In the last week, four of the seven vulnerabilities CISA added to its exploited catalogue related to artificial intelligence and developer tooling. The lesson: Keep your security colleagues with you on this journey! https://t.co/bu0jCKoCKR
CISA published two red team assessments of critical infrastructure organisations last week. One organisation was fully compromised without noticing, the other caught the threat early and contained it. Both shared broadly the same weaknesses, so what separated them? This is mini P.Lo sharing a 1-minute snippet from my weekly article.
CISA published two red team assessments of critical infrastructure organisations. One organisation was fully compromised without noticing, the other caught the attack early and contained it. The two carried broadly the same weaknesses, what separated them? https://t.co/J6rxm3S8ea
Adobe Commerce went from public disclosure to active attack in 2 days last week. SAP Commerce Cloud took 3, and a VMware vCenter flaw reached 361 compromised addresses across 47 countries inside 5 days. Read this week's article to see what you need to do. https://t.co/U96uLV43LV
Eight autonomous agents worked a government network for four days at the start of July, mapping 21 systems, taking at least 85 accounts and more than 2,500 personnel records, then moving on to a nuclear safety regulator and seven energy companies. https://t.co/O2KNbssucY
Gunra stopped being a criminal crew in January 2026 and became a franchise, with an affiliate panel, a configurable builder, partner documentation and a recruitment programme paying penetration testers a share of ransom for enterprise access. #ransomware https://t.co/8NuHxPyRxa
My latest article sets out why an AI policy and an AI agent scope control are different things, and the one list every board should be able to produce today #AIGovernance#CyberRisk#BoardGovernance#ThreatIntelligence https://t.co/GOATQHvUAE
@AnthropicAI Does that mean all foreign nationals get a discount? I pay for max for a reason, that is to get advance access to the new features? And why should we pay for extra token usage to do iterations to fix things that your less capable models introduce?
We launched the second phase of the Dubai Cyber Security Strategy to reinforce the emirate's position as one of the world’s safest cities in cyberspace. The new strategy will be driven by our exceptional national talent and diverse global partnerships that place us in a good position to defuse any kind of threat in the digital realm. We are committed to deploying advanced technologies and adopting world-class innovation to ensure the highest protection for our digital assets.