SEC536: Adversarial AI - Penetration Testing AI Systems


Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact UsThe SANS Difference Makers Awards (DMA) recognize cybersecurity practitioners advancing the industry through innovation, security achievements, mentorship, content, and community leadership.
Nominations are open through Monday, September 14. Help recognize individuals making a meaningful impact and raising the bar for the cybersecurity community.
Last week, the White House issued a memorandum outlining plans to allow private sector companies "to conduct Cyber Surveillance Operations and Cyber Effects Operations against foreign Cyber-Enabled Transnational Criminal Organizations (CE-TCOs), under the control and oversight of the Federal Government." The program will be created, managed, and maintained by the National Coordination Center (NCC), and will be overseen by co-Executive Directors from the Department of Justice and the Department of Homeland Security. Participating private sector companies will be vetted and expected to abide by "strict operational procedures." By October 11, 2026, the Program Executive Directors, in coordination with the Homeland Security Council, are expected "to establish consensus operating procedures for the Program that ensure the Federal Government’s complete oversight and control of Participating Companies’ performance." The program is barred from approving activity that could "result in the loss of life or serious injury or rise to the level of use of force or armed attack under international law."

Criminal infrastructure is rarely neatly isolated. A server, hosting provider, cloud service, botnet node, or compromised device being used by criminals may also support legitimate organizations or provide a pathway into systems with operational dependencies. The ISAC community has an important role in preventing these unintended consequences. The MS-ISAC, WaterISAC, E-ISAC, and other sector organizations understand dependencies and operational conditions that may not be obvious to those planning a disruption operation. They should not become part of the offensive mission, but could provide an important deconfliction and early warning bridge between those conducting an operation and the critical infrastructure that could inadvertently be affected.

This is a noteworthy development in the long-running discussion about private-sector participation in disrupting cybercrime. Heck, I've heard people talking about this for 20-plus years. An especially important aspect of the memorandum is that this is not a general authorization for companies to "hack back." Participating companies are to be vetted and contracted by the government, with operations conducted under federal control, approval, deconfliction, and legal authorities. The implementation details will matter enormously, particularly the operating procedures now being developed. There's a lot to be concerned about here, including proper attribution, staying in scope, and even the safety of organizations who participate in this program. It'll be fascinating to see how this shakes out.

Before jumping to, "yes, we can attack back," make sure that you're aware of the needed contract, training, procedures, and vetting required before you can do that. The good news is that this also opens the door for partnerships with federal, state, local, tribal and territorial agencies who will be identifying threats to participating companies. The hard part will be waiting for the procedures to see if you want to participate.

This is not a carte blanche to just hack back. This is a memorandum to allow specific vetted companies the ability to conduct very precise operations. I am waiting to see this one shake out and see if it survives an administration, maybe two.

On paper this may seem like a good idea, but the road to hell is often paved with good intentions. Allowing private companies to participate in offensive cyber operations falls under this category. Once private companies participate in offensive cyber operations, they risk becoming targets themselves. The lines between cybercrime and state-sponsored activity are often blurred, and disrupting suspected criminal infrastructure could inadvertently interfere with the interests or infrastructure of a hostile state. That could expose participating companies, and potentially their employees, to retaliation without the legal, diplomatic, or physical protections afforded to US government agencies and personnel. Companies considering taking part will need strong government oversight and even stronger legal advice. There is a very thin line between disrupting cybercrime and becoming part of an international incident.

Said another way, the order allows private sector companies to participate with the government in such activity. While such an order may provide some cover, be careful.
What possibly could go wrong here...
In late July 2026, St. Louis Public Television station Nine PBS, also known as KETC Channel 9, sued Iron Mountain Data Centers in an attempt to recover 50TB of data stored on equipment housed in one of Iron Mountain's data centers. KETC had contracted with a company called Open Source Storage for "hardware, software, and cloud storage services;" when KETC attempted to renew its contract with Open Source Storage in March of this year, the station discovered that the data storage company has ceased operations. Furthermore, KETC found they were unable to access their data despite a clause in the contract that allowed KETC 30 days following contract termination to retrieve data. Further investigation determined that Open Source Storage contracted with Iron Mountain to house equipment in that company's data centers. Iron Mountain refused to return KETC's data because it is housed on equipment belonging to Open Source Storage. In a hearing on Wednesday, August 12, a District Court Judge in Denver ordered Iron Mountain to surrender physical devices that contain the data and ordered KETC to find a third-party with the skills to retrieve the station's data without in any way compromising data of other OSS customers. KETC has reportedly found a former data center employee to help with the data retrieval. If it is discovered that the data are encrypted or other complications are encountered, another hearing will be scheduled.

