Visualização normal

Ontem — 7 de Setembro de 2026Cybersecurity News
  • ✇Cybersecurity News
  • Weekly CVE Report: Daily Cybersecurity Beats CISA KEV on Exploited Flaws Do Son
    This weekly CVE report covers 10 exploited vulnerabilities added to CISA KEV and 2,316 new CVEs from Aug 31 to Sep 6, 2026. Patch fast. Related Posts: Weekly CVE Report: 11 Exploited Flaws Added to KEV Weekly Threat Intelligence Report: Late August 2026 Weekly Threat Intelligence Report: Mid-August 2026 The post Weekly CVE Report: Daily Cybersecurity Beats CISA KEV on Exploited Flaws appeared first on Daily CyberSecurity.
     
Antes de ontemCybersecurity News
  • ✇Security | CIO
  • Cyber resilience is a very human decision problem, not just a technology one
    Organizations today are not short of data, particularly in the domain of cyber. What many lack is a timely, trusted assessment that can help leaders act with greater confidence. When a cyber incident begins, the technical questions surface first. What happened? Which systems are affected? Is the activity contained? But the questions that often shape the outcome are rarely technical alone. Who is behind the activity? What are they trying to achieve? Is this an isolated e
     

Cyber resilience is a very human decision problem, not just a technology one

2 de Setembro de 2026, 06:00

Organizations today are not short of data, particularly in the domain of cyber. What many lack is a timely, trusted assessment that can help leaders act with greater confidence.

When a cyber incident begins, the technical questions surface first. What happened? Which systems are affected? Is the activity contained? But the questions that often shape the outcome are rarely technical alone. Who is behind the activity? What are they trying to achieve? Is this an isolated event or part of a broader campaign? Which customers, suppliers, assets or services are exposed? Is there a sanction, legal, regulatory or reputational dimension? And what is a proportionate immediate response while the facts are still incomplete?

This is why cyber is, in a meaningful sense, as much a human decision-making problem as a technological one. The OECD argues that digital security risk should be integrated into broader decision-making, rather than treated only as a technical issue. Tools can detect signals, spot patterns, correlate events and flag anomalies, but it takes people to decide what those signals mean, when to escalate, which trade-offs matter and what action the organization should take. In Moody’s recent whitepaper on supporting decision dominance through financial, corporate and trade intelligence, we make the case that the decisive moments in a cyber incident belong not only to systems, but to judgement.

That matters for CIOs and other technology decision-makers, because theirs is one of the most demanding decision environments in the enterprise. Reporting lines and structures vary by organization, but common themes tend to recur: technical complexity, compressed timelines, uncertain attribution and fragmented responsibility. Security teams may see indicators before they understand intent. Legal teams may need to assess obligations before the full scope of an incident is known. Communications teams often must prepare for scrutiny while operations are still working through containment. Business leaders may first need to decide when a decision must be made, then whether to pause a service, isolate a supplier, notify a regulator, issue a public statement or accept some temporary disruption to prevent greater harm.

The result can be a gap between signal and action, at a time when many organizations are experiencing a growing volume of cyber signals and alerts. Organizations commonly track mean time to detect and respond. But a less visible but equally consequential metric is decision latency: the time it takes to move from a technical signal to a shared understanding of what matters, and a decision about what to do. An organization can identify a threat quickly and still act too slowly if it cannot interpret the signal, convene the relevant stakeholders or agree on a proportionate response. The challenge is not simply speed — decisions made quickly but poorly can amplify harm. It is reducing decision latency without sacrificing judgement. This urgency is not theoretical and shouldn’t simply be admired. In her 2026 GCHQ Annual Lecture at Bletchley Park, Director Anne Keast-Butler described “a moment of consequence” shaped by the radical uncertainty. Her wider point is key for CIOs and their peers across the board: cyber security is a critical priority, and resilience depends on the ability to act with urgency, judgement and trusted partnerships.

From signal to context

Technical signals tend to become more useful when connected to wider context. A malicious domain, an unusual login, a compromised account or malware signature may tell a security team that something is happening. On its own, that signal rarely tells an executive what the organization should do next. Context reframes the question from “what does this indicator mean?” to “what decision should we make?”

