That Legitimate OAuth Login Might Be a Russian Hack

<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/that-legitimate-oauth-login-might-be-russian-hack-image_small-3-a-32634.jpg" align=right hspace=4><b>Attackers Use Real Google and Microsoft Authentication Before Redirecting Victims</b><br>Google says three Russia-linked espionage clusters are abusing legitimate Google and Microsoft authentication flows to steal tokens and account access from defense, government, academic and think tank targets, exposing a visibility gap around personal accounts.

閱讀更多

Mandiant Opens Agentic Security Harness to Industry

<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/mandiant-opens-agentic-security-harness-to-industry-image_small-10-a-32633.jpg" align=right hspace=4><b>AVDH Scans Enterprise Code at Scale to Find and Validate Exploit Paths</b><br>Google Mandiant opened its playbook on agentic security by releasing the architecture it used to develop its Agentic Vulnerability Discovery Harness to analyzes code and quickly identify exploit paths during reviews, penetration testing and red team operations.

閱讀更多

AI Analytics Hits a Trust Barrier

<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/ai-analytics-hits-trust-barrier-image_small-8-a-32632.jpg" align=right hspace=4><b>Widespread Experimentation Has Yet to Produce Enterprise-Scale Adoption</b><br>Enterprises are pushing AI analytics into production, but most employees still rely on dashboards and manual requests. A new survey finds limited confidence in AI-generated answers is holding back organization-wide adoption and changing the skills required of data teams.

閱讀更多

ISMG Editors: AI-Assisted Cyberattacks Gain Speed and Scale

<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/ismg-editors-ai-assisted-cyberattacks-gain-speed-scale-image_small-4-a-32631.jpg" align=right hspace=4><b>Also: OpenAI Hits Pause as AI Risks Rise, Black Hat Sharpens AI Security Debate</b><br>In this week's panel, four ISMG editors discussed AI's growing role in cyberattacks, OpenAI's unusual decision to pause frontier-model training and, one week on from our Black Hat coverage, which conversations from Las Vegas really mattered - and which didn't.

閱讀更多

Annual Report to Congress on Breaches of Unsecured Protected Health Information

The Department of Health and Human Services' Office for Civil Rights provided a report to Congress on health information breaches from September 2009 through 2010, as required under the HITECH Act. Nearly 7.9 million Americans were affected by almost 30,800 health information breaches, according to the report.

閱讀更多

FFIEC Final Authentication Guidance

The Final FFIEC Guidance has been issued and its main intent is to reinforce the 2005 Guidance's risk management framework and update the Agencies' expectations regarding customer authentication, layered security, or other controls in the increasingly hostile online environment.

閱讀更多

Accounting of Disclosures Under the HITECH Act

A notice of proposed rulemaking from the HHS Office for Civil Rights that would modify the HIPAA Privacy Rule standard for accounting of disclosures of protected health information and add new requirements for access reports.

閱讀更多

ENISA: Software vulnerability prevention initiatives

The European Network and Information Security Agency, ENISA, has compiled a list of existing initiatives focused on finding and preventing software vulnerabilities.

閱讀更多

Webinar | The New Security Architecture: Trust, Identity, and Collaboration in the AI Era

閱讀更多

The AI Workforce Is Here. Is Your Security Strategy Ready?

閱讀更多

推薦訂閱