Dark Reading, Tuesday, March 17th, 2026
More Attackers Are Logging In, Not Breaking In
Credential theft soared in the second half of 2025, thanks in part to the industrialization of infostealer malware and AI-enabled social engineering.
more →
2,417 articles · page 6 of 49
Dark Reading, Tuesday, March 17th, 2026
Credential theft soared in the second half of 2025, thanks in part to the industrialization of infostealer malware and AI-enabled social engineering.
more →
ComputerWeekly.com, Tuesday, March 17th, 2026
The Security Think Tank looks at platformisation, considering questions such as how CISOs can distinguish between a truly integrated platform and 'integration theater, and how to protect unified platforms.
more →
techradar.pro, Monday, March 16th, 2026
Today's threat of a third-party data vendor breach
more →
SC Media, Monday, March 16th, 2026
Field Effect's 2026 Cyber Threat Outlook reveals that compromised cloud identities were the primary driver behind more than 80% of incident-related alerts investigated last year, signaling a fundamental shift in attacker focus, reports Security Brief Asia.
more →
Analytics Insight, Monday, March 16th, 2026
Top 10 Cybersecurity Projects That Help Build Real-World Digital Security Skills Recognized by the Industry
more →
Security Bouelevard, Monday, March 16th, 2026
The evolution of cybersecurity challenges and the rapid pace of digital transformation have led security leaders to focus increasingly on robust and adaptive security frameworks. Among them, zero trust identity management has emerged as a cornerstone of modern security strategies.
more →
Security Bouelevard, Monday, March 16th, 2026
PDF files are the workhorses of modern business. They look official, are easy to share, and are universally trusted for contracts, invoices, HR forms, and financial reports. This very familiarity, however, has made them one of the most potent weapons in a cybercriminal's arsenal.
more →
Security Bouelevard, Monday, March 16th, 2026
Ever feel like your ai infrastructure is just a house of cards waiting for a stiff breeze? Honestly, with the way we're rushing to plug models into everything, the "secure" perimeter we spent years building is basically a screen door in a hurricane.
more →
Professional Security Magazine, Monday, March 16th, 2026
Identity attacks could never be described as novel or new cyber crime techniques. They have been around for years, yet they remain the biggest threat organisations face. Over the last year, security teams have faced an increase in attacks targeting corporate identities, and if defences are not prioritised, these attacks are likely to result in full-scale compromises with devastating impacts.
more →
SC Media, Friday, March 13th, 2026
A report based on millions of phishing emails reported to Hoxhunt in 2025 and early 2026 revealed a massive surge in AI-generated phishing attempts at the end of last year, as well as a 50-fold increase in malicious SVG attachments.
more →
Secure , Friday, March 13th, 2026
As cyber threats grow more complex, organizations increasingly rely on security platforms like SIEM, XDR, and MDR. However, many leaders and IT teams still struggle to understand how these technologies differ and how they work together to strengthen an organization's security posture.
more →
Dark Reading, Thursday, March 12th, 2026
Organizations have to prepare to ensure they have cryptography in place in the post-quantum world.
more →
Security Week, Wednesday, March 11th, 2026
Cardwell started her career at Netscape, become a VP of engineering at American Express, CISO at UnitedHealth Group, and now CISO in Residence at Transcend.
more →
Dark Reading, Wednesday, March 11th, 2026
The real frontline of American cybersecurity is a bidding war on eBay for 30-year-old industrial controllers.
more →
The Hacker News, Tuesday, March 10th, 2026
You can't control when the next critical vulnerability drops. You can control how much of your environment is exposed when it does. The problem is that most teams have more internet-facing exposure than they realise. Intruder's Head of Security digs into why this happens and how teams can manage it deliberately.
more →
LevelAct, Tuesday, March 10th, 2026
Artificial intelligence is transforming nearly every sector of the technology industry, and cybersecurity is quickly becoming one of the most affected. For decades, cybersecurity strategies relied on signature-based detection systems, rule-driven firewalls, and manual monitoring performed by security analysts. While these approaches remain important, the scale and speed of modern cyber threats have grown far beyond what traditional security tools can handle alone.
