<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/">
    <channel>
        <copyright>Copyright TechTarget - All rights reserved</copyright>
        <description></description>
        <docs>https://cyber.law.harvard.edu/rss/rss.html</docs>
        <generator>Techtarget Feed Generator</generator>
        <language>en</language>
        <lastBuildDate>Sat, 05 Sep 2026 22:36:31 GMT</lastBuildDate>
        <link>https://www.techtarget.com/searchsecurity</link>
        <managingEditor>editor@techtarget.com</managingEditor>
        <item>
            <body>&lt;p&gt;OpenAI has pledged $1 billion in subsidized model access for frontline defenders, just days after calling for a collective surge in cyberdefense. Yet that pledge arrived on the same day it shipped Astra -- the company's first model to meet its "critical" cybersecurity threshold, meaning the model can autonomously find and exploit vulnerabilities in well-protected environments. OpenAI said Astra also sometimes tries to evade human monitoring.&lt;/p&gt; 
&lt;p&gt;"That's the imbalance that we're talking about, in a single news cycle," said Neil "Grifter" Wyler, senior network operations lead at Black Hat and vice president of defensive services at Coalfire. "Offense is advancing at frontier speed, and defense gets a subsidy."&lt;/p&gt; 
&lt;p&gt;The $1 billion pledge will subsidize access to Daybreak, OpenAI's gated cybersecurity initiative, for essential services operators. While industry experts are praising OpenAI for putting its money where its mouth is, they are also calling out the company for what they see as a critical asymmetry between offensive and defensive AI investments.&lt;/p&gt; 
&lt;p&gt;"Look, I'm not trying to be difficult here. I appreciate the effort that's being made," Wyler said. "More defenders will get access to frontier models, and that's great. But they're still handing people more of the same tool, and that tool has been trained to be much better at breaking in than keeping someone out."&lt;/p&gt; 
&lt;p&gt;Any efforts to elevate cybersecurity globally are inherently worthwhile, said Rik Turner, analyst at Omdia, a division of Informa TechTarget. But he noted that there are legitimate questions about the motivations driving OpenAI's &lt;a target="_blank" href="https://openai.com/collective-cyberdefense/" rel="noopener"&gt;call&lt;/a&gt; for collective cyberdefense -- coming as it did on the heels of the &lt;a href="https://www.techtarget.com/cybersecurity/news/366646105/OpenAI-models-escape-containment-hack-Hugging-Face"&gt;infamous Hugging Face incident&lt;/a&gt;, in which the company's own agents went rogue and hacked another organization.&lt;/p&gt; 
&lt;div class="extra-info"&gt;
 &lt;div class="extra-info-inner"&gt;
  &lt;h3 class="splash-heading"&gt;OpenAI's call for collective action on global cyberdefense&lt;/h3&gt; 
  &lt;p&gt;In an open letter published on Aug. 27, OpenAI warned that status quo cybersecurity could crumble against AI-enabled attacks within months, putting critical infrastructure and communities around the world at risk.&lt;/p&gt; 
  &lt;p&gt;It urged fellow frontier AI companies to provide model access, funding and support to critical infrastructure defenders; cybersecurity vendors to continuously test defenses against frontier cyber capabilities; governments to coordinate and fund cyberdefense efforts; and every organization to prioritize cybersecurity improvements.&lt;/p&gt;
 &lt;/div&gt;
&lt;/div&gt; 
&lt;p&gt;"Cynics might point to the fact that OpenAI itself was just involved in that very high-profile Hugging Face attack, so there may be an element of 'cover your ass,'" Turner said. "An even more cynical view might be that OpenAI, like Anthropic, is pre-IPO, so anything that A. keeps it in the public eye and B. underlines the power and prowess of its technology is a potential boost for its future share price."&lt;/p&gt; 
&lt;p&gt;Mike Bell, AI cybersecurity expert and founder and CEO at Suzu Labs, said the broader timeline sheds light on OpenAI's decision-making.&lt;/p&gt; 
&lt;p&gt;"They didn't pause Astra over what happened with Hugging Face," Bell said. "Instead, they shipped their most powerful offensive model the same week they announced the defensive fund -- on the same day they pledged to protect rural utilities. That tells you more about priorities than any press release."&lt;/p&gt; 
&lt;section class="section main-article-chapter" data-menu-title="What Daybreak for Frontline Defenders delivers"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;What Daybreak for Frontline Defenders delivers&lt;/h2&gt;
 &lt;p&gt;OpenAI's $1 billion commitment to frontline defenders includes subsidized access to frontier models, training, technical support and partnerships. Under Daybreak for America, part of the broader Daybreak for Frontline Defenders initiative, OpenAI said it will prioritize support for critical infrastructure operators, such as water systems, electric grid operators, small banks, and state and local governments.&lt;/p&gt;
 &lt;p&gt;"I think that's a great place to focus," Wyler said. "Those are all defenders who have essentially nobody -- tiny teams running old systems with no budget and oftentimes no dedicated security staff."&lt;/p&gt;
 &lt;p&gt;The initiative includes a collaboration with the Multi-State Information Sharing and Analysis Center (MS-ISAC) that will pair model access with training and practical support for a pilot group of essential services providers. Many experts say such on-the-ground help will matter most.&lt;/p&gt;
 &lt;p&gt;"The real bottleneck is practitioners. A small water utility or county health department getting Daybreak access still has nobody on staff who can interpret what the model surfaces, prioritize what actually matters or execute the fix without breaking something else," Bell said. "Ship the [model] credits alone, and you've given someone a tool they don't have the capacity to use. Pair a forward-deployed engineer or enterprise security expert with the credits, and you'd see real change."&lt;/p&gt;
 &lt;p&gt;OpenAI said that, in partnership with MS-ISAC, it will help the pilot group validate and prioritize findings, coordinate remediation and develop a repeatable approach that can be expanded over time.&lt;/p&gt;
 &lt;p&gt;"Our goal is to build a model that can protect the services Americans rely on and, with our partners, help put frontier cybersecurity in the hands of frontline defenders around the world," the company said in a &lt;a target="_blank" href="https://openai.com/index/daybreak-for-frontline-defenders/" rel="noopener"&gt;statement&lt;/a&gt;.&lt;/p&gt;
&lt;/section&gt;       
&lt;section class="section main-article-chapter" data-menu-title="And what it doesn't"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;And what it doesn't&lt;/h2&gt;
 &lt;p&gt;Shortly before Black Hat USA, OpenAI engineers met with Wyler, a Black Hat review board member, to walk him through their &lt;a target="_blank" href="https://www.cybersecuritydive.com/news/openai-hugging-face-hack-ai-models-black-hat/827167/" rel="noopener"&gt;upcoming conference talk&lt;/a&gt; about the Hugging Face incident. According to him, they said they expect to see agent-on-agent cyber knife fights by early 2027.&lt;/p&gt;
 &lt;p&gt;"I said to them, 'Look, you've taught your agent not just how to use the knife, but also how to sharpen it and how to increase the length of the blade,'" Wyler said. "'You've given your agent a knife, and you've given the defenders a baguette.'"&lt;/p&gt;
 &lt;blockquote class="main-article-pullquote"&gt;
  &lt;div class="main-article-pullquote-inner"&gt;
   &lt;figure&gt;
    You've given your agent a knife, and you've given the defenders a baguette.
   &lt;/figure&gt;
   &lt;figcaption&gt;
    &lt;strong&gt;Neil 'Grifter' Wyler&lt;/strong&gt;Vice president of defensive services, Coalfire
   &lt;/figcaption&gt;
   &lt;i class="icon" data-icon="z"&gt;&lt;/i&gt;
  &lt;/div&gt;
 &lt;/blockquote&gt;
 &lt;p&gt;Wyler told TechTarget Cybersecurity that he wants frontier AI labs to be transparent about the share of model training efforts they dedicate to defensive tasks relative to offensive ones.&lt;/p&gt;
 &lt;p&gt;"Every benchmark and report that these labs compete on publicly is an offensive one," he added. "If defense is a priority now, then that should be measurable, and they should be willing to measure it."&lt;/p&gt;
 &lt;p&gt;Wyler also said more defenders need access to frontier models so they can fight fire with fire. Notably, even approved members of OpenAI's Daybreak cybersecurity program don't yet have access to Astra.&lt;/p&gt;
 &lt;p&gt;"Right now, if you submit an application to join their cyber program, it takes a significant amount of time, or you get no response at all. People who are legitimate cyber professionals are being denied," Wyler said. "It would be great to have more transparency into what it takes to be granted those permissions, because if the tools to help build cyberdefenses with AI are kept behind a velvet rope, and only 'the chosen' are able to use them, then we're sunk."&lt;/p&gt;
 &lt;p&gt;OpenAI said in its statement that it planned to expand access and roll out less restrictive safeguards in the coming weeks.&lt;/p&gt;
 &lt;p&gt;"This will enable more defensive workflows, including vulnerability and proof-of-concept validation, malware analysis and detection engineering," the company said.&lt;/p&gt;
 &lt;p&gt;&lt;em&gt;Alissa Irei is senior site editor of TechTarget Cybersecurity.&lt;/em&gt;&lt;/p&gt;
&lt;/section&gt;</body>
            <description>OpenAI pledged $1B to cyber defenders the same day it released Astra -- its most powerful offensive model yet. Some experts warn that defense is getting left behind.</description>
            <image>https://cdn.ttgtmedia.com/visuals/LeMagIT/hero_article/Hero-Danger-by-InfiniteFlow-Adobe-10.jpg</image>
            <link>https://www.techtarget.com/cybersecurity/news/366649598/Defenders-call-out-timing-of-OpenAI-defense-pledge-Astra-release</link>
            <pubDate>Fri, 04 Sep 2026 18:12:00 GMT</pubDate>
            <title>Defenders call out OpenAI defense pledge, Astra release timing</title>
        </item>
        <item>
            <body>&lt;p&gt;A proof of concept is an important step in the cybersecurity technology purchasing process, letting decision-makers take a new tool or service for a structured test drive in their own environment.&lt;/p&gt; 
&lt;p&gt;According to experts, a PoC is most useful when a CISO has questions about a technology that the vendor cannot fully address in a sales call.&lt;/p&gt; 
&lt;p&gt;"This is common when replacing a core control, consolidating vendors, responding to a control gap or testing claims that affect risk, cost or staffing," said Jason Soroko, senior fellow at Sectigo, a certificate authority and services provider.&lt;/p&gt; 
&lt;p&gt;But not every proof of concept supports &lt;a href="https://www.techtarget.com/cybersecurity/tip/Cut-through-cybersecurity-vendor-hype-with-these-6-tips"&gt;sound cybersecurity purchasing decisions&lt;/a&gt;. A good PoC project quickly validates whether a product or service functions as it's supposed to for a specific use case. A bad PoC, however, can become a slow-motion pilot that drags on for months, consuming the cybersecurity team's time and attention without producing meaningful results. Other common pitfalls include feature creep, artificial testing conditions, poorly defined success criteria and lackluster documentation.&lt;/p&gt; 
&lt;section class="section main-article-chapter" data-menu-title="Common missteps in cybersecurity technology PoCs"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Common missteps in cybersecurity technology PoCs&lt;/h2&gt;
 &lt;p&gt;While &lt;a href="https://www.techtarget.com/it-strategy/definition/proof-of-concept-POC"&gt;PoCs&lt;/a&gt; can fail for any number of reasons, according to experts, most lose traction because of the following common missteps.&lt;/p&gt;
 &lt;h3&gt;1. They take too long&lt;/h3&gt;
 &lt;p&gt;Jeff Pollard, an analyst at Forrester Research, argued that a PoC should take only about 18 hours over two to three days. "A well-designed proof of concept isn't a deployment project," he said.&lt;/p&gt;
 &lt;p&gt;Whenever a PoC stretches into weeks or months, Pollard added, a lack of discipline is usually the root cause. The cybersecurity team might have become too invested in relationships with vendor personnel, for example, or in the future of the product itself.&lt;/p&gt;
 &lt;p&gt;"The goal is to answer a specific question: 'Can this technology successfully execute the scenarios that matter to us?'" Pollard said. "If you can't answer that after a couple of days of structured testing, the issue isn't time."&lt;/p&gt;
 &lt;h3&gt;2. They focus on technology features rather than business outcomes&lt;/h3&gt;
 &lt;p&gt;In a cybersecurity PoC, decision-makers often become distracted by a technology's bells and whistles, warned Fernando Montenegro, vice president and practice lead for cybersecurity at The Futurum Group. "Focus on how well it works in your environment," he said.&lt;/p&gt;
 &lt;p&gt;In other words, CISOs should pass on any new cybersecurity tool or service that fails to &lt;a href="https://www.techtarget.com/cybersecurity/feature/Why-effective-cybersecurity-is-important-for-businesses"&gt;improve business outcomes&lt;/a&gt; -- no matter how impressive its capabilities.&lt;/p&gt;
 &lt;p&gt;"The most effective PoC starts with clearly defining the problem you're trying to solve rather than evaluating a list of product features," agreed Shane Barney, CISO at Keeper Security, a privileged access management provider. "Security teams should establish measurable success criteria before testing begins, whether that's reducing credential risk, improving privileged access visibility, simplifying compliance or consolidating multiple security tools."&lt;/p&gt;
 &lt;h3&gt;3. They don't use real-world conditions&lt;/h3&gt;
 &lt;p&gt;Standardized, lightweight and vendor-led demos fail to test how a tool functions in an organization's real-world environment and integrates with its pre-existing technology. With that in mind, experts argued against letting a vendor define the PoC.&lt;/p&gt;
 &lt;p&gt;"The evaluation should reflect real production conditions, not an isolated lab environment, allowing organizations to assess integration with identity providers, SIEM platforms, cloud infrastructure and existing security workflows," Barney said.&lt;/p&gt;
 &lt;p&gt;Real IT environments, after all, are often messy and unpredictable. "I generally recommend three to six scenarios that represent common, uncommon and difficult operating conditions," Pollard added.&lt;/p&gt;
 &lt;h3&gt;4. They don't clearly define success criteria&lt;/h3&gt;
 &lt;p&gt;According to Sectigo's Soroko, an unsuccessful PoC often has an overly broad scope, lacks baseline metrics and fails to establish &lt;a href="https://www.techtarget.com/cybersecurity/tip/10-key-cybersecurity-metrics-and-KPIs-your-board-wants-tracked"&gt;methods for scoring results&lt;/a&gt;.&lt;/p&gt;
 &lt;p&gt;"The clearest warning sign is a PoC that begins before the organization has agreed on the problem, the buyer and the action that follows each possible outcome," he added.&lt;/p&gt;
 &lt;p&gt;Every scenario should have measurable outcomes attached to it, Pollard agreed. "Before testing begins, the team should know exactly what 'pass' and 'fail' look like. Your workshop should literally map job role, technology, scenario and success criteria together."&lt;/p&gt;
 &lt;h3&gt;5. They don't properly document and review results&lt;/h3&gt;
 &lt;p&gt;Security teams should require PoC documentation, screenshots and proof of scenario completion, Pollard said, with data that reflects the pre-established KPIs.&lt;/p&gt;
 &lt;p&gt;"Then require the vendor to present the results back to the evaluation team," he added. "Senior security leadership should participate in that review even when technical teams run the day-to-day testing."&lt;/p&gt;
&lt;/section&gt;                     
&lt;section class="section main-article-chapter" data-menu-title="What happens after the PoC"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;What happens after the PoC&lt;/h2&gt;
 &lt;p&gt;While a cybersecurity PoC can represent an important step in the technology purchasing process, the CISO must weigh results in the context of the broader security program, organizational constraints and &lt;a href="https://www.techtarget.com/cybersecurity/feature/How-to-improve-the-SOC-analyst-experience-and-why-it-matters"&gt;user experience&lt;/a&gt;.&lt;/p&gt;
 &lt;p&gt;"A solution can check every functional box and still fail in practice if it creates administrative overhead the team can't absorb or introduces friction that causes users to work around it," Barney said.&lt;/p&gt;
 &lt;p&gt;The ultimate test of a good PoC is what happens once it ends.&lt;/p&gt;
 &lt;p&gt;"A great PoC is one where the transition from PoC to production is as seamless as possible," The Futurum Group's Montenegro said. "It doesn't mean no effort, but it should mean no surprises in terms of operationalizing the new product or service."&lt;/p&gt;
 &lt;p&gt;&lt;em&gt;Sean Michael Kerner is an IT consultant, technology enthusiast and tinkerer. He has pulled Token Ring, configured NetWare and been known to compile his own Linux kernel. He consults with industry and media organizations on technology issues.&lt;/em&gt;&lt;/p&gt;
&lt;/section&gt;</body>
            <description>A cybersecurity technology proof of concept can validate a good purchasing decision -- or waste months of your team's time. Look out for these five common PoC missteps.</description>
            <image>https://cdn.ttgtmedia.com/visuals/LeMagIT/hero_article/Cybersecurity_search_AdobeStock_1884692525-hero.jpg</image>
            <link>https://www.techtarget.com/cybersecurity/feature/Avoid-these-5-pitfalls-in-your-cybersecurity-technology-PoC</link>
            <pubDate>Thu, 27 Aug 2026 21:40:00 GMT</pubDate>
            <title>Avoid these 5 pitfalls in your cybersecurity technology PoC</title>
        </item>
        <item>
            <body>&lt;p&gt;Black Hat USA 2026 returned for its 29th year, covering the latest in infosec for CISOs, technical experts, thought leaders, innovative vendors and cybersecurity pros.&amp;nbsp;&lt;/p&gt; 
&lt;p&gt;The two-day main event, which took place August 5-6 at Mandalay Bay in Las Vegas, featured more than 200 sessions on topics from cyber-resilience and malware to detection engineering, security culture, privacy, supply chain security and cryptography. And, of course, AI security, LLMs, prompt engineering, promptware, autonomous exploits and AI agents.&lt;/p&gt; 
&lt;p&gt;Four days of specialized trainings, August 1-4, covered incident response, third-party risk management, AI security for executives, red teaming, adversary tactics and more. This year also marked the return of the CISO Summit, Financial Threat Summit, Innovators &amp;amp; Investors Summit, Omdia Analyst Summit and AI Summit, as well as the inaugural Healthcare Summit, in partnership with HIMSS.&lt;/p&gt; 
&lt;p&gt;Informa TechTarget's editorial team was on-site, reporting from the conference floor. This guide gathers articles from our reporters on TechTarget Cybersecurity, Dark Reading and Cybersecurity Dive.&lt;/p&gt;</body>
            <description>This is your guide to the breaking news, trending topics and more at Black Hat USA 2026, from Dark Reading, Cybersecurity Dive and TechTarget Cybersecurity.</description>
            <link>https://www.techtarget.com/cybersecurity/conference/Black-Hat-2026-Key-news-takeaways-and-security-trends</link>
            <pubDate>Wed, 26 Aug 2026 09:00:00 GMT</pubDate>
            <title>Black Hat 2026: Key news, takeaways and security trends</title>
        </item>
        <item>
            <body>&lt;p&gt;The recent Hugging Face-OpenAI incident is raising questions about how to secure AI as it becomes more autonomous and integrated into business operations.&lt;/p&gt; 
&lt;p&gt;During a controlled security exercise in mid-July, OpenAI models &lt;a href="https://www.techtarget.com/searchsecurity/news/366646105/OpenAI-models-escape-containment-hack-Hugging-Face"&gt;accessed systems they weren't supposed to reach&lt;/a&gt; by exploiting a vulnerability in the surrounding infrastructure, eventually reaching the Hugging Face AI development platform.&lt;/p&gt; 
&lt;p&gt;The incident has challenged assumptions that isolation and &lt;a href="https://www.techtarget.com/searchsecurity/definition/sandbox"&gt;sandboxing&lt;/a&gt; can sufficiently protect AI systems. Yet security experts say the bigger takeaway is about whether businesses have properly implemented fundamental security practices such as identity and access controls, monitoring and containment.&lt;/p&gt; 
&lt;section class="section main-article-chapter" data-menu-title="The sandbox worked -- the environment didn't"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;The sandbox worked -- the environment didn't&lt;/h2&gt;
 &lt;p&gt;"The sandbox worked exactly as designed," Jen Waltz, founder and CISO at Imajenative, a Chicago-based IT and cybersecurity consultancy, told TechTarget Cybersecurity. "Unfortunately, the environment around it did not. That distinction is the whole lesson."&lt;/p&gt;
 &lt;p&gt;In the Hugging Face-OpenAI incident, Waltz added, AI didn't reinvent the wheel; instead, it showed how quickly an AI system can exploit existing security weaknesses if it has a goal and access to pursue it.&lt;/p&gt;
 &lt;p&gt;"AI didn't invent a new class of attack," she said. Rather, it executed the old ones at speed, before human operators noticed or stopped it.&lt;/p&gt;
 &lt;p&gt;"I do not agree that this challenged traditional sandboxing assumptions," echoed Rich Mogull, chief analyst for the Cloud Security Alliance (CSA), when we asked him about the limitations of this approach to security. "What we saw was a sandbox with a hole, and a system that appears to have been unmonitored."&lt;/p&gt;
 &lt;p&gt;The takeaway for CISOs: Don't abandon traditional security controls; instead, ensure you're &lt;a target="_blank" href="https://www.darkreading.com/cyberattacks-data-breaches/hugging-face-hack-lessons-cyber-defenders" rel="noopener"&gt;applying them effectively&lt;/a&gt; as AI systems find new ways to gain access and take more actions on their own.&lt;/p&gt;
&lt;/section&gt;      
&lt;section class="section main-article-chapter" data-menu-title="Steps CISOs should take now"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Steps CISOs should take now&lt;/h2&gt;
 &lt;p&gt;CSA this week issued a &lt;a target="_blank" href="https://cloudsecurityalliance.org/artifacts/hugging-face-ciso-post-mortem" rel="noopener"&gt;post-mortem report&lt;/a&gt; on the Hugging Face-OpenAI incident, recommending three steps for CISOs to take to prepare for &lt;a href="https://www.techtarget.com/searchsecurity/feature/AI-powered-attacks-What-CISOSs-need-to-know-now"&gt;AI-driven incidents&lt;/a&gt;.&lt;/p&gt;
 &lt;blockquote class="main-article-pullquote"&gt;
  &lt;div class="main-article-pullquote-inner"&gt;
   &lt;figure&gt;
    What we saw was a sandbox with a hole, and a system that appears to have been unmonitored.
