Infosec stories
Despite rising cyber maturity, most large organisations still lack basic protections against AI-specific attacks such as prompt injection, Wavestone says.
UK organisations will gain continuous testing of cyber controls as Acumen Cyber adds AttackIQ's platform to spot exploitable attack paths.
Developers using npm could have secrets exposed as 176 malicious packages were set up to hijack dependency resolution and run postinstall malware.
The funding will help the London-based cybersecurity start-up expand in the UK and US as phishing-driven credential theft keeps rising.
The registry is tightening checks after malicious uploads exposed a gap between declared skill purpose and actual behaviour.
Enterprises get a single control layer for AI agents and data as Snowflake adds security and governance tools to curb errors and misuse.
Boards will get clearer visibility of cyber threats as the new software ties vulnerability data to strategic priorities and business impact.
Gallagher Security has won the Cloud Security category at the 2026 Fortress Cybersecurity Awards for its cloud-based platform OneLink.
Rising vulnerability volumes are outpacing fix times, prompting HackerOne to roll out an AI system that feeds confirmed threats into developer tools.
Security teams can now apply the same rules to AI-generated code across development and deployment, as Salt broadens its platform to curb flaws earlier.
It gives Japanese businesses a controlled way to manage accounts outside single sign-on, where staff often still store passwords informally.
Businesses adopting AI now face a single service aimed at filling gaps in governance, monitoring and incident response across workflows.
Only 12% of chief information security officers have recently validated controls they expect to stop intruders moving sideways through networks.
New silicon-level controls aim to curb unauthorised agent access and data exposure in enterprise AI storage, while keeping traffic fast.
AI-driven vulnerability discovery is leaving companies less time to patch, prompting new focus on clean recovery, air-gapped backups and testing.
Organisations are being pushed to spot hidden privilege paths in AI and machine accounts as BeyondTrust widens its identity risk assessment.
AI-driven vulnerability scanning is forcing firms to rethink complacency as Check Point says existing defences still help against Mythos.
Microsoft patched a CVE-2025-59199 flaw in October after researchers showed a single click could let low-integrity code escape Windows 11's sandbox.
Excessive access rights across hybrid estates can now be trimmed more safely, as XM Cyber adds usage data to pinpoint permissions that are no longer needed.
New procurement rules could keep critical emergency and health systems in local hands, as Catalyst warns reliance on offshore vendors raises costs and risks.