more →
The Register, Monday, March 9th, 2026
Researchers at red-team security startup CodeWall say their AI agent hacked McKinsey's internal AI platform and gained full read and write access to the chatbot in just two hours.
more →
Security Boulevard, Friday, March 6th, 2026
An analysis of 136 unique major breaches involving third-parties affecting 710 companies, published this week by Black Kite, finds approximately 26,000 additional organizations were impacted, affecting as many as 433 million individuals.
more →
The Hacker News, Thursday, March 5th, 2026
Organizations typically roll out multi-factor authentication (MFA) and assume stolen passwords are no longer enough to access systems. In Windows environments, that assumption is often wrong. Attackers still compromise networks every day using valid credentials. The issue is not MFA itself, but coverage.
more →
LevelAct, Wednesday, March 4th, 2026
Cloud security in 2026 isn't just about firewalls and vulnerability scans anymore. The cloud has become the execution environment for AI, the connective tissue for APIs, and the storage layer for high-value data. That combination-AI workloads + APIs + sensitive data-creates a threat surface that is broader, faster-moving, and more complex than the 'cloud security' conversations of a few years ago.
more →
The Hacker News, Tuesday, March 3rd, 2026
Every CISO knows the uncomfortable truth about their Security Operations Center: the people most responsible for catching threats in real time are the people with the least experience. Tier 1 analysts sit at the front line of detection, and yet they are also the most vulnerable to the cognitive and organizational pressures that quietly erode SOC performance over time.
more →
Security Boulevard, Tuesday, March 3rd, 2026
Modern enterprises are rapidly shifting toward API-centric architectures, leveraging APIs to connect internal systems, external partners, and digital services. With 74% of organizations adopting API-first development models, APIs now drive critical business logic and data exchanges at scale.
more →
ZDNet, Monday, March 2nd, 2026
Generative AI is moving from chatbot to autonomous actor. When agents can launch other agents, spend money, and modify systems, the line between productivity tool and insider threat disappears.
more →
ZDNet, Monday, March 2nd, 2026
Don't wait until AI-enabled deepfakes and malware overwhelm your organization. Experts recommend these aggressive best practices for hardening your defenses.
more →
Help Net Security, Thursday, February 26th, 2026
This month's roundup features exceptional open-source cybersecurity tools that are gaining attention for strengthening security across various environments.
more →
Security Boulevard, Thursday, February 26th, 2026
Security models that were effective a few years ago are now under immense strain because of how rapidly organizations are changing. As we move into 2026, many teams are dealing with a larger and more complex risk landscape.
more →
Search Security, Thursday, February 26th, 2026
Forewarned is forearmed, and dark web monitoring can alert organizations when they're in attacker crosshairs. But for many, the risk and expense make it more trouble than it's worth.
more →
Professional Security Magazine, Wednesday, February 25th, 2026
Now free to read as a 'flip page', digital edition online and landing through physical letter-boxes is the March edition of Professional Security Magazine. Its major feature is the Police Reform White Paper, promising more of everything from the Labour Government; more tech for police, more professional performance, and a continued stress on neighbourhood policing.
more →
Security Boulevard, Wednesday, February 25th, 2026
Vulnerability management today is not failing because teams stopped scanning. It's failing because the ground underneath it shifted.
more →
CyberSecurity Dive, Wednesday, February 25th, 2026
A report by VulnCheck shows threat groups are exploiting a small percentage of critical flaws well before security teams can mitigate.
more →
Dark Reading, Wednesday, February 25th, 2026
Attackers are bypassing email gateways through telephone-oriented attack delivery (TOAD), in which the only email payload is a phone number.
more →
techradar.pro, Wednesday, February 25th, 2026
Patching is not a security strategy - it is a change-management decision with financial, operational, and risk consequences.
