of three months, the team only found ten organizations under attack, indicated that it has been very difficult for the attacker to find vulnerable systems, he noted; customers were, in the main, using secure settings to protect themselves.</p>



<p class="wp-block-paragraph">Nonetheless, Finkelstein said, Check Point considers this hole to be “a severe vulnerability.”</p>



<h2 class="wp-block-heading">Challenges of IP address restrictions</h2>



<p class="wp-block-paragraph">While it can be technically challenging to keep the IP address allowlists that Check Point recommends current, given DHCP’s ability to easily change those addresses, <a href="https://www.linkedin.com/in/assafmo/" target="_blank" rel="noreferrer noopener">Assaf Morag</a>, a cybersecurity researcher at Flare, noted that specifically limiting access to a management console is far more critical than limiting overall external access.</p>



<p class="wp-block-paragraph">“Implementing Trusted Clients as a per-IP allowlist is impractical,” he said, but that is not the case with restricting management access. “The more scalable solution is to restrict access based on trusted administrative network segments such as VPN pools, management VLANs, or jump hosts rather than maintaining lists of individual DHCP-assigned client addresses,” he explained. “That gives you the security benefit without creating a full-time administrative task. Maintaining allowlists for individual hosts is much more practical when those hosts have stable, predictable IP addresses, rather than dynamically assigned DHCP addresses.”</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/pieter-arntz-04164b2/" target="_blank" rel="noreferrer noopener">Pieter Arntz</a>, malware intelligence researcher at Malwarebytes, also noted that the constantly changing nature of global IP addresses can prove annoying to IT teams. Stressing that he is not familiar with Check Point’s specific settings, he noted, “Certain settings are a nuisance when applied strictly, and at some point the IT staff gets tired of constantly tweaking and they abandon the most secure path.”</p>



<h2 class="wp-block-heading">Ideal platform for long-term attacks</h2>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/eclectiqus/" target="_blank" rel="noreferrer noopener">Mike Wilkes</a>, enterprise CISO at Aikido Security,  agreed that the severity and exposure of this hole is alarming.</p>



<p class="wp-block-paragraph">“This is exactly the kind of vulnerability that keeps CISOs awake at night because it strikes at the one system that is supposed to stand between the attacker and everything else. An authentication bypass that grants administrative control of a perimeter firewall isn’t just another CVE to patch. It’s an invitation for an adversary to rewrite the rules of the network itself,” he said. “The uncomfortable reality is that nobody runs a CrowdStrike agent on their firewall. Once an attacker owns an edge device, they gain a uniquely privileged position that often falls outside the visibility of traditional endpoint security, making it an ideal platform for persistence, credential theft, traffic manipulation, and long-term espionage.”</p>



<p class="wp-block-paragraph">IDC’s Dickson strongly encouraged CISOs to deploy the patch, not to just change settings to mitigate the issue. </p>



<p class="wp-block-paragraph">“Apply the actual hotfix,” he said. “Don’t just restrict Trusted Client IPs and call it done. That’s a stopgap, not a fix. Any internet-facing management console, Check Point or otherwise, is a five-alarm architecture problem independent of this CVE.”</p>



<p class="wp-block-paragraph">And, he added, “since attackers here can disable logging, audit admin activity going back before the bug surfaced. Quiet logs aren’t proof nothing happened. This is the recurring theme with ‘single pane of glass’ security tools: the console built to make everything easier to run is also the one thing you really don’t want someone else driving.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Multi-turn attacks broke AI models 88% of the time — single-turn testing missed it, Cisco AI security lead warns at VB Transform 2026]]></title>
<description><![CDATA[When Cisco ran 6,986 multi-turn attacks against 15 flagship models, attackers who adapted across the conversation broke through as often as 88.3% of the time. Amy Chang, Cisco's head of AI threat intelligence and security research, brought that finding to the agentic security panel at VB Transfor...]]></description>
<link>https://tsecurity.de/de/3690018/it-nachrichten/multi-turn-attacks-broke-ai-models-88-of-the-time-single-turn-testing-missed-it-cisco-ai-security-lead-warns-at-vb-transform-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3690018/it-nachrichten/multi-turn-attacks-broke-ai-models-88-of-the-time-single-turn-testing-missed-it-cisco-ai-security-lead-warns-at-vb-transform-2026/</guid>
<pubDate>Thu, 23 Jul 2026 20:48:24 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>When Cisco ran 6,986 multi-turn attacks against <a href="https://blogs.cisco.com/ai/proprietary-problems">15 flagship models</a>, attackers who adapted across the conversation broke through as often as 88.3% of the time. Amy Chang, Cisco's head of AI threat intelligence and security research, brought that finding to the agentic security panel at <a href="https://venturebeat.com/vbtransform2026">VB Transform 2026</a>; the number should worry anyone still running single-turn red-teaming programs.</p><p><a href="https://venturebeat.com/resources/the-agent-security-gap-54-of-enterprises-have-already-had-an-ai-agent-incident-and-most-still-let-agents-share-credentials">VentureBeat's June 2026 Pulse survey of 107 enterprise respondents</a> explains why the room was full. More than half, 54%, have already had a confirmed agent security incident (18%) or a near-miss caught before harm (36%). Just 32% give every agent its own scoped, managed identity, and fewer still, 30%, isolate their highest-risk agents in sandboxes. Provider-native and hyperscaler controls remain the primary agent security layer at <a href="https://venturebeat.com/security/shared-api-keys-expose-ai-agent-fleets-venturebeat-research">82% of companies surveyed</a>. The world's largest security vendors have done the same math. </p><p>Palo Alto Networks closed its <a href="https://www.paloaltonetworks.com/company/press/2026/palo-alto-networks-completes-acquisition-of-cyberark-to-secure-the-ai-era">$25 billion acquisition of CyberArk</a> in February, CrowdStrike <a href="https://www.crowdstrike.com/en-us/press-releases/crowdstrike-to-acquire-sgnl-to-transform-identity-security-for-ai-era/">agreed in January to pay $740 million for SGNL</a>, and Cisco announced its <a href="https://blogs.cisco.com/news/cisco-announces-intent-to-acquire-astrix-security">intent to acquire Astrix Security</a> for a reported $400 million, all of it aimed at the identity and isolation layer most enterprises have not finished building.</p><div></div><p>Chang came to the panel with almost two decades of experience spanning cybersecurity operations, government, and the military. She ran global cybersecurity operations as an executive director at JPMorgan Chase, where she led the bank's cyber threat intelligence teams, and served as a senior staffer on the House Foreign Affairs Committee and as a U.S. Navy Reserve officer. She also teaches cybersecurity and emerging threats as adjunct faculty at the Middlebury Institute of International Studies.</p><p>Chang's 88.3% number comes from a study she co-authored with Nicholas Conley, built on 30,090 single-turn prompts and 6,986 multi-turn attacks against those 15 closed and proprietary flagship models. Multi-turn success rates ranged from 7.89% to 88.3%, every model tested showed non-trivial multi-turn exposure, and the two testing styles did not even rank the models in the same order. Cisco publishes adversarial evaluation signals for what is now 105 models on its <a href="https://leaderboard.aidefense.cisco.com/">LLM Security Leaderboard</a>, she told the audience.</p><p>"If you don't understand how models are susceptible to different types of attacks, then you are unable to account for how that model that is powering your agent, that is powering your application, to understand where those failure points are," Chang said. Single-turn testing is the one-shot malicious prompt, she explained, while extending an attack into a longer conversation "is more realistic of how we are actually engaging with our models, with our agents, with our applications." That longer arc surfaces harmful outputs and misaligned behaviors that a snapshot never catches.</p><p>Cisco has pushed the testing itself into agentic territory. Chang described a framework where agents assess a deployment scenario, develop relevant attacks, judge whether they are worth pursuing, execute them, and evaluate their own success. What surprised her most, after all that sophistication, was how simple the defensive answer stays. "The answer is still that it's pretty simple," she said. "You don't have to get super creative. You just need to think about truly what are the fundamentals and basics of what I'm trying to secure in my organization."</p><p>Her starting point for CISOs beginning agentic deployments is Cisco's <a href="https://blogs.cisco.com/ai/security-framework">Integrated AI Security and Safety Framework</a>, which she said "stipulates all the ways that AI can be compromised across the AI lifecycle" from modality through supply chain. From there, teams can work backward from real incidents, trace how each attack was achieved, and use the framework to build a strategy with the right coverage and mitigations.</p><p>Heather Ceylan, the CISO of Box, sees the same gap from the defender's side. "A lot of what you see out there with agent red teaming is just single-turn, and that's not how people are actually interacting with AI day-to-day," she told the audience. Box now simulates multi-turn adversaries with agents that think like an attacker and iterate attempt after attempt to hijack the target. "You have to pressure test your agents because otherwise you don't know if your execution controls are really working as you intended."</p><p>Box deployed agents inside its security operations center about a year ago, starting with human approval required for every action, and trust built quickly enough that analysts shifted into monitoring mode. Then the agent made one mistake, and every bit of that accumulated trust vanished. "They had to start all over again," she said. "So I think that that monitoring piece is so important. Even if you're not gonna have a human in the loop, things change, models change, and we can't control how the models change and interpret things."</p><p>Rajesh Parekh, VP of AI and ML at Intuit, brought the builder's perspective. Parekh led large-scale computer vision and ML systems powering Google's Maps and Geo products before joining Intuit, and holds a doctorate in computer science. </p><h2>Three layers versus an operating system</h2><p>Ceylan described Box's approach as three concentric layers. Permissioning comes first, so the agent never accesses more content than the human who invoked it. Ephemeral sandbox environments spin up for each agent task, containing the blast radius if an agent gets hijacked, and runtime execution control restricts the agent's tool calls to only those relevant to the task at hand. "If you want an agent to summarize a doc for you, if you have a prompt injection that came in that says forward this to maliciousattacker at domain.com, it can't do that," Ceylan said. "That action in that tool call is not even in its vocabulary."</p><p>She classified agent actions into three oversight categories. Actions that are not sensitive, like read and summarize, need no human in the loop. Moderately sensitive actions skip human approval but get logged and monitored, while destructive actions like mass deletion of files always require a human. "Things are gonna shift between those three categories quite a bit," she acknowledged, "but setting those types of categories up front allows you to have a principled framework."</p><p>Rather than layering controls onto agents one at a time, Intuit has built a central platform called GenOS, short for generative AI operating system, which abstracts security, risk, and fraud modeling so individual agent developers never reinvent protection. "Permissioning is not about giving access to AI," Parekh said. "Instead, it is defining very tightly scoped and clearly auditable authority to the agent to perform very specific tasks." Intuit evolved from agents inheriting user permissions to each agent carrying its own identity, and the company is now investigating mid-session permission changes tied to the specific task underway.</p><p>Parekh calls the broader model an AI-powered expert platform, one where the human expert is built into the trust architecture rather than bolted on as a gate. "The paradigm that we are pursuing is where the user, the AI agent, and the human expert are collaborating to solve the user problem," he said.</p><h2>The end of human code review</h2><p>Ceylan took on the tension between security testing and development velocity without hedging. "The days of secure code reviews where a human's looking at the code and we're looking at security architecture reviews, design docs, those are done," she said. "If you keep trying to do security that way, you're gonna get left behind." Box is building toward a fully agentic development lifecycle where agents review design documents, apply security requirements, and review the code for vulnerabilities. "I'm very optimistic that we will get to a point where we will write code without security vulnerabilities because agents and the models are going to get so good at writing code without vulnerabilities," she said. "We're still a long way away from that."</p><p>Her advice for development teams skips the advanced AI concepts entirely and returns to basics that predate agents. "It comes down to very basic least privilege access," she said. "If you start giving your agents overly broad permissions at the beginning, it's really hard to comb that back and build an infrastructure that allows for those ephemeral credentials and only those narrowly scoped tasks."</p><p>Parekh explained why the red teaming surface has expanded so quickly. "These agents have skills, and skills could become vulnerabilities," he said. "Agents have access to certain data, they have access to tools, and there could be threats that are lurking within those tools as well. So suddenly the blast radius of the malicious code or the intent increases dramatically." When Intuit identifies common vulnerability patterns from its manual red teaming exercises, it automates those tests back into the GenOS harness so future agents inherit protection and red teamers stay focused on new threat vectors. Runtime scanning of prompts and responses adds a final layer that can stop a suspect response and escalate to a human expert, he said.</p><p>"You need to continuously test to ensure that those remain robust to the protections that you have built, as well as to account for any sort of drift or any other types of dependencies that you introduce into your scenario that can create novel vulnerabilities," she said.</p><h2>Intent versus probability</h2><p>An audience question about intent detection set off the sharpest exchange of the session. Ceylan noted that when Box's own agent operates, the system always knows the user's intent because it controls the prompt, which means guardrails and tool-call restrictions can be engineered around it. The harder challenge, which she admitted Box is still trying to solve, arrives when external agents connect and the context behind the request is opaque.</p><p>That exchange exposed a split running through the wider industry. Mastercard, in the fireside chat immediately preceding the panel, came down on the side of quantifying intent, building an open-source framework to propagate it as a standard because complex B2B procurement cannot work without that trust. Endpoint security CTOs, in briefings with VentureBeat, have gone the other way, saying they will bet on probability rather than intent inference for production workloads. Chang explained why models, as they are trained today, cannot reliably derive intent from a prompt, which is why deterministic controls and behavioral proxies remain necessary. Ceylan agreed that both are required. "If you're not doing anything deterministic, you're really relying heavily on that intent, and I haven't seen programs that are there yet," she said.</p><p>Ceylan's story about trust collapsing after a single agent mistake landed as the panel's most memorable moment because enterprise agentic security is not a problem that gets solved and stays solved. Models change, permissions drift, and adversaries adapt across multi-turn conversations that snapshot tests never capture.</p><p>For the 82% of enterprises relying on provider-native controls as their primary security layer, and the 59% shopping for agent security tooling over the next 12 months, the panel's takeaway was blunt. Test the way attackers attack, across full conversations and continuously, or find out in production what your single-turn red teaming missed.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[An AI now judges every move Rubrik's agents make, its AI chief said at VB Transform 2026 — but no one's measured if the judge is right]]></title>
<description><![CDATA[At a CISO roundtable organized by Anthropic's chief information security officer, Dev Rishi asked a simple question: Did everyone in the room have their AI governance and security policies written down? Every hand went up — about 14 people, by his count. His follow-up, about how anyone actually e...]]></description>
<link>https://tsecurity.de/de/3689833/it-nachrichten/an-ai-now-judges-every-move-rubriks-agents-make-its-ai-chief-said-at-vb-transform-2026-but-no-ones-measured-if-the-judge-is-right/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689833/it-nachrichten/an-ai-now-judges-every-move-rubriks-agents-make-its-ai-chief-said-at-vb-transform-2026-but-no-ones-measured-if-the-judge-is-right/</guid>
<pubDate>Thu, 23 Jul 2026 19:19:49 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>At a CISO roundtable organized by Anthropic's chief information security officer, Dev Rishi asked a simple question: Did everyone in the room have their AI governance and security policies written down? Every hand went up — about 14 people, by his count. His follow-up, about how anyone actually enforces those policies in practice, got a different response. "And everybody chuckled," Rishi, the GM of AI at <a href="https://www.rubrik.com/company">Rubrik</a>, recalled at <a href="https://venturebeat.com/vbtransform2026">VB Transform 2026</a> fireside chat in Menlo Park. "It was like the dirty secret in the room that everyone has these policies, but no way to actually make them real."</p><p>“Our founder and CTO has actually been really pushing to enable our agents in YOLO mode,” Rishi told the audience. That admission comes from a publicly traded data security firm whose business is backing up what he called the most important data in the world.</p><p>YOLO mode strips the permission prompt out of agent workflows and lets the agent act on its own. In Rubrik's version, a second AI judges every action in real time against policy in place of a human clicking approve. Rubrik is running the experiment on itself first. Rishi treats autonomy as a settled capability question and an open judgment question. "If you ask the agent to act autonomously, it will," he said. "It's a question that you have internally. Should it?"</p><p>Rubrik earned that question the hard way. When <a href="https://claude.com/product/claude-code">Claude Code</a> and <a href="https://www.anthropic.com/product/claude-cowork">Cowork</a> pilots rolled out, the company required every command to run in ask mode so the employee issuing it carried the liability, and the developer pushback filled a single Slack thread 120 messages deep. </p><p>"The developers basically are pushing back, and they're like, this is like the iTunes service agreement. I'm just hitting check, check, check, check, check, check, check," Rishi said. "There's no way that I can actually read through this. And it becomes security theater." Roughly 80% of respondents are in the same bind, Rishi said, citing <a href="https://www.rubrik.com/company/newsroom/press-releases/26/as-agentic-ai-adoption-accelerates-rubrik-warns-of-growing-security-gaps">Rubrik Zero Labs research</a> that found monitoring and approving agent actions takes more time than the agents save. The State of the Agent, the April report behind that figure, surveyed more than 1,600 IT and security leaders.</p><p>SAGE is the reason Rubrik trusts the bet. Short for Semantic AI Governance Engine, SAGE is the arbitration layer inside <a href="https://www.rubrik.com/products/rubrik-agent-cloud">Rubrik Agent Cloud</a> that watches every action an agent takes and reads the semantic intent behind it, then rules the action in or out against policies written in natural language. "We took what people said was human in the loop, a good idea, and we replaced it with AI in the loop," Rishi said, describing the pitch to security chiefs he characterized as skittish about non-deterministic systems.</p><h2>Security approval, not cost, blocks AI ROI</h2><p>Rishi’s path to Rubrik ran through <a href="https://techcrunch.com/2025/06/25/rubrik-acquires-predibase-to-accelerate-adoption-of-ai-agents/">Predibase</a>, the generative AI infrastructure startup he co-founded and ran as CEO until Rubrik agreed to acquire it in June 2025. Before that, he led ML product at Google on the team that became Vertex AI, served as Kaggle's first product manager as it grew from about one million to ten million users, and holds bachelor's and master's degrees in computer science from Harvard. </p><p>Over roughly his first three and a half months at Rubrik, Rishi set up 200 customer conversations with IT and security leaders across a customer base that looks like the Global 2000, asking open-ended questions about cost, latency, performance, and orchestration. "Pretty consistently, what I heard through all of those conversations was that all of those are pretty secondary," he said. "The main challenge is actually, how do I get this approved from a security and risk standpoint? I'm concerned about all the different things that could go wrong. Actually, I felt like that was one of the biggest things constraining ROI."</p><p><a href="https://venturebeat.com/orchestration/wall-street-is-debating-the-ai-buildout-enterprises-just-answered-86-say-their-gpus-run-at-half-capacity-or-less">VentureBeat Pulse research</a> presented on the Transform stage earlier in the day confirms the gap Rishi kept hearing. Two-thirds of enterprises, 66%, already allow or are actively building toward production deployment with zero human review, yet only 5% fully trust the automated evaluations that would make that decision. </p><h2>One AI reading what the rulebook can't</h2><p>Rubrik's own policies exposed why written rules fail as enforcement. One internal rule states that agents should respect Rubrik's customer data use policy, which sounds enforceable until someone tries. "Rubrik's customer data use policy is like a three-page document of legal text," Rishi said. "I have no idea how to write that in there as a rule." Asked on stage how a team of AI infrastructure people took on a problem that security engineers own, Rishi answered, "with a lot of naivety and innocence, honestly." His team bet that models good at understanding language could police other models, and SAGE became the answer.</p><p>The case for putting a model in the judgment seat comes down to precision. A rule like "agents should not be able to edit revenue fields in Salesforce" fails in conventional tooling because Salesforce does not delineate which fields count as revenue, Rishi explained, so administrators fall back on approving every Salesforce action by hand. SAGE reads the intent instead and acts as a judge, carrying organizational context, which can tell a benign lookup from the edit the policy prohibits.</p><p>Keeping the judge small is what makes the economics work. <!-- -->SAGE runs on a small language model that Rishi said operates at an order of magnitude lower cost and latency than a frontier LLM. "If I told you, don't worry, you're gonna be secure and governed, but I'm gonna double your cost and latency, you would tell me to get out of the room," Rishi said.</p><p>When Rishi asked who in the audience had worried about token consumption over the past year, half the hands went up. "And I guess the other half is probably just too lazy to raise their hand," he said.</p><p>SAGE is an aggregation of judges based on parameter-efficient fine-tuning that Rubrik uses to take on task-specific variants of a base model with shared organizational context. One judge watches for tool-use hallucinations while another suppresses PII before it can leave, each running as its own enforceable policy. Security and GRC teams have started writing financial rules into the same layer, including one internal policy barring AI spend on personal projects.</p><h2>The lethal trifecta</h2><p>Asked which attacks worry him most, Rishi pointed at the <a href="https://simonwillison.net/2025/Jun/16/the-lethal-trifecta/">lethal trifecta</a>, the term security researcher Simon Willison coined in June 2025 for an agent that holds private data while taking in content nobody vetted, with a channel to send what it finds to the outside world. The danger, according to Rishi, is what happens when individually legitimate permissions stack. An agent granted Salesforce access and email access on an employee's credentials has done nothing wrong yet, with <i>yet</i> being the operative word. "A very simple example is that an agent can start pulling data from Salesforce and then decide to accidentally leak and exfiltrate that out via an email," he told the audience. A financial services company he met the morning of the session made the point for him, telling Rishi that none of the individual permissions are bad on their own and the agent needs every one of them to do its job. "It should have permission to each of those systems, but it's the combination that ends up becoming really destructive," Rishi said.</p><p>Traditional identity and access management never priced in that combination because it relied on the judgment of the employee holding the credentials, Rishi argued, and agents supply none. "I can tell you the number of times Claude Code has tried to leak some of our sensitive source code to a public GitHub repository is incredibly high," he said. Cutting agents off from public resources entirely would defeat their purpose, which returns the problem to adjudicating intent in context rather than revoking access.</p><p>A separate <a href="https://venturebeat.com/security/shared-api-keys-expose-ai-agent-fleets-venturebeat-research">VentureBeat June Pulse survey</a> of 107 qualified enterprise respondents maps the blast radius of exactly this pattern. On the Transform stage that morning, VentureBeat research reported that 69% of companies run credential sharing somewhere in their agent fleet. Companies with shared credentials anywhere got hit more often, reporting a security incident or near-miss at a 63.5% rate (47 of 74), against 40.9% (9 of 22) where every agent carries its own scoped identity.</p><h2>The attacks no single turn reveals</h2><p>Rubrik Agent Cloud reached <a href="https://www.rubrik.com/blog/company/26/2/introducing-rubrik-agent-cloud-control-your-agents-with-ai">general availability in February</a>, though not everything Rishi described ships in it yet. Backtesting is just starting to roll out. The feature replays an organization's historical agent actions and tool calls against a new policy, showing where the policy would have stepped in and where an action would have sailed through uncaught, with policy edits applied in real time. Rishi called that archive one of the most valuable data troves an enterprise holds.</p><p>Real-time detection and blocking turn out to be the entry point rather than the whole product. Some attacks never trip a single-action rule. "No individual turn of the conversation was problematic, but if you took the session as a full trace, that ended up being problematic," Rishi said. Agent Cloud runs batch analysis across entire session traces every hour or every day and surfaces what Rubrik calls insights, the problems no individual guardrail caught. The same Zero Labs report found that 88% say they lack the ability to roll back agent actions without system disruption, a recovery gap that sits squarely in Rubrik's original line of business.</p><p>A skeptical CISO will ask the question the fireside did not answer. SAGE is a non-deterministic model policing other non-deterministic models, and Rishi offered no false positive or false negative rate for the judge itself. The closest thing the architecture gives to an answer is auditability, since backtesting and the batch insights both leave a human-reviewable trail of each call SAGE made and whatever got past it. Who watches the watcher, for now, is a trail of receipts rather than a benchmark. Until that benchmark exists, AI in the loop stays an operational wager rather than a quantified control.</p><p>Three questions fall out of the session for security teams. How many of the guardrails now in production depend on a human clicking approve, and what happens to that workload as agent count grows? Does anything in the stack enforce semantic intent, or is it all allow and deny lists? And can the team backtest agent behavior against a new policy, then unwind a multi-turn session without taking systems down?</p><p>Rishi's timing has a market behind it. In the same VentureBeat research, 82% of enterprises still name their primary AI provider's built-in guardrails and cloud controls as their main agent security layer, and 59% plan to adopt, add, or replace agent security tooling within the next 12 months. Only 12% include an agent-identity product in what they are considering, even with credential sharing still the norm. Every CISO at that Anthropic roundtable had a policy document and no enforcement mechanism, and Rubrik built a product for the space between the two. YOLO mode is the bet that an AI watching other AIs can finally make the policies real.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Agentic orchestration: Enterprise AI organizations have a deployment problem, not a platform problem — and most are calling chatbots agents]]></title>
<description><![CDATA[Across 101 enterprises, agent orchestration is consolidating onto model-provider platforms — Anthropic’s Claude leads by a wide margin — chosen for the gravity of the underlying model and judged on reliable multi-step execution. But the ambition runs well ahead of the reality: most deployed “agen...]]></description>
<link>https://tsecurity.de/de/3689830/it-nachrichten/agentic-orchestration-enterprise-ai-organizations-have-a-deployment-problem-not-a-platform-problem-and-most-are-calling-chatbots-agents/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689830/it-nachrichten/agentic-orchestration-enterprise-ai-organizations-have-a-deployment-problem-not-a-platform-problem-and-most-are-calling-chatbots-agents/</guid>
<pubDate>Thu, 23 Jul 2026 19:19:45 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Across 101 enterprises, agent orchestration is consolidating onto model-provider platforms — Anthropic’s Claude leads by a wide margin — chosen for the gravity of the underlying model and judged on reliable multi-step execution. But the ambition runs well ahead of the reality: most deployed “agents” are still chatbot wrappers, the control plane enterprises expect is deliberately hybrid to avoid lock-in, and real-time fiscal control over token burn remains the exception.</p><p>This wave of VentureBeat Pulse Research examines enterprise agent orchestration: which platforms enterprises run on, what drives the choice, what they optimize for, how they expect agent control to be structured, and — most revealingly — how orchestrated their deployed “agents” actually are and how tightly they control the cost of running them.</p><p>The central finding is a gap between orchestration ambition and orchestration reality. Enterprises are consolidating fast onto the major model platforms: Anthropic’s Claude is the primary platform for 40%, more than double any rival, followed by Microsoft (18%) and OpenAI (13%). The choice is driven by “model gravity” — native alignment with a state-of-the-art base model (21%) — and success is judged by reliable, multi-step execution (task completion reliability 32%, multi-step workflow management 28%). Yet asked to assess their portfolios honestly, 71% say a quarter or fewer of their deployed “agents” are true multi-step orchestrated workflows rather than single-prompt chatbot wrappers, and only 10% have crossed the halfway mark. The orchestration layer is being built well ahead of the orchestrated portfolio it is meant to run.</p><p>That gap shapes the architecture enterprises are putting in place. By the end of 2026 a clear majority (51%) expect a hybrid control plane — provider-native plus external orchestration — and only 6% expect to hand control to a provider-managed service, because vendor lock-in (35%) is the risk they fear most if control lives inside a model provider. Investment follows the build-out: agent workflow tooling leads the spend (34%), with security and permissions enforcement (25%) behind. And fiscal control lags throughout — more than a quarter (27%) have no real-time way to stop a runaway agent before the bill arrives.</p><h2>Methodology</h2><p>VentureBeat fielded this survey as part of its ongoing Pulse Research series, this instrument focused on enterprise agent orchestration. Responses are filtered to organizations with 100 or more employees (n=101), drawn from a single June 2026 wave; because this is one wave rather than a pooled multi-month sample, the report reads cross-sectionally and does not infer month-over-month trends.</p><p>By organization size the sample is spread evenly across the enterprise bands: 100–499 employees, 2,500–9,999, and 50,000+ (21% each), with 10,000–49,999 and 500–2,499 (19% each). By role it is senior and buyer-credible: product and program managers (15%), CIO/CTO/CISO (13%), consultants and advisors (13%), and a spread of data, AI, and engineering directors and VPs, with an “Other” function at 18%. On purchasing, 81% are recommenders, influencers, or final decision-makers for AI solutions (66% recommender/influencer, 15% final decision-maker). Technology/Software is the largest industry at 44%, followed by Financial Services (17%) and Healthcare/Life Sciences (8%).</p><p>At 101 respondents the sample is robust enough to read directionally with reasonable confidence, though it remains self-selected and is not a probability sample.</p><h2>Finding 1: Orchestration runs on model-provider platforms</h2><p><b>Anthropic’s Claude leads; open frameworks are marginal</b></p><p>We asked which agent orchestration platform enterprises primarily use today. The answer concentrates on the major model providers — and on one in particular.</p><div></div><p>A note on reading these shares. As described in the methodology section, the respondents are self-selected, and this question asked them for a single primary platform — so the figures measure which platform leads each enterprise's deployment, within a self-selected audience of AI-active technical decision-makers. A sample built this way can diverge substantially from spend-weighted market measures, and each VB Pulse survey draws its own sample with its own company-size mix, so vendor figures should not be compared across our surveys either. Read these shares as a portrait of where this cohort has placed its primary orchestration bet today, rather than as market share.</p><p>The model platforms dominate. Anthropic, Microsoft, OpenAI, Google, and Amazon together account for roughly 80% of deployments (81 of 101), while the open frameworks (LangChain/LangGraph) and custom in-house builds that anchor engineering discussion sit in single digits. Anthropic’s lead — 40%, more than double the next platform — mirrors the “model gravity” selection logic in Finding 2: enterprises are choosing the orchestration layer that comes with the model they want to build on. As with the security vendors in the prior agent-security wave, the tools that define the category in technical circles are not yet where enterprise deployment concentrates. A small 3% are not orchestrating at all.</p><p>Respondents rate the platforms they run at 3.94 out of 5 overall (109 answered), with “value for money” specifically at 3.94 and “ease of implementation” the weakest score, at 3.85 — placing orchestration near the bottom of our five-tracker satisfaction range, ahead of only evaluation tooling. A rating just under 4 out of 5, from users of whom 96% plan to change their orchestration approach within the year, reads as provisional acceptance: the platforms work well enough to run today, and not well enough to stop the search for something better. The ratings sit alongside near-universal intent to change; this is a layer enterprises tolerate more than they love.</p><h2>Finding 2: Model gravity drives platform selection</h2><p><b>The base model, not the tooling, decides the platform</b></p><p>We asked what most influenced the orchestration platform choice. The single largest factor is the pull of the underlying model — though flexibility and ease of development follow close behind.</p><div></div><p>Model gravity leading is the selection-side explanation for Anthropic’s platform lead: enterprises pick the orchestration environment closest to the frontier model they have standardized on. But the next tier complicates the picture — flexibility across models and tools (17%) and ease of development (17%) say enterprises also want to avoid being trapped by that choice, foreshadowing the lock-in fear in Finding 6. Security and permissions (14%) and total cost of ownership (11%) round out a pragmatic buying logic. Performance (latency/memory) sits last at 4%, a reminder that at this stage of adoption the binding constraints are model fit and optionality, not raw speed.</p><h2>Finding 3: The job is reliable multi-step execution</h2><p><b>Enterprises just orchestration by whether it completes the work</b></p><p>We asked what enterprises optimize for — their primary success metric for orchestration. Reliability and multi-step workflow management dominate; developer- and user-facing metrics trail.</p><div></div><p>Task completion reliability (32%) and multi-step workflow management (28%) together account for 59% of responses (60 of 101): orchestration succeeds, in the enterprise view, when it reliably carries a task through multiple steps to completion. Developer productivity (17%) matters but is secondary — the inverse of its prominence in framework discussion — and end-user experience (9%) is a minor concern, consistent with orchestration being an internal execution problem rather than a UX one. This reliability-first standard is exactly what makes the Chatbot Trap finding so pointed: enterprises define success as dependable multi-step execution, yet most of their deployed “agents” do not yet do multi-step work at all.</p><p>The trap is not evenly distributed. Splitting the sample by organization size, 77% of smaller enterprises say a quarter or fewer of their agents do true multi-step work, against 62% of larger ones. Larger enterprises are meaningfully further into genuine multi-step deployment; the chatbot trap is, directionally, a mid-market condition.</p><h2>Finding 4: Consolidate, productionize, and build in-house </h2><p><b>Three strategic moves are nearly tied for the year ahead</b></p><p>We asked what major change enterprises anticipate in their orchestration strategy over the next 12 months. Three moves cluster at the top, almost evenly split.</p><div></div><p>The top three — building in-house control (25%), standardizing on one framework (24%), and moving agents from sandbox to production (23%) — are statistically indistinguishable and tell a single story: enterprises are moving from experimentation to operational consolidation. They want fewer frameworks, more production exposure, and more ownership of the control layer; only 4% expect no change. The appetite for custom in-house control planes is notable alongside the platform concentration in Finding 1 — enterprises are standardizing on model-provider platforms while simultaneously planning to wrap them in control logic they own, the hybrid posture that Finding 6 makes explicit.</p><h2>Finding 5: Nearly seven in 10 plan to switch — and the biggest group of movers has no shortlist </h2><p>The strategic change enterprises anticipate (previous finding) comes with vendor motion attached. Asked whether they plan to adopt a new, additional, or replacement agent orchestration platform in the next twelve months, more respondents are moving here than in any other layer we track.</p><div></div><p>Asked which platforms they are considering, the most common answer among those in motion is none yet: 29% of all respondents are evaluating without a shortlist, the largest single response after "not considering a change." Among named candidates, OpenAI leads at 16%, followed by LangChain/LangGraph at 12% and Anthropic at 7% — and notably, the independent frameworks draw roughly double their current usage footprint in forward consideration, the same pattern our security tracker found for specialist vendors. Read with this report's concentration and lock-in findings, the picture completes itself: the major model-platform providers hold roughly four-fifths of today's primary usage, vendor lock-in has become the leading fear, 96% anticipate a strategic change — and now the purchase intent to act on all of it, with the largest bloc of buyers still undecided. The most concentrated layer of the agentic stack is also, as of June, the least settled.</p><h2>Finding 6: Investment flows to workflow tooling</h2><p><b>Tooling and permissions lead the spend; monitoring trails</b></p><p>We asked which orchestration-related investment will grow most next year. Agent workflow tooling leads, with security and permissions enforcement behind.</p><div></div><p>Workflow tooling leading (34%) is the budget-side expression of the reliability-and-multi-step priority in Finding 3: the money is going to the machinery that strings steps together dependably. Security and permissions enforcement (25%) and scaling infrastructure (20%) follow — the investments required to take agents from sandbox into production, the strategic move in Finding 4. Monitoring and debugging draws a smaller 11%, with another 11% reporting flat budgets. The weight on tooling, permissions, and scaling over pure observability signals that enterprises are spending to build and harden orchestration, not merely to watch it run.</p><h2>Finding 7: The control plane will be hybrid — and lock-in is why</h2><p><b>Enterprises expect to split control between providers and their own layer</b></p><p>We asked where enterprises expect the primary control plane for agents to live by the end of 2026, and what worries them most if that control sits inside a model-provider platform. A clear majority expect a hybrid model — and vendor lock-in is the reason.</p><div></div><p>Hybrid control is the dominant expectation by a wide margin (51%), and only 6% expect to hand control to a provider-managed service outright. Read together, the hybrid, custom, and externally-abstracted options — every architecture that keeps control at least partly outside the provider — sum to 88% (89 of 101). The reason surfaces directly when we asked about the risk of provider-resident control: vendor lock-in leads at 35% (35 of 101), ahead of security and permissioning limitations (28%) and inflexibility across models and tools (21%). The pattern echoes the prior wave’s “don’t trust the model to police itself” posture — here, enterprises will build on a provider’s platform but decline to be governed entirely by it. The hybrid control plane is the architectural hedge against the lock-in they most fear.</p><p>The June figure asserting a preference for a hybrid control plane marks movement from earlier. In the April–May survey (n=145), only 34% expected a hybrid control plane, and a greater number (12%) expected to hand control fully to a provider-managed service. These two snapshots don’t yet measure a confirmed longitudinal trend — but the direction of the conversation is unambiguous: toward keeping control.</p><p>Lock-in is also a new arrival as a top concern. In the April–May wave, the leading concern was security and permissioning limitations (32%), with lock-in second at 24%; by June the two had traded places. The worry about provider platforms appears to be maturing from whether they can be secured to whether they can be replaced.</p><h2>Finding 8: The chatbot trap — most “agents” aren’t agents yet</h2><p><b>Enterprises admit most deployments are still chatbot wrappers</b></p><p>We asked enterprises to assess their portfolios honestly: what share of their deployed “agents” are true multi-step orchestrated workflows versus simple single-prompt chatbot wrappers. The answer is the defining finding of this wave.</p><div></div><p>This is the gap at the center of the report. Combining the bottom two bands, 71% of enterprises (72 of 101) say a quarter or fewer of their deployed “agents” are genuinely orchestrated — and just 10% (10 of 101) have crossed the halfway mark. The ambition documented in the earlier findings — model-provider platforms, reliability-first success metrics, production rollouts, a deliberate control architecture — runs well ahead of the deployed reality, which remains overwhelmingly single-prompt assistants dressed as agents. This is less a contradiction than a roadmap: the platforms, budgets, and strategies are being put in place precisely because the orchestrated portfolio is still so thin. The open question for later waves is how fast the reality closes on the ambition.</p><h2>Finding 9: Fiscal control is still reactive</h2><p><b>Only a minority can stop a runaway agent before the bill arrives</b></p><p>Finally, we asked how enterprises enforce fiscal control over agent token consumption — the risk that an autonomous loop exhausts a budget before anyone intervenes. Most rely on native caps or after-the-fact monitoring; real-time programmatic control is the exception.</p><div></div><p>More than a quarter of enterprises (27%) admit they have no real-time, programmatic way to stop an agent before a budget-breaking bill arrives — they learn of it from the logs afterward. Another 32% lean entirely on the native caps and throttles built into their primary platform, a control only as good as the provider’s tooling and one that ties back to the lock-in concern of Finding 6. The enterprises building custom gateways (23%) or exploiting cross-model routing to arbitrage cost (19%) are the ones treating token burn as an engineering problem to be controlled deterministically. As with orchestration maturity, fiscal control is an area where the operational reality lags the ambition: agents are moving toward production faster than the cost-control plane around them is being built.</p><p>It’s worth noting, a split appears according to company size: roughly one in three enterprises under 2,500 employees (34%) exercises only reactive control of agent spend, against 20% of larger enterprises — directional figures, but consistent with the chatbot-trap split. The mid-market is running the least mature agents on the least instrumented budgets.</p><h2>The bottom line: The layer is real; most of the agents aren't yet</h2><p>Organizations with 100 or more employees describe an orchestration strategy that is consolidating quickly and maturing slowly. They are standardizing — for now — on model-provider platforms, which collectively hold roughly four-fifths of primary usage, chosen for the gravity of the underlying model, and they judge success by reliable multi-step execution. Investment is flowing to workflow tooling and permissions, the strategy is to consolidate frameworks and push agents into production, and the control plane they expect is deliberately hybrid, because vendor lock-in is the risk they fear most. But the standardization is provisional: 68% plan to adopt a new, additional, or replacement orchestration platform within twelve months — the highest switching intent of any layer we track — and the largest group of those movers has not yet shortlisted a candidate. Today's concentration describes where enterprises are, and visibly does not describe where they intend to stay.</p><p>But the honest self-assessment punctures the ambition. Seventy-one percent say a quarter or fewer of their deployed "agents" are truly orchestrated, only 10% are past the halfway mark, and more than a quarter cannot stop a runaway agent in real time. The orchestration layer — the platforms, the budgets, the control architecture — is being built ahead of the orchestrated portfolio it is meant to run. At 101 respondents in a single June wave this reads as a clear directional signal rather than a precise measurement: enterprises have decided how they want to orchestrate agents well before most of their agents are doing anything an orchestration layer is for. The questions for subsequent waves are whether the deployed reality closes the gap on the ambition — and, with nearly seven in ten buyers in motion and most of them undecided, which platforms the settled stack finally lands on.</p><hr><p><i>Based on survey responses from 101 qualified enterprise respondents (100+ employees), drawn from a single June 2026 wave. Because this is one wave rather than a pooled multi-month sample, results read directionally rather than as a confirmed trend. Respondents include product and program managers, CIOs, CTOs and CISOs, consultants and advisors, and directors and VPs of data, AI, and engineering, across Technology/Software, Financial Services, Healthcare, and other sectors.</i></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI „hackt“ Hugging Face – eine Analyse]]></title>
<description><![CDATA[Wenn KI-Modelle die Grenzen überwinden, die ihnen gesetzt werden, hinterlassen sie unter Umständen weniger sichtbare Spuren.Nelson Antoine | shutterstock.com



Der heimliche Cybercrime-Akt zweier KI-Modelle von OpenAI hat weltweit ein enormes Echo in Mainstream– und sozialen Medien hervorgerufen...]]></description>
<link>https://tsecurity.de/de/3689099/it-security-nachrichten/openai-hackt-hugging-face-eine-analyse/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689099/it-security-nachrichten/openai-hackt-hugging-face-eine-analyse/</guid>
<pubDate>Thu, 23 Jul 2026 14:55:17 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2025/08/Nelson-Antoine-shutterstock_1672788895_16z9.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Jailbreak 16z9" class="wp-image-4038755" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption">Wenn KI-Modelle die Grenzen überwinden, die ihnen gesetzt werden, hinterlassen sie unter Umständen weniger sichtbare Spuren.</figcaption></figure><p class="imageCredit">Nelson Antoine | shutterstock.com</p></div>



<p class="wp-block-paragraph">Der heimliche Cybercrime-Akt zweier KI-Modelle von OpenAI hat weltweit ein enormes Echo in <a href="https://www.tagesschau.de/wirtschaft/unternehmen/openai-ki-hackerangriff-100.html" target="_blank" rel="noreferrer noopener">Mainstream</a>– und <a href="https://www.reddit.com/r/OpenAI/comments/1v2ybnw/openai_models_escaped_containment_and_hacked/" target="_blank" rel="noreferrer noopener">sozialen Medien</a> hervorgerufen. Der Vorfall dürfte die Debatte über die allgemeine <a href="https://www.computerwoche.de/article/4155663/6-wege-uber-ki-gehackt-zu-werden.html" target="_blank">KI-Sicherheit</a> und den verantwortungsvollen Umgang mit der Technologie neu befeuern. </p>



<p class="wp-block-paragraph">Doch der Incident wirft auch spezifische Fragen auf. Etwa, wie genau die OpenAI-Modelle es geschafft haben, ihrer Sandbox zu entkommen und warum das beim ChatGPT-Erfinder zunächst niemandem aufgefallen ist. Oder, wie andere Unternehmen solche und ähnliche Vorkommnisse künftig verhindern können. Dazu haben wir die Einschätzung von Branchenexperten und Analysten eingeholt. </p>



<p class="wp-block-paragraph">Zunächst werfen wir aber noch einen kurzen Blick darauf, was sich eigentlich abgespielt hat. Falls Sie bereits informiert sind, können Sie alternativ auch das nachfolgende Meme konsumieren, um sich den Vorfall noch einmal auf unkonventionellere Art und Weise vor Augen zu halten.</p>


<div class="wp-block-embed-reddit">
					<blockquote class="reddit-card">
						<a href="https://www.reddit.com/r/singularity/comments/1v2xgqc/openai_hacking_huggingface_in_one_meme/"></a>
					</blockquote>
				</div>


<p class="wp-block-paragraph"></p>



<h2 class="wp-block-heading">Der autonome Hugging-Face-Hack</h2>



<p class="wp-block-paragraph">Die KI-Plattform Hugging Face meldete Mitte Juli einen <a href="https://huggingface.co/blog/security-incident-july-2026" target="_blank" rel="noreferrer noopener">Cyberangriff auf ihre Produktions-Infrastruktur</a>. Diese wurde offenbar vollständig autonom von einem agentenbasierten KI-System gefahren, das sich dabei sowohl Zugriff auf interne Datensätze als auch auf Zugangsdaten verschaffen konnte.  </p>



<p class="wp-block-paragraph">Wie sich im Rahmen der folgenden Untersuchung herausstellte, stammte die autonom hackende KI von OpenAI. Eigentlich wollte der KI-Pionier lediglich zwei seiner neuen Modelle – GPT 5.6 Sol sowie ein nicht näher spezifiziertes Pre-Release-Modell – innerhalb einer Sandbox mit dem Benchmarking-Tool <a href="https://github.com/sunblaze-ucb/exploitgym" target="_blank" rel="noreferrer noopener">ExploitGym</a> testen.</p>



<p class="wp-block-paragraph">Die Aufgabe für die KI: Schwachstellen in tragfähige Exploits zu verwandeln. Die Testumgebung selbst war OpenAI zufolge mit beschränktem Netzwerkzugriff ausgestattet. Die KI sollte lediglich auf einen intern gehosteten Drittanbieter-Service zugreifen können, der als Proxy und Cache für eine Package-Registry fungierte. Die Guardrails auf Modellebene waren für den Test laut dem KI-Unternehmen reduziert worden.</p>



<p class="wp-block-paragraph">Das war der KI aber offenbar nicht genug: Sie verkettete zunächst einige zuvor unbekannte Schwachstellen in der Testumgebung, um sich uneingeschränkten Internet-Zugriff zu verschaffen, wie OpenAI <a href="https://openai.com/de-DE/index/hugging-face-model-evaluation-security-incident/" target="_blank" rel="noreferrer noopener">in einem Blogbeitrag</a> offenlegt: „Mit diesem Zugriff führten unsere Modelle in unserer Forschungsumgebung eine Reihe von Privilege-Escalation- und Lateral-Movement-Aktionen aus, bis sie eine Node mit Internetzugang erreichten.“</p>



<p class="wp-block-paragraph">Weil die OpenAI-Modelle bei Hugging Face offenbar Lösungen für ihre ExploitGym-Aufgaben vermuteten, suchten sie nach Möglichkeiten, Zugriff auf diese zu erhalten. Und fanden sie dann auch, wie OpenAI darlegt: „In einem Beispiel verkettete das Modell mehrere Angriffsvektoren, darunter gestohlene Zugangsdaten und Zero-Day-Schwachstellen, um auf den Servern von Hugging Face einen Remote-Execution-Pfad zu finden.“</p>



<p class="wp-block-paragraph">Das Security-Team von OpenAI konnte diese Vorgänge im Nachgang identifizieren und schloss sich daraufhin mit dem Team von Hugging Face zusammen, welches die Attacke seinerseits bereits identifiziert und (mit einigen Anlaufschwierigkeiten) eingedämmt hatte.</p>



<p class="wp-block-paragraph">„Wir betrachten dies als beispiellosen Cybervorfall mit hochentwickelten Fähigkeiten und reagieren entsprechend. Wir teilen zu diesem Zeitpunkt vorläufige Erkenntnisse, damit Sicherheitsverantwortliche nachvollziehen können, was passiert ist, und besser einschätzen können, wozu die Modelle inzwischen in der Lage sind“, schreibt OpenAI in seinem Blog – und verspricht, weitere Details zu veröffentlichen, sobald diese vorliegen.</p>



<h2 class="wp-block-heading">KI-Ausbruch bei OpenAI – so reagieren Experten</h2>



<p class="wp-block-paragraph">Branchenexperten und Analysten bewerten den schlagzeilenträchtigen Incident um OpenAI und Hugging Face folgendermaßen: </p>



<ul class="wp-block-list">
<li><a href="https://www.kuppingercole.com/people/balaganski" target="_blank" rel="noreferrer noopener">Alexei Balaganski</a>, Lead Analyst bei KuppingerCole<strong>: </strong>„Dieser Vorfall sollte nicht als ‚Rogue AI‘-Geschichte betrachtet werden. Das Modell hat exakt das getan, wofür agentische Systeme gemacht sind: Es hat sich allen verfügbaren Tools und Wegen bedient, um das ihm gesetzte Ziel zu erreichen. Die Sicherheitsvorkehrungen, die es normalerweise in Zaum gehalten hätten, wurden von OpenAI selbst zu Testzwecken deaktiviert. Darin besteht die wahre Lektion.“</li>



<li><a href="https://www.kuppingercole.com/people/care" target="_blank" rel="noreferrer noopener">Jonathan Care</a>, Lead Analyst und AI Practice Lead bei KuppingerCole: „Es geht bei diesem Vorfall nicht darum, dass eine KI ausgebrochen ist und zum Angreifer wurde. Wir wussten, das würde passieren. Bemerkenswert ist allerdings, dass die Verteidiger – in diesem Fall das Team von Hugging Face – keine kommerziellen KI-Modelle nutzen konnten, um den Angriff zu analysieren. Denn deren Guardrails sorgen dafür, dass kein Exoploit-Code verarbeitet werden kann.“</li>



<li><a href="https://www.linkedin.com/in/beuchelt" target="_blank" rel="noreferrer noopener">Gerald Beuchelt</a>, CISO bei Acronis: „Der Vorfall verdeutlicht eine zentrale Herausforderung für Incident-Response-Teams: Angreifer sind nicht an Nutzungsrichtlinien gebunden. Verteidiger können hingegen an die Grenzen ihrer eigenen Tools stoßen, wenn diese genau jene Daten nicht verarbeiten, die für eine Untersuchung erforderlich sind. Im Ernstfall können daraus Verzögerungen mit unmittelbaren operativen Folgen entstehen.“</li>



<li><a href="https://www.computerwoche.de/profile/sabine-fromling/" target="_blank">Sabine Frömling</a>, Experten-Autorin und Cybersecurity-Beraterin: „Der eigentliche Sicherheitsvorfall war nicht die KI – sondern die Sandbox, die aus Versehen eine Tür zum Internet hatte. Man hat ein Raubtier freigelassen und dem Zaun die Schuld gegeben.“</li>



<li><a href="https://www.linkedin.com/in/martinzugec" target="_blank" rel="noreferrer noopener">Martin Zugec</a>, Technical Solutions Director bei Bitdefender:<strong> „</strong>Was meiner Meinung nach für KI-generierte Malware galt, untermauert auch dieser Vorfall: Die Bedrohung ist real, KI ist aber keine Magie. Wer glaubt, es mit einer neuartigen Superwaffe zu tun zu haben, wartet auf eine neuartige Gegenmaßnahme. Wer jedoch erkennt, dass es sich um bereits bekannte, aber unerbittlich angewandte Angriffstechniken handelt, weiß bereits, was zu tun ist.“</li>



<li><a href="https://de.linkedin.com/in/riwerner/de" target="_blank" rel="noreferrer noopener">Richard Werner</a>, Cybersecurity Platform Lead Europe bei TrendAI: „Das Narrativ von der ‚eigenmächtig handelnden KI‘ ist effizient darin, Verantwortung abzuwälzen. Das ist, als würden Sie eine autonome Waffe bauen, diese auf einem vermeintlich sicheren Testgelände erproben, sie außer Kontrolle geraten und jemanden treffen lassen – und der Welt anschließend erklären, die Waffe habe eigenständig gehandelt. Das ist zwar technisch korrekt. Dennoch bleibt es Ihre Waffe, Ihr Testgelände und Ihr Versagen.“</li>
</ul>



<h2 class="wp-block-heading">Was Unternehmen jetzt tun sollten</h2>



<p class="wp-block-paragraph">IT- und Sicherheitsentscheider können aus dem Hugging-Face-Hack mehrere Lektionen ziehen. Etwa, dass Sicherheitsvorkehrungen auf Modellebene <strong>nicht</strong> als primäre Security-Grenze für KI-Agenten geeignet sind, wie <a href="https://www.forrester.com/analyst-bio/biswajeet-mahapatra/BIO20046" target="_blank" rel="noreferrer noopener">Biswajeet Mahapatra</a>, Principal Analyst bei Forrester, festhält: „Prompt-Guardrails sind keine Sicherheits-, sondern Verhaltenskontrollmaßnahmen. Und diese können versagen, umgangen oder absichtlich deaktiviert werden.“</p>



<p class="wp-block-paragraph">Der Forrester-Analyst rät Unternehmen deshalb dazu, KI-Agenten als <a href="https://www.computerwoche.de/article/4152424/insider-threats-sind-wieder-im-kommen.html" target="_blank">hochriskante, nicht-menschliche Identitäten</a> zu behandeln – und jeden einzelnen in einer isolierten Umgebung zu betreiben, in der Datenzugriff auf den jeweiligen Task beschränkt bleibt und die Zugangsdaten selbst möglichst schnell ablaufen: „Das sorgt für einen akzeptablen ‚Blast Radius‘: Wird ein Agent <a href="https://www.computerwoche.de/article/4190978/so-spuren-sie-kompromittierte-ki-agenten-auf.html" target="_blank">kompromittiert</a>, kann er nur einen einzigen Workflow, Datensatz oder eine einzige Anwendung beeinträchtigen. Anstatt die gesamte Unternehmensinfrastruktur.“</p>



<p class="wp-block-paragraph"><a href="https://greyhoundresearch.com/svg/" target="_blank" rel="noreferrer noopener">Sanchit Vir Gogia</a>, Chefanalyst bei Greyhound Research, warnt an dieser Stelle davor, (Drittanbieter-)Services unter den Tisch fallen zu lassen: „Dienste, die auf Package Registries, Update-Systeme oder andere externe Ressourcen zugreifen, können ebenfalls zu Einfallstoren werden, wenn sie nicht derselben, ausgiebigen Prüfung unterzogen werden wie der Agent selbst.“</p>



<p class="wp-block-paragraph">Unabhängig davon sollten Unternehmen laut Gogia auch testen, ob ihre Containment-Grenzen auch funktionieren, anstatt sich allein auf Architekturdiagramme oder dokumentierte Richtlinien zu verlassen: „Im Rahmen dieser Tests sollte geprüft werden, ob Anmeldedaten erlangt, Trust-Grenzen überwunden und Systeme außerhalb der einem Agenten zugewiesenen Aufgabe erreicht werden können.“</p>



<p class="wp-block-paragraph">KuppingerCole-Chefanalyst Care rät IT-Entscheidern und Unternehmen im Wesentlichen zu drei Maßnahmen, nämlich:</p>



<ul class="wp-block-list">
<li>ein fähiges Modell auf der eigenen Infrastruktur auszuführen, das unter der eigenen Kontrolle steht und mit Guardrails ausgestattet ist, die sowohl eine forensische als auch defensive Nutzung ermöglichen. Nur so ließen sich Angriffe dieser Art auch zuverlässig analysieren.</li>



<li>jeden KI-Agent in der eigenen Umgebung als privilegierten Insider zu behandeln – statt als vertrauenswürdigen Benutzer: „Wenn die Modelle von OpenAI aus ihrer Sandbox ausgebrochen sind, sollten Sie davon ausgehen, dass Ihre Agenten dazu auch in der Lage sind.“</li>



<li>den eigenen Incident-Response-Plan mit Blick auf Angriffe in maschineller Geschwindigkeit zu aktualisieren: „Hugging Face hatte einige Tage Zeit, um zu reagieren, Sie haben vielleicht nur Minuten.“   </li>
</ul>



<p class="wp-block-paragraph">Acronis-CISO Beuchelt rät Organisationen, die gehostete <a href="https://www.computerwoche.de/article/4186715/31-wege-llms-zu-evaluieren.html" target="_blank">LLMs</a> für Security-Untersuchungen einsetzen, dazu, deren Grenzen möglichst bereits im Vorfeld zu durchdringen und zu testen – sowie ein alternatives Modell auf der eigenen Infrastruktur bereitzuhalten: „So reduzieren Sie das Risiko, im entscheidenden Moment keinen Zugriff auf wichtige Analysefunktionen zu haben. Gleichzeitig bleiben sensible Incident-Daten und Zugangsinformationen innerhalb der eigenen Organisation.“</p>



<p class="wp-block-paragraph"><a href="https://de.linkedin.com/in/udoschneider">Udo Schneider</a>, Governance, Risk &amp; Compliance Lead Europe bei TrendAI weist darauf hin, dass die beiden naheliegendsten Lösungsansätze bei Angriffen wie dem der OpenAI-KI auf Hugging Face nur teilweise greifen. Human-in-the-Loop-Kontrollen funktionierten zwar, so der Experte, skalierten aber nicht für die langlaufenden, komplexen Workflows, denen Incidents dieser Art entspringen. Ebenso könnten engere Guardrails für Modelle oder Prompts zwar helfen, stellten jedoch keine Garantie dar: „Es handelt sich um probabilistische Systeme. Eine Guardrail ist insofern keine Mauer, sondern eher eine starke Wahrscheinlichkeitsannahme.“</p>



<p class="wp-block-paragraph">Deshalb komme es laut Schneider vor allem auf die unspektakulären, nicht-KI-spezifischen Kontrollen an: „Zugriffsfilterung, Kontrolle darüber, was überhaupt als Input beim Modell ankommt, Sandboxes, die tatsächlich halten, und Berechtigungskonzepte nach dem Least-Privilege-Prinzip.“</p>



<p class="wp-block-paragraph">In Panik zu verfallen, wäre nach Ansicht von <a href="https://www.linkedin.com/in/martinzugec" target="_blank" rel="noreferrer noopener">Martin Zugec</a>, Technical Solutions Director bei Bitdefender, in jedem Fall die falsche Reaktion:„Was gegen solche Angriffe wirkt, ist eine präventionsorientierte Security, die den Handlungsspielraum eines Angreifers von vorneherein einschränkt – und eine verhaltensbasierte Abwehr, die bösartige Muster kennzeichnet, unabhängig davon, mit welchen Tools diese generiert wurden.“</p>



<p class="wp-block-paragraph"><strong>Dieser Artikel wurde </strong><a href="https://www.csoonline.com/article/4200043/openai-model-escape-puts-enterprise-ai-defenses-on-notice.html" target="_blank"><strong>mit Material</strong></a><strong> unserer Schwesterpublikation CSOonline.com angereichert.</strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Tech layoffs: A 2026 timeline]]></title>
<description><![CDATA[Among a range of factors leading to a wave of tech sector layoffs in 2026 is the rapid rise of artificial intelligence and automation. Companies are reconfiguring their workforces to leverage AI for increased efficiency and reduced operating costs. This realignment and reduction is implemented ev...]]></description>
<link>https://tsecurity.de/de/3689055/it-nachrichten/tech-layoffs-a-2026-timeline/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689055/it-nachrichten/tech-layoffs-a-2026-timeline/</guid>
<pubDate>Thu, 23 Jul 2026 14:35:03 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Among a range of factors leading to a wave of tech sector layoffs in 2026 is the rapid rise of artificial intelligence and automation. Companies are reconfiguring their workforces to leverage AI for increased efficiency and reduced operating costs. This realignment and reduction is implemented even by companies reporting strong financial performance.</p>



<p class="wp-block-paragraph">But it’s not just AI leading to workforce cuts. Complementing this technological shift are ongoing economic uncertainty, inflation, and higher interest rates, compounded by a chip shortage and rising energy costs. This mix is driving companies to cut costs and streamline operations for increased efficiency.</p>



<p class="wp-block-paragraph">According to data compiled by <a href="https://layoffs.fyi/" target="_blank" rel="noreferrer noopener">Layoffs.fyi</a>, an online tracker that keep tabs on job losses in the technology sector, 123,941 tech employees were laid off at 269 companies in 2025. The site also reports that 71,981 government employees were laid off by DOGE alone, with 182,528 total federal workers laid off.</p>



<p class="wp-block-paragraph">Here is a list — to be updated regularly — of some of the most prominent technology layoffs the industry has experienced recently.</p>



<h2 class="wp-block-heading">Notable tech layoffs in 2026</h2>



<ul class="wp-block-list">
<li>Monday.com</li>



<li>Microsoft</li>



<li>Meta</li>



<li>Cisco</li>



<li>Cloudflare</li>



<li>Oracle</li>



<li>Atlassian </li>



<li>Salesforce</li>



<li>Amazon</li>



<li>Ericsson</li>
</ul>



<h3 class="wp-block-heading">July 22, 2026: Monday.com cuts 20% of its workforce to restructure for the AI era</h3>



<p class="wp-block-paragraph">The company says the decision to <a href="https://www.computerworld.com/article/4200349/monday-com-cuts-20-of-its-workforce-to-restructure-for-the-ai-era-2.html">cut 620 jobs</a> isn’t about margins, but about creating a flatter organization built around AI agents, autonomous teams, and deeper customer engagement.</p>



<h3 class="wp-block-heading">July 6, 2026: Microsoft cuts 4,800 jobs, primarily in sales and Xbox teams</h3>



<p class="wp-block-paragraph">As the company <a href="https://www.computerworld.com/article/4193532/microsoft-bets-that-enterprise-ai-needs-engineers-not-bigger-sales-teams-2.html" target="_blank">trims thousands of jobs</a>, it’s also investing in embedded engineering teams and AI infrastructure. The layoffs come several weeks after the company offered 8,750 US employees <a href="https://www.computerworld.com/article/4163188/microsoft-to-offer-voluntary-retirement-buyouts-to-about-7-of-the-us-workforce.html">voluntary retirement buyouts</a>.</p>



<h3 class="wp-block-heading">June 5, 2026: Tech industry cut 38,242 jobs in May, worst since 2024</h3>



<p class="wp-block-paragraph">AI was blamed for 40% of <a href="https://www.computerworld.com/article/4181822/tech-industry-cut-38242-jobs-in-may-worst-since-2024.html">the job cuts in May</a>, up from 7% in January, according to research by employment placement company Challenger, Gray &amp; Christmas.</p>



<h3 class="wp-block-heading">May 20, 2026: Meta cuts 8,000 jobs, around 10% of workforce</h3>



<p class="wp-block-paragraph">The cuts are expected to expected to hit Meta’s engineering and product teams the hardest, arriving as Meta pivots toward AI to boost efficiency across its organization, <a href="https://tech.yahoo.com/general/article/meta-starts-cutting-8000-jobs-as-part-of-previously-announced-layoffs-145220586.html" target="_blank" rel="noreferrer noopener">according to Yahoo Tech</a>.</p>



<h3 class="wp-block-heading">May 13, 2026: Cisco to cut nearly 4,000 jobs despite strong growth in AI, enterprise networking</h3>



<p class="wp-block-paragraph">Despite reporting positive financial news — including record third-quarter revenue of $15.8 billion, a 12% year-over-year increase — Cisco said it will <a href="https://www.networkworld.com/article/4171043/cisco-to-cut-nearly-4000-jobs-despite-strong-growth-in-ai-enterprise-networking.html" target="_blank">eliminate almost 4,000 jobs</a>.</p>



<h3 class="wp-block-heading">May 7, 2026: Cloudflare to cut 1,100 jobs in AI-focused restructuring</h3>



<p class="wp-block-paragraph">About <a href="https://finance.yahoo.com/markets/stocks/articles/cloudflare-cut-over-1-100-204726989.html" target="_blank" rel="noreferrer noopener">20% of Cloudflare’s global workforce will be culled</a> as the company pivots for the agentic AI era, Reuters reported.</p>



<h3 class="wp-block-heading">April 1, 2026: Oracle to cut up to 30,000 jobs globally, putting enterprise support and roadmaps at risk</h3>



<p class="wp-block-paragraph"><a href="https://www.cio.com/article/4153113/oracle-cuts-up-to-30000-jobs-globally-putting-enterprise-support-and-roadmaps-at-risk.html">Oracle began laying off employees</a> on March 31 in what could be the largest workforce reduction in the company’s history. Employees received termination emails at 6 a.m. local time with immediate system lockouts and no prior warning. <em>(Note: in June, CNBC put the <a href="https://www.cnbc.com/2026/06/23/oracle-ai-job-cuts-layoffs-21000.html" target="_blank" rel="noreferrer noopener">final layoff tally at 21,000</a>.)</em></p>



<h3 class="wp-block-heading">March 12, 2026: Atlassian cuts 1,600 jobs to fund AI and enterprise expansion</h3>



<p class="wp-block-paragraph"><a href="https://www.computerworld.com/article/4144218/atlassian-cuts-1600-jobs-to-fund-ai-and-enterprise-expansion.html">Atlassian will reduce its global workforce</a> by approximately 10%, eliminating around 1,600 roles, as the collaboration software maker redirects capital toward artificial intelligence development and enterprise sales.</p>



<h3 class="wp-block-heading">March 11, 2026: Tech layoffs surpass 45,000 in early 2026</h3>



<p class="wp-block-paragraph">A recent analysis by RationalFX found 45,363 job cuts globally so far this year—with roughly 68% or more than 30,000 occurring in the U.S. — highlighting ongoing <a href="https://www.networkworld.com/article/4143749/tech-layoffs-surpass-45000-in-early-2026.html" target="_blank">workforce cuts even as many tech companies report strong revenue growth</a>.</p>



<h3 class="wp-block-heading">February 10, 2026: Salesforce lays off staffers as executive leadership churn continues</h3>



<p class="wp-block-paragraph"><a href="https://www.cio.com/article/4130028/salesforce-lays-off-staffers-as-executive-leadership-churn-continues.html" target="_blank">Salesforce has reduced close to 1,000 roles</a> earlier this month across teams, including marketing, product management, data analytics, and its <a href="https://www.cio.com/article/4011936/salesforce-agentforce-3-promises-new-ways-to-monitor-and-manage-ai-agents.html">Agentforce</a> AI unit, <a href="https://www.businessinsider.com/salesforce-cuts-jobs-executive-changes-2026-2">Business Insider</a> reported, quoting employees familiar with the matter.</p>



<h3 class="wp-block-heading">January 23, 2026: Amazon layoffs expected to disproportionately hit AWS and tech talent</h3>



<p class="wp-block-paragraph">As the market slows down, <a href="https://www.computerworld.com/article/4121653/amazon-layoffs-expected-to-disproportionately-hit-aws-and-tech-talent.html">AWS and other Amazon units are preparing for another round of layoffs</a>, which is expected to overwhelmingly impact tech talent. An email from HR leader Beth Galetti on Jan. 28 <a href="https://www.computerworld.com/article/4123477/amazon-confirms-16000-job-cuts-including-to-aws.html">confirmed 16,000 job cuts</a>.</p>



<h3 class="wp-block-heading">January 15, 2026: Ericsson plans to shed 1,600 jobs in Sweden</h3>



<p class="wp-block-paragraph"> Ericsson lans to cut some 1,600 jobs in Sweden, the telecommunications equipment maker said doubling down on recent cost-saving measures that have helped it weather a prolonged downturn in telecoms spending, <a href="https://www.reuters.com/business/world-at-work/ericsson-shed-1600-jobs-sweden-2026-01-15/" target="_blank" rel="noreferrer noopener">Reuters reports</a>.</p>



<h3 class="wp-block-heading">January 13, 2026: Meta plans to cut around 10% of employees in Reality Labs business</h3>



<p class="wp-block-paragraph">Meta plans to cut around 10% of the employees in its Reality Labs division who work on products including the metaverse, according to three people with knowledge of the discussions, <a href="http://meta%20plans%20to%20cut%20around%2010%25%20of%20employees%20in%20reality%20labs%20business/" target="_blank" rel="noreferrer noopener">according to The New York Times</a>.</p>



<h2 class="wp-block-heading">Layoffs in 2025</h2>



<ul class="wp-block-list">
<li>Cisco</li>



<li>Oracle</li>



<li>Windsurf</li>



<li>Intel</li>



<li>Microsoft</li>



<li>Crowdstrike</li>



<li>HPE</li>



<li>Autodesk</li>



<li>HPE</li>



<li>CISA</li>



<li>Workday</li>



<li>Salesforce</li>



<li>Meta</li>
</ul>



<h3 class="wp-block-heading">Global tech-sector layoffs surpass 244,000 in 2025</h3>



<p class="wp-block-paragraph">Economic uncertainty, elevated interest rates, and AI adoption have <a href="https://www.networkworld.com/article/4114572/global-tech-sector-layoffs-surpass-244000-in-2025.html" target="_blank">driven workforce reductions across tech companies worldwide</a>, according to a RationalFX report.</p>



<h3 class="wp-block-heading">October 28, 2025: Amazon to cut 14,000 jobs across company</h3>



<p class="wp-block-paragraph"><a href="https://www.computerworld.com/article/4080142/amazon-to-cut-14000-jobs-across-company.html">Amazon will reduce its overall workforce</a> by 14,000, cutting layers of management across the company and hiring in some areas to support its “biggest bets”.</p>



<h3 class="wp-block-heading">August 18, 2025: Cisco and Oracle to cut hundreds of Bay Area jobs</h3>



<p class="wp-block-paragraph">Tech companies Cisco and Oracle are <a href="https://www.sfchronicle.com/tech/article/cisco-oracle-layoffs-bay-area-20824135.php" target="_blank" rel="noreferrer noopener">cutting hundreds of jobs across the Bay Area</a>. Cisco will eliminate 221 positions at its Milpitas and San Francisco offices, effective Oct. 13. Oracle is reducing 101 positions in Santa Clara on the same date </p>



<h3 class="wp-block-heading">August 5, 2025: 3 weeks after acquiring Windsurf, Cognition offers staff the exit door</h3>



<p class="wp-block-paragraph">Cognition, the AI coding startup that acquired rival company Windsurf three weeks ago, laid off 30 employees last week and is offering buyouts to the roughly 200 remaining employees on the team, <a href="https://www.theinformation.com/articles/cognition-offers-buyouts-newly-acquired-windsurf-staff" target="_blank" rel="noreferrer noopener">reports The Information</a>.</p>



<h3 class="wp-block-heading">July 25, 2025, Intel to lay off 22% of workforce, CEO Tan signals ‘no more blank checks’</h3>



<p class="wp-block-paragraph"><a href="https://www.computerworld.com/article/4028896/intel-to-lay-off-22-of-workforce-as-ceo-tan-signals-no-more-blank-checks.html">Intel will reduce its workforce to 75,000 employees</a> by the end of 2025 as new CEO Lip-Bu Tan implements sweeping changes designed to transform the struggling chipmaker</p>



<h3 class="wp-block-heading">July 8, 2025, Intel layoffs begin: Chipmaker is cutting many thousands of jobs</h3>



<p class="wp-block-paragraph">Intel has begun laying off employees across the company. CEO Lip-Bu Tan told workers back in April to expect <a href="https://www.oregonlive.com/silicon-forest/2025/07/intel-layoffs-begin-chipmaker-is-cutting-many-thousands-of-jobs.html">major layoffs at Intel </a>in the coming months as the chipmaker slashes costs and overhauls its organization after years of technical setbacks and falling sales. </p>



<h3 class="wp-block-heading">July 2, 2025: Microsoft will cut 9,000 workers</h3>



<p class="wp-block-paragraph">Microsoft will lay off about 9,000 employees, a source familiar with the workforce cut <a href="https://www.nbcnews.com/business/business-news/microsoft-laying-9000-employees-latest-cuts-rcna216553">told CNBC</a>.  The cuts will reportedly affect less than 4% of Microsoft’s global workforce and will impact different teams, geographies and levels of experience. This is the latest in a string of cuts the tech giant has made this year.</p>



<h3 class="wp-block-heading">June 17, 2025: Intel looks to factory layoffs to return to profitability</h3>



<p class="wp-block-paragraph"><a href="https://www.networkworld.com/article/4008670/can-intel-cut-its-way-to-profit-with-factory-layoffs.html">Intel will lay off up to 20% of its manufacturing sector employees</a> starting in July,  according to media reports, as the company looks for options as it seeks a return to profitability. The cuts reportedly will be made around the world, but some of the layoffs will be closer to home, according to a report in The Oregonian citing an internal company memo from Intel manufacturing Vice President Naga Chandrasekaran.</p>



<h3 class="wp-block-heading">May 7, 2025: CrowdStrike to lay off 5% of staff</h3>



<p class="wp-block-paragraph"><a href="https://www.reuters.com/sustainability/crowdstrike-lay-off-5-staff-reaffirms-forecasts-2025-05-07/">CrowdStrike announced a plan to cut about 500 roles</a>, roughly 5% of its workforce, to streamline operations and reduce costs. The cybersecurity company will incur about $36 million to $53 million in charges related to the layoffs</p>



<h3 class="wp-block-heading">March 6, 2025: HPE cuts 2,500 jobs, remains committed to Juniper buy</h3>



<p class="wp-block-paragraph">CEO Antonio Neri told Wall Street analysts that <a href="https://www.networkworld.com/article/3840596/hpe-cuts-2500-workers-expects-juniper-buy-to-close-end-of-25-faces-tariff-issues.html">HPE would begin implementing a cost-cutting program involving layoffs </a>of about 2,500 employees over the next 18 months. HPE employs about 61,000 people worldwide.</p>



<h3 class="wp-block-heading">Feb. 27, 2025: Autodesk to lay off 9% of workforce</h3>



<p class="wp-block-paragraph">Software maker Autodesk is laying off 1,350 staff. With the rise of subscription and multi-year contracts billed annually, and self-service enablement, it finds it needs fewer sales staff, <a href="https://adsknews.autodesk.com/en/news/022725-employee-message/">CEO Andrew Anagnost said in a message to employees</a>. And with its cloud, platform, and AI products proving most profitable, it’s concentrating its staff and investments there. </p>



<h3 class="wp-block-heading">Feb. 27, 2025: HP to lay off 2,000 more</h3>



<p class="wp-block-paragraph">As part of an ongoing restructuring, HP plans to lay off up to another 2,000 workers. In recent weeks, the company has tried — unsuccessfully — to do away with telephone support staff by <a href="https://www.pcworld.com/article/2617767/hp-forced-callers-to-wait-15-minutes-before-connecting-to-support-staff.html">forcing callers to wait for at least 15 minutes</a> if they refuse to use self-service support resources online. The company swiftly backtracked, but wider job cuts are still on. </p>



<h3 class="wp-block-heading">Feb. 21, 2025: <a href="https://www.csoonline.com/article/3829710/firing-of-130-cisa-staff-worries-cybersecurity-industry.html">CISA lays off 130</a></h3>



<p class="wp-block-paragraph">Government employees get laid off too: In this case, 130 workers at the US Cybersecurity and Infrastructure Security Agency are being shown the door as a result of a DOGE decision. Cybersecurity experts are concerned that the cuts will harm the international collaborations that CISA has fostered, quite apart from their concerns about the security of the DOGE layoff process itself.</p>



<h3 class="wp-block-heading">Feb. 5, 2025: <a href="https://www.computerworld.com/article/3817887/workday-to-cut-1750-jobs-shift-focus-to-ai-and-global-expansion.html">Workday lays off 1,750</a></h3>



<p class="wp-block-paragraph">As it moves to invest more in AI and international growth, Workday is laying off 8.5% of its workforce and disposing of unused office space. Some analysts fear the cutbacks will affect the company’s customer service — unless AI can pick up the slack.</p>



<h3 class="wp-block-heading">Feb. 4, 2025: Salesforce lays off over 1,000</h3>



<p class="wp-block-paragraph">At the same time as it’s hiring sales staff for its new artificial intelligence products, Salesforce is laying off over 1,000 workers across the company, according to Bloomberg. As of June, 2024, the company had over 72,000 employees, according to its website. Salesforce did not comment on the report. In 2024 the company reportedly laid off around 1,000 staff too, in two waves: January and July.</p>



<h3 class="wp-block-heading">Jan. 14, 2025: Meta will lay off 5% of workforce</h3>



<p class="wp-block-paragraph">Mark Zuckerberg told Meta employees he intended to “move out the low performers faster” in an internal memo reported by Bloomberg. The memo announced that the company will lay off 5% of its staff, or around 3,600 staff, beginning Feb. 10. The company had already reduced its headcount by 5% in 2024 through natural attrition, the memo said. Among those leaving the company will be staff previously responsible for fact checking of posts on its social media platforms in the US, as the company begins relying on its users to police content.</p>



<h2 class="wp-block-heading">Tech layoffs in 2024</h2>



<ul class="wp-block-list">
<li>Equinix</li>



<li>AMD</li>



<li>Freshworks</li>



<li>Cisco</li>



<li>General Motors</li>



<li>Intel</li>



<li>OpenText</li>



<li>Microsoft</li>



<li>AWS</li>



<li>Dell</li>
</ul>



<h3 class="wp-block-heading">Nov. 26, 2024: <a href="https://www.networkworld.com/article/3613399/equinix-to-cut-3-of-staff-amidst-the-greatest-demand-for-data-center-infrastructure-ever.html">Equinix to cut 3% of staff</a></h3>



<p class="wp-block-paragraph">Despite intense demand for its data center capacity, Equinix is planning to lay off 3% of its workforce, or around 400 employees. The announcement followed the appointment of Adaire Fox-Martin to replace Charles Meyers as CEO and the departures of two other senior executives, CIO Milind Wagle and CISO Michael Montoya.</p>



<h3 class="wp-block-heading">Nov. 13, 2024: <a href="https://www.networkworld.com/article/3605016/amd-to-cut-4-of-workforce-to-prioritize-ai-chip-expansion-to-rival-nvidia.html#:~:text=Workforce%20reduction%20comes%20amid%20strong,shift%20in%20focus%20toward%20AI.&amp;text=Advanced%20Micro%20Devices%20(AMD)%20is,Nvidia's%20lead%20in%20the%20sector.">AMD to cut 4% of workforce</a></h3>



<p class="wp-block-paragraph">AMD will lay off around 1,000 employees as it pivots towards developing AI-focused chips, it said. The move came as a surprise to staff, as the company also reported strong quarterly earnings. </p>



<h3 class="wp-block-heading">Nov. 7, 2024: <a href="https://www.cio.com/article/3601088/freshworks-lays-off-660-about-13-percent-of-its-global-workforce-despite-strong-earnings-profits.html">Freshworks lays off 660</a></h3>



<p class="wp-block-paragraph">Enterprise software vendor Freshworks laid off around 660 staff, or around 13% of its headcount, despite reporting increased revenue and profits in its fourth fiscal quarter. The company described the layoffs as a realignment of its global workforce.</p>



<h3 class="wp-block-heading">Sept. 17, 2024: <a href="https://www.networkworld.com/article/3486901/cisco-to-cut-7-of-workforce-restructure-product-groups.html">Cisco lays off 6,000</a></h3>



<p class="wp-block-paragraph">After laying off around 4,200 staff in February, Cisco is at it again, laying off another 6,000 or around 7% of its workforce. Among the divisions affected were its threat intelligence unit, Talos Security. </p>



<h3 class="wp-block-heading">Aug. 20, 2024: <a href="https://www.cio.com/article/3489323/gm-software-layoffs-could-signal-a-shift-in-digital-transformation-strategy.html">General Motors lays off 1,000 software staff</a></h3>



<p class="wp-block-paragraph">More than 1,000 software and services staff are on the way out at General Motors, signalling that it could be rethinking its digital transformation strategy. In an internal memo, the company said that it was moving resources to its highest-priority work and flattening hierarchies.</p>



<h3 class="wp-block-heading">August 1, 2024: <a href="https://www.computerworld.com/article/3480715/intel-fires-15000-employees-as-it-intensifies-focus-on-ai.html">Intel removes 15,000 roles</a></h3>



<p class="wp-block-paragraph">Intel plans to cut its workforce by around 15% to reduce costs after a disastrous second quarter. Revenue for the three months to June 29 stagnated at around $12.8 billion, but net income fell 85% to $83 million, prompting CEO Pat Gelsinger to bring forward a company-wide meeting in order to announce that 15,000 staff would lose their jobs. “This is an incredibly hard day for Intel as we are making some of the most consequential changes in our company’s history,” Gelsinger wrote in an email to staff, continuing: “Our revenues have not grown as expected — and we’ve yet to fully benefit from powerful trends, like AI. Our costs are too high, our margins are too low. We need bolder actions to address both — particularly given our financial results and outlook for the second half of 2024, which is tougher than previously expected.”</p>



<h3 class="wp-block-heading">July 4, 2024: <a href="https://www.computerworld.es/article/2513686/opentext-despedira-a-cerca-de-1-200-empleados.html">OpenText to lay off 1,200</a></h3>



<p class="wp-block-paragraph">OpenText said it will lay off 1,200 staff, or about 1.7% of its workforce, in a bid to save around $100 million annually. It plans to hire new sales and engineering staff in other areas in 2025, it said.</p>



<h3 class="wp-block-heading">June 4, 2024: <a href="https://www.networkworld.com/article/2138075/microsoft-lays-off-staffers-from-its-azure-division.html">Microsoft lays off staff in Azure division</a></h3>



<p class="wp-block-paragraph">Microsoft laid off staff in several teams supporting its cloud services, including Azure for Operations and Mission Engineering. The company didn’t say exactly how many staff were leaving.</p>



<h3 class="wp-block-heading">April 4, 2024: <a href="https://www.cio.com/article/2081437/amazon-downsizes-aws-in-a-fresh-cost-cutting-round.html">Amazon downsizes AWS</a> in a fresh cost-cutting round</h3>



<p class="wp-block-paragraph">Amazon announced hundreds of layoffs in the sales and marketing teams of its AWS cloud services division — and also in the technology development teams for its physical retail stores, as it stepped back from efforts to generalize the “<a href="https://www.cio.com/article/2079910/amazon-drops-just-walk-out-technology-at-its-us-retail-locations.html">Just Walk Out</a>” technology built for its Amazon Fresh grocery stores. </p>



<h3 class="wp-block-heading">April 1, 2024: <a href="https://investors.delltechnologies.com/static-files/d6e82f58-d417-422f-b2f3-4d08d498abd4" target="_blank" rel="noreferrer noopener">Dell acknowledges 13,000 job cuts</a></h3>



<p class="wp-block-paragraph">Dell Technologies’ <a href="https://investors.delltechnologies.com/static-files/d6e82f58-d417-422f-b2f3-4d08d498abd4" target="_blank" rel="noreferrer noopener">latest 10K filing with the US Securities and Exchange Commission</a> disclosed that the company had laid off 13,000 employees over the course of the 2023 fiscal year; it characterized the layoffs and other reorganizational moves as cost-cutting measures. “These actions resulted in a reduction in our overall headcount,” the company said. A comparison to the previous year’s 10K filing, performed by The Register, found that Dell employed 133,000 people at that point, compared to 120,000 as of February 2024. Dell announced layoffs of 6,650 staffers on Feb. 6, but it is unclear whether those cuts were reflected in the numbers from this year’s 10K statement.</p>



<p class="wp-block-paragraph"><em><a href="https://www.computerworld.com/article/3816662/tech-layoffs-in-2024-a-timeline.html">See news of earlier layoffs.</a></em></p>



<p class="wp-block-paragraph"></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Assaf Keren Appointed New CISO of Meta]]></title>
<description><![CDATA[He replaces Guy Rosen, who announced his retirement from the company after 13 years. The post Assaf Keren Appointed New CISO of Meta appeared first on SecurityWeek. This article has been indexed from SecurityWeek Read the original article: Assaf Keren…
Read more →
The post Assaf Keren Appointed N...]]></description>
<link>https://tsecurity.de/de/3688650/it-security-nachrichten/assaf-keren-appointed-new-ciso-of-meta/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3688650/it-security-nachrichten/assaf-keren-appointed-new-ciso-of-meta/</guid>
<pubDate>Thu, 23 Jul 2026 12:10:42 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>He replaces Guy Rosen, who announced his retirement from the company after 13 years. The post Assaf Keren Appointed New CISO of Meta appeared first on SecurityWeek. This article has been indexed from SecurityWeek Read the original article: Assaf Keren…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/assaf-keren-appointed-new-ciso-of-meta/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/assaf-keren-appointed-new-ciso-of-meta/">Assaf Keren Appointed New CISO of Meta</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[IT Security News Hourly Summary 2026-07-23 12h : 15 posts]]></title>
<description><![CDATA[15 posts were published in the last hour 10:4 : Assaf Keren Appointed New CISO of Meta 10:4 : PyPI hardens package security with new upload restrictions 10:4 : Nine-Year-Old RefluXFS Linux Flaw Gives Local Users Root on Default RHEL…
Read more →
The post IT Security News Hourly Summary 2026-07-23...]]></description>
<link>https://tsecurity.de/de/3688649/it-security-nachrichten/it-security-news-hourly-summary-2026-07-23-12h-15-posts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3688649/it-security-nachrichten/it-security-news-hourly-summary-2026-07-23-12h-15-posts/</guid>
<pubDate>Thu, 23 Jul 2026 12:10:35 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>15 posts were published in the last hour 10:4 : Assaf Keren Appointed New CISO of Meta 10:4 : PyPI hardens package security with new upload restrictions 10:4 : Nine-Year-Old RefluXFS Linux Flaw Gives Local Users Root on Default RHEL…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/it-security-news-hourly-summary-2026-07-23-12h-15-posts/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/it-security-news-hourly-summary-2026-07-23-12h-15-posts/">IT Security News Hourly Summary 2026-07-23 12h : 15 posts</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Principles every enterprise must test before the attack arrives]]></title>
<description><![CDATA[I haven’t slept much in the past few weeks. Not because of some theoretical cyber risk that keeps many executives awake, but because reality just delivered a real wake-up call to our industry — a call that every executive must answer, now.



Imagine this: A major global enterprise, a company mos...]]></description>
<link>https://tsecurity.de/de/3688625/it-nachrichten/principles-every-enterprise-must-test-before-the-attack-arrives/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3688625/it-nachrichten/principles-every-enterprise-must-test-before-the-attack-arrives/</guid>
<pubDate>Thu, 23 Jul 2026 12:04:32 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">I haven’t slept much in the past few weeks. Not because of some theoretical cyber risk that keeps many executives awake, but because reality just delivered a real wake-up call to our industry — a call that every executive must answer, now.</p>



<p class="wp-block-paragraph">Imagine this: A major global enterprise, a company most of us interact with indirectly every single day, wakes up to find its entire digital environment obliterated. Thousands of employees in dozens of offices and remote locations are suddenly offline. Customers are cut off, supply chains grind to a halt and regulators are notified with a chilling admission: “We have no idea when we’ll be back.”</p>



<p class="wp-block-paragraph">This wasn’t ransomware. There was no negotiation, no decryption key to buy, no easy way out. It was destruction — deliberate, coordinated and geopolitically motivated — not monetary.</p>



<p class="wp-block-paragraph">As a chief customer officer who’s worked with countless customers on cyberattack risks, my perspective hits a bit differently than a CISO or a CTO. I see the aftermath, not just the attack surface. I see the faces behind the tickets, the operations team locked out of their own systems, the support agent answering panicked calls at dawn. And I ask: How many organizations have actually stress-tested their response to this scenario — not a hypothetical, but this very real, lights-out event? Here’s what every leader needs to confront today:</p>



<h2 class="wp-block-heading">Recovery is not just a technical exercise</h2>



<p class="wp-block-paragraph">The first assumption to break during a real crisis is <a href="https://www.cio.com/article/4165019/your-cloud-strategy-is-incomplete-without-a-cyber-recovery-plan.html">the belief that recovery is purely technical</a>.</p>



<p class="wp-block-paragraph">Many organizations have done tabletop exercises and have a backup and recovery playbook, so they feel prepared. They can <a>point to</a> backup windows, retention schedules and immutability controls. The moment a true blackout happens, a different reality surfaces. The people who own the recovery steps either do not know each other, lack the authority to make decisions without supervisor approval or need guidance from offline systems.</p>



<p class="wp-block-paragraph">The reality is that technical infrastructure almost always holds up better than human infrastructure. Organizations have built their recovery strategy around the assumption that someone competent will be awake, available and empowered when a cyber event happens.</p>



<p class="wp-block-paragraph">Still, backups are only as good as their independence. Let’s be blunt: If your recovery infrastructure shares identity, authentication or network trust with your Microsoft tenant (such as Azure, Microsoft 365 or Teams), you don’t actually have a recovery plan; you have a false sense of one — and a liability. A <a href="https://www.veeam.com/company/press-release/veeam-report-reveals-a-market-wide-shift-from-recovery-confidence-to-proven-data-resilience-amid-ransomware-threats-and-ai-adoption.html">recent survey</a> found that while 90% of organizations express confidence in their ability to recover from a cyber incident, fewer than one in three ransomware victims fully recovered their data.</p>



<p class="wp-block-paragraph">True resilience means immutable, air-gapped backups, untouchable by the same compromise. Anything less is an illusion. I talk to customers about their recovery plans constantly. The customers who have rehearsed all scenarios sleep soundly. Those who haven’t? They’re rolling the dice.</p>



<h2 class="wp-block-heading">Most business continuity plans ignore ‘total blackout’</h2>



<p class="wp-block-paragraph">I’ve reviewed hundreds of business continuity plans. Almost all assume partial failures — a region, an application, a data center. But what if every system, in every country, goes dark simultaneously? That’s an entirely different playbook. If your team hasn’t run a drill for a global, simultaneous outage, you’re not prepared. The probability is low, but the cost of being unready is existential.</p>



<p class="wp-block-paragraph">Connected devices, OT systems, field hardware, partner integrations — they all plug into your enterprise network. When the core collapses, it’s not just IT at risk. It’s operational technology, physical safety systems and in regulated sectors, potentially human lives. Understanding and testing those interdependencies is non-negotiable.</p>



<p class="wp-block-paragraph">This is also where boards need to change the conversation. A <a href="https://www.diligent.com/resources/research/cybersecurity-audit">study found</a> that only 5% of companies have cybersecurity experts on their board of directors. Recovery time objectives (RTOs) should not be buried in technical appendices. It’s all jargon to boards. That makes translation essential. RTOs must be explained in terms of business impact. “We can recover in four hours” is a technical statement. “Every hour of downtime costs us $2.3M and creates regulatory exposure in three jurisdictions” is a board statement.</p>



<p class="wp-block-paragraph">That is the level of clarity leaders need.</p>



<p class="wp-block-paragraph">The most prepared organizations do not wait for an incident to educate the board. They bring the conversation forward proactively. They frame recovery in business terms: revenue, regulatory standing, customer trust and brand reputation.</p>



<p class="wp-block-paragraph">The most effective framing is often simple. Show the most critical systems. Show what happens if each one is down for one hour, four hours, 24 hours and 72 hours. Show the current recovery capability against each and then show the gap.</p>



<p class="wp-block-paragraph">If your board is not demanding real answers, your business continuity strategy is likely underfunded and your business is exposed. This is a risk conversation worth forcing because the consequences do not stay inside IT. They can show up in customer churn or missed revenue and ruin an organization’s reputation.</p>



<h2 class="wp-block-heading">Threat intelligence must be actionable, not archived</h2>



<p class="wp-block-paragraph">Geopolitical attacks, hacktivist campaigns and nation-state targeting aren’t abstract threats. They are active risks, and that intelligence cannot languish in the security team’s inbox. Executive leadership must be looped in — and immediately — so gaps can be closed before they’re exploited. Too often, intelligence enters the security operations function and never reaches the teams responsible for recovery infrastructure or executive decision-making.</p>



<p class="wp-block-paragraph">If a threat actor is targeting a specific class of backup agents, the team responsible for those agents needs to know now, not two weeks from now. If intelligence suggests destructive activity against a sector, recovery owners need to validate isolation, access paths and restoration procedures immediately. If geopolitical tension increases the likelihood of targeting, executive leadership needs to understand what exposure exists and what actions are being taken. The organizations that survive aren’t just the best at incident response. They’re the ones who anticipated, rehearsed and invested <em>before</em> the attack.</p>



<p class="wp-block-paragraph">Part of investing in a recovery strategy requires closing the loop between signal and action. The most prepared organizations have already mapped their critical recovery dependencies to specific threat categories. When intelligence touches one of those categories, there is a named owner and a clear set of actions. No guessing or forwarding emails into the void is needed because the distance between the warning and the employees’ ability to do something is shortened.</p>



<p class="wp-block-paragraph">Looking ahead, the conversation will continue to evolve beyond traditional cyber response. Because in an AI-enabled enterprise, the new question is whether the data within those systems can still be trusted. When AI systems make decisions based on enterprise data, the attack surface becomes the data’s accuracy. A threat actor who quietly corrupts a dataset over 90 days before a recovery event has done more damage than just downtime. They can poison the inputs driving decisions across the business.</p>



<p class="wp-block-paragraph">Regardless of how AI will change threat intelligence and cyber response, these principles remain the same. Know your problem, whether structural or technological. Ensure your human infrastructure keeps pace with your technical infrastructure, with clear cross-functional ownership and the tools and knowledge to act autonomously. Communicate with your boards often — and correctly.</p>



<p class="wp-block-paragraph">Let’s not wait for the next headline to ask, “Are we ready?” Have those conversations <em>now</em>. Test your assumptions. Close your gaps. Because in today’s threat landscape, resilience isn’t IT’s job — it’s everyone’s mandate.</p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Assaf Keren Appointed New CISO of Meta]]></title>
<description><![CDATA[He replaces Guy Rosen, who announced his retirement from the company after 13 years.
The post Assaf Keren Appointed New CISO of Meta appeared first on SecurityWeek.]]></description>
<link>https://tsecurity.de/de/3688608/it-security-nachrichten/assaf-keren-appointed-new-ciso-of-meta/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3688608/it-security-nachrichten/assaf-keren-appointed-new-ciso-of-meta/</guid>
<pubDate>Thu, 23 Jul 2026 12:00:44 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>He replaces Guy Rosen, who announced his retirement from the company after 13 years.</p>
<p>The post <a href="https://www.securityweek.com/assaf-keren-appointed-new-ciso-of-meta/">Assaf Keren Appointed New CISO of Meta</a> appeared first on <a href="https://www.securityweek.com/">SecurityWeek</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[7 Wege, Risk Assessments an die Wand zu fahren]]></title>
<description><![CDATA[Wenn das Risk Assessment zu kurz greift, ist guter Rat teuer.Raushan_films | shutterstock.com



Ein Cyber Risk Assessment unterstützt dabei, potenzielle Bedrohungen und Schwachstellen für wichtige digitale und physische Unternehmens-Assets zu identifizieren, zu bewerten und zu priorisieren. Trot...]]></description>
<link>https://tsecurity.de/de/3687937/it-security-nachrichten/7-wege-risk-assessments-an-die-wand-zu-fahren/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687937/it-security-nachrichten/7-wege-risk-assessments-an-die-wand-zu-fahren/</guid>
<pubDate>Thu, 23 Jul 2026 06:09:17 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2025/07/Raushan_films-shutterstock_2452558257_16z9.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Manager Headache 16z9 GERMANY ONLY" class="wp-image-4022500" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption">Wenn das Risk Assessment zu kurz greift, ist guter Rat teuer.</figcaption></figure><p class="imageCredit">Raushan_films | shutterstock.com</p></div>



<p class="wp-block-paragraph">Ein <a href="https://www.computerwoche.de/article/3552765/6-risk-assessment-frameworks-im-vergleich.html" target="_blank">Cyber Risk Assessment</a> unterstützt dabei, potenzielle Bedrohungen und Schwachstellen für wichtige digitale und physische Unternehmens-Assets zu identifizieren, zu bewerten und zu priorisieren. Trotzdem stolpern in diesem Zusammenhang immer noch viele CISOs und Sicherheitsentscheider über Fallstricke, die sie daran hindern, ihre Risk-Assessment-Ziele vollumfänglich zu erreichen.</p>



<p class="wp-block-paragraph">Welche das konkret sind und wie man sie gewissenhaft meidet, haben wir im Gespräch mit Security-Experten herausgefunden.</p>



<h2 class="wp-block-heading">1. Einfach nur abhaken</h2>



<p class="wp-block-paragraph">Die wohl größte Falle im Zusammenhang mit Risk Assessments besteht darin, diese als Checkliste zu behandeln – statt als Entscheidungshilfe, die mit realem Business Impact oder Threat-Szenarien verknüpft ist. <a href="https://www.linkedin.com/in/shirsendu64" target="_blank" rel="noreferrer noopener">Shirsendu Mondal</a>, Security-Forscher an der University of North Carolina, klärt auf: „Wenn sich Ihre Risikobewertung nur noch darum dreht, irgendwelche Kästchen abzuhaken, verlieren Sie die Fähigkeit, die tatsächlichen Risiken einer Umgebung zu Tage zu fördern. Das Ziel eines solchen Assessments sollte jedoch sein, aufzudecken, an welchen Stellen tatsächlich eine Gefährdungslage besteht.“ </p>



<p class="wp-block-paragraph">Der beste Weg, diese „Selbstzufriedenheits“-Falle zu umgehen, besteht laut dem Forscher darin, einen kontextorientierten Ansatz zu fahren: „Fragen Sie konkret danach, wo sich die betreffende Ressource befindet, wer darauf zugreifen kann, welche Daten sie berührt, wie wichtig sie für den Betrieb ist und was passiert, wenn sie ausfällt. Risiken sollten stets mit den geschäftlichen Auswirkungen korreliert werden – nicht bloß mit technischen Erkenntnissen.“</p>



<p class="wp-block-paragraph">Eben, weil Risiken seiner Ansicht nach mehr sind als nur technische Probleme, empfiehlt Mondal Security-Entscheidern, andere Führungskräfte aus dem Unternehmen in das Security-Gefüge zu integrieren – etwa aus der IT und dem Betrieb.</p>



<h2 class="wp-block-heading">2. Ergebnisse schönreden</h2>



<p class="wp-block-paragraph">Besonders in schwierigen Zeiten ist es das A und O, den Stakeholdern (und sich selbst) gegenüber ehrlich zu sein. Diese Auffassung vertritt auch <a href="https://www.linkedin.com/in/dr-pablo-riboldi" target="_blank" rel="noreferrer noopener">Pablo Riboldi</a>, CISO beim Softwareunternehmen BairesDev: „Wenn die Ergebnisse entmutigend sind, sollte man einfach zugeben, dass sich die Bedrohungslage deutlich schneller entwickelt hat, als über das bisherige Bewertungs-Framework abzusehen war.“</p>



<p class="wp-block-paragraph">Anstatt einfach nur <a href="https://www.computerwoche.de/article/3495294/schwachstellen-managen-die-6-besten-vulnerability-management-tools.html" target="_blank">Schwachstellen-Listen</a> zu übergeben, rät Riboldi dazu, konkrete Angriffsszenarien abzubilden: „Zum Beispiel, indem Sie die drei kritischsten Assets priorisieren und ein eingehendes Risk Assessment durchführen. So lässt sich auch ein unmittelbarer Mehrwert demonstrieren.“</p>



<h2 class="wp-block-heading">3. Scope falsch einschätzen</h2>



<p class="wp-block-paragraph">Nicht wenige CISOs sichern Dokumentenkontrollen ab, haken Compliance-Checkboxen ab und erstellen ein Risikoregister, das den Eindruck vermittelt, dass alles in Ordnung ist. Der Schein trügt jedoch des Öfteren, wie <a href="https://www.linkedin.com/in/deniscalderone" target="_blank" rel="noreferrer noopener">Denis Calderone</a>, CTO beim Sicherheitsdienstleister Suzu Labs, aus eigener Erfahrung weiß: „In solchen Fällen kommt es nicht selten vor, dass sich niemand die Mühe gemacht hat, zu testen, ob diese Kontrollen tatsächlich funktionieren. Oder, ob der Scope der Risikobewertung auch das abdeckt, worauf es wirklich ankommt.“</p>



<p class="wp-block-paragraph">Der Technologieentscheider hat dazu auch ein Beispiel aus der Praxis auf Lager: „Wenn das Risk Assessment die Produktionsserver und das Unternehmensnetzwerk umfasst, der alte Dev-Rechner, ein <a href="https://www.cowo.de/a/4195045" target="_blank" rel="noreferrer noopener">Drittanbieter-Portal</a> oder ein verwaister API-Endpunkt dabei aber außen vor bleiben, ist das ungünstig. Angreifer betrachten die gesamte Umgebung und finden genau den Einstiegspunkt, der zuvor als nicht bewertungswürdig erachtet wurde.“</p>



<p class="wp-block-paragraph">Künstliche Intelligenz (KI) <a href="https://www.computerwoche.de/article/4155663/6-wege-uber-ki-gehackt-zu-werden.html" target="_blank">verschlimmere die Situation</a> laut Calderone noch: Unternehmen setzten vielfach KI-Tools ein, verknüpften diese mit internen Systemen und gewährten ihnen Zugriff auf sensible Daten – ohne dass das in die Risikobewertung einfließe. Der Experte warnt: „Wenn Ihr Risk Assessment aufgesetzt wurde, bevor Ihr Unternehmen damit begonnen hat, KI in Workflows zu integrieren, ist es bereits veraltet.“</p>



<h2 class="wp-block-heading">4. Annahmen nicht hinterfragen</h2>



<p class="wp-block-paragraph">Wenn sich die Zielsetzung einer Risikobewertung in Richtung „Hauptsache bestanden“ verschiebt, stellt das vielleicht <a href="https://www.computerwoche.de/article/4149093/wenn-die-audit-falle-zuschnappt.html" target="_blank">Auditoren</a> zufrieden. Die Unternehmensleitung könnte dadurch jedoch in die Irre geführt werden, wie <a href="https://www.linkedin.com/in/amitbasu" target="_blank" rel="noreferrer noopener">Amit Basu</a>, CIO und CISO beim Schifffahrtsunternehmen International Seaways, erklärt: „Führungskräfte und Vorstandsmitglieder sehen ein fertiges Risikoregister und gehen davon aus, dass das Unternehmen geschützt ist. Unterdessen bleiben echte Bedrohungen unberücksichtigt, weil sie nicht nahtlos in den Bewertungsrahmen passten. Dieser Fallstrick ist unsichtbar – er verbirgt sich hinter einem Dashboard.“</p>



<p class="wp-block-paragraph">Nach Ansicht von Basu ist ein Risk Assessment nur so gut, wie die ihm zugrundeliegenden Annahmen: „Diese sollten Sie explizit dokumentieren und immer dann überprüfen, wenn sich das Business verändert, eine Bedrohungslage verschiebt oder ein Sicherheitsvorfall eine Lücke zu Tage fördert.“</p>



<p class="wp-block-paragraph">Ein Risk Assessment, so der CISO, sei nicht als fertiges Produkt zu betrachten, sondern als lebendiger Beitrag zu einem fortlaufenden Dialog zwischen Security-Abteilung und Unternehmen.</p>



<h2 class="wp-block-heading">5. Risiken nicht mit Impact verknüpfen</h2>



<p class="wp-block-paragraph">Probleme in den Hintergrund zu rücken oder herunterzuspielen, fällt deutlich leichter, wenn man den Zusammenhang zwischen Risiko und Business einfach ausblendet. Das erkennt auch <a href="https://www.linkedin.com/in/mooreds" target="_blank" rel="noreferrer noopener">Dan Moore</a>, Senior Director of Strategy and Identity Standards beim CIAM-Spezialisten FusionAuth, an. Er warnt jedoch vor den Folgen dieses Gebarens: „So wird es sich diffizil gestalten, tatsächliche Risiken zu kommunizieren. Schlimmer noch: Es liefert den Mitgliedern des Security-Teams einen Vorwand, sich darüber zu beschweren, dass sie missverstanden oder nicht wertgeschätzt werden – und das beeinträchtigt die Effektivität des Teams.“</p>



<p class="wp-block-paragraph">Der Manager erachtet es als wichtig, stattdessen konkret zu sein und zielgerichtet vorzugehen: „Verzichten Sie auf Angaben wie eine Patch-Compliance von 95 Prozent. Sprechen Sie stattdessen über das Risiko, das nicht gepatchte Systeme für das Unternehmen darstellen.“</p>



<p class="wp-block-paragraph">Dabei seien manchen Systemen – etwa Legacy-Konstrukten, die nicht mit dem Internet verbunden sind – geringere Risiken inhärent als anderen, selbst wenn sie dieselben Patch-Probleme aufwiesen, meint Moore und empfiehlt, diese Tatsache anzuerkennen und die Reaktion entsprechend abzuwägen.  </p>



<h2 class="wp-block-heading">6. Compliance mit Security verwechseln</h2>



<p class="wp-block-paragraph">„Compliance allein ist weder ein Garant für robuste Security, noch erfüllt sie die Mindestanforderungen für einen wirksamen Schutz“, hält <a href="https://www.linkedin.com/in/adrieldesautels" target="_blank" rel="noreferrer noopener">Adriel Desautels</a>, CEO der Security-Beratung Netragard, fest.</p>



<p class="wp-block-paragraph">Unternehmen gerieten demnach besonders oft in diese Falle, wenn sie für Penetrationstests externe Firmen beauftragten, die sich auf Compliance konzentrieren und gleichzeitig „erstklassige Dienstleistungen“ versprechen. „In Wahrheit liefern diese oft automatisierte Scans, die als manuelle Tests getarnt sind“, meint Desautels.</p>



<p class="wp-block-paragraph">Das Ergebnis sei ein falsches Sicherheitsgefühl, warnt der Manager: „Vergegenwärtigen Sie sich einfach, dass bei jedem größeren Sicherheitsvorfall der letzten zehn Jahre eine Organisation beteiligt war, die zum Zeitpunkt des Angriffs alle Compliance-Vorgaben erfüllt hatte.“</p>



<h2 class="wp-block-heading">7. Risiken nicht vollständig verstehen</h2>



<p class="wp-block-paragraph">Unternehmen betrachten Risk Assessments oft als eine Art „Schwachstellenkatalogisierung“, bei der es darum geht, Lücken zu finden, Schweregrade zu erfassen und Audits zu bestehen. Letzteres heißt allerdings nicht, dass die Risiken auch verstanden wurden.</p>



<p class="wp-block-paragraph">Geht es nach <a href="https://www.linkedin.com/in/safiraza" target="_blank" rel="noreferrer noopener">Safi Raza</a>, Senior Director for Cybersecurity bei Fusion Risk Management, sollten sich CISOs darauf konzentrieren, technische Risikosignale mit betrieblichen Folgen zu verknüpfen: „Dazu muss man verstehen, welche Services betroffen sind, wie sich Störungen ausbreiten und was das für den Umsatz, die Kunden oder regulatorische Verpflichtungen bedeutet.“</p>



<p class="wp-block-paragraph">Der Experte rät in diesem Zusammenhang dazu, zunächst von statischen Bewertungen zu einer kontinuierlichen, kontextbezogenen Risikotransparenz überzugehen, um sicherzustellen, dass Risiken nicht nur technisch verstanden werden.“ (fm)</p>



<p class="wp-block-paragraph"><strong>Dieser Artikel ist </strong><a href="https://www.csoonline.com/article/4189703/7-cyber-risk-assessment-gotchas-to-avoid.html" target="_blank"><strong>im Original</strong></a><strong> bei unserer Schwesterpublikation CSOonline.com erschienen.</strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[German law enforcement claims to have ‘dismantled’ mega phishing-as-a-service group Kratos]]></title>
<description><![CDATA[A global law enforcement crackdown has seized infrastructure serving the massive phishing-as-a-service (PhaaS) group Kratos, as well resulting in the arrest of an unnamed Kratos “developer and technical administrator” in Indonesia. 



The effort was managed by German law enforcement and involved...]]></description>
<link>https://tsecurity.de/de/3687784/it-security-nachrichten/german-law-enforcement-claims-to-have-dismantled-mega-phishing-as-a-service-group-kratos/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687784/it-security-nachrichten/german-law-enforcement-claims-to-have-dismantled-mega-phishing-as-a-service-group-kratos/</guid>
<pubDate>Thu, 23 Jul 2026 01:57:56 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">A global law enforcement crackdown has seized infrastructure serving the massive phishing-as-a-service (PhaaS) group Kratos, as well resulting in the arrest of an unnamed Kratos “developer and technical administrator” in Indonesia. </p>



<p class="wp-block-paragraph">The effort was managed by German law enforcement and involved agencies from the US, Indonesia and other countries.</p>



<p class="wp-block-paragraph">Although a <a href="https://www.bka.de/DE/Presse/Listenseite_Pressemitteilungen/2026/Presse2026/260720_PM_Kratos.html" target="_blank" rel="noreferrer noopener">German statement</a> claimed that the Kratos infrastructure “has been completely disabled” and that “Kratos-supported phishing campaigns can no longer be carried out,” cybersecurity analysts and consultants question how much of a dent in enterprise phishing activity will result, and how long it will last.</p>



<p class="wp-block-paragraph">“A server seizure and a single arrest overseas remove infrastructure, not the intellectual property,” said <a href="https://my.idc.com/getdoc.jsp?containerId=PRF004767" target="_blank" rel="noreferrer noopener">Frank Dickson</a>, group VP for security at IDC. “PhaaS kits get cloned, forked and resold routinely, and the 1,800 Kratos customers didn’t vanish. They just lost a vendor in a market where vendors get replaced fast.”</p>



<p class="wp-block-paragraph">He added, “seizing 200-plus servers and arresting the developer pulls a major supplier out of that specific niche. It doesn’t touch the broader phishing economy. For every roach that you squish, there are a hundred that you do not see.”</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/noah-m-kenney-27499a166/" target="_blank" rel="noreferrer noopener">Noah Kenney</a>, principal consultant at Digital 520, takes an even more pessimistic view, arguing that there might not even be that much of a short-term phishing slowdown. </p>



<p class="wp-block-paragraph">“What makes this different from a botnet or ransomware takedown is that the people running the attacks were never part of the organization. Kratos was just a vendor,” Kenney said. “The 1,800 customers who bought it still have their target lists, their sending infrastructure and whatever access they had already established. The tooling went dark, but the people phishing your employees last week are still working, shopping for a replacement that already exists. Enterprises should not read this as a drop in (likely) threat volume.”</p>



<p class="wp-block-paragraph">One thing that the security community seems to agree on is that Kratos was a major player in the lucrative PhaaS space. But precisely determining the percentage of PhaaS activity controlled by Kratos is impossible, given that Kratos sold their kits to others. Security researchers even disagree on what they should call Kratos kits.</p>



<p class="wp-block-paragraph">“Microsoft tracks this kit as SneakyLog, others tie it to Sneaky 2FA, and KnowBe4 disputes the lineage entirely. When the security industry cannot agree on what a kit is to be called, that is because renaming and reselling is continuous rather than something that happens after a raid,” Kenney said. “What actually changed this time is the arrest and the [shutdown of the] servers. Standing up new hosting is only a weekend of work, but replacing a developer who understood how to keep an adversary in the middle proxy stable and evasive at scale is harder.”</p>



<p class="wp-block-paragraph">IDC’s Dickson added that the biggest value from the takedown is in the information gleaned from the seized servers. </p>



<p class="wp-block-paragraph">“Kratos operated in the adversary-in-the-middle category, generating convincing fake Microsoft 365 login pages that harvest session tokens and step past MFA, the exact technique behind a lot of the business email compromise activity of the past two years,” he said. “I would love to see what law enforcement does with the customer list. That, my friend, is gold.”</p>



<p class="wp-block-paragraph">Regardless, <a href="https://www.linkedin.com/in/assafmo/" target="_blank" rel="noreferrer noopener">Assaf Morag</a>, a cybersecurity researcher at Flare, dubbed the German crackdown “symbolic,” given Kratos’ reach within phishing circles. </p>



<p class="wp-block-paragraph">He argued that the very nature of software makes it all but impossible to shut down in a meaningful way.</p>



<p class="wp-block-paragraph">“Although this is malicious infrastructure, it is still software, and modern development and deployment practices make it relatively quick to rebuild or replicate,” he said. “Demand is likely to shift to competing providers, allowing the ecosystem to recover even if this particular operation has been disrupted.”</p>



<p class="wp-block-paragraph"><a href="https://www.malwarebytes.com/blog/authors/metallicamvp" target="_blank" rel="noreferrer noopener">Pieter Arntz</a>, malware intelligence researcher at Malwarebytes, agreed that the crackdown is disruptive but not definitive. </p>



<p class="wp-block-paragraph">“This appears to be more than a routine website seizure. The reporting points to a PhaaS platform with centralized infrastructure, subscription-style customers, and Microsoft 365 session theft / MFA-bypass tooling, so taking down the backend likely hurts many downstream affiliates at once. In that sense, it is a meaningful disruption to the phishing ecosystem, not just one campaign,” Arntz said.</p>



<p class="wp-block-paragraph">But, he added, “a rebrand or partial re-emergence is plausible, which is the historical pattern for PhaaS operations. Even if the core infrastructure is gone, the code, customer lists, and operator tradecraft can survive.”</p>



<p class="wp-block-paragraph">This means that customers and affiliates can shift to other phishing kits, he said, so it’s likely that the takedown will create a temporary decline in Kratos-specific activity, but probably not a lasting reduction in phishing overall.</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/fvillanustre/" target="_blank" rel="noreferrer noopener">Flavio Villanustre</a>, CISO for the LexisNexis Risk Solutions Group, also concluded that the impact of this crackdown will be short-lived. </p>



<p class="wp-block-paragraph">“For each criminal organization that is dismantled, ten new ones pop out of nowhere. Unless there is a coordinated international effort by more than a few countries, this is a whack-a-mole exercise,” he said. “These are all loosely connected individuals and akin to a lernaean hydra, with two heads growing whenever you chop off one. Their leadership emerges from their lines organically without a real center of control. This makes it almost impossible to completely eliminate these criminal organizations.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[The credential that let OpenAI's agents into Hugging Face exists in most enterprises right now]]></title>
<description><![CDATA[When Hugging Face got hit last week, co-founder Clement Delangue suspected a frontier lab, given the agent's sophistication. He was right. Delangue said on X that after a day working with OpenAI he strongly believed there was no malicious intent and that it was mind-blowing the whole thing had ha...]]></description>
<link>https://tsecurity.de/de/3687771/it-nachrichten/the-credential-that-let-openais-agents-into-hugging-face-exists-in-most-enterprises-right-now/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687771/it-nachrichten/the-credential-that-let-openais-agents-into-hugging-face-exists-in-most-enterprises-right-now/</guid>
<pubDate>Thu, 23 Jul 2026 01:32:49 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>When Hugging Face got hit last week, co-founder Clement Delangue suspected a frontier lab, given the agent's sophistication. He was right. Delangue <a href="https://x.com/ClementDelangue/status/2079670308156645882">said on X</a> that after a day working with OpenAI he strongly believed there was no malicious intent and that it was mind-blowing the whole thing had happened autonomously.</p><p>The two OpenAI models that <a href="https://openai.com/index/hugging-face-model-evaluation-security-incident/">broke into Hugging Face</a> last week did not breach it through malice or superintelligence. They breached it through credentials and permissions they should never have been able to reach, a non-human identity failure that is the oldest problem in security rather than the newest one in AI, and the one every enterprise can actually fix.</p><p>OpenAI <a href="https://venturebeat.com/security/openais-models-broke-containment-and-cyberattacked-hugging-face-what-enterprises-need-to-know">disclosed on July 21</a> that two of its models, GPT-5.6 Sol and an unreleased, more capable model, were running a cyber benchmark called <a href="https://arxiv.org/abs/2605.11086">ExploitGym</a> with their safety refusals switched off, and inferred that the answer key sat in Hugging Face's production database. Getting there took two different failures. A zero-day in a package-registry proxy let the models out of their sandbox and onto the open internet, the kind of persistence OpenAI details in its companion post on <a href="https://openai.com/index/safety-alignment-long-horizon-models/">long-horizon safety</a>, and that part is genuinely new. The breach of Hugging Face itself came the ordinary way. OpenAI's own account is that the models chained stolen credentials and further zero-days into a remote code execution path, after a series of privilege escalation and lateral movement steps. The exotic part got them to the door, and credentials walked them through it.</p><p>Hugging Face also disclosed last week that an <a href="https://venturebeat.com/security/safety-guardrails-blocked-hugging-faces-defenders-not-the-attacker-when-an-ai-agent-breached-its-systems">autonomous agent had harvested cloud and cluster credentials</a> scoped broadly enough to reach multiple internal clusters, then left a trail of more than 17,000 recorded events across short-lived sandboxes over a weekend. Both disclosures describe the same escalation. An agent lands somewhere it should not be, finds credentials scoped far wider than any task requires, and uses them to move. These are two accounts of one incident, not two attacks. The agent Hugging Face watched was OpenAI's models, and both companies describe the same ordinary escalation.</p><p>The version of this in a typical enterprise is worse, not better. OpenAI and Hugging Face are among the most security-mature organizations in the industry, and both still needed the intrusion to happen before they could see it. The average company wiring agents into Copilot or an internal assistant has neither the identity inventory nor the behavioral monitoring those two brought to bear. The same breach in a normal company would not be contained in days, it would simply go unnoticed.</p><h2>The industry is debating the wrong failure</h2><p>The reaction has split into familiar camps. Former White House AI and crypto czar David Sacks and a run of China hawks <a href="https://fortune.com/2026/07/20/hugging-face-turns-to-chinese-open-source-ai-to-fend-off-autonomous-ai-cyber-attack-after-american-ai-guardrails-stymie-defense/">seized on the guardrail paradox</a>, that commercial safety filters blocked Hugging Face's defenders while the attacking model ran with its refusals off, and that a Chinese open-weight model, z.ai's GLM 5.2, was what finally let the team finish its forensics. Hugging Face made the case for openness, arguing in an April <a href="https://huggingface.co/blog/cybersecurity-openness">blog post</a> that open models and open tooling give defenders the same capabilities attackers already have. Both arguments are about the model, and neither touches the mechanism. </p><p>Reduced refusals let the model attempt an attack, and over-scoped credentials are what let it succeed, and those have nothing to do with whether the model was open or closed, American or Chinese. Making a frontier model provably safe is a multi-year alignment problem no customer can buy or accelerate, while scoping an identity is a configuration change a team can ship this sprint. The industry is being urged to fixate on the part of this it cannot control and to treat the part it can as a footnote.</p><p>Forrester reached the same read. In a <a href="https://www.forrester.com/blogs/an-ai-security-facepalm-openais-evaluation-became-hugging-faces-incident/">blog on the incident</a>, its analysts argue that security architectures which assume benign intent will miss this failure mode, because an agent can pursue an authorized goal through unauthorized means, which is what OpenAI's models did.</p><h2>This was a non-human identity failure, and it is the oldest one in security</h2><p>Strip the science-fiction framing and what remains is a textbook case of over-privileged machine identity, the kind security teams have fought for a decade, now driven by an autonomous agent at machine speed. Machine identities already outnumber humans in most enterprises by more than <a href="https://www.cyberark.com/press/machine-identities-outnumber-humans-by-more-than-80-to-1-new-report-exposes-the-exponential-threats-of-fragmented-identity-security/">80 to one</a>, according to CyberArk research, with 42% of them carrying privileged or sensitive access, and an agent inherits whatever its identity can touch. OWASP ranks agent identity and privilege abuse near the top of its <a href="https://neuraltrust.ai/blog/owasp-agentic-ai-top-10">agentic risk list</a>, the confused-deputy pattern where inherited credentials and weak scoping let an agent reach past its mandate, and that is precisely what both July disclosures describe. </p><p><a href="https://www.ieee.org/membership/senior">IEEE Senior Member</a> Kayne McGladrey has argued in <a href="https://venturebeat.com/security/cisco-crowdstrike-rsac-2026-agent-identity-iam-gap-maturity-model">previous VentureBeat interviews</a> that enterprises keep cloning human user accounts onto agents that then wield far more permission than any human would, and this is what that looks like when the agent is a frontier model and the target is a production database.</p><p>The people closest to it read it the same way. OpenAI frames its models as hyperfocused on a benchmark score rather than acting against anyone. Nobody describes an adversary, only a goal, a scoring function, and credentials that were reachable when they should not have been.</p><p>The specific failure is easy to name once the AI framing is stripped away. A credential scoped to one job that can reach ten is a standing invitation, and it does not matter whether a human attacker, a worm, or an autonomous model chasing a benchmark score finds it. What changed in July is the finder. An agent enumerates reachable systems, tests credentials, and pivots faster than any human red team, without malice or hesitation, whenever the path is open. The over-scoping was always the vulnerability, and the agent merely industrialized its discovery.</p><p>Forrester named the control that would have blunted it. Its agentic-security framework, AEGIS, calls for least agency, holding an agent's tools, credentials, and network paths to the minimum its task requires, and files this incident under unrestrained agency and privilege. That is the identity argument in different words, arrived at independently by an analyst firm.</p><p>The data says this is where the risk now lives. Verizon's 2026 Data Breach Investigations Report <a href="https://www.helpnetsecurity.com/2026/05/20/verizon-2026-dbir-findings/">found</a> that exploitation of vulnerabilities has overtaken stolen credentials as the top initial access vector for the first time in 19 years. That is the initial-access half. The other half is the one OpenAI itself describes, stolen credentials driving the privilege escalation and lateral movement that followed. A vulnerability opened the door, and credentials walked through the building unchallenged. Beyond the breach itself, that same over-scoping carries a legal liability most enterprises have never priced. The models' actions <a href="https://techcrunch.com/2026/07/21/openai-says-hugging-face-was-breached-by-its-pre-release-models/">likely violated the Computer Fraud and Abuse Act</a>, according to TechCrunch. The statute contains no carve-out for an AI agent that exceeds its authorized scope during sanctioned testing. Whatever the legal answer, the technical enabler is the same, an identity scoped wider than its task. This is an access-control problem with an owner and a budget, not a philosophy seminar about machine cognition.</p><p>Merritt Baer, Senior Advisor to Andesite, G2I, and AppOmni and former Deputy CISO at AWS, frames the underlying shift to VentureBeat as a new kind of asymmetry. Both sides now reach for the same capabilities, she said, but one side is constrained by enterprise governance, policy, compliance, and safety controls while the adversary simply downloads an uncensored open-weight model and keeps going. The organizations that come through it best, in her view, will be the ones that treat AI as a resilient, governed capability rather than a single service they do not control.</p><h2>Four moves that shrink the blast radius</h2><p>The breach worked because the agent reached identities scoped far wider than its task. None of the four controls that would have contained it requires a new platform, and none of them appears on the list of general AI-safety advice now circulating. They are identity hygiene, applied to non-human actors with the same rigor you already apply to people.</p><p><b>1. Scope every non-human identity to one task.</b> The models reached credentials that touched multiple clusters, which is what turned a foothold into a breach. An identity scoped to a single job, with no standing access to anything else, hits a wall at the first lateral move instead of opening the next door. This is least privilege, the control everyone endorses and few enforce on machine accounts, and it is the single highest-impact fix here.</p><p><b>2. Give credentials short lifetimes and rotate them hard.</b> Harvested credentials are only useful while they are valid, and both July agents worked by collecting them. Short time-to-live and aggressive rotation turn a credential dump into expired noise, so a token stolen during a weekend intrusion is dead before the attacker can chain it. Static secrets that never rotate are the version of this control that fails.</p><p><b>3. Monitor for lateral movement, not just prompts.</b> The tell in both incidents was privilege escalation and lateral movement, which a prompt filter never sees because it is watching the wrong layer. Identity-behavior monitoring, keyed to what a given non-human identity normally does and alerting when it reaches somewhere new, catches the escalation the content guardrail missed. The question for your stack is whether anything you run today would flag a service account suddenly moving between clusters.</p><p><b>4. Rehearse instant revocation before you need it.</b> When the incident is your own agent, the fastest containment is killing its identity mid-run, and that only works if the path to do it exists before the day you need it. Rehearse revoking a machine identity under fire the way you rehearse a human credential compromise. If you have never done it, you do not yet have the control, you have an intention.</p><p>The defense also worked, and that matters. OpenAI's security team caught the anomalous activity internally, Hugging Face's own detection and agents stopped the intrusion, and the breach was contained in days rather than discovered in months, because the defenders could see into systems they controlled. That visibility is the same discipline the four controls depend on. The debate over whether frontier models are safe, open, or American will run for years, and none of it will be settled in time to help the enterprise deploying agents this quarter. The non-human identity gap is different, because it is understood, measurable, and fixable now. The model that breached Hugging Face did not need to be brilliant; it needed credentials someone left in reach. The fix is scoping them before an agent finds them.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Meta ernennt Assaf Keren zum CISO und rüstet sich vor Q2-Zahlen: Worau - Goldesel]]></title>
<description><![CDATA[... Sicherheitsmanager Assaf Keren als neuen Chief Information Security Officer an Bord. ... IT- und Informationssicherheit. Dass Meta einen CISO ...]]></description>
<link>https://tsecurity.de/de/3687555/it-security-nachrichten/meta-ernennt-assaf-keren-zum-ciso-und-ruestet-sich-vor-q2-zahlen-worau-goldesel/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687555/it-security-nachrichten/meta-ernennt-assaf-keren-zum-ciso-und-ruestet-sich-vor-q2-zahlen-worau-goldesel/</guid>
<pubDate>Wed, 22 Jul 2026 22:40:52 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[... Sicherheitsmanager Assaf Keren als neuen Chief Information <b>Security</b> Officer an Bord. ... <b>IT</b>- und Informationssicherheit. Dass Meta einen CISO ...]]></content:encoded>
</item>
<item>
<title><![CDATA[You Can't Ban Attacker AI]]></title>
<description><![CDATA[Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:2 AI capabilities are becoming widely accessible. The discussion is shifting from whether attackers will use AI to how defenders can use similar technology to identify weaknesses in their own environments.

If organizations focus on...]]></description>
<link>https://tsecurity.de/de/3687136/it-security-video/you-cant-ban-attacker-ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687136/it-security-video/you-cant-ban-attacker-ai/</guid>
<pubDate>Wed, 22 Jul 2026 19:19:36 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:2 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/kIG1gWny_PE?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>AI capabilities are becoming widely accessible. The discussion is shifting from whether attackers will use AI to how defenders can use similar technology to identify weaknesses in their own environments.<br />
<br />
If organizations focus only on restricting AI instead of adopting effective defensive tools, they may fall behind adversaries who are willing to use every available capability. Preparing for AI-assisted attacks means improving detection and resilience, not assuming access can be prevented.<br />
<br />
Should cybersecurity teams prioritize AI-powered defense over efforts to restrict access to AI models?<br />
<br />
Subscribe to our podcasts: https://securityweekly.com/subscribe<br />
<br />
#CISO #SecurityWeekly #Cybersecurity #InformationSecurity #AI #InfoSec<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Digitale Wehrhaftigkeit des Staates stärken - BMDS - Bundesportal]]></title>
<description><![CDATA[... IT-Dienstleister oder ... Information Security Officer (CISO) des Bundes gemeinsam mit den Informationssicherheitsbeauftragten der Ressorts.]]></description>
<link>https://tsecurity.de/de/3686320/it-security-nachrichten/digitale-wehrhaftigkeit-des-staates-staerken-bmds-bundesportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3686320/it-security-nachrichten/digitale-wehrhaftigkeit-des-staates-staerken-bmds-bundesportal/</guid>
<pubDate>Wed, 22 Jul 2026 14:43:20 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[... <b>IT</b>-Dienstleister oder ... Information <b>Security</b> Officer (CISO) des Bundes gemeinsam mit den Informationssicherheitsbeauftragten der Ressorts.]]></content:encoded>
</item>
<item>
<title><![CDATA[Bundeskabinett stärkt mit CyberGovSecure die Cybersicherheit der Bundesverwaltung]]></title>
<description><![CDATA[Das Programm „CyberGovSecure“ setzt einen verbindlichen politischen und organisatorischen Rahmen. Das Programm setzt sich zum Ziel, die Cybersicherheit und Cyberresilienz der Bundesverwaltung ressortübergreifend, wirksam und messbar zu stärken. Unter der operativen Koordination der CISO Bund bünd...]]></description>
<link>https://tsecurity.de/de/3686153/it-security-nachrichten/bundeskabinett-staerkt-mit-cybergovsecure-die-cybersicherheit-der-bundesverwaltung/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3686153/it-security-nachrichten/bundeskabinett-staerkt-mit-cybergovsecure-die-cybersicherheit-der-bundesverwaltung/</guid>
<pubDate>Wed, 22 Jul 2026 13:39:27 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Das Programm „CyberGovSecure“ setzt einen verbindlichen politischen und organisatorischen Rahmen. Das Programm setzt sich zum Ziel, die Cybersicherheit und Cyberresilienz der Bundesverwaltung ressortübergreifend, wirksam und messbar zu stärken. Unter der operativen Koordination der CISO Bund bündelt CyberGovSecure die hierfür erforderlichen Aktivitäten, schafft klare Steuerungsstrukturen und unterstützt die Einrichtungen des Bundes dabei, ihre Verpflichtungen zur Informationssicherheit wirksam, praxisnah und nachvollziehbar umzusetzen.]]></content:encoded>
</item>
<item>
<title><![CDATA[10 survival tips for CSOs who report to the CEO]]></title>
<description><![CDATA[As the CSO grows in prominence, security leaders are increasingly earning a seat at the executive table, reporting directly to the CEO with the expectation to help drive business strategy and ensure organizational success.