This is a tricky but not unlikely backup scenario. Your data is stored with a third party (OSS) and housed in a fourth-party facility (Iron Mountain). You put a clause in the contract allowing for access to that data in the event that something happens, but you still don't have access. This exact scenario is not likely, but it should be considered. Iron Mountain, or any other hosting provider, isn't going readily grant access to their infrastructure/servers without a court order. This is as it should be. Your mission, should you decide to accept it, is to talk to third parties who have your data — likely housed at a fourth-party data center, cloud or otherwise — to find out what recourse you have in this situation. Have a solution lined up well ahead. Make sure any timeframes are long enough to accommodate any legal or technical complications, say, at least 90 days.

This has been an ongoing issue with smaller cloud-based hosting companies going out of business. Customers usually have little recourse to recover their data if the company they hired to protect it stops paying its cloud bills. Nine PBS is lucky that the data has not already been deleted. But for a backup strategy, relying on a single company should be avoided. There are plenty of options. For 60 TB of what sounds like archive data, keeping a copy in a solution like Amazon Glacier or Backblaze (in addition to the solution they had) is likely an affordable way to protect the data.

This is a remarkable reminder that availability planning needs to include the possibility that a service provider simply ceases to exist. When we entrust important data to a third party, we should know not only how we back it up, but how we get it back: in what format, through what mechanism, on what timetable, and what happens if the provider disappears or becomes unreachable. Those questions belong in contracting and resilience planning before there is an emergency. Seventy years of historical archives should not require a judge and a former employee of a defunct vendor to recover them.

Years ago I was thinking over Iron Mountain and what it meant to so many companies. I had friends whose entire job was taking tape backups for systems that were decommissioned years, maybe even decades ago by now, and moving them to Iron Mountain. I have always wondered, who is going to be the one to restore that tape? Who could even read the media or understand the operating system or format of that backup? This one is interesting because it's recent and new, but how many of backups does Iron Mountain have in their possession for systems that are no longer around, and how will we get to that data? Will we even need to preserve it? Fascinating to watch this one play out.
KETC did the contracting right, but dropped the ball on regular backup tests and audits. OSS was clearly at fault, closing shop without warning and leaving KETC’s data stranded. The judge hit the mark with this ruling, and it's a great wakeup call to regularly audit your data recovery plans and vet your storage vendors’ financials.

Iron Mountain's responsibility was to its customer, i.e., OSS. A suit provided cover for Iron Mountain to release data, media, or devices to OSS's customers.
Ars Technica
Current
Current
FirstAlert4
Two ongoing malware campaigns are targeting macOS systems: One exploits a recently disclosed Screen Sharing flaw to deliver a Monero cryptominer, and the other is a ClickFix-style attack delivering an infostealer dubbed "AmnesiaStealer." The Netherlands National Cyber Security Centre (NCSC) warned on August 12, 2026 that CVE-2026-65400 — a high-severity authentication flaw in the Screen Sharing service for macOS Sonoma, Sequoia, and Tahoe — was observed under active abuse following security firm Calif's publication of proof-of-concept (PoC) exploit code. The attacks target systems with port 5900 exposed to the internet, and in every case have resulted in the attacker gaining root access and installing a Monero cryptominer. Apple released out-of-cycle fixes for this flaw on August 6, and users can also mitigate risk by toggling off Screen Sharing in macOS System Settings > General > Sharing. Jamf Threat Labs published a blog post on August 13 warning that a counterfeit GitHub page offering a "Terminal installation" is being used as a lure to install AmnesiaStealer, an infostealer that shares this page template and other qualities with Atomic, MacSync, and CrashStealer malware. The malicious page instructs users to open Spotlight Search, launch the Terminal app, and then copy, paste, and run the command before entering their device password to "confirm the installation." The command begins the process of downloading and installing a persistent infostealer payload, which uses the surrendered password to unlock keychains and target Apple Notes, documents, Chromium browsers, and Safari cookies. The second stage of the malware is "an interactive remote-control component built around the Chrome DevTools Protocol (CDP). [...] The [attacker] receives a live screencast of the session at around 3fps and can drive it with a full input set: keyboard, mouse, scroll, navigation and tab management. These are translated into CDP calls against the headless browser in real time." Jamf notes that several of the malware's macOS bypasses have been fixed for years, but that the second stage browser-hijacking component makes the threat worth tracking. The blog post offers indicators of compromise (IoCs), and users are urged not to copy and paste unknown commands found online.

