#1 Trusted Cybersecurity News Platform
Followed by 5.20+ million
The Hacker News Logo
Subscribe – Get Latest News

The Hacker News | Expert Insights — Index Page

How to Evaluate a Unified Security Platform Using a One-Incident Test

How to Evaluate a Unified Security Platform Using a One-Incident Test

Sept 14, 2026
A software dashboard can look unified even when the incident workflow remains fragmented. The fastest way to expose the difference between a unified platform and a unified dashboard is to run one representative incident from the first alert through containment to clean restoration, counting every console switch, every time information has to be manually carried from one tool into another, and every ownership handoff. Acronis Cyber Protect is designed to combine cyber security, backup, recovery and endpoint management within a unified operational model, helping in-house IT teams reduce the number of disconnected tools and workflows involved in detecting, responding to and recovering from incidents. Available capabilities depend on the selected edition, deployment model and licensed components. But integration should be demonstrated, not inferred from a feature list. Treat a proof of concept like an incident drill: compare the proposed solution with the current operational workflow...
Stop Trying to Control AI Behavior. Control What AI Can Reach

Stop Trying to Control AI Behavior. Control What AI Can Reach

Sept 14, 2026
You cannot reliably predict what an AI agent is going to do. That is a feature, not a flaw.  When things go well, developers can save a lot of time and effort. When it goes wrong, it can be disastrous. For example, in April 2026, a Cursor agent working on a staging task for PocketOS encountered a credential mismatch, found an unrelated Railway API token with blanket GraphQL permissions , and used it to delete the production database and its volume-level backups in nine seconds.  Unlike deterministic scripts, which produce fixed outcomes given the same input, we use agents because they can take a loosely defined objective and determine the steps themselves. An agent can read context, choose tools, query systems, revise its plan, and take a path nobody explicitly programmed. Security teams can decide afterward whether those actions were acceptable, but fully enumerating them in advance is not only antithetical to using an agent but also practically impossible. On the ot...
What Happens to Data Inside AI Agents

What Happens to Data Inside AI Agents

Sept 08, 2026
AI agents have become incredibly useful across many industries by their ability to reach inboxes, documents, and financial information, then search, summarize, or act on what they find. But that access creates a data-in-use problem: conventional encryption protects information in storage and transit, but an agent generally needs it decrypted in memory while processing it, where sensitive material can be exposed to application code, logs and debugging systems, infrastructure operators, or a compromised host. Conan Yu's work offers one practical response to that problem. He is co-founder of Rena Labs , which develops infrastructure for confidential AI training and inference using trusted execution environments (TEEs), hardware-isolated environments designed to limit the surrounding host's access while code and data are processed. Over roughly two years, Yu has worked across hardware and cloud TEE deployments, privacy-preserving financial-data analysis, and private AI inference. He a...
Why Are So Many Security Professionals Keeping Breaches Quiet?

Why Are So Many Security Professionals Keeping Breaches Quiet?

Sept 07, 2026
More than half of IT & cybersecurity professionals who experienced a breach in the past 12 months say they were told to keep it confidential, even when it was reportable. That finding comes from the 2026 Bitdefender Cybersecurity Assessment , a study Bitdefender has run for several years running. Disclosure rules have expanded significantly since the question was first asked in 2023, but the pressure to hide breaches continues. How Many Organizations Hide Breaches? Roughly half of 1,200 IT and security professionals surveyed reported a breach or security incident in the last 12 months. Of that group, 55.2% said they had been asked to keep a breach confidential even when it should have been disclosed. That's a snapshot. Here's the trendline: In 2023, 42.0% of respondents said they'd been asked to keep a breach quiet. By 2025 that number had climbed to 57.6%. In 2026 it settled back to 55.2%, which appears to be a plateau, not a reversal. IT & security pr...
Blind Spots and Backdoors: Practical Advice for Identity Risk Reduction

Blind Spots and Backdoors: Practical Advice for Identity Risk Reduction

Sept 07, 2026
Check your expanding identity attack surface Identity has become the new perimeter, and attackers know it. According to new research from CrowdStrike, 80% of modern cyberattacks are identity-driven , leveraging compromised credentials.  This substantial volume is driven by the widespread use of well-known directories such as Active Directory, and the vulnerabilities associated with compromised privileged accounts that are overprivileged or unmanaged, not network intrusion.  The explosion of privileged credentials and lack of adequate visibility or oversight can be attributed to growth, whether due to migration to the cloud, mergers and acquisition, the increased use of contractors, or simple organic business growth. This growth outpaces the ability to adequately govern the environment, leaving exploitable vulnerabilities.
The Economics of Dwell Time and Why AI Native SIEM Changes the Equation