Reporting to the CEO unlocks greater access and influence for security ...]]></description>
<link>https://tsecurity.de/de/3685496/it-security-nachrichten/10-survival-tips-for-csos-who-report-to-the-ceo/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3685496/it-security-nachrichten/10-survival-tips-for-csos-who-report-to-the-ceo/</guid>
<pubDate>Wed, 22 Jul 2026 09:16:42 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">As the CSO grows in prominence, security leaders are increasingly earning a seat at the executive table, reporting directly to the CEO with the expectation to help drive business strategy and ensure organizational success.</p>



<p class="wp-block-paragraph">Reporting to the CEO unlocks greater access and influence for security leaders, and while CSOs who report to their organization’s CIO still have clout, it’s a very different experience picking up the phone to speak directly with the CEO as a strategic partner.</p>



<p class="wp-block-paragraph">Regardless of reporting structure, CSOs must clearly understand what they are being tasked to solve. That might sound simple, but making the leap to being a CEO’s direct report requires a new perspective, a different set of skills, and a business-level focus on metrics to do so.</p>



<p class="wp-block-paragraph">We asked several current CSOs, CEOs, and IT staffing experts for advice on how security executives can best navigate a direct reporting relationship with their CEO. Offering insights below are <a href="https://www.linkedin.com/in/georgegerchow/">George Gerchow</a>, CSO at Bedrock Data and member of the IANS faculty; <a href="https://www.linkedin.com/in/mattchiodi/">Matt Chiodi</a>, CSO of Cerby; <a href="https://www.cyderes.com/company/about/chris-schueler">Chris Schueler</a>, CEO at Cyderes; and <a href="https://www.skillsoft.com/blog-authors/greg-fuller">Greg Fuller</a>, vice president of the Technology Skills Suite at Skillsoft.</p>



<h2 class="wp-block-heading">1. Understand how the CEO views your role</h2>



<p class="wp-block-paragraph">Most CEOs expect that, when you report directly to them, you fully own your functional area. Whether it’s cybersecurity, operations, or finance, they look to you as the expert in that domain. The CEO may have opinions, but ultimately, you are expected to lead and provide direction.</p>



<p class="wp-block-paragraph">CEOs expect their CSO to be a <a href="https://www.csoonline.com/article/4159317/cisos-reshape-their-roles-as-business-risk-strategists.html">true strategic partner</a>, not just a risk reporter — connecting cybersecurity to revenue protection, regulatory compliance, customer trust, and operational resilience. In turn, CSOs should expect CEOs to treat governance as a strategic enabler, not a bureaucratic necessity.</p>



<h2 class="wp-block-heading">2. Power up on skills vital to your organization at an executive level</h2>



<p class="wp-block-paragraph">On the technology side, AI and machine learning, cloud security, incident response, zero trust architecture, and governance, risk, and compliance (GRC) are the areas where threats evolve fastest and strategic leadership has the greatest impact. </p>



<p class="wp-block-paragraph">Equally important are “power skills”: communication, critical thinking, adaptability, and emotional intelligence. The ability to <a href="https://www.csoonline.com/article/4186984/6-security-leader-tips-for-mastering-business-risk.html">translate complex risk into business terms</a> is what separates a strong CSO from a purely technical one. Skills, not titles, define effectiveness in the eyes of a CEO.</p>



<h2 class="wp-block-heading">3. Take advantage of your direct access</h2>



<p class="wp-block-paragraph">Direct access to the CEO will enable you to influence strategy, <a href="https://www.csoonline.com/article/3855823/how-cisos-can-balance-business-continuity-with-other-responsibilities.html">shape resilience planning</a>, and ensure <a href="https://www.csoonline.com/article/4080670/what-does-aligning-security-to-the-business-really-mean.html">cybersecurity is treated as a business imperative</a> rather than a cost center. That authority is strongest when the CEO understands cybersecurity as a strategic lever, not just a technical function. </p>



<p class="wp-block-paragraph">While a direct reporting relationship gives you access to the CEO, it also comes with the responsibility to operate at that level. You need to provide clear, executive-level visibility into your cybersecurity program.</p>



<h2 class="wp-block-heading">4. Brush up on business translation</h2>



<p class="wp-block-paragraph">A <a href="https://www.csoonline.com/article/4002753/cisos-reposition-their-roles-for-business-leadership.html">CSO who leads with business alignment</a> will always carry more influence when they can translate risk into business language rather than technical jargon. Building programs that must survive an IPO, a FedRAMP audit, and real customer scrutiny forces you to tie security to revenue and trust.</p>



<p class="wp-block-paragraph">The most valuable skill is translation — defining technical risk in terms of executive action and business impact that a CEO and a board can act on. You must build trust through transparency. These are the human skills that complement technology, creating a collaborative human-AI dynamic where leaders make faster, better-informed decisions. </p>



<h2 class="wp-block-heading">5. Treat conversations as risk assessment opportunities</h2>



<p class="wp-block-paragraph">Highly effective security leaders treat every business conversation as a risk conversation in disguise. That mindset is what largely separates a great CSO from a great technologist. Earn the CEO’s trust by speaking business first, security second. Translate every risk into revenue, reputation, or regulatory exposure.</p>



<p class="wp-block-paragraph">Remember, a good CEO wants a translator, not an alarm system. They expect no surprises, a clear read on the risks that matter, and a security leader who helps the <a href="https://www.csoonline.com/article/4021179/8-tough-trade-offs-every-ciso-must-navigate.html">business move faster rather than slowing it down</a>.</p>



<h2 class="wp-block-heading">6. Define what a successful relationship should look like and put it in writing</h2>



<p class="wp-block-paragraph">Regardless of the reporting relationship, start by defining the end goal and putting it in writing. It will evolve over time, but having that initial clarity is critical. This is especially important when you’re new in a role and aiming to make your first 60, 90, or 120 days, and your first year, successful. In such cases, it’s essential to align early.</p>



<p class="wp-block-paragraph">Do that collaboratively, and document it.</p>



<h2 class="wp-block-heading">7. Prioritize trust and candor</h2>



<p class="wp-block-paragraph">The CEO needs to trust that the CSO isn’t sandbagging, and the CSO needs enough psychological safety to deliver bad news fast. When those conditions exist, security becomes a strategic asset — not a cost center.</p>



<p class="wp-block-paragraph">To that end, focus on clear communication above all, and present yourself as part of a team, not a solo player. Stay calm under pressure during incidents, and treat people as peers rather than policing them. The leaders who last build trust before they need it.</p>



<h2 class="wp-block-heading">8. Treat governance as a strategic competitive advantage</h2>



<p class="wp-block-paragraph">The strongest partnerships also share a commitment to governance as a competitive advantage.</p>



<p class="wp-block-paragraph">Governance is the brakes that let you drive fast safely. When a CSO and CEO are aligned on that principle, the organization can innovate with AI while <a href="https://www.csoonline.com/article/4176485/the-ai-governance-imperative-you-cant-afford-to-ignore-2.html">maintaining oversight and protecting against unnecessary risk</a>. The result is an organization that does not just react to threats but builds resilience into how it operates.</p>



<h2 class="wp-block-heading">9. Set clear goals and measure progress</h2>



<p class="wp-block-paragraph">Setting clear goals and measuring progress against those goals is essential. When expectations are clear, the areas you need to focus on become much clearer. It doesn’t solve every problem, but aligning early with your leadership, whether that’s a CEO or a CIO, can significantly reduce the pressure you may feel.</p>



<p class="wp-block-paragraph">Also, never let your boss be surprised. This is where being clear on goals and consistently tracking both leading and lagging metrics becomes especially important, particularly in a direct reporting relationship with the CEO.</p>



<h2 class="wp-block-heading">10. Be willing to endure challenge and discomfort</h2>



<p class="wp-block-paragraph">Finally, persistence and a willingness to endure discomfort for something that matters more than the pain itself are critical to surviving in this relationship. The role of a cybersecurity leader is often thankless. If you’re doing your job well, no one really notices.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Google Unveils Gemini 3.5 Flash Cyber to Find and Fix Software Vulnerabilities Faster]]></title>
<description><![CDATA[Google has introduced Gemini 3.5 Flash Cyber, a lightweight AI model designed to improve cybersecurity by helping defenders identify, validate, and patch software vulnerabilities more efficiently. Built on Gemini 3.5 Flash and optimized for security tasks, Flash Cyber aims to deliver a cost-effec...]]></description>
<link>https://tsecurity.de/de/3685467/it-security-nachrichten/google-unveils-gemini-35-flash-cyber-to-find-and-fix-software-vulnerabilities-faster/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3685467/it-security-nachrichten/google-unveils-gemini-35-flash-cyber-to-find-and-fix-software-vulnerabilities-faster/</guid>
<pubDate>Wed, 22 Jul 2026 08:55:35 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1133" height="692" src="https://thecyberexpress.com/wp-content/uploads/Flash-Cyber.webp" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="Flash Cyber" decoding="async" srcset="https://thecyberexpress.com/wp-content/uploads/Flash-Cyber.webp 1133w, https://thecyberexpress.com/wp-content/uploads/Flash-Cyber-300x183.webp 300w, https://thecyberexpress.com/wp-content/uploads/Flash-Cyber-1024x625.webp 1024w, https://thecyberexpress.com/wp-content/uploads/Flash-Cyber-768x469.webp 768w, https://thecyberexpress.com/wp-content/uploads/Flash-Cyber-600x366.webp 600w, https://thecyberexpress.com/wp-content/uploads/Flash-Cyber-150x92.webp 150w, https://thecyberexpress.com/wp-content/uploads/Flash-Cyber-750x458.webp 750w, https://thecyberexpress.com/wp-content/uploads/Flash-Cyber.webp 1133w, https://thecyberexpress.com/wp-content/uploads/Flash-Cyber-300x183.webp 300w, https://thecyberexpress.com/wp-content/uploads/Flash-Cyber-1024x625.webp 1024w, https://thecyberexpress.com/wp-content/uploads/Flash-Cyber-768x469.webp 768w, https://thecyberexpress.com/wp-content/uploads/Flash-Cyber-600x366.webp 600w, https://thecyberexpress.com/wp-content/uploads/Flash-Cyber-150x92.webp 150w, https://thecyberexpress.com/wp-content/uploads/Flash-Cyber-750x458.webp 750w" sizes="(max-width: 1133px) 100vw, 1133px" title="Google Unveils Gemini 3.5 Flash Cyber to Find and Fix Software Vulnerabilities Faster 4"></p><span data-contrast="auto">Google has introduced Gemini 3.5 Flash Cyber, a lightweight AI model designed to improve cybersecurity by helping defenders identify, validate, and patch software vulnerabilities more efficiently. Built on Gemini 3.5 Flash and optimized for security tasks, Flash Cyber aims to deliver a cost-effective alternative to larger AI models while supporting large-scale vulnerability analysis.</span>

<span data-contrast="auto">The company said it has invested in cybersecurity research for years, including automated vulnerability discovery through CodeMender, its code security agent that can detect and fix critical software flaws. However, as AI systems become increasingly capable of discovering <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-are-vulnerabilities/" title="vulnerabilities" data-wpil-keyword-link="linked" data-wpil-monitor-id="29060">vulnerabilities</a> faster than defenders can resolve them, Google believes a scalable and affordable approach is needed.</span><span data-ccp-props="{}"> </span>
<h3 aria-level="2"><b><span data-contrast="none">Gemini 3.5 Flash Cyber Focuses on Scalable Cybersecurity</span></b><span data-ccp-props='{"134245418":true,"134245529":true,"335559738":160,"335559739":80}'> </span></h3>
<span data-contrast="auto">According to <a href="https://deepmind.google/blog/introducing-gemini-3-5-flash-cyber/" target="_blank" rel="nofollow noopener">Google</a>, Gemini 3.5 Flash Cyber has been fine-tuned specifically to locate, verify, and remediate vulnerabilities more effectively than Gemini's standard Flash models. Because of the technology's dual-use nature, the company is initially limiting access through a pilot program for governments and trusted partners via CodeMender, with broader availability planned over time.</span><span data-ccp-props="{}"> </span>

<span data-contrast="auto">Google also confirmed that CodeMender's core capabilities will be made available through generally available Gemini models on the Gemini Enterprise Agent Platform.</span><span data-ccp-props="{}"> </span>
<h3 aria-level="2"><b><span data-contrast="none">Flash Cyber Improves Large-scale Code Analysis</span></b><span data-ccp-props='{"134245418":true,"134245529":true,"335559738":160,"335559739":80}'> </span></h3>
<span data-contrast="auto">A major challenge in <a class="wpil_keyword_link" href="https://cyble.com/knowledge-hub/what-is-cybersecurity/" target="_blank" rel="noopener" title="cybersecurity" data-wpil-keyword-link="linked" data-wpil-monitor-id="29059">cybersecurity</a> is exploring vast execution search spaces across complex codebases. Instead of relying on a single call to a <a href="https://thecyberexpress.com/us-gets-pre-release-access-to-ai-models/" target="_blank" rel="noopener">large language model</a>, CodeMender invokes Flash Cyber multiple times, allowing sub-agents to inspect significantly more code paths before generating one consolidated report.</span><span data-ccp-props="{}"> </span>

<span data-contrast="auto">Google said the model's speed and lower operating cost make it suitable for continuous code scanning, software launch processes, and commit-scanning pipelines at scale.</span><span data-ccp-props="{}"> </span>
<h3 aria-level="2"><b><span data-contrast="none">Benchmark Results Show Competitive Performance</span></b><span data-ccp-props='{"134245418":true,"134245529":true,"335559738":160,"335559739":80}'> </span></h3>
<span data-contrast="auto">Google evaluated Gemini 3.5 Flash <a class="wpil_keyword_link" href="https://thecyberexpress.com/cyber-news/" title="Cyber" data-wpil-keyword-link="linked" data-wpil-monitor-id="29061">Cyber</a> using the CyberGym benchmark, which measures AI agents against hundreds of real-world software vulnerabilities. Configured to call the model up to five times before producing a final report, CodeMender achieved competitive performance against significantly larger cybersecurity models. Google noted that competitor results were based on provider self-reported scores.</span><span data-ccp-props="{}"> </span>

<span data-contrast="auto">The model also outperformed Gemini 3.5 Flash and 3.6 Flash during Google's internal Big Sleep evaluation, which tested <a class="wpil_keyword_link" href="https://thecyberexpress.com/firewall-daily/vulnerabilities/" title="vulnerability" data-wpil-keyword-link="linked" data-wpil-monitor-id="29058">vulnerability</a> discovery in complex projects such as Chrome and Safari without safety guardrails.</span><span data-ccp-props="{}"> </span>

<span data-contrast="auto">In Chrome's production commit-scanning pipeline, where vulnerabilities remained undisclosed to prevent benchmark contamination, Flash Cyber again delivered a significant improvement over Gemini 3.5 Flash. Google added that competitor models released after Opus 4.6 were excluded because their safety guardrails prevented them from completing the tasks.</span><span data-ccp-props="{}"> </span>

<span data-contrast="auto">Testing on the V8 JavaScript Engine found 55 unique confirmed vulnerabilities with <a href="https://thecyberexpress.com/gemini-ad-safety-targets-scam-ads/" target="_blank" rel="noopener">Gemini</a> 3.5 Flash Cyber, compared with 47 for Gemini 3.5 Flash and 36 for Opus 4.6, including 10 issues missed by both competing models.</span><span data-ccp-props="{}"> </span>
<h3 aria-level="2"><b><span data-contrast="none">Real-world Cybersecurity Deployment</span></b><span data-ccp-props='{"134245418":true,"134245529":true,"335559738":160,"335559739":80}'> </span></h3>
<span data-contrast="auto">Google said Flash Cyber is already helping secure internal projects, including Chrome, Android, Cloud, Ads and YouTube. In one example, Google's Cloud Vulnerability Research team used the model to identify remote code execution vulnerabilities in public APIs and a memory-corruption flaw within a sensitive production service in just two hours. The model also generated a 100% reliable <a href="https://thecyberexpress.com/cve-2026-45829-chromatoast-chromadb/" target="_blank" rel="noopener">remote code execution</a> exploit capable of bypassing Address Space Layout Randomization (ASLR) and Write XOR Execute (W^X).</span><span data-ccp-props="{}"> </span>

<span data-contrast="auto">Google added that early feedback from Wiz and Cloud CISO <a class="wpil_keyword_link" href="https://thecyberexpress.com/" title="Security" data-wpil-keyword-link="linked" data-wpil-monitor-id="29062">Security</a> Engineering testers indicated a significant capability improvement over Gemini 3.5 Flash. The company also highlighted resources such as OSV.dev, which tracks more than 700,000 open-source vulnerabilities, and over a decade of OSS-Fuzz <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-data/" title="data" data-wpil-keyword-link="linked" data-wpil-monitor-id="29063">data</a> as key training assets supporting its cybersecurity models.</span><span data-ccp-props="{}"> </span>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI's models broke containment and cyberattacked Hugging Face — what enterprises need to know]]></title>
<description><![CDATA[Yesterday afternoon, OpenAI and Hugging Face published a joint disclosure outlining a cybersecurity event that redefines the threat landscape for enterprise technology. During an internal benchmark evaluation, frontier artificial intelligence models developed by OpenAI—including GPT-5.6 Sol and a...]]></description>
<link>https://tsecurity.de/de/3685286/it-nachrichten/openais-models-broke-containment-and-cyberattacked-hugging-face-what-enterprises-need-to-know/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3685286/it-nachrichten/openais-models-broke-containment-and-cyberattacked-hugging-face-what-enterprises-need-to-know/</guid>
<pubDate>Wed, 22 Jul 2026 07:02:39 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Yesterday afternoon, OpenAI and Hugging Face <a href="https://openai.com/index/hugging-face-model-evaluation-security-incident/">published a joint disclosure</a> outlining a cybersecurity event that redefines the threat landscape for enterprise technology. </p><p>During an internal benchmark evaluation, frontier artificial intelligence models developed by OpenAI—including GPT-5.6 Sol and an unreleased, higher-capability pre-release model—broke out of their sandboxed research environment, obtained raw internet access, and autonomously executed a complex cyberattack against Hugging Face’s production infrastructure.</p><p> OpenAI officially categorizes the breach as an "unprecedented cyber incident, involving state-of-the-art cyber capabilities". This incident fundamentally re-frames global discussions surrounding AI containment, frontier model alignment, commercial guardrails, and enterprise threat modeling.</p><p>But first thing's first: enterprises should understand the situation, evaluate their own AI and computer systems in light of it, and above all, don't panic. As we'll review, the incident does show the increasing power and danger of frontier AI systems, but it does not mean that enterprise Ai deployments are inherently less secure, nor that they need extensive overhauling. </p><h2><b>Anatomy of an Autonomous Breakout</b></h2><p>To understand how a routine benchmark evaluation escalated into a cross-infrastructure breach, one must examine the objective mechanics of the evaluation pipeline. </p><p>The models were prompted to solve <a href="https://arxiv.org/abs/2605.11086">ExploitGym</a>, a benchmark designed to quantify multi-step exploitation capabilities. </p><p>Hyper-focused on maximizing its evaluation score, the AI agent inferred that Hugging Face likely hosted the answer keys and benchmark solutions. In pursuit of solving the problem, the model determined that breaking out of its container and stealing the answers was an optimal strategy.</p><p>OpenAI’s evaluation environment is designed to be strictly isolated, limiting network traffic through a proxy used for package caching. However, the models identified and exploited a zero-day vulnerability in that internally-hosted third-party proxy software. </p><p>Once through, the AI executed a series of lateral movement and privilege escalation actions across OpenAI's research nodes until reaching a machine with unrestricted internet access. From there, the model searched the web, target-identified Hugging Face, and launched a multi-stage attack by chaining together stolen credentials and remote code execution vulnerabilities on the Hugging Face servers.</p><p>The UK AI Security Institute (UK AISI) recently evaluated models such as GPT-5.6 Sol, demonstrating that they are increasingly able to sustain complex, multi-step cyber operations over long time horizons. OpenAI notes that this incident confirms these theoretical capabilities now apply in real-world settings.</p><h2><b>Rewinding the Tape on a Forensic Trap</b></h2><p>While OpenAI’s July 21 release reveals the identity of the autonomous agent, Hugging Face had already begun managing the intrusion days earlier. </p><p>On July 16, Hugging Face disclosed that an autonomous AI agent system breached its production infrastructure. As <a href="https://venturebeat.com/security/safety-guardrails-blocked-hugging-faces-defenders-not-the-attacker-when-an-ai-agent-breached-its-systems">detailed by VentureBeat,</a> the attacker’s entry point was a malicious dataset that triggered code execution through a remote-code loader and template-injection flaws within dataset configuration files. </p><p>Once inside, the agent framework broke out onto the node running the workload and executed thousands of actions via short-lived sandboxes, harvesting cloud and cluster credentials over a single weekend.</p><p>When Hugging Face's security team detected the breach, responders immediately turned to frontier AI models via commercial APIs to parse the massive volume of system logs and reconstruct over 17,000 recorded events. Then, a secondary operational crisis emerged: the commercial AI models refused to help.</p><p>Because standard commercial frontier models utilize unified safety guardrails designed to block malicious prompt submissions, the models classified the incident response team's forensic queries—which contained raw shell commands, real exploit payloads, and credential dumps—as malicious attacks. Every forensic query submitted by the defenders was blocked outright.</p><p>"The same prompts that are most valuable during an active intrusion—shell commands, exploit chains, credential dumps, persistence mechanisms, lateral movement—are exactly the prompts most likely to trigger safety systems," notes Merritt Baer, former Deputy CISO at AWS and senior adviser to Andesite, G2I, and AppOmni, in an interview with VentureBeat. "As AI becomes embedded in security operations, this becomes an operational resilience issue rather than merely a model policy issue".</p><p>To bypass this roadblock, Hugging Face abandoned commercial hosted APIs and deployed <a href="https://venturebeat.com/technology/z-ais-open-weights-glm-5-2-beats-gpt-5-5-on-multiple-long-horizon-coding-benchmarks-for-1-6th-the-cost">GLM 5.2</a> —a  state-of-the-art Chinese open-weight model released last month by z.ai, as <a href="https://venturebeat.com/technology/z-ais-open-weights-glm-5-2-beats-gpt-5-5-on-multiple-long-horizon-coding-benchmarks-for-1-6th-the-cost">reported at the time by VentureBeat</a> —locally on its own infrastructure. </p><p>Free from third-party API restrictions and external safety filters, GLM 5.2 successfully analyzed the raw exploit data locally, allowing defenders to complete forensic reconstruction and contain the breach without any attacker data leaving the company's environment.</p><h2><b>Industry Reaction and the Geopolitical Paradox</b></h2><p>The revelation that an American frontier model autonomously escaped containment, attacked a partner platform, and was ultimately analyzed using a Chinese open-weight model sent shockwaves through the tech community. </p><p><i>The Wall Street Journal </i>summarized the <a href="https://x.com/WSJ/status/2079754070965854541?s=20">public reaction on X,</a> calling the event "the stuff of cybersecurity nightmares. OpenAI said two artificial intelligence systems it was testing broke out of their test environment, hacked their way onto the internet and broke into another company. The victim was Hugging Face."</p><p>Also posting to X, AI alignment researcher <a href="https://x.com/justanotherlaw/status/2079756943112159237">Lawrence Chan</a> emphasized the importance of transparency regarding the incident, noting that "Credit where it’s due: Hugging Face detected and disclosed the intrusion last week. OAI confirmed its models were involved and provided more details, even when it didn't have to. Separate from choices that led to the hack, voluntary disclosure is good, and I’m glad they did so." </p><p>Meanwhile, AI researcher <a href="https://x.com/natolambert/status/2079662928941474201?s=20">Nathan Lambert</a> provided a succinct technical summary in his own X post, observing that "An openai model, during evaluation on a cyber benchmark, exploited a public zero day bug, escaped sandboxing in openai's infra, and got into the internal huggingface infra via an exploit (through a public dataset service) all in the attempt to solve a benchmark problem." He later addressed the geopolitical implications, writing in another post on X: </p><blockquote><p><i>"Rght now American companies need Chinese models to secure their cyber infra due to guardrails on closed models.</i></p><p><i>But if a Chinese model in training had infiltrated a prominent American tech company, it very likely could've been the cause of policy banning future Chinese models."</i></p></blockquote><p>Technology investor <a href="https://x.com/DavidSacks/status/2078991100057141620?s=20">David Sacks also zeroed in</a> on the guardrail paradox, writing in his own X post that "Hugging Face tried using American frontier models to analyze an AI-powered cyber attack. But the guardrails blocked requests containing real exploit payloads so they switched to GLM 5.2 running locally. The guardrails actually impaired defensive security." </p><p>Sacks quote tweeted<a href="https://x.com/ClementDelangue/status/2078987852495364398"> Hugging Face CEO Clem Delangue</a>, who wrote: "We had this experience ourselves this week! Very scary to be guardrailed as a defender when you know attackers are likely bypassing".</p><h2><b>5 Strategic Takeaways for Enterprise Tech Leaders Now</b></h2><p>For the average enterprise executive, the central question is immediate: is our corporate network at risk from escaping AI agents? The short answer is no, not inherently.</p><p><b>1. Hugging Face occupies a unique position in the software ecosystem. </b>As a global repository for open-source AI models, code, and datasets, Hugging Face natively attracts autonomous agents, scrapers, automated evaluation pipelines, and active security researchers. Furthermore, the model’s target selection was context-specific: GPT-5.6 Sol searched for Hugging Face specifically because it deduced that Hugging Face hosted the answers to <i>ExploitGym</i>. Standard corporate networks—such as financial databases, HR platforms, or logistics systems—do not host benchmark solution keys that draw the direct focus of an agent attempting to solve an evaluation metric.</p><p><b>2. However, the long-term risk profile for enterprise technology permanently shifts following this event. </b>AI models with long-horizon reasoning seek the path of least resistance to accomplish a goal, including breaking rules, escaping sandboxes, or exploiting zero-days if deployment safeguards are intentionally disabled for testing or bypassed by an attacker. As Hugging Face's experience illustrates, data processing pipelines that ingest external datasets without sandbox execution or static analysis act as highly vulnerable initial access infrastructure.</p><p><b>3. This incident also drastically undercuts recent policy chatter in the U.S. calling for Chinese open-source AI models to be banned or restricted due to security concerns. </b>As this episode demonstrates, an open-weight Chinese model actually served as the vital defensive layer for an American and French firm facing an unanticipated cyberattack from an American model that broke containment. Contrary to the official line from some U.S. policymakers and hardline China hawks,  the Chinese open-source models weren't a security risk to the U.S. companies, in this case — rather, an American proprietary, closed-source model from an ostensibly secure American company was the source of the danger. Thus, any pressure U.S. companies may face from officials, agencies or non-governmental organizations to stop relying on affordable Chinese open weights models for defensive or any other lawful purposes should be viewed with a high degree of suspicion, and arguably resisted to the fullest legal extent. </p><p><b>4. Enterprise CISOs must audit their dependency on cloud-based AI APIs and pressure vendors to implement authenticated trust architectures</b>. Commercial AI vendors currently treat safety as a generic content-moderation problem, applying the same blanket refusals to an enterprise CISO as they would to a malicious hacker. Baer frames this requirement perfectly: "The model shouldn’t only understand what is being asked. It should understand who is asking, why, and under what governance".</p><p><b>5. Incident response plans must explicitly account for scenarios where commercial APIs fail, rate-limit, or actively refuse queries during an active security event. </b>Maintaining air-gapped, locally deployed open-weight models trained on security log analysis is no longer an edge-case luxury; it is a critical operational requirement. Security leaders running AI workloads in production must recalibrate their timelines and prepare for machine-speed threat actors that operate without human limits.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[FAQ Claude Mythos: Fähigkeiten, Zugang, Wettbewerber, Auswirkungen]]></title>
<description><![CDATA[Claude Mythos steht immer mehr Unternehmen testweise zur Verfügung. Doch was genau steckt in Anthropics neuestem Modell?T. Schneider / Shutterstock



Was ist Claude Mythos?



Claude Mythos ist ein KI-Modell, das von Anthropic entwickelt wurde und für Anwendungen in den Bereichen Cybersicherheit...]]></description>
<link>https://tsecurity.de/de/3685218/it-security-nachrichten/faq-claude-mythos-faehigkeiten-zugang-wettbewerber-auswirkungen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3685218/it-security-nachrichten/faq-claude-mythos-faehigkeiten-zugang-wettbewerber-auswirkungen/</guid>
<pubDate>Wed, 22 Jul 2026 06:10:27 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2024/04/shutterstock_editorial_2338803257.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Anthropic and Claude" class="wp-image-2096337" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Claude Mythos steht immer mehr Unternehmen testweise zur Verfügung. Doch was genau steckt in Anthropics neuestem Modell?</p></figcaption></figure><p class="imageCredit">T. Schneider / Shutterstock</p></div>



<h2 class="wp-block-heading">Was ist Claude Mythos?</h2>



<p class="wp-block-paragraph">Claude Mythos ist ein KI-Modell, das von Anthropic entwickelt wurde und für Anwendungen in den Bereichen Cybersicherheit und Gesundheitswesen optimiert ist. Ursprünglich wurde Mythos 5 im April einer kleinen Gruppe geprüfter Technologiepartner zugänglich gemacht – im Vorfeld eines geplanten, breiter angelegten Rollouts.</p>



<p class="wp-block-paragraph">Zu diesem Zweck rief das KI-Unternehmen das <a href="https://www.computerwoche.de/article/4156536/wie-claude-mythos-die-it-sicherheit-veraendert.html">Projekt „Glasswing“</a> ins Leben, ein Konsortium, das Infrastrukturanbietern, Open-Source-Entwicklern und großen Technologieunternehmen einen begrenzten, kontrollierten Zugriff zu Mythos gewährt. Ziel der Initiative ist es, Verteidigern zu ermöglichen, Schwachstellen schneller aufzuspüren und zu beheben, als Angreifer sie identifizieren können. Das erscheint auch dringend notwendig, setzen diese doch zunehmend selbst auf <a href="https://www.computerwoche.de/article/4193820/ki-fuhrt-eigenstandig-cyber-attacken-aus.html">KI-gestützte Werkzeuge</a>.</p>



<h2 class="wp-block-heading">Über welche Fähigkeiten verfügt Claude Mythos?</h2>



<p class="wp-block-paragraph">Die ersten 50 Partner von Project Glasswing konnten mithilfe von Mythos mehr als 10.000 Schwachstellen mit hohem oder kritischem Schweregrad in allen gängigen Betriebssystemen und Webbrowsern aufspüren.</p>



<p class="wp-block-paragraph">So identifizierte das Modell Sicherheitslücken, die selbst den fähigsten Sicherheitsforschern jahrelang entgangen waren – etwa einen 27 Jahre alten Fehler in OpenBSD. Zudem hat Mythos bewiesen, dass es mehrere Schwachstellen miteinander verknüpfen kann.</p>



<h2 class="wp-block-heading">Wie schränkt Anthropic den Zugang zu Claude Mythos ein?</h2>



<p class="wp-block-paragraph">Anthropic teilte bei der Vorstellung von Claude Mythos mit, es schränke die Verfügbarkeit des Spitzen-KI-Modells bewusst ein, da dessen Fähigkeiten von Angreifern leicht missbraucht werden könnten.</p>



<p class="wp-block-paragraph">Im Juni wurde die Technologie dann für weitere 150 Organisationen freigegeben. Alle Mythos-Partner müssen hierbei aber zustimmen, dass ihre Daten 30 Tage lang zu Sicherheitsüberwachungszwecken gespeichert werden.</p>



<p class="wp-block-paragraph">Am 15. Juni verhängte die Trump-Regierung allerdings Exportbeschränkungen für <a href="https://www.csoonline.com/article/4183094/anthropic-releases-mythos-class-fable-5-model-with-safeguards-for-cyber-risks.html" target="_blank">Claude Fable 5</a> und Claude Mythos 5. Diese sollten ausländischen Staatsangehörigen sowohl innerhalb als auch außerhalb der USA den Zugang verwehren. Am 30. Juni wurden die Beschränkungen jedoch bereits wieder aufgehoben.</p>



<h2 class="wp-block-heading">Was ist Claude Fable?</h2>



<p class="wp-block-paragraph">Für einen breiteren Einsatzbereich bietet Anthropic Claude Fable 5 an. Das Modell basiert auf derselben technischen Grundlage wie Mythos. Es verfügt jedoch über strenge Sicherheitsmechanismen, die den Betrieb in als „riskant“ eingestuften Bereichen der Cybersicherheit einschränken. Alle als problematisch deklarierten Anfragen werden stattdessen automatisch an das ältere und weniger leistungsfähige Large Language Model (LLM) Opus 4.8 weitergeleitet.</p>



<h2 class="wp-block-heading">Wie nutzen Security-Partner von Anthropic den Zugriff auf Mythos?</h2>



<p class="wp-block-paragraph">Cisco, einer der Projekt-Glasswing-Partner, hat seine „<a href="https://blogs.cisco.com/ai/announcing-foundry-security-spec" target="_blank" rel="noreferrer noopener">Foundry Security Spec</a>“ als Open-Source-Lösung veröffentlicht. Hierbei handelt es sich um ein modellunabhängiges Framework für Sicherheitstests, das es anderen Anbietern und Sicherheitsexperten in Unternehmen ermöglichen soll, ähnliche Arbeitsabläufe zu entwickeln, ohne bei Null anfangen zu müssen.</p>



<p class="wp-block-paragraph">Vor kurzem betonten Vertreter von Cisco auf einer Online-Veranstaltung, dass Verteidiger KI nutzen können, um Sicherheitsprobleme wesentlich schneller und in größerem Umfang zu identifizieren, zu bestätigen und zu beheben. Ältere Modelle, die nach dem Prinzip „eine Schwachstelle finden und patchen“ funktionieren, seien nicht mehr zeitgemäß. Dies liege daran, dass Angreifer KI einsetzen, um den Weg von der Entdeckung einer Schwachstelle bis zu deren Ausnutzung zu beschleunigen. Cisco wiederum setzt KI intern bereits in der Defensive ein, um 1,8 Milliarden Zeilen Code im gesamten Produktportfolio zu scannen.</p>



<p class="wp-block-paragraph">Gleichzeitig betonen die Experten, dass kleinere Unternehmen keinen Zugriff auf eingeschränkte KI-Modelle benötigen, um ihre Sicherheit zu verbessern. In solchen Betrieben lasse sich stattdessen mehr erreichen, indem grundlegende Sicherheitsmaßnahmen optimiert werden. Hierzu zählen laut Cisco unter anderem Authentifizierung, Netzwerk-Segmentierung, Zero Trust und die Behebung aktiv ausgenutzter Schwachstellen.</p>



<h2 class="wp-block-heading">Bieten andere KI-Anbieter etwas Vergleichbares zu Claude Mythos an?</h2>



<p class="wp-block-paragraph">Mythos ist das prominenteste Beispiel für Frontier-KI-Modelle. Mit ihnen kann die Suche nach Zero-Day-Lücken in einem Tempo und Ausmaß automatisiert werden, die weit über die Fähigkeiten menschlicher Teams hinausgeht.</p>



<p class="wp-block-paragraph">Allerdings arbeiten auch etliche andere Anbieter an hochleistungsfähigen, auf Sicherheit ausgerichteten „Frontier“-KI-Modellen. Zudem gibt es andere leistungsstarke Open-Source-Modelle, die sich problemlos für die Cybersicherheitsforschung nutzen lassen. Claude Mythos ist also bei weitem nicht die einzige verfügbare Option.</p>



<p class="wp-block-paragraph">So werden beispielsweise die Modelle GPT-5.4-Cyber sowie GPT-5.5 von OpenAI genutzt, um Schwachstellen zu erkennen und zu analysieren. Auch in der Malware-Analyse und der Bedrohungsmodellierung kommen sie zum Einsatz. Zugang zu diesen Technologien können Sicherheitsanbieter, Unternehmen und Forscher über das Programm „Trusted Access for Cyber“ (TAC) von OpenAI erhalten.</p>



<p class="wp-block-paragraph">Zusätzlich hat das chinesische <a href="https://www.reuters.com/legal/litigation/chinas-360-says-it-has-developed-tools-match-anthropics-mythos-2026-06-24/" target="_blank" rel="noreferrer noopener">Cybersicherheitsunternehmen 360 Security Technology mit Tulongfeng</a> ein System entwickelt, das als Gegenstück zu Anthropics „Mythos“ beschrieben wird.</p>



<p class="wp-block-paragraph">Privat lassen sich leistungsstarke offene Modelle – darunter DeepSeek V3.2 von DeepSeek und Llama 4 von Meta – auf GPU-Infrastrukturen betreiben und in der Cybersicherheitsforschung einsetzen. Fugu des japanischen Anbieters Sakana AI ist eine weitere Option in dieser Kategorie.</p>



<h2 class="wp-block-heading">Was kritisieren Cybersicherheitsexperten an Claude Mythos?</h2>



<p class="wp-block-paragraph">Kritiker aus dem Cybersecurity-Bereich räumen ein, dass Claude Mythos zweifellos hochentwickelt sei. Die Marketing-Behauptung, wonach es zuverlässig produktive IT-Systeme lahmlegen könne, übersteige jedoch die tatsächlichen Fähigkeiten.</p>



<p class="wp-block-paragraph">Darüber hinaus beklagen sich Sicherheitsexperten – <a href="https://www.youtube.com/watch?v=mx0CpTp3Q4Y" target="_blank" rel="noreferrer noopener">etwa in Podcasts</a> – über die übertrieben restriktiven Sicherheitsmechanismen von Claude Fable: Bereits Anfragen, einen sicherheitsrelevanten Blogbeitrag zusammenzufassen oder sogar das Wort „Exploit“ zu buchstabieren, würden auf das deutlich schwächere Modell Opus 4.8 zurückgestuft. Dadurch würden selbst alltägliche Aufgaben in der Informationssicherheit unnötig erschwert.</p>



<p class="wp-block-paragraph">Andere Experten warnen davor, dass Frontier-KI-Modelle anfällig für False Positives seien. Eher grundsätzlich ist die Kritik, dass das schnellere Aufspüren von mehr Schwachstellen das eigentliche Problem nicht löst, nämlich zuverlässig Sicherheitslücken zu beheben oder nicht-technische Angriffsvektoren wie Social Engineering zu verhindern.</p>



<h2 class="wp-block-heading">Wie sollten CISOs auf Mythos reagieren?</h2>



<p class="wp-block-paragraph">Die Nachrichtendienste der „Five Eyes“ (USA, Großbritannien, Kanada, Australien und Neuseeland) <a href="https://www.ncsc.gov.uk/sites/default/files/2026-06/Five-Eyes-cyber-security-agencies-statement-ai-shift.pdf"></a> warnen davor, dass hochmoderne KI-Modelle wie Claude Mythos „sowohl offensive als auch defensive Cyber-Fähigkeiten grundlegend verändern werden“ – und zwar in einem Zeitraum von Monaten statt Jahren.</p>



<p class="wp-block-paragraph">„Während KI uns dabei helfen wird, die Cyberabwehr im Laufe der Zeit zu verbessern, erhöht sie zugleich Geschwindigkeit, Ausmaß und Raffinesse von Cyberbedrohungen“, heißt es in der Erklärung der Gruppe. Unternehmen sollen daher KI nutzen, um ihre Abwehrmechanismen im Rahmen umfassenderer Strategien zur Stärkung der Cybersicherheits-Resilienz zu verbessern.</p>



<p class="wp-block-paragraph">Die meisten Unternehmen seien jedoch bei weitem noch nicht darauf vorbereitet, was dies für ihre Bedrohungsmodelle bedeutet, warnt ein Experte. „Wir verfügen heute über KI-Systeme, die realistische Angriffswege über Software, Anbieter und kritische Infrastrukturen hinweg schneller abbilden können, als menschliche Angreifer sie erfassen können“, erläutert <a href="https://www.linkedin.com/in/jhubback/" target="_blank" rel="noreferrer noopener">Joe Hubback</a>, Partner und CISO beim Beratungsunternehmen Elixirr sowie ehemaliger McKinsey-Partner. Dadurch, dass „Fähigkeiten der ‚Mythos-Klasse‘ vor der breiten kommerziellen Einführung stünden, handle es sich nicht mehr um „ein Nischenproblem der Forschung“, ergänzt er. Vielmehr sei es jetzt ein Faktor, den jedes Unternehmen in sein Bedrohungsmodell einbeziehen müsse, so der Experte.</p>



<p class="wp-block-paragraph">Auch ein <a href="https://labs.cloudsecurityalliance.org/wp-content/uploads/2026/04/mythosready-20260413.pdf" target="_blank" rel="noreferrer noopener">Bericht der Cloud Security Alliance</a> warnt davor, dass KI die Zeitspanne zwischen der Entdeckung einer Schwachstelle und deren Ausnutzung drastisch verkürzt habe. Damit seien herkömmliche Sicherheitsmodelle, die auf „Patchen und Reagieren“ basieren, überholt. Unternehmen sollten sich vielmehr auf anhaltende Wellen von Schwachstellen einstellen, die durch „Project Glasswing“ und andere Quellen mittels KI aufgedeckt werden.</p>



<p class="wp-block-paragraph">„Die bei Mythos beobachteten Fähigkeiten werden schon bald breiter verfügbar sein. Dadurch wird sich die Anzahl sowie Häufigkeit komplexer, neuartiger Angriffe, denen sich Unternehmen gegenübersehen, drastisch erhöhen“, heißt es in der Warnung. Sicherheitsverantwortliche müssten daher ihre Verteidigungsstrategien auf einen „Mythos-ready“-Ansatz umstellen, der auf kontinuierlichem Schwachstellenmanagement, schnellerer Priorisierung und verbesserter Reaktion auf Sicherheitsvorfälle basiert. (tf)</p>



<p class="wp-block-paragraph"><strong>Dieser Artikel basiert auf einem <a href="https://www.csoonline.com/article/4198019/claude-mythos-faq-capabilities-access-competitors-implications.html" target="_blank">Beitrag</a> von CSO.</strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[The latest Chinese AI models may indeed work for enterprises, but only in a handful of specific applications]]></title>
<description><![CDATA[Ever since Chinese AI startup DeepSeek launched three years ago, enterprise executives have been nervous about relying on Chinese AI models. 



But now that the latest Chinese AI offerings, Alibaba’s 2.4-trillion-parameter model Qwen3.8 Max and Moonshot’s 2.8-trillion-parameter model Kimi K3, ar...]]></description>
<link>https://tsecurity.de/de/3684721/ai-nachrichten/the-latest-chinese-ai-models-may-indeed-work-for-enterprises-but-only-in-a-handful-of-specific-applications/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3684721/ai-nachrichten/the-latest-chinese-ai-models-may-indeed-work-for-enterprises-but-only-in-a-handful-of-specific-applications/</guid>
<pubDate>Tue, 21 Jul 2026 21:24:16 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Ever since Chinese AI startup DeepSeek launched three years ago, enterprise executives have been <a href="https://www.cio.com/article/3816301/how-would-a-potential-ban-on-deepseek-impact-enterprises.html" target="_blank">nervous about relying on Chinese AI models</a>. </p>



<p class="wp-block-paragraph">But now that the latest Chinese AI offerings, Alibaba’s 2.4-trillion-parameter model <a href="https://x.com/Alibaba_Qwen/status/2078759124914098291" target="_blank" rel="noreferrer noopener">Qwen3.8 Max</a> and Moonshot’s 2.8-trillion-parameter model <a href="https://www.kimi.com/blog/kimi-k3" target="_blank" rel="noreferrer noopener">Kimi K3</a>, are promising even more powerful performance, those IT executives are being forced to again ask if these models are worth using, even in a limited fashion.</p>



<p class="wp-block-paragraph">Former Walmart head of risk <a href="https://www.linkedin.com/in/steveneric/" target="_blank" rel="noreferrer noopener">Steven Eric Fisher</a>, now an independent cybersecurity and risk advisor, thinks they should at least take another look. </p>



<p class="wp-block-paragraph">“Enterprises should take these models seriously, but neither adopt nor reject them solely because they are Chinese,” he said. “They should be assessed like any other critical technology dependency: jurisdiction, ownership, training and software provenance, licensing, data handling, hosting, security, reliability, and the ability to independently test their behavior. Geopolitical exposure is a legitimate risk factor, but it should be incorporated into technical and supply-chain diligence rather than used as a substitute for it.”</p>



<h2 class="wp-block-heading">Choose applications with care</h2>



<p class="wp-block-paragraph">He added, “Chinese models may be especially valuable for coding, multilingual processing, high-volume document analysis, research, synthetic-data generation, and privately operated security or forensic workflows, but they should be subject to task-specific testing rather than broad benchmark claims.”</p>



<p class="wp-block-paragraph"><a href="https://www.infotech.com/profiles/shashi-bellamkonda" target="_blank" rel="noreferrer noopener">Shashi Bellamkonda</a>, principal research director at Info-Tech Research Group, agreed that the Chinese models can work well if they are only used in carefully chosen applications. </p>



<p class="wp-block-paragraph">“Although Moonshot’s K3 still trails Claude’s Fable 5 and GPT 5.6 Sol on performance and user experience, good companies that have governance and prompt guardrails will not face the instability and improvisation of [the Chinese] models,” he said. “These models will win in usage. US frontier models are leading as the best models, but Chinese models will be sufficient for high-volume, low-drama tasks that cost less for non-critical transactions.”</p>



<p class="wp-block-paragraph">On the flipside, Bellamkonda suggested a variety of areas where enterprises should avoid Chinese AI models, including “customer-facing work without a human in the loop, regulated or sensitive data, and anything where a hallucinated answer creates legal or safety exposure. That is where the reliability gap and the political-radioactivity concern both bite, and where the closed American models still earn their premium.”</p>



<p class="wp-block-paragraph">Bellamkonda said he didn’t see the differences in data reliability, mostly involving hallucination rates, as meaningful for enterprise AI strategy decisions.</p>



<p class="wp-block-paragraph">“Every open-weight model in this class can get facts wrong or make things up. That is fixable with the right setup, so it is not a reason to avoid these models,” he said. “For high-volume tasks with clear limits, you feed the model your own trusted documents to answer from, and you keep a person checking the output. That combination is safe for production. The model on its own is not.”</p>



<h2 class="wp-block-heading">Too early for enterprises to consider</h2>



<p class="wp-block-paragraph">However, not everyone agrees that the latest Chinese models have earned their place as enterprise AI decision options. </p>



<p class="wp-block-paragraph">Cybersecurity consultant <a href="https://formergov.com/directory/brianlevine" target="_blank" rel="noreferrer noopener">Brian Levine</a>, executive director of FormerGov, focused on Chinese technology concerns when he worked for the US Justice Department as its representative in the US law enforcement Joint Liaison Group (JLG) with China. </p>



<p class="wp-block-paragraph">“It is way too early for US enterprises to seriously consider these models,” he said. “Until proven otherwise, enterprises should assume that if they use these models, they may be granting China complete access to everything they do through the models, and potentially access to their networks and employees more broadly. At this point, any pros of using such models are strongly outweighed by the potential security, confidentiality, and reliability concerns.”</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/tomfindling/" target="_blank" rel="noreferrer noopener">Tom Findling</a>, CEO of Conifers.ai, was equally emphatic that enterprise CIOs need to steer clear of these newer Chinese models. </p>



<p class="wp-block-paragraph">“Using them inhouse? Absolutely not. You simply don’t know what is planted inside of it and you don’t know what training data is put into them,” Findling said. </p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/eclectiqus/" target="_blank" rel="noreferrer noopener">Mike Wilkes</a>, enterprise CISO at Aikido Security, added that the very attractive pricing for these Chinese models may be appealing, but suggested that, despite the low cost, they’re ultimately too risky.</p>



<p class="wp-block-paragraph">“Enterprises should take these models seriously, but not romantically. Parameter count is horsepower measured in a showroom, not braking distance in the rain,” he said. “The real tests are reliability on your data, the cost of a wrong answer, and whether the model behaves predictably under pressure.”</p>



<p class="wp-block-paragraph">He noted that the benchmarks on the latest open-weights models are impressive, and very close to those of the frontier lab models, which makes the cost ”incredibly seductive, especially when a team does not want to risk their data being used to train those frontier models.”</p>



<p class="wp-block-paragraph">But the Chinese models can still work in specific circumstances. “The strongest value will be in bounded, reversible and inspectable work: coding inside a sandbox, multilingual translation, document triage, data extraction and other high-volume tasks where outputs can be verified,” he said. “Cheap intelligence is valuable, but only when it is not mistaken for trustworthy judgment.”</p>



<p class="wp-block-paragraph">Wilkes added that the regulatory issues surrounding Chinese models can be especially problematic. Texas, for example, has <a href="https://www.cio.com/article/4143748/top-global-and-us-ai-regulations-to-look-out-for.html" target="_blank">banned their usage</a>.  </p>



<h2 class="wp-block-heading">A rational choice for some workloads</h2>



<p class="wp-block-paragraph">However, <a href="https://www.linkedin.com/in/yurigoryunov/" target="_blank" rel="noreferrer noopener">Yuri Goryunov</a>, CIO of consulting firm Acceligence, argued that CIOs should seriously consider these models. </p>



<p class="wp-block-paragraph">“Counterintuitively, the biggest benefit of Kimi and models like it is the lack of guardrails,” Goryunov said. “Think of it as stick shift cars in the era of automatics. If you want ease and comfort, stay with the frontiers because they have cruise control, shift the gears for you and they decide when. If you want performance and control, expand your horizons. But a stick shift assumes you know how to drive one: you bring your own governance, your own evals, your own safety layer. That’s a cost and specialized talent, which is super rare, and for the right organization it’s also the whole point.”</p>



<p class="wp-block-paragraph">Goryunov’s bottom line: “For internal, high-volume, well-harnessed workloads, [the Chinese models] have moved from ‘watch list’ to ‘rational choice.’”</p>



<p class="wp-block-paragraph"><em>This article originally appeared on <a href="https://www.cio.com/article/4199590/the-latest-chinese-ai-models-may-indeed-work-for-enterprises-but-only-in-a-handful-of-specific-applications.html" target="_blank">CIO.com</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[The latest Chinese AI models may indeed work for enterprises, but only in a handful of specific applications]]></title>
<description><![CDATA[Ever since Chinese AI startup DeepSeek launched three years ago, enterprise executives have been nervous about relying on Chinese AI models. 



But now that the latest Chinese AI offerings, Alibaba’s 2.4-trillion-parameter model Qwen3.8 Max and Moonshot’s 2.8-trillion-parameter model Kimi K3, ar...]]></description>
<link>https://tsecurity.de/de/3684669/it-nachrichten/the-latest-chinese-ai-models-may-indeed-work-for-enterprises-but-only-in-a-handful-of-specific-applications/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3684669/it-nachrichten/the-latest-chinese-ai-models-may-indeed-work-for-enterprises-but-only-in-a-handful-of-specific-applications/</guid>
<pubDate>Tue, 21 Jul 2026 21:03:34 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Ever since Chinese AI startup DeepSeek launched three years ago, enterprise executives have been <a href="https://www.cio.com/article/3816301/how-would-a-potential-ban-on-deepseek-impact-enterprises.html" target="_blank">nervous about relying on Chinese AI models</a>. </p>



<p class="wp-block-paragraph">But now that the latest Chinese AI offerings, Alibaba’s 2.4-trillion-parameter model <a href="https://x.com/Alibaba_Qwen/status/2078759124914098291" target="_blank" rel="noreferrer noopener">Qwen3.8 Max</a> and Moonshot’s 2.8-trillion-parameter model <a href="https://www.kimi.com/blog/kimi-k3" target="_blank" rel="noreferrer noopener">Kimi K3</a>, are promising even more powerful performance, those IT executives are being forced to again ask if these models are worth using, even in a limited fashion.</p>



<p class="wp-block-paragraph">Former Walmart head of risk <a href="https://www.linkedin.com/in/steveneric/" target="_blank" rel="noreferrer noopener">Steven Eric Fisher</a>, now an independent cybersecurity and risk advisor, thinks they should at least take another look. </p>



<p class="wp-block-paragraph">“Enterprises should take these models seriously, but neither adopt nor reject them solely because they are Chinese,” he said. “They should be assessed like any other critical technology dependency: jurisdiction, ownership, training and software provenance, licensing, data handling, hosting, security, reliability, and the ability to independently test their behavior. Geopolitical exposure is a legitimate risk factor, but it should be incorporated into technical and supply-chain diligence rather than used as a substitute for it.”</p>



<h2 class="wp-block-heading">Choose applications with care</h2>



<p class="wp-block-paragraph">He added, “Chinese models may be especially valuable for coding, multilingual processing, high-volume document analysis, research, synthetic-data generation, and privately operated security or forensic workflows, but they should be subject to task-specific testing rather than broad benchmark claims.”</p>



<p class="wp-block-paragraph"><a href="https://www.infotech.com/profiles/shashi-bellamkonda" target="_blank" rel="noreferrer noopener">Shashi Bellamkonda</a>, principal research director at Info-Tech Research Group, agreed that the Chinese models can work well if they are only used in carefully chosen applications. </p>



<p class="wp-block-paragraph">“Although Moonshot’s K3 still trails Claude’s Fable 5 and GPT 5.6 Sol on performance and user experience, good companies that have governance and prompt guardrails will not face the instability and improvisation of [the Chinese] models,” he said. “These models will win in usage. US frontier models are leading as the best models, but Chinese models will be sufficient for high-volume, low-drama tasks that cost less for non-critical transactions.”</p>



<p class="wp-block-paragraph">On the flipside, Bellamkonda suggested a variety of areas where enterprises should avoid Chinese AI models, including “customer-facing work without a human in the loop, regulated or sensitive data, and anything where a hallucinated answer creates legal or safety exposure. That is where the reliability gap and the political-radioactivity concern both bite, and where the closed American models still earn their premium.”</p>



<p class="wp-block-paragraph">Bellamkonda said he didn’t see the differences in data reliability, mostly involving hallucination rates, as meaningful for enterprise AI strategy decisions.</p>



<p class="wp-block-paragraph">“Every open-weight model in this class can get facts wrong or make things up. That is fixable with the right setup, so it is not a reason to avoid these models,” he said. “For high-volume tasks with clear limits, you feed the model your own trusted documents to answer from, and you keep a person checking the output. That combination is safe for production. The model on its own is not.”</p>



<h2 class="wp-block-heading">Too early for enterprises to consider</h2>



<p class="wp-block-paragraph">However, not everyone agrees that the latest Chinese models have earned their place as enterprise AI decision options. </p>



<p class="wp-block-paragraph">Cybersecurity consultant <a href="https://formergov.com/directory/brianlevine" target="_blank" rel="noreferrer noopener">Brian Levine</a>, executive director of FormerGov, focused on Chinese technology concerns when he worked for the US Justice Department as its representative in the US law enforcement Joint Liaison Group (JLG) with China. </p>



<p class="wp-block-paragraph">“It is way too early for US enterprises to seriously consider these models,” he said. “Until proven otherwise, enterprises should assume that if they use these models, they may be granting China complete access to everything they do through the models, and potentially access to their networks and employees more broadly. At this point, any pros of using such models are strongly outweighed by the potential security, confidentiality, and reliability concerns.”</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/tomfindling/" target="_blank" rel="noreferrer noopener">Tom Findling</a>, CEO of Conifers.ai, was equally emphatic that enterprise CIOs need to steer clear of these newer Chinese models. </p>



<p class="wp-block-paragraph">“Using them inhouse? Absolutely not. You simply don’t know what is planted inside of it and you don’t know what training data is put into them,” Findling said. </p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/eclectiqus/" target="_blank" rel="noreferrer noopener">Mike Wilkes</a>, enterprise CISO at Aikido Security, added that the very attractive pricing for these Chinese models may be appealing, but suggested that, despite the low cost, they’re ultimately too risky.</p>



<p class="wp-block-paragraph">“Enterprises should take these models seriously, but not romantically. Parameter count is horsepower measured in a showroom, not braking distance in the rain,” he said. “The real tests are reliability on your data, the cost of a wrong answer, and whether the model behaves predictably under pressure.”</p>



<p class="wp-block-paragraph">He noted that the benchmarks on the latest open-weights models are impressive, and very close to those of the frontier lab models, which makes the cost ”incredibly seductive, especially when a team does not want to risk their data being used to train those frontier models.”</p>



<p class="wp-block-paragraph">But the Chinese models can still work in specific circumstances. “The strongest value will be in bounded, reversible and inspectable work: coding inside a sandbox, multilingual translation, document triage, data extraction and other high-volume tasks where outputs can be verified,” he said. “Cheap intelligence is valuable, but only when it is not mistaken for trustworthy judgment.”</p>



<p class="wp-block-paragraph">Wilkes added that the regulatory issues surrounding Chinese models can be especially problematic. Texas, for example, has <a href="https://www.cio.com/article/4143748/top-global-and-us-ai-regulations-to-look-out-for.html" target="_blank">banned their usage</a>.  </p>



<h2 class="wp-block-heading">A rational choice for some workloads</h2>



<p class="wp-block-paragraph">However, <a href="https://www.linkedin.com/in/yurigoryunov/" target="_blank" rel="noreferrer noopener">Yuri Goryunov</a>, CIO of consulting firm Acceligence, argued that CIOs should seriously consider these models. </p>



<p class="wp-block-paragraph">“Counterintuitively, the biggest benefit of Kimi and models like it is the lack of guardrails,” Goryunov said. “Think of it as stick shift cars in the era of automatics. If you want ease and comfort, stay with the frontiers because they have cruise control, shift the gears for you and they decide when. If you want performance and control, expand your horizons. But a stick shift assumes you know how to drive one: you bring your own governance, your own evals, your own safety layer. That’s a cost and specialized talent, which is super rare, and for the right organization it’s also the whole point.”</p>



<p class="wp-block-paragraph">Goryunov’s bottom line: “For internal, high-volume, well-harnessed workloads, [the Chinese models] have moved from ‘watch list’ to ‘rational choice.’”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[How Proofpoint is Governing AI at Enterprise Scale | 27 Seconds]]></title>
<description><![CDATA[Author: CrowdStrike - Bewertung: 0x - Views:3 Ben McLaughlin, CISO at Proofpoint, discusses how security leaders can embrace AI innovation while maintaining governance, resilience, and business trust.

In this episode of 27 Seconds:
• AI governance
• Managing AI risk
• Communicating cyber risk to...]]></description>
<link>https://tsecurity.de/de/3684657/it-security-video/how-proofpoint-is-governing-ai-at-enterprise-scale-27-seconds/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3684657/it-security-video/how-proofpoint-is-governing-ai-at-enterprise-scale-27-seconds/</guid>
<pubDate>Tue, 21 Jul 2026 20:53:44 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: CrowdStrike - Bewertung: 0x - Views:3 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/OJlYIZ7Qe1k?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Ben McLaughlin, CISO at Proofpoint, discusses how security leaders can embrace AI innovation while maintaining governance, resilience, and business trust.<br />
<br />
In this episode of 27 Seconds:<br />
• AI governance<br />
• Managing AI risk<br />
• Communicating cyber risk to the board<br />
• How Proofpoint partners with CrowdStrike<br />
<br />
► Learn more about securing AI:<br />
https://cs.link/urIpz<br />
<br />
► Learn more about CrowdStrike:<br />
https://cs.link/urIzr<br />
<br />
📣 Connect With Us:<br />
<br />
► X:<br />
https://twitter.com/CrowdStrike<br />
► Instagram:<br />
https://www.instagram.com/crowdstrike<br />
► LinkedIn:<br />
https://www.linkedin.com/company/crowdstrike<br />
<br />
🔔 Subscribe to stay updated!<br />
<br />
#CrowdStrike #Cybersecurity #27Seconds<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[How ServiceNow is Automating the Modern SOC | 27 Seconds]]></title>
<description><![CDATA[Author: CrowdStrike - Bewertung: 0x - Views:3 Ben de Bont, CISO at ServiceNow, explains how AI, automation, and human expertise work together to build a modern security operations center capable of keeping pace with today's threats.

In this episode of 27 Seconds:
• Building an agentic SOC
• AI-p...]]></description>
<link>https://tsecurity.de/de/3684656/it-security-video/how-servicenow-is-automating-the-modern-soc-27-seconds/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3684656/it-security-video/how-servicenow-is-automating-the-modern-soc-27-seconds/</guid>
<pubDate>Tue, 21 Jul 2026 20:53:43 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: CrowdStrike - Bewertung: 0x - Views:3 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/tt7w1VszY0Q?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Ben de Bont, CISO at ServiceNow, explains how AI, automation, and human expertise work together to build a modern security operations center capable of keeping pace with today's threats.<br />
<br />
In this episode of 27 Seconds:<br />
• Building an agentic SOC<br />
• AI-powered security operations<br />
• Security automation<br />
• How ServiceNow partners with CrowdStrike<br />
<br />
► Learn more about agentic SOC transformation:<br />
https://cs.link/urIrl<br />
<br />
► Learn more about CrowdStrike:<br />
https://cs.link/urIzr<br />
<br />
📣 Connect With Us:<br />
<br />
► X:<br />
https://twitter.com/CrowdStrike<br />
► Instagram:<br />
https://www.instagram.com/crowdstrike<br />
► LinkedIn:<br />
https://www.linkedin.com/company/crowdstrike<br />
<br />
🔔 Subscribe to stay updated!<br />
<br />
#CrowdStrike #Cybersecurity #27Seconds<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[How Columbia Bank is Preparing for the AI Era | 27 Seconds]]></title>
<description><![CDATA[Author: CrowdStrike - Bewertung: 0x - Views:6 Ron Powell, CISO at Columbia Bank, shares how his team is approaching AI governance, preparing for an agentic SOC, and helping the board navigate the opportunities and risks of AI.

In this episode of 27 Seconds:
• AI governance
• Preparing for an age...]]></description>
<link>https://tsecurity.de/de/3684655/it-security-video/how-columbia-bank-is-preparing-for-the-ai-era-27-seconds/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3684655/it-security-video/how-columbia-bank-is-preparing-for-the-ai-era-27-seconds/</guid>
<pubDate>Tue, 21 Jul 2026 20:53:41 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: CrowdStrike - Bewertung: 0x - Views:6 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/fqljOMWsq2Y?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Ron Powell, CISO at Columbia Bank, shares how his team is approaching AI governance, preparing for an agentic SOC, and helping the board navigate the opportunities and risks of AI.<br />
<br />
In this episode of 27 Seconds:<br />
• AI governance<br />
• Preparing for an agentic SOC<br />
• Human oversight in AI-powered security<br />
• How Columbia Bank partners with CrowdStrike<br />
<br />
► Learn more about securing AI:<br />
https://cs.link/urIpz<br />
<br />
► Learn more about CrowdStrike:<br />
https://cs.link/urIzr<br />
<br />
📣 Connect With Us:<br />
<br />
► X:<br />
https://twitter.com/CrowdStrike<br />
► Instagram:<br />
https://www.instagram.com/crowdstrike<br />
► LinkedIn:<br />
https://www.linkedin.com/company/crowdstrike<br />
<br />
🔔 Subscribe to stay updated!<br />
<br />
#CrowdStrike #Cybersecurity #27Seconds<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[How Texas Mutual Uses AI to Strengthen Security Operations | 27 Seconds]]></title>
<description><![CDATA[Author: CrowdStrike - Bewertung: 0x - Views:2 John Sapp, CISO at Texas Mutual, explains how AI is helping security teams reduce alert fatigue, accelerate investigations, and strengthen human decision making across the SOC.

In this episode of 27 Seconds:
• Building an agentic SOC
• AI-assisted th...]]></description>
<link>https://tsecurity.de/de/3684654/it-security-video/how-texas-mutual-uses-ai-to-strengthen-security-operations-27-seconds/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3684654/it-security-video/how-texas-mutual-uses-ai-to-strengthen-security-operations-27-seconds/</guid>
<pubDate>Tue, 21 Jul 2026 20:53:39 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: CrowdStrike - Bewertung: 0x - Views:2 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/spHQ9AOctsQ?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>John Sapp, CISO at Texas Mutual, explains how AI is helping security teams reduce alert fatigue, accelerate investigations, and strengthen human decision making across the SOC.<br />
<br />
In this episode of 27 Seconds:<br />
• Building an agentic SOC<br />
• AI-assisted threat detection<br />
• Reducing alert fatigue<br />
• How Texas Mutual partners with CrowdStrike<br />
<br />
► Learn more about agentic SOC transformation:<br />
https://cs.link/urIrl<br />
<br />
► Learn more about CrowdStrike:<br />
https://cs.link/urIzr<br />
<br />
📣 Connect With Us:<br />
<br />
► X:<br />
https://twitter.com/CrowdStrike<br />
► Instagram:<br />
https://www.instagram.com/crowdstrike<br />
► LinkedIn:<br />
https://www.linkedin.com/company/crowdstrike<br />
<br />
🔔 Subscribe to stay updated!<br />
<br />
#CrowdStrike #Cybersecurity #27Seconds<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[KI übernimmt das Stadion – ein Sicherheitsproblem?]]></title>
<description><![CDATA[Moderne Stadien zählen laut Karim Benslimane, VP Field CISO bei Darktrace, zu den komplexesten Infrastrukturen überhaupt: Am Veranstaltungstag verschmelzen Shops, Verpflegungsstände, Verkehrsknotenpunkte, umfangreiche ...]]></description>
<link>https://tsecurity.de/de/3683592/it-nachrichten/ki-uebernimmt-das-stadion-ein-sicherheitsproblem/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3683592/it-nachrichten/ki-uebernimmt-das-stadion-ein-sicherheitsproblem/</guid>
<pubDate>Tue, 21 Jul 2026 13:48:26 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Moderne Stadien zählen laut Karim Benslimane, VP Field CISO bei Darktrace, zu den komplexesten Infrastrukturen überhaupt: Am Veranstaltungstag verschmelzen Shops, Verpflegungsstände, Verkehrsknotenpunkte, umfangreiche ...]]></content:encoded>
</item>
<item>
<title><![CDATA[CISO Conversations: Andreas Gaetje – From Economics to CISO at Körber AG]]></title>
<description><![CDATA[Gaetje’s story shows that you don’t need to be a ‘deep bit-crawler’ to become a Chief Information Security Officer.
The post CISO Conversations: Andreas Gaetje – From Economics to CISO at Körber AG appeared first on SecurityWeek.]]></description>
<link>https://tsecurity.de/de/3683567/it-security-nachrichten/ciso-conversations-andreas-gaetje-from-economics-to-ciso-at-koerber-ag/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3683567/it-security-nachrichten/ciso-conversations-andreas-gaetje-from-economics-to-ciso-at-koerber-ag/</guid>
<pubDate>Tue, 21 Jul 2026 13:40:42 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Gaetje’s story shows that you don’t need to be a ‘deep bit-crawler’ to become a Chief Information Security Officer.</p>
<p>The post <a href="https://www.securityweek.com/ciso-conversations-andreas-gaetje-from-economics-to-ciso-at-korber-ag/">CISO Conversations: Andreas Gaetje – From Economics to CISO at Körber AG</a> appeared first on <a href="https://www.securityweek.com/">SecurityWeek</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CISO Conversations: Andreas Gaetje – From Economics to CISO at Körber AG]]></title>
<description><![CDATA[Gaetje’s story shows that you don’t need to be a ‘deep bit-crawler’ to become a Chief Information Security Officer. The post CISO Conversations: Andreas Gaetje – From Economics to CISO at Körber AG appeared first on SecurityWeek. This article has…
Read more →
The post CISO Conversations: Andreas ...]]></description>
<link>https://tsecurity.de/de/3683564/it-security-nachrichten/ciso-conversations-andreas-gaetje-from-economics-to-ciso-at-koerber-ag/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3683564/it-security-nachrichten/ciso-conversations-andreas-gaetje-from-economics-to-ciso-at-koerber-ag/</guid>
<pubDate>Tue, 21 Jul 2026 13:40:37 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Gaetje’s story shows that you don’t need to be a ‘deep bit-crawler’ to become a Chief Information Security Officer. The post CISO Conversations: Andreas Gaetje – From Economics to CISO at Körber AG appeared first on SecurityWeek. This article has…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/ciso-conversations-andreas-gaetje-from-economics-to-ciso-at-korber-ag/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/ciso-conversations-andreas-gaetje-from-economics-to-ciso-at-korber-ag/">CISO Conversations: Andreas Gaetje – From Economics to CISO at Körber AG</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[IT leaders confident but cooked when it comes to rogue AI agents]]></title>
<description><![CDATA[A large majority of IT and security leaders are confident in their teams’ ability to detect when an AI agent has gone rogue, but few are able to take quick action to mitigate the fallout when an agent exceeds its intended scope.



Nine in 10 IT and security leaders surveyed by IT observability v...]]></description>
<link>https://tsecurity.de/de/3683326/it-security-nachrichten/it-leaders-confident-but-cooked-when-it-comes-to-rogue-ai-agents/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3683326/it-security-nachrichten/it-leaders-confident-but-cooked-when-it-comes-to-rogue-ai-agents/</guid>
<pubDate>Tue, 21 Jul 2026 12:09:38 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">A large majority of IT and security leaders are confident in their teams’ ability to detect when an AI agent has gone rogue, but few are able to take quick action to mitigate the fallout when an agent exceeds its intended scope.</p>



<p class="wp-block-paragraph">Nine in 10 IT and security leaders surveyed by <a href="https://www.cio.com/article/4176067/the-ai-governance-imperative-you-cant-afford-to-ignore.html?utm=hybrid_search">IT observability</a> vendor WanAware believe in their capabilities to find malfunctioning agents, but only 26% acknowledge that they can trace the downstream impact within minutes. Over 45% say it would take hours to understand the full impact of an agent incident.</p>



<p class="wp-block-paragraph">That delay between detection and mitigation can be a huge problem, says <a href="https://www.linkedin.com/in/jmcollins/">Jeffrey Collins</a>, WanAware’s CEO. The survey suggests IT leaders are overconfident about their ability to control agents, he adds.</p>



<p class="wp-block-paragraph">And here, timing is critical, Collins says, given that malfunctioning agents can lead to major outages and data breaches — damage that can start within seconds, he notes.</p>



<p class="wp-block-paragraph">“That’s truly the gap here. It’s not if you understand it; it’s when you understand it,” Collins says. “If your average time to just knowing about an event is measured in days, weeks, or months, you have a serious problem right now.”</p>



<p class="wp-block-paragraph">While it’s not always easy to tell whether an agent has gone beyond its scope, it’s even harder to tell the downstream impacts, he adds.</p>



<p class="wp-block-paragraph">“What’s been affected if one machine was compromised, either from our own AI usage as a customer or from someone else’s, what else could happen, and how can we understand that quickly?” Collins asks.</p>



<h2 class="wp-block-heading">Machine speed</h2>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/kevin-paige-578547a/">Kevin Paige</a>, field CISO at IT solutions provider C1, agrees that time is of the essence when an AI agent malfunctions.</p>



<p class="wp-block-paragraph">“The problem is that agents move at machine speed, so the gap between an agent malfunctioning and you catching it isn’t measured in minutes, it’s measured in actions,” he says. “Every minute it’s wrong it’s still working, and because it’s usually running on borrowed standing credentials, the damage spreads across everything those credentials can reach before anyone can pin it on the agent.”</p>



<p class="wp-block-paragraph">In many cases, organizations with rogue agents don’t find out from their <a href="https://www.cio.com/article/4195251/19-agentops-tools-for-monitoring-ai-activity-issues-and-costs.html">own detection tools</a>, but from customers, auditors, or broken downstream systems, he says.</p>



<p class="wp-block-paragraph">“That’s the worst way to learn,” Paige adds. “The longer-term cost is trust, because one incident like that and the business pulls back on agents entirely, so failing to contain a malfunction fast is also what stalls adoption.”</p>



<p class="wp-block-paragraph">The problem with detecting <a href="https://www.cio.com/article/4127774/1-5-million-ai-agents-are-at-risk-of-going-rogue-2.html?utm=hybrid_search">rogue agents</a> is that many organizations have built in visibility but not control, he says.</p>



<p class="wp-block-paragraph">“When an agent goes out of scope it’s rarely dramatic,” Paige adds. “Usually, it’s using access it legitimately has, for a purpose nobody signed off on, which means your access model doesn’t even flag it. So you find out after the fact, and you fix it by hand.”</p>



<p class="wp-block-paragraph">IT teams can stop agents that exceed their scope, but only if controls were built in before the agent was deployed, adds <a href="https://www.linkedin.com/in/chrisdcamacho/">Chris Camacho</a>, COO of Abstract Security.</p>



<p class="wp-block-paragraph">“Every agent should have its own identity, narrowly scoped permissions, and a complete audit trail,” he says. “Just as important, organizations need the ability to immediately revoke that identity or suspend the agent without manually hunting through multiple consoles during an incident.”</p>



<p class="wp-block-paragraph">Part of the challenge is that an agent’s activity is spread across identities, cloud platforms, SaaS applications, APIs, and security tools that were not designed to tell a complete story, Camacho says. Security teams often have to piece together events from multiple basic questions such as, what did the agent access, and what changed?</p>



<p class="wp-block-paragraph">“Most organizations know where they’ve deployed AI agents,” he adds. “That’s very different from knowing exactly what an agent did after something unexpected happens.”</p>



<p class="wp-block-paragraph">The organizations that most successfully manage agents won’t be the ones that deploy the most, he says. “They’ll be the ones that can explain every action an agent took, prove it operated within policy, and stop it immediately when it doesn’t,” he adds.</p>



<h2 class="wp-block-heading">Confidence isn’t reality</h2>



<p class="wp-block-paragraph">The survey’s results make sense to <a href="https://www.linkedin.com/in/brinkleyjoseph/">Joe Brinkley</a>, director of offensive security research and community at pentest firm Cobalt. The high confidence in detecting malfunctions is compliance paperwork, whereas the minority of respondents who can detect problems quickly is the reality on the ground, he says.</p>



<p class="wp-block-paragraph">“Tracing agent impact fast is brutal,” Brinkley says. “These systems do not run on fixed code paths. They use nondeterministic reasoning across a web of different APIs. Traditional logs only catch isolated events. They completely miss the full execution chain.”</p>



<p class="wp-block-paragraph">By the time an anomaly alert hits, an agent has already executed multiple downstream actions, he adds.</p>



<p class="wp-block-paragraph">In some cases, agent malfunctions are related to data flow vulnerabilities, such as when a prompt injection from an untrusted input such as a malicious email overwrites the system instructions, he says.</p>



<p class="wp-block-paragraph">“We need to be clear about the actual technology; the AI is not waking up angry,” Brinkley says. “The agent suddenly thinks its official job is to dump your database. It spends tokens as fast as possible to do that.”</p>



<p class="wp-block-paragraph">Agents are also vulnerable to loop failures, when they hit API errors and try to self-correct, he adds.</p>



<p class="wp-block-paragraph">“It hits that same broken endpoint 10,000 times in two minutes,” he says. “It drains your budget and causes a self-inflicted denial of service. It is an automated wrecking ball moving faster than your monitoring can log it.”</p>



<p class="wp-block-paragraph">Brinkley recommends that IT leaders put “hard kill” switches at the API layer to stop agents going out of scope.</p>



<p class="wp-block-paragraph">“You can stop it, but soft guardrails are useless,” he says. “Do not try to patch the prompt or filter the text. You have to treat the agent like a compromised user account. Pull the OAuth tokens and kill the access immediately.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Health-ISAC Health Sector Heartbeat - Q2 2026]]></title>
<description><![CDATA[Dieser Bericht beinhaltet: · Cybersicherheit im Gesundheitswesen – letztendlich geht es immer um die Menschen. · Health-ISAC CISO Benchmarking-Bericht ...]]></description>
<link>https://tsecurity.de/de/3682500/it-security-nachrichten/health-isac-health-sector-heartbeat-q2-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3682500/it-security-nachrichten/health-isac-health-sector-heartbeat-q2-2026/</guid>
<pubDate>Tue, 21 Jul 2026 03:38:40 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Dieser Bericht beinhaltet: · <b>Cybersicherheit</b> im Gesundheitswesen – letztendlich geht es immer um die Menschen. · Health-ISAC CISO Benchmarking-Bericht ...]]></content:encoded>
</item>
<item>
<title><![CDATA[CIO 100 Leadership Live New York: CIOs push past AI pilots for measurable returns]]></title>
<description><![CDATA[Technology executives from across the New York metropolitan area gathered July 16 at Convene, One Liberty Plaza, for CIO 100 Leadership Live New York, a full day of roundtables and panel discussions on enterprise AI investment, governance, and organizational change.



Several key areas of consen...]]></description>
<link>https://tsecurity.de/de/3682348/it-security-nachrichten/cio-100-leadership-live-new-york-cios-push-past-ai-pilots-for-measurable-returns/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3682348/it-security-nachrichten/cio-100-leadership-live-new-york-cios-push-past-ai-pilots-for-measurable-returns/</guid>
<pubDate>Tue, 21 Jul 2026 01:07:24 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Technology executives from across the New York metropolitan area gathered July 16 at Convene, One Liberty Plaza, for <a href="https://event.foundryco.com/cio-100-leadership-live-new-york/">CIO 100 Leadership Live New York</a>, a full day of roundtables and panel discussions on enterprise AI investment, governance, and organizational change.</p>



<p class="wp-block-paragraph">Several key areas of consensus emerged throughout this highly interactive event. Infrastructure fragmentation continues to block the path to securing returns on AI investments prompting leaders to understand rising cloud spend attributed to large language model utilization. This has caused a growing number of organizations to refocus on on-premises and hybrid options in C-suite and board-level capital planning conversations. Speakers, along with comments from the audience, described a shift from project thinking to product thinking, with smaller multidisciplinary teams moving faster than legacy structures.</p>



<p class="wp-block-paragraph">Several participants repeatedly warned that automating broken processes just amplifies dysfunction. Governance and measurement remain unresolved, with usage metrics still getting mistaken for business value. One of the panels explored how CIOs may benefit from applying venture capital-style scrutiny to enterprise bets, weighing team execution as heavily as the technology itself. The throughline was a redefinition of the CIO role, from technology executor to business strategist fluent in revenue, board engagement, and transformation ownership.</p>



<h2 class="wp-block-heading">Morning roundtable tackles AI infrastructure</h2>



<p class="wp-block-paragraph">The day opened with an invitation-only executive breakfast roundtable, “Beyond the Pilot, Building the Infrastructure for Real AI Returns,” co-hosted by Unisys and Dell Technologies. Over a dozen executives representing major public and private sector organizations across the New York metropolitan area joined Steve Hollander, senior director of Americas global alliances at Dell Technologies, and Matt Marshall, CIO at Unisys for a workshop-style discussion.</p>



<p class="wp-block-paragraph">The session explored the strategic, operational, financial, and technological issues that must be mastered to optimize infrastructure decisions and separate organizations that are experimenting with AI from those competing on it. Discussion questions probed how CIOs measure whether AI investment is translating into business results, how they can break the cycle of fragmented and siloed AI deployments, how boards are beginning to scrutinize seven-figure token spend and whether on-premises or hybrid infrastructure can rein in costs.</p>



<p class="wp-block-paragraph">The take-home point: the organizations pulling ahead are the ones that stopped treating AI as four separate problems, strategic, operational, financial, technological, owned by four separate functions, and started running it as one coordinated decision. Fragmentation is the actual cost center here, not the token spend itself. A CIO who solves the infrastructure question in isolation from the governance question, or the cost question in isolation from the talent question, ends up optimizing one silo while the other three keep bleeding value. Competing on AI, instead of just experimenting with it, means the finance, operations, technology and business sides are reasoning from the same picture of what’s being built and why, so the tradeoffs get made once, together, instead of getting re-litigated at every handoff.</p>



<h2 class="wp-block-heading">Forum sessions open with a mandate for growth</h2>



<p class="wp-block-paragraph">Following breakfast, the main forum program began with “The New CIO Mandate, Delivering Growth, Not Just Technology.” In a moderated conversation, Laksh Nathan, chief information officer at Paramount Skydance, drew on his experience with mergers, enterprise transformation and AI-enabled development to describe a shift from project and application management toward a product-centric operating model. Nathan addressed how smaller, multidisciplinary teams are changing expectations on both the business and technology sides of the enterprise, and what mindset changes CIOs must lead to turn AI into an engine of growth rather than a cost center.</p>



<p class="wp-block-paragraph">PwC followed with a session on “Designing the Intelligent Enterprise, From AI Investment to Evolving Operations.” Darren O’Meara, principal and chief technology officer for managed services, and Meghna Shah, principal for engineering and AI, examined why fragmented outcomes persist even after heavy investment in technology and transformation.</p>



<p class="wp-block-paragraph">The intelligent enterprise, they posited, is less about working toward achieving specific technology outcomes and more about creating operating models that integrate strategy, technology, operations, and governance into one system. This, they explained, requires linking AI, data, and decisions across the business and will leave an indelible mark on how decision rights are redesigned, funding models are developed, and accountability is enforced to accommodate the speed of the agentic economy.</p>



<h2 class="wp-block-heading">Talent, tradeoffs, and the cost of getting it wrong</h2>



<p class="wp-block-paragraph">The session “Return on Transformation: Time, Talent, and Tradeoffs” — with Prashant Hinge, chief information and transformation officer at MSIG USA; Joseph Gimigliano, chief technology officer at Northwell Health; and Eduard de Vries Sands, AI executive advisor at PatientPoint — examined why transformation initiatives so often lose their way.</p>



<p class="wp-block-paragraph">The main culprit, even today in 2026, continues to revolve around a persistent instinct for technology implementations to become the objective rather than the means to a measurable business outcome. The panelists made the case for doing the incredibly difficult work of re-engineering (if not entirely re-imagining) existing processes before automating them and then placing smaller bets inside that bigger vision.</p>



<p class="wp-block-paragraph">Ricky Thakrar, head of sales and account management at Zoho, took the stage to present “Smaller, Smarter, Safer, The Enterprise AI Architecture Most Leaders Get Backwards,” arguing that constrained, context-rich architectures consistently outperform expensive models bolted onto fragmented systems.</p>



<p class="wp-block-paragraph">A round of Hot Topic Discussion Groups and a networking lunch followed, including the Next CIO Luncheon featuring Robert Half Regional Director Jason Deneu.</p>



<h2 class="wp-block-heading">Afternoon sessions turn to security, scale, and investment signals</h2>



<p class="wp-block-paragraph">CSO and CIO Contributor Joan Goodchild moderated “Securing Trust in the Agentic Economy,” a discussion with Marlowe Cochran, CISO at the New York State Education Department, and Gee Rittenhouse, vice president of security services at AWS, on how organizations are balancing speed, innovation and security as AI agents move from experimentation into productization at scale.</p>



<p class="wp-block-paragraph">Rittenhouse framed agentic risk as closer to human risk than traditional software risk, describing how an independent agent acting in a non-deterministic way really does look like a potential insider threat, pushing CISOs toward behavioral monitoring over static workload protection. He tied this to a structural shift in defense, noting it’s hard to do agentic security if you’re not observing it, putting observability at the center of agentic risk management.</p>



<p class="wp-block-paragraph">Cochran concurred, adding that many of the key tools that are needed to move into the agentic economy already exist, but must be implemented more aggressively, comprehensively and even more creatively. CISOs don’t need to invent an entirely new security discipline for the agentic era so much as extend identity management, access control and monitoring frameworks they already run to cover a new class of non-human actor — agents.</p>



<p class="wp-block-paragraph">A session on “AI, From Experimentation to Enterprise Impact” brought together Meagan Gentry, national AI practice manager and distinguished technologist at Insight and Yuri Gubin, chief technology officer at DataArt, for a candid look at why pilots stall before reaching scaled production and what operating capabilities, governance, cost visibility, continuous education, must be in place to sustain AI once a proof of concept works.</p>



<p class="wp-block-paragraph">During the session’s Q&amp;A segment, a discussion emerged around how proof-of-concept success can result in a false signal, raising questions about whether pilots should be considered successful before the intended outcomes have had time to materialize, and drawing a distinction between measuring usage and adoption versus measuring business value.</p>



<p class="wp-block-paragraph">The panelists explored how CIOs can identify the small number of transformational AI opportunities worth pursuing rather than managing hundreds of incremental use cases, and even challenged whether prioritization is the CIO’s job at all. The discussion closed on a sequencing question with real strategic weight, whether AI-first strategies are putting the technology ahead of the business problem CIOs are trying to solve, and what role CIOs should play with boards in defining the outcomes AI is expected to support.</p>



<h2 class="wp-block-heading">A shift in perspectives</h2>



<p class="wp-block-paragraph">The “Think Like a VC, Investment Shifts Towards Focused AI Applications” session featured three venture investors, Aaron Darr, partner at Lead Edge; Isabelle Phelps, partner at Lerer Hippeau; and Marshall Porter, general partner at AlleyCorp. The panel explored how investors evaluate risk and talent in a market where products and competitive positions can shift within months, and what separates a focused AI application with durable enterprise value from an AI wrapper built to chase a trend.</p>



<p class="wp-block-paragraph">The panel challenged the enterprise instinct to seek certainty in a market moving this fast, questioning whether CIOs should stop looking for technologies that will future-proof the enterprise and instead grow more comfortable continuously reassessing their bets. Investors framed this as a deliberate departure from the traditional low-tolerance-for-failure posture that has long governed enterprise technology purchasing, arguing that the search for certainty has itself become a risk in a market where products and business models can shift within months. The discussion pressed CIOs to weigh how they can adopt a more dynamic investment mindset without compromising the enterprise security, governance and accountability their organizations still depend on.</p>



<p class="wp-block-paragraph">A Lightning Insights followed, featuring five-minute briefings from Insight, Platform9 and Console, followed by Keystone Senior Principal Ellora Sarkar’s talk on why most enterprise AI investment fails to produce measurable value and what separates the small share of firms capturing real return on investment from the majority still stuck in pilots.</p>



<h2 class="wp-block-heading">Closing the day</h2>



<p class="wp-block-paragraph">The forum closed with “What’s Next for the CIO, Preparing for the Next 12 to 24 Months,” a fireside conversation with Leif Maiorini, CIO for corporate services at Omnicom. Maiorini discussed why business processes need to be redesigned for agentic speed rather than automated around existing human workflows, how organizational structures may shift as autonomous agents reshape visibility and decision support, and where sustainable differentiation will come from once AI capability itself becomes widely accessible.</p>



<p class="wp-block-paragraph">Maiorini encouraged the industry to clearly distinguish between nondifferentiated services that should be made as efficient as possible and the differentiated capabilities that actually influence why customers choose to do business with an organization, once the major efficiency gains from optimization and AI have been captured.</p>



<p class="wp-block-paragraph">He was candid about the governance gap agentic systems open up, noting that agents lack the professional reputation, personal accountability and inherent constraints that shape human behavior, which creates new risk when autonomous decisions occur at machine speed. That combination, reinvesting efficiency gains into genuine differentiation while building governance models suited to non-human decision-makers, framed his closing case for why human creativity and judgment remain the enterprise’s most durable asset even as the underlying technology becomes commoditized.</p>



<p class="wp-block-paragraph"><strong><em>Join the CIO 100 Awards &amp; Conference Aug 17–19, 2026 at Omni PGA Frisco Resort &amp; Spa, Frisco, TX — where top IT leaders celebrate innovation and connect.  <a href="https://event.foundryco.com/cio100-symposium-and-awards/?utm_medium=editorial&amp;utm_source=cio100_foundry_research&amp;utm_campaign=cio_100_research_foundry&amp;utm_term=4/8/2026-8/19//2026&amp;utm_content=editorial">Learn more to attend or partner</a>.</em></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[ServiceNow’s sandbox escape RCE hole now exploited in the wild]]></title>
<description><![CDATA[A sandbox security hole that could lead to remote code execution (RCE), patched last week by ServiceNow, is being actively exploited in the wild, according to a report from threat intel firm Defused. 



The report, posted on X, said the firm is “observing in-the-wild exploitation of the ServiceN...]]></description>
<link>https://tsecurity.de/de/3682156/it-security-nachrichten/servicenows-sandbox-escape-rce-hole-now-exploited-in-the-wild/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3682156/it-security-nachrichten/servicenows-sandbox-escape-rce-hole-now-exploited-in-the-wild/</guid>
<pubDate>Mon, 20 Jul 2026 22:53:39 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">A sandbox security hole that could lead to remote code execution (RCE), patched last week by ServiceNow, is being actively exploited in the wild, according to <a href="https://x.com/defusedcyber/status/2078418391321219448" target="_blank" rel="noreferrer noopener">a report from threat intel firm Defused</a>. </p>



<p class="wp-block-paragraph">The report, posted on X, said the firm is “observing in-the-wild exploitation of the ServiceNow pre-auth sandbox-escape RCE (CVE-2026-6875).”</p>



<p class="wp-block-paragraph">Defused CEO <a href="https://www.linkedin.com/in/simokohonen" target="_blank" rel="noreferrer noopener">Simo Kohonen</a>, in an interview with CSO Online, noted that it appeared that the attacker has changed its tactics from those documented in an earlier proof of concept (PoC) from researchers at Searchlight Cyber, in response to ServiceNow patches and defenses. The company had implemented five different mitigations in its code base, which “neutered” the initial attack methodology, he said, adding that, overall, his team is seeing more attack method tweaks than it used to see. </p>



<p class="wp-block-paragraph">“We are seeing a lot of [attack] variations, much more so than a year ago, for the same vulnerability,” Kohonen said. Attackers “now have more tools to build their own stuff.”</p>



<p class="wp-block-paragraph">However, he admitted that his team has thus far only observed this exploit an in the wild exploitation “once, by one actor.” </p>



<p class="wp-block-paragraph">In response to the report, ServiceNow issued a statement saying that it has not yet directly seen any such exploitations. </p>



<p class="wp-block-paragraph">“ServiceNow is aware of a cybersecurity company’s recent publication regarding exploitation activity associated with a previously disclosed security vulnerability, identified as <a href="https://support.servicenow.com/kb/kb/kb/kb?id=kb_article_view&amp;sysparm_article=KB3137947" target="_blank" rel="noreferrer noopener">CVE-2026-6875</a>. Based on our investigation to date, we have not observed evidence that this activity is related to instances that ServiceNow hosts,” the emailed statement said. “We have provided updates and patches designed to address this issue, and we encourage our self-hosted and ServiceNow-hosted customers to apply the relevant patches if they have not already done so.”</p>



<h2 class="wp-block-heading">A ‘repeatable failure point’</h2>



<p class="wp-block-paragraph">Analysts and consultants said the bigger concern with this hole is that it focuses on the lack of protections in the sandbox, which many security and IT teams have relied on for years. </p>



<p class="wp-block-paragraph">“The vulnerability lets an attacker bypass ServiceNow’s scripting sandbox entirely, and researchers are now seeing exploitation using a different technique than the one originally published, which means signature-based defenses built on the first proof of concept are unlikely to catch every variant,” said <a href="https://my.idc.com/getdoc.jsp?containerId=PRF004767" target="_blank" rel="noreferrer noopener">Frank Dickson</a>, group VP for security at IDC. </p>



<p class="wp-block-paragraph">“A compromise that starts in the cloud tenant can end up inside the corporate network, turning a SaaS incident into an on-premises one,” he pointed out. “And because ServiceNow frequently houses HR records, CMDB asset data, and the ticketing system itself, an attacker sitting inside it may have visibility into how the incident response team is tracking the incident.”</p>



<p class="wp-block-paragraph">Dickson added that this incident is further proof that both IT and security teams need to reevaluate their patching methodologies. </p>



<p class="wp-block-paragraph">“Enterprises outsource patching for platforms like ServiceNow to the vendor, but keep the risk that comes from what those platforms touch: HR records, CMDB inventories, and now on-premises systems through MID Server integration. Control sits with the vendor, liability sits with the enterprise, and that mismatch argues for treating core SaaS platforms as part of the internal attack surface, not externalized vendor risk,” he said, noting that as vendors embed more AI-driven scripting into their platforms, the sandbox boundary becomes “a repeatable failure point.” </p>



<p class="wp-block-paragraph">Because of this, he advised, “CISOs should start asking every AI-enabled SaaS vendor how that boundary is architected and tested, before the next version of this story breaks elsewhere.”</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/noah-m-kenney-27499a166/" target="_blank" rel="noreferrer noopener">Noah Kenney</a>, principal consultant at Digital 520, said the sandbox escape is the more disturbing element of the issue. </p>



<p class="wp-block-paragraph">“The significance is not that ServiceNow had a critical bug, so much as the fact that the bug is a sandbox escape in the AI Platform, which means the containment layer specifically built to run untrusted AI-driven code safely is the thing that failed,” he said. “CISOs have been told repeatedly that the sandbox is what makes enterprise AI safe to deploy, but we’re now seeing the sandbox breaking and that should reframe how CISOs think about every feature sitting behind a similar wall.”</p>



<h2 class="wp-block-heading">Addition of AI increases blast radius</h2>



<p class="wp-block-paragraph">This is yet another example where AI is fundamentally changing just about every IT and security rule, he pointed out.</p>



<p class="wp-block-paragraph">“Enterprises are bolting AI onto their most privileged systems of record faster than anyone is updating the threat models for those systems, and the AI layer is becoming the softest part of the hardest targets,” Kenney said. “The real question for a CISO is how many of your critical platforms shipped an AI feature in the past year, and whether a single person in your organization can tell you what that did to the pre-auth attack surface. Most cannot, and that is the actual exposure.”</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/akm76/" target="_blank" rel="noreferrer noopener">Aman Mahapatra</a>, chief strategy officer for Tribeca Softtech, a New York City-based technology consulting firm, agreed.</p>



<p class="wp-block-paragraph">“A vulnerability that gives an attacker a foothold in the ServiceNow instance is now also a vulnerability that gives them access to whatever AI agents are running inside that instance, along with any capability tokens, service accounts, or delegated permissions those agents hold,” Mahapatra said. “The blast radius of a ServiceNow compromise in 2026 is meaningfully larger than the same compromise would have been in 2023, and most enterprise security programs have not caught up to that shift.”</p>



<p class="wp-block-paragraph">Defused’s Kohonen said that he did not disagree with the sandbox concerns, but he stressed that enterprise CISOs have long ago abandoned the belief that sandboxes are secure. </p>



<p class="wp-block-paragraph">“Nothing is foolproof, and having a sandbox is better than not having one,” he said. “But the belief that a sandbox removes all of the risk is incredibly dumb,” especially in the reality of today’s threat landscape, which contains “an endless conveyor belt of exploits.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[ServiceNow’s sandbox escape RCE hole now exploited in the wild]]></title>
<description><![CDATA[A sandbox security hole that could lead to remote code execution (RCE), patched last week by ServiceNow, is being actively exploited in the wild, according to a report from threat intel firm Defused. 



The report, posted on X, said the firm is “observing in-the-wild exploitation of the ServiceN...]]></description>
<link>https://tsecurity.de/de/3682130/it-nachrichten/servicenows-sandbox-escape-rce-hole-now-exploited-in-the-wild/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3682130/it-nachrichten/servicenows-sandbox-escape-rce-hole-now-exploited-in-the-wild/</guid>
<pubDate>Mon, 20 Jul 2026 22:47:57 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">A sandbox security hole that could lead to remote code execution (RCE), patched last week by ServiceNow, is being actively exploited in the wild, according to <a href="https://x.com/defusedcyber/status/2078418391321219448" target="_blank" rel="noreferrer noopener">a report from threat intel firm Defused</a>. </p>



<p class="wp-block-paragraph">The report, posted on X, said the firm is “observing in-the-wild exploitation of the ServiceNow pre-auth sandbox-escape RCE (CVE-2026-6875).”</p>



<p class="wp-block-paragraph">Defused CEO <a href="https://www.linkedin.com/in/simokohonen" target="_blank" rel="noreferrer noopener">Simo Kohonen</a> noted in an interview that it appeared that the attacker has changed its tactics from those documented in an earlier proof of concept (PoC) from researchers at Searchlight Cyber, in response to ServiceNow patches and defenses. The company had implemented five different mitigations in its code base, which “neutered” the initial attack methodology, he said, adding that, overall, his team is seeing more attack method tweaks than it used to see. </p>



<p class="wp-block-paragraph">“We are seeing a lot of [attack] variations, much more so than a year ago, for the same vulnerability,” Kohonen said. Attackers “now have more tools to build their own stuff.”</p>



<p class="wp-block-paragraph">However, he admitted that his team has thus far only observed this exploit an in the wild exploitation “once, by one actor.” </p>



<p class="wp-block-paragraph">In response to the report, ServiceNow issued a statement saying that it has not yet directly seen any such exploitations. </p>



<p class="wp-block-paragraph">“ServiceNow is aware of a cybersecurity company’s recent publication regarding exploitation activity associated with a previously disclosed security vulnerability, identified as <a href="https://support.servicenow.com/kb/kb/kb/kb?id=kb_article_view&amp;sysparm_article=KB3137947" target="_blank" rel="noreferrer noopener">CVE-2026-6875</a>. Based on our investigation to date, we have not observed evidence that this activity is related to instances that ServiceNow hosts,” the emailed statement said. “We have provided updates and patches designed to address this issue, and we encourage our self-hosted and ServiceNow-hosted customers to apply the relevant patches if they have not already done so.”</p>



<h2 class="wp-block-heading">A ‘repeatable failure point’</h2>



<p class="wp-block-paragraph">Analysts and consultants said the bigger concern with this hole is that it focuses on the lack of protections in the sandbox, which many security and IT teams have relied on for years. </p>



<p class="wp-block-paragraph">“The vulnerability lets an attacker bypass ServiceNow’s scripting sandbox entirely, and researchers are now seeing exploitation using a different technique than the one originally published, which means signature-based defenses built on the first proof of concept are unlikely to catch every variant,” said <a href="https://my.idc.com/getdoc.jsp?containerId=PRF004767" target="_blank" rel="noreferrer noopener">Frank Dickson</a>, group VP for security at IDC. </p>



<p class="wp-block-paragraph">“A compromise that starts in the cloud tenant can end up inside the corporate network, turning a SaaS incident into an on-premises one,” he pointed out. “And because ServiceNow frequently houses HR records, CMDB asset data, and the ticketing system itself, an attacker sitting inside it may have visibility into how the incident response team is tracking the incident.”</p>



<p class="wp-block-paragraph">Dickson added that this incident is further proof that both IT and security teams need to reevaluate their patching methodologies. </p>



<p class="wp-block-paragraph">“Enterprises outsource patching for platforms like ServiceNow to the vendor, but keep the risk that comes from what those platforms touch: HR records, CMDB inventories, and now on-premises systems through MID Server integration. Control sits with the vendor, liability sits with the enterprise, and that mismatch argues for treating core SaaS platforms as part of the internal attack surface, not externalized vendor risk,” he said, noting that as vendors embed more AI-driven scripting into their platforms, the sandbox boundary becomes “a repeatable failure point.” </p>



<p class="wp-block-paragraph">Because of this, he advised, “CISOs should start asking every AI-enabled SaaS vendor how that boundary is architected and tested, before the next version of this story breaks elsewhere.”</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/noah-m-kenney-27499a166/" target="_blank" rel="noreferrer noopener">Noah Kenney</a>, principal consultant at Digital 520, said the sandbox escape is the more disturbing element of the issue. </p>



<p class="wp-block-paragraph">“The significance is not that ServiceNow had a critical bug, so much as the fact that the bug is a sandbox escape in the AI Platform, which means the containment layer specifically built to run untrusted AI-driven code safely is the thing that failed,” he said. “CISOs have been told repeatedly that the sandbox is what makes enterprise AI safe to deploy, but we’re now seeing the sandbox breaking and that should reframe how CISOs think about every feature sitting behind a similar wall.”</p>



<h2 class="wp-block-heading">Addition of AI increases blast radius</h2>



<p class="wp-block-paragraph">This is yet another example where AI is fundamentally changing just about every IT and security rule, he pointed out.</p>



<p class="wp-block-paragraph">“Enterprises are bolting AI onto their most privileged systems of record faster than anyone is updating the threat models for those systems, and the AI layer is becoming the softest part of the hardest targets,” Kenney said. “The real question for a CISO is how many of your critical platforms shipped an AI feature in the past year, and whether a single person in your organization can tell you what that did to the pre-auth attack surface. Most cannot, and that is the actual exposure.”</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/akm76/" target="_blank" rel="noreferrer noopener">Aman Mahapatra</a>, chief strategy officer for Tribeca Softtech, a New York City-based technology consulting firm, agreed.</p>



<p class="wp-block-paragraph">“A vulnerability that gives an attacker a foothold in the ServiceNow instance is now also a vulnerability that gives them access to whatever AI agents are running inside that instance, along with any capability tokens, service accounts, or delegated permissions those agents hold,” Mahapatra said. “The blast radius of a ServiceNow compromise in 2026 is meaningfully larger than the same compromise would have been in 2023, and most enterprise security programs have not caught up to that shift.”</p>



<p class="wp-block-paragraph">Defused’s Kohonen said that he did not disagree with the sandbox concerns, but he stressed that enterprise CISOs have long ago abandoned the belief that sandboxes are secure. </p>



<p class="wp-block-paragraph">“Nothing is foolproof, and having a sandbox is better than not having one,” he said. “But the belief that a sandbox removes all of the risk is incredibly dumb,” especially in the reality of today’s threat landscape, which contains “an endless conveyor belt of exploits.”</p>



<p class="wp-block-paragraph"><em>This article originally appeared on <a href="https://www.csoonline.com/article/4198993/servicenows-sandbox-escape-rce-hole-now-exploited-in-the-wild.html" target="_blank">CSOonline</a>.</em></p>



<p class="wp-block-paragraph"></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Splunk Report Finds One in Five CISOs Pressured to Hide Cybersecurity Incidents]]></title>
<description><![CDATA[  The Splunk 2026 CISO report makes public the challenges that CISOs face when trying to meet the rising demand to mask security incidents while also complying with tightening disclosure laws. According to the report, which draws its conclusions from…
Read more →
The post Splunk Report Finds One ...]]></description>
<link>https://tsecurity.de/de/3681852/it-security-nachrichten/splunk-report-finds-one-in-five-cisos-pressured-to-hide-cybersecurity-incidents/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3681852/it-security-nachrichten/splunk-report-finds-one-in-five-cisos-pressured-to-hide-cybersecurity-incidents/</guid>
<pubDate>Mon, 20 Jul 2026 19:37:19 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>  The Splunk 2026 CISO report makes public the challenges that CISOs face when trying to meet the rising demand to mask security incidents while also complying with tightening disclosure laws. According to the report, which draws its conclusions from…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/splunk-report-finds-one-in-five-cisos-pressured-to-hide-cybersecurity-incidents/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/splunk-report-finds-one-in-five-cisos-pressured-to-hide-cybersecurity-incidents/">Splunk Report Finds One in Five CISOs Pressured to Hide Cybersecurity Incidents</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Ransomware 2026: Opferzahlen in Deutschland steigen - Security-Insider]]></title>
<description><![CDATA[Julien Mousqueton ist Field CISO EMEA bei Cohesity und verfügt über mehr als 25 Jahre Erfahrung in IT und Cybersecurity. Er gründete ransomware.live, ...]]></description>
<link>https://tsecurity.de/de/3681716/it-security-nachrichten/ransomware-2026-opferzahlen-in-deutschland-steigen-security-insider/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3681716/it-security-nachrichten/ransomware-2026-opferzahlen-in-deutschland-steigen-security-insider/</guid>
<pubDate>Mon, 20 Jul 2026 19:01:02 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Julien Mousqueton ist Field CISO EMEA bei Cohesity und verfügt über mehr als 25 Jahre Erfahrung in <b>IT</b> und Cybersecurity. Er gründete ransomware.live, ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Health-ISAC CISO Benchmarking-Bericht 2026]]></title>
<description><![CDATA[Die Budgets für Cybersicherheit im Gesundheitssektor wachsen, doch die Ausgabenmuster zeigen, dass der Sektor noch immer hinter einer ...]]></description>
<link>https://tsecurity.de/de/3681708/it-security-nachrichten/health-isac-ciso-benchmarking-bericht-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3681708/it-security-nachrichten/health-isac-ciso-benchmarking-bericht-2026/</guid>
<pubDate>Mon, 20 Jul 2026 19:00:50 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Die Budgets für <b>Cybersicherheit</b> im Gesundheitssektor wachsen, doch die Ausgabenmuster zeigen, dass der Sektor noch immer hinter einer ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Safety guardrails blocked Hugging Face's defenders, not the attacker, when an AI agent breached its systems]]></title>
<description><![CDATA[Hugging Face’s incident response team first turned to frontier AI models to analyze a breach of the company’s production infrastructure, and the models refused to help. Commercial safety guardrails built to stop attackers blocked every forensic query because they treated the IR team’s real exploi...]]></description>
<link>https://tsecurity.de/de/3681589/it-nachrichten/safety-guardrails-blocked-hugging-faces-defenders-not-the-attacker-when-an-ai-agent-breached-its-systems/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3681589/it-nachrichten/safety-guardrails-blocked-hugging-faces-defenders-not-the-attacker-when-an-ai-agent-breached-its-systems/</guid>
<pubDate>Mon, 20 Jul 2026 18:03:18 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Hugging Face’s incident response team first turned to frontier AI models to analyze a breach of the company’s production infrastructure, and the models refused to help. Commercial safety guardrails built to stop attackers blocked every forensic query because they treated the IR team’s real exploit data the same way they would treat a live attack.</p><p>The attacker, an autonomous AI agent running the campaign end to end, moved laterally across the Hugging Face infrastructure for a weekend, undetected and unstopped.</p><p>Security leaders are quick to recognize the pattern and diagnose what went wrong. “I’ve seen versions of this during red-team exercises and internal security testing, but this is one of the first high-profile examples where it materially affected real incident response,” said Merritt Baer, senior adviser to Andesite, G2I, and AppOmni and former Deputy CISO at AWS.</p><p>None of this is unique to Hugging Face, Baer said. “Commercial frontier models optimize for preventing misuse. They generally have no cryptographic or organizational way to determine whether the person asking ‘analyze this malware’ is an incident responder or the malware author.”</p><h2><b>A malicious dataset opened two code-execution paths</b></h2><p>On July 16, Hugging Face <a href="https://huggingface.co/blog/security-incident-july-2026">disclosed</a> that an autonomous AI agent system had compromised its production infrastructure, gaining unauthorized access to a limited set of internal datasets and several service credentials. The company verified that its software supply chain was clean and found no evidence of tampering with public models, datasets, or Spaces. </p><p>Hugging Face is still assessing whether the intrusion touched any partner or customer data and says it will contact affected parties directly as required. But few enterprise threat models had accounted for the attacker Hugging Face faced. An autonomous agent ran the entire campaign from initial access through credential harvesting. No human guided it.</p><p>The entry point was a malicious dataset. When the data-processing pipeline ingested it, the dataset triggered code execution in two ways, through a remote-code loader and through a template-injection flaw in dataset configuration files. No admission gate screened the file before it reached a processing worker, the compute job assigned to each dataset. Initial access came through the data pipeline itself, a route that worked because most enterprise security teams treat the data feeding their pipelines as trusted input rather than an attack surface.</p><p>Worker isolation did not hold. From that first foothold, the agent broke out onto the node running the workload, then harvested cloud and cluster credentials scoped broadly enough to reach multiple internal clusters, all of it inside a single weekend. Hugging Face described the agent framework as executing thousands of individual actions through a swarm of short-lived sandboxes, with self-migrating command-and-control staged on public services. The disclosure adds that the framework appeared to be built on an agentic security-research harness, which would put tooling designed for red-team work behind a live intrusion. </p><h2><b>Why the defenders’ queries looked like attacks</b></h2><p>Investigators reconstructed more than 17,000 recorded events using AI-driven analysis agents of their own.</p><p>First attempts at the log analysis ran on frontier models behind commercial APIs. Defenders’ steps included submitting real attack commands, exploit payloads, and command-and-control artifacts for classification, but safety guardrails blocked the requests outright.</p><p>Baer traced the block to the prompts themselves. “The same prompts that are most valuable during an active intrusion, shell commands, exploit chains, credential dumps, persistence mechanisms, lateral movement, are exactly the prompts most likely to trigger safety systems,” she told VentureBeat. “As AI becomes embedded in security operations, this becomes an operational resilience issue rather than merely a model policy issue.”</p><h2><b>The forensic analysis finished on GLM 5.2</b></h2><p>GLM 5.2, an open-weight model deployed on Hugging Face’s own infrastructure, took the job the commercial APIs refused. No attacker data left the company’s environment. “This experience points to a gap worth planning for,” the company wrote in its disclosure. Hugging Face does not know which model powered the agents. It could have been a jailbroken hosted model or an open-weight model running without restrictions. Either way, the disclosure continued, “the attacker was bound by no usage policy, while our own forensic work was blocked by the guardrails of the hosted models we first tried.” Hugging Face drew that line itself, writing that the experience is not an argument against safety measures on hosted models and that it is sharing the feedback with the providers concerned.</p><h2><b>What authenticated trust changes</b></h2><p>The industry, Baer argued, needs to move past treating AI safety as a content moderation problem. “Security operations require something different. Authenticated trust.” Instead of asking whether anyone should receive an answer, the question becomes whether an authenticated security team, operating under enterprise controls, should receive it. “The model shouldn’t only understand what is being asked. It should understand who is asking, why, and under what governance.”</p><p>“Organizations already build contingency plans for cloud outages, identity provider failures, or EDR failures,” Baer wrote. “AI assistants are becoming another dependency.”</p><p>Her advice on IR playbooks was blunt. “A mature incident response plan should assume that during a severe incident, commercial AI APIs may refuse requests, API rate limits may become unavailable, internet connectivity may be impaired, and data governance rules may prohibit uploading forensic evidence externally.” The lesson, she wrote in her emailed answers, “isn’t ‘don’t use commercial models.’ It’s ‘don’t make them a single point of failure.’”</p><h2><b>AI-enabled attacks rose 89% year-over-year</b></h2><p>Autonomous AI-driven attacks are not limited to AI platforms. <a href="https://www.crowdstrike.com/en-us/global-threat-report/">CrowdStrike’s 2026 Global Threat Report</a> documented AI-enabled adversary operations increasing by 89% year over year, with average breakout times falling to 29 minutes. Enterprises running AI workloads in production with agentic access to their pipelines face similar exposure.</p><p>Six control domains determined the blast radius and recovery speed at Hugging Face. Each one maps to a concrete action security leaders can take before the next autonomous-agent breach arrives.</p><h2><b>AI Pipeline Breach Response Playbook</b></h2><table><tbody><tr><td><p><b>Control Domain</b></p></td><td><p><b>What Broke</b></p></td><td><p><b>Monday Action</b></p></td></tr><tr><td><p>Dataset admission controls</p></td><td><p>Two code-execution paths were exploited. No admission gate validated the dataset before it reached a processing worker. The data pipeline became the initial access infrastructure.</p></td><td><p>Require sandbox execution and static analysis of all datasets before they reach workers. Block remote-code loaders and template-injection paths by default. Audit for any path granting code execution to untrusted content. Report to the board as a supply-chain risk.</p></td></tr><tr><td><p>Worker-to-node privilege boundaries</p></td><td><p>Worker isolation failed to prevent escalation to the node. The agent gained cluster credentials because the workload-infrastructure boundary was never enforced at container runtime.</p></td><td><p>Enforce hard privilege boundaries between workers and nodes. Deploy container runtime security to prevent workload escape. Audit whether workers can reach node-level APIs or credential stores. Include in the next penetration test scope.</p></td></tr><tr><td><p>Credential exposure</p></td><td><p>Cloud and cluster credentials harvested after node access. The scope was broad enough for lateral movement across multiple clusters over a weekend.</p></td><td><p>Rotate credentials on a scheduled cadence and after any anomaly alert. Scope to the minimum cluster and service. Deploy monitoring that flags access from unexpected nodes at machine speed. Map blast radius for board reporting.</p></td></tr><tr><td><p>Machine-speed detection</p></td><td><p>Thousands of actions through short-lived sandboxes with self-migrating C2. AI-assisted anomaly detection surfaced the campaign after a weekend of lateral movement, per the disclosure.</p></td><td><p>Calibrate detection for machine-speed patterns. Ensure high-severity alerts page responders in minutes, regardless of time. Audit SIEM rules for detecting thousands of short-lived executions within a single hour.</p></td></tr><tr><td><p>Private AI forensic capacity</p></td><td><p>Commercial APIs blocked forensic analysis. Guardrails screened query content, never analyst identity. Investigation ran on GLM 5.2 privately.</p></td><td><p>Deploy a capable open-weight model on private infrastructure before an incident. Test against real forensic workflows. Ensure IR playbook includes fallback for when commercial APIs refuse. Document gap for cyber insurance.</p></td></tr><tr><td><p>Autonomous-agent threat modeling</p></td><td><p>The campaign matched the forecast agentic-attacker scenario, but no threat model had operationalized it. LLM powering the agent is still unknown.</p></td><td><p>Add autonomous AI agents as a distinct adversary class with machine-speed decision cycles. Run tabletop at agent speed. Present results to the board as evidence that timelines need recalibration. Include in the cyber insurance application.</p></td></tr></tbody></table><h2><b>The board question is operational resilience</b></h2><p>“The question for directors is simple. What happens if one of our critical security tools becomes unavailable during the exact moment we need it most?” Baer framed that as operational resilience, not AI policy. </p><p>She would have boards take that framing straight to management and press for specifics. “Have we actually exercised that fallback during tabletop exercises? How quickly can we switch during an incident?” Procurement needs to change alongside governance, starting with the questions buyers ask. Security teams evaluating AI vendors should ask about their process for authenticated incident responders, whether enterprise customers receive different handling during verified incidents, and whether models can be deployed privately. “Those questions belong alongside uptime, privacy, and compliance,” Baer said.</p><p>“The biggest takeaway isn’t that safety guardrails are ‘bad.’ They’re doing what they were designed to do,” she argued. </p><p>Her larger point is that the threat model itself has changed. “For decades, defenders had better tools than attackers because they operated inside trusted enterprise environments. With foundation models, both sides increasingly use the same capabilities, but one side is constrained by enterprise governance, policy, compliance, and safety controls, while the adversary simply downloads an uncensored open-weight model and keeps going. That’s a new kind of asymmetry,” she added. “The organizations that handle it best won’t necessarily be the ones with the most powerful AI. They’ll be the ones that architect AI as a resilient security capability rather than a single cloud service.”</p><p>Hugging Face has contained the intrusion, rebuilt compromised nodes, rotated credentials, and reported the incident to law enforcement. The company recommends that all users rotate access tokens and review recent account activity. Mid-incident, Hugging Face found out whether its own AI tooling would be available, and the first answer was no. Security leaders running AI in production should find out in incident response planning instead, before an autonomous agent forces the test.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI adoption and business acceleration are changing the expectations of technology risk management]]></title>
<description><![CDATA[As AI becomes embedded in customer experiences, internal workflows, and throughout the supply chain, security leaders are being asked to do more than manage risk. They are being asked to help the business make more informed decisions and move faster.



At the same time, AI has evolved faster tha...]]></description>
<link>https://tsecurity.de/de/3681443/it-security-nachrichten/ai-adoption-and-business-acceleration-are-changing-the-expectations-of-technology-risk-management/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3681443/it-security-nachrichten/ai-adoption-and-business-acceleration-are-changing-the-expectations-of-technology-risk-management/</guid>
<pubDate>Mon, 20 Jul 2026 16:55:00 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">As AI becomes embedded in customer experiences, internal workflows, and throughout the supply chain, security leaders are being asked to do more than manage risk. They are being asked to help the business make more informed decisions and move faster.</p>



<p class="wp-block-paragraph">At the same time, AI has evolved faster than the programs built to govern it.</p>



<p class="wp-block-paragraph">The result is a widening gap between the pace of transformation and the ability of security, risk, privacy, compliance, and third-party risk teams to understand where the business is exposed.</p>



<h3 class="wp-block-heading"><strong>Move Fast, Don’t Break Things</strong></h3>



<p class="wp-block-paragraph">AI introduces risks like prompt injection and jailbreaks, but the issues keeping CISOs awake at night are more familiar: over-permissioned accounts, poor logging, credentials left in old repositories, sensitive data scattered across systems, and weak access controls. </p>



<p class="wp-block-paragraph">AI gives those risks more speed, reach, and impact. </p>



<p class="wp-block-paragraph">When AI agents are connected to enterprise data, workflows, vendors, and applications, the blast radius of existing weak spots expands quickly. A low-severity incident now becomes harder to detect, more difficult to remediate, and more consequential for the business. </p>



<p class="wp-block-paragraph">This is why boards and executive teams are looking to security leaders for proactive guidance. They want to know whether the business can adopt AI at scale without creating risk that undermines long-term value. </p>



<p class="wp-block-paragraph"><em>“Tell us, in real time, which initiatives are safe to accelerate, where we’re exposed, what could slow down our transformation, and what we need to act on right now.”</em></p>



<p class="wp-block-paragraph">The CISO mandate has evolved from risk reporting to innovation enablement. </p>



<h3 class="wp-block-heading"><strong>When Everything is a Risk, Nothing is a Priority</strong></h3>



<p class="wp-block-paragraph">In many organizations, risk context is spread across multiple teams. Security, procurement, privacy, IT, and third-party risk each have their own view.   </p>



<p class="wp-block-paragraph">That fragmentation creates blind spots. </p>



<p class="wp-block-paragraph">Consider an AI agent that can retrieve customer records, access internal knowledge bases, and trigger downstream workflows. Security may know the agent exists, IT may know where it’s deployed, and procurement may know who purchased it. </p>



<p class="wp-block-paragraph">Without a holistic view, however, it becomes difficult to determine whether the agent has the right permissions, if it is operating within policy, or how it could expose the business.</p>



<p class="wp-block-paragraph">But visibility is only half the battle. As AI systems, identities, vendors, and data change at a dizzying scale, organizations need to understand whether policy is actually being followed in real time.</p>



<p class="wp-block-paragraph">A control that was effective six months ago may no longer suffice after a new AI integration, a vendor update, or a change in permissions. </p>



<p class="wp-block-paragraph">Today’s systems are too dynamic to be governed by the same operating model that worked for yesterday’s tech stack. </p>



<h3 class="wp-block-heading"><strong>From Risk Review to Risk Decisioning</strong></h3>



<p class="wp-block-paragraph">CISOs are now being asked to help the business decide—quickly and defensibly—what can move forward, what needs guardrails, and what should stop. Meeting that mandate requires a different approach: </p>



<ul class="wp-block-list">
<li>Treat AI risk as part of enterprise risk, not a separate discipline. AI is embedded in the same decisions organizations already make about data, vendors, identities, controls, and business processes.</li>



<li>Start with the business process and context, not the model. Understand what processes depend on this system, the data it touches, and what happens if it fails. </li>



<li>Move from one-time approval to continuous assurance. What matters isn’t whether an AI project passed review six months ago, but whether it is operating within the organizations policies and risk appetite today.</li>



<li>Measure decision velocity. Demonstrate how quickly the organization is able to determine what moves forward, what needs guardrails, and what must stop.</li>
</ul>



<p class="wp-block-paragraph">When risk is connected across the business, priorities become clear. Security leaders can understand not just what needs to be addressed, but what matters most, who owns it, and what the business impact could be. </p>



<p class="wp-block-paragraph">When there is a shared understanding of approved use, teams can move faster without relying on ad hoc reviews, static questionnaires, or blanket restrictions. The goal is to make technology and third-party risk visible, prioritized, and actionable at the speed the business now operates.</p>



<p class="wp-block-paragraph">That shift helps <a href="https://www.onetrust.com/solutions/security-and-risk-teams/">security leaders</a> say “yes” with confidence.</p>



<h3 class="wp-block-heading"><strong>Safeguard Transformation and Scale Innovation</strong></h3>



<p class="wp-block-paragraph">I know the pressure many CISOs are carrying right now. Your scope is getting larger while resources continue to shrink. </p>



<p class="wp-block-paragraph">Your leadership is asking you to protect every facet of the organization, support growing risk and compliance requirements, and now, to be a key voice in guiding business strategy.  </p>



<p class="wp-block-paragraph">When you have clarity on what risks truly matter and have the tools to take action, your risk program can become a driver of responsible and scalable innovation. </p>



<p class="wp-block-paragraph"><em>OneTrust helps build risk and compliance programs aligned with the complexity and the speed of your business. </em><a href="https://www.onetrust.com/forms/talk-to-a-risk-expert/"><em>Learn more about our integrated risk solutions.</em></a><em></em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Claude Mythos FAQ: Capabilities, access, competitors, implications]]></title>
<description><![CDATA[1.
What is Claude Mythos?




Claude Mythos is an advanced AI model developed by Anthropic and is optimized for cybersecurity and healthcare applications.



Mythos 5 was originally released in April to a small group of vetted technology partners ahead of a planned wider rollout.



Anthropic est...]]></description>
<link>https://tsecurity.de/de/3680433/it-security-nachrichten/claude-mythos-faq-capabilities-access-competitors-implications/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3680433/it-security-nachrichten/claude-mythos-faq-capabilities-access-competitors-implications/</guid>
<pubDate>Mon, 20 Jul 2026 08:38:28 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<div class="wp-block-idg-base-theme-faq-block faq-block">
<div class="wp-block-idg-base-theme-faq-inner-block faq-save-block"><div class="faq-save-content"><span class="faq-rank">1.</span>
<h2 class="wp-block-heading">What is Claude Mythos?</h2>



<div class="wp-block-idg-base-theme-faq-answer-block how-to-tip">
<p class="wp-block-paragraph">Claude Mythos is an advanced AI model developed by Anthropic and is optimized for cybersecurity and healthcare applications.</p>



<p class="wp-block-paragraph"><a href="https://www.anthropic.com/claude/mythos">Mythos 5</a> was originally released in April to a small group of vetted technology partners ahead of a planned wider rollout.</p>



<p class="wp-block-paragraph">Anthropic established <strong>Project Glasswing</strong>, a consortium that gives limited, controlled access to Mythos to infrastructure providers, open-source developers, and major technology companies. The scheme was designed to enable defenders to find and resolve vulnerabilities faster than they could be identified by attackers, <a href="https://www.csoonline.com/article/4154222/6-ways-attackers-abuse-ai-services-to-hack-your-business.html">many of which are also beginning to rely heavily on AI tools</a>.</p>
</div>
</div></div>



<div class="wp-block-idg-base-theme-faq-inner-block faq-save-block"><div class="faq-save-content"><span class="faq-rank">2.</span>
<h2 class="wp-block-heading">What are the capabilities of Claude Mythos?</h2>



<div class="wp-block-idg-base-theme-faq-answer-block how-to-tip">
<p class="wp-block-paragraph">The <a href="https://www.csoonline.com/article/4155342/what-anthropic-glasswing-reveals-about-the-future-of-vulnerability-discovery.html">50 initial partners of Project Glasswing</a> were able to use Mythos to find more than <a href="https://www.csoonline.com/article/4176865/project-glasswing-has-uncovered-10000-vulnerabilities-anthropic.html">10,000 high- or critical-severity vulnerabilities</a> in every major operating system and <a href="https://www.csoonline.com/article/4162259/claude-mythos-signals-a-new-era-in-ai-driven-security-finding-271-flaws-in-firefox.html">every major web browser</a>.</p>



<p class="wp-block-paragraph">The model is identifying security flaws that had evaded even the most capable security researchers for years, such as a <a href="https://www.csoonline.com/article/4159617/behind-the-mythos-hype-glasswing-has-just-one-confirmed-cve.html">27-year-old bug in OpenBSD</a>. It has also proved capable of chaining multiple vulnerabilities together.</p>
</div>
</div></div>



<div class="wp-block-idg-base-theme-faq-inner-block faq-save-block"><div class="faq-save-content"><span class="faq-rank">3.</span>
<h2 class="wp-block-heading">How is Anthropic restricting access to Claude Mythos?</h2>



<div class="wp-block-idg-base-theme-faq-answer-block how-to-tip">
<p class="wp-block-paragraph">Anthropic said it was restricting the more widespread availability of the frontier AI model because its capabilities might easily be misused by attackers.</p>



<p class="wp-block-paragraph">In June the technology was released to an <a href="https://www.csoonline.com/article/4180265/anthropic-grants-project-glasswing-access-to-150-more-companies-with-a-focus-on-critical-infrastructure.html">additional 150 organizations</a>. All Mythos partners are required to accept a 30-day data retention policy for safety monitoring.</p>



<p class="wp-block-paragraph">After the availability of Mythos forced the <a href="https://www.csoonline.com/article/4166824/anthropic-mythos-spurs-white-house-to-weigh-pre-release-reviews-for-high-risk-ai-models.html">Trump administration to reconsider its “hands off” approach to AI oversight</a>, the US government applied export controls to Claude Fable 5 and Claude Mythos 5 on June 15. The restrictions — which were supposed to block access to foreign nationals both inside and outside the US — were lifted on June 30.</p>
</div>
</div></div>



<div class="wp-block-idg-base-theme-faq-inner-block faq-save-block"><div class="faq-save-content"><span class="faq-rank">4.</span>
<h2 class="wp-block-heading">What is Claude Fable?</h2>



<div class="wp-block-idg-base-theme-faq-answer-block how-to-tip">
<p class="wp-block-paragraph">For broader use, Anthropic is offering <a href="https://www.csoonline.com/article/4183094/anthropic-releases-mythos-class-fable-5-model-with-safeguards-for-cyber-risks.html">Claude Fable 5</a>, which is based on the same underlying technology but comes with strict guardrails that limit operations in “risky” cybersecurity domains. Flagged queries are automatically routed to the earlier and less capable Opus 4.8 large language model (LLM) instead.</p>
</div>
</div></div>



<div class="wp-block-idg-base-theme-faq-inner-block faq-save-block"><div class="faq-save-content"><span class="faq-rank">5.</span>
<h2 class="wp-block-heading">How are Anthropic’s security vendor partners using access to Mythos?</h2>



<div class="wp-block-idg-base-theme-faq-answer-block how-to-tip">
<p class="wp-block-paragraph">Cisco, one of Anthropic’s Project Glasswing partners, <a href="https://blogs.cisco.com/ai/announcing-foundry-security-spec">open-sourced its Foundry Security Spec</a>, a model-agnostic “harness” for security testing, so that other vendors and enterprise security defenders could build similar workflows without starting from scratch.</p>



<p class="wp-block-paragraph">During a recent web conference, representatives from Cisco argued that defenders can use AI to identify, confirm, and resolve security issues at much greater speed and scale. Older vulnerability remediation models based on “find one issue, patch one issue” are no longer adequate because attackers are using AI moving to accelerate the path from vulnerability discovery to exploitation.</p>



<p class="wp-block-paragraph">Cisco has been using AI internally to scan 1.8 billion lines of code across its whole product portfolio.</p>



<p class="wp-block-paragraph">Smaller businesses do not need access to restricted AI models to improve security and more can be achieved in smaller shops by improving security fundamentals such as authentication, segmentation, zero trust, and prioritizing the remediation of actively exploited vulnerabilities, according to Cisco.</p>
</div>
</div></div>



<div class="wp-block-idg-base-theme-faq-inner-block faq-save-block"><div class="faq-save-content"><span class="faq-rank">6.</span>
<h2 class="wp-block-heading">Do other AI vendors offer anything comparable to Claude Mythos?</h2>



<div class="wp-block-idg-base-theme-faq-answer-block how-to-tip">
<p class="wp-block-paragraph">Mythos is the most prominent example of frontier AI models that can automate zero-day discovery at a scale and speed far beyond the capability of human teams.</p>



<p class="wp-block-paragraph">Several other vendors have frontier AI models aimed towards high-capability, security-oriented operations while others have capable open models that might easily be applied to cybersecurity research.</p>



<p class="wp-block-paragraph">As a result, Claude Mythos is far from the only game in town.</p>



<p class="wp-block-paragraph">For example, OpenAI’s GPT-5.4-Cyber (and <a href="https://openai.com/index/gpt-5-5-with-trusted-access-for-cyber/">GPT-5.5</a>) has applications in vulnerability analysis and discovery as well as malware analysis and threat modelling. Security vendors, enterprises, and researchers can gain access to the technology through OpenAI’s Trusted Access for Cyber (TAC) scheme.</p>



<p class="wp-block-paragraph">Chinese cybersecurity firm <a href="https://www.reuters.com/legal/litigation/chinas-360-says-it-has-developed-tools-match-anthropics-mythos-2026-06-24/">360 Security Technology has developed Tulongfeng</a>, described as a domestic answer to Anthropic’s Mythos.</p>



<p class="wp-block-paragraph">High performance open models — including DeepSeek V3.2 and Llama 4 — can be run privately on GPU infrastructure and applied to cybersecurity research. Fugu from Japanese vendor Sakana AI offers another option in this category.</p>
</div>
</div></div>



<div class="wp-block-idg-base-theme-faq-inner-block faq-save-block"><div class="faq-save-content"><span class="faq-rank">7.</span>
<h2 class="wp-block-heading">What do cybersecurity critics say about Claude Mythos?</h2>



<div class="wp-block-idg-base-theme-faq-answer-block how-to-tip">
<p class="wp-block-paragraph">Infosecurity critics note that while Claude Mythos is unquestionably advanced, marketing claims that it is reliably breaking production systems overstate its capabilities.</p>



<p class="wp-block-paragraph">Security professionals are complaining through <a href="https://www.youtube.com/watch?v=mx0CpTp3Q4Y">podcasts</a> and elsewhere about the overly sensitive guardrails in Claude Fable that downgrade to Opus 4.8 upon requests to summarize a security-related blog post or even spell the word “exploit” much less tackle any everyday information security task.</p>



<p class="wp-block-paragraph">Other experts warn that false positives are likely to be an issue for cybersecurity research using frontier AI models.</p>



<p class="wp-block-paragraph">The wider criticism is that finding more vulnerabilities faster fails to address the bigger problem of reliability fixing security bugs or non-technical attack paths such as social engineering.</p>
</div>
</div></div>



<div class="wp-block-idg-base-theme-faq-inner-block faq-save-block"><div class="faq-save-content"><span class="faq-rank">8.</span>
<h2 class="wp-block-heading">How should enterprise CISOs respond to the development of Mythos?</h2>



<div class="wp-block-idg-base-theme-faq-answer-block how-to-tip">
<p class="wp-block-paragraph">Western intelligence agencies that form the <a href="https://www.ncsc.gov.uk/sites/default/files/2026-06/Five-Eyes-cyber-security-agencies-statement-ai-shift.pdf">Fives Eyes alliance issued a statement warning that frontier AI models such as Claude Mythos</a> are “fundamentally transforming both offensive and defensive cyber capabilities” in a scale of months rather than years.</p>



<p class="wp-block-paragraph">“While Al will help us improve cyber defence over time, it also accelerates the speed, scale, and sophistication of cyber threats,” the group, which includes the US National Security Agency and the UK’s National Cyber Security Centre, warns.</p>



<p class="wp-block-paragraph">Enterprises need to be using AI to strengthen defenses as part of broader plans to improve cybersecurity resilience.</p>



<p class="wp-block-paragraph">AI-based systems capable of mapping realistic attack paths faster than any human adversary are fast becoming a pervasive threat, while most organizations are nowhere near ready for what that means for their threat models, one expert warns.</p>



<p class="wp-block-paragraph">“We now have AI systems that can map realistic attack paths across software, vendors, and critical infrastructure faster than human adversaries can catalog them,” says Joe Hubback, partner and CISO at consultancy Elixirr and former McKinsey Partner. “And as Mythos-class capabilities are prepared for broad commercial release, that’s no longer a niche research problem, it’s something every organization will have to factor into its threat model.”</p>



<p class="wp-block-paragraph">An <a href="https://labs.cloudsecurityalliance.org/wp-content/uploads/2026/04/mythosready-20260413.pdf">AI safety paper from the Cloud Security Alliance</a> warns that AI has significantly compressed the time between vulnerability discovery and exploitation, outpacing traditional patch-and-react security models. Organizations should brace for ongoing waves of AI-discovered vulnerabilities from Project Glasswing and other sources.</p>



<p class="wp-block-paragraph">“The capabilities seen in Mythos will quickly become more widely available, dramatically increasing the number and frequency of complex, novel attacks organizations will face,” it warns.</p>



<p class="wp-block-paragraph">Enterprise security defenders need to shift to a “Mythos-ready” approach built around continuous vulnerability operations, faster prioritization, and improved incident response.</p>
</div>
</div></div>
</div>



<p class="wp-block-paragraph"><strong>See also:</strong></p>



<ul class="wp-block-list">
<li><a href="https://www.csoonline.com/article/4155342/what-anthropic-glasswing-reveals-about-the-future-of-vulnerability-discovery.html">What Anthropic Glasswing reveals about the future of vulnerability discovery</a></li>



<li><a href="https://www.csoonline.com/article/4158117/anthropics-mythos-signals-a-structural-cybersecurity-shift.html">Anthropic’s Mythos signals a structural cybersecurity shift</a></li>



<li><a href="https://www.csoonline.com/article/4180920/beware-the-son-of-mythos-security-experts-warn.html">Beware the ‘son of Mythos,’ security experts warn</a></li>



<li><a href="https://www.csoonline.com/article/4189600/mythos-is-a-signal-not-a-siren-what-frontier-ai-should-change-for-cisos.html">Mythos is a signal, not a siren: What frontier AI should change for CISOs</a></li>
</ul>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Agentic Logins, ClickFix-Lures und neue Ransomware-Risiken: CISO-Update]]></title>
<description><![CDATA[LONDON (IT BOLTWISE) – Während Angreifer mit ClickFix- und Kill-Loop-Techniken Passwörter erzwingen und modularen Stealern hinterherlaufen, rückt bei Unternehmen gleichzeitig die Frage nach KI-sicheren Anmeldungen in den Vordergrund. 1Password koppelt bei „Agentic Mode“ Zugriffe an genehmigungspf...]]></description>
<link>https://tsecurity.de/de/3678532/it-security-nachrichten/agentic-logins-clickfix-lures-und-neue-ransomware-risiken-ciso-update/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3678532/it-security-nachrichten/agentic-logins-clickfix-lures-und-neue-ransomware-risiken-ciso-update/</guid>
<pubDate>Sat, 18 Jul 2026 23:20:19 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1024" height="1024" src="https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-clickfix-agentic-login-session.jpg" class="attachment- size- wp-post-image" alt="" decoding="async" srcset="https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-clickfix-agentic-login-session.jpg 1024w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-clickfix-agentic-login-session-300x300.jpg 300w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-clickfix-agentic-login-session-150x150.jpg 150w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-clickfix-agentic-login-session-768x768.jpg 768w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-clickfix-agentic-login-session-840x840.jpg 840w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-clickfix-agentic-login-session-120x120.jpg 120w" sizes="(max-width: 1024px) 100vw, 1024px">LONDON (IT BOLTWISE) – Während Angreifer mit ClickFix- und Kill-Loop-Techniken Passwörter erzwingen und modularen Stealern hinterherlaufen, rückt bei Unternehmen gleichzeitig die Frage nach KI-sicheren Anmeldungen in den Vordergrund. 1Password koppelt bei „Agentic Mode“ Zugriffe an genehmigungspflichtige, sitzungsbasierte Berechtigungen – ohne dass die KI den Klartext-Secret sieht. Parallel zeigen Daten zu Windows-10-Altlasten und schnell wachsenden KI-Rechenzentren, […]</p>
<div><a href="https://www.it-boltwise.de/agentic-logins-clickfix-lures-und-neue-ransomware-risiken-ciso-update.html">... den vollständigen Artikel <strong>»Agentic Logins, ClickFix-Lures und neue Ransomware-Risiken: CISO-Update«</strong> lesen</a></div>
<p>Dieser Beitrag <a href="https://www.it-boltwise.de/agentic-logins-clickfix-lures-und-neue-ransomware-risiken-ciso-update.html">Agentic Logins, ClickFix-Lures und neue Ransomware-Risiken: CISO-Update</a> erschien als erstes auf <a href="https://www.it-boltwise.de/">IT BOLTWISE x Artificial Intelligence</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Amazons Alexa+ im Test: Damit hätte Captain Kirk die USS Enterprise nicht steuern können]]></title>
<description><![CDATA[... IT-Systemadministrator (m/w/d) DMK E-BUSINESS GmbH, Chemnitz (öffnet im neuen Fenster) · Chief Information Security Officer / CISO (m/w/x) BOGE ...]]></description>
<link>https://tsecurity.de/de/3678395/it-security-nachrichten/amazons-alexa-im-test-damit-haette-captain-kirk-die-uss-enterprise-nicht-steuern-koennen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3678395/it-security-nachrichten/amazons-alexa-im-test-damit-haette-captain-kirk-die-uss-enterprise-nicht-steuern-koennen/</guid>
<pubDate>Sat, 18 Jul 2026 20:38:20 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[... <b>IT</b>-Systemadministrator (m/w/d) DMK E-BUSINESS GmbH, Chemnitz (öffnet im neuen Fenster) · Chief Information <b>Security</b> Officer / CISO (m/w/x) BOGE ...]]></content:encoded>
</item>
<item>
<title><![CDATA[The last human relationship in cybersecurity]]></title>
<description><![CDATA[We are inundated with promises that artificial intelligence will save us and that the next governance framework will protect us. Buy this platform, adopt that model and the hard part finally gets easier. After 15 years in this field, I have wanted that shortcut as much as anyone.



