That Legitimate OAuth Login Might Be a Russian Hack

<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/that-legitimate-oauth-login-might-be-russian-hack-image_small-3-a-32634.jpg" align=right hspace=4><b>Attackers Use Real Google and Microsoft Authentication Before Redirecting Victims</b><br>Google says three Russia-linked espionage clusters are abusing legitimate Google and Microsoft authentication flows to steal tokens and account access from defense, government, academic and think tank targets, exposing a visibility gap around personal accounts.

Read more

Mandiant Opens Agentic Security Harness to Industry

<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/mandiant-opens-agentic-security-harness-to-industry-image_small-10-a-32633.jpg" align=right hspace=4><b>AVDH Scans Enterprise Code at Scale to Find and Validate Exploit Paths</b><br>Google Mandiant opened its playbook on agentic security by releasing the architecture it used to develop its Agentic Vulnerability Discovery Harness to analyzes code and quickly identify exploit paths during reviews, penetration testing and red team operations.

Read more

AI Analytics Hits a Trust Barrier

<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/ai-analytics-hits-trust-barrier-image_small-8-a-32632.jpg" align=right hspace=4><b>Widespread Experimentation Has Yet to Produce Enterprise-Scale Adoption</b><br>Enterprises are pushing AI analytics into production, but most employees still rely on dashboards and manual requests. A new survey finds limited confidence in AI-generated answers is holding back organization-wide adoption and changing the skills required of data teams.

Read more

ISMG Editors: AI-Assisted Cyberattacks Gain Speed and Scale

<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/ismg-editors-ai-assisted-cyberattacks-gain-speed-scale-image_small-4-a-32631.jpg" align=right hspace=4><b>Also: OpenAI Hits Pause as AI Risks Rise, Black Hat Sharpens AI Security Debate</b><br>In this week's panel, four ISMG editors discussed AI's growing role in cyberattacks, OpenAI's unusual decision to pause frontier-model training and, one week on from our Black Hat coverage, which conversations from Las Vegas really mattered - and which didn't.

Read more

Annual Report to Congress on Breaches of Unsecured Protected Health Information

The Department of Health and Human Services' Office for Civil Rights provided a report to Congress on health information breaches from September 2009 through 2010, as required under the HITECH Act. Nearly 7.9 million Americans were affected by almost 30,800 health information breaches, according to the report.

Read more

FFIEC Final Authentication Guidance

The Final FFIEC Guidance has been issued and its main intent is to reinforce the 2005 Guidance's risk management framework and update the Agencies' expectations regarding customer authentication, layered security, or other controls in the increasingly hostile online environment.

Read more

Accounting of Disclosures Under the HITECH Act

A notice of proposed rulemaking from the HHS Office for Civil Rights that would modify the HIPAA Privacy Rule standard for accounting of disclosures of protected health information and add new requirements for access reports.

Read more

ENISA: Software vulnerability prevention initiatives

The European Network and Information Security Agency, ENISA, has compiled a list of existing initiatives focused on finding and preventing software vulnerabilities.

Read more

Webinar | The New Security Architecture: Trust, Identity, and Collaboration in the AI Era

Read more

The AI Workforce Is Here. Is Your Security Strategy Ready?

Read more

Recommended Feeds