The Economics of Dwell Time and Why AI Native SIEM Changes the Equation

Sept 07, 2026
Most security teams know that dwell time matters. The harder question is what to do about it. Dwell time is the period between an attacker gaining access and the security team containing the threat. During that window, a threat actor has time to learn the environment, steal credentials, move between systems, and reach sensitive data. For years, security teams have tried to reduce this window by adding more detection tools. The problem is that more alerts do not necessarily mean faster detection.  A recent industry incident response report puts the global median dwell time at 14 days, up from 11 the year before, quietly reversing a run of steady improvement that had held for close to a decade. The better way to think about it is as an operational problem. Two numbers matter most. Mean time to detect (MTTD) tells you how quickly the team recognizes a real threat, while mean time to respond (MTTR) tells you how quickly the team investigates and contains it. An AI native SIEM...
The Invisible Cybersecurity Challenge Transforming Advanced Power Grids: How Enterprise Asset Visibility Is Strengthening Critical Infrastructure Stability

The Invisible Cybersecurity Challenge Transforming Advanced Power Grids: How Enterprise Asset Visibility Is Strengthening Critical Infrastructure Stability

Sept 06, 2026
Why Cyber Asset Visibility Matters More Than Ever The California wildfire crisis reshaped the utility industry's approach to risk. Investigations into major wildfire events underscored the need for strong infrastructure, asset maintenance, operational oversight, vegetation management, and timely risk identification. Litigation and regulatory actions led utilities to invest billions in grid modernization, advanced monitoring, asset management, inspection technologies, and operational resilience. Suchismita Chatterjee, a cybersecurity product specialist who works on governance, risk, and compliance for a large U.S. electric utility, approached the problem from a different angle. "My work did not focus directly on wildfire prevention," she said. "It addressed an equally critical question." Working within the U.S. utility sector, Chatterjee has supported cybersecurity initiatives for North American Electric Reliability Corporation (NERC) regulated environmen...
April's $621 Million in DeFi Hacks Traced Mostly to Stolen Keys and Permissions

April's $621 Million in DeFi Hacks Traced Mostly to Stolen Keys and Permissions

Sept 03, 2026
April 2026 produced $621 million in decentralized finance hacks, the sector's worst month since March 2022, with 66% of the damage traced to compromised access controls rather than smart-contract flaws, according to Binance Research. The losses were not caused by code that failed. They were caused by permissions that ended up in the wrong hands. A Record Number of Incidents, and Almost None of the Damage Contracts have got harder to break, and that is the point. Years of audits and hardened engineering pushed the attack outward, onto the keys and credentials and the infrastructure a team logs into every morning. Most months bury that shift inside a single headline number. April did the opposite: its internal composition points the other way from its total. DL News counted 29 separate incidents across the month, the highest count it has recorded, and 24 of those came from ordinary code bugs. Those two dozen contract bugs produced about $42 million between them, which ...
The AI Agent in Your Stack Is a Privileged User. Most Small Companies Have No Way to Govern It

The AI Agent in Your Stack Is a Privileged User. Most Small Companies Have No Way to Govern It

Sept 01, 2026
Machine identities already outnumber human ones. For organizations without an identity function, the reachable control sits at the network layer. In access-control terms, an AI assistant that can read a customer database, move files between systems, or call an internal API is a user. It holds credentials, acts on resources, and if it is over-permissioned it becomes one more route into the network that nobody is watching. Small and midsize companies are wiring these agents into daily operations at speed. Very few have a way to decide what a given bot is allowed to touch. The scale is no longer arguable. Palo Alto Networks' 2026 Identity Security Landscape, drawn from a survey of more than 2,900 cybersecurity decision-makers, puts machine identities at 109 for every human. The same research found 96% of respondents reporting that human identities operate with access far beyond what their roles require. 109:1 machine identities to human identities, across 2,900+ organization...
The Missing Context Layer for AI Agents in Large Enterprise Codebases

The Missing Context Layer for AI Agents in Large Enterprise Codebases

Aug 31, 2026
As organizations deploy AI coding agents across large monorepos and microservices environments, a fundamental problem emerges: the model may be capable of making the change, yet still lack the organizational context required to make the right change safely. A developer can ask an AI coding agent to deprecate an API field, update an authentication flow, or modify a service interface. The agent can inspect the code available on the developer's machine and search for references. What it may not know is that the field is consumed by four other services across separate repositories, that one of those services belongs to another team, or that the same field eventually carries sensitive data into a third party integration. This is not simply a context window problem. It is a code context problem: providing AI agents with accurate, current, organization wide evidence about how software actually behaves. One emerging approach is to generate that evidence directly from source code us...
Shadow AI Is Now Hiding Inside Sanctioned AI Tools

