Sophos Working with OpenAI on security from AI, with AI, and for AI
The Sophos AI Security 2026 report, released last month, just showed us the current state of AI-enhanced cyberattacks: Timelines are...
The Sophos AI Security 2026 report, released last month, just showed us the current state of AI-enhanced cyberattacks: Timelines are...
Three separate research efforts last week demonstrated ways to defeat passkey protections without breaking the cryptography they rest on. Passkeys...
Over the last 48 hours, the partnership between the world’s most valuable smartphone maker and the king of generative AI...
A group of Russian hackers has spent the last year targeting nuclear scientists, defense contractors, and government employees in a...
Last week, Hugging Face disclosed a security incident of a new kind: an intrusion carried out end to end by...
Defense organizations processed last week’s CMMC Phase II suspension as a scheduling problem. The more useful frame is a governance...
When a devastating earthquake struck north central Venezuela last week, rescue teams were not the only ones who mobilised fast....
The core of my last post was an asymmetry. An attack can unfold in two steps or 20, but the...
Last Updated: 30 May 2026 The Future of Cybersecurity Cybersecurity isn’t about keeping up with trends anymore. It’s about surviving...
Last Updated: 30 April 2026 Identity for the Machine Age: A CISO’s Framework for Agentic AI Governance In 2026, one...
Last Updated: 16 May 2026 Building a Cyber Incident Response Team: The CISO’s Guide A cyber incident response team (CIRT)...
Last Updated: 16 May 2026 Inside the Boardroom and Beyond: Reflecting on My Induction into the EC-Council C|CISO Hall of...
Last Updated: 16 May 2026 ICS Security Fundamentals Industrial Control Systems (ICS) form the backbone of the world’s most critical...
24 May 2026 Well, that didn't last long! Recording this on Saturday morning my time, I observed ShinyHunters having gone...
Last week, researchers at Google and Forcepoint reported that indirect prompt injection — a category of attack the security community...