Gartner says 40% of enterprises will shut down autonomous #AI agents by 2027 after governance gaps surface.
The issue @Gartner_inc's Shiva Varma - treating a read-only bot & an agent that can change cloud configs as equal risks.
https://t.co/dZvGn0HQOi
#AISecurity#AgenticAI
11 minutes is not long.
But #Nx says that was enough time for a poisoned VS Code extension to sit in Microsoft’s Visual Studio Marketplace.
Here is our coverage of #TeamPCP supply-chain campaigns across VS Code, PyPI and npm. https://t.co/bioPWWNxmt
Cookie Popup banners were supposed to give people control. Instead, they became the internet’s most annoying privacy ritual.
SPB reports on #EIC2026 & #GPC, @maxschrems , @kuppingercole , @xmlgrrl the push to move consent closer to the user.
https://t.co/cJzV7qzzLt
#Privacy
EXCLUSIVE: Asked ZDI how many vuln submissions surged at #Pwn2Own Berlin.
The answer: 450% year-over-year. Rejected researchers are now dropping 0-days publicly.
https://t.co/eP4SdlQxSp @thezdi@orange_8361@briankrebs@SwiftOnSecurity
2026 top 30 cybersecurity startups?
@notablecap's list is less hype cycles & more where CISOs are actually feeling pain right now.
@OrcaSecurity, @1Password, @AbnormalAI, @Tines, @ProjectDiscovery, @TorqHQ
https://t.co/vWwwRLzhFn
The FBI says don’t pay ransomware crews.
But after the massive Canvas data theft, says it struck a deal with to get stolen student and educator data back.
Can you trust cybercriminals to keep their word? Gulp.
https://t.co/YniCva6IUt
#cybersecurity#ransomware#databreach
Configuration drift may be the least sexy problem in cybersecurity… until it blows a hole in your environment.
Sharp piece from @DanRaywood on how forgotten configs and “temporary” exceptions quietly become real exposure.
https://t.co/GszZ7SLy2J
Most people worry about passwords. Meanwhile, the app you authorized in 2019 may still be quietly reading your email.
#OAuth/token sprawl isn’t just an enterprise problem anymore.
New from Security Point Break:
https://t.co/ob8j0o2uxX
#Cybersecurity#Privacy#OAuth
Palo Alto firewall flaw hits CISA’s exploited bugs list.
Not great. Not random noise, either.
@shaundnichols has the latest:
Palo Alto Firewall Flaw Lands on CISA Exploited-vulnerability List https://t.co/OAGNYpjm6f via @SecPoBr#Cybersecurity#CISA
The weirdest ransomware story of the week?
The real ransomware attack that really wasn't.
@rapid7 says suspected Iranian MuddyWater operators used Chaos ransomware as a diversion.
Panic creates cover.
Good breakdown via @shaundnichols:
https://t.co/hn2tpnHYKc
#Ransomware
IBM Think 2026 takeaway:
Big Blue isn’t trying to out-OpenAI OpenAI.
IBM’s AI pitch is control — infrastructure, governance, hybrid cloud, mainframes, quantum systems and the plumbing underneath enterprise AI.
Honestly? Very IBM.
https://t.co/QDV1B3xGey
#IBMThink2026
EU to Huawei and ZTE: not banned (yet), but not welcome either. This isn’t telecom security—it’s supply chain control.
@shaundnichols tackles - EU Targets Huawei, ZTE in Escalating Telecom Security Push https://t.co/UkJdsv1uI0 via @SecPoBr#EU#China#TechPolicy#SupplyChain
OAuth said- approved
AI agents heard- run wild
Tokens are quietly becoming the new attack surface—and most teams aren’t watching the handoff.
This one’s a wake-up call for identity pros. 👇
The OAuth Access was Approved. But the AI Agent Chaos was Not https://t.co/KHGjnDryrD
Utah’s new age-verification law has a VPN problem baked in.
Protecting kids is the headline. Turning privacy tools into legal tripwires is the cyber story.
Utah Age-verification Law Puts VPNs in the Crosshairs
https://t.co/5ug6rIYvHU via @SecPoBr#VPN#Privacy#Identity
Canvas isn’t “just another school app.”
It’s grades, assignments, messages and daily school life.
That’s why a claimed 3.65TB #ShinyHunters theft tied to Instructure deserves a double take.
Gulp.
#Cybersecurity#EdTech#Canvas#ShinyHunters
https://t.co/lpOcJgl49m
New nightmare unlocked: You hire a #ransomware negotiator… and he’s actually working with the ransomware crew.
No Margarine for Error: Land O’Lakes Man Pleads Guilty in #BlackCat ransomware Case
https://t.co/B9Pauz78Nd via @SecPoBr
Fraud doesn’t end when money gets stolen.
A look at mule accounts & how criminals build, recruit, verify, package, & sell access to real financial identities.
Great report & sharp research #GroupIB.
https://t.co/p5xbKnp0N8
#Fintech#Fraud#IdentitySecurity