Search This Blog

Powered by Blogger.

Blog Archive

Labels

Footer About

Footer About

Labels

Latest News

UK Biobank Data Breach Rekindles Debate Over Research Data Security

  A recent case concerning the UK Biobank has once again brought up the topic of securing medical research databases, as well as the importa...

All the recent news you need to know

AI Agents Expose Growing Identity Security Gaps in Enterprise Environments

 

In the face of the rapid adoption of artificial intelligence agents, enterprise security is faced with an increased challenge, as organizations struggle to maintain an increasing number of non-human identities gaining access to sensitive information and critical systems. In an increasingly automated world, security experts warn that each new AI agent introduces another trusted identity into the organization. 

The use of machine identities increases an organization's attack surface without proper oversight, making it harder for security teams to maintain a complete inventory of privileged accounts and monitor their interactions with critical business systems if they are not monitored properly. As opposed to human users, AI agents, service accounts, OAuth applications, and workload identities do not follow traditional employee lifecycles. 

There are many advantages to generating them automatically, inheriting permissions, interacting across multiple systems, and often remaining active long after the applications that generated them cease to exist. In the opinion of security experts, this emerging ecosystem is leading to weaknesses in identity governance that many organizations have yet to address. According to the Non-Human Identity Management Group, machine identities outnumber human users by up to 50 to 1 in many enterprise environments. 

Some of these technologies exist only temporarily, while others continue to operate without any clear ownership for years, making it difficult to determine who created them, what resources they are allowed access to, and whether they are still necessary for security teams to monitor. During a cyber campaign conducted in 2025, threat actor UNC6395 exploited a trusted OAuth token associated with Salesloft's Drift chat integration, demonstrating the risk. 

Instead of exploiting a software vulnerability, the attackers exploited an already trustworthy machine identity in order to access AWS credentials, Snowflake tokens, and other sensitive data across Salesforce environments. The incident demonstrated how compromised machine identities can become gateways to broader enterprise cyberattacks. Security professionals emphasize that artificial intelligence itself is not creating new cybersecurity problems but rather accelerating existing ones. 

With organizations deploying AI-powered agents to automate business processes, the number of privileged identities is continuing to increase, increasing the attack surface if governance processes do not keep pace. Additionally, experts maintain that AI agents are not simply software tools but should be regarded as a distinct class of digital identity instead. 

With AI systems increasingly accessing enterprise applications, making decisions, and executing workflows independently, organizations must provide each AI agent with a unique identity, clear permissions, and full accountability in order to ensure that its actions can be monitored and audited.  

The Netwrix Data and Identity Security Report 2026 reported that organizations with significant increases in the number of identities experienced a 43% breach rate over the previous year, compared to 11% among organizations with no significant changes in their identity landscape due to artificial intelligence. There is no doubt that visibility alone is not sufficient to address the concerns of many affected organizations, as they already invested in identity governance and monitoring. 

There is also a growing concern regarding agent sprawl, in which organizations deploy artificial intelligence assistants and autonomous agents rapidly without establishing governance frameworks. As the number of machine identities within an organization increases, cybersecurity experts warn that this can cause duplicate AI agents, inconsistent permissions, and increased operational, security, and compliance risks.  

As well as stressing the importance of identifying machine identities, the report stresses the imperative of continuous identity governance which tracks ownership, permissions, lifecycles, and access rights throughout the lifespan of every AI agent and non-human identity. The accumulative nature of trusted identities can increase the likelihood that unauthorized access and misuse can occur without ongoing governance. The following four key questions should be answered continuously by organizations for every identity in their environment: What identities exist? 

Who owns them? What can they access? When should they be retired? Unless clear ownership and lifecycle management are in place, AI-driven identities may silently accumulate excessive privileges and provide an opportunity for attackers. Experts also recommend that AI agents be subject to the Zero Trust security principles. 

The same way that human users require continuous verification and least privilege access, AI agents should be given only the appropriate permissions to accomplish their duties. Keeping detailed audit logs and implementing lifecycle controls (including the capability of quickly eradicating or retiring unnecessary agents) can reduce security risks over the long term. 

