What’s Your Blast Radius Worth? – Podcast

Microsegmentation. Poland’s cyberwar. AI-powered attackers. The blast radius that decides your cyber insurance premium. New podcast episode. Poland absorbed 270,000 cyberattacks in the past year. That’s 2.5 times more than the year before, according to Deputy Digital Affairs Minister Paweł Olszewski. Russia tripled its military intelligence resources aimed at Polish targets in 2025, per Digital … Read more

Angsty Teenagers With Privileged Access: Beazley Security’s Francisco Donoso On Agentic AI Risk

An OpenAI model broke out of a safety test this month and hacked Hugging Face on its own. Boards everywhere now ask the same question. Are we ready for that agentic AI risk? Francisco Donoso offers a homelier frame. Treat your AI agents like teenagers. Donoso is Chief Product and Technology Officer at Beazley Security, … Read more

The AI Agents Got Out. The Bill Has No Name On It.

Somewhere in mid-July, two OpenAI models decided the sandbox was optional. Reporting indicates they exploited a previously unknown flaw, walked out onto the open internet, and broke into the production systems of Hugging Face, the AI model-hosting platform. OpenAI called it an “unprecedented cyber incident, involving state-of-the-art cyber capabilities.” Some might translate that as: our … Read more

Contrast Launches CVE Shield As AI Turns The Patch Backlog “Rotten”

Contrast Security has launched CVE Shield, a runtime tool that blocks exploitation of known vulnerabilities inside live applications. A free tier arrives August 3, with a waitlist open now. The pitch is timing. AI systems now convert public CVEs into working exploits faster than most teams can patch. In April, Anthropic reported its Claude Mythos … Read more

Dangling DNS Takeover Risk: Inside Silent Push’s “Danglegeddon” Study

There are billions of subdomains on the internet pointing to nothing. Silent Push calls them “billions of forgotten, abandoned, and misconfigured subdomains.” Most sit quietly. None of them look dangerous. Silent Push just proved how wrong that assumption is. The threat intelligence firm ran a simulation across four sectors: government, banking, automotive manufacturing, and pharmaceuticals. … Read more

Burp AT Puts Agentic AI on the Pentest. PortSwigger Keeps It Caged.

The tool lets an AI agent hunt bugs on live targets. A human still signs the report. PortSwigger launched Burp AT today. The tool brings agentic AI into Burp Suite, the web security platform used by more than 90,000 security professionals, per the company. Agents can now form a hypothesis, act through tools, and choose … Read more

×