Multifactor Authentication Password Management Risk management Vulnerability

Passkeys are strong, but not untouchable

Researchers have uncovered new attack vectors that can undermine passkey authentication, challenging the idea that passwordless automatically means attack-proof. The attacks focus on weaknesses around the authentication flow and implementation, rather than breaking the underlying cryptography. Manipulation of WebAuthn processes, fallback mechanisms and compromised environments can potentially allow attackers to bypass or weaken passkey protection. […]

AI Cybersecurity Digital Identity Identity & Access Management Zero Trust

When AI agents break IAM then Identity becomes the fault line

AI agents challenge traditional IAM by acting at machine speed and scale, with unpredictable access patterns that human-centric security models weren’t designed for. Prompt injection, credential exposure and multi-agent delegation create attack paths that conventional authentication and authorization controls struggle to govern. Existing behavioral monitoring can be effectively blind to autonomous agents, while ownership, accountability, […]

Data Protection EIDAS Privacy Technology

Verifiable credentials & decentralized identity reach the “Slope of Enlightenment”

Gartner sees Verifiable Credentials (VCs) and decentralized identity as transformational technologies poised to reshape digital identity across industries. VCs enable standardized, secure and compliant data exchange between multiple parties at lower cost and higher speed. Instead of repeatedly proving identity, users can receive verified credentials once and reuse them cryptographically across services and transactions. Decentralized […]

Compliance Data Breaches Privacy

Massive MyDr cyberattack exposes medical data of nearly 19 million Poles

Hackers breached the MyDr medical platform, potentially compromising sensitive data belonging to nearly 19 million Polish patients. The platform is used by thousands of clinics and medical practices, dramatically increasing the scale and impact of the breach. The stolen information reportedly includes highly sensitive medical data, with politicians and other public figures among those affected. […]

Data Breaches Incident Response Social engineering

Levi Strauss hit by social engineering cyberattack

Apparel giant Levi Strauss & Co. recently disclosed a cybersecurity incident after attackers used targeted social engineering tactics to compromise three employees’ company computers. This initial breach allowed the attackers to gain access to internal files and successfully exfiltrate specific corporate information. Thanks to a rapid incident response, Levi’s managed to contain the intrusion effectively. […]

AI Compliance Information Security Risk management

Open-Source AI tools are strong on security, but Governance remains human

A new study maps 21 open-source AI risk tools against 32 risk categories, including Promptfoo, Garak, PyRIT, NeMo Guardrails and Langfuse. The ecosystem performs particularly well in AI testing, red teaming, content safety, data governance and post-deployment monitoring. But major gaps remain in board oversight, regulatory compliance, legal remedies and financial/market controls, areas software alone […]

Data Protection Data Rights Encryption Privacy Privacy Procedures and Policy

Apple vs. UK where encryption showdown enters a new chapter

Apple is challenging the UK government’s renewed demand for access to encrypted iCloud backups of British users through the Investigatory Powers Tribunal. The tech giant reiterates it will never build a backdoor into its products, arguing it would weaken security for everyone. The UK says lawful access is essential for tackling terrorism, serious crime, and […]

AI Cybersecurity Risk management

Africa’s cyber threat surge: where AI supercharges digital crime

Cybercrime across Africa is evolving into a highly organized, AI-enabled ecosystem, with ransomware, business email compromise (BEC), online scams, data breaches, and digital sextortion driving unprecedented financial and societal damage. AI is accelerating phishing, deepfakes, identity fraud, and cybercrime-as-a-service, while weak legislation, limited cyber capabilities, and fragmented cross-border cooperation continue to benefit criminals. Financial services, […]

Cybersecurity Information Security Risk management Vulnerability

ENISA’s new CRA Maturity Model is a practical roadmap for SME Cyber Resilience

The European Union Agency for Cybersecurity (ENISA) has released a practical Cyber Resilience Maturity Assessment Model to help SMEs prepare for the Cyber Resilience Act (CRA) before it becomes fully applicable in December 2027. The model focuses on five key domains: governance, secure-by-design risk management, vulnerability & patch management, product lifecycle management, and cybersecurity skills. […]