A growing number of industries are adopting artificial intelligence, which requires cybersecurity strategies to evolve beyond traditional user-focused identity management strategies. It has been recommended that organizations establish stronger governance for non-human identities, identify an owner for each AI agent, and periodically review their permissions. 

A lack of such controls could result in trusted AI-powered identities becoming one of the most overlooked attack vectors in today's enterprise environments, according to experts.

Regular Website Maintenance: Why It Matters

 

A website is often the first place customers meet your brand, but many businesses treat it like a one-time project. That is a mistake. Once a site goes live, it needs regular attention to stay secure, fast, and useful. Without maintenance, even a well-designed website can begin to slow down, break in small ways, or create trust issues for visitors. Over time, outdated software, broken links, and stale content can quietly damage your online presence and make your business look inactive. 

The first major reason for regular maintenance is security. Websites are constantly exposed to threats such as outdated plugins, weak passwords, malware, and other vulnerabilities. When updates are ignored, attackers can exploit those gaps and compromise user data or site functionality. Regular patches, monitoring, and backups reduce that risk and give businesses a much stronger defense. For any company that collects leads, processes payments, or stores customer information, maintenance is a basic part of digital protection.

The second reason is performance. A website that loads slowly or behaves unpredictably can frustrate visitors within seconds. Images may become too heavy, scripts may conflict, and plugins may stop working properly after updates elsewhere in the system. Regular checks help identify these issues before they hurt conversions. A faster, smoother site also supports better engagement because users are more likely to stay, explore, and complete a form or purchase when the experience feels effortless. 

The third reason is search visibility. Search engines prefer websites that are current, technically sound, and easy to crawl. If pages contain broken links, missing metadata, outdated content, or poor mobile performance, rankings can suffer. Maintenance helps keep content fresh and signals that the site is active and relevant. That matters because search traffic is often one of the most valuable sources of visitors for businesses that want steady, long-term growth. 

Regular maintenance also improves credibility. Visitors notice when a site feels abandoned, loads slowly, or contains old information. A website should evolve with your business, your audience, and your goals. When you treat maintenance as an ongoing habit instead of an emergency fix, you protect your brand, support your marketing, and reduce expensive problems later. In short, a maintained website is not just healthier; it is more trustworthy and more effective.

Why AI Agents Are Challenging Identity Security


The wide adoption of AI agents is forcing organizations to rethink identity security as enterprises contend with an expanding population of non-human identities that increasingly outnumber employee accounts. While identity and access management programs have traditionally focused on managing people throughout their employment lifecycle, autonomous software identities are exposing governance gaps that many organizations are still struggling to address.

Unlike human users, machine identities, including AI agents, service accounts, workload identities, OAuth applications, and API credentials, are created to authenticate systems, automate processes, and enable communication between applications. As organizations embrace cloud computing, automation, and generative AI, these identities are being created at a pace that often exceeds traditional governance processes.

Human identities typically follow a predictable lifecycle. Employees are onboarded, assigned appropriate access, promoted or transferred to new roles, and eventually offboarded when they leave an organization. These lifecycle events form the foundation of identity governance, allowing security teams to periodically review permissions and revoke unnecessary access.

Machine identities operate differently. They may be generated automatically when new cloud workloads are deployed, inherit permissions from existing applications, communicate across multiple enterprise platforms, or exist only briefly before being replaced. Others remain active long after the application, automation workflow, or development project that created them has been retired. Without continuous oversight, organizations can lose visibility into who owns these identities, why they still exist, and what sensitive resources they are capable of accessing.

The scale of this challenge continues to grow. According to the Non-Human Identity Management Group, machine identities can outnumber human users by as much as 50 to one across many enterprise environments. While these identities are essential for modern business operations, security teams frequently struggle to maintain accurate inventories or establish clear ownership for every credential operating within their environments.