That context can take several forms. Payment flows may provide additional context regarding the financial networks associated with an event or risk scenario. Ownership structures can help identify relationships between suppliers, counterparties or entities that may merit further review. Sanctions exposure may change the legal and compliance implications of a response. Adverse media may provide indicators of potential reputational or integrity concerns. Corporate linkages may reveal that what looks like a narrow technical event is in fact connected to a wider network of actors, assets or interests.

None of this removes uncertainty altogether, and no decision-maker should wait for perfect information before acting. What broader context does is improve the conditions under which judgement is exercised. Two incidents may look similar at the technical level but demand different leadership responses. One may be opportunistic criminal activity with limited broader consequence. Another may involve connections to a sanctioned entity, an organized crime network, a critical supplier or a state-linked ecosystem. The signal may look similar, but the appropriate response is not.

A cross-discipline exercise

This distinction matters because cyber response is often not contained within the security function, especially in a learning organization. A serious incident typically draws in teams from across multiple disciplines, such as security, IT, legal, risk, compliance, finance, procurement, communications and business operations. It may also involve external parties such as law enforcement, intelligence agencies, regulators, financial institutions, infrastructure operators and key suppliers. The CIO will not own every lever in this environment, and organizational structure will influence how close to the centre of the systems they sit, dependencies and information flows that affect the organization’s ability to respond effectively. Is the CIO supported or supporting during an incident? What leeway is afforded the CIO to act when required?

A common challenge in cyber response is not the absence of technical capability, but the absence, or fragility, of a shared decision model. Teams will have data, dashboards and incident playbooks in place, but still lack clarity on who decides, what information is needed, which trade-offs are acceptable and how quickly business context can be brought to bear. Ensuring a common operating picture — one that gives the leadership team a shared understanding of the same facts — tends to be a differentiator between organizations that respond coherently and those that do not.

For CIOs and CEOs, this is an organizational design problem as much as a technology one. Experience suggests that a cyber strategy that stands alone may be less effective than one integrated into the organization’s broader strategy from the outset. Cyber maturity should not be judged only by the number of controls deployed, alerts processed or systems monitored, but also by the quality of the decisions an organization can make under pressure. Using scenarios to test decision making can help refine organizational design, highlight blockers that may emerge at critical times, and improve leaders’ understanding of the potential consequences of poor decision making. That wider coordination challenge is reflected in CISA’s incident response guidance, which treats serious cyber incidents as events requiring coordination across multiple stakeholders.

Where integrated intelligence adds value

This is where integrated intelligence has a role to play. Its value lies less in the sheer volume of information it provides — most organizations already have more data than they can absorb — and more in its ability to help prioritize, separating signal from noise. It can help distinguish activity that is technically interesting from activity that may be strategically material. Used well, it can help identify enabling networks associated with an attack, inform disruption options and help focus scarce defensive resources on the assets, relationships and dependencies most likely to matter.

The aim is not to know everything. It is to develop sufficient understanding of the most relevant factors early enough to support timely actions while meaningful response options remain available.

CIOs can make this practical by asking five questions:

  1. Which cyber decisions must be made in the first moments, the first hour, first day and first week of a serious incident?
  2. Who is authorized to make them, what is their availability 24/7 and who deputizes in their absence?
  3. Can technical indicators be linked quickly to business impact, financial exposure, legal risk, supplier dependency and external context?
  4. Can security teams escalate without creating unnecessary alarm?
  5. Can the CEO and board be briefed in decision-ready language, with recommendations rather than technical detail alone?

These questions move the conversation from reporting to leadership, and they reflect the human reality of cyber defence. Employees, analysts, managers and executives are asked to make repeated judgement calls under uncertainty, often with too much noise and too little time. Attackers are often well placed to exploit that reality; resilient organizations tend to design around it

Beyond visibility

Cybersecurity has spent years improving visibility, and that work remains essential. But visibility alone does not create resilience. The next challenge is decision quality.