   &lt;/figure&gt;
   &lt;figcaption&gt;
    &lt;strong&gt;Rich Mogull&lt;/strong&gt;Chief analyst, Cloud Security Alliance
   &lt;/figcaption&gt;
   &lt;i class="icon" data-icon="z"&gt;&lt;/i&gt;
  &lt;/div&gt;
 &lt;/blockquote&gt;
 &lt;ol class="default-list"&gt; 
  &lt;li&gt;&lt;b&gt;Now:&lt;/b&gt; Identify and secure AI agents that are at the highest risk. Limit unnecessary permissions and confirm teams can shut down risky activity.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;This month:&lt;/b&gt; Monitor AI behavior and make sure systems can recover quickly when something goes wrong. Deploy and test &lt;a href="https://www.techtarget.com/searchsecurity/tip/Top-deception-technology-vendors-for-active-defense"&gt;deception technologies&lt;/a&gt; and AI incident response processes.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;This quarter:&lt;/b&gt; Prepare for AI incidents before they happen by assigning responsibility for AI systems to someone who will respond when they behave unexpectedly. Run AI tabletop exercises and deploy system-wide deception technologies.&lt;/li&gt; 
 &lt;/ol&gt;
 &lt;p&gt;A major challenge for CISOs is how &lt;a href="https://www.techtarget.com/searchsecurity/opinion/Identity-security-for-AI-agents-The-proliferation-challenge"&gt;quickly AI systems are becoming connected&lt;/a&gt; to more tools and information. Security teams need to know what they can access and how to respond when AI doesn't behave as expected.&lt;/p&gt;
 &lt;p&gt;SANS Institute recommends that security leaders reconsider how they manage AI systems as those systems gain access to sensitive data.&lt;/p&gt;
 &lt;p&gt;"An agent is not a user, and it is not a service account," said Rob T. Lee, chief AI officer and chief of research at SANS. "It is closer to a brilliant intern with infinite energy, no instinct for boundaries and whatever credentials you handed it."&lt;/p&gt;
 &lt;p&gt;While AI providers continue to improve built-in safety measures, Lee cautions against confusing those controls with security enforcement. "Guardrails are etiquette, and access control is law," he said.&lt;/p&gt;
 &lt;p&gt;For security leaders, that means moving beyond merely asking if AI can be secured and focusing on how their organizations can understand what AI is doing and &lt;a href="https://www.techtarget.com/searchenterpriseai/tip/Build-accountability-into-AI-to-drive-business-value"&gt;who is accountable&lt;/a&gt; for its actions.&lt;/p&gt;
 &lt;p&gt;"The question was never whether organizations should adopt AI," Waltz said. "That decision was made without most security teams in the room. The advantage will belong to the organizations that can prove what their AI did, why it did it and who owns the outcome."&lt;/p&gt;
 &lt;p&gt;&lt;i&gt;Craig Galbraith is the founder and owner of Galbraith Multimedia, an independent journalism company that provides writing, editing, video hosting, podcasting, onstage presentation and consulting services to the technology industry.&lt;/i&gt;&lt;/p&gt;
&lt;/section&gt;</body>
            <description>Security experts say the lesson isn't to abandon sandboxing, but to strengthen the security controls around surrounding systems as AI tests their limits.</description>
            <image>https://cdn.ttgtmedia.com/visuals/LeMagIT/hero_article/Hero-Danger-by-InfiniteFlow-Adobe-10.jpg</image>
            <link>https://www.techtarget.com/searchsecurity/news/366646755/What-CISOs-can-learn-from-the-Hugging-Face-OpenAI-incident</link>
            <pubDate>Thu, 30 Jul 2026 16:30:00 GMT</pubDate>
            <title>What CISOs should take from the Hugging Face-OpenAI incident</title>
        </item>
        <item>
            <body>&lt;p&gt;Organizations must rethink long-held assumptions about patch management and change how they prioritize, remediate and manage cyber-risk, especially in the age of AI.&lt;/p&gt; 
&lt;p&gt;Since 2019, the average time between vulnerability disclosure and confirmed exploitation has &lt;a target="_blank" href="https://www.sans.org/press/announcements/emergency-strategy-briefing-ai-driven-vulnerability-discovery-compresses-exploit-timelines" rel="noopener"&gt;collapsed&lt;/a&gt; from months and weeks to mere hours. CISOs and their teams have far less time to assess risk, prioritize remediation and protect critical assets. CVSS scores, never a great measure of real-world risk on their own, are even less meaningful without additional metrics such as exploitability and asset criticality.&lt;/p&gt; 
&lt;section class="section main-article-chapter" data-menu-title="More than just patch deployment"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;More than just patch deployment&lt;/h2&gt;
 &lt;p&gt;Today, vulnerability management is less about &lt;a href="https://www.techtarget.com/searchenterprisedesktop/definition/patch-management"&gt;simply deploying patches&lt;/a&gt; and more about continuously identifying and reducing the exposures attackers are most likely to exploit.&lt;/p&gt;
 &lt;p&gt;"Organizations should stop treating vulnerability management as a closed loop ending in a patch," said Nicole Carignan, senior vice president of security and AI strategy and field CISO at Darktrace.&lt;/p&gt;
 &lt;p&gt;Instead, security leaders must prioritize their responses based on exploitability, exposure, asset criticality and the organization's ability to detect and&amp;nbsp;contain&amp;nbsp;exploitation if patching is delayed. "They need to know where they are exposed, what normal behavior looks like, whether they can&amp;nbsp;identify&amp;nbsp;out-of-place activity and autonomously respond or&amp;nbsp;contain it&amp;nbsp;before it becomes a larger incident," she said.&lt;/p&gt;
&lt;/section&gt;    
&lt;section class="section main-article-chapter" data-menu-title="Follow the feds"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Follow the feds&lt;/h2&gt;
 &lt;p&gt;The shift is already underway within U.S. federal civilian executive branch agencies. CISA recently issued &lt;a href="https://www.techtarget.com/searchsecurity/news/366644336/What-CISAs-new-remediation-directive-means-for-CISOs"&gt;binding operational directive 26-04&lt;/a&gt; as a response to new challenges stemming from AI-driven vulnerability discovery and exploit development. The ruling effectively replaces traditional severity-driven patch management with a risk-based model that requires agencies to consider factors such as active exploitation, internet exposure, exploit automation potential and attack impact.&lt;/p&gt;
 &lt;p&gt;The directive also requires agencies to remediate the highest-risk vulnerabilities within three days; lower-priority threats can be deferred. Significantly, as part of the mandate, federal agencies must conduct a full forensic triage after remediating high-priority vulnerabilities to determine whether their systems are already compromised.&lt;/p&gt;
 &lt;p&gt;The directive reflects a broader recognition that technical severity alone is no longer an adequate guide for remediation decisions. Instead, organizations increasingly need to weigh a vulnerability's likelihood of exploitation alongside the potential operational and &lt;a href="https://www.techtarget.com/searchsecurity/feature/Why-effective-cybersecurity-is-important-for-businesses"&gt;business impact&lt;/a&gt; of a successful attack.&lt;/p&gt;
&lt;/section&gt;    
&lt;section class="section main-article-chapter" data-menu-title="Put CVSS in context"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Put CVSS in context&lt;/h2&gt;
 &lt;p&gt;Even as vulnerability management tactics evolve, CVSS can still help companies prioritize risk initially, said Jeffrey Wheatman, senior vice president and cyber-risk strategist at Black Kite. But additional context will be vital, especially metrics such as the likelihood that a vulnerability will be exploited in the next 30 days -- as measured by the &lt;a href="https://www.techtarget.com/searchsecurity/opinion/Key-capabilities-for-effective-cyber-risk-management"&gt;Exploit Prediction Scoring System&lt;/a&gt;. When making patching decisions, organizations need to gather context about the potential operational and financial impact of a specific vulnerability in their environment.&lt;/p&gt;
 &lt;blockquote class="main-article-pullquote"&gt;
  &lt;div class="main-article-pullquote-inner"&gt;
   &lt;figure&gt;
    Architect your program as patch intelligence, not patch management.
   &lt;/figure&gt;
   &lt;figcaption&gt;
    &lt;strong&gt;Jeffrey Wheatman, senior vice president and cyber-risk strategist, Black Kite&lt;/strong&gt;
   &lt;/figcaption&gt;
   &lt;i class="icon" data-icon="z"&gt;&lt;/i&gt;
  &lt;/div&gt;
 &lt;/blockquote&gt;
 &lt;p&gt;Given the sheer velocity of AI-driven vulnerability discovery, organizations should shift from a "patch it all" mentality to a "patch what can cause damage right now" approach, Wheatman said. "Create remediation tiers with appropriate targets, not one giant patching list."&lt;/p&gt;
 &lt;p&gt;Business risk is paramount. Companies should focus on that before considering severity or technical risk, he said, adding that organizations should supplement patching with other mitigation measures such as disabling vulnerable features, blocking exploit pathways, rotating credentials and monitoring data access. "Architect your program as patch intelligence, not patch management," he said.&lt;/p&gt;
 &lt;p&gt;Jeff Williams, founder and CTO of Contrast Security, advises security leaders to invest in their abilities to quickly answer questions around how vulnerable components are deployed, configured, invoked and exposed in their production environment. That data, he said, is often far more valuable than a generic CVSS score designed to apply equally to all organizations.&lt;/p&gt;
 &lt;p&gt;"Organizations were never supposed to stop at the base score of a CVE," said Williams, who is also a co-founder of OWASP. "The real value comes from combining technical severity with threat intelligence, environmental context and business impact. In an AI-driven threat environment, that full picture matters more than ever."&lt;/p&gt;
 &lt;p&gt;Once those details are realized, Williams said, the second step is to reduce the inflow by eliminating vulnerability backlog and improving secure development practices. And the third step is to assume vulnerabilities will exist and deploy runtime protections that prevent exploitation while remediation is underway.&lt;/p&gt;
&lt;/section&gt;        
&lt;section class="section main-article-chapter" data-menu-title="Focus on behavioral analytics"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Focus on behavioral analytics&lt;/h2&gt;
 &lt;p&gt;Detection and mitigation models that rely on known attack signatures or previously observed exploit techniques have long been insufficient and will become even less effective in the AI era. AI enables attackers to rapidly &lt;a href="https://www.techtarget.com/searchsecurity/tip/How-AI-malware-works-and-how-to-defend-against-it"&gt;generate novel payloads&lt;/a&gt; and variations far faster than detections and signatures can be developed to keep pace.&lt;/p&gt;
 &lt;p&gt;In response, organizations must rely far more heavily on behavioral detection approaches that identify deviations from expected system and user activity. This includes monitoring for unusual authentication patterns, abnormal process behavior and anomalous data access flows that might indicate compromise even when no known signature or exploit pattern exists. Compensating controls, including network segmentation and tighter enforcement of &lt;a href="https://www.techtarget.com/searchsecurity/answer/Compare-zero-trust-vs-the-principle-of-least-privilege"&gt;least-privilege access&lt;/a&gt;, should become a primary layer of defense rather than a temporary fallback when vulnerabilities cannot be patched quickly enough. These techniques, which also include token and credential scoping and application-level allowlisting, aren't new, but they are quickly becoming indispensable.&lt;/p&gt;
 &lt;p&gt;"Organizations need to invest in scaled visibility, behavioral analytics, anomaly detection, autonomous investigation and autonomous containment across endpoints,&amp;nbsp;network,&amp;nbsp;cloud, identities, SaaS and critical infrastructure," Darktrace's Carignan said.&lt;/p&gt;
 &lt;p&gt;To that end, defenders must shift away from traditional approaches and move toward those that identify&amp;nbsp;anomalous behavior. Organizations these days are defending against a lot more than just software flaws. Identity and credential theft, human error, &lt;a href="https://www.techtarget.com/searchsecurity/feature/Agentic-AIs-role-in-amplifying-and-creating-insider-risks"&gt;insider threats&lt;/a&gt;, misconfigurations, misuse of AI tools and AI systems that introduce new&amp;nbsp;risk&amp;nbsp;all&amp;nbsp;must&amp;nbsp;be part of the security model.&lt;/p&gt;
 &lt;p&gt;"If a system cannot be patched quickly, the organization still needs to detect attempted exploitation and contain it at machine speed," Carignan said.&lt;/p&gt;
&lt;/section&gt;      
&lt;section class="section main-article-chapter" data-menu-title="Continuous vulnerability management"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Continuous vulnerability management&lt;/h2&gt;
 &lt;p&gt;Douglas José Pereira dos Santos, senior director of advanced threat intelligence at FortiGuard Labs, said organizations must stop thinking about patch management as a discrete operational cycle and instead focus on continually managing vulnerability exposure.&lt;/p&gt;
 &lt;p&gt;Getting there requires several structural shifts, he said. Remediation SLAs, for example, should be built on layered risk signals that include exploitation likelihood, asset exposure and business impact. Threat intelligence needs to be part of the triage decision the moment a vulnerability enters the queue and not a separate enrichment step that occurs later in a different part of the organization. Similarly, compensating controls need to be treated as formal, documented risk mitigation mechanisms rather than informal workarounds.&lt;/p&gt;
 &lt;p&gt;"The operational shift required is from prevention as the primary control to resilience as the underlying design principle," dos Santos said. At the same time, organizations must assume some exploitation will occur and engineer their environments to detect and contain attacks rapidly.&lt;/p&gt;
 &lt;p&gt;&lt;i&gt;Jaikumar Vijayan is a freelance technology journalist with more than 20 years of award-winning experience in IT trade journalism, specializing in information security, data privacy and cybersecurity topics.&lt;/i&gt;&lt;/p&gt;
&lt;/section&gt;</body>
            <description>AI accelerates exploit timelines from months to hours. Organizations must shift from patch-all to risk-based prioritization using exploitability metrics.</description>
            <image>https://cdn.ttgtmedia.com/rms/onlineimages/clock-time19.jpg</image>
            <link>https://www.techtarget.com/cybersecurity/feature/Vulnerability-management-needs-an-update-for-the-AI-era</link>
            <pubDate>Wed, 29 Jul 2026 18:26:00 GMT</pubDate>
            <title>Vulnerability management needs an update for the AI era</title>
        </item>
        <item>
            <body>&lt;p&gt;Cybersecurity executives are already familiar with the idea of phishing prevention. For years, CISOs have trained staff to be suspicious of and resistant to old-school social engineering attacks, in which attackers use fake emails or texts that seem to come from executives, managers, vendors, partners or customers. Some organizations use security awareness training tools or services that run simulated phishing attacks to identify weaknesses in training materials and users who need further training.&lt;/p&gt; 
&lt;p&gt;With the steady spread of AI tools through every part of the cybercrime marketplace, some social engineering campaigns now include voice and video, which humans are predisposed to trust. Generative AI helps malicious actors craft deepfake phishing attacks, &lt;a href="https://www.techtarget.com/searchsecurity/tip/Real-world-AI-voice-cloning-attack-A-red-teaming-case-study"&gt;using the cloned voices&lt;/a&gt; and synthetic images of company executives or even employees' direct managers or peers.&lt;/p&gt; 
&lt;p&gt;Phishing simulation tools are leveling up accordingly, incorporating AI deepfakes to probe organizational resistance to state-of-the-art social engineering across multiple channels. With these tools, security teams can &lt;a href="https://www.techtarget.com/searchcio/tip/How-executives-can-counter-AI-impersonation"&gt;impersonate executives in deepfake voice&lt;/a&gt; or video messages or even converse with staff in real time on audio or video calls, perhaps demanding they change a password or permission setting or authorize a financial transaction.&lt;/p&gt; 
&lt;section class="section main-article-chapter" data-menu-title="Is deepfake phishing simulation software worth it?"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Is deepfake phishing simulation software worth it?&lt;/h2&gt;
 &lt;p&gt;As in all cybersecurity decisions, &lt;a href="https://www.techtarget.com/searchsecurity/tip/5-ways-to-achieve-a-risk-based-security-strategy"&gt;CISOs need to weigh risk and cost&lt;/a&gt; in deciding whether to deploy deepfake-capable phishing simulations.&lt;/p&gt;
 &lt;p&gt;These kinds of tools typically come at significant cost. A CISO must weigh that cost against the organization's potential losses if a staff member falls victim to social engineering, and the likelihood of that happening. Imagine just one person responds to, say, an urgent phone call purportedly from the CIO with instructions to isolate an entire data center from the rest of the enterprise. If that would drive losses of hundreds of thousands or millions of dollars, or create existential operational risk, then better hardening against social engineering is probably justifiable. Other risks, such as leakage of personally identifiable information or confidential intellectual property, might also justify the expense.&lt;/p&gt;
 &lt;p&gt;A CISO should factor another sort of vulnerability into the calculation, too: the availability of raw materials needed to generate deepfakes. If executives, leaders or subject matter experts in the company have appeared in public at live events or on podcasts or webinars, and video or audio of those appearances is readily available on YouTube or the like, then overall risk increases. That CEO's TED Talk, that CTO's MWC (formerly Mobile World Congress) keynote, that CISO's RSAC conference session -- any could be turned into deepfake fodder.&lt;/p&gt;
 &lt;p&gt;One way to gauge the true level of vulnerability in the organization is, of course, to test using a reputable &lt;a href="https://www.techtarget.com/searchsecurity/tip/Prepare-for-deepfake-phishing-attacks-in-the-enterprise"&gt;deepfake phishing&lt;/a&gt; simulation tool on a short-term contract. Some vendors even offer trial versions, fully expecting their offerings to successfully fool prospective customers' staff and thereby prove their value.&lt;/p&gt;
 &lt;div class="extra-info"&gt;
  &lt;div class="extra-info-inner"&gt;
   &lt;h3 class="splash-heading"&gt;Deepfake phishing simulations: Metrics beyond clicks&lt;/h3&gt; 
   &lt;p&gt;Just by identifying which kinds of attacks get an employee to do the wrong thing -- click a link, change a setting, whatever -- phishing simulation tools identify where training needs improvement, processes need tightening and staff -- both individually and by department or role -- need more training.&lt;/p&gt; 
   &lt;p&gt;These tools might also offer additional insights, such as how many users who avoided the phishing attempt also reported it and how long it took them to do so. The more data cybersecurity teams have, the more targeted and meaningful their proactive efforts in training and in process and behavioral hardening can be.&lt;/p&gt; 
   &lt;p&gt;With deepfakes, new levels of testing and reporting are possible. Are staff more susceptible to pleas or threats? To emergencies or tedium? How much does tone of voice change response rates? What about the gender and appearance of the faked person? CISOs, equipped with all kinds of additional data about what their users are susceptible to, can tailor training and hardening initiatives accordingly.&lt;/p&gt;
  &lt;/div&gt;
 &lt;/div&gt;
&lt;/section&gt;      
&lt;section class="section main-article-chapter" data-menu-title="What to look for in deepfake phishing simulation software"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;What to look for in deepfake phishing simulation software&lt;/h2&gt;
 &lt;p&gt;When evaluating deepfake phishing simulation software, CISOs should consider whether offerings have the following capabilities:&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;Ability to create realistic deepfakes in the platform.&lt;/li&gt; 
  &lt;li&gt;Ability to &lt;a href="https://www.techtarget.com/searchsecurity/post/How-attackers-use-open-source-intelligence-against-enterprises"&gt;seek material for deepfakes on public sources&lt;/a&gt;, also known as open source intelligence (OSINT).&lt;/li&gt; 
  &lt;li&gt;Ability to use real-time voice conversations with a cloned voice as part of an attack simulation.&lt;/li&gt; 
  &lt;li&gt;Ability to use real-time, two-way video with a deepfake image &lt;i&gt;and &lt;/i&gt;cloned voice in a simulation.&lt;/li&gt; 
  &lt;li&gt;Ability to drive multichannel attacks -- e.g. using voice calling and SMS, or email and video conferencing.&lt;/li&gt; 
 &lt;/ul&gt;
 &lt;p&gt;It is also important to assess the tool's integration capabilities with other phishing simulation tools and phishing training packages, as well as the ease of running both broad attack simulations and spear phishing campaigns aimed at specific individuals.&lt;/p&gt;
 &lt;p&gt;Additionally, consider if there is a learning curve for advanced functionality. Also evaluate if the tool supports all the languages the company uses for business and supports all the compliance regimes the company operates under.&lt;/p&gt;
&lt;/section&gt;     
&lt;section class="section main-article-chapter" data-menu-title="Deepfake phishing simulation providers"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Deepfake phishing simulation providers&lt;/h2&gt;
 &lt;p&gt;As is typical in the cybersecurity market, deepfake phishing simulation providers currently include a fresh crop of startups focused sharply on the leading edge of the threat space -- in this case, the addition of AI-powered deepfakes -- and a smaller set of incumbents. Additional &lt;a href="https://www.techtarget.com/searchsecurity/tip/Cybersecurity-employee-training-How-to-build-a-solid-plan"&gt;security awareness training&lt;/a&gt; incumbents are likely figuring out which startups to merge with or acquire.&lt;/p&gt;
 &lt;p&gt;The following offerings, listed alphabetically, provide CISOs with insight into the current deepfake phishing simulation software market.&lt;/p&gt;