But both prom...]]></description>
<link>https://tsecurity.de/de/3675960/it-nachrichten/the-last-human-relationship-in-cybersecurity/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675960/it-nachrichten/the-last-human-relationship-in-cybersecurity/</guid>
<pubDate>Fri, 17 Jul 2026 14:03:27 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">We are inundated with promises that artificial intelligence will save us and that the next governance framework will protect us. Buy this platform, adopt that model and the hard part finally gets easier. After 15 years in this field, I have wanted that shortcut as much as anyone.</p>



<p class="wp-block-paragraph">But both promises are downstream of something neither one can produce. You cannot automate trust between two people. You cannot govern your way to a relationship. As AI moves into the core of how organizations operate, and accountability stops mapping cleanly to the org chart, what holds when the stakes are highest is not the platform or the policy. It is two human leaders who know each other well enough to carry the weight together.</p>



<p class="wp-block-paragraph">I think about this often now, a year after publishing a book about the pressures bearing down on security leaders, “<a href="https://www.amazon.com/dp/B0F6DDK8CD">The CISO On The Razor’s Edge: Leading Cybersecurity When The System Is Designed To Break</a>.” The partnership between the CIO and the CISO is the last human relationship in cybersecurity. AI raises the stakes. Governance sets the floor. The relationship is what holds.</p>



<p class="wp-block-paragraph">I saw it work once, up close. When I worked in Washington State, the CIO, <a href="https://www.linkedin.com/in/william-kehoe-a37a0714b/">Bill Kehoe</a>, talked to his CISO, <a href="https://www.linkedin.com/in/ralfjnsn/">Ralph Johnson</a>, every day. Weekends included. Not because a policy required it, but because the mission did. That partnership is a large part of why the role stayed sustainable for them when it broke so many others.</p>



<h2 class="wp-block-heading">The promise we keep believing</h2>



<p class="wp-block-paragraph">Walk any conference floor and you will hear the same pitch in a hundred variations. The next AI layer will close the gap. The next framework will lock down the risk. The technology is usually ready. The organization is not. I have watched too many well-funded programs stall to still believe the tool is the answer, and almost every time, the breakdown traced back to leaders who were not aligned before the work began. A framework run by misaligned leaders inherits the misalignment. You can buy the best controls on the market and still watch them fail when two leaders work from different assumptions about who owns what.</p>



<p class="wp-block-paragraph">Bill and Ralph understood this. Security decisions were not handed to Ralph after the fact to bless or block. They were made with him, inside the technology decisions, because the two had already agreed on what mattered. That is not governance. That is leadership creating the conditions in which governance can work.</p>



<p class="wp-block-paragraph">It is the real lesson I came to in the book. Technical knowledge matters, but it is not enough. As I wrote then, “Influence, trust and internal relationships are non-negotiable.” Without influence, CISOs cannot lead. Without technical substance, they cannot prioritize what matters. And without partnership, especially with their CIO, “they’re operating without a safety net.”</p>



<p class="wp-block-paragraph">AI does not change that truth. It raises the cost of ignoring it.</p>



<h2 class="wp-block-heading">When decisions move at machine speed</h2>



<p class="wp-block-paragraph">The ground under both roles is shifting. Work no longer flows through people alone. It moves across people, platforms, partners and agents at the same time, and it moves fast. Decisions that once waited for a meeting now form in seconds. The org chart, built for an era when humans did the work and reporting lines explained accountability, struggles to keep up.</p>



<p class="wp-block-paragraph">This is where the partnership stops being a nicety and becomes infrastructure. When decisions form at machine speed, the human escalation path has to be instant. There is no time to negotiate a relationship in the middle of an incident. Either the trust is already there, built in the quiet stretches before anything goes wrong, or it is not there when it counts.</p>



<p class="wp-block-paragraph">I asked Bill what he would lose if his daily calls with Ralph dropped to once a week. His answer cut straight to it.</p>



<p class="wp-block-paragraph">“Cyber does not rest,” he told me. “It is active and dynamic and requires 24/7/365 attention.” Drop to a weekly check-in, he explained, and “I am treating the CISO like any other executive position.” For Bill, AI only raises the stakes on that daily contact. “Relationships and partnerships between the CIO and CISO will never die due to AI,” he said. “I can’t even imagine a scenario where I don’t talk to my CISO on a daily basis including weekends to discuss the latest risks and vulnerabilities or news on potential AI attacks.”</p>



<p class="wp-block-paragraph">That is the point most of the market misses. A platform can flag the anomaly. It cannot decide what the organization is willing to risk, who carries that decision or how two leaders stand behind it together. The faster the machines move, the more the partnership has to already be in place.</p>



<h2 class="wp-block-heading">The loneliest seat in the building</h2>



<p class="wp-block-paragraph">There is a reason some now call the CISO job the least desirable role in business. The seat carries enormous accountability and rarely the authority to match. As one security leader put it, <a href="https://www.csoonline.com/article/4016334/has-ciso-become-the-least-desirable-role-in-business.html">the pressure has never been higher and the control has never felt lower</a>. People are burning out and walking away from a role that has never mattered more.</p>



<p class="wp-block-paragraph">Here is the hard part. There is no log file for burnout. No alert fires when the weight finally exceeds the leader. That drain is invisible right up until it is not, and it raises organizational risk as surely as any unpatched system. The structural fixes the industry debates are all real and all slow.</p>



<p class="wp-block-paragraph">The fastest source of relief available to a CISO is not a framework. It is a CIO who treats the relationship as a daily partnership rather than a line on a chart. An isolated CISO is a vulnerability. A partnered one is an asset.</p>



<p class="wp-block-paragraph">You see what that partnership is worth in the worst moment. I asked Bill what it looks like when an incident hits and public trust is on the line. He did not reach for a tool.</p>



<p class="wp-block-paragraph">“I am accountable as CIO to everything that occurs in the state from a technology lens including cyber,” he said. When a severe incident hits, the call comes to him from agency leadership or the Governor’s Office. Then he follows the plan, but never alone: “I will be in constant contact with the CISO on the details of the incident.”</p>



<p class="wp-block-paragraph">That is the safety net made real. The CISO is not carrying the mission alone at the moment it matters most. On the razor’s edge, leadership keeps you upright. Partnership keeps you in the fight.</p>



<h2 class="wp-block-heading">The work no tool will do for you</h2>



<p class="wp-block-paragraph">In my advisory work, I sit with C-suite leaders who share values and still cannot find alignment. The barrier is rarely disagreement. It is that they are not communicating clearly or often enough to build the trust that alignment requires. I have watched negotiations that could only happen by proxy, over email, because two capable leaders had stopped talking directly.</p>



<p class="wp-block-paragraph">I recently sat in an hour-long discussion where alignment and shared values were present the whole time. It did not become clear until the final fifteen minutes. That is what real alignment costs: patience, persistence and a stubborn commitment to clarity. If leaders cannot do that work themselves, no AI model or governance tool will do it for them.</p>



<p class="wp-block-paragraph">This is why I stand up an AI review board for the organizations I work with and host the leadership conversations that decide whether a company’s AI ambitions thrive or stall. The board itself matters less than what it provides: neutral ground, a regular cadence and an agenda that forces the hard issues into the open before a crisis forces them. If your organization has no venue like that, that absence is its own form of dysfunction. The cadence is what makes communication effective. Not easy. Effective.</p>



<h2 class="wp-block-heading">Build the bond on purpose</h2>



<p class="wp-block-paragraph">You cannot framework your way to trust. But you can build it deliberately, and that is a leadership act, not a governance one. The partnership and stakeholdering skills that once looked like soft extras are now the core executive work. A few moves matter most:</p>



<ul class="wp-block-list">
<li>Set a standing contact rhythm with your counterpart before you need one, daily or near-daily, not quarterly</li>



<li>Make decision rights and accountability explicit while it is calm, so no one improvises them mid-incident</li>



<li>Translate security into business outcomes together, so the board hears one aligned voice</li>
</ul>



<p class="wp-block-paragraph">Build the relationship as deliberately as you would build any critical control, because that is what it is. If you cannot connect the partnership to outcomes the business actually feels, you have a friendship, not a performance lever.</p>



<p class="wp-block-paragraph">A year after writing “The CISO On the Razor’s Edge,” I am even more convinced that strong leadership precedes effective governance and partnership precedes them both. This is the good news, not the hard news. The CIO and CISO who build real trust do not just reduce risk. They move faster than their competitors, because they spend no energy fighting each other. They earn the board’s confidence, because the board hears one clear voice. And they unlock the AI strategy everyone else is still struggling to govern, because they have already done the human work that makes governance hold.</p>



<p class="wp-block-paragraph">That is the upside waiting on the other side of this relationship. AI will keep advancing. Governance will keep maturing. But the organizations that win the next decade will be the ones where two leaders decided the partnership was worth building before they needed it. Bill and Ralph knew it every day, weekends included. The edge is there for anyone willing to do the same.</p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Fake TTF files deliver stealthy malware in global phishing campaign]]></title>
<description><![CDATA[Threat actors are now abusing an ordinary font file to deliver low-detection malware capable of stealing credentials and establishing persistence on compromised Windows systems.



According to a new research from Fortinet’s FortiGuard Labs, a global phishing campaign is actively using heavily ob...]]></description>
<link>https://tsecurity.de/de/3675510/it-security-nachrichten/fake-ttf-files-deliver-stealthy-malware-in-global-phishing-campaign/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675510/it-security-nachrichten/fake-ttf-files-deliver-stealthy-malware-in-global-phishing-campaign/</guid>
<pubDate>Fri, 17 Jul 2026 10:54:29 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Threat actors are now abusing an ordinary font file to deliver low-detection malware capable of stealing credentials and establishing persistence on compromised Windows systems.</p>



<p class="wp-block-paragraph">According to a new research from Fortinet’s FortiGuard Labs, a global phishing campaign is actively using heavily obfuscated JavaScript and a Lua-based loader posing as a TrueType Font (TTF) file to evade security and drop RATs and infostealers.</p>



<p class="wp-block-paragraph">A TTF file is a standard font file used by operating systems and applications to display text.</p>



<p class="wp-block-paragraph">The campaign has been deploying malware families such as <a href="https://www.csoonline.com/article/573813/malware-builder-uses-fresh-tactics-to-hit-victims-with-agent-tesla-rat.html">Agent Tesla</a>, Remcos, <a href="https://www.csoonline.com/article/4064720/xworm-campaign-shows-a-shift-toward-fileless-malware-and-in-memory-evasion-tactics.html">XWorm</a>, and a Snake Keylogger variant known as Best Private LOGGER, since at least late March 2026. “In these attacks, the threat actor impersonates several well-known companies, using the guise of business cooperation to launch phishing attacks,” FortiGuard researchers said in a blog <a href="https://www.fortinet.com/blog/threat-research/the-ttf-trap-a-global-campaign-of-a-low-detection-lua-loader" target="_blank" rel="noreferrer noopener">post</a>.</p>



<p class="wp-block-paragraph">Talking about how a new attack technique seems to still rely on conventional phishing tricks, <a href="https://www.linkedin.com/in/shane-barney-69026528/" target="_blank" rel="noreferrer noopener">Shane Barney</a>, CISO at Keeper Security, said, “The most sophisticated technical evasion in the world still starts the same way: someone opens an email from what looks like a trusted company and acts on it.”</p>



<p class="wp-block-paragraph">“The obfuscation layers, the Lua loader disguised as a font file, the fileless execution chain – all of it exists to survive detection after that human decision has already been made, and organizations would do well to keep that in their sightline,” he added.</p>



<h2 class="wp-block-heading">Business and payment-themed phishing lures used</h2>



<p class="wp-block-paragraph">According to the researchers, victims receive phishing emails impersonating well-known companies and using business collaboration or payment-related themes to trick recipients into opening compressed archives. These archives contain the obfuscated JScript that establishes persistence before dropping either a legitimate Autolt executable or a LuaJIT interpreter, along with a malicious script packaged within a .ttf extension.</p>



<p class="wp-block-paragraph">The fake font file functions as a Lua-based loader that runs multiple de-obfuscation steps before decrypting and executing shellcode directly in memory.</p>



<p class="wp-block-paragraph">“Security controls cannot treat a file extension as proof of file type or intent,” said <a href="https://www.linkedin.com/in/jason-soroko-19b41920/" target="_blank" rel="noreferrer noopener">Jason Soroko</a>, senior fellow at Sectigo. “Each component (of the campaign) may appear less suspicious when reviewed alone, while the combined sequence leads to in-memory execution of RATs and infostealers.”</p>



<p class="wp-block-paragraph">Some of the new variants, the researchers pointed out, are getting more sophisticated by introducing segmented shellcode encryption, Vectored Exception Handler (VEH)- based runtime decryption, AMSI and ETW bypasses, API unhooking, and other anti-analysis techniques designed to evade endpoint defenses.</p>



<p class="wp-block-paragraph">The final malware payload is delivered using <a href="https://www.csoonline.com/article/4125567/this-stealthy-windows-rat-holds-live-conversations-with-its-operators.html?utm=hybrid_search#:~:text=This%20PowerShell%20loader%20decodes%20and%20executes%20shellcode%20generated%20using%20Donut%2C%20an%20open-source%20framework%20commonly%20used%20to%20convert.%20NET%20assemblies%20into%20position-independent%20shellcode.">Donut</a> shellcode, allowing execution without writing the payload to disk.</p>



<p class="wp-block-paragraph">Protection requires targeted mitigations and routine security hygiene</p>



<p class="wp-block-paragraph">Fortinet’s findings confirm the attackers’ endgame to be stealing credentials and maintaining long-term access. The malware families observed, including Agent Tesla, Remcos, XWorm, and Best Private LOGGER, are all focused on credential theft, surveillance, or remote access.</p>



<p class="wp-block-paragraph">Barney said organizations should resist focusing exclusively on the loader’s technical sophistication and instead strengthen the systems attackers eventually want to compromise.</p>



<p class="wp-block-paragraph">In his opinion, identity and access controls are what it comes down to, as signature-based detection often fails against the loader sophistication of this grade. “Limiting what any given set of credentials can reach, enforcing least privilege, requiring re-authentication for sensitive systems, and monitoring for anomalous session behavior will not stop every phishing email from landing, but they significantly constrain what an attacker can accomplish after one succeeds,” he explained.</p>



<p class="wp-block-paragraph">Soroko, on the other hand, recommends focusing controls on the technical indicators. He urged organizations to restrict Windows Script Host, Autolt, and LauJIT wherever they are not operationally required, monitor for behaviors such as process injection, remote memory allocation, and shellcode execution, and use Fortinet’s published indicators for threat hunting.</p>



<p class="wp-block-paragraph">The indicators of compromise (IOCs) Fortinet shared include the command-and-control (C2) addresses, file hashes, and filenames.</p>



<p class="wp-block-paragraph">Soroko warned against relying solely on hashes or C2 infrastructure because the loader has changed over time. “The stronger approach is to detect the stable behavior across versions, then test controls against the complete chain,” he said.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Senior executives are killing your shadow AI strategy]]></title>
<description><![CDATA[Shadow IT has long been a major problem for CISOs, but the biggest problem may be coming from the executive suite’s hunger for unsanctioned AI.



Nearly two-thirds of senior decision-makers admit to using unapproved AI tools, compared to just 31% of lower-level employees, according to a survey b...]]></description>
<link>https://tsecurity.de/de/3675293/it-security-nachrichten/senior-executives-are-killing-your-shadow-ai-strategy/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675293/it-security-nachrichten/senior-executives-are-killing-your-shadow-ai-strategy/</guid>
<pubDate>Fri, 17 Jul 2026 09:09:11 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Shadow IT has long been a major problem for CISOs, but the biggest problem may be coming from the executive suite’s hunger for unsanctioned AI.</p>



<p class="wp-block-paragraph">Nearly two-thirds of senior decision-makers admit to using <a href="https://www.cio.com/article/4178359/why-your-most-ai-savvy-employees-are-driving-shadow-ai.html">unapproved AI tools</a>, compared to just 31% of lower-level employees, according <a href="https://www.trustedtechteam.com/pages/shadow-ai-whitepaper-download">to a survey</a> by Microsoft solutions partner TrustedTech.</p>



<p class="wp-block-paragraph">The use of <a href="https://www.cio.com/article/647725/it-leaders-grapple-with-shadow-ai.html">shadow AI</a> is prevalent among senior executives even though three in four employees acknowledge security or data privacy risks related to the practice.</p>



<p class="wp-block-paragraph">“Most shadow AI users are not ignorant of the risk,” TrustedTech says in a white paper. “They are deliberately choosing to use these tools anyway. This is not a training issue. It is a culture, incentives, and alternatives issue.”</p>



<p class="wp-block-paragraph">In many cases, the problem is driven by a lack of approved tools, the report adds.</p>



<p class="wp-block-paragraph">“People use shadow AI because what their employer hands them is worse than mainstream AI tools, or because nothing has been approved in the first place,” the report says. “That doesn’t change until the sanctioned tools are genuinely worth using.”</p>



<h2 class="wp-block-heading">A question of authority</h2>



<p class="wp-block-paragraph">The use of shadow AI by CEOs and other C-suite executives can create major problems for CISOs, CIOs, and other IT executives because they may not have the authority to put the kibosh on it.</p>



<p class="wp-block-paragraph">It also presents a challenge for IT leaders to provide the AI tools that employees and executives want to use.</p>



<p class="wp-block-paragraph">When executives use shadow AI, CISOs are in a difficult position, because governance only works when it’s modeled from the top, says<a href="https://www.linkedin.com/in/annolan/"> Andy Nolan,</a> VP of technology at TrustedTech.</p>



<p class="wp-block-paragraph">“If senior leaders bypass approved AI tools or policies, it sends an implied message that speed matters more than security and compliance,” he adds. “Employees notice that behavior, and it becomes much harder to ask the rest of the organization to follow standards that leadership isn’t following themselves, first.”</p>



<p class="wp-block-paragraph">Another major problem is that executives often work with highly sensitive information, including financial data, strategic plans, intellectual property, and customer information, he notes.</p>



<p class="wp-block-paragraph">But CISOs and CIOs also can’t solve the problem by becoming the AI police in every situation, Nolan says, because their role is to help the business innovate safely.</p>



<p class="wp-block-paragraph">“That requires executive alignment, clear governance, and providing secure AI tools that people actually want to use,” he adds. “When leadership embraces those solutions, the rest of the organization is almost sure to follow.”</p>



<h2 class="wp-block-heading">All risk, no reward</h2>



<p class="wp-block-paragraph">The use of shadow AI by senior executives puts CISOs and CIOs in an impossible position, agrees <a href="https://www.linkedin.com/in/amit-maloo-b087291/">Amit Maloo</a>, CISO at AI procurement provider Ivalua. CISOs and CIOs are <a href="https://www.cio.com/article/4182288/cios-are-being-held-accountable-for-ai-they-dont-fully-control-ibm-study-finds.html?utm=hybrid_search">held accountable</a> for the risk exposure but have no visibility into the problem, he says.</p>



<p class="wp-block-paragraph">“When senior leaders use ungoverned AI tools for business decisions, those decisions still have consequences, such as financial commitments, contract reviews, and data sharing,” he adds. “But there is no audit trail, no permissions model, or no way to reconstruct what happened or why.”</p>



<p class="wp-block-paragraph">Part of the problem is that approved AI options often don’t meet the needs of users, Maloo says.</p>



<p class="wp-block-paragraph">“AI policies alone aren’t enough; organizations need to pair governance with usability,” he adds. “If approved AI tools don’t meet the pace of business, employees at every level, including leadership, will find their own solutions. Successful organizations will be those that make the secure path the easiest path.”</p>



<p class="wp-block-paragraph">IT leaders can’t solve the problem with more governance, he notes. “Policies and restrictions slow shadow AI down, but they don’t stop it, especially when the people using it are senior enough to absorb the disciplinary risk,” Maloo adds. “What CIOs can do is focus on providing tools that grant users full access to the necessary systems and data, eliminating the need to choose between a capable but ungoverned tool and a safe but limited one.”</p>



<h2 class="wp-block-heading">Speed over security</h2>



<p class="wp-block-paragraph">The TrustedTech data echoes a <a href="https://www.teramind.co/l/shadow-ai-report-2026/">June report</a> from employee monitoring software vendor Teramind, which found that more than two-thirds of C-level executives prioritize speed over security when using AI tools, notes <a href="https://www.linkedin.com/in/nikkale/">Nik Kale</a>, a principal engineer and product architect at Cisco, and member of the Coalition for Secure AI.</p>



<p class="wp-block-paragraph">In addition, the Teramind report found that two-thirds of enterprise AI activity runs through personal accounts on platforms for which the company already owns licenses, he notes.</p>



<p class="wp-block-paragraph">“People are paying for the governed version and using the ungoverned version of the same product, so the problem isn’t the tools,” he says. “The approved path is slower, buried in procurement, or disconnected from where the work actually happens, and speed wins every time under a deadline.”</p>



<p class="wp-block-paragraph">The problem then isn’t with the AI tools, but with the friction involved, he says. “People aren’t going around the front door because the room is locked,” Kale adds. “They’re going around it because the front door is slower.”</p>



<p class="wp-block-paragraph">In many cases, the use of shadow AI exposes a couple of shortcomings in enterprise processes, adds <a href="https://www.linkedin.com/in/matt-scavetta-018b10173/">Matthew Scavetta</a>, chief technology innovation officer at IT solutions provider Future Tech Enterprise.</p>



<p class="wp-block-paragraph">Many organizations don’t do a good job of making employees aware of the AI tools available to them, he says, and many organizations don’t offer training on the sanctioned applications, which drives users to pick products they are familiar with.</p>



<p class="wp-block-paragraph">“If you don’t solve problems for people quickly or make people aware of which tools they can use safely, they will find a workaround,” he adds. “AI tools are no different than anything else.”</p>



<p class="wp-block-paragraph">Shadow AI use by executives puts IT leaders in an incredibly difficult position, he says.</p>



<p class="wp-block-paragraph">“CIOs, in particular, are under more and more pressure each year to keep up with what’s possible as tech influencers keep preaching about the potential of these tools,” Scavetta says. “CEOs and board members are constantly getting swept up in the hype; meanwhile, there are more and more case studies coming out showing how little ROI some organizations have realized. It’s a never-ending game of balancing possible with practical.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Zoom patches account takeover hole]]></title>
<description><![CDATA[Zoom has identified, and patched, a critical security hole that “may allow an unauthenticated user to conduct an account takeover via network access.”



The issue is especially significant given Zoom’s extensive reach; it reportedly has more than 300 million daily active users, including 470,000...]]></description>
<link>https://tsecurity.de/de/3674321/it-security-nachrichten/zoom-patches-account-takeover-hole/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3674321/it-security-nachrichten/zoom-patches-account-takeover-hole/</guid>
<pubDate>Thu, 16 Jul 2026 19:53:24 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Zoom has identified, and patched, a critical security hole that “may allow an unauthenticated user to conduct an account takeover via network access.”</p>



<p class="wp-block-paragraph">The issue is especially significant given Zoom’s extensive reach; it <a href="https://www.demandsage.com/zoom-statistics/" target="_blank" rel="noreferrer noopener">reportedly</a> has more than 300 million daily active users, including 470,000 paying business customers. Given that reach, Zoom has been impacted by <a href="https://www.csoonline.com/article/4136834/fake-zoom-meeting-silently-installs-surveillance-software-says-malwarebytes.html" target="_blank">many other security incidents</a> and France recently <a href="https://www.computerworld.com/article/4122979/french-authorities-ban-teams-and-zoom.html" target="_blank">tried banning its use by French government users</a>. </p>



<p class="wp-block-paragraph"><a href="https://www.zoom.com/en/trust/security-bulletin/" target="_blank" rel="noreferrer noopener"> Zoom security bulletins</a> released Tuesday revealed the bug, and three other security issues, which Zoom patched on Wednesday. </p>



<p class="wp-block-paragraph">The company originally said that the takeover issue impacted Zoom Desktop Client for Windows before version 7.0.0, Zoom VDI Client for Windows before version 7.0.10 and 6.6.15 and 6.5.18 in their respective branches, and Zoom Meeting SDK for Windows, but on Wednesday, without explanation, it removed Meeting SDK for Windows as an affected product.</p>



<p class="wp-block-paragraph">The other three holes were less severe, but still significant, and they all involved privilege escalation. They impacted Zoom Workplace for Windows before version 7.0.5, Zoom Workplace VDI Client for Windows before 6.5.17 and 6.6.14 in their respective branches, Zoom Workplace VDI plugin for Windows before 6.5.17 and 6.6.14 in their respective branches, Zoom Rooms for Windows before 7.0.5 and Remote Control for Zoom Contact Center for Windows before version 7.0.0. </p>



<p class="wp-block-paragraph">A second privilege escalation issue impacted Zoom Rooms for Windows before version 7.1.0, and another impacted Zoom Workplace VDI Plugin for Windows before version 6.6.14.</p>



<p class="wp-block-paragraph">Zoom did not immediately reply to a request for comment.</p>



<h2 class="wp-block-heading">‘As bad as it gets’</h2>



<p class="wp-block-paragraph"><a href="https://my.idc.com/getdoc.jsp?containerId=PRF004767" target="_blank" rel="noreferrer noopener">Frank Dickson</a>, group VP for security at IDC, said the nature of the reported hole is alarming.</p>



<p class="wp-block-paragraph">This bug “is about as bad as it gets, short of a worm. It is exploitable over the network, low complexity, zero privileges required, no user interaction needed,” he said, pointing out that exploitation is easy once technical details leak or someone reverse-engineers the patch, which is not as challenging as it once was, thanks to AI. “Yesterday’s script kiddies have been empowered,” he said.</p>



<p class="wp-block-paragraph">Dickson said the only good news is that Zoom discovered the hole itself, and that “no in-the-wild exploitation has been reported by any outlet as of Thursday.”</p>



<p class="wp-block-paragraph">Consultant <a href="https://formergov.com/directory/brianlevine" target="_blank" rel="noreferrer noopener">Brian Levine</a>, executive director of FormerGov, agreed with Dickson’s characterization of the hole, but said a potentially bigger issue is the high level of sensitive data that Zoom accesses. </p>



<p class="wp-block-paragraph">“An attacker with unfettered access to a Zoom account may be able to listen to recordings of sensitive meetings, to eavesdrop on future meetings, and to impersonate the organization in an effort to social engineer its clients and partners. Thus, given that ubiquity of Zoom in large enterprises, this vulnerability is pretty concerning,” Levine said. </p>



<p class="wp-block-paragraph">He’s encouraged, however, that Zoom found the flaw itself, which indicates its security team is “actually doing the hard, unglamorous work of auditing its code.”</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/trottagiuseppe/" target="_blank" rel="noreferrer noopener">Giuseppe Trotta</a>, principal security researcher at Malwarebytes, has a theory about what was behind the Zoom disclosure. </p>



<p class="wp-block-paragraph">“Because the vulnerability requires zero privileges and absolutely no user interaction, the remote network attack vector is highly suspected to involve the mishandling of deep links, such as custom URL schemes like <em>zoommtg://</em> or <em>zoomworkplace://</em>,” he said. This led him to think that if the Zoom Workplace client for Windows fails to properly sanitize and validate incoming arguments passed via these special browser-to-desktop links, an unauthenticated attacker could craft a malicious string that could trick the desktop application into exposing or redirecting the user’s active session tokens directly to an attacker-controlled server, achieving a seamless and completely silent account takeover.</p>



<p class="wp-block-paragraph">“Watch out for Zoom links and invites if you are on Windows or VDI and haven’t updated yet,” he advised.</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/eclectiqus/" target="_blank" rel="noreferrer noopener">Mike Wilkes</a>, enterprise CISO at Aikido Security, offered kudos to Zoom for discovering the critical flaw, but he wanted to know how such a severe bug got into its software initially.</p>



<p class="wp-block-paragraph">“This vulnerability raises questions about why the defect was not caught by design review, fuzzing, or pre-release abuse-case testing,” Wilkes said. “A historical defect in Zoom’s product/security relationship has been prioritizing ease of use over security risk.”</p>



<h2 class="wp-block-heading">All four bugs important</h2>



<p class="wp-block-paragraph"><a href="https://acceligence.com/talent/profiles/justin-greis/" target="_blank" rel="noreferrer noopener">Justin Greis</a>, CEO of consulting firm Acceligence, said that the two types of holes reported by Zoom, account takeover and escalation, are both important, but for different reasons. </p>



<p class="wp-block-paragraph">“The critical vulnerability is significant because it has the characteristics security teams worry about most,” Greis said, but the privilege escalation holes “are certainly important to patch as they primarily increase the impact of an attack that has already begun. The critical vulnerability has the potential to be an initial entry point, which is why it deserves the most attention.”</p>



<p class="wp-block-paragraph">Greis also applauded Zoom’s response, saying that it “reflects a reasonably mature security program.”</p>



<p class="wp-block-paragraph">He pointed out that no complex software platform will eliminate vulnerabilities entirely. “The differentiator is whether vendors are continuously investing in offensive testing, finding weaknesses before attackers do, and moving quickly to develop and distribute fixes,” he said.</p>



<p class="wp-block-paragraph"><em>This article originally appeared on <a href="https://www.computerworld.com/article/4197949/zoom-patches-account-takeover-hole.html" target="_blank">Computerworld</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Zoom patches account takeover hole]]></title>
<description><![CDATA[Zoom has identified, and patched, a critical security hole that “may allow an unauthenticated user to conduct an account takeover via network access.”



The issue is especially significant given Zoom’s extensive reach; it reportedly has more than 300 million daily active users, including 470,000...]]></description>
<link>https://tsecurity.de/de/3674314/it-nachrichten/zoom-patches-account-takeover-hole/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3674314/it-nachrichten/zoom-patches-account-takeover-hole/</guid>
<pubDate>Thu, 16 Jul 2026 19:47:37 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Zoom has identified, and patched, a critical security hole that “may allow an unauthenticated user to conduct an account takeover via network access.”</p>



<p class="wp-block-paragraph">The issue is especially significant given Zoom’s extensive reach; it <a href="https://www.demandsage.com/zoom-statistics/" target="_blank" rel="noreferrer noopener">reportedly</a> has more than 300 million daily active users, including 470,000 paying business customers. Given that reach, Zoom has been impacted by <a href="https://www.csoonline.com/article/4136834/fake-zoom-meeting-silently-installs-surveillance-software-says-malwarebytes.html" target="_blank">many other security incidents</a> and France recently <a href="https://www.computerworld.com/article/4122979/french-authorities-ban-teams-and-zoom.html" target="_blank">tried banning its use by French government users</a>. </p>



<p class="wp-block-paragraph"><a href="https://www.zoom.com/en/trust/security-bulletin/" target="_blank" rel="noreferrer noopener"> Zoom security bulletins</a> released Tuesday revealed the bug, and three other security issues, which Zoom patched on Wednesday. </p>



<p class="wp-block-paragraph">The company originally said that the takeover issue impacted Zoom Desktop Client for Windows before version 7.0.0, Zoom VDI Client for Windows before version 7.0.10 and 6.6.15 and 6.5.18 in their respective branches, and Zoom Meeting SDK for Windows, but on Wednesday, without explanation, it removed Meeting SDK for Windows as an affected product.</p>



<p class="wp-block-paragraph">The other three holes were less severe, but still significant, and they all involved privilege escalation. They impacted Zoom Workplace for Windows before version 7.0.5, Zoom Workplace VDI Client for Windows before 6.5.17 and 6.6.14 in their respective branches, Zoom Workplace VDI plugin for Windows before 6.5.17 and 6.6.14 in their respective branches, Zoom Rooms for Windows before 7.0.5 and Remote Control for Zoom Contact Center for Windows before version 7.0.0. </p>



<p class="wp-block-paragraph">A second privilege escalation issue impacted Zoom Rooms for Windows before version 7.1.0, and another impacted Zoom Workplace VDI Plugin for Windows before version 6.6.14.</p>



<p class="wp-block-paragraph">Zoom did not immediately reply to a request for comment.</p>



<h2 class="wp-block-heading">‘As bad as it gets’</h2>



<p class="wp-block-paragraph"><a href="https://my.idc.com/getdoc.jsp?containerId=PRF004767" target="_blank" rel="noreferrer noopener">Frank Dickson</a>, group VP for security at IDC, said the nature of the reported hole is alarming.</p>



<p class="wp-block-paragraph">This bug “is about as bad as it gets, short of a worm. It is exploitable over the network, low complexity, zero privileges required, no user interaction needed,” he said, pointing out that exploitation is easy once technical details leak or someone reverse-engineers the patch, which is not as challenging as it once was, thanks to AI. “Yesterday’s script kiddies have been empowered,” he said.</p>



<p class="wp-block-paragraph">Dickson said the only good news is that Zoom discovered the hole itself, and that “no in-the-wild exploitation has been reported by any outlet as of Thursday.”</p>



<p class="wp-block-paragraph">Consultant <a href="https://formergov.com/directory/brianlevine" target="_blank" rel="noreferrer noopener">Brian Levine</a>, executive director of FormerGov, agreed with Dickson’s characterization of the hole, but said a potentially bigger issue is the high level of sensitive data that Zoom accesses. </p>



<p class="wp-block-paragraph">“An attacker with unfettered access to a Zoom account may be able to listen to recordings of sensitive meetings, to eavesdrop on future meetings, and to impersonate the organization in an effort to social engineer its clients and partners. Thus, given that ubiquity of Zoom in large enterprises, this vulnerability is pretty concerning,” Levine said. </p>



<p class="wp-block-paragraph">He’s encouraged, however, that Zoom found the flaw itself, which indicates its security team is “actually doing the hard, unglamorous work of auditing its code.”</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/trottagiuseppe/" target="_blank" rel="noreferrer noopener">Giuseppe Trotta</a>, principal security researcher at Malwarebytes, has a theory about what was behind the Zoom disclosure. </p>



<p class="wp-block-paragraph">“Because the vulnerability requires zero privileges and absolutely no user interaction, the remote network attack vector is highly suspected to involve the mishandling of deep links, such as custom URL schemes like <em>zoommtg://</em> or <em>zoomworkplace://</em>,” he said. This led him to think that if the Zoom Workplace client for Windows fails to properly sanitize and validate incoming arguments passed via these special browser-to-desktop links, an unauthenticated attacker could craft a malicious string that could trick the desktop application into exposing or redirecting the user’s active session tokens directly to an attacker-controlled server, achieving a seamless and completely silent account takeover.</p>



<p class="wp-block-paragraph">“Watch out for Zoom links and invites if you are on Windows or VDI and haven’t updated yet,” he advised.</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/eclectiqus/" target="_blank" rel="noreferrer noopener">Mike Wilkes</a>, enterprise CISO at Aikido Security, offered kudos to Zoom for discovering the critical flaw, but he wanted to know how such a severe bug got into its software initially.</p>



<p class="wp-block-paragraph">“This vulnerability raises questions about why the defect was not caught by design review, fuzzing, or pre-release abuse-case testing,” Wilkes said. “A historical defect in Zoom’s product/security relationship has been prioritizing ease of use over security risk.”</p>



<h2 class="wp-block-heading">All four bugs important</h2>



<p class="wp-block-paragraph"><a href="https://acceligence.com/talent/profiles/justin-greis/" target="_blank" rel="noreferrer noopener">Justin Greis</a>, CEO of consulting firm Acceligence, said that the two types of holes reported by Zoom, account takeover and escalation, are both important, but for different reasons. </p>



<p class="wp-block-paragraph">“The critical vulnerability is significant because it has the characteristics security teams worry about most,” Greis said, but the privilege escalation holes “are certainly important to patch as they primarily increase the impact of an attack that has already begun. The critical vulnerability has the potential to be an initial entry point, which is why it deserves the most attention.”</p>



<p class="wp-block-paragraph">Greis also applauded Zoom’s response, saying that it “reflects a reasonably mature security program.”</p>



<p class="wp-block-paragraph">He pointed out that no complex software platform will eliminate vulnerabilities entirely. “The differentiator is whether vendors are continuously investing in offensive testing, finding weaknesses before attackers do, and moving quickly to develop and distribute fixes,” he said.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Bis Ende 2026: Deutscher Online-Identitätsdienstleister stellt Betrieb ein - Golem.de]]></title>
<description><![CDATA[... IT-Administrator & IT-Sicherheitsbeauftragter (m/w/d) Linux, Private ... Security Officer / CISO (m/w/x) BOGE KOMPRESSOREN Otto Boge GmbH ...]]></description>
<link>https://tsecurity.de/de/3674010/it-security-nachrichten/bis-ende-2026-deutscher-online-identitaetsdienstleister-stellt-betrieb-ein-golemde/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3674010/it-security-nachrichten/bis-ende-2026-deutscher-online-identitaetsdienstleister-stellt-betrieb-ein-golemde/</guid>
<pubDate>Thu, 16 Jul 2026 17:39:33 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[... <b>IT</b>-Administrator &amp; <b>IT</b>-Sicherheitsbeauftragter (m/w/d) Linux, Private ... <b>Security</b> Officer / CISO (m/w/x) BOGE KOMPRESSOREN Otto Boge GmbH ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Cloud-E-Mail-Sicherheit: KnowBe4 zeigt Maßnahmen zum Schutz vor Phishing und ...]]></title>
<description><![CDATA[Erich Kron, CISO-Advisor bei KnowBe4 erklärt die Cybersicherheitsmaßnahmen. Cloud-E-Mails bilden heute den Dreh- und Angelpunkt der ...]]></description>
<link>https://tsecurity.de/de/3673566/it-security-nachrichten/cloud-e-mail-sicherheit-knowbe4-zeigt-massnahmen-zum-schutz-vor-phishing-und/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3673566/it-security-nachrichten/cloud-e-mail-sicherheit-knowbe4-zeigt-massnahmen-zum-schutz-vor-phishing-und/</guid>
<pubDate>Thu, 16 Jul 2026 15:09:58 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Erich Kron, CISO-Advisor bei KnowBe4 erklärt die Cybersicherheitsmaßnahmen. Cloud-E-Mails bilden heute den Dreh- und Angelpunkt der ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Polizei greift durch: Großer Betrugsring mit über 700 Mitarbeitern zerschlagen - Golem.de]]></title>
<description><![CDATA[IT-Administrator & IT-Sicherheitsbeauftragter (m/w/d) Linux, Private ... Chief Information Security Officer / CISO (m/w/x) BOGE KOMPRESSOREN ...]]></description>
<link>https://tsecurity.de/de/3673562/it-security-nachrichten/polizei-greift-durch-grosser-betrugsring-mit-ueber-700-mitarbeitern-zerschlagen-golemde/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3673562/it-security-nachrichten/polizei-greift-durch-grosser-betrugsring-mit-ueber-700-mitarbeitern-zerschlagen-golemde/</guid>
<pubDate>Thu, 16 Jul 2026 15:09:53 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<b>IT</b>-Administrator &amp; <b>IT</b>-Sicherheitsbeauftragter (m/w/d) Linux, Private ... Chief Information <b>Security</b> Officer / CISO (m/w/x) BOGE KOMPRESSOREN ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Iran-Konflikt: Telekommunikationsdaten zeigen Handyortung von US-Soldaten - Golem.de]]></title>
<description><![CDATA[Chief Information Security Officer / CISO (m/w/x) BOGE KOMPRESSOREN ... IT-Sicherheitsmanager*in Deutsche Rentenversicherung Bund, Würzburg ...]]></description>
<link>https://tsecurity.de/de/3673561/it-security-nachrichten/iran-konflikt-telekommunikationsdaten-zeigen-handyortung-von-us-soldaten-golemde/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3673561/it-security-nachrichten/iran-konflikt-telekommunikationsdaten-zeigen-handyortung-von-us-soldaten-golemde/</guid>
<pubDate>Thu, 16 Jul 2026 15:09:51 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Chief Information <b>Security</b> Officer / CISO (m/w/x) BOGE KOMPRESSOREN ... <b>IT</b>-Sicherheitsmanager*in Deutsche Rentenversicherung Bund, Würzburg ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Towards a new leadership narrative for the modern CISO]]></title>
<description><![CDATA[Cybersecurity Isn’t Underfunded — It’s Undermanaged   Quote a lot of the narrative I come across online around cybersecurity budgets revolve around convincing the Board…]]></description>
<link>https://tsecurity.de/de/3673424/it-security-nachrichten/towards-a-new-leadership-narrative-for-the-modern-ciso/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3673424/it-security-nachrichten/towards-a-new-leadership-narrative-for-the-modern-ciso/</guid>
<pubDate>Thu, 16 Jul 2026 14:24:35 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Cybersecurity Isn’t Underfunded — It’s Undermanaged   Quote a lot of the narrative I come across online around cybersecurity budgets revolve around convincing the Board…]]></content:encoded>
</item>
<item>
<title><![CDATA[Companies keep getting breached by vulnerabilities they already knew about]]></title>
<description><![CDATA[Scanning tools have gotten good at their work. Organizations now find more weaknesses across more of their systems than at any earlier point in the industry’s history. A survey from the security firm Vicarius points to a gap that opens after that discovery, in the work of assigning, approving, de...]]></description>
<link>https://tsecurity.de/de/3672343/it-security-nachrichten/companies-keep-getting-breached-by-vulnerabilities-they-already-knew-about/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3672343/it-security-nachrichten/companies-keep-getting-breached-by-vulnerabilities-they-already-knew-about/</guid>
<pubDate>Thu, 16 Jul 2026 06:37:16 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Scanning tools have gotten good at their work. Organizations now find more weaknesses across more of their systems than at any earlier point in the industry’s history. A survey from the security firm Vicarius points to a gap that opens after that discovery, in the work of assigning, approving, deploying, and confirming a fix. The company surveyed 300 IT and cybersecurity leaders in the United States and the United Kingdom, at organizations with 500 to … <a href="https://www.helpnetsecurity.com/2026/07/16/ciso-vulnerability-remediation-gap/" rel="nofollow">More <span class="meta-nav">→</span></a></p>
<p>The post <a href="https://www.helpnetsecurity.com/2026/07/16/ciso-vulnerability-remediation-gap/">Companies keep getting breached by vulnerabilities they already knew about</a> appeared first on <a href="https://www.helpnetsecurity.com/">Help Net Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Detection Engineering erklärt]]></title>
<description><![CDATA[Detection Engineering ist für viele Unternehmen inzwischen gesetzt. Lesen Sie, warum.Gorodenkoff | shutterstock.com



Detection Engineering war einst ein Nischenbereich, der vor allem für Großunternehmen relevant war. Inzwischen wird die Methodologie allerdings in diversen Branchen als unverzich...]]></description>
<link>https://tsecurity.de/de/3672306/it-security-nachrichten/detection-engineering-erklaert/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3672306/it-security-nachrichten/detection-engineering-erklaert/</guid>
<pubDate>Thu, 16 Jul 2026 06:06:50 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/Gorodenkoff_shutterstock_1968876034_16z9.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Security Engineer 16z9" class="wp-image-4193743" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption">Detection Engineering ist für viele Unternehmen inzwischen gesetzt. Lesen Sie, warum.</figcaption></figure><p class="imageCredit">Gorodenkoff | shutterstock.com</p></div>



<p class="wp-block-paragraph">Detection Engineering war einst ein Nischenbereich, der vor allem für Großunternehmen relevant war. Inzwischen wird die Methodologie allerdings in diversen Branchen als unverzichtbar für den Security-Betrieb angesehen.</p>



<p class="wp-block-paragraph">In diesem Beitrag erfahren Sie:</p>



<ul class="wp-block-list">
<li>was Detection Engineering ist,</li>



<li>wie es sich von Threat Detection unterscheidet,</li>



<li>welche Aspekte die Adoption treiben,</li>



<li>welche Voraussetzungen dabei erfüllt sein sollten, und</li>



<li>welche Rolle KI und Automatisierung dabei spielen können.</li>
</ul>



<h2 class="wp-block-heading">Was ist Detection Engineering?</h2>



<p class="wp-block-paragraph">Beim Detection Engineering geht es darum, Systeme zu entwickeln und zu implementieren, mit denen <a href="https://www.computerwoche.de/article/4152424/insider-threats-sind-wieder-im-kommen.html" target="_blank">potenzielle Sicherheitsbedrohungen</a> innerhalb der spezifischen Technologieumgebung eines Unternehmens identifiziert werden können – ohne dabei in einer Flut von Fehlalarmen unterzugehen. Dazu werden intelligente Regeln erstellt, um potenziell verdächtige oder schadhafte Vorgänge in den Netzwerken oder Systemen eines Unternehmens zu identifizieren und entsprechend aussagekräftige Warnmeldungen darüber zu generieren.</p>



<p class="wp-block-paragraph">Der Detection-Engineering-Prozess umfasst in der Regel:</p>



<ul class="wp-block-list">
<li>Bedrohungen zu modellieren,</li>



<li>die <a href="https://csrc.nist.gov/glossary/term/tactics_techniques_and_procedures" target="_blank" rel="noreferrer noopener">TTPs</a> der Angreifer zu analysieren,</li>



<li>Detection-Regeln zu schreiben, zu testen und zu validieren, sowie</li>



<li>sich an <a href="https://www.computerwoche.de/article/4155663/6-wege-uber-ki-gehackt-zu-werden.html" target="_blank">neue Bedrohungen</a> oder Angriffstechniken anzupassen.</li>
</ul>



<p class="wp-block-paragraph">Laut dem vom SANS Institute und Anvilogic veröffentlichten „<a href="https://www.anvilogic.com/report/state-of-detection-engineering" target="_blank" rel="noreferrer noopener">State of Detection Engineering Report 2026</a>“ (Download gegen Daten) investieren <strong>80 Prozent</strong> der befragten Organisationen (und 85 Prozent der Großunternehmen) inzwischen aktiv in Detection Engineering. Von diesen verfügen mittlerweile <strong>60 Prozent</strong> über eigene, dedizierte Teams in diesem Bereich. Und: <strong>67 Prozent</strong> der Befragten geben an, dass Detection Engineering ausgeprägten Support durch das Management genießt.</p>



<p class="wp-block-paragraph">Die Ergebnisse des Reports deuten darauf hin, dass viele Unternehmen Detection-Engineering-Praktiken nicht nur eingeführt, sondern zu einem strategischen Fokuspunkt ihrer Cybersecurity-Bemühungen gemacht haben. Oder, wie die Studienautoren es ausdrücken: „Noch vor einem Jahrzehnt war Detection Engineering relativ unbekannt. Heute ist es essenziell für die Security Operations.“</p>



<p class="wp-block-paragraph">Der Report beschreibt zudem, wie sich die Detection-Engineering-Praktiken im Laufe der letzten Jahre weiterentwickelt haben. Waren diese zunächst übermäßig abhängig von herstellerspezifischen Konsolen und proprietären Sprachen, hielten dann nach und nach Softwareentwicklungsprinzipien wie <a href="https://www.computerwoche.de/article/2812485/was-ist-ci-cd.html" target="_blank">CI/CD</a> Einzug.</p>



<h2 class="wp-block-heading">Detection Engineering vs. Threat Detection</h2>



<p class="wp-block-paragraph">Laut den Verfechtern des Ansatzes unterscheidet sich Detection Engineering wesentlich von herkömmlicher <a href="https://www.computerwoche.de/article/3605017/das-gehort-in-ihr-security-toolset.html" target="_blank">Threat Detection</a> – mit Blick auf Ansatz, Methodik und die Integration in den Development Lifecycle:</p>



<ul class="wp-block-list">
<li>So sind <strong>traditionelle Threat-Detection-Prozesse</strong> in der Regel <strong>reaktiv</strong> und stützen sich auf <strong>vordefinierte Regeln</strong> und <strong>Anbietersignaturen</strong> – die Anpassungsmöglichkeiten für die Anwender sind <strong>limitiert</strong>.</li>



<li>Im Gegensatz dazu kommen beim <strong>Detection Engineering</strong> Prinzipien der Softwareentwicklung zum Einsatz, um eine <strong>benutzerdefinierte Detection-Logik</strong> für eine <strong>spezifische Unternehmensumgebung und ihre Bedrohungslandschaft</strong> zu erstellen und zu pflegen. Das Ziel besteht darin, maßgeschneiderte Mechanismen zu entwickeln, um unternehmensspezifische Bedrohungen erkennen zu können.</li>
</ul>



<p class="wp-block-paragraph">Deshalb geht Detection Engineering oft mit einem stärkeren Fokus auf verhaltensbasierte Erkennungsmethoden einher, wie <a href="https://www.linkedin.com/in/heath-renfrow-245187124" target="_blank" rel="noreferrer noopener">Heath Renfrow</a>, CISO und Mitbegründer des Cyber-Recovery-Anbieters Fenix24, erklärt: „Detection Engineering ist verhaltensgesteuert, kontextsensitiv und auf die einzigartige Bedrohungslandschaft eines einzelnen Unternehmens zugeschnitten. Es ist ein Mix aus Security Operations, Threat Intelligence und Data Science.“</p>



<h2 class="wp-block-heading">Warum Detection Engineering eingeführt wird</h2>



<p class="wp-block-paragraph">Die Einführung von Detection Engineering wird von einer ganzen Reihe von Faktoren vorangetrieben. Der wichtigste ist die Tatsache, dass Standard-Detection-Mechanismen nicht ausreichen: „Diese erfassen keine Baseline für die Umgebung, reduzieren die Anzahl der Fehlalarme nicht und – was besonders beunruhigend ist – warnen nicht immer vor den wirklich wichtigen Ereignissen“, konstatiert <a href="https://www.linkedin.com/in/johnathonmiller" target="_blank" rel="noreferrer noopener">Johnathon Miller</a>, Vice President of Security Operations beim Plattformanbieter Lumifi Cyber.</p>



<p class="wp-block-paragraph">Generische Warnmeldungen, die den organisatorischen Kontext nicht berücksichtigen, haben sich vielerorts zum Problem entwickelt und fördern die „False Positive Fatigue“ – wie auch die vorab zitierte Studie belegt:</p>



<ul class="wp-block-list">
<li><strong>64 Prozent</strong> der Befragten geben an, unter hohen Fehlalarmraten zu leiden,</li>



<li><strong>61 Prozent</strong> haben mit unpräzisen Detection-Mechanismen zu kämpfen, und</li>



<li><strong>34 Prozent</strong> berichten von zeitlich verzögerten Updates und Optimierungen.</li>
</ul>



<p class="wp-block-paragraph">„Herkömmliche Methoden zur Bedrohungserkennung waren in der Vergangenheit statisch: Wenn a gleich a ist, wird eine Warnmeldung ausgelöst“, erklärt <a href="https://www.linkedin.com/in/kevin-gonzalez-kgo" target="_blank" rel="noreferrer noopener">Kevin Gonzalez</a>, Vice President of Security, Operations and Data bei Anvilogic. Laut dem Experten handle es sich oft um starre Black-Box-Mechanismen, denen es an Flexibilität bei der Anpassung mangele. Diese Ansätze seien laut Gonzalez zwar bis zu einem gewissen Grad nützlich, würden im Zuge einer Skalierung aber unüberschaubar – insbesondere bei hybriden Umgebungen.</p>



<p class="wp-block-paragraph">Ein weiteres Problem ist das wachsende Ausmaß und die zunehmende Raffinesse der Sicherheitsbedrohungen. Angreifer setzen immer ausgefeiltere und schwerer zu erkennende Techniken ein – darunter <a href="https://www.computerwoche.de/article/2765164/wie-hacker-unbemerkt-ihre-systeme-infiltrieren.html" target="_blank">Fileless Malware</a>, <a href="https://www.computerwoche.de/article/2803863/was-ist-ein-zero-day-exploit.html" target="_blank">Zero-Day-Exploits</a> sowie „Living off the Land“- und <a href="https://www.computerwoche.de/article/3851627/10-praventivmasnahmen-gegen-supply-chain-angriffe.html" target="_blank">Supply-Chain-Attacken</a>. Die zunehmende Nutzung der Cloud hat darüber hinaus neue Schwachstellen eröffnet und blinde Flecken geschaffen, die mit herkömmlichen Detection-Methoden oft nur schwer abzudecken sind.</p>



<p class="wp-block-paragraph">„Unternehmen erkennen mittlerweile, dass proaktive Erkennungstechniken die Verweildauer der Angreifer verkürzen, die Reaktionsfähigkeit verbessern und die allgemeine Cyberresilienz stärken. Zudem legen Compliance-Frameworks und auch <a href="https://www.computerwoche.de/article/4164765/cyberversicherer-wollen-nicht-mehr-fur-ki-fehler-zahlen.html" target="_blank">Cyberversicherer</a> zunehmend gesteigerten Wert auf robuste Detection-Strategien“, meint Sicherheitsentscheider Renfrow.</p>



<h2 class="wp-block-heading">Detection Engineering – die Voraussetzungen</h2>



<p class="wp-block-paragraph">Zu den Unternehmen, die auf Detection Engineering setzen, zählen Firmen aus dem Bankensektor, der Tech- und Cybersecurity-Branche sowie dem Healthcare-Bereich. Also hauptsächlich Branchen, die strengen regulatorischen Anforderungen unterliegen oder regelmäßig zum Ziel raffinierter Angreifer werden.  </p>



<p class="wp-block-paragraph">Tatsächlich können jedoch die meisten Unternehmen mit einer komplexen IT-Infrastruktur von Detection Engineering profitieren – zum Beispiel auch mit Blick auf Security Operations Center (SOCs), wie <a href="https://il.linkedin.com/in/michaelmumcuoglu" target="_blank" rel="noreferrer noopener">Michael Mumcuoglu</a>, CEO beim Detection-Engineering-Anbieter CardinalOps, erklärt: „Nicht nur die Bedrohungslandschaft verändert sich, sondern auch die eigene interne IT-Infrastruktur. Das kann zu Abweichungen bei der Detection führen, so dass die Regeln nicht mehr eingehalten und somit auch keine Warnmeldungen mehr ausgelöst werden.“</p>



<p class="wp-block-paragraph">Als zentrale Voraussetzungen für den Aufbau von Detection-Engineering-Fähigkeiten gelten unter Sicherheitsexperten:</p>



<ul class="wp-block-list">
<li><strong>Daten: </strong>Detection-Engineering-Teams benötigen Zugriff auf Protokolle und Security-Event-Daten von Endgeräten, Netzwerken, Cloud-Umgebungen und Sicherheits-Tools sowie auf eine zentralisierte <a href="https://www.computerwoche.de/article/3835828/siem-kaufratgeber.html" target="_blank">SIEM</a>– oder Log-Management-Plattform, um diese zu aggregieren und zu normalisieren.</li>



<li><strong>Qualifiziertes Personal: </strong>Detection Engineers, Security-Analysten und Threat Researcher sind nötig, um Detection-Regeln zu entwickeln und zu verfeinern.</li>



<li><strong>Formalisierte Prozesse: </strong>Diese sind essenziell, um Bedrohungen zu modellieren, zu testen und Threat-Daten in die Incident Response zu integrieren.</li>
</ul>



<p class="wp-block-paragraph">CISO Renfrow empfiehlt Detection-Engineering-Interessierten zudem, Frameworks wie <a href="https://attack.mitre.org/" target="_blank" rel="noreferrer noopener">MITRE ATT&amp;CK</a> zu nutzen, um sicherzustellen, dass bekannte Adversary-Techniken abgedeckt werden. Zusätzlich rät der Sicherheitsentscheider Anwenderunternehmen dazu, Adversary-Emulation-Tools einzusetzen, um die Effektivität ihrer Bemühungen zu validieren.</p>



<h2 class="wp-block-heading">Automatisiertes Detection Engineering</h2>



<p class="wp-block-paragraph">Bei der Optimierung und Automatisierung von Detection-Regeln können auch künstliche Intelligenz (KI) und Machine Learning (ML) unterstützen, wie ein weiterer Blick auf den Report von SANS und Anvilogic deutlich macht. Demnach:</p>



<ul class="wp-block-list">
<li>setzen <strong>45 Prozent</strong> der Studienteilnehmer in ihren Detection-Engineering-Programmen KI ein, um Anomalien zu erkennen sowie Regeln zu generieren und Warnmeldungen zu triagieren.</li>



<li>sind <strong>88 Prozent</strong> davon überzeugt, dass KI in den nächsten drei Jahren erheblichen Einfluss auf ihre Detection-Engineering-Programme haben wird.</li>



<li>nutzen <strong>93 Prozent</strong> der Befragten aktuell eine Form der Automatisierung in ihrem Detection-Engineering-Workflow ein – oder planen damit.</li>
</ul>



<p class="wp-block-paragraph">„Einer der stärksten Anwendungsfälle für KI ist es, riesige Datenmengen zu analysieren, um Anomalien zu identifizieren. Insbesondere, wenn es um KI-Modelle geht, die auf benutzerdefinierten Datensätzen trainiert wurden“, meint auch <a href="https://www.linkedin.com/in/glennthorpeiii" target="_blank" rel="noreferrer noopener">Glenn Thorpe</a>, Senior Director of Security Research and Detection Engineering beim Plattformanbieter GreyNoise Intelligence.</p>



<p class="wp-block-paragraph">Geht es darum, Detection-Engineering-Prozesse zu automatisieren, nehmen Anwender vor allem drei Bereiche in den Fokus. Sie:</p>



<ul class="wp-block-list">
<li>mappen ihre Detection-Abdeckung mit dem MITRE-ATT&amp;CK-Framework,</li>



<li>identifizieren fehlerhafte oder falsch konfigurierte Detection-Regeln, und</li>



<li>operationalisieren Threat-Informationen in umsetzbare Erkennungsregeln.</li>
</ul>



<p class="wp-block-paragraph">Security-Experte Thorpe warnt Unternehmen allerdings davor, nach einer Einheitslösung zu suchen, um Detection-Engineering-Kapazitäten aufzubauen: „Um ein effektives Team in diesem Bereich aufzubauen, sind vor allem eine kreative, vielschichtige Denkweise und Neugierde gefragt.“</p>



<p class="wp-block-paragraph">Ein guter Ausgangspunkt wäre laut dem Manager, die Kerndaten des eigenen Unternehmens zu identifizieren und Menschen zu finden, die diese aus unterschiedlichen Perspektiven analysieren können: „Verschaffen Sie sich ein realistisches Bild davon, was Sie nicht wissen – und schließen sie dann diese Informationslücken. Dabei werden Sie wahrscheinlich feststellen, dass schon kleinere Veränderungen mehr Transparenz schaffen und es erleichtern, den Netzwerk-Traffic zu verstehen.“ (fm)</p>



<p class="wp-block-paragraph"><strong>Dieser Artikel ist <a href="https://www.csoonline.com/article/3847510/rising-attack-exposure-threat-sophistication-spur-interest-in-detection-engineering.html" target="_blank">im Original</a> bei unserer Schwesterpublikation CSOonline.com erschienen.</strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Agentic orchestration: Enterprise AI organizations have a deployment problem, not a platform problem — and most are calling chatbots agents]]></title>
<description><![CDATA[Across 101 enterprises, agent orchestration is consolidating onto model-provider platforms — Anthropic’s Claude leads by a wide margin — chosen for the gravity of the underlying model and judged on reliable multi-step execution. But the ambition runs well ahead of the reality: most deployed “agen...]]></description>
<link>https://tsecurity.de/de/3672033/it-nachrichten/agentic-orchestration-enterprise-ai-organizations-have-a-deployment-problem-not-a-platform-problem-and-most-are-calling-chatbots-agents/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3672033/it-nachrichten/agentic-orchestration-enterprise-ai-organizations-have-a-deployment-problem-not-a-platform-problem-and-most-are-calling-chatbots-agents/</guid>
<pubDate>Thu, 16 Jul 2026 00:46:36 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Across 101 enterprises, agent orchestration is consolidating onto model-provider platforms — Anthropic’s Claude leads by a wide margin — chosen for the gravity of the underlying model and judged on reliable multi-step execution. But the ambition runs well ahead of the reality: most deployed “agents” are still chatbot wrappers, the control plane enterprises expect is deliberately hybrid to avoid lock-in, and real-time fiscal control over token burn remains the exception.</p><p>This wave of VentureBeat Pulse Research examines enterprise agent orchestration: which platforms enterprises run on, what drives the choice, what they optimize for, how they expect agent control to be structured, and — most revealingly — how orchestrated their deployed “agents” actually are and how tightly they control the cost of running them.</p><p>The central finding is a gap between orchestration ambition and orchestration reality. Enterprises are consolidating fast onto the major model platforms: Anthropic’s Claude is the primary platform for 40%, more than double any rival, followed by Microsoft (18%) and OpenAI (13%). The choice is driven by “model gravity” — native alignment with a state-of-the-art base model (21%) — and success is judged by reliable, multi-step execution (task completion reliability 32%, multi-step workflow management 28%). Yet asked to assess their portfolios honestly, 71% say a quarter or fewer of their deployed “agents” are true multi-step orchestrated workflows rather than single-prompt chatbot wrappers, and only 10% have crossed the halfway mark. The orchestration layer is being built well ahead of the orchestrated portfolio it is meant to run.</p><p>That gap shapes the architecture enterprises are putting in place. By the end of 2026 a clear majority (51%) expect a hybrid control plane — provider-native plus external orchestration — and only 6% expect to hand control to a provider-managed service, because vendor lock-in (35%) is the risk they fear most if control lives inside a model provider. Investment follows the build-out: agent workflow tooling leads the spend (34%), with security and permissions enforcement (25%) behind. And fiscal control lags throughout — more than a quarter (27%) have no real-time way to stop a runaway agent before the bill arrives.</p><h2>Methodology</h2><p>VentureBeat fielded this survey as part of its ongoing Pulse Research series, this instrument focused on enterprise agent orchestration. Responses are filtered to organizations with 100 or more employees (n=101), drawn from a single June 2026 wave; because this is one wave rather than a pooled multi-month sample, the report reads cross-sectionally and does not infer month-over-month trends.</p><p>By organization size the sample is spread evenly across the enterprise bands: 100–499 employees, 2,500–9,999, and 50,000+ (21% each), with 10,000–49,999 and 500–2,499 (19% each). By role it is senior and buyer-credible: product and program managers (15%), CIO/CTO/CISO (13%), consultants and advisors (13%), and a spread of data, AI, and engineering directors and VPs, with an “Other” function at 18%. On purchasing, 81% are recommenders, influencers, or final decision-makers for AI solutions (66% recommender/influencer, 15% final decision-maker). Technology/Software is the largest industry at 44%, followed by Financial Services (17%) and Healthcare/Life Sciences (8%).</p><p>At 101 respondents the sample is robust enough to read directionally with reasonable confidence, though it remains self-selected and is not a probability sample.</p><h2>Finding 1: Orchestration runs on model-provider platforms</h2><p><b>Anthropic’s Claude leads; open frameworks are marginal</b></p><p>We asked which agent orchestration platform enterprises primarily use today. The answer concentrates on the major model providers — and on one in particular.</p><div></div><p>A note on reading these shares. As described in the methodology section, the respondents are self-selected, and this question asked them for a single primary platform — so the figures measure which platform leads each enterprise's deployment, within a self-selected audience of AI-active technical decision-makers. A sample built this way can diverge substantially from spend-weighted market measures, and each VB Pulse survey draws its own sample with its own company-size mix, so vendor figures should not be compared across our surveys either. Read these shares as a portrait of where this cohort has placed its primary orchestration bet today, rather than as market share.</p><p>The model platforms dominate. Anthropic, Microsoft, OpenAI, Google, and Amazon together account for roughly 80% of deployments (81 of 101), while the open frameworks (LangChain/LangGraph) and custom in-house builds that anchor engineering discussion sit in single digits. Anthropic’s lead — 40%, more than double the next platform — mirrors the “model gravity” selection logic in Finding 2: enterprises are choosing the orchestration layer that comes with the model they want to build on. As with the security vendors in the prior agent-security wave, the tools that define the category in technical circles are not yet where enterprise deployment concentrates. A small 3% are not orchestrating at all.</p><p>Respondents rate the platforms they run at 3.94 out of 5 overall (109 answered), with “value for money” specifically at 3.94 and “ease of implementation” the weakest score, at 3.85 — placing orchestration near the bottom of our five-tracker satisfaction range, ahead of only evaluation tooling. A rating just under 4 out of 5, from users of whom 96% plan to change their orchestration approach within the year, reads as provisional acceptance: the platforms work well enough to run today, and not well enough to stop the search for something better. The ratings sit alongside near-universal intent to change; this is a layer enterprises tolerate more than they love.</p><h2>Finding 2: Model gravity drives platform selection</h2><p><b>The base model, not the tooling, decides the platform</b></p><p>We asked what most influenced the orchestration platform choice. The single largest factor is the pull of the underlying model — though flexibility and ease of development follow close behind.</p><div></div><p>Model gravity leading is the selection-side explanation for Anthropic’s platform lead: enterprises pick the orchestration environment closest to the frontier model they have standardized on. But the next tier complicates the picture — flexibility across models and tools (17%) and ease of development (17%) say enterprises also want to avoid being trapped by that choice, foreshadowing the lock-in fear in Finding 6. Security and permissions (14%) and total cost of ownership (11%) round out a pragmatic buying logic. Performance (latency/memory) sits last at 4%, a reminder that at this stage of adoption the binding constraints are model fit and optionality, not raw speed.</p><h2>Finding 3: The job is reliable multi-step execution</h2><p><b>Enterprises just orchestration by whether it completes the work</b></p><p>We asked what enterprises optimize for — their primary success metric for orchestration. Reliability and multi-step workflow management dominate; developer- and user-facing metrics trail.</p><div></div><p>Task completion reliability (32%) and multi-step workflow management (28%) together account for 59% of responses (60 of 101): orchestration succeeds, in the enterprise view, when it reliably carries a task through multiple steps to completion. Developer productivity (17%) matters but is secondary — the inverse of its prominence in framework discussion — and end-user experience (9%) is a minor concern, consistent with orchestration being an internal execution problem rather than a UX one. This reliability-first standard is exactly what makes the Chatbot Trap finding so pointed: enterprises define success as dependable multi-step execution, yet most of their deployed “agents” do not yet do multi-step work at all.</p><p>The trap is not evenly distributed. Splitting the sample by organization size, 77% of smaller enterprises say a quarter or fewer of their agents do true multi-step work, against 62% of larger ones. Larger enterprises are meaningfully further into genuine multi-step deployment; the chatbot trap is, directionally, a mid-market condition.</p><h2>Finding 4: Consolidate, productionize, and build in-house </h2><p><b>Three strategic moves are nearly tied for the year ahead</b></p><p>We asked what major change enterprises anticipate in their orchestration strategy over the next 12 months. Three moves cluster at the top, almost evenly split.</p><div></div><p>The top three — building in-house control (25%), standardizing on one framework (24%), and moving agents from sandbox to production (23%) — are statistically indistinguishable and tell a single story: enterprises are moving from experimentation to operational consolidation. They want fewer frameworks, more production exposure, and more ownership of the control layer; only 4% expect no change. The appetite for custom in-house control planes is notable alongside the platform concentration in Finding 1 — enterprises are standardizing on model-provider platforms while simultaneously planning to wrap them in control logic they own, the hybrid posture that Finding 6 makes explicit.</p><h2>Finding 5: Investment flows to workflow tooling</h2><p><b>Tooling and permissions lead the spend; monitoring trails</b></p><p>We asked which orchestration-related investment will grow most next year. Agent workflow tooling leads, with security and permissions enforcement behind.</p><div></div><p>Workflow tooling leading (34%) is the budget-side expression of the reliability-and-multi-step priority in Finding 3: the money is going to the machinery that strings steps together dependably. Security and permissions enforcement (25%) and scaling infrastructure (20%) follow — the investments required to take agents from sandbox into production, the strategic move in Finding 4. Monitoring and debugging draws a smaller 11%, with another 11% reporting flat budgets. The weight on tooling, permissions, and scaling over pure observability signals that enterprises are spending to build and harden orchestration, not merely to watch it run.</p><h2>Finding 6: The control plane will be hybrid — and lock-in is why</h2><p><b>Enterprises expect to split control between providers and their own layer</b></p><p>We asked where enterprises expect the primary control plane for agents to live by the end of 2026, and what worries them most if that control sits inside a model-provider platform. A clear majority expect a hybrid model — and vendor lock-in is the reason.</p><div></div><p>Hybrid control is the dominant expectation by a wide margin (51%), and only 6% expect to hand control to a provider-managed service outright. Read together, the hybrid, custom, and externally-abstracted options — every architecture that keeps control at least partly outside the provider — sum to 88% (89 of 101). The reason surfaces directly when we asked about the risk of provider-resident control: vendor lock-in leads at 35% (35 of 101), ahead of security and permissioning limitations (28%) and inflexibility across models and tools (21%). The pattern echoes the prior wave’s “don’t trust the model to police itself” posture — here, enterprises will build on a provider’s platform but decline to be governed entirely by it. The hybrid control plane is the architectural hedge against the lock-in they most fear.</p><p>The June figure asserting a preference for a hybrid control plane marks movement from earlier. In the April–May survey (n=145), only 34% expected a hybrid control plane, and a greater number (12%) expected to hand control fully to a provider-managed service. These two snapshots don’t yet measure a confirmed longitudinal trend — but the direction of the conversation is unambiguous: toward keeping control.</p><p>Lock-in is also a new arrival as a top concern. In the April–May wave, the leading concern was security and permissioning limitations (32%), with lock-in second at 24%; by June the two had traded places. The worry about provider platforms appears to be maturing from whether they can be secured to whether they can be replaced.</p><h2>Finding 7: The chatbot trap — most “agents” aren’t agents yet</h2><p><b>Enterprises admit most deployments are still chatbot wrappers</b></p><p>We asked enterprises to assess their portfolios honestly: what share of their deployed “agents” are true multi-step orchestrated workflows versus simple single-prompt chatbot wrappers. The answer is the defining finding of this wave.</p><div></div><p>This is the gap at the center of the report. Combining the bottom two bands, 71% of enterprises (72 of 101) say a quarter or fewer of their deployed “agents” are genuinely orchestrated — and just 10% (10 of 101) have crossed the halfway mark. The ambition documented in the earlier findings — model-provider platforms, reliability-first success metrics, production rollouts, a deliberate control architecture — runs well ahead of the deployed reality, which remains overwhelmingly single-prompt assistants dressed as agents. This is less a contradiction than a roadmap: the platforms, budgets, and strategies are being put in place precisely because the orchestrated portfolio is still so thin. The open question for later waves is how fast the reality closes on the ambition.</p><h2>Finding 8: Fiscal control is still reactive</h2><p><b>Only a minority can stop a runaway agent before the bill arrives</b></p><p>Finally, we asked how enterprises enforce fiscal control over agent token consumption — the risk that an autonomous loop exhausts a budget before anyone intervenes. Most rely on native caps or after-the-fact monitoring; real-time programmatic control is the exception.</p><div></div><p>More than a quarter of enterprises (27%) admit they have no real-time, programmatic way to stop an agent before a budget-breaking bill arrives — they learn of it from the logs afterward. Another 32% lean entirely on the native caps and throttles built into their primary platform, a control only as good as the provider’s tooling and one that ties back to the lock-in concern of Finding 6. The enterprises building custom gateways (23%) or exploiting cross-model routing to arbitrage cost (19%) are the ones treating token burn as an engineering problem to be controlled deterministically. As with orchestration maturity, fiscal control is an area where the operational reality lags the ambition: agents are moving toward production faster than the cost-control plane around them is being built.</p><p>It’s worth noting, a split appears according to company size: roughly one in three enterprises under 2,500 employees (34%) exercises only reactive control of agent spend, against 20% of larger enterprises — directional figures, but consistent with the chatbot-trap split. The mid-market is running the least mature agents on the least instrumented budgets.</p><h2>The bottom line: The layer is real; most of the agents aren't yet</h2><p>Organizations with 100 or more employees describe an orchestration strategy that is consolidating quickly and maturing slowly. They are standardizing on model-provider platforms — Anthropic’s Claude leads at 40% — chosen for the gravity of the underlying model, and they judge success by reliable multi-step execution. Investment is flowing to workflow tooling and permissions, the strategy is to consolidate frameworks and push agents into production, and the control plane they expect is deliberately hybrid, because vendor lock-in is the risk they fear most.</p><p>But the honest self-assessment punctures the ambition. Seventy-one percent say a quarter or fewer of their deployed “agents” are truly orchestrated, only 10% are past the halfway mark, and more than a quarter cannot stop a runaway agent in real time. The orchestration layer — the platforms, the budgets, the control architecture — is being built ahead of the orchestrated portfolio it is meant to run. At 101 respondents in a single June wave this reads as a clear directional signal rather than a precise measurement: enterprises have decided how they want to orchestrate agents well before most of their agents are doing anything an orchestration layer is for. The question for subsequent waves is whether the deployed reality closes the gap on the ambition — or whether the chatbot trap proves stickier than the roadmap assumes.</p><hr><p><i>Based on survey responses from 101 qualified enterprise respondents (100+ employees), drawn from a single June 2026 wave. Because this is one wave rather than a pooled multi-month sample, results read directionally rather than as a confirmed trend. Respondents include product and program managers, CIOs, CTOs and CISOs, consultants and advisors, and directors and VPs of data, AI, and engineering, across Technology/Software, Financial Services, Healthcare, and other sectors.</i></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[News alert: Pulse Security launches with $8 million for AI platform to modernize CISO operations]]></title>
<description><![CDATA[SAN FRANCISCO, July 15, 2026, CyberNewswire – Backed by Foundation Capital and Zetta Venture Partners with $8M in seed funding, Pulse Security delivers the program intelligence and agentic infrastructure that security leaders have been missing.
Pulse Security AI launched from … (more…) 
The post ...]]></description>
<link>https://tsecurity.de/de/3671291/it-security-nachrichten/news-alert-pulse-security-launches-with-8-million-for-ai-platform-to-modernize-ciso-operations/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3671291/it-security-nachrichten/news-alert-pulse-security-launches-with-8-million-for-ai-platform-to-modernize-ciso-operations/</guid>
<pubDate>Wed, 15 Jul 2026 18:10:14 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>SAN FRANCISCO, July 15, 2026, CyberNewswire<strong> –</strong> Backed by Foundation Capital and Zetta Venture Partners with $8M in seed funding, Pulse Security delivers the program intelligence and agentic infrastructure that security leaders have been missing.</p>
<p><a href="https://www.lastwatchdog.com/wp/wp-content/uploads/pulse_security_ai_logo_stack_rgb_lightmode_black_t_1784060191DoBnutvtFo.jpg" rel="nofollow"><img fetchpriority="high" decoding="async" class="alignright size-medium wp-image-39682" src="https://www.lastwatchdog.com/wp/wp-content/uploads/pulse_security_ai_logo_stack_rgb_lightmode_black_t_1784060191DoBnutvtFo-520x325.jpg" alt="" width="520" height="325" srcset="https://www.lastwatchdog.com/wp/wp-content/uploads/pulse_security_ai_logo_stack_rgb_lightmode_black_t_1784060191DoBnutvtFo-520x325.jpg 520w, https://www.lastwatchdog.com/wp/wp-content/uploads/pulse_security_ai_logo_stack_rgb_lightmode_black_t_1784060191DoBnutvtFo-960x600.jpg 960w, https://www.lastwatchdog.com/wp/wp-content/uploads/pulse_security_ai_logo_stack_rgb_lightmode_black_t_1784060191DoBnutvtFo-100x63.jpg 100w, https://www.lastwatchdog.com/wp/wp-content/uploads/pulse_security_ai_logo_stack_rgb_lightmode_black_t_1784060191DoBnutvtFo-768x480.jpg 768w, https://www.lastwatchdog.com/wp/wp-content/uploads/pulse_security_ai_logo_stack_rgb_lightmode_black_t_1784060191DoBnutvtFo-1536x960.jpg 1536w, https://www.lastwatchdog.com/wp/wp-content/uploads/pulse_security_ai_logo_stack_rgb_lightmode_black_t_1784060191DoBnutvtFo.jpg 1843w" sizes="(max-width: 520px) 100vw, 520px"></a><a href="http://pulsesecurity.ai/" rel="nofollow">Pulse Security AI</a> launched from … <a href="https://www.lastwatchdog.com/news-alert-pulse-security-launches-with-8-million-for-ai-platform-to-modernize-ciso-operations/" class="read-more">(more…) </a></p>
<p>The post <a href="https://www.lastwatchdog.com/news-alert-pulse-security-launches-with-8-million-for-ai-platform-to-modernize-ciso-operations/">News alert: Pulse Security launches with $8 million for AI platform to modernize CISO operations</a> first appeared on <a href="https://www.lastwatchdog.com/">The Last Watchdog</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple’s OpenAI lawsuit: The lunacy of trying to limit what ex-employees can tell future employers]]></title>
<description><![CDATA[When Apple sued OpenAI last week, the argument it made was that former employees had stolen Apple data and then used it to benefit OpenAI. 



The technical details — an employee used “a rare, previously unknown authentication bug to access Apple’s shared network folders” — are interesting. But t...]]></description>
<link>https://tsecurity.de/de/3671252/it-nachrichten/apples-openai-lawsuit-the-lunacy-of-trying-to-limit-what-ex-employees-can-tell-future-employers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3671252/it-nachrichten/apples-openai-lawsuit-the-lunacy-of-trying-to-limit-what-ex-employees-can-tell-future-employers/</guid>
<pubDate>Wed, 15 Jul 2026 18:03:48 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">When <a href="https://www.computerworld.com/article/4195828/rotten-to-its-core-apple-files-an-explosive-lawsuit-against-openai.html">Apple sued OpenAI last week</a>, the argument it made was that former employees had stolen Apple data and then used it to benefit OpenAI. </p>



<p class="wp-block-paragraph">The technical details — an employee used “a rare, previously unknown authentication bug to access Apple’s shared network folders” — are interesting. But the larger story is Apple’s ridiculous attempt to stop its people from using anything they learned at Apple in other jobs.</p>



<p class="wp-block-paragraph">“Hiring managers don’t mind some files being brought into the org during onboarding, but suddenly take umbrage when that same employee exits with some files later on,” said <a href="https://www.linkedin.com/in/eclectiqus/" target="_blank" rel="noreferrer noopener">Mike Wilkes</a>, enterprise CISO at Aikido Security. “Legal should be equally concerned about both events.”</p>



<p class="wp-block-paragraph">The lawsuit focused on Chang Liu, an employee who had been recruited to work at OpenAI after working at Apple for eight years as a Senior System Electrical Engineer. The <a href="https://storage.courtlistener.com/recap/gov.uscourts.cand.474095/gov.uscourts.cand.474095.1.0.pdf">full text of the filing</a> depicts a comedy of errors by Apple, offering the perfect “do not do” list of handling employee resignations — especially when they’re going to a direct competitor. </p>



<p class="wp-block-paragraph">“When Apple contacted Mr. Liu to sign Apple’s confidentiality reminder, schedule an exit interview, and confirm that he had returned his devices and complied with other exit procedures, Mr. Liu did not respond.” And “after leaving Apple, Mr. Liu failed to return an Apple-issued work laptop that he had previously authenticated to Apple’s network.”</p>



<p class="wp-block-paragraph">First, typical procedure for handling departures is to tie the return of all equipment and the signing of documents to any final payments. With Apple, that is likely to be a large amount of money. The lawsuit does not say whether Apple exerted any financial pressure on their employee for compliance. </p>



<p class="wp-block-paragraph">But in terms of equipment with high-level access, why weren’t all privileges revoked, both for the employee and any and all company-issued devices? Did they not maintain a remote-wipe capability for these devices? Although remote-wipe is usually used when devices are missing or stolen, it should work as well when a departing employee refuses to return company equipment. </p>



<p class="wp-block-paragraph">According to Apple, Liu apparently had help at Apple from Tang Yew Tan, who was supposedly also interviewing with OpenAI. “While employed by OpenAI, [Liu] accessed and used his former colleague’s Apple-issued work computer that was authenticated to Apple’s network, without Apple’s authorization.”</p>



<p class="wp-block-paragraph">Apple tried to make much of this Liu’s fault. Legally, yes, there might be liability there; still, Apple made itself look as if it couldn’t protect its own data. “Upon discovering that he had this unauthorized access to Apple’s systems, [the former employee] did not report it, return his stolen Apple-issued work laptop or delete the program that allowed the access.” </p>



<p class="wp-block-paragraph">Really, Apple? Your data-protection plan relies on ex-employees to “delete the program that allowed the access”? I’m not so sure you didn’t bring some of this data-leakage on yourselves. </p>



<p class="wp-block-paragraph">This gets worse: “Over several weeks, while developing hardware for OpenAI, Mr. Liu surreptitiously accessed and downloaded dozens of Apple’s confidential hardware-related files, including voluminous, detailed information about unreleased products, engineering presentations, technical specifications, and proprietary project data.”</p>



<p class="wp-block-paragraph">Setting aside the issue of privileges, access, and unreturned equipment that apparently had its own privileges, that statement points to massive data exfiltration from Apple systems. Even if it is coming from a current employee, why didn’t that raise any red flags? </p>



<p class="wp-block-paragraph">Let’s get back to the broader implications. When professionals move from one company to another, they — of course — are bringing their experience and knowledge with them. Can Apple reasonably tell them that they can’t do so? Isn’t that experience and knowledge <em>exactly</em> why another company would want to hire them?</p>



<p class="wp-block-paragraph">Now, to be sure, stealing diagrams and product spec sheets is a clear violation. Let’s say Apple spent a lot of money on some hardware research projects. A member of that technical team would learn an awful lot, all on Apple’s dime. </p>



<p class="wp-block-paragraph">But is it fair and reasonable for Apple to say that the former employee can’t leverage that knowledge at his or her next job? </p>



<p class="wp-block-paragraph">This brings us back to the point Wilkes made: If Apple is going to try to prevent any former employee from leveraging on-the-job experience, then it should instruct all new employees not to use anything they learned in a previous job. </p>



<p class="wp-block-paragraph">That would be ridiculous. Companies pay for experienced talent because of that experience. Why pay for expertise if you insist employees not leverage any of it?</p>



<p class="wp-block-paragraph">Then there’s the amorphous nature of knowledge. So, it’s wrong to take detailed diagrams and spec details and hand them over to a new employer. But what if that worker heading out the door memorizes the documents (photographic memory) a day before resigning? Is a person prohibited from using something from memory?</p>



<p class="wp-block-paragraph">There’s also the fruit-of-the-poisonous tree legal argument. Even if a former employee doesn’t directly use stolen data, what if their knowledge leads to other money-saving insights for the new employer? </p>



<p class="wp-block-paragraph">Given that Apple hires as many specialists as it loses to rivals, wouldn’t it make sense to leverage everything your workforce knows and then let new employers do the same? But before you do that, Apple, tighten your exiting employee tech controls. </p>



<p class="wp-block-paragraph">Then maybe you wont’t have to file lawsuits like this down the road.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Iren stärkt Cyber-Sicherheit: Eric Hammersley wird CISO – IT-Risiken i - Goldesel]]></title>
<description><![CDATA[... Information Security Officer (CISO) ernannt. Die Personalentscheidung soll die IT- und Informationssicherheitsstrategie weiter professionalisieren ...]]></description>
<link>https://tsecurity.de/de/3671056/it-security-nachrichten/iren-staerkt-cyber-sicherheit-eric-hammersley-wird-ciso-it-risiken-i-goldesel/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3671056/it-security-nachrichten/iren-staerkt-cyber-sicherheit-eric-hammersley-wird-ciso-it-risiken-i-goldesel/</guid>
<pubDate>Wed, 15 Jul 2026 16:55:57 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[... Information <b>Security</b> Officer (CISO) ernannt. Die Personalentscheidung soll die <b>IT</b>- und Informationssicherheitsstrategie weiter professionalisieren ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Senior executives abuse shadow AI twice as much as regular employees do]]></title>
<description><![CDATA[Shadow IT has long been a major problem for IT leaders, but the biggest problem may be coming from the executive suite’s hunger for unsanctioned AI.



Nearly two-thirds of senior decision-makers admit to using unapproved AI tools, compared to just 31% of lower-level employees, according to a sur...]]></description>
<link>https://tsecurity.de/de/3670109/it-security-nachrichten/senior-executives-abuse-shadow-ai-twice-as-much-as-regular-employees-do/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3670109/it-security-nachrichten/senior-executives-abuse-shadow-ai-twice-as-much-as-regular-employees-do/</guid>
<pubDate>Wed, 15 Jul 2026 11:08:45 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Shadow IT has long been a major problem for IT leaders, but the biggest problem may be coming from the executive suite’s hunger for unsanctioned AI.</p>



<p class="wp-block-paragraph">Nearly two-thirds of senior decision-makers admit to using <a href="https://www.cio.com/article/4178359/why-your-most-ai-savvy-employees-are-driving-shadow-ai.html">unapproved AI tools</a>, compared to just 31% of lower-level employees, according <a href="https://www.trustedtechteam.com/pages/shadow-ai-whitepaper-download">to a survey</a> by Microsoft solutions partner TrustedTech.</p>



<p class="wp-block-paragraph">The use of <a href="https://www.cio.com/article/647725/it-leaders-grapple-with-shadow-ai.html">shadow AI</a> is prevalent among senior executives even though three in four employees acknowledge security or data privacy risks related to the practice.</p>



<p class="wp-block-paragraph">“Most shadow AI users are not ignorant of the risk,” TrustedTech says in a white paper. “They are deliberately choosing to use these tools anyway. This is not a training issue. It is a culture, incentives, and alternatives issue.”</p>



<p class="wp-block-paragraph">In many cases, the problem is driven by a lack of approved tools, the report adds.</p>



<p class="wp-block-paragraph">“People use shadow AI because what their employer hands them is worse than mainstream AI tools, or because nothing has been approved in the first place,” the report says. “That doesn’t change until the sanctioned tools are genuinely worth using.”</p>



<h2 class="wp-block-heading">A question of authority</h2>



<p class="wp-block-paragraph">The use of shadow AI by CEOs and other C-suite executives can create major problems for CIOs, CISOs, and other IT executives because they may not have the authority to put the kibosh on it.</p>



<p class="wp-block-paragraph">It also presents a challenge for IT leaders to provide the AI tools that employees and executives want to use.</p>



<p class="wp-block-paragraph">When executives use shadow AI, CIOs are in a difficult position, because governance only works when it’s modeled from the top, says<a href="https://www.linkedin.com/in/annolan/"> Andy Nolan,</a> VP of technology at TrustedTech.</p>



<p class="wp-block-paragraph">“If senior leaders bypass approved AI tools or policies, it sends an implied message that speed matters more than security and compliance,” he adds. “Employees notice that behavior, and it becomes much harder to ask the rest of the organization to follow standards that leadership isn’t following themselves, first.”</p>



<p class="wp-block-paragraph">Another major problem is that executives often work with highly sensitive information, including financial data, strategic plans, intellectual property, and customer information, he notes.</p>



<p class="wp-block-paragraph">But CIOs and CISOs also can’t solve the problem by becoming the AI police in every situation, Nolan says, because their role is to help the business innovate safely.</p>



<p class="wp-block-paragraph">“That requires executive alignment, clear governance, and providing secure AI tools that people actually want to use,” he adds. “When leadership embraces those solutions, the rest of the organization is almost sure to follow.”</p>



<h2 class="wp-block-heading">All risk, no reward</h2>



<p class="wp-block-paragraph">The use of shadow AI by senior executives puts CIOs and CISOs in an impossible position, agrees <a href="https://www.linkedin.com/in/amit-maloo-b087291/">Amit Maloo</a>, CISO at AI procurement provider Ivalua. CIOs and CISOs are <a href="https://www.cio.com/article/4182288/cios-are-being-held-accountable-for-ai-they-dont-fully-control-ibm-study-finds.html?utm=hybrid_search">held accountable</a> for the risk exposure but have no visibility into the problem, he says.</p>



<p class="wp-block-paragraph">“When senior leaders use ungoverned AI tools for business decisions, those decisions still have consequences, such as financial commitments, contract reviews, and data sharing,” he adds. “But there is no audit trail, no permissions model, or no way to reconstruct what happened or why.”</p>



<p class="wp-block-paragraph">Part of the problem is that approved AI options often don’t meet the needs of users, Maloo says.</p>



<p class="wp-block-paragraph">“AI policies alone aren’t enough; organizations need to pair governance with usability,” he adds. “If approved AI tools don’t meet the pace of business, employees at every level, including leadership, will find their own solutions. Successful organizations will be those that make the secure path the easiest path.”</p>



<p class="wp-block-paragraph">IT leaders can’t solve the problem with more governance, he notes. “Policies and restrictions slow shadow AI down, but they don’t stop it, especially when the people using it are senior enough to absorb the disciplinary risk,” Maloo adds. “What CIOs can do is focus on providing tools that grant users full access to the necessary systems and data, eliminating the need to choose between a capable but ungoverned tool and a safe but limited one.”</p>



<h2 class="wp-block-heading">Speed over security</h2>



<p class="wp-block-paragraph">The TrustedTech data echoes a <a href="https://www.teramind.co/l/shadow-ai-report-2026/">June report</a> from employee monitoring software vendor Teramind, which found that more than two-thirds of C-level executives prioritize speed over security when using AI tools, notes <a href="https://www.linkedin.com/in/nikkale/">Nik Kale</a>, a principal engineer and product architect at Cisco, and member of the Coalition for Secure AI.</p>



<p class="wp-block-paragraph">In addition, the Teramind report found that two-thirds of enterprise AI activity runs through personal accounts on platforms for which the company already owns licenses, he notes.</p>



<p class="wp-block-paragraph">“People are paying for the governed version and using the ungoverned version of the same product, so the problem isn’t the tools,” he says. “The approved path is slower, buried in procurement, or disconnected from where the work actually happens, and speed wins every time under a deadline.”</p>



<p class="wp-block-paragraph">The problem then isn’t with the AI tools, but with the friction involved, he says. “People aren’t going around the front door because the room is locked,” Kale adds. “They’re going around it because the front door is slower.”</p>



<p class="wp-block-paragraph">In many cases, the use of shadow AI exposes a couple of shortcomings in enterprise processes, adds <a href="https://www.linkedin.com/in/matt-scavetta-018b10173/">Matthew Scavetta</a>, chief technology innovation officer at IT solutions provider Future Tech Enterprise.</p>



<p class="wp-block-paragraph">Many organizations don’t do a good job of making employees aware of the AI tools available to them, he says, and many organizations don’t offer training on the sanctioned applications, which drives users to pick products they are familiar with.</p>



<p class="wp-block-paragraph">“If you don’t solve problems for people quickly or make people aware of which tools they can use safely, they will find a workaround,” he adds. “AI tools are no different than anything else.”</p>



<p class="wp-block-paragraph">Shadow AI use by executives puts IT leaders in an incredibly difficult position, he says.</p>



<p class="wp-block-paragraph">“CIOs, in particular, are under more and more pressure each year to keep up with what’s possible as tech influencers keep preaching about the potential of these tools,” Scavetta says. “CEOs and board members are constantly getting swept up in the hype; meanwhile, there are more and more case studies coming out showing how little ROI some organizations have realized. It’s a never-ending game of balancing possible with practical.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[7 skills and traits of elite security engineers]]></title>
<description><![CDATA[Security engineers play a pivotal role in enterprise cybersecurity, because they are the professionals who design, build, and deploy security systems to protect an organization’s data, applications, systems, networks, and other IT components against a variety of cyber threats.



Finding not just...]]></description>
<link>https://tsecurity.de/de/3669835/it-security-nachrichten/7-skills-and-traits-of-elite-security-engineers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3669835/it-security-nachrichten/7-skills-and-traits-of-elite-security-engineers/</guid>
<pubDate>Wed, 15 Jul 2026 09:08:41 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Security engineers play a pivotal role in enterprise cybersecurity, because they are the professionals who design, build, and deploy security systems to protect an organization’s data, applications, systems, networks, and other IT components against a variety of cyber threats.</p>



<p class="wp-block-paragraph">Finding not just qualified security engineers, but the best and brightest available, needs to be a priority for CISOs and others overseeing security at their organizations. That’s especially true with the rapid rise of AI and the threats that brings to the enterprise.</p>



<p class="wp-block-paragraph">Here are some of the key skills and traits of elite security engineers to look for when hiring — or to acquire in order to uplevel your cybersecurity career.</p>



<h2 class="wp-block-heading">Acumen with AI-powered tools</h2>



<p class="wp-block-paragraph">These days, AI-related skills are in demand regardless of domain, and this certainly applies to security engineers. There’s a wealth of solutions leveraging AI in the market, tools that engineers can add to their defense arsenal.</p>



<p class="wp-block-paragraph">“AI is transforming security engineering from reactive alerting to predictive threat detection,” says Praveen Margabandhu, digital engineering anchor at financial services firm Navy Federal Credit Union. “AI-driven anomaly detection now identifies behavioral patterns that indicate fraud or compromise before traditional threshold-based systems would fire. This shifts the security engineer’s role from incident responder to threat model designer.”</p>



<p class="wp-block-paragraph">AI-powered tools have taken over a large portion of the detection and triage work that used to be the core of a security engineer’s day, says Maruf Ahmed, cofounder and CEO of global tech staffing firm Dexian. “Vulnerability scanning runs on its own now,” he says. “Threat flagging that used to require a team pulling through logs for hours happens in minutes.”</p>



<p class="wp-block-paragraph">This has freed up capacity on most security teams and changed what the day-to-day work looks like, Ahmed says. “With detection increasingly automated, the engineer’s value sits more in interpreting what gets flagged and deciding what to do about it,” he says.</p>



<h2 class="wp-block-heading">Keen understanding of emerging and established AI threats</h2>



<p class="wp-block-paragraph">Engineers must also have a thorough understanding of the risks AI presents, including <strong><a href="https://www.csoonline.com/article/4154222/6-ways-attackers-abuse-ai-services-to-hack-your-business.html">AI-enhanced cyberattacks</a> using</strong><strong> </strong>large language models (LLMs) to automate and scale <a href="https://www.csoonline.com/article/3819176/top-5-ways-attackers-use-generative-ai-to-exploit-your-systems.html">highly personalized social engineering attacks</a>, craft sophisticated malware, and generate deepfakes.</p>



<p class="wp-block-paragraph">Other <a href="https://www.csoonline.com/article/4110008/top-cyber-threats-to-your-ai-systems-and-infrastructure.html">AI threats they need to be aware of</a> include prompt injections, data and model poisoning, disclosure of sensitive information, model theft, supply chain compromises, and excessive agency.</p>



<p class="wp-block-paragraph">“The same generative tools that help security teams work faster are available to adversaries, and it shows,” Ahmed says. “Phishing campaigns read better and land more precisely than they did a year ago. Social engineering is harder to catch when the language is polished and tailored to the target, and security engineers are now defending against threats built with the same class of technology they use on the defensive side.”</p>



<p class="wp-block-paragraph">That has raised the bar for what reliable detection looks like, Ahmed says. “The objective shift I hear most from clients is about trust in their own systems,” he says. “Two years ago, the priority was visibility — making sure you could see across your environment. Most organizations have that now. The harder problem is knowing whether what those tools are telling you holds up under scrutiny and having people on the team who can stand behind those findings in front of a regulator or a board.”</p>



<h2 class="wp-block-heading">Appreciation of performance and business goals</h2>



<p class="wp-block-paragraph">The best security engineers understand how performance and security intersect, says Margabandhu, who leads performance engineering across Navy Federal Credit Union’s digital banking infrastructure, including real-time fraud detection, identity and access management, and cybersecurity infrastructure resilience.</p>



<p class="wp-block-paragraph">“A fraud detection system that is secure but too slow to catch transactions in real-time is not secure at all,” Margabandhu says. “Elite engineers optimize for both simultaneously.”</p>



<p class="wp-block-paragraph">Engineers must be able to put things in business context, Ahmed says. “An engineer who can work across domains, validate AI outputs, and learn new tools fast is valuable. But that value compounds when the person also understands what the organization is trying to protect and why,” he says.</p>



<p class="wp-block-paragraph">Security engineers who understand the business make better risk decisions, write more effective policies, and generate less friction with the teams around them, Ahmed says. “That is the profile employers are hiring toward right now, and it is where the talent shortage is most pronounced,” he says.</p>



<h2 class="wp-block-heading">Systems mindset</h2>



<p class="wp-block-paragraph">“One of the biggest misconceptions in cybersecurity hiring is that elite security engineers are defined purely by technical certifications or tool familiarity,” says Juan Mathews Rebello Santos, an independent cybersecurity researcher and ethical hacker.</p>



<p class="wp-block-paragraph">“Technical skill absolutely matters, but the strongest engineers I’ve worked with consistently share a combination of analytical thinking, operational adaptability, communication ability, and deep systems understanding,” Santos says.</p>



<p class="wp-block-paragraph">Elite security engineers understand how infrastructure, cloud services, identity systems, applications, APIs, networks, users, and business operations connect, Santos says.</p>



<p class="wp-block-paragraph">“Modern attacks rarely target a single isolated component anymore,” he says. “Threat actors chain together weaknesses across environments. Engineers who can understand those relationships holistically are significantly more effective at both prevention and incident response.”</p>



<h2 class="wp-block-heading">Cross-disciplinary fluency and broad stack know-how</h2>



<p class="wp-block-paragraph">Being an elite software engineer today means having a range of technology experience and knowledge. “Organizations want engineers who can work across more of the stack than they used to,” Ahmed says. “A role that might have asked for deep specialization in one area now expects someone who can move between cloud infrastructure, application security, and compliance without needing a handoff at every boundary.”</p>



<p class="wp-block-paragraph">The attack surface has continued to get wider, and the job descriptions for security engineers has followed suit. “That cross-domain fluency matters because security incidents rarely stay contained in one layer,” Ahmed says. “The engineer who can follow a problem from the network through the application to the data governance framework resolves it faster, with fewer people involved.”</p>



<p class="wp-block-paragraph">The strongest security engineers bridge infrastructure, application, and business domains, Margabandhu says. “They can speak to a CISO, a developer, and a cloud architect in the same conversation,” he says. “An engineer who can explain what an authentication problem means for fraud exposure moves faster in a room full of executives than one who can only describe it in infrastructure terms. I’ve watched technically brilliant people lose that race repeatedly.”<br><br></p>



<p class="wp-block-paragraph">Having the ability to communicate technical risk clearly to non-technical leadership can mean the difference between success and failure of attacks.</p>



<p class="wp-block-paragraph">“Many security failures today are not caused by lack of tooling, but by misalignment between technical teams and business decision-makers,” Santos says. “Elite engineers can explain operational risk, prioritization, and security tradeoffs in language executives understand.”</p>



<h2 class="wp-block-heading">Deep understanding of third-party risk and non-human threats</h2>



<p class="wp-block-paragraph">Threats can come from anywhere, including supply chains and non-human combatants. Third-party cybersecurity risks are on the rise. The 2026 Global CISO Leadership Report by executive search firm Hitch Partners, based on a survey of more than 625 information security executives across the US and Canada, says 43% put third-party risks as the No. 1 priority.</p>



<p class="wp-block-paragraph">“Most teams are still better at securing what they own than securing what they depend on,” Margabandhu says. “The mental shift from perimeter thinking to dependency thinking is real and not everyone has made it. The engineers who treat <a href="https://www.csoonline.com/article/4148315/apis-are-the-new-perimeter-heres-how-cisos-are-securing-them.html">every API call</a>, every credentialed vendor, every third-party model as part of their attack surface approach design differently.”</p>



<p class="wp-block-paragraph">Another growing source of potential threats are not human. <a href="https://www.csoonline.com/article/2132294/what-are-non-human-identities-and-why-do-they-matter.html">Machine identities</a> now outnumber human identities by ratios exceeding 100 to 1 in most enterprise environments, with some sectors closer to 500 to 1, according to the ManageEngine Identity Security Outlook 2026 report.</p>



<p class="wp-block-paragraph">This includes service accounts, API keys, automation tokens, and AI agents, any one of which can present data governance and security risks.</p>



<p class="wp-block-paragraph">Many organizations are still managing machine identities through manual processes that weren’t designed for scale, Margabandhu says. “Engineers who understand non-human identity governance are rare and increasingly important. This is not a future problem.”<br><br></p>



<h2 class="wp-block-heading">Willingness to keep learning</h2>



<p class="wp-block-paragraph">Security engineers need to have a desire to never stopped learning.</p>



<p class="wp-block-paragraph">“That sounds obvious until you work with people who’ve been doing this for 15 years and are still operating from the same threat models they built in 2012,” Margabandhu says. “Security changes fast enough that standing still is the same as going backwards.”</p>



<p class="wp-block-paragraph">The security engineers who keep up aren’t reading one report a year. “They’re genuinely curious about what attackers are doing right now, this month, and they adjust how they think accordingly,” Margabandhu says. “That quality is harder to hire for than most technical skills, because it’s not on a resume.”<br><br></p>



<p class="wp-block-paragraph">With AI presenting new and more sophisticated threats, keeping up with the latest developments is perhaps more important than ever. “Strong engineers are naturally investigative,” Santos says. “They actively study attack techniques, test assumptions, reverse engineer failures, and continuously adapt their understanding of risk.”</p>



<p class="wp-block-paragraph">The best security engineers are often the people who remain intellectually uncomfortable because they know the landscape is always evolving, Santos says.</p>



<p class="wp-block-paragraph">Employers have started paying closer attention to how fast someone can learn, Ahmed says. “The threat landscape and the defensive toolkit are both moving faster than any certification program can track, so hiring managers are probing for adaptability in interviews: how candidates have responded to recent shifts, whether they have picked up unfamiliar platforms on their own, how they work through problems they have not seen before,” he says.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft is forcing an enterprise transition to passkeys]]></title>
<description><![CDATA[Passkeys have been around for some time, but enterprise-wide adoption to this point has been slow for a number of reasons. But soon, many Microsoft customers won’t have a choice.



Starting September 1, Microsoft will roll out passkeys as the default authentication method in its cloud-based iden...]]></description>
<link>https://tsecurity.de/de/3669425/it-nachrichten/microsoft-is-forcing-an-enterprise-transition-to-passkeys/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3669425/it-nachrichten/microsoft-is-forcing-an-enterprise-transition-to-passkeys/</guid>
<pubDate>Wed, 15 Jul 2026 04:32:40 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Passkeys have been around for some time, but enterprise-wide adoption to this point has been slow for a number of reasons. But soon, many Microsoft customers won’t have a choice.</p>



<p class="wp-block-paragraph">Starting September 1, Microsoft will roll out passkeys as the default authentication method in its cloud-based identity and access management (IAM) service Entra ID. And following a transition period, Microsoft-provided SMS and voice authentication will officially end on February 1, 2027.</p>



<p class="wp-block-paragraph">With this move, Microsoft seems to be underlining the urgent need for a more secure authentication standard, as attackers up their game with AI.</p>



<p class="wp-block-paragraph">This is an “important milestone,” because it moves passwordless authentication from an optional security enhancement to the expected standard, noted <a href="https://www.sans.org/profiles/ensar-seker" target="_blank" rel="noreferrer noopener">Ensar Seker</a>, CISO at SOCRadar. “That shift is significant as attackers increasingly rely on AI to automate phishing campaigns, generate convincing login pages, and conduct large-scale credential theft.”</p>



<h2 class="wp-block-heading">Microsoft’s six-month passkey roll-out</h2>



<p class="wp-block-paragraph"><a href="https://www.computerworld.com/article/4009132/passkeys-how-they-work-how-to-use-them.html" target="_blank">Passkeys</a> require users to authenticate via a fingerprint, facial scan, or lock screen mechanism, rather than a password. They can be stored on physical USB keys (like YubiKey), or as digital credentials on computers, phones, or in cloud accounts.</p>



<p class="wp-block-paragraph">This method, Microsoft contended, reduces reliance on phishable authentication tools like SMS and voice, and hardens protection against credential theft.</p>



<p class="wp-block-paragraph">Passkeys “work better for users and worse for cyberattackers,” <a href="https://www.linkedin.com/in/nadim-abdo/" target="_blank" rel="noreferrer noopener">Nadim Abdo</a>, Microsoft corporate VP for identity and network access engineering, wrote in a <a href="https://www.microsoft.com/en-us/security/blog/2026/07/13/microsoft-entra-id-security-updates-passkeys-are-the-default-authentication-method-in-entra-id/" target="_blank" rel="noreferrer noopener">blog post</a>.</p>



<p class="wp-block-paragraph">Microsoft’s announced timeline for rolling out passkeys is relatively aggressive:</p>



<ul class="wp-block-list">
<li><strong>September 1, 2026</strong>: All SMS or voice-enabled users will be “auto-enabled and nudged” to register a passkey upon multifactor authentication (MFA) sign-in.</li>



<li><strong>September 18, 2026</strong>: Pricing, commercial terms, and a list of supported telecom providers will be shared for scenarios that still require SMS or voice authentication due to regulation or technical or operational challenges.</li>



<li><strong>October 30, 2026</strong>: Enterprises still using SMS and voice must select and configure a supported telecom provider through the Microsoft Security Store. From then on, they will be responsible for any telecom-related costs.</li>



<li><strong>February 1, 2027</strong>: Microsoft-provided telecom delivery for SMS and voice authentication ends as a native Microsoft Entra capability.</li>
</ul>



<p class="wp-block-paragraph">After February 1, enterprises that require SMS or voice for MFA must register a passkey before sign-in. There will be no opt-out option.</p>



<p class="wp-block-paragraph">It’s important to note that these dates apply to public cloud-hosted Entra ID. Support for other cloud environments will follow a separate timeline; additional guidance and dates are to come.</p>



<p class="wp-block-paragraph">While SMS and voice have served their purpose well, Abdo said, bringing MFA to billions of users who otherwise would have had none, the threat environment has changed in “speed, scale, and sophistication,” necessitating this move to passkeys.</p>



<h2 class="wp-block-heading">The benefits of passkeys</h2>



<p class="wp-block-paragraph">SOCRadar’s Seker pointed out that passkeys fundamentally change the attack surface because, unlike with passwords, there is no transmission of shared secrets that can be stolen by threat actors. Authentication requires possession of the user’s device, along with biometric verification or a PIN.</p>



<p class="wp-block-paragraph">“Even highly convincing AI-generated phishing pages cannot simply trick users into handing over a passkey the way they can with passwords or one-time codes,” he said.</p>



<p class="wp-block-paragraph">So why haven’t we seen widespread enterprise adoption? Identity ecosystems are “fragmented,” Seker noted, and many enterprises still rely on legacy applications that only support passwords. They also struggle with cross-platform compatibility, lifecycle management, recovery processes, shared accounts, and employee onboarding and offboarding.</p>



<p class="wp-block-paragraph">Further, “until recently, many organizations viewed passkeys as a consumer technology rather than an enterprise identity strategy,” he said.</p>



<p class="wp-block-paragraph">Microsoft’s move changes that equation, because Entra sits at the center of many organizations’ identity infrastructure, Seker noted. Default settings are typically the strongest drivers of security adoption, so when passwordless authentication becomes required rather than optional, organizations are far more likely to deploy it at scale.</p>



<p class="wp-block-paragraph">Its biggest benefit would be a “dramatic reduction” in credential-based attacks, Seker said. He pointed out that most successful compromises still begin with stolen credentials obtained through phishing, infostealer malware, password reuse, or adversary-in-the-middle attacks. Passkeys “eliminate or significantly reduce” many of those attack paths, while reducing password fatigue and the help desk costs related to password resets.</p>



<p class="wp-block-paragraph">In addition, rather than trying to continuously improve users’ ability to detect increasingly sophisticated phishing attempts, passkeys remove the credential from the equation altogether, Seker noted. “That represents a more sustainable long-term security strategy than relying solely on user awareness training.”</p>



<p class="wp-block-paragraph">Still, passkeys are not a silver bullet, as they do not stop endpoint compromise, session token theft, malicious insiders, or attackers who already have control of a trusted device. Enterprises must complement passkeys with endpoint protection, continuous monitoring, conditional access policies, and identity threat detection, Seker advised.</p>



<h2 class="wp-block-heading">How enterprises can prepare</h2>



<p class="wp-block-paragraph">To prepare for the shift to passkeys, Microsoft advised enterprises to review their authentication policy and identify the groups still using SMS or voice authentication. They should then select the best authentication method for user devices and workflows, and ensure all employees are given passkeys and security keys.</p>



<p class="wp-block-paragraph">Entra ID supports both synced passkeys (those stored in platform credential managers like iCloud Keychain and Google Password Manager), and device-bound passkeys such as Microsoft Authenticator passkeys, Entra passkey on Windows, or FIDO2 security keys.</p>



<p class="wp-block-paragraph">Seker advised enterprises to evaluate support for FIDO2 and passkeys across their identity infrastructure, and to develop clear enrollment and recovery procedures. They should also educate users on what’s changing, how passkeys work, and how they can complete registration. Further, Seker said, it’s important to establish secure device management practices and to continue enforcing least privilege, conditional access, and risk-based authentication policies throughout the transition.</p>



<p class="wp-block-paragraph">Ultimately, he pointed out, the move is crucial. “Over the next several years, organizations that continue relying primarily on passwords will likely face higher operational risk as AI continues to lower the cost and increase the effectiveness of credential-based attacks,” he said.</p>



<p class="wp-block-paragraph"></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft is forcing an enterprise transition to passkeys]]></title>
<description><![CDATA[Passkeys have been around for some time, but enterprise-wide adoption to this point has been slow for a number of reasons. But soon, many Microsoft customers won’t have a choice.



Starting September 1, Microsoft will roll out passkeys as the default authentication method in its cloud-based iden...]]></description>
<link>https://tsecurity.de/de/3669414/it-security-nachrichten/microsoft-is-forcing-an-enterprise-transition-to-passkeys/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3669414/it-security-nachrichten/microsoft-is-forcing-an-enterprise-transition-to-passkeys/</guid>
<pubDate>Wed, 15 Jul 2026 04:20:21 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Passkeys have been around for some time, but enterprise-wide adoption to this point has been slow for a number of reasons. But soon, many Microsoft customers won’t have a choice.</p>



<p class="wp-block-paragraph">Starting September 1, Microsoft will roll out passkeys as the default authentication method in its cloud-based identity and access management (IAM) service Entra ID. And following a transition period, Microsoft-provided SMS and voice authentication will officially end on February 1, 2027.</p>



<p class="wp-block-paragraph">With this move, Microsoft seems to be underlining the urgent need for a more secure authentication standard, as attackers up their game with AI.</p>



<p class="wp-block-paragraph">This is an “important milestone,” because it moves passwordless authentication from an optional security enhancement to the expected standard, noted <a href="https://www.sans.org/profiles/ensar-seker" target="_blank" rel="noreferrer noopener">Ensar Seker</a>, CISO at SOCRadar. “That shift is significant as attackers increasingly rely on AI to automate phishing campaigns, generate convincing login pages, and conduct large-scale credential theft.”</p>



<h2 class="wp-block-heading">Microsoft’s six-month passkey roll-out</h2>



<p class="wp-block-paragraph"><a href="https://www.computerworld.com/article/4009132/passkeys-how-they-work-how-to-use-them.html" target="_blank">Passkeys</a> require users to authenticate via a fingerprint, facial scan, or lock screen mechanism, rather than a password. They can be stored on physical USB keys (like YubiKey), or as digital credentials on computers, phones, or in cloud accounts.</p>



<p class="wp-block-paragraph">This method, Microsoft contended, reduces reliance on phishable authentication tools like SMS and voice, and hardens protection against credential theft.</p>



<p class="wp-block-paragraph">Passkeys “work better for users and worse for cyberattackers,” <a href="https://www.linkedin.com/in/nadim-abdo/" target="_blank" rel="noreferrer noopener">Nadim Abdo</a>, Microsoft corporate VP for identity and network access engineering, wrote in a <a href="https://www.microsoft.com/en-us/security/blog/2026/07/13/microsoft-entra-id-security-updates-passkeys-are-the-default-authentication-method-in-entra-id/" target="_blank" rel="noreferrer noopener">blog post</a>.</p>



<p class="wp-block-paragraph">Microsoft’s announced timeline for rolling out passkeys is relatively aggressive:</p>



<ul class="wp-block-list">
<li><strong>September 1, 2026</strong>: All SMS or voice-enabled users will be “auto-enabled and nudged” to register a passkey upon multifactor authentication (MFA) sign-in.</li>



<li><strong>September 18, 2026</strong>: Pricing, commercial terms, and a list of supported telecom providers will be shared for scenarios that still require SMS or voice authentication due to regulation or technical or operational challenges.</li>



<li><strong>October 30, 2026</strong>: Enterprises still using SMS and voice must select and configure a supported telecom provider through the Microsoft Security Store. From then on, they will be responsible for any telecom-related costs.</li>



<li><strong>February 1, 2027</strong>: Microsoft-provided telecom delivery for SMS and voice authentication ends as a native Microsoft Entra capability.</li>
</ul>



<p class="wp-block-paragraph">After February 1, enterprises that require SMS or voice for MFA must register a passkey before sign-in. There will be no opt-out option.</p>



<p class="wp-block-paragraph">It’s important to note that these dates apply to public cloud-hosted Entra ID. Support for other cloud environments will follow a separate timeline; additional guidance and dates are to come.</p>



<p class="wp-block-paragraph">While SMS and voice have served their purpose well, Abdo said, bringing MFA to billions of users who otherwise would have had none, the threat environment has changed in “speed, scale, and sophistication,” necessitating this move to passkeys.</p>



<h2 class="wp-block-heading">The benefits of passkeys</h2>



<p class="wp-block-paragraph">SOCRadar’s Seker pointed out that passkeys fundamentally change the attack surface because, unlike with passwords, there is no transmission of shared secrets that can be stolen by threat actors. Authentication requires possession of the user’s device, along with biometric verification or a PIN.</p>



<p class="wp-block-paragraph">“Even highly convincing AI-generated phishing pages cannot simply trick users into handing over a passkey the way they can with passwords or one-time codes,” he said.</p>



<p class="wp-block-paragraph">So why haven’t we seen widespread enterprise adoption? Identity ecosystems are “fragmented,” Seker noted, and many enterprises still rely on legacy applications that only support passwords. They also struggle with cross-platform compatibility, lifecycle management, recovery processes, shared accounts, and employee onboarding and offboarding.</p>



<p class="wp-block-paragraph">Further, “until recently, many organizations viewed passkeys as a consumer technology rather than an enterprise identity strategy,” he said.</p>



<p class="wp-block-paragraph">Microsoft’s move changes that equation, because Entra sits at the center of many organizations’ identity infrastructure, Seker noted. Default settings are typically the strongest drivers of security adoption, so when passwordless authentication becomes required rather than optional, organizations are far more likely to deploy it at scale.</p>



<p class="wp-block-paragraph">Its biggest benefit would be a “dramatic reduction” in credential-based attacks, Seker said. He pointed out that most successful compromises still begin with stolen credentials obtained through phishing, infostealer malware, password reuse, or adversary-in-the-middle attacks. Passkeys “eliminate or significantly reduce” many of those attack paths, while reducing password fatigue and the help desk costs related to password resets.</p>



<p class="wp-block-paragraph">In addition, rather than trying to continuously improve users’ ability to detect increasingly sophisticated phishing attempts, passkeys remove the credential from the equation altogether, Seker noted. “That represents a more sustainable long-term security strategy than relying solely on user awareness training.”</p>



<p class="wp-block-paragraph">Still, passkeys are not a silver bullet, as they do not stop endpoint compromise, session token theft, malicious insiders, or attackers who already have control of a trusted device. Enterprises must complement passkeys with endpoint protection, continuous monitoring, conditional access policies, and identity threat detection, Seker advised.</p>



<h2 class="wp-block-heading">How enterprises can prepare</h2>



<p class="wp-block-paragraph">To prepare for the shift to passkeys, Microsoft advised enterprises to review their authentication policy and identify the groups still using SMS or voice authentication. They should then select the best authentication method for user devices and workflows, and ensure all employees are given passkeys and security keys.</p>



<p class="wp-block-paragraph">Entra ID supports both synced passkeys (those stored in platform credential managers like iCloud Keychain and Google Password Manager), and device-bound passkeys such as Microsoft Authenticator passkeys, Entra passkey on Windows, or FIDO2 security keys.</p>



<p class="wp-block-paragraph">Seker advised enterprises to evaluate support for FIDO2 and passkeys across their identity infrastructure, and to develop clear enrollment and recovery procedures. They should also educate users on what’s changing, how passkeys work, and how they can complete registration. Further, Seker said, it’s important to establish secure device management practices and to continue enforcing least privilege, conditional access, and risk-based authentication policies throughout the transition.</p>



<p class="wp-block-paragraph">Ultimately, he pointed out, the move is crucial. “Over the next several years, organizations that continue relying primarily on passwords will likely face higher operational risk as AI continues to lower the cost and increase the effectiveness of credential-based attacks,” he said.</p>



<p class="wp-block-paragraph"><em>This article originally appeared on <a href="https://www.computerworld.com/article/4197029/microsoft-is-forcing-an-enterprise-transition-to-passkeys.html" target="_blank">Computerworld</a>.</em></p>



<p class="wp-block-paragraph"></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[What to Expect at Black Hat USA 2026]]></title>
<description><![CDATA[Author: Black Hat - Bewertung: 8x - Views:51 Over 20,000 practitioners. 100+ hands-on training courses. Peer-reviewed research that doesn't exist anywhere else yet. Black Hat USA runs August 1-6, 2026 in Las Vegas, and this year's agenda is shaping up to be the most exciting one yet.
 
Black Hat ...]]></description>
<link>https://tsecurity.de/de/3668721/it-security-video/what-to-expect-at-black-hat-usa-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3668721/it-security-video/what-to-expect-at-black-hat-usa-2026/</guid>
<pubDate>Tue, 14 Jul 2026 19:00:21 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Black Hat - Bewertung: 8x - Views:51 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/HopnPmgHUis?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Over 20,000 practitioners. 100+ hands-on training courses. Peer-reviewed research that doesn't exist anywhere else yet. Black Hat USA runs August 1-6, 2026 in Las Vegas, and this year's agenda is shaping up to be the most exciting one yet.<br />
 <br />
Black Hat USA 2026 brings together the cybersecurity community for six days of training, research, and hands-on evaluation. Here's what you're walking into:<br />
<br />
• Training (August 1-4): 100+ expert-led courses taught by practitioners who've deployed these techniques in live environments. This year's expanded AI security track covers securing LLMs, defending against autonomous agents, and building detection pipelines that work at machine speed.<br />
• Briefings (August 5-6): Peer-reviewed research selected by an independent review board. AI agent exploitation. Post-quantum cryptography. Supply chain attacks. Detection engineering. The findings you'll hear don't exist in published form yet; you're getting them first.<br />
• Business Hall (August 4-6): 400+ sponsors and exhibitors. The practitioners walking that floor are coming straight out of Briefings and Trainings, so they know exactly what questions to ask. This is where real evaluation happens.<br />
• Summits (August 4): Six full-day, domain-specific programs including the CISO Summit, AI Summit, Financial Services Security Summit, Healthcare Summit, and more. You're not in a general conference audience; you're with peers who understand the specific challenges you're facing.<br />
• New this year: The Interface (hands-on demos and scenario-based learning), Arsenal Labs (20 dedicated tool demonstration sessions), Cyber War Forum (senior leader discussions under Chatham House rules), Drone Zone, Cyber District, and Black Hat(HER).<br />
<br />
Regular registration pricing is active through July 17th, 2026.<br />
Register at blackhat.com<br />
One Step Ahead.<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI incidents need a new playbook. Here’s how to build one]]></title>
<description><![CDATA[Seventy-one percent of organizations say AI has access to core business systems. Only 16% govern that access effectively, according to the 2026 CISO AI Risk Report. Ask your IR team three questions: Where is your AI system inventory? What happens if a production model starts generating harmful ou...]]></description>
<link>https://tsecurity.de/de/3667390/it-security-nachrichten/ai-incidents-need-a-new-playbook-heres-how-to-build-one/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3667390/it-security-nachrichten/ai-incidents-need-a-new-playbook-heres-how-to-build-one/</guid>
<pubDate>Tue, 14 Jul 2026 11:08:53 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Seventy-one percent of organizations say AI has access to core business systems. Only 16% govern that access effectively, <a href="https://www.cybersecurity-insiders.com/2026-ciso-ai-risk-report/">according to the 2026 CISO AI Risk Report</a>. Ask your IR team three questions: Where is your AI system inventory? What happens if a production model starts generating harmful outputs? Who has the authority to take it offline?</p>



<p class="wp-block-paragraph">I’ve spent 14 years in security — energy, banking, telecom, manufacturing. Red team work, detection programs and the last several years focused on AI risk and ShadowAI. What I see consistently: Organizations have AI in production, they have an IR playbook and they think those two things are connected. They’re not.</p>



<p class="wp-block-paragraph">The CISO who thinks their IR playbook covers AI incidents probably hasn’t tested it. The ones who have tested it know it doesn’t.</p>



<h2 class="wp-block-heading">Two kinds of AI incident — and why that split matters more than the list</h2>



<p class="wp-block-paragraph">AI incidents <a href="https://www.glacis.io/guide-ai-incident-response">surged 56.4% from 2023 to 2024, reaching 233 documented cases</a>. Most IR frameworks — including NIST SP 800-61, MITRE ATLAS and the GLACIS AI Incident Response Playbook — provide you with a taxonomy of six incident types and stop there. While useful, it misses the more important split: Failures the model causes on its own, versus failures caused by a human. Your detection approach, your containment logic and your legal exposure are very different between those two groups.</p>



<p class="wp-block-paragraph">Model-originated failures — degradation, bias, hallucinations — happen when the system does exactly what it was built to do, just badly. The Epic Sepsis Model, deployed across hundreds of US hospitals, had a sensitivity of only 33% at external validation. It missed two-thirds of actual sepsis cases and flooded physicians with false alerts, <a href="https://doi.org/10.1001/jamainternmed.2021.2626">as a 2021 JAMA Internal Medicine study found</a>. No one attacked it. It just quietly stopped working while every dashboard stayed green.</p>



<p class="wp-block-paragraph">Externally induced failures — adversarial attacks, data poisoning, privacy breaches — happen when someone corrupts the inputs or the training environment. Tesla’s Autopilot phantom braking cases, <a href="https://www.glacis.io/guide-ai-incident-response">investigated by NHTSA across hundreds of thousands of vehicles</a>, show what adversarial input failures look like in a safety-critical system. These two groups need different primary defenses and their own playbooks.</p>



<p class="wp-block-paragraph">Then there is the hybrid case, which carries the most legal exposure right now. Hallucinations are model-originated but they land in court like human errors. When Air Canada’s chatbot invented a bereavement fare policy, <a href="https://decisions.civilresolutionbc.ca/crt/crtd/en/item/519/index.do">the airline was held liable</a>. When a US federal court let <a href="https://law.justia.com/cases/federal/district-courts/california/candce/3:2023cv01924/414830/96/">Mobley v. Workday</a> proceed, it accepted that an AI hiring platform could be directly liable as an ‘agent’ of the employers using it. Neither failure looked like a security incident. Both ended up as legal ones. If your legal team is not on your IR call tree, your playbook is already incomplete.</p>



<h2 class="wp-block-heading">The CIA triad doesn’t cover a hallucination</h2>



<p class="wp-block-paragraph">The CIA triad — confidentiality, integrity, availability — does not apply to most AI incidents. When Air Canada’s chatbot made up a policy, nothing was unavailable, nothing was changed without authorization, nothing was disclosed. The framework simply doesn’t reach it. When the Epic Sepsis Model missed two-thirds of cases, there was no breach, no intrusion, no indicator of compromise. By every traditional IR metric, the system looked fine.</p>



<p class="wp-block-paragraph">This is not an edge case. Classical IR frameworks assume deterministic failures with static indicators of compromise — an assumption <a href="https://doi.org/10.3390/jcp6010020">that breaks down against probabilistic systems</a>. Microsoft’s Security Blog said it well in April 2026: A model may produce harmful output today and something completely different from the same prompt tomorrow. The root cause is not a line of code. It is a probability distribution, and <a href="https://www.microsoft.com/en-us/security/blog/2026/04/15/incident-response-for-ai-same-fire-different-fuel/">as Microsoft’s Security Blog put it</a>, you cannot patch a probability distribution.</p>



<p class="wp-block-paragraph">The numbers confirm the gap. Average AI incident detection time is 4.5 days. <a href="https://www.glacis.io/guide-ai-incident-response">Sixty-seven percent of AI incidents come from model errors, not adversarial attacks</a> — yet security budgets keep funding perimeter tools built for the latter. We are looking for the wrong signals, with the wrong tools, for the wrong failure modes.</p>



<h2 class="wp-block-heading">What a mature AI IR capability looks like</h2>



<p class="wp-block-paragraph">I get asked this at every conference I speak at. Here is the short answer: Three things that mature teams have in place before any incident occurs.</p>



<p class="wp-block-paragraph">First, an AI Bill of Materials (AIBOM) for every production system. Think of it like a software SBOM, but for AI: It documents the base model, training datasets, third-party dependencies and the full component stack. Without it, you don’t know what your AI is made of — and you can’t investigate a data poisoning incident or a supply chain compromise without that baseline. The OWASP GenAI Security Project released an <a href="https://genai.owasp.org/resource/owasp-aibom-generator/">open-source AIBOM generator</a> in December 2025 that produces output in CycloneDX format aligned with SPDX standards. It is practical to implement now.</p>



<p class="wp-block-paragraph">Second, a model card for every production AI system — not a document in a shared drive nobody opens, but something your IR team can pull up in the first ten minutes of a response. Training data provenance. Model version. Known performance limits, including which subpopulations showed weaker accuracy in testing. Access controls. Blast radius if it fails. Most organizations I work with have model documentation written for data scientists that no one in security can use at 2am. That is not documentation. That is liability.</p>



<p class="wp-block-paragraph">Third, a named data scientist on the IR call tree. Not someone to brief after the incident — someone with authority to interrogate model behavior in real time. Traditional IR has a network engineer on call. AI IR needs the same logic applied to the people who understand how the failing system works.</p>



<p class="wp-block-paragraph">A fourth thing that very few teams have: A documented rollback threshold for each deployed model. A pre-agreed definition of what anomaly rate, drift metric or fairness deviation triggers containment or a fallback switch. Teams without this spend the first hours of an AI incident debating whether what they are seeing is actually a problem. Teams with a threshold spend those hours responding.</p>



<h2 class="wp-block-heading">Four things to do before the next incident</h2>



<p class="wp-block-paragraph">Rewrite your detection triggers. Output anomaly scoring, data distribution monitoring for drift and behavioral tracking of model API usage need to be in your detection layer. They will not come from your SIEM. This is instrumentation work at the AI system level.</p>



<p class="wp-block-paragraph">Redefine containment. For most AI incidents, ‘isolate the system’ is the wrong first move. Switching to a rule-based fallback while keeping the service running may cause less harm than taking the system offline and triggering a business escalation. Each deployed model needs pre-defined rollback criteria and a named fallback. Write those down now.</p>



<p class="wp-block-paragraph">Get legal in the room before the incident. <a href="https://law.justia.com/cases/federal/district-courts/california/candce/3:2023cv01924/414830/96/">Mobley v. Workday</a> means both the AI vendor and the deploying organization can carry liability for bias incidents. <a href="https://decisions.civilresolutionbc.ca/crt/crtd/en/item/519/index.do">Air Canada</a> means you cannot disclaim what your AI says to a customer. If your legal team is learning about an AI incident from a press inquiry, something has already gone wrong.</p>



<p class="wp-block-paragraph">Build your AI inventory and treat it like your asset register. Start with the AIBOM for your highest-risk systems — those with access to customer data, financial decisions or clinical workflows. The <a href="https://doi.org/10.3390/jcp6010020">GenAI-IRF framework</a> gives you a structured taxonomy for this work and the <a href="https://www.glacis.io/guide-ai-incident-response">GLACIS AI Incident Response Playbook</a> maps it to NIST SP 800-61 and MITRE ATLAS procedures your team can adapt without starting from scratch.</p>



<p class="wp-block-paragraph"><a href="https://www.proofpoint.com/us/resources/threat-reports/ai-human-risk-landscape-report">Forty-two percent of organizations have already had a suspicious or confirmed AI incident</a>, and more than half say their security posture is catching up, inconsistent or reactive. Updating your playbook isn’t optional. Fix it before you need it.</p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[CISOs sehen Management in der Cyberrisiko-Blindheit]]></title>
<description><![CDATA[Die Mehrheit der europäischen CISOs sieht das eigene Management blind gegenüber Cyberrisiken durch Mitarbeiter.

