International Cyber Expo International Cyber Expo

Featured

The latest collection of expert opinions, news analysis and featured contributions from the IT security community

AI Autonomy

A nationally representative survey of 2,000 UK adults, commissioned by cybersecurity PR agency Eskenzi PR and conducted by Censuswide, found that 84% would be comfortable giving an AI agent moderate, low or no control over their day-to-day lives. More than a third (34%) would not give one any control at all. AI agents can carry out tasks on a user’s behalf, potentially including booking travel, managing diaries, making purchases and accessing connected accounts. However, the...

Read moreDetails
Prime Big Deal Days: scammers stock up early as Amazon impersonation attacks nearly triple

For millions of shoppers, Prime Big Deal Days on 6 and 7 October are about grabbing a bargain before the festive rush. For cybercriminals, it is harvest season, and they've laid the groundwork well in advance. Two separate studies published ahead of the event point in the same direction. KnowBe4's Threat Lab says Amazon impersonation attacks surged by 188% between late August and September. Check Point Research, meanwhile, found that newly registered Amazon- and Prime...

Read moreDetails
Cybersecurity Awareness Month “cannot be the strategy”: why awareness must become a year-round capability

Every October, security teams roll out refreshed training, posters and phishing simulations. But according to Rob Gregory, CISO at Optiv, organizations that treat the month as the centerpiece of their awareness efforts are missing the point. “I believe Cyber Awareness Month (CAM) is a valuable amplifier and another reminder about the importance we all play in an organization's cybersecurity risk management program. However, it cannot be the strategy,” he says. “If companies use CAM as another training module, then...

Read moreDetails
A familiar face is no longer proof: rethinking social engineering defence for the deepfake era

Deepfakes have spent much of their short history being treated as a curiosity. According to Anne Cutler, cybersecurity expert at Keeper Security, that complacency is now a risk in itself. “For many people, deepfakes still feel like an internet novelty – a fake celebrity video, an altered image or an amusing example of what AI can create. That perception needs to change,” she says. “Deepfakes are increasingly relevant to personal cybersecurity because the same technology...

Read moreDetails
Ship fast, verify independently: keeping application security in step with AI-written code

AI coding assistants have transformed how quickly software can be built, but they have also intensified a long-running tension between development speed and security assurance. “There's an awkward reality coming to light in the cybersecurity world: developers are being told to ship faster at the exact moment security teams need more scrutiny over what gets shipped,” says Katie Paxton-Fear, Staff Security Advocate at Semgrep. “Most developers want to build securely, but they're also under real...

Read moreDetails
Shadow AI and the permissions problem: what to check before handing AI the keys

AI tools have moved from novelty to daily habit with remarkable speed, and for many people they are now as much a part of the working day as email. For Corey Nachreiner, CSO at WatchGuard Technologies, that makes a few simple questions more urgent than ever. “People are already using AI for everyday questions, work tasks, and highly personal conversations. Before you type, stop and ask: What am I sharing? Who might see it? What...

Read moreDetails
Cybersecurity Awareness Month: AI agents are users too, and they need governing like it

For more than two decades, Cybersecurity Awareness Month has centered on people: the employee who might click a malicious link, reuse a password or approve a suspicious login. This October, as the campaign runs under the banner “Don’t Make It Easy for Them”, identity specialists say the conversation must widen to include a fast-growing population of users that will never sit through a training module: AI agents. “Cybersecurity Awareness Month has traditionally focused on human...

Read moreDetails
RMM abuse behind 45% of endpoint incidents as Huntress publishes inaugural Tragic Quadrant

Huntress has published the Huntress Tragic Quadrant, a ranking of the cyber tactics its Security Operations Center (SOC) is detecting and shutting down most often, plotted against what the company calls "pucker factor": how close each tactic puts an organisation to major damage once it lands. Built on telemetry from more than 5 million endpoints and 15 million identities across nearly 300,000 organisations, the report includes several previously unpublished findings. Chief among them: in Q1...

Read moreDetails
AI Is Making Software Cheaper to Attack. Defenders Need to Change the Price

By Ansgar Dodt, VP Product Management for Software Monetization at Thales Not every piece of software is worth attacking. Traditionally, that has offered software vendors a degree of protection. Reverse engineering takes time, specialist expertise and persistence, forcing attackers to weigh the potential reward against the effort involved. However, AI is beginning to change that trade-off. Recent AI-powered security incidents, including cases disclosed by OpenAI and Anthropic, suggest this is not a one-off development but...

Read moreDetails
How much does the average UK SME spend on cybersecurity each year?

There is no single official figure for what a UK SME spends on cybersecurity today, because the UK Government stopped collecting detailed cybersecurity investment figures after its 2019 survey.  The last official benchmark found that micro and small businesses spent an average of £3,490 a year, although the median was only £200 and 33% reported spending nothing. This large gap shows how differently SMEs approach security.  A more useful way to look at the question in...

Read moreDetails
Page 1 of 106 1 2 … 106