Many organizations still talk about the EU Cyber Resilience Act (CRA) as a 2027 problem. It stopped being one on Sept. 11, 2026. Since that date, manufacturers must report actively exploited ...
New research shows that attackers have already routed around a measure that npm adopted in July to close a longstanding security gap. Version 12 of the package manager stopped running dependency ...
Move beyond AI copilots and basic automation to see how autonomous agents can operate across modern security workflows. See how cloud infrastructure, real-time visibility, verified threat intelligence ...
A new research ecosystem is emerging focused on the application of advanced mathematics to address AI safety challenges. The effort is drawing some of the world’s leading mathematicians, including ...
Security is an engineering problem. Saša Zdjelar’s recent article makes that responsibility concrete: enforceable controls, named owners, and evidence that protections work. Saltzer and Schroeder’s ...
AI is increasing both the volume and speed of cyberthreats, pushing organizations to invest more in AI-powered security capabilities to keep pace. Yet overall cybersecurity budgets are barely growing, ...
Verifying what autonomous agents run, install, load, and send on the NVIDIA Open Agent Safety Platform NVIDIA’s Open Agent Safety Platform gives enterprises powerful controls over what AI agents are ...
Why the traditional mean-time-to-patch model is breaking down as exploitation moves ahead of disclosure. How AI-powered vulnerability research and the new generation of security clearinghouses are ...
The volume of malware on public repositories hasn’t decreased. ReversingLabs (RL) has never seen more malicious packages published on public repositories, and the overall count of malicious software ...
It’s a conundrum for application security (AppSec) today: How do you square agentic-assisted development with the basic security principles that keep software trustworthy? Chris Romeo, managing ...
The coding languages shift — fueled by Microsoft, Google, and Amazon and enabled by AI coding — is driven by the quest for secure software. John P. Mello Jr., Freelance technology writer.John P. Mello ...
Same old flaws, bigger stakes: ~40% of CISA's exploited-vulnerability catalog traces back to well-understood, preventable weaknesses (memory safety, input validation, injection). Attackers aren't ...