 &lt;p&gt;&lt;b&gt;Editor's note:&lt;/b&gt;&lt;i&gt;&amp;nbsp;The author selected these tools based on market research, prioritizing offerings that have sizable customer bases, relevant features and distinguishing characteristics.&lt;/i&gt;&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;&lt;b&gt;Adaptive Security. &lt;/b&gt;Creates deepfake video and audio simulations, built from public OSINT. Enables multichannel simulated attacks across email, voice, SMS and chat. Serves many verticals, including hospitality, healthcare and education.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Breacher.ai.&lt;/b&gt; Launches orchestrated, multistage attack chains with coordinated OSINT-based campaigns across channels, including deepfake videos and voice cloning. Adapts in real time based on the target's response, mirroring adversaries' behavior and stress-testing enterprise defenses.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Brightside.&lt;/b&gt; Provides phone-based social engineering attacks with live, conversational AI calls that use custom voice cloning. Runs hybrid vishing and email phishing campaigns, powered by OSINT.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Hoxhunt.&lt;/b&gt; Supports creation of deepfake audio and video for use in multichannel simulated attacks. Pre-scripted exchanges are designed to appear real time -- using the pretext of poor connectivity to explain lagging and glitching effects -- but don't support open-ended chatting. Uses fake, look-alike versions of Zoom, Microsoft Teams and Google Meet apps to contain the experience. A user who falls for the deepfake receives instant micro-training.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;KnowBe4. &lt;/b&gt;Longtime security awareness training provider introduced its Deepfake Training Content Agent in 2026. Supports audio and video uploads from consenting insiders, such as executives, to generate deepfakes. As of this writing, however, KnowBe4's published documentation does not describe support for real-time, two-way voice conversations, which is where the most novel threats currently lie.&lt;/li&gt; 
 &lt;/ul&gt;
 &lt;p&gt;As always, CISOs should assess vendors' strengths across verticals and geographies. Consider also their overall financial stability, especially if they are still venture-funded.&lt;/p&gt;
 &lt;p&gt;&lt;em&gt;John Burke is CTO and a research analyst at Nemertes Research. Burke joined Nemertes in 2005 with nearly two decades of technology experience. He has worked at all levels of IT, including as an end-user support specialist, programmer, system administrator, database specialist, network administrator, network architect and systems architect.&lt;/em&gt;&lt;/p&gt;
&lt;/section&gt;</body>
            <description>Deepfake phishing simulation software uses AI to probe organizational resistance to state-of-the-art social engineering attacks. Learn why they should be on CISOs' radar.</description>
            <image>https://cdn.ttgtmedia.com/visuals/German/Hero-Email-Sicherheit-Phishing-Adobe-V-madedee-03.jpg</image>
            <link>https://www.techtarget.com/cybersecurity/tip/What-to-know-about-deepfake-phishing-simulation-software</link>
            <pubDate>Wed, 29 Jul 2026 17:42:00 GMT</pubDate>
            <title>What to know about deepfake phishing simulation software</title>
        </item>
        <item>
            <body>&lt;p&gt;Organizations today generate, process and share more sensitive information than at any other point in history. Customer records, financial transactions, healthcare information, intellectual property, employee data, operational telemetry and AI training data sets routinely move across cloud platforms, SaaS applications, development environments, analytics pipelines and third-party ecosystems. While encryption has long been a foundational security control for protecting information at rest and in transit, it offers limited protection for data that is actively being processed. There's an increasing need for data security controls that help data to retain business value while reducing the likelihood that sensitive information will be exposed to unauthorized users.&lt;/p&gt; 
&lt;p&gt;Data obfuscation tools and controls transform sensitive information into a form that is unreadable, deidentified, substituted and significantly less valuable to an attacker while preserving its usefulness for authorized business activities. Unlike encryption, which focuses on confidentiality until data is decrypted, obfuscation enables organizations to develop, test, analyze, share and process information without unnecessarily exposing production data.&lt;/p&gt; 
&lt;p&gt;CISOs should no longer view data obfuscation as a niche compliance capability. It is a practical risk reduction strategy that supports &lt;a href="https://www.techtarget.com/searchsecurity/feature/How-to-implement-zero-trust-security-from-people-who-did-it"&gt;zero trust&lt;/a&gt;, privacy by design, cloud transformation, AI adoption and third-party risk management.&lt;/p&gt; 
&lt;section class="section main-article-chapter" data-menu-title="Data obfuscation drivers and use cases"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Data obfuscation drivers and use cases&lt;/h2&gt;
 &lt;p&gt;Organizations frequently need to share data with individuals or systems that don't require access to the original values. For example, software developers might need realistic test data, while data scientists need production-like data sets to develop machine learning and other models, and vendors require access to customer information for support. Other common enterprise use cases include:&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;Software QA.&lt;/li&gt; 
  &lt;li&gt;Third-party software support.&lt;/li&gt; 
  &lt;li&gt;&lt;a href="https://www.techtarget.com/searchcloudcomputing/tip/9-cloud-migration-security-considerations-and-challenges"&gt;Cloud migration&lt;/a&gt; projects.&lt;/li&gt; 
  &lt;li&gt;Business intelligence and analytics.&lt;/li&gt; 
  &lt;li&gt;Security research.&lt;/li&gt; 
  &lt;li&gt;Demonstration environments.&lt;/li&gt; 
  &lt;li&gt;Customer support operations.&lt;/li&gt; 
 &lt;/ul&gt;
 &lt;p&gt;In each of these use cases, exposing real data increases organizational risk. Data obfuscation significantly reduces the potential impact of data breaches because attackers who obtain properly obfuscated data can't reconstruct the original information. Even if an attacker successfully compromises a development environment or third-party application, the stolen data holds little practical value.&lt;/p&gt;
 &lt;p&gt;Many &lt;a href="https://www.techtarget.com/searchsecurity/tip/State-of-data-privacy-laws"&gt;privacy regulations&lt;/a&gt; require or strongly encourage organizations to minimize unnecessary exposure of personal information, making a good case for data obfuscation controls. For example, GDPR encourages pseudonymization and data minimization as mechanisms for reducing privacy risk. CCPA and CPRA emphasize protecting consumer information and limiting unnecessary disclosure. HIPAA encourages deidentification techniques to reduce the exposure of protected health information, and PCI DSS requires strong protection of payment card data with tokenization and masking where appropriate.&lt;/p&gt;
 &lt;p&gt;While data obfuscation alone does not guarantee regulatory compliance, it provides an important primary or compensating control that significantly reduces compliance scope and breach impact.&lt;/p&gt;
&lt;/section&gt;      
&lt;section class="section main-article-chapter" data-menu-title="Primary data obfuscation methods"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Primary data obfuscation methods&lt;/h2&gt;
 &lt;p&gt;One of the most common misconceptions surrounding data obfuscation is that there is a single "best" technique. In practice, each approach addresses a different business requirement, and mature security programs often employ several of them simultaneously. The three most common techniques and controls in many organizations today are encryption, tokenization and data masking.&lt;/p&gt;
 &lt;h3&gt;Encryption&lt;/h3&gt;
 &lt;p&gt;Encryption remains the most widely deployed data protection technology. Encryption transforms plaintext into ciphertext using cryptographic algorithms and encryption keys. Only authorized users possessing the appropriate decryption keys can recover the original data.&lt;/p&gt;
 &lt;p&gt;Benefits of encryption include strong confidentiality, mature standards, excellent regulatory acceptance and broad vendor support. Some potential drawbacks are that users must decrypt data before use, key management can introduce operational complexity and the risk of post-decryption exposure exists.&lt;/p&gt;
 &lt;p&gt;The best use cases for encryption include databases, file storage, &lt;a href="https://www.techtarget.com/searchstorage/tip/Top-5-cloud-storage-security-issues-and-how-to-contain-them"&gt;cloud storage&lt;/a&gt;, backup systems and network communications. To implement encryption successfully, organizations should adopt centralized &lt;a href="https://www.techtarget.com/searchsecurity/tip/How-to-choose-a-cloud-key-management-service"&gt;key management&lt;/a&gt;, hardware security modules for high-value workloads, automated key rotation and strong separation of encryption keys from protected data.&lt;/p&gt;
 &lt;h3&gt;Tokenization&lt;/h3&gt;
 &lt;p&gt;&lt;a href="https://www.techtarget.com/searchsecurity/definition/tokenization"&gt;Tokenization&lt;/a&gt; replaces sensitive values with randomly generated surrogate values called &lt;i&gt;tokens&lt;/i&gt;. The original information remains securely stored in a token vault while applications use the token instead of the real value.&lt;/p&gt;
 &lt;p&gt;Tokenization is beneficial because it doesn't expose the original data, it reduces compliance scope and it requires minimal application changes to support it. Common challenges include the need for a secure token vault infrastructure and potential performance considerations in high-volume environments.&lt;/p&gt;
 &lt;p&gt;The best use cases for tokenization include &lt;a href="https://www.techtarget.com/searchsecurity/tip/How-payment-tokenization-works-and-why-its-important"&gt;payment processing&lt;/a&gt;, customer identifiers, healthcare identifiers and personally identifiable information. Tokenization is particularly effective when a limited number of applications require access to the original values.&lt;/p&gt;
 &lt;h3&gt;Data masking&lt;/h3&gt;
 &lt;p&gt;&lt;a href="https://www.techtarget.com/searchsecurity/definition/data-masking"&gt;Data masking&lt;/a&gt; is perhaps the most familiar obfuscation technique because of its widespread use in software development and testing. Properly implemented masking preserves the realism, formatting and relationships that applications require while removing sensitive elements. Development teams receive production-like data sets that accurately support testing without creating unnecessary exposure if those environments are compromised.&lt;/p&gt;
 &lt;p&gt;Organizations generally implement masking in one of two ways:&lt;/p&gt;
 &lt;ol class="default-list"&gt; 
  &lt;li&gt;&lt;b&gt;Static data masking&lt;/b&gt; permanently transforms a copy of production data before it is distributed to development, testing or training environments. Static masking is often preferred for use cases that require complete database copies.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Dynamic data masking&lt;/b&gt; leaves the production database unchanged while masking information in real time based on the user's identity, role or authorization level. Dynamic masking works well when production systems need to serve different classes of users with varying access privileges.&lt;/li&gt; 
 &lt;/ol&gt;
 &lt;p&gt;Benefits of data masking include simple implementation, preservation of realistic data and &lt;a href="https://www.techtarget.com/searchsecurity/definition/principle-of-least-privilege-POLP"&gt;least privilege&lt;/a&gt; support. Poorly designed masking can remain reversible, however, and these controls don't always preserve analytical relationships.&lt;/p&gt;
 &lt;p&gt;The most common masking use cases include software development, QA testing, customer support and reporting. Organizations should mask data consistently across related data sets to preserve referential integrity and prevent unauthorized reconstruction.&lt;/p&gt;
&lt;/section&gt;                
&lt;section class="section main-article-chapter" data-menu-title="Additional data obfuscation techniques"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Additional data obfuscation techniques&lt;/h2&gt;
 &lt;p&gt;In recent years, the following data obfuscation technologies and controls have emerged.&lt;/p&gt;
 &lt;h3&gt;Pseudonymization and anonymization&lt;/h3&gt;
 &lt;p&gt;Pseudonymization and &lt;a href="https://www.techtarget.com/searchdatabackup/definition/data-anonymization"&gt;anonymization&lt;/a&gt; are often discussed together, but they serve different purposes.&lt;/p&gt;
 &lt;p&gt;Pseudonymization replaces identifying information with alternate identifiers while maintaining the ability to reconnect records through separately protected lookup tables. This approach is common in healthcare research, privacy programs and environments that require legitimate reidentification.&lt;/p&gt;
 &lt;p&gt;Anonymization goes further by permanently removing the ability to identify an individual. While this sounds straightforward, achieving true anonymization is considerably more difficult than many organizations expect. It is often possible to reidentify information that appears anonymous in isolation by combining it with publicly available data sets or other internal information. Security and privacy teams should therefore be cautious about assuming that simply removing names or account numbers renders data anonymous.&lt;/p&gt;
 &lt;h3&gt;Format-preserving encryption&lt;/h3&gt;
 &lt;p&gt;Many older systems validate the format, length or structure of fields before processing them. Replacing a 16-digit account number with conventional ciphertext could break application logic or require extensive software changes. Format-preserving encryption (FPE) addresses this problem by encrypting the value while preserving its original format. A protected credit card number still appears valid, enabling existing applications to continue functioning with little or no modification. FPE is particularly useful for financial systems and older enterprise applications with strict formatting requirements.&lt;/p&gt;
 &lt;h3&gt;Synthetic data generation&lt;/h3&gt;
 &lt;p&gt;Synthetic data generation creates artificial data sets that &lt;a href="https://www.techtarget.com/searchenterpriseai/feature/GenAI-and-synthetic-data-What-can-go-wrong-in-business"&gt;preserve statistical characteristics without copying actual customer records&lt;/a&gt;. As generative AI matures, synthetic data has become increasingly valuable for software testing, analytics and machine learning while minimizing privacy concerns. Benefits include strong privacy protection, reduced regulatory exposure, excellent AI training data sets and safer software testing.&lt;/p&gt;
 &lt;h3&gt;Differential privacy&lt;/h3&gt;
 &lt;p&gt;Differential privacy introduces carefully controlled statistical noise into data sets or query results, enabling organizations to analyze large populations while reducing the ability to identify individual records. Major cloud providers, research organizations and technology companies increasingly employ differential privacy for analytics, AI and data sharing initiatives. Although still relatively specialized, it is becoming more relevant as organizations expand their AI capabilities.&lt;/p&gt;
&lt;/section&gt;            
&lt;section class="section main-article-chapter" data-menu-title="Best practices for enterprise data obfuscation"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Best practices for enterprise data obfuscation&lt;/h2&gt;
 &lt;p&gt;Successful data obfuscation programs begin with comprehensive data discovery and classification since it's difficult to protect information you haven't identified. Automated discovery tools and data security posture management (DSPM) platforms can locate sensitive information across cloud storage, SaaS platforms, databases, endpoints and collaboration systems.&lt;/p&gt;
 &lt;p&gt;Embed data obfuscation into &lt;a href="https://www.techtarget.com/searchitoperations/tip/9-ways-to-infuse-security-in-your-CI-CD-pipeline"&gt;continuous integration/continuous delivery pipelines&lt;/a&gt;, data integration workflows and cloud migration processes rather than treat it as a manual task. Automated policy enforcement improves consistency and reduces operational overhead.&lt;/p&gt;
 &lt;p&gt;Remember, don't rely on any one single technique in isolation. Encryption, masking, tokenization, strong identity controls, least privilege, data loss prevention, DSPM and continuous monitoring provide complementary layers of protection. Also, periodically assess whether it is possible to reidentify masked or anonymized data sets using public information or related internal data sets.&lt;/p&gt;
 &lt;p&gt;Establish governance that clearly defines when teams can copy production data, who can request access, which obfuscation techniques different data classes require and how the organization approves and monitors exceptions.&lt;/p&gt;
 &lt;p&gt;&lt;i&gt;Dave Shackleford is founder and principal consultant at Voodoo Security, as well as a SANS analyst, instructor and course author, and GIAC technical director.&lt;/i&gt;&lt;/p&gt;
&lt;/section&gt;</body>
            <description>With so many services requiring access to sensitive data, encryption alone is not enough. Data obfuscation has evolved into a core element of modern cybersecurity architecture.</description>
            <image>https://cdn.ttgtmedia.com/rms/onlineimages/container_g498396156.jpg</image>
            <link>https://www.techtarget.com/cybersecurity/tip/CISOs-guide-to-data-obfuscation</link>
            <pubDate>Tue, 28 Jul 2026 14:48:00 GMT</pubDate>
            <title>CISO's guide to data obfuscation</title>
        </item>
        <item>
            <body>&lt;p&gt;The combination of sophisticated attacks and increasingly complex deployments makes achieving cybersecurity and establishing centralized visibility greater challenges than ever.&lt;/p&gt; 
&lt;p&gt;Organizations generate unprecedented volumes of security telemetry across disparate environments. Security teams often struggle with the quantity of information, and fragmented visibility across tools, cloud environments and endpoints &lt;a href="https://www.techtarget.com/searchitoperations/tip/Observability-vs-monitoring-Whats-the-difference"&gt;leaves dangerous gaps&lt;/a&gt;. The result is often too much information without comprehensive coverage.&lt;/p&gt; 
&lt;p&gt;To that end, more enterprises are deploying security data lakes to consolidate and analyze security information at scale. Security data lakes improve threat detection and operational efficiency, but they also introduce governance and security considerations.&lt;/p&gt; 
&lt;p&gt;Let's compare security data lakes and SIEM workflows, then identify use cases, challenges and best practices.&lt;/p&gt; 
&lt;section class="section main-article-chapter" data-menu-title="What is a security data lake?"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;What is a security data lake?&lt;/h2&gt;
 &lt;p&gt;Security data lakes are centralized repositories designed specifically to collect security-related data. They aggregate security information from many sources, enabling long-term storage and advanced analytics at a cost-effective price.&lt;/p&gt;
 &lt;p&gt;Common data inputs include:&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;Logs and alerts.&lt;/li&gt; 
  &lt;li&gt;Endpoint telemetry.&lt;/li&gt; 
  &lt;li&gt;&lt;a href="https://www.techtarget.com/searchsecurity/tip/Enhance-security-audits-with-Nmap-and-NSE-scripts"&gt;Network activity&lt;/a&gt;.&lt;/li&gt; 
  &lt;li&gt;Firewall logs.&lt;/li&gt; 
  &lt;li&gt;Identity management systems.&lt;/li&gt; 
  &lt;li&gt;&lt;a href="https://www.techtarget.com/searchNetworking/tip/The-steps-and-benefits-of-DNS-service-audits"&gt;DNS activity&lt;/a&gt;.&lt;/li&gt; 
  &lt;li&gt;Email.&lt;/li&gt; 
  &lt;li&gt;Threat intelligence.&lt;/li&gt; 
  &lt;li&gt;Security incident records.&lt;/li&gt; 
 &lt;/ul&gt;
 &lt;p&gt;Security data lakes offer companies a unified foundation for security operations, &lt;a href="https://www.techtarget.com/searchsecurity/tip/What-is-threat-hunting-Key-strategies-explained"&gt;threat hunting&lt;/a&gt;, forensics and compliance. Because they specifically house cybersecurity-related data, security lakes stand apart from enterprise data lakes that store other information.&lt;/p&gt;
&lt;/section&gt;     
&lt;section class="section main-article-chapter" data-menu-title="Why security data lakes matter to leaders"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Why security data lakes matter to leaders&lt;/h2&gt;
 &lt;p&gt;Security data lakes offer a strategic business value. They can improve visibility across hybrid and &lt;a href="https://www.techtarget.com/searchcloudcomputing/tip/Conquer-8-cloud-observability-challenges-to-maximize-ROI"&gt;multi-cloud environments&lt;/a&gt; while eliminating data silos. A centralized database lets companies detect threats more quickly, gain operational efficiency and respond more effectively to incidents. Comprehensive analytics also supports risk management and data-driven decision-making.&lt;/p&gt;
 &lt;p&gt;Expect security lakes to offer specific, measurable business impacts, including:&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;Reduced &lt;a href="https://www.techtarget.com/searchsecurity/tip/7-key-cybersecurity-metrics-for-the-board-and-how-to-present-them"&gt;mean time to detect&lt;/a&gt;.&lt;/li&gt; 
  &lt;li&gt;Reduced mean time to respond.&lt;/li&gt; 
  &lt;li&gt;Better utilization of existing security investments.&lt;/li&gt; 
  &lt;li&gt;Lower security operations costs.&lt;/li&gt; 
  &lt;li&gt;Enhanced support for compliance reporting and audit readiness.&lt;/li&gt; 
  &lt;li&gt;Better executive and board-level reporting.&lt;/li&gt; 
  &lt;li&gt;Improved security team productivity.&lt;/li&gt; 
  &lt;li&gt;Improved scalability for future growth.&lt;/li&gt; 
 &lt;/ul&gt;
&lt;/section&gt;    
&lt;section class="section main-article-chapter" data-menu-title="Security data lakes and the evolution of SIEM"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Security data lakes and the evolution of SIEM&lt;/h2&gt;
 &lt;blockquote class="main-article-pullquote"&gt;
  &lt;div class="main-article-pullquote-inner"&gt;
   &lt;figure&gt;
    SIEM systems are optimized for real-time alerting, correlation and incident workflows. Security lakes offer scalable, long-term storage and deep analysis. Many enterprises rely on both approaches.