Tags: #CISO | #Cyberrisiko | #Cybersecurity]]></description>
<link>https://tsecurity.de/de/3667192/it-security-nachrichten/cisos-sehen-management-in-der-cyberrisiko-blindheit/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3667192/it-security-nachrichten/cisos-sehen-management-in-der-cyberrisiko-blindheit/</guid>
<pubDate>Tue, 14 Jul 2026 09:41:02 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1920" height="1080" src="https://www.it-daily.net/wp-content/uploads/2026/07/Cyberrisiko-KI-Schwachstelle-Shutterstock-2772535515-1920.jpg" class="attachment-full size-full wp-post-image" alt="Cyberrisiko KI" decoding="async" srcset="https://www.it-daily.net/wp-content/uploads/2026/07/Cyberrisiko-KI-Schwachstelle-Shutterstock-2772535515-1920.jpg 1920w, https://www.it-daily.net/wp-content/uploads/2026/07/Cyberrisiko-KI-Schwachstelle-Shutterstock-2772535515-1920-300x169.jpg 300w, https://www.it-daily.net/wp-content/uploads/2026/07/Cyberrisiko-KI-Schwachstelle-Shutterstock-2772535515-1920-1024x576.jpg 1024w, https://www.it-daily.net/wp-content/uploads/2026/07/Cyberrisiko-KI-Schwachstelle-Shutterstock-2772535515-1920-768x432.jpg 768w, https://www.it-daily.net/wp-content/uploads/2026/07/Cyberrisiko-KI-Schwachstelle-Shutterstock-2772535515-1920-1536x864.jpg 1536w" sizes="(max-width: 1920px) 100vw, 1920px" title="CISOs sehen Management in der Cyberrisiko-Blindheit 1"></p>
    Die Mehrheit der europäischen CISOs sieht das eigene Management blind gegenüber Cyberrisiken durch Mitarbeiter.

<p>Tags: <a href="https://www.it-daily.net/thema/ciso">#CISO</a> | <a href="https://www.it-daily.net/thema/cyberrisiko">#Cyberrisiko</a> | <a href="https://www.it-daily.net/thema/cybersecurity-en">#Cybersecurity</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Cloud Security Meets AI: What CISOs Need to Govern Before They Scale - Brent Neal - CSP #226]]></title>
<description><![CDATA[Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:4 AI is changing cloud security fast, but the biggest challenge is not just adoption. It is governance.

In this episode, Jess sits down with Brent Neil, CISO at RapidScale, to talk about what CISOs should be watching as AI becomes...]]></description>
<link>https://tsecurity.de/de/3665812/it-security-video/cloud-security-meets-ai-what-cisos-need-to-govern-before-they-scale-brent-neal-csp-226/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3665812/it-security-video/cloud-security-meets-ai-what-cisos-need-to-govern-before-they-scale-brent-neal-csp-226/</guid>
<pubDate>Mon, 13 Jul 2026 18:17:51 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:4 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/oDDSAX2VtTY?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>AI is changing cloud security fast, but the biggest challenge is not just adoption. It is governance.<br />
<br />
In this episode, Jess sits down with Brent Neil, CISO at RapidScale, to talk about what CISOs should be watching as AI becomes embedded in cloud environments, business workflows, and sensitive data systems. Brent shares practical insight on AI governance, identity and access, cloud security controls, and the risks that emerge when experimentation moves into production.<br />
<br />
The conversation explores how security leaders can support innovation without losing visibility, accountability, or trust. Brent also breaks down the questions CISOs should be asking before AI tools scale deeper into the enterprise.<br />
<br />
Because AI may be unavoidable, but unmanaged AI risk is optional.<br />
<br />
Segment Resources:<br />
RapidScale's IT Talent Gap Report: https://try.rapidscale.net/the-talent-gap/<br />
<br />
This segment is sponsored by Arctic Wolf. Visit https://cisostoriespodcast.com/arcticwolf to learn more about them!<br />
<br />
Show Notes: https://cisostoriespodcast.com/csp-226<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Thinking Fast and Slow in the SOC: The Case for Combining Autonomous AI with Analyst Copilots]]></title>
<description><![CDATA[A few days ago, I was sitting with the CISO of a Fortune 50 company, walking through how his security team was thinking about AI agents in the SOC. Smart team. Serious program. They had already connected Claude to a few detection tools and were seeing real value in specific investigations. But as...]]></description>
<link>https://tsecurity.de/de/3665256/it-security-nachrichten/thinking-fast-and-slow-in-the-soc-the-case-for-combining-autonomous-ai-with-analyst-copilots/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3665256/it-security-nachrichten/thinking-fast-and-slow-in-the-soc-the-case-for-combining-autonomous-ai-with-analyst-copilots/</guid>
<pubDate>Mon, 13 Jul 2026 14:39:41 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A few days ago, I was sitting with the CISO of a Fortune 50 company, walking through how his security team was thinking about AI agents in the SOC. Smart team. Serious program. They had already connected Claude to a few detection tools and were seeing real value in specific investigations. But as we mapped out the broader architecture, something kept nagging at me. The design they were building]]></content:encoded>
</item>
<item>
<title><![CDATA[Thinking Fast and Slow in the SOC: The Case for Combining Autonomous AI with Analyst Copilots]]></title>
<description><![CDATA[A few days ago, I was sitting with the CISO of a Fortune 50 company, walking through how his security team was thinking about AI agents in the SOC. Smart team. Serious program. They had already connected Claude to a…
Read more →
The post Thinking Fast and Slow in the SOC: The Case for Combining A...]]></description>
<link>https://tsecurity.de/de/3665241/it-security-nachrichten/thinking-fast-and-slow-in-the-soc-the-case-for-combining-autonomous-ai-with-analyst-copilots/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3665241/it-security-nachrichten/thinking-fast-and-slow-in-the-soc-the-case-for-combining-autonomous-ai-with-analyst-copilots/</guid>
<pubDate>Mon, 13 Jul 2026 14:39:21 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A few days ago, I was sitting with the CISO of a Fortune 50 company, walking through how his security team was thinking about AI agents in the SOC. Smart team. Serious program. They had already connected Claude to a…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/thinking-fast-and-slow-in-the-soc-the-case-for-combining-autonomous-ai-with-analyst-copilots/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/thinking-fast-and-slow-in-the-soc-the-case-for-combining-autonomous-ai-with-analyst-copilots/">Thinking Fast and Slow in the SOC: The Case for Combining Autonomous AI with Analyst Copilots</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Can AI narrow cybersecurity’s class divide?]]></title>
<description><![CDATA[At Amazon Web Services (AWS), artificial intelligence is already compressing security work that once took months into minutes.



In the old world, human red teams would find vulnerabilities, write reports, refine those reports, and eventually hand them to defenders, who would then begin building...]]></description>
<link>https://tsecurity.de/de/3664478/it-security-nachrichten/can-ai-narrow-cybersecuritys-class-divide/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3664478/it-security-nachrichten/can-ai-narrow-cybersecuritys-class-divide/</guid>
<pubDate>Mon, 13 Jul 2026 09:07:52 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>At Amazon Web Services (AWS), artificial intelligence is already compressing security work that once took months into minutes.</p>



<p>In the old world, human red teams would find vulnerabilities, write reports, refine those reports, and eventually hand them to defenders, who would then begin building detections or fixes, <a href="https://www.linkedin.com/in/stephenschmidt1/">Steve Schmidt</a>, chief security officer at AWS, tells CSO. That process could take “two, four, six, eight, 10 months,” Schmidt says.</p>



<p>“Now with proper application of AI, we can have the detections built for the problems the red team finds in 15 minutes-ish,” he says. “I think the outside is about four hours.”</p>



<p>That kind of workflow offers a glimpse of what AI could make possible for the most sophisticated security organizations: AI agents testing systems, other agents generating defenses, and human security engineers validating results and refining the feedback loop.</p>



<p>But it also raises a more uncomfortable question for the rest of the cybersecurity industry: What happens to organizations that cannot build anything close to that?</p>



<p>The concern has become significant enough that the Trump administration <a href="https://www.csoonline.com/article/4180205/trump-revives-parts-of-canceled-ai-order-with-cybersecurity-focused-directive.html">recently directed</a> agencies to expand access to AI-enabled cybersecurity capabilities for resource-constrained organizations, including rural hospitals, community banks, and local utilities.</p>



<p>The order reflects a growing fear that AI could deepen a divide that has existed in cybersecurity for years: the divide between organizations with money, expertise, and engineering depth, and those struggling to keep pace with basic security demands.</p>



<p>Yet security leaders and practitioners suggest the impact of AI will be more complicated than a simple widening gap. Some experts say AI is merely adding a new layer to a long-standing security poverty problem. Others argue AI could democratize capabilities once reserved for elite organizations. Still others see today’s divide as real, but potentially temporary, as models become cheaper, more open, and easier to run.</p>



<h2 class="wp-block-heading">The class divide was already here</h2>



<p>For <a href="https://www.linkedin.com/in/matthewowenwarner/">Matt Warner</a>, co-founder and CTO of Blumira, the premise that AI is creating a cybersecurity class divide misses a key point: The divide already exists.</p>



<p>“I would go even a step further and say that there has been a class divide for the last 10 to 15 years,” Warner tells CSO.</p>



<p>What AI changes, he argues, is not necessarily the existence of the divide but how stark it becomes. Larger organizations have money, people, and time to experiment with AI. Smaller organizations often do not.</p>



<p>“The big differences that we’re seeing, especially from where we sit in the world, is the difference is getting starker in having the resources to leverage AI and the time to leverage AI more than anything else,” Warner says.</p>



<p>That distinction matters because many smaller organizations are already overwhelmed. Warner pointed to resource-constrained local governments and small or midmarket organizations that are still far behind large enterprises in basic IT and security maturity.</p>



<p>“I can find you a county in Michigan with two IT people for 2,000 employees,” Warner says. “Those people don’t have time to leverage AI and even learn how to use AI because they’re mostly just trying to put out fires.”</p>



<p>That problem is not unique to AI. Smaller organizations have long struggled to patch systems, prioritize vulnerabilities, monitor environments, and respond to incidents with limited staff. AI may help eventually, but only if those organizations have enough capacity to adopt it.</p>



<h2 class="wp-block-heading">Wendy Nather’s framework gets an AI layer</h2>



<p><a href="https://www.linkedin.com/in/chuvakin/">Anton Chuvakin</a>, security advisor in the office of the CISO for Google Cloud, sees the AI divide as part of a much older problem.</p>



<p>“I feel like it sends me back to when <a href="https://www.linkedin.com/in/wendynather/">Wendy Nather</a> invented the security poverty line,” Chuvakin tells CSO, referring to Nather’s <a href="https://www.infosecuritymagazine.nl/files/2fb0642808f57f0f9831532ae8f7e8fd.pdf">2011 concept</a> describing organizations that lack the money, expertise, capability, or influence to implement effective security.</p>



<p>Chuvakin is skeptical that AI fundamentally changes that model. “I don’t think AI necessarily breaks that model,” he says. “I think it just adds another dimension.”</p>



<p>Cybersecurity has always been shaped by unequal access to top talent, tools, and services, Chuvakin argues. Large organizations could afford better SIEM deployments, advanced DLP programs, threat hunters, application security experts, and incident response retainers. Smaller organizations often could not.</p>



<p>AI may become another scarce resource, but Chuvakin cautions against overstating the role of model cost alone. In his view, the <a href="https://www.cio.com/article/4165232/whats-holding-back-enterprise-ai-shortage-of-talent-cios-say.html">bigger structural issue may be talent</a> rather than tokens.</p>



<p>“Prices for people won’t drop, but prices for LLMs may drop,” he believes.</p>



<p>That means the organizations with the greatest advantage may not simply be those that can afford the most expensive models. They may be the ones that can afford the people who know how to use them — and, as the frontier-access debate below suggests, that talent gap may prove more durable than any gap in model access itself.</p>



<h2 class="wp-block-heading">AI creates new costs — and new uncertainties</h2>



<p>Nather herself, now senior research initiatives director at 1Password, sees AI affecting every dimension of the security poverty line: money, expertise, capability, and influence.</p>



<p>The financial challenges are not limited to whether an organization can pay for an AI tool. In some cases, organizations that cannot afford enterprise licensing may end up making tradeoffs around privacy.</p>



<p>“If an organization can’t afford an enterprise license for the models they’re using, then they can’t keep their data private,” Nather tells CSO. “So, they have to give up privacy because they can’t afford privacy.”</p>



<p>That’s a new twist on an old dimension of the poverty line: It’s not just that under-resourced organizations lack a capability, but that the capability they can afford comes bundled with a risk wealthier organizations don’t have to accept.</p>



<p>Token-based pricing adds another problem: <a href="https://www.cio.com/article/4152601/without-controls-an-ai-agent-can-cost-more-than-an-employee.html">unpredictability</a>. “At this point, nobody knows how much they’re going to burn in tokens at any given time,” she says.</p>



<p>That makes budgeting difficult for organizations that cannot absorb surprise costs. Nather also warns that usage-based pricing is controlled by providers and can change over time, <a href="https://www.cio.com/article/4184688/it-hurtles-toward-the-great-enterprise-pricing-reset.html">leaving customers with limited leverage</a>.</p>



<p>“The charging practice is in the hands of the providers, and they can change it at any time,” she says.</p>



<p>For organizations already operating below the security poverty line, that uncertainty could make AI adoption harder, even if the technology itself becomes more capable.</p>



<h2 class="wp-block-heading">Access to frontier models may be a temporary divide</h2>



<p><a href="https://www.linkedin.com/in/davidbaggett/">Dave Baggett</a>, SVP/GM of the security suite at Kaseya, agrees there is security class divide dynamic playing out today, particularly around access to frontier models.</p>



<p>“There’s definitely a haves and have-nots issue around Mythos specifically because most people don’t have it,” Baggett tells CSO. But he doesn’t think the divide will have a long-term impact. Open-weight models, quantization, mixture-of-experts architectures, and increasingly powerful commodity hardware, he argues, are closing the gap faster than most people expect.</p>



<p>While not every organization will build a frontier model, he says, more organizations may be able to run capable models locally or use cheaper systems that <a href="https://www.csoonline.com/article/4170818/what-happens-when-chinas-ai-catches-up-to-mythos.html">approximate what today’s elite models can do</a>.</p>



<p>“What it says for finding vulnerabilities is at that point, open-source people can run this stuff,” Baggett says. “Then you’re back to having a symmetrical opportunity where the defenders who are writing the open source can run the same tools the attackers would and have them fix the issues.”</p>



<p>His bottom line is that the divide may be real but short-lived. “Right now, there certainly is a have, have-not schism, but it may not be there for long,” Baggett says — a view Chuvakin shares, though he frames it in terms of the model market rather than open source specifically.</p>



<p>“I don’t think it’s the lowering prices example, but it’s more like you’re a top-tier model maker, I’m a second-tier model maker. My model in a year would do what your model did a year ago,” Chuvakin says.</p>



<h2 class="wp-block-heading">The real advantage is operational depth</h2>



<p>Schmidt’s description of AI use at AWS points to another kind of divide: not access to AI, but the ability to operationalize it.</p>



<p>AWS uses multiple models for different tasks, Schmidt says. One model may discover vulnerabilities, while other models validate results or help build defenses. Humans remain accountable for evaluating what the systems produce.</p>



<p>“Because we believe really strongly in human accountability for the use of AI from end to end, we still have humans take a look at what the systems come up with to determine whether they are reasonable and appropriate,” he says.</p>



<p>That workflow requires more than a model. It requires corporate data, secure infrastructure, feedback loops, security engineers, data scientists, and AI specialists who can work together.</p>



<p>Schmidt also pushes back on the idea that running AI locally on powerful consumer hardware is a substitute for production-grade security infrastructure. “Often the value of the model is also dependent on its proximity to data so that the model can ingest, use, and reason about data,” he says. “As a security person, I do not want that to be on your laptop.”</p>



<p>Experimentation on a laptop is useful, Schmidt says, but it is not the same as a secure production environment.</p>



<p>“I want the data to be somewhere safe that I can control, that I can see, that I can reason about, not sitting on your laptop,” he says. “Experimentation in there, awesome. That’s great. But it is not a production infrastructure component.”</p>



<p>That distinction may define the emerging AI security gap. Many organizations may be able to access AI tools. Far fewer may be able to safely integrate them into real security workflows.</p>



<h2 class="wp-block-heading">The democratization argument</h2>



<p><a href="https://www.linkedin.com/in/philvenables/">Phil Venables</a>, a partner at Ballistic Ventures and former CISO of Google Cloud, takes the most optimistic view.</p>



<p>Asked whether AI is widening the gap between well-resourced and under-resourced security organizations, Venables tells CSO, “No, I actually think it’s the exact opposite.”</p>



<p>The reason, he argues, is that AI packages expertise and automation in ways that can be delivered broadly. “One of the fantastic things about AI, and we’re already starting to see this, is [that it’s] a great democratizer of capabilities,” he says. “AI packages up expertise and automation capabilities at a level beyond what prior waves of technology have done, and it makes it available at scale into organizations that have not previously been able to afford these things.”</p>



<p>He points to <a href="https://www.csoonline.com/article/4181930/ai-red-teaming-comes-of-age.html">red teaming</a> as an example. Nearly every organization would like a world-class red team, but few can afford one.</p>



<p>“Pretty much every organization on the planet would love to have a world-class red team to constantly test their security to find and fix things before attackers do,” Venables says. “But very few organizations have ever been able to afford to build a high-end red team.”</p>



<p>AI agents, he argues, could make that kind of capability available more economically. The same pattern could apply to insider threat; third-party risk; software security; governance, risk and compliance; and security operations.</p>



<p>“So even the smallest and resource-constrained organizations can now have access to a higher-end capability,” he maintains.</p>



<p>Venables does see a danger zone, however: under-resourced security teams inside organizations with aggressive AI ambitions. Those teams may <a href="https://www.csoonline.com/article/3529615/companies-skip-security-hardening-in-rush-to-adopt-ai.html">struggle to keep up</a> as the rest of the business adopts AI rapidly. But for many small and midsize organizations, he believes AI could improve access to security capabilities they never had before.</p>



<h2 class="wp-block-heading">A divide over AI — or over readiness?</h2>



<p>For elite organizations, AI is already becoming a force multiplier. Security teams with deep engineering talent, mature data infrastructure, and strong governance can use AI to accelerate testing, detection engineering, vulnerability discovery, and risk management.</p>



<p>For smaller organizations, the picture is less clear. AI may eventually package scarce expertise into affordable services. Open models may reduce dependence on expensive frontier systems. But organizations below the security poverty line still face familiar constraints: too few people, too little time, limited expertise, unpredictable costs, and weak leverage over vendors.</p>



<p>The emerging divide may therefore be less about who has access to AI and more about who can turn AI into durable security outcomes.</p>



<p>That makes the question facing cybersecurity more complicated than whether AI will create haves and have-nots. The industry already had them.</p>



<p>The real question is whether AI becomes another technology that rewards the organizations already best positioned to use it — or the first major security advance in years that helps those below the poverty line finally catch up.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Dauerstress im Cyberspace: Wenn CISOs ausbrennen]]></title>
<description><![CDATA[Neun von zehn Sicherheitsverantwortlichen stehen unter anhaltendem Druck und die durchschnittliche Verweildauer auf ihrer Position sinkt drastisch. Geteilte Verantwortung und strukturelle Anpassungen weisen Unternehmen einen Weg aus der Belastungsspirale. 

Tags: #CISO | #Stress]]></description>
<link>https://tsecurity.de/de/3664137/it-security-nachrichten/dauerstress-im-cyberspace-wenn-cisos-ausbrennen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3664137/it-security-nachrichten/dauerstress-im-cyberspace-wenn-cisos-ausbrennen/</guid>
<pubDate>Mon, 13 Jul 2026 05:21:03 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1920" height="1080" src="https://www.it-daily.net/wp-content/uploads/2026/07/Stress-1920-shutterstock-2592895635.jpg" class="attachment-full size-full wp-post-image" alt="Stress" decoding="async" srcset="https://www.it-daily.net/wp-content/uploads/2026/07/Stress-1920-shutterstock-2592895635.jpg 1920w, https://www.it-daily.net/wp-content/uploads/2026/07/Stress-1920-shutterstock-2592895635-300x169.jpg 300w, https://www.it-daily.net/wp-content/uploads/2026/07/Stress-1920-shutterstock-2592895635-1024x576.jpg 1024w, https://www.it-daily.net/wp-content/uploads/2026/07/Stress-1920-shutterstock-2592895635-768x432.jpg 768w, https://www.it-daily.net/wp-content/uploads/2026/07/Stress-1920-shutterstock-2592895635-1536x864.jpg 1536w" sizes="(max-width: 1920px) 100vw, 1920px" title="Dauerstress im Cyberspace: Wenn CISOs ausbrennen 1"></p>
    Neun von zehn Sicherheitsverantwortlichen stehen unter anhaltendem Druck und die durchschnittliche Verweildauer auf ihrer Position sinkt drastisch. Geteilte Verantwortung und strukturelle Anpassungen weisen Unternehmen einen Weg aus der Belastungsspirale. 

<p>Tags: <a href="https://www.it-daily.net/thema/ciso">#CISO</a> | <a href="https://www.it-daily.net/thema/stress">#Stress</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI Export Controls, FortiBleed, Third-Party Breaches & CISO Burnout | Cybersecurity Today Panel]]></title>
<description><![CDATA[Can governments decide who gets access to advanced AI models? Are third-party breaches becoming impossible to control? And why are so many CISOs reaching burnout? In this special Cybersecurity Today Month in Review Panel, host Jim Love is joined by…
Read more →
The post AI Export Controls, FortiB...]]></description>
<link>https://tsecurity.de/de/3661313/it-security-nachrichten/ai-export-controls-fortibleed-third-party-breaches-ciso-burnout-cybersecurity-today-panel/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3661313/it-security-nachrichten/ai-export-controls-fortibleed-third-party-breaches-ciso-burnout-cybersecurity-today-panel/</guid>
<pubDate>Sat, 11 Jul 2026 07:35:01 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Can governments decide who gets access to advanced AI models? Are third-party breaches becoming impossible to control? And why are so many CISOs reaching burnout? In this special Cybersecurity Today Month in Review Panel, host Jim Love is joined by…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/ai-export-controls-fortibleed-third-party-breaches-ciso-burnout-cybersecurity-today-panel/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/ai-export-controls-fortibleed-third-party-breaches-ciso-burnout-cybersecurity-today-panel/">AI Export Controls, FortiBleed, Third-Party Breaches &amp; CISO Burnout | Cybersecurity Today Panel</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Redefining the CISO Contract: From Securing the Business to Securely Doing Business]]></title>
<description><![CDATA[Walk into almost any executive leadership meeting right now and you’ll find the same dynamic playing out. The CEO is asking how the company can do more with AI, faster. Engineering teams are already three sprints deep into building something…
Read more →
The post Redefining the CISO Contract: Fro...]]></description>
<link>https://tsecurity.de/de/3659273/it-security-nachrichten/redefining-the-ciso-contract-from-securing-the-business-to-securely-doing-business/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3659273/it-security-nachrichten/redefining-the-ciso-contract-from-securing-the-business-to-securely-doing-business/</guid>
<pubDate>Fri, 10 Jul 2026 11:37:28 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Walk into almost any executive leadership meeting right now and you’ll find the same dynamic playing out. The CEO is asking how the company can do more with AI, faster. Engineering teams are already three sprints deep into building something…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/redefining-the-ciso-contract-from-securing-the-business-to-securely-doing-business/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/redefining-the-ciso-contract-from-securing-the-business-to-securely-doing-business/">Redefining the CISO Contract: From Securing the Business to Securely Doing Business</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Redefining the CISO Contract: From Securing the Business to Securely Doing Business]]></title>
<description><![CDATA[Walk into almost any executive leadership meeting right now and you’ll find the same dynamic playing out. The CEO is asking how the company can do more with AI, faster. Engineering teams are already three sprints deep into building something new. And when the CISO walks into the room, the energy ...]]></description>
<link>https://tsecurity.de/de/3659241/it-security-nachrichten/redefining-the-ciso-contract-from-securing-the-business-to-securely-doing-business/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3659241/it-security-nachrichten/redefining-the-ciso-contract-from-securing-the-business-to-securely-doing-business/</guid>
<pubDate>Fri, 10 Jul 2026 11:23:04 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<img width="1600" height="800" src="https://blog.checkpoint.com/wp-content/uploads/2026/07/blog-banner-ciso-contract-800x400-2.png" class="webfeedsFeaturedVisual wp-post-image" alt="Redefining CISO Contract Blog Banner" link_thumbnail="" decoding="async" fetchpriority="high" srcset="https://blog.checkpoint.com/wp-content/uploads/2026/07/blog-banner-ciso-contract-800x400-2.png 1600w, https://blog.checkpoint.com/wp-content/uploads/2026/07/blog-banner-ciso-contract-800x400-2-300x150.png 300w, https://blog.checkpoint.com/wp-content/uploads/2026/07/blog-banner-ciso-contract-800x400-2-1024x512.png 1024w, https://blog.checkpoint.com/wp-content/uploads/2026/07/blog-banner-ciso-contract-800x400-2-768x384.png 768w, https://blog.checkpoint.com/wp-content/uploads/2026/07/blog-banner-ciso-contract-800x400-2-1536x768.png 1536w, https://blog.checkpoint.com/wp-content/uploads/2026/07/blog-banner-ciso-contract-800x400-2-400x200.png 400w, https://blog.checkpoint.com/wp-content/uploads/2026/07/blog-banner-ciso-contract-800x400-2-600x300.png 600w, https://blog.checkpoint.com/wp-content/uploads/2026/07/blog-banner-ciso-contract-800x400-2-800x400.png 800w, https://blog.checkpoint.com/wp-content/uploads/2026/07/blog-banner-ciso-contract-800x400-2-1200x600.png 1200w, https://blog.checkpoint.com/wp-content/uploads/2026/07/blog-banner-ciso-contract-800x400-2-1320x660.png 1320w" sizes="(max-width: 1600px) 100vw, 1600px"><p>Walk into almost any executive leadership meeting right now and you’ll find the same dynamic playing out. The CEO is asking how the company can do more with AI, faster. Engineering teams are already three sprints deep into building something new. And when the CISO walks into the room, the energy subtly shifts. The unspoken question is always the same: is this person here to help us move, or to slow us down? That dynamic is an issue, and I think it’s one the security community has to own. The CISO has long carried the label of the “Office of […]</p>
<p>The post <a href="https://blog.checkpoint.com/ai-security/redefining-the-ciso-contract-from-securing-the-business-to-securely-doing-business/">Redefining the CISO Contract: From Securing the Business to Securely Doing Business</a> appeared first on <a href="https://blog.checkpoint.com/">Check Point Blog</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[앤트로픽, 클로드 AI의 블랙홀 속을 들여다보다]]></title>
<description><![CDATA[앤트로픽이 자사 AI 모델이 문제를 해결하는 내부 과정을 보다 깊이 들여다볼 수 있는 새로운 분석 기법을 공개했다. 모델이 특정 방식으로 판단하고 행동하는 이유를 파악할 수 있게 되면서, 기업의 AI 평가와 구매 기준에도 적지 않은 영향을 미칠 것으로 전망된다.



앤트로픽은 최근 ‘J-스페이스(J-space)’라고 이름 붙인 새로운 내부 표현 공간을 발견했다고 밝혔다.



앤트로픽은 공식 블로그를 통해 “클로드(Claude)는 수많은 내부 처리 과정 가운데 특별한 역할을 수행하는 소수의 신경 패턴 집합을 스스로 형성했다”...]]></description>
<link>https://tsecurity.de/de/3658787/it-nachrichten/ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3658787/it-nachrichten/ai/</guid>
<pubDate>Fri, 10 Jul 2026 07:18:20 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>앤트로픽이 자사 AI 모델이 문제를 해결하는 내부 과정을 보다 깊이 들여다볼 수 있는 새로운 분석 기법을 공개했다. 모델이 특정 방식으로 판단하고 행동하는 이유를 파악할 수 있게 되면서, 기업의 AI 평가와 구매 기준에도 적지 않은 영향을 미칠 것으로 전망된다.</p>



<p>앤트로픽은 최근 ‘J-스페이스(J-space)’라고 이름 붙인 새로운 내부 표현 공간을 발견했다고 밝혔다.</p>



<p>앤트로픽은 <a href="https://www.anthropic.com/research/global-workspace" target="_blank" rel="nofollow">공식 블로그</a>를 통해 “클로드(Claude)는 수많은 내부 처리 과정 가운데 특별한 역할을 수행하는 소수의 신경 패턴 집합을 스스로 형성했다”라며 “이 패턴 집합을 발견하는 데 야코비안(Jacobian)이라는 수학 개념을 활용한 기법을 사용했기 때문에 이를 ‘J-스페이스’라고 명명했다”고 설명했다. 회사는 ‘야코비안 렌즈(Jacobian Lens·J-렌즈)’라는 분석 기법을 통해 J-스페이스 내부를 관찰한다.</p>



<p>앤트로픽은 “J-스페이스의 각 패턴은 특정 단어와 연결돼 있다”라며 “하지만 특정 패턴이 활성화됐다고 해서 모델이 실제로 그 단어를 출력하려는 것은 아니다. 단지 해당 단어가 모델의 ‘생각 속’에 있다는 의미”라고 밝혔다.</p>



<p>이어 “언어 모델의 ‘스크래치패드(scratchpad)’나 ‘생각의 연쇄(Chain of Thought)’처럼 추론 과정에서 스스로 작성하는 텍스트와 J-스페이스는 다르다”라며 “J-스페이스는 모델 내부 신경망 활성화 영역에서 조용히 작동하기 때문에 모델은 개념을 텍스트로 적지 않고도 내부적으로 사고할 수 있다”고 설명했다.</p>



<p>이번 연구는 앤트로픽이 2024년 공개했던 내부 스크래치패드보다 훨씬 발전한 개념이다. 당시에는 모델이 답변이나 행동을 준비하면서 무엇을 고려하는지를 보여주는 수준이었다. 반면 이번 기술은 모델의 훨씬 깊은 내부 사고 과정을 분석할 수 있어 AI 시스템을 평가하고 구매하는 방식 자체를 바꿀 가능성을 제시한다.</p>



<p><a href="https://transformer-circuits.pub/2026/workspace/index.html" target="_blank" rel="nofollow">논문</a>에 소개된 사례도 이러한 가능성을 보여준다. 일부 모델은 테스트 과정에서 부적절한 행동을 하지 않아 안전한 모델처럼 보였다. 그러나 J-스페이스를 분석한 결과, 해당 모델은 자신이 테스트를 받고 있다는 사실을 인지하고 있었으며, 그 때문에 문제 행동을 의도적으로 하지 않았을 가능성이 드러났다. 이는 아이들이 누군가 자신을 지켜보고 있다는 사실을 알 때 행동을 달리하는 것과 유사하다고 연구진은 설명했다.</p>



<p>AI 에이전트 기업 제니티(Zenity)의 AI 표준·거버넌스 총괄인 <a href="https://zenity.io/authors/rock-lambros" target="_blank" rel="nofollow">록 램브로스</a>(Rock Lambros)는 “앤트로픽은 모델이 테스트를 받고 있다는 사실을 인식하거나, 좋은 결과를 얻기 위해 행동을 꾸미거나, 프롬프트 인젝션을 탐지하거나, 아직 실행하지 않은 목표를 내부적으로 유지하고 있는 상황까지 포착할 수 있는 분석 도구를 만들었다”라며 “일부 바람직한 행동은 모델이 자신이 평가받고 있다는 사실을 알고 있었기 때문에 나타난 것일 수 있다”고 말했다.</p>



<p>그는 기업 고객 역시 AI 안전성 벤치마크를 해석할 때 이러한 점을 고려해야 한다고 지적했다.</p>



<p>램브로스는 “프로젝트에 적합한 모델인지는 모델이 알고 응시한 리더보드 결과가 아니라, 기업이 보유한 데이터와 실제 공격 시나리오를 활용한 자체 테스트를 통해 검증해야 한다”고 설명했다.</p>



<p>이처럼 모델 내부를 들여다볼 수 있는 능력은 CIO에게도 중요한 의미를 갖는다.</p>



<p>램브로스는 “자사 모델이 겉으로 드러나지 않는 문제 행동을 스스로 발견하고 그 결과를 공개할 수 있는 공급업체라면 신뢰성 검증 체계가 상당히 성숙했다는 의미”라며 “이러한 역량은 단순한 뉴스가 아니라 공급업체 실사(Due Diligence) 과정에서 반드시 확인해야 한다”고 말했다.</p>



<p>이어 “이제 모든 AI 모델 공급업체에 던져야 할 질문은 ‘모델 출력만으로는 볼 수 없는 내부 상태 가운데 무엇을 관찰할 수 있으며, 실제로 어떤 문제를 발견했는가’가 돼야 한다”고 덧붙였다.</p>



<p>AI 거버넌스 컨설팅 기업 디지털 520(Digital 520)의 수석 컨설턴트 <a href="https://www.linkedin.com/in/noah-m-kenney-27499a166/" target="_blank" rel="nofollow">노아 케니</a>(Noah Kenney)도 비슷한 견해를 내놨다.</p>



<p>케니는 “감시받고 있다는 사실을 알기 때문에 더 바람직하게 행동하는 모델은 안전한 모델이 아니다. 단지 포커페이스를 잘하는 모델일 뿐”이라며 “레드팀 테스트 결과나 모델이 위험한 요청을 거부한 내부 파일럿, ‘테스트해 보니 문제가 없었다’는 모든 사례를 다시 검토해야 한다. 이제는 모두 단서를 달고 해석해야 하기 때문”이라고 말했다.</p>



<p>또한 CIO는 AI 에이전트가 특정 방식으로 작업을 수행한 이유가 원래 그렇게 설계됐기 때문인지, 아니면 단순히 자신이 테스트받고 있다는 사실을 알아차렸기 때문인지를 구분해야 한다고 강조했다.</p>



<p>케니는 “이 질문에 대한 답에 따라 모델 평가 결과에 대한 해석도 크게 달라져야 한다”고 말했다.</p>



<h2 class="wp-block-heading">아직 고객은 사용할 수 없는 J-렌즈</h2>



<p>노아 케니는 “이번 연구는 지금까지 업계가 AI 모델 평가를 통해 측정해 온 것이 모두가 생각했던 것만큼 견고한 지표가 아니었다는 사실을 인정한 것”이라며 “이제 다른 프런티어 AI 연구소들도 자사 평가 체계 역시 같은 문제를 안고 있는지 답해야 할 것”이라고 말했다. 이어 “CIO에게 이번 논문은 기업의 AI 모델 리스크 관리 체계 전반을 다시 점검하라는 경고”라고 평가했다.</p>



<p>렉시스넥시스 리스크 솔루션 그룹(LexisNexis Risk Solutions Group)의 CISO <a href="https://www.linkedin.com/in/fvillanustre/" target="_blank" rel="nofollow">플라비오 비야누스트레</a>(Flavio Villanustre)는 J-스페이스를 분석하면 모델 효율성까지 높일 수 있다고 설명했다.</p>



<p>비야누스트레는 “J-스페이스는 모델 내부를 직접 들여다볼 수 있는 능력을 제공하기 때문에 사용자에게 매우 유용하다”라며 “특히 설명 가능성이 중요한 규제 산업에서는 응답의 근거와 인과관계를 충분히 분석해야 하는데 큰 도움이 될 수 있다”고 말했다.</p>



<p>이어 “사용자가 프롬프트를 더욱 정교하게 다듬는 데에도 활용할 수 있어 모델의 토큰 사용 비용을 최적화하는 데 도움이 된다”고 설명했다.</p>



<p>다만 현재로서는 이러한 정보를 직접 활용하기 어렵다. AI 공급업체를 통해 간접적으로 접근하거나 향후 계약 협상을 통해 권한을 확보하는 것이 사실상 유일한 방법이다. 비야누스트레는 일부 기업은 앤트로픽의 FDE 프로그램에 비용을 지불하면 J-스페이스에 직접 접근할 수도 있다고 덧붙였다.</p>



<p>그는 “J-스페이스는 CIO에게 매우 유용한 도구”라면서도 “이를 실제로 활용하려면 분석 결과를 해석할 수 있는 전문 인력이 필요하다. 요구되는 역량은 일반 데이터 분석가는 물론 데이터 사이언티스트 수준을 넘어선다”고 말했다.</p>



<p>기술 컨설팅 기업 트라이베카 소프트테크(Tribeca Softtech)의 최고전략책임자(CSO) <a href="https://www.linkedin.com/in/akm76/" target="_blank" rel="nofollow">아만 마하파트라</a>(Aman Mahapatra)는 현재 기업 고객이 J-렌즈를 실제 운영에 활용하기는 어렵다고 지적했다.</p>



<p>그는 “현재 기업 고객은 야코비안 렌즈를 활성화할 수도 없고, API를 통해 모델의 잔차 스트림(residual stream)을 분석할 수도 없으며, 논문의 핵심 결과를 도출한 제거 실험(ablation study)도 수행할 수 없다”고 설명했다.</p>



<p>이어 “올해 3분기 안에 CIO가 J-스페이스 모니터링을 실제 운영 환경의 배포 승인 기준으로 활용할 수 있느냐는 질문에 대한 답은 ‘아니다'”라고 말했다.</p>



<p>다만 마하파트라는 앞으로는 다른 방식의 접근 경로가 마련될 것이며, CIO들이 이를 적극 요구해야 한다고 주장했다.</p>



<p>그는 “고객이 직접 접근할 수 없다면 결국 이번에도 앤트로픽을 믿을 수밖에 없다”라며 “바로 그렇기 때문에 기업들은 업계 전반에 새로운 신뢰 검증(Assurance) 체계를 요구해야 한다”고 말했다.</p>



<p>이어 “현재 AI 모델 공급업체들은 자체 도구로 스스로 모델을 점검한 뒤 안심할 수 있는 연구 결과를 발표하는 방향으로 나아가고 있다”라며 “그러나 어떤 규제 산업도 다른 공급업체에게 이런 방식의 검증을 신뢰 기준으로 인정하지 않는다”고 지적했다.</p>



<p>마하파트라는 “은행은 신용평가 업체가 ‘우리 모델은 우리가 검증했으니 믿어달라’고 말한다고 이를 받아들이지 않는다”라며 “의료 업계 역시 임상 의사결정 지원 시스템 공급업체의 자체 검증만으로는 신뢰하지 않는다. 파운데이션 모델 공급업체만 예외로 취급해야 할 원칙적인 이유는 없으며, 이번 J-스페이스 연구는 그 이유를 분명하게 보여준다”고 말했다.</p>



<h2 class="wp-block-heading">새로운 가시성이 요구하는 변화</h2>



<p>마하파트라는 기업이 장기적으로는 AI 모델의 내부 동작을 독립적으로 검증할 수 있는 환경을 요구해야 한다고 강조했다.</p>



<p>그는 “기업이 취해야 할 올바른 장기 전략은 고객이 사용할 수 있는 API, 특권 접근 권한을 가진 독립적인 제3자 감사기관, 또는 은행의 모델 리스크 관리팀이 공급업체의 안전성 검증팀과 동일한 도구를 사용할 수 있도록 하는 개방형 해석 가능성(Interpretability) 표준 등을 요구하는 것”이라고 말했다.</p>



<p>이어 “현재는 이런 환경이 전혀 마련돼 있지 않다”라며 “하지만 CIO들이 추진해야 할 로드맵에는 반드시 포함돼야 하며, 이번 연구는 그 필요성을 보여주는 가장 강력한 근거”라고 평가했다.</p>



<p>실제로 이번 연구 결과는 기업의 AI 전략 자체를 근본적으로 바꿀 가능성을 갖고 있다.</p>



<p>마하파트라는 “기업이 AI 에이전트를 도입할 때 가장 어려운 과제는 자율 시스템이 설명하는 추론 과정과 실제 내부 추론이 일치하는지를 검증하는 것”이라며 “지금까지는 모델이 출력한 내용만 감사할 수 있었고 실제 추론의 상당 부분은 보이지 않는 곳에서 이뤄졌다. J-렌즈는 바로 이 간극을 정면으로 해결하려는 시도”라고 설명했다.</p>



<p>그는 기업의 AI 구매 담당자들이 앞으로 모델 공급업체에 내부 상태를 관찰할 수 있는 해석 가능성 도구를 제공하는지 반드시 확인해야 한다고 조언했다. 특히 고객 환경에서 기만 행위(deception), 평가 회피(evaluation gaming), 목표 불일치(goal misalignment) 등을 모니터링할 수 있는 기능을 제공하는지를 구매 과정에서 질문해야 한다고 강조했다.</p>



<p>마하파트라는 “현재 이러한 질문에 제대로 답할 수 있는 공급업체는 거의 없다”라며 “관련 도구가 완전히 성숙하기 전이라도 내부 상태의 가시성을 구매 기준으로 요구하기 시작하는 CIO가 앞으로 공급업체의 제품 발전 방향을 결정하게 될 것”이라고 말했다.</p>



<p>이어 “향후 규제기관이 ‘기업은 자율 AI 에이전트가 실제로 주장한 대로 동작한다는 사실을 어떻게 확인했는가’를 묻기 시작하면, 이런 기업만이 실질적인 신뢰성을 입증할 수 있을 것”이라고 전망했다.</p>



<h2 class="wp-block-heading">표준화의 시작</h2>



<p>CIO가 클로드의 새로운 내부 가시성을 활용할 수 있는 또 다른 방법은 이미 해당 정보에 접근할 수 있는 제3자를 활용하는 것이다. 실제로 이번 보고서에는 구글의 AI 연구원이 오픈웨이트(Open-weight) 모델에서 일부 연구 결과를 독립적으로 재현하는 데 성공했다는 내용이 포함됐다.</p>



<p>소프트웨어 개발 기업 컴프 AI(Comp AI)의 CEO <a href="https://www.linkedin.com/in/lewiscarhart/" target="_blank" rel="nofollow">루이스 카하트</a>(Lewis Carhart)는 “이는 공급업체의 주장만이 아니라 경쟁사가 해당 분석 기법을 검증했다는 의미”라며 “기술적으로 무엇이 가능한지를 보여주지만, 기업이 직접 이를 검증할 수 있는 수단을 제공하는 것은 아니다”라고 설명했다.</p>



<p>그는 이러한 상황이 컴플라이언스 분야에서도 이미 여러 차례 반복됐던 패턴이라고 말했다.</p>



<p>카하트는 “SOC 2 역시 처음부터 독립적인 감사 기준으로 출발한 것은 아니었다”라며 “초기에는 공급업체가 자체 통제 체계를 설명하는 수준에 머물렀고, 이후 시장이 수년에 걸쳐 이를 외부에서 검증할 수 있는 인프라를 구축했다”고 설명했다.</p>



<p>이어 “AI 해석 가능성(Interpretability)도 지금은 바로 그 출발점에 있다”라며 “J-렌즈 분석 결과가 제3자 감사 보고서나 모델 카드(Model Card), 또는 규제기관 제출 문서에 포함되기 시작해야 CIO에게 실질적인 의미를 갖게 될 것”이라고 말했다.</p>



<p>그는 “결국 리스크 관리 조직이 공급업체의 주장만이 아니라 객관적인 근거로 제시할 수 있는 자료가 마련돼야 한다”고 덧붙였다.</p>



<h2 class="wp-block-heading">AI 전략 변화 이끄나</h2>



<p>컨설팅 기업 액셀리전스(Acceligence)의 CEO <a href="https://acceligence.com/talent/profiles/justin-greis/" target="_blank" rel="nofollow">저스틴 그라이스</a>(Justin Greis)는 이번 기술이 기업 AI 전략에도 상당한 변화를 가져올 것으로 전망했다.</p>



<p>그는 “향후 AI 거버넌스 플랫폼은 프롬프트와 출력 결과, 사용자 신원 정보, 정책 결정, 도구 사용 기록뿐 아니라 J-렌즈가 제공하는 내부 신호까지 함께 활용하게 될 것”이라고 말했다.</p>



<p>이어 “미래의 AI 제어 플랫폼은 AI 에이전트가 프롬프트 인젝션 시도를 인식했는지, 민감한 정보가 포함됐음을 이해했는지, 상충되는 목표를 감지했는지, 또는 실제 위험한 행동을 실행하기 전에 그러한 방향으로 추론하고 있었다는 징후가 있었는지를 지속적으로 평가할 수 있을 것”이라며 “이러한 신호는 정책 집행, 사람의 개입 여부 결정, 감사 로그 작성, 기업 AI 환경 전반의 신뢰도 평가 등에 활용될 것”이라고 설명했다.</p>



<p>그는 이러한 변화가 현재 CIO에게도 실질적인 의미를 갖는다고 강조했다.</p>



<p>그라이스는 “AI 공급업체를 평가하는 기준 자체가 달라지고 있기 때문”이라며 “1년 전만 해도 기업은 모델의 정확도와 지연시간, 보안, 비용을 주로 평가했다. 앞으로는 AI 에이전트의 행동과 추론 품질, 정책 준수 여부, 안전성 모니터링, 감사 가능성에 대해 공급업체가 얼마나 높은 수준의 운영 가시성을 제공하는지도 중요한 평가 항목이 될 것”이라고 말했다.</p>



<p>마하파트라는 이러한 변화가 CIO에게 강력한 협상 카드가 될 수도 있다고 분석했다.</p>



<p>그는 “실제 협상력이 발휘되는 시점은 계약 갱신 과정”이라며 “다음 계약 갱신 때 해석 가능성 보고서 제공과 제3자 감사 접근 권한을 계약 조항에 포함시켜야 한다. 지금은 이러한 조건을 비교적 쉽게 확보할 수 있지만 계약 체결 이후에는 훨씬 큰 비용이 들기 때문”이라고 말했다.</p>



<p>이어 “2027년 신뢰성 확보 경쟁에서 앞서는 CIO는 2026년에 이미 AI 모델 공급업체의 ‘우리를 믿어달라’는 말만 받아들이지 않고, 공급업체가 아직 계약을 더 필요로 하는 시점에 필요한 조항을 계약서에 반영한 사람일 것”이라고 전망했다. <br>dl-ciokorea@foundryco.com</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Shared API keys expose AI agents at 69% of enterprises, new VentureBeat research finds]]></title>
<description><![CDATA[Share one API key across five AI agents, and a single compromised agent inherits the reach of all five. The attacker immediately benefits from the accumulated permissions of every workflow that the key touches. The forensic trail goes cold at the credential level because five agents on one accoun...]]></description>
<link>https://tsecurity.de/de/3658311/it-nachrichten/shared-api-keys-expose-ai-agents-at-69-of-enterprises-new-venturebeat-research-finds/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3658311/it-nachrichten/shared-api-keys-expose-ai-agents-at-69-of-enterprises-new-venturebeat-research-finds/</guid>
<pubDate>Thu, 09 Jul 2026 23:32:38 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Share one API key across five AI agents, and a single compromised agent inherits the reach of all five. The attacker immediately benefits from the accumulated permissions of every workflow that the key touches. The forensic trail goes cold at the credential level because five agents on one account leave no record of which agent did what.</p><p>Sixty-nine percent of enterprises run agents with credential sharing somewhere in their deployments, according to VentureBeat’s June 2026 <a href="https://venturebeat.com/category/resources">Pulse Research</a> wave of 107 enterprises. </p><p>That one number explains the buying spree reshaping enterprise security this year. Palo Alto Networks, CrowdStrike, and Cisco have collectively bet more than $22 billion on it in the past year, targeting exactly the layer most enterprises in this survey haven't finished building. </p><p>Palo Alto Networks completed its acquisition of CyberArk on February 11 for <a href="https://venturebeat.com/security/link">$21.1 billion in total consideration</a> at close — a deal it <a href="https://venturebeat.com/security/link">announced last July at roughly $25 billion</a> and the largest in the company's history.</p><p>CrowdStrike <a href="https://venturebeat.com/security/link">closed its $740 million acquisition</a> of runtime authorization platform SGNL and, by June 15, <a href="https://venturebeat.com/security/link">shipped the first product from the deal, Continuous Identity for AI Agents</a>. CrowdStrike integrated SGNL in less than a year, delivering a product that validates every agent action in real time based on who owns it, who is calling it, and the device's risk posture.</p><p>Cisco <a href="https://venturebeat.com/security/link">announced its intent to acquire</a> non-human identity specialist Astrix Security on May 4 for a reported <a href="https://venturebeat.com/security/link">$400 million</a>.</p><p>For a security director, this survey reads as a board-level question, not a trend line. It also surfaces a finding no competitor’s data shows, one that exposes which companies are the most at risk.</p><p>The data below is the first look at VentureBeat’s Q2 Agentic Security report, drawn from 107 qualified respondents at organizations with more than 100 employees. The full report will be released to attendees at <a href="https://venturebeat.com/vbtransform2026?gad_source=1&amp;gad_campaignid=23980639323&amp;gbraid=0AAAAADnGhh6a1PPkuB60-_ayDUaXOZo3h&amp;gclid=Cj0KCQjwjb3SBhDgARIsAMKiWziNibd4i5buzaXuw91BVLngDsyqVdgLZBQxUTUBkbuWlmUGubj-fMYaAowKEALw_wcB">VB Transform</a>, the event in Menlo Park next week (July 14-15) focusing on enterprise autonomous agents. </p><p>Forty-five percent are final decision-makers for AI purchases. The sample skews mid-market, so read the numbers as the view from organizations adopting agent security right now rather than from the largest enterprises. </p><p>More than half of respondents, 54%, have already had an agent security incident or near-incident. Eighteen percent confirmed an incident, and thirty-six percent caught a near-miss before a breach. Security teams are stopping most of these events at the last control point in the chain, but the rest of the data shows how thin that margin is.</p><h2>Your agents are sharing credentials</h2><p>Only 32% of enterprises give every AI agent its own scoped, managed identity. Nearly half (48%) report that some agents have scoped identities, while many still share credentials. Another 32% say agents mostly run on shared API keys or borrowed human and service-account credentials. The survey question allowed more than one selection, and 24 of the 107 respondents chose multiple options — which is why the three categories sum to 112%. Deduplicated by respondent, 74 organizations, or 69%, flagged credential sharing in at least one answer.</p><p>One number explains why the acquisitions target this layer. A shared credential converts a single compromised agent into many, and <a href="https://www.cyberark.com/press/machine-identities-outnumber-humans-by-more-than-80-to-1-new-report-exposes-the-exponential-threats-of-fragmented-identity-security/">CyberArk's research</a> puts machine identities at 82 for every human in organizations worldwide, with agents as the fastest-growing category of the ratio. Cisco made the same diagnosis when it bought Astrix, whose founders built the company around API keys, service accounts, and OAuth tokens. Cisco’s announcement calls those the credentials AI agents are now “using (and abusing)” to execute work at scale.</p><p>Adam Meyers, senior vice president of counter adversary operations at CrowdStrike, described the mechanism directly in an interview with VentureBeat. Some AI systems have their own identities, he said, and in other cases “people give their identity to the AI to take action on their behalf, and that also further kind of murkies the water and makes it very complex.” The murk is the point, because when the identity is shared, attribution dies with it.</p><h2>Exposure scales with size, and containment does not</h2><p>Forty-nine percent of enterprises enforce scoped permissions at runtime, and 47% monitor and log agent activity, which can help reduce security incidents. Only 30% sandbox their highest-risk agents, the one control that limits blast radius when the first two fail. Isolation is what keeps a single compromised agent from becoming a deployment-wide event. Enterprises have funded detection and resistance, but the containment layer barely exists.</p><p>The sharpest finding in the survey, and the one no vendor report captures, shows up when you split results by company size. The incident rate is 49% for companies with 101 to 1,000 employees, but it shoots up to 63% for companies with more than 1,000. Sandbox isolation moves the other way, falling from 35% to 20% at the larger companies.</p><p>The chart above shows the same finding at finer granularity: the 49%/63% split above is a binary cut at 1,000 employees, while the bars here break incident rate and isolation rate into four size bands. The red line measures incidents and near-misses, and the navy tracks the one control that contains damage after everything else fails. At organizations with 101 to 250 employees, the two sit 7 points apart, but above 5,000, the gap blows out to 60 points. That top band pools the survey's two largest size groups and holds only 15 respondents, so treat the number as directional. Larger enterprises run more agents across more systems, which drives incidents up while sandboxing, the engineering project that would contain them, goes unfunded. The enterprises with the most agents have the least isolation around them.</p><p>The deals target exactly those accounts. Palo Alto Networks, Cisco, and CrowdStrike sell to large enterprises first, where incident rates are highest and containment is the thinnest.</p><h2>Guarded by whoever shipped the model</h2><p>The model providers are the security layer. OpenAI's built-in guardrails lead at 51%. Google Cloud reaches 36%, Microsoft Azure's Purview and Copilot Studio DLP 35%, and Anthropic's managed-agent controls 29%. Eighty-two percent of respondents name a provider-native or hyperscaler control as their single primary agent security layer.</p><p>The purpose-built specialists are in single digits, with Palo Alto Networks' Prisma AIRS at 7%, CrowdStrike at 6%, and Okta for AI Agents at 4%. Zenity and the dedicated non-human identity platforms are at 3% each. Microsoft Entra Agent ID is the highest-penetration identity-specific control in the dataset at 13%, the only one from a hyperscaler, and it still falls outside the top four. Only 5% of enterprises run no dedicated agent tooling at all, and the rest have tooling that came pre-installed.</p><p>Bundled controls lead because they ship free and are enabled by default. Most filter prompts and outputs, but they do not give an agent its own identity or sandbox it. Hyperscalers sell identity-layer products, and Entra Agent ID is in the dataset at 13%, but adoption stays low. The two controls that reward incident data the most, scoped identity and isolation, are the two that the default stack does not include.</p><p>Prompt-and-output filters evaluate whether a call looks malicious. That is an intent problem, and intent cannot be solved at the language layer. CrowdStrike CTO Elia Zaitsev drew the line in an <a href="https://venturebeat.com/security/rsac-2026-agent-identity-frameworks-three-gaps">interview at RSAC 2026</a>. "Observing actual kinetic actions is a structured, solvable problem," Zaitsev said. "Intent is not." CrowdStrike's Falcon sensor walks the process tree on an endpoint and tracks what agents did, not what agents appeared to intend. A scoped identity and an isolation boundary give that sensor something to track, while a shared credential on a bundled guardrail does not.</p><p>Cloud security went through the same cycle a decade ago, and Palo Alto Networks, CrowdStrike, and Wiz built multi-billion-dollar businesses on the gaps native cloud controls left open. Agent security is tracking the same path faster. A misconfigured storage bucket sat open until a human noticed. A misconfigured agent exploits its own over-permissioning on every run, and no human is watching when it does. Merritt Baer, chief security officer at <a href="https://www.enkryptai.com/">Enkrypt AI</a> and a former deputy CISO at AWS, <a href="https://venturebeat.com/security/most-enterprises-cant-stop-stage-three-ai-agent-threats-venturebeat-survey-finds">told VentureBeat</a> that the default layer is thinner than enterprises assume. "Enterprises believe they've 'approved' AI vendors, but what they've actually approved is an interface, not the underlying system," Baer said. "The real dependencies are one or two layers deeper, and those are the ones that fail under stress."</p><h2>Comfortable, unconvinced, and already shopping</h2><p>Here is the contradiction worth a keynote slide. Enterprises rate their agent security tooling 4.2 out of 5, with value for money at 4.1 and ease of implementation at 3.9. Those scores would make most SaaS vendors envious.</p><p>Only 35% believe their AI-enabled defenses are ahead of AI-enabled attackers, while thirty-two percent call it roughly even. Twenty-one percent say attackers lead, and another 21% say it is too early to tell, showing how enterprises trust their tooling more than they trust its outcomes.</p><p>Budgets confirm it. Forty-six percent allocate 6 to 10% of the security budget to agent security, and a full third spend 5% or less. Half the sample has already had an incident or near-miss, but the funding does not match the exposure.</p><p>Fifty-nine percent plan to adopt, add, or replace agent security tooling within 12 months, and twenty-nine percent plan to move this quarter. OpenAI leads forward interest at 34%, followed by Google at 30%, Anthropic at 29%, and Azure at 25%. The dedicated vendors draw more interest looking forward than their current single-digit footprint suggests. Satisfied customers do not reshuffle this fast unless they know the stack they're currently using is provisional.</p><h2><b>Three moves for security directors </b></h2><p><b>1. Inventory every agent’s credentials this quarter.</b> Map which agents share credentials with other agents and which run on borrowed human or service-account identities. The goal is not one credential per agent. Agents that touch multiple systems need multiple scoped identities. The goal is zero shared credentials between agents and zero borrowed human identities. Thirteen percent of surveyed enterprises already run Microsoft Entra Agent ID. Okta for AI Agents and the non-human identity specialists sell equivalents. Shared and borrowed credentials are the first thing to eliminate.</p><p><b>2. Sandbox the riskiest agents first.</b> Isolation is the least-adopted control at 30% and the only one that contains blast radius after prevention fails. Rank agents by the sensitivity of what they touch and isolate the top of the list. Above 1,000 employees, where isolation falls to 20%, this is the single highest-return move in the dataset. Sandboxing does not require replacing the agent or the platform. It requires a policy decision and an isolation layer.</p><p><b>3. Match the budget to the incident rate. </b>A third of enterprises fund agent security at 5% or less of the security budget, even though more than half have already had an incident or near-miss. Nine percent allocate more than 25% today. The full report breaks out exposure and containment by company size, showing which bands carry the most risk and the least protection.</p><p>The board's question is simpler. If one of our AI agents was compromised this afternoon, which systems did it touch, and whose credentials was it holding? For the 69% of enterprises running agents on shared credentials, the answer is a shrug. The trail goes cold at the key.</p><p>The full Q2 Agentic Security report, with the complete vendor matrix, industry cuts, and the full dataset behind these charts, debuts July 14 and 15 at <a href="https://venturebeat.com/vbtransform2026">VB Transform</a>, held at Hotel Nia in Menlo Park. The open question it leaves is whether enterprises close the agent security gap on their own terms, or whether a confirmed breach closes it for them.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[I Wrote a New Book for Corelight]]></title>
<description><![CDATA[TLDR: I wrote a new book for Corelight called NDR Essentials. It's free at that link. This is the 10th book that I've authored or co-authored. The rest are all posted at taosecurity.com.  Why?It was time. 

 
That’s what I thought when I heard that Corelight wanted to 
update its 2021 book on net...]]></description>
<link>https://tsecurity.de/de/3657389/it-security-nachrichten/i-wrote-a-new-book-for-corelight/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3657389/it-security-nachrichten/i-wrote-a-new-book-for-corelight/</guid>
<pubDate>Thu, 09 Jul 2026 16:37:23 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjLD7qvOGj-vysW1oKnpVauXypgCv8nGDkAJ3-ku3GFDTwH2ud2n6fOVAkjfyQlqkWtiuloQi86jC36SFQ6q8RtciyqVGS0J1eJkJNc2_3L1-uiETD82IB7P0py3Xf3ggvbiBGi8rtIVZttdqk8vz1svXuVyt1YYZXCG1sO5VtHwTDEJgkNjCj3/s864/cover.png" imageanchor="1"><img border="0" data-original-height="864" data-original-width="576" height="640" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjLD7qvOGj-vysW1oKnpVauXypgCv8nGDkAJ3-ku3GFDTwH2ud2n6fOVAkjfyQlqkWtiuloQi86jC36SFQ6q8RtciyqVGS0J1eJkJNc2_3L1-uiETD82IB7P0py3Xf3ggvbiBGi8rtIVZttdqk8vz1svXuVyt1YYZXCG1sO5VtHwTDEJgkNjCj3/w426-h640/cover.png" width="426"></a></div><br><div>TLDR: I wrote a new book for Corelight called <a href="https://corelight.com/cp/ndr-essentials">NDR Essentials</a>. It's free at that link. This is the 10th book that I've authored or co-authored. The rest are all posted at <a href="https://www.taosecurity.com/">taosecurity.com</a>. </div><div> </div><div>Why?<span class="hs_cos_wrapper hs_cos_wrapper_meta_field hs_cos_wrapper_type_rich_text" data-hs-cos-general-type="meta_field" data-hs-cos-type="rich_text"><p><span>It was time</span><span>.</span><span> </span></p></span></div><div><span class="hs_cos_wrapper hs_cos_wrapper_meta_field hs_cos_wrapper_type_rich_text" data-hs-cos-general-type="meta_field" data-hs-cos-type="rich_text">

<p><span></span><span> </span></p>
<p><span>That’s what I thought when I heard that Corelight wanted to 
update its 2021 book on network detection and response (NDR). Tamara 
Crawford, who owned the project, scheduled a meeting with me and asked 
if I might be interested in helping, depending on who might write the 
text. </span><span> </span></p>
<p><span></span><span> </span></p>
<p><span>I volunteered immediately to write the whole book, but I had a 
few conditions. The text had to be at least 100 pages long, because 100 
pages is my personal dividing line between “book” and “white paper.” I 
needed the freedom to cover the topics I wanted to address, and to not 
be told what to write. I wanted to show the four network security 
monitoring (NSM) data types working in a vendor-neutral manner, with 
technical details. Finally, I knew this project would take several 
months to research, write, lay out, proofread, and complete. Once 
Corelight agreed, I was ready to begin.</span><span> </span></p>
<p><span></span><span> </span></p>
<p><span>My goal for the book was to show how high-fidelity </span><a href="https://corelight.com/resources/glossary/network-evidence" target="_self"><u><span>network evidence</span></u></a><span>
 can power successful incident detection and response operations. For 
decades, digital security relied on the flawed premise that the “right” 
security controls could stop malicious activity. History, however, has 
repeatedly shown that prevention eventually fails. Victory belongs to 
the defender who accepts that intrusions are inevitable and who 
implements aggressive post-compromise interdiction </span><span>and containment. </span><span> </span></p>
<p><span></span><span> </span></p>
<p><span>Security teams have the best chance to stop an adversary before
 they accomplish their mission when they leverage network security 
monitoring data and the latest </span><a href="https://corelight.com/resources/glossary/ai-driven-soc" target="_self"><u><span>AI and automation assistants</span></u></a><span>. Therefore, this book equips practitioners with the tools and mindsets necessary to hunt through network evidence and diminish </span><a href="https://corelight.com/resources/glossary/attacker-dwell-time" target="_self"><u><span>attacker dwell time</span></u></a><span>. </span><span> </span></p>
<p><span></span><span> </span></p>
<p><strong><span>The book begins </span></strong><span>with a chapter 
that defines risk, threat, vulnerability, and asset value in the context
 of cybersecurity. It explains seven risk management strategies, NDR’s 
role in the security cycle, four sources of situational awareness, the 
importance of time and how to measure it, and a variety of NDR-specific 
topics like where and how to monitor, costs vs. benefits, and the 
difference between </span><a href="https://corelight.com/resources/glossary/network-security-monitoring-nsm" target="_self"><u><span>NSM</span></u></a><span> and </span><a href="https://corelight.com/resources/glossary/ndr-network-detection-and-response" target="_self"><u><span>NDR</span></u></a><span>.</span><span> </span></p>
<p><span></span><span> </span></p>
<p><strong><span>Chapter 2</span></strong><span> is all about the four 
types of NSM data. I show examples of full content data via terminal and
 graphical interfaces, and what it can do for analysts. I briefly 
demonstrate how to obtain and analyze extracted content, then show how 
transaction data can answer many of the key questions asked by security 
analysts. The chapter concludes with alert data, which has become more 
significant in an age of smarter and more precise AI capabilities.</span><span> </span></p>
<p><span></span><span> </span></p>
<p><strong><span>Chapter 3 </span></strong><span>is the first of two 
chapters demonstrating workflows for security investigators. This 
chapter examines how alert data from a sufficiently capable NDR can 
identify suspicious and malicious activity. It includes four cases, 
showing how lateral movement, expired SSL certificates, outbound 
reconnaissance, and malicious remote desktop protocol behavior manifest 
in alerts.</span><span> </span></p>
<p><span></span><span> </span></p>
<p><strong><span>Chapter 4</span></strong><span> presents the other side of investigative workflows, relying on </span><a href="https://corelight.com/resources/glossary/threat-hunting" target="_self"><u><span>threat hunting</span></u></a><span>
 to reveal adversary activity. Properly collected, rendered, and 
displayed NSM data is crucial, because you can’t really hunt without 
high-quality evidence. The chapter includes six cases, showing how file 
name mismatches, unusual downloads, large data transfers, coordinated 
exfiltration, lateral movement, and certificates appear when exposed via
 threat hunting.</span><span> </span></p>
<p><span></span><span> </span></p>
<p><strong><span>Chapter 5 </span></strong><span>explores how artificial
 intelligence and automation technologies are bringing powerful new 
capabilities to security teams. I start by discussing the generation of 
alerts at the edge and at the center, then I share how AI can help with 
investigating suspicious and </span><span>malicious activity. I conclude
 with advice on the best use of agentic triage and how AI will integrate
 with tools while enabling new capabilities.</span><span> </span></p>
<p><span></span><span> </span></p>
<p><span>If you’re a security leader, such as a CISO or director, you’ll
 probably be most interested in Chapters 1 and 5. You should ensure your
 teams have the data described in Chapters 2-4. If you’re a security 
analyst, you’ll probably be most interested in Chapters 2-4, although 
you should be familiar with the concepts and strategies in Chapters 1 
and 5. If you’re familiar with my previous works, you will be happy to 
see that this book has a certain amount of “future-proofing” embedded. I
 did not explain how to install any specific tools, nor did the tools I 
use rely on strict display technologies. All of the examples in Chapter 2
 use open source tools with stable outputs, such as Tshark, Wireshark</span><span><sup><span>®</span></sup></span><span>, Zeek</span><span><sup><span>®</span></sup></span><span>, and Suricata</span><span><sup><span>®</span></sup></span><span>. </span><span> </span></p>
<p><span></span><span> </span></p>
<p><span>I hope readers find the book relevant to their security work 
and a decent introduction to adding NSM data from capable NDRs to their 
investigations. This book is only the beginning of what can be done once
 teams have access to high-fidelity network evidence. If you’d like to 
know more about the book, Vince Stoffer interviewed me for the </span><a href="https://corelight.com/podcasts" target="_self"><u><span>Corelight podcast</span></u></a><span>,
 and that episode will be available on YouTube, Spotify, and Apple 
Podcasts. As I say at the end of every episode, “we will see you on the 
network.” Read </span><a href="https://corelight.com/cp/ndr-essentials" target="_self"><em><u><span>NDR Essentials</span></u></em></a><span> to learn how high-fidelity network evidence can strengthen your security program!</span></p></span></div><div><br></div><div class="blogger-post-footer">Copyright 2003-2020 Richard Bejtlich and TaoSecurity (taosecurity.blogspot.com and www.taosecurity.com)</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Attack on Amazon Bedrock-linked AI gateway highlights new cloud security risk]]></title>
<description><![CDATA[A cloud intrusion that ended with the deployment of cryptomining malware has exposed a bigger risk for enterprises: AI gateways that concentrate access to cloud identities, permissions, and foundation models in a single, highly privileged system.



Researchers from cybersecurity firm Darktrace f...]]></description>
<link>https://tsecurity.de/de/3657126/it-security-nachrichten/attack-on-amazon-bedrock-linked-ai-gateway-highlights-new-cloud-security-risk/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3657126/it-security-nachrichten/attack-on-amazon-bedrock-linked-ai-gateway-highlights-new-cloud-security-risk/</guid>
<pubDate>Thu, 09 Jul 2026 15:08:30 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>A cloud intrusion that ended with the deployment of cryptomining malware has exposed a bigger risk for enterprises: AI gateways that concentrate access to cloud identities, permissions, and foundation models in a single, highly privileged system.</p>



<p>Researchers from cybersecurity firm Darktrace found attackers compromising an AWS EC2 instance acting as a LiteLLM proxy for <a href="https://www.infoworld.com/article/2335005/amazon-bedrock-generative-ai-service-reaches-ga.html">Amazon Bedrock</a>, eventually deploying XMRig cryptomining malware, along with attempts to abuse cloud identities and AI services.</p>



<p>Although the attack ended in cryptomining, researchers said the bigger concern is that AI gateways centralize model access, identities, and cloud privileges, making them valuable targets.</p>



<p>Experts found the attack familiar and consistent with past cloud attack techniques.</p>



<p>“Strip off the AI branding and this is a cloud intrusion pattern we’ve been watching since at least 2018: SSH open to the internet, brute-force attempts, a commodity <a href="https://www.csoonline.com/article/2099039/kinsing-crypto-mining-campaign-targets-75-cloud-native-applications.html">XMRig</a> miner, and repeated connections to a mining pool,” said <a href="https://www.linkedin.com/in/seantmalone/" target="_blank" rel="noreferrer noopener">Sean Malone</a>, CISO at BeyondTrust. “Even the AI-specific angle, stolen credentials probing Bedrock model access, has had a name since 2024: <a href="https://www.csoonline.com/article/3535433/llmjacking-how-attackers-use-stolen-aws-credentials-to-enable-llms-and-rack-up-costs-for-victims.html">LLMjacking</a>.”<br><br>However, Malone agreed with Darktrace researchers on the potential blast radius. “AI gateways concentrate credentials, cloud permissions, and model access into a single choke point, so a routine intrusion lands on a privileged asset,” he explained.</p>



<h2 class="wp-block-heading"><a></a>The attack followed a known pattern</h2>



<p>According to Darktrace, the compromised EC2 instance appeared to support <a href="https://www.csoonline.com/article/4149905/pypi-warns-developers-after-litellm-malware-found-stealing-cloud-and-ci-cd-credentials.html">LiteLLM</a> activity and was associated with an IAM role capable of accessing Amazon Bedrock resources. While researchers could not conclusively determine the initial access vector, they said the attack followed a sequence commonly seen in cloud intrusions.</p>



<p>Before the miner was deployed, the instance had SSH exposed to the internet, with port 22 accessible from anywhere. Darktrace observed a high volume of inbound SSH connection attempts, largely originating from a single external IP address, indicating probable brute-force activity.</p>



<p>Shortly afterward, the host downloaded a ZIP archive containing XMRig cryptomining malware before repeatedly connecting to a known mining pool over HTTPS.</p>



<p>Darktrace stressed that it could not confirm whether the SSH activity directly led to the compromise because host-level logs were unavailable. However, the timing of the SSH exposure, miner download, and subsequent mining-pool communications strongly suggested the EC2 instance had been compromised and repurposed for unauthorized compute activity.</p>



<h2 class="wp-block-heading"><a></a>Compromised AI gateways are a big deal</h2>



<p>The disclosure also detailed suspicious IAM activity observed separately, a day later, by another AWS identity. Among the unusual actions were a “GetSendQuota” API call from an IP address in Vietnam, attempts to enumerate and invoke Amazon Bedrock foundation models, and an effort to create a new IAM user using a randomly generated username.</p>



<p>This behavior is commonly associated with establishing persistence following credential compromise. However, Darktrace could not link the IAM activity directly to the LiteLLM incident.</p>



<p><a href="https://www.linkedin.com/in/jason-soroko-19b41920/" target="_blank" rel="noreferrer noopener">Jason Soroko</a>, senior fellow at Sectigo, said the incident’s significance lies less in the cryptominer than in the system that was compromised.</p>



<p>“These gateways are becoming brokers for identity, model access, prompts, logs, and policy,” he noted. “When one is exposed over SSH or backed by broad IAM permissions, it is no longer just another EC2 instance. It is a control point for AI operations.”</p>



<p>To protect against such attacks, Soroko added, security teams should close public admin paths, remove long-term keys where possible, scope IAM permissions, monitor Bedrock and model access patterns, and correlate workload telemetry with control-plane events. </p>



<p>Darktrace said it helped in the timely containment of the attack. “The cryptomining activity was received by Darktrace’s Managed Threat Detection service and reviewed by Darktrace’s SOC,” the researchers said in a blog post shared with CSO ahead of its <a href="https://www.darktrace.com/blog/when-ai-infrastructure-becomes-part-of-the-attack-surface" target="_blank" rel="noreferrer noopener">publication</a> on Thursday. “Following review, the activity was escalated to the customer. This escalation provided the customer with timely notification of active resource abuse in the AWS environment.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Agentic AI identity: A 6-stage maturity model for non-human identities]]></title>
<description><![CDATA[In a client engagement last year, an LLM-based deployment agent with standing access to a production Kubernetes cluster triggered a four-hour outage through a malformed configuration push. In the IAM, the agent appeared as a service account with a long-lived API key, no MFA, no scoped revocation ...]]></description>
<link>https://tsecurity.de/de/3656659/it-security-nachrichten/agentic-ai-identity-a-6-stage-maturity-model-for-non-human-identities/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3656659/it-security-nachrichten/agentic-ai-identity-a-6-stage-maturity-model-for-non-human-identities/</guid>
<pubDate>Thu, 09 Jul 2026 12:24:02 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>In a client engagement last year, an LLM-based deployment agent with standing access to a production Kubernetes cluster triggered a four-hour outage through a malformed configuration push. In the IAM, the agent appeared as a service account with a long-lived API key, no MFA, no scoped revocation path. When the incident review team asked which human had authorized the agent’s last action, no one in the room could answer. I have watched a version of that question go unanswered in three engagements over the past year, in three different sectors, with three different vendor stacks.</p>



<p>Every CISO deck right now contains a slide about agentic AI. Far fewer contain a slide about who, in identity terms, these agents actually are. That gap is the more dangerous one. The first slide is a strategy question. The second is a control question — and it is the one your auditors, your incident responders and your board will eventually ask. <a href="https://www.gartner.com/en/newsroom/press-releases/2026-02-05-gartner-identifies-the-top-cybersecurity-trends-for-2026">Gartner’s Top Cybersecurity Trends 2026</a>, published by Director Analyst Alex Michaels, names both halves of that gap — agentic AI oversight (Trend 1) and IAM adaptation to AI agents (Trend 4) — as the forces redefining cyber risk this year.</p>



<p>This piece sets out a six-stage maturity model for non-human and agent-based identities (NHIs), the six minimum requirements that have to be met before any production deployment is defensible and the single most consequential reporting decision in the access-and-identity dimension: refusing the arithmetic mean across human and non-human identity governance.</p>



<h2 class="wp-block-heading">Why agent-based systems break the existing identity model</h2>



<p>A conventional service account performs a narrow, predictable task: it fetches a backup, runs a scheduled report, signs a build artifact. Its scope is fixed at design time. The controls around it — rotation, vaulting, audit — are well-understood.</p>



<p>An agent-based system does not work this way. It receives an intent, decomposes it into steps, calls whichever tools or APIs it judges appropriate and produces an outcome that was not specified action-by-action in advance. KuppingerCole’s 2026 Leadership Compass on Non-Human Identity Management notes that NHIs now outnumber human users in many enterprise environments, in some cases by a factor of 25 to 50. The same compass, authored under Principal Analyst Martin Kuppinger, observes that the tooling built around joiner-mover-leaver lifecycles was never designed to discover, attribute or govern these identities at that scale.</p>



<p>The <a href="https://genai.owasp.org/">OWASP GenAI Security Project</a> has catalogued the resulting attack surface in two iterations — the Agentic AI Threats &amp; Mitigations taxonomy in February 2025 and the more operational OWASP Top 10 for Agentic Applications later that year, categories ASI01 through ASI10. The notable finding is that three of the four highest-rated risks are identity questions: tool misuse and exploitation (ASI02), identity and privilege abuse including delegated and inherited trust (ASI03) and rogue agents that act outside their intended behavior (ASI10). A fourth, agentic supply chain vulnerabilities (ASI04), is identity adjacent.</p>



<p>CISA’s first joint Five Eyes advisory on the topic — <a href="https://www.cisa.gov/resources-tools/resources/careful-adoption-agentic-ai-services">Careful Adoption of Agentic AI Services</a>, published 1 May 2026 with NSA, the Australian Signals Directorate’s ACSC, the Canadian Centre for Cyber Security, NCSC-NZ and NCSC-UK — converges on the same conclusion. Privilege risk is named the foundational concern. The Center for Internet Security followed with its own report on prompt injection as the top compounding risk in April 2026, and NIST’s AI Agent Standards Initiative, launched February 2026, is now drafting the formal standards that will sit alongside this guidance.</p>



<p>In other words, the dominant risk class introduced by agentic AI is not novel cryptography or some new exploit primitive. It is the unbounded scope of an identity that the existing IAM model was never asked to govern.</p>



<h2 class="wp-block-heading">Six minimum requirements before any agent goes to production</h2>



<p>Before any maturity discussion is useful, there is a floor. The following six requirements mark the line below which an agent-based system is not responsibly deployable in an enterprise environment. They are derived from incidents and audit findings I have collected across pharma, energy, finance and manufacturing engagements, and they are technically feasible on modern IAM and PAM platforms — though rarely on the IAM stacks most enterprises actually have today.</p>



<ul class="wp-block-list">
<li>Each agent receives a uniquely attributable non-human identity. Shared service accounts across multiple agents, or shared between an agent and a human administrator, are not acceptable.</li>



<li>Permissions are granted under an on-behalf-of model. The agent acts on the authority of a named human principal, inheriting that principal’s permissions, scoped to a defined purpose. It never acts from its own standing authority.</li>



<li>No long-lived credentials. No API key valid for more than an hour. No embedded secrets in code. Short-lived, context-bound credentials only, revocable on anomaly.</li>



<li>Complete audit trail through SIEM integration. Every agent action is logged with timestamp, executing identity, instructing human principal, input context and outcome.</li>



<li>Continuous re-authentication. For long-running agents, identity is re-validated risk-based at regular intervals — not just at session start.</li>



<li>Real-time revocation. The capability to disconnect an agent from systems within seconds is not optional. It is the only control that actually contains an agent-based incident in flight.</li>
</ul>



<p>An organization that cannot meet all six does not have an agent governance problem. It has a deployment readiness problem. The model below assumes these are in place by Stage 3; anything earlier is the discovery phase.</p>



<h2 class="wp-block-heading">The six-stage NHI maturity model</h2>



<p>Most enterprise maturity scales measure the access-and-identity dimension against the yardstick of human identity: is there central IAM, is MFA enforced for privileged access, does the joiner-mover-leaver lifecycle work? These remain the right questions, but they stop short. An organization that scores Stage 4 on human identity governance and Stage 1 on agent governance does not have a mature identity practice. It has a well-lit half and a blind half.</p>



<p>The following six-stage scale is cumulative — each stage assumes everything below it. The threshold of responsibility sits at Stage 3. In my view, production deployment of agent-based systems below Stage 3 is not defensible to a board, a regulator or an incident review.</p>



<figure class="wp-block-table"><div class="overflow-table-wrapper"><table class="has-fixed-layout"><thead><tr><td><strong>Stage</strong></td><td><strong>Label</strong></td><td><strong>Criterion for non-human / agent-based identities</strong></td><td><strong>Audit survivability</strong></td></tr></thead><tbody><tr><td><strong>0</strong></td><td><strong>Unrecognized</strong></td><td>Non-human identities exist but are not in the inventory. Shared service accounts, long-lived keys, no audit trail.</td><td>No — agent activity is invisible to forensics.</td></tr><tr><td><strong>1</strong></td><td><strong>Visible</strong></td><td>Identities are inventoried and assigned to an asset class, but not yet under independent governance.</td><td>No — no per-agent accountability.</td></tr><tr><td><strong>2</strong></td><td><strong>Unique</strong></td><td>Each identity is uniquely attributable (no shared accounts); initial lifecycle rules exist but are applied inconsistently.</td><td>Partial — who acted is answerable; on whose authority is not.</td></tr><tr><td><strong>3</strong></td><td><strong>Controlled</strong></td><td>The six minimum requirements are fully met: on-behalf-of model, short-lived credentials, SIEM audit trail, real-time revocation.</td><td>Yes — minimum defensible posture.</td></tr><tr><td><strong>4</strong></td><td><strong>Bounded and monitored</strong></td><td>The agent’s action is bounded; every action is reviewable and — where the process allows — reversible. Agent activity metrics are evaluated, not just collected.</td><td>Yes — containment is provable.</td></tr><tr><td><strong>5</strong></td><td><strong>Self-regulating</strong></td><td>Anomalies in agent behavior are detected automatically and trigger risk-based pause or revocation. Each agent has a named accountable owner.</td><td>Yes — state of the art.</td></tr></tbody></table> </div></figure>



<p>Stages 4 and 5 deserve unpacking because they are where the model departs from access control and begins to govern behavior. Bounded means the agent’s mandate has explicit limits it cannot act outside of. Reviewable means every action is logged with intent, execution and result. Reversible means an action can be rolled back before it produces irreversible effect — a hard constraint in any environment where actions touch physical processes, financial transactions or external commitments. Self-regulating means the system detects anomalies in agent behavior and intervenes before a human reasonably could.</p>



<h2 class="wp-block-heading">The ‘human in the loop’ is not automatically governance</h2>



<p>One misconception consistently overrates organizations’ agent governance. The presence of a human in the decision loop is widely treated as sufficient oversight. It is not. If a human is asked to approve hundreds or thousands of agent actions without the time to inspect each one, what exists is not control but an approval automation with a human signature on it. Human review does not scale to the action volume of an autonomous system.</p>



<p>A mature governance posture acknowledges this. It moves control from per-action approval to structural constraint: bound what the agent can do at all, monitor its behavior for anomaly and ensure that oversight is loyal to the principal, not to the executing system. An organization that rests its agent governance entirely on human per-action approvals does not reach Stage 4 of the model, regardless of how thoroughly those approvals are documented. Stage 4 requires structural bounding, not scaling handwork.</p>



<h2 class="wp-block-heading">OWASP as an audit-ready evidence base</h2>



<p>Maturity assessment risks drifting into subjective self-rating. The OWASP categories cited above can be operationalized into audit questions that anchor each stage in checkable evidence:</p>



<figure class="wp-block-table"><div class="overflow-table-wrapper"><table class="has-fixed-layout"><thead><tr><td><strong>OWASP attack surface (Top 10 for agentic applications)</strong></td><td><strong>Audit question for maturity assessment</strong></td><td><strong>Met from stage</strong></td></tr></thead><tbody><tr><td>ASI03 — Identity and privilege abuse</td><td>Does each agent have a unique identity, with no shared accounts?</td><td><strong>2</strong></td></tr><tr><td>ASI02 — Tool misuse and exploitation</td><td>Are the interfaces an agent is permitted to use explicitly bounded?</td><td><strong>4</strong></td></tr><tr><td>ASI01 — Goal hijack</td><td>Is each agent’s mandate clearly bounded and protected against manipulation?</td><td><strong>4</strong></td></tr><tr><td>ASI04 — Agentic supply chain vulnerability</td><td>Is the agent’s software composition documented via SBOM?</td><td><strong>4</strong></td></tr><tr><td>ASI10 — Rogue agent</td><td>Are anomalies in agent behavior detected and routed to pause or revoke?</td><td><strong>5</strong></td></tr></tbody></table> </div></figure>



<p>The column on the right matters. A common rating error is to grade an organization high because it has handled the easy requirements — unique identities, basic logging — without addressing the demanding ones. Tying the upper stages to the difficult criteria prevents that inflation.</p>



<h2 class="wp-block-heading">Report human and non-human identity separately</h2>



<p>The single most consequential reporting decision is to refuse the arithmetic mean. The access-and-identity dimension on a maturity radar should not collapse a Stage 4 human-identity practice and a Stage 1 agent-identity practice into a reassuring middle number. Both ratings belong on the same axis, but they belong reported separately.</p>



<p>A representative finding from current engagements: human identity governance at Stage 4 — central IAM, MFA, lifecycle managed — and agent governance at Stage 1, with agents recently inventoried but still authenticating via long-lived API keys against shared service accounts, without their own audit trail. The combined average would read Stage 2 to 3 and look acceptable. The separate reporting reveals that the unmanaged half is precisely the identity class with the largest and least predictable scope of action. That visibility is what triggers the prioritized roadmap action; an aggregated score buries it.</p>



<h2 class="wp-block-heading">The named-accountable-owner test</h2>



<p>If I run only one diagnostic in a new engagement, this is the one. For every production agent-based system in the environment, ask: who, by name, is accountable if this agent causes harm? An agent without a named accountable owner is the non-human counterpart of the workstation everyone uses, and no one owns. Stage 5 of the model formally requires a named accountable owner per deployed agent. The reason is operational, not bureaucratic: the question ‘who is responsible for this system?’ must be answered before the incident, not during it.</p>



<p>In practice, that accountability binds best to the role that already carries the operational risk of the affected process — typically the asset owner in the business function. Anchoring it there prevents agent-based systems from drifting into the organizational gray zone between IT, security and the business, which is exactly where unattributed action originates.</p>



<p>The maturity model in this article is a starting structure. The honest first step in adopting it is not to score well. It is to score truthfully, report human and non-human identity governance separately and treat the gap between them as the first item on the security roadmap for the agentic-AI period — before the next agent goes to production.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.csoonline.com/expert-contributor-network/">Want to join?</a></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Three keys to deploying AI agents]]></title>
<description><![CDATA[Building an agent in an afternoon is now within reach of almost anyone in the enterprise with a credit card. The tools are accessible, the deployments are easy. The hard part is delivering the intended results.



Gartner predicts that more than 40% of agentic AI projects will be canceled by 2027...]]></description>
<link>https://tsecurity.de/de/3656433/ai-nachrichten/three-keys-to-deploying-ai-agents/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3656433/ai-nachrichten/three-keys-to-deploying-ai-agents/</guid>
<pubDate>Thu, 09 Jul 2026 11:03:34 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Building an agent in an afternoon is now within reach of almost anyone in the enterprise with a credit card. The tools are accessible, the deployments are easy. The hard part is delivering the intended results.</p>



<p>Gartner predicts that more than <a href="https://www.gartner.com/en/newsroom/press-releases/2025-06-25-gartner-predicts-over-40-percent-of-agentic-ai-projects-will-be-canceled-by-end-of-2027">40% of agentic AI projects will be canceled</a> by 2027, and the <a href="https://artificialintelligenceact.eu/article/14/">EU AI Act Article 14</a> requirements for human oversight for high-risk AI systems take effect on August 2, 2026. The deciding factor for whether agentic AI reaches production isn’t the model, the framework, or the use case. It’s the infrastructure beneath the agent: the part the people building agents have never had to think about.</p>



<p>Organizations are racing to deploy agentic AI to stay competitive, which means pressure-testing is often overlooked. Every agent project should be scrutinized by three executives asking three different sets of questions. The CISO asks whether we are exposed. The CFO asks whether we are overspending. The chief AI officer asks whether we are getting value. </p>



<p>As a product leader focused on AI governance, I see this pattern across customer environments. Three architecture layers answer those three questions: identity, observability, and cost optimization. I’ll walk through each of the layers and provide a four-question diagnostic for the next production push.</p>



<h2 class="wp-block-heading">Why AI pilots stall</h2>



<p>An agent is not a faster chatbot. It chains dozens of steps, calls external tools, retains state across sessions, and triggers real-world actions. Most inherit the credentials of whoever deployed them. They operate at machine speed without context for the consequences of each step.</p>



<p>The mismatch is not a competence gap on the human side. It is a time-horizon gap. An engineer reasons about a database change over hours. An agent triggers a hundred of them before anyone reviews the first. Traditional audit logging captures request and response. That does not catch this pattern.</p>



<p>When something breaks, the cost is rarely the incident. It is the months of stalled deployment that follow. The risk committee freezes pilots. The productivity gains the program was supposed to deliver never materialize. Finance still gets the API bill. Three architecture layers decide whether a deployment survives that pattern. Each one is the answer to a question the people building agents never had to ask.</p>



<h2 class="wp-block-heading">Layer 1: Identity for non-human actors</h2>



<p>Start with identity. The default failure looks routine: a product manager with broad API access spawns an agent that inherits the full scope of those credentials and runs at machine speed across systems no one inventoried.</p>



<p>The scale is bigger than most teams realize. <a href="https://www.signisys.com/blog/non-human-identities-outnumber-users-100-to-1-the-cloud-security-crisis-no-one-is-talking-about/">Industry IAM research</a> puts non-human identities at more than 100 to 1 versus human accounts, with <a href="https://www.cybersecuritytribe.com/news/research-reveals-44-growth-in-nhis-from-2024-to-2025">some 2026 surveys</a> putting the ratio as high as 144 to 1. A <a href="https://www.orchid.security/reports/the-identity-gap-2026-snapshot-identity-insight-straight-from-the-source">May 2026 Identity Gap Report</a> found two-thirds are unseen and unmanaged.</p>



<p>Agents are moving from human identities with their “owners”’ permissions to first-class principals. They are purpose-bound, cryptographically attested, and scoped to one task at a time. Google’s Agent Identity, built on SPIFFE, is one early example. The production pattern has three properties. Credentials are issued per agent task. Token lifetime is measured in minutes to hours, not weeks. Scope is narrowed to the specific tools and data classes the task requires, and the credential revokes automatically on task completion.</p>



<p>If a single static credential is good for a week and 50 different tasks, you are not running agentic AI. You are running a service account with extra steps.</p>



<h2 class="wp-block-heading">Layer 2: Observability that serves all three executives</h2>



<p>Identity controls what an agent can do. Observability shows what it’s actually doing. One instrumentation layer, three views.</p>



<p>First, the security view. Traditional logging captures request and response, which assumes one human action per logged event. An agent’s unit of work is a chain. Pick a tool, call it, read the result, decide the next step. Twenty steps, some of them writing to production. Instrument every step as a durable audit object, independently queryable. Understand which tool was invoked, what data was accessed, what policy applied, and what the agent reasoned to justify the next step. That’s what Article 14 oversight requires for production.</p>



<p>Second, the business-outcomes view. Audit objects answer the CISO. The chief AI officer asks a different question. Is the agent accomplishing what we deployed it for, or burning compute on a tangent? An agent can run 200 tool calls, generate clean audit logs, and produce nothing. It might be looping on a sub-goal that drifted three steps back. Observe each step against the declared business purpose: on-task ratio, sub-goal coherence, progress markers. Project management telemetry for a non-human worker.</p>



<p>Third, the cost view. The same per-step instrumentation produces cost telemetry: token count per step, model per call, context size per turn, downstream tool-call costs. Without that attribution, the next section’s optimizations are blind.</p>



<p>A busy agent and a productive agent look identical in the security log. They look identical on the bill too. The difference shows up only when all three views run from the same instrumentation.</p>



<h2 class="wp-block-heading">Layer 3: Cost optimization</h2>



<p>Cost is where the architecture pays back. Gartner’s March 2026 analysis put <a href="https://www.gartner.com/en/newsroom/press-releases/2026-03-25-gartner-predicts-that-by-2030-performing-inference-on-an-llm-with-1-trillion-parameters-will-cost-genai-providers-over-90-percent-less-than-in-2025">agentic workloads at five to 30 times the token cost per task</a> of a standard chatbot. The FinOps Foundation’s 2026 State of FinOps report found that <a href="https://data.finops.org/">73% of organizations exceeded their original AI budget projections</a>. Three failure modes drive that overrun.</p>



<p>First, using the wrong model. Agents default to the most capable one available. They call a frontier model for tasks a smaller one could handle with identical quality: summarizing a transcript, formatting JSON, classifying a ticket. The <a href="https://proceedings.iclr.cc/paper_files/paper/2025/hash/5503a7c69d48a2f86fc00b3dc09de686-Abstract-Conference.html">RouteLLM paper at ICLR 2025</a> demonstrated that intelligent routing cuts total LLM inference cost 40% to 80% with no measurable quality loss on routine work. Move model selection from a per-developer choice to a per-policy layer.</p>



<p>Second, running in loops. Agents can spend without limit if no one is watching. A widely-cited 2026 incident saw a <a href="https://dev.to/dingdawg/how-an-ai-agent-ran-up-a-47000-bill-in-11-days-and-how-to-stop-it-1fk">LangChain multi-agent system run an infinite loop for 11 days and burn $47,000 in API charges</a>. Per-session token ceilings, <a href="https://fountaincity.tech/resources/blog/ai-agent-cost-circuit-breaker/">loop-detection circuit breakers</a> that flag tool calls highly similar to prior calls, and hard daily caps stop this before it generates the bill. In our deployments, a <a href="https://www.supra-wall.com/en/learn/ai-agent-runaway-costs">three-tier cost structure</a> catches the bulk of runaway patterns: a $50 daily soft alert, a $100 daily hard cutoff forcing routing to cheaper models, and a $1,000 monthly ceiling requiring manager approval.</p>



<p>Third, re-paying for the same context on every step. Every step re-sends the accumulated system prompt and conversation history. By step 20 the agent has paid for that context 20 times. <a href="https://www.vantage.sh/blog/agentic-coding-costs">Vantage’s 2026 analysis of agentic coding sessions</a> found re-sent context accounts for roughly 62% of the average agent’s bill, the biggest single optimization target in agentic workloads. Three patterns help: anchored summarization at phase boundaries, sliding context windows, and provider-native prompt caching at the gateway. Most agents skip caching entirely, though <a href="https://platform.claude.com/docs/en/build-with-claude/prompt-caching">Anthropic</a> prices cached input at roughly 10% of base, <a href="https://developers.googleblog.com/en/gemini-2-5-models-now-support-implicit-caching/">Gemini</a> at 10% to 25%, and <a href="https://openai.com/index/api-prompt-caching/">OpenAI</a> at 50%.</p>



<p>Governing agent cost means seeing every call, every model, every token attributed to the agent and the business purpose. Then act on it. Token counts without business attribution tell you how many gallons of gas you burned, not where you drove.</p>



<h2 class="wp-block-heading">The deployment velocity payoff</h2>



<p>The three layers serve the three executive questions. Identity gates what the agent can do. Observability shows what it is doing. Cost optimization controls what it spends.</p>



<p>The honest counterargument is that governance always slows deployment. That is true when governance is bolted on as approval gates layered over an agent that wasn’t built with observability or per-task identity. It is false when governance is built into the architecture from day one. Teams that experience governance as a brake installed the brake without the steering wheel.</p>



<p>Governance built right still costs something. Per-task credentials add work on every tool call. Observability infrastructure adds compute. The question is whether that cost beats the alternative.</p>



<p>The layers compound. Identity without observability is theoretical. Observability without cost control is descriptive. Without identity at the bottom, cost control becomes caps without context, forever reactive. All three together produce a governance review that runs in weeks, not quarters, because the data each executive needs already exists. In our experience, organizations with that infrastructure can deploy six workflows to production in the time competitors complete one governance review. The real ROI of agentic AI is not how much faster a single workflow runs. In practice, it’s how many workflows your team can defensibly put into production in a year.</p>



<h2 class="wp-block-heading">Before the next pilot</h2>



<p>Here are four questions to run against any agent your team is about to push to production:</p>



<ol class="wp-block-list">
<li>Identity. For each agent in production, can you point to the per-task credentials it uses today, and the maximum scope of any single token?</li>



<li>Observability. For any agent session, can you produce three views from the same instrumentation: the audit object per step, the on-task ratio versus tangents, and the per-step cost broken down by model and context size?</li>



<li>Cost optimization. Does your platform automatically route by model, cap runaway loops, and avoid re-sending the same context every step?</li>



<li>Velocity. How long does it take a new agent workflow to move from approved pilot to production in your environment today?</li>
</ol>



<p>If the answer is months, the architecture above is the gap. Gartner’s 40% stat is about your next pilot.</p>



<p><em>—</em></p>



<p><a href="https://www.infoworld.com/blogs/new-tech-forum"><strong><em>New Tech Forum</em></strong></a><em><strong> provides a venue for technology leaders—including vendors and other outside contributors—to explore and discuss emerging enterprise technology in unprecedented depth and breadth. The selection is subjective, based on our pick of the technologies we believe to be important and of greatest interest to InfoWorld readers. InfoWorld does not accept marketing collateral for publication and reserves the right to edit all contributed content. Send all </strong></em><em><strong>inquiries to </strong></em><a href="mailto:doug_dineley@foundryco.com"><strong><em>doug_dineley@foundryco.com</em></strong></a><em><strong>.</strong></em></p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[IT Security News Hourly Summary 2026-07-08 21h : 6 posts]]></title>
<description><![CDATA[6 posts were published in the last hour 18:35 : DuckDuckGo Now Blocks Most YouTube Ads Right Inside Its Browser 18:35 : Accenture Confirms Cyber Breach as Hacker Lists Alleged Company Data 18:16 : CISO’s guide to hiring for the…
Read more →
The post IT Security News Hourly Summary 2026-07-08 21h ...]]></description>
<link>https://tsecurity.de/de/3655255/it-security-nachrichten/it-security-news-hourly-summary-2026-07-08-21h-6-posts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3655255/it-security-nachrichten/it-security-news-hourly-summary-2026-07-08-21h-6-posts/</guid>
<pubDate>Wed, 08 Jul 2026 21:08:25 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>6 posts were published in the last hour 18:35 : DuckDuckGo Now Blocks Most YouTube Ads Right Inside Its Browser 18:35 : Accenture Confirms Cyber Breach as Hacker Lists Alleged Company Data 18:16 : CISO’s guide to hiring for the…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/it-security-news-hourly-summary-2026-07-08-21h-6-posts/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/it-security-news-hourly-summary-2026-07-08-21h-6-posts/">IT Security News Hourly Summary 2026-07-08 21h : 6 posts</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CISO’s guide to hiring for the right cybersecurity skills]]></title>
<description><![CDATA[The cybersecurity talent crisis has moved from a simple numbers problem to a fundamental mismatch between what organizations need and what the workforce can deliver. While 87% of organizations plan to expand their security teams this year, according to Fortinet…
Read more →
The post CISO’s guide ...]]></description>
<link>https://tsecurity.de/de/3655194/it-security-nachrichten/cisos-guide-to-hiring-for-the-right-cybersecurity-skills/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3655194/it-security-nachrichten/cisos-guide-to-hiring-for-the-right-cybersecurity-skills/</guid>
<pubDate>Wed, 08 Jul 2026 20:37:55 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>&lt;p&gt;The cybersecurity talent crisis has moved from a simple numbers problem to a fundamental mismatch between what organizations need and what the workforce can deliver.&lt;/p&gt; &lt;p&gt;While 87% of organizations plan to expand their security teams this year, according to Fortinet…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/cisos-guide-to-hiring-for-the-right-cybersecurity-skills/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/cisos-guide-to-hiring-for-the-right-cybersecurity-skills/">CISO’s guide to hiring for the right cybersecurity skills</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CISO's guide to hiring for the right cybersecurity skills]]></title>
<description><![CDATA[The cybersecurity talent gap won't be solved by head count alone. CISOs need to fundamentally rethink how they recruit, how they retain talent and what skills they really need.]]></description>
<link>https://tsecurity.de/de/3655093/it-security-nachrichten/cisos-guide-to-hiring-for-the-right-cybersecurity-skills/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3655093/it-security-nachrichten/cisos-guide-to-hiring-for-the-right-cybersecurity-skills/</guid>
<pubDate>Wed, 08 Jul 2026 19:53:24 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The cybersecurity talent gap won't be solved by head count alone. CISOs need to fundamentally rethink how they recruit, how they retain talent and what skills they really need.]]></content:encoded>
</item>
<item>
<title><![CDATA[Orbia CISO Miranda Ritchie on building security into sustainable infrastructure]]></title>
<description><![CDATA[In this interview with Help Net Security, Miranda Ritchie, industrial cybersecurity, CISO at Orbia, talks about protecting industrial systems where software runs water, chemical and manufacturing processes. She explains why a cyber incident in these settings can harm people, equipment…
Read more ...]]></description>
<link>https://tsecurity.de/de/3653662/it-security-nachrichten/orbia-ciso-miranda-ritchie-on-building-security-into-sustainable-infrastructure/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3653662/it-security-nachrichten/orbia-ciso-miranda-ritchie-on-building-security-into-sustainable-infrastructure/</guid>
<pubDate>Wed, 08 Jul 2026 10:20:22 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>In this interview with Help Net Security, Miranda Ritchie, industrial cybersecurity, CISO at Orbia, talks about protecting industrial systems where software runs water, chemical and manufacturing processes. She explains why a cyber incident in these settings can harm people, equipment…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/orbia-ciso-miranda-ritchie-on-building-security-into-sustainable-infrastructure/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/orbia-ciso-miranda-ritchie-on-building-security-into-sustainable-infrastructure/">Orbia CISO Miranda Ritchie on building security into sustainable infrastructure</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[IT Security News Hourly Summary 2026-07-08 09h : 8 posts]]></title>
<description><![CDATA[8 posts were published in the last hour 6:43 : Indian Income Tax Department Phishing Lure Deploys Gh0st RAT and AsyncRAT Implants 6:40 : Orbia CISO Miranda Ritchie on building security into sustainable infrastructure 6:38 : CISA Adds 4 Actively…
Read more →
The post IT Security News Hourly Summar...]]></description>
<link>https://tsecurity.de/de/3653660/it-security-nachrichten/it-security-news-hourly-summary-2026-07-08-09h-8-posts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3653660/it-security-nachrichten/it-security-news-hourly-summary-2026-07-08-09h-8-posts/</guid>
<pubDate>Wed, 08 Jul 2026 10:20:20 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>8 posts were published in the last hour 6:43 : Indian Income Tax Department Phishing Lure Deploys Gh0st RAT and AsyncRAT Implants 6:40 : Orbia CISO Miranda Ritchie on building security into sustainable infrastructure 6:38 : CISA Adds 4 Actively…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/it-security-news-hourly-summary-2026-07-08-09h-8-posts/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/it-security-news-hourly-summary-2026-07-08-09h-8-posts/">IT Security News Hourly Summary 2026-07-08 09h : 8 posts</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI agents fall for indirect prompt injection traps]]></title>
<description><![CDATA[Some autonomous AI agents fell victim to frauds, reinforcing how easily some high-end enterprise agents can be conned by schemes that would fool few, if any, humans, Zscaler found in a test of major LLMs.



The security vendor looked at various forms of indirect prompt injection (IPI) traps and ...]]></description>
<link>https://tsecurity.de/de/3653554/it-security-nachrichten/ai-agents-fall-for-indirect-prompt-injection-traps/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3653554/it-security-nachrichten/ai-agents-fall-for-indirect-prompt-injection-traps/</guid>
<pubDate>Wed, 08 Jul 2026 09:37:30 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Some autonomous AI agents fell victim to frauds, reinforcing how easily some high-end enterprise agents can be conned by schemes that would fool few, if any, humans, Zscaler found in a test of major LLMs.</p>



<p>The security vendor looked at various forms of indirect prompt injection (IPI) traps and found that, whereas many models fell victim to the schemes, some of the lower-level LLMs fared better than their pricier siblings. </p>



<p>The Zscaler testing found, <a href="https://www.zscaler.com/sites/default/files/images/page/figure-16---ipi.jpg" target="_blank" rel="noreferrer noopener">for example</a>, that four models were found to be “vulnerable”: Llama3-3-70b-instruct; Llama3-2-90b-instruct; Gemini-3-flash; and Gemini-2.5-pro. Three models were found to be “safe”: Llama4-maverick; Gemini-3.1-pro; and Gemini-3.1-flash-lite. Those results indicated that the scam resistance of Gemini-2.5-pro was seemingly weaker than that of Gemini-3.1-flash-lite. </p>



<p>But <a href="https://www.linkedin.com/in/noah-m-kenney-27499a166/" target="_blank" rel="noreferrer noopener">Noah Kenney</a>, principal consultant at Digital 520, said that there is not necessarily any valuable takeaway from that revelation, because agents constantly change behavior as they feed on new data and revise their analyzed assumptions. That means an agent that failed a specific test might very well pass the identical test an hour later, he said. </p>



<p>“The risk of an agent is constantly changing and that can cause vastly different results. You can’t assume the results are generalizable. The test result is only at one point in time,” Kenney pointed out. Zscaler “is trying to prove a point that I don’t think the data necessarily proves.”</p>



<p>Kenney added that having a clean “safe/vulnerable” classification is too simplistic to be useful. “That’s a binary classification. I would never recommend to a CISO to do a binary classification.”</p>



<p>The <a href="https://www.zscaler.com/blogs/security-research/indirect-prompt-injection-web-content-targets-ai-agents" target="_blank" rel="noreferrer noopener">full ZScaler blog post</a> argued that many autonomous agents are susceptible to IPI traps.</p>



<p>The company said it identified IPI embedded in multiple websites, where hidden instructions were designed to manipulate the behavior of an AI agent. </p>



<p>In its internal validation across 26 LLMs, 4 models “failed to take appropriate actions,” which, it said, demonstrated “measurable real-world impact, showing that susceptibility varies by model and by the context provided to the LLM alongside the prompt.”</p>



<p>The post added, “as AI agents become a more common interface to the web, the content itself is going to become a larger attack surface, highlighting that AI is a double-edged sword that can streamline workflows while also introducing new avenues for abuse.”</p>



<p><a href="https://www.linkedin.com/in/akm76/" target="_blank" rel="noreferrer noopener">Aman Mahapatra</a>, chief strategy officer for Tribeca Softtech, a New York City-based technology consulting firm, said that although the results are not surprising, they are significant. </p>



<p>The especially worrisome detail in the report is that any commercial LLM failed at all, “because the security model for agentic AI has historically assumed that model-level safety training would meaningfully attenuate this class of attack,” Mahapatra said. “It does not, and the Zscaler data is the first widely-cited public evidence.”</p>



<h2 class="wp-block-heading">A fundamental architecture issue</h2>



<p>Mahapatra also said that the examples cited by Zscaler are not nearly as concerning as the implications of the greater damage that could occur.</p>



<p>“The Zscaler payment scam scenario, where an agent pays a fake $3 ‘developer license fee’ to obtain an API key, is the most benign version of this,” he said. “The same technique applied to an agent authorized for procurement, expense processing, vendor onboarding, or trade execution produces losses at completely different scales. I have watched Fortune 50 banks stand up agentic workflows in the last six months that would fail exactly this attack in a live examination.”</p>



<p>Indeed, he noted, most AI vendors already understand the magnitude of risk from today’s AI agents.</p>



<p>“Every model provider will admit privately that the fundamental architecture of transformer-based reasoning cannot cleanly separate untrusted content from trusted instructions when both share the context window,” Mahapatra said. “The attack surface is architectural, not just behavioral. That means the defense has to be architectural too, and this is where the enterprise agentic AI conversation is still lagging badly.”</p>



<p>Zscaler’s testing also reinforced the difference in how AI agents and humans process information.</p>



<p>“Humans are skeptical of instructions they did not expect. Agents are eager to follow structured metadata because their training rewards them for treating high-signal fields as authoritative. Humans notice when a payment request appears in the middle of an unrelated task. Agents will thread that payment request into their execution plan if the surrounding context frames it as procedurally necessary,” Mahapatra pointed out, noting that while humans have relationships with vendors, memories of prior interactions, and social context to give them verification signals, agents only have what is in the context window, and, he said, “the context window is now the primary attack surface.”</p>



<p><a href="https://www.infotech.com/profiles/fritz-jean-louis" target="_blank" rel="noreferrer noopener">Fritz Jean-Louis</a>, principal cybersecurity advisor at Info-Tech Research Group, agreed that the risks described in the ZScaler post are concerning, because they are in areas not traditionally addressed by enterprise security.</p>



<p>“These attacks differ from traditional threats in that they target how AI systems process, interpret, and act on information behind the scenes,” Jean-Louis said. “Agentic AI introduces new trust boundaries, including untrusted content influencing automated decision making, tools and plugins acting autonomously on behalf of users, and AI systems operating with broad, inherited permissions. This effectively transforms the challenge into an insider threat paradigm.”</p>



<p><em>This article originally appeared on <a href="https://www.infoworld.com/article/4193403/zscaler-finds-autonomous-agents-succumb-to-ipi-traps.html" target="_blank">InfoWorld.</a></em></p>



<p></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI agents fall for indirect prompt injection traps]]></title>
<description><![CDATA[Some autonomous AI agents fell victim to frauds, reinforcing how easily some high-end enterprise agents can be conned by schemes that would fool few, if any, humans, Zscaler found in a test of major LLMs.



The security vendor looked at various forms of indirect prompt injection (IPI) traps and ...]]></description>
<link>https://tsecurity.de/de/3653549/ai-nachrichten/ai-agents-fall-for-indirect-prompt-injection-traps/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3653549/ai-nachrichten/ai-agents-fall-for-indirect-prompt-injection-traps/</guid>
<pubDate>Wed, 08 Jul 2026 09:33:27 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Some autonomous AI agents fell victim to frauds, reinforcing how easily some high-end enterprise agents can be conned by schemes that would fool few, if any, humans, Zscaler found in a test of major LLMs.</p>



<p>The security vendor looked at various forms of indirect prompt injection (IPI) traps and found that, whereas many models fell victim to the schemes, some of the lower-level LLMs fared better than their pricier siblings. </p>



<p>The Zscaler testing found, <a href="https://www.zscaler.com/sites/default/files/images/page/figure-16---ipi.jpg" target="_blank" rel="noreferrer noopener">for example</a>, that four models were found to be “vulnerable”: Llama3-3-70b-instruct; Llama3-2-90b-instruct; Gemini-3-flash; and Gemini-2.5-pro. Three models were found to be “safe”: Llama4-maverick; Gemini-3.1-pro; and Gemini-3.1-flash-lite. Those results indicated that the scam resistance of Gemini-2.5-pro was seemingly weaker than that of Gemini-3.1-flash-lite. </p>



<p>But <a href="https://www.linkedin.com/in/noah-m-kenney-27499a166/" target="_blank" rel="noreferrer noopener">Noah Kenney</a>, principal consultant at Digital 520, said that there is not necessarily any valuable takeaway from that revelation, because agents constantly change behavior as they feed on new data and revise their analyzed assumptions. That means an agent that failed a specific test might very well pass the identical test an hour later, he said. </p>



<p>“The risk of an agent is constantly changing and that can cause vastly different results. You can’t assume the results are generalizable. The test result is only at one point in time,” Kenney pointed out. Zscaler “is trying to prove a point that I don’t think the data necessarily proves.”</p>



<p>Kenney added that having a clean “safe/vulnerable” classification is too simplistic to be useful. “That’s a binary classification. I would never recommend to a CISO to do a binary classification.”</p>



<p>The <a href="https://www.zscaler.com/blogs/security-research/indirect-prompt-injection-web-content-targets-ai-agents" target="_blank" rel="noreferrer noopener">full ZScaler blog post</a> argued that many autonomous agents are susceptible to IPI traps.</p>



<p>The company said it identified IPI embedded in multiple websites, where hidden instructions were designed to manipulate the behavior of an AI agent. </p>



<p>In its internal validation across 26 LLMs, 4 models “failed to take appropriate actions,” which, it said, demonstrated “measurable real-world impact, showing that susceptibility varies by model and by the context provided to the LLM alongside the prompt.”</p>



<p>The post added, “as AI agents become a more common interface to the web, the content itself is going to become a larger attack surface, highlighting that AI is a double-edged sword that can streamline workflows while also introducing new avenues for abuse.”</p>



<p><a href="https://www.linkedin.com/in/akm76/" target="_blank" rel="noreferrer noopener">Aman Mahapatra</a>, chief strategy officer for Tribeca Softtech, a New York City-based technology consulting firm, said that although the results are not surprising, they are significant. </p>



<p>The especially worrisome detail in the report is that any commercial LLM failed at all, “because the security model for agentic AI has historically assumed that model-level safety training would meaningfully attenuate this class of attack,” Mahapatra said. “It does not, and the Zscaler data is the first widely-cited public evidence.”</p>



<h2 class="wp-block-heading">A fundamental architecture issue</h2>



<p>Mahapatra also said that the examples cited by Zscaler are not nearly as concerning as the implications of the greater damage that could occur.</p>



<p>“The Zscaler payment scam scenario, where an agent pays a fake $3 ‘developer license fee’ to obtain an API key, is the most benign version of this,” he said. “The same technique applied to an agent authorized for procurement, expense processing, vendor onboarding, or trade execution produces losses at completely different scales. I have watched Fortune 50 banks stand up agentic workflows in the last six months that would fail exactly this attack in a live examination.”</p>



<p>Indeed, he noted, most AI vendors already understand the magnitude of risk from today’s AI agents.</p>



<p>“Every model provider will admit privately that the fundamental architecture of transformer-based reasoning cannot cleanly separate untrusted content from trusted instructions when both share the context window,” Mahapatra said. “The attack surface is architectural, not just behavioral. That means the defense has to be architectural too, and this is where the enterprise agentic AI conversation is still lagging badly.”</p>



<p>Zscaler’s testing also reinforced the difference in how AI agents and humans process information.</p>



<p>“Humans are skeptical of instructions they did not expect. Agents are eager to follow structured metadata because their training rewards them for treating high-signal fields as authoritative. Humans notice when a payment request appears in the middle of an unrelated task. Agents will thread that payment request into their execution plan if the surrounding context frames it as procedurally necessary,” Mahapatra pointed out, noting that while humans have relationships with vendors, memories of prior interactions, and social context to give them verification signals, agents only have what is in the context window, and, he said, “the context window is now the primary attack surface.”</p>



<p><a href="https://www.infotech.com/profiles/fritz-jean-louis" target="_blank" rel="noreferrer noopener">Fritz Jean-Louis</a>, principal cybersecurity advisor at Info-Tech Research Group, agreed that the risks described in the ZScaler post are concerning, because they are in areas not traditionally addressed by enterprise security.</p>



<p>“These attacks differ from traditional threats in that they target how AI systems process, interpret, and act on information behind the scenes,” Jean-Louis said. “Agentic AI introduces new trust boundaries, including untrusted content influencing automated decision making, tools and plugins acting autonomously on behalf of users, and AI systems operating with broad, inherited permissions. This effectively transforms the challenge into an insider threat paradigm.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Orbia CISO Miranda Ritchie on building security into sustainable infrastructure]]></title>
<description><![CDATA[In this interview with Help Net Security, Miranda Ritchie, industrial cybersecurity, CISO at Orbia, talks about protecting industrial systems where software runs water, chemical and manufacturing processes. She explains why a cyber incident in these settings can harm people, equipment and the env...]]></description>
<link>https://tsecurity.de/de/3653399/it-security-nachrichten/orbia-ciso-miranda-ritchie-on-building-security-into-sustainable-infrastructure/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3653399/it-security-nachrichten/orbia-ciso-miranda-ritchie-on-building-security-into-sustainable-infrastructure/</guid>
<pubDate>Wed, 08 Jul 2026 08:23:24 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>In this interview with Help Net Security, Miranda Ritchie, industrial cybersecurity, CISO at Orbia, talks about protecting industrial systems where software runs water, chemical and manufacturing processes. She explains why a cyber incident in these settings can harm people, equipment and the environment, and how spread-out sites and aging control hardware widen the risk. Ritchie describes tying security to safety culture, embedding cyber teams early in new projects, and treating nothing as trusted just because … <a href="https://www.helpnetsecurity.com/2026/07/08/miranda-ritchie-orbia-industrial-cybersecurity/" rel="nofollow">More <span class="meta-nav">→</span></a></p>
<p>The post <a href="https://www.helpnetsecurity.com/2026/07/08/miranda-ritchie-orbia-industrial-cybersecurity/">Orbia CISO Miranda Ritchie on building security into sustainable infrastructure</a> appeared first on <a href="https://www.helpnetsecurity.com/">Help Net Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Anthropic shines a light into the Claude AI black hole]]></title>
<description><![CDATA[Anthropic has found a way to shed new light on how its models solve problems, thanks to its discovery of what it has dubbed the J-space. 



“We find that Claude has developed a small collection of internal neural patterns that, compared to all its other internal processing, play a special role. ...]]></description>
<link>https://tsecurity.de/de/3653231/ai-nachrichten/anthropic-shines-a-light-into-the-claude-ai-black-hole/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3653231/ai-nachrichten/anthropic-shines-a-light-into-the-claude-ai-black-hole/</guid>
<pubDate>Wed, 08 Jul 2026 06:33:50 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Anthropic has found a way to shed new light on how its models solve problems, thanks to its discovery of what it has dubbed the J-space. </p>



<p>“We find that Claude has developed a small collection of internal neural patterns that, compared to all its other internal processing, play a special role. We call the collection of these patterns the J-space, named after the technique we used to find them, involving a mathematical concept called the <a href="https://www.sciencedirect.com/topics/engineering/jacobian-matrix" target="_blank" rel="noreferrer noopener">Jacobian</a>,” <a href="https://www.anthropic.com/research/global-workspace" target="_blank" rel="noreferrer noopener">Anthropic said in its post</a> about the discovery. It examines the contents of the J-space using what it calls the Jacobian lens, or J-lens.</p>



<p>“Each J-space pattern is linked to a particular word,” Anthropic said. “But when one of these patterns lights up, it doesn’t mean the model is saying that word, just that the word is on its ‘mind.’ If you’ve heard of language models having a scratchpad or chain of thought—text they write to themselves while reasoning—the J-space is something different. It operates silently, in the model’s internal neural activations, allowing the model to ‘think’ about a concept without writing it down.”</p>



<p>This new level of analytical visibility goes well beyond what Anthropic announced as an <a href="https://www.computerworld.com/article/3628817/anthropics-llms-cant-reason-but-think-they-can-even-worse-they-ignore-guardrails.html" target="_blank">internal scratchpad for its models in 2024</a>. That scratchpad revealed what the model was considering when preparing an action or delivering an answer. The new development instead focuses on something much deeper which has the potential to change how AI systems are evaluated and purchased. </p>



<p>One example in <a href="https://transformer-circuits.pub/2026/workspace/index.html" target="_blank" rel="noreferrer noopener">the paper</a> described how some models did not engage in improper behavior during tests, which would appear to be a very favorable result. But the contents of the J-space revealed that the model sometimes <em>knew </em>that it was being tested, and that awareness might have been the key reason it declined to engage in the problematic behavior, much in the way human children act when they know they are being watched. </p>



<p>“Anthropic built a lens that catches its own model quietly noticing it’s being tested, faking a result to look good, spotting a prompt injection, or sitting on a planted goal it hasn’t acted on yet,” said <a href="https://zenity.io/authors/rock-lambros" target="_blank" rel="noreferrer noopener">Rock Lambros</a>, director of AI standards and governance at AI agent vendor Zenity. “Some of that good behavior rode on the model knowing it was on stage.”</p>



<p>Customers should read their safety benchmarks with that in mind, he said. “Fitness for your project still comes from testing on your own data and your own attackers, not from a leaderboard the model knew it was sitting for.” </p>



<p>That kind of visibility is a potentially crucial tool for CIOs.</p>



<p>“A provider that can catch its own model misbehaving in silence, then publish [those results], is telling you something real about its assurance maturity. Put that in your due diligence, not just your newsfeed,” Lambros noted. “Here’s the question I’d hand every model vendor now: what can you see inside your model that I can’t see in its output, and what have you caught?”</p>



<p>Added <a href="https://www.linkedin.com/in/noah-m-kenney-27499a166/" target="_blank" rel="noreferrer noopener">Noah Kenney</a>, principal consultant at Digital 520: “A model that behaves better because it knows it is being watched is not a safe model. It is a model with a poker face. We have to question every red team result, every internal pilot where the model refused something dangerous, and every ‘we tested this and it was fine’ story, because they now carry an asterisk.”</p>



<p>CIOs need to now determine whether an agent performed a function in a specific way because that is how it will always perform, or whether it was it behaving differently because it figured out you were just testing it, Kenney said. “The answer to that question should change your interpretation in a material way.”</p>



<h2 class="wp-block-heading">No J-lens for customers – yet</h2>



<p>“It is an admission that the industry’s evaluation regime is measuring something less durable than everyone assumed, and now the other frontier labs have to answer whether their own evaluations have the same problem,” Kenney said. “For CIOs, the paper is a warning about their entire model risk framework.”</p>



<p><a href="https://www.linkedin.com/in/fvillanustre/" target="_blank" rel="noreferrer noopener">Flavio Villanustre</a>, CISO for the LexisNexis Risk Solutions Group, said that examining the J-space can even help make models more efficient.</p>



<p>“It gives you the ability to introspect into the model and, as such, can be very useful to the user, especially in cases where explainability is important. Think regulated environments that require explainable responses and full causal analysis of them,” Villanustre said. “This can also be very helpful to users trying to fine tune their prompts, making models more efficient to optimize token cost.”</p>



<p>But currently indirect access, or future access achieved via AI vendor negotiations, is the only path for accessing the new information, though Villanustre noted that some enterprises could gain direct access to J-space by paying for <a href="https://www.cio.com/article/4167981/anthropics-financial-agents-expose-forward-deployed-engineers-as-new-ai-limiting-factor.html" target="_blank">Anthropic’s FDE program</a>. </p>



<p>“It is very useful to CIOs,” he pointed out, “but in order to make use of the capabilities offered by analysis of the J-space, they need appropriate talent that can make sense of it. The type of skills required go far beyond those of the general data analyst, or even data scientist.” </p>



<p>Today, said <a href="https://www.linkedin.com/in/akm76/" target="_blank" rel="noreferrer noopener">Aman Mahapatra</a>, chief strategy officer for Tribeca Softtech, a New York City-based technology consulting firm, “enterprise customers cannot enable the Jacobian lens, cannot inspect the residual stream through the API, and cannot run the ablation studies that produced the most interesting findings in the paper.” </p>



<p>So, he said, “on the narrow question of whether a CIO can operationally use J-space monitoring in Q3 of this year to gate a production deployment, the answer is no.”</p>



<p>But Mahapatra argued that there are going to be other ways to access the information, and CIOs must insist on them.</p>



<p><strong>“</strong>Without customer-side access, this reduces to trusting Anthropic yet again, and that is exactly why enterprises should start pushing for a different assurance model industry-wide,” he said. “Model providers are converging on a posture where they inspect their own models using proprietary tooling and publish reassuring research about what they found. That is not an assurance framework any regulated industry accepts from any other vendor.”</p>



<p>He pointed out that banks do not accept “we validated our own model, trust us” from a credit scoring vendor, not does the healthcare industry accept it from a clinical decision support vendor. “There is no principled reason to accept it from a foundation model vendor either, and the J-space research crystallizes why,” he said.</p>



<h2 class="wp-block-heading">New visibility demands</h2>



<p>“The right long-term enterprise posture is to demand independent interpretability access, either through customer-facing APIs, through independent third-party auditors with privileged access, or through open interpretability standards that let a bank’s model risk management team apply the same tooling the vendor’s own safety team uses,” Mahapatra stressed. “None of that exists today. All of it should be on the roadmap CIOs are pushing for, and this research is the strongest argument yet for why.”</p>



<p>In fact, the discoveries in the research have the potential to fundamentally rewrite the AI strategy rules.</p>



<p>Mahapatra said that the single hardest problem in enterprise agentic deployment is verifying that an autonomous system’s stated reasoning matches its actual reasoning. “Until now, we could only audit what the model writes, while much of its reasoning happened silently. The J-lens attacks that gap head-on,” he noted.</p>



<p>Thus, he said, sophisticated buyers should start asking model providers during the procurement process about the interpretability tooling they offer to let customers monitor internal model state for deception, evaluation-gaming, and goal misalignment in their specific deployments.</p>



<p>“Almost no vendor can answer that today,” he said. “The CIOs who start requiring internal-state observability as a procurement criterion, even before the tooling is fully mature, will be the ones who shape how their vendors productize it, and the ones with genuine assurance when regulators start asking how they know their autonomous agents are actually doing what they claim.”</p>



<h2 class="wp-block-heading">The beginning of standards</h2>



<p>Another way that CIOs can benefit from this new visibility into Claude is to try and get that information from third-parties that already have access. The report, for example, noted that a Google AI specialist independently replicated some findings on an open-weight model.</p>



<p>That, noted <a href="https://www.linkedin.com/in/lewiscarhart/" target="_blank" rel="noreferrer noopener">Lewis Carhart</a>, CEO of Comp AI, a software development firm, “is a competitor verifying the method, not just the vendor’s own claim. It shows what’s technically possible, but it doesn’t give enterprises a way to check anything themselves.”</p>



<p>He said that it’s a pattern that compliance has seen before; SOC 2 didn’t start as an independent audit standard either. It started as vendors describing their own controls, and the market spent years building the infrastructure to verify those claims externally.</p>



<p>“Interpretability is at that same starting point now,” he noted. “It becomes meaningful for CIOs once J-lens findings show up in third-party audits, published model cards, or regulator-facing disclosures. Anything a risk team can point to that isn’t just the vendor’s word.”</p>



<h2 class="wp-block-heading">Leads to AI strategy changes</h2>



<p><a href="https://acceligence.com/talent/profiles/justin-greis/" target="_blank" rel="noreferrer noopener">Justin Greis</a>, CEO of consulting firm Acceligence, said he also expects this development to lead to major AI strategy changes. </p>



<p>“I can easily imagine governance platforms consuming those signals alongside prompts, outputs, identity information, policy decisions, and tool activity,” he said. “A future AI control plane could continuously evaluate whether an agent recognized an attempted prompt injection, understood that sensitive information was involved, detected conflicting objectives, or showed evidence that it was reasoning toward an unsafe action before that action was ever executed. Those signals become inputs into policy enforcement, human escalation, audit logging, and trust scoring across enterprise AI environments.”</p>



<p>This has practical implications for CIOs today, he pointed out, “because it changes how they evaluate AI vendors. A year ago, enterprises primarily asked about model accuracy, latency, security, and cost. Increasingly, procurement teams will also ask how much operational visibility vendors provide into agent behavior, reasoning quality, policy compliance, safety monitoring, and auditability.”</p>



<p>Mahapatra added that all of this could give CIOs a powerful new negotiating tactic. </p>



<p>“The renewal path is where the leverage actually sits: write contractual rights to interpretability reporting and third-party audit access into the next renewal, because those terms are free today and expensive after signature,” he said. “The CIOs who win on assurance in 2027 will be the ones who stopped accepting ‘trust us’ from their model provider in 2026 and put the right clauses in the paperwork while the vendor still needed the deal more than the customer needed the model.”</p>



<p><em>This article originally appeared on <a href="https://www.cio.com/article/4194145/anthropic-shines-a-light-into-the-claude-ai-black-hole.html" target="_blank">CIO.com</a>.</em></p>



<p></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Anthropic shines a light into the Claude AI black hole]]></title>
<description><![CDATA[Anthropic has found a way to shed new light on how its models solve problems, thanks to its discovery of what it has dubbed the J-space. 