Apple remote desktop and screen sharing uses TCP/UDP ports 3283 and 5900, as well as UDP ports 5901 and 5902. Just like port 3389 (RDP), these ports should not be exposed to the Internet. Apply the macOS update, and make sure those ports are not directly accessible.

This screen sharing vulnerability is something new for Mac users, as it allows — if screen sharing is enabled and exposed — simple zero-click exploitation. As usual, if you find a crypto miner on your Mac, do not stop looking. This is an easy-to-exploit vulnerability, and you may also find less-visible malware. Do not assume that only one attacker found your system.

Why is VNC Exposed to the internet? Just, why? It’s never been designed for this, and how are people putting their Macs on the internet in a way that VNC is exposed? Are people purposefully port forwarding VNC and just thinking, this is fine?

The ClickFix technique fascinates me because the attacker effectively persuades the victim to become part of the exploit chain: open a terminal, paste my command, and, while you're at it, please give me your password. Technical controls remain vital, but attackers will always look for ways to convince a human being to help them around those controls. Please be extraordinarily suspicious whenever a website tells you to paste commands into a shell. That kind of user interaction seems to be increasingly popular for legitimate AI-related installs these days, such as the popular "curl pipe through bash" pattern, which always makes me pause and think carefully. Be cautious whenever you see installs like that, and make sure you are dealing with a legitimate site that you trust with your entire computer.
A rare zero-click vulnerability targeting macOS users. Even rarer, an out-of-cycle fix from AAPL. Take advantage of that fix and apply now, it's relatively straightforward. If you can't for business reasons, then turn off the screen sharing application. Oh, and don't forget to check for other signs of compromise.

PoC code is sometimes necessary to demonstrate a vulnerability to the developers who will fix it. However, the publication of such code reduces the cost of exploiting the vulnerability and is, at best, ethically questionable.
Jamf
BleepingComputer
The Hacker News
NCSC
Help Net Security
The Hacker News
Ars Technica
ISC
Threat actors have begun exploiting a critical code injection vulnerability in SAP Commerce Cloud just three days after the flaw was disclosed. The vulnerability, CVE-2026-58231, CVSS score 10.0, "allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to certain functions lacking sufficient validation. Successful exploitation could enable arbitrary code execution and compromise internal components." SAP released patches for the vulnerability on Tuesday, August 11, and researchers at Defused reported exploitation attempts targeting their honeypots on August 14. KEVIntel also reported that their "sensors observed exploitation attempts with confirmed confidence," and urged users to "patch immediately, validate internet-facing exposure, and monitor for matching requests." A critical incorrect authorization vulnerability in Adobe Commerce was also exploited within days of its disclosure. Adobe released updates to fix the vulnerability, CVE-2026-71362, CVSS score 9.1, on Tuesday, August 11. The Sansec Forensics team reported exploitation attempts the same day and "confirmed that the vulnerability lets attackers switch a customer session to another customer account. This gives them access to the victim's account and private customer data." The issue affects Adobe's Commerce and Magento platforms.

That timeline between a patch and successful exploit, presumably derived from reverse-engineering the fix/update, is converging on zero. Beyond expeditious patch application, make sure that you're leveraging additional protections, such as a WAF, segmentation, MFA, and EDR to make vulnerable components harder to reach and harder to (attempt to) exploit in the first place.

In the last NewsBites edition we were talking about exploitation within days of vulnerability disclosure. And… here we go again. For Internet-facing, business-critical systems, vulnerability management increasingly needs an emergency lane that can rapidly answer three questions: Are we affected? Are we exposed? Can we safely remediate right now? The emerging paradigm of VulnOps is all about optimizing our vulnerability pipelines to deal with this new AI vulnerability discovery age. Adobe's decision to provide an isolated security patch is particularly helpful, because reducing the operational friction of patching can be every bit as important as publishing the fix itself.