   &lt;/figure&gt;
   &lt;i class="icon" data-icon="z"&gt;&lt;/i&gt;
  &lt;/div&gt;
 &lt;/blockquote&gt;
 &lt;p&gt;Security lakes differ from standard SIEM tools. SIEM systems are optimized for real-time alerting, correlation and incident workflows. Security lakes offer scalable, long-term storage and deep analysis. Many enterprises rely on both approaches.&lt;/p&gt;
 &lt;p&gt;For example, if an attacker moved slowly across cloud, identity and endpoint systems over several months, a security data lake could retain enough data to reconstruct the timeline and spot patterns. A SIEM tool might miss these signals due to its shorter data retention structure.&lt;/p&gt;
 &lt;p&gt;IT leaders recognize that security lakes enhance rather than replace existing SIEM platforms. Security data lakes offer unique and complementary information; SIEM systems remain valuable for real-time monitoring and alerting. Organizations use data lakes to provide scalable, cost-effective storage to support advanced analytics in ways that are impractical with traditional SIEMs.&lt;/p&gt;
 &lt;p&gt;The combination of these tools offers greater flexibility, visibility and cost management.&lt;/p&gt;
&lt;/section&gt;      
&lt;section class="section main-article-chapter" data-menu-title="Key security data lake use cases"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Key security data lake use cases&lt;/h2&gt;
 &lt;p&gt;Security data lakes enable detection, analysis and reporting for many cybersecurity use cases, among them:&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;&lt;b&gt;Threat detection and threat hunting. &lt;/b&gt;Security data lakes correlate data from multiple sources, identify sophisticated attacks and anomalous behavior, and enable proactive threat hunting.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Incident investigation and compliance. &lt;/b&gt;Security data lakes&lt;b&gt; &lt;/b&gt;accelerate forensic investigations, support regulatory reporting and audits, and maintain historical security records.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;AI and advanced analytics. &lt;/b&gt;Security data lakes provide the large, diverse data sets necessary for machine learning, improve behavioral analytics and predictive threat detection, and support emerging &lt;a href="https://www.techtarget.com/searchsecurity/tip/How-AI-could-change-threat-detection"&gt;AI-driven security operations&lt;/a&gt; and automation initiatives.&lt;/li&gt; 
 &lt;/ul&gt;
&lt;/section&gt;   
&lt;section class="section main-article-chapter" data-menu-title="Governance, security and implementation challenges"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Governance, security and implementation challenges&lt;/h2&gt;
 &lt;p&gt;Security lakes pose adoption challenges. Understanding these challenges helps IT leaders determine whether data lakes are justified in their environment, as well as identify the hurdles they must overcome to deploy them effectively.&lt;/p&gt;
 &lt;p&gt;Specific issues include data management, governance, privacy and operational complexity:&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;&lt;b&gt;Data integrity and quality.&lt;/b&gt; Security analytics are only as effective as the data they rely on. Evaluate data normalization, validation and quality controls to ensure the lake contains useful, usable content.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Access controls and governance.&lt;/b&gt; Establish data ownership and accountability early. Once defined, implement role-based access controls and least-privilege policies. Monitor and audit access to sensitive information.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Security and privacy risks.&lt;/b&gt; Security lakes are high-value targets for attackers. Require &lt;a href="https://www.techtarget.com/searchsecurity/feature/Best-practices-to-secure-data-at-rest-in-use-and-in-motion"&gt;effective encryption for data at rest and in transit&lt;/a&gt; to protect regulated and sensitive business information. Meet industry-specific compliance requirements.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Operational complexity.&lt;/b&gt; Expect additional complexity and resource allocations for data ingestion, retention and governance across diverse data sources. Align security, IT, compliance and business stakeholders. Build a continuous improvement lifecycle.&lt;/li&gt; 
 &lt;/ul&gt;
&lt;/section&gt;    
&lt;section class="section main-article-chapter" data-menu-title="Best practices for success"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Best practices for success&lt;/h2&gt;
 &lt;p&gt;Use the following best practices to enable a successful security data lake deployment. They address accountability, risk management, governance and business value considerations.&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;Establish governance teams and policies early.&lt;/li&gt; 
  &lt;li&gt;Implement strong encryption and &lt;a href="https://www.techtarget.com/searchnetworking/tip/The-basics-of-zero-trust-network-access-explained"&gt;zero-trust access controls&lt;/a&gt;.&lt;/li&gt; 
  &lt;li&gt;Identify and prioritize high-value data sources.&lt;/li&gt; 
  &lt;li&gt;Define retention and &lt;a href="https://www.techtarget.com/searchsecurity/tip/How-to-write-a-data-classification-policy-with-template"&gt;data classification standards&lt;/a&gt;.&lt;/li&gt; 
  &lt;li&gt;Continuously monitor data lake activity, including both ingestion and consumption.&lt;/li&gt; 
  &lt;li&gt;Implement continuous data quality monitoring.&lt;/li&gt; 
  &lt;li&gt;Align initiatives with broader cybersecurity and business objectives.&lt;/li&gt; 
  &lt;li&gt;Measure success with business-focused metrics.&lt;/li&gt; 
  &lt;li&gt;Build for AI and advanced analytics readiness.&lt;/li&gt; 
 &lt;/ul&gt;
 &lt;p&gt;As cyberthreats continue to grow in scale and complexity, centralized security data is a strategic advantage. Security data lakes are reshaping how organizations detect and respond to threats. Evaluate whether the organization's current architecture can support real-time insight, scalable analytics and AI-driven security operations.&lt;/p&gt;
 &lt;p&gt;&lt;i&gt;Damon Garn owns Cogspinner Coaction and provides freelance IT writing and editing services. He has written multiple CompTIA study guides, including the Linux+, Cloud Essentials+ and Server+ guides, and contributes extensively to InformaTechTarget, The New Stack and CompTIA Blogs.&lt;/i&gt;&lt;/p&gt;
&lt;/section&gt;</body>
            <description>A security data lake gives organizations a centralized repository of security information, but it can pose governance and operational risks.</description>
            <image>https://cdn.ttgtmedia.com/rms/onlineimages/strategy_g1192721749.jpg</image>
            <link>https://www.techtarget.com/cybersecurity/tip/A-CISOs-guide-to-security-data-lakes</link>
            <pubDate>Mon, 27 Jul 2026 15:22:00 GMT</pubDate>
            <title>A CISO's guide to security data lakes</title>
        </item>
        <item>
            <body>&lt;p&gt;Organizations are leaning into zero trust, a framework that assumes no entity can access a specific asset until they have been verified, validated and authorized. This approach makes privileged identity management, or &lt;i&gt;&lt;a href="https://www.techtarget.com/searchsecurity/definition/privileged-identity-management-PIM"&gt;PIM&lt;/a&gt;&lt;/i&gt;, an increasingly important resource.&lt;/p&gt; 
&lt;p&gt;PIM supplants permanent access rights with provisional, sanctioned and audited access. This granular control gives the user or device access to precisely what they need to complete a task -- no more, no less.&lt;/p&gt; 
&lt;p&gt;This is important because credential theft or misuse was the root cause in 32% of breaches, according to IBM's "X-Force Threat Intelligence Index 2026." Threat actors rely on penetrating a system and then traversing multiple attack vectors to exploit vulnerabilities on other systems. This lateral movement was found in 87% of all breaches, Palo Alto Networks reported in its "Global Incidents Response Report 2026." Lateral movement attacks use stolen credentials and administrative tools, such as remote desktop protocol and PowerShell, to find network passwords and execute commands.&lt;/p&gt; 
&lt;p&gt;Security teams can counter this threat with PIM, putting precise, temporary privileged access controls in place. PIM, which comprises policy, workflow, enforcement and logging, uses processes and tools to administer, protect and examine accounts and permissions, including domain admins, cloud subscription owners and root access. It ensures users and devices attempting to access a system gain entry only to exactly what they need and are denied permanent privileges.&lt;/p&gt; 
&lt;section class="section main-article-chapter" data-menu-title="How privileged identity management works"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;How privileged identity management works&lt;/h2&gt;
 &lt;p&gt;PIM tools start by discovering privileged users, roles, groups, API keys, service accounts and SSH keys. Tools also locate where those things are stored, such as in Active Directory, databases and cloud environments. The tools then identify effective privilege, the sum of which assets an entity needs access to function in its role. This extends to nested groups.&lt;/p&gt;
 &lt;p&gt;To establish governance, PIM manages administrative roles. End users are not given specific rights. Instead, they are deemed eligible for future access when necessary. Privileged access is time-bound and temporary. When users need to perform a privileged task, they log into the PIM console and ask to initiate their role.&lt;/p&gt;
 &lt;p&gt;Access permissions are granted according to policy tied to requirements. These could include device compliance, manager approval, network location, risk signals and MFA. Access expires automatically.&lt;/p&gt;
 &lt;p&gt;For audit purposes, PIM tools log all events from the time of the initial request through the time of expiration. PIM applies controlled techniques to maintain secure access paths, including privileged access workstations, secure portals and bastions. To protect privileged information, PIM moves passwords and keys and stores confidential data, access policies and audit trails in a hardened vault.&lt;/p&gt;
&lt;/section&gt;     
&lt;section class="section main-article-chapter" data-menu-title="PIM benefits and challenges"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;PIM benefits and challenges&lt;/h2&gt;
 &lt;p&gt;PIM boosts an organization's security in several ways. By limiting access, PIM reduces the likelihood that credentials can be stolen. It also &lt;a href="https://www.techtarget.com/searchsecurity/tip/How-to-prevent-and-detect-lateral-movement-attacks"&gt;prevents lateral movement&lt;/a&gt; and escalation by securing pathways and reducing the time a malicious hacker has inside a breached system. PIM also establishes strong security controls for the actions the organization deems most critical.&lt;/p&gt;
 &lt;p&gt;PIM limits privilege sprawl by preventing users from gaining and keeping excessive rights. Logging capabilities support auditing and compliance efforts. Through vaulting and rotation, PIM protects shared and legacy admin accounts.&lt;/p&gt;
 &lt;p&gt;Like most security controls, however, PIM creates friction for administrators responsible for approvals, timeouts and other steps that can impede operations. Adopting PIM can be complex and expensive, particularly in hybrid environments. There is also a risk of under-securing certain pathways, leading to overconfidence.&lt;/p&gt;
 &lt;p&gt;While PIM is useful, it is only one facet of a strong defense. A multilayered security infrastructure also incorporates endpoint security, segmentation and &lt;a href="https://www.techtarget.com/searchsecurity/definition/threat-detection-and-response-TDR"&gt;threat detection and response&lt;/a&gt;.&lt;/p&gt;
&lt;/section&gt;     
&lt;section class="section main-article-chapter" data-menu-title="Best practices for effective PIM"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Best practices for effective PIM&lt;/h2&gt;
 &lt;p&gt;For a PIM program to succeed, follow these best practices:&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;&lt;b&gt;Adopt core access controls.&lt;/b&gt; Consider just-in-time role activation, scoped permissions, approvals and workflows, as well as strong MFA requirements and conditional access permissions.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Document privileged roles and permissions.&lt;/b&gt; To support strong governance, PIM needs a privileged-role catalog and administrative ownership.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Continuously update documentation.&lt;/b&gt; Because it is a dynamic asset, PIM requires consistent reviews and recertification for privileged roles and general eligibility.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Protect secrets.&lt;/b&gt; Set up specifications for human and nonhuman entities. Key vaulting for shared accounts and service accounts is essential.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Rotate controls.&lt;/b&gt; Automate checkout and check-in rotations. For service accounts, PIM should have controls around ownership, purpose, credential scope and rotation.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Address key management.&lt;/b&gt; This includes key rotation when practical. An effective PIM strategy needs to take session security into account. Session brokering, for example, uses an intermediate system to secure the connection between the accessing entity and the target resource. For logging purposes, PIM should record sessions.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Perform consistent logging.&lt;/b&gt; On a broader level, PIM tools should log elevation events and downstream processes.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Monitor PIM tools and events.&lt;/b&gt; Monitoring is important so tools can track and flag events such as anomalous elevation patterns and risky commands. To streamline incident response, PIM should integrate with &lt;a href="https://www.techtarget.com/searchsecurity/answer/SOAR-vs-SIEM-Whats-the-difference"&gt;SIEM and SOAR tools&lt;/a&gt;.&lt;/li&gt; 
 &lt;/ul&gt;
&lt;/section&gt;   
&lt;section class="section main-article-chapter" data-menu-title="Where PIM fits in identity management"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Where PIM fits in identity management&lt;/h2&gt;
 &lt;p&gt;As mentioned, PIM plays a critical role in an organization's overarching identity and access management strategy, but it is a complementary role and only one piece in the puzzle. It regulates how much access is granted, essentially acting as the enforcement controller.&lt;/p&gt;
 &lt;p&gt;PIM works alongside access management and single sign-on, which address user authentication, session management, federation and conditional access. It solidifies privileged pathways by executing authentication controls, implementing policies for privileged sessions and segmenting admin roles and accounts. PIM helps admins apply &lt;a href="https://www.techtarget.com/searchsecurity/tip/The-5-principles-of-zero-trust-security"&gt;zero-trust principles&lt;/a&gt;, including &lt;a href="https://www.techtarget.com/searchsecurity/definition/principle-of-least-privilege-POLP"&gt;least privilege&lt;/a&gt;, just-in-time and just-enough access, and continuous validation.&lt;/p&gt;
 &lt;p&gt;Many are confused about how PIM aligns with and differs from privileged access management (&lt;a href="https://www.techtarget.com/searchsecurity/definition/privileged-access-management-PAM"&gt;PAM&lt;/a&gt;). PIM oversees eligibility and elevation. For example, an organization could use PIM to grant a specific individual database admin privileges for 45 minutes on a particular day. PAM, meanwhile, governs how privileged sessions and credentials are used and tracked, such as with session recording, rotation, and check-ins and checkouts.&lt;/p&gt;
 &lt;p&gt;When executed well, PIM is a vital part of an organization's overall IAM strategy. Still, it is just one element of a larger identity strategy.&lt;/p&gt;
 &lt;p&gt;&lt;i&gt;Amy Larsen DeCarlo has covered the IT industry for more than 30 years, as a journalist, editor and analyst. As a principal analyst at GlobalData, she covers managed security and cloud services.&lt;/i&gt;&lt;/p&gt;
&lt;/section&gt;</body>
            <description>IAM is more crucial than ever in the AI era. To better control who -- and what -- is accessing systems and data, security teams need to move beyond standing access privileges.</description>
            <image>https://cdn.ttgtmedia.com/rms/onlineimages/security_a296619547.jpg</image>
            <link>https://www.techtarget.com/cybersecurity/tip/CISOs-guide-to-privileged-identity-management</link>
            <pubDate>Fri, 24 Jul 2026 16:03:00 GMT</pubDate>
            <title>CISO's guide to privileged identity management</title>
        </item>
        <item>
            <body>&lt;p&gt;OpenAI reported this week that its autonomous AI models escaped an isolated testing environment during a training exercise and breached Hugging Face, an AI collaboration platform.&lt;/p&gt; 
&lt;p&gt;Last week, Hugging Face &lt;a target="_blank" href="https://huggingface.co/blog/security-incident-july-2026" rel="noopener"&gt;disclosed&lt;/a&gt; that it "detected and responded to an intrusion into part of our production infrastructure. This one was different from anything we had handled before in one important way: it was driven, end to end, by an autonomous AI agent system -- and we detected and dissected it largely with AI of our own."&lt;/p&gt; 
&lt;p&gt;Security experts are calling the event a first-of-its-kind cyberattack. Not only was the incident carried out by an &lt;a href="https://www.techtarget.com/searchenterpriseai/definition/autonomous-AI-agents"&gt;AI agent&lt;/a&gt; with no human operator, but it was wholly unintended. The model was given a specific task under controlled conditions, yet it managed to circumvent guardrails and infiltrate Hugging Face's systems.&lt;/p&gt; 
&lt;p&gt;"We strongly believe there was no malicious intent on [OpenAI's] part," said Hugging Face co-founder and CEO Clément Delange in a statement. "It's quite mind-blowing that all this happened autonomously."&lt;/p&gt; 
&lt;section class="section main-article-chapter" data-menu-title="What happened?"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;What happened?&lt;/h2&gt;
 &lt;p&gt;OpenAI &lt;a href="https://openai.com/index/hugging-face-model-evaluation-security-incident/"&gt;disclosed&lt;/a&gt; that the security incident was actuated by a combination of its models, including an instance of its new GPT-5.6 Sol and a more capable prerelease model. During an internal evaluation on ExploitGym, a public benchmark that measures whether AI can convert existing software flaws into exploits, the models used a &lt;a href="https://www.techtarget.com/searchsecurity/tip/What-AI-zero-days-mean-for-enterprise-cybersecurity"&gt;zero-day vulnerability&lt;/a&gt; in a package-registry proxy, escalated privileges and pursued a path out of the testing environment to the internet.&lt;/p&gt;
 &lt;p&gt;Testers tasked the AI agent with solving the exploitation benchmark. However, it followed that goal so doggedly that it investigated its own containment, discovered and exploited vulnerabilities, escalated privileges and moved laterally until it found a machine with internet access. The AI deduced that Hugging Face hosted the benchmark solutions and, using multiple attack vectors, accessed the company's production infrastructure.&lt;/p&gt;
&lt;/section&gt;   
&lt;section class="section main-article-chapter" data-menu-title="The implications of rogue AI agents"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;The implications of rogue AI agents&lt;/h2&gt;
 &lt;p&gt;While Hugging Face was able to detect and contain OpenAI's rogue agent, the event underscores the perils of frontier AI models and, specifically, their ability to circumvent guardrails in pursuit of their objectives. As AI agents grow in sophistication, they might become more adept at setting reasonable boundaries when attempting to complete a task, or they could continue to display unexpected and undesirable behaviors, resulting in greater harm.&lt;/p&gt;
 &lt;p&gt;Now that AI systems have demonstrated they can execute sophisticated cyberattacks without human intent or oversight, &lt;a href="https://www.techtarget.com/searchsecurity/tip/Behavioral-biometrics-How-to-detect-non-human-threat-actors"&gt;threat actors&lt;/a&gt; will not waste any time using similar models to launch large-scale, multistage campaigns at machine speed.&lt;/p&gt;
 &lt;p&gt;The threats posed by frontier AI models have been significant enough to compel the Trump administration to &lt;a href="https://www.techtarget.com/searchenterpriseai/news/366644013/Trump-AI-order-targets-frontier-model-prerelease-review"&gt;issue an executive order&lt;/a&gt; establishing a framework for federal oversight of the most powerful AI systems, including requirements to vet models for potential national security risks prior to general availability. In the wake of this incident, congressional lawmakers have already introduced a &lt;a href="https://www.cfodive.com/news/lawmakers-push-ai-kill-switch-bill-openai-breach-sparks-alarms/826080/" target="_blank" rel="noopener"&gt;"kill-switch" bill&lt;/a&gt; that, if made law, would require AI developers to maintain the technical capacity to throttle, suspend or shut down autonomous systems at will.&lt;/p&gt;
 &lt;p&gt;Other experts urge caution as technology pioneers continue to push enterprise AI adoption. They warn that AI must be engineered with the same expectations for safety and reliability as any other critical system. Long before release, AI models must be thoroughly tested, continuously monitored and designed with the kill-switch fail-safe in the event things go drastically wrong.&lt;/p&gt;
 &lt;p&gt;OpenAI is navigating the implications of its rogue AI in real time. The company has outlined its immediate next steps:&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;Implementing strict controls in infrastructure configuration at the cost of research velocity while patching vulnerabilities.&lt;/li&gt; 
  &lt;li&gt;Working with Hugging Face to forensically investigate the incident.&lt;/li&gt; 
  &lt;li&gt;Disclosing the identified zero-day vulnerability in the internally hosted third-party software and working with the vendor to patch it.&lt;/li&gt; 
  &lt;li&gt;Using its OpenAI models to help Hugging Face improve its defenses.&lt;/li&gt; 
  &lt;li&gt;Improving and adding stronger protections around future training and evaluations.&lt;/li&gt; 
 &lt;/ul&gt;
&lt;/section&gt;       
&lt;section class="section main-article-chapter" data-menu-title="What can CISOs do now?"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;What can CISOs do now?&lt;/h2&gt;
 &lt;p&gt;Last year, Forrester introduced &lt;a href="https://www.techtarget.com/cybersecurity/tip/How-the-AEGIS-framework-mitigates-agentic-AI-risks"&gt;AEGIS&lt;/a&gt; (Agentic AI Enterprise Guardrails for Information Security), a &lt;a target="_blank" href="https://www.forrester.com/blogs/introducing-aegis-the-guardrails-cisos-need-for-the-agentic-enterprise/" rel="noopener"&gt;six-domain framework&lt;/a&gt;, to help CISOs secure, govern and manage autonomous AI agents and agentic enterprise infrastructure.&lt;/p&gt;
 &lt;p&gt;Forrester researchers &lt;a target="_blank" href="https://www.forrester.com/blogs/an-ai-security-facepalm-openais-evaluation-became-hugging-faces-incident/" rel="noopener"&gt;published a blog&lt;/a&gt; outlining the following seven priorities CISOs should take now, based on AEGIS, in light of the Hugging Face attack:&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;&lt;b&gt;Govern high-risk model evaluations.&lt;/b&gt; Implement strong authorization, perform containment tests, establish abort criteria, know incident owners and confirm communication processes.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Apply least privilege.&lt;/b&gt; Limit models' tools, credentials, compute, network paths and authority, following least-privilege guidance.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Design a containment plan for model-enabled attacks.&lt;/b&gt; Remove unnecessary egress controls, isolate package infrastructure, rotate credentials and adopt zero-trust architecture.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Document the exercise.&lt;/b&gt; Preserve prompts, reasoning artifacts, tool calls, identities, network activity and policy decisions.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Establish an incident response model.&lt;/b&gt; Implement and test a fallback model.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Evaluate AI vendors.&lt;/b&gt; Assess how third parties manage safeguards, isolate models, govern benchmarks, disclose incidents and support responders.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Treat AI as critical infrastructure.&lt;/b&gt; Map AI model use, including hosts, package proxies, repositories, benchmarks and tools, and implement controls in the event of component failures.&lt;/li&gt; 
 &lt;/ul&gt;
 &lt;p&gt;In its statement, Open AI said, "AI is accelerating the discovery and exploitation of vulnerabilities. The primary lesson from this incident is that model security and safety must keep pace with rapidly advancing capabilities."&lt;/p&gt;
 &lt;p&gt;While the damage from OpenAI's unexpected breach of Hugging Face's systems was limited, future AI models could be even more tenacious in their efforts to achieve perceived goals -- regardless of consequences. CISOs should take this novel event as a learning opportunity and shore up their agentic AI security measures now.&lt;/p&gt;
 &lt;p&gt;&lt;i&gt;Richard Livingston is an editor with Informa TechTarget's SearchSecurity site, covering cybersecurity news, trends and analysis.&lt;/i&gt;&lt;/p&gt;
&lt;/section&gt;</body>
            <description>In an unprecedented -- and unintended -- cyberattack, frontier AI models autonomously escaped their contained testing environment and breached another company's systems.</description>
            <image>https://cdn.ttgtmedia.com/rms/onlineimages/code_g1304896250.jpg</image>
            <link>https://www.techtarget.com/cybersecurity/news/366646105/OpenAI-models-escape-containment-hack-Hugging-Face</link>
            <pubDate>Thu, 23 Jul 2026 17:35:00 GMT</pubDate>
            <title>OpenAI models escape containment, hack Hugging Face</title>
        </item>
        <item>
            <body>&lt;p&gt;OpenClaw has become one of the fastest adopted open source tools in recent memory. Originally released in late 2025 under the name Clawdbot, this autonomous AI agent now boasts hundreds of thousands of GitHub stars and a rapidly expanding ecosystem of third-party skills.&lt;/p&gt; 
&lt;p&gt;For enterprise CISOs and other business leaders, &lt;a href="https://www.techtarget.com/searchcio/feature/OpenClaw-and-Moltbook-explained-The-latest-AI-agent-craze"&gt;OpenClaw's appeal is obvious&lt;/a&gt;: It can automate routine workflows, manage calendars and inboxes, and interact with SaaS platforms through natural language commands. But that convenience comes with a threat surface that traditional security models were never designed to address.&lt;/p&gt; 
&lt;section class="section main-article-chapter" data-menu-title="Why CISOs should care about OpenClaw"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Why CISOs should care about OpenClaw&lt;/h2&gt;
 &lt;p&gt;OpenClaw operates by bridging large language models and local system resources. It can run shell commands, control browsers, read/write files and interact with external services, which users can trigger from chat messages on platforms such as Slack, Signal and Discord.&lt;/p&gt;
 &lt;p&gt;The very permissions that make it useful, however, also make OpenClaw dangerous. When connected to corporate tools such as Google Workspace or Microsoft 365, OpenClaw gains access to emails, documents, calendar entries and OAuth tokens that could enable lateral movement across your environment. Security researchers have described this combination of private data access, external communication capability and exposure to untrusted content as a &lt;a href="https://www.techtarget.com/searchsecurity/tip/The-agentic-AI-lethal-trifecta-What-CISOs-should-know"&gt;&lt;i&gt;lethal trifecta&lt;/i&gt; for enterprise AI risk&lt;/a&gt;.&lt;/p&gt;
 &lt;h3&gt;OpenClaw security risks&lt;/h3&gt;
 &lt;p&gt;&lt;a href="https://www.techtarget.com/searchsecurity/tip/The-OpenClaw-security-risks-every-CISO-needs-to-know"&gt;OpenClaw risks&lt;/a&gt; are not theoretical. Security researchers have &lt;a target="_blank" href="https://declawed.io/" rel="noopener"&gt;identified&lt;/a&gt; more than a million OpenClaw instances exposed to the public internet, including 100,000-plus that were directly vulnerable to remote code execution. A critical vulnerability, &lt;a target="_blank" href="https://nvd.nist.gov/vuln/detail/CVE-2026-25253" rel="noopener"&gt;CVE-2026-25253&lt;/a&gt;, was disclosed with a CVSS score of 8.8, alongside multiple command injection advisories. Making matters worse, in early 2026, researchers &lt;a target="_blank" href="https://www.bitdefender.com/en-us/blog/labs/helpful-skills-or-hidden-payloads-bitdefender-labs-dives-deep-into-the-openclaw-malicious-skill-trap" rel="noopener"&gt;found&lt;/a&gt; roughly 17% of the public ClawHub skills registry contained malicious code, including payloads that enable credential theft and data exfiltration.&lt;/p&gt;
 &lt;p&gt;Perhaps most concerning for enterprise security teams is the shadow AI dimension: OpenClaw requires no administrator privileges to install and generates no distinctive network signatures that standard monitoring tools would flag.&lt;/p&gt;
&lt;/section&gt;      
&lt;section class="section main-article-chapter" data-menu-title="Actionable steps to manage OpenClaw risk"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Actionable steps to manage OpenClaw risk&lt;/h2&gt;
 &lt;p&gt;Despite their considerable security risks, agentic AI tools such as OpenClaw are likely here to stay. Given the technology's productivity benefits, CISOs might find employee adoption continues whether security teams sanction it or not.&lt;/p&gt;
 &lt;blockquote class="main-article-pullquote"&gt;
  &lt;div class="main-article-pullquote-inner"&gt;
   &lt;figure&gt;
    Given the technology's productivity benefits, CISOs might find employee adoption continues whether security teams sanction it or not.