Shadow AI Is Now Hiding Inside Sanctioned AI Tools

Aug 31, 2026
AI coding agents are already inside engineering organizations. The problem security teams need to solve is not only that AI-generated code might be vulnerable. You already have ways to catch that: code review, CI, SAST, dependency scanning, and production monitoring. The real problem is that tools such as Claude Code, OpenAI Codex, Claude Cowork, and GitHub Copilot are becoming extensible agent runtimes. Skills, plugins, hooks, repository instructions, and MCP servers can influence what the agent reads, which tools it selects, what commands it runs, and where enterprise data is sent. Most AI governance programs stop at approving the application. Very few can tell you everything that has been installed inside it. That is the supply-chain gap. What changed: Third-party components are no longer participating only at build or deploy. They are participating in the agent's decision loop. From coding assistant to agent runtime The first generation of coding assistants mainly...
The EU CRA Will Make You Report What It Hasn't Yet Made You Fix

The EU CRA Will Make You Report What It Hasn't Yet Made You Fix

Aug 31, 2026
In eleven days, on September 11, manufacturers of products with digital elements sold into the European Union have to tell a regulator within 24 hours of learning that a vulnerability in one of their products is being actively exploited, with a fuller account due at 72 hours. I have a decent idea what the next eleven days look like inside most of those companies, having spent close to thirty years watching software organizations get ready for a date on a calendar. There will be a spreadsheet of products and owners that somebody builds over a weekend, a notification template that goes to legal for review, probably a consultant on a two-week engagement. It will mostly work. By September 10, the majority of them will be able to file inside 24 hours, and they will be right to feel relieved about it, because filing on time is exactly what the regulation asks, and it is not a trivial thing to arrange. What I would gently point out is that almost none of them will come out of the exercise ...
Why Cloud Security Teams Need Risk Context, Not More Alerts

Why Cloud Security Teams Need Risk Context, Not More Alerts

Aug 26, 2026
Alerts in the context of cloud security can be useful, but they require the right procedures in place to effectively act on them. Cloud security posture management (CSPM) is becoming increasingly valuable as more businesses and organizations make use of services like SaaS and IaaS to power their routine operations. The problem is, as modern cloud environments become more complex, traditional alert-by-alert security management processes become less useful. While knowing what problems are out there is useful, without the right context, knowing which problems to prioritize is much harder. One potential solution is to seek out services that are adequately prepared for this issue, thus making the best CSPM vendor one that understands which weaknesses matter together. When Cloud Scale Makes Raw Data Less Useful Modern cloud environments are, in a word, expansive. As companies take on more data, such environments necessarily grow in response. These changes might take the form of infra...
Why Threat Intelligence Needs OT Context to Protect Critical Infrastructure

Why Threat Intelligence Needs OT Context to Protect Critical Infrastructure

Aug 24, 2026
Cybersecurity teams have no shortage of threat data: New vulnerabilities are disclosed, malware is discovered, attack campaigns are analyzed, and manufacturers, CERTs, and security agencies continuously publish indicators of compromise (IoCs), security advisories, and other technical information. For operators of critical infrastructure, however, collecting this information is not even the most challenging part. Security teams still need to determine whether a threat is relevant to their environment, which assets may be affected, and what the observed activity actually means in the context of an operational network. In the energy sector, that requires knowledge extending beyond enterprise security and into the protocols, equipment, and processes that keep power systems operating. A suspicious packet in an office network is one thing. Understanding whether communication between an engineering workstation and a protection device using IEC 61850 represents expected maintenance activi...
Why AI Teams Need Verifiable Search Data Instead of Black-Box Signals

Why AI Teams Need Verifiable Search Data Instead of Black-Box Signals

Aug 24, 2026
Many AI systems depend on input signals that teams cannot fully inspect or explain. These opaque sources reduce visibility into the data paths that influence model behavior. Engineers lose provenance records, limiting the diagnosis of abnormal outputs. This complicates the work of security teams that need clear records of what influenced a model at any point in time. Verifiable search data offers a stable alternative. It gives teams an input they can examine, store, and reproduce in controlled conditions. Engineers can compare model behavior against information that was publicly accessible at the time a result was produced, rather than depend on hidden internal signals. This article outlines why verifiable search data gives AI and security teams the clarity required to maintain operational control. Why Traceability Matters in AI Systems Traceability lets teams follow an input from its origin through each processing step. When every stage can be inspected, engineers can review...
Why Your AI Developer Tools Might Be Your Biggest Security Risk

