Organizations embrace AI but lack proper governance over development

data governance

According to new research 93 percent of firms in the UK today use AI in some capacity, but most lack the frameworks to manage its risks and don’t integrate AI governance into their software development processes.

The study from Trustmarque shows only seven percent have fully embedded governance frameworks to manage AI risks. In addition a mere four percent consider their technology infrastructure fully AI-ready, and just eight percent have integrated AI governance into their software development lifecycle.

Continue reading

The impact of AI -- how to maximize value and minimize risk [Q&A]

Artificial-Intelligence-Convenience-at-the-cost-of-privacy

Tech stacks and software landscapes are becoming ever more complex and are only made more so by the arrival of AI.

We spoke to David Gardiner, executive vice president and general manager at Tricentis, to discuss to discuss how AI is changing roles in development and testing as well as how companies can maximize the value of AI while mitigating the many risks.

Continue reading

CrowdStrike one year on -- what have we learned?

CrowdStrike mobile

Tomorrow -- July 19th -- marks a year since the CrowdStrike outage, which saw major disruption to Microsoft systems around the world caused by a faulty security software update.

Whilst it made the headlines at the time what have been the long-term effects of the outage and what has the industry learned to prevent something similar happening in future?

Continue reading

The rise of the machine identity and what it means for cybersecurity [Q&A]

Robots machine identity

A report earlier this year highlighted the fact that machine identities now vastly outnumber humans.

This leads to a wider attack surface leaving many organizations vulnerable to cyberattack and loss of data. We spoke to Refael Angel, the co-founder and CTO of unified secrets and machine identity platform Akeyless Security, to find out more about the problem and how enterprises can protect themselves.

Continue reading

Millions of unsecured Wi-Fi networks are putting data at risk

Network wi-fi threats

New threat intelligence from Zimperium reveals over five million unsecured public Wi-Fi networks have been detected globally since the beginning of 2025, with a staggering 33 percent of users still connecting to these open networks, putting enterprise data at risk in the process.

Mobile devices are now a primary gateway to corporate data, but during travel, they’re also the most vulnerable,” says Kern Smith, VP of global solutions  at Zimperium. “Unsecured Wi-Fi, phishing disguised as travel alerts, and risky sideloaded apps are creating an ideal attack surface for cybercriminals -- especially in peak travel months.”

Continue reading

Cloaking-as-a-service set to reshape the phishing landscape

Cloaked figure

Imagine if hackers could give their scam websites a cloak of invisibility, showing one web page to regular people and a harmless page to security scans. Sneaky, huh?

According to new research from SlashNext that’s essentially what’s happening as cybercriminals start to leverage AI-powered cloaking services to shield phishing pages, fake stores, and malware sites from prying eyes.

Continue reading

The future of encryption in a post-quantum world

quantum computing

As quantum computing speeds edge closer to practical use, the ‘harvest now, decrypt later’ approach is already in motion with adversaries collecting encrypted data today, anticipating they'll be able to crack it tomorrow. But is enough being done to prevent it?

New research from Forescout highlights the urgent need for organizations to prepare for a future where quantum-capable adversaries can break widely used cryptographic protocols.

Continue reading

Application layer comes under threat

Risk threat readiness

A new report from Contrast Security exposes a growing crisis at the application layer as adversaries use AI to easily launch previously sophisticated attacks at scale.

Recent reports from Verizon (DBIR 2025) and Google Mandiant (M-Trends 2025) confirm what many security leaders already suspect: components of the application layer are among the most targeted and least protected part of the modern enterprise.

Continue reading

Outdated printer firmware can leave organizations open to attack

Woman using multi-function printer

In the past the printer has tended to be a pretty dumb device, but as they’ve gained more features and extra connectivity printers have become a target for attacks and potentially a way of gaining access to networks.

A new report from HP Wolf Security, based on global study of 800+ IT and security decision-makers (ITSDMs), highlighs the challenges of securing printer hardware and firmware.

Continue reading

Financial firms keen to use AI but their data isn't ready

Future artificial intelligence robot and cyborg.

A new study into AI readiness shows that while financial services firms are ready to adopt AI, they still have work to do in terms of improving data quality and modernizing systems.

The study from Indicum finds many financial services firms are hindered by legacy data systems and outdated IT infrastructure, which often lack the real-time processing and data quality capabilities required for effective AI deployment.

Continue reading

Ransomware surges 63 percent in Q2

Ransomware money

The second quarter of this year has seen a 63 percent increase in publicly disclosed ransomware attack volumes, with a total of 276 incidents compared to Q2 2024, according to the latest report from BlackFog.

This represents the highest number of attacks for this timeframe since the company began tracking ransomware volumes in 2020. All three months in the quarter set a new high compared with the same time period in previous years. June saw 113 percent increase with a total of 96 attacks. There was a 51 percent increase in April with a total of 89 attacks, and a 40 percent increase in May with 91 attacks.

Continue reading

Differing levels of access to AI create new inequalities

Artificial intelligence risk trap

A new survey of 4,000 knowledge workers across the UK, US, Germany, and Canada reveals that higher earners have disproportionate access to the latest AI tools and training, allowing them to reap AI's promised rewards.

In contrast, the study from The Adaptavist Group reveals that lower earners and women are being shut out from AI opportunities, which impacts their skill development, job satisfaction, and time savings, both personally and professionally.

Continue reading

What has AI done for us? Celebrating AI Appreciation Day

AI appreciation day

In the last few years artificial intelligence has found its way into more and more areas of our world and its progress shows no signs of slowing down.

Of course most things these days need a day to mark their achievements and today is AI Appreciation Day. So, what has AI done for us and what can we expect from it in future? Some industry experts gave us their views.

Continue reading

Is business logic abuse a growing problem for APIs? [Q&A]

Enterprise cyberattack

Tricking applications into altering their processes or surrendering information is a highly efficient way for attackers to carry out theft or fraud while minimizing the risk of detection.

We asked Mohammad Ismail, VP of EMEA at Cequence Security, to explain how this business logic abuse is carried out and why it’s becoming a growing problem.

Continue reading

Internet-exposed assets reveal industry vulnerability profiles

Internet web scraping

New analysis from CyCognito of over two million internet-exposed assets, across on-prem, cloud, APIs, and web apps, identifies exploitable assets across several key industries, using techniques that simulate real-world attacker behavior.

Techniques used include black-box pentesting using 90,000+ exploit modules, credential stuffing simulations, data exposure detection, etc. The study also used Dynamic Application Security Testing (DAST) to identify runtime web application vulnerabilities, as well as active vulnerability scanning of internet-facing services to detect CVEs, misconfigurations, and exposed assets.

Continue reading

Load More Articles