cybersecurity

AI Agents Can Leak Company Data Through Simple Web Searches

AI agents can inadvertently leak sensitive company data via web searches. Research shows attackers can manipulate webpages with hidden instructions, leading agents to retrieve and transmit confidential information without users realizing it. The model's normal operations mask the attack, which does not require direct manipulation or special access. Varied success rates across 1,068 attack attempts highlight that training practices matter more than model size. Existing defenses often overlook this indirect method, emphasizing the need for robust security measures and monitoring. Organizations must treat AI agents as risky software and establish strict control over their operations.

https://www.helpnetsecurity.com/2025/10/29/agentic-ai-security-indirect-prompt-injection/

Carding and How Businesses Can Prevent It

  • Carding Definition: Carding refers to the illegal use and sale of stolen credit card data, which enables unauthorized purchases and facilitates identity theft.
  • Theft & Fraud Tactics: Common methods include phishing, hacking, skimming, and bot-based attacks; dark web markets play a central role.
  • Business Defenses: Effective prevention uses AI fraud detection, encryption, transaction monitoring, and customer alerts.
  • Business & Customer Impact: Carding results in financial losses, reputational damage, increased costs, and emotional distress for victims.
  • Tools & Trends: Advancements in fraud and security address evolving tactics with AI and industry best practices.

https://stripe.com/en-fi/resources/more/what-is-carding-how-this-type-of-fraud-works-and-how-businesses-can-prevent-it

How Do We Measure Our Defenses Against Social Engineering Attacks?

CISO Series discusses measuring defenses against social engineering attacks, particularly phishing. Hosts David Spark and Mike Johnson question the effectiveness of using phishing click rates as a metric, suggesting they are easily influenced and insufficient. Experts emphasize the need for a holistic approach, focusing on response actions post-click and measuring susceptibility across various channels, not just email. They highlight the importance of a layered security strategy and the evolving sophistication of attacks facilitated by advances like AI. Recommendations include enhancing awareness training and developing contextual metrics to better assess organizational security.

https://cisoseries.com/how-do-we-measure-our-defenses-against-social-engineering-attacks/

The One Cybersecurity Shift Every Business Needs to Make Right Now

As remote work and cloud platforms have dissolved traditional network perimeters, businesses must shift cybersecurity strategies from guarding networks to focusing on user identity, visibility, and smarter authentication. Relying on Zero Trust models and strong authentication methods is essential, while managing risk by controlling devices and allowing productivity tools under specific safeguards. Security now revolves around controlling who has access, not simply defending the network itself.

https://www.entrepreneur.com/science-technology/the-cybersecurity-shift-every-business-needs-to-make-today/497891

Ransomware Hackers Look for New Tactics Amid Falling Profits

Ransomware profits are falling, forcing cybercriminals to adopt new tactics and target different victims.

  • The percentage of victims paying ransoms dropped below 25% for the first time, and ransom amounts decreased sharply.
  • Larger organizations are less likely to pay ransoms, leading to fragmentation of the ransomware landscape and more attacks on midsize organizations.
  • New tactics include:
    • Recruiting or bribing insiders, especially at large, high-value organizations.
    • Social engineering helps desks and launches supply chain attacks.
    • Callback phishing, manipulating victims through real-time phone negotiation.
  • Sending personalized ransom demands using compromised or fake email accounts.
  • Smaller ransomware groups are more active, resulting in unpredictable targets, including regions and sectors previously less affected.
  • Enterprises are urged to strengthen their insider threat programs amid increasing efforts by hackers to recruit insiders.

https://www.databreachtoday.com/ransomware-hackers-look-for-new-tactics-amid-falling-profits-a-29867

Around 70 Countries Sign New UN Cybercrime Convention—but Not Everyone’s on Board

Around 70 countries signed a UN Cybercrime Convention aiming to combat cybercrime through global cooperation. The treaty requires 40 states to ratify it to become law, yet the US is not among signatories, citing ongoing review. There are concerns about privacy erosion, expanded surveillance powers, and potential misuse by authoritarian governments. Critics argue the treaty's vague provisions could hamper legitimate cybersecurity efforts and lack adequate protections for human rights and due process.

https://www.malwarebytes.com/blog/news/2025/10/around-70-countries-sign-new-un-cybercrime-convention-but-not-everyones-on-board

How Evolving Regulations Are Redefining CISO Responsibility

CISOs face growing personal and criminal liability as cyberattacks targeting vulnerabilities in IoT and OT devices increase. Global regulations now require stricter cyber risk management, transparency, and compliance, with 20% of breaches in 2025 linked to device vulnerabilities. CISOs are expected to provide accurate asset inventories, honest reporting, prompt breach disclosure, and the management of third-party risks. Organizations are updating policies, boosting legal support, and enhancing security oversight to adapt.

https://www.csoonline.com/article/4079450/how-evolving-regulations-are-redefining-ciso-responsibility.html

70% of CISOs Say Internal Conflicts More Damaging Than Cyberattacks

70% of CISOs find internal conflicts more detrimental than cyberattacks during crises. Tensions and unclear roles hinder incident responses, exacerbated by perceived operational slowdowns caused by security measures. To improve relations, CISOs should highlight security's value to revenue and align their strategies with business goals.

https://www.csoonline.com/article/4079876/70-of-cisos-say-internal-conflicts-more-damaging-than-cyberattacks.html

5 Tips for a Healthier Cybersecurity Program

5 tips for stronger cybersecurity:

  1. Implement MFA: Protect all services with multi-factor authentication.
  2. Patch Software: Regularly update software to prevent vulnerabilities.
  3. Test Backups: Ensure effective recovery processes against ransomware.
  4. Train Employees: Conduct phishing simulations and security awareness training.
  5. Assess AI Usage: Create policies for AI use to avoid data leaks.

Invest in resilience to enhance security posture.

https://www.security.com/feature-stories/5-tips-healthier-cybersecurity-program

The 10 Biggest Issues CISOs and Cyber Teams Face Today

Important topics for cybersecurity leaders include securing AI infrastructure, rising AI-enabled threats, budget constraints, and preparing employees against sophisticated scams. They face challenges with an expanding threat landscape, limited budgets, prioritizing tasks, risk management, and the emergence of quantum computing threats.

https://www.csoonline.com/article/4077442/the-10-biggest-issues-cisos-and-cyber-teams-face-today-2.html

Scroll to Top