For CIOs, the strategic shift is that cyber signals become most valuable when connected to real-world consequences: financial, operational, legal, reputational and geopolitical. In a fast-moving incident, the critical question is rarely whether the organization has more data. It is whether leaders can understand what matters, decide what to do and act while meaningful response options remain available.

The organizations that are often most effective in this environment are not necessarily those with the most dashboards. They are often those that have worked to reduce decision latency without sacrificing judgement, often through rehearsal, scenario testing and learning from gaps identified during those exercises. In an environment shaped by ambiguity, compressed timelines and interconnected risk, the ability to make better decisions faster may become one of the defining measures of not just cyber resilience, but of leadership itself.

  • ✇Cybersecurity News
  • Weekly Threat Intelligence Report: Mid-August 2026 Do Son
    Read our weekly threat intelligence report for mid-August 2026. Explore critical active vulnerability updates, Metabase exploits, and CISA KEV additions. Related Posts: Weekly CVE Report: 6 Actively Exploited Flaws and 1,877 New CVEs CVE Weekly Roundup: July 27 – August 2, 2026 Weekly Threat Intelligence Briefing: Late July 2026 The post Weekly Threat Intelligence Report: Mid-August 2026 appeared first on Daily CyberSecurity.
     

Apple Fixes 194 Security Flaws Across iPhone, Mac and Other Devices

28 de Julho de 2026, 15:26

Apple’s latest iPhone, iPad and Mac updates patch 194 unique security flaws involving root access, kernel code execution and protected data.

The post Apple Fixes 194 Security Flaws Across iPhone, Mac and Other Devices appeared first on TechRepublic.

  • ✇Firewall Daily – The Cyber Express
  • Before You Give AI Access to Your Code, Read This NCSC Warning Samiksha Jain
    The growing use of AI vulnerability management tools is changing how organisations identify security flaws, but the UK’s National Cyber Security Centre (NCSC) has warned that companies must not rush into adopting artificial intelligence without understanding the risks and operational challenges involved. In a detailed advisory, Ruth C, Head of Vulnerability Management Group at the NCSC, outlined 10 critical questions organisations should ask before using AI models to identify vulnerabilities
     

Before You Give AI Access to Your Code, Read This NCSC Warning

AI vulnerability management

The growing use of AI vulnerability management tools is changing how organisations identify security flaws, but the UK’s National Cyber Security Centre (NCSC) has warned that companies must not rush into adopting artificial intelligence without understanding the risks and operational challenges involved. In a detailed advisory, Ruth C, Head of Vulnerability Management Group at the NCSC, outlined 10 critical questions organisations should ask before using AI models to identify vulnerabilities in systems, software, and infrastructure. The guidance comes as businesses increasingly face pressure to adopt AI-driven security tools amid rising cyber threats and growing board-level focus on cyber resilience. The NCSC said that while AI can help improve security capabilities, simply finding vulnerabilities does not automatically make an organisation safer. In some cases, poor implementation of AI systems could even introduce new risks.

AI Vulnerability Management Should Start With Security Basics

A key message from the guidance is that organisations should prioritise cyber hygiene before investing heavily in AI vulnerability management solutions. According to the NCSC, unpatched systems and weak access controls remain far more dangerous than many advanced zero-day threats. The agency stressed that businesses should first understand their IT estate, software dependencies, and patching processes before relying on AI tools to uncover vulnerabilities. The advisory noted that thousands of vulnerabilities are reported every year, but only a relatively small percentage are actively exploited by attackers. The NCSC referenced data showing that more than 40,000 vulnerabilities were assigned CVEs in 2025, while only a fraction appeared in exploitation tracking systems such as the Known Exploited Vulnerabilities (KEV) catalog. This highlights why prioritised patching and effective remediation remain central to strong cybersecurity practices.

Organisations Must Prepare to Handle AI-Discovered Vulnerabilities

The NCSC warned that companies adopting AI vulnerability management tools need a mature process for handling the large number of findings these systems can generate. Security teams must be able to receive, prioritise, assess, and fix vulnerabilities without overwhelming operational teams. The guidance also emphasised the importance of addressing the root cause of vulnerabilities instead of only fixing individual flaws. The agency encouraged organisations to develop structured vulnerability management processes and maintain clear workflows for remediation and patch deployment.

