cybersecurity

Project Glasswing: Securing Critical Software for the AI Era Anthropic

Project Glasswing is a new collaborative initiative by Anthropic and major industry partners like Amazon, Apple, Google, and Microsoft to secure critical software using advanced AI capabilities. Leveraging Anthropic's frontier AI model, Claude Mythos Preview, which can autonomously identify and exploit software vulnerabilities, the project aims to proactively find and fix security flaws across vital infrastructure to defend against increasingly sophisticated cyber threats. This effort addresses the urgent cybersecurity challenges posed by AI-driven exploits and emphasizes broad industry cooperation and transparency to enhance global cyber resilience.

https://www.anthropic.com/glasswing

How to Be Less Busy and More Effective in Cyber

The article discusses how cybersecurity professionals often mistake busyness for effectiveness, highlighting a new framework inspired by MITRE ATT&CK that identifies common unproductive patterns like excessive meetings and fragmented attention that degrade performance. Experts emphasize focusing on meaningful outcomes rather than activities, managing work-life boundaries, and regularly assessing tasks and meetings to improve both security posture and personal well-being.

https://cisoseries.com/how-to-be-less-busy-and-more-effective-in-cyber/

Block the Prompt, Not the Work: The End of “Doctor No”

The article discusses how traditional enterprise security approaches, often characterized by rigid blocking of tools and websites (“Doctor No”), are now a liability because they push users to find invisible workarounds that bypass controls, creating blind spots and risks. It advocates for a shift toward session-level governance that secures data at the browser session and prompt level with agentless, real-time controls, enabling secure productivity rather than impeding it.

https://thehackernews.com/2026/04/block-prompt-not-work-end-of-doctor-no.html

Google Drive Ransomware Detection Now on by Default for Paying Users

Google has announced that its AI-powered ransomware detection feature for Google Drive is now generally available and enabled by default for all paying users with business, enterprise, education, and frontline licenses. The feature pauses file syncing upon detecting ransomware, alerts users and admins, and provides detailed file restoration instructions, significantly reducing ransomware impact on stored documents.

https://www.bleepingcomputer.com/news/security/google-drive-ransomware-detection-now-on-by-default-for-paying-users/

Longtime CISO (and Former Police Officer): ‘AI Can Help Protect Our Organizations’

Emily Heath, a longtime chief information security officer (CISO) and former police officer, highlights how AI is transforming cybersecurity by offering powerful new tools to protect organizations amid rapidly evolving threats. She emphasizes that today’s CISOs must integrate business understanding with technical expertise to manage cyber risks consciously, and she sees the AI era as a groundbreaking shift that enables stronger defense capabilities and collaborative innovation in the field.

https://deloitte.wsj.com/cio/longtime-ciso-and-former-police-officer-ai-can-help-protect-our-organizations-f5fc2dbe

Shadow AI Usage Statistics 2026: Latest Insights

Shadow AI—employees using unapproved AI tools at work—has become a widespread business risk, with over 80% of workers globally engaging in such use to boost productivity despite limited corporate governance. This unregulated adoption exposes organizations to significant security, compliance, and financial risks, including costly data breaches averaging $4.2 million, while many companies lack adequate policies or visibility to manage these challenges effectively.

https://sqmagazine.co.uk/shadow-ai-usage-statistics/

Shadow AI Solutions Need a Unified Security Approach

Shadow AI presents a significantly greater enterprise risk than the previous shadow IT challenges, as employees' unsanctioned use of generative AI tools leads to compliance, data leakage, and regulatory penalties risks. Fortinet's executive Russ Schafer highlights the need for unified security platforms incorporating agentic AI to reduce attack resolution times from hours to seconds, emphasizing governance, access management, and interconnected agent frameworks to maintain control and security in AI-driven environments.

https://siliconangle.com/2026/03/30/shadow-ai-needs-unified-security-approach-rsac26/

Teleport Report Finds Over-Privileged AI Systems Linked to Fourfold Rise in Security Incidents

A report by Teleport found that enterprises granting excessive access permissions to AI systems experience 4.5 times more security incidents than those restricting AI access, highlighting identity management's lag behind AI adoption. Based on interviews with 205 security leaders, the study shows that broad AI access correlates with higher incident rates, often due to static credentials and lack of automated governance controls, emphasizing the need for unified, machine-speed identity management to mitigate risks.

https://www.infoq.com/news/2026/03/teleport-ai-report/

Watch Your Words: Tim Brown’s Advice for CISOs

Tim Brown, former CISO of SolarWinds, shared insights at RSAC 2026 about the 2020 SolarWinds supply chain attack and his personal experience as the first CISO indicted in a civil lawsuit by the SEC for alleged fraud related to cybersecurity disclosures. Brown highlighted how excessive communication and misunderstood internal language during the ensuing SEC investigation led to legal challenges, emphasizing the critical need for clear communication policies and cautious internal messaging to prevent misinterpretation and legal risks in cybersecurity incident management.

https://www.techtarget.com/searchsecurity/feature/Watch-your-words-Tim-Browns-advice-for-CISOs

Why Cybersecurity’s Uncertainty Problem Is Getting Worse

Cybersecurity faces increasing uncertainty, with leading cryptographers unable to agree on the greatest threats. Paul Kocher, a cryptography researcher, warns that AI will accelerate the discovery of vulnerabilities in protocols and implementations, posing a significant threat to cybersecurity.

https://www.govinfosecurity.com/cybersecuritys-uncertainty-problem-getting-worse-a-31232

Scroll to Top