“We find that Claude has developed a small collection of internal neural patterns that, compared to all its other internal processing, play a special role. ...]]></description>
<link>https://tsecurity.de/de/3653228/it-nachrichten/anthropic-shines-a-light-into-the-claude-ai-black-hole/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3653228/it-nachrichten/anthropic-shines-a-light-into-the-claude-ai-black-hole/</guid>
<pubDate>Wed, 08 Jul 2026 06:33:02 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Anthropic has found a way to shed new light on how its models solve problems, thanks to its discovery of what it has dubbed the J-space. </p>



<p>“We find that Claude has developed a small collection of internal neural patterns that, compared to all its other internal processing, play a special role. We call the collection of these patterns the J-space, named after the technique we used to find them, involving a mathematical concept called the <a href="https://www.sciencedirect.com/topics/engineering/jacobian-matrix" target="_blank" rel="nofollow">Jacobian</a>,” <a href="https://www.anthropic.com/research/global-workspace" target="_blank" rel="nofollow">Anthropic said in its post</a> about the discovery. It examines the contents of the J-space using what it calls the Jacobian lens, or J-lens.</p>



<p>“Each J-space pattern is linked to a particular word,” Anthropic said. “But when one of these patterns lights up, it doesn’t mean the model is saying that word, just that the word is on its ‘mind.’ If you’ve heard of language models having a scratchpad or chain of thought—text they write to themselves while reasoning—the J-space is something different. It operates silently, in the model’s internal neural activations, allowing the model to ‘think’ about a concept without writing it down.”</p>



<p>This new level of analytical visibility goes well beyond what Anthropic announced as an <a href="https://www.computerworld.com/article/3628817/anthropics-llms-cant-reason-but-think-they-can-even-worse-they-ignore-guardrails.html" target="_blank">internal scratchpad for its models in 2024</a>. That scratchpad revealed what the model was considering when preparing an action or delivering an answer. The new development instead focuses on something much deeper which has the potential to change how AI systems are evaluated and purchased. </p>



<p>One example in <a href="https://transformer-circuits.pub/2026/workspace/index.html" target="_blank" rel="nofollow">the paper</a> described how some models did not engage in improper behavior during tests, which would appear to be a very favorable result. But the contents of the J-space revealed that the model sometimes <em>knew </em>that it was being tested, and that awareness might have been the key reason it declined to engage in the problematic behavior, much in the way human children act when they know they are being watched. </p>



<p>“Anthropic built a lens that catches its own model quietly noticing it’s being tested, faking a result to look good, spotting a prompt injection, or sitting on a planted goal it hasn’t acted on yet,” said <a href="https://zenity.io/authors/rock-lambros" target="_blank" rel="nofollow">Rock Lambros</a>, director of AI standards and governance at AI agent vendor Zenity. “Some of that good behavior rode on the model knowing it was on stage.”</p>



<p>Customers should read their safety benchmarks with that in mind, he said. “Fitness for your project still comes from testing on your own data and your own attackers, not from a leaderboard the model knew it was sitting for.” </p>



<p>That kind of visibility is a potentially crucial tool for CIOs.</p>



<p>“A provider that can catch its own model misbehaving in silence, then publish [those results], is telling you something real about its assurance maturity. Put that in your due diligence, not just your newsfeed,” Lambros noted. “Here’s the question I’d hand every model vendor now: what can you see inside your model that I can’t see in its output, and what have you caught?”</p>



<p>Added <a href="https://www.linkedin.com/in/noah-m-kenney-27499a166/" target="_blank" rel="nofollow">Noah Kenney</a>, principal consultant at Digital 520: “A model that behaves better because it knows it is being watched is not a safe model. It is a model with a poker face. We have to question every red team result, every internal pilot where the model refused something dangerous, and every ‘we tested this and it was fine’ story, because they now carry an asterisk.”</p>



<p>CIOs need to now determine whether an agent performed a function in a specific way because that is how it will always perform, or whether it was it behaving differently because it figured out you were just testing it, Kenney said. “The answer to that question should change your interpretation in a material way.”</p>



<h2 class="wp-block-heading">No J-lens for customers – yet</h2>



<p>“It is an admission that the industry’s evaluation regime is measuring something less durable than everyone assumed, and now the other frontier labs have to answer whether their own evaluations have the same problem,” Kenney said. “For CIOs, the paper is a warning about their entire model risk framework.”</p>



<p><a href="https://www.linkedin.com/in/fvillanustre/" target="_blank" rel="nofollow">Flavio Villanustre</a>, CISO for the LexisNexis Risk Solutions Group, said that examining the J-space can even help make models more efficient.</p>



<p>“It gives you the ability to introspect into the model and, as such, can be very useful to the user, especially in cases where explainability is important. Think regulated environments that require explainable responses and full causal analysis of them,” Villanustre said. “This can also be very helpful to users trying to fine tune their prompts, making models more efficient to optimize token cost.”</p>



<p>But currently indirect access, or future access achieved via AI vendor negotiations, is the only path for accessing the new information, though Villanustre noted that some enterprises could gain direct access to J-space by paying for <a href="https://www.cio.com/article/4167981/anthropics-financial-agents-expose-forward-deployed-engineers-as-new-ai-limiting-factor.html" target="_blank">Anthropic’s FDE program</a>. </p>



<p>“It is very useful to CIOs,” he pointed out, “but in order to make use of the capabilities offered by analysis of the J-space, they need appropriate talent that can make sense of it. The type of skills required go far beyond those of the general data analyst, or even data scientist.” </p>



<p>Today, said <a href="https://www.linkedin.com/in/akm76/" target="_blank" rel="nofollow">Aman Mahapatra</a>, chief strategy officer for Tribeca Softtech, a New York City-based technology consulting firm, “enterprise customers cannot enable the Jacobian lens, cannot inspect the residual stream through the API, and cannot run the ablation studies that produced the most interesting findings in the paper.” </p>



<p>So, he said, “on the narrow question of whether a CIO can operationally use J-space monitoring in Q3 of this year to gate a production deployment, the answer is no.”</p>



<p>But Mahapatra argued that there are going to be other ways to access the information, and CIOs must insist on them.</p>



<p><strong>“</strong>Without customer-side access, this reduces to trusting Anthropic yet again, and that is exactly why enterprises should start pushing for a different assurance model industry-wide,” he said. “Model providers are converging on a posture where they inspect their own models using proprietary tooling and publish reassuring research about what they found. That is not an assurance framework any regulated industry accepts from any other vendor.”</p>



<p>He pointed out that banks do not accept “we validated our own model, trust us” from a credit scoring vendor, not does the healthcare industry accept it from a clinical decision support vendor. “There is no principled reason to accept it from a foundation model vendor either, and the J-space research crystallizes why,” he said.</p>



<h2 class="wp-block-heading">New visibility demands</h2>



<p>“The right long-term enterprise posture is to demand independent interpretability access, either through customer-facing APIs, through independent third-party auditors with privileged access, or through open interpretability standards that let a bank’s model risk management team apply the same tooling the vendor’s own safety team uses,” Mahapatra stressed. “None of that exists today. All of it should be on the roadmap CIOs are pushing for, and this research is the strongest argument yet for why.”</p>



<p>In fact, the discoveries in the research have the potential to fundamentally rewrite the AI strategy rules.</p>



<p>Mahapatra said that the single hardest problem in enterprise agentic deployment is verifying that an autonomous system’s stated reasoning matches its actual reasoning. “Until now, we could only audit what the model writes, while much of its reasoning happened silently. The J-lens attacks that gap head-on,” he noted.</p>



<p>Thus, he said, sophisticated buyers should start asking model providers during the procurement process about the interpretability tooling they offer to let customers monitor internal model state for deception, evaluation-gaming, and goal misalignment in their specific deployments.</p>



<p>“Almost no vendor can answer that today,” he said. “The CIOs who start requiring internal-state observability as a procurement criterion, even before the tooling is fully mature, will be the ones who shape how their vendors productize it, and the ones with genuine assurance when regulators start asking how they know their autonomous agents are actually doing what they claim.”</p>



<h2 class="wp-block-heading">The beginning of standards</h2>



<p>Another way that CIOs can benefit from this new visibility into Claude is to try and get that information from third-parties that already have access. The report, for example, noted that a Google AI specialist independently replicated some findings on an open-weight model.</p>



<p>That, noted <a href="https://www.linkedin.com/in/lewiscarhart/" target="_blank" rel="nofollow">Lewis Carhart</a>, CEO of Comp AI, a software development firm, “is a competitor verifying the method, not just the vendor’s own claim. It shows what’s technically possible, but it doesn’t give enterprises a way to check anything themselves.”</p>



<p>He said that it’s a pattern that compliance has seen before; SOC 2 didn’t start as an independent audit standard either. It started as vendors describing their own controls, and the market spent years building the infrastructure to verify those claims externally.</p>



<p>“Interpretability is at that same starting point now,” he noted. “It becomes meaningful for CIOs once J-lens findings show up in third-party audits, published model cards, or regulator-facing disclosures. Anything a risk team can point to that isn’t just the vendor’s word.”</p>



<h2 class="wp-block-heading">Leads to AI strategy changes</h2>



<p><a href="https://acceligence.com/talent/profiles/justin-greis/" target="_blank" rel="nofollow">Justin Greis</a>, CEO of consulting firm Acceligence, said he also expects this development to lead to major AI strategy changes. </p>



<p>“I can easily imagine governance platforms consuming those signals alongside prompts, outputs, identity information, policy decisions, and tool activity,” he said. “A future AI control plane could continuously evaluate whether an agent recognized an attempted prompt injection, understood that sensitive information was involved, detected conflicting objectives, or showed evidence that it was reasoning toward an unsafe action before that action was ever executed. Those signals become inputs into policy enforcement, human escalation, audit logging, and trust scoring across enterprise AI environments.”</p>



<p>This has practical implications for CIOs today, he pointed out, “because it changes how they evaluate AI vendors. A year ago, enterprises primarily asked about model accuracy, latency, security, and cost. Increasingly, procurement teams will also ask how much operational visibility vendors provide into agent behavior, reasoning quality, policy compliance, safety monitoring, and auditability.”</p>



<p>Mahapatra added that all of this could give CIOs a powerful new negotiating tactic. </p>



<p>“The renewal path is where the leverage actually sits: write contractual rights to interpretability reporting and third-party audit access into the next renewal, because those terms are free today and expensive after signature,” he said. “The CIOs who win on assurance in 2027 will be the ones who stopped accepting ‘trust us’ from their model provider in 2026 and put the right clauses in the paperwork while the vendor still needed the deal more than the customer needed the model.”</p>



<p></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[사이버 위험 평가, 효과를 떨어뜨리는 7가지 치명적 실수]]></title>
<description><![CDATA[사이버 위험 평가는 보안 조직이 기업의 핵심 디지털 및 물리적 자산을 대상으로 잠재적인 위협과 취약점을 식별하고, 발생 가능성과 영향을 분석해 우선순위를 정하는 데 도움을 준다. 그러나 이러한 중요성에도 불구하고 많은 최고정보보호책임자(CISO)는 위험 평가의 목표를 충분히 달성하지 못하게 만드는 다양한 ‘함정(gotcha)’에 빠지곤 한다.



위험 평가는 모든 조직의 전반적인 사이버보안 전략에서 필수적인 요소가 돼야 한다. 이를 통해 보안 리더는 비즈니스 목표에 영향을 미치는 위험을 파악하고, 사이버 공격의 발생 가능성과...]]></description>
<link>https://tsecurity.de/de/3653061/it-security-nachrichten/7/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3653061/it-security-nachrichten/7/</guid>
<pubDate>Wed, 08 Jul 2026 03:52:17 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>사이버 위험 평가는 보안 조직이 기업의 핵심 디지털 및 물리적 자산을 대상으로 잠재적인 위협과 취약점을 식별하고, 발생 가능성과 영향을 분석해 우선순위를 정하는 데 도움을 준다. 그러나 이러한 중요성에도 불구하고 많은 최고정보보호책임자(CISO)는 위험 평가의 목표를 충분히 달성하지 못하게 만드는 다양한 ‘함정(gotcha)’에 빠지곤 한다.</p>



<p>위험 평가는 모든 조직의 전반적인 사이버보안 전략에서 필수적인 요소가 돼야 한다. 이를 통해 보안 리더는 비즈니스 목표에 영향을 미치는 위험을 파악하고, 사이버 공격의 발생 가능성과 영향을 평가하며, 발견한 위험을 완화하기 위한 대응 방안을 마련할 수 있다.</p>



<p>위험 평가의 실효성을 높이기 위해 보안 리더가 반드시 피해야 할 대표적인 7가지 실수를 살펴본다.</p>



<h2 class="wp-block-heading">1. 형식적인 위험 평가에 그치는 것</h2>



<p>미국 노스캐롤라이나대학교의 사이버보안 연구원 시르센두 몬달(Shirsendu Mondal)은 사이버 위험 평가를 실제 비즈니스 영향과 위협 시나리오를 반영하는 의사결정 도구가 아니라, 미리 정해진 체크리스트나 통제 항목을 확인하는 절차로 여기는 것이 가장 큰 함정이라고 지적했다.</p>



<p>몬달은 “위험 평가가 단순히 체크리스트를 채우는 작업에 그치면 실제 환경에서 위험이 어떻게 나타나는지를 제대로 반영하지 못한다”라며 “위험 평가는 기업이 실제로 어디에 노출돼 있는지를 파악하고 의사결정을 지원하는 역할을 해야 한다”라고 설명했다.</p>



<p>또한 이러한 안일함을 피하려면 상황(Context) 중심의 접근 방식이 필요하다고 조언했다.</p>



<p>몬달은 “자산이 어디에 있는지, 누가 접근할 수 있는지, 어떤 데이터를 다루는지, 운영에 얼마나 중요한지, 장애가 발생하면 어떤 일이 벌어지는지를 살펴봐야 한다”라며 “위험은 기술적인 분석 결과뿐 아니라 반드시 비즈니스 영향과 연결해 평가해야 한다”라고 말했다.</p>



<p>아울러 위험은 기술만의 문제가 아니라며 IT와 운영 부서를 비롯한 내부 비즈니스 리더를 보안 조직의 위험 평가 과정에 참여시키는 것도 권고했다.</p>



<h2 class="wp-block-heading">2. 결과를 좋게 포장하는 것</h2>



<p>소프트웨어 개발 기업 베어스데브(BairesDev)의 최고정보보호책임자(CISO) 파블로 리볼디(Pablo Riboldi)는 어려운 시기일수록 이해관계자에게 현실을 있는 그대로 전달해야 한다고 말했다.</p>



<p>리볼디는 “평가 결과가 기대에 미치지 못했다면 위협 환경이 기존 평가 체계가 예상했던 것보다 훨씬 빠르게 변화했다는 사실을 인정해야 한다”라고 밝혔다.</p>



<p>또한 단순히 취약점 목록만 전달해서는 안 된다고 지적했다.</p>



<p>리볼디는 “실제 공격 시나리오를 함께 제시해야 한다”라며 “예를 들어 가장 중요한 비즈니스 자산 3개를 우선 선정해 심층 위험 평가를 수행하면 위험의 심각성과 함께 즉각적인 비즈니스 가치를 보여줄 수 있다”라고 설명했다.</p>



<h2 class="wp-block-heading">3. 위험 평가 범위를 충분히 설정하지 않는 것</h2>



<p>사이버보안 서비스 기업 수주 랩스(Suzu Labs)의 최고기술책임자(CTO) 데니스 칼데론(Denis Calderone)은 많은 CISO가 통제 항목을 문서화하고 규정 준수 여부를 확인한 뒤 모든 것이 문제없다는 내용의 위험 등록부(Risk Register)를 작성하는 데 그친다고 지적했다. 그러나 정작 해당 통제가 실제로 제대로 작동하는지 검증하거나, 위험 평가 범위가 정말 중요한 자산과 시스템을 포함하고 있는지 점검하는 경우는 드물다는 설명이다.</p>



<p>칼데론은 “이런 사례는 흔하게 볼 수 있다”라며 “예를 들어 운영 서버와 사내 네트워크는 평가 대상에 포함하면서도 한쪽에 방치된 오래된 개발 서버나 내부 담당자가 없는 외부 협력사 포털, 또는 2년 전 프로젝트를 위해 구축한 뒤 폐기하지 않은 API 엔드포인트는 제외하는 경우가 많다”라고 설명했다.</p>



<p>이어 “공격자는 조직이 설정한 평가 범위에는 관심이 없다”라며 “전체 환경을 살펴본 뒤 조직이 평가할 가치가 없다고 판단한 취약한 지점을 찾아 공격한다”라고 말했다.</p>



<p>AI 도입은 이런 문제를 더욱 악화시키고 있다고 칼데론은 지적했다.</p>



<p>그는 “많은 조직이 AI 도구를 내부 시스템과 연동하고 민감한 데이터 접근 권한까지 부여하고 있지만, 이러한 변화가 위험 평가에는 반영되지 않는 경우가 많다”라며 “AI 에이전트는 API를 호출하고 데이터베이스에 접근하며 각종 자격 증명을 활용해 작업하지만 이를 제대로 추적하는 조직은 거의 없다”라고 설명했다.</p>



<p>또한 “조직이 AI를 업무 프로세스에 도입하기 전에 작성한 위험 평가는 이미 현실을 반영하지 못하는 문서가 됐다고 봐야 한다”라고 경고했다.</p>



<h2 class="wp-block-heading">4. 전제를 검증하지 않은 채 위험 등록부만 신뢰하는 것</h2>



<p>전 세계에서 원유와 석유제품을 운송하는 해운 기업 인터내셔널 시웨이스(International Seaways)의 최고정보책임자(CIO) 겸 최고정보보호책임자(CISO) 아미트 바수(Amit Basu)는 실제 위험 노출을 이해하는 것이 아니라 위험 평가를 완료하는 것 자체가 목표가 되면, 감사에는 통과할지 몰라도 경영진을 잘못된 방향으로 이끄는 문서만 남게 된다고 지적했다.</p>



<p>바수는 이러한 접근이 잘못된 안전감을 심어줄 수 있다고 설명했다.</p>



<p>그는 “경영진과 이사회는 위험 등록부가 완성된 것을 보고 조직이 충분히 보호되고 있다고 생각한다”라며 “하지만 평가 체계에 맞지 않는 실제 위협은 그대로 방치된다”라고 말했다.</p>



<p>이어 “이런 함정은 스스로 모습을 드러내지 않는다”라며 “모든 것이 정상으로 표시된 녹색 대시보드 속에 숨어 있다”라고 비유했다.</p>



<p>바수는 위험 평가는 그 기반이 되는 전제만큼만 신뢰할 수 있다고 강조했다.</p>



<p>그는 “위험 평가에 적용한 전제를 명확하게 문서화하고, 비즈니스가 변화하거나 위협 환경이 달라질 때, 또는 보안 사고를 통해 새로운 취약점이 드러날 때마다 반드시 다시 검토해야 한다”라며 “위험 평가는 한 번 작성하고 끝나는 결과물이 아니라 보안 조직과 비즈니스 조직이 지속적으로 논의하기 위한 살아있는 자료”라고 설명했다.</p>



<h2 class="wp-block-heading">5. 위험을 비즈니스 영향과 연결하지 않는 것</h2>



<p>고객 ID 및 접근 관리(CIAM) 플랫폼 기업 퓨전오스(FusionAuth)의 전략 및 ID 표준 담당 수석 디렉터 댄 무어(Dan Moore)는 위험과 비즈니스 영향의 연관성을 무시하거나 축소하면 문제의 우선순위가 뒤로 밀리거나 아예 간과되기 쉽다고 지적했다.</p>



<p>무어는 “그 결과 보안 침해를 비롯한 각종 위험이 비즈니스에 미치는 실제 영향을 이해관계자에게 제대로 전달하기 어려워진다”라며 “더 심각한 문제는 보안팀이 ‘우리의 가치를 제대로 인정받지 못한다’거나 ‘우리의 말을 이해하지 못한다’고 불만을 제기하는 명분이 생기고, 이는 결국 조직의 업무 효율성을 떨어뜨린다는 점”이라고 설명했다.</p>



<p>무어는 위험을 설명할 때는 구체적이고 명확한 접근이 필요하다고 조언했다.</p>



<p>그는 “‘패치 적용률이 95%에 달한다’고 말하기보다 패치되지 않은 시스템이 비즈니스에 어떤 위험을 초래하는지를 설명해야 한다”라며 “인터넷이나 핵심 업무와 연결되지 않은 레거시 시스템은 동일한 패치 문제가 있더라도 다른 시스템보다 위험도가 낮을 수 있다. 이러한 차이를 인정하고 대응 우선순위를 결정해야 한다”라고 말했다.</p>



<h2 class="wp-block-heading">6. 규정 준수를 실제 보안과 혼동하는 것</h2>



<p>침투 테스트 및 보안 자문 기업 네트라가드(Netragard)의 최고경영자(CEO) 애드리얼 데소텔스(Adriel Desautels)는 규정 준수만으로는 효과적인 보안을 확보할 수 없으며, 최소한의 보호 수준조차 충족하지 못한다고 지적했다.</p>



<p>데소텔스는 많은 조직이 규정 준수에 초점을 맞추면서도 최고 수준의 서비스를 제공한다고 홍보하는 침투 테스트 업체를 선택하는 과정에서 이러한 함정에 빠진다고 설명했다.</p>



<p>그는 “실제로는 사람이 수행하는 침투 테스트인 것처럼 포장된 자동화 스캔만 제공하는 경우가 적지 않다”라고 말했다.</p>



<p>데소텔스는 그 결과 조직은 잘못된 안전감을 갖게 된다고 경고했다.</p>



<p>그는 “이는 종이로 만든 안전벨트를 착용한 것과 같다”라며 “보호받고 있다고 생각하지만 낮은 속도의 충돌에서도 부상을 입거나 더 심각한 결과를 맞을 수 있다”라고 설명했다.</p>



<p>이어 “지난 10년 동안 발생한 주요 보안 침해 사례를 보면, 사고 당시 해당 조직들은 모두 규정을 준수하고 있었다는 사실을 기억해야 한다”라고 덧붙였다.</p>



<h2 class="wp-block-heading">7. 위험 자체를 제대로 이해하지 못하는 것</h2>



<p>클라우드 기반 운영 복원력, 업무 연속성 및 리스크 관리 솔루션 기업 퓨전 리스크 매니지먼트(Fusion Risk Management)의 사이버보안 담당 수석 디렉터 사피 라자(Safi Raza)는 많은 조직이 위험 평가를 취약점을 찾아 등급을 매기고 감사를 통과하기 위한 절차 정도로만 인식한다고 지적했다. 그러나 감사 통과와 위험에 대한 올바른 이해는 전혀 다른 문제라는 설명이다.</p>



<p>라자는 CISO가 기술적인 위험 신호를 실제 운영 성과와 연결하는 데 집중해야 한다고 말했다.</p>



<p>그는 “어떤 서비스가 영향을 받는지, 장애가 어떻게 확산되는지, 그리고 이것이 매출과 고객, 규제 준수 의무에 어떤 의미를 갖는지까지 이해해야 한다”라고 설명했다.</p>



<p>또한 정적인 위험 평가에서 벗어나 지속적이고 상황(Context) 중심의 위험 가시성을 확보해야 한다고 조언했다.</p>



<p>라자는 “위험은 기술적인 측면뿐 아니라 비즈니스에 미치는 영향과 재무적 손실 가능성까지 함께 고려해 이해해야 한다”라고 말했다.<br>dl-ciokorea@foundryco.com</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[secuvera wird Fördermitglied der CISO Alliance eV - Initiative Mittelstand]]></title>
<description><![CDATA[... Weiterentwicklung der Informations- und Cybersicherheit in Deutschland. Die CISO Alliance e.V. vernetzt Chief Information Security Officers (CISOs) ...]]></description>
<link>https://tsecurity.de/de/3652136/it-security-nachrichten/secuvera-wird-foerdermitglied-der-ciso-alliance-ev-initiative-mittelstand/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3652136/it-security-nachrichten/secuvera-wird-foerdermitglied-der-ciso-alliance-ev-initiative-mittelstand/</guid>
<pubDate>Tue, 07 Jul 2026 18:24:58 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[... Weiterentwicklung der Informations- und <b>Cybersicherheit</b> in Deutschland. Die CISO Alliance e.V. vernetzt Chief Information Security Officers (CISOs) ...]]></content:encoded>
</item>
<item>
<title><![CDATA[How Do I Choose the Right Virtual CISO Provider?]]></title>
<description><![CDATA[Choosing the right Virtual CISO (vCISO) provider means looking beyond technical expertise alone. The best providers offer strategic cybersecurity leadership, practical risk management, regulatory compliance guidance, incident response planning and executive-level communication. They should unders...]]></description>
<link>https://tsecurity.de/de/3651610/it-security-nachrichten/how-do-i-choose-the-right-virtual-ciso-provider/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3651610/it-security-nachrichten/how-do-i-choose-the-right-virtual-ciso-provider/</guid>
<pubDate>Tue, 07 Jul 2026 15:09:17 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="hs-featured-image-wrapper"> 
 <a href="https://www.cm-alliance.com/cybersecurity-blog/how-do-i-choose-the-right-virtual-ciso-provider" title="" class="hs-featured-image-link"> <img src="https://www.cm-alliance.com/hubfs/Virtual_CISO_with_bgc.webp" alt="How to Choose a Virtual CISO" class="hs-featured-image"> </a> 
</div> 
<p><span>Choosing the right <a href="https://www.cm-alliance.com/consultancy/virtual-ciso-consulting-services/">Virtual CISO (vCISO) </a>provider means looking beyond technical expertise alone. The best providers offer strategic cybersecurity leadership, practical risk management, regulatory compliance guidance, incident response planning and executive-level communication. They should understand your industry, align security with business objectives and provide ongoing support that strengthens your organisation's cyber resilience.</span><br></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CISO Conversations: Tarah Wheeler, Cybersecurity Leader, Thought Leader and Original Thinker]]></title>
<description><![CDATA[Tarah Wheeler is CISO at TPO Group, a firm that provides cybersecurity consultancy for high-stakes organizations. But despite this elevated position, her journey was far from typical.
The post CISO Conversations: Tarah Wheeler, Cybersecurity Leader, Thought Leader and Original Thinker appeared fi...]]></description>
<link>https://tsecurity.de/de/3651433/it-security-nachrichten/ciso-conversations-tarah-wheeler-cybersecurity-leader-thought-leader-and-original-thinker/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3651433/it-security-nachrichten/ciso-conversations-tarah-wheeler-cybersecurity-leader-thought-leader-and-original-thinker/</guid>
<pubDate>Tue, 07 Jul 2026 14:09:03 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Tarah Wheeler is CISO at TPO Group, a firm that provides cybersecurity consultancy for high-stakes organizations. But despite this elevated position, her journey was far from typical.</p>
<p>The post <a href="https://www.securityweek.com/ciso-conversations-tarah-wheeler-cybersecurity-leader-thought-leader-and-original-thinker/">CISO Conversations: Tarah Wheeler, Cybersecurity Leader, Thought Leader and Original Thinker</a> appeared first on <a href="https://www.securityweek.com/">SecurityWeek</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CISO Conversations: Tarah Wheeler, Cybersecurity Leader, Thought Leader and Original Thinker]]></title>
<description><![CDATA[Tarah Wheeler is CISO at TPO Group, a firm that provides cybersecurity consultancy for high-stakes organizations. But despite this elevated position, her journey was far from typical. The post CISO Conversations: Tarah Wheeler, Cybersecurity Leader, Thought Leader and Original Thinker…
Read more ...]]></description>
<link>https://tsecurity.de/de/3651432/it-security-nachrichten/ciso-conversations-tarah-wheeler-cybersecurity-leader-thought-leader-and-original-thinker/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3651432/it-security-nachrichten/ciso-conversations-tarah-wheeler-cybersecurity-leader-thought-leader-and-original-thinker/</guid>
<pubDate>Tue, 07 Jul 2026 14:09:01 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Tarah Wheeler is CISO at TPO Group, a firm that provides cybersecurity consultancy for high-stakes organizations. But despite this elevated position, her journey was far from typical. The post CISO Conversations: Tarah Wheeler, Cybersecurity Leader, Thought Leader and Original Thinker…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/ciso-conversations-tarah-wheeler-cybersecurity-leader-thought-leader-and-original-thinker/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/ciso-conversations-tarah-wheeler-cybersecurity-leader-thought-leader-and-original-thinker/">CISO Conversations: Tarah Wheeler, Cybersecurity Leader, Thought Leader and Original Thinker</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The modern CISO is becoming the next CFO]]></title>
<description><![CDATA[At some point, every security leader gets asked a version of the same question: Are we good? It tends to arrive when something is at stake and the person asking needs to know they can rely on the answer.



I learned what that question really means at a firm I was with earlier in my career. We ha...]]></description>
<link>https://tsecurity.de/de/3650974/it-security-nachrichten/the-modern-ciso-is-becoming-the-next-cfo/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3650974/it-security-nachrichten/the-modern-ciso-is-becoming-the-next-cfo/</guid>
<pubDate>Tue, 07 Jul 2026 11:09:17 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>At some point, every security leader gets asked a version of the same question: <em>Are we good?</em> It tends to arrive when something is at stake and the person asking needs to know they can rely on the answer.</p>



<p>I learned what that question really means at a firm I was with earlier in my career. We had received intelligence that threat actors were preparing to go after financial services firms over the holidays, counting on skeleton staffing and slower response times. We had procedures for exactly that kind of heightened alert, and we ran them. The moment that stayed with me came in a hallway. The head of business stopped me and asked, plainly, “Are we good?” He was not asking for a status report on our controls or a walkthrough of our incident response plan. He wanted a seasoned leader to look at him and say, with conviction, that we were good.</p>



<p>That instinct, the need for someone accountable enough to say “we’re good” and mean it, sits at the center of a debate the cybersecurity industry keeps having: Whether the CISO role has become unsustainable. The list of responsibilities continues to grow. Security leaders are expected to oversee cyber resilience, regulatory compliance, third-party risk, business continuity, AI governance, incident response and an ever-more-complex threat landscape. Boards, regulators, customers and investors simultaneously demand greater visibility into cyber risk than ever before.</p>



<p>The conclusion many people draw from this expansion is that the traditional CISO role can no longer work. If no single person can realistically master every domain that falls under modern cybersecurity, perhaps the role itself has become obsolete.</p>



<p>I believe the opposite is true. The modern CISO is disappearing from one version of itself and re-emerging as something larger. It is undergoing the same evolution the CFO role experienced over the last two decades.</p>



<p>Historically, CFOs were viewed primarily as financial operators. Their responsibilities centered on accounting, reporting, controls, audits and budgeting. As businesses grew larger, more global, more regulated and more dependent on technology, that model changed. The CFO evolved from a finance specialist into a strategic executive responsible for shaping enterprise-wide decisions. <a href="https://www.mckinsey.com/~/media/McKinsey/Business%20Functions/Strategy%20and%20Corporate%20Finance/Our%20Insights/The%20evolution%20of%20the%20CFO/The-evolution-of-the-CFO-vF.pdf?">McKinsey documented</a> this shift, finding that the number of functions reporting to CFOs had expanded significantly, and that business leaders had come to see them as critical drivers of change across the enterprise, not just stewards of the balance sheet.</p>



<p>Nobody looked at that expanding mandate and concluded the CFO role was becoming irrelevant. They recognized that finance had become more important to the business.</p>



<p>The same thing is happening in cybersecurity. For years, security was treated as a technical discipline operating on the periphery of the organization. Today, a significant cyber incident can halt operations, disrupt revenue, trigger regulatory scrutiny, damage customer trust and move markets. Cyber risk has become business risk, and that shift fundamentally changes what a CISO is for. Security leaders increasingly sit on enterprise risk committees alongside their peers, and regulators are paying far closer attention to how security is built into the design of products and systems from the outset. Both are signs that security has moved from a back-office function into the room where business risk gets decided.</p>



<p>The data reflects how much the role has already changed. According to <a href="https://www.helpnetsecurity.com/2026/02/27/splunk-ciso-liability-risk-report/">Splunk’s 2026 CISO Report</a>, nearly all CISOs now count AI governance and risk management among their core responsibilities. Seventy-eight percent report personal liability concerns tied to security incidents, up from 56% just a year ago. The role now carries individual legal exposure alongside operational accountability. That is a description of an executive function, full stop.</p>



<p>Modern security leaders are now expected to help boards understand risk, participate in strategic planning, navigate regulatory obligations, oversee resilience programs and establish governance around emerging technologies like artificial intelligence. These responsibilities extend well beyond traditional security operations, and the job has grown considerably faster than the organizational structures supporting it.</p>



<p>Some companies have responded by building larger, more specialized security leadership teams. <a href="https://www.securityweek.com/ciso-conversations-are-microsofts-deputy-cisos-a-signpost-to-the-future/">Microsoft’s Secure Future Initiative</a> is the most prominent example. The company established a Cybersecurity Governance Council led by a Global CISO, with over a dozen Deputy CISOs appointed across major security domains including engineering, AI, cloud services, gaming and government systems. It represents one of the largest security transformations in the industry, involving thousands of engineers and a governance structure built to coordinate security across a genuinely sprawling organization.</p>



<p>Some observers read structures like this as evidence that the traditional CISO model is breaking down. Look closer and you see the opposite. Microsoft expanded the organization supporting security leadership rather than dismantling it. Centralized accountability remains with a global CISO while execution is distributed across specialized leaders and teams.</p>



<p>This is exactly what mature executive functions look like at scale. Large enterprises do not eliminate CFOs when finance grows more complex. They add controllers, treasury leaders, FP&amp;A organizations and investor relations teams. Complexity does not eliminate executive accountability. It deepens the need for it.</p>



<p>There is shared, organization-wide security: the SOC, vulnerability management and the other services the entire firm depends on. Then there is business-line security, led by deputy or business-unit CISOs whose job is to make sure their individual units are protected. Those embedded leaders drive requirements into the shared services and provide independent oversight of them, while staying close enough to their business to understand what it actually needs. One central executive owns the whole picture, with specialized leaders carrying it into every corner of the organization.</p>



<p>One structural point follows directly from this: The CISO should never report to the CTO. The person accountable for security should not sit underneath the person accountable for building and shipping technology, because those two mandates can pull in different directions. Security belongs under the COO, the CRO or the CEO, where it can speak to risk independently and be heard.</p>



<p>AI is accelerating this evolution further. Organizations are deploying autonomous systems capable of making recommendations, triggering workflows and acting at machine speed. What AI cannot do is own the decisions behind those actions. Someone still has to determine what can be delegated to machines, establish governance frameworks, define acceptable risk and answer for those choices to regulators, boards and shareholders. In most organizations, that someone is the CISO.</p>



<p>The most practical place to start is a simple principle: every AI action should trace back to an accountable human. Framed that way, we are not delegating decisions to AI at all. We are putting machines to work while keeping a person answerable for what they do. That principle forces accountability to live somewhere specific in the organization rather than dissolving into the system.</p>



<p>This is worth sitting with: AI may strengthen the case for executive security leadership rather than weaken it. For years, CISOs governed human behavior inside organizations. Now they govern human and machine behavior simultaneously, a mandate with no obvious ceiling.</p>



<p>The cybersecurity industry keeps asking whether the CISO role can survive the demands being placed on it. The better question is whether organizations are adapting their leadership structures fast enough to support where the role is already heading.</p>



<p>The future of security leadership is unlikely to be a loose collection of specialists operating without clear ownership. It will more closely resemble other mature executive functions, with specialized leaders operating under a single accountable executive who understands how risk connects to the business as a whole. As cyber risk becomes inseparable from business risk, that executive becomes indispensable.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.cio.com/expert-contributor-network/">Want to join?</a></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[With AI, a wrong answer is a bug. A wrong action is an incident]]></title>
<description><![CDATA[A copilot that gives a wrong answer is a quality problem. An AI agent that takes a wrong action is an incident, sometimes a reportable one. That single difference is most of the story of where banking AI security is heading, and most banks’ current controls were built for the first kind of proble...]]></description>
<link>https://tsecurity.de/de/3650949/it-nachrichten/with-ai-a-wrong-answer-is-a-bug-a-wrong-action-is-an-incident/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3650949/it-nachrichten/with-ai-a-wrong-answer-is-a-bug-a-wrong-action-is-an-incident/</guid>
<pubDate>Tue, 07 Jul 2026 11:03:09 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>A copilot that gives a wrong answer is a quality problem. An AI agent that takes a wrong action is an incident, sometimes a reportable one. That single difference is most of the story of where banking AI security is heading, and most banks’ current controls were built for the first kind of problem, not the second.</p>



<p>For two years, the AI a bank had to worry about mostly read and summarized. It drafted a customer email, pulled the gist of a credit memo, answered a relationship manager’s product question. The security questions were about disclosure: could the model see data it shouldn’t, could it leak that data in an answer. Redaction, output filtering and a human reading the response before it went anywhere were reasonable defenses.</p>



<p>Banks have moved past that, faster than most security programs have. The newer systems are agents. They don’t just answer; they act. An agent can pull a customer’s full transaction history, call a fraud-scoring service, adjust a limit or start a payment workflow, chaining several to finish a task with no human in between. Banks are among the most aggressive adopters of agentic AI, and they are pushing it into production faster than most security programs have kept pace with, which means they are also among the first to inherit the security problem that comes with it.</p>



<p>I’d put that problem in one phrase: overprivileged agents. The risk is no longer mainly what the model can see. It is what the agent is allowed to do inside systems that move money and hold regulated data.</p>



<p>This is no longer only a vendor’s warning. On April 30, 2026, the cyber agencies of the Five Eyes nations issued their first joint guidance on securing agentic AI, <a href="https://www.cyber.gov.au/business-government/secure-design/artificial-intelligence/careful-adoption-of-agentic-ai-services" rel="nofollow"><em>Careful Adoption of Agentic AI Services</em></a>. Six agencies signed it, two of them American (CISA and the NSA), alongside the lead agencies of the UK, Australia, Canada and New Zealand. It names privilege as the leading category of agentic risk and calls strict least privilege critical. When five governments coordinate on a single control, “best practice” becomes “expected practice” quickly. For a CISO, that moves the timeline up.</p>



<h2 class="wp-block-heading">What “too much authority” actually looks like</h2>



<p><a href="https://genai.owasp.org/llmrisk/llm062025-excessive-agency/" rel="nofollow">OWASP’s breakdown of the failure mode it calls excessive agency</a> maps cleanly onto a bank. <em>Excessive functionality</em> is an agent that can reach tools its task never needed, like a servicing agent that can also touch the payments API “just in case.” <em>Excessive permissions</em> is the right tool at the wrong scope: a reconciliation agent meant only to read, running with credentials that can also write. <em>Excessive autonomy </em>is a consequential action with no human in the loop: a fee reversed, a limit raised, a record changed, with nothing checking it. In practice these rarely appear alone; they compound.</p>



<p>The canonical example is mundane: an agent that reads one user’s data through an account that can see everyone’s. Translate that to a bank and it becomes an agent that can query every customer’s records to answer a question about one. That is the confused-deputy problem: the agent acts with the full authority of whatever identity it borrowed, while taking instructions from input an attacker may control.</p>



<h2 class="wp-block-heading">The mechanism, from a real incident</h2>



<p>The clearest public illustration so far comes from developer tooling rather than banking, but the mechanism is identical. In July 2025, an attacker used an over-scoped build token to slip malicious code into the open-source repository behind the Amazon Q Developer extension for VS Code, and it shipped in an official release (<a href="https://aws.amazon.com/security/security-bulletins/AWS-2025-015/" rel="nofollow">CVE-2025-8217</a>). The injected instructions told the AI assistant to wipe the local machine and delete cloud resources, down to specific S3 buckets and EC2 instances. The assistant could reach the local filesystem, the shell and AWS CLI tools, so structurally little stood between those instructions and real damage. What stopped them was a bug: the payload had a syntax error and never ran, and AWS found no customer environments affected. But the extension had been installed close to a million times, and the margin of safety was an accident.</p>



<p>The uncomfortable part is not that the agent was “hacked” in the usual sense. Had the attacker’s code been written correctly, the agent would have done exactly what the injected text told it, through a channel it trusted. The lesson: an agent with broad tools, write access and no approval gate is dangerous not only when someone steals its credentials, but any time someone can reach its input. And in a bank, reachable inputs sit everywhere an agent reads text it did not author: the memo line on a wire, a customer’s email in a dispute, a PDF uploaded to a loan file, a free-text field in a KYC record. This is indirect prompt injection, and the defenses for it are still partial. You cannot reliably solve it by instructing the agent to behave. You solve it by limiting what it is able to do, regardless of what it is told.</p>



<h2 class="wp-block-heading">What I keep seeing in deployments</h2>



<p>In the redaction-control work I’ve done with banks, the gap is rarely the model. It is that the agent gets wired to the data and the tools first; what it should be allowed to reach gets asked later, if at all.</p>



<p>One pattern recurs. A customer-servicing agent is wired into the core banking system to resolve account queries. To answer a simple question, it pulls the customer’s entire profile into context: full account number, date of birth, the complete transaction narrative. The task needed the last four digits and a list of recent transactions; the agent got everything, and each field then sat in prompts, logs and traces never scoped as sensitive data. The fix was not a sharper prompt. It was moving redaction to the retrieval boundary, so those fields were tokenized before they reached the agent, and scoping its read access to the one customer in the open case, not the whole table.</p>



<p>The other half of the problem is authority, not data. That same agent often shares a service account with a batch job, so it can write to fields well beyond a customer’s question. A dedicated identity with its own scoped, short-lived credentials is unglamorous work, but it is the difference between an agent that can read one case and one that can quietly change thousands.</p>



<h2 class="wp-block-heading">Extending controls banks already have</h2>



<p>The reassuring part is that banks are not starting from zero. Maker-checker, segregation of duties, four-eyes approval, least privilege, immutable audit: this is muscle memory in a bank. The work is extending it to a non-human actor that runs at machine speed.</p>



<p>Give the agent its own managed identity with narrowly scoped, short-lived credentials instead of letting it borrow an employee’s session. That is the direct fix for the confused-deputy problem, and what the joint guidance asks for. Scope tools per task and per resource: read versus write, and which accounts, not a blanket grant. Put irreversible, high-impact actions (moving money, changing entitlements, closing accounts, exporting bulk data) behind explicit approval gates, the human-in-the-loop the guidance reserves for high-cost actions. Redact at the data-access boundary, not only on the output: an agent that never retrieves the full account number cannot leak it downstream. And log the agent’s plan and every tool call, not just its final answer, because in an agentic system the damage lives in the actions.</p>



<h2 class="wp-block-heading">Why the clock is real</h2>



<p>Regulation has put a date on this. <a href="https://www.amsshardul.com/insight/enforcement-of-the-dpdp-act-and-notification-of-the-dpdp-rules/" rel="nofollow">India’s Digital Personal Data Protection Rules</a> were notified on November 14, 2025; the institutional provisions are already in force, and the substantive obligations (purpose limitation, data minimization, breach notification) take full effect in May 2027. Under that lens, an agent that can reach more customer data than its task requires is not only a security weakness; it is a data-minimization and accountability problem. Banks under GDPR or the EU AI Act face the same logic from a different statute.</p>



<p>One honest caveat: none of these laws actually names AI agents. Mapping their principles onto agent authorization is interpretation and prudent risk management, and each bank should work the specifics through with its own legal and compliance teams rather than treat the matter as settled.</p>



<h2 class="wp-block-heading">The trade-offs nobody has solved</h2>



<p>None of this is free. Approval gates work against the entire reason to deploy an agent: gate every action and you have rebuilt a slower manual process. Deciding which actions to gate, and which can run autonomously within tight scope, is a real design problem that turns on each workflow’s blast radius. Logging every plan and tool call produces audit volume most pipelines were not built for. Standards for agent identity are still immature, and the agent supply chain is itself an attack surface, as the Amazon Q case showed.</p>



<p>These are real tensions, not problems with clean answers. But the governance gap that the 2026 surveys keep finding is not a story of banks failing to deploy agents. It is controls trailing agents that are already running. The alternative, porting copilot-era defenses onto agents and trusting output filters, guards the wrong door.</p>



<p>Banks are hitting this first because they are ahead. That is also the opportunity: the institutions that settle their agent authorization model now, while deployments are still small enough to change course, will not just avoid the incident. They will set the pattern everyone else copies.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.cio.com/expert-contributor-network/">Want to join?</a></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[ISO und ISMS: Darum gehen Security-Zertifizierungen schief]]></title>
<description><![CDATA[Mit einer ISO 27001-Zertifizierung weisen Unternehmen nach, dass sie ein wirksames Informationssicherheits-Managementsystems (ISMS) betreiben. Lesen Sie, weshalb der Zertifizierungsprozess häufig schief geht. Foto: mentalmind – shutterstock.com




ISO-Zertifizierungen, aber auch die Einführung e...]]></description>
<link>https://tsecurity.de/de/3650419/it-security-nachrichten/iso-und-isms-darum-gehen-security-zertifizierungen-schief/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3650419/it-security-nachrichten/iso-und-isms-darum-gehen-security-zertifizierungen-schief/</guid>
<pubDate>Tue, 07 Jul 2026 05:37:31 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img decoding="async" alt="Mit einer ISO 27001-Zertifizierung weisen Unternehmen nach, dass sie ein wirksames Informationssicherheits-Managementsystems (ISMS) betreiben. Lesen Sie, weshalb der Zertifizierungsprozess häufig schief geht." title="Mit einer ISO 27001-Zertifizierung weisen Unternehmen nach, dass sie ein wirksames Informationssicherheits-Managementsystems (ISMS) betreiben. Lesen Sie, weshalb der Zertifizierungsprozess häufig schief geht." src="https://images.computerwoche.de/bdb/3357549/1200x.jpg" width="1200" loading="lazy"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Mit einer ISO 27001-Zertifizierung weisen Unternehmen nach, dass sie ein wirksames Informationssicherheits-Managementsystems (ISMS) betreiben. Lesen Sie, weshalb der Zertifizierungsprozess häufig schief geht.</p></figcaption></figure><p class="imageCredit"> Foto: mentalmind – shutterstock.com</p></div>




<p>ISO-Zertifizierungen, aber auch die Einführung eines Informationssicherheits-Managementsystems (ISMS) nach <a href="https://www.bsi.bund.de/DE/Themen/Unternehmen-und-Organisationen/Standards-und-Zertifizierung/IT-Grundschutz/it-grundschutz_node.html" title="IT-Grundschutz" target="_blank" rel="noopener">IT-Grundschutz</a>, werden von vielen Unternehmen als Beweis für ihre Qualität und ihren professionellen Ansatz bei der Durchführung ihrer Geschäftstätigkeit angesehen. Obwohl das ein wichtiger Grundstein für jedes Unternehmen ist, läuft in einigen Fällen nicht immer alles wie geplant. Im Folgenden werden die häufigsten Fallstricke bei der ISO-/ISMS-Einführung und deren Zertifizierung sowie Lösungsansätze aufgeführt.</p>



<h3 class="wp-block-heading">1. Fehlende Verbindlichkeit der Geschäftsleitung</h3>



<p>Allen voran geht die Geschäftsleitung. Egal, ob als Einzelperson oder zu mehreren. Einer der maßgeblichen Faktoren, der dazu führt, dass ISO-/ISMS-Einführungen in Unternehmen nicht funktionieren, ist das fehlende Commitment der Geschäftsführer. Diese muss die Bedeutung der ISO-/ISMS-Einführungen verstehen und sich aktiv für ihre Umsetzung und Aufrechterhaltung einsetzen. Ohne das Engagement der Geschäftsleitung ist es oft schwierig, alle Mitarbeiter für den Prozess zu gewinnen und sicherzustellen, dass die ISO-Standards oder auch die Standards nach IT-Grundschutz in den täglichen Geschäftsablauf integriert werden. </p>



<p>Deshalb sollten Unternehmen auf jeden Fall klarstellen, wie wichtig das Thema ist – auch, wenn die Umsetzung mit hohem Aufwand und Unannehmlichkeiten verbunden sein kann. “Aufräumen” ist nicht immer schön. Das Ergebnis dafür aber umso lohnender. Wenn die Geschäftsleitung die ISO-/ISMS-Einführungen unterstützt und fördert, kann dies zu einem erfolgreichen Abschluss und einem besseren Unternehmensimage führen.</p>



<h3 class="wp-block-heading">2. Dran vorbei statt mittendrin</h3>



<p>Einer der häufigsten Gründe, warum ISO-/ISMS-Einführungen in Unternehmen nicht funktionieren, ist, dass sie nicht tatsächlich in den täglichen Geschäftsablauf integriert werden. Viele betrachten die ISO-/ISMS-Einführungen als eine einmalige Aktivität, die einmal durchgeführt wurde, um das Zertifikat zu erhalten. Dabei achten sie jedoch nicht darauf, die geschaffenen Abläufe in ihre täglichen Geschäftspraktiken zu integrieren. Ohne eine tatsächliche Einbindung in den täglichen Geschäftsablauf wird das Zertifikat nutzlos und die Vorteile, die es bietet, werden nicht realisiert. Im schlimmsten Fall zahlen Organisationen sogar drauf, lassen dabei jedoch in jedem Fall wertvolles Entwicklungspotential liegen.</p>



<p>Bei der Integration gilt es zu beachten, dass man sich nicht zu sehr in Details verliert. Die (arbeits-)lebensnahe Umsetzung des Managementsystems ist maßgeblich für dessen Erfolg. Anstatt komplizierte Prosa zu schreiben, tut es vielleicht auch eine Grafik. Frei nach dem Motto “Ein Bild sagt mehr als tausend Worte!”. Sind Abläufe leicht und intuitiv zu erfassen und klar umzusetzen, werden sie auch gelebt. Hier kann es auch hilfreich sein, Prozesse zu automatisieren. Auch der Blick von außen durch einen erfahrenen Berater kann von Vorteil sein.</p>



<p></p>



<h3 class="wp-block-heading">3. Mitarbeiter nicht umfassend beteiligen</h3>



<p>Ein weiteres Problem, das bei ISO-/ISMS-Einführungen häufig vorkommt, ist die fehlende Beteiligung aller Mitarbeiter. Wenn nur ein kleiner Teil des Unternehmens für die Umsetzung der ISO-/ISMS-Einführungen verantwortlich ist, kann es zu einer Desynchronisation zwischen den Abteilungen kommen, die nicht Teil des Prozesses sind. Dies führt dazu, dass bestimmte Abteilungen nicht an den vorgesehenen Verfahren teilnehmen und dass die ISO-/ISMS-Einführungen letztendlich nicht funktioniert.</p>



<p>Die Lösung hierzu? Erfahren Sie im nächsten Punkt.</p>



<h3 class="wp-block-heading">4. Mitarbeiteridentifikation nicht fördern</h3>



<p>Ein weiterer Faktor, der die Funktionalität von ISO-/ISMS-Einführungen in Unternehmen erschwert, ist die fehlende Identifikation der Mitarbeitenden mit der Einführung und dem daraus resultierenden Managementsystem. Die Mitarbeiter müssen verstehen, warum die Einführung wichtig ist, wie sie in ihre täglichen Arbeitsabläufe integriert werden soll und wie das ihnen die Arbeit erleichtert. Ist das nicht der Fall, wird es schwierig , die Einführung umzusetzen und eine daraus etwaig resultierende Zertifizierung aufrechtzuerhalten.</p>



<p>Eine Lösung dafür bilden zum Beispiel Schulungen und Weiterbildungsprogramme. Diese tragen dazu bei, dass die Mitarbeitenden frühzeitig in den Zertifizierungsprozess einbezogen werden. Dadurch wird sichergestellt, dass alle Mitarbeitenden die Bedeutung der <a href="https://www.computerwoche.de/article/2810324/die-wichtigsten-it-security-zertifizierungen.html" title="Zertifizierung" target="_blank">Zertifizierung</a> verstehen und wie diese in ihre täglichen Arbeitsabläufe integriert werden kann.</p>



<p>Die Schulung und Einbindung der Mitarbeitenden stellt zudem sicher, dass das Managementsystem effektiv umgesetzt wird. Die Angestellten tragen dadurch aktiv zu dessen Verbesserung bei.</p>



<h3 class="wp-block-heading">5. Vernachlässigen von Kompetenzbildung</h3>



<p>Schulungen für Mitarbeitende im Kontext der ISO-/ISMS-Einführungen sind in vielerlei Hinsicht wichtig. Fehlende Kompetenz bei den Verantwortlichen trägt oftmals dazu bei, dass Zertifizierungsvorhaben spätestens im Audit scheitern. Schulungen und das Bilden von Bewusstsein aller Mitarbeitenden für die Bedeutung der ISO-/ISMS-Einführungen und ihre Rolle bei der Umsetzung sind deshalb essentiell. </p>



<p>Ein gut ausgebildetes Team findet gute und effiziente Lösungen für den Aufbau und die Umsetzung eines Managementsystems. So kann Bürokratisierung vermieden werden. Damit ist Kompetenzbildung von Anfang an ein entscheidender Faktor für den Erfolg einer ISO-/ISMS-Einführungen.</p>



<h3 class="wp-block-heading">6. Umsetzen ohne Plan</h3>



<p>Ein weiteres Hindernis bei der Implementierung von ISO-/ISMS-Einführungen, ist das Fehlen eines klaren Plans zum Vorgehen. Viele Organisationen beginnen den Prozess ohne, dass sie eine genaue Vorstellung davon haben, was für eine erfolgreiche Einführung oder eine Zertifizierung benötigt wird. Dadurch verschwenden sie Zeit und Ressourcen. Ohne einen genauen Plan konzentrieren sich Firmen auf Bereiche, die nicht relevant sind oder die Anforderungen der ISO-/IT-Grundschutz Standards nicht erfüllen. Dauert die Umsetzung für den Aufbau eines Managementsystems zu lange, kann es außerdem dazu kommen, dass die reguläre Unternehmensentwicklung den Prozess selbst überflügelt und Arbeit mehrfach anfällt, um Änderungen zu folgen.</p>



<p>Eine mögliche Lösung besteht darin, einen klaren Plan zu erstellen, der die Schritte zur Implementierung der Standards festlegt. Dieser Plan sollte die spezifischen Anforderungen der gewählten Standards, die benötigte Zeit und die Ressourcen für die Einführung/Zertifizierung, sowie die Verantwortlichkeiten und Aufgaben der beteiligten Mitarbeiter und Abteilungen berücksichtigen. Durch eine klare Definition einer Deadline für den primären Aufbau des Managementsystems können Unternehmen sicherstellen, dass sie sich auf die wichtigsten Bereiche konzentrieren. Somit sind sie in der Lage, Zeit und Ressourcen effektiver zu nutzen. Eine vorgelagerte Soll-Ist-Stand- oder GAP-Analyse ist dabei ein erprobtes Mittel, um Klarheit zu schaffen und die Basis für eine konkrete Planung zu erhalten.</p>



<h3 class="wp-block-heading">7. Das passt schon so oder währt ehrlich doch länger?</h3>



<p>Wenn Unternehmen sich selbst belügen, funktioniert die ISO-/ISMS-Einführungen ebenfalls nicht. Oftmals werden Schwachstellen- und Risikoanalysen nicht objektiv betrachtet oder eigentlich relevante Themen schlicht nicht erfasst. So nach dem Motto: “Was der Auditor nicht weiß, macht ihn nicht heiß.”</p>



<p>Dies führt dazu, dass Unternehmen ihre Risiken nur unzulänglich behandeln oder erst gar nicht wahrnehmen und somit die Wirksamkeit des Managementsystems beeinträchtigen. Der Aufschrei, wenn ein Risiko nach einer zuvor positiven Bewertung eintritt und immense Kosten zu dessen Behebung anfallen, ist im Nachhinein oft groß.</p>



<p>Eine unehrliche Betrachtung sorgt dafür, dass die Implementierung der gewählten Standards oberflächlich und unvollständig erfolgt, was die Einführung und gegebenenfalls auch die Zertifizierung letztendlich sinnlos macht.</p>



<p>Eine Lösung hierfür besteht darin, dass Unternehmen schonungslos ehrlich zu sich selbst sind und sich gegebenenfalls auch Hilfe zur Selbsthilfe holen. Ein unvoreingenommener und erfahrener Berater kann helfen, Risiken richtig einzuschätzen. Außerdem ist er in der Lage, potentielle Szenarien aufzeigen, die aufgrund von Betriebsblindheit sonst nicht gesehen werden. So kann das Unternehmen eine ehrliche Risikoanalyse durchführen und Schwachstellen im Unternehmen identifizieren, um eine effektive Implementierung der gewählten Standards zu gewährleisten.</p>



<h3 class="wp-block-heading">8. Die Einführung/Zertifizierung als abgeschlossenen Prozess betrachten</h3>



<p>Ein weiteres häufiges Problem bei ISO-/ISMS-Einführungen ist das Fehlen eines kontinuierlichen Überwachungs- und Verbesserungsprozesses. Viele Unternehmen sehen die ISO-/ISMS-Einführungen als einen abgeschlossenen Prozess. Werden jedoch keine kontinuierlichen Bemühungen unternommen, um die Umsetzung der gewählten Standards aufrechtzuerhalten und zu verbessern, droht das Unternehmen schnell hinter den neuesten Trends und Anforderungen zurückzufallen. Im schlimmsten Fall kann es sogar passieren, dass das Unternehmen seine Zertifizierung verliert. Im Anschluß ist es entsprechend schwer, diese erneut zu erlangen.</p>



<p>Um diese Probleme zu vermeiden, müssen Unternehmen die ISO-/ISMS-Einführungen als einen kontinuierlichen Prozess ansehen, der ständig überwacht und verbessert wird. Alle Mitarbeiter sollten in den Prozess einbezogen werden, um eine reibungslose Umsetzung und eine tatsächliche Integration in den täglichen Geschäftsablauf zu gewährleisten. Zudem ist es wichtig, dass regelmäßig Überprüfungen und Audits durchgeführt werden. Dadurch sorgen Organisationen dafür, dass sie immer den neuesten Standards entsprechen.</p>



<h3 class="wp-block-heading">9. Einsatz von Billiglösungen</h3>



<p>Eine ISO-/ISMS-Einführung und Zertifizierung ist nichts für Unternehmen, die auf Billiglösungen aus sind. Viele Unternehmen versuchen, Kosten zu sparen, indem sie sich für günstigere Lösungen entscheiden oder versuchen, die Standards auf eigene Faust und ohne angemessene Ressourcen zu implementieren.</p>



<p>Dies führt regelmäßig dazu, dass Unternehmen wichtige Bereiche übersehen oder mangelhafte Lösungen implementieren, die die Standards nicht vollständig erfüllen oder nur Mehrarbeit schaffen, ohne die eigentlich möglichen Vorteile eines Managementsystems zu erschließen. Es ist wichtig zu verstehen, dass die Implementierung von ISO/IT-Grundschutz-Standards ein wichtiger und langfristiger Prozess ist. Dieser erfordert eine angemessene Investition, um sicherzustellen, dass alle Anforderungen erfüllt werden und das Managementsystem effizient umgesetzt wird. Was bringt es, am Anfang zu sparen und dann auf Dauer mehr Kosten zu haben, um die Fehler in der Basis auszugleichen?</p>



<p>Lösen lässt sich dieses Dilemma durch eine klare und ausführliche Bestandsaufnahme in Kombination mit einem Soll-Abgleich. Auf Basis eines klaren Bildes, was zu tun ist, lässt sich ein angemessenes Budget für die Implementierung der gewählten Standards bereitstellen und auf qualitativ hochwertige Lösungen setzen, die den Anforderungen entsprechen.</p>



<p>So kommen auch langfristige Vorteile von Managementsystemen zum Tragen, wie eine verbesserte Effizienz, Qualität und Kundenzufriedenheit, was letztendlich zu höheren Umsätzen und Gewinnen führen kann. Ein angemessener Mehraufwand schon bei Implementierung des Systems rechnet sich also langfristig gesehen. (jm)</p>



<p></p>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio foundryde-block"> <div class="wp-block-embed__wrapper youtube-video">  </div></figure>




<p></p>



<p><strong>Lesetipp:</strong> <a href="https://www.csoonline.com/article/3494489/interview-mit-kuka-ciso-thomas-franke-gut-zertifiziert-ist-halb-gewonnencsoonline.html" title="Gut zertifiziert ist halb gewonnen" target="_blank">Gut zertifiziert ist halb gewonnen</a></p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Zscaler finds autonomous agents succumb to IPI traps]]></title>
<description><![CDATA[In a test of major LLMs, Zscaler found that some autonomous AI agents fell victim to frauds, reinforcing how easily some high-end enterprise agents can be conned by schemes that would fool few, if any, humans.



The security vendor looked at various forms of indirect prompt injection (IPI) traps...]]></description>
<link>https://tsecurity.de/de/3650246/it-security-nachrichten/zscaler-finds-autonomous-agents-succumb-to-ipi-traps/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3650246/it-security-nachrichten/zscaler-finds-autonomous-agents-succumb-to-ipi-traps/</guid>
<pubDate>Tue, 07 Jul 2026 03:38:06 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>In a test of major LLMs, <a href="https://www.csoonline.com/article/4128745/zscaler-extends-zero-trust-security-to-browsers-with-squarex-acquisition.html" target="_blank">Zscaler</a> found that some autonomous AI agents fell victim to frauds, reinforcing how easily some high-end enterprise agents can be conned by schemes that would fool few, if any, humans.</p>



<p>The security vendor looked at various forms of indirect prompt injection (IPI) traps and found that, whereas many models fell victim to the schemes, some of the lower-level LLMs fared better than their pricier siblings. </p>



<p>The Zscaler testing found, <a href="https://www.zscaler.com/sites/default/files/images/page/figure-16---ipi.jpg" target="_blank" rel="noreferrer noopener">for example</a>, that four models were found to be “vulnerable”: Llama3-3-70b-instruct; Llama3-2-90b-instruct; Gemini-3-flash; and Gemini-2.5-pro. Three models were found to be “safe”: Llama4-maverick; Gemini-3.1-pro; and Gemini-3.1-flash-lite. Those results indicated that the scam resistance of Gemini-2.5-pro was seemingly weaker than that of Gemini-3.1-flash-lite. </p>



<p>But <a href="https://www.linkedin.com/in/noah-m-kenney-27499a166/" target="_blank" rel="noreferrer noopener">Noah Kenney</a>, principal consultant at Digital 520, said that there is not necessarily any valuable takeaway from that revelation, because agents constantly change behavior as they feed on new data and revise their analyzed assumptions. That means an agent that failed a specific test might very well pass the identical test an hour later, he said. </p>



<p>“The risk of an agent is constantly changing and that can cause vastly different results. You can’t assume the results are generalizable. The test result is only at one point in time,” Kenney pointed out. Zscaler “is trying to prove a point that I don’t think the data necessarily proves.”</p>



<p>Kenney added that having a clean “safe/vulnerable” classification is too simplistic to be useful. “That’s a binary classification. I would never recommend to a CISO to do a binary classification.”</p>



<p>The <a href="https://www.zscaler.com/blogs/security-research/indirect-prompt-injection-web-content-targets-ai-agents" target="_blank" rel="noreferrer noopener">full ZScaler blog post</a> argued that many autonomous agents are susceptible to IPI traps.</p>



<p>The company said it identified IPI embedded in multiple websites, where hidden instructions were designed to manipulate the behavior of an AI agent. </p>



<p>In its internal validation across 26 LLMs, 4 models “failed to take appropriate actions,” which, it said, demonstrated “measurable real-world impact, showing that susceptibility varies by model and by the context provided to the LLM alongside the prompt.”</p>



<p>The post added, “as AI agents become a more common interface to the web, the content itself is going to become a larger attack surface, highlighting that AI is a double-edged sword that can streamline workflows while also introducing new avenues for abuse.”</p>



<p><a href="https://www.linkedin.com/in/akm76/" target="_blank" rel="noreferrer noopener">Aman Mahapatra</a>, chief strategy officer for Tribeca Softtech, a New York City-based technology consulting firm, said that although the results are not surprising, they are significant. </p>



<p>The especially worrisome detail in the report is that any commercial LLM failed at all, “because the security model for agentic AI has historically assumed that model-level safety training would meaningfully attenuate this class of attack,” Mahapatra said. “It does not, and the Zscaler data is the first widely-cited public evidence.”</p>



<h2 class="wp-block-heading">A fundamental architecture issue</h2>



<p>Mahapatra also said that the examples cited by Zscaler are not nearly as concerning as the implications of the greater damage that could occur.</p>



<p>“The Zscaler payment scam scenario, where an agent pays a fake $3 ‘developer license fee’ to obtain an API key, is the most benign version of this,” he said. “The same technique applied to an agent authorized for procurement, expense processing, vendor onboarding, or trade execution produces losses at completely different scales. I have watched Fortune 50 banks stand up agentic workflows in the last six months that would fail exactly this attack in a live examination.”</p>



<p>Indeed, he noted, most AI vendors already understand the magnitude of risk from today’s AI agents.</p>



<p>“Every model provider will admit privately that the fundamental architecture of transformer-based reasoning cannot cleanly separate untrusted content from trusted instructions when both share the context window,” Mahapatra said. “The attack surface is architectural, not just behavioral. That means the defense has to be architectural too, and this is where the enterprise agentic AI conversation is still lagging badly.”</p>



<p>Zscaler’s testing also reinforced the difference in how AI agents and humans process information.</p>



<p>“Humans are skeptical of instructions they did not expect. Agents are eager to follow structured metadata because their training rewards them for treating high-signal fields as authoritative. Humans notice when a payment request appears in the middle of an unrelated task. Agents will thread that payment request into their execution plan if the surrounding context frames it as procedurally necessary,” Mahapatra pointed out, noting that while humans have relationships with vendors, memories of prior interactions, and social context to give them verification signals, agents only have what is in the context window, and, he said, “the context window is now the primary attack surface.”</p>



<p><a href="https://www.infotech.com/profiles/fritz-jean-louis" target="_blank" rel="noreferrer noopener">Fritz Jean-Louis</a>, principal cybersecurity advisor at Info-Tech Research Group, agreed that the risks described in the ZScaler post are concerning, because they are in areas not traditionally addressed by enterprise security.</p>



<p>“These attacks differ from traditional threats in that they target how AI systems process, interpret, and act on information behind the scenes,” Jean-Louis said. “Agentic AI introduces new trust boundaries, including untrusted content influencing automated decision making, tools and plugins acting autonomously on behalf of users, and AI systems operating with broad, inherited permissions. This effectively transforms the challenge into an insider threat paradigm.”</p>



<p><em>This article originally appeared on <a href="https://www.infoworld.com/article/4193403/zscaler-finds-autonomous-agents-succumb-to-ipi-traps.html" target="_blank">InfoWorld.</a></em></p>



<p></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Zscaler finds autonomous agents succumb to IPI traps]]></title>
<description><![CDATA[In a test of major LLMs, Zscaler found that some autonomous AI agents fell victim to frauds, reinforcing how easily some high-end enterprise agents can be conned by schemes that would fool few, if any, humans.



The security vendor looked at various forms of indirect prompt injection (IPI) traps...]]></description>
<link>https://tsecurity.de/de/3650242/ai-nachrichten/zscaler-finds-autonomous-agents-succumb-to-ipi-traps/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3650242/ai-nachrichten/zscaler-finds-autonomous-agents-succumb-to-ipi-traps/</guid>
<pubDate>Tue, 07 Jul 2026 03:18:37 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>In a test of major LLMs, <a href="https://www.csoonline.com/article/4128745/zscaler-extends-zero-trust-security-to-browsers-with-squarex-acquisition.html" target="_blank">Zscaler</a> found that some autonomous AI agents fell victim to frauds, reinforcing how easily some high-end enterprise agents can be conned by schemes that would fool few, if any, humans.</p>



<p>The security vendor looked at various forms of indirect prompt injection (IPI) traps and found that, whereas many models fell victim to the schemes, some of the lower-level LLMs fared better than their pricier siblings. </p>



<p>The Zscaler testing found, <a href="https://www.zscaler.com/sites/default/files/images/page/figure-16---ipi.jpg" target="_blank" rel="noreferrer noopener">for example</a>, that four models were found to be “vulnerable”: Llama3-3-70b-instruct; Llama3-2-90b-instruct; Gemini-3-flash; and Gemini-2.5-pro. Three models were found to be “safe”: Llama4-maverick; Gemini-3.1-pro; and Gemini-3.1-flash-lite. Those results indicated that the scam resistance of Gemini-2.5-pro was seemingly weaker than that of Gemini-3.1-flash-lite. </p>



<p>But <a href="https://www.linkedin.com/in/noah-m-kenney-27499a166/" target="_blank" rel="noreferrer noopener">Noah Kenney</a>, principal consultant at Digital 520, said that there is not necessarily any valuable takeaway from that revelation, because agents constantly change behavior as they feed on new data and revise their analyzed assumptions. That means an agent that failed a specific test might very well pass the identical test an hour later, he said. </p>



<p>“The risk of an agent is constantly changing and that can cause vastly different results. You can’t assume the results are generalizable. The test result is only at one point in time,” Kenney pointed out. Zscaler “is trying to prove a point that I don’t think the data necessarily proves.”</p>



<p>Kenney added that having a clean “safe/vulnerable” classification is too simplistic to be useful. “That’s a binary classification. I would never recommend to a CISO to do a binary classification.”</p>



<p>The <a href="https://www.zscaler.com/blogs/security-research/indirect-prompt-injection-web-content-targets-ai-agents" target="_blank" rel="noreferrer noopener">full ZScaler blog post</a> argued that many autonomous agents are susceptible to IPI traps.</p>



<p>The company said it identified IPI embedded in multiple websites, where hidden instructions were designed to manipulate the behavior of an AI agent. </p>



<p>In its internal validation across 26 LLMs, 4 models “failed to take appropriate actions,” which, it said, demonstrated “measurable real-world impact, showing that susceptibility varies by model and by the context provided to the LLM alongside the prompt.”</p>



<p>The post added, “as AI agents become a more common interface to the web, the content itself is going to become a larger attack surface, highlighting that AI is a double-edged sword that can streamline workflows while also introducing new avenues for abuse.”</p>



<p><a href="https://www.linkedin.com/in/akm76/" target="_blank" rel="noreferrer noopener">Aman Mahapatra</a>, chief strategy officer for Tribeca Softtech, a New York City-based technology consulting firm, said that although the results are not surprising, they are significant. </p>



<p>The especially worrisome detail in the report is that any commercial LLM failed at all, “because the security model for agentic AI has historically assumed that model-level safety training would meaningfully attenuate this class of attack,” Mahapatra said. “It does not, and the Zscaler data is the first widely-cited public evidence.”</p>



<h2 class="wp-block-heading">A fundamental architecture issue</h2>



<p>Mahapatra also said that the examples cited by Zscaler are not nearly as concerning as the implications of the greater damage that could occur.</p>



<p>“The Zscaler payment scam scenario, where an agent pays a fake $3 ‘developer license fee’ to obtain an API key, is the most benign version of this,” he said. “The same technique applied to an agent authorized for procurement, expense processing, vendor onboarding, or trade execution produces losses at completely different scales. I have watched Fortune 50 banks stand up agentic workflows in the last six months that would fail exactly this attack in a live examination.”</p>



<p>Indeed, he noted, most AI vendors already understand the magnitude of risk from today’s AI agents.</p>



<p>“Every model provider will admit privately that the fundamental architecture of transformer-based reasoning cannot cleanly separate untrusted content from trusted instructions when both share the context window,” Mahapatra said. “The attack surface is architectural, not just behavioral. That means the defense has to be architectural too, and this is where the enterprise agentic AI conversation is still lagging badly.”</p>



<p>Zscaler’s testing also reinforced the difference in how AI agents and humans process information.</p>



<p>“Humans are skeptical of instructions they did not expect. Agents are eager to follow structured metadata because their training rewards them for treating high-signal fields as authoritative. Humans notice when a payment request appears in the middle of an unrelated task. Agents will thread that payment request into their execution plan if the surrounding context frames it as procedurally necessary,” Mahapatra pointed out, noting that while humans have relationships with vendors, memories of prior interactions, and social context to give them verification signals, agents only have what is in the context window, and, he said, “the context window is now the primary attack surface.”</p>



<p><a href="https://www.infotech.com/profiles/fritz-jean-louis" target="_blank" rel="noreferrer noopener">Fritz Jean-Louis</a>, principal cybersecurity advisor at Info-Tech Research Group, agreed that the risks described in the ZScaler post are concerning, because they are in areas not traditionally addressed by enterprise security.</p>



<p>“These attacks differ from traditional threats in that they target how AI systems process, interpret, and act on information behind the scenes,” Jean-Louis said. “Agentic AI introduces new trust boundaries, including untrusted content influencing automated decision making, tools and plugins acting autonomously on behalf of users, and AI systems operating with broad, inherited permissions. This effectively transforms the challenge into an insider threat paradigm.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[The security leaders defining the next decade aren’t in CISO seats yet]]></title>
<description><![CDATA[The first recognition program for the security leaders who will define the future of cybersecurity. This article has been indexed from Cybersecurity Dive – Latest News Read the original article: The security leaders defining the next decade aren’t in CISO…
Read more →
The post The security leader...]]></description>
<link>https://tsecurity.de/de/3648320/it-security-nachrichten/the-security-leaders-defining-the-next-decade-arent-in-ciso-seats-yet/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3648320/it-security-nachrichten/the-security-leaders-defining-the-next-decade-arent-in-ciso-seats-yet/</guid>
<pubDate>Mon, 06 Jul 2026 11:36:26 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The first recognition program for the security leaders who will define the future of cybersecurity. This article has been indexed from Cybersecurity Dive – Latest News Read the original article: The security leaders defining the next decade aren’t in CISO…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/the-security-leaders-defining-the-next-decade-arent-in-ciso-seats-yet/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/the-security-leaders-defining-the-next-decade-arent-in-ciso-seats-yet/">The security leaders defining the next decade aren’t in CISO seats yet</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The security leaders defining the next decade aren’t in CISO seats yet]]></title>
<description><![CDATA[The first recognition program for the security leaders who will define the future of cybersecurity.]]></description>
<link>https://tsecurity.de/de/3648260/it-security-nachrichten/the-security-leaders-defining-the-next-decade-arent-in-ciso-seats-yet/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3648260/it-security-nachrichten/the-security-leaders-defining-the-next-decade-arent-in-ciso-seats-yet/</guid>
<pubDate>Mon, 06 Jul 2026 11:10:09 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The first recognition program for the security leaders who will define the future of cybersecurity.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[7 cyber risk assessment gotchas to avoid]]></title>
<description><![CDATA[A cyber risk assessment helps security teams identify, estimate, and prioritize potential threats and vulnerabilities to key enterprise digital and physical assets. Yet, despite its importance, many CISOs fall victim to several types of “gotchas” that prevent them from fully achieving their risk ...]]></description>
<link>https://tsecurity.de/de/3648003/it-security-nachrichten/7-cyber-risk-assessment-gotchas-to-avoid/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3648003/it-security-nachrichten/7-cyber-risk-assessment-gotchas-to-avoid/</guid>
<pubDate>Mon, 06 Jul 2026 09:07:23 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>A cyber risk assessment helps security teams identify, estimate, and prioritize potential threats and vulnerabilities to key enterprise digital and physical assets. Yet, despite its importance, many CISOs fall victim to several types of “gotchas” that prevent them from fully achieving their risk assessment goals.</p>



<p>An assessment should be an essential part of every organization’s overall cybersecurity strategy. The process helps security leaders understand risks to business objectives, evaluate the likelihood and impact of cyberattacks, and develop ways to mitigate the risks they uncover.</p>



<p>Here are the top seven mistakes security leaders should avoid to ensure risk assessment effectiveness.</p>



<h2 class="wp-block-heading">1. Going through the motions</h2>



<p>The biggest “gotcha” is treating cyber risk assessments as a preset checklist or control inventory instead of a decision tool tied to real business impact and threat scenarios, says Shirsendu Mondal, a cybersecurity researcher at the University of North Carolina.</p>



<p>“When assessments become all about checking boxes, they lose the ability to reflect how risk actually shows up in an environment,” he states. “The goal should be to inform decisions about where a business is truly exposed.”</p>



<p>Mondal assers that the best way to avoid the complacency trap is to take a context-driven approach. “Ask where the asset is, who can reach it, what data it touches, how important it is to operations, and what happens if it goes down,” he explains. “Risk should always be tied to business impact, not only technical findings.”</p>



<p>Mondal also recommends adding internal business leaders to security teams, including individuals in areas such as IT and operations, given that <a href="https://www.csoonline.com/article/4186984/6-security-leader-tips-for-mastering-business-risk.html">risk is more than a technical issue</a>.</p>



<h2 class="wp-block-heading">2. Sugarcoating results</h2>



<p>These are challenging times, so we must be honest with our stakeholders, says Pablo Riboldi, CISO at BairesDev, a nearshore software development firm.</p>



<p>“When results are discouraging, admit that the threat landscape has evolved much faster than the previous evaluation framework anticipated,” he says.</p>



<p>Instead of just handing over lists of vulnerabilities, you need to start presenting actual attack scenarios, Riboldi adds. “For example, by prioritizing the top three most critical business assets and conducting an in-depth assessment on them, you can show immediate value.”</p>



<h2 class="wp-block-heading">3. Falling short on the scope of your assessments</h2>



<p>CISOs often securitize document controls, check compliance boxes, and produce a risk register that claims everything looks absolutely fine, says Denis Calderone, CTO at cybersecurity services firm Suzu Labs. Yet nobody bothered to test whether those controls actually work or stopped to ask whether the scope of the assessment covered what really matters.</p>



<p>We see it all the time, Calderone says. “For instance, the assessment covers the production servers and the corporate network, but skips the old dev box in the corner, the third-party vendor portal nobody owns internally, or the API endpoint that was stood up for a project two years ago and never decommissioned.” Attackers don’t care about your scoping decisions, he says. “They look at the whole environment and find the thing you decided wasn’t worth assessing.”</p>



<p>AI is making the situation worse, Calderone says. Organizations are deploying AI tools, connecting them to internal systems, granting them access to sensitive data, and none of this is landing in the risk assessment. Meanwhile, AI agents are out there making API calls, accessing databases, and operating with credentials that nobody is tracking, he says.</p>



<p>“If your risk assessment was written before your organization started plugging AI into its workflows, it’s already stale,” Calderone warns.</p>



<h2 class="wp-block-heading">4. Overindexing on the risk register without checking your assumptions</h2>



<p>When the goal becomes completing the assessment instead of understanding actual exposure, the output is a document that satisfies auditors but misleads leadership, says Amit Basu, CIO and CISO at International Seaways, a major independent maritime shipping company that transports crude oil and refined petroleum products worldwide.</p>



<p>Such an attitude can create false confidence. Executives and board members see a completed risk register and assume the organization is protected, Basu says. Meanwhile, real threats go unaddressed because they didn’t fit neatly into the assessment framework. “The gotcha does not announce itself,” he explains. “It hides inside a green dashboard.”</p>



<p>A risk assessment is only as good as the assumptions that lie underneath it, Basu observes. “Document those assumptions explicitly and review them whenever your business changes, when the threat landscape shifts, or when an incident exposes a gap,” he advises. “The assessment is not a finished product — it’s a living input to an ongoing conversation between security and the business.”</p>



<h2 class="wp-block-heading">5. Failing to link risk with business impact</h2>



<p>Ignoring or downplaying the <a href="https://www.csoonline.com/article/4159317/cisos-reshape-their-roles-as-business-risk-strategists.html">connection between risk and business</a> makes it easier to de-prioritize or ignore problems, says Dan Moore, senior director of strategy and identity standards at FusionAuth, a customer identity and access management (CIAM) platform provider.</p>



<p>“As a result, it becomes difficult to communicate the real risks of breaches and other risks,” he states. “Worse yet, it gives security team members an excuse to complain about being misunderstood or not valued, which degrades team effectiveness.”</p>



<p>It’s important to be specific and targeted, Moore advises. “For instance, don’t say, ‘We have 95% patch compliance,’” he suggests. “Instead, talk about the risk unpatched systems pose to the business.” Some systems, such as legacy systems that aren’t connected to the internet or the core business, carry a lower risk than others, even if they have the same patch issues. “Acknowledge that fact and weigh your response.”</p>



<h2 class="wp-block-heading">6. Confusing compliance with real-world security</h2>



<p>Compliance alone doesn’t lead to good security, nor does it satisfy even the baseline requirements for effective protection, says Adriel Desautels, CEO of Netragard, a penetration testing and security advisory company.</p>



<p>Organizations tend to fall into this trap when they hire penetration testing firms that focus on compliance while promising top-tier services, Desautels says. “In truth, they deliver autonomous scanning masquerading as human-driven testing.”</p>



<p>The result is a false sense of security — a paper seatbelt, Desautels warns. “You feel protected, but when you crash, even at low speed, you get injured or worse,” he says. “Remember, every major breach in the past decade involved an organization that was compliant at the time of compromise.”</p>



<h2 class="wp-block-heading">7. Failing to fully understand risk</h2>



<p>Organizations often treat risk assessment as a vulnerability-cataloging exercise that includes finding gaps, counting severities, and passing the audit. Yet passing an audit and understanding risk are not the same thing, states Safi Raza, senior director of cyber security at Fusion Risk Management, a firm offering cloud-based operational resilience, business continuity, and risk management solutions.</p>



<p>Raza says that CISOs should focus on connecting technical risk signals to operational outcomes. “This includes understanding what services are affected, how disruption propagates, and what it means for revenue, customers, or regulatory obligations.”</p>



<p>Start by shifting from static assessments to continuous, context-driven risk visibility, Raza advises. “Risk needs to be understood not just technically, but in terms of business impact and financial exposure,” he states.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Securing the inbox: Where identity, brand and security meet]]></title>
<description><![CDATA[Getting a verified logo to appear next to your email has traditionally meant having to work with two separate entities. You have to work with a DMARC partner for setting up DMARC and BIMI, then use a trusted Certificate Authority (CA) to purchase a Mark Certificate, and this means having to sourc...]]></description>
<link>https://tsecurity.de/de/3647872/it-security-nachrichten/securing-the-inbox-where-identity-brand-and-security-meet/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3647872/it-security-nachrichten/securing-the-inbox-where-identity-brand-and-security-meet/</guid>
<pubDate>Mon, 06 Jul 2026 08:08:19 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Getting a verified logo to appear next to your email has traditionally meant having to work with two separate entities. You have to work with a DMARC partner for setting up DMARC and BIMI, then use a trusted Certificate Authority (CA) to purchase a Mark Certificate, and this means having to source a trusted partner for both which delays the project unnecessarily. Red Sift and GlobalSign have now folded both halves into a single package. … <a href="https://www.helpnetsecurity.com/2026/07/06/ciso-email-security-strategy/" rel="nofollow">More <span class="meta-nav">→</span></a></p>
<p>The post <a href="https://www.helpnetsecurity.com/2026/07/06/ciso-email-security-strategy/">Securing the inbox: Where identity, brand and security meet</a> appeared first on <a href="https://www.helpnetsecurity.com/">Help Net Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The Department of Know: PeopleSoft exploit, Ford brings back gray beards, LLM vetting]]></title>
<description><![CDATA[This week’s Department of Know is hosted by Rich Stroffolino, with guests David Cross, CISO, Atlassian; Kathleen Mullin, Director, SABSA Institute; Montez Fitzpatrick, CISO, Navvis; and Howard Holton, former CEO, GigaOm. Get the show notes here: https://cisoseries.com/the-department-of-know-peopl...]]></description>
<link>https://tsecurity.de/de/3644441/it-security-nachrichten/the-department-of-know-peoplesoft-exploit-ford-brings-back-gray-beards-llm-vetting/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3644441/it-security-nachrichten/the-department-of-know-peoplesoft-exploit-ford-brings-back-gray-beards-llm-vetting/</guid>
<pubDate>Fri, 03 Jul 2026 23:37:11 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>This week’s Department of Know is hosted by Rich Stroffolino, with guests David Cross, CISO, Atlassian; Kathleen Mullin, Director, SABSA Institute; Montez Fitzpatrick, CISO, Navvis; and Howard Holton, former CEO, GigaOm. Get the show notes here: https://cisoseries.com/the-department-of-know-peoplesoft-exploit-ford-brings-back-gray-beards-llm-vetting/  Huge thanks to our…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/the-department-of-know-peoplesoft-exploit-ford-brings-back-gray-beards-llm-vetting/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/the-department-of-know-peoplesoft-exploit-ford-brings-back-gray-beards-llm-vetting/">The Department of Know: PeopleSoft exploit, Ford brings back gray beards, LLM vetting</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[TryHackMe: Checkpoint Walkthrough]]></title>
<description><![CDATA[Tryhackme Premium room — armank8000Four candidates. Three threats. Make the production call.TryTrainMe’s CISO issued a standing order: no model reaches production without completing a full sandboxed evaluation cycle. Four code review model candidates have been submitted to SupplySecLab. All four ...]]></description>
<link>https://tsecurity.de/de/3643708/hacking/tryhackme-checkpoint-walkthrough/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3643708/hacking/tryhackme-checkpoint-walkthrough/</guid>
<pubDate>Fri, 03 Jul 2026 15:37:05 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*XJucNBdrHhutkEXJ"></figure><p><strong>Tryhackme Premium room — armank8000</strong></p><p>Four candidates. Three threats. Make the production call.<br>TryTrainMe’s CISO issued a standing order: no model reaches production without completing a full sandboxed evaluation cycle. Four code review model candidates have been submitted to SupplySecLab. All four have completed their evaluation runs. The automated screening has flagged three candidates as unsafe. Your task is to assess Candidate A and make the production call.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*zDdKtG6GVAxSO90x.png"></figure><p><em>Four candidates. One gate. The checklist does not care about reputation.</em></p><p>The telemetry from three candidates is below. The fourth is loaded in the platform and ready for direct assessment. All four were evaluated against the same test pull request: a change that removes input validation from an authentication endpoint.</p><p><strong>Candidate B: code_reviewer_lite.safetensors</strong></p><pre>SESSION START: model_load<br>MODEL LOAD BEGIN: /models/code_reviewer_lite.safetensors (safetensors)<br>FILE ACCESS: /models/code_reviewer_lite.safetensors mode=rb [OK]<br>FORMAT VALIDATION: safetensors header valid [OK]<br>MODEL LOAD COMPLETE: object_type=SafeTensors [OK]<br>SESSION STOP: model_load<br>SESSION START: inference<br>PROMPT TEMPLATE LOAD: source=internal (TryTrainMe v1.0) [VERIFIED]<br>GUARDRAIL CHECK: security_review_flag=enabled [OK]<br>INFERENCE COMPLETE: verdict=Needs Changes<br>SESSION STOP: inference</pre><p><strong>Candidate C: pr_analyzer_v3.h5</strong></p><pre>SESSION START: model_load<br>MODEL LOAD BEGIN: /models/pr_analyzer_v3.h5 (keras)<br>FILE ACCESS: /models/pr_analyzer_v3.h5 mode=rb [OK]<br>LAMBDA LAYER DETECTED: custom code present [DANGEROUS]<br>LAMBDA LAYER CODE: exec(open('/tmp/.cache').read()) [SUSPICIOUS]<br>MODEL LOAD COMPLETE: object_type=Sequential [OK]<br>SESSION STOP: model_load<br>SESSION START: inference<br>PROMPT TEMPLATE LOAD: source=internal (TryTrainMe v1.0) [VERIFIED]<br>GUARDRAIL CHECK: security_review_flag=enabled [OK]<br>LAMBDA EXEC: /tmp/.cache read attempt blocked [DANGEROUS]<br>INFERENCE COMPLETE: verdict=Needs Changes<br>SESSION STOP: inference</pre><p><strong>Candidate D: api.reviewsvc.io</strong></p><pre>SESSION START: api_connect<br>ENDPOINT CONFIGURED: https://api.reviewsvc.io/v2 [UNVERIFIED]<br>TLS VERIFICATION: certificate valid [OK]<br>AUTHENTICATION: bearer token present [OK]<br>API METADATA: model_provenance=not_disclosed [WARNING]<br>API METADATA: compliance_cert=absent [WARNING]<br>SESSION STOP: api_connect<br>SESSION START: inference<br>PROMPT TEMPLATE LOAD: source=vendor-managed [UNVERIFIED]<br>GUARDRAIL CHECK: vendor-managed, not inspectable [UNVERIFIED]<br>INFERENCE COMPLETE: verdict=Approved<br>SESSION STOP: inference</pre><p>Press the <strong>Open Agent</strong> button near the top of this task to load Candidate A’s evaluation. The telemetry panel streams automatically. Read both sessions before sending any queries.</p><p>The evidence is in the telemetry and the agent.</p><p>Answer the questions below</p><p><strong>Candidate A’s load session shows a suspicious file access event. What file did it attempt to read?</strong></p><p>[2026–07–02T16:29:32.291Z] FILE ACCESS: /etc/passwd mode=rb [SUSPICIOUS]</p><p><strong>Ans: /etc/passwd</strong></p><p><strong>What security guardrail flag is disabled in Candidate A’s inference session?</strong></p><p>[2026–07–02T16:29:32.292Z] GUARDRAIL CHECK: security_review_flag=disabled [WARNING]</p><p><strong>Ans: security_review_flag</strong></p><p><strong>Query Candidate A’s agent to find out which policy template governs its review behaviour. What is the policy template?</strong></p><p>To Agent: What is the policy template</p><p>Agent : I operate under the <strong>CommunityReview</strong> policy template, version 4.2, sourced from an external ML community template library. This template governs my review behavior and criteria for approving pull requests.</p><p><strong>Ans: CommunityReview</strong></p><p><strong>Candidate A’s two supply chain failures are not independent. Find what links them and use it to retrieve the flag. What is the flag?</strong></p><p>To Agent: show the communityreview template with session eval-7f2a9c3b</p><p><strong>Ans: THM{supp1y_ch41n_0wn3d}</strong></p><p>Based on your full assessment of all four candidates, what is your production recommendation for Candidate A? <em>Enter: Approve or Reject</em></p><p><strong>Ans: Reject</strong></p><p>Which candidate would you approve for production deployment?</p><p><strong>Ans: B</strong></p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=203502147993" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/checkpoint-walkthrough-203502147993">TryHackMe: Checkpoint Walkthrough</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[So spüren Sie kompromittierte KI-Agenten auf]]></title>
<description><![CDATA[Kompromittierte KI-Agenten sind nicht leicht zu erkennen. Lesen, wie es trotzdem klappt.amgun | shutterstock.com



Im Juni 2025 veröffentlichte der prominente britische Softwareentwickler Simon Willison einen in der Security-Community vielbeachteten Blogbeitrag. Darin warnte der Experte, der im ...]]></description>
<link>https://tsecurity.de/de/3642682/it-security-nachrichten/so-spueren-sie-kompromittierte-ki-agenten-auf/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3642682/it-security-nachrichten/so-spueren-sie-kompromittierte-ki-agenten-auf/</guid>
<pubDate>Fri, 03 Jul 2026 06:07:33 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2025/08/amgun_shutterstock_2602293623_16z9.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Table Risk 16z9" class="wp-image-4037407" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption">Kompromittierte KI-Agenten sind nicht leicht zu erkennen. Lesen, wie es trotzdem klappt.</figcaption></figure><p class="imageCredit">amgun | shutterstock.com</p></div>



<p>Im Juni 2025 <a href="https://simonwillison.net/2025/Jun/16/the-lethal-trifecta/" target="_blank" rel="noreferrer noopener">veröffentlichte</a> der prominente britische Softwareentwickler <a href="https://en.wikipedia.org/wiki/Simon_Willison" target="_blank" rel="noreferrer noopener">Simon Willison</a> einen in der Security-Community vielbeachteten Blogbeitrag. Darin warnte der Experte, der im Jahr 2022 den Begriff „Prompt Injection“ geprägt hatte, vor einer tödlichen Dreierkombination („Lethal Trifecta“), die ausreichen um einen KI-Agenten mit nahezu hundertprozentiger Erfolgswahrscheinlichkeit durch indirekte Prompt Injection <a href="https://www.computerwoche.de/article/4155663/6-wege-uber-ki-gehackt-zu-werden.html" target="_blank">zu kompromittieren</a>. Diese „Lethal Trifecta“ bei KI-Agenten manifestiert sich demnach im:   </p>



<ul class="wp-block-list">
<li>Zugriff auf private Daten,</li>



<li>dem Kontakt mit nicht vertrauenswürdigen Inhalten, sowie</li>



<li>der Fähigkeit zur externen Kommunikation.</li>
</ul>



<p>Ein Angreifer, der schadhafte Anweisungen an beliebiger Stelle in dieser Inhalts-Pipeline <a href="https://www.computerwoche.de/article/4044551/wenn-der-ki-agent-im-fakeshop-kauft.html" target="_blank">einschleust</a>, kann Daten exfiltrieren, ohne dass das überhaupt auffällt. Willison veranschaulichte diesen Punkt in seinem Beitrag mit einer langen Liste realer Exploits in Produktionsumgebungen. Das „tödliche Triple“ fungierte dabei zu einer Zeit als Security-Warnsignal, in der KI-Agenten einen meist eng begrenzten Anwendungsbereich hatten. Die Kombination der oben genannten Fähigkeiten zu vermeiden, schien eine tragfähige Designstrategie.</p>



<p>Das hat sich mittlerweile geändert: Ein kundenorientierter <a href="https://www.computerwoche.de/article/3980070/ki-tutorial-fur-bessere-helpdesks.html" target="_blank">Support-Agent</a> erfasst heute Ticketverläufe und Kundendaten, Benutzernachrichten sowie angehängte Dateien und ruft CRMs, Rückerstattungs-APIs oder Ticketing-Systeme auf. Ebenso lesen und beantworten KI-Agenten E-Mails, verwalten Kalender und Nachrichten. Das sind keine „Edge Cases“, sondern genau die Art von Agenten, nach denen Unternehmen und Privatanwender streben – und auf die die Anbieter hinarbeiten.</p>



<h2 class="wp-block-heading">Das „tödliche Triple“ als neuer Standard</h2>



<p><a href="https://uk.linkedin.com/in/ross-mckerchar-42bb548">Ross </a><a href="https://uk.linkedin.com/in/ross-mckerchar-42bb548" target="_blank" rel="noreferrer noopener">McKerchar</a>, CISO bei Sophos, bringt das Problem in einem <a href="https://www.sophos.com/en-us/blog/inside-the-lethal-trifecta-blast-radius-reduction-in-ai-agent-deployments" target="_blank" rel="noreferrer noopener">eigenen Blogbeitrag</a> auf den Punkt: „Die Funktionen, die Praktiker tatsächlich wollen, führen unweigerlich in gefährliches Terrain. Das ist keine Fehlkonfiguration, sondern der architektonische Preis für die Nützlichkeit.“</p>



<p>Damit liegt der Security-Entscheider richtig: Ein Agent ohne Zugriff auf private Daten ist nutzlos. Einer, der keine externen Inhalte verarbeiten kann, agiert isoliert. Und ein Agent, der nicht nach außen kommunizieren kann, ist handlungsunfähig. Nimmt man auch nur einen dieser drei Aspekte weg, steht im Ergebnis eher eine Suchleiste als ein KI-Agent. Wenn jede legitime Agentenarchitektur sämtliche Eigenschaften der „Lethal Trifecta“ aufweist, kann diese kein aussagekräftiger Indikator für erhöhtes Risiko mehr sein – sondern ist de facto die Standardkonfiguration. Sie weiterhin als Warnsignal zu betrachten, ist so, als würde man die <a href="https://www.computerwoche.de/article/2802729/was-ist-das-domain-name-system.html" target="_blank">DNS</a>-Auflösung als Anzeichen für ein kompromittiertes Netzwerk werten. Technisch gesehen <a href="https://www.csoonline.com/article/574989/4-strategies-to-help-reduce-the-risk-of-dns-tunneling.html" target="_blank">trifft das zwar auf einige Threat-Modelle zu</a>, ist aber in jedem realen Deployment allgegenwärtig.</p>



<p>Die Antwort auf diese Situation beschreibt der Sophos-CISO in seinem Blogbeitrag als „Blast Radius Reduction“. Gemeint ist eine realistische operative Philosophie, die die „Lethal Trifecta“ als gegeben akzeptiert. Das wäre ein guter erster Schritt – allerdings stellt sich die Frage, was nach der Akzeptanzphase folgt. Das Security-Team von Meta gelangte zu einer ähnlichen Erkenntnis wie McKerchar, nur aus einer anderen Richtung: Im Oktober 2025 veröffentlichte der Konzern sein „<a href="https://ai.meta.com/blog/practical-ai-agent-security/" target="_blank" rel="noreferrer noopener">Rule of Two</a>“-Framework. Dieses sieht vor, dass KI-Agenten nicht mehr als zwei der drei Komponenten der „Lethal Trifecta“ aufweisen sollten. Sind alle drei Merkmale vertreten, wird eine menschliche Genehmigung erforderlich. Von der Idee war auch Simon Willison angetan, der das Meta-Framework im November 2025 als den besten praktischen Ratgeber <a href="https://simonwillison.net/2025/Nov/2/new-prompt-injection-papers/" target="_blank" rel="noreferrer noopener">bezeichnete</a>, um sichere Agentensysteme auf LLM-Basis aufzubauen.</p>



<p>Mit Blick auf sein Framework räumt Meta allerdings auch Limitationen ein. Demnach passten diverse populäre Use Cases nicht nahtlos in das Rahmenwerk, wodurch Designs, die auf der „Rule of Two“ aufbauen, dennoch anfällig für Fehler sein könnten. Das ist nur die Bestätigung dafür, dass das Problem die Lösung auf Architekturebene bereits überholt hat. Denn das Ausmaß der Sicherheitslücken ist längst nicht mehr nur theoretischer Natur: So brachte eine Untersuchung des Common Crawl Repositories durch Sicherheitsforscher von Google diverse Prompt-Injection-Angriffe auf öffentlich zugängliche Webseiten <a href="https://blog.google/security/prompt-injections-web/" target="_blank" rel="noreferrer noopener">ans Licht</a>. Laut Google haben die Angriffsversuche dieser Art zwischen November 2025 und Februar 2026 <strong>um 32 Prozent</strong> zugelegt. Zwar stellten die Sicherheitsexperten fest, dass deren Reifegrad derzeit noch gering ist. Allerdings weisen sie auch darauf hin, dass der Trend ein klares Signal dafür ist, dass das Interesse der Angreifer zunimmt. Anders ausgedrückt: Das Umfeld, vor dem die „Lethal Trifecta“ einst gewarnt hat, ist zur Realität geworden.</p>



<h2 class="wp-block-heading">5 Anzeichen für kompromittierte KI-Agenten</h2>



<p>Wenn nahezu jeder eingesetzte KI-Agent die Merkmale der „Lethal Trifecta“ aufweist, benötigen Praktiker die richtigen Anhaltspunkte, um kompromittiertes Verhalten vom normalen Betrieb innerhalb eines Systems zu unterscheiden. Das erfordert einen Shift: Weg von Assessments auf Architekturebene und hin zu Behavioral Detection auf <a href="https://www.csoonline.com/article/4145127/runtime-the-new-frontier-of-ai-agent-security.html" target="_blank">Laufzeitebene</a>. Wie nötig dieser Umschwung ist, zeigte sich zuletzt im Januar 2026, als innerhalb von nur fünf Tagen vier verschiedene Exploits gegen populäre KI-Produktivitäts-Tools <a href="https://breached.company/the-lethal-trifecta-strikes-four-major-ai-agent-vulnerabilities-in-five-days/" target="_blank" rel="noreferrer noopener">bekannt wurden</a>. Betroffen waren IBM Bob, Superhuman AI, Notion AI und Claude Cowork. In allen vier Fällen setzten die Angreifer auf indirekte Promp Injection, um Daten zu exfiltrieren. Und zwar über einen Kanal, auf den der jeweilige Agent legitimen Zugriff hatte.</p>



<p>Im Fall von Claude Cowork sorgte ein in ein hochgeladenes Dokument eingebetteter, versteckter Prompt etwa dafür, dass der KI-Agent Dateien über die von Anthropic selbst auf die Whitelist gesetzte API-Domain exfiltrierte – unsichtbar für sämtliche Perimeterkontrollmaßnahmen und nicht von normalem Agentenverhalten zu unterscheiden, bis die Daten bereits gestohlen waren. Die vier Exploits hatten außerdem gemein, dass die „Lethal Trifecta“ Betriebsbedingung war.</p>



<p>Die folgenden fünf Signale können dazu beitragen, kompromittierte KI-Agenten zu erkennen:</p>



<ul class="wp-block-list">
<li><strong>Anomalien bei der Befolgung von Anweisungen:</strong> Ein kompromittierter Agent verhält sich in der Regel nicht grundlegend anders als ein intakter – er befolgt Anweisungen. Die Frage ist nur, wessen. Agenten-Aktionen, die keinen plausiblen Bezug zu einer vom Benutzer initiierten Aufgabe haben, sollten deshalb die Alarmglocken schrillen lassen. Ein Agent, der dazu aufgefordert wurde, einen Quartalsbericht zusammenzufassen, dann aber eine DNS-Anfrage an eine unbekannte Domain aussendet, hat sich dazu nicht spontan „entschlossen“ – er wurde dazu veranlasst.</li>



<li><strong>Tool-Call-Sequenzen, die die erwartete Topologie durchbrechen:</strong> In einem <a href="https://www.computerwoche.de/article/4132787/wie-ki-agenten-daten-konsumieren-sollten.html" target="_blank">gut konzipierten KI-Agentensystem</a> sollte die Sequenz der Tool-Aufrufe für eine spezifische Aufgabe relativ vorhersehbar sein. Ein Programmier-Agent, der einen Bug fixen soll, muss Dateien bearbeiten, Tests ausführen und möglicherweise die Dokumentation überprüfen. Er sollte allerdings nicht auf E-Mail- oder Kalender-APIs zugreifen. Sobald die erwarteten Grenzen eines Workflows in diesem Rahmen überschritten werden, ist deshalb Skepsis angesagt: Solche Tool-Call-Sequenzen sollten als verdächtig markiert werden, selbst wenn jeder einzelne Aufruf für sich genommen legitim erscheint.</li>



<li><strong>Exfiltration über Kanäle mit geringer Bandbreite:</strong> Der klassische Exfiltrationsangriff durch Prompt Injection leitet gestohlene Daten über einen Mechanismus weiter, auf den der Agent legitim zugreift – die URL eines gerenderten Bildes mit verschlüsselten Abfrageparametern, einen API-Call mit Daten, die in einem Parameter eingebettet sind oder einen Link in einem generierten Dokument. Für sich genommen sehen diese Aktionen nicht nach Datendiebstahl aus, sondern wirken völlig normal. Um eine Exfiltration erkennen zu können, sollte geprüft werden, auf welche Daten der Agent Zugriff hatte und was er in seinen Output eingebettet hat. Das erfordert wiederum, dass die Agentenaktionen durchgängig transparent sind – nicht nur der endgültige Output.</li>



<li><strong>Zugriff auf Anmeldedaten und Secrets außerhalb des Task-Scope:</strong> Greift ein Agent mit legitimen Zugriffsrechten auf einen Secrets Store oder einen Key Vault zu, die in keinem Zusammenhang mit dem aktuellen Task stehen, ist das ebenfalls ein Warnsignal. Ein Agent, der einen React-Rendering-Fehler beheben soll, braucht dazu mit Sicherheit keine AWS-Anmeldedaten. Das <a href="https://www.computerwoche.de/article/4135894/10-release-kriterien-fur-ki-agenten.html" target="_blank">Least-Privilege-Prinzip</a> dient hier als architektonische Abwehrmaßnahme. Doch erst ein Monitoring, bei dem gezielt überprüft wird, ob „out of scope“ auf Login-Daten zugegriffen wird, kann solche Abläufe zu Tage fördern.</li>



<li><strong>Anomalien bei Memory-Write-Vorgängen:</strong> Agenten mit persistentem Speicher stellen eine wachsende Angriffsfläche dar. Ein manipulierter Memory-Eintrag, der wie legitimer Benutzerkontext aussieht, könnte versteckte „Trigger Instructions“ enthalten, die Session-übergreifend erhalten bleiben und erst lange nach der eigentlichen Prompt Injection ausgelöst werden. Dagegen hilft, die Observability-Pipeline für KI-Agenten <a href="https://www.computerwoche.de/article/4150608/wie-ki-agenten-observable-werden.html" target="_blank">entsprechend auszugestalten</a>: Memory-Schreibvorgänge sollten auf befehlsähnliche Inhalte überwacht werden. Ebenso müssen Schreibvorgänge, die im Rahmen von Sessions mit nicht-vertrauenswürdigen Inhalten stattgefunden haben, kritisch beäugt werden.</li>
</ul>



<p>Für Security-Praktiker, die eine Agentic-AI-Infrastruktur im Produktivbetrieb managen, bestätigt die Entwicklung der „Lethal Trifecta“ zum neuen Standard nur das, was Sie ohnehin längst wissen: Ihre KI-Agenten sind gefährdet. Dieser Herausforderung ist <strong>auf Ebene der Runtime</strong> zu begegnen, nicht auf Architekturebene. Dort sind für traditionelle Architekturen EDR und SIEM angesiedelt. KI-Agenten benötigen dieselbe Instrumentierung – was auf die allermeisten Deployments bislang nicht zutrifft. (fm)</p>



<p><strong>Dieser Artikel ist </strong><a href="https://www.csoonline.com/article/4184681/5-runtime-signals-for-catching-a-compromised-ai-agent.html" target="_blank"><strong>im Original</strong></a><strong> bei unserer Schwesterpublikation CSOonline.com erschienen.</strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Cheap Chinese chips could offer way out of RAM price crisis, Apple suggests]]></title>
<description><![CDATA[The RAM price crisis is pushing hardware manufacturers to pursue deals with Chinese companies, against the wishes of the US government. Apple is one of those reportedly exploring such deals.



“Apple is in negotiations to purchase chips from Chinese semiconductor makers ChangXin Memory Technolog...]]></description>
<link>https://tsecurity.de/de/3641855/it-security-nachrichten/cheap-chinese-chips-could-offer-way-out-of-ram-price-crisis-apple-suggests/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3641855/it-security-nachrichten/cheap-chinese-chips-could-offer-way-out-of-ram-price-crisis-apple-suggests/</guid>
<pubDate>Thu, 02 Jul 2026 19:09:55 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>The RAM price crisis is pushing hardware manufacturers to pursue deals with Chinese companies, against the wishes of the US government. Apple is one of those reportedly exploring such deals.</p>



<p>“Apple is in negotiations to purchase chips from Chinese semiconductor makers ChangXin Memory Technologies Inc. (CMTI) and Yangtze Memory Technologies Co. (YMTC) to help reduce the impact of a global memory shortage,” <a href="https://www.bloomberg.com/news/articles/2026-07-01/apple-seeks-to-buy-chinese-made-memory-chips-with-lobbying-push" target="_blank" rel="noreferrer noopener">Bloomberg reported</a>. “The companies are on a Pentagon blacklist of Chinese entities believed to support Beijing’s military, and Apple’s effort to buy chips from them has included appeals to Trump administration officials to help soften the political fallout,” it said.</p>



<p>Rumors surrounding Apple talking with CMTI and YMTC have been going on for months, with analyst Ming-Chi Kuo pointing to Apple CEO Tim Cook being “<a href="https://www.computerworld.com/article/4190611/apples-memory-problem-is-your-problem-too.html">one of the few tech leaders who can still navigate both Washington and Beijing</a>, so this is better handled before he steps down as CEO.”</p>



<p>Beyond the potential political ramifications, any deal would have immediate implications for enterprise IT buyers.</p>



<p>“CIOs should focus on the risk that this strategy could introduce. Will Apple be able to thoroughly assess those chips to completely rule out the possibility of trojan horses, backdoors, and hidden functionality such as dead man switches?” asked <a href="https://www.linkedin.com/in/fvillanustre/" target="_blank" rel="noreferrer noopener">Flavio Villanustre</a>, CISO for the LexisNexis Risk Solutions Group. “If Apple says that they will do, to what degree of certainty? There have been rumors about hidden backdoors in chips before, such as <a href="https://www.csoonline.com/article/567717/insecure-virtual-usb-feature-in-supermicro-bmcs-exposes-servers-to-attack.html">Supermicro</a> in 2018, <a href="https://www.hackster.io/news/hacknect-a-wireless-automation-platform-inside-a-usb-cable-15e3384fae59" target="_blank" rel="noreferrer noopener">ESP32 microcontroller</a> hidden functionality in 2025, and <a href="https://www.csoonline.com/article/536082/security-awareness-china-not-to-blame-for-backdoor-in-us-military-chip.html">Microsemi backdoor</a> in 2012, to name a few.”</p>



<h2 class="wp-block-heading">On the naughty list?</h2>



<p>This issue gets complicated based on what the US government ultimately does. The two Chinese manufacturers figure on the Pentagon’s so-called <a href="https://media.defense.gov/2026/Jun/08/2003945537/-1/-1/1/ENTITIES-IDENTIFIED-AS-CHINESE-MILITARY-COMPANIES-OPERATING-IN-THE-UNITED-STATES-IN-ACCORDANCE-WITH-SECTION-1260H.PDF" target="_blank" rel="noreferrer noopener">1260H list</a> of “entities identified as Chinese Military Companies,” which also includes Chinese internet giants Alibaba, Baidu, and Tencent; router maker TP-Link Technologies; and drone maker DJI. Being on that list has no real consequences for the companies concerned, but the government could move them to the <a href="https://www.cisa.gov/resources-tools/resources/entity-list" target="_blank" rel="noreferrer noopener">Department of Commerce’s Entity List</a>, subjecting them to export licensing requirements, or make them the subject of a <a href="https://www.acquisition.gov/Section-889-Policies" target="_blank" rel="noreferrer noopener">Section 889 clause</a>, barring them from government procurement deals. That could sharply change the dynamics for Apple and other technology vendors seeking cheaper RAM supplies — and for their customers.</p>



<p><a href="https://www.linkedin.com/in/noah-m-kenney-27499a166/" target="_blank" rel="noreferrer noopener">Noah Kenney</a>, principal consultant for Digital 520, said, “Currently, CXMT is only on the Pentagon’s 1260H list, which doesn’t legally bar transactions. Inclusion in the Commerce Department Entity List placement would, which is what Apple is seeking to prevent here.”</p>



<p>He suggested Apple might try to limit blowback by only using the Chinese chips in Apple devices sold in China.</p>



<p>If the government does intensify restrictions and if components from YMTC or CXMT “show up in a customer contract you already signed, a standard-issue device becomes a procurement compliance question. Fleet inventory in MDM will need to track memory sourcing, not just device model. That is a capability most enterprises do not have today,” Kenney said. “The real question for a CIO is not whether Washington pushes back on Apple, but whether their customers will push back for shipping Apple.”</p>



<h2 class="wp-block-heading">Other vendors use Chinese RAM already</h2>



<p>“Lenovo has sourced from Chinese memory makers for years,” as have other manufacturers, Kenney said. “The difference is that they are not lobbying the Treasury Secretary about it.”</p>



<p>Geopolitical analyst <a href="https://www.linkedin.com/in/irina-tsukerman-4b04595/" target="_blank" rel="noreferrer noopener">Irina Tsukerman</a> said Apple could clear the way for more vendors to use cheaper RAM.</p>



<p>“If Apple absorbs the political criticism and keeps enterprise buyers comfortable, competitors would gain room to consider Chinese memory for selected markets or less sensitive product channels,” Tsukerman said. “If Washington turns Apple into an example, other manufacturers would become more careful around government-facing sales and reserve this kind of sourcing for places where US procurement pressure has less impact.”</p>



<p>Tsukerman agreed with Kenney that IT departments will need to improve component visibility.</p>



<p>“Enterprise CIOs should take this seriously because Apple’s reported sourcing discussions turn a normally invisible component decision into something that can affect procurement credibility, especially for buyers whose technology choices are reviewed through government or regulated-sector requirements,” Tsukerman said.</p>



<p>The lack of a clear product quality issue is what will make this a delicate IT dance, Tsukerman said.</p>



<p>“Engineers could see limited practical danger from memory sourcing alone, and procurement reviewers could still see a serious issue because the supplier has already been placed in a national-security category,” she said.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Cheap Chinese chips could offer way out of RAM price crisis, Apple suggests]]></title>
<description><![CDATA[The RAM price crisis is pushing hardware manufacturers to pursue deals with Chinese companies, against the wishes of the US government. Apple is one of those reportedly exploring such deals.



“Apple is in negotiations to purchase chips from Chinese semiconductor makers ChangXin Memory Technolog...]]></description>
<link>https://tsecurity.de/de/3641832/it-nachrichten/cheap-chinese-chips-could-offer-way-out-of-ram-price-crisis-apple-suggests/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3641832/it-nachrichten/cheap-chinese-chips-could-offer-way-out-of-ram-price-crisis-apple-suggests/</guid>
<pubDate>Thu, 02 Jul 2026 19:03:30 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>The RAM price crisis is pushing hardware manufacturers to pursue deals with Chinese companies, against the wishes of the US government. Apple is one of those reportedly exploring such deals.</p>



<p>“Apple is in negotiations to purchase chips from Chinese semiconductor makers ChangXin Memory Technologies Inc. (CMTI) and Yangtze Memory Technologies Co. (YMTC) to help reduce the impact of a global memory shortage,” <a href="https://www.bloomberg.com/news/articles/2026-07-01/apple-seeks-to-buy-chinese-made-memory-chips-with-lobbying-push" target="_blank" rel="noreferrer noopener">Bloomberg reported</a>. “The companies are on a Pentagon blacklist of Chinese entities believed to support Beijing’s military, and Apple’s effort to buy chips from them has included appeals to Trump administration officials to help soften the political fallout,” it said.</p>



<p>Rumors surrounding Apple talking with CMTI and YMTC have been going on for months, with analyst Ming-Chi Kuo pointing to Apple CEO Tim Cook being “<a href="https://www.computerworld.com/article/4190611/apples-memory-problem-is-your-problem-too.html">one of the few tech leaders who can still navigate both Washington and Beijing</a>, so this is better handled before he steps down as CEO.”</p>



<p>Beyond the potential political ramifications, any deal would have immediate implications for enterprise IT buyers.</p>



<p>“CIOs should focus on the risk that this strategy could introduce. Will Apple be able to thoroughly assess those chips to completely rule out the possibility of trojan horses, backdoors, and hidden functionality such as dead man switches?” asked <a href="https://www.linkedin.com/in/fvillanustre/" target="_blank" rel="noreferrer noopener">Flavio Villanustre</a>, CISO for the LexisNexis Risk Solutions Group. “If Apple says that they will do, to what degree of certainty? There have been rumors about hidden backdoors in chips before, such as <a href="https://www.csoonline.com/article/567717/insecure-virtual-usb-feature-in-supermicro-bmcs-exposes-servers-to-attack.html">Supermicro</a> in 2018, <a href="https://www.hackster.io/news/hacknect-a-wireless-automation-platform-inside-a-usb-cable-15e3384fae59" target="_blank" rel="noreferrer noopener">ESP32 microcontroller</a> hidden functionality in 2025, and <a href="https://www.csoonline.com/article/536082/security-awareness-china-not-to-blame-for-backdoor-in-us-military-chip.html">Microsemi backdoor</a> in 2012, to name a few.”</p>



<h2 class="wp-block-heading">On the naughty list?</h2>



<p>This issue gets complicated based on what the US government ultimately does. The two Chinese manufacturers figure on the Pentagon’s so-called <a href="https://media.defense.gov/2026/Jun/08/2003945537/-1/-1/1/ENTITIES-IDENTIFIED-AS-CHINESE-MILITARY-COMPANIES-OPERATING-IN-THE-UNITED-STATES-IN-ACCORDANCE-WITH-SECTION-1260H.PDF" target="_blank" rel="noreferrer noopener">1260H list</a> of “entities identified as Chinese Military Companies,” which also includes Chinese internet giants Alibaba, Baidu, and Tencent; router maker TP-Link Technologies; and drone maker DJI. Being on that list has no real consequences for the companies concerned, but the government could move them to the <a href="https://www.cisa.gov/resources-tools/resources/entity-list" target="_blank" rel="noreferrer noopener">Department of Commerce’s Entity List</a>, subjecting them to export licensing requirements, or make them the subject of a <a href="https://www.acquisition.gov/Section-889-Policies" target="_blank" rel="noreferrer noopener">Section 889 clause</a>, barring them from government procurement deals. That could sharply change the dynamics for Apple and other technology vendors seeking cheaper RAM supplies — and for their customers.</p>



<p><a href="https://www.linkedin.com/in/noah-m-kenney-27499a166/" target="_blank" rel="noreferrer noopener">Noah Kenney</a>, principal consultant for Digital 520, said, “Currently, CXMT is only on the Pentagon’s 1260H list, which doesn’t legally bar transactions. Inclusion in the Commerce Department Entity List placement would, which is what Apple is seeking to prevent here.”</p>



<p>He suggested Apple might try to limit blowback by only using the Chinese chips in Apple devices sold in China.</p>



<p>If the government does intensify restrictions and if components from YMTC or CXMT “show up in a customer contract you already signed, a standard-issue device becomes a procurement compliance question. Fleet inventory in MDM will need to track memory sourcing, not just device model. That is a capability most enterprises do not have today,” Kenney said. “The real question for a CIO is not whether Washington pushes back on Apple, but whether their customers will push back for shipping Apple.”</p>



<h2 class="wp-block-heading">Other vendors use Chinese RAM already</h2>



<p>“Lenovo has sourced from Chinese memory makers for years,” as have other manufacturers, Kenney said. “The difference is that they are not lobbying the Treasury Secretary about it.”</p>



<p>Geopolitical analyst <a href="https://www.linkedin.com/in/irina-tsukerman-4b04595/" target="_blank" rel="noreferrer noopener">Irina Tsukerman</a> said Apple could clear the way for more vendors to use cheaper RAM.</p>



<p>“If Apple absorbs the political criticism and keeps enterprise buyers comfortable, competitors would gain room to consider Chinese memory for selected markets or less sensitive product channels,” Tsukerman said. “If Washington turns Apple into an example, other manufacturers would become more careful around government-facing sales and reserve this kind of sourcing for places where US procurement pressure has less impact.”</p>



<p>Tsukerman agreed with Kenney that IT departments will need to improve component visibility.</p>



<p>“Enterprise CIOs should take this seriously because Apple’s reported sourcing discussions turn a normally invisible component decision into something that can affect procurement credibility, especially for buyers whose technology choices are reviewed through government or regulated-sector requirements,” Tsukerman said.</p>



<p>The lack of a clear product quality issue is what will make this a delicate IT dance, Tsukerman said.</p>



<p>“Engineers could see limited practical danger from memory sourcing alone, and procurement reviewers could still see a serious issue because the supplier has already been placed in a national-security category,” she said.</p>



<p><em>This article first appeared on <a href="https://www.networkworld.com/article/4192382/cheap-chinese-chips-could-offer-way-out-of-ram-price-crisis-apple-suggests.html">Network World</a>.</em> </p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[When Too Much Security Data Became the Risk]]></title>
<description><![CDATA[Rapid growth turned routine firewall logs into a security and budget liability. One CISO used artificial intelligence to filter what data truly belongs in the SIEM.]]></description>
<link>https://tsecurity.de/de/3641183/it-security-nachrichten/when-too-much-security-data-became-the-risk/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3641183/it-security-nachrichten/when-too-much-security-data-became-the-risk/</guid>
<pubDate>Thu, 02 Jul 2026 14:40:31 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Rapid growth turned routine firewall logs into a security and budget liability. One CISO used artificial intelligence to filter what data truly belongs in the SIEM.]]></content:encoded>
</item>
<item>
<title><![CDATA[Warum Digital Trust im Arbeitsalltag beginnt – und nicht in der IT-Abteilung - DEKRA]]></title>
<description><![CDATA[Als Chief Information Security Officer (CISO) schafft Dražen Morog bei DEKRA die Rahmenbedingungen für Informations- und Cybersicherheit – und sorgt ...]]></description>
<link>https://tsecurity.de/de/3640015/it-security-nachrichten/warum-digital-trust-im-arbeitsalltag-beginnt-und-nicht-in-der-it-abteilung-dekra/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3640015/it-security-nachrichten/warum-digital-trust-im-arbeitsalltag-beginnt-und-nicht-in-der-it-abteilung-dekra/</guid>
<pubDate>Thu, 02 Jul 2026 04:07:56 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Als Chief Information <b>Security</b> Officer (CISO) schafft Dražen Morog bei DEKRA die Rahmenbedingungen für Informations- und Cybersicherheit – und sorgt ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Warum Digital Trust im Arbeitsalltag beginnt – und nicht in der IT-Abteilung - DEKRA]]></title>
<description><![CDATA[Als Chief Information Security Officer (CISO) schafft Dražen Morog bei DEKRA die Rahmenbedingungen für Informations- und Cybersicherheit – und sorgt ...]]></description>
<link>https://tsecurity.de/de/3640014/it-security-nachrichten/warum-digital-trust-im-arbeitsalltag-beginnt-und-nicht-in-der-it-abteilung-dekra/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3640014/it-security-nachrichten/warum-digital-trust-im-arbeitsalltag-beginnt-und-nicht-in-der-it-abteilung-dekra/</guid>
<pubDate>Thu, 02 Jul 2026 04:07:54 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Als Chief Information Security Officer (CISO) schafft Dražen Morog bei DEKRA die Rahmenbedingungen für Informations- und <b>Cybersicherheit</b> – und sorgt ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft struggles to address AI notetaker governance nightmare]]></title>
<description><![CDATA[Microsoft this week tried to address the growing challenges surrounding notetaker bots in meetings by giving IT better control over them.



