The European Union Agency for Cybersecurity (ENISA) has released a practical Cyber Resilience Maturity Assessment Model to help SMEs prepare for the Cyber Resilience Act (CRA) before it becomes fully applicable in December 2027. The model focuses on five key domains: governance, secure-by-design risk management, vulnerability & patch management, product lifecycle management, and cybersecurity skills. […]
Hugging Face disclosed a groundbreaking cyberattack in which an autonomous AI agent independently executed the entire intrusion—from initial compromise to privilege escalation and lateral movement. The attacker exploited vulnerabilities in the dataset-processing pipeline, performing more than 17,000 automated actions over a single weekend without direct human control. Although public models, datasets, and the software supply […]
The UK’s communications regulator, Ofcom, is demanding stronger age verification measures from social media platforms ahead of a proposed social media age ban. The regulator has launched an investigation into TikTok, questioning whether its current age assurance methods effectively protect minors. Ofcom is also investigating dozens of adult websites and working with Google and Bing […]
AI has evolved from a technology initiative into a board-level strategic and enterprise risk that demands continuous oversight, not periodic reviews. Boards must establish clear governance, accountability, and AI risk appetite while ensuring innovation is balanced with responsible use. Traditional cybersecurity alone is no longer sufficient, organizations must protect AI-driven decision-making, data, identities, and autonomous […]
Google warns quantum computing could soon break today’s encryption, threatening global digital security. Quantum machines aren’t powerful enough yet, but progress is accelerating faster than expected. A major risk is “store now, decrypt later,” where hackers collect data today to crack it in the future. Google plans to shift to post-quantum cryptography by 2029, urging […]
Indirect prompt injection is the most widespread and serious vulnerability in AI agents today, not just a theoretical risk. Research shows attacks can transfer across models and behaviors, revealing a fundamental weakness in how agents interpret context. More capable models aren’t safer, high performance often comes with equally high vulnerability. Attacks are especially dangerous because […]
The Future Jobs: Robots, Artificial Intelligence, and Digital Platforms in East Asia and Pacific by the World Bank explores how new technologies are reshaping jobs. Robots and automation increase productivity but can replace some routine manual jobs. AI can both replace and assist workers depending on the tasks involved. Dgital platforms are creating new flexible […]
China’s National Computer Network Emergency Response Technical Team warned that the open-source AI agent OpenClaw has weak default security settings that attackers could exploit to gain system control. Attackers can use prompt injection, embedding malicious instructions in web pages to trick the AI into leaking sensitive data. Researchers showed that features like link previews in […]
Clorox is suing IT provider Cognizant after a 2023 ransomware attack cost the company $380 million. The lawsuit claims Cognizant’s helpdesk handed over employee passwords to attackers posing as staff. No hacking skills were needed, just a phone call and a convincing story, Clorox alleges. Cognizant denies responsibility, stating it only offered limited helpdesk support. […]
Everyone is annoyed when coming up with, remembering and entering hard-to-guess passwords as shown in this video. 77.6% of people find passwords difficult to remember, while 89.2% have an easy-to-guess or retrieve password, with 8% of all passwords already leaked. ID Control helps you manage your usernames, passwords and other secrets (e.g. credit card details) […]
- 1
- 2

