Offensive Security stories
Boards are being pushed to rethink data platforms and cyber controls as AI adoption exposes Australian firms to faster attacks and stricter governance demands.
Access to ChatGPT and GPT-5.6 is being tightened for some accounts as OpenAI moves to hardware-backed passkeys amid rising phishing risk.
Tests on five models found a planted text string sharply reduced successful AI-led intrusions, cutting full compromise to 1% in an AWS range.
Security teams are being pressed to prove their defences work in live attacks, as spending scrutiny shifts from tools to real-world response.
The controlled trial could help security teams cut false positives and speed remediation as frontier AI moves beyond finding bugs to validating risk.
New tools for governing AI agents are moving to the fore as Google picks 33 cybersecurity startups for its first cybersecurity forum cohort.
The AWS badge could help XBOW win more enterprise deals as buyers seek continuous testing that shows which vulnerabilities are exploitable.
Firms with manually rotated ADFS certificates could still be exposed, as attackers may recover live signing keys and forge SAML logins.
The two-hour exercise is designed to show whether security teams can recover cleanly as AI-driven attacks can now unfold in minutes.
The real risk is growing backlogs and patching delays, as AI speeds up exploit development faster than security teams can respond.
Hidden tracking markers and a US standoff over a vulnerability-finding model are fuelling fears that AI now carries cyber and national security risks.
Security leaders can now map team gaps more precisely as the platform adds crisis simulation, AI coaching and SOC training tools.
Organisations risk missed exposures as cloud, APIs and AI systems change far faster than annual security checks can keep up.
Enterprise security teams gain a new AI-assisted way to spot exploitable code flaws, as IBM widens its cyber work with OpenAI.
The move aims to help defenders turn faster vulnerability discovery into working fixes, as OpenAI broadens access to its cyber tools and partners.
The pilot could speed up vulnerability hunting across government systems, but it also leaves human teams to verify and fix each AI flag.
A financial services cloud was taken over in seconds in a test, highlighting how approved permissions can still let attackers reach full AWS control.
The certifications may help reassure UK customers and public-sector buyers as cyber breaches remain widespread and scrutiny of suppliers intensifies.
Developers can now pull thousands of hardened container images for free, as the company drops registration and expands access across its library.
Continuous attack testing aims to help customers spot exploitable gaps before criminals do, including misconfigurations hiding outside core systems.