Why Your AI Developer Tools Might Be Your Biggest Security Risk

Aug 17, 2026
Artificial intelligence is everywhere now. From automated code completion to autonomous infrastructure management, AI tools and AI agents help DevOps speed up deployment cycles and change how development teams operate in general. At the same time, this rapid adoption of AI has created a reality that is hard for security teams to ignore: as with the growth of AI capability within the software development life cycle, the attack surface also grows. In 2025, there were 68 AI-related incidents recorded across major DevOps platforms according to the 2026 DevOps Threats Unwrapped Report . In the first half of 2026, the number of AI-related incidents visibly grew — research from GitProtect Lab tracked 84 AI-related incidents in six months alone. Thus, comparing the first half of 2026 to the same period in 2025 shows that AI-related incidents in development environments have nearly tripled. What do DevOps and DevSecOps say about AI incidents in general? According to GitProtect Lab 's surve...
The Long Road From Pentest Finding to Verified Fix

The Long Road From Pentest Finding to Verified Fix

Aug 17, 2026
Penetration testing is intended to help organizations identify weaknesses before attackers can exploit them. Once testing ends, findings must be documented, reviewed, formatted, delivered, assigned, tracked, remediated, and eventually retested. In many organizations, each of those steps happens in a different system and depends on a manual handoff. Testers work in one set of tools. Reports are assembled in Word or spreadsheets. Findings are delivered through PDFs. Security teams recreate them in ticketing systems. Engineering teams update remediation status somewhere else. Retesting is coordinated through email or meetings. By the time the right owner receives the information needed to act, days or weeks may have passed. At PlexTrac , we see this as one of the largest operational gaps in modern offensive security: organizations have invested in finding vulnerabilities, but the process surrounding the pentest has not kept pace. The next phase of pentest modernization is removin...
Identity Governance Wasn't Built for Breaches That Happen in Hours

Identity Governance Wasn't Built for Breaches That Happen in Hours

Aug 17, 2026
Identity is the attack surface now. Most identity governance and administration (IGA) programs still run on manual certifications, static role models, and quarterly reviews that go stale the day someone signs off on them. That's not a compliance inconvenience for a CISO. It's a structural gap. Attackers don't wait for the next recertification cycle, so identity risk detection can't either. Autonomous identity governance turns IGA from a periodic, human-driven exercise into something that runs continuously, watching real usage, learning what normal looks like, and acting on deviations before they turn into incidents. That autonomy applies across every identity and entitlement placed under governance, continuously reassessing access as usage, roles, and risk signals change. Three things are colliding to force this shift. Identity sprawl across cloud and SaaS environments has grown past what manual reviews can realistically handle, service accounts and non-human identi...
Evaluating the Real Impact of an AI SOC Agent in 2026

Evaluating the Real Impact of an AI SOC Agent in 2026

Aug 17, 2026
An AI SOC agent promises faster triage, fewer missed alerts, and analysts freed from repetitive work. This guide examines what an AI SOC Agent actually delivers, the prerequisites for AI-driven SOC automation, how to test explainability, and the practical benchmarks security leaders should use before signing a contract. Why your SOC needs an AI SOC agent today Most security operations centers are not failing because they lack detection technology. They are failing because the volume of signals produced by that technology exceeds what a human team can review with any consistency. A mid-sized organization routinely generates tens of thousands of alerts per week across endpoint, identity, cloud, and network telemetry, and analyst attention is the scarcest resource in the building. The pressures forcing the conversation Alert volume outpacing headcount: Detection coverage keeps expanding while SOC staffing stays flat or shrinks. Attacker speed: Credential abuse and ransomw...
Agents Work Everywhere Now. Governance Has to See Everywhere Too.

Agents Work Everywhere Now. Governance Has to See Everywhere Too.

Aug 10, 2026
A security leader at a global finance company told us recently that his team discovered three times more AI tools running in their environment than IT had approved. Nobody had smuggled them in. Employees had simply pointed agents at their work, and the agents brought their own tools with them. That conversation is not unusual. It is the conversation. Over the past year, in customer discussions across finance, healthcare, manufacturing, and government, the same four struggles come up so consistently that we have started treating them as the shape of the problem itself. Every company effectively hired a second workforce this year, human workers and agentic workers side by side, and the agentic workers never went through onboarding. No handbook, no scoped credentials, no acceptable-use policy they can actually read. Here is what teams are struggling with, what our research says about why, and what closing each gap actually requires.
Cybersecurity Resources