more →
The Register, Wednesday, February 25th, 2026
And they're being stressed by geopolitical concerns that threaten to slow important data-sharing efforts
more →
ET Insights, Tuesday, February 24th, 2026
The modern ransomware attack no longer begins with a dramatic breach. It begins quietly with a login that looks routine, a firewall rule that appears legitimate, or a user added to a privileged group during what seems like everyday IT maintenance.
more →
Security Boulevard, Monday, February 23rd, 2026
SOAR is a set of tools that help organizations and enterprises efficiently respond to cyberthreats by automating important tasks involved in robust cybersecurity practices.
more →
techradar.pro, Monday, February 23rd, 2026
Data security and readiness for AI are IT teams' biggest priorities
more →
IT Security Guru, Friday, February 20th, 2026
Cybersecurity expert Purvi Kay spoke to the IT Security Guru about what it takes to be a true cyber leader and what the future of the industry may hold
more →
How-To Geek, Friday, February 20th, 2026
I've used Bitwarden for years, and for a long time I felt pretty good about that decision. I wasn't reusing passwords, I had strong, unique logins everywhere, and I wasn't relying on my browser to remember everything. But lately, with the steady rise in account takeovers, phishing kits, and credential-stealing malware, 'pretty good' stopped feeling good enough.
more →
Security Boulevard, Thursday, February 19th, 2026
How should security rules be organized? At first glance, this sounds like a simple data-modeling choice. In practice, it defines the daily reality of security operations: how quickly incidents can be debugged, how safely policies can evolve, how easily new offices or user communities can be onboarded, and whether growth leads to clarity-or chaos.
more →
The Hacker News, Wednesday, February 18th, 2026
In 2025, navigating the digital seas still felt like a matter of direction. Organizations charted routes, watched the horizon, and adjusted course to reach safe harbors of resilience, trust, and compliance.
more →
tech.co, Wednesday, February 18th, 2026
Plus, AI-powered phishing campaigns represented over 80% of social engineering events in 2025.
more →
Security Boulevard, Wednesday, February 18th, 2026
You know the drill - monitoring has basically turned into dashboard upon dashboard. What actually predicts a breach rarely fits neatly into a slide. The signals are uncomfortable, sometimes embarrassing, and usually harder to measure.
more →
Security Boulevard, Wednesday, February 18th, 2026
We are seeing a steady rise in cyberattacks against critical infrastructure and it's not surprising. Many of these systems rely on legacy software riddled with known vulnerabilities. When these systems fail, the impact moves quickly from networks to operations, and from operations to public safety.
more →
SecurityWeek, Tuesday, February 17th, 2026
New research shows attackers increasingly abusing APIs at machine speed as AI-driven systems widen exposure and amplify impact.
more →
SC Media, Tuesday, February 17th, 2026
For your organization to stay ahead of current and future threats, it can't rely on yesterday's cybersecurity technology. Unfortunately, even as attackers continue to refine their skills and use new techniques, many companies continue to deploy outdated firewalls and legacy endpoint protections.
more →
SC Media, Tuesday, February 17th, 2026
A seismic shift has taken place, one so profound that only a handful of companies will survive in its wake. This isn't incremental improvement: it's a foundational rewrite of how software, infrastructure, and networks operate, powered by GPU-driven reasoning, ultra-fast inference, collapsing cost curves, and agentic intelligence.
more →
SC Media, Tuesday, February 17th, 2026
Identity abuse now drives nearly two-thirds of all breaches, according to a Feb. 17 report by the Unit 42 research group at Palo Alto Networks.
more →
Security Boulevard, Tuesday, February 17th, 2026
Defenders might be bummed, but not surprised, to know that adversaries have shifted from immediate disruption to long-lived access, according to research from Picus Labs.
more →
Security Boulevard, Monday, February 16th, 2026
Firewall penetration testing examines the firewall as a security control and identifies the weaknesses that allow unwanted traffic to reach internal systems.
more →
Secure Reading, Friday, February 13th, 2026
Attackers rarely 'hack' systems directly anymore. Instead, they log in. Phishing, credential stuffing, password reuse, and data breaches have made passwords easy to steal and cheap to abuse.
more →