Peter Tippett used to teach that patching completely was more important than patching quickly. However, the window is shrinking.
SecurityWeek
BleepingComputer
The Hacker News
X
KEVIntel
NIST
SecurityWeek
BleepingComputer
Sansec
NIST
On Thursday, August 13, 2026, Apple users in 110 countries received a push notification stating, "Apple detected a mercenary spyware attack targeted at your iPhone. There are actions you can take now to protect your data and device." Apple published a support article the same day to explain the notifications and to emphasize the complexity and focus of mercenary spyware attacks, which expend considerable resources to target a small number of individuals, "often journalists, activists, politicians, and diplomats." The notification will arrive as an alert on the lock screen and the Settings menu, as well as in emails from threat-notifications(at)email[.]apple[.]com to associated addresses, and as a banner on the user's account page in a browser. Apple recommends that users who receive this notification enable Lockdown Mode and enlist expert emergency security assistance such as the Access Now Digital Security Helpline. The company also recommends all users keep their devices up to date; use a passcode, Touch ID, or Face ID; use multifactor authentication; turn on Stolen Device Protection; only install apps from the App Store; use strong passwords and passkeys; and avoid links and attachments from unknown senders. Apple has been sending these notifications multiple times a year since 2021. Starting in 2029, the annual Wiretap Report issued by the Administrative Office of the US Courts will include disclosures of authorized government use of certain hacking tools and spyware. This report has been issued yearly since 1997 and covers "information provided by federal and state officials on applications for orders for interception of wire, oral, or electronic communications ... [including] offenses under investigation, types and locations of interception devices, and costs and duration of authorized intercepts" within the preceding calendar year. The newly added categories are deemed network investigating techniques (NITs), and according to coverage by TechCrunch, "will only reveal when authorities have used spyware to intercept communications, such as Signal and WhatsApp calls and messages, and not when they use tools to remotely hack into a phone and extract data stored inside of it, such as images, files, and their location," because the latter use constitutes a search and not a wiretap.

The advice given applies for all your mobile fleet: keep them updated, require passcodes, Touch ID or Face ID, enable Find My and Stolen Device Protection, and only install apps from the Apple App Store or enterprise app store. Have travelers in risky areas use lockdown mode. One other guideline I would add is to conduct a regular review of apps on mobile devices; like wire coat hangers, they tend to accumulate. Removing unused ones reduces risks, to include app abandonment scenarios. If you missed it, Apple just dropped updates to iOS 26 and 18, as well as macOS 26, last night. Time to see how that "keep things updated" mantra plays out.

While some have criticised Apple for displaying these warnings as pop-up messages, potentially creating yet another phishing vector, the alerts themselves are important. If Apple tells you that you are being targeted with mercenary spyware, that is one notification you should not swipe away. If you are responsible for cybersecurity in an organisation with people likely to be targeted because of their role, such as executives, journalists, and politicians, you should have procedures for responding to these alerts, including access to specialist support. Protecting staff who are at elevated risk increasingly means recognising that their personal devices can provide attackers with a route not only to the individual, but potentially into your organisation.

Lockdown mode is for those receiving the notification, mostly "...journalists, activists, politicians, and diplomats." The other recommendations are good for all iPhone users.
Apple
TechCrunch
BleepingComputer
The Hacker News
TechCrunch
US Courts
Two cryptocurrency hardware wallet manufacturers have recently disclosed customer data breaches. Trezor, a Czechia-based cryptocurrency hardware wallet maker, has confirmed that a security breach at one of the company's logistics partners has exposed sensitive customer data. ShipMonk, a shipping provider, alerted Trezor to the incident on August 10, 2026, and ShipMonk reportedly said the customer data were accessed via a vulnerability in Metabase. The compromised data include names, phone numbers, and email and physical addresses. The breach affects 11,742 Trezor customers in seven countries who placed orders between May 10 and August 8, 2026, as well as 1,947 customers who made purchases prior to May 10. Trezor reportedly said in a social media post that they are working on an "Anonymous Delivery" method for customers, which would allow them to make purchases without linking home addresses or identities. Trezor has notified all affected customers about the breach and urged them to be cautious about possible phishing attempts. Another cryptocurrency hardware wallet company, SafePal, has confirmed that the personal information of close to 40,000 customers was compromised in a recent cybersecurity incident. The breach affects individuals who placed orders with the company between March 2, 2025, and April 11, 2026. The compromised data include names, email and shipping addresses, phone numbers, and purchase information. SafePal has not provided details about the incident apart from noting that they had identified a vulnerability "in the order-tracking function for a plug-in associated with customer order information [that] under certain conditions ... allowed unauthorized access to another customer's order information." SafePal has notified affected customers via email and set up a website to help people determine if they were affected by the incident.

