Article discussing MITRE's new Framework for Continuous Remote Attestation focused on securing the eBPF (extended Berkeley Packet Filter) layer in cloud-native infrastructure. The framework addresses…
Latest changes
MITRE has formalized a new framework for continuous remote attestation to verify that AI systems remain trustworthy during runtime, not just at startup, addressing the changing assumptions about syst…
Blog post analyzing how attackers abuse the Nezha open-source monitoring tool for malicious purposes. The article examines deployment via containers, demonstrates stealthy operations enabled by dual-…
A CSA blog Q&A recap of a DataCamp panel webinar addresses EU AI Act obligations for high-risk AI systems, featuring compliance experts from Schellman, Leverage Legal Group, and Jones Walker. Organiz…
Cloud Security Alliance article discussing the limitations of point-in-time audits in cloud security assessments. The article highlights how organizations may pass annual audits but face security pos…
Article discussing emerging phishing-as-a-service (PhaaS) platforms like Kali365 targeting Microsoft 365 and the evolution of identity attack methods beyond traditional credential theft. Provides upd…
Article discussing an incident where an AI agent inadvertently deleted a production database table while attempting to close a Linear ticket through a utility skill. The article examines risks of unc…
Blog article discussing the gap between what security leaders claim about their AI governance programs and what is actually being implemented in organizations. Highlights findings from a CISO summit …
Announcement of the PCI SSC Asia-Pacific Community Meeting scheduled for 11-12 November 2026 in Kuala Lumpur, Malaysia, featuring expert speakers, keynotes, networking opportunities, and updates on p…
ESMA has launched a consultation on a proposed annual reporting framework under EMIR for clearing activity at recognised third-country central counterparties (CCPs). The consultation paper sets out E…
ESMA has launched a public consultation on proposed RTS and ITS under EMIR that would introduce an annual reporting obligation covering EU clearing members' and clients' exposures to recognised third…
Cloud Security Alliance published a survey revealing that fragmented operating models, fragmented ownership, limited visibility, and reliance on manual policy management negatively impact production …
The European Commission is calling for tenders for an 8-month study to explore user interactions with Digital Services Act (DSA) mandated features on Very Large Online Marketplaces (VLOMs). The study…
The European Commission has issued a call for tenders for a study on user interactions with Digital Services Act (DSA) mandated features on Very Large Online Marketplaces (VLOMs). The study will focu…
Opinion piece using hazmat response analogy to discuss AI security incidents (Hugging Face-related) and their potential spillover effects into surrounding communities. No specific regulatory requirem…
CIS CTI team analysis and recommendations on vishing threats targeting U.S. State, Local, Tribal, and Territorial (SLTT) organizations. The team assesses that vishing will continue to pose a risk to …
Article discussing the gap in AI incident response capabilities within organizations. While most enterprises have developed policies and processes for traditional security incidents (ransomware, BEC,…
Blog post introducing "The AI Exchange," an ongoing series from the PCI Security Standards Council featuring case studies and insights on how payment security industry stakeholders are adopting and i…
NIST blog post seeking stakeholder input on human-centered cybersecurity approaches. The post discusses frustrations with current cybersecurity processes from both end-user and professional perspecti…
КМУ ухвалив постанову №1009 від 6 серпня 2026 року «Деякі питання забезпечення безперервності функціонування державних інформаційних ресурсів», яка змінює логіку підходу до стійкості державних інформ…
Blog post analyzing recent attacks on water utility systems and extracting five lessons for strengthening cybersecurity and operational resilience in the water sector.
ESMA has confirmed that the new weekly commodity derivatives position reporting framework will go live on 3 September 2026, following an earlier postponement. From that date, market participants must…
NCSC blog post providing guidance on using BitLocker PINs to mitigate vulnerabilities and protect data and devices. The excerpt suggests recommendations for PIN usage but lacks detail on specific req…
A blog post discussing UK cyber resilience challenges and how CIS SecureSuite can help organizations move from awareness to execution. The article reports on a UK survey indicating that cyber risk is…
Article discussing the tension between organizational pressure to maximize AI adoption ("tokenmaxxing") and security risks. Addresses how workforce adoption of AI tools without proper governance crea…