Infosec stories
New procurement rules could keep critical emergency and health systems in local hands, as Catalyst warns reliance on offshore vendors raises costs and risks.
Gallagher Security has won the Cloud Security category at the 2026 Fortress Cybersecurity Awards for its cloud-based platform OneLink.
Rising vulnerability volumes are outpacing fix times, prompting HackerOne to roll out an AI system that feeds confirmed threats into developer tools.
Security teams can now apply the same rules to AI-generated code across development and deployment, as Salt broadens its platform to curb flaws earlier.
It gives Japanese businesses a controlled way to manage accounts outside single sign-on, where staff often still store passwords informally.
Businesses adopting AI now face a single service aimed at filling gaps in governance, monitoring and incident response across workflows.
Only 12% of chief information security officers have recently validated controls they expect to stop intruders moving sideways through networks.
New silicon-level controls aim to curb unauthorised agent access and data exposure in enterprise AI storage, while keeping traffic fast.
AI-driven vulnerability discovery is leaving companies less time to patch, prompting new focus on clean recovery, air-gapped backups and testing.
Organisations are being pushed to spot hidden privilege paths in AI and machine accounts as BeyondTrust widens its identity risk assessment.
AI-driven vulnerability scanning is forcing firms to rethink complacency as Check Point says existing defences still help against Mythos.
Microsoft patched a CVE-2025-59199 flaw in October after researchers showed a single click could let low-integrity code escape Windows 11's sandbox.
Excessive access rights across hybrid estates can now be trimmed more safely, as XM Cyber adds usage data to pinpoint permissions that are no longer needed.
Regulated sectors can now route AI prompts through regional controls and zero-retention storage, reducing data-leakage risk for sensitive workloads.
Enterprises using AI tools may now face a tougher check on their defences as benchmark scores give way to real-world attack testing.
Industrials remained the main target as the monthly ransomware total eased 7%, even as The Gentlemen surged to second place among active gangs.
The move gives the cyber risk provider closer access to EMEA customers as demand rises for better oversight of supplier vulnerabilities.
Demand for secure AI infrastructure is pushing enterprises towards systems that combine computing, networking and storage in one stack.
More than half of patched flaws in major DevOps tools were high or critical in 2025, putting software supply chains at greater risk.
Security teams may get broader visibility into phishing campaigns as Doppel adds inbox defence to its platform for social engineering attacks.