The shipping information is expected to be leveraged in an attempt to trick customers into providing access to their digital wallet or a backup thereof. Trezor's anonymous shipping option — where the device is sent in unbranded packaging to an alias at a shipping locker not tied to the real account name or address, followed by separate communication of the PIN to open the locker — should serve to make captured shipping data almost without value. It will be interesting to see if any other online retailers implement a similar scheme.

This incident is a prime example of why context matters when assessing the risks associated with data. Names and home addresses may not sound as sensitive as wallet credentials, but when those records identify people who own cryptocurrency hardware wallets, the risk changes significantly. Combining otherwise ordinary personal information can create phishing, extortion, and even physical security risks for the people affected.

The information stolen in this breach should not provide access to the customer’s crypto wallets. However, in the past, data like this has often been used to start targeted phishing campaigns.

Dr. Ullrich is exactly right about the phishing risk from this kind of exposed customer information. There's also an important bit of good security engineering buried in this unfortunate breach, too. Trezor says its strict 90-day customer-data-retention policy, which it also required of fulfillment partners, limited the scope of the exposure. That's data minimization doing exactly what it is supposed to do. You don't have to protect sensitive data forever if you don't keep it forever.

How does one find reliable software for digital currency? Brian Snow once said at RSA that NSA spent "at least as much" on implementations and procedures as on codes and ciphers.
The Register
SecurityWeek
BleepingComputer
Trezor
The Record
Help Net Security
SecurityWeek
TechCrunch
SafePal
Government organizations in France and Scotland have both disclosed data breaches this week. La Direction Generale des Finances Publiques (DGFiP), France's government agency in charge of public finances and taxation, conducted an audit in June 2026 that cut off unauthorized access to their system. DGFiP launched an investigation on August 12 following a threat actor's claim of unauthorized access, and discovered that data belonging to 678,000 individuals and businesses had been accessed and stolen, including reference tax income, family quotient or withholding tax rate, companies' names and SIREN identifiers, and cadastral data. DGFiP is continuing to investigate, and has implemented additional security measures and ensured that unauthorized access is cut off. The threat actor accessed the system using credentials belonging to a DGFiP agent and an authorized third party. The agency reported the incident to the French data regulator, Commission nationale de l'informatique et des libertés (CNIL), and has mobilized IT teams in liaison with the country's national defense and cybersecurity agencies, SHFDS and ANSSI. Those affected will be contacted by email or mail next week with additional information about specific exposed data and protective measures. Scotland's Crown Office and Procurator Fiscal Service (COPFS), an agency that handles public prosecution and death investigations, has disclosed that suspicious activity occurred on a third-party supplier's systems on August 5. A threat actor may have accessed details such as names, roles, and work email addresses associated with a 2025 online data maturity assessment managed by this third-party supplier. COPFS systems have not been breached, and there is no evidence that information about cases, victims, witnesses, or public citizens was affected, nor any impact to COPFS operations and casework.

We're all challenged with removing unneeded access — we're getting pretty good at cutting access off when people leave, but less so when their roles change. Making sure that users only have access to authorized systems and are not over-provisioned, with regular reviews, has to be SOP. You're going to need that process as identities tied to or supporting AI emerge; it's common to find they have much more access than they should, or that they are no longer needed as solutions are tried and replaced. You're going to need the data owners in this process, as they will know what the access means and who should approve.
Credential theft is rising sharply and remains a leading entry point for cyberattacks. According to the 2026 Verizon DBIR, stolen credentials directly fuel ransomware attacks and lateral network movement. Enforce multi-factor authentication across your entire enterprise today — it is one of your strongest defenses, and is a mandatory safeguard under CIS Critical Security Control 6 (Access Control Management).

I recall one audit engagement in which we found four hundred User IDs to a financial system that had not been used in a year. Further investigation found that half of those belonged to non-employees, consultants, and contractors.
French Economic Ministry
Help Net Security
The Register
The Record
COPFS
The Register
Dark Reading
Authorities in Poland are investigating a breach of MyDr, a software provider used by doctors, clinics, and other healthcare providers. The incident may have compromised sensitive information belonging to 19 million people across 12,000 medical facilities. According to an August 14 update on the MyDr incident web page, the organization has "identified and removed the cause [of the breach] and implemented additional security measures," has contacted the President of the Personal Data Protection office, and "established intensive cooperation with CERT Polska and the Central Bureau for Combating Cybercrime (CBZC)." An August 17 update says that MyDr is "currently in the final stages of determining the scope of the incident, including what data and which customers and patients may have been affected." Earlier updates indicate that the breach likely affected information dating back to 2024.