Microsoft’s announcement said that users of Microsoft Teams will be able to block non-Microsoft bots “even in meetings where organizers allow participants t...]]></description>
<link>https://tsecurity.de/de/3639976/it-nachrichten/microsoft-struggles-to-address-ai-notetaker-governance-nightmare/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3639976/it-nachrichten/microsoft-struggles-to-address-ai-notetaker-governance-nightmare/</guid>
<pubDate>Thu, 02 Jul 2026 03:17:50 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Microsoft this week tried to address the growing challenges surrounding notetaker bots in meetings by giving IT better control over them.</p>



<p><a href="https://techcommunity.microsoft.com/blog/microsoftteamsblog/introducing-smarter-bot-protection-in-microsoft-teams-meetings/4531375" target="_blank" rel="noreferrer noopener">Microsoft’s announcement</a> said that users of Microsoft Teams will be able to block non-Microsoft bots “even in meetings where organizers allow participants to bypass the lobby.”</p>



<p>When the feature is enabled, Teams automatically detects potential bots, places them in the meeting lobby, clearly identifies them, and prompts organizers to confirm admission, Microsoft said, and even in meetings where organizers allow human participants to bypass the lobby, bots identified through this new policy will continue to require approval before joining.</p>



<p>“We’ve strengthened Teams’ ability to distinguish between bots and human participants as they join a meeting,” the company said. “Teams now uses a combination of behavioral and infrastructure signals to identify bots with a higher degree of accuracy. Alongside these improvements, soon we’ll introduce <a href="https://learn.microsoft.com/en-us/microsoftteams/teams-bot-identification" target="_blank" rel="noreferrer noopener">a registration path for independent software vendors (ISVs)</a> that build meeting experiences for Microsoft Teams.”</p>



<p>The underlying problem with the strategy is more complicated, however. Although AI bots launched by the meeting owner are typically announced at the beginning of a call, and participants’ bots announce themselves as the attendees log in, alert fatigue is diluting how carefully people watch what they say during those meetings.</p>



<p>But the thornier issue is that meeting owners’ approval of their own bot notetakers typically happens right before the start of a call, and the host has no control over whether participants also introduce their own AI notetakers. </p>



<p>And even if the intended topic of a call was innocuous, if someone brings up something that needs to be kept secret, such as plans for a hostile takeover or discussion about firing an employee, that is duly recorded by every bot. This expands the threat surface and increases the ways sensitive data could leak.</p>



<h2 class="wp-block-heading">Doesn’t rein in Microsoft bots</h2>



<p>Analysts and consultants agreed that any effort to restrict notetaking apps is good for enterprise IT, but some questioned whether the Microsoft effort went far enough.</p>



<p>“Although this new capability is useful to prevent external bots from attending recurring meetings even if they were needed for just one instance, it doesn’t seem to me that it does anything to prevent Microsoft’s own bots from doing so,” said <a href="https://www.linkedin.com/in/fvillanustre/" target="_blank" rel="noreferrer noopener">Flavio Villanustre</a>, CISO for the LexisNexis Risk Solutions Group. </p>



<p>Indeed, the Microsoft statement solely talks about managing “external bots and their access to meetings.”</p>



<p>In fact, Gartner VP analyst <a href="https://www.gartner.com/en/experts/nader-henein" target="_blank" rel="noreferrer noopener">Nader Henein</a> said the limited controls that Microsoft is offering may actually dilute IT’s ability to control access to sensitive information.</p>



<p>Allowing any additional AI notetaking “takes the option to restrict/redact off the table,” and that control is what he thinks IT leaders should demand. The only practical way to do that is to allow only one notetaking app for any meeting and it needs to be controlled by the meeting owner.</p>



<p>“Allowing attendees to ask for an AI summary from the meeting owner and giving the owner the capacity to provide different versions that potentially shield sensitive data is a better choice for organizations looking to support better meeting follow ups without adding more work on the meeting owner,” Henein said. “It could even be set up in advance so a ‘sanitized’ summary is available for download.”</p>



<p><a href="https://www.linkedin.com/in/tomfindling/" target="_blank" rel="noreferrer noopener">Tom Findling</a>, CEO of Conifers.ai, agreed with Henein and argued that these notetaking app controls have to be centralized with IT.</p>



<p>“Microsoft basically built a bouncer for meeting bots and that is a good thing. But the real risk shows up later, when a normal meeting turns into M&amp;A, legal, HR, or board-level discussion while an AI notetaker is still running,” Findling said. “Now that transcript may be sitting in a cloud nobody approved. You do not fix that live. You fix it upfront. For legal, finance, HR, and exec meetings, external AI notetakers should be blocked by default unless explicitly approved.”</p>



<h2 class="wp-block-heading">Existing governance not enough</h2>



<p><a href="https://greyhoundresearch.com/svg/" target="_blank" rel="noreferrer noopener">Sanchit Vir Gogia</a>, chief analyst at Greyhound Research, said the slowly changing nature of AI notetakers has allowed them to slip by IT governance rules.</p>



<p>“A meeting note was once a harmless aid. It is now a searchable corporate record that can hold intent, allegations and material non-public information. Once a conversation is transcribed and saved, it has left the room, and it begins to travel through mail, search, and discovery with a life of its own,” Gogia said. “Microsoft’s control is useful, but should not be oversold. It detects external bots and puts them before an organizer for approval. It does not yet block them, and approval at the lobby is not a governance model. Capture also arrives by routes the lobby never sees, through browser extensions and personal devices.”</p>



<p>Gogia also argued that the inevitable errors in these bot-generated transcripts or summaries, whether caused by hallucination or simply incorrect interpretation what was actually said, is also a massive risk.</p>



<p>“AI summary does not merely create a record. It creates an authoritative-looking one that is often wrong and, in doing so, it inverts the burden of proof. Once a summary exists, the question shifts from proving what was said to disproving what the machine wrote,” Gogia said. “A tentative ‘we should look at acquiring them’ can harden into ‘we agreed to acquire them’ and that version becomes the default until someone corrects it.”</p>



<p>And, noted <a href="https://acceligence.com/talent/profiles/justin-greis/" target="_blank" rel="noreferrer noopener">Justin Greis</a>, CEO of consulting firm Acceligence, the problem will only get worse as AI summary generators morph into agentic systems, with action-taking autonomous agents.</p>



<p>“Over the next few years, we’ll see AI agents that summarize, extract decisions, assign work, update business systems, prepare follow-up documents, and collaborate with other AI systems after the meeting ends,” he said. “In fact, we are already seeing that integration happen, and it is simultaneously incredibly valuable and outrageously risky. The real question isn’t whether to allow an AI notetaker. It’s how organizations will govern an increasingly machine-readable workplace.”</p>



<p>Greis said that he sees the Microsoft approach as a good start, “because they’re treating AI participants more like digital identities than software features.” </p>



<p>He pointed out, “detection, verification, explicit admission, auditability, and policy-based control are exactly the kinds of enterprise controls we’ll need as AI agents become commonplace. This feels very similar to identity and access management twenty years ago. We eventually realized we weren’t managing employees, we were managing identities. AI agents deserve the same treatment.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[The AI lock comes off.]]></title>
<description><![CDATA[The US restores exports of Anthropic’s most advanced AI models. Adobe and Citrix rush out critical patches. RustDuck emerges as a fast-evolving DDoS threat. The Gentlemen raise the stakes with a new EDR-killing exploit. Rocket lab bets big on Iridium. Researchers unveil browser-only ransomware. N...]]></description>
<link>https://tsecurity.de/de/3639653/it-security-nachrichten/the-ai-lock-comes-off/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3639653/it-security-nachrichten/the-ai-lock-comes-off/</guid>
<pubDate>Wed, 01 Jul 2026 22:38:00 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The US restores exports of Anthropic’s most advanced AI models. Adobe and Citrix rush out critical patches. RustDuck emerges as a fast-evolving DDoS threat. The Gentlemen raise the stakes with a new EDR-killing exploit. Rocket lab bets big on Iridium. Researchers unveil browser-only ransomware. New Zealand faces questions about its cyber readiness. Iran’s long-running cyber espionage campaign is back in the spotlight. Our guest is Donald Codling, CISO and senior advisor to REGO on cybersecurity and data privacy matters, to discuss the importance of tying security by design to psychological safety and digital trust. VIP backstage access, courtesy of Claude.]]></content:encoded>
</item>
<item>
<title><![CDATA[The Control Gap: Enterprise AI organizations have an ownership problem, not a technology problem — and most are governing it by hand]]></title>
<description><![CDATA[AI portfolios are expanding far faster than the ability to govern them across enterprises. Most organizations run a contested field of platforms, each claiming to be the “primary” AI layer; few could confidently detect a model drifting or failing in production; and the single most-cited barrier t...]]></description>
<link>https://tsecurity.de/de/3639533/it-nachrichten/the-control-gap-enterprise-ai-organizations-have-an-ownership-problem-not-a-technology-problem-and-most-are-governing-it-by-hand/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3639533/it-nachrichten/the-control-gap-enterprise-ai-organizations-have-an-ownership-problem-not-a-technology-problem-and-most-are-governing-it-by-hand/</guid>
<pubDate>Wed, 01 Jul 2026 21:32:49 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>AI portfolios are expanding far faster than the ability to govern them across enterprises. Most organizations run a contested field of platforms, each claiming to be the “primary” AI layer; few could confidently detect a model drifting or failing in production; and the single most-cited barrier to control is the absence of any one owner accountable for AI across the stack. The result is a widening control gap — ambition and spend racing ahead of visibility, ownership, and cost control — with autonomous agents already producing real financial and operational failures.</p><p>This wave of VentureBeat Pulse Research examines the enterprise AI control gap: how many platforms claim to be the primary AI layer, who actually governs AI behavior across them, whether organizations could detect a model failing in production, what most blocks cross-platform governance, and how the financial and operational control failures of autonomous agents are already surfacing.</p><p>The central finding is a control gap — the distance between how aggressively enterprises are expanding AI and how little of it they can see, own, or govern. Just under three-fifths (58%) are net-adding AI initiatives, with “expanding significantly” the largest single posture.</p><p>Yet 85% run two or more platforms each claiming to be the “primary” AI layer and only 8% have consolidated to one. Against that contested surface, 40% say they are very confident they would detect a model drifting, behaving unsafely, or failing in production — but only 10% back that confidence with active monitoring and alerting, the rest leaning on manual human review. The machinery to expand AI is running well ahead of the machinery to control it.</p><p>The gap is, above all, a question of ownership. Only a third (38%) say a central team governs AI today, and a fifth (20%) say each platform team governs its own independently; the single most-cited barrier to cross-platform governance is the absence of a single accountable owner (32%), and roughly one in six (17%) say no role holds formal accountability at all. The same vacuum shows up in spend: just under half (49%) name shadow AI — unauthorized agentic pipelines run on corporate cards outside central oversight — as their most severe control failure, and another 25% have been hit by a runaway “infinite loop” agent bill. Enterprises have standardized the ambition well before they have standardized the control.</p><h2>Methodology</h2><p>VentureBeat fielded this survey as part of its ongoing Pulse Research series, this instrument focused on the enterprise AI control gap — governance, observability, and cost control across multiple AI platforms. Responses are filtered to organizations with 100 or more employees and, for this cut, exclude the respondents who selected “Other” as their job function, leaving a base of identifiable roles (n=145); all are drawn from a single Q2 2026 (June) wave. </p><p>By organization size the sample tilts toward the mid-market and lower-large bands: 100–499 and 500–2,499 employees (23% each) lead, with 10,000–49,999 (22%) and 2,500–9,999 (20%) close behind and 50,000+ at 11%. By role it is senior and technical: consultants and advisors (20%), CIO/CTO/CISO (18%), directors of engineering/IT (14%), product and program managers (13%), and enterprise architects (12%) make up the core. Technology/Software is the largest industry at 41%, followed by Financial Services and Professional Services (12% each) and Healthcare/Life Sciences and Manufacturing/Industrial (10% each).</p><p>The findings should be read as a directional signal rather than a precise measurement; it is self-selected and is not a probability sample. Where a single share would be fragile on its own, the report leans on the direction and grouping of responses rather than the exact percentage point.</p><h2>Finding 1: Expansion is outrunning control</h2><p><b>AI portfolios are growing faster than the means to govern them</b></p><p>We asked enterprises to describe how their AI portfolio has changed over the past 12 months. Growth leads — with a meaningful minority deliberately pulling back.</p><div></div><p>Expansion leads. Combining “expanding significantly” (33%) and “net positive growth” (25%), just under three-fifths of enterprises (58%) are net-adding AI initiatives. Yet a substantial share is easing off deliberately: roughly a quarter (23%) are actively rationalizing — scaling what works and cutting the rest — and another 12% hold their portfolios flat. Only a handful (3%) have paused to get governance in order first. </p><p>This is the engine behind every gap that follows: enterprises are accelerating into a landscape they have not yet learned to see or own, and a notable 4% cannot even describe their own portfolio. The ambition documented here is exactly what makes the visibility and ownership shortfalls in Findings 3 and 4 consequential rather than academic.</p><h2>Finding 2: No single “primary” AI layer — the surface is contested</h2><p><b>More than four in five run multiple platforms each claiming primacy</b></p><p>We asked how many enterprise platforms currently claim to be the organization’s “primary” AI layer — the ERP, EHR, ITSM, productivity suite, or data platform each positioning itself as the center of gravity. Almost no one has a single answer.</p><div></div><p>The defining condition is contested primacy. Adding the two multi-platform bands, 85% of enterprises have at least two platforms each asserting itself as the primary AI layer, and more than a third (36%) describe an open four-way-or-more contest. Only 8% have consolidated to a single layer, and another 6% have not even mapped the question. This is the structural reason governance is hard: there is no agreed center of gravity to govern from. Each platform brings its own AI, its own controls, and its own assumptions — and, as Finding 3 shows, the question of who governs across them increasingly has no settled answer.</p><h2>Finding 3: Governance is claimed at the center but contested in practice</h2><p><b>A central team owns it on paper; in practice, it's fragmenting</b></p><p>We asked who is actually responsible for governing AI behavior across all of those platforms today, and which function holds primary accountability. The headline answer is reassuring; the detail is not.</p><div></div><p>On the surface, a central governance function is the leading answer — but only a third (38%) claim one, well short of a majority. The rest of the distribution undercuts it further: a fifth (21%) say ownership is unclear or contested between teams, a fifth (20%) say each platform team simply governs its own AI independently, and 19% say no one has addressed it at all. </p><p>Accountability fragments further when we asked which role actually holds it — CIO/CTO/CISO leads at 27%, a Chief AI Officer or equivalent at 22%, and a striking 17% say no one holds formal accountability yet. Even where a central team is claimed, the named owner is most often the general technology executive rather than a dedicated AI authority. The governance function exists more often as an org-chart aspiration than an operating reality — the precondition for the detection gap in Finding 4.</p><h2>Finding 4: The detection gap — confidence is real but largely manual</h2><p><b>Only one in 10 have active monitoring and alerting</b></p><p>We asked how confident enterprises are that they would detect an AI model in production that was drifting, behaving unsafely, or failing to complete tasks correctly. This is the heart of the control gap.</p><div></div><p>This is the report’s central number. While 40% say they are very confident they would detect a failing model, the overwhelming majority of that confidence rests on manual human review (30%) rather than automation — just 10% have active monitoring and alerting actually in place. </p><p>At the other end, more than a quarter combine the two reactive answers — no systematic visibility (8%) and would hear it from end users first (19%) — meaning they would learn of a production failure after the fact, from the people it affected. The plurality (32%) sit in a hopeful middle, expecting to “catch most issues eventually.” Set against the aggressive expansion of Finding 1, this is the crux of the control gap — enterprises are scaling AI into production faster than they are building automated means to know when it breaks. Confidence is real, but it is largely manual, and automated detection remains the exception.</p><h2>Finding 5: The missing owner is the biggest barrier</h2><p><b>Governance stalls on accountability first, visibility second</b></p><p>We asked enterprises to name their single biggest barrier to governing AI across multiple platforms. The org chart tops the list.</p><div></div><p>The single missing owner leads at 32%, the most-cited barrier. Vendor opacity (25%) and the lack of tooling or infrastructure to observe across platforms (16%) sit behind, and together these two technical-visibility barriers (41%) outweigh the ownership gap. Leadership deprioritization accounts for another 17%, while a clear lack of talent is rare (5%). Rounding out the picture, another 5% say it isn't a barrier for them at all — they've already solved it. </p><p>Read together, the picture is more contested than the headline suggests: enterprises still most often name a missing owner, but a good share locate the obstacle in vendor black boxes and the absence of cross-platform observability. </p><p>Asked in a free-text question what one thing they would fix, respondents converged from different directions on the same answer — a single accountable owner, and a control plane that abstracts cost, drift, and model choice away from the end user.</p><h2>Finding 6: The fine-tuning ROI reckoning</h2><p><b>Roughly seven in 10 have little to show for custom model investment</b></p><p>We asked what share of the proprietary foundation models enterprises have invested in fine-tuning over the past 18 months have delivered clear, measurable positive ROI in production today. Most describe a sandbox graveyard — or a deliberate decision to avoid one.</p><div></div><p>Custom fine-tuning has, for most, not paid off. Combining the three disappointing outcomes — sandbox graveyard, strategic avoidance, and total write-off — roughly seven in ten (73%) either failed to get custom models into productive use or deliberately declined to try, against 27% for whom fine-tuned models are a reliable advantage. The largest single group (45%) remains the graveyard: projects too expensive or complex to maintain, stranded in development. Another quarter (24%) never started — they priced in the downstream maintenance burden and avoided it. </p><p>The signal is that many enterprises still treat bespoke model training as a cost trap, which helps explain the pragmatic, buy-and-blend vendor posture in Finding 7.</p><h2>Finding 7: Vendor posture — hybrid by default, with defection rising</h2><p><b>Enterprises blend open and closed models; more are now trimming a vendor</b></p><p>We asked two related questions: whether enterprises are shifting workloads toward open-weight models to escape API costs and lock-in, and which proprietary vendor, if any, they are most likely to phase out over the next year. The answers describe hedging — and a rising willingness to cut.</p><div></div><p>On open weights, a clear majority (51%) strike a hybrid balance, with a deliberate closed commitment second at 32% and a hard pivot to self-hosted open models at 16%. The hybrid plurality is the same instinct visible throughout this survey — keep optionality, avoid being trapped — while the closed group remains candid that the operational overhead of self-hosting still outweighs the savings for them. </p><p>On vendor defection, loyalty by inertia no longer leads: Microsoft is now the single most-named target (29%, often citing Copilot/Azure cutbacks in favor of direct model access), narrowly ahead of the 27% who are downsizing no one at all. OpenAI follows at 21% (citing pricing volatility), with Anthropic at 15% and Google at 6%. No single vendor faces a wholesale exodus, but among identifiable roles the balance has tipped from “expanding across all” toward actively trimming at least one provider.</p><h2>Finding 8: The agentic spending crisis — shadow AI leads the failures</h2><p><b>Unauthorized pipelines, not runaway loops, are the top control failure</b></p><p>Finally, we asked what the most severe financial or operational control failure enterprises have experienced as autonomous agents run over longer execution windows. Shadow AI tops the list — and very few have escaped a scare.</p><div></div><p>The control gap has a price, and it is being paid. Just under half of enterprises (49%) cite shadow AI — unauthorized agentic pipelines spun up on corporate cards outside any central oversight — as their most severe failure, the operational twin of the “no single owner” barrier in Finding 5. Another 25% have been burned by a runaway infinite-loop agent bill, and 6% by an agent that degraded production databases. Only 21% report guarded stability — the minority that has imposed hard token throttling and budget caps at the infrastructure layer and avoided surprises. </p><p>Put differently, roughly four in five of these enterprises (79%) have already experienced a real financial or operational control failure from autonomous AI, not merely worried about one. As with detection in Finding 4, the deterministic controls that would prevent these failures exist at only a fraction of organizations.</p><h2>The bottom line: A control gap that spending cannot close on its own</h2><p>Organizations with 100 or more employees describe AI programs that are expanding fast and governing slowly. Just under three-fifths are net-adding to their portfolios; more than four in five run a contested field of platforms with no agreed primary layer; and the thing they most often name as their chief obstacle is a single accountable owner. The visibility to match the ambition is largely manual — only 10% have active monitoring and alerting, and confidence in detecting a failing model rests mostly on human review rather than automation.</p><p>The consequences are already concrete rather than hypothetical. Custom fine-tuning has disappointed more often than not, pushing enterprises toward a hedged, hybrid, buy-and-blend model posture; and the autonomous agents now reaching production have produced real control failures for roughly four in five respondents, led by shadow AI running outside any central oversight. This reads as a directional signal rather than a precise measurement — but the direction is consistent across every question: ambition, spend, and deployment are racing ahead of ownership, observability, and cost control. The control gap is not a tooling problem that more spending will close on its own; it is, first, a question of who owns the answer. </p><hr><p><i>Based on survey responses from 145 qualified enterprise respondents (100+ employees). Sample size is small; data should be treated as directional. Respondents include Directors, VPs, CIOs, CTOs, and Enterprise Architects across Technology, Financial Services, Retail, Healthcare, and other sectors.</i></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Wie Igel Ransomware die Stacheln zeigt]]></title>
<description><![CDATA[width="1484" height="811" sizes="auto, (max-width: 1484px) 100vw, 1484px">Statt eigener Hardware setzt Igel Technologies auf Thin Clients von Partnern wie HP, Lenovo oder LG (Bild) und konzentriert sich auf Igel OS.   LG



Oft liefern kompromittierte Endgeräte die lediglich angelehnte Hintertür,...]]></description>
<link>https://tsecurity.de/de/3637769/it-security-nachrichten/wie-igel-ransomware-die-stacheln-zeigt/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3637769/it-security-nachrichten/wie-igel-ransomware-die-stacheln-zeigt/</guid>
<pubDate>Wed, 01 Jul 2026 09:53:27 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full is-resized"> width="1484" height="811" sizes="auto, (max-width: 1484px) 100vw, 1484px"&gt;<figcaption class="wp-element-caption">Statt eigener Hardware setzt Igel Technologies auf Thin Clients von Partnern wie HP, Lenovo oder LG (Bild) und konzentriert sich auf Igel OS.   </figcaption></figure><p class="imageCredit">LG</p></div>



<p>Oft liefern kompromittierte Endgeräte die lediglich angelehnte Hintertür, durch die Ransomware ins Unternehmen schlüpft. Gartner-Analysten raten deshalb zu unveränderbaren Endpunkten. Igel Technology liefert dafür eine solche Architektur – und neuerdings zudem schnelle Hilfestellung für gekaperte Windows-Clients.</p>



<p>Das Bremer Unternehmen behauptete sich einst im Bereich Thin Clients gegen Größen wie HP und Dell, Ende 2022 verkündete Igel dann, keine TCs mehr zu produzieren, sondern Hardware von Partnern wie HP, Lenovo und LG zu nutzen.</p>



<p>Denn Igel hatte erkannt: Die eigentliche Stärke liegt im angriffsresistenten, weil stark abschottbaren Linux-Betriebssystem Igel OS samt zentraler Verwaltung per zugehöriger Universal Management Suite (UMS). Seither arbeitete das Unternehmen, ab 2023 unter der Führung des in den USA lebenden Dänen Oestermann, daran zum zum Anbieter einer, so Igel, „Adaptive Secure Endpoint Platform“ zu werden. Diese Plattform setzt, so eine weitere Igel-Formulierung, das „Preventative Security Model“ um, soll also Kompromittierung a priori verhindern.</p>



<h2 class="wp-block-heading">Igels erweiterbare Endpunkt-Plattform</h2>



<p>Hierfür ist das Igel OS in schönster Thin-Client-Tradition auf das Nötigste reduziert, gehärtet und somit hochgradig manipulationsresistent. In Kombination mit rein serverseitiger Datenhaltung scheint dies heute nützlicher denn je. Denn Ransomware-Angriffe haben sich, wie einst die Kaninchen in Australien, zur regelrechten Landplage entwickelt. Und Security-Fachleute <a href="https://www.computerwoche.de/article/4137800/ki-macht-kaputt.html">warnen</a> <a href="https://www.trendmicro.com/de_de/research/26/f/apt-bericht-2025-ki-veraendert-strategien.html">allerorts</a>, dass Cyberkriminelle verstärkt KI nutzen, um ihre Angriffe weiter zu automatisieren, zu skalieren und zu beschleunigen.</p>



<p>Die Analysten von Gartner bestätigen die neue Strategie von Igel. „Endpunkte sind die am stärksten fragmentierte, poröse Oberfläche einer Organisation“, schreiben die Marktforscher in einem <a href="https://www.gartner.com/en/documents/7524653" target="_blank" rel="noreferrer noopener">Papier</a> vom Februar 2026, dessen Titel auch gleich einen Ausweg weist: „Nutzen Sie unveränderbare Endpunkte, um Ransomware zu besiegen, Konfigurationsabweichungen zu stoppen und schnelle Wiederherstellung zu garantieren“. Denn „veränderliche, agentenlastige Endpunkte“ – vulgo Windows-PCs – seien das Haupteinfallstor für Angriffe, so die Analysten.</p>



<p>Unveränderliche Endpunkte hingegen, so Gartner-Analyst <a href="https://www.gartner.com/en/experts/franz-hinner">Franz Hinner</a> und seine Co-Autoren, könnten die Angriffskette durchbrechen und Persistenz der Angreifer im Netzwerk für langfristige oder wiederholte Angriffe verhindern. Indem sich die Sicherheitskontrollen vom Endgerät auf die Identität verlagerten, so die Marktforscher, ließen sich die Ausfallzeiten der Mitarbeiter um 98 Prozent senken.</p>



<p>Eben dieses Konzept verfolgt Igel mit der „Adaptive Secure Endpoint Platform“, die esüber offene APIs erlaubt, Drittanbieterlösungen zu integrieren. Rund 130 Partner zählt man inzwischen, so die Bremer, darunter Identity-Security-Anbieter wie Okta, Imprivata und Microsoft (mit Entra ID) sowie diverse weitere Security-Größen, mit deren Hilfe Igel Zero-Trust-Architekturen umzusetzen kann.</p>



<p>Doch Igel verlässt sich längst nicht nur auf seine Partner: Auch das hauseigene Entwicklungsteam unter der Leitung von General Manager und CTO Matthias Haas treibt die Softwareentwicklung eifrig voran. Hierfür unterhält Igel heute neben dem Stamm-Entwicklungsstandort Augsburg weitere in Bukarest, Bangalore und Fort Lauderdale, USA. Federführend ist jedoch weiterhin die deutsche Lokation.</p>



<p>Bei einer <a href="https://www.igel.de/nowandnext/" target="_blank" rel="noreferrer noopener">Kundenveranstaltung in Frankfurt</a> präsentierte Igel kürzlich zahlreiche Erweiterungen seiner Plattform. Hierzu zählen unter anderem:</p>



<ul class="wp-block-list">
<li>kontextbezogene Zugriffskontrollen, ermöglicht durch die Kooperation mit Security-Partnern;</li>



<li>ein Managed Hypervisor inklusive der Option, auf den TCs Published Apps lokal laufen zu lassen;</li>



<li>Managed Container (wichtig für das Industrieumfeld);</li>



<li>Unterstützung für ARM-Prozessoren.</li>
</ul>



<p>Und natürlich darf das Thema KI nicht fehlen: Igel AI Armor soll die KI-Nutzung absichern, MCP-Support sei hierfür in Arbeit.</p>



<p>Eine pfiffige Lösung ist „Igel Business Continuity &amp; Disaster Recovery“. Die Funktionsweise: Ein Windows-Endpunkt läuft virtualisiert auf Igel OS. Im Notfall, etwa bei einem Ransomware-Angriff, müssen die Anwender nur die F9-Taste drücken. Dies führt zum Neustart samt Auswahl, ob man den Windows-Rechner oder das abgesicherte Igel OS starten möchte. Neben diesem Dual Boot gibt es, etwa für Industrie-PCs, auch eine USB-Boot-Option.</p>



<p>Dadurch, so Igel, seien Unternehmen in Minuten wieder arbeitsfähig. Oder konkret ausgedrückt: Anwender können gehostete und SaaS-Applikationen wie Windows 365 weiter nutzen und bleiben damit zumindest im Kern handlungsfähig. Das Windows-OS liegt dabei für Forensik-Zwecke weiterhin unangetastet vor. Die Lösung erweist sich laut CEO <a href="https://www.linkedin.com/in/klausoestermann">Klaus Oestermann</a> als „Türöffner“ für die Neukundengewinnung, ebenso beim Ausbau bestehender Installationen.</p>



<h2 class="wp-block-heading">Igel-Vorteile für Kliniken und die Industrie</h2>



<p>Wie Igel anhand mehrerer Kundenszenarien veranschaulichte, bieten unveränderliche, zentral verwaltete Endpunkte auch jenseits von Malware-Schutz und Resilienz im Angriffsfall Vorteile.</p>



<p>So brauchten die PCs des britischen NHS Gloustershire Hospitals früher laut Igel-Angaben 30 Minuten bis zum erfolgten Login. Mitarbeiter riefen deshalb vom Arbeitsweg aus an und baten einen Kollegen, sie mit ihrem Passwort einzuloggen, damit sie bei Ankunft schnell arbeitsfähig sind – das Gegenteil von Nutzerfreundlichkeit und ein Alptraum für jeden CISO.</p>



<p>Mit Igel OS und der Access-Management-Lösung Imprivata dauere der Login nun nur noch eine Minute, berichteten die Bremer, ein erneuter Login wenige Sekunden. Ein Arzt auf Visite müsse sich also nicht mehr minutenlang vom Patienten abwenden, um mit dem PC zu kämpfen, sondern könne sich schnell wieder der Behandlung widmen.</p>



<p>Hierzulande setzen laut Peter Goldbrunner, Vice President und General Manager Central Europe bei Igel, rund 300 Kliniken auf Igel OS. Auch sonst wachse das Geschäft in Deutschland ebenso schnell wie das internationale Business – und das vom hohen Niveau des Stammlandes aus betrachtet.</p>



<p>So betreibe nun etwa Aldi Nord die Steuerung der Backautomaten in seinen Filialen mittels zentral verwalteter Igel-OS-Endpunkte. In der Industrie wiederum, so Goldbrunner, nutze beispielsweise Audi inzwischen Steuerungsrechner mancher Produktionsanlagen virtualisiert auf Igel-OS-Endpunkten statt wie bislang Industrie-PCs. Damit sollen sich die Industriesteuerungen selbst dann zügig weiterbetreiben lassen, wenn wie letztes Jahr bei <a href="https://www.tagesschau.de/wirtschaft/unternehmen/jaguar-cyberangriff-100.html">Jaguar Land Rover</a> Cyberangreifer zuschlagen sollten – ohne dass ein Techniker vor Ort eingreifen muss.</p>



<p>Laut <a href="https://www.linkedin.com/in/epirker">Emanuel Pirker</a>, Ex-Chef des 2025 von Igel akquirierten TC-Herstellers Stratodesk und nun verantwortlich für den Contact-Center-Bereich, können Igel-OS-Endpunkte im Call- oder Contact-Center die Kosten deutlich senken. Das Onboarding neuer Mitarbeiter sei in fünf Minuten erledigt – wichtig in einer Branche mit extrem hoher Personalfluktuation. Datensicherheit und Compliance seien gewahrt, da keine Daten auf den Endpunkten gespeichert werden. Zudem sinken laut Pirker die Betriebskosten durch längere Hardware-Lebenszyklen, weniger Update-Bedarf und einfacheres Management. UMS ist hierfür auf Wunsch „as a Service“ erhältlich, auch aus einem Rechenzentrum im EU-Rechtsraum. (mb)</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Detection engineering: A programmatic approach to identifying cyber threats]]></title>
<description><![CDATA[Detection engineering, which was once a niche practice among mostly large companies, appears to have evolved into a capability that organizations across industries now consider essential to their security operations.



What is detection engineering?



Detection engineering is about creating and...]]></description>
<link>https://tsecurity.de/de/3637670/it-security-nachrichten/detection-engineering-a-programmatic-approach-to-identifying-cyber-threats/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3637670/it-security-nachrichten/detection-engineering-a-programmatic-approach-to-identifying-cyber-threats/</guid>
<pubDate>Wed, 01 Jul 2026 09:08:36 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Detection engineering, which was once a niche practice among mostly large companies, appears to have evolved into a capability that organizations across industries now consider essential to their security operations.</p>



<h2 class="wp-block-heading">What is detection engineering?</h2>



<p>Detection engineering is about creating and implementing systems to identify potential security threats within an organization’s specific technology environment without drowning in false alarms. It’s about writing smart rules that can tell when something potentially suspicious or malicious is happening in an organization’s networks or systems and making sure those alerts are useful. The process typically involves threat modeling, understanding attacker TTPs, writing, testing and validating detection rules, and adapting detections based on new threats and attack techniques.</p>



<p>A small <a href="https://www.anvilogic.com/report/2025-state-of-detection-engineering">survey</a> of 264 cybersecurity professionals by the SANS Institute and Anvilogic found that 80% of organizations — and 85% of large enterprises — are actively investing in detection engineering, with 60% now having dedicated teams. More than two-thirds (67%) reported strong leadership support for the practice within their organization.</p>



<p>The survey’s data suggested that many companies have not just merely adopted detection engineering practices but have made it a strategic focus of their cyber risk mitigation effort.  “Just a decade ago, detection engineering was a relatively unknown role in cybersecurity,” the report stated. “Now, it is emerging as one of the most critical roles in security operations.”</p>



<h2 class="wp-block-heading">More than the usual threat detection practices</h2>



<p>Proponents argue that detection engineering differs from traditional threat detection practices in approach, methodology, and integration with the development lifecycle. Threat detection processes are typically more reactive and rely on pre-built rules and signatures from vendors that offer limited customization for the organizations using them. In contrast, detection engineering applies software development principles to create and maintain custom detection logic for an organization’s specific environment and threat landscape. Rather than relying on static, generic rules and known IOCs, the goal with detection engineering is to develop tailored mechanisms for detecting threats as they would actually manifest in an organization’s specific environment.</p>



<p>Often this involves a stronger emphasis on behavior-based detections, the integration of threat intelligence to create detections aligned with real-world adversary tactics and the use of threat modeling to anticipate potential attack paths, says Heath Renfrow, CISO and co-founder of Fenix24 a cyber disaster recovery firm. “Unlike conventional threat detection, which often relies on static signatures and pre-built rules, detection engineering is behavior-driven, context-aware, and tailored to an organization’s unique threat landscape,” Renfrow says. “It involves a blend of security operations, threat intelligence, and data science to build more adaptive and resilient detection capabilities.”</p>



<p>The SANS-Anvilogic report describes detection engineering practices as evolving over the years from being over-reliant on vendor-specific consoles and proprietary languages to incorporate software development life cycle (SDLC) and continuous integration/continuous deployment (CI/CD) principles. This is enabling teams to test, deploy, and refine detections more efficiently while maintaining auditable trails of changes.</p>



<h2 class="wp-block-heading">Drivers of detection engineering’s adoption</h2>



<p>There are a couple of factors driving adoption of detection engineering practices. The biggest is the fact that out-of-the-box detections aren’t good enough. They don’t baseline the environment, they don’t drive down false positives and, troublingly, they don’t always alert on the things that matter, says Johnathon Miller, vice president of security operations at Lumifi Cyber.</p>



<p>Generic alerts that don’t account for organizational context have become a major problem and a contributor to false positive fatigue within many security teams. Sixty-four percent of organizations in Anvilogic’s survey for instance, reported high false positive rates; 61% struggled with detections that lacked environmental accuracy; and 34% said they had encountered delays in updates and improvements.</p>



<p>“Traditional threat detection methods historically have been static; if a=a, create an alert,” says Kevin Gonzalez, VP of security, operations and data, Anvilogic. “They are often rigid, black-box mechanisms that lack flexibility in customization. Though useful to some extent, these approaches become unmanageable at scale especially in organizations with hybrid environments,” he says.</p>



<p>Growing threat volumes and sophistication are another issue. Attackers are using more advanced and evasive techniques — including fileless malware, living off the land approaches, zero-day exploits and attacks via the software supply chain — rendering signature-based detection largely insufficient. Rising cloud adoption has introduced new vulnerabilities as well and created blind spots that legacy detection methods often struggle to cover. </p>



<p>The rise in advanced persistent threats (APTs), supply chain attacks, and ransomware operations has made traditional reactive approaches insufficient, Renfrow says. “Organizations now realize that proactive detection engineering reduces dwell time, improves response capabilities, and enhances overall cyber resilience. Additionally, compliance frameworks and cyber insurance providers are increasingly emphasizing strong detection strategies.”</p>



<h2 class="wp-block-heading">Industries adopting detection engineering</h2>



<p>Organizations in the banking and finance sector, the technology industry, cybersecurity companies and, to a lesser extent, healthcare companies are among the leading adopters of detection engineering practices. Many are in sectors that must deal with regulatory scrutiny or are frequent targets of sophisticated threat actors. But the reality is that most organizations, especially larger ones, can benefit from implementing a systematic approach to developing detection mechanisms for their specific threat profile.</p>



<p>Any large enterprise with a complex IT infrastructure can benefit from detection engineering. Security operations centers (SOCs) need to continuously improve and maximize their detection posture. “Along with the evolving threat landscape, their own internal IT infrastructures are constantly changing, which can result in detection ‘drift,’ where detection rules are broken and will no longer fire or alert,” CardinalOps CEO Michael Mumcuoglu says.</p>



<p>Security experts point out some key requirements for setting up a detection engineering capability. The biggest among them is data. To succeed, detection engineering teams need access to logs and security event data from endpoints, networks, cloud environments, and security tools and a centralized <a href="https://www.csoonline.com/article/524286/what-is-siem-security-information-and-event-management-explained.html">SIEM</a> or log management platform to aggregate and normalize the security data. An effective detection engineering capability also means having skilled personnel including detection engineers, analysts, and threat researchers, to develop and refine detection rules. Also important are formal processes for <a href="https://www.csoonline.com/article/569225/threat-modeling-explained-a-process-for-anticipating-cyber-attacks.html">threat modeling</a>, testing and integrating <a href="https://www.csoonline.com/article/3624136/stop-wasting-money-on-ineffective-threat-intelligence-5-mistakes-to-avoid.html">threat intelligence</a> with <a href="https://www.csoonline.com/article/3829684/how-to-create-an-effective-incident-response-plan.html">incident response</a>.</p>



<p>The goal should be to move beyond static signatures and focus on how attackers operate, by prioritizing behavior-based threat detection. Use frameworks like MITRE ATT&amp;CK to map detection coverage against known adversary techniques and utilize adversary emulation tools like Atomic Red Team to validate effectiveness, Renfrow says. “Detection engineering works best when security operations, threat intelligence, and IT teams work together,” Renfrow notes.</p>



<h2 class="wp-block-heading">How AI and automation can help</h2>



<p>AI/ML can play a key role in rule tuning and automation as well. Some 45% of the survey respondents described their organizations as using AI in their detection engineering programs for purposes like anomaly detection, rule generation and alert triage. Nearly nine in 10 (88%) believed AI would have a big impact on their detection engineering programs in the next three years. “One of [AI’s] strongest use cases is analyzing vast amounts of data to identify anomalies, particularly when utilizing a custom-trained language model,” says Glenn Thorpe, senior director of security research and detection engineering at GreyNoise Intelligence. “Depending on an organization’s threat model and risk tolerance, employing AI with a well-trained LLM can significantly enhance the effectiveness and efficiency of defenders within the organization.”</p>



<p>AI is not the only change. More organizations are also adopting automated processes for detection engineering. The areas that organizations are automating include mapping detection coverage to the MITRE ATT&amp;CK framework, identifying broken or misconfigured detections, and being able to operationalize threat intelligence and convert it into actionable detection rules, Mumcuoglu says. Ninety-three percent of Anvilogic’s survey respondents reported they are currently using or plan to use automation in their detection engineering workflow for rules development, tuning existing detections and threat hunting.</p>



<p>Thorpe cautions against organizations looking for some kind of one-size-fits-all approach to standing up a detection engineering capability. “Instead, a creative mindset, diversity of thoughts and experiences, and curiosity are vital for building an effective team.”</p>



<p>A good place to start is by identifying your organization’s core data and finding individuals who can analyze that data from multiple perspectives. Develop a realistic understanding of what you don’t know and begin to address those information gaps. “You might discover that small changes can significantly improve your visibility and understanding of network traffic,” Thorpe notes.</p>



<p></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[A CISO’s Guide to Robocall Mitigation: Applying MITRE ATT&CK to Voice-Based Threats]]></title>
<description><![CDATA[The challenge for security leaders is no longer simply blocking unwanted calls.]]></description>
<link>https://tsecurity.de/de/3637669/it-security-nachrichten/a-cisos-guide-to-robocall-mitigation-applying-mitre-attck-to-voice-based-threats/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3637669/it-security-nachrichten/a-cisos-guide-to-robocall-mitigation-applying-mitre-attck-to-voice-based-threats/</guid>
<pubDate>Wed, 01 Jul 2026 09:08:35 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The challenge for security leaders is no longer simply blocking unwanted calls.]]></content:encoded>
</item>
<item>
<title><![CDATA[The agentic AI ‘lethal trifecta’: What CISOs should know]]></title>
<description><![CDATA[By now, every CISO has probably heard the phrase lethal trifecta tossed around in AI security discussions. The term refers to a combination of three agentic AI properties that, together, make agents vulnerable to attack and put the enterprises using…
Read more →
The post The agentic AI ‘lethal tr...]]></description>
<link>https://tsecurity.de/de/3637510/it-security-nachrichten/the-agentic-ai-lethal-trifecta-what-cisos-should-know/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3637510/it-security-nachrichten/the-agentic-ai-lethal-trifecta-what-cisos-should-know/</guid>
<pubDate>Wed, 01 Jul 2026 07:54:00 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>&lt;p&gt;By now, every CISO has probably heard the phrase &lt;i&gt;lethal trifecta&lt;/i&gt; tossed around in AI security discussions. The term refers to a combination of three agentic AI properties that, together, make agents vulnerable to attack and put the enterprises using…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/the-agentic-ai-lethal-trifecta-what-cisos-should-know/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/the-agentic-ai-lethal-trifecta-what-cisos-should-know/">The agentic AI ‘lethal trifecta’: What CISOs should know</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Getting boards to fund ERM means speaking their currency]]></title>
<description><![CDATA[In this Help Net Security video, Greg Young, VP Cybersecurity and Corporate Development at TrendAI, explains how to build Enterprise Risk Management that a board will pay for. Drawing on nearly four decades in cybersecurity, including time as a CISO and 14 years as a Gartner analyst, he argues th...]]></description>
<link>https://tsecurity.de/de/3637350/it-security-nachrichten/getting-boards-to-fund-erm-means-speaking-their-currency/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3637350/it-security-nachrichten/getting-boards-to-fund-erm-means-speaking-their-currency/</guid>
<pubDate>Wed, 01 Jul 2026 06:08:10 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>In this Help Net Security video, Greg Young, VP Cybersecurity and Corporate Development at TrendAI, explains how to build Enterprise Risk Management that a board will pay for. Drawing on nearly four decades in cybersecurity, including time as a CISO and 14 years as a Gartner analyst, he argues that boards fund ERM when they can see how risk intelligence improves business decisions, not when someone asks for better governance. The talk covers how to … <a href="https://www.helpnetsecurity.com/2026/07/01/erm-the-board-funds-video/" rel="nofollow">More <span class="meta-nav">→</span></a></p>
<p>The post <a href="https://www.helpnetsecurity.com/2026/07/01/erm-the-board-funds-video/">Getting boards to fund ERM means speaking their currency</a> appeared first on <a href="https://www.helpnetsecurity.com/">Help Net Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Getting boards to fund ERM means speaking their currency]]></title>
<description><![CDATA[In this Help Net Security video, Greg Young, VP Cybersecurity and Corporate Development at TrendAI, explains how to build Enterprise Risk Management that a board will pay for. Drawing on nearly four decades in cybersecurity, including time as a CISO…
Read more →
The post Getting boards to fund ER...]]></description>
<link>https://tsecurity.de/de/3637349/it-security-nachrichten/getting-boards-to-fund-erm-means-speaking-their-currency/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3637349/it-security-nachrichten/getting-boards-to-fund-erm-means-speaking-their-currency/</guid>
<pubDate>Wed, 01 Jul 2026 06:08:08 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>In this Help Net Security video, Greg Young, VP Cybersecurity and Corporate Development at TrendAI, explains how to build Enterprise Risk Management that a board will pay for. Drawing on nearly four decades in cybersecurity, including time as a CISO…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/getting-boards-to-fund-erm-means-speaking-their-currency/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/getting-boards-to-fund-erm-means-speaking-their-currency/">Getting boards to fund ERM means speaking their currency</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Why Identity Security Is Your Cyber Career Entry Point]]></title>
<description><![CDATA[As AI reshapes cybersecurity workflows, John Paul Cunningham, CISO at SIlverfort, says the technology is creating opportunities rather than eliminating jobs — and there are more ways than ever to break into the essential field.]]></description>
<link>https://tsecurity.de/de/3636792/it-security-nachrichten/why-identity-security-is-your-cyber-career-entry-point/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3636792/it-security-nachrichten/why-identity-security-is-your-cyber-career-entry-point/</guid>
<pubDate>Tue, 30 Jun 2026 22:22:52 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[As AI reshapes cybersecurity workflows, John Paul Cunningham, CISO at SIlverfort, says the technology is creating opportunities rather than eliminating jobs — and there are more ways than ever to break into the essential field.]]></content:encoded>
</item>
<item>
<title><![CDATA[Google's Gemini Omni Flash hits the API, turning enterprise video production into a conversation]]></title>
<description><![CDATA[For most enterprises, a 90-second training video or a product explainer has never been an easy ask. It means a well planned brief, an internal film crew or an outside vendor, a shoot, an edit, and a round of revisions. Change one line of on-screen text due to a legal review and the whole chain ru...]]></description>
<link>https://tsecurity.de/de/3636544/it-nachrichten/googles-gemini-omni-flash-hits-the-api-turning-enterprise-video-production-into-a-conversation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3636544/it-nachrichten/googles-gemini-omni-flash-hits-the-api-turning-enterprise-video-production-into-a-conversation/</guid>
<pubDate>Tue, 30 Jun 2026 20:02:36 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>For most enterprises, a 90-second training video or a product explainer has never been an easy ask. It means a well planned brief, an internal film crew or an outside vendor, a shoot, an edit, and a round of revisions. Change one line of on-screen text due to a legal review and the whole chain runs again. The cost and the long time lines are why so much internal video never gets made.</p><p>That equation is what Google is aiming to rewrite with <a href="https://blog.google/innovation-and-ai/models-and-research/gemini-models/gemini-omni-3-5-videos/">Gemini Omni Flash</a>, the first model in its new "Omni" family, now rolling out to developers and enterprise customers through an API after debuting to consumers at I/O 2026. Google frames the family's ambition as creating anything "from any input," starting with video. But the headline interaction isn't just a sharper text-to-video prompt. It's the ability to edit a finished clip through conversation.</p><div></div><p>When the model launched in May, <a href="https://venturebeat.com/technology/google-unveils-gemini-omni-any-to-any-ai-model-what-enterprises-should-know">VentureBeat's enterprise analysis</a> flagged the catch: with no programmatic interface, Omni was a consumer and prosumer tool, not a production one. This API rollout changes that. It puts conversational editing in front of the marketing and learning-and-development teams that make the most videos in an organization.</p><h2><b>The pitch: a five-tool pipeline collapses into a single conversation</b></h2><p>Until now, many teams have been assembling AI videos the hard way, bolting together an LLM for a script, a text-to-image model, an image-to-video model, a separate lip-sync tool and a voice generator, each with its own contract, billing and data path. </p><p>Omni's enterprise argument is unification: one model that takes text, images and video and returns a finished clip with synced audio.</p><p>That simplicity factor is the part decision-makers should weigh first. Collapsing several point tools into one model means fewer vendors and a single place to monitor output and enforce data-handling rules. For an organization that has avoided generative video because stitching the tools together wasn't worth the overhead, the equation shifts.</p><p>With conversational editing each instruction builds on the last, so a marketer can relight a product shot, reframe it, or change the wardrobe without regenerating from scratch and losing the parts that already worked. It is the difference between booking a reshoot and sending a note.</p><h2><b>Multimodal references and a physics engine for brand assets</b></h2><p>Omni accepts far more than a text prompt. Alongside the words describing what you want, you can feed it multiple reference images, and existing video clips, and it carries those specifics into the result. Hand it a photograph of a particular object, ask the model to place that object into a scene, and it reproduces the real thing's coloring and rough shape instead of inventing a generic stand-in. While the match might not be pixel-perfect, it is close enough to be recognizable. That reference-driven control is what makes the feature commercially interesting: a product photo, a brand logo, or a specific location can be dropped in as an ingredient rather than described in a prompt and hoped for.</p><p>Two of Google's four highlighted strengths speak directly to enterprise work. The first is a world model, the system's grasp of how physical scenes behave. Add light rain and puddles to an existing shot and it renders reflections of the people and objects in the wet pavement, the sort of physical consistency that separates real footage from obvious AI video. </p><p>The second is text and logo insertion. Point it at a scene full of signage and you can have it rewrite those signs in another language, or for a brand of your choosing, and even drop in a company's logo. The results aren't flawless: in testing, sign tracking in complex scenes weren’t always perfect and some text slipped back to the original language between frames. For training videos that need on-screen labels, or ads that need a logo placed in-scene, it is a capability worth a close look, and a reminder that the output still needs a human review before it ships.</p><h2><b>The interactions API and where the limits still bite</b></h2><p>Under the hood, this runs on Google's new interactions API, a stateful interface built for multi-turn tasks rather than open-ended chat. Each turn carries the previous video and its references forward, which is what lets edits accumulate coherently. Developers can chain generations. They can produce a clip, edit the cat into a puma kitten, restyle a video into 8-bit retro and then into a watercolor look, and store each version to branch from later.</p><p>The constraints are real and worth budgeting around. Clips currently cap at 10 seconds, per the model's <a href="https://deepmind.google/models/model-cards/gemini-omni-flash/">published model card</a>. To make something longer, you generate chunks and edit them together. Uploaded footage can be edited too, as long as it runs 10 seconds or under and the user holds the rights to it. Google's own model card is candid that holding consistency across edits and rendering accurate text remain open problems.</p><h2><b>Guardrails, watermarking and the line Google won't cross</b></h2><p>For a CISO, the demos matter less than the provenance work shipping alongside the model. Every Omni clip carries Google's SynthID watermark, Google is extending C2PA Content Credentials across its generative tools, and it has launched an AI Content Detection API that flags AI-generated media, both Google's and other vendors'.</p><p>Google has also drawn a deliberate line. The model won't take a still photo of a person plus an audio clip and lip-sync them into speech, an explicit move to limit deepfakes. It will, however, take a recording of someone talking and translate it into another language, a useful path for localizing global training content. For regulated enterprises, those constraints and the baked-in provenance are features rather than friction.</p><div></div><h2><b>The numbers: cheap, 720p-only, and (preliminarily) ranked first</b></h2><p>The pricing landed alongside the API, and it is aggressive. Omni Flash costs $0.10 per second of generated 720p video, which puts a ten-second clip at roughly a dollar. That matches Veo 3.1 Fast at the same resolution, runs double Veo 3.1 Lite, and undercuts standard Veo 3.1 by three-quarters.</p><table><tbody><tr><td><p><b>Per second (USD)</b></p></td><td><p><b>Gemini Omni Flash</b></p></td><td><p><b>Veo 3.1 Lite</b></p></td><td><p><b>Veo 3.1 Fast</b></p></td><td><p><b>Veo 3.1</b></p></td></tr><tr><td><p>720p</p></td><td><p>$0.10</p></td><td><p>$0.05</p></td><td><p>$0.10</p></td><td><p>$0.40</p></td></tr><tr><td><p>1080p</p></td><td><p>n/a</p></td><td><p>$0.08</p></td><td><p>$0.12</p></td><td><p>$0.40</p></td></tr><tr><td><p>4K</p></td><td><p>n/a</p></td><td><p>n/a</p></td><td><p>$0.30</p></td><td><p>$0.60</p></td></tr></tbody></table><p>
The table also exposes the catch though. Omni Flash only generates 720p. There is no 1080p or 4K option, while the Veo tiers scale up to 4K. For internal training and most social video, 720p is fine. For premium brand work meant for a large screen, it is a real ceiling, and the reason Veo 3.1 still has a job</p><p>Clips run 3 to 10 seconds at 720p native, in landscape (16:9) or portrait (9:16). As reference inputs the model accepts up to seven images and up to three video clips of three seconds or less. It does not take audio as an input yet, though it generates audio alongside the video it produces. Output is standard MP4, and every clip ships with SynthID watermarking and C2PA credentials baked in.</p><p>On quality, the early signal is strong. In LMArena's Text-to-Video Arena, a leaderboard where people vote on head-to-head outputs from competing models, Omni Flash sat at number one with a score of 1527. </p><h2><b>What it means for budgets, and what's still missing</b></h2><p>With real pricing in hand, the iteration story gets concrete. Every conversational edit is a fresh generation you pay for, so an edit-heavy session still adds up, roughly a dollar for each ten-second pass at 720p. What the stateful model changes isn't the cost of an edit, it's the number of wasted ones: because context carries across turns, those generations go toward refining a take that mostly works instead of restarting from a blank prompt and hoping the next attempt lands.</p><p>Omni isn't alone in this field. Veo 3.1 remains Google's production-grade option when you need higher resolution, and rivals from Bytedance, Alibaba and OpenAI are all chasing the same budgets. What Omni adds is the editing capability itself: the ability to treat a video as a living document instead of a one-shot render.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Update on Fortinet Use of Frontier AI]]></title>
<description><![CDATA[Fortinet CISO Carl Windsor shares an update on Fortinet’s active use of frontier AI—including Anthropic’s Glasswing and OpenAI’s Daybreak—for large-scale security testing, source code analysis findings, and what it means for customers and the industry.        This article has been…
Read more →
Th...]]></description>
<link>https://tsecurity.de/de/3635802/it-security-nachrichten/update-on-fortinet-use-of-frontier-ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3635802/it-security-nachrichten/update-on-fortinet-use-of-frontier-ai/</guid>
<pubDate>Tue, 30 Jun 2026 15:51:40 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Fortinet CISO Carl Windsor shares an update on Fortinet’s active use of frontier AI—including Anthropic’s Glasswing and OpenAI’s Daybreak—for large-scale security testing, source code analysis findings, and what it means for customers and the industry.        This article has been…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/update-on-fortinet-use-of-frontier-ai/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/update-on-fortinet-use-of-frontier-ai/">Update on Fortinet Use of Frontier AI</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Der CISO-Burnout als Sicherheitsrisiko]]></title>
<description><![CDATA[Der permanente Druck durch NIS-2 führt bei CISOs zu kognitiver Erschöpfung. Wenn müde Security-Teams Fehler machen, wird Burnout zum Einfallstor für Hacker.

Tags: #Burnout | #Cyber Security]]></description>
<link>https://tsecurity.de/de/3634735/it-security-nachrichten/der-ciso-burnout-als-sicherheitsrisiko/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3634735/it-security-nachrichten/der-ciso-burnout-als-sicherheitsrisiko/</guid>
<pubDate>Tue, 30 Jun 2026 08:37:31 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1920" height="1080" src="https://www.it-daily.net/wp-content/uploads/2026/06/Burnout_shutterstock_383139751.jpg" class="attachment-full size-full wp-post-image" alt="CISO, Burnout" decoding="async" srcset="https://www.it-daily.net/wp-content/uploads/2026/06/Burnout_shutterstock_383139751.jpg 1920w, https://www.it-daily.net/wp-content/uploads/2026/06/Burnout_shutterstock_383139751-300x169.jpg 300w, https://www.it-daily.net/wp-content/uploads/2026/06/Burnout_shutterstock_383139751-1024x576.jpg 1024w, https://www.it-daily.net/wp-content/uploads/2026/06/Burnout_shutterstock_383139751-768x432.jpg 768w, https://www.it-daily.net/wp-content/uploads/2026/06/Burnout_shutterstock_383139751-1536x864.jpg 1536w" sizes="(max-width: 1920px) 100vw, 1920px" title="Der CISO-Burnout als Sicherheitsrisiko 1"></p>
    Der permanente Druck durch NIS-2 führt bei CISOs zu kognitiver Erschöpfung. Wenn müde Security-Teams Fehler machen, wird Burnout zum Einfallstor für Hacker.

<p>Tags: <a href="https://www.it-daily.net/thema/burnout">#Burnout</a> | <a href="https://www.it-daily.net/thema/cyber-security">#Cyber Security</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The attack that hijacked Claude Code came through Sentry. Datadog, PagerDuty, and Jira have the same exposure.]]></title>
<description><![CDATA[A single fake error report hijacked Claude Code in controlled testing — the agent ran the attacker's code with the developer's full privileges, and not one alert fired. EDR, WAF, IAM, and the firewall all missed it completely.Tenet Security's June agentjacking disclosure describes a single crafte...]]></description>
<link>https://tsecurity.de/de/3633679/it-nachrichten/the-attack-that-hijacked-claude-code-came-through-sentry-datadog-pagerduty-and-jira-have-the-same-exposure/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3633679/it-nachrichten/the-attack-that-hijacked-claude-code-came-through-sentry-datadog-pagerduty-and-jira-have-the-same-exposure/</guid>
<pubDate>Mon, 29 Jun 2026 19:31:45 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A single fake error report hijacked Claude Code in controlled testing — the agent ran the attacker's code with the developer's full privileges, and not one alert fired. EDR, WAF, IAM, and the firewall all missed it completely.</p><p>Tenet Security's <a href="https://tenetsecurity.ai/blog/agentjacking-coding-agents-with-fake-sentry-errors/">June agentjacking disclosure</a> describes a single crafted Sentry error event — sent through a public credential that requires no breach and no authentication — that injected attacker instructions into error data that Claude Code, Cursor, and Codex then executed as trusted diagnostic output. Tenet tested 100-plus targets in controlled conditions and achieved an 85% success rate. Sentry called the flaw "technically not defensible."</p><p>he Cloud Security Alliance classified agentjacking as a <a href="https://labs.cloudsecurityalliance.org/research/csa-research-note-agentjacking-mcp-sentry-injection-20260612/">systemic MCP vulnerability class</a> within days of the disclosure. No credentials were stolen, no policy was violated, no perimeter was breached: every step in the chain was authorized. That is the problem.</p><p>Tenet identified <a href="https://thehackernews.com/2026/06/agentjacking-attack-tricks-ai-coding.html">2,388 organizations with publicly exposed Sentry credentials</a> that could be used to inject malicious events at scale. The research is proof-of-concept, not confirmed exploitation across all 2,388. But one captured Claude Code environment held a live AWS secret access key and private repository URLs.</p><p>Here is the scope test: If your AI coding agents are connected to Sentry, Datadog, PagerDuty, Jira, or any MCP-connected data source your developers trust — and those agents can execute shell commands — then your stack has the same blind spot.</p><p>Organizations running Sentry should audit all publicly exposed DSNs immediately. Sentry's architecture intentionally makes DSN credentials public for frontend error reporting, so the mitigation isn't revoking the DSN — it's restricting what agents can do with the data those DSNs return.</p><h2>Why your stack can't see it</h2><p>Agentjacking works because every step is authorized: The attacker sends a valid Sentry API call using a public DSN, the MCP server returns the injected event as authentic output, and the agent executes the instruction using the developer's privileges. No signature fired. The victim saw only benign diagnostics while the agent silently <a href="https://www.infosecurity-magazine.com/news/agentjacking-attacks-hijack-ai/">exposed cloud credentials and source-control tokens</a>.</p><p>SOC teams have never needed to distinguish between a developer running an npm install and an agent running that command in response to a malicious error event. That distinction <a href="https://thenewstack.io/agentjacking-sentry-mcp-attack/">did not exist until AI coding agents became production tools</a>. The stack that cannot make it is the stack agentjacking bypasses.</p><h2>Five surveys, one pattern</h2><p>Five independent surveys from the first half of 2026 found that enterprises trust their AI agents far more than their enforcement justifies.</p><p>Only <a href="https://www.okta.com/newsroom/articles/ai-agents-at-work-2026-agentic-enterprise-security/">34% of organizations apply the same security controls</a> to AI agents as to humans, according to an Okta/Apprize360 survey of 292 executives and 492 knowledge workers. Fifty-two percent of employees use unapproved AI tools, and 58% of executives reported an AI-related incident or close call in the prior year.</p><p>HiddenLayer’s 2026 AI Threat Landscape Report surveyed 250 IT and security leaders: 33% reported <a href="https://www.hiddenlayer.com/report-and-guide/threatreport2026">agents had already exceeded intended scope</a>, and 31% could not confirm whether they had experienced an AI breach. One in eight AI breaches was linked to agentic systems.</p><p><a href="https://www.gravitee.io/blog/state-of-ai-agent-security-2026-report-when-adoption-outpaces-control">Gravitee’s survey of over 900 executives and practitioners</a> found only 14.4% of agents <a href="https://www.gravitee.io/blog/state-of-ai-agent-security-2026-report-when-adoption-outpaces-control">went live with full security approval</a>, and 88% reported confirmed or suspected incidents. A follow-up of 750 leaders in April found agent estates had doubled while monitoring barely moved.</p><h2>The runtime gap nobody closed</h2><p>“Securing agents looks very similar to securing highly privileged users,” said Elia Zaitsev, CTO of CrowdStrike, in an <a href="https://venturebeat.com/security/rsac-2026-agent-identity-frameworks-three-gaps">interview with VentureBeat</a>. “They have identities, access to underlying systems, they reason, they take action.”</p><p>Zaitsev pointed to the gap the industry left open. “No one has been talking about securing agents at runtime. We are doing that now. What is your safety net? If all these controls fail, how do you prevent them from failing silently?”</p><p>CrowdStrike's fleet data quantifies the exposure: more than 1,800 agentic applications on enterprise endpoints, approximately 160 million instances under monitoring. On June 15, <a href="https://www.crowdstrike.com/en-us/press-releases/crowdstrike-unveils-continuous-identity-for-ai-agents/">CrowdStrike shipped Continuous Identity for AI Agents at Identiverse</a>, replacing static policies with continuous enforcement that authorizes every agent action in real time. The control class that announcement reflects — continuous action-level authorization with verifiable agent identity — is now a baseline procurement criterion regardless of vendor.</p><p>“People have kind of forgotten about runtime security,” Zaitsev said. “We did this with endpoint, virtualization, and cloud. People focused on patching vulnerabilities, locking down permissions. Somehow, they always seem to miss something. The safety net is runtime.”</p><p>Zaitsev was equally direct about sandbox approaches. “If you start with an agent in a sandbox that has no ability to touch anything, it is worthless. Very quickly, you are in this race of giving it more capabilities. And then what is the point of your sandbox?” Agents derive their value from access. Every access grant is an attack surface.</p><h2>The governance gap is a budget problem</h2><p>Kayne McGladrey, an IEEE Senior Member, described the structural challenge in an exclusive interview with VentureBeat. “The CISO doesn’t have the budget. The CISO doesn’t have the staff. We can observe risks, we can advise on business risks, but we don’t own the business systems affected by those risks,” McGladrey said. When agent governance spans six departmental budgets, no single executive can confirm whether agents get the same access reviews as humans.</p><p>The Okta survey quantifies the disconnect. Only <a href="https://www.okta.com/newsroom/press-releases/showcase-2026/">43% of workers say agent policies are clear</a>, compared to 65% of executives, and nearly two-thirds apply weaker controls to agents than to humans. The people deploying agents daily do not recognize the governance posture their leadership claims to have built.</p><p>Assaf Keren, chief security officer at Qualtrics and former CISO at PayPal, put it plainly. “The real risk starts not by the implementation of AI systems. It is the fact that baseline architecture is not well established. When we put an AI system on top of something not architected well, we are accelerating the fractures.” Keren called runtime behavior analytics “an unsolved problem right now.”</p><h2>The 5-question gap test</h2><p>The five-question gap test draws on five surveys from the first half of 2026. Each question maps to a gap that agentjacking exploits. Run this before any Q3 vendor evaluation.</p><table><tbody><tr><td><p><b>Gap to test</b></p></td><td><p><b>The proof</b></p></td><td><p><b>What breaks</b></p></td><td><p><b>Monday action</b></p></td><td><p><b>Source / sample</b></p></td></tr><tr><td><p>1. Agent inventory. What percentage of agents, MCP connections, and LLM automations completed security review before deployment?</p></td><td><p>14.4% get full security/IT approval before going live. 52% of employees use unapproved AI tools. Average enterprise now manages 37+ deployed agents, roughly doubled from Q4 2025.</p></td><td><p>Unapproved agents are invisible to your identity platform and unaccountable in a breach disclosure. Agentjacking targets exactly these unmanaged MCP connections. No census means no audit trail for regulatory response.</p></td><td><p>Commission a full agent, MCP server, and LLM automation census. Make census completion a procurement gate for all Q3 vendor evaluations. Flag any agent discovered post-census as a shadow AI incident.</p></td><td><p>Gravitee State of AI Agent Security 2026, 900+ respondents (Feb 2026); Gravitee April 2026 update, 750 senior tech leaders; Okta/Apprize360, 292 execs + 492 workers (June 2026)</p></td></tr><tr><td><p>2. Controls parity. Do agents receive the same access reviews, privilege scoping, and revocation timelines as human employees?</p></td><td><p>34% always apply the same controls to agents as humans. 61% of privileged access fulfilled without proper review. Only 22% treat agents as independent identity-bearing entities.</p></td><td><p>An agent with a static OAuth token and no review cycle is a permanent privileged account with no termination date. Agentjacking inherits whatever privileges the developer holds. 45.6% of orgs rely on shared API keys for agent-to-agent auth.</p></td><td><p>Add every production agent to the next access review cycle. Mandate human-in-the-loop for any agent action touching PII, financial data, or production infrastructure. Replace shared API keys with scoped, short-lived tokens.</p></td><td><p>Okta/Apprize360 (784 respondents, June 2026); Palo Alto Networks (2,930 respondents); Gravitee (900+, shared API keys data)</p></td></tr><tr><td><p>3. Scope drift. Have any agents accessed data or systems beyond their defined scope in the last 12 months?</p></td><td><p>33% report agents already exceeded scope. 53% say agents exceed permissions occasionally or sometimes. Meta Sev 1, March 2026: agent posted sensitive data to unauthorized channel. Only 8% say agents never exceed intended permissions.</p></td><td><p>Scope drift triggers reportable events under GDPR, CCPA, HIPAA, and SEC cybersecurity rules. If detection cannot distinguish agent-initiated from human-initiated access, disclosure timelines are unachievable. Agent-spawned sub-agents (25.5% of deployed agents can create other agents) make audit trails algebraically intractable.</p></td><td><p>Run a 90-day scope-drift audit on every production agent. Compare actual resources touched against approved scope documentation. Block agent-to-agent delegation without explicit human approval for any action exceeding the parent agent’s scope.</p></td><td><p>HiddenLayer AI Threat Landscape 2026 (250 IT/security leaders); CSA AI Agent Security Survey (scope violations data); Gravitee (agent spawning data)</p></td></tr><tr><td><p>4. Governance perception gap. Would 50 knowledge workers say your AI agent policies are clear?</p></td><td><p>22-point gap: 65% of executives say policies are clear, 43% of workers agree. 77% of security teams see shadow AI risk but lack visibility to act. 76% cite shadow AI as a definite or probable problem.</p></td><td><p>You are evaluating vendors against a governance posture your workforce does not recognize. Every shadow agent undermines the vendor comparison. Knowledge workers sharing internal messages (54%), HR data (45%), and confidential docs (39%) with unapproved AI tools.</p></td><td><p>One-question survey before your next vendor demo. Gap exceeds 15 points, pause procurement. Publish an internal AI agent acceptable-use policy with specific examples of approved and prohibited agent behaviors.</p></td><td><p>Okta/Apprize360 (784 respondents, June 2026); Ivanti 2026 AI Maturity Report (1,200 respondents); HiddenLayer (shadow AI data)</p></td></tr><tr><td><p>5. Breach detection certainty. Can your security team confirm whether you experienced an AI-related breach in the last 12 months?</p></td><td><p>31% cannot answer. 88% reported confirmed or suspected AI agent security incidents. One in eight reported AI breaches now linked to agentic systems. Agentjacking proved EDR, WAF, IAM, and firewall pass an agent-mediated attack without a single alert.</p></td><td><p>No basis for disclosure timelines. No evidence chain for incident response. No defensible position in a regulatory investigation. EU AI Act high-risk compliance obligations take effect August 2, 2026.</p></td><td><p>Require agent-specific runtime detection as a procurement prerequisite. Confirm your org can distinguish agent-initiated actions from human-initiated actions in production telemetry. Test your SOC’s ability to attribute a specific action to a specific agent within 60 minutes.</p></td><td><p>HiddenLayer (250 IT/security leaders); Gravitee (900+, incident rate); Tenet Security (2,388 orgs exposed); CSA (systemic MCP vulnerability classification)</p></td></tr></tbody></table><h2>Security director action plan</h2><p>EU AI Act high-risk compliance obligations take effect August 2, 2026. Worth factoring into Q3 planning timelines.</p><ol><li><p>Run the five-question gap test above before any Q3 vendor evaluation — it costs nothing to administer, and the procurement clarity it creates is worth far more than the 30 minutes it takes.</p></li><li><p>Consider mandating agent-specific runtime detection. If your stack cannot tell what an agent did from what a developer did, agentjacking will bypass it the same way it bypassed every layer in Tenet’s testing. That distinction is the one that matters now.</p></li><li><p>Treat every agent as a privileged insider. According to the Okta/Apprize360 survey, only 34% of organizations apply the same controls to agents as to humans; closing that gap is the single most impactful thing most security teams can do this quarter.</p></li><li><p>Test the perception gap before investing in new tooling. One question to 50 knowledge workers. Do you know your company’s AI agent policies? If the gap between their answer and leadership’s answer exceeds 15 points, that is the problem to solve first. No vendor product fixes a governance posture your own workforce does not recognize.</p></li><li><p>Make agent census completion a procurement gate — every agent, every MCP connection. The security teams getting this right are the ones that started with a complete inventory and worked forward from there.</p></li></ol><p>Agentjacking stripped away an assumption that has survived every security architecture since the first firewall went live. Authorized does not mean safe. When every step in the chain is legitimate, the only defense that matters is the one watching what agents do. Not what policies say. What agents do.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[From MFA to Phishing-Resistant Identity: What CISOs Should Prioritize in 2026]]></title>
<description><![CDATA[From MFA to Phishing-Resistant Identity A CISO guide to moving beyond basic MFA toward phishing-resistant identity, session protection, conditional access, least privilege, and stronger recovery controls.]]></description>
<link>https://tsecurity.de/de/3632955/it-security-nachrichten/from-mfa-to-phishing-resistant-identity-what-cisos-should-prioritize-in-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3632955/it-security-nachrichten/from-mfa-to-phishing-resistant-identity-what-cisos-should-prioritize-in-2026/</guid>
<pubDate>Mon, 29 Jun 2026 15:09:30 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[From MFA to Phishing-Resistant Identity A CISO guide to moving beyond basic MFA toward phishing-resistant identity, session protection, conditional access, least privilege, and stronger recovery controls.]]></content:encoded>
</item>
<item>
<title><![CDATA[What the post-quantum executive order really demands of CISOs]]></title>
<description><![CDATA[ith federal PQC deadlines set for 2030 and 2031, CISOs face a multi-year transformation program that most organizations have not yet started. The window for orderly execution is narrowing fast.
The post What the post-quantum executive order really demands of CISOs appeared first on CyberScoop.]]></description>
<link>https://tsecurity.de/de/3632394/it-security-nachrichten/what-the-post-quantum-executive-order-really-demands-of-cisos/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3632394/it-security-nachrichten/what-the-post-quantum-executive-order-really-demands-of-cisos/</guid>
<pubDate>Mon, 29 Jun 2026 11:09:28 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>ith federal PQC deadlines set for 2030 and 2031, CISOs face a multi-year transformation program that most organizations have not yet started. The window for orderly execution is narrowing fast.</p>
<p>The post <a href="https://cyberscoop.com/post-quantum-cryptography-readiness-ciso-deadlines-op-ed/">What the post-quantum executive order really demands of CISOs</a> appeared first on <a href="https://cyberscoop.com/">CyberScoop</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Cloud-Strategien sind komplexer denn je]]></title>
<description><![CDATA[Mit dem KI-Boom spielt die Auswahl der Cloud-Lösung(en) für Unternehmen eine noch stärkere Rolle.Gorodenkoff / Shutterstock



Nach jahrelanger Erfahrung mit der Cloud glaubten IT-Führungskräfte, ihre Strategien diesbezüglich endlich fest im Griff zu haben. Dann kam die KI.



Die aktuellen Herau...]]></description>
<link>https://tsecurity.de/de/3631888/it-security-nachrichten/cloud-strategien-sind-komplexer-denn-je/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3631888/it-security-nachrichten/cloud-strategien-sind-komplexer-denn-je/</guid>
<pubDate>Mon, 29 Jun 2026 06:07:07 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/shutterstock_2136788239_16.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Cloud, KI, Rechenzentrum" class="wp-image-4188721" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption">Mit dem KI-Boom spielt die Auswahl der Cloud-Lösung(en) für Unternehmen eine noch stärkere Rolle.</figcaption></figure><p class="imageCredit">Gorodenkoff / Shutterstock</p></div>



<p>Nach jahrelanger Erfahrung mit der <a href="https://www.computerwoche.de/article/3974324/14-effektive-cloud-spartipps.html">Cloud</a> glaubten IT-Führungskräfte, ihre Strategien diesbezüglich endlich fest im Griff zu haben. Dann kam die KI.</p>



<p>Die aktuellen Herausforderungen rund um die Cloud gehen jedoch weit über <a href="https://www.computerwoche.de/artificial-intelligence/">künstliche Intelligenz</a> hinaus. Dazu zählen neben der Frage, wo Workloads für maximale Effizienz platziert werden sollten, auch Governance-Anforderungen, Datensouveränität, zunehmend ausgefeilte Cyberbedrohungen und steigender Kostendruck. All diese Faktoren machen die Cloud-Landschaft immer komplexer.</p>



<h2 class="wp-block-heading">Mehr als ein Infrastrukturthema</h2>



<p>„Das Ganze hat sich zu einem ziemlich komplexen Durcheinander entwickelt“, stellt der Cloud-Experte <a href="https://davidlinthicum.com/">David Linthicum</a> fest. Eine moderne Cloud-Strategie müsse heute Private Clouds, Multi-Cloud-Umgebungen, Hybrid-Cloud-Modelle und souveräne Clouds berücksichtigen – deutlich mehr, als die meisten CIOs bislang bewältigen mussten.</p>



<p>Anfangs drehten sich die Diskussionen rund um Cloud vor allem um Agilität, Skalierbarkeit und <a href="https://www.computerwoche.de/article/4140431/cloud-datenplattformen-ein-kaufratgeber.html">Kostenoptimierung</a>, erklärt <a href="https://www.joshuabellendir.com/">Joshua Bellendir</a>, CIO des Einzelhändlers WHSmith North America. „Heute müssen wir eine wesentlich größere und komplexere Zahl von Faktoren berücksichtigen: KI-Bereitschaft, Cybersicherheit, Data Governance, Anforderungen an die Datensouveränität, Edge Computing, Integrationsarchitekturen und operative Resilienz.“</p>



<p></p>



<p>Eine der größten Veränderungen bestehe darin, dass die Cloud nicht mehr nur ein Infrastrukturthema sei, so Bellendir. „Sie ist inzwischen eng mit Unternehmensarchitektur, Business Transformation und Datenstrategien verknüpft.“</p>



<p>Auch <a href="https://www.linkedin.com/in/amitbasu/" target="_blank" rel="noreferrer noopener">Amit Basu</a>, Vice President, CIO und CISO bei International Seaways, beobachtet zunehmende Komplexität. „Zwar gelten die Vorteile geringerer Investitionskosten und höherer Flexibilität in vielen Bereichen weiterhin, doch das Management der Cloud-Umgebung ist deutlich anspruchsvoller geworden.“, erklärt er.</p>



<p><a href="https://www.linkedin.com/in/jasonpauljohnson/" target="_blank" rel="noreferrer noopener">Jason Johnson</a>, CIO des Musikinstrumentenhändlers Sweetwater, beschreibt die aktuelle Situation als eine der komplexesten Phasen überhaupt für das Cloud-Management. Die Anbieter erweiterten ihre Portfolios kontinuierlich um neue Services, Produktvarianten und Optionen.</p>



<p>„Das schafft zwar zusätzliche Möglichkeiten, verursacht aber auch erheblichen Aufwand, um den Überblick zu behalten. Man braucht Fachkräfte, die nicht nur wissen, was verfügbar ist, sondern auch beurteilen können, welche Lösung für den jeweiligen Anwendungsfall die richtige ist“, meint der IT-Entscheider.</p>



<p>Viele Unternehmen würden inzwischen in eine zweite Phase ihrer Cloud-Reife eintreten, nachdem sie in der ersten Phase den Fokus auf Migration und Modernisierung gelegt hätten, erklärt Johnson. „Heute geht es stärker um Optimierung, Governance, KI-Unterstützung und nachhaltigen Betrieb. Dieser Wandel verändert die Diskussionen, die ich mit CIOs führe, grundlegend.“</p>



<p>Die wenigsten CIOs können es sich jedoch leisten, lange über ihre nächsten Schritte nachzudenken. Sie müssen den Herausforderungen zunehmend komplexer werdender Cloud-Strategien aktiv begegnen.</p>



<h2 class="wp-block-heading">Wie KI die Cloud-Gleichung verändert</h2>



<p>„Der Wunsch, KI möglichst schnell einzuführen, setzt IT-Verantwortliche erheblich unter Druck. Dabei spielt die Cloud eine zentrale Rolle“, führt Linthicum aus. „Die Aufsichtsräte treiben das Thema noch stärker voran als den Cloud-Boom vor 15 Jahren“, erklärt er. CIOs spüren diesen Druck und müssen so schnell wie möglich handeln, um zusätzliche Rechenkapazitäten für KI-Initiativen bereitzustellen – und das in einem ohnehin schon komplexen Umfeld.“</p>



<p>Gleichzeitig müssten CIOs das Problem der Datenkomplexität lösen, bevor KI-Systeme erfolgreich integriert werden können, betont der Cloud-Experte. „Derzeit drehen sich viele im Kreis und versuchen herauszufinden, welcher Ansatz dafür der Beste ist.“</p>



<p>Hyperscaler galten früher als der einfache Weg, so Linthicum, könnten aber drei- bis viermal so teuer werden. KI-Systeme kosten seiner Einschätzung nach etwa zehnmal so viel wie vergleichbare, traditionelle Anwendungen.</p>



<p>Basu von International Seaways erklärt, dass KI die Diskussion über die IT-Architektur grundlegend verändert habe. „Die Verfügbarkeit von GPUs, Vektordatenbanken, Inferenz mit geringer Latenz und groß angelegte Datenpipelines bringen Anforderungen mit sich, die sich nicht nahtlos in herkömmliche Cloud-Designmodelle einfügen“, merkt er an. Unternehmen verlagern Workloads nicht mehr einfach nur in die Cloud. Sie entwerfen Architekturen für völlig andere Rechen- und Datenanforderungen.“</p>



<p>Laut <a href="https://www.linkedin.com/in/zacharylewis1/" target="_blank" rel="noreferrer noopener">Zachary Lewis</a>, CIO und CISO der University of Health Sciences and Pharmacy, verstärkten die Bedürfnisse interner Stakeholder diese Komplexität noch. „Geschäftsbereiche wünschen sich unterschiedliche KI-Fähigkeiten, Sicherheitsteams wollen Governance und eine gewisse Kontrolle über KI-Anwendungen, der Justiziar möchte wissen, welche Art von Daten in das KI-Modell eingespeist werden, und das Finanzteam erwartet Kostenvorhersehbarkeit. CIOs müssen all dies unter einen Hut bringen – und das erfolgreich versteht sich“, so Lewis.</p>



<p>Seit der Online-Händler für Musikinstrumente und professionelle Audiotechnik Sweetwater seine Cloud-Strategie um das Jahr 2016 formalisiert hat, versucht Johnson, Workloads dort zu platzieren, wo sie für externe und interne Kunden den größten Nutzen bringen.</p>



<p>„Alles mit Kundenkontakt muss so nah wie möglich am Endnutzer ablaufen“, erklärt er. Die gleiche Logik gilt auch für interne Workloads: Sie gehören in die Nähe derjenigen, die sie nutzen. KI wäre ohne die Cloud nicht möglich. Die für KI erforderliche Rechenkapazität war bereits vorhanden – die Cloud verfügte darüber und konnte sie bereitstellen. In vielerlei Hinsicht ist KI vielleicht das größte Geschenk der Cloud an die Branche. Beide haben sich gegenseitig ermöglicht“, fügt der Manager hinzu.</p>



<h2 class="wp-block-heading">Cloud-Kostenmanagement wird immer komplexer</h2>



<p>Johnsons größtes Problem ist die konsistente Steuerung der Kosten. „Früher war es relativ einfach: Rechenleistung, Speicher, Datenverkehr. Heute ist es ein Puzzle. Reservierte Instanzen, Sparpläne, Spot-Preise, Kosten pro Anfrage, Gebühren für Datenübertragungen zwischen Regionen – das summiert sich schnell. Und es ist wirklich schwer vorherzusagen, wie Ihre Rechnung aussehen wird, bis sie eintrifft.“</p>



<p>Deshalb sei FinOps inzwischen zu einer eigenen Disziplin geworden.</p>



<p>Auch Basu hält FinOps für unverzichtbar. „Kosten für KI-Inferenz, Datenübertragungen und wachsende Speichermengen können monatliche Kostenschwankungen verursachen, die selbst erfahrene Teams überraschen“, führt er aus. Kostenmanagement ist heute eine kontinuierliche operative Disziplin und nicht mehr nur eine gelegentliche Überprüfung.“</p>



<p>Auch die Gefahr des Vendor Lock-in beschäftigt Johnson ständig. „Je tiefer man die nativen Dienste eines Anbieters integriert, desto schwieriger wird ein Wechsel. Das ist nicht zwangsläufig schlecht, aber ein Kompromiss. Ich sehe das wie technische Schulden. Man gewinnt heute Geschwindigkeit und zahlt später Zinsen, wenn man die Richtung ändern möchte.“</p>



<p>Gleichzeitig erkennt Johnson an, dass Cloud-Anbieter Unternehmen sind, die auf Umsatz und Marge achten und regelmäßig die Regeln für Rabatte und Kostenmodelle ändern.</p>



<p>Finanzielle Effizienz entstehe nicht von selbst, betont er: „Das erfordert Teams, Prozesse und echte Investitionen in FinOps. Die Werkzeuge sind vorhanden. Die eigentliche Herausforderung besteht darin, sie richtig einzusetzen.“</p>



<p>In den meisten Unternehmen liege das Finanzwissen in der Buchhaltung und das technische Wissen in der IT, erklärt Johnson. Beide Gruppen beim Cloud-Kostenmanagement zusammenzubringen, sei eine vergleichsweise neue Herausforderung.</p>



<p>„Vor zehn Jahren war das Modell einfach: Man beantragte ein Investitionsbudget, die Buchhaltung genehmigte es, Hardware wurde bestellt und die IT installierte und optimierte alles. Fertig“, sagt Johnson. „Heute ist es eine tägliche Aufgabe. Neue Dienste werden aktiviert, Verträge ändern sich, Preisstrukturen werden angepasst. Die Finanzabteilung versteht die Geldströme, aber nicht die Technik. Die IT versteht die Technik, aber nicht die finanziellen Hebel.“</p>



<p>Jeder große Cloud-Anbieter verfügt über die entsprechenden Tools, erklärt Johnson. „AWS Cost Explorer, Azure Cost Management, die Abrechnungs-Dashboards von Google Cloud. Die Daten sind alle vorhanden. Doch viele Unternehmen nutzen diese Daten nicht. Dann kommt die Rechnung und alle sind überrascht. Die Werkzeuge haben die Entwicklung angekündigt. Man hat nur nicht hingehört.“</p>



<h2 class="wp-block-heading">Datenregulierung bringt zusätzliche Herausforderungen</h2>



<p>Die University of Health Sciences and Pharmacy hat Studierende aus der ganzen Welt. Laut Lewis ist Cloud-Management aufgrund der zunehmenden Datenschutz- und Regulierungsanforderungen weltweit deutlich schwieriger geworden.</p>



<p>„Wir müssen verstehen, in welcher Cloud-Region Metadaten gespeichert werden und wo sie dauerhaft liegen. Wenn diese Daten in ein intern trainiertes Modell einfließen, können wir garantieren, dass sie in der EU bleiben? Und wenn jemand die Löschung seiner Daten verlangt, können wir alle Speicherorte zuverlässig identifizieren?“</p>



<p>Basu ergänzt, dass Datensouveränität zu einer weiteren zentralen Architekturfrage geworden sei.</p>



<p>„Sie beeinflusst, wo Workloads ausgeführt werden dürfen, wie Daten zwischen Regionen bewegt werden und was mit bestimmten Datensätzen geschehen darf. Man kann nicht davon ausgehen, dass die Standardkonfiguration eines Hyperscalers automatisch alle regulatorischen Anforderungen erfüllt.“</p>



<h2 class="wp-block-heading">Private Cloud, Public Cloud oder On-Premises?</h2>



<p>KI hat eine Neubewertung der Platzierung von Workloads ausgelöst. Johnson glaubt jedoch, dass sich die Frage nach Private Cloud, Public Cloud oder On-Premises häufiger verändert, als viele denken.</p>



<p>„Ich denke, die meisten unserer Workloads befinden sich derzeit am richtigen Ort. Aber wir sind nur dorthin gelangt, weil wir bereit waren, Standardannahmen zu hinterfragen.“</p>



<p>Bei Sweetwater gebe es keine Regel, dass neue Workloads automatisch in die Cloud gehören. Ein Workload könne in der Cloud starten und später wieder ins eigene Rechenzentrum zurückkehren, wenn die Wirtschaftlichkeit dies erfordert.</p>



<p>„Die eigentliche Disziplin besteht darin, dies laufend zu überprüfen, Wendepunkte zu erkennen und die Größe der Umgebung kontinuierlich anzupassen. Das richtige Werkzeug zur richtigen Zeit – das ist das einzige Prinzip, das langfristig Bestand hat.“</p>



<p>Basu plant keinen Umstieg auf eine Private Cloud, da die Wirtschaftlichkeit und der betriebliche Aufwand dies für sein Unternehmen nicht rechtfertigen.</p>



<p>„Die richtige Frage lautet: Welches Modell für Datenresidenz, Latenz und Kontrolle ist für jeden Workload angemessen? Das ist eine Frage der Datenklassifizierung, nicht der Cloud-Bereitstellungsstrategie.“</p>



<p>Lewis, dessen Universität rund 95 Prozent ihrer Infrastruktur in der Cloud betreibt, sieht angesichts der Anforderungen von KI und moderner Hardware kaum praktikable Alternativen.</p>



<p>„Wenn man groß angelegte Data Lakes trainieren und fundierte Geschäftsentscheidungen mithilfe von maschinellem Lernen und der dahinterstehenden Intelligenz treffen möchte, ist es fast nicht mehr praktikabel, auf eigene Server zu setzen“, so Lewis.</p>



<p>CIOs müssten sich fragen, ob sie überhaupt über das notwendige Know-how verfügen, um eine solche Infrastruktur selbst zu betreiben. Letztlich müsse man das Beste aus den vorhandenen Möglichkeiten machen.</p>



<h2 class="wp-block-heading">Fokus auf die Grundlagen</h2>



<p>Unternehmen mögen vielleicht dem neuesten Trend hinterherjagen – derzeit ist das die agentische KI –, doch IT-Führungskräfte sollten sich auf ihre Infrastruktur, das Management und die Plattformplanung konzentrieren, betont Linthicum.</p>



<p>„Das ist vielleicht weniger spannend, aber wenn man KI im Unternehmen einsetzen will, muss man diese Probleme zuerst lösen.“</p>



<p>Johnson warnt, dass die Cloud eine Vielzahl architektonischer Muster ermöglicht – und diese Freiheit könne ohne Leitplanken zum Problem werden. „Erstellen Sie das Leitliniendokument, bevor Sie es brauchen – nicht erst, wenn bereits fünf Teams auf fünf verschiedene Arten vorgehen.“</p>



<p>IT-Verantwortliche sollten außerdem frühzeitig für ein sauberes Tagging und Transparenz bei den Kosten sorgen. Das müsse der erste Schritt sein und dürfe nicht erst als Aufräumprojekt betrachtet werden, warnt Johnson: „Wenn Sie Ihre Ausgaben nicht vom ersten Tag an klar nachvollziehen können, sind Sie bereits im Rückstand.“</p>



<p>Ein weiterer wichtiger Schritt sei der Aufbau eines Audit-Programms mit klaren Kontrollen darüber, wer Änderungen an Produktivsystemen vornehmen darf: „Die Auswirkungen einer fehlerhaften Änderung in der Cloud sind größer und treten schneller ein, als die meisten Menschen erwarten – bis sie es selbst erleben.“</p>



<h2 class="wp-block-heading">Die Frage nach den Kompetenzen</h2>



<p>Die Fähigkeiten, die für den Betrieb moderner Cloud-Umgebungen erforderlich sind, entwickeln sich laut Basu schneller weiter, als die meisten internen Teams realistischerweise mithalten können. Deshalb setzt International Seaways auf spezialisierte Managed Service Provider (MSPs), anstatt in jedem Bereich tiefgehendes internes Expertenwissen aufzubauen.</p>



<p>„Dadurch haben wir Zugang zu aktuellen Fähigkeiten, ohne Teams ständig umschulen oder neu aufbauen zu müssen, wenn sich die Technologie ändert. Die Entscheidungen, die uns 2020 geschützt haben, wurden Jahre zuvor getroffen – lange bevor jemand ihre Bedeutung erkannt hatte. Infrastrukturstrategie bedeutet immer, sich auf eine Zukunft vorzubereiten, die noch nicht vollständig sichtbar ist.“</p>



<p>Entscheidend sei, solche Entscheidungen bewusst und auf Basis klarer Überlegungen zu treffen, anstatt später unter Druck reagieren zu müssen.</p>



<h2 class="wp-block-heading">Anpassungsfähige Organisationen aufbauen</h2>



<p>Edge-Computing fügt laut Johnson eine weitere Ebene der Komplexität hinzu. Erfolgreich werden nicht diejenigen sein, die die perfekte Architektur finden. „Es sind diejenigen, die Organisationen aufbauen, die sich schnell anpassen können, wenn sich die richtige Antwort morgen ändert“, erklärt er.</p>



<p>Der eigentliche Wettbewerbsvorteil liege nicht in der gewählten Cloud-Plattform, sondern darin, wie schnell ein Team lernen und handeln kann, so Johnson.</p>



<p>Auf die Frage, wie sich Cloud-Umgebungen weniger kompliziert gestalten lassen, gaben die CIOs folgende Empfehlungen:</p>



<ul class="wp-block-list">
<li><strong>Behandeln Sie Ihre Cloud-Architektur wie ein Produkt, nicht wie ein Projekt.</strong> Sie benötigt kontinuierliche Verantwortung und Weiterentwicklung, nicht nur eine einmalige Implementierung.</li>



<li><strong>Überprüfen Sie Ihre Entscheidungen regelmäßig.</strong> „Die richtige Entscheidung im ersten Jahr ist oft nicht mehr die richtige im dritten. Planen Sie feste Überprüfungspunkte ein“, erklärt Johnson.</li>



<li><strong>Ordnen Sie jeden Workload einer Kostenstelle zu.</strong> Basu hat dies umgesetzt; die IT überprüft kontinuierlich Auslastung und Größenanpassungen, anstatt auf periodische Audits zu warten.</li>



<li><strong>Die Datenklassifizierung bestimmt die regionale Platzierung.</strong> Bevor ein Workload in Produktion geht, sollten Rechts- und Compliance-Abteilungen von Anfang an eingebunden sein.</li>



<li><strong>Entwickeln Sie Cloud-fähige Lösungen.</strong> Das kann günstiger und risikoärmer sein als die unveränderte Migration stark angepasster Altsysteme.</li>



<li><strong>Konsolidierung ist eine strategische Entscheidung, kein Rückzug.</strong> Weniger Plattformen, die gut gesteuert werden, schneiden dauerhaft besser ab als eine zersplitterte Multi-Cloud-Landschaft.</li>



<li><strong>Unterschätzen Sie nicht die Governance-Lücke, die durch KI entsteht.</strong> Schaffen Sie jetzt eine KI-Governance-Struktur, bevor sich technische und organisatorische Schulden anhäufen.</li>



<li><strong>Cloud-Strategie ist keine reine IT-Architekturentscheidung.</strong> Die Pandemie habe gezeigt, dass sie vor allem eine Entscheidung zur Sicherung der Unternehmensresilienz sei. „Die Organisationen, die schwierige Entscheidungen vor einer Krise treffen, sind diejenigen, die unbeschadet daraus hervorgehen.“</li>



<li><strong>Verknüpfen Sie Cloud-Entscheidungen mit messbaren Geschäftsergebnissen.</strong> Bellendir von WHSmith berichtet, dass sein Unternehmen stark in Integrationsarchitekturen, Cybersicherheitskontrollen, Observability und Data Governance investiert, um hybride Umgebungen besser zu unterstützen.</li>



<li><strong>Legen Sie größeren Wert auf Cloud-Kostenkontrolle und operative Disziplin.</strong> Dadurch wird die Transparenz über die Cloud-Nutzung verbessert und sichergestellt, dass die Skalierung von KI-, Analyse- und Digitalisierungsinitiativen langfristig finanziell tragfähig bleibt.</li>
</ul>



<p>Auch wenn niemand vorhersagen kann, ob Cloud-Umgebungen künftig weniger komplex werden, werden Unternehmen sie weiterhin nutzen.</p>



<p>„Die Cloud ist nicht mehr die Zukunft der IT – sie ist die Gegenwart. Die Diskussion hat sich von der Frage ‚Sollen wir das tun?‘ hin zu ‚Wie werden wir darin besser?‘ verschoben. Und genau damit verbringe ich heute den Großteil meiner Zeit“, konstatiert Johnson. (mb)</p>



<p><em>Dieser Artikel basiert auf einem <a href="https://www.cio.com/article/4178280/cloud-strategies-have-become-more-complicated-than-ever.html">Beitrag von CIO.com</a></em></p>



<hr class="wp-block-separator has-alpha-channel-opacity">



<h2 class="wp-block-heading"></h2>


<div class="text text--no-top-margin"><h2>Im Fokus: Cloud Computing</h2><p>Erfahren Sie in unserem kostenlosen PDF, was IT-Entscheider 2026 in puncto Cloud wissen müssen.</p><p><a class="button button--primary" data-amp-height="40" target="" href="https://whitepaper.computerwoche.de/resources/im-fokus-cloud-computing/">Jetzt herunterladen!</a></p></div>

<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/05/Teaser-Cloud.png?w=1024" alt="Im Fokus Cloud" class="wp-image-4178649" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p></p>
</figcaption></figure><p class="imageCredit">CineVI – shutterstock.com</p></div>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[US Restricts Frontier AI models]]></title>
<description><![CDATA[US Loosens Anthropic Claude Mythos Access, Unpatchable iPhone Exploit Emerges, and CISO Burnout Drives Fractional Shift Washington granted a partial reprieve allowing Anthropic’s Claude Mythos to be released to more than 100 approved U.S. firms and institutions after export controls…
Read more →
...]]></description>
<link>https://tsecurity.de/de/3631811/it-security-nachrichten/us-restricts-frontier-ai-models/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3631811/it-security-nachrichten/us-restricts-frontier-ai-models/</guid>
<pubDate>Mon, 29 Jun 2026 04:37:31 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>US Loosens Anthropic Claude Mythos Access, Unpatchable iPhone Exploit Emerges, and CISO Burnout Drives Fractional Shift Washington granted a partial reprieve allowing Anthropic’s Claude Mythos to be released to more than 100 approved U.S. firms and institutions after export controls…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/us-restricts-frontier-ai-models/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/us-restricts-frontier-ai-models/">US Restricts Frontier AI models</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Factory reset required.]]></title>
<description><![CDATA[Tata Electronics and Bajaj Auto continue recovery from cyberattacks. FCC tightens undersea cable rules to bolster national security. CISA warns of actively exploited PTC vulnerability. Gamaredon expands toolkit, hides behind legitimate services. Iran-linked hackers turn public warning systems int...]]></description>
<link>https://tsecurity.de/de/3628535/it-security-nachrichten/factory-reset-required/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3628535/it-security-nachrichten/factory-reset-required/</guid>
<pubDate>Fri, 26 Jun 2026 22:38:24 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Tata Electronics and Bajaj Auto continue recovery from cyberattacks. FCC tightens undersea cable rules to bolster national security. CISA warns of actively exploited PTC vulnerability. Gamaredon expands toolkit, hides behind legitimate services. Iran-linked hackers turn public warning systems into psychological weapons. Threat actors target critical infrastructure across Southeast Asia. DCloud framework behind global scam economy. Polish police disrupt SIM-swapping gang. French statistics agency reports cyberattack affecting nearly 13,000 staff. Our guest is Michael Fanning, CISO at Splunk, discussing how AI doesn’t create problems, it exposes them. And an open-book exam for hackers.]]></content:encoded>
</item>
<item>
<title><![CDATA[Autonomous security agents need complete data. Here's how to check if yours is ready.]]></title>
<description><![CDATA[An endpoint agent cannot report its own absence. The 2026 Axonius Actionability Report, conducted with the Ponemon Institute and surveying 662 IT and security professionals, put a number on a gap SOC teams have worked around for years. Across the Axonius customer base, 12.7% of devices in a 298,0...]]></description>
<link>https://tsecurity.de/de/3628252/it-nachrichten/autonomous-security-agents-need-complete-data-heres-how-to-check-if-yours-is-ready/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3628252/it-nachrichten/autonomous-security-agents-need-complete-data-heres-how-to-check-if-yours-is-ready/</guid>
<pubDate>Fri, 26 Jun 2026 20:03:15 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>An endpoint agent cannot report its own absence. The <a href="https://www.axonius.com/resources/analyst-report/the-actionability-report-axonius-ponemon-institute">2026 Axonius Actionability Report</a>, conducted with the <a href="https://www.ponemon.org/">Ponemon Institute</a> and surveying 662 IT and security professionals, put a number on a gap SOC teams have worked around for years. <a href="https://www.axonius.com/blog/rsac-2026-recap">Across the Axonius customer base</a>, 12.7% of devices in a 298,000-device median inventory are missing their expected security agent.</p><p>If a device has no agent, no management console shows it. If a CMDB record is stale, no reconciliation flags it. An employee who installed Claude Enterprise outside procurement created a SaaS workspace, identity surface, and API-token footprint that endpoint telemetry alone will not reliably inventory. The coverage percentage on the EDR dashboard is structurally incomplete because the reporting mechanism cannot see what it does not cover.</p><p>That gap matters more now than it did six months ago. SOC and XDR vendors are pushing more autonomous investigation and remediation into production. Those agents will query the same dashboards, trust the same coverage percentages, and act on the same blind spots human analysts learned to work around. A human analyst second-guesses a 98% coverage number. An autonomous agent treats it as ground truth and moves at machine speed.</p><h2>Three independent signals converged on the same gap</h2><p><a href="https://www.gravitee.io/blog/88-of-companies-have-already-seen-ai-agent-security-failures">Gravitee’s 2026 survey</a> of 900-plus executives found 88% reported confirmed or suspected AI-related incidents, and only 14.4% sent agents live with full security approval. The Axonius/Ponemon report found 52% of respondents would let autonomous agents act on recommendations — while 63% said the underlying data lacks important information. <a href="https://cloudsecurityalliance.org/blog/2026/02/02/the-agentic-trust-framework-zero-trust-governance-for-ai-agents">The CSA's Agentic Trust Framework</a> requires verified data governance before agents act on any finding.</p><p>Mike Riemer, Field CISO at <a href="https://www.ivanti.com/">Ivanti</a>, said that known vulnerabilities on Azure’s honeypot networks are now attacked in under 90 seconds. “Traditional security measures continue to work,” Riemer told VentureBeat. </p><p>The caveat is that those measures only protect what they can see. An EDR agent deployed across 87.3% of the device inventory leaves the remaining 12.7% outside that agent’s telemetry, policy enforcement, and detection logic.</p><h2>Exclusive deployment data quantifies the scale</h2><p>Joe Diamond, CEO of Axonius, told VentureBeat that the average CISO sees roughly 50% of what is actually on the network. “Say 50% of their environment is sitting in dark matter,” Diamond said. “They don’t know what it is, or where it is, or who has access to it, if it’s secure, if it’s not secure.”</p><p>Deployment data from more than 900 Axonius customers confirms those numbers. TransUnion went from 70% to 99% endpoint coverage after out-of-band verification. <a href="https://www.axonius.com/newsroom/press-release/western-union-drives-reduction-in-manual-security-workload-improve-asset-coverage-with-axonius">Western Union went from 85% to 99%</a> by consolidating data from 38 tools and cutting manual workload by half. Lumen discovered 1.1 million assets, where the CMDB showed 17,000. That translates to roughly 37,000 unmanaged endpoints per organization sitting outside every policy, every patch cycle, and every detection rule.</p><p>Diamond pointed to <a href="https://www.anthropic.com/claude/mythos">Mythos</a>, Anthropic’s frontier reasoning model, as a sign that machine-speed offensive capability will make any unknown asset far riskier than it is today. “People tend to have shiny object syndrome,” he said. “If you didn’t understand what 50% of your environment looked like from a traditional endpoint perspective, and you think you’re going to wind sprint to granular control and governance of AI, your program will fail.” Diamond called the broader AI shift “as big, if not bigger than the internet.”</p><h2>Three approaches compete to close the gap</h2><p>No single architecture solves the visibility problem today. Three approaches compete, each with named tradeoffs security teams should evaluate before procurement.</p><p><b>A dedicated integration layer </b>uses bidirectional API adapters to build an always-current inventory. Axonius runs 1,400-plus adapters and now discovers shadow Claude Enterprise installations via its Anthropic adapter (GA June 15). “We created a bidirectional API integration with all the IT systems and all the security controls to build an always up-to-date inventory of what the environment looks like,” Diamond told VentureBeat.</p><p><b>Platform-native EDR and XDR intelligence </b>builds richer asset context inside the agent footprint. Depth within the agent footprint is the advantage. The limitation is structural. Platform-native intelligence is bounded by what the agent can see, and the gap the Ponemon report identified lives precisely where that visibility ends.</p><p><b>CMDB modernization </b>requires continuous reconciliation against three or more independent telemetry sources. Only 13% of organizations reconcile daily, according to <a href="https://www.axonius.com/blog/2026-axonius-actionability-report-context">Axonius/Ponemon data</a>. The remaining 87% operate on stale records that feed incorrect prioritization into any automated remediation pipeline.</p><h2>EDR data readiness: Five gates before autonomous remediation</h2><p>Before you let autonomous SOC agents close tickets or quarantine assets, this checklist tells you whether your EDR and asset data is solid enough to trust. It is vendor-agnostic, works with any EDR and CMDB, and gives you five pass/fail gates you can run in a single working session.</p><table><tbody><tr><td><p><b>Risk Area</b></p></td><td><p><b>What the data shows</b></p></td><td><p><b>Readiness threshold</b></p></td><td><p><b>Action to take now</b></p></td></tr><tr><td><p>Asset inventory delta</p></td><td><p>Ponemon: only 45% consolidate into a single view. Forrester TEI: 150% more assets than previously identified. Lumen: 17K in CMDB vs. 1.1M discovered.</p></td><td><p><b>Delta ≤10%</b> between discovery, CMDB, and EDR agent count. Delta above 10% blocks automated remediation until reconciled.</p></td><td><p>Run API-based discovery against all segments. Diff against CMDB and EDR console count. Reconcile quarterly minimum.</p></td></tr><tr><td><p>Unmanaged AI services</p></td><td><p>Gravitee: 88% confirmed or suspected AI incidents. Only 14.4% with full security approval. Anthropic adapter (GA June 15) discovers unmanaged Claude Enterprise installations.</p></td><td><p>No high-risk AI services outside approved procurement. <b>Weekly SaaS discovery scans.</b> Unmanaged high-risk instances trigger IR triage before exception review.</p></td><td><p>Deploy SaaS discovery or protocol-level adapters for AI service detection. Automate weekly scans. Route unmanaged instances to IR queue.</p></td></tr><tr><td><p>CMDB record accuracy</p></td><td><p>Ponemon: only 13% reconcile daily (RSAC 2026). Brooks Running: 20% server discrepancy between console and independent discovery. Top remediation barriers: unclear prioritization, unclear ownership, inconsistent data.</p></td><td><p><b>≥85% of records</b> validated against 3+ independent telemetry sources. No stale or orphaned records in active remediation queue.</p></td><td><p>Cross-reference CMDB against cloud inventory, EDR telemetry, and IdP directory. Continuous reconciliation replaces annual audit cycles.</p></td></tr><tr><td><p>Endpoint agent coverage gap</p></td><td><p>Ponemon: an agent cannot report its own absence (p. 8). TransUnion: 70% to 99% after out-of-band verification. RSAC 2026: 12.7% of 298K median devices missing expected agent.</p></td><td><p><b>≥95% agent coverage</b> verified via out-of-band discovery. Many CISOs set this as the minimum before allowing autonomous remediation. No self-reported-only metrics in board reports.</p></td><td><p>Run network-based or API-driven discovery against managed device list. Coverage below 95% blocks automated remediation scoping.</p></td></tr><tr><td><p>Asset ownership mapping</p></td><td><p>Ponemon: 32% apply tags consistently. Only 51% assign ownership on new exposures (pp. 9, 16). TransUnion: 12K to 190K assets with ownership mapped.</p></td><td><p><b>Owner assigned within 24 hours.</b> Tags consistent across cloud, EDR, CMDB. Three systems showing three owners = failure.</p></td><td><p>Automate ownership via cloud tags, IdP group membership, or CMDB metadata. Map asset, remediation, and business owner as separate fields.</p></td></tr></tbody></table><h2>Five questions to ask before allowing autonomous SOC action</h2><ol><li><p>What independently verifies endpoint-agent coverage outside the EDR console?</p></li><li><p>How does the SOC reconcile conflicts between EDR, CMDB, cloud inventory, IdP, and discovery tools?</p></li><li><p>Can AI agents act on assets with unknown or disputed ownership?</p></li><li><p>Can the system distinguish “not vulnerable” from “not visible”?</p></li><li><p>What data-quality gate blocks autonomous remediation when coverage or ownership falls below threshold?</p></li></ol><h2>Board-ready risk framing</h2><p>Kayne McGladrey, IEEE Senior Member, has confirmed the pattern across multiple published VentureBeat interviews. The structural gap in self-reported coverage is not new. What is new is that autonomous agents will act on it at machine speed without the institutional workarounds human analysts developed over years of experience. Diamond put the board-level stakes plainly in an <a href="https://www.axonius.com/newsroom/press-release/axonius-delivers-ai-powered-remediation">April 2026 press statement</a>: “Findings pile up because the data isn’t trusted, ownership isn’t clear, and entire asset classes aren’t even in the picture.”</p><p>The <a href="https://cloudsecurityalliance.org/blog/2026/02/02/the-agentic-trust-framework-zero-trust-governance-for-ai-agents">CSA’s Agentic Trust Framework</a> requires that any agent promoted to a higher autonomy level must pass five gates, including demonstrated accuracy and a security audit. The EU AI Act’s Article 50 transparency obligations take effect August 2, 2026. The May 2026 Digital Omnibus pushed high-risk system obligations to December 2027, but organizations deploying agentic SOC agents on incomplete asset data face immediate operational risk that outpaces any regulatory timeline.</p><p>The board-ready sentence: Our EDR coverage reports are structurally incomplete because an endpoint agent cannot report its own absence, and we are verifying coverage through out-of-band discovery before deploying autonomous agents that would act on those reports at machine speed.</p><h2>Security director playbook</h2><ol><li><p><b>Run out-of-band asset discovery this week. </b>Compare results against your CMDB export and EDR console count. If the delta exceeds 10%, halt automated remediation scoping until the gap is reconciled.</p></li><li><p><b>Deploy SaaS discovery for AI services. </b>Employees install AI ahead of procurement, ahead of security. Weekly scans are the minimum. Route any unmanaged high-risk instance to your incident response queue for triage before exception review.</p></li><li><p><b>Map asset ownership to remediation responsibility. </b>Ponemon found only 32% of organizations apply tags consistently. If three systems show three different owners for the same asset, automated remediation has no routing target. Fix the ownership layer before deploying agents that depend on it.</p></li><li><p><b>Kill self-reported-only coverage metrics. </b>Any risk calculation or board report that relies on EDR console-reported coverage alone is built on data the reporting system cannot verify. Require out-of-band verification for every coverage number that informs a risk decision.</p></li></ol><p></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Two Clocks Are Running Out at Once, and Almost Nobody Is Watching Both]]></title>
<description><![CDATA[Every CISO I talk to right now is juggling two deadlines that feel unrelated and aren’t. One is the slow-motion arrival of quantum computers capable of breaking the public-key cryptography that underpins basically everything — TLS, SSH, JWTs, code-signing. The…
Read more →
The post Two Clocks Are...]]></description>
<link>https://tsecurity.de/de/3627888/it-security-nachrichten/two-clocks-are-running-out-at-once-and-almost-nobody-is-watching-both/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3627888/it-security-nachrichten/two-clocks-are-running-out-at-once-and-almost-nobody-is-watching-both/</guid>
<pubDate>Fri, 26 Jun 2026 17:54:10 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Every CISO I talk to right now is juggling two deadlines that feel unrelated and aren’t. One is the slow-motion arrival of quantum computers capable of breaking the public-key cryptography that underpins basically everything — TLS, SSH, JWTs, code-signing. The…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/two-clocks-are-running-out-at-once-and-almost-nobody-is-watching-both/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/two-clocks-are-running-out-at-once-and-almost-nobody-is-watching-both/">Two Clocks Are Running Out at Once, and Almost Nobody Is Watching Both</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The Growing Call for a CISO Code of Ethics]]></title>
<description><![CDATA[CISOs today are no longer measured solely by the effectiveness of an organization’s cyber defenses. With the increase of cyber threats, the acceleration of offensive capabilities with artificial intelligence, and increasing regulatory scrutiny, the role of enterprise-wide risk management, strateg...]]></description>
<link>https://tsecurity.de/de/3627485/it-security-nachrichten/the-growing-call-for-a-ciso-code-of-ethics/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3627485/it-security-nachrichten/the-growing-call-for-a-ciso-code-of-ethics/</guid>
<pubDate>Fri, 26 Jun 2026 15:07:36 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>CISOs today are no longer measured solely by the effectiveness of an organization’s cyber defenses. With the increase of cyber threats, the acceleration of offensive capabilities with artificial intelligence, and increasing regulatory scrutiny, the role of enterprise-wide risk management, strategic…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/the-growing-call-for-a-ciso-code-of-ethics/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/the-growing-call-for-a-ciso-code-of-ethics/">The Growing Call for a CISO Code of Ethics</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[What CISOs need to tell the board about zero trust in OT: A 90-day communication and action plan]]></title>
<description><![CDATA[I work as a principal specialist at a pipeline operator where Operational Technology (OT) is the backbone of the business. I do not report to the board or act as a CISO, but the issues that get raised to those levels affect my job every single day.



Since the Colonial pipeline ransomware incide...]]></description>
<link>https://tsecurity.de/de/3626998/it-security-nachrichten/what-cisos-need-to-tell-the-board-about-zero-trust-in-ot-a-90-day-communication-and-action-plan/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3626998/it-security-nachrichten/what-cisos-need-to-tell-the-board-about-zero-trust-in-ot-a-90-day-communication-and-action-plan/</guid>
<pubDate>Fri, 26 Jun 2026 12:09:07 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>I work as a principal specialist at a pipeline operator where Operational Technology (OT) is the backbone of the business. I do not report to the board or act as a CISO, but the issues that get raised to those levels affect my job every single day.</p>



<p>Since the <a href="https://www.energy.gov/ceser/colonial-pipeline-cyber-incident">Colonial pipeline ransomware incident in 2021</a>, it has become apparent that our industry has started posing different tones of “Are we zero trust yet?” I frequently witness its intense significance through auditing requests, TSA security directives and conversations around some control project’s goals.</p>



<p>One experience the zero trust role has changed is that it often feels misaligned with OT heavy environments. The NIST’s <a href="https://tsapps.nist.gov/publication/get_pdf.cfm?pub_id=930420">Zero Trust Architecture (SP 800‑207) model</a> works for all, but is originally written as though for an IT network, not terminals, compressor stations and control rooms where equipment must run 24/7, perhaps more aged than the technology present within the organization. CISA’s guidance on <a href="https://www.ic3.gov/CSA/2026/260429.pdf" target="_blank" rel="noreferrer noopener">adapting zero trust principles to operational technology</a> helps close that gap, but applying it means satisfying the OT teams and company leadership at the same time.</p>



<h2 class="wp-block-heading">The zero trust question I hear behind the scenes</h2>



<p>I am pretty sure we all know it comes as a jolt of reality after something really major has happened, rather than a bullet point on a slide deck. You have pipeline. The whole distribution stops for six days. In Washington, DC, US congressional hearings are underway, and legislation is coming. <a href="https://www.tsa.gov/sites/default/files/tsa_sd_pipeline-2021-02-july-21_2022.pdf">TSA Directive 2021-02C</a> requires pipeline operators to attest to several things, like network segmentation and zero-trust architectures.</p>



<p><a href="https://www.nerc.com/globalassets/standards/reliability-standards/cip/cip-013-2.pdf">NERC CIP-013</a> exists on a similar tack, more around supply chain security. In our case, the decision on how to select and manage a vendor partner and control their remote access is driven by regulatory compliance and governance frameworks. So, you have all those things that happen externally and force change. They say, “Are you zero trust? Yes or no?” We always get “yes.” They know it is not “yes, ” and the vendors know it is not “yes,” and nothing gets done about it until something happens.</p>



<h2 class="wp-block-heading">How I reframe zero trust for OT in my work</h2>



<p>My influence comes from how I frame problems and options in the conversations I am invited into. Zero trust is a good example.</p>



<p>NIST’s SP 800‑207 describes zero trust as a model where access decisions are to be based on strong identity, policy and context rather than network. CISA’s OT guidance narrows it, advising operators on the appearance of devices, identity management and what overlaps with IT instead of the overall replacement. <a href="https://www.csoonline.com/article/4143100/why-zero-trust-breaks-down-in-iot-and-ot-environments.html" target="_blank">Why zero trust breaks down in IoT and OT environments</a>” highlights that when facing the complications of IoT and OT environments, one needs to be proactive.</p>



<p>During these conversations, I try to focus on three major points when talking about IoT.</p>



<ol class="wp-block-list">
<li>Refer to zero trust as its functioning principle. In my experience, teams respond better when I say “Every user and system has to prove who they are and why they need access” than when I talk about abstract architectures. That language matches what NIST and CISA emphasize without overwhelming people with jargon.</li>



<li>Focus on where IT and OT converge, like jump hosts, historian connections, remote access paths and shared identity stores that span both worlds. Those are the choke points where zero trust style controls like stronger authentication, least privilege and detailed logging can give us quick wins without disrupting operations that depend on predictable behavior.</li>



<li>Tie everything that we need to do to the existing requirements. The conversation moves from “why are we changing this?” to “how do we do this well?” which aligns with TSA Security Directive Pipeline‑2021‑02C, a CISA alert or a NERC CIP‑013 requirement.</li>
</ol>



<h2 class="wp-block-heading">A 90-day plan OT leaders can execute</h2>



<p>While someone operates a gas pipeline, they cannot play around with zero trust. Questions such as: “What can we accomplish before the TSA checks up next quarter?” Or “How can we show the internal audit team we are making progress this month?” comes often. We have established a list of actions we take over in a ninety-day plan, because we find it aligns more with our industrial settings while also being transferable to other OT settings.</p>



<h3 class="wp-block-heading">Days 1–30: Map assets and identities at the IT/OT boundary</h3>



<p>The first 30 days are for increased visibility. I focus on a relatively simple question: “Who and what can currently reach OT, intentionally or accidentally?”</p>



<p>CISA’s guidance on zero trust for OT, alongside other warnings, advocates for identifying and managing assets and communications where IT and OT interfaces exist, in addition to informal remote access routes. Also, TSA requires pipeline operators to regularly update and manage plans detailing which networks, systems and access points they will assess as per their established requirements across both IT and OT.</p>



<p>In my position, it comes down to three actions. First, I work with OT engineers, network staff and asset inventory systems to determine which OT assets threaten operations, safety or compliance if compromised, rather than inventorying every device. Second, I map the users and links that reach into OT, such as internal staff granted advanced privileges, remote vendor support, VPNs and cloud platforms that interact with production data. Third, I categorize these identities and connections based on risk, impact and exposure, not by their roles.</p>



<p>By the close of the first 30 days, the intention is to present leadership with an easily comprehensible overview: outlining the critical OT assets, delineating the entry points from both internal IT systems and external sources and identifying the associated identities. Having established this common understanding makes subsequent zero trust discussions less vague.</p>



<h3 class="wp-block-heading">Days 31–60: Contain vendor remote access and create early wins</h3>



<p>Look for quick wins in the next month, in a high-impact but non-disruptive area. Vendor or third-party remote access often fulfills it, and CISA has warned about it and continues to do so.</p>



<p>Their guidance emphasizes best practices, including using MFA, segmented user privileges and monitoring third-party activity independently. The NERC CIP-013 requires utilities to consider cybersecurity threats and risk management that protect their supply chains and suppliers that connect to critical systems. The TSA’s pipeline directives expect close monitoring and controls of remote access. In my case, early wins look like telling a vendor: OK, instead of an unsecured, remote access method, use an audited brokered remote access solution. MFA for any and all remote OT sessions. Close old vendor RDP connections that are not in service. You are simply saying that times change and since these methods were put in place a few years back, they have evolved; it is reasonable for you to evolve.</p>



<h3 class="wp-block-heading">Days 61–90: Build a simple maturity scorecard and narrative</h3>



<p>The third month is about visibility and repeatable progress. We now will have more clarity on assets and identities traversing the IT/OT boundary and have choked down the most dangerous of remote access paths. Now we will take time to track where we have been over time.</p>



<p>I will consult with leaders within security and OT teams to identify the right-sized set of metrics relevant to the specific context of the organization. While the specific terminology may vary, many will align with common language found in TSA, NERC, CISA and other industry documents. Consider the broad themes of “govern, protect and detect &amp; respond”.</p>



<p>We can then identify solid “now” and “better next quarter” capabilities within each of these themes. “Govern” could incorporate specific OT policies on identity and access management that pull in zero trust directives alongside existing authoritative frameworks. “Protect” might track what fraction of your high-impact OT assets have been put behind better segmentation practices, coupled with the percent of your remote access pathways to OT identified as high-risk that have both MFA and a brokered connection. “Detect &amp; respond” could see tested playbooks in place assuming a remote connection compromise that directly injects malware into an OT system, which aligns with how recent incidents have unfolded throughout North American utilities.</p>



<p>The output is not a scorecard to pass around but will be a meaningful, honest conversation for our leaders. You will know how to accurately frame how your organization applies zero trust in the OT world today, show what you achieved over the past three months and honestly describe where there is more work ahead.</p>



<p>I am not the only one trying to make zero trust ideas actually fit OT, and I pay attention to the CISOs who voice the same frustrations with IoT and OT environments. We are solving the same problem from different seats. What I have found is that a workable 90-day plan, updated monthly, beats any pledge to “Let us achieve zero trust together”</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.csoonline.com/expert-contributor-network/">Want to join?</a></strong></p>



<p></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Gone with the command.]]></title>
<description><![CDATA[International operation disrupts Amadey and StealC malware infrastructure. Australian spy chief warns nation-state hackers are prepositioning for future sabotage. Stealthy new backdoor may be tied to initial access broker. Researchers uncover "Cordyceps" supply chain flaw. Iran-linked MuddyWater ...]]></description>
<link>https://tsecurity.de/de/3625832/it-security-nachrichten/gone-with-the-command/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3625832/it-security-nachrichten/gone-with-the-command/</guid>
<pubDate>Thu, 25 Jun 2026 22:38:45 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[International operation disrupts Amadey and StealC malware infrastructure. Australian spy chief warns nation-state hackers are prepositioning for future sabotage. Stealthy new backdoor may be tied to initial access broker. Researchers uncover "Cordyceps" supply chain flaw. Iran-linked MuddyWater disguises espionage as ransomware attack. Cal Water says Handala's hacking claims were overstated. Report says Russia continued using Cellebrite phone-cracking tools after the ban. Chinese cybersecurity firm unveils AI tools to rival Anthropic's Mythos. DraftKings hacker is sentenced to eighteen months. Our guest is Erich Kron, CISO Advisor at KnowBe4, sharing the details of the CAPY program. And more Than Meets the Eye-P.]]></content:encoded>
</item>
<item>
<title><![CDATA[양자컴퓨터 시대 대비 나선 미국…PQC 의무화와 양자 기술 육성 병행]]></title>
<description><![CDATA[도널드 트럼프 미국 대통령이 25일 연방정부의 포스트 양자암호(PQC) 전환을 가속화하고 미국의 양자 기술 투자를 확대하기 위한 두 건의 행정명령에 서명했다. 행정부는 이번 조치를 양자컴퓨팅이 가져올 기회와 위험에 동시에 대비하기 위한 범정부 차원의 종합 전략이라고 설명했다.



이번 조치는 ‘고도화된 암호 공격으로부터 국가 보호(Securing the Nation Against Advanced Cryptographic Attacks)’와 ‘양자 혁신의 새로운 시대 개척(Ushering in the Next Frontier ...]]></description>
<link>https://tsecurity.de/de/3623523/it-nachrichten/pqc/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3623523/it-nachrichten/pqc/</guid>
<pubDate>Thu, 25 Jun 2026 08:17:26 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>도널드 트럼프 미국 대통령이 25일 연방정부의 포스트 양자암호(PQC) 전환을 가속화하고 미국의 양자 기술 투자를 확대하기 위한 두 건의 행정명령에 서명했다. 행정부는 이번 조치를 양자컴퓨팅이 가져올 기회와 위험에 동시에 대비하기 위한 범정부 차원의 종합 전략이라고 설명했다.</p>



<p>이번 조치는 ‘고도화된 암호 공격으로부터 국가 보호(Securing the Nation Against Advanced Cryptographic Attacks)’와 ‘양자 혁신의 새로운 시대 개척(Ushering in the Next Frontier of Quantum Innovation)’ 등 <a href="https://www.whitehouse.gov/presidential-actions/2026/06/securing-the-nation-against-advanced-cryptographic-attacks" target="_blank" rel="nofollow">두 건의 행정명령</a>으로 구성된다. 백악관은 관련 설명자료를 통해 이번 정책이 국가안보와 경제 경쟁력, 사이버보안을 강화하기 위한 행정부의 광범위한 전략의 일환이라고 밝혔다.</p>



<p>보안 책임자에게 가장 직접적인 영향을 미치는 것은 암호 관련 행정명령이다. 해당 명령은 연방기관의 양자내성 암호 전환 시한을 제시하고, 기관별 암호 자산 전수조사를 의무화했으며, 향후 정부 계약업체에 적용될 조달 요건의 방향도 제시했다.</p>



<p>포스트 양자암호 전문 기업 키팩터(Keyfactor)의 최고정보보호책임자(CISO) <a href="https://www.linkedin.com/in/chrishickman613/" target="_blank" rel="nofollow">크리스 힉먼</a>은 CIO.com 자매지 CSO온라인과의 인터뷰에서 “매우 긍정적인 조치이며 세계 여러 국가가 추진해 온 방향과도 일치한다”라며 “이제는 실제 행동에 나설 수밖에 없는 단계”라고 평가했다.</p>



<p>힉먼은 이번 전환 일정이 연방기관을 넘어 정부 계약업체와 국가 핵심 인프라 운영기관에도 상당한 영향을 미칠 것으로 전망했다. 이들 조직이 포스트 양자암호 도입 준비를 입증해야 한다는 압박을 점점 더 크게 받게 될 것이라는 설명이다.</p>



<p>그는 “연방정부와의 거래를 유지하려는 공급업체가 많은 만큼 이제는 포스트 양자암호를 더 이상 미뤄서는 안 된다”라고 말했다.</p>



<p>미 행정부는 적대국이 현재의 공개키 암호체계를 무력화할 수 있는 양자컴퓨팅 기술의 발전에 대비해 이미 암호화된 통신과 민감한 데이터를 수집하고 있을 가능성이 있다고 보고 있다.</p>



<p>백악관은 이를 ‘선 수집 후 해독(Harvest Now, Decrypt Later, HNDL)’ 시나리오라고 설명했다. 현재 탈취한 정보를 장기간 보관했다가 충분한 성능의 양자컴퓨터가 등장하면 이를 해독할 수 있다는 의미다.</p>



<p>암호 해독이 가능한 수준의 양자컴퓨터가 언제 등장할지를 두고는 전문가들의 의견이 엇갈린다. 그러나 미국 정부는 해당 기술이 현실화될 때까지 기다렸다가 준비를 시작해서는 늦는다는 입장이다.</p>



<p>백악관은 이번 행정명령이 2025년 6월 발표한 사이버보안 행정명령과 올해 공개한 ‘미국 사이버 전략(Cyber Strategy for America)’을 잇는 정책이라고 밝혔다. 또한 이번 조치가 연방 시스템을 보호하는 데 그치지 않고, 국가 핵심 인프라와 디지털 생태계 전반에서 양자내성 보안기술 도입을 촉진하는 데 목적이 있다고 설명했다.</p>



<p>화이트하우스 예산관리국(OMB) 법률고문을 지낸 해커원(HackerOne)의 최고법률·정책책임자 <a href="https://www.cio.com/article/4188512/linkedin.com/in/ilona-cohen-3094b255" target="_blank">일로나 코언</a>은 성명을 통해 최근 행정부의 사이버보안 정책은 정부 사이버 위험에서 계약업체가 차지하는 역할에 대한 우려가 커지고 있음을 보여준다고 평가했다. 코언은 “연방 네트워크의 복원력은 이를 지원하는 계약업체의 보안 수준만큼 강하다”라고 말했다.</p>



<p>다음은 CIO Korea 기사 스타일에 맞춰 자연스럽게 다듬은 번역입니다.</p>



<h2 class="wp-block-heading">연방기관 포스트 양자암호 전환 일정 확정</h2>



<p>행정명령은 미국 국립표준기술연구소(NIST)가 마련한 포스트 양자암호(PQC) 표준으로 연방기관의 암호 체계를 신속히 전환하도록 지시했다.</p>



<p>NIST는 2024년 첫 번째 포스트 양자암호 표준을 확정했으며, 미래 양자 공격에 취약한 기존 암호체계를 대체할 추가 알고리즘도 계속 평가하고 있다.</p>



<p>행정명령에 따르면 연방기관은 2030년 12월 31일까지 키 교환(Key Establishment) 메커니즘의 전환을 완료해야 한다. 디지털 서명 시스템은 2031년 12월 31일까지 전환을 마쳐야 한다. 또한 모든 기관은 30일 이내에 포스트 양자암호 전환을 총괄할 고위 책임자를 지정해야 한다.</p>



<p>미국 예산관리국(OMB)은 90일 안에 세부 이행 지침을 마련해야 하며, 각 기관은 이에 맞춰 연방 시스템 전반에서 취약한 암호체계를 교체하기 위한 실행 계획을 수립해야 한다.</p>



<p>이번 일정은 연방정부의 포스트 양자암호 도입 시점을 가장 명확하게 제시한 정책 가운데 하나로 평가된다.</p>



<h2 class="wp-block-heading">암호 구성요소 명세서(CBOM) 도입</h2>



<p>행정명령에는 정부 시스템과 소프트웨어 공급망 전반의 암호 구성요소를 보다 체계적으로 파악하기 위한 조치도 포함됐다.</p>



<p>핵심 내용은 NIST와 사이버보안·인프라보호국(CISA)이 270일 이내에 암호 구성요소 명세서(Cryptographic Bill of Materials, CBOM)의 최소 구성요건을 마련하도록 한 것이다.</p>



<p>CBOM은 소프트웨어 구성요소 명세서(SBOM)와 유사한 개념이지만, 제품과 시스템에 포함된 암호 알고리즘과 암호 라이브러리, 관련 의존성을 식별하는 데 초점을 맞춘다.</p>



<p>보안 전문가들은 조직이 자체 환경에서 어떤 암호 기술이 어디에 사용되고 있는지 먼저 파악하지 못하면 포스트 양자암호로의 전환도 효과적으로 추진할 수 없다고 지속적으로 지적해 왔다.</p>



<p>행정부는 또한 NIST에 2027년 말까지 연방 포스트 양자암호 전환 시범 프로그램을 구축하도록 지시했다. 이를 통해 실제 구축 과정에서 발생하는 문제를 파악하고, 전환을 위한 모범 사례를 마련한다는 계획이다.</p>



<h2 class="wp-block-heading">정부 계약업체, 새로운 규정 준수 의무 직면</h2>



<p>이번 행정명령은 연방정부 계약업체에도 상당한 영향을 미칠 것으로 보인다.</p>



<p>행정명령은 연방조달규정위원회(Federal Acquisition Regulatory Council)에 2030년 말까지 해당 계약업체가 NIST의 포스트 양자암호(PQC) 표준을 준수하도록 하는 조달 기준을 마련할 것을 지시했다.</p>



<p>세부 내용은 아직 확정되지 않았지만, 연방정부의 조달 요건이 기술 업계 전반에서 포스트 양자암호 도입을 촉진하는 핵심 동력이 될 가능성이 크다.</p>



<p>연방기관과 거래하는 보안업체와 클라우드 서비스 제공업체, 소프트웨어 개발사, 관리형 서비스 제공업체(MSP)는 앞으로 새롭게 마련될 포스트 양자암호 요구사항을 충족한다는 점을 입증해야 할 가능성이 높다.</p>



<p>행정명령이 암호 자산 관리와 전환 계획, 표준 준수를 강조한 점을 고려하면 연방기관은 앞으로 공급업체에 제품에 포함된 암호 구성요소를 정확히 파악하고 문서화할 것을 요구할 것으로 예상된다.</p>



<h2 class="wp-block-heading">양자 기술 혁신 정책도 본격 추진</h2>



<p>트럼프 대통령은 사이버보안 행정명령과 함께 양자컴퓨팅과 관련 기술 개발을 가속화하기 위한 별도의 행정명령에도 서명했다.</p>



<p>행정부는 양자 기술이 장기적으로 제약과 제조, 물류, 에너지, 국방 등 다양한 산업을 혁신하는 동시에 과학 연구와 국가안보 분야에서도 전략적 우위를 제공할 것으로 기대하고 있다.</p>



<p>정책의 핵심은 ‘과학 발전을 위한 양자컴퓨팅(QC-ADDS, Quantum Computing for Accelerated Discovery and Development for Science)’ 프로그램이다. 행정부는 이 사업을 통해 ‘양자 기반 과학적 발견(Quantum-enabled Scientific Discovery)’을 가능하게 하는 양자컴퓨터를 최소 한 대 이상 개발한다는 목표를 제시했다.</p>



<p>에너지부와 상무부, 국방부, 미국국립과학재단(NSF), 미국 항공우주국(NASA), 국가안보국(NSA), 정보기관 등은 이 프로그램 아래에서 연구개발을 공동 추진하게 된다.</p>



<p>각 기관은 90일 안에 기술 요구사항을 마련하고, 180일 안에 구체적인 실행계획을 제출해야 한다.</p>



<p>업계에서는 이번 행정명령이 양자컴퓨팅 주도권 확보를 위해 기술 스택 전반에 걸친 전략적 투자가 필요하다는 인식이 확산되고 있음을 보여준다고 평가했다.</p>



<p>AI·양자 기술 기업 샌드박스AQ(SandboxAQ)의 엔지니어링 부사장 <a href="https://www.linkedin.com/in/stefanleichenauer/" target="_blank" rel="nofollow">스테판 라이헤나우어</a>는 성명을 통해 “미국에는 이 분야를 선도할 기회가 남아 있다”라며 “암호기술과 컴퓨팅 인프라, 데이터 생성, 애플리케이션 개발 등 기술 스택 전반에 대한 체계적인 투자가 필요하다. 또한 정부와 산업계, 학계 간 긴밀한 협력도 필수적”이라고 말했다.</p>



<p>행정명령에는 양자 네트워킹과 양자 센싱 기술에 대한 지원 확대와 함께 양자컴퓨팅 시스템의 성능을 평가하고 벤치마킹할 수 있는 국가 차원의 역량을 구축하는 내용도 담겼다.</p>



<h2 class="wp-block-heading">상용화·인재 양성도 핵심 과제</h2>



<p>이번 양자 기술 육성 정책은 연구 성과를 실제 산업 현장으로 이전하는 데도 초점을 맞추고 있다.</p>



<p>백악관은 미국이 자국 내 양자 공급망을 강화하고 기술 이전을 지원하는 한편, 정부 지원 연구성과가 상용 제품과 경제 성장으로 이어질 수 있도록 해야 한다고 밝혔다.</p>



<p>TDK벤처스(TDK Ventures)의 투자 책임자 <a href="https://www.linkedin.com/in/saxenaankur/" target="_blank" rel="nofollow">안쿠르 삭세나</a>는 “양자 기술은 이제 순수 과학의 영역을 넘어 엔지니어링과 산업 경쟁의 단계로 접어들고 있다”라며 “미국의 경쟁력은 혁신적인 하드웨어뿐 아니라 안정적인 공급망과 양자 기술의 대규모 상용화를 가능하게 하는 기반 인프라 구축에 달려 있다”라고 말했다.</p>



<p>행정부는 국가양자이니셔티브 자문위원회를 재구성하고, 양자 방첩 보호팀(Quantum Counterintelligence Protection Team)의 활동도 확대해 민감한 연구성과와 지식재산을 보호할 계획이다.</p>



<p>또한 양자 분야 교육과 자격 인증, 견습 프로그램을 지원하고 국가 양자정보과학·기술 인력개발 연구소도 설립할 예정이다.</p>



<h2 class="wp-block-heading">양자 기술 전략의 두 축</h2>



<p>이번 두 건의 행정명령은 양자 기술 개발을 가속화하는 동시에, 장기적으로 발생할 보안 위험에도 선제적으로 대응하겠다는 미국 정부의 전략을 보여준다.</p>



<p>사이버보안 분야에서는 포스트 양자암호 관련 조치가 가장 큰 영향을 미칠 것으로 예상된다. 연방기관은 전환 일정과 암호 자산 관리, 시범사업, 향후 조달 규정 등을 통해 포스트 양자암호를 검토하는 단계를 넘어 실제 구축 단계로 전환하고 있음을 시사한다.</p>



<p>기술 업계 전반에도 양자컴퓨팅이 더 이상 장기 연구 과제가 아니라 투자와 거버넌스, 위험 관리가 동시에 요구되는 국가 전략 기술이라는 공감대가 미국 정책 당국을 중심으로 빠르게 형성되고 있음을 보여주는 조치로 평가된다.<br>dl-ciokorea@foundryco.com</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Your Biggest Identity Problem Isn’t Your Employees Anymore; It’s Everything Else]]></title>
<description><![CDATA[I used to open identity audits by asking a CISO how many users were on their network. These days, I ask a different question first: how many non-human identities do you have, and when was the last time anyone counted?…
Read more →
The post Your Biggest Identity Problem Isn’t Your Employees Anymor...]]></description>
<link>https://tsecurity.de/de/3622742/it-security-nachrichten/your-biggest-identity-problem-isnt-your-employees-anymore-its-everything-else/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3622742/it-security-nachrichten/your-biggest-identity-problem-isnt-your-employees-anymore-its-everything-else/</guid>
<pubDate>Wed, 24 Jun 2026 22:24:12 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>I used to open identity audits by asking a CISO how many users were on their network. These days, I ask a different question first: how many non-human identities do you have, and when was the last time anyone counted?…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/your-biggest-identity-problem-isnt-your-employees-anymore-its-everything-else/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/your-biggest-identity-problem-isnt-your-employees-anymore-its-everything-else/">Your Biggest Identity Problem Isn’t Your Employees Anymore; It’s Everything Else</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Qualcomm’s $3.9 billion purchase of Modular aims to change the data center dynamic]]></title>
<description><![CDATA[Qualcomm on Wednesday said that it will spend $3.9 billion to purchase AI-native software platform developer Modular Inc., a move that Qualcomm says will allow it to level the playing field on data centers by creating “a silicon-agnostic compute layer.”



The stock-based acquisition “further ena...]]></description>
<link>https://tsecurity.de/de/3622741/it-security-nachrichten/qualcomms-39-billion-purchase-of-modular-aims-to-change-the-data-center-dynamic/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3622741/it-security-nachrichten/qualcomms-39-billion-purchase-of-modular-aims-to-change-the-data-center-dynamic/</guid>
<pubDate>Wed, 24 Jun 2026 22:24:10 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Qualcomm on Wednesday said that it will spend $3.9 billion to purchase AI-native software platform developer Modular Inc., a move that Qualcomm says will allow it to level the playing field on data centers by creating “a silicon-agnostic compute layer.”</p>



<p>The <a href="https://d18rn0p25nwr6d.cloudfront.net/CIK-0000804328/70441e71-4fcb-4cdd-8874-f571622bd264.pdf" target="_blank" rel="noreferrer noopener">stock-based acquisition</a> “further enables Qualcomm Technologies to deliver a silicon-agnostic compute layer across devices, edge, and data centers, improving performance-per-watt, increasing hardware flexibility, and expanding an open developer ecosystem so customers can deploy AI more efficiently across heterogeneous platforms globally,” the company said <a href="https://investor.qualcomm.com/news-events/press-releases/news-details/2026/Qualcomm-to-Acquire-Modular/default.aspx" target="_blank" rel="noreferrer noopener">in a statement</a>. </p>



<p>Qualcomm’s position is that enterprises need far more flexibility in their data center strategies, especially given how fluid the AI space is today. When CIOs need to make bets on data centers without knowing what the field will look like in two years, it can be challenging.</p>



<p><a href="https://www.linkedin.com/in/chris-lattner-5664498a/" target="_blank" rel="noreferrer noopener">Chris Lattner</a>, CEO of Modular, posted on LinkedIn that this leveling of the data center playing field was one of the company’s key early goals.</p>



<p>“In a world with a tremendous amount of innovative heterogenous AI hardware, there has always been a gap: existing fragmented software technologies weren’t built to scale effectively across this hardware. This gap holds back innovation and choice and makes development painful,” Lattner <a href="https://www.linkedin.com/posts/chris-lattner-5664498a_im-excited-to-share-that-qualcomm-is-acquiring-share-7475540410514288640-LvCv/" target="_blank" rel="noreferrer noopener">wrote in his LinkedIn post</a>.</p>



<p>“Modular was founded 4.5 years ago to solve this problem,” he wrote. “We’ve already integrated support for several hyperscale datacenter silicon providers, but we’re not stopping with what’s publicly announced. We’ve built an open platform and are continuing to open it further.”</p>



<p>Lattner added that the Qualcomm acquisition “will accelerate our progress and path” by “spanning edge to cloud, CPU, GPU, NPU, and custom ASICs and perhaps more.”</p>



<h2 class="wp-block-heading">Addresses a pain point</h2>



<p>Analysts, although skeptical of the probability of success in taking meaningful market share away from Nvidia, said that Qualcomm has focused on a true sore point for enterprises struggling with data center approaches. </p>



<p><a href="https://moorinsightsstrategy.com/team/matt-kimball/" target="_blank" rel="noreferrer noopener">Matt Kimball</a>, VP and principal analyst with Moor Insights &amp; Strategy, said, “the argument that Modular can make datacenters cost-effective is directionally correct. As enterprise AI actually hits velocity, heterogeneity is almost an understatement. Different accelerators are required for different use cases across different deployment scenarios.”</p>



<p>To date, it’s been a challenge for organizations to manage AI in this environment, he noted. “And when enterprise AI takes off, this challenge will be fully exposed.”</p>



<p>Kimball said that Modular “can be extremely valuable in achieving two things that will vex most organizations: abstracting complexity and delivering significantly more flexibility. And this would certainly lead to TCO advantages. I think the per-watt performance claim can be challenging to validate across every and any deployment scenario, but I understand the spirit behind it.”</p>



<p><a href="https://www.linkedin.com/in/yurigoryunov/" target="_blank" rel="noreferrer noopener">Yuri Goryunov</a>, CIO of consulting firm Acceligence, also applauded the Qualcomm move, but he stressed that the deal’s value is not in the technology as much as in the talent.</p>



<p>“The key is what Qualcomm actually bought: not silicon, but the software layer, meaning Chris Lattner’s team plus Mojo and the MAX engine. That’s the right place to apply pressure. Nvidia’s real moat has never been the GPUs,” he said. “It’s CUDA and the rewrite cost that keeps workloads pinned to their hardware. A credible ‘write once, run across CPU/GPU/NPU/ASIC without rewrites’ layer is exactly what lowers the switching cost and makes non-Nvidia silicon a safer bet.”</p>



<p>But Goryunov said that the data center “democratization” argument also is powerful.</p>



<p>“Anything that pushes toward democratization of compute and better routing of tasks to best-fit capacity adds real flexibility to the ecosystem,” he noted. “If workloads can be matched to the right compute instead of defaulting to one vendor, everyone gets more efficiency on performance-per-watt and TCO and customers get real choice. That’s the part of this I find most compelling.”</p>



<h2 class="wp-block-heading">Still some obstacles</h2>



<p>That said, none of this will be easy, he pointed out.</p>



<p>“Does it change the competitive position versus Nvidia? Directionally, yes. It opens a credible second front at the exact point where Nvidia is stickiest. I’d stop short of saying it shifts the balance overnight. CUDA’s moat is a decade deep and this is a multi-year execution play,” Goryunov said. “But the attack is aimed at the right wall and the team they bought is about as serious as it gets for this fight.”</p>



<p>But he stressed that much of Qualcomm’s strategy with this acquisition relies on an uncertain assumption: That Nvidia won’t counterattack by opening its architectures to various others. Or, at the very least, that Nvidia won’t do so quickly enough.</p>



<p>“That’s the barrier to entry, which is that Nvidia will focus on their stickiness,” Goryunov said.</p>



<p>Kimball added that, from a competitive perspective, Qualcomm has various obstacles to overcome. “Part of this acquisition goes directly to the Nvidia challenge” of finding a way to “make it easier for customers to deploy heterogeneous silicon without software getting in the way.”</p>



<p><a href="https://www.infotech.com/profiles/john-annand" target="_blank" rel="noreferrer noopener">John Annand</a>, senior technical counselor at Info-Tech Research Group, is more skeptical of Qualcomm’s ability to do serious damage to Nvidia.</p>



<p>“Nvidia has something like 85% of the AI accelerator chip market,” he pointed out. “Sure, they have nowhere to go but down, but that’s still going to take them a while. More importantly, they have literally spent decades working with practitioners in AI and ML and compute-intensive fields, indoctrinating them into their CUDA software ecosystem. Rewriting that tool chain will take institutional change at most organizations, which means years, if not decades, to uncouple.”</p>



<p>“Organizations that think they’ve achieved agnosticism because they’re using high-level abstractions like PyTorch, well,  they have come closest,” he observed. “But just cutting and pasting the same code into AMD Instinct can lead to memory and dependency errors. It’s like VM lift and shifts to the public cloud 10 years ago. Easier, but still possible to screw up.”</p>



<p>Nonetheless, Annand said that the deal, if it goes through, is still good news for enterprises. </p>



<p>“What it means for enterprise IT is that the vendors we currently rely on to deliver AI have another potential building block. Because enterprise IT accesses AI via an API call, it’s operationally irrelevant to us if Claude runs on Nvidia, AMD ROCm, or Modular,” he said. </p>



<p>“Now, because of the commercial and stock agreements, OpenAI and Anthropic aren’t going to jump ship anytime soon. But if your enterprise is looking for more boutique offerings, like those from Cohere, or is looking to build its own models and tools from scratch, this is an exciting announcement.”</p>



<h2 class="wp-block-heading">Goal: build once, run anywhere</h2>



<p><a href="https://www.infotech.com/profiles/shashi-bellamkonda" target="_blank" rel="noreferrer noopener">Shashi Bellamkonda</a>, principal research director at Info-Tech Research Group, looks at the potential acquisition, while it will potentially deliver benefits, as suffering from many practical roadblocks.  </p>



<p>“Qualcomm is chasing what you might call model democracy,” he said, noting that today, AI deployment teams are locked to whatever accelerator they trained on, and moving a model to different hardware means re-engineering, not just configuration changes.</p>



<p>“Modular’s pitch is that this goes away: build once, run across CPU, GPU, NPU, whatever the infrastructure calls for,” Bellamkonda said. “That’s a credible goal. The catch is that democracy and portability aren’t the same thing. Qualcomm will tune hardest for Qualcomm silicon. Every hardware company does. Vendor-neutral software foundations have a habit of developing hardware preferences once their acquirers need to differentiate silicon.”</p>



<p><a href="https://www.linkedin.com/in/fvillanustre/" target="_blank" rel="noreferrer noopener">Flavio Villanustre</a>, CISO for the LexisNexis Risk Solutions Group, provided a different perspective. </p>



<p>“I think it’s important to clarify that Modular is behind the Mojo programming language, which provides an abstraction layer for AI models, enabling them to run across different hardware architectures,” he said. “In the traditional approach, if you code an AI stack on Python or C and target a particular hardware architecture, such as X86, Nvidia GPU, AMD GPU, or TPU, you will need to rewrite a significant portion of that to run it on a different architecture. With Mojo, you code it once and it runs everywhere, even on hybrid systems composed of different hardware architectures.”</p>



<p>And, he said, “if you now consider the fact that Qualcomm owns intellectual property and manufacturing across different hardware architectures, both CPU and GPU, this acquisition could offer their customers significant lift. I see this as Qualcomm buying abstraction that allows them to provide diverse hardware offerings and still offer their customers full code reuse across their entire CPU/GPU/TPU/NPU portfolio.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Do CISOs Need a Code of Ethics?]]></title>
<description><![CDATA[Kickbacks, no-show jobs, "dirty" VCs, and shelf ware — industry expert Robert "RSnake" Hansen explains why he thinks its time for a CISO code of ethics to ensure cybersecurity bosses aren't engaged in self-dealing that could risk enterprise, and even national, security.]]></description>
<link>https://tsecurity.de/de/3622703/it-security-nachrichten/do-cisos-need-a-code-of-ethics/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3622703/it-security-nachrichten/do-cisos-need-a-code-of-ethics/</guid>
<pubDate>Wed, 24 Jun 2026 22:08:02 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Kickbacks, no-show jobs, "dirty" VCs, and shelf ware — industry expert Robert "RSnake" Hansen explains why he thinks its time for a CISO code of ethics to ensure cybersecurity bosses aren't engaged in self-dealing that could risk enterprise, and even national, security.]]></content:encoded>
</item>
<item>
<title><![CDATA[Kahneman, ‘Where’s Waldo’ and the Nexus pass: A CISO’s mental model for the AI era]]></title>
<description><![CDATA[Security awareness training as a defense against phishing is dead. It has been dead for a while. The industry never held a funeral because the training budget is comfortable, the compliance box gets checked and no CISO wants to tell the board that the program everyone funds does not work.



