Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

The AI notetaker you can't see in the participant list

For about three years, the governance question around AI meeting assistants had a convenient property: you could see them. The tool joined the call as a named participant. It appeared in the attendee list. Everyone in the meeting had at least the theoretical opportunity to object, and a security team reviewing an incident could reconstruct which meetings had been recorded by looking at who else was in them.

Cyber Risk Appetite Statements That Can Be Breached

Most cyber risk appetite statements cannot be breached. A board approves language about maintaining a low tolerance for disruption, the statement enters the policy library, and no observable event in the following three years violates it. A statement no event can cross is a value rather than a control. ‍ Making one testable requires four terms that get used interchangeably and mean different things, thresholds expressed in units something can exceed, and a defined response for when it does.

How Regulated Data Leaks Through AI, One Paste at a Time

A support coordinator has a difficult letter to write. The customer record is open in one tab, a consumer AI assistant in another, and the deadline is this afternoon. She selects the record, copies it, pastes it into the prompt box, and asks for a polite draft. Thirty seconds later she has a good letter and a regulatory problem, and nobody in the organization knows about either. ‍ The sequence below traces that single action through to its consequences.

What Is PCI DSS Compliance? the Essential Guide

You're reviewing payment flows, the bank has asked for proof, and the audit deadline suddenly feels real. The problem isn't usually that the team has done nothing, it's that nobody has turned day-to-day security work into evidence a card brand, acquirer, or assessor can use. PCI DSS compliance is where that gap gets exposed, and it's why security teams that already run SIEM, XDR, or EDR still get pulled into a separate compliance scramble.

How AI Is Accelerating Adversary Activity | Adam Meyers on Yahoo Finance

AI is changing the threat landscape and the pace defenders have to keep up with. Adam Meyers, Head of Counter Adversary Operations at CrowdStrike, joined Yahoo Finance to unpack key findings from the latest CrowdStrike Threat Hunting Report, including: Watch the full interview for Adam’s take on how AI is reshaping adversary activity and what defenders need to know.

AI Is Changing Cyberattacks on Hotels: Here's How to Stay Protected

Peak season brings challenges to the hospitality industry every year. Thousands of guests, temporary staff, vendors, and business partners interact daily with reservation systems, management platforms, mobile apps, and loyalty programs. That operational complexity makes hotels a particularly attractive target for cybercriminals. Artificial intelligence hasn't created a new problem for hotels, it is simply accelerating an existing one: identity-based attacks.

Cyber Threat Intelligence for the Insurance Sector: A Sector Under Two Kinds of Pressure

The insurance sector faces mounting pressure from both commercial growth and a persistent, evolving cyber threat landscape. This blog examines why insurers remain key targets, where their security gaps lie, and how cyber threat intelligence helps close the gap between ambition and resilience.

CrowdStrike Threat Hunts for Shell Command Obfuscation on VMware ESX

VMware ESX systems are a recurring target in ransomware campaigns. Threat groups including SCATTERED SPIDER, BlackBasta, Royal (aka BlackSuit), Akira, and the ESX-focused ransomware as a service (RaaS) platform shinysp1d3r have demonstrated that once an adversary reaches the hypervisor layer, they can rapidly encrypt virtual machines, disable logging, and cripple an entire data center.