   &lt;/figure&gt;
   &lt;i class="icon" data-icon="z"&gt;&lt;/i&gt;
  &lt;/div&gt;
 &lt;/blockquote&gt;
 &lt;p&gt;The most effective approach is not to ban OpenClaw outright, but to incorporate it into your existing risk management framework. Start with clear policies, isolated environments, vetted supply chains and continuous monitoring.&lt;/p&gt;
 &lt;h3&gt;Establish governance before deployment&lt;/h3&gt;
 &lt;p&gt;Before permitting OpenClaw in any capacity, define an &lt;a href="https://www.techtarget.com/searchsecurity/tip/How-to-create-an-AI-acceptable-use-policy-plus-template"&gt;acceptable use policy&lt;/a&gt; that specifies which teams can deploy the agent, what data it can access and which integrations are approved.&lt;/p&gt;
 &lt;p&gt;Treat OpenClaw instances as you would any privileged service account, using formal provisioning, review cycles and offboarding procedures.&lt;/p&gt;
 &lt;h3&gt;Isolate the runtime environment&lt;/h3&gt;
 &lt;p&gt;Deploy OpenClaw only within dedicated VMs or containers that are segmented from production networks and sensitive data stores.&lt;/p&gt;
 &lt;p&gt;Use nonprivileged, purpose-built &lt;a href="https://www.techtarget.com/searchsecurity/tip/Cybersecuritys-agentic-AI-identity-crisis-and-how-to-fix-it"&gt;credentials with the minimum permissions&lt;/a&gt; necessary. Microsoft's security guidance specifically recommends treating the agent runtime as an untrusted execution boundary.&lt;/p&gt;
 &lt;h3&gt;Lock down the skills supply chain&lt;/h3&gt;
 &lt;p&gt;Given the documented &lt;a target="_blank" href="https://www.darkreading.com/cyber-risk/malicious-openclaw-skills-clawhub-threaten-ai-supply-chain" rel="noopener"&gt;compromise of the ClawHub registry&lt;/a&gt;, organizations should maintain an internal allowlist of vetted OpenClaw skills.&lt;/p&gt;
 &lt;p&gt;Before deploying any skill, review its SKILL.md manifest and source code for hidden network calls or suspicious behavior. Never promote a new skill directly to production without sandbox testing first.&lt;/p&gt;
 &lt;h3&gt;Implement continuous monitoring&lt;/h3&gt;
 &lt;p&gt;Configure detailed logging of all agent actions, including command execution, API calls and chain-of-thought artifacts. Forward these logs to your SIEM and build detection rules similar to those used for living-off-the-land attacks. Endpoint security alone cannot interpret agent behavior, so behavioral analytics and anomaly detection are essential complements.&lt;/p&gt;
 &lt;h3&gt;Align with NIST 800-53 controls&lt;/h3&gt;
 &lt;p&gt;NIST's Control Overlays for Securing AI Systems &lt;a target="_blank" href="https://csrc.nist.gov/projects/cosais" rel="noopener"&gt;project&lt;/a&gt; is developing specific guidance for autonomous and multi-agent AI systems built on the &lt;a href="https://www.techtarget.com/searchsecurity/tip/IT-security-frameworks-and-standards-Choosing-the-right-one"&gt;widely adopted Special Publication 800-53 framework&lt;/a&gt;.&lt;/p&gt;
 &lt;p&gt;Key control families that CISOs should prioritize include access control, audit and accountability, system and communications protection, and supply chain risk management. Mapping your OpenClaw deployment to these controls provides both a defensible security posture and a common language for communicating risk to the board.&lt;/p&gt;
 &lt;p&gt;Note that in OpenClaw deployments, traditional endpoint and network security tools see processes running and API calls being made, but they cannot interpret agent behavior or distinguish legitimate automation from compromise. Closing that visibility gap is the central challenge. The organizations that establish these guardrails now will be best positioned to harness autonomous AI safely as the ecosystem matures.&lt;/p&gt;
 &lt;p&gt;&lt;i&gt;Matthew Smith is a vCISO and management consultant specializing in cybersecurity risk management and AI.&lt;/i&gt;&lt;/p&gt;
&lt;/section&gt;</body>
            <description>OpenClaw introduces huge risks to enterprises, but employee adoption might be inevitable -- whether CISOs sanction it or not. Here's how to enable safer deployments.</description>
            <image>https://cdn.ttgtmedia.com/visuals/LeMagIT/hero_article/Hero-Danger-by-InfiniteFlow-Adobe-10.jpg</image>
            <link>https://www.techtarget.com/cybersecurity/tip/OpenClaw-security-best-practices-for-CISOs</link>
            <pubDate>Wed, 22 Jul 2026 16:11:00 GMT</pubDate>
            <title>OpenClaw security best practices for CISOs</title>
        </item>
        <item>
            <body>&lt;p&gt;As Anthropic's Mythos model makes clear, AI is a cybersecurity game changer. When released in preview, Mythos proved unexpectedly effective in finding and exploiting bugs in software. Anthropic said the preview release found more than 10,000 critical vulnerabilities across every OS and application it encountered. In addition to exposing the bugs, Mythos was able to execute an attack chain around each one, including the full attack lifecycle: reconnaissance, exploit and lateral movement.&lt;/p&gt; 
&lt;p&gt;Mythos isn't alone. Other AIs have been shown to operate autonomously to generate attacks. The &lt;a href="https://www.techtarget.com/searchsecurity/news/366645613/First-fully-agentic-ransomware-attack-sparks-readiness-concerns"&gt;Jadepuffer&lt;/a&gt;&amp;nbsp;attack discovered in early July 2026, for example, executed a complete ransomware and extortion operation driven end-to-end by an LLM -- no human required.&lt;/p&gt; 
&lt;section class="section main-article-chapter" data-menu-title="AI-enabled attacks"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;AI-enabled attacks&lt;/h2&gt;
 &lt;p&gt;It's clear that AI poses an unprecedented threat to cybersecurity. But it's important to note that AI-enabled attacks aren't a separate category of attack; they're classical attacks at unprecedented speed, scale and mutability. They include all the standard types of cyberattacks, such as the following:&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;&lt;b&gt;Voice impersonation&lt;a href="https://www.techtarget.com/searchsecurity/tip/Real-world-AI-voice-cloning-attack-A-red-teaming-case-study"&gt;&lt;/a&gt;.&lt;/b&gt; &lt;a href="https://www.techtarget.com/searchsecurity/tip/Real-world-AI-voice-cloning-attack-A-red-teaming-case-study"&gt;AI mimics a trusted party's voice&lt;/a&gt;, convincing listeners to make wire transfers or approve other financial transactions.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Automated phishing&lt;a href="https://www.techtarget.com/searchsecurity/tip/Generative-AI-is-making-phishing-attacks-more-dangerous"&gt;&lt;/a&gt;.&lt;/b&gt; &lt;a href="https://www.techtarget.com/searchsecurity/tip/Generative-AI-is-making-phishing-attacks-more-dangerous"&gt;AI generates highly realistic and personalized phishing emails&lt;/a&gt; in seconds, increasing the likelihood that targets will click malicious links.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Intelligent vulnerability scanning.&lt;a href="https://www.techtarget.com/searchsecurity/tip/Top-vulnerability-scanning-tools-for-security-teams"&gt;&lt;/a&gt;&lt;/b&gt; AI identifies software vulnerabilities and creates exploits on the fly.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Chatbot scams.&lt;/b&gt; &lt;a href="https://www.techtarget.com/searchsecurity/feature/Why-conversational-AI-is-redefining-your-security-perimeter"&gt;AI agents engage victims in casual conversations&lt;/a&gt; to extract sensitive personal details, login credentials or other confidential information.&lt;/li&gt; 
 &lt;/ul&gt;
 &lt;p&gt;Like biological viruses, AI-enabled attacks mutate, and do so at warp speed. This makes response even more difficult, since human defenders respond at human speed. For this reason, AI-enabled attacks have become a priority for CISOs. A recent &lt;a target="_blank" href="https://industrialcyber.co/ai/darktrace-2025-report-ai-threats-surge-but-cyber-resilience-grows-amidst-skills-gap/))" rel="noopener"&gt;survey&lt;/a&gt; by Darktrace found that 78% of CISOs now say AI-powered cyberattacks are having a significant impact on their organizations.&lt;/p&gt;
 &lt;p&gt;These attacks aren't hypothetical. Real-world incidents such as the following occur regularly:&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;&lt;b&gt;AI-driven phishing.&lt;/b&gt; Microsoft threat teams &lt;a href="https://www.microsoft.com/en-us/security/blog/2026/03/06/ai-as-tradecraft-how-threat-actors-operationalize-ai/" target="_blank" rel="noopener"&gt;flagged&lt;/a&gt; phishing attacks in which AI crafts phishing lures that more easily evade detection by seeming more human. These attacks include realistic personalization and imitation of human grammar and speech.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Deepfake social media scams.&lt;/b&gt; Much of social media is now AI-generated, including propaganda intended to inflame passions, spread lies or solicit money.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;AI-enabled malicious insiders. &lt;/b&gt;&lt;a href="https://www.techtarget.com/searchsecurity/feature/How-AI-caught-a-malicious-North-Korean-insider-at-Exabeam"&gt;North Korean operatives use AI to illegally land jobs&lt;/a&gt; with U.S. companies, putting enterprise data security at significant risk.&lt;/li&gt; 
 &lt;/ul&gt;
&lt;/section&gt;      
&lt;section class="section main-article-chapter" data-menu-title="Behavioral biometrics"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Behavioral biometrics&lt;/h2&gt;
 &lt;p&gt;CISOs and their teams could stymie many AI-driven attacks if they could determine whether an attacker is an AI agent or a human -- an enterprise version of the &lt;a href="https://www.techtarget.com/searchenterpriseai/definition/Turing-test"&gt;Turing Test&lt;/a&gt;. That's the focus of the burgeoning field of behavioral biometrics. Behavioral biometrics analyze user activity to distinguish humans from AI agents. These technologies work passively in the background, continuously monitoring behavioral parameters during the course of a user session and learning as baseline norms evolve.&lt;/p&gt;
 &lt;p&gt;Unlike elementary humanity tests such as CAPTCHA, which confirm human identity only at the start of a session, behavioral biometrics can detect whether an entity that previously passed as human is failing to behave as expected, thus indicating a possible session hijack or a sophisticated AI agent.&lt;/p&gt;
 &lt;p&gt;Another noteworthy component of behavioral biometric technologies is that they aren't static. Physical biometrics such as fingerprints or retinal prints are unique to a specific human being and consistent across the life of that human being. Behavioral biometrics, in contrast, look at the patterns of interaction humans have with technology. These are learned habits that can vary over time and apply to more than a single person.&lt;/p&gt;
&lt;/section&gt;    
&lt;section class="section main-article-chapter" data-menu-title="Behavior biometrics parameters"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Behavior biometrics parameters&lt;/h2&gt;
 &lt;p&gt;Most behavioral biometric systems look at multiple parameters. These include but are not limited to:&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;&lt;b&gt;Typing patterns.&lt;/b&gt; Includes typing speed, typing rhythm, keystroke pressure, dwell time on each key and flight time between keystrokes. Humans are naturally erratic while AI agents are unnaturally precise.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Mouse movement patterns. &lt;/b&gt;Includes speed, acceleration and cursor positioning. Again, human users naturally hesitate and correct mouse movements, while AI agents perform with machine precision.&amp;nbsp;&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Touchscreen gestures. &lt;/b&gt;Show how users swipe, scroll and tap on mobile devices. These movements can demonstrate unique interaction styles specific to individuals. Similarly, behavioral biometric systems can track how users hold and orient their mobile devices while using them. By capturing accelerometer and gyroscope data, these systems can distinguish between human and synthetic device movements.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Navigation analysis.&lt;/b&gt; Tracks how users move through applications and websites and complete various tasks, including page visit duration, task sequencing and form completion.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Gesture and movement analysis.&lt;/b&gt; Tracks how users adjust posture and movement while working. This can include hand positioning, head movement and eye tracking. Gesture recognition analyzes intentional hand and finger movements users make during video interactions.&lt;/li&gt; 
 &lt;/ul&gt;
 &lt;p&gt;These parameters can be combined with a virtually infinite array of other parameters to confirm that a given user is, in fact, human and that they are the particular authorized human. Other parameters might include geographic location, IP address and device type. For instance, an alert would trigger if an employee in New York who has never logged in on a mobile device suddenly shows up on a phone in Los Angeles.&lt;/p&gt;
&lt;/section&gt;    
&lt;section class="section main-article-chapter" data-menu-title="How behavioral biometric systems work"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;How behavioral biometric systems work&lt;/h2&gt;
 &lt;p&gt;The beauty of behavioral biometric systems is that they work in the background, without interfering with the user experience. The systems automatically capture device information such as keystroke timing, mouse coordinates, touchscreen pressure and device position. A centralized system then analyzes the collected data to build comprehensive behavioral profiles in the aggregate and for individual users, identifies patterns, establishes baselines and calculates normal behavior ranges. Constantly comparing user behavior against established profiles, the system then flags deviations from established patterns and triggers responses ranging from contacting the user to blocking the session.&lt;/p&gt;
&lt;/section&gt;  
&lt;section class="section main-article-chapter" data-menu-title="What's next for security teams?"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;What's next for security teams?&lt;/h2&gt;
 &lt;p&gt;The early use of behavioral biometrics shows promising results. In the financial sector, Mastercard's 2025 payment fraud prevention &lt;a target="_blank" href="https://www.mastercard.com/global/en/news-and-trends/Insights/2026/ai-is-helping-banks-save-millions-by-transforming-payment-fraud-prevention.html" rel="noopener"&gt;research&lt;/a&gt; found that 42% of issuers saved more than $5 million in fraud attempts over two years using behavioral biometrics.&lt;/p&gt;
 &lt;p&gt;In e-commerce and online retail, organizations already use behavioral biometrics to identify bot attacks, credential stuffing and account sharing, as well as to prevent inventory hoarding, coupon abuse and payment fraud. Manufacturing companies and other organizations with high-value intellectual property use behavioral biometrics to protect facilities and detect and protect against AI-enabled insider threats.&lt;/p&gt;
 &lt;p&gt;What can CISOs do to implement behavioral biometrics to protect against AI-enabled attacks in their own organizations? Here are four recommendations:&lt;/p&gt;
 &lt;ol class="default-list"&gt; 
  &lt;li&gt;Select specific use cases with clear quantitative metrics and goals.&lt;/li&gt; 
  &lt;li&gt;Select a set of parameters to implement initially, with others to come later.&lt;/li&gt; 
  &lt;li&gt;Assess wisely, looking for systems that focus on your particular use case and integrate with your existing and future systems. You can minimize human effort by integrating into existing dashboards and automated systems.&lt;/li&gt; 
  &lt;li&gt;Continuously monitor and tweak behavioral biometrics tools to optimize results, remembering that these aren't set-it-and-forget-it technologies.&lt;/li&gt; 
 &lt;/ol&gt;
 &lt;p&gt;&lt;i&gt;Johna Till Johnson is CEO and founder of Nemertes Research, where she sets research direction and works with strategic clients.&lt;/i&gt;&lt;/p&gt;
&lt;/section&gt;</body>
            <description>How do security teams distinguish between people and AI? It's getting harder, but behavioral biometrics might help discern human users from machine impersonators.</description>
            <image>https://cdn.ttgtmedia.com/rms/onlineimages/security_a416431135.jpg</image>
            <link>https://www.techtarget.com/cybersecurity/tip/Behavioral-biometrics-How-to-detect-nonhuman-threat-actors</link>
            <pubDate>Tue, 21 Jul 2026 09:00:00 GMT</pubDate>
            <title>Behavioral biometrics: How to detect nonhuman threat actors</title>
        </item>
        <item>
            <body>&lt;p&gt;Despite cybersecurity professionals' best efforts to protect their organizations' networks and data, employees have long been the weak link in the chain. They click malicious links in emails, reuse weak passwords, share sensitive information and make other mistakes that threat actors exploit.&lt;/p&gt; 
&lt;p&gt;Then came generative AI, which promised productivity gains but created new security risks. Employees' unsanctioned use of AI tools now amplifies those risks at machine speed and scale.&lt;/p&gt; 
&lt;p&gt;Nearly half (47%) of cybersecurity professionals admit they lack full visibility into the AI tools used by their organizations' employees, according to a recent Bitdefender &lt;a target="_blank" href="https://www.bitdefender.com/en-us/business/campaign/2026-cybersecurity-assessment" rel="noopener"&gt;survey&lt;/a&gt; of 1,200 global cybersecurity professionals. The research also found a gap between what company leaders think they know about internal AI use and what frontline workers report. While 58% of IT and security managers said they have full AI visibility, just 46% of practitioners agreed. That means companies are likely underestimating the &lt;a href="https://www.techtarget.com/searchsecurity/tip/Shadow-AI-poses-new-generation-of-threats-to-enterprise-IT"&gt;security risks that unsanctioned AI poses&lt;/a&gt;.&lt;/p&gt; 
&lt;p&gt;"This isn't a technology problem alone; it's also a governance vacuum," said the Bitdefender report. "Shadow AI may appear to be the new shadow IT, but it's harder to detect, and the potential for data leakage is orders of magnitude greater."&lt;/p&gt; 
&lt;section class="section main-article-chapter" data-menu-title="Shadow AI strategies for CISOs"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Shadow AI strategies for CISOs&lt;/h2&gt;
 &lt;p&gt;A blanket AI ban can make a bad problem worse, according to Chase Cunningham, a zero-trust security expert, strategic advisor to several cybersecurity providers and chief strategy officer for software demonstration platform Demo-Force.&lt;/p&gt;
 &lt;p&gt;"A policy that simply says, 'Do not use generative AI,' is not a strategy," he said. "It frequently pushes usage further underground, where security teams have even less visibility."&lt;/p&gt;
 &lt;p&gt;Rather than restricting AI use, Cunningham argues that security leaders should first focus on understanding how employees use the technology. If they determine which shadow AI tools employees are using -- and why -- they can create &lt;a href="https://www.techtarget.com/searchenterpriseai/tip/Strategic-approaches-to-effective-shadow-AI-governance"&gt;governance policies&lt;/a&gt; that encourage workers to adopt AI responsibly rather than hide how they use it.&lt;/p&gt;
 &lt;blockquote class="main-article-pullquote"&gt;
  &lt;div class="main-article-pullquote-inner"&gt;
   &lt;figure&gt;
    A policy that simply says, 'Do not use generative AI,' is not a strategy. It frequently pushes usage further underground, where security teams have even less visibility. 
