#1 Trusted Cybersecurity News Platform
Followed by 5.20+ million
The Hacker News Logo
Subscribe – Get Latest News

The Hacker News | Expert Insights

Enterprise Mobile AI: The Security Trade-Offs You Can't Ignore

Enterprise Mobile AI: The Security Trade-Offs You Can't Ignore

Sept 21, 2026
It feels like every AI conversation starts the same way: "We need an AI strategy!" Leadership wants the productivity gains. Employees want the convenience. And IT is expected to make it all happen—securely, of course. AI can summarize meetings, translate conversations, draft emails, and surface information in seconds. It promises to eliminate the kind of repetitive work that quietly steals hours from every week. But beneath all the excitement lies a question that needs more attention. Before AI can help you work smarter, it needs access to your information. That could be a calendar invite, next quarter's product roadmap, or IP. Think of AI like hiring the world's smartest intern. It can research, summarize, and help organize your otherwise disorganized meeting notes. In other words, you have to hand it your notebook full of your confidential information. The real question is what happens to that notebook after you've handed it over. Shadow AI isn...
Beyond ISO 27001: Building a Risk Program That Can Keep Up With AI

Beyond ISO 27001: Building a Risk Program That Can Keep Up With AI

Sept 21, 2026
There are two common mistakes you might be making with ISO 27001: treating certification as the finish line, and treating certification as proof that your controls will keep working.   Neither of these assumptions works well as AI becomes a bigger part of business operations.  ISO 27001 helps set up the right processes, ownership, controls, and risk methods for an organization. But AI systems now connect to more data, applications, and business processes, and they often act with less human oversight.  Meanwhile, businesses aren’t slowing down.  OneTrust’s latest research shows that 86% of organizations had at least one AI-related incident last year, but only 27% slowed or paused their AI rollout.  For CISOs and risk leaders, just showing that controls exist isn’t enough anymore. Teams now need to check if those controls still work, what risks remain as things change, and who is responsible if risks go beyond what the organization can accept.  Th...
The Login Worked. That Was the Attack.

The Login Worked. That Was the Attack.

Sept 21, 2026
Session theft has been productized. The control most organizations still treat as the finish line does not touch it. Somewhere in your environment this quarter, an employee is going to authenticate correctly. Right password, right second factor, right device, no failed attempts, no alert. And an attacker is going to be inside that account seconds later, holding a session your identity provider considers entirely legitimate. That is the documented operating model of at least two commercial phishing services running right now, one of them a $320-a-month kit called NovaCookies, and it is what happened to a set of customers at one of the most security-literate software companies in the industry within the last month. What makes these attacks uncomfortable is not just their sophistication, but also that they are cheap, rented, and specifically engineered to produce a sign-in event that looks ordinary. The $320 Phishing Kit Selling Session Theft as a Service Researchers at Island di...
Why Deepfake Legislation Won't Save the 2026 Elections

Why Deepfake Legislation Won't Save the 2026 Elections

Sept 21, 2026
As the 2026 election cycle hits full stride with midterms approaching, the threats that voters, campaigns, and candidates are coming face-to-face with have completely changed from even two years ago. In 2024, most synthetic media and generative AI attacks were still unpolished, easy to spot, and deployed in isolated experiments.  Fast forward to today, and AI tools have grown up fast. What used to be scrappy proof-of-concept attacks are now slick, automated operations running at scale. That shift changes everything about what election security actually means. It's no longer just about locking down voter rolls or hardening voting machines. The real fight has moved upstream, into the channels where public trust gets shaped in the first place. If you're a security leader, a campaign staffer, or someone running digital infrastructure, the old perimeter-defense playbook won't cut it anymore.  For campaign security teams, that means the job has expanded well beyond protec...
How to Evaluate a Unified Security Platform Using a One-Incident Test

How to Evaluate a Unified Security Platform Using a One-Incident Test

Sept 14, 2026
A software dashboard can look unified even when the incident workflow remains fragmented. The fastest way to expose the difference between a unified platform and a unified dashboard is to run one representative incident from the first alert through containment to clean restoration, counting every console switch, every time information has to be manually carried from one tool into another, and every ownership handoff. Acronis Cyber Protect is designed to combine cyber security, backup, recovery and endpoint management within a unified operational model, helping in-house IT teams reduce the number of disconnected tools and workflows involved in detecting, responding to and recovering from incidents. Available capabilities depend on the selected edition, deployment model and licensed components. But integration should be demonstrated, not inferred from a feature list. Treat a proof of concept like an incident drill: compare the proposed solution with the current operational workflow...
Stop Trying to Control AI Behavior. Control What AI Can Reach

Stop Trying to Control AI Behavior. Control What AI Can Reach

Sept 14, 2026
You cannot reliably predict what an AI agent is going to do. That is a feature, not a flaw.  When things go well, developers can save a lot of time and effort. When it goes wrong, it can be disastrous. For example, in April 2026, a Cursor agent working on a staging task for PocketOS encountered a credential mismatch, found an unrelated Railway API token with blanket GraphQL permissions , and used it to delete the production database and its volume-level backups in nine seconds.  Unlike deterministic scripts, which produce fixed outcomes given the same input, we use agents because they can take a loosely defined objective and determine the steps themselves. An agent can read context, choose tools, query systems, revise its plan, and take a path nobody explicitly programmed. Security teams can decide afterward whether those actions were acceptable, but fully enumerating them in advance is not only antithetical to using an agent but also practically impossible. On the ot...
What Happens to Data Inside AI Agents