Data Exposure and Infrastructure Risks Remain Major Concerns

The guidance also highlighted several risks associated with using AI models for vulnerability discovery. One of the biggest concerns is data exposure. Organisations may unknowingly provide AI platforms with access to sensitive code repositories, internal documentation, historic bug reports, or even production systems. The NCSC advised organisations to carefully assess how AI systems are deployed, what permissions they receive, and whether infrastructure is properly sandboxed. Businesses were also urged to review data retention policies, legal obligations, and jurisdictional issues before using hosted AI models. The advisory specifically asked organisations to consider questions such as whether the AI system can access production environments, how infrastructure will be secured, and whether the organisation understands the terms and conditions attached to AI services.

Human Expertise Still Critical in AI Vulnerability Management

While AI tools are becoming more capable, the NCSC made clear that they are not a replacement for cybersecurity professionals. The guidance stated that AI models should be viewed as tools that enhance the capabilities of security teams rather than replace them. Organisations were encouraged to invest in skilled cybersecurity staff who can validate AI-generated findings and interpret results accurately. The NCSC also recommended combining AI analysis with human verification to reduce false positives and improve the reliability of vulnerability assessments.

Long-Term Planning Needed as AI Models Evolve

The advisory stressed that organisations must prepare for rapid advancements in AI cybersecurity capabilities over the coming years. The NCSC believes frontier AI developments will play a major role in cyber resilience throughout the next decade. As new models emerge with evolving capabilities, organisations will need long-term strategies for managing resources, updating security workflows, supporting customers, and responding to vulnerabilities discovered in third-party products and services. The agency also emphasised the importance of strong asset management and dependency management practices, noting that organisations should have a clear understanding of all systems, libraries, and services operating within their environments. As interest in AI vulnerability management continues to grow, the NCSC’s guidance serves as a reminder that AI adoption in cybersecurity requires careful planning, governance, and operational maturity rather than quick deployment driven by hype alone.
  • ✇Security Boulevard
  • How AutoSecT Uses AI to Find Vulnerabilities That Actually Matter Puja Saikia
    We always think we are more vulnerable than our fellow contemporaries! In general sense, this shows lack of confidence, but when you are dealing with security, this is one of the best traits you can have! Sounds strange, right! Let’s be honest, most security teams aren’t short on vulnerability data. They’re drowning in it. Scan […] The post How AutoSecT Uses AI to Find Vulnerabilities That Actually Matter appeared first on Kratikal Blogs. The post How AutoSecT Uses AI to Find Vulnerabilities Tha
     

How AutoSecT Uses AI to Find Vulnerabilities That Actually Matter

1 de Maio de 2026, 07:25

We always think we are more vulnerable than our fellow contemporaries! In general sense, this shows lack of confidence, but when you are dealing with security, this is one of the best traits you can have! Sounds strange, right! Let’s be honest, most security teams aren’t short on vulnerability data. They’re drowning in it. Scan […]

The post How AutoSecT Uses AI to Find Vulnerabilities That Actually Matter appeared first on Kratikal Blogs.

The post How AutoSecT Uses AI to Find Vulnerabilities That Actually Matter appeared first on Security Boulevard.

  • ✇Security Boulevard
  • We Need a Shared Responsibility Model for AI Or Eshed
    Over the past 6-8 months, researchers at my company discovered vulnerabilities across multiple AI tools that allowed external bad actors to steal data, exploit AI browsers, or poison the core memories of AI systems. As we responsibly disclosed these flaws, we found that AI vendors almost universally told us, “It’s not our problem.” In their.. The post We Need a Shared Responsibility Model for AI appeared first on Security Boulevard.
     

We Need a Shared Responsibility Model for AI

17 de Abril de 2026, 16:23

Over the past 6-8 months, researchers at my company discovered vulnerabilities across multiple AI tools that allowed external bad actors to steal data, exploit AI browsers, or poison the core memories of AI systems. As we responsibly disclosed these flaws, we found that AI vendors almost universally told us, “It’s not our problem.” In their..