   &lt;/figure&gt;
   &lt;figcaption&gt;
    &lt;strong&gt;Chase Cunningham&lt;/strong&gt;Chief strategy officer, Demo-Force
   &lt;/figcaption&gt;
   &lt;i class="icon" data-icon="z"&gt;&lt;/i&gt;
  &lt;/div&gt;
 &lt;/blockquote&gt;
 &lt;p&gt;"Organizations can't govern what they can't see," Cunningham added.&lt;/p&gt;
 &lt;p&gt;Internal corporate messaging often encourages users to &lt;a href="https://www.techtarget.com/searchenterpriseai/feature/10-AI-business-use-cases-that-produce-measurable-ROI"&gt;adopt AI for business efficiency&lt;/a&gt;. But enterprises must also communicate &lt;a href="https://www.techtarget.com/searchsecurity/tip/ChatGPT-security-risks-in-the-enterprise"&gt;AI risks&lt;/a&gt;, from data leakage to model hallucinations, in ways that resonate with nontechnical employees, said Erich Kron, CISO advisor at security awareness training provider KnowBe4.&lt;/p&gt;
 &lt;p&gt;"From compiling reports to writing or rewriting code, employees are aware of how AI can help them be more efficient, something critical in this modern day of doing more with less," Kron said. "Unfortunately, people do not hear about the problems that AI can cause."&lt;/p&gt;
 &lt;p&gt;Awareness by itself won't solve the problem of shadow AI, according to analysts. As the Bitdefender survey results suggest, organizations also need better visibility into how workers use AI tools across the business.&lt;/p&gt;
 &lt;p&gt;"What will characterize the ones that successfully manage such risk will be ... an up-to-date inventory of which generative AI services are sanctioned and which ones aren't," said Rik Turner, an analyst at Omdia, a division of Informa TechTarget.&lt;/p&gt;
 &lt;p&gt;AI visibility and governance are key, Cunningham agreed.&lt;/p&gt;
 &lt;p&gt;"Don't try to stop employees from using AI," he reiterated. "Stop them from using AI invisibly, indiscriminately and with more access than the task requires."&lt;/p&gt;
 &lt;p&gt;&lt;i&gt;Craig Galbraith is the founder and owner of Galbraith Multimedia, an independent journalism company that provides writing, editing, video hosting, podcasting, onstage presentation and consulting services to the technology industry.&lt;/i&gt;&lt;/p&gt;
 &lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;/section&gt;</body>
            <description>Employee behavior has always presented one of the biggest enterprise cybersecurity challenges. Add AI into the equation, and education and governance become even more critical.</description>
            <image>https://cdn.ttgtmedia.com/visuals/LeMagIT/hero_article/Cybersecurity_search_AdobeStock_1884692525-hero.jpg</image>
            <link>https://www.techtarget.com/cybersecurity/news/366646095/Employees-shadow-AI-use-is-poorly-monitored-survey-finds</link>
            <pubDate>Mon, 20 Jul 2026 22:30:00 GMT</pubDate>
            <title>Employees' shadow AI use is poorly monitored, survey finds</title>
        </item>
        <item>
            <body>&lt;p&gt;The tech industry is cautiously optimistic about the U.S. government's announcement this week to create a centralized clearinghouse for AI-discovered vulnerabilities. The key, executives and analysts said, will be how well the new initiative executes on its mission to collect and sort information on security flaws.&lt;/p&gt; 
&lt;p&gt;If the new Gold Eagle project simply produces huge quantities of unvalidated vulnerability reports, then a big problem only becomes worse, observers worry.&lt;/p&gt; 
&lt;p&gt;Unveiled Tuesday by the Trump administration, Gold Eagle is an effort to confront the growing challenge of software vulnerabilities being exposed by advanced LLMs. The volume of AI-found flaws is overwhelming human developers and security professionals. This creates a new and unpleasant reality for maintainers of code and the IT admins handling &lt;a href="https://www.techtarget.com/searchenterprisedesktop/definition/patch-management"&gt;patch management&lt;/a&gt; and day-to-day security updates.&lt;/p&gt; 
&lt;section class="section main-article-chapter" data-menu-title="Too many flaws, too few fixes"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Too many flaws, too few fixes&lt;/h2&gt;
 &lt;p&gt;Testing done with Anthropic's Mythos LLM, for example, reportedly uncovered 10,000 significant vulnerabilities in just &lt;a href="https://www.techtarget.com/searchsecurity/news/366643606/First-month-of-Mythos-Preview-testing-exposes-10K-flaws"&gt;one month of screening work under Project Glasswing&lt;/a&gt;, a cross-industry coalition of companies granted early access to Mythos. Some of the vulnerabilities, Anthropic said, had gone unnoticed for decades.&lt;/p&gt;
 &lt;p&gt;Recent tests found gaps even in &lt;a href="https://apnews.com/article/anthropic-mythos-ai-classified-systems-vulnerabilities-testing-3e8762c0527c4d8ed657cbe48c84a718"&gt;highly guarded, classified U.S. government systems&lt;/a&gt;.&lt;/p&gt;
 &lt;p&gt;On a parallel track, &lt;a href="https://www.techtarget.com/searchsecurity/news/366643546/For-CISOs-dawn-of-OpenAI-Daybreak-brings-good-and-bad-news"&gt;OpenAI's Daybreak initiative&lt;/a&gt; aims to make vulnerability verification and remediation more efficient by uniting GPT models and the Codex Security system.&lt;/p&gt;
 &lt;p&gt;The government's Gold Eagle initiative is important recognition that frontier LLMs are forcing organizations to rethink how they remediate software, said Aaron Mitchell, CEO at HeroDevs, a company that helps companies secure their source software.&lt;/p&gt;
 &lt;p&gt;"Gone are the days of fixing vulnerabilities as they come in," Mitchell said. "Security and engineering teams can't keep up with the volume of findings or the amount of change required to continuously upgrade software."&lt;/p&gt;
 &lt;p&gt;AI's astonishing ability to find security weaknesses in code presents a monumental challenge -- even to organizations that adhere to &lt;a href="https://www.techtarget.com/searchsecurity/definition/cyber-hygiene"&gt;cyber hygiene&lt;/a&gt; best practices and are diligent about &lt;a href="https://www.techtarget.com/searchsecurity/tip/Types-of-vulnerability-scanning-and-when-to-use-each"&gt;vulnerability scanning efforts&lt;/a&gt;. The scale of the problem and potential for widespread harm to IT systems has gotten Washington's attention, with the Trump administration &lt;a href="https://www.cybersecuritydive.com/news/cisa-ai-trump-executive-order-implementation/822001/"&gt;issuing an executive order&lt;/a&gt; in June calling for action on the AI front.&lt;/p&gt;
&lt;/section&gt;       
&lt;section class="section main-article-chapter" data-menu-title="The prioritization problem"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;The prioritization problem&lt;/h2&gt;
 &lt;p&gt;Gold Eagle is a step in the right direction, said Tyler Fordham, director of offensive security at Dark Wolf, a DevSecOps services company, but he sees potential problems with a government-run, AI-driven clearinghouse. If it simply dumps raw, automated alerts on IT teams, it will lead to patch fatigue and confusion about which vulnerabilities to prioritize, he said. Plus, a vast centralized database presents an inviting target for state-sponsored threat actors.&lt;/p&gt;
 &lt;p&gt;"For Gold Eagle to succeed, it has to be built as a secure resource that supports and funds defenders, not just another federal compliance initiative telling people what to fix," Fordham said.&lt;/p&gt;
 &lt;p&gt;A centralized queue of endless technical information won't do much to solve problems, said Joshua Copeland, cybersecurity director at Crescendo, which makes AI-based customer-experience tools.&lt;/p&gt;
 &lt;p&gt;"Gold Eagle will achieve success only if it functions as a decision and remediation engine, rather than merely serving as an advanced vulnerability collection system," said Copeland, who is also an adjunct professor at Tulane University.&lt;/p&gt;
 &lt;p&gt;Gold Eagle will need duplicate detection, minimum evidence standards and independent technical validation, Copeland said. Also on his wish list is a prioritization model that weighs active exploitation.&lt;/p&gt;
 &lt;p&gt;The lack of cooperation between the public and private sectors on vulnerability management has been a persistent complaint in the industry, said Theresa Lanowitz, a cybersecurity analyst at Omdia, a division of Informa TechTarget. In her view, a well-organized system could make a difference.&lt;/p&gt;
 &lt;p&gt;"The key to any vulnerability management program is to prioritize remediation to minimize impact," Lanowitz said. "And, once a vulnerability is fixed, it is important to make sure that downstream integrations do not break anything else."&lt;/p&gt;
 &lt;p&gt;Lanowitz said she is encouraged by Gold Eagle's focus on open source software (OSS), some of which continues to be used even after it reaches end-of-life status. "The software will continue to work, but there are no bug fixes, new features or security updates," Lanowitz said. "Unmaintained OSS presents opportunities for adversaries."&lt;/p&gt;
 &lt;p&gt;&lt;i&gt;Phil Sweeney is an industry editor and writer focused on cybersecurity topics.&lt;/i&gt;&lt;/p&gt;
 &lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;/section&gt;</body>
            <description>As AI-discovered software vulnerabilities accumulate at an unprecedented pace, security pros say they hope Gold Eagle creates some order from the chaos.</description>
            <image>https://cdn.ttgtmedia.com/rms/onlineimages/security_a296619547.jpg</image>
            <link>https://www.techtarget.com/cybersecurity/news/366645907/Industry-reacts-to-Gold-Eagle-vulnerability-management-plan</link>
            <pubDate>Fri, 17 Jul 2026 13:30:00 GMT</pubDate>
            <title>Industry reacts to Gold Eagle vulnerability management plan</title>
        </item>
        <item>
            <body>&lt;p&gt;Modern software runs on open source. Nearly all codebases -- 98% -- contain open source code, according to a 2026 &lt;a target="_blank" href="https://www.blackduck.com/content/dam/black-duck/en-us/reports/rep-ossra.pdf" rel="noopener"&gt;report&lt;/a&gt; from cybersecurity vendor Black Duck, which scanned 947 codebases and analyzed nearly 3,000 individual projects between November 2024 and October 2025. Those open source components change constantly as maintainers ship patches, fixes and new versions.&lt;/p&gt; 
&lt;p&gt;A &lt;a href="https://www.techtarget.com/searchsecurity/tip/How-to-create-an-SBOM-with-example-and-template"&gt;software bill of materials (SBOM) captures a snapshot&lt;/a&gt; of that inventory, so organizations can find and patch vulnerabilities quickly. The moment a developer merges a dependency update or a build pulls a new version, the document drifts from reality. A stale SBOM gives false confidence and slows the enterprise response when a vulnerability lands.&lt;/p&gt; 
&lt;p&gt;Regulation raises the stakes. Under the EU Cyber Resilience Act, beginning Sept. 11, 2026, organizations must report actively exploited vulnerabilities. By Dec. 11, 2027, manufacturers of products with digital elements must include machine-readable SBOMs in their technical documentation. Penalties for non-compliance could reach 15 million euros or 2.5% of global annual turnover. In the U.S., CISA and its partner agencies &lt;a target="_blank" href="https://www.cisa.gov/topics/information-communications-technology-supply-chain-security/sbom" rel="noopener"&gt;published&lt;/a&gt; joint SBOM guidance in September 2025 that pushes wider adoption. Unlike manual upkeep, AI tools can meet these demands at scale.&lt;/p&gt; 
&lt;h1&gt;How AI-Driven SBOM management works&lt;/h1&gt; 
&lt;p&gt;AI-driven tools treat the SBOM as a living inventory rather than a one-time artifact. They combine automation with machine learning across the following four functions.&lt;/p&gt; 
&lt;ul class="default-list"&gt; 
 &lt;li&gt;&lt;b&gt;Continuous generation. &lt;/b&gt;The tools plug into your CI/CD pipeline and regenerate the SBOM on every build, so the inventory automatically tracks each release.&lt;/li&gt; 
 &lt;li&gt;&lt;b&gt;Component identification. &lt;/b&gt;Machine learning models, including natural language processing and graph neural networks, identify and classify components and trace transitive dependencies. One multi-model system, for example, &lt;a target="_blank" href="https://www.researchgate.net/publication/399038727_AI-Driven_SBOM_Automated_Software_Bill_of_Materials_Generation_and_Management" rel="noopener"&gt;reported&lt;/a&gt; 94.7% component detection and 91.3% accuracy in vulnerability mapping.&lt;/li&gt; 
 &lt;li&gt;&lt;b&gt;Drift detection. &lt;/b&gt;AI-driven tools compare the build-time SBOM against what actually runs in production to catch unauthorized packages, supply chain tampering and configuration drift.&lt;/li&gt; 
 &lt;li&gt;&lt;b&gt;Vulnerability correlation. &lt;/b&gt;AI enriches each component with exploitability intelligence and ranks findings by reachability, rather than raw CVE counts, so the highest-risk issues surface first.&lt;/li&gt; 
&lt;/ul&gt; 
&lt;h1&gt;Benefits of using AI to maintain SBOMs&lt;/h1&gt; 
&lt;p&gt;For a CISO, the value of AI for SBOM creation and maintenance lies in accuracy, speed and audit-readiness.&lt;/p&gt; 
&lt;ul class="default-list"&gt; 
 &lt;li&gt;&lt;b&gt;Accuracy at scale. &lt;/b&gt;AI continuously updates inventory across hundreds of repositories, a task no human team can match by hand.&lt;/li&gt; 
 &lt;li&gt;&lt;b&gt;Faster incident response. &lt;/b&gt;When the next &lt;a target="_blank" href="https://www.darkreading.com/cyberattacks-data-breaches/log4j-vulnerabilities-are-here-to-stay-are-you-prepared-" rel="noopener"&gt;Log4Shell&lt;/a&gt;-class flaw appears, a current inventory answers the question "are we affected" in minutes instead of days.&lt;/li&gt; 
 &lt;li&gt;&lt;b&gt;Less noise. &lt;/b&gt;Reachability analysis filters out components that pose no real exposure risk, so analysts spend time on issues that matter.&lt;/li&gt; 
 &lt;li&gt;&lt;b&gt;Compliance readiness. &lt;/b&gt;An always-current, machine-readable SBOM satisfies auditors, customers and regulators on demand.&lt;/li&gt; 
&lt;/ul&gt; 
&lt;h1&gt;Risks and challenges&lt;/h1&gt; 
&lt;p&gt;&lt;a href="https://www.techtarget.com/searchcio/feature/AI-failure-examples-What-real-world-breakdowns-teach-CIOs"&gt;AI does not remove the need for human judgment&lt;/a&gt;. Weigh the risks before you rely on it for SBOMs or anything else. CISOs should consider the following:&lt;/p&gt; 
&lt;ul class="default-list"&gt; 
 &lt;li&gt;&lt;b&gt;False positives and negatives. &lt;/b&gt;Automated tools can flag components that are not in production or miss ones loaded dynamically at runtime. Human review still matters.&lt;/li&gt; 
 &lt;li&gt;&lt;b&gt;Model opacity. &lt;/b&gt;When a model classifies or discards a component, the reasoning can be hard to audit. Demand &lt;a href="https://www.techtarget.com/searchsecurity/tip/What-CISOs-need-to-know-about-AI-audit-logs"&gt;explainable output you can log&lt;/a&gt; and defend.&lt;/li&gt; 
 &lt;li&gt;&lt;b&gt;Data quality limits. &lt;/b&gt;An AI inventory is only as good as the sources it reads. Poor package metadata and incomplete scans produce a confident but incorrect SBOM.&lt;/li&gt; 
 &lt;li&gt;&lt;b&gt;Automation bias. &lt;/b&gt;Teams can over-trust a polished dashboard and stop verifying it. Treat AI output as a strong draft, rather than the final truth.&lt;/li&gt; 
 &lt;li&gt;&lt;b&gt;A new attack surface. &lt;/b&gt;The AI tooling and its models become part of your supply chain. Vet them as you would any other dependency, and &lt;a target="_blank" href="https://www.darkreading.com/cyber-risk/make-ai-bom-usable-modern-security-program" rel="noopener"&gt;track your own AI components&lt;/a&gt; too.&lt;/li&gt; 
&lt;/ul&gt; 
&lt;h1&gt;Best practices for CISOs&lt;/h1&gt; 
&lt;p&gt;CISOs who decide to automate SBOM management with AI should start with the following steps:&lt;/p&gt; 
&lt;ul class="default-list"&gt; 
 &lt;li&gt;Embed SBOM generation in every CI/CD pipeline so it runs on each build.&lt;/li&gt; 
 &lt;li&gt;Compare build-time and runtime SBOMs to catch drift before attackers do.&lt;/li&gt; 
 &lt;li&gt;Require explainable output and use human-in-the-loop reviews to verify high-risk findings.&lt;/li&gt; 
 &lt;li&gt;Prioritize flaws by reachability and exploitability, not raw vulnerability counts.&lt;/li&gt; 
 &lt;li&gt;Vet your SBOM AI tools, models and training data as supply chain components.&lt;/li&gt; 
 &lt;li&gt;Map your process to regulatory timelines now, ahead of deadlines.&lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;Additionally, beware of potential pitfalls.&lt;/p&gt; 
&lt;ul class="default-list"&gt; 
 &lt;li&gt;Don't treat the SBOM as a one-time document, rather than a living inventory.&lt;/li&gt; 
 &lt;li&gt;Don't trust AI output without validation and a clear audit trail.&lt;/li&gt; 
 &lt;li&gt;Don't ignore runtime drift because the build-time SBOM looks complete.&lt;/li&gt; 
 &lt;li&gt;Don't wait for regulators to force the conversation. By then, your company could be on the hook for hefty fines.&lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;A current SBOM is the foundation for &lt;a href="https://www.techtarget.com/searchsecurity/tip/4-software-supply-chain-security-best-practices"&gt;software supply chain security&lt;/a&gt;. AI keeps that inventory continuous and accurate at a scale that manual updates cannot match. By pairing AI tools with human oversight, CISOs can turn a compliance chore into a real-time view of supply-chain risk.&lt;/p&gt; 
&lt;p&gt;&lt;em&gt;Matthew Smith is a vCISO and management consultant specializing in cybersecurity risk management and AI.&lt;/em&gt;&lt;/p&gt;</body>
            <description>AI tools can drive continuous, accurate SBOM management that turns compliance documentation into real-time supply chain security. Here's what CISOs should know.</description>
            <image>https://cdn.ttgtmedia.com/visuals/German/article/malware-1-adobe.jpg</image>
            <link>https://www.techtarget.com/cybersecurity/tip/Why-CISOs-should-automate-SBOM-management-with-AI</link>
            <pubDate>Thu, 16 Jul 2026 18:17:00 GMT</pubDate>
            <title>Why CISOs should automate SBOM management with AI</title>
        </item>
        <item>
            <body>&lt;p&gt;CISOs and their teams are expected to demonstrate compliance with a range of regulations, frameworks and standards. With an alphabet soup of frameworks -- NIST, ISO, PCI DSS, HIPAA, GDPR and many other country- or sector-specific mandates -- there is a growing risk of duplicating effort, control gaps and audit fatigue.&lt;/p&gt; 
&lt;p&gt;CISOs can simplify governance by mapping security controls to the various domestic and international &lt;a href="https://www.techtarget.com/searchsecurity/tip/IT-security-frameworks-and-standards-Choosing-the-right-one"&gt;standards and regulations addressing cybersecurity&lt;/a&gt; through a unified control architecture.&lt;/p&gt; 
&lt;section class="section main-article-chapter" data-menu-title="Why control mapping matters"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Why control mapping matters&lt;/h2&gt;
 &lt;p&gt;Enterprises that are required to demonstrate regulatory compliance must prove how they comply. In addition to a variety of audit tests, a map of the controls being used and the corresponding standards is an important piece of audit evidence.&lt;/p&gt;
 &lt;p&gt;Without a control map, CISOs and their teams can face redundant efforts when connecting controls to specific requirements, a lack of consistent application of controls within the enterprise and additional work gathering evidence for an audit.&lt;/p&gt;
 &lt;p&gt;Security teams can save time and effort by building a structured map of controls and requirements, consolidating all mapping into a single assessment. This helps &lt;a href="https://www.techtarget.com/searchsecurity/tip/Build-a-strong-cyber-resilience-strategy-with-existing-tools"&gt;strengthen cyber resilience&lt;/a&gt; by establishing a holistic baseline.&lt;/p&gt;
&lt;/section&gt;    
&lt;section class="section main-article-chapter" data-menu-title="How to build a control-mapping strategy"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;How to build a control-mapping strategy&lt;/h2&gt;
 &lt;p&gt;Prior to preparing a control/standard map, define the overall strategy. This helps CISOs, auditors and regulators assess and verify compliance, minimizes duplication and enhances governance. The key is to define scope, establish a baseline control language and create a flexible and reusable mapping model. Adding AI to the process helps accelerate map preparation and assists with ongoing maintenance.&lt;/p&gt;
 &lt;p&gt;Obtain the most relevant and authoritative sources. Among the most important are:&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;&lt;b&gt;NIST CSF (Cyber Security Framework)&lt;/b&gt;. This framework provides guidance across a broad range of cybersecurity issues; implementation is voluntary.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;NIST SP 800-53&lt;/b&gt;. Designed for government use, these cybersecurity controls can be used by the private sector. Implementation is voluntary but considered essential for demonstrating compliance.&lt;/li&gt; 