The security implications became evident during the UNC6395 campaign in 2025, when attackers reportedly obtained an OAuth token associated with Salesloft's Drift chat integration and leveraged the trusted credential to move across Salesforce environments used by hundreds of organizations. Rather than exploiting a software vulnerability, the attackers abused an identity that had already been authorized within enterprise systems. Investigations found that the compromised access enabled attackers to obtain additional secrets, including AWS credentials and Snowflake tokens, demonstrating how a single trusted machine identity can provide a pathway to multiple connected environments.

AI agents are not creating an entirely new category of identity risk, but they are accelerating an existing challenge. Modern AI systems increasingly perform tasks autonomously, interact with multiple business applications, retrieve sensitive information, and execute workflows without continuous human involvement. As these agents operate across cloud services, they introduce additional trusted identities, inherit permissions from existing accounts, and expand the number of credentials that organizations must secure.

This rapid growth creates a governance challenge that extends beyond simple visibility. Security teams may know that identities exist, but effective identity security also requires understanding who owns each identity, what permissions it has been granted, what sensitive data it can reach, and when that identity should no longer exist. Without continuous lifecycle management, dormant or forgotten machine identities can quietly expand an organization's attack surface.

Findings published in the 2026 Data and Identity Security Report illustrate the scale of the problem. Organizations that reported AI exponentially increasing the number of identities within their environments experienced a 43% breach rate over the previous year, compared with 11% among organizations where AI had not substantially expanded their identity footprint. Notably, many organizations affected by breaches also reported implementing stronger governance practices, suggesting that visibility alone is insufficient if identity ownership, permissions, and access reviews are not continuously maintained.

As enterprises continue integrating AI into daily operations, identity security is becoming less about managing employee accounts and more about governing a rapidly expanding ecosystem of trusted non-human identities. Maintaining comprehensive identity inventories, enforcing least-privilege access, continuously reviewing permissions, and assigning clear ownership to every human and machine identity will be essential to reducing risk. As AI agents become more autonomous, the identities organizations overlook may prove just as valuable to attackers as those they actively monitor.

Ransomware activity climbs in Q2 2026 as leading gangs consolidate attacks and AI streamlines extortion efforts

 


Ransomware groups claimed responsibility for 2,279 attacks worldwide during the second quarter of 2026, marking a 7% increase from the previous quarter and a 43% jump compared with the same period last year, according to GuidePoint Security's latest quarterly ransomware report. Researchers also recorded the highest number of active ransomware groups seen in a single quarter, reflecting an ecosystem that continues to attract new threat actors even as attacks remain concentrated among a relatively small number of established operations.

Despite the growing number of ransomware groups, a handful of operators continue to dominate victim claims. GuidePoint found that the five most active groups were collectively responsible for more than 40% of all publicly reported ransomware incidents during the quarter, suggesting that while new groups continue to emerge, only a few have achieved sustained operational scale.

Qilin remained the most active ransomware operation during Q2, accounting for approximately 13% of all recorded victim claims. It was closely followed by The Gentlemen, a comparatively new group that has expanded rapidly in recent months. Together with Akira and DragonForce, the two groups make up what GuidePoint describes as a "four-headed monster," representing the most prolific ransomware operations currently shaping the threat landscape.

Rather than relying on a single dominant ransomware syndicate, today's ransomware ecosystem is distributed across several highly active groups capable of absorbing affiliates from disrupted operations. Researchers noted that this structure could reduce the long-term impact of law enforcement takedowns, as affiliates displaced from one ransomware-as-a-service (RaaS) platform may quickly transition to another established operation without substantially disrupting attack activity.

The United States remained the country most frequently targeted by ransomware groups during the quarter, accounting for 40% of publicly claimed victims. Germany ranked second with 32%. However, GuidePoint observed a noticeable shift in targeting patterns, with the U.S. accounting for a smaller proportion of victims than in previous quarters, when roughly half of all reported incidents involved American organizations.

Researchers linked this broader geographic distribution to increased activity from groups including Qilin, The Gentlemen and LockBit, each of which claimed a larger share of victims outside the United States during Q2. The findings suggest that ransomware affiliates are expanding their operations across a wider range of regions instead of concentrating primarily on U.S.-based organizations.

