@SCMagazinei
iAccount based inUnited States
About this account
- Account based in
- United States
- Connected via
- Web
Account-level information from X, not a live location or the device used for a specific post.
The official Twitter feed for all things IT security. A CyberRisk Alliance Resource.
NYC
Joined November 2008
- Tweets101K
- Following1.8K
- Followers119K
- Likes1.3K
Pinned Tweet
Compromised MemOS packages on npm and PyPI spread cross-platform malware that steals developer credentials and may use stolen tokens to compromise more packages, @SocketSecurity reported. #cybersecurity #CISO #infosec bit.ly/4hdOXRQ
The @CISAgov is pushing the CVE program into a new “Quality Era” as #AI helps drive vulnerability volumes higher, focusing on better governance, data and actionable records. #cybersecurity #CISO #infosec bit.ly/3Ti2ej3
AI agents are expanding the attack surface faster than security teams can track them. Continuous discovery and runtime controls can help rein in shadow #AI without blocking adoption, @F5's Kunal Anand said in a recent blog post. #cybersecurity #infosec bit.ly/3T2jFUJ
#Ransomware groups are exploiting a critical TeamCity flaw, putting CI/CD pipelines at risk, the @CISAgov warned. Experts urge teams to patch, rotate credentials and check for compromise. #cybersecurity #CISO #infosec bit.ly/4hbeWcx
Compromised MemOS packages on npm and PyPI spread cross-platform malware that steals developer credentials and may use stolen tokens to compromise more packages, @SocketSecurity reported. #cybersecurity #CISO #infosec bit.ly/4hdOXRQ
At #Oktane26, @okta's Todd McKinnon says securing #AI agents will take industry-wide collaboration and announced the launch of an alliance to develop open standards for identity, visibility and control. #cybersecurity #CISO #infosec bit.ly/4yexqi9
APIs were built for predictable applications. #AI agents change the equation. Financial firms need stronger identity, permissions and guardrails before agents act at machine speed, says @viewtrade's Sergei Lishchenko in this op-ed. #cybersecurity #infosec bit.ly/4yalfD6
#AI risk isn’t just about rogue machines. Human attackers and reckless deployments are the threat. The answer, says @approov_io's Ted Miracco in this op-ed: accountability that makes failures costly. #cybersecurity #CISO #infosec bit.ly/4d3DstA
ShinyHunters claims it stole 2 TB of sensitive data on thousands of current and former FBI agents. The FBI is investigating, but the breach claims remain unconfirmed. #cybersecurity #CISO #infosec bit.ly/4dRqRKg
Just 13% of network segments with OT devices are OT-only, @Forescout found. Poor segmentation can give attackers a path from compromised IT or IoT devices into critical systems. #cybersecurity #CISO #infosec bit.ly/4yaVDWD
#AI agents move too fast for periodic access reviews. @okta is pushing identity governance toward real-time controls, just-in-time access and continuous threat detection. #cybersecurity #CISO #infosec bit.ly/4hcWJdc
.@TalosSecurity uncovered malware that lets four #AI models vote on its next move, showing how attackers could automate post-exploitation while reducing the need for human operators. #cybersecurity #CISO #infosec bit.ly/46AxQDD
Trump plans an “AI Force” and new AI czar as security experts call for guardrails, accountability and clearer rules for increasingly autonomous #AI systems. #cybersecurity #CISO #infosec bit.ly/4xFY6Yh
BREAKING: @Kiteworks is urging customers to shut down servers tonight after law enforcement warned of a possible imminent attack. No compromise has been confirmed. #cybersecurity #CISO #infosec bit.ly/4hMa8KL
The @CISAgov is pushing the CVE program into a new “Quality Era” as #AI helps drive vulnerability volumes higher, focusing on better governance, data and actionable records. #cybersecurity #CISO #infosec bit.ly/3Ti2ej3
#Ransomware groups are exploiting a critical TeamCity flaw, putting CI/CD pipelines at risk, the @CISAgov warned. Experts urge teams to patch, rotate credentials and check for compromise. #cybersecurity #CISO #infosec bit.ly/4hbeWcx
At #Oktane26, @okta's Todd McKinnon says securing #AI agents will take industry-wide collaboration and announced the launch of an alliance to develop open standards for identity, visibility and control. #cybersecurity #CISO #infosec bit.ly/4yexqi9
A @CISAgov KEV listing should trigger more than a patch, says @BlackDuck_SW's Collin Hogue-Spears in this op-ed. Teams should prioritize by exposure and impact, investigate for compromise and remediate the highest-risk flaws first. #cybersecurity #infosec bit.ly/4rnEnee
SC Media retweeted
As #AI agents move from information to action, financial infrastructure needs to evolve too.
Sergei Lishchenko explores the guardrails needed for agentic AI in his latest commentary for @SCMagazine.
Thank you to @snd_wagenseil for the opportunity.
hubs.ly/Q04ybjbv0
Law enforcement can disrupt hacker infrastructure, but OT security starts with the devices. Manufacturers and operators must build trust across the entire device lifecycle, says @OmniTrust_TLM's David Sequino in this op-ed. #cybersecurity #CISO #infosec bit.ly/4h87L4O