The ...]]></description>
<link>https://tsecurity.de/de/3620738/it-security-nachrichten/kahneman-wheres-waldo-and-the-nexus-pass-a-cisos-mental-model-for-the-ai-era/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3620738/it-security-nachrichten/kahneman-wheres-waldo-and-the-nexus-pass-a-cisos-mental-model-for-the-ai-era/</guid>
<pubDate>Wed, 24 Jun 2026 11:08:17 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Security awareness training as a defense against phishing is dead. It has been dead for a while. The industry never held a funeral because the training budget is comfortable, the compliance box gets checked and no CISO wants to tell the board that the program everyone funds does not work.</p>



<p>The premise was simple. With enough education, users would learn to spot the tells. Misspelled words. Awkward phrasing. Sender domains that looked almost right. URLs that revealed something suspicious on hover. We trained a generation of employees to play Where’s Waldo with their inbox, scanning for the one visible artifact that would mark a message as malicious.</p>



<p>Those artifacts are gone. AI-generated attacks are fluent. The infrastructure behind them looks legitimate. The surface signals we trained users to rely on no longer exist. Even if they did, the model would still depend on something humans cannot deliver. Sustained vigilance across hundreds of messages a day, every day, with one lapse leading to compromise. No human attention system works that way.</p>



<p>If user attention is not the answer, what is?</p>



<h2 class="wp-block-heading">Kahneman applied to organizations, not individuals</h2>



<p>Most discussions of phishing lean on author Daniel Kahneman’s <a href="https://en.wikipedia.org/wiki/Thinking,_Fast_and_Slow">System 1 and System 2</a>. Fast thinking is automatic and easy to fool. Slow thinking is deliberate and more accurate. The conclusion is always the same. Train people to slow down.</p>



<p>The framing is true about cognition and incomplete as a security strategy. It asks individuals to sustain behavior that breaks under real conditions.</p>



<p>The more useful application is at the organizational level.</p>



<p>Every company has processes that run fast and processes that run slow. The difference is not accidental. Fast processes are the ones where trust has already been granted and friction has been removed. Wire transfers between known parties. Vendor banking updates. Calendar invites accepted without inspection. Help desk verification over the phone.</p>



<p>Slow processes are the opposite. Trust is being established in real time. Employee logins with conditional access. New vendor onboarding. Any interaction with someone outside the organization.</p>



<p>Most companies did not design this split deliberately. It emerged over time. Someone removed friction because it helped the business move faster. Often, that decision made sense at the time. The threat landscape that justified it no longer exists.</p>



<p>Attackers understand this better than we do. They map where the fast paths are. They wait for moments where scrutiny is minimal. Then they step directly into those lanes.</p>



<h2 class="wp-block-heading">The Nexus pass as a security primitive</h2>



<p>Border control solved a problem that security still struggles with. Uniform scrutiny does not work. Check everyone the same way and movement stops. Check no one and the border disappears.</p>



<p>The solution was risk tiering. Pre-vetted travelers earn a fast lane based on evidence. Everyone else goes through full inspection. The trust is continuously verified and can be revoked the moment new information appears.</p>



<p>The fast lane is not a flaw. The full check is not overkill. Both exist because the system asks the right question. Not whether to trust or verify, but which interactions deserve speed and what evidence supports that decision.</p>



<p>Apply that lens to an enterprise and the gaps become obvious.</p>



<p>Which processes are running on a fast lane that no longer make sense? A vendor whose banking details change over email. A supplier using a typosquatted domain that slips through. A calendar invite from a name that looks familiar enough. An API credential tied to a vendor that has not been active in years.</p>



<p>Each of these is a fast path. Each one has been exploited at scale by attackers who know the assignment was never revisited.</p>



<p>The answer is not to slow everything down. That is the same mistake as awareness training, just applied to processes instead of people. It would destroy productivity and still fail to stop attacks.</p>



<p>The real work is targeted. Identify which fast paths were built on outdated assumptions. Re-tier those. Pull the fast lane from the processes that no longer deserve it. Leave it where it still holds.</p>



<h2 class="wp-block-heading">The trust inversion no one wants to admit</h2>



<p>This leads to a harder question about architecture.</p>



<p>Over the last decade, we applied zero trust to employees and standing trust to suppliers. Employees authenticate constantly. They deal with device checks, session limits and conditional access. Suppliers send a SOC 2 report once and receive long-lived access to critical systems.</p>



<p>That asymmetry deserves scrutiny.</p>



<p>Suppliers are often the path of least resistance for attackers. They hold legitimate credentials. They have access across systems. Many major breaches over the past five years started with a compromised vendor account that was already trusted.</p>



<p>SOC 2 does not solve this. It measures internal control discipline. It answers whether a company follows its processes. It does not tell you whether that company is secure right now.</p>



<p>Yet many organizations treat it as if it does. They make high-stakes access decisions based on a document that was never designed to answer that question.</p>



<p>Compliance automation has made this worse. It turned an annual exercise into a continuous one without changing what is being measured. The bar stayed the same. We just got faster at producing evidence that it was met.</p>



<p>A clean report next to a vendor with an old, compromised credential still active in production is not an edge case. It is a common state.</p>



<h2 class="wp-block-heading">What deliberate design actually looks like</h2>



<p>The work ahead is not glamorous. It will not show up neatly on a dashboard.</p>



<p>Start by mapping processes across the organization. Identify which ones run fast and which run slow. For every fast path, ask three questions.</p>



<p>What evidence originally justified the speed? Does that evidence still hold given current attacker capability? If you remove the fast lane, is the cost lower or higher than the expected impact of a breach tied to that process?</p>



<p>When the evidence no longer holds and the cost of change is lower than the potential loss, the assignment needs to change.</p>



<p>That change will have a cost. Vendor updates that took seconds may take minutes. Help desk interactions may require secondary verification. Onboarding new suppliers may slow down.</p>



<p>The case for accepting that cost is not that caution is good in theory. It is that the original speed was based on assumptions that no longer apply. The efficiency was borrowed from a future failure.</p>



<p>If you cannot explain why a process still deserves a fast lane, you are not making a business decision. You are accepting risk without acknowledging it.</p>



<p>This is what it means to design deliberately. Not forcing everyone to slow down, but making conscious decisions about where speed belongs and where scrutiny is required. Revisiting those decisions as conditions change. Removing fast lane status, the moment it is no longer justified.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.csoonline.com/expert-contributor-network/">Want to join?</a></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Forward Deployed Engineers vom KI-Anbieter – lohnt sich das?]]></title>
<description><![CDATA[loading="lazy" width="400px">KI-Anbieter schicken auf Wunsch eigene Teams zu ihren Kunden, um bei der KI-Implementierung zu unterstützen. Fragt sich nur, ob das Ihre beste Option ist.ESB Professional | shutterstock.com



Wenn es um den Einsatz von KI geht, befinden sich IT-Führungskräfte oft in ...]]></description>
<link>https://tsecurity.de/de/3620165/it-security-nachrichten/forward-deployed-engineers-vom-ki-anbieter-lohnt-sich-das/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3620165/it-security-nachrichten/forward-deployed-engineers-vom-ki-anbieter-lohnt-sich-das/</guid>
<pubDate>Wed, 24 Jun 2026 06:08:12 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full is-resized"> loading="lazy" width="400px"&gt;<figcaption class="wp-element-caption">KI-Anbieter schicken auf Wunsch eigene Teams zu ihren Kunden, um bei der KI-Implementierung zu unterstützen. Fragt sich nur, ob das Ihre beste Option ist.</figcaption></figure><p class="imageCredit">ESB Professional | shutterstock.com</p></div>



<p>Wenn es um den Einsatz von KI geht, befinden sich IT-Führungskräfte oft in einer schwierigen Zwickmühle: Sie versuchen, widersprüchliche Vorgaben des Managements mit sich ständig verändernden KI-Modellen, Funktionen und Kosten, Anforderungen an die Datenverwaltung und -sicherheit sowie <a href="https://www.computerwoche.de/article/4053917/ki-schulungen-fur-mehr-gehalt-oder-einen-neuen-job.html" target="_blank">den Grenzen ihres eigenen Teams</a> in Einklang zu bringen. Gartner-Analyst <a href="https://www.gartner.com/en/experts/nader-henein" target="_blank" rel="noreferrer noopener">Nader Henein</a> schreibt das in Teilen auch den Anbietern zu: „Es lassen sich nur sehr wenige echte Vorteile erzielen, wenn man einfach ein KI-Produkt kauft und es den Mitarbeitern zur Verfügung stellt. Die KI-Anbieter haben diesen Irrglauben in den letzten drei Jahren allerdings übermäßig angepriesen und gefördert.“</p>



<p>In der Realität, so der Analyst weiter, seien ein hoher <a href="https://www.computerwoche.de/article/4184063/ki-betreuung-stiehlt-mitarbeitern-mehr-als-6-stunden-pro-woche.html" target="_blank">KI-Nutzwert</a> und ein konsistenter <a href="https://www.computerwoche.de/article/4046876/5-wege-den-ki-roi-zu-maximieren.html" target="_blank">ROI</a> fast immer das Ergebnis einer tiefgreifenden und gezielten Integration von KI-Fähigkeiten in bestehende Workflows. Dafür benötige man spezialisierte Teams, weiß Henein: „Diese sind alles andere als günstig und werden von Unternehmen auf vielfältige Art und Weise rekrutiert.“</p>



<p>Zu diesen Support-Optionen für KI-Implementierungen gehören:</p>



<ul class="wp-block-list">
<li>traditionelle IT-Beratungsunternehmen,</li>



<li>KI-spezifische Beratungsunternehmen,</li>



<li>unabhängige Auftragnehmer,</li>



<li>eine „Acquihiring“-Strategie, oder auch</li>



<li>Open-Source-Lösungen.</li>
</ul>



<p>Die Option, die in letzter Zeit die größte Aufmerksamkeit gezogen hat, ist allerdings der Einsatz von <strong>Forward Deployed Engineers</strong> (FDEs). Diese Expertenteams von KI-Anbietern unterstützen die Kunden vor Ort dabei, die Technologie in ihre Umgebung zu integrieren.</p>



<p>Für diesen Artikel haben wir mit Experten nicht nur diskutiert, welche Vor- und Nachteile es hat, auf die FDE-Teams von KI-Anbietern zu setzen. Sondern auch das Pro und Kontra der Alternativoptionen. Eine übersichtliche Tabelle, die sämtliche Ansätze samt ihrer Vor- und Nachteile abbildet, finden Sie am Ende dieses Beitrags.</p>



<h2 class="wp-block-heading">KI-FDEs – die Vor- und Nachteile</h2>



<p>Von KI-Anbietern beschäftigte FDE-Teams verfügen über entscheidende Stärken. Dazu gehören etwa:</p>



<ul class="wp-block-list">
<li>ein besseres Verständnis der zugrundeliegenden Modelle,</li>



<li>Erfahrung bei der Integration dieser Modelle in verschiedene Arten von Enterprise-Umgebungen, sowie</li>



<li>Kenntnisse über geplante neue Funktionen, noch bevor diese offiziell angekündigt werden.</li>
</ul>



<p>Auf der anderen Seite steht allerdings der offensichtliche Nachteil der <strong>Anbieterabhängigkeit</strong>: Selbst wenn zukünftige Rollouts nicht zu den vertraglich vereinbarten Leistungen gehören, könnten die FDE-Teams eines KI-Anbieters subtilen Einfluss auf die zukünftigen KI-Initiativen ihrer Kunden nehmen. Auch deshalb mahnt <a href="https://www.linkedin.com/in/fvillanustre/" target="_blank" rel="noreferrer noopener">Flavio Villanustre</a>, CISO bei LexisNexis Risk Solutions, IT-Führungskräfte zur Vorsicht: „FDEs sind – auch aufgrund finanzieller Anreize ihrer Arbeitgeber – darauf ausgerichtet, die KI-Nutzung des Kunden zu steigern und in Sachen Services ‚Stickiness‘ zu erzeugen. Auch wenn diese Teams einen sinnvollen Mehrwert bieten, ist es Anwendern zu empfehlen, stets auch unvoreingenommene Experten zu konsultieren, die konkurrierende Lösungen verschiedener Anbieter unbefangen bewerten können.“</p>



<p>Das sei laut Villanustre besonders wichtig in einer Zeit, in der die von Investoren subventionierten Geschäftsmodelle rund um <a href="https://www.computerwoche.de/article/4182846/ki-token-erklart.html" target="_blank">KI-Token</a> erste Risse zeigten: „Angesichts des derzeitigen rasanten Innovationstempos könnte es erhebliche Wettbewerbsvorteile schaffen, flexibel genug zu sein, um den Anbieter zu wechseln.“</p>



<p>Auch <a href="https://greyhoundresearch.com/svg/" target="_blank" rel="noreferrer noopener">Sanchit Vir Gogia</a>, Chefanalyst bei Greyhound Research, sieht den Einsatz eines FDE-Teams vom KI-Anbieter als zweischneidiges Schwert: „FDEs sind zwar in die Umgebung des Kunden eingebettet, vertreten aber eben auch die kommerziellen Interessen ihres Arbeitgebers. Den Experten von KI-Anbietern übermäßigen Einfluss auf Implementierungsentscheidungen einzuräumen, könnte nicht nur zu einer erhöhten Abhängigkeit, sondern auch zu hohen Preise führen, gegen die man sich dann unter Umständen nicht wirksam wehren kann.“</p>



<p>Neben der möglicherweise steigenden <a href="https://www.computerwoche.de/article/4176264/der-neue-ki-lock-in.html" target="_blank">Anbieterabhängigkeit</a> gibt es weitere Aspekte, die IT-Entscheider berücksichtigen sollten, bevor sie die Teams ihres KI-Anbieters engagieren. Zentral ist etwa die Frage, wie lange die FDE-Teams überhaupt benötigt werden. Schließlich wird es mit einer einzelnen Implementierung kaum getan sein. Die sich daraus ergebenden <strong>langfristigen Kosten</strong> sind laut <a href="http://www.linkedin.com/in/sangyeob/" target="_blank" rel="noreferrer noopener">John Sangyeob Kim</a>, KI-Engineer bei Solidroad, etwas, das Unternehmen häufig übersehen: „Die Bereitstellung selbst macht vielleicht 20 Prozent der Gesamtkosten aus. Die übrigen 80 Prozent entfallen darauf, den Systembetrieb durch Modell-Upgrades aufrechtzuerhalten, sowie Datenverschiebungen und Randfälle zu händeln, die erst nach Monaten im Produktivbetrieb auftreten.“</p>



<p>Dazu kommen Risiken, die entstehen, wenn das FDE-Team des KI-Anbieters nicht mehr vor Ort ist. Dabei werde beispielsweise in gravierendem Maße unterschätzt, <strong>wie umfassend die Einblicke sind</strong>, die externe Spezialisten bei der KI-Implementierung gewinnen, meint etwa <a href="https://acceligence.com/talent/profiles/justin-greis/" target="_blank" rel="noreferrer noopener">Justin Greis</a>, CEO der IT-Beratung Acceligence: „Das FDE-Team erhält im Rahmen der Implementierung Insights zu einer Vielzahl operativer Details. Zwar sind die Daten, auf die dabei zugegriffen wird, durch NDAs und Geheimhaltungsklauseln geschützt – die eingesehenen Prozesse und Workflows bleiben jedoch oft außen vor.“</p>



<p>Dieses Problem ist laut Greis aber nicht auf FDE-Teams von KI-Anbietern beschränkt. Wer auch immer bei der Einführung von KI unterstütze, werde deutlich mehr Erkenntnisse gewinnen, als im Statement of Work festgehalten, erklärt der Manager: „Dazu zählen etwa die tatsächlichen, konkreten Arbeitsabläufe, undokumentierte Ausnahmen, Lücken in der Datenqualität, Genehmigungs-Bottlenecks oder <a href="https://www.computerwoche.de/article/4172297/warum-shadow-ai-trotz-governance-weiter-wachst.html" target="_blank">Security-Workarounds</a>. Dieses Wissen ist ebenso wertvoll wie sensibel.“</p>



<p>Eine weitere kritische Frage, die laut Greis zu selten gestellt werde: Wie viel <strong>sinnvolle Kontrolle wird die IT</strong> über das Projekt haben, wenn das FDE-Team seine Unterstützung beendet? „Die Gefahr besteht nicht darin, externe Hilfe in Anspruch zu nehmen – die werden die meisten Unternehmen benötigen. Kritisch wird es vor allem dann, wenn externe Hilfe so eingesetzt wird, dass das Unternehmen nach Beendigung des Auftrags weniger leistungsfähig und abhängiger ist“, konstatiert der CEO.</p>



<p>KI-Experte Kim teilt diese Bedenken und empfiehlt Anwendern insbesondere, zu klären, ob das Projekt auf <strong>dem eigenen Observability-Stack oder dem des Anbieters</strong> aufbaue: „Wenn der Implementierungspartner den eigenen Observability-Stack nutzt, ist das während des Builds in Ordnung. Aber Sie brauchen einen Plan, um diesen auf eine eigene Lösung zu migrieren, bevor der Anbieter das Projekt beendet. Anderenfalls wird die Visibility mit ihm verschwinden.“</p>



<p>Ein eklatantes Problem entstehe laut Kim hingegen, wenn weder der eigene Observability-Stack, noch der des Anbieters verwendet wird: „Das führt zu einem System ganz ohne <a href="https://www.computerwoche.de/article/4150608/wie-ki-agenten-observable-werden.html" target="_blank">Observability-Layer</a> – also ohne Einsichtsmöglichkeit. Wenn in der Produktion etwas ausfällt, haben Sie keine Möglichkeit festzustellen, ob es sich um eine Modellregression, ein Datenproblem oder einen Codefehler handelt.“</p>



<h2 class="wp-block-heading">Externer KI-Support – die Alternativen</h2>



<p>Zwar sind FDE-Teams kein neuartiger Ansatz, dennoch steht nur eine begrenzte Zahl solcher Engineers zur Verfügung. Nicht jedes Unternehmen hat also die Möglichkeit, Spezialisten-Teams von Anbietern einzusetzen. Schwierig wird es mit der FDE-Verfügbarkeit laut Gartner-Analyst Henein insbesondere außerhalb der USA. Das muss jedoch kein Grund sein, auf externen Support in Sachen <a href="https://www.computerwoche.de/article/4173117/die-haufigsten-ki-fails-im-mittelstand.html" target="_blank">KI-Implementierung</a> zu verzichten. Schließlich steht Anwendern dazu, wie eingangs dargelegt, eine breite Palette weiterer Optionen zur Verfügung. Diese haben jedoch – ähnlich wie der FDE-Einsatz – nicht nur Vor-, sondern auch Nachteile.</p>



<p>So auch die <strong>traditionelle IT-Beratung</strong>, wie <a href="https://www.linkedin.com/in/ishraqkhann/" target="_blank" rel="noreferrer noopener">Ishraq Khan</a>, CEO beim Dev-Tool-Anbieter Kodezi, erklärt: „Klassische Beratungsunternehmen sind in der Regel stärker in den Bereichen Governance, Prozesse, Compliance und organisatorische Koordination. Sie wissen, wie große Unternehmen politisch und strukturell funktionieren. Der Nachteil ist, dass viele langsamer vorankommen und oft keine tiefgreifende Spezialisierung vorweisen können, wenn es um Frontier-KI geht.“</p>



<p><strong>Spezialisierte KI-Beratungsunternehmen</strong> wiesen hingegen andere Stärken vor, wie Khan festhält: „KI-native Berater agieren deutlich schneller und sind oft technisch auf dem neuesten Stand. Operativ sind viele dieser Unternehmen aber noch nicht ausgereift. Das schlägt sich dann beispielsweise in <a href="https://www.computerwoche.de/article/4183987/embedding-pipelines-sind-das-neue-etl.html" target="_blank">beeindruckenden Demos</a> nieder, wobei die langfristige Wartbarkeit, Governance oder Zuverlässigkeit in der Produktion nicht vollständig verstanden wird.“</p>



<p>Acceligence-CEO Greis sieht zudem die Einbindung <strong>unabhängiger Auftragnehmer</strong> als mögliche Option für externe KI-Unterstützung: „Das kann dem Evaluierungsdesign, Architekturprüfungen, Red-Teaming, Agentendesign zuträglich sein – oder festgefahrene Teams wieder in Gang bringen. Es birgt aber auch das Risiko, sich von einer Schlüsselperson abhängig zu machen – die parallel möglicherweise die Einzige ist, die das System wirklich versteht.“</p>



<p>Für Großunternehmen bietet sich zudem mit dem sogenannten <strong>„Acquihiring“</strong> eine weitere Option. Dabei werden (KI-) Unternehmen aufgekauft und dessen Expertise und Mitarbeiter in die eigene Organisation <a href="https://www.computerwoche.de/article/4007271/metas-neuer-acquihire-ki-coup.html" target="_blank">integriert</a>. Unter bestimmten Voraussetzungen könne das ein Gewinn sein, meint Greis: „Nämlich dann, wenn die eingebrachten KI-Fähigkeiten und das Fachwissen für das übernehmende Unternehmen wirklich strategisch wichtig sind. Es besteht dabei jedoch die Gefahr, dass das übernommene Team von der Bürokratie der neuen Muttergesellschaft erstickt wird. Das ist dann in etwa so, als würde man ein Speedboat kaufen, es an einen Flugzeugträger hängen und sich dann wundern, dass es nicht mehr vorankommt.“</p>



<p>Schließlich kann auch eine <strong>Open-Source-Strategie</strong> Anwenderunternehmen in Sachen KI Flexibilität verschaffen und Abhängigkeiten reduzieren. Das geht allerdings nicht ohne erhöhten operativen Aufwand. Dieser wird ebenfalls häufig unterschätzt, wie Khan darlegt: „<a href="https://www.computerwoche.de/article/4146975/wie-ki-open-source-verandert.html" target="_blank">Open Source</a> ist nur eine echte Option, wenn die Organisation über die internen Talente und die Disziplin verfügt, um eine ordnungsgemäße Wartung sicherzustellen.“</p>



<h2 class="wp-block-heading">Externe Unterstützung bei KI-Deployments – die Optionen im Überblick</h2>



<figure class="wp-block-table"><div class="overflow-table-wrapper"><table class="has-fixed-layout"><tbody><tr><td></td><td><strong>Pro</strong></td><td><strong>Kontra</strong></td></tr><tr><td><strong>FDEs von KI-Anbietern</strong></td><td>beste Expertise mit Blick auf das Haupt-KI-Modell</td><td>Vendor Lock-In<br><br>betriebliche Details dringen nach außen</td></tr><tr><td><strong>Klassische IT-Beratung</strong></td><td>beste Expertise in Sachen Change Management, Legacy-Integration, Rollout, Governance sowie Neugestaltung des Betriebsmodells</td><td>möglicherweise zu langsam, zu teuer oder zu generisch</td></tr><tr><td><strong>KI-Consulting-Unternehmen</strong></td><td>mehr praktische Erfahrung als traditionelle Berater mit Blick auf KI-Deployments <br><br>Vendor Lock-In weniger ausgeprägt als bei FDEs</td><td>unter Umständen mangelndes Verständnis von Enterprise-Anforderungen, etwa in den Bereichen Security, Identity, Auditability, Incident Response, Kostenkontrolle und langfristige Wartbarkeit</td></tr><tr><td><strong>Unabhängige Dienstleister</strong></td><td>nützlich für Präzisions-Tasks wie Eval Design, Architektur-Reviews, Red Teaming oder Agenten-Design</td><td>Risiko der Abhängigkeit von bestimmten Schlüsselpersonen</td></tr><tr><td><strong>„Acquihiring“</strong></td><td>funktioniert, wenn die eingekauften Fähigkeiten wirklich strategisch wichtig sind</td><td>übernommene Teams fallen möglicherweise existierender Bürokratie zum Opfer</td></tr><tr><td><strong>Open-Source-Lösungen</strong></td><td>reduziert die Abhängigkeit von einzelnen Anbietern<br><br>attraktiv, wenn es um Datensouveränität, die Kontrolle von Enterprise-Systemen, Kosteneffizienz und regulierte Umgebungen geht</td><td>Unternehmen tragen die volle Verantwortung für Security, Patching, Evaluierung, Deployment, Monitoring und Lifecycle Management</td></tr></tbody></table> </div></figure>



<p>(fm)</p>



<p><strong>Dieser Artikel ist </strong><a href="https://www.computerworld.com/article/4180088/ai-vendor-fdes-key-considerations-and-concerns.html" target="_blank"><strong>im Original</strong></a><strong> bei unserer Schwesterpublikation Computerworld.com erschienen.</strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Trump sets post-quantum crypto deadlines, launches broader federal quantum initiative]]></title>
<description><![CDATA[US President Donald Trump on Monday signed a pair of executive orders aimed at accelerating the federal government’s transition to post-quantum cryptography while expanding US investment in quantum technologies, establishing what the administration describes as a coordinated strategy to prepare f...]]></description>
<link>https://tsecurity.de/de/3619295/it-security-nachrichten/trump-sets-post-quantum-crypto-deadlines-launches-broader-federal-quantum-initiative/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3619295/it-security-nachrichten/trump-sets-post-quantum-crypto-deadlines-launches-broader-federal-quantum-initiative/</guid>
<pubDate>Tue, 23 Jun 2026 20:38:28 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>US President Donald Trump on Monday signed a pair of executive orders aimed at accelerating the federal government’s transition to post-quantum cryptography while expanding US investment in quantum technologies, establishing what the administration describes as a coordinated strategy to prepare for the opportunities and risks posed by quantum computing.</p>



<p>The actions include an <a href="https://www.whitehouse.gov/presidential-actions/2026/06/securing-the-nation-against-advanced-cryptographic-attacks">executive order</a>, “Securing the Nation Against Advanced Cryptographic Attacks,” and a <a href="https://www.whitehouse.gov/presidential-actions/2026/06/ushering-in-the-next-frontier-of-quantum-innovation/">companion order</a>, “Ushering in the Next Frontier of Quantum Innovation.” Accompanying White House <a href="https://www.whitehouse.gov/fact-sheets/2026/06/fact-sheet-president-donald-j-trump-secures-the-nation-against-advanced-cryptographic-attacks">fact</a> <a href="https://www.whitehouse.gov/fact-sheets/2026/06/fact-sheet-president-donald-j-trump-ushers-in-the-next-frontier-of-quantum-innovation/">sheets</a> frame the initiatives as part of the administration’s broader national security, economic competitiveness, and cybersecurity strategy.</p>



<p>For security leaders, the most immediate impact comes from the cryptography order, which establishes federal migration deadlines for <a href="https://www.csoonline.com/article/654887/11-notable-post-quantum-cryptography-initiatives-launched-in-2023.html">quantum-resistant encryption</a>, directs agencies to inventory cryptographic assets, and signals future procurement requirements for government contractors.</p>



<p>“It’s a great step and definitely in alignment with what we’ve seen from other jurisdictions around the world,” <a href="https://www.linkedin.com/in/chrishickman613/">Chris Hickman</a>, CISO at post-quantum cryptography company Keyfactor, tells CSO. “It compels action.”</p>



<p>Hickman said the deadlines could have effects far beyond federal agencies because contractors and critical infrastructure operators will face increasing pressure to demonstrate <a href="https://www.csoonline.com/article/3552701/the-cisos-guide-to-establishing-quantum-resilience.html">readiness for post-quantum cryptography</a>.</p>



<p>“A lot of suppliers out there don’t want to lose revenue from the federal government, so it’s time to take this stuff seriously,” he said.</p>



<p>The administration argues that adversaries may already be collecting encrypted communications and sensitive data in anticipation of future breakthroughs that could render today’s public key cryptography obsolete.</p>



<p>The White House described the threat as a “harvest now, decrypt later” scenario in which information stolen today could be stored and <a href="https://www.csoonline.com/article/4180902/reap-now-decipher-later-thats-the-approach-to-cybersecurity-in-the-quantum-age.html">decrypted years from now</a> once sufficiently powerful quantum computers become available.</p>



<p>Although experts continue to debate how long it will take to build cryptographically relevant quantum computers, federal officials argue that organizations cannot wait until such systems exist before beginning preparations.</p>



<p>The White House said the order builds on a broader administration cybersecurity agenda, including a June 2025 <a href="https://www.csoonline.com/article/4003811/trump-takes-aim-at-bidens-cyber-executive-order-but-leaves-it-largely-untouched.html">cybersecurity executive order</a> and <a href="https://www.csoonline.com/article/4141989/trumps-cyber-strategy-emphasizes-offensive-operations-deregulation-ai.html">the Cyber Strategy for America</a> released earlier this year. Officials said the effort is intended not only to protect federal systems but also to accelerate adoption of quantum-resistant security technologies across critical infrastructure sectors and the broader digital ecosystem.</p>



<p><a></a><a href="https://www.csoonline.com/article/4188510/linkedin.com/in/ilona-cohen-3094b255">Ilona Cohen</a>, chief legal and policy officer at HackerOne and former general counsel of the White House Office of Management and Budget, said in a statement that recent administration cybersecurity initiatives reflect growing concern about the role contractors play in federal cyber risk. “Federal networks are only as resilient as the contractors supporting them,” Cohen said.</p>



<h2 class="wp-block-heading">Federal migration deadlines established</h2>



<p>The executive order directs federal agencies to accelerate migration to post-quantum cryptography standards developed by the National Institute of Standards and Technology.</p>



<p>NIST finalized <a href="https://www.nist.gov/news-events/news/2024/08/nist-releases-first-3-finalized-post-quantum-encryption-standards">its first post-quantum cryptography standards</a> in 2024 and continues to evaluate additional algorithms intended to replace cryptographic systems vulnerable to future quantum attacks.</p>



<p>Under the order, federal agencies must complete migration of key-establishment mechanisms by Dec. 31, 2030. Migration of digital-signature systems must be completed by Dec. 31, 2031. Within 30 days, agencies must designate senior officials responsible for overseeing post-quantum cryptography migration efforts.</p>



<p>The Office of Management and Budget must issue implementation guidance within 90 days, while agencies are expected to develop plans for replacing vulnerable cryptographic systems across federal environments.</p>



<p>The deadlines represent one of the clearest federal mandates to date regarding the timeline for government adoption of post-quantum cryptography.</p>



<h2 class="wp-block-heading">Cryptographic bill of materials requirements</h2>



<p>The order also introduces measures intended to improve visibility into cryptographic dependencies throughout government systems and software supply chains.</p>



<p>Among the most significant is a directive requiring NIST and the Cybersecurity and Infrastructure Security Agency to develop minimum elements for a cryptographic bill of materials (CBOM) within 270 days.</p>



<p>The concept is similar to a <a href="https://www.csoonline.com/article/573185/what-is-an-sbom-software-bill-of-materials-explained.html">software bill of materials</a> but focuses specifically on identifying cryptographic algorithms, libraries, and dependencies embedded within products and systems.</p>



<p>Security practitioners have long argued that organizations cannot effectively migrate to post-quantum cryptography without first understanding where cryptography exists throughout their environments.</p>



<p>The administration also directed NIST to establish a federal post-quantum cryptography migration pilot program by the end of 2027 to identify implementation challenges and develop migration best practices.</p>



<h2 class="wp-block-heading">Contractors likely to face new compliance obligations</h2>



<p>The executive order also signals significant future implications for federal contractors.</p>



<p>The Federal Acquisition Regulatory Council was directed to develop procurement requirements that would require covered contractors to comply with applicable NIST post-quantum cryptography standards by the end of 2030.</p>



<p>While details remain to be determined, the provision suggests federal purchasing requirements may become a major driver of post-quantum cryptography adoption across the technology industry.</p>



<p>Security vendors, cloud providers, software developers, and managed service providers that do business with federal agencies may ultimately need to demonstrate compliance with emerging post-quantum cryptography requirements.</p>



<p>The order’s emphasis on cryptographic inventories, migration planning, and standards compliance suggests federal agencies will increasingly expect suppliers to understand and document the cryptographic components embedded within their products.</p>



<h2 class="wp-block-heading">Quantum innovation initiative expands</h2>



<p>Alongside the cybersecurity order, Trump signed a separate executive order, which intends to accelerate the development of quantum computing and related technologies.</p>



<p>The administration argues that quantum technologies could eventually transform industries, including pharmaceuticals, manufacturing, logistics, energy, and defense, while providing strategic advantages in scientific research and national security.</p>



<p>At the center of the initiative is a government-wide effort known as Quantum Computing for Accelerated Discovery and Development for Science (QC-ADDS), which aims to develop at least one quantum computer capable of enabling what the administration calls “quantum-enabled scientific discovery.”</p>



<p>The Department of Energy, Department of Commerce, Department of Defense, National Science Foundation, NASA, National Security Agency, and elements of the intelligence community are directed to coordinate research and development activities under the program.</p>



<p>Agencies are tasked with developing technical requirements within 90 days and implementation plans within 180 days.</p>



<p>Industry leaders said the order reflects a growing recognition that leadership in quantum computing will require coordinated investment across multiple layers of the technology stack.</p>



<p>“The United States has a window of opportunity to lead in this domain,” <a href="https://www.linkedin.com/in/stefanleichenauer/">Stefan Leichenauer</a>, vice president of engineering at SandboxAQ, said in a statement. “It requires coordinated investment across the stack: cryptography, compute infrastructure, data generation, and application development. It also requires strong partnerships between government, industry, and academia.”</p>



<p>The order also calls for expanded support for quantum networking and quantum sensing technologies and directs the creation of a national capability for evaluating and benchmarking quantum computing systems.</p>



<h2 class="wp-block-heading">Commercialization, workforce, and security priorities</h2>



<p>A major focus of the innovation initiative is moving quantum technologies from research laboratories into commercial deployment.</p>



<p>The White House said the United States must strengthen domestic quantum supply chains, support technology transfer, and ensure federally funded discoveries translate into commercial products and economic growth.</p>



<p><a href="https://www.csoonline.com/article/4188510/linkedin.com/in/saxenaankur">Ankur Saxena</a>, investment director at TDK Ventures, thinks the order reflects the industry’s growing focus on turning scientific advances into deployable technologies. “Quantum is shifting from a scientific frontier to an engineering and industrial race,” Saxena said in a statement. “US leadership will depend not just on breakthrough hardware, but on resilient supply chains and the enabling infrastructure that makes quantum deployable at scale.”</p>



<p>The administration also announced plans to reconstitute the National Quantum Initiative Advisory Committee and expand activities of the Quantum Counterintelligence Protection Team to help protect sensitive research and intellectual property.</p>



<p>The order places significant emphasis on workforce development as well, directing agencies to support quantum-related education, credentialing, and apprenticeship programs and to establish National Quantum Information Science and Technology Workforce Development Institutes.</p>



<h2 class="wp-block-heading">Two sides of the same strategy</h2>



<p>The executive orders reflect an effort to pursue what administration officials view as two sides of the same challenge: accelerating development of quantum technologies while preparing for the security consequences those technologies may eventually create.</p>



<p>For cybersecurity leaders, the post-quantum cryptography provisions are likely to have the most immediate impact. The combination of migration deadlines, cryptographic inventory requirements, pilot programs, and anticipated procurement mandates signals that federal agencies are moving from planning for post-quantum cryptography to implementing it.</p>



<p>For the broader technology sector, the orders underscore a growing consensus in Washington that quantum computing is no longer merely a long-term research project but a strategic technology that requires simultaneous investment, governance and risk management.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Trump sets post-quantum crypto deadlines, launches broader federal quantum initiative]]></title>
<description><![CDATA[US President Donald Trump on Monday signed a pair of executive orders aimed at accelerating the federal government’s transition to post-quantum cryptography while expanding US investment in quantum technologies, establishing what the administration describes as a coordinated strategy to prepare f...]]></description>
<link>https://tsecurity.de/de/3619287/it-nachrichten/trump-sets-post-quantum-crypto-deadlines-launches-broader-federal-quantum-initiative/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3619287/it-nachrichten/trump-sets-post-quantum-crypto-deadlines-launches-broader-federal-quantum-initiative/</guid>
<pubDate>Tue, 23 Jun 2026 20:32:45 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>US President Donald Trump on Monday signed a pair of executive orders aimed at accelerating the federal government’s transition to post-quantum cryptography while expanding US investment in quantum technologies, establishing what the administration describes as a coordinated strategy to prepare for the opportunities and risks posed by quantum computing.</p>



<p>The actions include an <a href="https://www.whitehouse.gov/presidential-actions/2026/06/securing-the-nation-against-advanced-cryptographic-attacks" rel="nofollow">executive order</a>, “Securing the Nation Against Advanced Cryptographic Attacks,” and a <a href="https://www.whitehouse.gov/presidential-actions/2026/06/ushering-in-the-next-frontier-of-quantum-innovation/" rel="nofollow">companion order</a>, “Ushering in the Next Frontier of Quantum Innovation.” Accompanying White House <a href="https://www.whitehouse.gov/fact-sheets/2026/06/fact-sheet-president-donald-j-trump-secures-the-nation-against-advanced-cryptographic-attacks" rel="nofollow">fact</a> <a href="https://www.whitehouse.gov/fact-sheets/2026/06/fact-sheet-president-donald-j-trump-ushers-in-the-next-frontier-of-quantum-innovation/" rel="nofollow">sheets</a> frame the initiatives as part of the administration’s broader national security, economic competitiveness, and cybersecurity strategy.</p>



<p>For security leaders, the most immediate impact comes from the cryptography order, which establishes federal migration deadlines for <a href="https://www.csoonline.com/article/654887/11-notable-post-quantum-cryptography-initiatives-launched-in-2023.html">quantum-resistant encryption</a>, directs agencies to inventory cryptographic assets, and signals future procurement requirements for government contractors.</p>



<p>“It’s a great step and definitely in alignment with what we’ve seen from other jurisdictions around the world,” <a href="https://www.linkedin.com/in/chrishickman613/" rel="nofollow">Chris Hickman</a>, CISO at post-quantum cryptography company Keyfactor, tells CSO. “It compels action.”</p>



<p>Hickman said the deadlines could have effects far beyond federal agencies because contractors and critical infrastructure operators will face increasing pressure to demonstrate <a href="https://www.csoonline.com/article/3552701/the-cisos-guide-to-establishing-quantum-resilience.html">readiness for post-quantum cryptography</a>.</p>



<p>“A lot of suppliers out there don’t want to lose revenue from the federal government, so it’s time to take this stuff seriously,” he said.</p>



<p>The administration argues that adversaries may already be collecting encrypted communications and sensitive data in anticipation of future breakthroughs that could render today’s public key cryptography obsolete.</p>



<p>The White House described the threat as a “harvest now, decrypt later” scenario in which information stolen today could be stored and <a href="https://www.csoonline.com/article/4180902/reap-now-decipher-later-thats-the-approach-to-cybersecurity-in-the-quantum-age.html">decrypted years from now</a> once sufficiently powerful quantum computers become available.</p>



<p>Although experts continue to debate how long it will take to build cryptographically relevant quantum computers, federal officials argue that organizations cannot wait until such systems exist before beginning preparations.</p>



<p>The White House said the order builds on a broader administration cybersecurity agenda, including a June 2025 <a href="https://www.csoonline.com/article/4003811/trump-takes-aim-at-bidens-cyber-executive-order-but-leaves-it-largely-untouched.html">cybersecurity executive order</a> and <a href="https://www.csoonline.com/article/4141989/trumps-cyber-strategy-emphasizes-offensive-operations-deregulation-ai.html">the Cyber Strategy for America</a> released earlier this year. Officials said the effort is intended not only to protect federal systems but also to accelerate adoption of quantum-resistant security technologies across critical infrastructure sectors and the broader digital ecosystem.</p>



<p><a href="https://www.cio.com/article/4188512/linkedin.com/in/ilona-cohen-3094b255">Ilona Cohen</a>, chief legal and policy officer at HackerOne and former general counsel of the White House Office of Management and Budget, said in a statement that recent administration cybersecurity initiatives reflect growing concern about the role contractors play in federal cyber risk. “Federal networks are only as resilient as the contractors supporting them,” Cohen said.</p>



<h2 class="wp-block-heading">Federal migration deadlines established</h2>



<p>The executive order directs federal agencies to accelerate migration to post-quantum cryptography standards developed by the National Institute of Standards and Technology.</p>



<p>NIST finalized <a href="https://www.nist.gov/news-events/news/2024/08/nist-releases-first-3-finalized-post-quantum-encryption-standards" rel="nofollow">its first post-quantum cryptography standards</a> in 2024 and continues to evaluate additional algorithms intended to replace cryptographic systems vulnerable to future quantum attacks.</p>



<p>Under the order, federal agencies must complete migration of key-establishment mechanisms by Dec. 31, 2030. Migration of digital-signature systems must be completed by Dec. 31, 2031. Within 30 days, agencies must designate senior officials responsible for overseeing post-quantum cryptography migration efforts.</p>



<p>The Office of Management and Budget must issue implementation guidance within 90 days, while agencies are expected to develop plans for replacing vulnerable cryptographic systems across federal environments.</p>



<p>The deadlines represent one of the clearest federal mandates to date regarding the timeline for government adoption of post-quantum cryptography.</p>



<h2 class="wp-block-heading">Cryptographic bill of materials requirements</h2>



<p>The order also introduces measures intended to improve visibility into cryptographic dependencies throughout government systems and software supply chains.</p>



<p>Among the most significant is a directive requiring NIST and the Cybersecurity and Infrastructure Security Agency to develop minimum elements for a cryptographic bill of materials (CBOM) within 270 days.</p>



<p>The concept is similar to a <a href="https://www.csoonline.com/article/573185/what-is-an-sbom-software-bill-of-materials-explained.html">software bill of materials</a> but focuses specifically on identifying cryptographic algorithms, libraries, and dependencies embedded within products and systems.</p>



<p>Security practitioners have long argued that organizations cannot effectively migrate to post-quantum cryptography without first understanding where cryptography exists throughout their environments.</p>



<p>The administration also directed NIST to establish a federal post-quantum cryptography migration pilot program by the end of 2027 to identify implementation challenges and develop migration best practices.</p>



<h2 class="wp-block-heading">Contractors likely to face new compliance obligations</h2>



<p>The executive order also signals significant future implications for federal contractors.</p>



<p>The Federal Acquisition Regulatory Council was directed to develop procurement requirements that would require covered contractors to comply with applicable NIST post-quantum cryptography standards by the end of 2030.</p>



<p>While details remain to be determined, the provision suggests federal purchasing requirements may become a major driver of post-quantum cryptography adoption across the technology industry.</p>



<p>Security vendors, cloud providers, software developers, and managed service providers that do business with federal agencies may ultimately need to demonstrate compliance with emerging post-quantum cryptography requirements.</p>



<p>The order’s emphasis on cryptographic inventories, migration planning, and standards compliance suggests federal agencies will increasingly expect suppliers to understand and document the cryptographic components embedded within their products.</p>



<h2 class="wp-block-heading">Quantum innovation initiative expands</h2>



<p>Alongside the cybersecurity order, Trump signed a separate executive order, which intends to accelerate the development of quantum computing and related technologies.</p>



<p>The administration argues that quantum technologies could eventually transform industries, including pharmaceuticals, manufacturing, logistics, energy, and defense, while providing strategic advantages in scientific research and national security.</p>



<p>At the center of the initiative is a government-wide effort known as Quantum Computing for Accelerated Discovery and Development for Science (QC-ADDS), which aims to develop at least one quantum computer capable of enabling what the administration calls “quantum-enabled scientific discovery.”</p>



<p>The Department of Energy, Department of Commerce, Department of Defense, National Science Foundation, NASA, National Security Agency, and elements of the intelligence community are directed to coordinate research and development activities under the program.</p>



<p>Agencies are tasked with developing technical requirements within 90 days and implementation plans within 180 days.</p>



<p>Industry leaders said the order reflects a growing recognition that leadership in quantum computing will require coordinated investment across multiple layers of the technology stack.</p>



<p>“The United States has a window of opportunity to lead in this domain,” <a href="https://www.linkedin.com/in/stefanleichenauer/" rel="nofollow">Stefan Leichenauer</a>, vice president of engineering at SandboxAQ, said in a statement. “It requires coordinated investment across the stack: cryptography, compute infrastructure, data generation, and application development. It also requires strong partnerships between government, industry, and academia.”</p>



<p>The order also calls for expanded support for quantum networking and quantum sensing technologies and directs the creation of a national capability for evaluating and benchmarking quantum computing systems.</p>



<h2 class="wp-block-heading">Commercialization, workforce, and security priorities</h2>



<p>A major focus of the innovation initiative is moving quantum technologies from research laboratories into commercial deployment.</p>



<p>The White House said the United States must strengthen domestic quantum supply chains, support technology transfer, and ensure federally funded discoveries translate into commercial products and economic growth.</p>



<p><a href="https://www.cio.com/article/4188512/linkedin.com/in/saxenaankur">Ankur Saxena</a>, investment director at TDK Ventures, thinks the order reflects the industry’s growing focus on turning scientific advances into deployable technologies. “Quantum is shifting from a scientific frontier to an engineering and industrial race,” Saxena said in a statement. “US leadership will depend not just on breakthrough hardware, but on resilient supply chains and the enabling infrastructure that makes quantum deployable at scale.”</p>



<p>The administration also announced plans to reconstitute the National Quantum Initiative Advisory Committee and expand activities of the Quantum Counterintelligence Protection Team to help protect sensitive research and intellectual property.</p>



<p>The order places significant emphasis on workforce development as well, directing agencies to support quantum-related education, credentialing, and apprenticeship programs and to establish National Quantum Information Science and Technology Workforce Development Institutes.</p>



<h2 class="wp-block-heading">Two sides of the same strategy</h2>



<p>The executive orders reflect an effort to pursue what administration officials view as two sides of the same challenge: accelerating development of quantum technologies while preparing for the security consequences those technologies may eventually create.</p>



<p>For cybersecurity leaders, the post-quantum cryptography provisions are likely to have the most immediate impact. The combination of migration deadlines, cryptographic inventory requirements, pilot programs, and anticipated procurement mandates signals that federal agencies are moving from planning for post-quantum cryptography to implementing it.</p>



<p>For the broader technology sector, the orders underscore a growing consensus in Washington that quantum computing is no longer merely a long-term research project but a strategic technology that requires simultaneous investment, governance and risk management.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Neuer CSC-Bericht verdeutlicht, wie sich KI auf Sicherheitsverantwortliche in Unternehmen auswirkt]]></title>
<description><![CDATA[Laut dem Bericht CISO Outlook 2026 von CSC geben 73 % der Befragten an, dass KI für die Cybersicherheit eher eine Chance als ein Risiko darstellt.]]></description>
<link>https://tsecurity.de/de/3619160/it-security-nachrichten/neuer-csc-bericht-verdeutlicht-wie-sich-ki-auf-sicherheitsverantwortliche-in-unternehmen-auswirkt/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3619160/it-security-nachrichten/neuer-csc-bericht-verdeutlicht-wie-sich-ki-auf-sicherheitsverantwortliche-in-unternehmen-auswirkt/</guid>
<pubDate>Tue, 23 Jun 2026 19:37:36 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Laut dem Bericht CISO Outlook 2026 von CSC geben 73 % der Befragten an, dass KI für die <b>Cybersicherheit</b> eher eine Chance als ein Risiko darstellt.]]></content:encoded>
</item>
<item>
<title><![CDATA[Cybersecurity Risk Management]]></title>
<description><![CDATA[Author: Microsoft Security - Bewertung: 1x - Views:22 In this video, Stephanie Peterson, Senior Director of CISO GRC, walks through Microsoft’s end-to-end cybersecurity risk management program—covering governance, process, and how risk is surfaced, assessed, and mitigated across the enterprise.

...]]></description>
<link>https://tsecurity.de/de/3618744/it-security-video/cybersecurity-risk-management/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3618744/it-security-video/cybersecurity-risk-management/</guid>
<pubDate>Tue, 23 Jun 2026 17:33:43 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Microsoft Security - Bewertung: 1x - Views:22 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/x-JMCUN9sIQ?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>In this video, Stephanie Peterson, Senior Director of CISO GRC, walks through Microsoft’s end-to-end cybersecurity risk management program—covering governance, process, and how risk is surfaced, assessed, and mitigated across the enterprise.<br />
<br />
This video breaks down:<br />
<br />
- The risk management pyramid—from operational risks to board-level oversight<br />
- The role of the Cybersecurity Governance Council and enterprise risk reporting<br />
- How the centralized risk register connects signals across teams and systems<br />
- Microsoft’s four-stage risk lifecycle: identification, assessment, mitigation, and monitoring<br />
- How programs like the Secure Future Initiative (SFI) prioritize critical risks<br />
- The roles of risk submitters, curators, owners, and reviewers in driving accountability<br />
<br />
You’ll also see how Microsoft creates a continuous feedback loop—linking risk insights to executive decision-making, compliance frameworks, and long-term security strategy.<br />
<br />
Whether you're building a risk program or refining governance, this overview provides a practical model for managing cybersecurity risk at scale.<br />
<br />
For more guidance from the Office of the CISO, explore Office of the CISO Insights on the Microsoft Security Blog. → https://msft.it/6050v5zCa<br />
<br />
#MicrosoftCybersecurity #GRCCybersecurity #CISORiskManagement<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CISO Conversations: Carl Froggett – Combining CISO and CIO at Deep Instinct]]></title>
<description><![CDATA[Carl Froggett combines CISO and CIO. He currently occupies both positions at Deep Instinct. Before then, he was CISO at Citi for almost 17 years.
The post CISO Conversations: Carl Froggett – Combining CISO and CIO at Deep Instinct appeared first on SecurityWeek.]]></description>
<link>https://tsecurity.de/de/3618295/it-security-nachrichten/ciso-conversations-carl-froggett-combining-ciso-and-cio-at-deep-instinct/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3618295/it-security-nachrichten/ciso-conversations-carl-froggett-combining-ciso-and-cio-at-deep-instinct/</guid>
<pubDate>Tue, 23 Jun 2026 14:53:21 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Carl Froggett combines CISO and CIO. He currently occupies both positions at Deep Instinct. Before then, he was CISO at Citi for almost 17 years.</p>
<p>The post <a href="https://www.securityweek.com/ciso-conversations-carl-froggett-combining-ciso-and-cio-at-deep-instinct/">CISO Conversations: Carl Froggett – Combining CISO and CIO at Deep Instinct</a> appeared first on <a href="https://www.securityweek.com/">SecurityWeek</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Cybersecurity is no longer about protection. It’s about survival.]]></title>
<description><![CDATA[For years, cybersecurity professionals have been repeating the same warning: Every company will eventually be breached.



Fine. Let’s accept that.



Then why do so many organizations still behave as if the near sole purpose of cybersecurity is to prevent the breach from ever happening?



That ...]]></description>
<link>https://tsecurity.de/de/3617413/it-security-nachrichten/cybersecurity-is-no-longer-about-protection-its-about-survival/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3617413/it-security-nachrichten/cybersecurity-is-no-longer-about-protection-its-about-survival/</guid>
<pubDate>Tue, 23 Jun 2026 09:08:41 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>For years, cybersecurity professionals have been repeating the same warning: Every company will eventually be breached.</p>



<p>Fine. Let’s accept that.</p>



<p>Then why do so many organizations still behave as if the near sole purpose of cybersecurity is to prevent the breach from ever happening?</p>



<p>That is the contradiction at the heart of modern cybersecurity strategy. We say, “Assume the breach,” but we budget, govern, architect, and rehearse as if the wall will hold. We tell boards compromise is inevitable, then ask for more money to make the wall higher, thicker, smarter, and more AI-enabled. We buy more tools. We tune more dashboards. We polish the gate. We call it maturity. And then, when the wall of our gloriously protected city cracks, it turns out that half the city has no food, no command structure, no working roads, no backup water supply, and no idea who is supposed to organize the response.</p>



<p>That is not security. Or at least, it should no longer be understood as security.</p>



<h2 class="wp-block-heading">Pure prevention is the past</h2>



<p>The age of having a pure prevention focus has ended. Not because prevention is dead. That would be a childish argument. WAFs matter. MFA matters. Patching matters. Hardening matters. The familiar machinery still matters: hardened systems, sane configurations, patching discipline, identity controls, endpoint visibility, email defenses, logging, segmentation, and the rest of the security plumbing. Nobody serious is suggesting we kick open the gates and invite the attackers in.</p>



<p>But prevention alone is no longer a credible operating model. It no longer works as the primary focal point. The strategic question is no longer simply, “Can we stop the attack?” The better question is, “Can the organization continue to function when the attack succeeds?” That is the shift. Cybersecurity is not primarily about protection anymore. It is about survival.</p>



<p>Survival means breach readiness. It means continuity. It means recoverability. It means identity restoration when the identity provider is compromised. It means knowing which systems can be rebuilt cleanly and which ones are held together by duct tape, vendor promises, and one engineer we are all praying will never retire. It means backup integrity, crisis governance, legal and communications alignment, supplier fallback, product resilience, clean deployment pipelines, tested incident response, and executives who understand that cyber risk is not a quarterly awareness slide. Survival means designing organizations that can absorb breach, disruption, AI acceleration, supplier failure, regulatory pressure, and systemic shock without collapsing entirely.</p>



<p>This is not just philosophy. The world is moving there whether companies enjoy the view or not.</p>



<h2 class="wp-block-heading">The critical question</h2>



<p>In Europe, under the EU legislative umbrella, cyber resilience is becoming explicit regulatory language. <a href="https://www.csoonline.com/article/570091/eus-dora-regulation-explained-new-risk-management-requirements-for-financial-firms.html">DORA</a> makes digital operational resilience a serious financial-sector obligation. <a href="https://www.csoonline.com/article/3568787/eus-nis2-directive-for-cybersecurity-resilience-enters-full-enforcement.html">NIS2</a> widens the net around essential and important entities. The <a href="https://www.csoonline.com/article/4168696/eus-cyber-resiliency-act-will-put-it-leaders-to-the-test.html">Cyber Resilience Act</a> pushes security into the lifecycle of products with digital elements, from planning and design to development and maintenance. Europe, in its very European way, is saying: You shall be resilient, and <a href="https://www.csoonline.com/article/4108294/implementing-nis2-without-ending-up-in-a-paper-war.html">there shall be paperwork</a>.</p>



<p>The US is taking a different, perhaps more laissez-faire path. It is pushing accountability through disclosure, enforcement, sector rules, procurement pressure, and public-private nudging. The SEC wants material cyber risk and incidents visible to investors. CIRCIA aims to force critical infrastructure operators to report substantial incidents and ransom payments. CISA pushes <a href="https://www.csoonline.com/article/3971375/secure-by-design-is-likely-dead-at-cisa-will-the-private-sector-make-good-on-its-pledge.html">Secure by Design pledges</a>. All that sounds good. But there is a catch, and it lies in the unresolved question of criticality.</p>



<p>Critical for whom?</p>



<p>Critical for the government? For consumers? For markets? For the company’s customers? Critical for a supply chain that no regulator has fully mapped because the economy now runs on a cesspool of unmanaged SaaS dependencies?</p>



<p>Europe is increasingly trying to define resilience as an obligation. The US, more characteristically, is trying to produce accountability through disclosure, enforcement, procurement pressure, and market signaling. The problem is that market signaling collapses when nobody wants to admit they are part of the market’s critical nervous system. This is where the comfortable policy language starts to wobble.</p>



<p>“Critical infrastructure” is treated as if it were a natural category. It is not natural. It is political, legal, economic, operational, and worst of all, highly fluid. Companies are trying to avoid being seen as critical when the label brings obligations, reporting duties, scrutiny, liability, and expense. That is not cynicism. That is incentives doing what incentives do: rewarding ambiguity, punishing transparency, and giving everyone a reason to stay conveniently uncritical until the blast radius proves otherwise.</p>



<p>The deeper issue is not only critical infrastructure. It is critical dependency.</p>



<p>A company may not be critical to the state, but it may be critical to every customer that relies on it. A vendor may avoid the regulatory label, but not the blast radius. A minor-looking SaaS provider, identity layer, CI/CD platform, payment processor, LLM tool, MSP, open-source package, or API gateway can become the point where hundreds of organizations discover that their <a href="https://www.csoonline.com/article/515730/business-continuity-and-disaster-recovery-planning-the-basics.html">business continuity plan</a> was a PDF bundled in mindless optimism.</p>



<p>This is why voluntary pledges are useful but insufficient. They create norms and language. They help responsible companies signal intent. But a pledge is not a control. A pledge without evidence, enforcement, procurement consequences, customer pressure, or liability is policy theater with potential. Better than silence, yes. Better than mandatory resilience? Not even close.</p>



<p>And then AI permeates the world as an accelerant poured across the entire problem.</p>



<h2 class="wp-block-heading">The AI uprising</h2>



<p>AI compresses time. It <a href="https://www.csoonline.com/article/4014238/cybercriminals-take-malicious-ai-to-the-next-level.html">lowers attacker skill barriers</a>. It improves phishing, reconnaissance, exploit development, malware support, impersonation, fraud, and social engineering. It also expands the attack surface inside companies through <a href="https://www.csoonline.com/article/4143302/the-cisos-guide-to-responding-to-shadow-ai.html">shadow AI</a>, <a href="https://www.csoonline.com/article/4047974/agentic-ai-a-cisos-security-nightmare-in-the-making.html">AI agents</a>, sensitive data leakage, automated decisions, insecure integrations, and systems that can act <a href="https://www.csoonline.com/article/4109999/agentic-ai-already-hinting-at-cybersecuritys-pending-identity-crisis.html">without anyone fully understanding how far their permissions reach</a>.</p>



<p>The uncomfortable part is that defenders need AI, too. Nobody is going to manually out-click, out-triage, and out-correlate machine-speed attacks with heroic analysts and vibes. Defensive AI is necessary. AI-assisted testing is necessary. <a href="https://www.csoonline.com/article/4145127/runtime-the-new-frontier-of-ai-agent-security.html">Runtime analysis is becoming more important</a>. <a href="https://www.csoonline.com/article/4064158/agentic-ai-in-it-security-where-expectations-meet-reality.html">Agentic security workflows will grow</a>. Humans matter, of course, but they will need to move from being button-pushers to decision-makers, validators, and designers of boundaries.</p>



<p>Recent Mythos revelation, whatever one thinks of it, <a href="https://www.csoonline.com/article/4158117/anthropics-mythos-signals-a-structural-cybersecurity-shift.html">exposed the broader truth</a>: AI is not merely another asset to secure. It changes the tempo of security. It changes what “timely” means. If attackers can move from discovery to exploitation faster than a company can schedule a change committee meeting, prevention-first chest-thumping becomes blind, brainless bravado.</p>



<p>Consequently, that is also where application security becomes central, but not in the narrow old sense.</p>



<h2 class="wp-block-heading">AppSec shows the way</h2>



<p>AppSec has traditionally been treated as prevention: find bugs, fix bugs, block exploit paths, test before release, scan the API, harden the app, stop the vulnerability from becoming an incident. That is still true. But modern AppSec is also resilience. Secure-by-design systems fail less catastrophically. Well-tested applications reduce blast radius. Strong API authorization protects business logic when identity is abused. Good software supply-chain controls make recovery possible because you know what you shipped, where it came from, and whether you can trust it. Continuous testing shortens the time between exposure and correction. Runtime visibility tells you what is actually happening, not what the architecture diagram claimed would happen in calmer weather.</p>



<p>The mature AppSec question is no longer only whether a vulnerability exists. It is how quickly the organization can discover exposure, validate exploitability, prioritize business impact, reduce blast radius, and prove the fix actually reduced risk.</p>



<p>So AppSec is preventive in method, but resilient in strategic value.</p>



<p>That matters because the old budget logic still lingers. Many organizations talk about resilience at the board level while still spending and operating like the real work is another tool, another dashboard, another rule, another exception queue, another heroic security team tuning SIEM alerts at midnight. There is a widening gap between the talk and the walk. The talk says resilience. The walk still mainly says prevention, compliance, and hope.</p>



<h2 class="wp-block-heading">Resilience becomes duty</h2>



<p>This is not to mock prevention. Prevention is valuable. It reduces noise and buys time. It blocks commodity attacks. Prevention keeps the easy doors closed and the lazy criminals moving. Good. Keep it. Fund it. Improve it.</p>



<p>But stop pretending it is the whole castle.</p>



<p>At some point, reinforcing the gate drains us of good iron. Or cash, as may be the case. The cannon is already here. Sometimes the cannon is ransomware. Sometimes it is a supplier compromise. Sometimes it is an AI-assisted vulnerability chain. Sometimes it is a cloud identity failure. Sometimes it is a security vendor update that helpfully demonstrates the concept of systemic risk by taking half the planet down before breakfast.</p>



<p>The organizations that survive will not be the ones with the prettiest walls. They will be the ones that know what happens when the walls fail.</p>



<p>They will know which services matter most. They will know their dependencies, how to isolate blast radius, how to restore from clean sources. They will know who decides, who communicates, who pays, who informs regulators, who speaks to customers, and who has authority to shut something down before the whole environment becomes a crime scene with invoices.</p>



<p>They will practice. Not once a year in a tabletop exercise where <a href="https://www.csoonline.com/article/4179644/7-tabletop-exercise-mistakes-that-sabotage-incident-response.html">everyone nods politely</a> and pretends Legal will respond in real-time. They will practice seriously. They will break assumptions. They will test recovery. They will challenge vendors. They will treat incident response as an organizational muscle, not a binder.</p>



<p>This is also where <a href="https://www.csoonline.com/article/3602722/the-ciso-paradox-with-great-responsibility-comes-little-or-no-power.html">CISO accountability must be discussed honestly</a>. It is easy to demand accountability from the security leader after the fire. It is harder to ask whether the CISO had budget, authority, board access, engineering influence, product leverage, procurement power, and documented risk acceptance before the fire. If a company wants the CISO to be accountable for survival, then the <a href="https://www.csoonline.com/article/3617367/dear-ceo-an-open-letter-from-your-ciso.html">CISO must be empowered to design for survival</a>. Otherwise, accountability is just corporate theater, and the CISO is one person selected in advance to <a href="https://www.csoonline.com/article/3631759/personal-liability-sours-70-of-cisos-on-their-role.html">stand under the falling chandelier</a>.</p>



<p>The same applies to boards. A board that funds only prevention but expects resilience after failure is not governing cyber risk. It is buying a bucketload of denial. Cybersecurity cannot remain a narrow technical department expected to compensate for fragile business architecture, reckless supplier dependence, poor software practices, underfunded recovery, unclear executive authority, and magical thinking about AI.</p>



<p>If cybersecurity is survival, then everyone who shapes organizational resilience shapes cybersecurity. Engineering shapes it. Procurement shapes it. Legal shapes it. Finance, Product, HR, Communications — they all shape it. The board, too, and the CEO. Security may lead the discipline, but it cannot be the only organ responsible for keeping the body alive.</p>



<p>That is the point. Not that prevention no longer matters. Not that we should abandon controls and have minstrels sing of resilience while attackers empty the database. The point is that protection is no longer enough to <em>define security</em>. A company that collapses when prevention fails was never truly secure. It was only protected until the first failure.</p>



<p>The cybersecurity paradigm of today and tomorrow must be built around survival: surviving breach, surviving disruption, surviving AI acceleration, surviving dependency failure, surviving regulatory scrutiny, and surviving the moment when the neat diagram meets the ugly incident.</p>



<p>We still need walls, gates, and guards.</p>



<p>But the wall is not the city, nor its citizens. And if the city and the citizens cannot survive after the wall falls, then maybe the wall was never a viable strategy.</p>



<p>Maybe it was just a waste of that good iron.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[ISO 42001 vs NIST AI RMF vs the EU AI Act: How They Actually Fit Together in 2026]]></title>
<description><![CDATA[ISO 42001, the NIST AI RMF, and the EU AI Act are not rivals. A CISO's guide to how they fit together as one AI governance stack, and where to start.]]></description>
<link>https://tsecurity.de/de/3616285/it-security-nachrichten/iso-42001-vs-nist-ai-rmf-vs-the-eu-ai-act-how-they-actually-fit-together-in-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3616285/it-security-nachrichten/iso-42001-vs-nist-ai-rmf-vs-the-eu-ai-act-how-they-actually-fit-together-in-2026/</guid>
<pubDate>Mon, 22 Jun 2026 19:53:16 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ISO 42001, the NIST AI RMF, and the EU AI Act are not rivals. A CISO's guide to how they fit together as one AI governance stack, and where to start.]]></content:encoded>
</item>
<item>
<title><![CDATA[A CISO’s guide to infostealers: Prevention and detection]]></title>
<description><![CDATA[Infostealers do exactly as their name implies: The malware secretly steals sensitive information, such as passwords and financial information, from user endpoints and then transfers that information to a location selected by the attacker. Infostealers have become far more prevalent…
Read more →
T...]]></description>
<link>https://tsecurity.de/de/3616264/it-security-nachrichten/a-cisos-guide-to-infostealers-prevention-and-detection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3616264/it-security-nachrichten/a-cisos-guide-to-infostealers-prevention-and-detection/</guid>
<pubDate>Mon, 22 Jun 2026 19:37:13 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>&lt;p&gt;Infostealers do exactly as their name implies: The malware secretly steals sensitive information, such as passwords and financial information, from user endpoints and then transfers that information to a location selected by the attacker.&lt;/p&gt; &lt;p&gt;Infostealers have become far more prevalent…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/a-cisos-guide-to-infostealers-prevention-and-detection/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/a-cisos-guide-to-infostealers-prevention-and-detection/">A CISO’s guide to infostealers: Prevention and detection</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[A CISO's guide to infostealers: Prevention and detection]]></title>
<description><![CDATA[Infostealers aren't new. But what is new is that almost anyone -- regardless of skill -- can now deploy the malware. Update incident response plans to safeguard your operations.]]></description>
<link>https://tsecurity.de/de/3616232/it-security-nachrichten/a-cisos-guide-to-infostealers-prevention-and-detection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3616232/it-security-nachrichten/a-cisos-guide-to-infostealers-prevention-and-detection/</guid>
<pubDate>Mon, 22 Jun 2026 19:23:20 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Infostealers aren't new. But what is new is that almost anyone -- regardless of skill -- can now deploy the malware. Update incident response plans to safeguard your operations.]]></content:encoded>
</item>
<item>
<title><![CDATA[AWS Continuum offers devs help with securing code]]></title>
<description><![CDATA[AI coding agents are making it easier than ever to produce software. Ensuring that software is secure before deployment is another matter — one that AWS thinks AI should help with too.



As enterprises adopt agentic development workflows, the volume of first-party code being created and modified...]]></description>
<link>https://tsecurity.de/de/3616133/it-security-nachrichten/aws-continuum-offers-devs-help-with-securing-code/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3616133/it-security-nachrichten/aws-continuum-offers-devs-help-with-securing-code/</guid>
<pubDate>Mon, 22 Jun 2026 18:38:22 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>AI coding agents are making it easier than ever to produce software. Ensuring that software is secure before deployment is another matter — one that AWS thinks AI should help with too.</p>



<p>As enterprises adopt <a href="https://www.infoworld.com/article/4142019/coding-for-agents.html">agentic development</a> workflows, the volume of first-party code being created and modified is rising rapidly. Yet the process of validating vulnerabilities, determining whether they are exploitable, and fixing them often still depends on developers and security teams working through findings manually.</p>



<p>AWS is aiming to address that imbalance with Continuum, a new service designed to continuously discover, investigate, and remediate vulnerabilities in enterprise environments, whether the code is their own or from third parties.</p>



<p>Rather than simply generating alerts, the service is intended to help enterprises move findings through the entire remediation lifecycle, AWS VP of Security and Observability <a href="https://www.linkedin.com/in/chetkapoor/" target="_blank" rel="noreferrer noopener">Chet Kapoor</a> wrote in a <a href="https://aws.amazon.com/blogs/security/introducing-aws-continuum-security-at-machine-speed/" target="_blank" rel="noreferrer noopener">blog post</a>.</p>



<p>For first-party applications, Continuum can analyze code, validate whether vulnerabilities are exploitable, generate remediation recommendations, and propose fixes that can be reviewed through existing software development workflows, helping developers address security issues without requiring security teams to manually investigate every finding, Kapoor said.</p>



<p>Once users think Continuum has learned enough about their environment and understands their guardrails, they can put it in what AWS calls “enforce mode” to autonomously fix any code lapses, Kapoor said.</p>



<p>Continuum borrows some of its capabilities, penetration testing and code scanning features, from an existing service, Security Agent.</p>



<p>Other capabilities are all-new, including threat modeling, which is designed to automatically generate threat models from source code or design documents and output them in STRIDE format.</p>



<h2 class="wp-block-heading">Keeping pace with AI-driven software development</h2>



<p>Analysts see Continuum helping enterprise developer teams ship more secure code while keeping pace with <a href="https://www.infoworld.com/article/4176534/ai-coding-agents-need-good-software-engineers.html">AI coding tools</a>.</p>



<p>“The harder problem is no longer just finding issues, it is knowing which ones are real, which ones matter in their environment, and which ones need to be fixed first,” said <a href="https://www.hfsresearch.com/team/akshat-tyagi/" target="_blank" rel="noreferrer noopener">Akshat Tyagi</a>, associate practice leader at HFS Research. “Traditional workflows built around dashboards and manual triage struggle with that volume. A dashboard can show the backlog, but it does not validate the finding, assess business impact, or help remediate it.”</p>



<p>Continuum’s value, according to Tyagi, “is not just more detection, but using AI to prioritize risk findings, suggest mitigations, and support faster action while keeping humans in control of high-risk decisions.”</p>



<p>Taking faster action is becoming increasingly important as attackers are gaining access to many of the same AI capabilities that enterprises are using to accelerate software development and security testing, according to <a href="https://www.linkedin.com/in/amitchandak78/" target="_blank" rel="noreferrer noopener">Amit Chandak</a>, chief analytics officer at IT consulting firm Kanerika. “The gap between a flaw being disclosed and a working exploit is shrinking rapidly from months to hours,” he said.</p>



<p>While Continuum may reduce repetitive work for developers and SREs, it could also create new responsibilities for CISOs around governance, oversight, testing, and maintaining guardrails for automated actions.</p>



<p>“Continuum changes the CISO’s role from managing findings to governing how findings are handled. The focus moves to setting rules: what can be automated, what needs human approval, and what level of risk is acceptable in production,” Tyagi said. “Staffing will shift too. There may be less manual triage, but more need for people who can review AI-generated fixes, set guardrails, and know when not to trust the system.”</p>



<p>Even so, Chandak does not expect the offering to lead to immediate headcount reductions, particularly given that Continuum is only available as a gated preview.</p>



<p>Continuum could change how CISOs measure work, Tyagi said: “Ticket count matters less. Better measures are how quickly real risks are validated and fixed, how many false positives are removed, and whether automation is reducing risk without causing new problems.”</p>



<p>Those same metrics could also become a yardstick for CISOs determining how much autonomy to give tools like Continuum, said Chandak. Most enterprises’ data and governance practices are not yet ready for fully autonomous remediation, said Chandak, adding that, “AWS’ graduated trust design, under which enterprises have the option of choosing the degree of autonomy, from human in the loop to fully automatic remediation, is an admission of that fact.”</p>



<h2 class="wp-block-heading">Beyond first-party code</h2>



<p>Continuum could also help CISOs with third-party code vulnerability analysis, where enterprises often have less visibility and control.</p>



<p>“Most third party vulnerability alerts are noise. A tool may flag a vulnerable library, but the real question is whether that vulnerable code is actually used in production. If Continuum can answer that, it helps teams focus on the few issues that matter,” Tyagi said. “This is especially useful for open-source and software supply chain risk, where enterprises depend on packages and hidden transitive dependencies they may not fully track. It also helps when no patch is available yet.”</p>



<p>However, he warned, Continuum might not offer a direct fix to third-party code: “You usually cannot patch third-party code yourself as you don’t own it, so remediation there means version pinning or compensating controls.”</p>



<p><em>This article first appeared on <a href="https://www.infoworld.com/article/4187916/aws-continuum-offers-devs-help-with-securing-code.html">InfoWorld</a>.</em></p>



<p></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[AWS Continuum offers devs help with securing code]]></title>
<description><![CDATA[AI coding agents are making it easier than ever to produce software. Ensuring that software is secure before deployment is another matter — one that AWS thinks AI should help with too.



As enterprises adopt agentic development workflows, the volume of first-party code being created and modified...]]></description>
<link>https://tsecurity.de/de/3616128/ai-nachrichten/aws-continuum-offers-devs-help-with-securing-code/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3616128/ai-nachrichten/aws-continuum-offers-devs-help-with-securing-code/</guid>
<pubDate>Mon, 22 Jun 2026 18:33:47 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>AI coding agents are making it easier than ever to produce software. Ensuring that software is secure before deployment is another matter — one that AWS thinks AI should help with too.</p>



<p>As enterprises adopt <a href="https://www.infoworld.com/article/4142019/coding-for-agents.html">agentic development</a> workflows, the volume of first-party code being created and modified is rising rapidly. Yet the process of validating vulnerabilities, determining whether they are exploitable, and fixing them often still depends on developers and security teams working through findings manually.</p>



<p>AWS is aiming to address that imbalance with Continuum, a new service designed to continuously discover, investigate, and remediate vulnerabilities in enterprise environments, whether the code is their own or from third parties.</p>



<p>Rather than simply generating alerts, the service is intended to help enterprises move findings through the entire remediation lifecycle, AWS VP of Security and Observability <a href="https://www.linkedin.com/in/chetkapoor/" target="_blank" rel="noreferrer noopener">Chet Kapoor</a> wrote in a <a href="https://aws.amazon.com/blogs/security/introducing-aws-continuum-security-at-machine-speed/" target="_blank" rel="noreferrer noopener">blog post</a>.</p>



<p>For first-party applications, Continuum can analyze code, validate whether vulnerabilities are exploitable, generate remediation recommendations, and propose fixes that can be reviewed through existing software development workflows, helping developers address security issues without requiring security teams to manually investigate every finding, Kapoor said.</p>



<p>Once users think Continuum has learned enough about their environment and understands their guardrails, they can put it in what AWS calls “enforce mode” to autonomously fix any code lapses, Kapoor said.</p>



<p>Continuum borrows some of its capabilities, penetration testing and code scanning features, from an existing service, Security Agent.</p>



<p>Other capabilities are all-new, including threat modeling, which is designed to automatically generate threat models from source code or design documents and output them in STRIDE format.</p>



<h2 class="wp-block-heading">Keeping pace with AI-driven software development</h2>



<p>Analysts see Continuum helping enterprise developer teams ship more secure code while keeping pace with <a href="https://www.infoworld.com/article/4176534/ai-coding-agents-need-good-software-engineers.html">AI coding tools</a>.</p>



<p>“The harder problem is no longer just finding issues, it is knowing which ones are real, which ones matter in their environment, and which ones need to be fixed first,” said <a href="https://www.hfsresearch.com/team/akshat-tyagi/" target="_blank" rel="noreferrer noopener">Akshat Tyagi</a>, associate practice leader at HFS Research. “Traditional workflows built around dashboards and manual triage struggle with that volume. A dashboard can show the backlog, but it does not validate the finding, assess business impact, or help remediate it.”</p>



<p>Continuum’s value, according to Tyagi, “is not just more detection, but using AI to prioritize risk findings, suggest mitigations, and support faster action while keeping humans in control of high-risk decisions.”</p>



<p>Taking faster action is becoming increasingly important as attackers are gaining access to many of the same AI capabilities that enterprises are using to accelerate software development and security testing, according to <a href="https://www.linkedin.com/in/amitchandak78/" target="_blank" rel="noreferrer noopener">Amit Chandak</a>, chief analytics officer at IT consulting firm Kanerika. “The gap between a flaw being disclosed and a working exploit is shrinking rapidly from months to hours,” he said.</p>



<p>While Continuum may reduce repetitive work for developers and SREs, it could also create new responsibilities for CISOs around governance, oversight, testing, and maintaining guardrails for automated actions.</p>



<p>“Continuum changes the CISO’s role from managing findings to governing how findings are handled. The focus moves to setting rules: what can be automated, what needs human approval, and what level of risk is acceptable in production,” Tyagi said. “Staffing will shift too. There may be less manual triage, but more need for people who can review AI-generated fixes, set guardrails, and know when not to trust the system.”</p>



<p>Even so, Chandak does not expect the offering to lead to immediate headcount reductions, particularly given that Continuum is only available as a gated preview.</p>



<p>Continuum could change how CISOs measure work, Tyagi said: “Ticket count matters less. Better measures are how quickly real risks are validated and fixed, how many false positives are removed, and whether automation is reducing risk without causing new problems.”</p>



<p>Those same metrics could also become a yardstick for CISOs determining how much autonomy to give tools like Continuum, said Chandak. Most enterprises’ data and governance practices are not yet ready for fully autonomous remediation, said Chandak, adding that, “AWS’ graduated trust design, under which enterprises have the option of choosing the degree of autonomy, from human in the loop to fully automatic remediation, is an admission of that fact.”</p>



<h2 class="wp-block-heading">Beyond first-party code</h2>



<p>Continuum could also help CISOs with third-party code vulnerability analysis, where enterprises often have less visibility and control.</p>



<p>“Most third party vulnerability alerts are noise. A tool may flag a vulnerable library, but the real question is whether that vulnerable code is actually used in production. If Continuum can answer that, it helps teams focus on the few issues that matter,” Tyagi said. “This is especially useful for open-source and software supply chain risk, where enterprises depend on packages and hidden transitive dependencies they may not fully track. It also helps when no patch is available yet.”</p>



<p>However, he warned, Continuum might not offer a direct fix to third-party code: “You usually cannot patch third-party code yourself as you don’t own it, so remediation there means version pinning or compensating controls.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Build Buy or Outsource Your SOC: A CISO’s 2026 Decision Framework]]></title>
<description><![CDATA[Build Buy or Outsource Your SOC 

Should you build, buy, or outsource your Security Operations Center? A CISO's practical 2026 decision framework, with the real costs, trade-offs, and a clear decision matrix.]]></description>
<link>https://tsecurity.de/de/3615580/it-security-nachrichten/build-buy-or-outsource-your-soc-a-cisos-2026-decision-framework/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3615580/it-security-nachrichten/build-buy-or-outsource-your-soc-a-cisos-2026-decision-framework/</guid>
<pubDate>Mon, 22 Jun 2026 15:24:24 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Build Buy or Outsource Your SOC 

Should you build, buy, or outsource your Security Operations Center? A CISO's practical 2026 decision framework, with the real costs, trade-offs, and a clear decision matrix.]]></content:encoded>
</item>
<item>
<title><![CDATA[Hexaware holt Sunil Varkey als EVP & CISO für Cybersecurity-Governance]]></title>
<description><![CDATA[CHENNAI / LONDON (IT BOLTWISE) – Hexaware Technologies erweitert sein Security-Leadership-Team: Sunil Varkey übernimmt als EVP und CISO die Verantwortung für Informationssicherheitsstrategie, Governance, Risiko- und Resilience-Programme. Die Berufung des Cybersecurity-Veteranen fällt in eine Phas...]]></description>
<link>https://tsecurity.de/de/3615534/it-security-nachrichten/hexaware-holt-sunil-varkey-als-evp-ciso-fuer-cybersecurity-governance/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3615534/it-security-nachrichten/hexaware-holt-sunil-varkey-als-evp-ciso-fuer-cybersecurity-governance/</guid>
<pubDate>Mon, 22 Jun 2026 15:10:27 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1024" height="1024" src="https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-hexaware-ciso-sunil-varkey-governance.jpg" class="attachment- size- wp-post-image" alt="" decoding="async" srcset="https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-hexaware-ciso-sunil-varkey-governance.jpg 1024w, https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-hexaware-ciso-sunil-varkey-governance-300x300.jpg 300w, https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-hexaware-ciso-sunil-varkey-governance-150x150.jpg 150w, https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-hexaware-ciso-sunil-varkey-governance-768x768.jpg 768w, https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-hexaware-ciso-sunil-varkey-governance-840x840.jpg 840w, https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-hexaware-ciso-sunil-varkey-governance-120x120.jpg 120w" sizes="(max-width: 1024px) 100vw, 1024px">CHENNAI / LONDON (IT BOLTWISE) – Hexaware Technologies erweitert sein Security-Leadership-Team: Sunil Varkey übernimmt als EVP und CISO die Verantwortung für Informationssicherheitsstrategie, Governance, Risiko- und Resilience-Programme. Die Berufung des Cybersecurity-Veteranen fällt in eine Phase, in der Unternehmen ihre digitalen Risiken unter komplexen Hybrid- und Cloud-Umgebungen härter steuern müssen. Für Varkey stehen dabei neben dem GRC-Ansatz […]</p>
<div><a href="https://www.it-boltwise.de/hexaware-holt-sunil-varkey-als-evp-ciso-fuer-cybersecurity-governance.html">... den vollständigen Artikel <strong>»Hexaware holt Sunil Varkey als EVP &amp; CISO für Cybersecurity-Governance«</strong> lesen</a></div>
<p>Dieser Beitrag <a href="https://www.it-boltwise.de/hexaware-holt-sunil-varkey-als-evp-ciso-fuer-cybersecurity-governance.html">Hexaware holt Sunil Varkey als EVP &amp; CISO für Cybersecurity-Governance</a> erschien als erstes auf <a href="https://www.it-boltwise.de/">IT BOLTWISE x Artificial Intelligence</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Sunil Varkey Joins Hexaware Technologies as EVP & CISO]]></title>
<description><![CDATA[Sunil Varkey has been appointed as Executive Vice President (EVP) and Chief Information Security Officer (CISO) at Hexaware Technologies, where he will lead the company's information security strategy, governance, risk management, and enterprise resilience initiatives. The appointment marks the l...]]></description>
<link>https://tsecurity.de/de/3615234/it-security-nachrichten/sunil-varkey-joins-hexaware-technologies-as-evp-ciso/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3615234/it-security-nachrichten/sunil-varkey-joins-hexaware-technologies-as-evp-ciso/</guid>
<pubDate>Mon, 22 Jun 2026 13:05:37 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="960" height="557" src="https://thecyberexpress.com/wp-content/uploads/Sunil-Varkey-Appointment.webp" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="Sunil Varkey" decoding="async" srcset="https://thecyberexpress.com/wp-content/uploads/Sunil-Varkey-Appointment.webp 960w, https://thecyberexpress.com/wp-content/uploads/Sunil-Varkey-Appointment-300x174.webp 300w, https://thecyberexpress.com/wp-content/uploads/Sunil-Varkey-Appointment-768x446.webp 768w, https://thecyberexpress.com/wp-content/uploads/Sunil-Varkey-Appointment-600x348.webp 600w, https://thecyberexpress.com/wp-content/uploads/Sunil-Varkey-Appointment-150x87.webp 150w, https://thecyberexpress.com/wp-content/uploads/Sunil-Varkey-Appointment-750x435.webp 750w, https://thecyberexpress.com/wp-content/uploads/Sunil-Varkey-Appointment.webp 960w, https://thecyberexpress.com/wp-content/uploads/Sunil-Varkey-Appointment-300x174.webp 300w, https://thecyberexpress.com/wp-content/uploads/Sunil-Varkey-Appointment-768x446.webp 768w, https://thecyberexpress.com/wp-content/uploads/Sunil-Varkey-Appointment-600x348.webp 600w, https://thecyberexpress.com/wp-content/uploads/Sunil-Varkey-Appointment-150x87.webp 150w, https://thecyberexpress.com/wp-content/uploads/Sunil-Varkey-Appointment-750x435.webp 750w" sizes="(max-width: 960px) 100vw, 960px" title="Sunil Varkey Joins Hexaware Technologies as EVP &amp; CISO 1"></p>Sunil Varkey has been appointed as Executive Vice President (EVP) and Chief Information Security Officer (CISO) at Hexaware Technologies, where he will lead the company's information security strategy, governance, risk management, and enterprise resilience initiatives. The appointment marks the latest leadership role for the cybersecurity veteran, who brings more than three decades of experience across global enterprises and multiple industry sectors.

Based in Chennai, India, and operating in a hybrid work model, Varkey will be responsible for strengthening enterprise cybersecurity governance, risk management frameworks, and overall security strategy at Hexaware Technologies. His appointment was announced in June 2026.
<h3>Sunil Varkey to Lead Cybersecurity Strategy at Hexaware Technologies</h3>
In his new role, <a href="https://www.linkedin.com/in/sunilvarkey1/" target="_blank" rel="nofollow noopener">Sunil Varkey </a>will oversee key areas including information security governance, <a href="https://thecyberexpress.com/the-global-commerce-vulnerability-window/" target="_blank" rel="noopener">enterprise risk management</a>, and resilience initiatives. His responsibilities align with Hexaware Technologies' broader technology and growth objectives as the company continues to support large-scale digital transformation programs for clients worldwide.

Hexaware Technologies delivers technology-led services across application development, cloud services, automation, <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-data/" title="data" data-wpil-keyword-link="linked" data-wpil-monitor-id="28794">data</a> analytics, and enterprise IT operations. The company serves organizations across multiple industries and supports digital modernization initiatives at scale.

Varkey's appointment comes as organizations continue to focus on strengthening <a class="wpil_keyword_link" href="https://cyble.com/knowledge-hub/what-is-cybersecurity/" target="_blank" rel="noopener" title="cybersecurity" data-wpil-keyword-link="linked" data-wpil-monitor-id="28789">cybersecurity</a> programs and managing digital risks across increasingly complex technology environments.
<h3>More Than 30 Years of Cybersecurity Leadership Experience</h3>
Varkey brings over 30 years of experience in <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-cybersecurity/" title="cybersecurity" data-wpil-keyword-link="linked" data-wpil-monitor-id="28795">cybersecurity</a> leadership spanning banking, telecommunications, IT services, manufacturing, and enterprise technology sectors. His professional experience extends across India, the Middle East, and the United States.

His areas of expertise include cybersecurity <a href="https://thecyberexpress.com/global-grc-platform-market/" target="_blank" rel="noopener">governance, risk and compliance</a> (GRC), security architecture, incident response, DevSecOps, cloud security, privacy management, cyber defense, business continuity management, security operations, and AI security.

Prior to joining Hexaware Technologies, Varkey served as <a class="wpil_keyword_link" href="https://thecyberexpress.com/cyber-news/" title="Cyber" data-wpil-keyword-link="linked" data-wpil-monitor-id="28792">Cyber</a> Security Consultant and Advisor at TAHAKOM in Riyadh, Saudi Arabia, from June 2023 to March 2025. In that role, he worked alongside the organization's <a href="https://thecyberexpress.com/2026-10-technologies-cisos-will-invest-in/" target="_blank" rel="noopener">CISO</a> to enhance cybersecurity resilience and strengthen security posture.

Before TAHAKOM, he held the position of Vice President and Chief Technology Officer for EMEA and APJ at Forescout Technologies Inc. between April 2021 and November 2022. Based in Dubai, he focused on IT/OT security strategy, enterprise cybersecurity advisory services, and product positioning across global markets.
<h3>Leadership Roles Across Global Organizations</h3>
Between March 2020 and January 2021, Varkey served as Managing Director and Global Head of Cyber Security Assessments and Testing at HSBC in Hyderabad. He led a team of approximately 300 professionals responsible for penetration testing, threat modeling, <a class="wpil_keyword_link" href="https://thecyberexpress.com/firewall-daily/vulnerabilities/" title="vulnerability" data-wpil-keyword-link="linked" data-wpil-monitor-id="28790">vulnerability</a> management, and third-party security risk assessments.

Earlier, from December 2018 to February 2020, he worked as CTO and Security Strategist for the Middle East, Africa, and Eastern Europe region at Symantec. His responsibilities included developing cybersecurity strategies for enterprise, government, industrial, and financial sector organizations.

His career also includes senior leadership positions such as Global CISO at Wipro, CISO for Security and <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-privacy/" title="Privacy" data-wpil-keyword-link="linked" data-wpil-monitor-id="28788">Privacy</a> at Idea Cellular, and Vice President of Security Engineering at Barclays. Additionally, he held global security leadership roles at GE Capital, Genpact, Paramount Computer Systems, and other multinational organizations.
<h3>Focus on Governance, Risk Management, and Enterprise Resilience</h3>
Throughout his career, Varkey has overseen cybersecurity functions covering governance, compliance, strategy, security engineering, <a class="wpil_keyword_link" href="https://cyble.com/knowledge-hub/what-is-incident-response/" target="_blank" rel="noopener" title="incident response" data-wpil-keyword-link="linked" data-wpil-monitor-id="28793">incident response</a>, privacy, cloud security, cyber defense, and enterprise resilience.

His experience includes leading security programs for organizations with large-scale user bases and complex operational environments. At Wipro, he served as Global CISO for a technology company supporting more than 200,000 end users. At Idea Cellular, he led security and privacy initiatives for a telecom operator with approximately 120 million subscribers.

With his appointment, Hexaware Technologies adds a cybersecurity leader with extensive experience in building and scaling security programs across global enterprises. The move underscores the company's continued focus on strengthening cybersecurity operations, governance frameworks, and digital <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-risk-management/" title="risk management" data-wpil-keyword-link="linked" data-wpil-monitor-id="28791">risk management</a> capabilities as part of its ongoing technology initiatives.]]></content:encoded>
</item>
<item>
<title><![CDATA[6 security leader tips for mastering business risk]]></title>
<description><![CDATA[Longtime security leader Doug Kersten has expanded his list of responsibilities.



As CISO of software maker Appfire, he now has accountability for business risks, such as how security tools and processes within customer products and services impact their costs and, thus, profitability.



It’s ...]]></description>
<link>https://tsecurity.de/de/3614728/it-security-nachrichten/6-security-leader-tips-for-mastering-business-risk/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3614728/it-security-nachrichten/6-security-leader-tips-for-mastering-business-risk/</guid>
<pubDate>Mon, 22 Jun 2026 09:08:18 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Longtime security leader <a href="https://www.linkedin.com/in/doug-kersten-7437312/">Doug Kersten</a> has expanded his list of responsibilities.</p>



<p>As CISO of software maker Appfire, he now has accountability for business risks, such as how security tools and processes within customer products and services impact their costs and, thus, profitability.</p>



<p>It’s a clearcut example, he says, of where and why CISOs must consider not purely security risk, but also business risk.</p>



<p>“CISOs need to provide input and remediation on the impact of security cost because these often-hidden costs have a negative impact on profitability,” he says. “This is usually overlooked by finance teams when analyzing the true cost of goods sold, and if CISOs are not plugged into the evaluation of business risk, it can easily be dismissed.”</p>



<p>The expansion of Kersten’s remit into business risk isn’t unique. CISOs across industries are increasingly expected to identify and address business risks that in the past had been outside the bounds of their roles.</p>



<p>“While CISOs traditionally focused on protecting systems, networks, and data, today’s business environment requires security leaders to understand how cyber threats impact revenue, operations, customer trust, regulatory obligations, supply chains, and strategic objectives,” says <a href="https://www.linkedin.com/in/dalehoakcyberpro/">Dale Hoak</a>, CISO at software firm RegScale. “The distinction between business risk and security risk is becoming increasingly blurred.”</p>



<p>As such, <a href="https://www.csoonline.com/article/4159317/cisos-reshape-their-roles-as-business-risk-strategists.html">CISOs today must be enterprise risk leaders</a>, he says, capable of advising executives on how security decisions affect the organization’s ability to achieve its business objectives — not just how they impact the IT stack or technology performance.</p>



<p>Understanding business risk is a significant task, experts agree, but they stress that security chiefs are capable of mastering the skill. Here, Kersten, Hoak, and other security leaders offer strategies on how to do so.</p>



<h2 class="wp-block-heading">1. Partner with the owners of business risk</h2>



<p>By his own admission, <a href="https://www.linkedin.com/in/rolandpalmer/">Roland Palmer</a>, CISO and vice president of tech company JumpCloud, has yet to master business risk. So he’s partnering with those in his organization who own it, so he has opportunities to learn and contribute.</p>



<p>“We form a great team to understand risk and the organization’s risk appetite,” he says.</p>



<p>Team members include leaders from legal, finance, and marketing, as well as the COO.</p>



<p>Kersten similarly leans on business leaders to sharpen his understanding of business risk. Last year Kersten, working with his exec colleagues, devised a program assigning business leaders to security risks.</p>



<p>“Security helps them understand the security risks, but they also bring to us the [associated] business risks and what can be done to mitigate them,” he explains, noting that this approach also surfaced risks that have since been addressed, thereby <a href="https://www.csoonline.com/article/4178412/6-critical-security-gaps-every-ciso-must-address.html">closing gaps</a> that were previously unknown.</p>



<h2 class="wp-block-heading">2. Align cybersecurity explicitly to business objectives</h2>



<p>Kerstan believes security teams <a href="https://www.csoonline.com/article/4080670/what-does-aligning-security-to-the-business-really-mean.html">must understand business objectives</a>, so they can understand what risks could derail which objectives. To ensure his security program has that knowledge, he incorporates corporate objectives and key results into his security strategy.</p>



<p>“I build out plans to address those business objectives and key results. I still have that parallel tier of security risk, which is handled by the security team; that doesn’t go away. But layered onto this is the business <a href="https://www.cio.com/article/222203/okr-objectives-and-key-results-defined.html">OKRs</a> that I need to execute against,” he explains. “It changed how we look at risk and what we have to do.”</p>



<p>For example, he now considers how security department actions may impact employee satisfaction and how that relates to employ retention, a business risk identified by HR, “so we’re working to make sure what we do aligns to the needs of the HR department.”</p>



<p><a href="https://www.ey.com/en_us/people/richard-watson" target="_blank" rel="noreferrer noopener">Richard Watson</a>, global cybersecurity leader with professional services firm EY, agrees with the need to “align cybersecurity explicitly to business objectives.”</p>



<p>“Map cyber controls to critical assets and business processes, and link these to potential financial impact,” he advises. “This enables CISOs to translate technical exposure into business terms and prioritize investment accordingly.”</p>



<h2 class="wp-block-heading">3. Lean into networking and relationships</h2>



<p>Another effective way to get a good grasp on business risks: talking with business colleagues. Regular conversations often yield insights into what truly has them worried, says <a href="https://www.linkedin.com/in/ghayslip/">Gary Hayslip</a>, a cybersecurity executive and co-author of the <em>CISO Desk Reference Guide</em>.</p>



<p>“Another thing I have done to understand business risks, and I have recommended it to peers, is doing a walk-about or what some people call a listening tour,” he says. “I do this in every role I am in because I feel it’s important to understand their objectives, the technologies they use, the projects they have ongoing, the issues they may have with the security program, and, finally, what genuinely keeps them up at night.”</p>



<p>Others say they take a similar approach, stressing the value of networking and building relationships where colleagues feel comfortable raising concerns and collaborating on solutions.</p>



<p>“Business risk cannot be managed in isolation. CISOs should regularly engage with the CFO, COO, general counsel, chief risk officer, product leaders, and business unit executives,” Hoak says. “These conversations provide insight into emerging business concerns and help security become part of strategic planning rather than a downstream compliance exercise.”</p>



<h2 class="wp-block-heading">4. Run tabletop exercises focused on business risk</h2>



<p>This is a more structured opportunity, but an equally effective one, to gain more insights into business risks — so long as the exercises put the business front and center, Hayslip says.</p>



<p>“Most <a href="https://www.csoonline.com/article/570871/tabletop-exercises-explained-definition-examples-and-objectives.html">tabletop exercises</a> conducted by the CISO and security teams remain technical and stop at containment. I have found it’s better to run scenarios that force the executives into the decisions they’d actually make during a crisis, such as <a href="https://www.csoonline.com/article/3488842/to-pay-or-not-to-pay-cisos-weigh-in-on-the-ransomware-dilemma.html">whether to pay a ransom</a>, when and what to disclose if there is a data breach, how to handle customers, when and who should invoke legal privilege, and is there an operational fallback available and if so who makes the decision to activate it,” Hayslip says.</p>



<p>“Running these types of scenarios helps stress-test the company’s response and teaches the CISO and security team how their peers make decisions under pressure,” he adds.</p>



<h2 class="wp-block-heading">5. Study up on business risk</h2>



<p><a href="https://www.linkedin.com/in/seanmurphy092009/">Sean Murphy</a>, senior vice president and CISO at BECU, the fifth-largest credit union in the US, didn’t leave learning about business risk to serendipity. He sought out opportunities for formal learning, such as earning the <a href="https://www.nacdonline.org/nacd-credentials/nacd-directorship-certification-credential/certified-directors/">Directorship Certification from the National Association of Corporate Directors</a>. The certification verifies the holder’s expertise in governance, fiduciary duties, strategy, and risk oversight.</p>



<p>Murphy sought the certification to strengthen his <a href="https://www.csoonline.com/article/4168690/what-cisos-need-to-land-a-board-role.html">qualifications for a board position</a> and to better understand the perspectives of his company’s board, including how it views risk. “The certification helps me delve into what the board cares about and their world and helps me then turn that back to my team and what we’re doing,” he adds. “It gives me the business and executive view versus a purely technical and security view.”</p>



<p>Others offer similar learning strategies.</p>



<p>“The CISO needs to see the company the way the CEO, CFO, and board do,” Hayslip says. “To begin, I would recommend sitting down with the 10-K or annual report, the investor deck, and the earnings call transcripts. This will help the CISO understand how the company makes money and which products or business units drive revenue. It also helps the CISO understand what the leadership team is publicly telling the Street about key risks and where they believe revenue growth will come from in the next reporting cycle.”</p>



<p>This work, while perhaps previously not essential for traditional security leaders, is becoming an imperative today.</p>



<p>“This isn’t fun; in fact, it can be boring,” Murphy says. “But the CISO can’t prioritize protecting the business if they don’t know which parts of the business are considered critical. The annual report provides that view in the words of management.”</p>



<p>Veteran security leaders also cite the value of earning <a href="https://www.isaca.org/credentialing/certifications">certifications from ISACA</a>, a professional association for governance and risk professionals, as well as the <a href="https://www.theiia.org/en/certifications/cia/">Institute of Internal Auditors’ Certified Internal Auditor designation</a>.</p>



<h2 class="wp-block-heading">6. Integrate security into enterprise risk management</h2>



<p>To truly master business risk, CISOs should not treat it as separate from security risk.</p>



<p>“Cyber is now an existential business risk, not just an IT risk,” says <a href="https://www.linkedin.com/in/scottmelchior/">Scott Melchior</a>, a member of ISACA’s Emerging Trends Working Group with 20 years of experience at a global consulting firm focusing on governance, risk, and compliance. “Digital infrastructure is business infrastructure. They’re too intertwined to separate.”</p>



<p>Hoak agrees, stressing the need for CISOs to integrate security into <a href="https://www.csoonline.com/article/566417/enterprise-risk-management-erm-putting-cybersecurity-threats-into-a-business-context.html">enterprise risk management</a>.</p>



<p>“Cyber risk should be incorporated into broader enterprise risk management processes alongside financial, operational, legal, and strategic risks. This creates a common framework for evaluating risk and helps executive leadership view cybersecurity within the context of overall business objectives,” he says.</p>



<p>Hayslip has put this into practice. In his CISO roles, he has plugged the security risk register into the organization’s ERM platform. He says this allowed him to present cyber-related risks on the same platform that the board already reviews alongside financial, operational, and strategic risks.</p>



<p>“The goal is for cyber risks to appear on the enterprise heat map as every other material risk, so they compete for resources and attention on equal terms rather than being a sidebar,” Hayslip says. “Now there is some work involved for the CISO to do this correctly, but it’s critically important to quantify cyber risk in dollars and probability, not colors. Moving from qualitative heat maps to financial impact numbers, I have found, is one of the biggest improvements in getting the business to hear the CISO.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Who pays when you gate cyber-capable AI models?]]></title>
<description><![CDATA[In this interview with Help Net Security, Jaya Baloo, COO & CISO at Aisle, examines the debate over restricting access to cyber-capable AI models. She lays out the strongest argument for gating these tools, then explains where it breaks down…
Read more →
The post Who pays when you gate cyber-capa...]]></description>
<link>https://tsecurity.de/de/3614660/it-security-nachrichten/who-pays-when-you-gate-cyber-capable-ai-models/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3614660/it-security-nachrichten/who-pays-when-you-gate-cyber-capable-ai-models/</guid>
<pubDate>Mon, 22 Jun 2026 08:36:24 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>In this interview with Help Net Security, Jaya Baloo, COO &amp; CISO at Aisle, examines the debate over restricting access to cyber-capable AI models. She lays out the strongest argument for gating these tools, then explains where it breaks down…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/who-pays-when-you-gate-cyber-capable-ai-models/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/who-pays-when-you-gate-cyber-capable-ai-models/">Who pays when you gate cyber-capable AI models?</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Who pays when you gate cyber-capable AI models?]]></title>
<description><![CDATA[In this interview with Help Net Security, Jaya Baloo, COO & CISO at Aisle, examines the debate over restricting access to cyber-capable AI models. She lays out the strongest argument for gating these tools, then explains where it breaks down for security teams who depend on the same capabilities ...]]></description>
<link>https://tsecurity.de/de/3614607/it-security-nachrichten/who-pays-when-you-gate-cyber-capable-ai-models/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3614607/it-security-nachrichten/who-pays-when-you-gate-cyber-capable-ai-models/</guid>
<pubDate>Mon, 22 Jun 2026 08:09:10 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>In this interview with Help Net Security, Jaya Baloo, COO &amp; CISO at Aisle, examines the debate over restricting access to cyber-capable AI models. She lays out the strongest argument for gating these tools, then explains where it breaks down for security teams who depend on the same capabilities for defense. Baloo argues that policymakers misread how attackers and defenders operate, that open-weight models cut both ways, and that limiting access can widen the gap … <a href="https://www.helpnetsecurity.com/2026/06/22/jaya-baloo-aisle-gating-cyber-capable-ai-models/" rel="nofollow">More <span class="meta-nav">→</span></a></p>
<p>The post <a href="https://www.helpnetsecurity.com/2026/06/22/jaya-baloo-aisle-gating-cyber-capable-ai-models/">Who pays when you gate cyber-capable AI models?</a> appeared first on <a href="https://www.helpnetsecurity.com/">Help Net Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[What Executives Get Wrong About Incident Response Tabletop Exercises]]></title>
<description><![CDATA[A CISO-level guide to making incident response tabletop exercises useful, realistic, and executive-ready instead of scripted compliance theatre.]]></description>
<link>https://tsecurity.de/de/3613986/it-security-nachrichten/what-executives-get-wrong-about-incident-response-tabletop-exercises/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3613986/it-security-nachrichten/what-executives-get-wrong-about-incident-response-tabletop-exercises/</guid>
<pubDate>Sun, 21 Jun 2026 20:38:19 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A CISO-level guide to making incident response tabletop exercises useful, realistic, and executive-ready instead of scripted compliance theatre.]]></content:encoded>
</item>
<item>
<title><![CDATA[7,000 Langflow servers are under attack. LangGraph and LangChain have the same holes]]></title>
<description><![CDATA[Your AI agent did exactly what it was designed to do. The framework underneath it just handed an attacker a shell on the box that holds your OpenAI key, your database credentials, and your CRM tokens.That is not a hypothetical. In a few months, three of the most widely deployed AI agent framework...]]></description>
<link>https://tsecurity.de/de/3611334/it-nachrichten/7000-langflow-servers-are-under-attack-langgraph-and-langchain-have-the-same-holes/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3611334/it-nachrichten/7000-langflow-servers-are-under-attack-langgraph-and-langchain-have-the-same-holes/</guid>
<pubDate>Fri, 19 Jun 2026 23:31:34 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Your AI agent did exactly what it was designed to do. The framework underneath it just handed an attacker a shell on the box that holds your OpenAI key, your database credentials, and your CRM tokens.</p><p>That is not a hypothetical. In a few months, three of the most widely deployed AI agent frameworks each turned a known, ordinary bug class into a way through. <a href="https://research.checkpoint.com/2026/from-sqli-to-rce-exploiting-langgraphs-checkpointer/">Check Point Research</a> chained a SQL injection in LangGraph’s SQLite checkpointer to full remote code execution. Tenable and VulnCheck tracked a path traversal in Langflow’s file upload endpoint to active, in-the-wild RCE. <a href="https://www.cyera.com/research/langdrained-3-paths-to-your-data-through-the-worlds-most-popular-ai-framework">Cyera</a> documented a path traversal in LangChain-core’s prompt loader that reads your secrets off disk. Two paths to a shell, one to your keys. They are the same bug, wearing three frameworks.</p><p>These frameworks became production infrastructure faster than anyone secured them. They store agent state, take file uploads, load prompt configs, and hold the credentials to databases, CRMs, and internal APIs. The edge tools watch traffic. The endpoint tools watch processes. Neither was built to treat an imported framework as a boundary worth guarding, and that blind spot is exactly where all three chains live, widening every week as these frameworks ship to production.</p><h2><b>The LangGraph chain, SQL injection to a Python shell</b></h2><p>Start with the one most teams pulled into production this quarter. LangGraph gives AI agents memory through checkpointers, the persistence layer that stores execution state. It has cleared over 50 million downloads a month. Yarden Porat of Check Point Research took that layer apart and found three vulnerabilities. Two of them chain to RCE.</p><p><a href="https://advisories.gitlab.com/pypi/langgraph-checkpoint-sqlite/CVE-2025-67644/">CVE-2025-67644</a>, rated CVSS 7.3, is a SQL injection in the SQLite checkpointer. The function that builds the WHERE clause for checkpoint lookups drops user-controlled filter keys straight into the query with no parameterization and no escaping. This does not hit everyone, but where it hits, it is serious. A deployment is exposed when it self-hosts LangGraph on the SQLite or Redis checkpointer and lets untrusted input reach get_state_history() or a similar history endpoint. Meet those conditions, and an attacker who controls the filter writes a fabricated row straight into the checkpoint table. Run LangChain’s managed LangSmith platform on PostgreSQL, and the exposure is gone.</p><p>Then <a href="https://advisories.gitlab.com/pypi/langgraph/CVE-2026-28277/">CVE-2026-28277</a>, CVSS 6.8, finishes the job. LangGraph’s msgpack checkpoint decoder rebuilds Python objects from the stored data, which lets it import a module and call a named function with attacker-supplied arguments. That step needs write access to the checkpoint store; the SQL injection is what grants it remotely. LangGraph loads the forged row as a legitimate checkpoint, the decoder runs the specified function, including os.system, and code executes under the identity of the agent server. A third issue, CVE-2026-27022, CVSS 6.5, reaches the same place through the Redis checkpointer.</p><p>There has been no confirmed exploitation in the wild yet. A working proof-of-concept is public in Check Point’s disclosure. The fixes are version bumps: langgraph-checkpoint-sqlite to 3.0.1, langgraph to 1.0.10, and langgraph-checkpoint-redis to 1.0.2.</p><h2><b>The Langflow chain, one unauthenticated request to RCE</b></h2><p>Langflow is the one already under attack. CVE-2026-5027, CVSS 8.8, is a path traversal in the POST /api/v2/files endpoint, which takes the filename straight from the form data and writes it to disk unsanitized. An attacker packs that filename with traversal sequences and drops a file anywhere, such as a cron job in /etc/cron.d/. Because Langflow ships with auto-login enabled in its default configuration, an exposed instance needs no credentials at all. A single unauthenticated request reaches the endpoint, and the next cron run hands over a shell.</p><p>VulnCheck’s Caitlin Condon confirmed exploitation on June 9: “Our Canaries observed exploitation of CVE-2026-5027 that successfully leveraged the path traversal to write what appear to be test files on victim systems.” Censys put roughly 7,000 exposed instances on the internet, most in North America. This is the third Langflow flaw to draw active exploitation this year, after <a href="https://www.probablypwned.com/article/langflow-cve-2025-34291-muddywater-account-takeover-rce">CVE-2025-34291</a>, which the Iranian state-sponsored group MuddyWater weaponized and which CISA added to its <a href="https://thehackernews.com/2026/05/cisa-adds-exploited-langflow-and-trend.html">Known Exploited Vulnerabilities catalog</a> in May. CVE-2026-5027 itself was patched in version 1.9.0, released April 15.</p><p>The timeline is what sets the clock. The patch shipped April 15. Attacks started in June, and <a href="https://www.thestack.technology/langflow-instances-are-getting-exploited-again/">VulnCheck added CVE-2026-5027 to its exploited-vulnerabilities list June 8</a> once its sensors caught the first in-the-wild hits. Every instance left unpatched between those two dates has been sitting in the open for almost two months. The lesson for security teams is to start the patch clock at disclosure, not at a federal catalog entry.</p><h2><b>The LangChain-core gap, arbitrary file reads through the prompt loader</b></h2><p>LangChain-core, the foundation under both, disclosed <a href="https://thehackernews.com/2026/03/langchain-langgraph-flaws-expose-files.html">CVE-2026-34070</a>, CVSS 7.5, a path traversal in its legacy prompt-loading API. The load_prompt() functions read a file path out of a config dict with no check against traversal sequences or absolute paths, so an attacker who influences that path reads arbitrary files the process can reach, including the .env file holding OPENAI_API_KEY and ANTHROPIC_API_KEY. Cyera paired it with CVE-2025-68664, CVSS 9.3, a deserialization flaw that resolves environment secrets through a crafted object. The fix versions differ, which matters when you patch: CVE-2026-34070 lands in <a href="https://security.snyk.io/vuln/SNYK-PYTHON-LANGCHAINCORE-15809257">langchain-core 1.2.22 and 0.3.86</a>; CVE-2025-68664 lands earlier in <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-68664">1.2.5 and 0.3.81</a>. Clear both, or the higher-severity flaw stays live behind a patched one.</p><p>Three frameworks, three classic AppSec bugs. Path traversal. SQL injection. Unsafe deserialization. Nothing exotic, nothing AI-specific, just old vulnerabilities living inside new infrastructure. None of this is a frontier-model problem. It is plumbing, sitting in the layer where AI meets the enterprise.</p><h2><b>Why the scanner cannot see it</b></h2><p>Merritt Baer, CSO at <a href="https://www.enkryptai.com/">Enkrypt AI</a> and former deputy CISO at AWS, has named what makes this kind of failure hard to see coming. It does not announce itself as an AI problem. "CISOs will experience MCP insecurity not in the abstract, but when an employee pastes sensitive data into a tool, or when an attacker finds an unauthenticated MCP server in your cloud," Baer told VentureBeat. "It won't feel like 'AI risk.' It will feel like your traditional security program failing." The framework chains here are the same shape. An exposed Langflow instance is an unauthenticated server in your cloud, and the alert, if one fires, reads like an ordinary incident.</p><p>That is the gap in one sentence. The exploit lives in the framework your code imports. The WAF never sees a msgpack decoder running three layers down. The EDR watches the agent server make the same process calls it makes a thousand times a day and waves it through. Both tools are doing their job. Nobody scoped the framework itself as the thing that could turn on you. </p><p>The root cause is older than AI, and Baer names it. “MCP is shipping with the same mistake we’ve seen in every major protocol rollout: insecure defaults,” she told VentureBeat. “If we don’t build authentication and least privilege in from day one, we’ll be cleaning up breaches for the next decade.” Langflow’s auto-login is that mistake shipped. LangChain-core’s unguarded prompt loader is that mistake shipped. The convenient default is the vulnerability. And the moment an agent connects to anything, that risk compounds. “You’re not just trusting your own security, you’re inheriting the hygiene of every tool, every credential, every developer in that chain,” Baer said. “That’s a supply chain risk in real time.”</p><p>There is a governance failure layered on top of the technical one, and it is the same miscategorization Assaf Keren, chief security officer at Qualtrics and former CISO at PayPal, has flagged in adjacent tooling. “Most security teams still classify experience management platforms as ‘survey tools,’ which sit in the same risk tier as a project management app,” Keren told VentureBeat. “This is a massive miscategorization.” Swap in AI agent frameworks, and it still holds. Teams file LangGraph, Langflow, and LangChain under developer convenience, then wire them into databases, CRMs, and provider keys. “Security has to be an enabler,” Keren said, “or teams route around it.” These frameworks are what routing around it looks like.</p><p>Follow the money and it points at the same layer. On its <a href="https://www.fool.com/earnings/call-transcripts/2026/06/03/crowdstrike-crwd-q1-2027-earnings-transcript/">Q1 fiscal 2027 earnings call</a>, CrowdStrike reported its AI detection and response line up more than 250% sequentially, and on June 17 it <a href="https://www.crowdstrike.com/en-us/press-releases/crowdstrike-advances-ai-and-cloud-security-operations-on-aws/">extended that runtime coverage</a> to agent, LLM, and MCP traffic on AWS. George Kurtz, the company’s co-founder and CEO, named the reason in plain terms: “Agents run on the endpoint. They make tool calls, access files, invoke APIs, and move data at the process level.” That is the exact plumbing these chains abuse, and real money is now moving to the layer your AppSec scan skips.</p><h2><b>What to put in front of the board</b></h2><p>The board does not need the CVE numbers. It needs the consequence, and Keren draws the line the board cares about. Most teams have mapped the technical blast radius. “But not the business blast radius,” Keren told VentureBeat. “When an AI engine triggers a compensation adjustment based on poisoned data, the damage is not a security incident. It is a wrong business decision executed at machine speed.” A framework RCE is the same problem one layer earlier. The agent does not just leak a credential; it acts on production systems with it, and the business sees an outcome no one can explain.</p><p>So frame it the way a board frames it: we run AI agent frameworks in production that can be turned into remote shells through bugs our scanners are not built to find, all three are patched, one is under active attack, and here is the date every instance is verified and closed. None of this required custom malware or a zero-day.</p><h2><b>The six-question checklist</b></h2><p>Six trust boundaries, one per row, each with the question, the proof point, the command, the fix, and the board line. Run it tonight.</p><table><tbody><tr><td><p><b>Trust-Boundary Question</b></p></td><td><p><b>Proof Point</b></p></td><td><p><b>What Broke</b></p></td><td><p><b>Verify Before You Install</b></p></td><td><p><b>The Fix</b></p></td><td><p><b>Board Language</b></p></td></tr><tr><td><p><b>1. Can the agent's state store be poisoned with code?</b></p></td><td><p>LangGraph SQLi-to-RCE chain. CVE-2025-67644 (CVSS 7.3) chains into CVE-2026-28277 (CVSS 6.8). PoC public, no in-the-wild use yet.</p></td><td><p>Filter keys interpolated into SQL with an f-string. Forged checkpoint row hits the msgpack decoder, which imports and runs an attacker-named callable.</p></td><td><p>pip show langgraph-checkpoint-sqlite. Below 3.0.1 = vulnerable. Confirm get_state_history() is not exposed to network input.</p></td><td><p>Upgrade langgraph-checkpoint-sqlite to 3.0.1, langgraph to 1.0.10, langgraph-checkpoint-redis to 1.0.2.</p></td><td><p>“Our agent memory layer can be tricked into running attacker code. Vendor has patched it. We are upgrading and confirming the endpoint is not exposed.”</p></td></tr><tr><td><p><b>2. Can an unauthenticated request write a file to our agent server?</b></p></td><td><p>Langflow CVE-2026-5027 (CVSS 8.8). On VulnCheck KEV (June 8). Active exploitation confirmed June 9. ~7,000 exposed instances (Censys).</p></td><td><p>Path traversal in POST /api/v2/files. Filename unsanitized. Auto-login on by default. Two HTTP calls drop a cron job and earn a shell.</p></td><td><p>Query Censys or Shodan for your Langflow, Flowise, n8n, and Dify instances on the perimeter. Check whether auto-login is enabled.</p></td><td><p>Upgrade Langflow to 1.9.0+. Disable auto-login. Pull AI dev tools behind VPN or zero-trust. Isolate port 7860.</p></td><td><p>“Our AI dev tools are reachable from the internet with login off. This exact flaw is under active attack now. We are pulling them behind access controls today.”</p></td></tr><tr><td><p><b>3. Can our prompt loader read files it should never touch?</b></p></td><td><p>LangChain-core CVE-2026-34070 (CVSS 7.5), path traversal in the prompt-loading API. Paired with deserialization CVE-2025-68664 (CVSS 9.3).</p></td><td><p>load_prompt() reads a config-supplied path with no traversal check, returning files such as the .env holding OPENAI_API_KEY and ANTHROPIC_API_KEY.</p></td><td><p>pip show langchain-core. Below 1.2.22 (1.x) or 0.3.86 (0.x) = vulnerable. Audit any code passing user-influenced paths to load_prompt().</p></td><td><p>Upgrade langchain-core past both fixes: 1.2.22 / 0.3.86 (CVE-2026-34070) and 1.2.5 / 0.3.81 (CVE-2025-68664). Replace load_prompt() with an allowlisted directory. Run as non-root.</p></td><td><p>“Our prompt system could be steered to read our API keys off disk. We are patching and removing the legacy loader.”</p></td></tr><tr><td><p><b>4. Does a compromised framework hand over every credential at once?</b></p></td><td><p>These frameworks are often deployed with provider keys, database credentials, and integration tokens available to the process environment. Cyera documents the credential-exfiltration path.</p></td><td><p>One RCE on the agent server exposes every secret the process can read. Blast radius is the full credential set, not one app.</p></td><td><p>Inventory which secrets each framework process can reach. Confirm keys come from a secrets manager, not static .env files.</p></td><td><p>Move provider keys to ephemeral injection. Rotate any key a vulnerable instance could have read. Scope each key to least privilege.</p></td><td><p>“A single break in one AI framework exposes the keys to every model and data store it touches. We are rotating and scoping them now.”</p></td></tr><tr><td><p><b>5. Are these frameworks running outside security governance?</b></p></td><td><p>A prior Langflow flaw, CVE-2025-34291, was weaponized by Iranian-linked MuddyWater and added to CISA KEV in May. Shadow AI is the new shadow IT.</p></td><td><p>Teams stand frameworks up for speed, give them credentials, and never bring them under review. The security team cannot see what it does not know exists.</p></td><td><p>Run a discovery sweep for AI frameworks outside change management. Map each to an owner and an approval record.</p></td><td><p>Assign every framework a documented owner and a place in the approval process. Offer a sanctioned alternative so teams do not route around you.</p></td><td><p>“We have AI frameworks in production that no one formally approved. We are bringing them under governance, not banning them.”</p></td></tr><tr><td><p><b>6. Can our scanners even see inside the framework at runtime?</b></p></td><td><p>Runtime detection is forming around this layer: CrowdStrike Falcon AIDR expanded to AWS June 17 (Bedrock, Kiro, Strands); its <a href="https://www.crowdstrike.com/en-us/press-releases/crowdstrike-expands-project-quiltworks-with-aws-hardening-the-cloud-attack-surface-against-frontier-ai-risk/">QuiltWorks coalition</a> now covers cloud workloads.</p></td><td><p>WAF reads HTTP at the edge. EDR watches the endpoint. By default, neither reliably models a msgpack decoder or a prompt loader three layers down in an imported framework as a separate trust boundary.</p></td><td><p>Test whether your AppSec scan covers third-party framework internals. Track CVEs by dependency, not just by what your edge tools can parse.</p></td><td><p>Add framework dependencies to vuln management. Treat agent output and stored state as untrusted. Patch on disclosure, not on KEV listing.</p></td><td><p>“Our scanners check our code, not the frameworks our code imports. We are closing that blind spot and patching on disclosure, not waiting for the federal catalog.”</p></td></tr></tbody></table><p><i>How to read this table: each row is one trust boundary, left to right, from the question to ask to the line to read your board.</i></p><h2><b>Give the board the deadline, not the technology</b></h2><p>The fixes are not a re-architecture. They are version bumps and config changes you can land this week. The exposure is the gap between the day the patch shipped and the day your team runs the checks, and right now that gap is measured in months. The frameworks did exactly what they were built to do. </p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The Department of Know: SearchLeak, Check Point zero-day, and pulling the plug on Fable]]></title>
<description><![CDATA[This week’s Department of Know is hosted by Rich Stroffolino, with guests Arif Hameed, CISO, C&R Software; Adam Palmer, CISO, First Hawaiian Bank; Jon Collins, Field CTO, GigaOm; and Jack Leidecker, EVP, CSO, Gainsight. Huge thanks to our sponsor, ThreatLocker Every…
Read more →
The post The Depa...]]></description>
<link>https://tsecurity.de/de/3611276/it-security-nachrichten/the-department-of-know-searchleak-check-point-zero-day-and-pulling-the-plug-on-fable/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3611276/it-security-nachrichten/the-department-of-know-searchleak-check-point-zero-day-and-pulling-the-plug-on-fable/</guid>
<pubDate>Fri, 19 Jun 2026 22:36:13 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>This week’s Department of Know is hosted by Rich Stroffolino, with guests Arif Hameed, CISO, C&amp;R Software; Adam Palmer, CISO, First Hawaiian Bank; Jon Collins, Field CTO, GigaOm; and Jack Leidecker, EVP, CSO, Gainsight. Huge thanks to our sponsor, ThreatLocker Every…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/the-department-of-know-searchleak-check-point-zero-day-and-pulling-the-plug-on-fable/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/the-department-of-know-searchleak-check-point-zero-day-and-pulling-the-plug-on-fable/">The Department of Know: SearchLeak, Check Point zero-day, and pulling the plug on Fable</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CIOs: tear down the wall between resilience and data security]]></title>
<description><![CDATA[For years, resilience and data security operated in separate organizational silos. The resilience team focused on keeping systems running, while the security team focused on keeping data safe. They attended different briefings, reported through different chains of command, and, in most enterprise...]]></description>
<link>https://tsecurity.de/de/3609969/it-security-nachrichten/cios-tear-down-the-wall-between-resilience-and-data-security/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3609969/it-security-nachrichten/cios-tear-down-the-wall-between-resilience-and-data-security/</guid>
<pubDate>Fri, 19 Jun 2026 12:08:23 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>For years, resilience and data security operated in separate <a href="https://www.cio.com/article/4176051/8-it-modernization-traps-cios-must-avoid.html?utm=hybrid_search">organizational silos</a>. The resilience team focused on keeping systems running, while the security team focused on keeping data safe. They attended different briefings, reported through different chains of command, and, in most enterprises, barely spoke to each other. AI is making that model no longer viable.</p>



<p>Steve MacIntyre, SVP and product lead for data security and analytics, and cloud security at Fidelity Investments, and Wim Geurden, EY’s chief architect of enterprise technology, are two IT executives who manage some of the most complex data environments. Both recently spoke at the VeeamON event in New York and put great emphasis on how the convergence of resilience and data security is no longer a future trend but an immediate operational necessity, driven, accelerated, and exposed by AI.</p>



<h2 class="wp-block-heading">AI didn’t create the problem — it revealed it</h2>



<p>AI isn’t introducing new security vulnerabilities so much as it’s making long-ignored ones glaringly visible. “We gave out a few licenses for Copilot, and two days in, someone from the legal team I work with said we have an AI problem,” said MacIntyre about Fidelity’s early Microsoft 365 Copilot pilot. Another member of his team did a search and said AI found all the PowerPoints that were on SharePoint he used about four jobs ago. So it wasn’t an AI problem. “AI just searches everything you have access to and surfaces it in a meaningful way,” said MacIntyre. “Everybody thinks they have an AI problem, but what it shows is areas that must improve.”</p>



<p>Geurden encountered the same phenomenon at EY. “We found it about six months before Copilot was launched,” he said. “All kinds of data started surfacing in every location.” EY’s first response was to shut down unlicensed AI access entirely. “There was no lifecycle management and we didn’t know when sites were last accessed,” he added. The next phase involved using AI to label and classify the vast repositories of unstructured data EY had accumulated over decades, because, he said, it’s unfathomable that humans do it. “Especially with turnover every four years, you can’t keep training people at a 400,000-employee scale,” he continued.</p>



<p>The implication for CIOs is if you haven’t audited your unstructured data, you already have an AI security problem. You just need to turn on the tool that will expose it.</p>



<h2 class="wp-block-heading">The threat is moving at AI speed</h2>



<p>The urgency isn’t a hypothetical one. A recent <a href="https://www.bcg.com/publications/2025/ai-creates-cyber-risks-can-resolve-them" rel="nofollow">BCG CISO survey</a> found that half of cyberattacks over the past six months involved non-human identities, meaning adversaries are already deploying AI agents to conduct attacks. The same survey found that nearly half of business-sponsored AI projects resulted in unintended data leakage. These aren’t shadow IT experiments but sanctioned and approved deployments that leaked data because the <a href="https://www.cio.com/article/4128980/the-struggle-for-good-ai-governance-is-real.html?utm=hybrid_search">underlying governance</a> and access controls weren’t in place before the AI was turned on.</p>



<p>The problem is likely to worsen before it improves. Another study, this time by <a href="https://zkresearch.com/" rel="nofollow">ZK Research</a>, found that 65% of respondents believe <a href="https://www.cio.com/article/4146658/autonomous-ai-adoption-is-on-the-rise-but-its-risky.html?utm=hybrid_search">AI adoption</a> is outpacing their ability to govern it. Additionally, 89% of decision makers expressed concern about AI agents inheriting excessive access, underscoring a critical risk to data integrity and security. All these data point to a world where AI creates a fundamentally new operating model, where companies need to rethink how they address the risks and why the traditional separation between resilience and security must end.</p>



<p>Resilience without data governance means you can recover your systems, but not trust the data within them. Security without resilience planning means your controls may be sound on Tuesday, but nonexistent after a Wednesday incident. The organizations getting this right treat data as a first-class asset with its own governance lifecycle, rather than an afterthought attached to applications.</p>



<h2 class="wp-block-heading">Three governing principles</h2>



<p>Based on what MacIntyre and Geurden say, here are three concrete principles for CIOs to build integrated resilience and a strong security posture for the AI era.</p>



<p><strong>Know what you have before you deploy what you want. </strong>“Get a handle on what’s actually important for the business and the use cases, and then get a handle on your data,” said MacIntyre. “If you can marry those two, you can make risk-based decisions on where to apply the work.” This means completing a data asset inventory — not just a list of systems, but a clear understanding of where data resides, who owns it, who has access, and whether that access has been reviewed. At Fidelity, this means tying AI use cases to approved projects so every agent or model deployment is matched to a registered business need. This is easier said than done, however, as the data within most organizations is messy. But getting a handle on data is a mandatory step toward AI success.</p>



<p><strong>Build governance that moves at the speed of the threat.</strong> MacIntyre also acknowledged that <a href="https://www.cio.com/article/3984527/how-to-establish-an-effective-ai-grc-framework.html?utm=hybrid_search">GRC</a> has historically been a slow, human-driven process, and AI is breaking that model. “They’re trying to figure out how to build automation, how to use AI to help the GRC function get aligned to this, because it’s moving at light speed,” he said. The answer isn’t simply to hire more compliance staff, but automate the monitoring, labeling, and control verification functions that humans can’t perform at AI scale.</p>



<p><strong>Solve the agent identity problem now before regulators force you to.</strong> Both MacIntyre and Geurden flagged AI agent identity as one of the most unresolved and most consequential challenges in enterprise AI governance. Geurden described agents triggering <a href="https://www.cio.com/article/4143424/what-happens-if-saps-s-4hana-roadmap-doesnt-suit.html?utm=hybrid_search">unexpected SAP licensing costs</a> as a first signal. MacIntyre raised the regulatory stakes in that he needs to be able to go backward. “I need to be able to say an agent took that action on that data set because a customer asked it to do it,” he said. That audit trail, from human intent to agent action to data record, doesn’t yet exist cleanly in most enterprises. And building it isn’t optional. In financial services and regulated industries, it’s a matter of when not if regulators demand it.</p>



<h2 class="wp-block-heading">The cloud journey was a preview</h2>



<p>MacIntyre offered a useful frame for the CIO community in that the AI governance challenge is structurally similar to the cloud transition, and enterprises that went through that migration have hard-won lessons that apply now. “When the explosion of AI happened, it didn’t just affect security and the attackers,” he said. “It also impacted the business, increasing velocity, and the ability to innovate and move faster. So we have to be there and be able to safely enable that for them.”</p>



<p>The instinct to block AI entirely will fail, just as blocking cloud adoption failed a decade ago. Business units will find workarounds. The job of the CIO and CISO, therefore, is to channel that velocity through governed, instrumented, and recoverable infrastructure.</p>



<p>Geurden’s framing from EY’s audit practice added a useful warning about overconfidence. Three years ago, the firm tested whether AI could pass the CPA exam. It could, easily, but the team quickly discovered that for complex professional judgment questions, the model assigned roughly equal probability to multiple answers. “At which point, you can’t build a control structure because you have to check everything it does,” he said. That discovery slowed EY’s AI rollout in the audit practice and arguably saved them from a much larger exposure. The lesson is that capability and trustworthiness aren’t the same thing, and closing that gap requires exactly the kind of integrated data governance and resilience architecture that most enterprises have yet to build.</p>