What Happens to Data Inside AI Agents

Sept 08, 2026
AI agents have become incredibly useful across many industries by their ability to reach inboxes, documents, and financial information, then search, summarize, or act on what they find. But that access creates a data-in-use problem: conventional encryption protects information in storage and transit, but an agent generally needs it decrypted in memory while processing it, where sensitive material can be exposed to application code, logs and debugging systems, infrastructure operators, or a compromised host. Conan Yu’s work offers one practical response to that problem. He is co-founder of Rena Labs , which develops infrastructure for confidential AI training and inference using trusted execution environments (TEEs), hardware-isolated environments designed to limit the surrounding host’s access while code and data are processed. Over roughly two years, Yu has worked across hardware and cloud TEE deployments, privacy-preserving financial-data analysis, and private AI inference. He a...
Why Are So Many Security Professionals Keeping Breaches Quiet?

Why Are So Many Security Professionals Keeping Breaches Quiet?

Sept 07, 2026
More than half of IT & cybersecurity professionals who experienced a breach in the past 12 months say they were told to keep it confidential, even when it was reportable. That finding comes from the 2026 Bitdefender Cybersecurity Assessment , a study Bitdefender has run for several years running. Disclosure rules have expanded significantly since the question was first asked in 2023, but the pressure to hide breaches continues. How Many Organizations Hide Breaches? Roughly half of 1,200 IT and security professionals surveyed reported a breach or security incident in the last 12 months. Of that group, 55.2% said they had been asked to keep a breach confidential even when it should have been disclosed. That's a snapshot. Here's the trendline: In 2023, 42.0% of respondents said they'd been asked to keep a breach quiet. By 2025 that number had climbed to 57.6%. In 2026 it settled back to 55.2%, which appears to be a plateau, not a reversal. IT & security pr...
Blind Spots and Backdoors: Practical Advice for Identity Risk Reduction

Blind Spots and Backdoors: Practical Advice for Identity Risk Reduction

Sept 07, 2026
Check your expanding identity attack surface Identity has become the new perimeter, and attackers know it. According to new research from CrowdStrike, 80% of modern cyberattacks are identity-driven , leveraging compromised credentials.  This substantial volume is driven by the widespread use of well-known directories such as Active Directory, and the vulnerabilities associated with compromised privileged accounts that are overprivileged or unmanaged, not network intrusion.  The explosion of privileged credentials and lack of adequate visibility or oversight can be attributed to growth, whether due to migration to the cloud, mergers and acquisition, the increased use of contractors, or simple organic business growth. This growth outpaces the ability to adequately govern the environment, leaving exploitable vulnerabilities.
The Economics of Dwell Time and Why AI Native SIEM Changes the Equation

The Economics of Dwell Time and Why AI Native SIEM Changes the Equation

Sept 07, 2026
Most security teams know that dwell time matters. The harder question is what to do about it. Dwell time is the period between an attacker gaining access and the security team containing the threat. During that window, a threat actor has time to learn the environment, steal credentials, move between systems, and reach sensitive data. For years, security teams have tried to reduce this window by adding more detection tools. The problem is that more alerts do not necessarily mean faster detection.  A recent industry incident response report puts the global median dwell time at 14 days, up from 11 the year before, quietly reversing a run of steady improvement that had held for close to a decade. The better way to think about it is as an operational problem. Two numbers matter most. Mean time to detect (MTTD) tells you how quickly the team recognizes a real threat, while mean time to respond (MTTR) tells you how quickly the team investigates and contains it. An AI native SIEM...
The Missing Context Layer for AI Agents in Large Enterprise Codebases

The Missing Context Layer for AI Agents in Large Enterprise Codebases

Aug 31, 2026
As organizations deploy AI coding agents across large monorepos and microservices environments, a fundamental problem emerges: the model may be capable of making the change, yet still lack the organizational context required to make the right change safely. A developer can ask an AI coding agent to deprecate an API field, update an authentication flow, or modify a service interface. The agent can inspect the code available on the developer's machine and search for references. What it may not know is that the field is consumed by four other services across separate repositories, that one of those services belongs to another team, or that the same field eventually carries sensitive data into a third party integration. This is not simply a context window problem. It is a code context problem: providing AI agents with accurate, current, organization wide evidence about how software actually behaves. One emerging approach is to generate that evidence directly from source code us...
Shadow AI Is Now Hiding Inside Sanctioned AI Tools