The post We Need a Shared Responsibility Model for AI appeared first on Security Boulevard.

  • ✇Security Boulevard
  • National Vulnerability Database (NVD) Shifts to Selective Enrichment as CVE Volume Surges Flashpoint
    Under a new model announced by the National Institute of Standards and Technology, NVD will no longer enrich every CVE. Instead, enrichment efforts will focus on a defined subset, including vulnerabilities in the CISA KEV catalog, software used by the federal government, and software designated as critical. The post National Vulnerability Database (NVD) Shifts to Selective Enrichment as CVE Volume Surges appeared first on Flashpoint. The post National Vulnerability Database (NVD) Shifts to Selec
     

National Vulnerability Database (NVD) Shifts to Selective Enrichment as CVE Volume Surges

17 de Abril de 2026, 14:58

Under a new model announced by the National Institute of Standards and Technology, NVD will no longer enrich every CVE. Instead, enrichment efforts will focus on a defined subset, including vulnerabilities in the CISA KEV catalog, software used by the federal government, and software designated as critical.

The post National Vulnerability Database (NVD) Shifts to Selective Enrichment as CVE Volume Surges appeared first on Flashpoint.

The post National Vulnerability Database (NVD) Shifts to Selective Enrichment as CVE Volume Surges appeared first on Security Boulevard.

  • ✇Security Boulevard
  • Breaking the Patch Sound Barrier: Your Vulnerability Remediation Will Not Keep Up With AI Exploit… Anton Chuvakin
    Breaking the Patch Sound Barrier: Your Vulnerability Remediation Will Not Keep Up With AI Exploit Speed. So? Many years ago while at Gartner, I wrote a blog post where I defined the concept of the “Patch Sound Barrier.” (original via Archive if you don’t believe that I was that smart back in 2013 :-)) This was an idea of a maximum speed that a given organization could fix a given vulnerability. If you full throttle beyond that, the engines will whirr louder, but the plane won’t fly faster, essen
     

Breaking the Patch Sound Barrier: Your Vulnerability Remediation Will Not Keep Up With AI Exploit…

10 de Abril de 2026, 18:44

Breaking the Patch Sound Barrier: Your Vulnerability Remediation Will Not Keep Up With AI Exploit Speed. So?

Many years ago while at Gartner, I wrote a blog post where I defined the concept of the “Patch Sound Barrier.” (original via Archive if you don’t believe that I was that smart back in 2013 :-)) This was an idea of a maximum speed that a given organization could fix a given vulnerability. If you full throttle beyond that, the engines will whirr louder, but the plane won’t fly faster, essentially.

Gemini illustration for this

The discussion arose from people constantly asking about the “optimal” or “desired” speed of patching. In my time as an analyst, I reviewed plenty of policies as well as “operational practices” (which is what people call it when they don’t actually follow their own policy “because reasons” :-)). BTW, I utterly hated “30 days flat” policies that say that vulnerabilities are fixed within 30 days no matter what, and always steered people to more nuanced risk-based policies.

One concept emerged: Given a particular IT environment, there is often a maximum physical speed at which an organization can patch. That is my Patch Sound Barrier.

Why bring this up now? Because the speed of vulnerability discovery is accelerating and so does exploit dev speed, but for many organizations, the speed of remediation simply cannot be accelerated. It is not accelerating, because it cannot. Full stop.

In the past, my guidance was to focus on better vulnerability prioritization so that you fix “real risks” using CISA KEV, EPSS, CVSS (OK, maybe not in the 2020s) and various tools that analyze the data and give you a ranked list.

But today we will have more vulns and prioritization tools won’t save you. If you have 1,000,000 vulns and 1000 are “risky for you” (however defined, let’s say you have the magical tool that reveals the true and real risk for your organization … ha), you can reduce the risk enough by fixing the 1000, if you have the bandwidth to fix the 1000 (in theory). Now, imagine you have 10m vulns (thanks AI!) and say 5000 are risky. But your bandwidth is there to only fix the 1000. So your risk goes up anyway, while you work as hard as before.

