Threat modelling stories
Belgian software SMEs risk losing B2B contracts as new EU rules expose weak threat modelling and scant security training, a PXL study says.
Weak default safeguards and uneven sandboxing could leave developers exposed to command execution before workspace trust is granted.
Encrypted data could be exposed years before practical quantum computers arrive, putting identity, telecoms and payments under pressure.
The AWS badge could help XBOW win more enterprise deals as buyers seek continuous testing that shows which vulnerabilities are exploitable.
New safeguards will let Fable 5 block more harmful cyber prompts, as Anthropic also seeks a common scale for jailbreak risk.
Its internal security team says automated agents now speed vulnerability checks, patching and production monitoring as attacks intensify.
The move aims to help defenders turn faster vulnerability discovery into working fixes, as OpenAI broadens access to its cyber tools and partners.
MDR buyers risk missing attacks if they focus on price and log limits instead of coverage across identities, endpoints and cloud systems.
Periodic penetration tests miss most systems, prompting Australian and New Zealand firms to use AI-driven checks for broader coverage and faster risk spotting.
Millions of downloads were exposed to silent code execution as a flaw in Hugging Face Transformers let malicious models run on load.
Microsoft patched a CVE-2025-59199 flaw in October after researchers showed a single click could let low-integrity code escape Windows 11's sandbox.
Broader Claude access should help MIND sharpen data discovery and loss prevention for customers, after it joined Anthropic's cyber scheme.
Members are backing tougher open source security as OpenSSF expands guidance on regulation, Python coding and AI-driven vulnerability tools.
The findings suggest AI-assisted bug hunting is edging closer to practical exploitation, raising the stakes for software teams racing to patch flaws.
Security teams under pressure to prove real exploitability can now test live production systems for attack paths rather than theoretical flaws.
Industrial operators can now test cyber exposures without touching live systems, helping prioritise fixes that could prevent costly downtime.
Security teams may be able to cut false alarms as Picus says its new platform proves whether a vulnerability can actually be exploited.
A financial services cloud was taken over in seconds in a test, highlighting how approved permissions can still let attackers reach full AWS control.
The chip could bolster banking and cloud security by proving its randomness is intact even as hardware ages, drifts or is tampered with.
A free account could have let attackers alter Zapier-maintained packages and hijack logged-in users' browser sessions, researchers said.