Penetration testing stories
Buyers of AI tools now have a benchmark to judge testing providers, as CREST's new standard targets gaps in assurance and due diligence.
Australian and New Zealand businesses face greater pressure to prove cyber controls work as the firms back continuous testing over periodic reviews.
Patching is urgent for Cudy WR3000 rev 2.0 routers, as public code shows how two flaws can let attackers gain root command execution.
The appointment gives UltraViolet Cyber a CISO who knows its operations from the client side and will steer AI governance and internal security.
Basic security lapses are leaving web apps exposed, with Barracuda saying routine misconfigurations account for most of 20 flaws per site.
Misconfigured models are giving attackers a fresh route into cloud systems, raising the risk of data theft and service compromise.
Owners of certain Cudy WR3000 routers face a root takeover risk unless they update firmware to patch two chained flaws.
In two days, the system uncovered more than 100 critical bugs in stolen code repositories, outpacing manual review and aiding incident response.
Unauthorised access could let attackers send arbitrary commands to spacecraft and instruments via NASA's AIT-GUI console, now fixed in version 2.5.2.
CyberCatch's continuous compliance tools will be folded into Datavault AI's data platforms if the all-cash deal wins approvals.
Realistic-looking security evidence can be fabricated when memory, simulation and model hallucinations blur provenance in AI workflows.
Approved defenders will gain broader access to cyber tools as the new tiered Daybreak programme adds GPT-5.6-Cyber for advanced security work.
Customers in Australia and New Zealand may now see Liverton Security as a lower-risk supplier after the Wellington firm won CREST ANZ membership.
Security teams should treat AI patching with caution after 53.9% of 6,080 model-generated fixes failed or introduced new flaws.
The combined group now serves more than 3,000 customers in 57 countries as Brinqa adds validation tools to close the remediation gap.
Stolen credentials can become an operational foothold within hours, leaving annual assessments too slow to catch the real attack paths.
The move gives the crypto exchange's security team AI help to hunt flaws in critical code as threats to financial infrastructure grow.
Customer demand is helping the Boston and London startup expand as enterprises race to secure AI systems against fresh attack risks.
Up to 85 government accounts were compromised in a four-day campaign that also reached nuclear and energy organisations, researchers said.
Indonesia's digital skills gap is fuelling demand for practical cyber and AI training, as firms struggle to hire workers.