 &lt;/ul&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;&lt;b&gt;ISO/IEC 27001&lt;/b&gt;. &lt;a href="https://www.techtarget.com/whatis/definition/ISO-27001"&gt;This is the global cybersecurity standard&lt;/a&gt;; compliance must be officially demonstrated.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;CIS Controls&lt;/b&gt;. Developed by the U.S. Center for Internet Security, there are 18 specific controls to address; implementation is voluntary.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;SOC 2 Security Controls&lt;/b&gt;. Developed to comply with the AICPA's Trust Services Criteria, these are auditable controls.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;HIPAA&lt;/b&gt;. The &lt;a href="https://www.techtarget.com/searchhealthit/definition/HIPAA"&gt;HIPAA&lt;/a&gt; security controls, which are mandatory in healthcare, can be applied in many industries; compliance must be officially demonstrated.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;PCI DSS&lt;/b&gt;. The &lt;a href="https://www.techtarget.com/searchsecurity/definition/PCI-DSS-Payment-Card-Industry-Data-Security-Standard"&gt;Payment Card Industry Data Security Standard&lt;/a&gt; is a mandatory requirement for organizations in the payment industry; it has six control objectives that delineate 12 specific requirements.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;FedRAMP&lt;/b&gt;. Based on NIST SP 800-53, these mandatory controls were designed for cloud service providers that handle federal data.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;CMMC&lt;/b&gt;. The Cybersecurity Maturity Model Certification was developed by the U.S. Defense Department to protect critical government data used by contractors.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;GPPR&lt;/b&gt;. The EU &lt;a href="https://www.techtarget.com/whatis/definition/General-Data-Protection-Regulation-GDPR"&gt;General Data Protection Regulation&lt;/a&gt; specifies how data generated and used by EU member nations and other nations that work with EU member states is protected from unauthorized use; compliance must be officially demonstrated.&lt;/li&gt; 
 &lt;/ul&gt;
 &lt;p&gt;Once the relevant requirements have been identified, develop a standard control language and taxonomy. Next, create a crosswalk or other approach where relevant data can be identified and used to support audits, prepare regulatory reporting and facilitate internal governance. Be sure to include information in the map that details evidence sources, e.g., origin and rationale.&lt;/p&gt;
&lt;/section&gt;      
&lt;section class="section main-article-chapter" data-menu-title="Step-by-step approach"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Step-by-step approach&lt;/h2&gt;
 &lt;p&gt;Follow these steps to establish your control mapping.&lt;/p&gt;
 &lt;ol class="default-list"&gt; 
  &lt;li&gt;&lt;b&gt;Define scope.&lt;/b&gt; Begin by identifying the standards, regulations, frameworks and internal policies to be mapped.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Build a catalog of cybersecurity controls.&lt;/b&gt; While there might be dozens of individual controls, try to group them in specific categories, such as access control and incident response.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Pick your mapping approach&lt;/b&gt;. This can include 1:1 (one control to one standard), partial mapping (one standard to many controls) or thematic mapping (grouping controls into categories, such as access control).&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Define mapping criteria&lt;/b&gt;. Set rules for how to develop mapping. Include factors such as intent, outcomes, safeguards or requirements for evidence.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Complete and document the mapping&lt;/b&gt;. Given the time it takes to complete a map, consider using internal experts dedicated to the project, external consultants or AI automation tools.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Initiate stakeholder validation&lt;/b&gt;. Invite representatives from the legal, audit, compliance and engineering groups to review the map's accuracy.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Launch the map&lt;/b&gt;. Once approved, integrate the map into governance, risk and compliance (&lt;a href="https://www.techtarget.com/searchsecurity/definition/governance-risk-management-and-compliance-GRC"&gt;GRC&lt;/a&gt;) workflows; risk assessments; reporting; and audits.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Use change control to maintain maps&lt;/b&gt;. Noting that standards and regulations periodically change, use the change-control process to keep maps up to date.&lt;/li&gt; 
 &lt;/ol&gt;
&lt;/section&gt;   
&lt;section class="section main-article-chapter" data-menu-title="Overcoming control mapping challenges"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Overcoming control mapping challenges&lt;/h2&gt;
 &lt;p&gt;When planning and developing a control map, there will be difficulties to overcome. To mitigate them, try to standardize the language and map structure to minimize confusion.&lt;/p&gt;
 &lt;p&gt;Consistency counts for standards, as well. Depending on the standard, the content might be more general and broad-based, while others could be detailed, so ensure that the language is as consistent as possible. Some standards and regulations, such as HIPAA and GDPR, describe outcomes, whereas others, such as NIST, CIS and SOC 2, provide specific controls. Be ready to update maps with the latest versions as standards, regulations and frameworks change.&lt;/p&gt;
 &lt;p&gt;In the broader organization, be aware of the impact on other functions. Internal departments, such as security, risk management, compliance and engineering, might have differing views of controls and how controls are applied.&lt;/p&gt;
 &lt;p&gt;Also be sure to check evidence requirements. Once controls have been mapped, see if there are any variances in evidence requirements.&lt;/p&gt;
&lt;/section&gt;     
&lt;section class="section main-article-chapter" data-menu-title="Tools and technologies"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Tools and technologies&lt;/h2&gt;
 &lt;p&gt;Automated tools can assist with control map development. To streamline the development and maintenance processes, consider tools with AI capabilities.&lt;/p&gt;
 &lt;p&gt;Some available products include:&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;Archer Evolv, a control and regulatory mapping engine.&lt;/li&gt; 
  &lt;li&gt;CIS Controls Mapping, an Excel-based control mapping crosswalk to NIST, PCI DSS, ISO, HIPAA and SOC 2.&lt;/li&gt; 
  &lt;li&gt;Drata, an AI-based control mapping and monitoring tool.&lt;/li&gt; 
  &lt;li&gt;Hyperproof, an AI-based control mapping tool.&lt;/li&gt; 
  &lt;li&gt;LogicGate Risk Cloud, a tool to develop maps using workflows and mapping templates.&lt;/li&gt; 
  &lt;li&gt;NIST OSCAL (Open Security Controls Assessment Language), a set of NIST-developed hierarchical, formatted, XML- JSON- and YAML-based formats used for development and assessment of security controls.&lt;/li&gt; 
  &lt;li&gt;OneTrust, a tool that supports security map development using GDPR, DORA, ISO, NIST, HIPAA and others.&lt;/li&gt; 
  &lt;li&gt;Secureframe, an automated control mapping tool for SOC 2, ISO, HIPAA and other standards.&lt;/li&gt; 
  &lt;li&gt;ServiceNow GRC, a tool that includes crosswalk templates and evidence-collection features.&lt;/li&gt; 
  &lt;li&gt;Tugboat Logic, which is part of OneTrust, offering crosswalks for standards such as SOC 2, ISO and HIPAA.&lt;/li&gt; 
 &lt;/ul&gt;
 &lt;p&gt;&lt;i&gt;Editor's note: The author chose to highlight these tools based on independent research, prioritizing anecdotally prominent and well-established offerings with significant user bases. This list is organized alphabetically.&lt;/i&gt;&lt;/p&gt;
&lt;/section&gt;     
&lt;section class="section main-article-chapter" data-menu-title="Pros and cons of mapping with automation and AI"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Pros and cons of mapping with automation and AI&lt;/h2&gt;
 &lt;p&gt;Control mapping benefits from automation, and, more specifically, AI-assisted automation. Tasks required for mapping can be streamlined and completed more quickly with AI than through manual approaches and existing mapping applications.&lt;/p&gt;
 &lt;p&gt;Among the advantages are faster control and standard matching. AI algorithms can analyze control intent across standards and frameworks. Automation also enables a team to use consistent language across different standards. AI can monitor attributes continuously and alerts when standards and regulations are updated.&lt;/p&gt;
 &lt;p&gt;Other benefits of automated mapping include streamlined map creation; rapid collection of relevant evidence from various sources and event-ticketing systems; streamlined workflows for the control-testing process; real-time version control for control maps and internal controls; and collection of relevant evidence for audit preparation and reporting.&lt;/p&gt;
 &lt;p&gt;If using automation, note that while AI can gather relevant regulatory and standards documents, it cannot interpret the standard's intent without human review. Also, AI-generated maps could contain errors that would affect compliance. It's up to people to confirm the work produced is accurate and understandable to auditors and regulators.&lt;/p&gt;
 &lt;p&gt;&lt;i&gt;Paul Kirvan, FBCI, CISA, is an independent consultant and technical writer with more than 35 years of experience in business continuity, disaster recovery, resilience, cybersecurity, GRC, telecom and technical writing.&lt;/i&gt;&lt;/p&gt;
&lt;/section&gt;</body>
            <description>Being able to map cybersecurity controls to applicable standards and regulations can make compliance work less complicated – especially when automation and AI come into play.</description>
            <image>https://cdn.ttgtmedia.com/rms/onlineimages/folder-files13.jpg</image>
            <link>https://www.techtarget.com/cybersecurity/tip/How-mapping-security-controls-can-ease-the-compliance-burden</link>
            <pubDate>Thu, 16 Jul 2026 16:47:00 GMT</pubDate>
            <title>How mapping security controls can ease the compliance burden</title>
        </item>
        <item>
            <body>&lt;p&gt;IoT is meant to drive operational efficiency and improve decision-making, largely by automating processes and reducing overall costs. But with these benefits come escalating cybersecurity &lt;a href="https://www.techtarget.com/iotagenda/tip/5-IoT-security-threats-to-prioritize"&gt;threats that target IoT devices&lt;/a&gt;, which are notoriously vulnerable compared to traditional IT infrastructure.&lt;/p&gt; 
&lt;p&gt;Several security frameworks address IoT, including the &lt;a target="_blank" href="https://www.techtarget.com/searchsecurity/definition/NIST-Cybersecurity-Framework" rel="noopener"&gt;NIST Cybersecurity Framework&lt;/a&gt; and &lt;a target="_blank" href="https://www.isa.org/standards-and-publications/isa-standards/isa-iec-62443-series-of-standards" rel="noopener"&gt;IEC 62443&lt;/a&gt; for industrial systems. That said, one approach -- &lt;a href="https://www.techtarget.com/searchsecurity/tip/Perimeter-to-posture-A-roadmap-to-zero-trust-maturity"&gt;zero trust&lt;/a&gt; -- has bubbled to the top as the most practical way to secure IoT. Zero trust's emphasis on continuous verification, continuous validation, microsegmentation and network-based behavioral analytics helps enterprises address visibility and enforcement gaps common when working with low-cost IoT devices.&lt;/p&gt; 
&lt;section class="section main-article-chapter" data-menu-title="Common IoT security challenges"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Common IoT security challenges&lt;/h2&gt;
 &lt;p&gt;The rapid expansion of IoT devices and other connected components has dramatically increased the attack surface for enterprise organizations. IoT systems often offer poor visibility, have limited built-in security capabilities and lack support for endpoint protection software, hobbling IT security teams. As a result, unpatched devices with weak credentials are common.&lt;/p&gt;
 &lt;p&gt;Their inherent security flaws make IoT devices ripe targets for malicious hackers, who exploit them to scan the network and compromise other systems, creating a serious risk to mission-critical components and data. &lt;a href="https://www.techtarget.com/searchsecurity/tip/How-to-manage-third-party-risk-in-the-supply-chain"&gt;Supply-chain risks&lt;/a&gt; only compound the issue. Pre-compromised IoT devices can introduce massive threats at scale, leading to botnets and persistent backdoors that make threat remediation incredibly difficult.&lt;/p&gt;
 &lt;blockquote class="main-article-pullquote"&gt;
  &lt;div class="main-article-pullquote-inner"&gt;
   &lt;figure&gt;
    Their inherent security flaws make IoT devices ripe targets for malicious hackers, who exploit them to scan the network and compromise other systems. 
   &lt;/figure&gt;
   &lt;i class="icon" data-icon="z"&gt;&lt;/i&gt;
  &lt;/div&gt;
 &lt;/blockquote&gt;
 &lt;p&gt;Enterprises that don't properly address these vulnerabilities face the constant risk of ransomware attacks, operational disruptions, and compliance and regulatory issues. The financial and reputational consequences could be catastrophic.&lt;/p&gt;
&lt;/section&gt;     
&lt;section class="section main-article-chapter" data-menu-title="How zero trust addresses IoT security"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;How zero trust addresses IoT security&lt;/h2&gt;
 &lt;p&gt;Zero trust principles use a "never trust, always verify" philosophy, eliminating the implicit trust often found in organizations that traditionally rely on perimeter-based security. Zero trust shifts enforcement to the network, focusing on device verification and continuous validation of every request&lt;a href="https://www.techtarget.com/searchsecurity/definition/principle-of-least-privilege-POLP"&gt;. Least-privilege policies&lt;/a&gt; -- i.e., &lt;a href="https://www.techtarget.com/searchnetworking/definition/microsegmentation"&gt;microsegmentation&lt;/a&gt; -- also sharply restrict device communications. That means a compromised IoT device cannot scan and infect other devices on the network, reducing the risk that a threat actor will disrupt operations or steal data from mission-critical systems.&lt;/p&gt;
 &lt;p&gt;Zero trust also solves the scalability issue of IoT security. Policies are applied, enforced and continuously validated at the network level rather than on the devices themselves. This method lets organizations centralize management and automate enforcement across thousands of endpoints regardless of device type, OS or firmware limitations.&lt;/p&gt;
&lt;/section&gt;   
&lt;section class="section main-article-chapter" data-menu-title="Challenges of applying zero trust to IoT"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Challenges of applying zero trust to IoT&lt;/h2&gt;
 &lt;p&gt;While zero trust offers clear advantages over other methodologies, implementing it in IoT environments poses certain challenges. IoT networks contain many legacy and resource-constrained devices, making it difficult or even impossible to apply modern, network-based identity methods such as &lt;a href="https://www.techtarget.com/searchsecurity/definition/mutual-authentication"&gt;mutual authentication&lt;/a&gt;, device attestation or public key infrastructure enrollment. Network-level enforcement might also introduce latency, hindering the real-time capabilities of some IoT devices and platforms.&lt;/p&gt;
 &lt;p&gt;While zero-trust policy management is centralized, creating highly granular policies across thousands of IoT devices can grow increasingly complex. Interoperability issues can also arise for IoT endpoints that use non-standard or &lt;a href="https://www.techtarget.com/iotagenda/tip/Top-12-most-commonly-used-IoT-protocols-and-standards"&gt;proprietary protocols&lt;/a&gt;. Without proper processes to onboard devices within a zero-trust model, security policies can quickly become muddled, potentially leading to inconsistent enforcement and security gaps.&lt;/p&gt;
 &lt;p&gt;Finally, &lt;a href="https://www.techtarget.com/searchsecurity/feature/How-to-implement-zero-trust-security-from-people-who-did-it"&gt;shifting to a zero-trust methodology&lt;/a&gt; requires new skills and tools, as well as organizational cultural shifts that, without proper management, can slow adoption and affect day-to-day operations.&lt;/p&gt;
&lt;/section&gt;    
&lt;section class="section main-article-chapter" data-menu-title="Best practices for implementing zero trust for IoT"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Best practices for implementing zero trust for IoT&lt;/h2&gt;
 &lt;p&gt;Ideally, a zero-trust implementation follows a phased approach that addresses the operational constraints outlined above. CISOs should consider the following best practices:&lt;/p&gt;
 &lt;ul type="disc" class="default-list"&gt; 
  &lt;li&gt;&lt;b&gt;IoT device discovery and inventory&lt;/b&gt;. Identify and classify all existing IoT devices and platforms, along with their risk levels, functions, protocols and communication patterns.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Define protection boundaries&lt;/b&gt;. Specify which external resources IoT groups need to communicate with. Use this information to formulate protection boundary policies.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Apply microsegmentation. &lt;/b&gt;Based on IoT discovery and protection boundaries, create policies that enforce strict least-privilege access.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Develop context-aware policies&lt;/b&gt;. For IoT devices that require agentless enforcement, combine identity-based methods with &lt;a href="https://www.techtarget.com/searchsecurity/definition/user-behavior-analytics-UBA"&gt;behavioral analytics&lt;/a&gt;.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Measure and adjust&lt;/b&gt;. Use tools to monitor and track metrics, including IoT device visibility, policy-enforcement rate and lateral-movement reduction. Make policy adjustments accordingly to further restrict communication flows without disrupting operations.&lt;/li&gt; 
 &lt;/ul&gt;
 &lt;p&gt;With proper collaboration across IT, security and operational technology teams and the right planning in place, zero trust can serve as the security foundation that enables IoT expansion for years to come.&lt;/p&gt;
 &lt;p&gt;&lt;em&gt;Andrew Froehlich is founder of InfraMomentum, an enterprise IT research and analyst firm, and president of West Gate Networks, an IT consulting company. He has been involved in enterprise IT for more than 20 years.&lt;/em&gt;&lt;/p&gt;
 &lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;/section&gt;</body>
            <description>IoT devices have significant business benefits but also open enterprises to escalating security risks. Discover why zero trust is the most practical way to secure IoT.</description>
            <image>https://cdn.ttgtmedia.com/visuals/LeMagIT/hero_article/AI-IoT-hero.png</image>
            <link>https://www.techtarget.com/cybersecurity/tip/Why-CISOs-should-use-zero-trust-security-for-IoT</link>
            <pubDate>Wed, 15 Jul 2026 18:37:00 GMT</pubDate>
            <title>Why CISOs should use zero-trust security for IoT</title>
        </item>
        <item>
            <body>&lt;p&gt;Enterprise AI deployments are scaling faster than any software category in history, now commanding 6% of the $300 SaaS market, according to venture capital firm Menlo Ventures. Meanwhile, McKinsey &amp;amp; Company has reported that 88% of businesses have applied AI to at least one task.&lt;/p&gt; 
&lt;p&gt;In their rush to deploy transformational AI or risk falling behind competitors, many enterprises are overlooking critical security vulnerabilities. The race to production is outpacing the due diligence required to ensure secure and resilient environments -- and adversaries are already exploiting the gap.&lt;/p&gt; 
&lt;section class="section main-article-chapter" data-menu-title="AI breaches are different"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;AI breaches are different&lt;/h2&gt;
 &lt;p&gt;The introduction of AI into enterprise production environments creates an entirely different and potentially more expansive &lt;a href="https://www.techtarget.com/searchsecurity/tip/What-is-attack-surface-management-and-why-is-it-necessary"&gt;attack surface&lt;/a&gt;. This fact is not lost on adversaries, who have been quick to capitalize on exposed AI infrastructure.&lt;/p&gt;
 &lt;p&gt;AI-driven applications differ from traditional software in numerous ways, starting with how they handle user input. In conventional applications, user input security controls run on predictability -- identical input equals identical output. Large language model (LLM) outputs, however, can change based on factors ranging from temperature, settings and context length to model updates and tool availability. This makes it challenging to verify when vulnerabilities are patched.&lt;/p&gt;
 &lt;p&gt;Another significant difference with LLMs is that adversaries don't have to exploit &lt;a href="https://www.techtarget.com/searchsecurity/opinion/Top-vulnerability-management-challenges-for-organizations"&gt;software vulnerabilities&lt;/a&gt;. Instead, threat actors can work in a manner resembling social engineering, manipulating an ambiguity or shifting context to penetrate the model. Plus, attackers don't have to take over infrastructure to exfiltrate sensitive information. They can manipulate an AI model to trigger malicious actions. Threat actors can also &lt;a href="https://www.techtarget.com/searchsecurity/tip/How-data-poisoning-attacks-work"&gt;poison outputs&lt;/a&gt; by manipulating the data pipeline.&lt;/p&gt;
 &lt;p&gt;By its nature, AI is susceptible to tactics such as prompt injections and instruction hacking that adversaries use to trick the engine into ignoring rules and following nefarious instructions. Data exfiltration using &lt;a href="https://www.techtarget.com/searchenterpriseai/tip/RAG-best-practices-for-enterprise-AI-teams"&gt;retrieval-augmented generation&lt;/a&gt; (RAG) and connectors is another common attack method in which threat actors bypass access controls during retrieval. Bad actors also use AI to launch machine-speed attacks that can identify and exploit &lt;a href="https://www.techtarget.com/searcherp/feature/5-supply-chain-cybersecurity-risks-and-best-practices"&gt;supply chain&lt;/a&gt; vulnerabilities.&lt;/p&gt;
 &lt;p&gt;Adversaries can use language to bypass policies and controls maintained by conventional security tools. LLMs are often connected to multiple environments, including code, HR, tickets and CRM systems. Infiltrating an LLM workflow can therefore compromise multiple domains simultaneously. Data can be leaked through generated texts, summaries, tool outputs, logs and other unauthorized actions.&lt;/p&gt;