Now, you might say, “Anton, you’re making absolute statements. Surely things are flexible given enough money, enough talented engineers, and these days, enough LLM tokens?”

This is true in theory. But notice I said, “given the IT environment.”

There are definitely methods for accelerating remediation in a modern, beautifully and carefully designed environment (check our podcast episode 109 for those ideas).

But let’s review the scoreboard:

  • The speed of vulnerability discovery? Increased.
  • The speed of exploit development? Increased.
  • The speed of remediation in legacy environments? Unchanged.

OK, some of you might still think “cannot” is too harsh. But people at modern organizations — all DevOps, CI/CD, open source and now AI agents — sometimes cannot comprehend what it takes to deal with a 1990s-era “DBA from Hell” who views his beloved database as a pet, not cattle, and will only allow a patch twice a year on a rigid schedule. Don’t even get me started on OT or the sea of unpatched edge appliances out there (there are “forti” millions of them there, I hear …)

So, yes, I spent years providing recommendations on how to deal with this “vulnerability flood.” This isn’t just about the current fascination with AI; at one point, the “boogeyman” was Metasploit, or something else. Or, as old people told me, SATAN / SANTA in the mid-1990s.

The fact remains: there are more risky vulns than you have time / capability. Today. AI can find the bugs in milliseconds, but it still can’t convince a legacy middleware admin to reboot a production server on a Tuesday. Or in July. Or in 2026. Or this freakin’ century …

So far it sounds like a rehash of my past ideas, but I actually want to leverage some thoughts from Phil Venables’ blog series about speed (“Things Are Getting Wild: Re-Tool Everything for Speed” and “Cybersecurity’s Need for Speed & Where To Find It”)

Before we go there, we must remember about reducing risk without remediating vulnerabilities. This was often the most insightful bit I shared with clients back in my analyst days: Sometimes your focus must be on reducing your risk, rather than fixing the bug. Kinda “assume the breach”, but for vulns: “assume you can’t patch” then what?

So, how do you get speed to break through the sound barrier (alert: these do NOT apply to everybody):

  • Brutally destroy legacy systems; if it cannot be patched quickly and safely, don’t use it. Think “SaaS and Chromebooks” (and cloud) world. Don’t think 1980s ERP crap.
  • Modernize. Kill pets. Grow cattle. Ideally, get replaceable tiny insects as cattle. They are simpler, more replaceable and less cute. Think “pets -> cattle -> insects.” [P.S. I do not recall where I got this idea, if I stole this from you, I am sorry — happy to restore credit if you tell me]
  • Evolve IT culture to accept automatic patching, everywhere. If Chrome can autopatch 1b systems safely for 10 years, perhaps there is a way to do it, eh?
  • Eliminate the risk entirely (e.g., via micro-segmentation or data avoidance) when patching is impossible. If you cannot remove the vuln, remove the connection, the system or the entire business process.
  • Shift focus from patching to overall IT lifecycle velocity by decoupling the application from infrastructure. In faster IT, patching is faster. Fight friction, just like you fight toil.

These are some ideas on how to shift from “floor the gas” to “build a supersonic plane” to break the patch sound barrier! Are you still debating patch cycles, or are you architecting your way out of the need for them? Please share more!

Enjoy … living in interesting times!


Breaking the Patch Sound Barrier: Your Vulnerability Remediation Will Not Keep Up With AI Exploit… was originally published in Anton on Security on Medium, where people are continuing the conversation by highlighting and responding to this story.

The post Breaking the Patch Sound Barrier: Your Vulnerability Remediation Will Not Keep Up With AI Exploit… appeared first on Security Boulevard.

  • ✇Security Boulevard
  • 112 or 22 to 2: Who Moved the Vulnerability Cheese? Alan Shimel
    AI can now scan codebases and generate hundreds of potential vulnerabilities in minutes. But when 112 bug reports collapse into 22 confirmed flaws and only two exploitable issues, the real disruption is how AI is reshaping the entire vulnerability lifecycle. The post 112 or 22 to 2: Who Moved the Vulnerability Cheese? appeared first on Security Boulevard.
     
❌
❌