OtherDark Reading·1 week ago

Sherlock Holmes Was the 'OG' Social Engineer

The crime solver wore disguises, spied on targets, and built intelligence networks long before modern-day tactics emerged. He has lessons for today's ethical- and unethical hackers.

OtherWeLiveSecurity·1 week ago

Are AI tutors safe for your kids?

AI tutors can offer useful support, but their quality and safeguards vary widely. Here’s what parents should check before handing one to a child.

OtherElastic Security Labs·2 weeks ago

Benchmarking the Agentic SOC: How we evaluate LLMs for security workflows

Elastic Security Labs has developed an evaluation framework designed to assess large language models specifically for security operations center workflows, moving beyond generic public leaderboards to test real-world performance. The framework grades models on their ability to execute security tasks including tool calls, execution traces, and blind judging across three key areas: Agent Builder, Attack Discovery, and automatic migration.

OtherBishop Fox·3 weeks ago

What Security Leaders Think About Frontier AI Models: Firsthand of Mythos

Frontier AI models are democratizing attack capabilities while amplifying the effectiveness of sophisticated threat actors, creating a widening security gap. Security leaders from Vista Equity, Cisco, and Bishop Fox discuss the practical implications of this shift, the necessary evolution of defensive technologies, and the timeline for defenders to regain parity against AI-enabled threats.

OtherKrebs on Security·1 month ago

Felons, Fraudsters Flog Offensive Cybersecurity Startup

A cybersecurity startup offering substantial payments for zero-day vulnerabilities is operated by individuals with convictions and a history of deceptive ventures, including fake intelligence firms and a defunct AI-based lobbying platform run under aliases. The operators are identified as far-right conspiracy theorists whose track record raises questions about how acquired vulnerabilities might be used and whether the startup's true intentions align with legitimate security research.

OtherCloudflare Blog·1 month ago

Unmasking the crawls with Attribution Business Insights

Cloudflare has launched Attribution Business Insights, a new dashboard designed to help website owners gain visibility into crawler behavior, activity levels, and potential business value. The tool aims to enable data-driven discussions about crawl resource costs and fair compensation between websites and crawlers.

OtherCloudflare Blog·2 months ago

Unlocking the Cloudflare app ecosystem with OAuth for all

Cloudflare has expanded OAuth access to all developers on its platform through Self-Managed OAuth, enabling broader integration capabilities within its app ecosystem. The company executed a zero-downtime migration of its core OAuth infrastructure to support this rollout, ensuring uninterrupted service during the transition.

OtherCloudflare Blog·2 months ago

Turning Cloudflare’s threat indicators into real-time WAF rules

Cloudflare has integrated Cloudforce One threat intelligence directly into its WAF, enabling customers to automatically block high-risk traffic based on threat indicators in real time. Security teams can now leverage new cf.intel fields to create rules that target specific threat actors and protect against attacks aimed at their industry vertical.

OtherCloudflare Blog·3 months ago

Post-quantum encryption for Cloudflare IPsec is generally available

Cloudflare has made post-quantum encryption support for IPsec generally available, implementing hybrid ML-KEM to protect against future quantum computing threats. The company has validated interoperability with Cisco and Fortinet, demonstrating practical compatibility across major networking vendors.