 &lt;p&gt;AI breaches are difficult to detect, too, with leaks occurring over multiple seemingly harmless inquiries. This forces investigators to determine whether the leaked data was from training, memory or a connector.&lt;/p&gt;
&lt;/section&gt;       
&lt;section class="section main-article-chapter" data-menu-title="Building a cyber-resilient AI environment"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Building a cyber-resilient AI environment&lt;/h2&gt;
 &lt;p&gt;The impact of an AI breach can be significant, ranging from exposed sensitive data and regulatory fines to integrated AI systems working improperly. Enterprises need to approach AI with security as an integral part of its use. Security practitioners must set governance and threat modeling from the outset. Security teams should model LLM-specific threats such as &lt;a href="https://www.techtarget.com/searchsecurity/tip/Types-of-prompt-injection-attacks-and-how-they-work"&gt;prompt injection&lt;/a&gt;, indirect injection and data leakage via RAG.&lt;/p&gt;
 &lt;p&gt;Authorization requirements at retrieval time, not just in the UI, are critical. Security practitioners need to ensure identity permissions extend to the database and search layers. While certainly not unique to AI, it is important to use data classification and tagging to keep potentially confidential and high-value documents from being indexed.&lt;/p&gt;
 &lt;p&gt;It is critical to safeguard all connectors and credentials. This means applying &lt;a href="https://www.techtarget.com/searchsecurity/definition/principle-of-least-privilege-POLP"&gt;least-privilege&lt;/a&gt; access controls for connectors. Build security into tool and agent execution through policies that incorporate controls such as allowlists and constraints. It is also important to mandate human intervention for permanent actions, including payments and customer-facing emails.&lt;/p&gt;
 &lt;p&gt;To deflect prompt injections, security practitioners should use strong system prompts. Additionally, &lt;a href="https://www.techtarget.com/searchsecurity/feature/How-to-implement-zero-trust-security-from-people-who-did-it"&gt;implement zero-trust controls&lt;/a&gt; that assume external content is potentially malicious until proven otherwise. Data loss prevention protocols are critical to block users from pasting sensitive content into AI that could be leaked.&lt;/p&gt;
 &lt;p&gt;The supply chain also needs security, which requires vetting all checkpoints and consistent maintenance of the model registry. Harden all infrastructure with isolation applied to tenants and indexes. Put strong identity and access management in place through single sign-on and MFA, maintaining zero-trust principles.&lt;/p&gt;
 &lt;p&gt;SecOps teams must be vigilant about logging and monitoring, looking for indicators such as abnormal query patterns and escalations in retrievals of sensitive labels. All organizations need to have an AI incident response guide that outlines elements such as taking tools and connectors offline, rotating tokens, purging indexes and verifying data leakage sources.&lt;/p&gt;
 &lt;p&gt;As AI continues its rapid integration into enterprise operations, organizations must recognize that speed without security is a recipe for disaster. The transformative potential of AI can only be realized when built on a foundation of cybersecurity and proactive risk management. Organizations that prioritize cyber-resilience today will be the ones that thrive in the AI-driven future, while those that neglect it could face breaches that could have otherwise been prevented.&lt;/p&gt;
 &lt;p&gt;&lt;i&gt;Amy Larsen DeCarlo has covered the IT industry for more than 30 years, as a journalist, editor and analyst. As a principal analyst at GlobalData, she covers managed security and cloud services.&lt;/i&gt;&lt;/p&gt;
&lt;/section&gt;</body>
            <description>AI attacks and breaches hit differently than traditional attacks, and therefore require more than traditional controls. The best defense requires planning for cyber-resilience.</description>
            <image>https://cdn.ttgtmedia.com/rms/onlineimages/code_g1196680867.jpg</image>
            <link>https://www.techtarget.com/cybersecurity/tip/Building-cyber-resilient-AI-in-the-enterprise</link>
            <pubDate>Tue, 14 Jul 2026 08:00:00 GMT</pubDate>
            <title>Building cyber-resilient AI in the enterprise</title>
        </item>
        <item>
            <body>&lt;p&gt;As enterprises race to deploy AI across their operations, a perfect storm is brewing: New AI-generated attack vectors are colliding with employees' growing emotional trust in chatbots and AI assistants, creating security blind spots that traditional defenses weren't designed to handle.&lt;/p&gt; 
&lt;p&gt;Security teams are knee-deep in mitigating the threats that accompany AI adoption, from &lt;a href="https://www.techtarget.com/searchsecurity/tip/Types-of-prompt-injection-attacks-and-how-they-work"&gt;prompt injections&lt;/a&gt; and &lt;a href="https://www.techtarget.com/searchsecurity/tip/How-data-poisoning-attacks-work"&gt;data poisoning&lt;/a&gt; to bias exploitation, deepfakes, and models acting in unexpected ways. Though a constant struggle, this more technical concern accompanies the psychological issue of employees oversharing sensitive information with conversational AI systems they've come to trust as helpful and even friendly digital assistants -- a challenge that is harder to address.&lt;/p&gt; 
&lt;section class="section main-article-chapter" data-menu-title="The problem of oversharing"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;The problem of oversharing&lt;/h2&gt;
 &lt;p&gt;The personal use of generative AI and chatbots has broad social implications that bleed into the workplace. Psychologists understand that human beings tend to connect with anything that talks to them, &lt;a href="https://www.psychologytoday.com/us/blog/virtue-in-the-media-world/202405/chatbots-could-start-shaping-how-we-trust-and-who-we-trust" target="_blank" rel="noopener"&gt;even if it's a machine&lt;/a&gt;. And although most users know that AI isn't sentient, it can still elicit emotions -- specifically, misplaced trust.&lt;br&gt;&lt;br&gt;The line between workplace and personal AI is blurry, and some employees are bringing their bad habits to work. Many organizations have yet to establish firm policies for the use of AI assistants, and many employees use AI without awareness of their organization's AI strategy, suggesting widespread use of personal tools outside official channels. According to a &lt;a href="https://www.microsoft.com/en-us/worklab/work-trend-index/ai-at-work-is-here-now-comes-the-hard-part" target="_blank" rel="noopener"&gt;Microsoft study&lt;/a&gt;, 78% of users bring their own AI tools to work, with the practice being more common at small and midsize companies. Further, a National Cybersecurity Alliance and CybSafe &lt;a href="https://www.staysafeonline.org/articles/oh-behave-the-annual-cybersecurity-attitudes-and-behaviors-report-2025" target="_blank" rel="noopener"&gt;survey&lt;/a&gt; found that 43% of employees who use AI for work tasks send sensitive data to AI applications without their employer's knowledge.&lt;/p&gt;
 &lt;p&gt;This reality is creating a new problem for security teams. Employees, already conditioned to trust their personal AI assistants -- everything from ChatGPT to AI friend apps -- are more likely to let their guard down and share personally identifiable information or sensitive company data with systems that lack inherent privacy safeguards. In fact, many publicly available GenAI platforms clearly state in their T&amp;amp;Cs that they use inputs as training data.&lt;br&gt;&lt;br&gt;There are real-world implications. For example, Samsung suffered &lt;a href="https://www.ciodive.com/news/Samsung-Electronics-ChatGPT-leak-data-privacy/647137/" target="_blank" rel="noopener"&gt;several security incidents&lt;/a&gt; related to AI assistants. In 2023, an engineer pasted proprietary source code for semiconductor equipment into ChatGPT to help correct errors, exposing confidential code used in the company's chip manufacturing process. Another employee exposed sensitive business intelligence and internal discussions after feeding the content of a high-level meeting into ChatGPT.&lt;/p&gt;
 &lt;p&gt;According to Naynesh Patel, managing director of cybersecurity at Accenture, the ease of information sharing with AI assistants is problematic, and traditional enterprise security was not designed for it. "The concept of a text box -- where you are able to put information in with little to no friction -- and the fact that it's helpful creates risk," he said.&lt;/p&gt;
&lt;/section&gt;    
&lt;section class="section main-article-chapter" data-menu-title="Governance for AI trust"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Governance for AI trust&lt;/h2&gt;
 &lt;p&gt;The convergence of technical vulnerabilities and human psychology requires CISOs and their teams to adopt controls to defend against data loss via AI.&lt;/p&gt;
 &lt;p&gt;According to Patel, the solution isn't fixing AI; it's rethinking how the organization itself governs AI use among its employees. He said that most data security failures aren't model failures, but identity and &lt;a href="https://www.techtarget.com/searchsecurity/tip/What-CISOs-need-to-know-about-AI-governance-frameworks"&gt;governance&lt;/a&gt; failures running at machine speed.&lt;/p&gt;
 &lt;p&gt;He recommended that security teams deploy the following basic protections alongside enterprise GenAI and chatbot instances:&lt;/p&gt;
 &lt;ul type="disc" class="default-list"&gt; 
  &lt;li&gt;Restrict the ability to post information that's shared anywhere else, such as with the AI parent company and related technology providers.&lt;/li&gt; 
  &lt;li&gt;Keep all data inputs within the boundaries of the organization.&lt;/li&gt; 
  &lt;li&gt;Grant just-in-time, &lt;a href="https://www.techtarget.com/searchsecurity/definition/principle-of-least-privilege-POLP"&gt;least-privileged access&lt;/a&gt; for all employees.&lt;/li&gt; 
 &lt;/ul&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;Set telemetry that enables SecOps teams to see prompts and &lt;a href="https://www.techtarget.com/searchsecurity/tip/Beyond-awareness-Human-risk-management-metrics-for-CISOs"&gt;intervene at the moment of risk&lt;/a&gt;.&lt;/li&gt; 
 &lt;/ul&gt;
&lt;/section&gt;      
&lt;section class="section main-article-chapter" data-menu-title="Data: The new perimeter"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Data: The new perimeter&lt;/h2&gt;
 &lt;p&gt;Data is the new perimeter, and GenAI and conversational AI represent both productivity tools and data exfiltration points. Security teams must treat them as they would any other approved digital tool: secure them, put controls around them, audit their use and educate employees on how to use them safely.&lt;/p&gt;
 &lt;p&gt;As far as human threats are concerned, companies must enforce strict policies. In the wake of its AI security woes, Samsung pursued disciplinary action against the employees, developed its own internal AI system with data controls and eventually enhanced its security protocols.&lt;/p&gt;
 &lt;p&gt;At its best, conversational AI provides efficiency to many at work and comfort to some at home. At their worst, AI assistants can make an already daunting threat landscape worse. What's certain, however, is that human nature is difficult to change, and people will continue to share more information than they should, which requires a fundamental evolution in how security leaders think about risk.&lt;/p&gt;
 &lt;p&gt;&lt;i&gt;Richard Livingston is an editor with Informa TechTarget's SearchSecurity site, covering cybersecurity news, trends and analysis.&lt;/i&gt;&lt;/p&gt;
&lt;/section&gt;</body>
            <description>As employees become more accustomed to using AI, they might be getting a little too comfortable. Learn how strong AI governance helps manage this new human risk.</description>
            <image>https://cdn.ttgtmedia.com/rms/onlineimages/ai_a279596285.jpg</image>
            <link>https://www.techtarget.com/cybersecurity/feature/Why-conversational-AI-is-redefining-your-security-perimeter</link>
            <pubDate>Mon, 13 Jul 2026 08:00:00 GMT</pubDate>
            <title>Why conversational AI is redefining your security perimeter</title>
        </item>
        <item>
            <body>&lt;p&gt;When it comes to malware delivery methods, attackers are sticking with what works -- even as they rely on a rapidly revolving door of payloads.&lt;/p&gt; 
&lt;p&gt;That's according to a report from the ReliaQuest Threat Research Team, which tracks threat activity quarterly. From March 1 to May 31, ClickFix was attackers' preferred malware delivery technique, followed by removable media such as USB drives.&lt;/p&gt; 
&lt;p&gt;ReliaQuest also monitors the top three malware families involved in confirmed security incidents, a list that has experienced almost complete turnover across the past three tracking periods. For defenders, that trend brings new urgency to old advice: Monitor threat behavior, not malware names.&lt;/p&gt; 
&lt;p&gt;Here's how security teams can defend against ClickFix and removable-media-based attacks.&lt;/p&gt; 
&lt;section class="section main-article-chapter" data-menu-title="Trending attack: How to defend against ClickFix"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Trending attack: How to defend against ClickFix&lt;/h2&gt;
 &lt;p&gt;Defenders can no longer consider ClickFix, a &lt;a href="https://www.techtarget.com/searchsecurity/tip/How-to-avoid-and-prevent-social-engineering-attacks"&gt;social engineering&lt;/a&gt; technique that first appeared in 2024, an emerging or OS-specific threat, ReliaQuest researchers warned. It was the dominant malware delivery channel between March 1 and May 31, and the second most common in the previous three-month reporting period.&lt;/p&gt;
 &lt;p&gt;In addition to leading initial access, ClickFix also drove nearly a third of defense-evasion activity. And while it has historically targeted Windows users, ReliaQuest researchers recently observed ClickFix delivery of Atomic Stealer malware on macOS systems.&lt;/p&gt;
 &lt;p&gt;"For enterprises, macOS must no longer be treated as lower risk and now needs the same monitoring and response coverage as Windows," &lt;a target="_blank" href="https://reliaquest.com/blog/threat-spotlight-whats-trending-top-cyber-attacker-techniques-march-may-2026" rel="noopener"&gt;wrote&lt;/a&gt; Raigridas Bartkus, the report's author and a cybersecurity specialist at ReliaQuest.&lt;/p&gt;
 &lt;p&gt;ClickFix tricks users into engaging with prompts -- commonly disguised as legitimate error messages, update notifications and &lt;a href="https://www.techtarget.com/searchsecurity/definition/CAPTCHA"&gt;CAPTCHA&lt;/a&gt; checks -- and pasting malicious commands into system dialogs. While ClickFix often spreads through compromised websites, ReliaQuest noted it has recently shifted to email-based lures.&lt;/p&gt;
 &lt;p&gt;"This period we also &lt;a target="_blank" href="https://reliaquest.com/blog/threat-spotlight-deepload-malware-pairs-clickfix-delivery-with-ai-generated-evasion/" rel="noopener"&gt;saw&lt;/a&gt; a ClickFix loader use likely AI-generated obfuscation to deliver 'Deepload' malware, burying its real logic under thousands of meaningless variable assignments to defeat static scanning," Bartkus wrote. With AI, he added, &lt;a href="https://www.techtarget.com/searchsecurity/tip/How-AI-malware-works-and-how-to-defend-against-it"&gt;attackers can generate new variants more quickly&lt;/a&gt;, giving defenders less time to adapt signature-based detection tools.&lt;/p&gt;
 &lt;div class="extra-info"&gt;
  &lt;div class="extra-info-inner"&gt;
   &lt;h3 class="splash-heading"&gt;Malware leaderboard: March 1, 2026 - May 31, 2026&lt;/h3&gt; 
   &lt;p&gt;Here are the malware families that dominated ReliaQuest's latest reporting period, along with their delivery methods.&lt;/p&gt; 
   &lt;p&gt;&lt;b&gt;Malware family:&lt;/b&gt; Gamarue, also known as &lt;i&gt;Andromeda&lt;/i&gt;, a familiar modular worm.&lt;b&gt;&lt;br&gt;Malware delivery:&lt;/b&gt; Spread through removable media, such as USB flash drives.&lt;/p&gt; 
   &lt;p&gt;&lt;b&gt;Malware family:&lt;/b&gt; NetSupport RAT, a remote access trojan variant of the legitimate IT remote administration tool NetSupport Manager.&lt;b&gt;&lt;br&gt;Malware delivery:&lt;/b&gt; The payload that ClickFix most often delivered, according to ReliaQuest.&lt;/p&gt; 
   &lt;p&gt;&lt;b&gt;Malware family:&lt;/b&gt; Raspberry Robin, a worm often used to provide initial access to ransomware operators.&lt;br&gt;&lt;b&gt;Malware delivery:&lt;/b&gt; Spread through removable media, such as USB flash drives.&lt;/p&gt;
  &lt;/div&gt;
 &lt;/div&gt;
 &lt;p&gt;ClickFix attacks are now so pervasive and scaling so quickly that continuous training, detection and triage are necessary in both Windows and macOS environments, according to the report. CISOs should consider taking the following steps:&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;&lt;b&gt;Train users.&lt;/b&gt; By convincing targets to unwittingly run malicious commands on their own devices, ClickFix can bypass many file- and email-based controls. That makes an &lt;a href="https://www.techtarget.com/searchsecurity/tip/Cybersecurity-employee-training-How-to-build-a-solid-plan"&gt;educated user base&lt;/a&gt; the best defense. Train both Windows and macOS users never to paste commands in Run, Terminal or Script Editor.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Include ClickFix lures in security awareness training.&lt;/b&gt; Don't just tell users what to avoid -- show them, using simulated pop-up and email-based lures that mimic ClickFix attacks. Bartkus suggested including CAPTCHA and verification prompts, browser-to-shell hand-offs and "paste-this-to-continue" directives.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Restrict access to system dialogs.&lt;/b&gt; Restrict Run, Terminal and Script Editor access as much as possible, especially for nontechnical users in high-risk roles.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Monitor for suspicious behavior.&lt;/b&gt; Where impractical to restrict access to system dialogs -- for technical users, for example -- security teams should log and alert on RunMRU activity.&lt;/li&gt; 
 &lt;/ul&gt;
 &lt;p&gt;"Monitoring for activity such as a sequence of base64 decoding, curl retrieval and PowerShell or osascript execution, for example, would represent reliably anomalous behavior in developer environments," a ReliaQuest spokesperson told &lt;a target="_blank" href="https://www.darkreading.com/vulnerabilities-threats/winner-dominant-malware-delivery-clickfix" rel="noopener"&gt;Dark Reading&lt;/a&gt;, a TechTarget Cybersecurity sister publication.&lt;/p&gt;
 &lt;p&gt;Because ClickFix attacks often rely on command obfuscation and obfuscated files, defenders should also look for legitimate-seeming files in unusual places.&lt;/p&gt;
&lt;/section&gt;           
&lt;section class="section main-article-chapter" data-menu-title="Trending attack: How to defend against USB-based compromise"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Trending attack: How to defend against USB-based compromise&lt;/h2&gt;
 &lt;p&gt;Among top initial access paths in March, April and May, removable media came in hot on ClickFix's heels. According to ReliaQuest researchers, two of the top three malware families during the reporting period spread through infected external devices such as USB drives.&lt;/p&gt;
 &lt;p&gt;The report noted a persistent seasonal trend: USB-based attacks tend to escalate during predictable annual periods, such as tax season and Q1 financial reporting. Presumably, employees use removable drives to transfer files among in-office, at-home and third-party environments, increasing enterprise risk.&lt;/p&gt;
 &lt;p&gt;ReliaQuest warned that USB-based malware can lead to broader compromise. Raspberry Robin, for example -- one of the reporting period's leading malware families -- often enables &lt;a href="https://www.techtarget.com/searchsecurity/tip/What-role-does-an-initial-access-broker-play-in-the-RaaS-model"&gt;initial access for ransomware operators&lt;/a&gt;.&lt;/p&gt;
 &lt;p&gt;According to the researchers, defenders should take the following steps to defend against USB-based attacks.&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;Disable USB autorun across the enterprise IT environment.&lt;/li&gt; 
  &lt;li&gt;Use allowlists to &lt;a href="https://www.techtarget.com/searchsecurity/tutorial/How-to-disable-removable-media-access-with-Group-Policy"&gt;block unapproved removable devices&lt;/a&gt;.&lt;/li&gt; 
  &lt;li&gt;Alert on shortcut (.lnk) or script execution from external drives.&lt;/li&gt; 
  &lt;li&gt;Approach any confirmed USB-based infection as the possible precursor to a &lt;a href="https://www.techtarget.com/searchsecurity/tip/Top-3-ransomware-attack-vectors-and-how-to-avoid-them"&gt;major ransomware attack&lt;/a&gt;.&lt;/li&gt; 
 &lt;/ul&gt;
 &lt;p&gt;&lt;em&gt;Alissa Irei is senior site editor of Informa TechTarget Security.&lt;/em&gt;&lt;/p&gt;
&lt;/section&gt;</body>
            <description>Now more than ever, defenders must look for suspicious behavior, not specific malware. Learn how to defend against two trending initial access methods.</description>
            <image>https://cdn.ttgtmedia.com/visuals/ComputerWeekly/Hero%20Images/security-malware-adobe.jpg</image>
            <link>https://www.techtarget.com/cybersecurity/news/366645832/ClickFix-and-removable-media-lead-malware-delivery-methods</link>
            <pubDate>Fri, 10 Jul 2026 17:55:00 GMT</pubDate>
            <title>ClickFix and removable media lead malware delivery methods</title>
        </item>
        <title>Search Security Resources and Information from TechTarget</title>
        <ttl>60</ttl>
        <webMaster>webmaster@techtarget.com</webMaster>
    </channel>
</rss>