Shadow AI Is Now Hiding Inside Sanctioned AI Tools

Aug 31, 2026
AI coding agents are already inside engineering organizations. The problem security teams need to solve is not only that AI-generated code might be vulnerable. You already have ways to catch that: code review, CI, SAST, dependency scanning, and production monitoring. The real problem is that tools such as Claude Code, OpenAI Codex, Claude Cowork, and GitHub Copilot are becoming extensible agent runtimes. Skills, plugins, hooks, repository instructions, and MCP servers can influence what the agent reads, which tools it selects, what commands it runs, and where enterprise data is sent. Most AI governance programs stop at approving the application. Very few can tell you everything that has been installed inside it. That is the supply-chain gap. What changed: Third-party components are no longer participating only at build or deploy. They are participating in the agent’s decision loop. From coding assistant to agent runtime The first generation of coding assistants mainly...
The EU CRA Will Make You Report What It Hasn't Yet Made You Fix

The EU CRA Will Make You Report What It Hasn't Yet Made You Fix

Aug 31, 2026
In eleven days, on September 11, manufacturers of products with digital elements sold into the European Union have to tell a regulator within 24 hours of learning that a vulnerability in one of their products is being actively exploited, with a fuller account due at 72 hours. I have a decent idea what the next eleven days look like inside most of those companies, having spent close to thirty years watching software organizations get ready for a date on a calendar. There will be a spreadsheet of products and owners that somebody builds over a weekend, a notification template that goes to legal for review, probably a consultant on a two-week engagement. It will mostly work. By September 10, the majority of them will be able to file inside 24 hours, and they will be right to feel relieved about it, because filing on time is exactly what the regulation asks, and it is not a trivial thing to arrange. What I would gently point out is that almost none of them will come out of the exercise ...
Why Threat Intelligence Needs OT Context to Protect Critical Infrastructure

Why Threat Intelligence Needs OT Context to Protect Critical Infrastructure

Aug 24, 2026
Cybersecurity teams have no shortage of threat data: New vulnerabilities are disclosed, malware is discovered, attack campaigns are analyzed, and manufacturers, CERTs, and security agencies continuously publish indicators of compromise (IoCs), security advisories, and other technical information. For operators of critical infrastructure, however, collecting this information is not even the most challenging part. Security teams still need to determine whether a threat is relevant to their environment, which assets may be affected, and what the observed activity actually means in the context of an operational network. In the energy sector, that requires knowledge extending beyond enterprise security and into the protocols, equipment, and processes that keep power systems operating. A suspicious packet in an office network is one thing. Understanding whether communication between an engineering workstation and a protection device using IEC 61850 represents expected maintenance activi...
Why AI Teams Need Verifiable Search Data Instead of Black-Box Signals

Why AI Teams Need Verifiable Search Data Instead of Black-Box Signals

Aug 24, 2026
Many AI systems depend on input signals that teams cannot fully inspect or explain. These opaque sources reduce visibility into the data paths that influence model behavior. Engineers lose provenance records, limiting the diagnosis of abnormal outputs. This complicates the work of security teams that need clear records of what influenced a model at any point in time. Verifiable search data offers a stable alternative. It gives teams an input they can examine, store, and reproduce in controlled conditions. Engineers can compare model behavior against information that was publicly accessible at the time a result was produced, rather than depend on hidden internal signals. This article outlines why verifiable search data gives AI and security teams the clarity required to maintain operational control. Why Traceability Matters in AI Systems Traceability lets teams follow an input from its origin through each processing step. When every stage can be inspected, engineers can review...
Why Your AI Developer Tools Might Be Your Biggest Security Risk

Why Your AI Developer Tools Might Be Your Biggest Security Risk

Aug 17, 2026
Artificial intelligence is everywhere now. From automated code completion to autonomous infrastructure management, AI tools and AI agents help DevOps speed up deployment cycles and change how development teams operate in general. At the same time, this rapid adoption of AI has created a reality that is hard for security teams to ignore: as with the growth of AI capability within the software development life cycle, the attack surface also grows. In 2025, there were 68 AI-related incidents recorded across major DevOps platforms according to the 2026 DevOps Threats Unwrapped Report . In the first half of 2026, the number of AI-related incidents visibly grew — research from GitProtect Lab tracked 84 AI-related incidents in six months alone. Thus, comparing the first half of 2026 to the same period in 2025 shows that AI-related incidents in development environments have nearly tripled. What do DevOps and DevSecOps say about AI incidents in general? According to GitProtect Lab ’s surve...
The Long Road From Pentest Finding to Verified Fix

The Long Road From Pentest Finding to Verified Fix

Aug 17, 2026
Penetration testing is intended to help organizations identify weaknesses before attackers can exploit them. Once testing ends, findings must be documented, reviewed, formatted, delivered, assigned, tracked, remediated, and eventually retested. In many organizations, each of those steps happens in a different system and depends on a manual handoff. Testers work in one set of tools. Reports are assembled in Word or spreadsheets. Findings are delivered through PDFs. Security teams recreate them in ticketing systems. Engineering teams update remediation status somewhere else. Retesting is coordinated through email or meetings. By the time the right owner receives the information needed to act, days or weeks may have passed. At PlexTrac , we see this as one of the largest operational gaps in modern offensive security: organizations have invested in finding vulnerabilities, but the process surrounding the pentest has not kept pace. The next phase of pentest modernization is removin...
Cybersecurity Resources