Alongside changes in victim targeting, the report examined how artificial intelligence is being incorporated into ransomware operations. While concerns have grown around the possibility of AI creating entirely new forms of cyberattacks, GuidePoint found little evidence to support that scenario. Instead, threat actors are primarily using large language models (LLMs) to accelerate tasks that previously required significant manual effort, allowing them to improve efficiency without fundamentally changing their attack methods.

One case study highlighted in the report involved the data extortion group FulcrumSec. After obtaining a large volume of stolen information, the group reportedly used an LLM to examine complex databases and identify individuals appearing across multiple datasets. According to researchers, completing this level of analysis manually would have required either extensive knowledge of the victim's database architecture or a substantial investment of time by human operators.

The information extracted from the stolen data was then paired with AI-generated negotiation messages written in English. By demonstrating a detailed understanding of the compromised information, FulcrumSec strengthened its position during ransom negotiations, providing victims with evidence of the data in its possession while using those findings to justify its ransom demands.

GuidePoint also documented DragonForce's use of large language models during extortion negotiations. Researchers said the group generated convincing messages that sought to increase pressure on victims, including claims that it had legal counsel available to advise its operations. Although the report describes that assertion as almost certainly false, it illustrates how AI can help cybercriminals produce persuasive communications intended to exploit concerns around regulatory obligations, legal consequences and reputational damage.

According to the researchers, the effectiveness of these messages does not necessarily depend on their accuracy. Instead, their value lies in presenting information in a manner that appears credible enough to influence decision-making during negotiations. Large language models, which are capable of generating fluent and convincing text within seconds, are increasingly being used to support these psychological tactics.

Taken together, the findings indicate that AI is currently serving as an operational force multiplier rather than introducing an entirely new category of ransomware attacks. Tasks such as analyzing stolen data, organizing information, preparing victim communications and drafting negotiation messages can now be completed more quickly, enabling threat actors to devote more time to other stages of their operations.

At the same time, the continued concentration of attacks among a small group of highly active ransomware operations suggests that scale, organization and affiliate networks remain key drivers of today's ransomware economy. While new groups continue to enter the ecosystem, a limited number of established operators continue to account for a disproportionate share of publicly claimed attacks, reinforcing their influence across the global ransomware ecosystem.

Splunk Report Finds One in Five CISOs Pressured to Hide Cybersecurity Incidents

 

The Splunk 2026 CISO report makes public the challenges that CISOs face when trying to meet the rising demand to mask security incidents while also complying with tightening disclosure laws. According to the report, which draws its conclusions from the responses of 650 CISOs, 20% of respondents had experienced pressure from their organization not to disclose a cybersecurity incident or breach, and 53% of those who were challenged had reported an incident or breach anyway. 

It is stated that business and regulatory priorities conflict, putting CISOs in the middle of a regulatory dilemma. In addition, there is a growing sense among CISOs that they could face disciplinary or legal repercussions if they fail to protect the company from cyber ​​security threats. The percentage of CISOs concerned about being held accountable for a cyber ​​incident increased from 56% in 2025 to 78% in 2026. 

The report also shows that 79% of CISOs believe their jobs have become increasingly complex over the last year, with 43% reporting having taken on new roles and responsibilities outside their primary function, such as preventing fraud and financial crime. Moreover, 96% of CISOs responded that they are now responsible for the governance and risk management of artificial intelligence. This is yet another factor contributing to the complexity of the CISO’s work, as they must ensure that companies adopt responsible AI practices. 

The increasing difficulty of the CISO position is reflected in the fact that 26% of CISOs stated they have considered quitting their jobs due to the burdensome nature of the role. It is therefore not surprising that the report’s findings coincide with new government regulations that further tighten cybersecurity disclosure laws. For example, according to the Cyber Security and Resilience (Network and Information Systems) Bill currently under consideration in the UK Parliament, organizations in the UK will be required to report on major cyber ​​security incidents and strengthen board-level oversight of cybersecurity. 

