Infosec stories
UK firms face tighter cyber rules and faster reporting deadlines, as a new package combines protection, compliance and insurance cover.
Rising vulnerability volumes are outpacing fix times, prompting HackerOne to roll out an AI system that feeds confirmed threats into developer tools.
Security teams can now apply the same rules to AI-generated code across development and deployment, as Salt broadens its platform to curb flaws earlier.
It gives Japanese businesses a controlled way to manage accounts outside single sign-on, where staff often still store passwords informally.
Businesses adopting AI now face a single service aimed at filling gaps in governance, monitoring and incident response across workflows.
Only 12% of chief information security officers have recently validated controls they expect to stop intruders moving sideways through networks.
New silicon-level controls aim to curb unauthorised agent access and data exposure in enterprise AI storage, while keeping traffic fast.
AI-driven vulnerability discovery is leaving companies less time to patch, prompting new focus on clean recovery, air-gapped backups and testing.
Organisations are being pushed to spot hidden privilege paths in AI and machine accounts as BeyondTrust widens its identity risk assessment.
AI-driven vulnerability scanning is forcing firms to rethink complacency as Check Point says existing defences still help against Mythos.
Microsoft patched a CVE-2025-59199 flaw in October after researchers showed a single click could let low-integrity code escape Windows 11's sandbox.
Excessive access rights across hybrid estates can now be trimmed more safely, as XM Cyber adds usage data to pinpoint permissions that are no longer needed.
Regulated sectors can now route AI prompts through regional controls and zero-retention storage, reducing data-leakage risk for sensitive workloads.
Enterprises using AI tools may now face a tougher check on their defences as benchmark scores give way to real-world attack testing.
Industrials remained the main target as the monthly ransomware total eased 7%, even as The Gentlemen surged to second place among active gangs.
The move gives the cyber risk provider closer access to EMEA customers as demand rises for better oversight of supplier vulnerabilities.
Demand for secure AI infrastructure is pushing enterprises towards systems that combine computing, networking and storage in one stack.
More than half of patched flaws in major DevOps tools were high or critical in 2025, putting software supply chains at greater risk.
Enterprises are putting greater weight on fraud controls and identity checks as AI-driven customer messaging becomes central to CPaaS buying decisions.
Security teams may get broader visibility into phishing campaigns as Doppel adds inbox defence to its platform for social engineering attacks.