Sherlock Holmes Was the 'OG' Social Engineer
The crime solver wore disguises, spied on targets, and built intelligence networks long before modern-day tactics emerged. He has lessons for today's ethical- and unethical hackers.
The crime solver wore disguises, spied on targets, and built intelligence networks long before modern-day tactics emerged. He has lessons for today's ethical- and unethical hackers.
AI tutors can offer useful support, but their quality and safeguards vary widely. Here’s what parents should check before handing one to a child.
A 40-line CEL integration snapshots .npmrc files every 6 hours to catch cooldown removals. This post walks through the three ways we broke filestream before landing on snapshot semantics.
Learn why KuppingerCole named Microsoft a Leader in its Leadership Compass: Cloud Native Application Protection Platforms report. The post Microsoft named a Leader in the KuppingerCole Leadership Compass for Cloud Native Application Protection Platforms (CNAPP) appeared first on Microsoft Security Blog.
Elastic Security Labs has developed an evaluation framework designed to assess large language models specifically for security operations center workflows, moving beyond generic public leaderboards to test real-world performance. The framework grades models on their ability to execute security tasks including tool calls, execution traces, and blind judging across three key areas: Agent Builder, Attack Discovery, and automatic migration.
Frontier AI models are democratizing attack capabilities while amplifying the effectiveness of sophisticated threat actors, creating a widening security gap. Security leaders from Vista Equity, Cisco, and Bishop Fox discuss the practical implications of this shift, the necessary evolution of defensive technologies, and the timeline for defenders to regain parity against AI-enabled threats.
A cybersecurity startup offering substantial payments for zero-day vulnerabilities is operated by individuals with convictions and a history of deceptive ventures, including fake intelligence firms and a defunct AI-based lobbying platform run under aliases. The operators are identified as far-right conspiracy theorists whose track record raises questions about how acquired vulnerabilities might be used and whether the startup's true intentions align with legitimate security research.
Cloudflare has launched Attribution Business Insights, a new dashboard designed to help website owners gain visibility into crawler behavior, activity levels, and potential business value. The tool aims to enable data-driven discussions about crawl resource costs and fair compensation between websites and crawlers.
Cloudflare has expanded OAuth access to all developers on its platform through Self-Managed OAuth, enabling broader integration capabilities within its app ecosystem. The company executed a zero-downtime migration of its core OAuth infrastructure to support this rollout, ensuring uninterrupted service during the transition.
Cloudflare has integrated Cloudforce One threat intelligence directly into its WAF, enabling customers to automatically block high-risk traffic based on threat indicators in real time. Security teams can now leverage new cf.intel fields to create rules that target specific threat actors and protect against attacks aimed at their industry vertical.
Cloudflare has made post-quantum encryption support for IPsec generally available, implementing hybrid ML-KEM to protect against future quantum computing threats. The company has validated interoperability with Cisco and Fortinet, demonstrating practical compatibility across major networking vendors.