A Shared Vision of Software Bill of Materials (SBOM) for Cybersecurity

CISA and NSA, alongside 19 global cybersecurity organizations, released guidance for a unified Software Bill of Materials (SBOM) to enhance software transparency, security, and risk management in the digital supply chain. This initiative promotes SBOM adoption, standardized implementations, and integration into security processes for better vulnerability management.

https://www.cisa.gov/resources-tools/resources/shared-vision-software-bill-materials-sbom-cybersecurity

GenAI Is Fueling Smarter Fraud, but Broken Teamwork Is the Real Problem

80% of U.S. companies faced socially engineered fraud, with many suffering financial losses exceeding $500,000. Misalignment between finance and security teams exacerbates risks, as attackers exploit communication gaps. Generative AI complicates fraud detection by enabling sophisticated attacks across systems. Recommendations for CISOs include fostering teamwork between finance and security, adopting GenAI-resilient defenses, and considering broader impacts of fraud beyond direct losses.

https://www.helpnetsecurity.com/2025/09/01/ciso-fraud-prevention-genai/

Here’s How Top CIOs Build Highly Effective AI Teams

Effective AI teams are crucial for organizations in response to rising demands for AI solutions. Key roles involve executive sponsors, end user engagement, product managers, and transformation engineering. Companies are focusing on staff training and may also outsource expertise. Leadership is essential for aligning AI initiatives with business goals, encouraging collaboration across teams, and fostering a culture of continuous learning.

https://www.cio.com/article/4040008/heres-how-top-cios-build-highly-effective-ai-teams.html

SIEM’s “Evil Secret”: Agents Are Not Always Needed

Modern SIEM solutions often rely on outdated endpoint agents that increase costs and operational complexities. While still necessary in some cases, there's a transition towards cloud-native, agentless solutions that can centralize data processing, simplify operations, and reduce burdens on endpoints. The shift acknowledges the end of on-prem resource constraints, urging organizations to develop a plan for gradual phasing out of agents while maintaining security and compliance. Embracing agentless architecture is increasingly seen as essential for future readiness and efficiency.

https://securitybrief.com.au/story/siem-s-evil-secret-agents-are-not-always-needed

CIISec: Most Security Professionals Want Stricter Regulations

69% of security professionals want stricter cybersecurity laws, per a CIISec survey. Major regulations like the Cyber Security and Resilience Bill make senior management liable for breaches. 91% believe boards should be accountable for incidents. The UK plans to ban ransomware payments for certain sectors and enforce mandatory incident reporting.

https://www.infosecurity-magazine.com/news/ciisec-security-professionals/

The CISO’s AI Cybersecurity Survival Guide

CISOs face AI's hype in cybersecurity, urging a 10-step checklist to assess AI solutions effectively—focused on real problems, data integrity, explainability, performance metrics, integration, security, scalability, vendor reliability, ethical compliance, and cost. This guide stresses that AI enhances security but should not replace human intuition, highlighting the need for critical evaluation over marketing hype.

https://builtin.com/articles/ciso-ai-cybersecurity-survival-guide

AWS CEO Says AI Replacing Junior Staff Is ‘dumbest Idea’

AWS CEO Matt Garman criticized the idea of replacing junior staff with AI, calling it the “dumbest thing” he's ever heard. He emphasized the importance of junior employees, noting they are affordable and capable of learning with AI tools. Garman believes that firing these workers would hinder future talent development. He also dismissed measuring AI's value by code quantity, suggesting quality is more important. Instead, he advocates for education that fosters critical thinking and problem-solving skills for future careers in a rapidly changing tech landscape.

https://www.theregister.com/2025/08/21/aws_ceo_entry_level_jobs_opinion/

AWS in 2025: The Stuff You Think You Know That’s Now Wrong

AWS has evolved significantly over nearly two decades, now featuring capabilities like live migration of EC2 instances, read-after-write consistency in S3, improved Lambda performance, and more reliable DynamoDB. Key changes include the removal of EC2-classic, adjustments in networking costs, introduction of cost-saving features, and enhanced IAM for authentication. Many legacy assumptions about AWS services are now outdated, reflecting a more durable and user-friendly platform.

https://www.lastweekinaws.com/blog/aws-in-2025-the-stuff-you-think-you-know-thats-now-wrong/

MIT Report: 95% of Generative AI Pilots at Companies Are Failing

MIT report: 95% of generative AI pilots fail in companies. Successful AI deployments depend on tailored solutions, partnerships, and proper resource allocation. Issues stem from flawed integration, learning gaps, and ineffective internal builds. Successful firms empower managers and prioritize tools that adapt over time.

https://fortune.com/2025/08/18/mit-report-95-percent-generative-ai-pilots-at-companies-failing-cfo/

Scroll to Top