The MyDr site has regular updates on the incident, including service status and information on what actions, if any, patients and doctors need to take. They are even monitoring the Dark Web for the pilfered information. Unfortunately, they are not disclosing the exact nature of the compromise other than the core issues being resolved. There are reports that the certificates needed to access MyDr's GitHub source code repository were allegedly compromised, and that threat actors were able to download the source for the application and find information needed to access the AWS back end for the service, which is why MyDr is replacing all their authentication certificates. Even with this shortfall, the notification on the MyDr site is worth capturing for future reference.
Law enforcement authorities in Germany and Brazil have arrested multiple individuals in connection with a cyberattack in which roughly €30 million (US$34.7 million) was stolen from German bank accounts. The Frankfurt am Main Public Prosecutor's Office, Central Office for Combating Internet Crime (ZIT), and the Federal Criminal Police Office (BKA) say three suspects were arrested and charged with fraud; Brazil's Polícia Federal announced Operation Klonen late last week, which involved carrying out more than 20 search and seizure warrants and four preventive arrest warrants. The November 2023 cyberattack exploited a vulnerability in a payment provider, resulting in "numerous unauthorized withdrawals from the accounts of German online banking users" over the course of four days. The stolen funds were laundered in four European countries and in Brazil. According to Polícia Federal, investigations indicate that the funds obtained through the fraud were moved and concealed using payment cards issued without the beneficiaries' consent, as well as using pass-through accounts, companies, payment institutions, and virtual asset platforms. The suspects arrested in Europe will face charges in Spain and Bulgaria.

Score one for BKA and ZIT cooperation, aka Operation Clone, to catch these guys. The courts also ordered seizure of their financial assets, vehicles, and real estate. In case you're wondering about the customers who were defrauded, the bank covered their losses. The hack, which only lasted four days, exploited a software vulnerability introduced by a faulty update in a payment and transaction processing system. The flaw was subsequently corrected. Given the complexity of the efforts to launder the pilfered funds, it's pretty cool that authorities were able to trace the funds back to the criminals.
The Record
Help Net Security
BleepingComputer
Federal Police
BKA
SANS Internet Storm Center StormCast Tuesday, August 18, 2026
Apple Patches; Screen Sharing Security; Download More RAM
https://isc.sans.edu/podcastdetail/10056
Apple Patches or iOS and macOS
https://isc.sans.edu/diary/Apple+Patches+iOS+and+macOS/33254
Screen Sharing Security
https://isc.sans.edu/diary/Apple+Screen+Sharing+Security/33252
Download More RAM: Dismantling Windows Operating System Defenses with Mischievous Memory
https://www.usenix.org/system/files/usenixsecurity26-collins.pdf
SANS Internet Storm Center StormCast Monday, August 17, 2026
MacOS Screen Sharing; GeoServer Patch; SAP Exploited; ChainDrop npm Worm
https://isc.sans.edu/podcastdetail/10054
macOS Screen Sharing Vulnerability Exploited
https://advisories.ncsc.nl/2026/ncsc-2026-0280.html
GeoServer Patch
https://geoserver.org/announcements/vulnerability/2026/08/14/geoserver-3-0-1-released.html
Recent SAP Commerce Cloud Vuln Exploited
https://x.com/DefusedCyber/status/2088240809355153647
ChainDrop npm Worm
My Upcoming Classes
Catch up on recent editions of NewsBites or browse our full archive of expert-curated cybersecurity news.
Mythos didn't break cybersecurity. It exposed a reality the industry is still adapting to: AI is accelerating the path from vulnerability discovery to exploitation. Watch our webinar to learn why modern exposure management prioritizes exploitability over theoretical risk or CVSS scores.
Webinar | Cloud Summit Solutions Track 2026 | Tuesday, August 18 | Explore innovative solutions for securing AWS, Azure, Google Cloud, Kubernetes, containers, and hybrid cloud environments.
Survey | Detection & Response Survey | Your insights are critical to helping the community understand what's working, what's not, and where the gaps remain.
Webinar | From Framework to Action: Applying the SANS AI Security Maturity Model | Wednesday, September 16 | Chris Cochran, Diana Kelley, Malcolm Harkins, and Kyriakos "Rock" Lambros