CISOs must therefore carefully weigh the risks and benefits of any response, as reporting an incident too soon could result in financial losses for the company, whereas reporting it later could incur severe regulatory penalties. The report recommends that CISOs focus on building and maintaining strong governance by providing detailed information on how and by whom incidents were uncovered, as well as which steps had been taken to investigate and remediate the damage. 

This will ensure that the CISO’s decisions regarding disclosure of an incident are based on verifiable facts and figures. By analyzing all relevant data across enterprise networks, cloud, endpoints, or servers, the security leader can build a comprehensive report outlining the exact course of action taken after the breach was discovered. This will help to both satisfy regulatory authorities during an audit and assist in determining if and when a report needs to be filed. 

The report therefore highlights the fact that the role of the CISO has changed dramatically and now entails a wide range of responsibilities, requiring them to make decisions that go beyond the realm of traditional cybersecurity.

EU Mandates Driver Distraction Warning Systems in All New Vehicles Amid Privacy and Safety Debate

 

The European Union has introduced stricter vehicle safety regulations, making Advanced Driver Distraction Warning (ADDW) systems mandatory in all newly registered vehicles across member states from this week. The move is part of the European Commission’s expanded General Safety Regulation, aimed at reducing road fatalities and improving overall traffic safety.

Although Europe is considered one of the safest regions for road travel, the European Commission noted in its announcement that "the number of deaths and injuries from road accidents is still too high." To address this, the updated rules introduce several advanced safety requirements for new vehicles.

In addition to ADDW systems, the new legislation requires advanced emergency braking systems capable of detecting pedestrians and cyclists, along with improved forward visibility features. Driver distraction monitoring technology, which uses cameras to observe a driver's attention levels, will now become a standard feature in all newly registered vehicles.

These camera-based systems continuously monitor a driver's eye movements and facial expressions using sensors positioned behind the steering wheel or above the vehicle’s infotainment display. If the system determines that the driver has looked away from the road for an extended period, it issues alerts encouraging them to refocus.

Depending on the manufacturer, these alerts may include audible warnings, dashboard notifications, or the temporary disabling of features such as adaptive cruise control and other automated driving functions.

However, the mandate has sparked criticism from some quarters. The European Conservative described the Commission’s decision as the "latest annoying piece of EU overregulation," raising concerns over the lack of transparency regarding how data collected by these systems will be managed.

Current ADDW systems are designed to function in a closed-loop environment, where all information is processed locally within the vehicle without being transmitted to external servers. Despite this, concerns persist over the future handling of driver data as vehicles become increasingly connected.

Since April 2018, all newly approved passenger cars and light vans sold in the European Union have been equipped with the eCall emergency system, which automatically contacts emergency services following a serious accident. Combined with forecasts from consulting firm McKinsey that 95% of vehicles worldwide will be internet-connected by 2030, experts believe driver-monitoring information could eventually be transmitted beyond the vehicle.

Privacy concerns have already been highlighted in previous research. In 2023, Mozilla reviewed the privacy practices of 25 automotive brands and found that none met the organization's own privacy and security expectations. The report described connected vehicles as "the worst product category we have ever reviewed for privacy."

The issue has also drawn regulatory attention outside Europe. In 2024, the Texas Attorney General launched an investigation into several automobile manufacturers following allegations that they were collecting extensive driver data and selling it to third parties.

Critics argue that the European Union has yet to clearly define how information gathered by ADDW systems will be governed. They warn that such data could potentially be used in areas such as insurance pricing or legal proceedings in the future.

Beyond privacy issues, some motorists have questioned the usability of driver monitoring technology, arguing that overly sensitive systems can themselves become a source of distraction by issuing unnecessary alerts during routine driving activities.

While Euro NCAP has indicated that it aims to reduce reliance on "annoying" in-car safety features, the European Union’s latest regulations place greater emphasis on driver monitoring technologies, highlighting the ongoing debate between improving road safety and protecting driver privacy.

Featured