Infosec stories
With one in three firms still lacking basic protection, smaller UK businesses are facing a sharper threat and higher breach costs as attacks rise.
Security teams face a shrinking window to spot and fix flaws as AI models like Mythos find exposures in minutes, not days.
Enterprise teams can now monitor chats, files and project logs in Claude, closing a security gap as AI tools take on more workplace tasks.
Security teams can now spot browser-based credential threats alongside identity and cloud alerts after Dashlane's Sentinel link.
Banks and payment firms could spot scams mid-session, as Darwinium's updated mobile SDKs track live calls, screen sharing and device evasion.
The new integration keeps passwords out of prompts and repos, reducing the risk of leaks as AI coding agents move into production workflows.
Only a small fraction of disclosed flaws are likely to hit suppliers, leaving security teams to focus on the 58 highest-risk CVEs.
Enterprise users could gain tighter oversight as Versa applies identity checks and approval rules to every AI agent action before it runs.
Victims are being lured into handing over card details after completing bogus brand surveys promising prizes, as short-lived domains evade filters.
Most workers are blurring the line between corporate and personal AI use, leaving employers blind to sensitive data shared outside approved accounts.
Patching alone has left some older SonicWall devices exposed to VPN attacks, with reliaQuest finding the first known in-the-wild use of CVE-2024-12802.
Independent security checks are gaining urgency as fast-growing AI and software firms face rising scrutiny from customers, partners and regulators.
Browser-based fraud is scaling fast, with Barracuda saying CypherLoc has driven about 2.8 million attacks since the start of 2026.
Security teams can now track Claude use alongside other threats, as CrowdStrike folds compliance logs into Falcon's monitoring and response tools.
Security teams will gain continuous oversight of Claude use as Netskope brings the AI assistant under existing compliance and data-loss rules.
Exposed systems are becoming the main target, as Rapid7 says flaws were used in 38% of incidents and patch windows shrank to five days.
Fresh funding is prompting Bedrock Data to strengthen its leadership team as enterprises rush for better controls over sensitive information in AI systems.
The integration could help health systems curb account takeover and fraud as MyChart use grows for records, bookings and messages.
Enterprise admins can now approve vault access and share credentials inside ServiceNow, reducing manual steps for security teams and auditors.
UpGuard says exposed credentials and supplier risk leave Australia's biggest listed firms vulnerable, despite a modest rise in security scores.