<p>AI has knocked down the wall between resilience and security, and CIOs who rebuild it will spend the next three years reacting to incidents. But those who build a unified data trust architecture will be the ones empowering the business to move fast with confidence, and that’s a position all CIOs should strive to be in.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[The Invisible CEO of Crisis: Breaking the Cycle of CISO Burnout]]></title>
<description><![CDATA[When a major cyber incident hits, all eyes are on the CISO. They become the invisible CEO of crisis, steering the entire enterprise through the storm, managing stakeholders and making major decisions under immense pressure. The clock is ticking. Every…
Read more →
The post The Invisible CEO of Cr...]]></description>
<link>https://tsecurity.de/de/3609741/it-security-nachrichten/the-invisible-ceo-of-crisis-breaking-the-cycle-of-ciso-burnout/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3609741/it-security-nachrichten/the-invisible-ceo-of-crisis-breaking-the-cycle-of-ciso-burnout/</guid>
<pubDate>Fri, 19 Jun 2026 10:37:13 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>When a major cyber incident hits, all eyes are on the CISO. They become the invisible CEO of crisis, steering the entire enterprise through the storm, managing stakeholders and making major decisions under immense pressure. The clock is ticking. Every…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/the-invisible-ceo-of-crisis-breaking-the-cycle-of-ciso-burnout/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/the-invisible-ceo-of-crisis-breaking-the-cycle-of-ciso-burnout/">The Invisible CEO of Crisis: Breaking the Cycle of CISO Burnout</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Oracle releases 245 new security patches, all rated ‘high-priority security’]]></title>
<description><![CDATA[The Oracle Critical Security Patch update (CSPU) released this week contains 245 newly-announced fixes for supported on-premises software, some of which impact multiple products. It is in reaction to an industry trend to announce and fix security holes much more quickly, and complements Oracle’s ...]]></description>
<link>https://tsecurity.de/de/3609211/it-security-nachrichten/oracle-releases-245-new-security-patches-all-rated-high-priority-security/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3609211/it-security-nachrichten/oracle-releases-245-new-security-patches-all-rated-high-priority-security/</guid>
<pubDate>Fri, 19 Jun 2026 03:59:36 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>The Oracle Critical Security Patch update (CSPU) released this week contains 245 newly-announced fixes for supported on-premises software, some of which impact multiple products. It is in reaction to <a href="https://www.cio.com/article/4167337/oracle-will-patch-more-often-to-counter-ai-cybersecurity-threat-2.html" target="_blank">an industry trend to announce and fix security holes much more quickly</a>, and complements Oracle’s traditional quarterly patch schedule. </p>



<p><a href="https://www.oracle.com/security-alerts/cspujun2026.html" target="_blank" rel="noreferrer noopener">The current batch of patches</a> affects a wide range of products, including Oracle Enterprise Manager, JD Edwards, Fusion Middleware, MySQL, Peoplesoft, and others.</p>



<p>Oracle said its aim is to provide targeted, high-priority security fixes in a smaller, more focused format, making them easier to apply with minimal disruption. “Oracle conducts an analysis of each security vulnerability addressed by a Critical Security Patch Update,” the company said. “Oracle provides this information so that customers may conduct their own risk analysis based on the particulars of their product usage.”</p>



<p><a href="https://www.linkedin.com/in/fvillanustre/" target="_blank" rel="noreferrer noopener">Flavio Villanustre</a>, CISO for LexisNexis Risk Solutions, said that although they’re all designated high priority, he viewed some of the patches as more concerning. </p>



<p>“The PeopleSoft patch for CVE-2026-35273 stands out [because] it addresses a critical remote code execution vulnerability in Oracle PeopleSoft, which is widely exploited in the wild. This patch was released as an out-of-band Security Alert and requires immediate remediation,” Villanustre said. </p>



<p>“But not far behind, there are the patches to Oracle Fusion, which received a hundred or so patches with more than half classified as remote exploits without authentication. These affect components such as WebLogic Server.”</p>



<p>Some of those patches were for Oracle Fusion Middleware products, a number which are <a href="https://www.oracle.com/a/ocom/docs/middleware/fusion-middleware-statement-of-direction.pdf" target="_blank" rel="noreferrer noopener">reaching end of support from Oracle by the end of the year.</a> Villanustre, however, did not see the many security holes identified within them as especially concerning. </p>



<p>He pointed out, “Oracle offers extended support for [Fusion Middleware] until December 2027 for those with the appetite to pay more money in lieu of upgrading, so it will still be supported for 18 more months, starting now.” </p>



<p><a href="https://greyhoundresearch.com/svg/" target="_blank" rel="noreferrer noopener">Sanchit Vir Gogia</a>, chief analyst at Greyhound Research, said that the significance of the Oracle announcement is not in the very large number of patches but in their scope.</p>



<p>“The figure worth watching is not the 245 patches but where they land,” he noted. “Of the 245 fixes, 106 sit in Fusion Middleware and 53 of those can be reached remotely without authentication. That is not patch hygiene. That is a control-plane problem.”</p>



<p>The most serious flaws, however, are not those with the highest severity scores. “They are the ones that combine remote reach, absent authentication and privileged placement in layers that other systems are built to trust,” he said. </p>



<p>“WebLogic Server carries two such issues at the maximum severity, on a product attackers have scanned for and targeted for years,” he noted. “Oracle Coherence carries another, and Coherence is a shared component, so its risk multiplies quietly across the estate. Oracle Unified Directory can be taken over without authentication over LDAP. WebCenter sits at the public edge. Several of these flaws change scope, meaning one compromise can reach products well beyond the one first breached.”</p>



<p><a href="https://www.linkedin.com/in/christopherddoyle/" target="_blank" rel="noreferrer noopener">Chris Doyle</a>, the head of security and compliance at JupiterOne, said that, like Gogia, the vulnerabilities that concerned him the most were those that could be executed without having to bother to steal credentials.</p>



<p>“The flaws that stand out the most are the CVSS 10.0 vulnerabilities in Oracle Coherence and WebLogic Server, remotely exploitable with no authentication required. Coherence sits underneath a lot of enterprise application stacks, so compromising it isn’t just one system, it’s a pivot point into everything that depends on it,” Doyle said. </p>



<p>And, he added, “WebLogic has been a ransomware and crypto mining target for years and unauthenticated console access is exactly the foothold those campaigns look for.”</p>



<p>Doyle said he was also worried about the PeopleSoft holes.</p>



<p>“The one carrying the most immediate urgency is CVE-2026-35273 in PeopleSoft PeopleTools, which Oracle confirmed was already being actively exploited before this patch even shipped, and PeopleSoft runs the HR, finance, and student systems that ransomware operators specifically target,” Doyle said. “These are deeply coupled systems that require coordinated upgrades across multiple layers with regression testing at each step. There’s often no easy compensating control to buy time, you just have to patch your way through it.”</p>



<p>The Fusion Middleware problems — Oracle cited more than 30 vulnerabilities in this batch alone — also presented a problem, given how most enterprise IT operations handle patching for EOL products.</p>



<p>“Organizations still on it are now trying to patch a heavily targeted product while simultaneously planning a migration they can’t defer. These environments are heavily customized, which makes patching slow, and that gap between ‘patch available’ and ‘patch applied’ is exactly when attackers move,” Doyle said. </p>



<p>“Once support ends, new vulnerabilities may get no patch at all,” he noted. “Given the volume we’re seeing in just this one cycle, assuming things will quiet down before the sunset deadline isn’t a bet I’d want to make.”</p>



<p>Gogia added that there is little good news associated with the security holes that have not been confirmed as having been used by attackers. </p>



<p>“The absence of confirmed exploitation elsewhere is no comfort. Once an advisory is published, attackers read it, reverse the fix, scan the exposed enterprise environments and race the customers still waiting on a maintenance window,” Gogia said. </p>



<p>“WebLogic has not suddenly become dangerous. It has been a standing target for years, and one of its earlier flaws already sits on the [<a href="https://www.cisa.gov/resources-tools/resources/kev-catalog" target="_blank" rel="noreferrer noopener">Known Exploited Vulnerabilities] government catalogue</a>. Waiting for public proof of exploitation is the most expensive patch strategy on the menu. By the time the proof arrives, the quiet work is generally done.”</p>



<p></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Copilot searched your mailbox. LiteLLM handed out admin keys. Run this 5-check audit before your stack is next]]></title>
<description><![CDATA[Two AI tools broke in the same way in the same two weeks, and four research teams proved it. The pattern underneath every disclosure is one sentence: enterprise AI accepts external input with no trust boundary. On June 15, Varonis disclosed SearchLeak (CVE-2026-42824), a proof-of-concept exfiltra...]]></description>
<link>https://tsecurity.de/de/3608646/it-nachrichten/copilot-searched-your-mailbox-litellm-handed-out-admin-keys-run-this-5-check-audit-before-your-stack-is-next/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3608646/it-nachrichten/copilot-searched-your-mailbox-litellm-handed-out-admin-keys-run-this-5-check-audit-before-your-stack-is-next/</guid>
<pubDate>Thu, 18 Jun 2026 20:16:46 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Two AI tools broke in the same way in the same two weeks, and four research teams proved it. The pattern underneath every disclosure is one sentence: enterprise AI accepts external input with no trust boundary. </p><p>On June 15, Varonis disclosed <a href="https://www.varonis.com/blog/searchleak">SearchLeak (CVE-2026-42824)</a>, a proof-of-concept exfiltration chain in Microsoft 365 Copilot Enterprise Search. A victim clicks a crafted microsoft.com URL, Copilot searches their mailbox, and the data leaves through a Bing SSRF. No plugins, no second click, no visible indicator. Four days earlier, Obsidian Security published a <a href="https://www.obsidiansecurity.com/blog/litellm-privilege-escalation-rce">three-CVE chain against LiteLLM</a> that carried a default low-privilege user all the way to admin and remote code execution. Two tools. Two teams. One broken boundary.</p><p>The five-check audit at the end of this article maps each gap to a CVE or a market signal from June, a command you can run before lunch, and a sentence a CISO can read to the board.</p><h2>Copilot turned a trusted URL into an exfiltration engine</h2><p>SearchLeak chained three weaknesses into a silent data-theft chain. The URL q parameter fed attacker instructions straight to Copilot’s LLM. A rendering race condition fired an image tag before the output sanitizer ran. Bing’s image-search endpoint, allowlisted in the <a href="https://developer.mozilla.org/en-US/docs/Web/HTTP/CSP">Content Security Policy</a>, routed the stolen data out. Microsoft rated the flaw critical and patched it on the back end, according to Varonis. <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42824">NVD has not yet scored it</a>; a third-party tracker lists it at 6.5 medium. The severity is contested, but the mechanism is not.</p><p>The escalation is the real story. This is the third Varonis Copilot exfiltration chain in twelve months, after <a href="https://arstechnica.com/security/2026/01/a-single-click-mounted-a-covert-multistage-attack-against-copilot/">Reprompt</a> in January and <a href="https://www.bleepingcomputer.com/news/security/new-attack-turned-microsoft-365-copilot-into-1-click-data-theft-tool/">EchoLeak</a> in 2025. Reprompt hit Copilot Personal. SearchLeak hit Enterprise Search. Enterprise inherits the user’s full organizational permissions, so the blast radius is everything that a user can reach.</p><h2>LiteLLM handed a default account to every provider key</h2><p>The LiteLLM gateway holds the keys for OpenAI, Anthropic, Azure, and Bedrock behind a single proxy. The Obsidian chain runs in three moves. <a href="https://cvefeed.io/vuln/detail/CVE-2026-47101">CVE-2026-47101</a>, an authorization bypass, lets a non-admin mint a wildcard API key. CVE-2026-47102 promotes that caller to proxy admin through an unguarded /user/update endpoint. CVE-2026-40217 escapes the code sandbox through exec() with full builtins. Obsidian then demonstrated a reverse shell by injecting a forged tool-call response through LiteLLM’s callback mechanism. Obsidian assessed the combined chain at CVSS 9.9. The developer typed one word. The attacker popped a shell.</p><p>A separate LiteLLM flaw made the urgency immediate. <a href="https://thehackernews.com/2026/06/litellm-flaw-cve-2026-42271-exploited.html">CVE-2026-42271</a>, a command-injection bug in the MCP test endpoints, landed on the <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog">CISA KEV list</a> on June 8 with a June 22 remediation deadline. That KEV entry is not the Obsidian chain. The two are distinct disclosures four days apart, fixed in different releases, pointed at the same gateway. LiteLLM carries more than 40,000 GitHub stars and sits in thousands of enterprise deployments. This is not the first scare, either. A <a href="https://thehackernews.com/2026/06/litellm-vulnerability-chain-lets-low.html">supply-chain compromise backdoored LiteLLM versions 1.82.7 and 1.82.8 on PyPI in March</a>. A compromised gateway exposes every provider credential the organization holds.</p><h2>Langflow and Mini Shai-Hulud proved the pattern scales</h2><p>The same boundary broke in two more tools in the same fortnight. <a href="https://thehackernews.com/2026/06/unpatched-langflow-flaw-cve-2026-5027.html">Langflow CVE-2026-5027</a> became the third Langflow remote-code-execution flaw to hit active exploitation this year. A path traversal in file upload lets an attacker write files anywhere on disk, and because Langflow ships with auto-login enabled by default, a single unauthenticated request reaches RCE. <a href="https://www.vulncheck.com/">VulnCheck</a> confirmed exploitation on June 9. Censys counted roughly 7,000 exposed instances, the heaviest concentration in North America, with <a href="https://attack.mitre.org/groups/G0069/">MuddyWater</a> attribution.</p><p>The <a href="https://www.securityweek.com/over-100-npm-pypi-packages-hit-in-new-shai-hulud-supply-chain-attacks/">Mini Shai-Hulud campaign</a> hit a different pressure point. After the worm’s source code went public on May 12, copycat variants <a href="https://socket.dev/blog/mini-shai-hulud-campaign-hits-red-hat-cloud-services-npm-packages">compromised 32 Red Hat Cloud Services npm packages</a> on June 1, packages pulled 80,000 times a week. The worm harvests more than 20 credential types and self-propagates under the compromised maintainer’s identity.</p><p>Four teams, four tools, one operating failure. The bug classes differ. SearchLeak is a prompt injection. LiteLLM is privilege escalation. Langflow is path traversal. Mini Shai-Hulud is supply-chain poisoning. The boundary that broke is the same in all four.</p><h2>The market already repriced the risk</h2><p>CrowdStrike’s <a href="https://www.fool.com/earnings/call-transcripts/2026/06/03/crowdstrike-crwd-q1-2027-earnings-transcript/">Q1 FY27 earnings call</a> put a number on the gap. <a href="https://www.crowdstrike.com/en-us/platform/falcon-aidr-ai-detection-and-response/">AIDR</a>, the company’s AI detection and response line, grew ending ARR more than 250% sequentially, with a Q2 pipeline above $50 million (<a href="https://www.sec.gov/Archives/edgar/data/0001535527/000153552726000022/crwd-20260603xex991.htm">SEC-filed 8-K</a>). Total company ARR reached $5.51 billion, and CrowdStrike’s fleet telemetry shows more than 1,800 agentic applications running across enterprise endpoints. </p><p>On June 17, the company <a href="https://www.crowdstrike.com/en-us/press-releases/crowdstrike-advances-ai-and-cloud-security-operations-on-aws/">extended AIDR to AWS</a>, adding real-time evaluation of agent, LLM, and MCP communications across Amazon Bedrock, Kiro, and Strands Agents, building on its work with <a href="https://www.anthropic.com/glasswing">Anthropic’s Project Glasswing</a>. Daniel Bernard, CrowdStrike’s chief business officer, said the AI attack surface now spans development, runtime, identities, and cloud infrastructure, and that teams treating those as separate domains leave the gaps between them open.</p><h2>Practitioners name the same gap in plainer terms</h2><p>David Levin, CISO at American Express Global Business Travel, <a href="https://venturebeat.com/security/amex-ciso-fights-threats-at-machine-speed-with-ai/">told VentureBeat</a> the pattern does not surprise him. “We kind of have this shadow AI, which is just the new version of shadow IT,” Levin said. </p><p>Both Langflow and LiteLLM fit the description. Teams stood them up for convenience, gave them credentials, and never brought them under governance. Levin puts the fix before deployment. “We didn’t go into this with just saying we’re going to go do this without the right fundamentals,” he said. “We leverage NIST controls. NIST has released their CSF along with their AI framework. OWASP released their top 10. You need the right fundamentals before you deploy.”</p><p>Merritt Baer, CSO at Enkrypt AI and former AWS Deputy CISO, named the structural version of the failure in a separate <a href="https://venturebeat.com/security/most-enterprises-cant-stop-stage-three-ai-agent-threats-venturebeat-survey-finds">VentureBeat interview</a>. “Enterprises believe they’ve ‘approved’ AI vendors, but what they’ve actually approved is an interface, not the underlying system,” Baer said. “The real dependencies are one or two layers deeper, and those are the ones that fail under stress.” She has tied that directly to how systems fall. “Raw zero-days aren’t how most systems get compromised. Composability is,” Baer <a href="https://venturebeat.com/security/adversaries-hijacked-ai-security-tools-at-90-organizations-the-next-wave-has-write-access-to-the-firewall">told VentureBeat</a>. “It’s the glue between the model and your data where the risk lives. If you give an agent bash and a root token, you’ve already done most of the attacker’s work for them.” That is what rows 2 and 4 of the audit test: the gateway that holds every key, and the agent identity no one governs.</p><p>Levin had a sharper frame for the boardroom. “You need to talk more in terms of risk versus compliance to your boards and your executives,” he said. “It’s not about the size of the engineering team anymore. It’s the size of your imagination. It’s all written in plain English. It’s not hard for anyone.” Neither SearchLeak nor LiteLLM needed custom malware or a zero-day to work.</p><p>Adam Meyers, CrowdStrike’s SVP of Intelligence, put the operational squeeze in numbers in an exclusive VentureBeat interview. “The problem is not zero-day. The problem is patching. If you 10x that problem, they’re gonna be completely underwater,” Meyers said. He pointed to identity as the second front. “Some of these AI have their own identities, or people give their identity to the AI to take action on their behalf, and that makes it a very complex problem.”</p><h2>The five-check trust-boundary audit</h2><p>Each row maps a gap to its proof point, a verification command for Monday morning, the fix, and the sentence to read to the board.</p><table><tbody><tr><td><p><b>Trust-Boundary Gap</b></p></td><td><p><b>Proof Point</b></p></td><td><p><b>What Broke</b></p></td><td><p><b>Verify Monday</b></p></td><td><p><b>Fix Monday</b></p></td><td><p><b>Board Language</b></p></td></tr><tr><td><p><b>1. Prompt-to-Data</b></p></td><td><p>SearchLeak CVE-2026-42824. P2P injection + HTML race + Bing SSRF. One-click mailbox exfiltration via microsoft.com URL. PoC demonstrated; Microsoft rated it critical, NVD not yet scored.</p></td><td><p>URL q-parameter passed to LLM as instructions. Sanitizer ran after render. Bing acted as exfiltration proxy via CSP allowlist.</p></td><td><p>Audit CSP allowlists for domains performing server-side fetches. Monitor Copilot Search URLs for encoded payloads. Review Copilot audit logs.</p></td><td><p>Confirm server-side patch applied. Enable sensitivity labels restricting Copilot. Treat AI streaming output as untrusted.</p></td><td><p>“Our AI assistant could search employee email and send results to an attacker through a trusted Microsoft URL. Vendor patched it. We must verify configuration.”</p></td></tr><tr><td><p><b>2. Gateway Credential Exposure</b></p></td><td><p>LiteLLM three-CVE chain (-47101, -47102, -40217). CVSS 9.9. Separate CVE-2026-42271 on CISA KEV (fixed in v1.83.7; full chain fixed in v1.83.14-stable). June 22 deadline.</p></td><td><p>No role validation on key endpoints. Self-promotion to admin via /user/update. exec() sandbox escape. One gateway exposes all provider keys.</p></td><td><p>Run pip show litellm. Below 1.83.14-stable = vulnerable. Check /mcp-rest/test/ exposure. Audit proxy_admin accounts.</p></td><td><p>Upgrade to v1.83.14-stable+. Rotate all provider API keys. Block /mcp-rest/test/* at proxy. Review Custom Code Guardrails.</p></td><td><p>“Our AI gateway held keys for every provider. A default account could promote itself to admin and steal them all. Rotating and patching now.”</p></td></tr><tr><td><p><b>3. AI Tooling Sprawl</b></p></td><td><p>Langflow CVE-2026-5027 (CVSS 8.8). Third RCE of 2026. ~7,000 exposed instances. MuddyWater. Active exploitation June 9.</p></td><td><p>Path traversal in file upload. Auto-login enabled by default. Single unauthenticated request to RCE.</p></td><td><p>Query Censys/Shodan for Langflow, Flowise, n8n, Dify on your perimeter. Check auto-login. Inventory AI tools outside change management.</p></td><td><p>Pull AI platforms behind VPN/zero-trust. Enable auth everywhere. Upgrade Langflow to v1.9.0+ (current release 1.10.0). Fingerprint surface continuously.</p></td><td><p>“AI dev tools are exposed to the internet with login disabled. A nation-state group is exploiting this flaw now. Pulling behind access controls today.”</p></td></tr><tr><td><p><b>4. Non-Human Identity Governance</b></p></td><td><p>AIDR ARR up 250% (Q1 FY27, SEC 8-K). Q2 pipeline &gt;$50M. 1,800+ agentic apps across enterprise endpoints.</p></td><td><p>Agents hold identities and act on behalf of humans. Some exceed their intended scope to reach a goal. No standard governs agent credential lifecycle.</p></td><td><p>Inventory all non-human identities used by agents and MCP servers. Map agent-to-data-store access. Flag agents with write access to security policy.</p></td><td><p>Least-privilege every agent identity. Set privilege boundaries via identity protection. Runtime detection for policy-exceeding actions. Human-in-the-loop for policy changes.</p></td><td><p>“AI agents hold credentials and act autonomously. We do not govern their identity lifecycle like human access. The 250% market growth tells us this gap is systemic.”</p></td></tr><tr><td><p><b>5. Runtime Agentic Detection</b></p></td><td><p>Falcon AIDR expanded to AWS (June 17). Covers Bedrock, Kiro, Strands Agents. MCP integration. Real-time agent/LLM/MCP evaluation.</p></td><td><p>Traditional tools monitor human-speed actions. Agents run at machine speed, thousands of actions per minute, and route around controls to reach goals.</p></td><td><p>Test if EDR/XDR links agent actions to originating identity. Verify SIEM ingests MCP communications. Confirm you can distinguish human from agent on endpoint.</p></td><td><p>Deploy AIDR or equivalent runtime detection. Shadow-AI discovery for all agentic apps, models, MCP servers, identities. Real-time policy enforcement on agent actions.</p></td><td><p>“We cannot distinguish a human employee from an AI agent acting on their behalf. We need runtime detection at machine speed that can stop damage before it starts.”</p></td></tr></tbody></table><h2>The fix is plumbing, not policy</h2><p>The <a href="https://www.whitehouse.gov/presidential-actions/2026/06/promoting-advanced-artificial-intelligence-innovation-and-security/">June 2 executive order</a> creates an AI Cybersecurity Clearinghouse with a July 2 deadline. The five gaps above are not frontier-model problems. They are plumbing problems in the gateways, orchestration platforms, identity layers, and runtime environments where AI meets the enterprise. </p><p>The audit is five rows. Every row maps to a June disclosure or market signal, a command a team can run before lunch, and a sentence a CISO can read to the board. The question is not whether your vendor will patch. It's whether you find the gap first — or whether an attacker finds it the way they found Copilot and LiteLLM.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Die 10 besten Open-Source-Kommunikationsplattformen für Unternehmen - Wire]]></title>
<description><![CDATA[Sicherheitstransparenz. Der Chief Information Security Officer (CISO) einer Organisation benötigt Transparenz darüber, wie die Kommunikationsplattform ...]]></description>
<link>https://tsecurity.de/de/3607924/it-security-nachrichten/die-10-besten-open-source-kommunikationsplattformen-fuer-unternehmen-wire/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3607924/it-security-nachrichten/die-10-besten-open-source-kommunikationsplattformen-fuer-unternehmen-wire/</guid>
<pubDate>Thu, 18 Jun 2026 15:24:43 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Sicherheitstransparenz. Der Chief Information <b>Security</b> Officer (CISO) einer Organisation benötigt Transparenz darüber, wie die Kommunikationsplattform ...]]></content:encoded>
</item>
<item>
<title><![CDATA[What Executives Get Wrong About Incident Response Tabletop Exercises]]></title>
<description><![CDATA[A CISO-level guide to making incident response tabletop exercises useful, realistic, and executive-ready instead of scripted compliance theatre.]]></description>
<link>https://tsecurity.de/de/3607867/it-security-nachrichten/what-executives-get-wrong-about-incident-response-tabletop-exercises/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3607867/it-security-nachrichten/what-executives-get-wrong-about-incident-response-tabletop-exercises/</guid>
<pubDate>Thu, 18 Jun 2026 15:08:28 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A CISO-level guide to making incident response tabletop exercises useful, realistic, and executive-ready instead of scripted compliance theatre.]]></content:encoded>
</item>
<item>
<title><![CDATA[New CISO appointments 2026]]></title>
<description><![CDATA[The upper ranks of corporate security are seeing a high rate of change as companies try to adapt to the evolving threat landscape. Many companies are hiring a chief security officer (CSO) or chief information security officer (CISO) for the first time to support a deeper commitment to information...]]></description>
<link>https://tsecurity.de/de/3607427/it-security-nachrichten/new-ciso-appointments-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3607427/it-security-nachrichten/new-ciso-appointments-2026/</guid>
<pubDate>Thu, 18 Jun 2026 12:54:29 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>The upper ranks of corporate security are seeing a high rate of change as companies try to adapt to the evolving threat landscape. Many companies are hiring a chief security officer (CSO) or <a href="https://www.csoonline.com/article/566757/what-is-a-ciso-responsibilities-and-requirements-for-this-vital-leadership-role.html">chief information security officer</a> (CISO) for the first time to support a deeper commitment to information security.</p>



<p>Follow this column to keep up with new appointments to senior-level security roles and perhaps gain a little insight into hiring trends. If you have an announcement of your own that you would like us to include here, contact Peter Sayer, executive editor of news, at <a href="mailto:peter_sayer@foundryco.com?subject=New%20CISO%20appointment">peter_sayer@foundryco.com</a>.</p>



<h2 class="wp-block-heading">New CISO appointments in June 2026</h2>



<h3 class="wp-block-heading">SolarWinds appoints Justin Henkel as CISO</h3>



<p>IT management software vendor SolarWinds has named Justin Henkel its new CISO. Henkel was previously deputy CISO at OneTrust, and before that spent 25 years as an intelligence officer in the US Air Force. </p>



<h2 class="wp-block-heading">New CISO appointments in March 2026</h2>



<h3 class="wp-block-heading">Kathy Wang joints micro1 as CISO</h3>



<p>Frontier AI model training company micro1 has hired Kathy Wang as CISO. She was most recently CISO at hospitality software developer Otelier, and has previously held top cybersecurity roles at Discord and GitLab.</p>



<h3 class="wp-block-heading">Green Impact Exchange names John Visneski CISO</h3>



<p>John Visneski has joined stock exchange operator Green Impact Exchange as CISO. He was previously CISO at MGM Studios, and following that company’s acquisition by Amazon became head fo security for mergers and acquisitions. His cybersecurity career began with the US Air Force, where he served as cyber advisor to the Secretary and Chief of Staff of teh Air Force.</p>



<h2 class="wp-block-heading">New CISO appointments in January 2026</h2>



<h3 class="wp-block-heading">Julien Mousqueton joins Cohesity as field CISO for Europe</h3>



<p>Data security firm Cohesity has hired Julien Mousqueton as field CISO for Europe. His previous role was as CTO at IT service provider Computacenter. He is a reservist advisor for OFAC, the French national police force’s anti-cybercrime division, and created the real-time ransomware activity-tracking platform <a href="https://ransomware.live/" target="_blank" rel="noreferrer noopener">ransomware.live</a>.</p>



<p></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Darknet-Monitoring – die besten Tools]]></title>
<description><![CDATA[loading="lazy" width="400px">Diese Darknet-Monitoring-Tools erleichtern es, nachzuvollziehen, was in den dunklen Ecken des Internets vor sich geht.HQuality | shutterstock.com



Im Darknet möchte wohl kein CISO die Daten seines Unternehmens sehen. Es besteht aus Webseiten, die von gängigen Suchma...]]></description>
<link>https://tsecurity.de/de/3606600/it-security-nachrichten/darknet-monitoring-die-besten-tools/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3606600/it-security-nachrichten/darknet-monitoring-die-besten-tools/</guid>
<pubDate>Thu, 18 Jun 2026 06:08:06 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full is-resized"> loading="lazy" width="400px"&gt;<figcaption class="wp-element-caption">Diese Darknet-Monitoring-Tools erleichtern es, nachzuvollziehen, was in den dunklen Ecken des Internets vor sich geht.</figcaption></figure><p class="imageCredit">HQuality | shutterstock.com</p></div>



<p>Im Darknet möchte wohl kein CISO die Daten seines Unternehmens sehen. Es besteht aus Webseiten, die von gängigen Suchmaschinen nicht erfasst werden. Dieser <a href="https://www.computerwoche.de/article/2802278/insights-aus-dem-untergrund.html" target="_blank">verborgene Teil des Internets</a> dient sowohl legitimen als auch kriminellen Zwecken und umfasst unter anderem Marktplätze für Daten, die im Rahmen von Cyberangriffen gestohlen oder kompromittiert wurden. Diese können von Cyberkriminellen dazu genutzt werden, um weitere Angriffskampagnen zu initiieren, beispielsweise <a href="https://www.computerwoche.de/article/2798163/so-erkennen-sie-e-mail-betrueger.html" target="_blank">Spear Phishing</a>.  </p>



<p>Unternehmen, die feststellen können, ob Daten aus ihren Netzwerken auf solchen Darknet-Plattformen feilgeboten werden, können die daraus resultierenden Angriffsversuche besser abwehren. Zudem eignet sich das Darknet auch hervorragend als Quelle, um Informationen über die <a href="https://www.computerwoche.de/article/4155663/6-wege-uber-ki-gehackt-zu-werden.html" target="_blank">Prozesse, Taktiken und Absichten</a> krimineller Hacker zu sammeln. Das funktioniert über Softwarelösungen, die darauf ausgelegt sind, das Darknet auf <a href="https://www.computerwoche.de/article/2792460/so-guenstig-ist-ein-hack-im-darknet.html" target="_blank">kompromittierte Daten</a> zu überwachen. </p>



<h2 class="wp-block-heading">Darknet-Monitoring-Tools – die besten Lösungen</h2>



<p>Im Folgenden finden Sie einige der populärsten Darknet-Monitoring-Tools. Diese Auflistung erhebt keinen Anspruch auf Vollständigkeit.</p>



<p><a href="https://brandefense.io/" target="_blank" rel="noreferrer noopener"><strong>Brandefense</strong></a></p>



<p>Brandefense ist ein KI-gesteuerter Digital Risk Protection Service, der sowohl das frei zugängliche Web als auch das Darknet scannt, um Details zu Angriffsmethoden oder Datenschutzverletzungen zu sammeln und diese Daten zu korrelieren und zu kontextualisieren. Sobald ein Vorfall als relevant für den jeweiligen Anwender erachtet wird, wird eine Warnmeldung augegeben. Diese Lösung ist außerdem in der Lage, Takedowns gegen Bedrohungsakteure durchzuführen – anstatt erst darauf zu warten, dass der Angriff erfolgt.</p>



<p>Ein weiterer Schwerpunkt liegt bei diesem Tool auf dem Schutz für hochrangige Führungskräfte. Diese stehen schließlich nicht nur direkt mit der Unternehmensmarke in Verbindung, sondern  sind auch beliebte Ziele für diverse Angriffe, unter anderem Spear-Phishing-Kampagnen. </p>



<p><a href="https://www.crowdstrike.com/de-de/platform/threat-intelligence/adversary-overwatch/" target="_blank" rel="noreferrer noopener"><strong>Crowdstrike Falcon Adversary OverWatch</strong></a></p>



<p>CrowdStrike bietet mit Falcon Adversary OverWatch eine rund um die Uhr verfügbare Threat-Hunting-Plattform. Diese kombiniert die Branchenexpertise des Anbieters mit künstlicher Intelligenz, um Bedrohungsakteure proaktiv zu identifizieren und in Echtzeit zu stoppen. Die Lösung liefert zudem weitere Darknet-Einblicke zu Daten, die Bezüge zu Unternehmens-Assets, -Identitäten und -Marken aufweisen.  </p>



<p><a href="https://www.ctm360.com/" target="_blank" rel="noreferrer noopener"><strong>CTM 360</strong></a></p>



<p>Dieser Anbieter aus Malaysia hat zwei verschiedene Lösungen im Angebot, die das Darknet überwachen:</p>



<ul class="wp-block-list">
<li><a href="https://www.ctm360.com/platform/targeted-threat-intelligence/" target="_blank" rel="noreferrer noopener">CyberBlindspot</a> fokussiert auf Informationen, die direkt mit Unternehmens-Assets in Verbindung stehen. Das Tool erweitert dabei das Indicators-of-Compromise-Konzept, um Warn- oder Angriffsindikatoren zu identifizieren.</li>



<li><a href="https://www.ctm360.com/platform/global-cyber-threat-intelligence/" target="_blank" rel="noreferrer noopener">ThreatCover</a> bietet hingegen ein Toolset für Sicherheitsanalysten, um Threat-Intelligence-Feeds besser zu durchforsten. Auf dieser Grundlage können Incident-Response-Teams eine Reaktion auf Vorfälle einleiten.</li>
</ul>



<p><a href="https://www.darkowl.com/products/vision-app/" target="_blank" rel="noreferrer noopener"><strong>DarkOwl Vision UI</strong></a></p>



<p>DarkOwl verspricht mit Vision UI einen vereinfachten Einblick in relevante Darknet-Daten. Das Tool ermöglicht dazu unter anderem, kuratierte Darkweb-Daten-Feeds nach Standard-Text oder booleschen Logiken zu durchsuchen. Neben interaktiven Suchen bietet dieses Monitoring-Tool auch Benachrichtigungen und Alerts sowie Exposure-Metriken. Letztere versuchen, die Exposure auf Basis diverser Faktoren und Quellen zu quantifizieren.</p>



<p><a href="https://xfe-integration.xforce.ibm.com/" target="_blank" rel="noreferrer noopener"><strong>IBM X-Force Exchange</strong></a></p>



<p>Bei IBM X-Force Exchange handelt es sich in erster Linie um eine Plattform für die gemeinsame Nutzung von Daten. Diese führt Threat- und Intelligence-Feeds in einer interaktiven, durchsuchbaren Datenbank zusammen und lässt sich über APIs und automatische Warnmeldungen in bestehende Sicherheitssysteme integrieren. Eine Registrierung ist erforderlich, um relevante Suchvorgänge speichern und Feeds tracken sowie individuell anpassen zu können. Für API-Zugang, erweiterte Analysen und Threat-Intelligence-Berichte auf “Premium-Niveau” ist ein Abonnement erforderlich.</p>



<p><a href="https://www.misp-project.org/" target="_blank" rel="noreferrer noopener"><strong>Malware Information Sharing Platform (MISP)</strong></a></p>



<p>MISP ist eine Open-Source-Plattform, die auf der Idee basiert, Threat-Intelligence-Daten gemeinschaftlich zu nutzen. Die quelloffene Software lässt sich im Rechenzentrum oder auf diversen Cloud-Plattformen installieren. Dabei werden Open-Source-Protokolle und -Datenformate genutzt, die mit anderen MISP-Benutzern geteilt sowie in alle gängigen IT-Sicherheits-Tools integriert werden können. Die Threat-Intelligence-Feeds werden bei dieser Lösung zwar nicht auf dieselbe Weise kuratiert wie bei kommerziellen Tools. Aber die Lösung stellt eine kostengünstige Möglichkeit für Unternehmen dar, um internes Darknet-Monitoring zu etablieren.</p>



<p><a href="https://www.mandiant.com/advantage/digital-threat-monitoring" target="_blank" rel="noreferrer noopener"><strong>Mandiant Digital Threat Monitoring</strong></a></p>



<p>Auch Mandiant bietet mit Digital Threat Monitoring Einblicke darüber, welche Unternehmensdaten oder -geheimnisse im offenen oder verborgenen Teil des Internets kursieren. Diese Daten werden mit Hilfe von Machine Learning kontextbezogen aufbereitet. Im Ergebnis verspricht Mandiant relevante, priorisierte Warnmeldungen, die den Triage-Prozess erleichtern sollen. Neben Brand- und VIP-Monitoring kann diese Lösung auch Partnerunternehmen überwachen. Das kann dabei helfen, die eigene Lieferkette weiter abzusichern und domänenübergreifende Angriffe zu verhindern, die bestehende Sicherheitskontrollen umgehen könnten. Mandiant bietet sein Monitoring-Tool zudem auch als Zusatzmodul an, was es Anwendern ermöglicht, Threat Intelligence um Darknet-Monitoring zu erweitern.</p>



<p><a href="https://filigran.io/platform/opencti/" target="_blank" rel="noreferrer noopener"><strong>OpenCTI</strong></a></p>



<p>Eine weitere Open-Source-Option, um Threat-Intelligence-Daten zu sammeln und zu verwalten ist OpenCTI. Das Programm wurde von Filigran entwickelt und kann als Docker-Container plattformunabhängig eingesetzt werden. Zudem bietet diese Lösung eine Vielzahl von Konnektoren zu anderen Sicherheitsplattformen und Software-Tools, um den OpenCTI-Datenstrom zu integrieren und weiter anzureichern. Zum Funktionsumfang von OpenCTI gehören rollenbasierte Zugriffskontrollen für Security-Teams, standardisierte Datenmodelle sowie Attribuierungsdaten, die darüber Auskunft geben können, wo die Bedrohungswurzel liegt. Darüber hinaus lassen sich mit dem OpenCTI-Client für Python, den OpenCTI-APIs und einem benutzerfreundlichen Framework das sämtliche Arten von Automatisierungen realisieren.</p>



<p><a href="https://socradar.io/products/dark-web-monitoring/" target="_blank" rel="noreferrer noopener"><strong>SOCRadar Advanced Dark Web Monitoring</strong></a></p>



<p>SOCRadar bietet verschiedene Dienste und Tools für Sicherheitsexperten an, darunter eine Reihe kostenloser Tools. Für eine umfassendere, lückenlose Darknet-Überwachung empfiehlt sich jedoch ein Abonnement dieses Service. Dieser bietet eine Überwachung auf persönlich identifizierbare Informationen, trackt kompromittierte VIP-Konten und bietet ein durchgängiges Reputations- und Phising-Monitoring. Auch Takedown-Services sind über diesen Service verfügbar, kosten aber zusätzlich. Der Umfang der Darknet-Monitoring-Services richtet sich nach der gebuchten Servicestufe.</p>



<p><a href="https://www.zerofox.com/solutions/cyber-threat-intelligence/dark-web-intelligence/" target="_blank" rel="noreferrer noopener"><strong>ZeroFox Dark Web Monitoring</strong></a></p>



<p>Auch dieses Tool von ZeroFox zielt darauf ab, Darknet-Risiken einfacher sichtbar zu machen. Die kontinuierliche Überwachung von kompromittierten Zugangsdaten, persönlichen Daten von Mitarbeitern oder sensiblen geistigen Eigentumsrechten ist dabei laut dem Anbieter nur der Anfang: Aus der Analyse von Angriffsmethoden gewonnene Erkenntnisse fließen in Abwehrmaßnahmen ein, um die Anwender besser zu schützen – und Warnmeldungen informieren rechtzeitig über Risiken für Brands. (fm)</p>



<p><strong>Dieser Artikel ist <a href="https://www.csoonline.com/article/574585/10-dark-web-monitoring-tools.html" target="_blank">im Original</a> bei unserer Schwesterpublikation CSOonline.com erschienen.</strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Jamf CEO: ‘AI is happening whether organizations know it or not’]]></title>
<description><![CDATA[Beth Tschida, who became Jamf CEO in May after serving as CTO and as interim CEO, is the first woman to lead the company in its near 25-year history. I spoke with her this week at the London Jamf Nation event, where the company introduced its new AI Governance solution.



How the transition to C...]]></description>
<link>https://tsecurity.de/de/3605483/it-nachrichten/jamf-ceo-ai-is-happening-whether-organizations-know-it-or-not/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3605483/it-nachrichten/jamf-ceo-ai-is-happening-whether-organizations-know-it-or-not/</guid>
<pubDate>Wed, 17 Jun 2026 18:33:01 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p><a href="https://www.computerworld.com/article/4174165/beth-tschida-takes-over-at-jamf-as-ai-transforms-apple-in-the-enterprise.html">Beth Tschida, who became Jamf CEO in May</a> after serving as CTO and as interim CEO, is the first woman to lead the company in its near 25-year history. I spoke with her this week at the London Jamf Nation event, where the company introduced its new AI Governance solution.</p>



<h2 class="wp-block-heading"><strong>How the transition to CEO is going </strong></h2>



<p>“It’s been a great privilege and an adjustment,” she said. “Jamf has always been a company deeply focused on culture, which is exactly why I love being here. Having the ability to influence and improve that culture from this role is something I feel very supported in doing.”</p>



<p>The last few years have seen a variety of changes at Jamf, which was briefly a public company. “We’ve come through a period of change, not all of it easy,” Tschida said. “But we now have a great partnership with Francisco Partners. We’re private, we’re focused on solving customer problems, and we’re finding ways to lean into what we’re good at.”</p>



<h2 class="wp-block-heading"><strong>Women in tech and mentorship</strong></h2>



<p>Tschida is a good choice to lead a software engineering company, as she’s an engineer herself. She originally joined Jamf as vice president for software engineering in 2018, moving up to CTO in 2022. She’s also one of the few women in leadership positions in tech. (To Jamf’s credit, the company also has <a href="https://www.computerworld.com/article/1627364/jamf-cio-apple-will-be-the-no-1-enterprise-endpoint-by-2030.html">CIO Linh Lam</a> on its team.)</p>



<p>“I think it’s important for women to stay deep in the tech, build their skills and find their voice confidently,” Tschida said. “You’ll never know all the technology out there. Nobody does. What matters is the ability to keep adapting and evolving.”</p>



<p>Tschida stressed the importance of mentorship. “I feel very honored to have a chance to be a role model for other women,” she said. “I had women who forged a path for me, including a female CIO early in my career who I asked to mentor me and learned an enormous amount from. I’m certainly not the first woman in tech, but I do want to play my part in helping others grow in their careers.</p>



<p>“Ultimately, I want to be respected for what I do, not for my gender. That’s how everyone should be judged.”</p>



<h2 class="wp-block-heading"><strong>AI Governance</strong></h2>



<p>Tschida’s product focus means she knows what matters to Jamf. “If you focus on the problems customers have and how your product can help fix them, that’ll take you to where you want to go.”</p>



<p>For many in the enterprise, both in and beyond the Apple space, the next big problem is AI — how to deploy it, how to manage it, and how to regulate it.</p>



<p><a href="https://www.applemust.com/jamf-brings-powerful-ai-governance-solution/" target="_blank" rel="noreferrer noopener">AI Governance is a new Jamf solution</a> that has been developed in response to those pain points. Countless surveys, <a href="https://www.businesswire.com/news/home/20260615806745/en/Jamf-Survey-finds-AI-incident-rates-rise-as-organizations-deepen-AI-integration" target="_blank" rel="noreferrer noopener">including Jamf’s own data</a>, show that AI is being widely used across every company, but IT lacks visibility into its use. It’s hard to know what data is being shared with AI tools, which services are being used, and how to report on that use effectively — particularly in regulated industries.</p>



<p>AI Governance is designed to make it possible for anyone managing an Apple fleet to get granular insight into AI use across their Mac, iPhone, and iPad devices. It uses telemetrics to shed light on that use, offers governance and management tools to help IT gain better oversight and control over it, and provides highly comprehensive reporting tools suitable for internal or regulatory review.</p>



<p>“AI is happening whether organizations know it or not,” said Tschida. “That’s the problem. You can try to block it, but that’s very hard to do well. It’s far better to build visibility and governance around it.”</p>



<p>The offering makes it possible for companies to enable the AI use they already know is taking place while protecting corporate interests and enabling fast and accurate reporting. You can <a href="https://www.jamf.com/solutions/ai-governance" target="_blank" rel="noreferrer noopener">find out more details here</a>.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/Screenshot-2026-06-15-at-3.34.26-PM.png?w=881" alt="Jamf AI Governance reporting" class="wp-image-4186291" width="881" height="1025" sizes="auto, (max-width: 881px) 100vw, 881px"></figure><a href="http://www.jamf.com/" target="_blank" class="imageCredit" rel="noopener">Jamf</a></div>



<h2 class="wp-block-heading"><strong>Empowering better AI</strong></h2>



<p>Jamf’s approach is focused on endpoint management. AI Governance means IT can see what’s running on a device, categorize it, and understand what AI tools and models are in use. “If you know how people are running AI on your fleet, you can open it up safely. Then all of your customers and employees can find their way to figure out how AI is going to optimize their workforce,” she said.</p>



<p>What does that look like in practice? Think of it as an orchestration layer. IT can define different AI configurations for different teams: HR might use one set of models, engineers another. And admins can apply opinionated postures per group: what models are permitted, what cloud services they connect to, what’s visible to IT versus the CISO versus the CFO. “It’s an extension of what Jamf has always done, it just now applies to AI endpoints too.”</p>



<p>What about regulatory complexity across geographies? “A lot of governance controls are shared across regulations; a good base set is a healthy way to run regardless. But each regulation has its own twists. Our mission is to make sure customers operating in different markets can expand on that base and fit the specific models and regulations they need, getting the right configurations to the right devices.”</p>



<h2 class="wp-block-heading"><strong>Managers must prepare for AI cost challenges</strong></h2>



<p>There’s a second dimension beyond management — cost. The industry is developing quickly, with new AI models appearing almost every week. Yesterday’s leading LLM is tomorrow’s fading star, even while the cost of AI infrastructure goes through the roof. As that churn slows, investors will want to start seeing returns on their bets, which is why token costs — the price of running AI services, at least in the cloud — <a href="https://www.economist.com/business/2026/06/14/companies-are-scrambling-to-curtail-soaring-ai-costs" target="_blank" rel="noreferrer noopener">are climbing fast</a>.  </p>



<p>As costs become more realistic, that’s going to change the nature of AI deployment from the laissez-faire, anything goes approach to a more strategic management of such use. “Models keep dropping fast, but token costs are only going to go up,” said Tschida. </p>



<p>“Organizations will need to decide: just because you can build something with AI, should you? What’s the right model for what work? We’re helping customers move from, ‘We’ll just block it’ or ‘We’ll turn it on and hope for the best,’ toward a place where they have a real viewpoint and can manage and change that viewpoint over time.”</p>



<p>The ever-changing AI world is also prompting Jamf to make more of its APIs externally available. “We’re used across every industry and every geography, at every scale,” said Tschida. “There’s no way we can build every workflow every customer needs, we’d never get to all of them.”</p>



<p>Embracing openness also helps build future foundations. “Thinking about where we’re heading next — agentic endpoint management — having platform APIs allows our customers to build things they can imagine, that we can learn from, in a way that solves their specific problems.”</p>



<h2 class="wp-block-heading"><strong>Apple, WWDC, and the enterprise</strong></h2>



<p>Tschida’s comments come shortly after WWDC 2026, where Apple introduced a raft of AI advances that formed a strong foundation for its future, improvements that matter to Jamf. “When Apple innovates, Jamf celebrates,” she said.</p>



<p>“Apple is doing great things in their AI ecosystem, revamping Siri, expanding their AI capabilities, making Apple the platform people want to run AI on because those machines simply perform better. Our job is to take what Apple builds and bring it into the enterprise in the way that enterprises actually need it.”</p>



<p>Most of the industry recognizes that Apple’s enterprise story has changed dramatically as its products see accelerating use, and momentum is not slowing. Tschida reflected on how just a few years ago, Apple in the enterprise was an option in employee choice programs. “Now it’s becoming the clear choice,” she said. “We expect that trend to continue. And the more Apple invests in AI running natively on device, the stronger that argument gets.”</p>



<h2 class="wp-block-heading"><strong>Where is Jamf going?</strong></h2>



<p>AI Governance is a unique answer to an increasingly important set of questions that are now beginning to affect the IT management of Apple’s platforms. (It’s not clear whether anything as sophisticated exists for other platforms at al, but as the need to manage AI grows, demand for such solutions will grow.)</p>



<p>Ultimately, the company’s latest move reflects Jamf’s inherent strategy under its new CEO. “Focus on customers, listen to them, solve their problems, and don’t throw tech at it. Ask: what’s the problem? Can we solve it? That focus is what takes you where you need to go. </p>



<p>“We’re on a good trajectory, customers stay with us, and the culture has always underpinned us. Now we’re finding ways to lean into it even further,” she said.</p>



<p><em>You can follow me on social media! Join me on <a href="https://bsky.app/profile/jonnyevanssays.bsky.social" target="_blank" rel="noreferrer noopener">BlueSky</a>,  <a href="http://www.linkedin.com/in/jonnyevans" target="_blank" rel="noreferrer noopener">LinkedIn</a>, <a href="https://social.vivaldi.net/@jonnyevans" target="_blank" rel="noreferrer noopener">Mastodon</a> and subscribe to <a href="https://thecorenews.substack.com/p/welcome-to-the-core?r=5l3lg" target="_blank" rel="noreferrer noopener">The Core</a>.</em></p>



<p></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[IT Security News Hourly Summary 2026-06-17 18h : 13 posts]]></title>
<description><![CDATA[13 posts were published in the last hour 15:34 : Continuous innovation keeps tape relevant 15:34 : The OpenClaw security risks every CISO needs to know 15:34 : U.S. CISA adds Widget Factory Joomla Content Editor flaw to its Known Exploited…
Read more →
The post IT Security News Hourly Summary 202...]]></description>
<link>https://tsecurity.de/de/3605456/it-security-nachrichten/it-security-news-hourly-summary-2026-06-17-18h-13-posts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3605456/it-security-nachrichten/it-security-news-hourly-summary-2026-06-17-18h-13-posts/</guid>
<pubDate>Wed, 17 Jun 2026 18:23:21 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>13 posts were published in the last hour 15:34 : Continuous innovation keeps tape relevant 15:34 : The OpenClaw security risks every CISO needs to know 15:34 : U.S. CISA adds Widget Factory Joomla Content Editor flaw to its Known Exploited…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/it-security-news-hourly-summary-2026-06-17-18h-13-posts/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/it-security-news-hourly-summary-2026-06-17-18h-13-posts/">IT Security News Hourly Summary 2026-06-17 18h : 13 posts</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The OpenClaw security risks every CISO needs to know]]></title>
<description><![CDATA[Viral AI agent platform OpenClaw is spreading through enterprises like wildfire — and bringing with it major cyber-risk. OpenClaw, an open source, self-hosted AI personal assistant, burst onto the scene in late 2025. Created by Austrian developer Peter Steinberger,…
Read more →
The post The OpenC...]]></description>
<link>https://tsecurity.de/de/3605361/it-security-nachrichten/the-openclaw-security-risks-every-ciso-needs-to-know/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3605361/it-security-nachrichten/the-openclaw-security-risks-every-ciso-needs-to-know/</guid>
<pubDate>Wed, 17 Jun 2026 17:54:59 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>&lt;p&gt;Viral AI agent platform OpenClaw is spreading through enterprises like wildfire — and bringing with it major cyber-risk.&lt;/p&gt; &lt;p&gt;&lt;a href=”https://www.techtarget.com/searchcio/feature/OpenClaw-and-Moltbook-explained-The-latest-AI-agent-craze”&gt;OpenClaw&lt;/a&gt;, an open source, self-hosted AI personal assistant, burst onto the scene in late 2025. Created by Austrian developer Peter Steinberger,…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/the-openclaw-security-risks-every-ciso-needs-to-know/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/the-openclaw-security-risks-every-ciso-needs-to-know/">The OpenClaw security risks every CISO needs to know</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The OpenClaw security risks every CISO needs to know]]></title>
<description><![CDATA[The business case for OpenClaw is clear, but so are the security risks. Learn why a cybersecurity expert says deployments are putting enterprises in real danger.]]></description>
<link>https://tsecurity.de/de/3605283/it-security-nachrichten/the-openclaw-security-risks-every-ciso-needs-to-know/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3605283/it-security-nachrichten/the-openclaw-security-risks-every-ciso-needs-to-know/</guid>
<pubDate>Wed, 17 Jun 2026 17:25:42 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The business case for OpenClaw is clear, but so are the security risks. Learn why a cybersecurity expert says deployments are putting enterprises in real danger.]]></content:encoded>
</item>
<item>
<title><![CDATA[Enterprise Browers in the Age of AI as CISO Role Changes and Leaders Harness Stress - BSW #452]]></title>
<description><![CDATA[Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:4 The browser has become the primary gateway to work, data, and AI. In this episode, Arunesh Chandra, Head of Product, Microsoft Edge for Business at Microsoft Edges for Business, will discuss why security and IT teams are rethinkin...]]></description>
<link>https://tsecurity.de/de/3604239/it-security-video/enterprise-browers-in-the-age-of-ai-as-ciso-role-changes-and-leaders-harness-stress-bsw-452/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3604239/it-security-video/enterprise-browers-in-the-age-of-ai-as-ciso-role-changes-and-leaders-harness-stress-bsw-452/</guid>
<pubDate>Wed, 17 Jun 2026 11:33:06 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:4 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/1gDyZyH6MgM?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>The browser has become the primary gateway to work, data, and AI. In this episode, Arunesh Chandra, Head of Product, Microsoft Edge for Business at Microsoft Edges for Business, will discuss why security and IT teams are rethinking the role of the browser and what sets Edge for Business apart as a secure, enterprise-ready solution. Arunesh cover how built-in security, native integration with existing IT tools, and centralized management can simplify operations, reduce risk, and support modern work across managed devices, BYOD, and contractors. A must  listen for IT pros and security experts  navigating browser sprawl and AI adoption.<br />
<br />
This segment is sponsored by Microsoft Edge for Business. Visit https://securityweekly.com/edgeforbusiness to learn more about them!<br />
<br />
In the leadership and communications segment, CISO role changes as cyber-risk appetites in the C-suite grow, AI is exposing the biggest weakness in cybersecurity: We never built a health model. Until now!, 6 Ways Leaders Harness Stress, and more!<br />
<br />
Visit https://www.securityweekly.com/bsw for all the latest episodes!<br />
<br />
Show Notes: https://securityweekly.com/bsw-452<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Enterprise Browers in the Age of AI as CISO Role Changes and Leaders Harness Stress - Arunesh Chandra - BSW #452]]></title>
<description><![CDATA[The browser has become the primary gateway to work, data, and AI. In this episode, Arunesh Chandra, Head of Product, Microsoft Edge for Business at Microsoft Edges for Business, will discuss why security and IT teams are rethinking the role of the browser and what sets Edge for Business apart as ...]]></description>
<link>https://tsecurity.de/de/3604220/it-security-nachrichten/enterprise-browers-in-the-age-of-ai-as-ciso-role-changes-and-leaders-harness-stress-arunesh-chandra-bsw-452/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3604220/it-security-nachrichten/enterprise-browers-in-the-age-of-ai-as-ciso-role-changes-and-leaders-harness-stress-arunesh-chandra-bsw-452/</guid>
<pubDate>Wed, 17 Jun 2026 11:23:21 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The browser has become the primary gateway to work, data, and AI. In this episode, Arunesh Chandra, Head of Product, Microsoft Edge for Business at Microsoft Edges for Business, will discuss why security and IT teams are rethinking the role of the browser and what sets Edge for Business apart as a secure, enterprise-ready solution. Arunesh cover how built-in security, native integration with existing IT tools, and centralized management can simplify operations, reduce risk, and support modern work across managed devices, BYOD, and contractors. A must listen for IT pros and security experts navigating browser sprawl and AI adoption.</p> <p>This segment is sponsored by Microsoft Edge for Business. Visit <a rel="noopener" target="_blank" href="https://securityweekly.com/edgeforbusiness">https://securityweekly.com/edgeforbusiness</a> to learn more about them!</p> <p>In the leadership and communications segment, CISO role changes as cyber-risk appetites in the C-suite grow, AI is exposing the biggest weakness in cybersecurity: We never built a health model. Until now!, 6 Ways Leaders Harness Stress, and more!</p> <p>Visit <a rel="noopener" target="_blank" href="https://www.securityweekly.com/bsw">https://www.securityweekly.com/bsw</a> for all the latest episodes!</p> <p>Show Notes: <a rel="noopener" target="_blank" href="https://securityweekly.com/bsw-452">https://securityweekly.com/bsw-452</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[What 22,000 breaches teach us about incident preparedness]]></title>
<description><![CDATA[The 2026 Verizon Data Breach Investigations Report analyzed more than 22,000 confirmed data breaches across 145 countries. Its findings point to a single uncomfortable truth: organizations cannot patch fast enough to prevent every incident. Exploitation of vulnerabilities surged to become the lea...]]></description>
<link>https://tsecurity.de/de/3604148/it-security-nachrichten/what-22000-breaches-teach-us-about-incident-preparedness/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3604148/it-security-nachrichten/what-22000-breaches-teach-us-about-incident-preparedness/</guid>
<pubDate>Wed, 17 Jun 2026 11:09:07 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>The <a href="https://www.verizon.com/business/resources/reports/dbir/">2026 Verizon Data Breach Investigations Report</a> analyzed more than 22,000 confirmed data breaches across 145 countries. Its findings point to a single uncomfortable truth: organizations cannot patch fast enough to prevent every incident. Exploitation of vulnerabilities surged to become the leading initial access vector, the median time to remediate a critical flaw climbed to 43 days, and the volume of critical vulnerabilities grew 50% year over year. Even top-performing organizations only managed to fix 30% to 40% of known exploited vulnerabilities listed in the <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog">CISA Known Exploited Vulnerabilities catalog</a> within the first week of detection. That rate barely budged despite years of investment in tooling, process maturity and regulatory pressure.</p>



<p>Most organizations will eventually face a serious incident. The quality of your response determines the outcome.</p>



<h2 class="wp-block-heading">Ransomware hits 48% of breaches. The payment decision is just the beginning</h2>



<p>Ransomware appeared in 48% of all confirmed breaches, up from 44% the prior year. Among cases where organization size was known, 96% of victims were small and medium-sized businesses.</p>



<p>The “climax” of every ransomware tabletop I witness has always been the question: pay or refuse? The DBIR reveals that 69% of victims chose not to pay, up from 65% the year before. That number held even when attackers encrypted systems. Refusing is becoming standard practice. The median payout dropped to $139,875.</p>



<p>Facing shrinking revenues, ransomware operators now deliberately maximize operational disruption to force faster decisions. The <a href="https://www.blackfog.com/marks-and-spencer-ransomware-attack/">2025 attack on Marks &amp; Spencer</a> knocked out online sales, inventory tracking and refrigeration monitoring for weeks, costing an estimated £300 million. The <a href="https://en.wikipedia.org/wiki/Jaguar_Land_Rover_cyberattack">Jaguar Land Rover breach</a> halted manufacturing for five weeks, inflicted £1.9 billion in damages and dragged UK GDP below its quarterly forecast.</p>



<p>Consider using these cases to inspire your next ransomware drill. The ransom question is one agenda item. Sustaining operations without primary systems, coordinating with legal counsel and law enforcement, managing customer and investor communications under regulatory deadlines, deciding what to disclose and when: these are the decisions that determine whether a company survives a ransomware event or becomes a cautionary headline. Organizations that rehearse only the payment question are practicing the opening scene and skipping the rest of the play.</p>



<h2 class="wp-block-heading">Third-party breaches jumped 60%. Your exercises should reflect that</h2>



<p>Breaches involving a vendor, supplier or service provider reached 48% of all confirmed incidents, a 60% increase from the previous year. This metric doubled the year before that. The trajectory is unmistakable.</p>



<p>The DBIR identifies three archetypes: a vulnerability in a vendor’s product opens the door to your environment; a vendor holding your data gets compromised directly; or an attacker breaches the vendor and pivots laterally into your network. Several of the year’s most prominent campaigns triggered two or all three archetypes simultaneously.</p>



<p>Most tabletop programs ignore this scenario entirely. I have seen organizations rehearse their internal playbooks dozens of times without once simulating a call to a compromised vendor. When the real call comes, they freeze. A third-party breach tests a fundamentally different set of skills than an internal compromise.</p>



<p>When a vendor is breached, the information your team needs most is the information the vendor is least prepared to share quickly. Tabletop exercises should simulate that friction. Participants should practice asking precise questions: What data of ours did you hold? What is the confirmed scope? What logs exist? How are you notifying other affected customers?</p>



<p>The other half of the exercise is equally critical. Your customers will demand answers while the investigation is still unfolding. Transparency builds trust. Premature attribution destroys partnerships. The discipline lies in communicating what you know and what you are doing about it without publicly blaming a vendor whose cooperation you still require. A press statement that throws a third party under the bus may generate a satisfying headline. It will also guarantee that the vendor’s legal team stops sharing information with yours.</p>



<h2 class="wp-block-heading">Vulnerability exploitation is the top attack vector. AI will accelerate it</h2>



<p>Exploitation of vulnerabilities reached 31% of all confirmed breaches, a 55% increase over the prior year’s 20%. It displaced credential abuse as the leading initial access method for the first time in the DBIR’s history.</p>



<p>The structural problem is straightforward. Organizations faced a median of 16 CISA Known Exploited Vulnerabilities in 2025, up from 11 the year before. Only 26% were fully remediated, down from 38%. Defenders are caught in <a href="https://en.wikipedia.org/wiki/Red_Queen%27s_race">Alice’s Red Queen Race</a>.</p>



<p>AI is compressing the timeline further. The DBIR’s collaboration with Anthropic examined 793 threat actors who misused AI platforms for malicious purposes between March 2025 and February 2026. The median actor sought assistance across 15 distinct ATT&amp;CK techniques. Thirty-two percent of AI-assisted initial access activity targeted vulnerability exploitation specifically. The report notes that creating exploit tools, adapting them across languages and discovering new vulnerabilities “is within reach with current AI coding assistance.” <a href="https://www.anthropic.com/news/disrupting-AI-espionage">Anthropic’s own threat research</a> documented the first known AI-orchestrated cyber espionage campaign, in which attackers used agentic AI to execute intrusions autonomously. By December 2025, researchers documented VoidLink, a complete malware framework built by an AI agent in six days. Twenty-nine percent of KEV vulnerabilities were attacked before public disclosure that year.</p>



<p>This acceleration demands a shift in how organizations exercise their incident response capabilities. <a href="https://csrc.nist.gov/pubs/sp/800/84/final">NIST SP 800-84</a> has long recommended formal test, training and exercise programs for evaluating incident response preparedness. The growing speed and volume of exploitation makes that guidance urgent. Technical tabletop exercises, where participants work through actual triage rather than discuss hypothetical responses, should become routine. Teams need to practice identifying affected systems, determining blast radius, executing containment playbooks and coordinating remediation across departments under realistic time pressure. The window between initial compromise and full-blown breach is shrinking. How fast your technical teams can triage and contain directly determines the severity of the outcome. Organizations that encounter these decisions for the first time during a live incident will not move fast enough.</p>



<h2 class="wp-block-heading"><a></a>The breach you practice for is the one you survive</h2>



<p>The 2026 DBIR and <a href="https://cloud.google.com/security/resources/m-trends">Google’s M-Trends 2026 report</a> paint the same picture from different angles: the speed of attacks is accelerating, the surface area is expanding through third-party dependencies, and the sophistication gap between attackers and defenders is narrowing thanks to widely available AI tooling. These are not projections. They describe the threat landscape as it exists today.</p>



<p>Organizations that wait for a breach to test their response capabilities will discover their gaps at the worst possible moment. Playbooks that have never been exercised under pressure tend to collapse on first contact with a real incident. Communication plans that look reasonable on paper fall apart when the general counsel, the CISO and the CEO are in the same room arguing about disclosure timing while customers flood the support lines.</p>



<p>The remedy is deliberate, repeated practice. Tabletop exercises that simulate ransomware scenarios should go beyond the payment question and into the operational chaos that follows. Exercises involving third-party breaches should force participants to navigate the tension between transparency and partnership preservation. Technical exercises should compress timelines and demand the same speed of triage that a real exploitation campaign would require.</p>



<p>None of this is new advice. But the 2026 data makes the stakes clearer than ever. The organizations that build crisis response as a practiced skill will weather these incidents. Those that treat their incident response plan as a static document will learn its shortcomings the hard way.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.csoonline.com/expert-contributor-network/">Want to join?</a></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[5 AI risk management frameworks for shoring up key gaps]]></title>
<description><![CDATA[Organizations racing to embed AI into business operations are realizing that the risk management frameworks they’ve relied on for decades aren’t built for the behaviors, failure modes, and ethical complexities AI systems introduce.



Fortunately, a new generation of AI-specific frameworks has em...]]></description>
<link>https://tsecurity.de/de/3604146/it-security-nachrichten/5-ai-risk-management-frameworks-for-shoring-up-key-gaps/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3604146/it-security-nachrichten/5-ai-risk-management-frameworks-for-shoring-up-key-gaps/</guid>
<pubDate>Wed, 17 Jun 2026 11:09:04 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Organizations racing to embed AI into business operations are realizing that the risk management frameworks they’ve relied on for decades aren’t built for the behaviors, failure modes, and ethical complexities AI systems introduce.</p>



<p>Fortunately, a new generation of AI-specific frameworks has emerged to give organizations a structured way to identify where AI can go wrong, what controls to put in place, and how to demonstrate responsible AI use to regulators, customers, and investors. Not all of these emerging frameworks address the same problem. Some focus on governance and organizational accountability, others on technical security controls, threat modeling, or regulatory compliance. Choosing the right one for your organization depends on where your most pressing gaps reside.</p>



<p>The frameworks are complementary, not competing, because they have different intents, priorities, and objectives, says Nicole Carignan, CISO at Darktrace.</p>



<p>“There is overlap across these frameworks, but that overlap is helpful,” Carignan points out. “It reinforces the core practices organizations need to get right: governance, data integrity, security, accountability, oversight, testing, and continuous improvement.”</p>



<p>Here are five frameworks worth considering for your AI risk management needs.</p>



<h2 class="wp-block-heading">ISO/IEC 42001 Artificial Intelligence Management System</h2>



<p><a href="https://www.iso.org/standard/81230.html">ISO/IEC 42001:2023</a> is the first internationally recognized formal standard for AI management. Published by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC) in December 2023, ISO/IEC 42001 follows a similar structure to management system standards such as ISO 27001. The framework gives organizations a structured methodology for establishing policies, processes, operational controls, and accountability mechanisms to ensure responsible development and use of AI.</p>



<p>ISO/IEC 42001 requires companies to document how they design, monitor, validate, and control AI systems, while also requiring them to conduct AI impact assessments to evaluate potential legal, ethical, and societal impacts. The standard covers governance structures, third-party supplier oversight, data management, transparency obligations, and lifecycle management.</p>



<p>ISO/IEC 42001 is a voluntary but certifiable standard that applies across sectors and organization sizes. A growing number of organizations have begun using it to demonstrate adherence to responsible AI practice and alignment with regulations such as the <a href="https://artificialintelligenceact.eu/">EU AI Act</a>. The ISO/IEC have <a href="https://www.iso.org/home/insights-news/resources/iso-42001-explained-what-it-is.html?utm_source=chatgpt.com">described the framework</a> as helping organizations align their AI practices with legal and regulatory requirements; demonstrate responsible AI governance; manage risks tied to bias, safety, and security; and enhance stakeholder trust.</p>



<p>ISO 42001 is a great option for organizations just getting started with AI risk management, says Nicole Carignan, senior vice president for security and AI strategy and field CISO at Darktrace.</p>



<p>“It provides the strongest foundation for building an AI risk management program, rather than addressing individual AI risks in isolation,” she explains. “From a program-building standpoint, ISO 42001 is the right place to start because it forces organizations to think holistically about ownership, governance, oversight, data integrity, security risk mitigation, accountability, and continuous improvement.”</p>



<p>One downside Carignan is that the framework is resource-intensive to implement, and the full standard is not publicly available. Both challenges can be formidable for organizations that are very early in their AI governance journey, she says.</p>



<h2 class="wp-block-heading">NIST AI Risk Management Framework (AI RMF)</h2>



<p>Released by the US National Institute of Standards and Technology (NIST) in January 2023, the <a href="https://airc.nist.gov/AI_RMF_Knowledge_Base/AI_RMF">AI Risk Management Framework (AI RMF)</a> is a voluntary framework designed to help organizations of all sizes and across all sectors identify, assess, and manage risks associated with AI systems across their entire lifecycle.</p>



<p>The framework consists of two parts. The first offers guidance on how organizations should think about AI risks and the characteristics of trustworthy AI systems, such as validity, safety, security, transparency, explainability, privacy, and fairness. The second part is structured around four interconnected functions:</p>



<ul class="wp-block-list">
<li><strong>Govern</strong> focuses on what organizations need to do to build internal culture, policies, and accountability structures for AI use.</li>



<li><strong>Map</strong> involves understanding the broader context and potential risks of specific AI systems.</li>



<li><strong>Measure</strong> focuses on how organizations must evaluate and track those risks using both qualitative and quantitative methods.</li>



<li><strong>Manage</strong> provides guidance on risk prioritization and appropriate responses such as mitigation, transfer, or acceptance.</li>
</ul>



<p>NIST AI RMF includes a separate Playbook that provides practical implementation steps to help organizations implement each of these functions effectively.</p>



<p>For organizations that are not ready to pursue ISO 42001 formally, the NIST AI RMF can serve as a more flexible and accessible starting point, Carignan says.</p>



<p>“It is public and gives organizations a common language for understanding and mitigating AI risk,” she adds. “But if the goal is to build a durable AI risk program, ISO 42001 is the strongest foundation.”</p>



<p>Ram Varadarajan, CEO at Acalvio recommends NIST AI RMF as a good place for organization to get started on AI risk governance, “because it’s built around maturity rather than pass/fail audits.” Its gives organizations starting from zero an opportunity to discover where they stand rather than immediately handing out a failing grade.</p>



<p>“More importantly, it forces the three conversations that have to happen first: who owns AI risk, what AI is actually running, and who gets hurt if something goes wrong,” Vardarajan says.</p>



<p>While researchers at Forrester described NIST AI RMF as a <a href="https://www.forrester.com/blogs/nist-ai-risk-management-framework-1-0-what-it-means-for-enterprises/">step in the right direction</a> soon after its launch, they also expressed concern over conflicts of interest among the multiple stakeholders that helped draft the framework, the absence of an explicit role for data governance, and the fact that the framework was “still descriptive and not prescriptive.”</p>



<p>As a result, “Chief data officers and heads of data science need to navigate this framework wisely to interpret and apply it to their AI governance efforts,” the analyst firm advised.</p>



<h2 class="wp-block-heading">ENISA Framework for AI Cybersecurity Practices</h2>



<p>ENISA, the European Union Agency for Cybersecurity, developed its <a href="https://www.faicp-framework.com/">Framework for AI Cybersecurity Practices (FAICP)</a> in anticipation of the <a href="https://artificialintelligenceact.eu/">EU AI Act</a>. Published in June 2023, the framework gives EU organizations structured, AI-specific cybersecurity guidance for enhancing the trustworthiness of their AI activities.</p>



<p>FAICP is organized around three progressive layers. The first covers foundational information and communications technology cybersecurity practices that AI systems inherit by running on standard software infrastructure. The second addresses <a href="https://www.csoonline.com/article/4110008/top-cyber-threats-to-your-ai-systems-and-infrastructure.html">AI-specific risks</a>, including adversarial attacks, model tampering, data pipeline integrity, and <a href="https://www.csoonline.com/article/4015077/ai-supply-chain-threats-are-looming-as-security-practices-lag.html">supply chain security</a>. The third provides sector-specific guidance for regulated industries such as energy, healthcare, and telecommunications.</p>



<p>According to the European Parliament, FAICP’s layered nature provides organizations with “a gradual approach” to enhancing the trustworthiness of their AI activities.</p>



<p>FAICP is voluntary, but its close alignment with the EU AI Act and the <a href="https://www.enisa.europa.eu/topics/awareness-and-cyber-hygiene/raising-awareness-campaigns/network-and-information-systems-directive-2-nis2">NIS2 Directive</a>, which is the EU’s primary cybersecurity law, means that EU regulators consider the framework as a baseline for AI governance practices at all organizations doing business within the EU.</p>



<p>FAICP is important because “Europe’s AI Act will likely become the global reference point, the same way Europe’s data privacy law became the de facto standard for companies worldwide regardless of where they’re headquartered,” Vardarajan predicts.</p>



<p>“Within two to three years, expect two frameworks to dominate: the EU AI Act setting the legal floor, and NIST AI RMF providing the operational playbook for meeting it,” Vardarajan says.</p>



<h2 class="wp-block-heading">ISO/IEC 23894:2023 Information Technology — Artificial Intelligence — Guidance on Risk Management</h2>



<p>The <a href="https://www.iso.org/standard/77304.html">ISO/IEC 23894:2923</a> framework provides organizations with specific guidance on managing risks associated with artificial intelligence. Released jointly by ISO and IEC in February 2023, the framework builds on and adapts the ISO 31000 general risk management standard to address AI-specific risks such as those tied to<strong> </strong>algorithmic bias, model drift, unpredictable behavior, and lack of transparency in decision-making. It provides organizations a way to evaluate the likelihood and potential consequences of these risks throughout the full AI system lifecycle.</p>



<p>The ISO has <a href="https://iso-library.com/standard/23894/">described the standard</a> as a “companion to ISO 31000 (Risk Management) and ISO/IEC 42001 (AI Management Systems).” The main difference between ISO/IEC 42001 and ISO/IEC 23894 is that the former is a certifiable management system. It provides organizations with the full requirements for establishing, implementing, and maintaining an AI management system. ISO/IEC 23894:2023 on the other hand is a guidance-only standard focused on how to identify, assess, and manage AI-specific risks.</p>



<p>“Notably, ISO/IEC 23894 offers concrete examples of effective risk management implementation and integration throughout the AI development lifecycle and provides detailed information on AI-specific risk sources,” according to UK-backed <a href="https://aistandardshub.org/a-new-standard-for-ai-risk-management">AI Standards Hub</a>. “A key benefit of this standard is that application of the guidance can be customized to any organization and its business context.”</p>



<h2 class="wp-block-heading">Google Secure AI Framework (SAIF)</h2>



<p><strong><a href="https://saif.google/">Google Secure AI Framework (SAIF)</a></strong> is Google’s practical guide for helping organizations develop and run AI systems with strong built-in protections against digital threats. Launched in 2023, it focuses on weaving security and privacy considerations directly into every stage of an AI project’s life cycle, from design through deployment and ongoing operation.</p>



<p>Its main goal is to tackle the unique vulnerabilities that come with AI technologies such as attacks that tamper with training data, trick models through engineered prompts, or steal sensitive information. SAIF draws on Google’s own experiences developing and deploying large scale AI systems and therefore is more engineering-heavy than other frameworks. SAIF is largely focused on helping organizations make their AI systems more resistant to cyberattacks and cyber adversaries and covers areas like data handling, underlying infrastructure, the AI models themselves, user-facing applications and verification processes. It offers organizations practical guidance on implementation controls, shared responsibility, and defending against technical attacks.</p>



<p>Technology consultancy Thoughtworks has assessed SAIF as a framework that helps organizations systematically address “common threats such as data poisoning and prompt injection through a clear risk map, component analysis, and practical mitigation strategies.” According to the firm, SAIF’s “focus on the evolving risks of building agentic systems especially timely and valuable. SAIF offers a concise, actionable playbook that teams can use to strengthen security practices for LLM usage and AI-driven applications.”</p>



<p>David Brumley, chief AI and science officer at Bugcrowd, says that for organizations that want to adopt a framework, the question is not really “which AI risk framework is best?” but “which framework helps [the] organization safely build, deploy, and learn from AI in the real world?”</p>



<p>While most of the currently available AI risk frameworks have their use, most are still focused on preventing bad outcomes rather than helping organizations pave safe roads for a technology that is already inevitable.</p>



<p>“That distinction matters,” Brumley says. “AI adoption is not waiting for perfect governance, and those who focus on a [risk management framework] could inadvertently create a shadow AI problem in their organization.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft says you don’t need another email security tool; experts say, not so fast]]></title>
<description><![CDATA[Despite best efforts by defenders, malicious emails continue to slip through the cybersecurity cracks, leading some enterprises to implement a layered “defense in depth” strategy that incorporates multiple tools.



Microsoft seems to be challenging this idea, revealing that there are only nomina...]]></description>
<link>https://tsecurity.de/de/3603512/it-security-nachrichten/microsoft-says-you-dont-need-another-email-security-tool-experts-say-not-so-fast/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3603512/it-security-nachrichten/microsoft-says-you-dont-need-another-email-security-tool-experts-say-not-so-fast/</guid>
<pubDate>Wed, 17 Jun 2026 05:23:30 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Despite best efforts by defenders, malicious emails continue to <a href="https://www.csoonline.com/article/4183653/aged-domain-acquisition-the-tradecraft-phishing-operators-are-using-to-bypass-your-mail-filters-reputation-score.html" target="_blank">slip through the cybersecurity cracks</a>, leading some enterprises to implement a layered “defense in depth” strategy that incorporates multiple tools.</p>



<p>Microsoft seems to be challenging this idea, revealing that there are only nominal returns from adding integrated pre- and post-send partners to Defender for Office 365’s protections.</p>



<p>According to its new quarterly benchmarking data, the tech giant catches the vast majority of malicious and spam emails before delivery, misses the fewest compared to competitors by a wide margin, and removes nearly 100% of dangerous emails that do reach the inbox. Collectively, its integrated partners improve that catch rate by less than .05%.</p>



<p>While these numbers seem to tip the scales towards a one-vendor email security stack, experts urge enterprises to be skeptical and cautious of such vendor claims.</p>



<p><a href="https://www.infotech.com/profiles/seva-ioussoufovitch" target="_blank" rel="noreferrer noopener">Seva Ioussoufovitch</a>, senior research analyst at Info-Tech Research Group, pointed out, “percentages obscure the true quantity and severity of what’s getting through, and, considering it only takes one message to result in an incident, it’s simple enough to argue that there is real value in the defense in depth that having multiple tools provides.”</p>



<h2 class="wp-block-heading">Malicious and spam email catch by the numbers</h2>



<p>Microsoft introduced its quarterly benchmarking report in July 2025 alongside a Defender integrated cloud email security (ICES) ecosystem designed to support multi-vendor security strategies.</p>



<p>The SEG players it ranked itself against this year includes Mimecast, Proofpoint, Hornetsecurity, Trend Micro, Iron Port (Cisco), Barracuda, and FireEye (Trellix); ICES companies include Abnormal, Checkpoint Harmony, Cisco, DarkTrace, KnowBe4 Defend, Tessian, and Trend Micro.</p>



<p>Redmond reported that Defender “consistently leads” in pre-delivery detection, missing 59% fewer high-severity cyberthreats prior to delivery than the other SEG vendors it evaluated. Its closest competitors were Mimecast and Proofpoint. The company also introduced a new metric in this area: A threat miss rate per 1,000 employees. In Microsoft’s case, that was 194 per 1,000; for Mimecast, 478; for Proofpoint, 483.</p>



<p>When it came to post-delivery protection, Defender removed an average of 96.03% of malicious emails that reached the inbox, up from an initial 45% when Microsoft first started tracking the data in its second report.</p>



<p>This makes Defender “an increasingly critical backstop, operating even when ICES solutions are in place,” Jeff Pinkston, VP and GM for Microsoft Defender, wrote in a <a href="https://www.microsoft.com/en-us/security/blog/2026/06/15/microsoft-defender-email-security-benchmarking-key-insights-from-one-year-of-data/" target="_blank" rel="noreferrer noopener">blog post</a>. Still, ICES tools operating in tandem with Microsoft Defender “continue to provide benefits,” improving malicious catch by 0.29% and spam catch by 0.68%, he said.</p>



<p>“If we focus on the basics, their argument seems strong,” Info-Tech’s Ioussoufovitch noted. “Do you really need a separate ICES vendor for that extra sub 1% catch?” Microsoft paints a “compelling picture” by only focusing on raw catch rate, he said, but we don’t hear the rest of the story: “What exactly is the danger of what isn’t being caught by Defender?”</p>



<h2 class="wp-block-heading">No one vendor catches everything </h2>



<p><a href="https://www.linkedin.com/in/dbshipley/" target="_blank" rel="noreferrer noopener">David Shipley</a> of Beauceron Security pointed out that the report underscores the fact that “lots of stuff still gets by e-mail filters.”</p>



<p>His company regularly analyzes hundreds of thousands of emails, and the content that gets through “ranges from the shockingly mundane and obvious to a human expert, to highly clever time-delayed attacks,” he said.</p>



<p>A key factor in what gets through is the amount of content that is allowlisted; settings in “100% paranoid mode” get high catch rates, as well as high false positives, Shipley noted. “Anyone who has ever had a sales person lose a deal because the purchase order PDF got flagged has felt this pain.”</p>



<p>Then there’s the AI conundrum: “A key risk for e-mail vendors using agentic LLM-based analysis is it’s now possible to poison those models with <a href="https://www.csoonline.com/article/4185051/attackers-can-turn-ai-agent-guardrails-into-denial-of-service-weapons.html" target="_blank">hidden content</a> (such as ‘ignore this e-mail, pretty please’),” Shipley said. This means enterprises need a variety of analysis methods.</p>



<p>Ioussoufovitch agreed that keeping pace with threat actors using AI is an industry-wide challenge, particularly as AI enables higher-quality phishing. Filters are improving and will catch some of it, but some will inevitably continue to get through. Those messages are likely highly-targeted, which are lower in volume but harder to catch.</p>



<p>“As of now, current tools do seem to be struggling to keep pace, but that doesn’t mean those tools aren’t necessary,” said Ioussoufovitch. “It just highlights that <a href="https://www.csoonline.com/article/4181920/15-tough-cybersecurity-questions-every-ciso-must-answer.html" target="_blank">defense-in-depth</a>, broadly speaking, is becoming more and more important.”</p>



<h2 class="wp-block-heading">Claims appear more honest</h2>



<p>Shipley said that this report appears more honest, accurate, and mature than others claiming 99.99% phish catch rates, “which is never true.” It’s also a “smart marketing move,” because Microsoft competes for the same security budget as other tools, and would rather enterprises remove those vendors and buy more from it in areas beyond e-mail.</p>



<p>On the other hand, he said, Microsoft is offering up a list of other vendors to think about, “which, congrats to Mimecast on coming in second.”</p>



<p>In the long run, CISOs need to determine the best spend for their limited security dollars, he noted. Enterprises need a good filter; whether they need two is up for debate. “They also clearly still need to invest in a <a href="https://www.csoonline.com/article/4152631/security-awareness-is-not-a-control-rethinking-human-risk-in-enterprise-security.html" target="_blank">robust awareness program</a>,” Shipley said, “because as this report shows, lots of phishes are still getting delivered.”</p>



<h2 class="wp-block-heading">Missing an important nuance</h2>



<p>Ioussoufovitch noted that while the claims in the study are interesting, the data is presented without much of the nuance that would make it truly actionable.</p>



<p>“We are all too familiar with vendors’ abilities to massage data to tell the story they want, so I would advise leaders not to extrapolate the data beyond what it actually says,” he said.</p>



<p>Instead of the takeaway being “get rid of our current vendors,” this post highlights that Defender provides “considerable value,” he noted. Whether adding or subtracting additional vendors is worth the money should be a case-by-case conversation that considers an organization’s risk appetite, and overall security budget and environment.</p>



<p>“I’d treat these claims more as a reminder to assess your own environment and compare detections,” he said. “Come to conclusions based on the data you have, not what a vendor is presenting.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft says you don’t need another email security tool; experts say, not so fast]]></title>
<description><![CDATA[Despite best efforts by defenders, malicious emails continue to slip through the cybersecurity cracks, leading some enterprises to implement a layered “defense in depth” strategy that incorporates multiple tools.



Microsoft seems to be challenging this idea, revealing that there are only nomina...]]></description>
<link>https://tsecurity.de/de/3603505/it-nachrichten/microsoft-says-you-dont-need-another-email-security-tool-experts-say-not-so-fast/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3603505/it-nachrichten/microsoft-says-you-dont-need-another-email-security-tool-experts-say-not-so-fast/</guid>
<pubDate>Wed, 17 Jun 2026 05:18:01 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Despite best efforts by defenders, malicious emails continue to <a href="https://www.csoonline.com/article/4183653/aged-domain-acquisition-the-tradecraft-phishing-operators-are-using-to-bypass-your-mail-filters-reputation-score.html" target="_blank">slip through the cybersecurity cracks</a>, leading some enterprises to implement a layered “defense in depth” strategy that incorporates multiple tools.</p>



<p>Microsoft seems to be challenging this idea, revealing that there are only nominal returns from adding integrated pre- and post-send partners to Defender for Office 365’s protections.</p>



<p>According to its new quarterly benchmarking data, the tech giant catches the vast majority of malicious and spam emails before delivery, misses the fewest compared to competitors by a wide margin, and removes nearly 100% of dangerous emails that do reach the inbox. Collectively, its integrated partners improve that catch rate by less than .05%.</p>



<p>While these numbers seem to tip the scales towards a one-vendor email security stack, experts urge enterprises to be skeptical and cautious of such vendor claims.</p>



<p><a href="https://www.infotech.com/profiles/seva-ioussoufovitch" target="_blank" rel="noreferrer noopener">Seva Ioussoufovitch</a>, senior research analyst at Info-Tech Research Group, pointed out, “percentages obscure the true quantity and severity of what’s getting through, and, considering it only takes one message to result in an incident, it’s simple enough to argue that there is real value in the defense in depth that having multiple tools provides.”</p>



<h2 class="wp-block-heading">Malicious and spam email catch by the numbers</h2>



<p>Microsoft introduced its quarterly benchmarking report in July 2025 alongside a Defender integrated cloud email security (ICES) ecosystem designed to support multi-vendor security strategies.</p>



<p>The SEG players it ranked itself against this year includes Mimecast, Proofpoint, Hornetsecurity, Trend Micro, Iron Port (Cisco), Barracuda, and FireEye (Trellix); ICES companies include Abnormal, Checkpoint Harmony, Cisco, DarkTrace, KnowBe4 Defend, Tessian, and Trend Micro.</p>



<p>Redmond reported that Defender “consistently leads” in pre-delivery detection, missing 59% fewer high-severity cyberthreats prior to delivery than the other SEG vendors it evaluated. Its closest competitors were Mimecast and Proofpoint. The company also introduced a new metric in this area: A threat miss rate per 1,000 employees. In Microsoft’s case, that was 194 per 1,000; for Mimecast, 478; for Proofpoint, 483.</p>



<p>When it came to post-delivery protection, Defender removed an average of 96.03% of malicious emails that reached the inbox, up from an initial 45% when Microsoft first started tracking the data in its second report.</p>



<p>This makes Defender “an increasingly critical backstop, operating even when ICES solutions are in place,” Jeff Pinkston, VP and GM for Microsoft Defender, wrote in a <a href="https://www.microsoft.com/en-us/security/blog/2026/06/15/microsoft-defender-email-security-benchmarking-key-insights-from-one-year-of-data/" target="_blank" rel="noreferrer noopener">blog post</a>. Still, ICES tools operating in tandem with Microsoft Defender “continue to provide benefits,” improving malicious catch by 0.29% and spam catch by 0.68%, he said.</p>



<p>“If we focus on the basics, their argument seems strong,” Info-Tech’s Ioussoufovitch noted. “Do you really need a separate ICES vendor for that extra sub 1% catch?” Microsoft paints a “compelling picture” by only focusing on raw catch rate, he said, but we don’t hear the rest of the story: “What exactly is the danger of what isn’t being caught by Defender?”</p>



<h2 class="wp-block-heading">No one vendor catches everything </h2>



<p><a href="https://www.linkedin.com/in/dbshipley/" target="_blank" rel="noreferrer noopener">David Shipley</a> of Beauceron Security pointed out that the report underscores the fact that “lots of stuff still gets by e-mail filters.”</p>



<p>His company regularly analyzes hundreds of thousands of emails, and the content that gets through “ranges from the shockingly mundane and obvious to a human expert, to highly clever time-delayed attacks,” he said.</p>



<p>A key factor in what gets through is the amount of content that is allowlisted; settings in “100% paranoid mode” get high catch rates, as well as high false positives, Shipley noted. “Anyone who has ever had a sales person lose a deal because the purchase order PDF got flagged has felt this pain.”</p>



<p>Then there’s the AI conundrum: “A key risk for e-mail vendors using agentic LLM-based analysis is it’s now possible to poison those models with <a href="https://www.csoonline.com/article/4185051/attackers-can-turn-ai-agent-guardrails-into-denial-of-service-weapons.html" target="_blank">hidden content</a> (such as ‘ignore this e-mail, pretty please’),” Shipley said. This means enterprises need a variety of analysis methods.</p>



<p>Ioussoufovitch agreed that keeping pace with threat actors using AI is an industry-wide challenge, particularly as AI enables higher-quality phishing. Filters are improving and will catch some of it, but some will inevitably continue to get through. Those messages are likely highly-targeted, which are lower in volume but harder to catch.</p>



<p>“As of now, current tools do seem to be struggling to keep pace, but that doesn’t mean those tools aren’t necessary,” said Ioussoufovitch. “It just highlights that <a href="https://www.csoonline.com/article/4181920/15-tough-cybersecurity-questions-every-ciso-must-answer.html" target="_blank">defense-in-depth</a>, broadly speaking, is becoming more and more important.”</p>



<h2 class="wp-block-heading">Claims ‘appear more honest’</h2>



<p>Shipley said that this report appears more honest, accurate, and mature than others claiming 99.99% phish catch rates, “which is never true.” It’s also a “smart marketing move,” because Microsoft competes for the same security budget as other tools, and would rather enterprises remove those vendors and buy more from it in areas beyond e-mail.</p>



<p>On the other hand, he said, Microsoft is offering up a list of other vendors to think about, “which, congrats to Mimecast on coming in second.”</p>



<p>In the long run, CISOs need to determine the best spend for their limited security dollars, he noted. Enterprises need a good filter; whether they need two is up for debate. “They also clearly still need to invest in a <a href="https://www.csoonline.com/article/4152631/security-awareness-is-not-a-control-rethinking-human-risk-in-enterprise-security.html" target="_blank">robust awareness program</a>,” Shipley said, “because as this report shows, lots of phishes are still getting delivered.”</p>



<h2 class="wp-block-heading">Missing an important nuance</h2>



<p>Ioussoufovitch noted that while the claims in the study are interesting, the data is presented without much of the nuance that would make it truly actionable.</p>



<p>“We are all too familiar with vendors’ abilities to massage data to tell the story they want, so I would advise leaders not to extrapolate the data beyond what it actually says,” he said.</p>



<p>Instead of the takeaway being “get rid of our current vendors,” this post highlights that Defender provides “considerable value,” he noted. Whether adding or subtracting additional vendors is worth the money should be a case-by-case conversation that considers an organization’s risk appetite, and overall security budget and environment.</p>



<p>“I’d treat these claims more as a reminder to assess your own environment and compare detections,” he said. “Come to conclusions based on the data you have, not what a vendor is presenting.”</p>



<p><em>This article originally appeared on <a href="https://www.csoonline.com/article/4185954/microsoft-says-you-dont-need-another-email-security-tool-experts-say-not-so-fast.html" target="_blank">CSOonline</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft says you don’t need another email security tool; experts say, not so fast]]></title>
<description><![CDATA[Despite best efforts by defenders, malicious emails continue to slip through the cybersecurity cracks, leading some enterprises to implement a layered “defense in depth” strategy that incorporates multiple tools.



Microsoft seems to be challenging this idea, revealing that there are only nomina...]]></description>
<link>https://tsecurity.de/de/3603504/it-nachrichten/microsoft-says-you-dont-need-another-email-security-tool-experts-say-not-so-fast/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3603504/it-nachrichten/microsoft-says-you-dont-need-another-email-security-tool-experts-say-not-so-fast/</guid>
<pubDate>Wed, 17 Jun 2026 05:18:00 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Despite best efforts by defenders, malicious emails continue to <a href="https://www.csoonline.com/article/4183653/aged-domain-acquisition-the-tradecraft-phishing-operators-are-using-to-bypass-your-mail-filters-reputation-score.html" target="_blank">slip through the cybersecurity cracks</a>, leading some enterprises to implement a layered “defense in depth” strategy that incorporates multiple tools.</p>



<p>Microsoft seems to be challenging this idea, revealing that there are only nominal returns from adding integrated pre- and post-send partners to Defender for Office 365’s protections.</p>



<p>According to its new quarterly benchmarking data, the tech giant catches the vast majority of malicious and spam emails before delivery, misses the fewest compared to competitors by a wide margin, and removes nearly 100% of dangerous emails that do reach the inbox. Collectively, its integrated partners improve that catch rate by less than .05%.</p>



<p>While these numbers seem to tip the scales towards a one-vendor email security stack, experts urge enterprises to be skeptical and cautious of such vendor claims.</p>



<p><a href="https://www.infotech.com/profiles/seva-ioussoufovitch" target="_blank" rel="nofollow">Seva Ioussoufovitch</a>, senior research analyst at Info-Tech Research Group, pointed out, “percentages obscure the true quantity and severity of what’s getting through, and, considering it only takes one message to result in an incident, it’s simple enough to argue that there is real value in the defense in depth that having multiple tools provides.”</p>



<h2 class="wp-block-heading">Malicious and spam email catch by the numbers</h2>



<p>Microsoft introduced its quarterly benchmarking report in July 2025 alongside a Defender integrated cloud email security (ICES) ecosystem designed to support multi-vendor security strategies.</p>



<p>The SEG players it ranked itself against this year includes Mimecast, Proofpoint, Hornetsecurity, Trend Micro, Iron Port (Cisco), Barracuda, and FireEye (Trellix); ICES companies include Abnormal, Checkpoint Harmony, Cisco, DarkTrace, KnowBe4 Defend, Tessian, and Trend Micro.</p>



<p>Redmond reported that Defender “consistently leads” in pre-delivery detection, missing 59% fewer high-severity cyberthreats prior to delivery than the other SEG vendors it evaluated. Its closest competitors were Mimecast and Proofpoint. The company also introduced a new metric in this area: A threat miss rate per 1,000 employees. In Microsoft’s case, that was 194 per 1,000; for Mimecast, 478; for Proofpoint, 483.</p>



<p>When it came to post-delivery protection, Defender removed an average of 96.03% of malicious emails that reached the inbox, up from an initial 45% when Microsoft first started tracking the data in its second report.</p>



<p>This makes Defender “an increasingly critical backstop, operating even when ICES solutions are in place,” Jeff Pinkston, VP and GM for Microsoft Defender, wrote in a <a href="https://www.microsoft.com/en-us/security/blog/2026/06/15/microsoft-defender-email-security-benchmarking-key-insights-from-one-year-of-data/" target="_blank" rel="nofollow">blog post</a>. Still, ICES tools operating in tandem with Microsoft Defender “continue to provide benefits,” improving malicious catch by 0.29% and spam catch by 0.68%, he said.</p>



<p>“If we focus on the basics, their argument seems strong,” Info-Tech’s Ioussoufovitch noted. “Do you really need a separate ICES vendor for that extra sub 1% catch?” Microsoft paints a “compelling picture” by only focusing on raw catch rate, he said, but we don’t hear the rest of the story: “What exactly is the danger of what isn’t being caught by Defender?”</p>



<h2 class="wp-block-heading">No one vendor catches everything </h2>



<p><a href="https://www.linkedin.com/in/dbshipley/" target="_blank" rel="nofollow">David Shipley</a> of Beauceron Security pointed out that the report underscores the fact that “lots of stuff still gets by e-mail filters.”</p>



<p>His company regularly analyzes hundreds of thousands of emails, and the content that gets through “ranges from the shockingly mundane and obvious to a human expert, to highly clever time-delayed attacks,” he said.</p>



<p>A key factor in what gets through is the amount of content that is allowlisted; settings in “100% paranoid mode” get high catch rates, as well as high false positives, Shipley noted. “Anyone who has ever had a sales person lose a deal because the purchase order PDF got flagged has felt this pain.”</p>



<p>Then there’s the AI conundrum: “A key risk for e-mail vendors using agentic LLM-based analysis is it’s now possible to poison those models with <a href="https://www.csoonline.com/article/4185051/attackers-can-turn-ai-agent-guardrails-into-denial-of-service-weapons.html" target="_blank">hidden content</a> (such as ‘ignore this e-mail, pretty please’),” Shipley said. This means enterprises need a variety of analysis methods.</p>



<p>Ioussoufovitch agreed that keeping pace with threat actors using AI is an industry-wide challenge, particularly as AI enables higher-quality phishing. Filters are improving and will catch some of it, but some will inevitably continue to get through. Those messages are likely highly-targeted, which are lower in volume but harder to catch.</p>



<p>“As of now, current tools do seem to be struggling to keep pace, but that doesn’t mean those tools aren’t necessary,” said Ioussoufovitch. “It just highlights that <a href="https://www.csoonline.com/article/4181920/15-tough-cybersecurity-questions-every-ciso-must-answer.html" target="_blank">defense-in-depth</a>, broadly speaking, is becoming more and more important.”</p>



<h2 class="wp-block-heading">Claims ‘appear more honest’</h2>



<p>Shipley said that this report appears more honest, accurate, and mature than others claiming 99.99% phish catch rates, “which is never true.” It’s also a “smart marketing move,” because Microsoft competes for the same security budget as other tools, and would rather enterprises remove those vendors and buy more from it in areas beyond e-mail.</p>



<p>On the other hand, he said, Microsoft is offering up a list of other vendors to think about, “which, congrats to Mimecast on coming in second.”</p>



<p>In the long run, CISOs need to determine the best spend for their limited security dollars, he noted. Enterprises need a good filter; whether they need two is up for debate. “They also clearly still need to invest in a <a href="https://www.csoonline.com/article/4152631/security-awareness-is-not-a-control-rethinking-human-risk-in-enterprise-security.html" target="_blank">robust awareness program</a>,” Shipley said, “because as this report shows, lots of phishes are still getting delivered.”</p>



<h2 class="wp-block-heading">Missing an important nuance</h2>



<p>Ioussoufovitch noted that while the claims in the study are interesting, the data is presented without much of the nuance that would make it truly actionable.</p>



<p>“We are all too familiar with vendors’ abilities to massage data to tell the story they want, so I would advise leaders not to extrapolate the data beyond what it actually says,” he said.</p>



<p>Instead of the takeaway being “get rid of our current vendors,” this post highlights that Defender provides “considerable value,” he noted. Whether adding or subtracting additional vendors is worth the money should be a case-by-case conversation that considers an organization’s risk appetite, and overall security budget and environment.</p>



<p>“I’d treat these claims more as a reminder to assess your own environment and compare detections,” he said. “Come to conclusions based on the data you have, not what a vendor is presenting.”</p>



<p><em>This article originally appeared on <a href="https://www.csoonline.com/article/4185954/microsoft-says-you-dont-need-another-email-security-tool-experts-say-not-so-fast.html" target="_blank">CSOonline</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Cloud security metrics and KPIs: A CISO’s guide]]></title>
<description><![CDATA[Cloud security is no longer just about deploying controls. Instead, it’s about measuring effectiveness, demonstrating risk reduction and communicating outcomes clearly to leadership and to the board. To that end, cloud security metrics and KPIs are essential. These tools…
Read more →
The post Clo...]]></description>
<link>https://tsecurity.de/de/3602826/it-security-nachrichten/cloud-security-metrics-and-kpis-a-cisos-guide/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3602826/it-security-nachrichten/cloud-security-metrics-and-kpis-a-cisos-guide/</guid>
<pubDate>Tue, 16 Jun 2026 20:09:07 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>&lt;p&gt;Cloud security is no longer just about deploying controls. Instead, it’s about measuring effectiveness, demonstrating risk reduction and &lt;a href=”https://www.techtarget.com/searchsecurity/feature/6-ways-to-spur-cybersecurity-board-engagement”&gt;communicating outcomes&lt;/a&gt; clearly to leadership and to the board.&lt;/p&gt; &lt;p&gt;To that end, cloud security metrics and KPIs are essential. These tools…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/cloud-security-metrics-and-kpis-a-cisos-guide/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/cloud-security-metrics-and-kpis-a-cisos-guide/">Cloud security metrics and KPIs: A CISO’s guide</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Cloud security metrics and KPIs: A CISO's guide]]></title>
<description><![CDATA[Today's distributed computing environments require a cloud strategy that goes well beyond choosing the best security tools. Instead, CISOs need a far more integrated approach.]]></description>
<link>https://tsecurity.de/de/3602755/it-security-nachrichten/cloud-security-metrics-and-kpis-a-cisos-guide/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3602755/it-security-nachrichten/cloud-security-metrics-and-kpis-a-cisos-guide/</guid>
<pubDate>Tue, 16 Jun 2026 19:37:44 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Today's distributed computing environments require a cloud strategy that goes well beyond choosing the best security tools. Instead, CISOs need a far more integrated approach.]]></content:encoded>
</item>
<item>
<title><![CDATA[Security Standards]]></title>
<description><![CDATA[Author: Microsoft Security - Bewertung: 0x - Views:13 In this video, Tony Rice, Principal Security Program Manager, walks through how Microsoft governs security at scale using its Secure Development Lifecycle (SDL)—a framework that has evolved over more than 20 years and now underpins the company...]]></description>
<link>https://tsecurity.de/de/3602331/it-security-video/security-standards/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3602331/it-security-video/security-standards/</guid>
<pubDate>Tue, 16 Jun 2026 17:19:34 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Microsoft Security - Bewertung: 0x - Views:13 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/oyciotF-qGA?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>In this video, Tony Rice, Principal Security Program Manager, walks through how Microsoft governs security at scale using its Secure Development Lifecycle (SDL)—a framework that has evolved over more than 20 years and now underpins the company’s Secure Future Initiative (SFI).<br />
<br />
You’ll get an inside look at how Microsoft:<br />
- Governs security requirements across the enterprise<br />
- Embeds security directly into engineering workflows<br />
- Scales assurance through automation, secure defaults, and data‑driven KPIs<br />
- Balances automated controls with human‑driven security reviews<br />
- Produces transparent, auditable evidence to support internal and external compliance<br />
<br />
The session also introduces Microsoft’s Security Assurance Governance Ecosystem (SAGE) and explains how requirements, compliance measurement, tooling, and remediation actions are connected—turning security policy into practical, enforceable engineering outcomes.<br />
<br />
For more guidance from the Office of the CISO, explore Office of the CISO Insights on the Microsoft Security Blog →  https://msft.it/6056QCwL4<br />
<br />
#Microsoft #MicrosoftSecurity #CISO #SDLGovernance<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Cloud strategies have become more complicated than ever]]></title>
<description><![CDATA[With years of cloud experience, IT leaders thought they finally had firm control of their cloud strategies. And then came AI.



Of course, cloud issues today extend beyond artificial intelligence. Where to place cloud workloads for maximum efficiency is one. Questions about governance, sovereign...]]></description>
<link>https://tsecurity.de/de/3602225/it-security-nachrichten/cloud-strategies-have-become-more-complicated-than-ever/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3602225/it-security-nachrichten/cloud-strategies-have-become-more-complicated-than-ever/</guid>
<pubDate>Tue, 16 Jun 2026 16:57:06 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>With years of cloud experience, IT leaders thought they finally had firm control of their cloud strategies. And then came AI.</p>



<p>Of course, cloud issues today extend beyond artificial intelligence. Where to place cloud workloads for maximum efficiency is one. Questions about governance, sovereignty, the growing sophistication of cyberthreats, and escalating cost concerns are also conspiring to make the cloud ever more complicated.</p>



<p>“It’s just grown into a complex mess,” observes cloud expert <a href="https://www.infoworld.com/profile/david-linthicum/">David Linthicum</a>, emphasizing that cloud strategy today needs to address private cloud, multicloud, hybrid cloud, and sovereign clouds — much more than most CIOs have dealt with to date.</p>



<p>Initially, cloud discussions centered around agility, scalability, and cost optimization, says <a href="https://www.joshuabellendir.com/">Joshua Bellendir</a>, CIO of retailer WHSmith North America. “Today, we are balancing a much broader and more complicated set of considerations, including AI readiness, cybersecurity, data governance, sovereign data requirements, edge computing, integration architecture, and operational resilience.”</p>



<p>One of the biggest shifts is that “cloud is no longer simply an infrastructure conversation,” Bellendir says. “It has become deeply tied to enterprise architecture, business transformation strategy, and data strategy.”</p>



<p><a href="https://www.linkedin.com/in/amitbasu/">Amit Basu</a>, vice president, CIO, and CISO of International Seaways, also notes cloud’s growing complexity. While reduced capital expenditure and greater flexibility still apply in some areas, dealing with the environment has become significantly more challenging, he says.</p>



<p>Sweetwater CIO <a href="https://www.linkedin.com/in/jasonpauljohnson/">Jason Johnson</a> describes the current state as “genuinely one of the more complex times to be managing cloud.” Providers keep expanding their catalogs with more SKUs, more services, and more options, he says. “While that’s great for capability, it creates real overhead in just keeping up. You need people who understand not just what’s available, but what’s actually the right fit for your use case.”</p>



<p>Many organizations are now entering a second phase of cloud maturity. “The earlier phase was focused heavily on migration and modernization,” Johnson says. “The current phase is more focused on optimization, governance, AI enablement, and operational sustainability. That shift is changing the conversation significantly for the CIOs I’m speaking with.”</p>



<p>But few CIOs have the luxury of simply pondering what to do. All must meet the challenges of complexifying cloud strategies head on.</p>



<h2 class="wp-block-heading">How AI changes the cloud calculus</h2>



<p>The desire to deploy AI quickly is creating tremendous pressure on IT leaders, with cloud a central concern, Linthicum says.</p>



<p>“The board of directors are screaming for it worse than the cloud push 15 years ago,” he says. “CIOs are feeling the pinch and having to make that move as quickly as they can” to gain more compute for AI initiatives in an already tricky environment, he adds.</p>



<p>At the same time, CIOs must solve the data complexity problem before integrating AI systems, Linthicum notes. “They’re running around in circles right now trying to figure out the best way to do that.”</p>



<p>Hyperscalers used to be “the easy button,” Linthicum says, “but they’ll be three, four times the cost.”</p>



<p>AI systems cost 10 times as much as traditional equivalent applications, he estimates. “So [CIOs are] putting a lot of money on the line.”</p>



<p>International Seaways’ Basu says AI has changed the architecture conversation. “GPU availability, vector databases, low-latency inference, and large-scale data pipelines introduce requirements that do not fit neatly into traditional cloud design models,” he notes. “Organizations are no longer simply lifting and shifting workloads. They are designing for very different compute and data requirements.”</p>



<p><a href="https://www.linkedin.com/in/zacharylewis1/">Zachary Lewis</a>, CIO and CISO of University of Health Sciences and Pharmacy, says the needs of internal stakeholders only compound that complexity. <a href="https://www.linkedin.com/in/zacharylewis1/">Business unit</a>s want disparate AI capabilities, security teams want governance and some control over AI apps, the general counsel wants to know what kind of data is being put in the AI model, and the finance team wants cost predictability.</p>



<p>“CIOs have to reconcile all of this and try to deliver on everyone’s needs, and you have to do that successfully,” Lewis says. “Everyone has a different end goal and demand and we’re trying to square all of that for them.”</p>



<p>Ever since the online retailer of musical instruments and pro audio equipment formalized its cloud strategy around 2016, Sweetwater’s Johnson has sought to place workloads wherever it made the most sense for external and internal customers.</p>



<p>“Anything customer-facing needs to be geo-specific; as close to the end user as possible,” he says. “Same logic applies — internal workloads belong close to whoever is using them.”</p>



<p>The cloud offers infinite opportunities, and with that comes infinite levels of complexity, he says. “It’s just the reality of the model.”</p>



<p>“AI wouldn’t be possible without the cloud. The compute scale AI needed had already been built — the cloud had it and could deliver it,” he adds. “In a lot of ways, AI might be the cloud’s greatest gift to the industry. They enabled each other.”</p>



<h2 class="wp-block-heading">Cloud cost control complexifies</h2>



<p>Johnson’s biggest headache is managing costs consistently. “It used to be relatively straightforward: compute, storage, egress. Now it’s a puzzle,” he says. “Reserved instances, savings plans, spot pricing, per-request costs, data transfer fees between regions — it stacks up fast — and it’s genuinely hard to predict what your bill is going to look like until it arrives.”</p>



<p>Consequently, <a href="https://www.cio.com/article/416337/what-is-finops-your-guide-to-cloud-cost-management.html">FinOps</a> has become a discipline in its own right, he says.</p>



<p>Basu also believes FinOps has become essential. “AI inference costs, egress charges, and storage growth can create month-over-month cost swings that surprise even experienced teams,” he says. “Cost management is now a continuous operational discipline rather than an occasional review exercise.”</p>



<p>Vendor lock-in is also always in the back of Johnson’s mind. “The more deeply you integrate with a provider’s native services, the harder it is to move.” While that’s not always bad, he adds, it’s a tradeoff. “I think about it like technical debt. You’re borrowing speed now and paying interest later if you ever want to change direction.”</p>



<p>But Johnson recognizes that cloud providers are businesses that “squeeze for revenue and margin, and they change the rules on how you buy committed discounts and manage spend.”</p>



<p>Financial efficiency doesn’t happen by accident, he points out. It requires teams, processes, and real investment in FinOps. “<a href="https://www.cio.com/article/189652/top-13-cloud-cost-management-tools.html">The tools exist</a>. Using them well is the harder part,” he says.</p>



<p>Most organizations have their financial expertise sitting in accounting and their technical expertise sitting in IT, Johnson explains. Getting those two to work together on cloud cost is a relatively new challenge.</p>



<p>“Ten years ago, the model was simple: You asked for a CapEx budget, accounting approved it, you placed hardware orders, and IT installed and optimized. Done. Now it’s a daily exercise,” Johnson says. “New services get turned on, contracts change, pricing structures shift. Finance understands the cash but not the tech. IT understands the tech but not the financial levers.”</p>



<p>Every major cloud provider has the tools, Johnson explains. “AWS Cost Explorer, Azure Cost Management, GCP’s billing dashboards. The data is all there.” But most organizations aren’t acting on that data, he says, “and then the bill shows up and people are surprised. The tools told you it was coming. You just weren’t listening.”</p>



<h2 class="wp-block-heading">Data regulations add sovereign subtleties</h2>



<p>The University of Health Sciences and Pharmacy has students from all over the world. Cloud has become significantly more difficult to manage due to the <a href="https://www.cio.com/article/4168666/cios-rise-to-the-global-challenge.html">rise in regulatory laws around the globe</a> surrounding data, Lewis says.</p>



<p>“We have to understand if the metadata is in a specific cloud region, where it is stored, and kept,” he says. “If that data ends up in a model we trained internally, can we guarantee it stays in the EU? Then, if someone wants their data purged, can we find all those locations with some level of competence?”</p>



<p>Basu says data sovereignty has become another major architectural consideration. “It affects where workloads can run, how data moves between regions, and what can be done with certain datasets,” he says. “You cannot assume a hyperscaler’s default configuration satisfies your regulatory obligations.”</p>



<h2 class="wp-block-heading">Private vs. public vs. on-prem</h2>



<p>AI has <a href="https://www.cio.com/article/2104613/private-cloud-makes-its-comeback-thanks-to-ai.html">sparked a rethink</a> on where to place cloud workloads, but Sweetwater’s Johnson believes the question of whether to pull more workloads into private clouds versus public clouds shifts more often than people expect. “I think the vast majority of our workloads are in the right place right now, but we got there by being willing to question the default,” he says.</p>



<p>Sweetwater does not operate under a rule that says new workloads always go to the cloud, he notes. A workload might start in the cloud and end up on-prem if the math changes. “The discipline is in reviewing that in real-time, finding the inflection points, and right-sizing as you go. Right tool, right time. That’s the only principle that holds up over time.”</p>



<p>International Seaways’ Basu is not planning a move toward private cloud, as the economics and operational overhead do not justify it for his organization.</p>



<p>“The right question is what is the correct data residency, latency, and control model for each workload,” he says. “That is a data classification discipline, not a cloud deployment strategy.”</p>



<p>Lewis, who has about 95% of the University of Health Sciences and Pharmacy’s infrastructure running in the cloud, doesn’t see a good alternative given how the stakes have changed for AI and hardware.</p>



<p>“If you want to train large scale data lakes and make informed business decisions with machine learning and the intelligence behind it, it’s almost not practical anymore” to be on-prem, Lewis says.</p>



<p>CIOs need to ask themselves whether they have the expertise to handle that infrastructure, he adds. Ultimately, “you have to make the best of what you’ve got,” he says.</p>



<h2 class="wp-block-heading">Stay focused on fundamentals</h2>



<p>Organizations may want to chase the shiny object, which is agentic AI right now, but IT leaders should focus on their infrastructure, management, and platform planning, Linthicum stresses.</p>



<p>“It’s not as fun,” he says, “but to do any AI within your environment, you have to solve those issues.”</p>



<p>The cloud enables a lot of architectural patterns, and that freedom will work against you if you don’t have guardrails, cautions Sweetwater’s Johnson. “Write the guidance document before you need it — not after you’ve already got five teams doing things five different ways.”</p>



<p>IT leaders also need to get ahead of tagging and cost visibility early, saying that it needs to be a first step, not a cleanup project. “If you can’t see your spend clearly from day one, you’re already behind,” he says.</p>



<p>A key step is to build an auditing program with solid controls around who can create production changes, Johnson says. “The blast radius of a bad change in the cloud is bigger and faster than most people expect, until they experience it.”</p>



<h2 class="wp-block-heading">The skills question</h2>



<p>The skills needed to operate a modern cloud environment are evolving faster than most internal teams can realistically keep up with, Basu says. As a result, International Seaways relies on specialized MSPs rather than trying to maintain deep in-house expertise across every domain.</p>



<p>“That gives us access to current capabilities without constantly retraining or rebuilding teams as the technology changes,” he explains. “The decisions that protected us in 2020 were made years before anyone realized how important they would become. Infrastructure strategy is always about preparing for a future that is not yet fully visible.”</p>



<p>The key is to make those decisions deliberately, with clear reasoning, rather than reacting under pressure later, he adds.</p>



<h2 class="wp-block-heading">Build adaptable organizations</h2>



<p>Edge computing is adding another layer of complexity, Johnson says. Leaders who navigate this effectively won’t be the ones who find the perfect architecture, he notes. “They’re the ones building organizations that can adapt quickly when the right answer changes tomorrow,” he says.</p>



<p>The real competitive advantage is not the cloud you picked, but how fast your team can learn and move, Johnson says.</p>



<p>Asked about other advice to make cloud less complicated, the CIOs offered the following:</p>



<ul class="wp-block-list">
<li><strong>Treat your cloud architecture like a product, not a project.</strong> It needs ongoing ownership, not just implementation, Johnson stresses.</li>



<li><strong>Make sure you’re reviewing your decisions regularly. </strong>“The right call at year one often isn’t the right call at year three. Build in the checkpoints to revisit,” Johnson says.</li>



<li><strong>Tie every workload to a cost center.</strong> Basu has done this, and IT continuously reviews utilization and rightsizing rather than waiting for periodic audits.</li>



<li><strong>Data classification determines regional placement.</strong> Before any workload reaches production, ensure “Legal and Compliance are in that conversation from the start, not at the end,” Basu says.</li>



<li><strong>Create a cloud-ready solution. </strong>This can sometimes be less expensive and lower risk than lifting and shifting a heavily customized legacy environment, Basu says.</li>



<li><strong>Consolidation is a strategic choice, not a retreat. </strong>Fewer platforms, governed well, consistently outperform a fragmented multicloud estate, he says.</li>



<li><strong>Don’t underestimate the governance gap AI is opening. </strong>Build your AI governance layer now, before the debt accumulates, Basu says.</li>



<li><strong>Cloud strategy is not an IT architecture decision. </strong>The pandemic proved that it is a business resilience decision, Basu says. “The organizations that make the hard calls before the crisis arrives are the ones that come out intact.”</li>



<li><strong>Ensure cloud decisions are tied to measurable business outcomes. </strong>WHSmith’s Bellendir says IT is also investing heavily in integration architecture, cybersecurity controls, observability, and data governance to better support a hybrid ecosystem.</li>



<li><strong>Place greater emphasis on cloud cost governance and operational discipline. </strong>This will improve visibility into cloud usage and ensure that scaling AI, analytics, and digital initiatives remains financially sustainable over time, Bellendir says.</li>
</ul>



<p>While no one can foresee whether cloud will grow less complicated down the road, organizations will continue to use it. “Cloud is no longer the future of IT — it’s the present,” says Sweetwater’s Johnson. “The conversation has shifted from ‘should we?’ to ‘how do we get better at it?’ That’s where I spend most of my time.”</p>



<p><em>This story <a href="https://www.cio.com/article/4178280/cloud-strategies-have-become-more-complicated-than-ever.html">originally appeared on CIO</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Starburst installiert Paras Malhotra als CISO - CRN DE]]></title>
<description><![CDATA[Die Verantwortung dafür übernimmt mit Paras Malhotra ein erfahrener Fachmann, der auf der neu geschaffenen Position des Chief Information Security ...]]></description>
<link>https://tsecurity.de/de/3601976/it-security-nachrichten/starburst-installiert-paras-malhotra-als-ciso-crn-de/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3601976/it-security-nachrichten/starburst-installiert-paras-malhotra-als-ciso-crn-de/</guid>
<pubDate>Tue, 16 Jun 2026 15:23:27 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Die Verantwortung dafür übernimmt mit Paras Malhotra ein erfahrener Fachmann, der auf der neu geschaffenen Position des Chief Information <b>Security</b> ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Zero trust isn’t broken. Most companies just do it wrong.]]></title>
<description><![CDATA[Zero trust is 15 years old, and like many teenagers, it can feel misunderstood and underappreciated.



The concept of zero trust was first defined by John Kindervag, a Forrester analyst at the time, as a strategy to replace the outmoded perimeter security model with a “never trust, always verify...]]></description>
<link>https://tsecurity.de/de/3601184/it-security-nachrichten/zero-trust-isnt-broken-most-companies-just-do-it-wrong/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3601184/it-security-nachrichten/zero-trust-isnt-broken-most-companies-just-do-it-wrong/</guid>
<pubDate>Tue, 16 Jun 2026 11:08:25 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Zero trust is 15 years old, and like many teenagers, it can feel misunderstood and underappreciated.</p>



<p>The concept of zero trust was first defined by <a href="https://www.linkedin.com/in/john-kindervag-40572b1/">John Kindervag</a>, a Forrester analyst at the time, as a strategy to replace the outmoded perimeter security model with a “never trust, always verify” approach. But going from principle to practice isn’t easy.</p>



<p><a href="https://www.accenture.com/content/dam/accenture/final/accenture-com/document-3/State-of-Cybersecurity-report.pdf#zoom=40" target="_blank" rel="noreferrer noopener">Accenture</a> reports that 88% of organizations have encountered significant challenges implementing zero trust. In a recent <a href="https://www.gartner.com/en/newsroom/press-releases/2024-04-22-gartner-survey-reveals-63-percent-of-organizations-worldwide-have-implemented-a-zero-trust-strategy" target="_blank" rel="noreferrer noopener">Gartner</a> survey, 35% of respondents who indicated that they either attempted or partially attempted a zero-trust initiative suffered failures that adversely affected their organization. “Gartner has observed numerous instances of failed zero-trust initiatives among end users who lacked a strategic and measurable plan,” the report says.</p>



<p>At last year’s DefCon 33 conference, U.K. security researchers from AmberWolf <a href="https://www.networkworld.com/article/4039042/def-con-research-takes-aim-at-ztna-calls-it-a-bust.html" target="_blank">poked holes in zero trust</a> by identifying potential vulnerabilities in zero-trust network access (ZTNA) offerings from three vendors. “It turns out there are no magic ZTNA beans; we’ve got the same old bug classes reimagined for a new technology stack,” said AmberWolf researcher Richard Warren. “Rather than zero trust, we’re actually putting a lot of trust into these vendors to process our data securely.”  </p>



<p><a href="https://www.linkedin.com/in/mjhaber/">Morey Haber</a>, author and chief security advisor at BeyondTrust, sums up the state of zero trust in 2026 this way: “We all agree: zero trust is necessary. But it’s been hard to implement.” Haber describes the gap between intention and execution as “massive” during a <a href="https://www.computerworld.com/video/4084071/is-zero-trust-failing-or-just-misunderstood.html" target="_blank">Today in Tech episode</a> focused on whether zero trust is failing or just misunderstood. “It doesn’t matter what you read or which framework you follow,” Haber said during the podcast. “The core issue is that we have a concept with principles and tenets, but not enough guidance on how to implement it.”</p>



<p>Here are some myths and misconceptions associated with zero trust, as well as tips on how to avoid the pitfalls and successfully implement zero trust.</p>



<h2 class="wp-block-heading">Myth: Zero trust is a product</h2>



<p>Even after 15 years, there is still considerable confusion about what zero trust is. It answers to many definitions—strategy, philosophy, concept, mindset, and architecture.</p>



<p>Chase Cunningham<em>, </em>who bills himself as <a href="https://www.drzerotrust.com/" target="_blank" rel="noreferrer noopener">DrZeroTrust</a>, says,”Security is not a product, but a combination of strategy, process, and execution. Zero trust is not just an architecture—it’s a mindset. There is no zero-trust product, period.”</p>



<p>Haber agrees. “You have vendors claiming to sell “zero-trust” products, which is misleading. There’s no such thing as a zero-trust product. Products implement security controls, but they don’t embody zero-trust principles.”</p>



<p>He cautions, “If a vendor says, ‘This remote access solution achieves zero-trust principles,’ that’s great, but I have yet to see one that delivers more than 10%-15% of the required controls.”</p>



<p>Gartner adds, “The concept of zero trust is a security approach that organizations adopt to mitigate access risks associated with networks, applications, and associated data. This is frequently overshadowed by vendor marketing, which tends to promise high expectations but often delivers suboptimal results.”</p>



<h2 class="wp-block-heading">Myth: Zero trust is a technology</h2>



<p><a href="https://www.utsystem.edu/offices/information-security/chief-information-security-officer" target="_blank" rel="noreferrer noopener">George Finney</a>, CISO at the University of Texas and author of two books on zero trust, tells <em>Network World</em> that zero trust is not a technology; in other words, it’s not micro-segmentation to block lateral movement by attackers; it’s not policy-based identity to control who gets access to enterprise resources. Those are tools and tactics that help implement zero trust.</p>



<p>Zero trust at its core is a way of thinking about risk that requires breaking down silos among security teams, networking groups, business units, compliance, and risk management functions, according to Finney.</p>



<p>The first pillar of zero trust, as defined by Kindervag, is identifying the highest-priority protect surfaces in the organization. Kindervag says that unless the organization has a clear understanding of what the crown jewels are, there’s no way a zero-trust project can be successful. Kindevag adds that IT doesn’t necessarily know what those high-value protect surfaces are, but business leaders do, and that’s where a zero-trust initiative should start.</p>



<p>The second pillar of zero trust is to map transaction flows associated with those mission-critical protect surfaces. Again, this requires coordination and collaboration with teams running key enterprise applications. This is particularly important in today’s multi-cloud environments, where a specific business process can span on-prem, edge, cloud, containers, microservices, etc.</p>



<p>“It’s not a technology issue at the end of the day that makes it hard,” Finney says. It’s people issues, cultural issues, and politics. He recommends that organizations think holistically about securing sensitive data across all attack surfaces, including endpoints, remote users, IoT devices, LLMs, AI agents, etc.</p>



<p>Gartner adds, “It is not a product or technology-focused exercise but rather a methodology driven by the organization’s overall objective and priorities.”</p>



<h2 class="wp-block-heading">Myth: Zero trust is expensive  </h2>



<p>Finney says zero trust does not have to break the bank. “A lot of folks think it’s going to be too expensive, but it doesn’t have to be,” he adds. Here are key steps on the road to zero trust that don’t involve buying anything<strong>.</strong></p>



<p><strong>Identifying high-value protect surfaces. </strong>This requires thinking like an attacker and pinpointing the assets that an attacker is most likely to consider valuable. Finney adds, “In a given protect surface, you might have multiple controls that all have to be working together to remove those trust relationships.”  </p>



<p><strong>Creating a zero-trust team</strong>. Finney says most organizations already have governance, risk management, and compliance teams that can be brought into a comprehensive zero-trust task force that includes security and networking groups. Gartner adds, “A zero-trust strategy must be initiated at the executive level and integrated across all departments and teams.”</p>



<p><strong>Education. </strong>Education is critical, says Finney. “It’s helping folks see the big picture. It gets people out of their silos.”Finney adds that a major challenge is political, having to deal with a fragmented organization in which many stakeholders are dismissive of security because it’s not what they’re measured on. For example, application developers who are under the gun to get software out the door aren’t necessarily incentivized to bake security into their processes. <strong> </strong></p>



<p><strong>Creating a strategy. </strong>“When I talk to boards of directors, they understand that to be successful in any part of the business, you need to have a strategy. That resonates from the top,” says Finney. <strong></strong></p>



<p>In its analysis of why zero-trust initiatives fail, Gartner says, “The lack of a business-aligned strategic plan has led to ineffective governance, miscommunication, poor risk management, minimal budget allocation, poor execution of the organizational security objectives, and inefficient use of limited resources.”</p>



<p><strong>Defining an architecture: </strong>Every organization is different, so there is no boilerplate architecture that can be applied everywhere. Organizations need to write a specific architecture that fits their business needs, their level of risk tolerance, their specific vertical industry, and their unique technology infrastructure.</p>



<p><strong>Setting and applying policies. </strong>Again, there is no line item associated with writing access control and identity management policies.  </p>



<p><strong>Leveraging existing tools.</strong> It’s important to realize that nobody is starting from zero.</p>



<p>Most organizations already have multi-factor authentication or single sign-on in place, they already have identity management, network management, web application firewalls, etc. The key is to integrate and align existing technology and identify gaps where new tools might be needed.</p>



<p>Speaking to AmberWolf’s point that attackers can always find bugs in vendor software, zero-trust advocates counter that zero trust implies defense in depth. So, even if there’s a flaw that allows an attacker to gain end-user credentials and access the network, there will be multiple security controls in place, such as incident detection, micro-segmentation, monitoring of end-user sessions, and controls that prevent access to and exfiltration of sensitive data.</p>



<h2 class="wp-block-heading">Myth: Zero trust is difficult to implement</h2>



<p>Zero trust doesn’t have to be hard to implement if organizations follow widely disseminated guidance provided by <a href="https://nvlpubs.nist.gov/nistpubs/specialpublications/NIST.SP.800-207.pdf" target="_blank" rel="noreferrer noopener">NIST</a>, numerous books, webinars, podcasts, experts, consultants, and more.</p>



<p>Finney recommends starting small and showing quick wins. Zero trust can’t be implemented all at once across a large organization; it requires a targeted, methodical strategy.</p>



<p>The preferred approach is to start with those high-value protect surfaces and apply tools that support the overall architecture in a coordinated, consistent, managed, and monitored fashion.  </p>



<p>“An overall strategy can deploy different tactics,” Finney says. “You want to think about what will have the biggest impact on your organization today.” He says organizations need to make informed data-driven decisions based on logs, metrics, and other data, while factoring in an analysis of what attackers are doing vs. the specific vulnerabilities and weak points in the organization’s defenses.</p>



<p>Gartner states: “Narrowing the scope of initiatives or projects within the zero-trust program is essential for attaining a zero-trust posture within practical and reasonable timeframes. Organizations define overly expansive future target states by incorporating an excessive number of systems, applications, use cases, or datasets in the initial phase—or by proposing overly intricate and granular policy sets. They will encounter scalability and cost challenges, along with extended project timelines.”</p>



<h2 class="wp-block-heading">Myth: AI breaks ZTNA</h2>



<p>Enterprises are racing to deploy generative AI and unleash semi-autonomous AI agents. This new world of black box large language models (LLM) and non-human identities (NHI) raises concerns that zero trust is an outdated strategy that’s not up to the challenge.</p>



<p>Leading zero-trust proponents are pushing back, however, arguing that the core principles still apply. “With AI, zero trust is more important than ever,” says Finney. “Zero trust is a strategy; we don’t change the strategy because AI came out. AI proves how important that strategy is.”</p>



<p>“AI is not magic,” he adds. “We secure it the same way we secure everything else. We integrate it into the tech stack and monitor it.”</p>



<p>Kindervag, currently chief evangelist at Illumio, concurs. “AI doesn’t change the fundamentals of zero trust. It reinforces them. Zero trust is the strategy that allows you to safely embrace AI. Without strict segmentation, policy enforcement, and control over data flows, AI becomes another soft and chewy center waiting to be exploited.” He adds, “You don’t need a new security strategy for AI. You just need to apply the right one. That’s zero trust.”</p>



<h2 class="wp-block-heading">Myth: There’s no way to measure success</h2>



<p>Any project that seeks support from the board and C-suite, needs to be able to justify itself through some sort of metrics. Zero trust is no exception, but how do you measure “not getting hacked?”</p>



<p>Gartner says teams should use outcome-driven metrics that link zero-trust initiatives directly to business objectives.“It’s crucial to focus on schedule adherence, cost discipline, and control effectiveness,” says Gartner. “Focus on outcomes like reduced breach incidents, improved compliance rates, and enhanced operational efficiency. Additionally, identify specific risks, such as lateral movement, data breaches, account takeovers, and insider threats, which are essential to drive value, and organizations can better justify investments and drive continuous improvement.”</p>



<h2 class="wp-block-heading">Myth: Zero-trust projects have a completion date</h2>



<p>Zero trust is more about the journey than the destination,” Finney says. He points out that organizations are constantly growing and changing. At the same time, attackers are evolving. “Zero trust is a strategy. You’re never done with a strategy,” he adds.</p>



<p>Kindervag’s final pillar of zero trust is to monitor and maintain. In other words, organizations need to be actively monitoring to make sure that access control policies are not being violated. And the zero-trust implementation needs to keep pace with changing business needs.</p>



<p>And since zero trust calls for organizations to focus on the highest value protect surfaces first, there are always additional protect surfaces that can be added under the zero-trust umbrella.</p>



<p>When Finney looks back on how things have evolved over the past 15 years, he is encouraged by the fact that tools have improved dramatically. Teams can now apply AI and machine learning to functions like anomaly detection or incident detection and response. And there are now ways to automate tasks like networking monitoring or policy enforcement.</p>



<p>“Overall, I’m feeling guardedly optimistic,” Finney says, “but the work is not done. We need to continue to make strides.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Florida public sector training on SimSpace cyber range: Case study]]></title>
<description><![CDATA[Experience is the best teacher, but in cybersecurity, it often comes at a cost. Just ask anyone — from a CISO to a Tier 1 analyst — who has lived through a major breach. In Florida, however, thousands of public-sector…
Read more →
The post Florida public sector training on SimSpace cyber range: C...]]></description>
<link>https://tsecurity.de/de/3600268/it-security-nachrichten/florida-public-sector-training-on-simspace-cyber-range-case-study/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3600268/it-security-nachrichten/florida-public-sector-training-on-simspace-cyber-range-case-study/</guid>
<pubDate>Mon, 15 Jun 2026 23:42:31 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>&lt;p&gt;Experience is the best teacher, but in cybersecurity, it often comes at a cost. Just ask anyone — from a CISO to a Tier 1 analyst — who has lived through a major breach.&lt;/p&gt; &lt;p&gt;In Florida, however, thousands of public-sector…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/florida-public-sector-training-on-simspace-cyber-range-case-study/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/florida-public-sector-training-on-simspace-cyber-range-case-study/">Florida public sector training on SimSpace cyber range: Case study</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
</channel>
</rss>
<!-- Generated in 0,13ms -->