#1 Trusted Cybersecurity News Platform
Followed by 5.20+ million
The Hacker News Logo
Subscribe – Get Latest News

The Hacker News | Expert Insights — Index Page

When AI Writes the Code, Who Owns the Security Decisions?

When AI Writes the Code, Who Owns the Security Decisions?

Oct 05, 2026
AI is changing software development by compressing work that once took days into hours. Code can be generated, tested, refactored, and documented faster, allowing development teams to deliver functionality at a pace that was previously difficult to achieve.  That acceleration creates an important challenge for security teams.  AI-powered software development can accelerate innovation, but it can also introduce hidden vulnerabilities when security implications are not clearly understood. Watch this webinar series on AI threat realities and proactive security readiness to gain firsthand knowledge of what makes this AI threat unique, coupled with remediation guidance for long-term resilience:  This series also explores how organizations can securely adopt and implement AI at business speed without losing control of cyber risk.  The risk is not simply that AI-generated code can contain vulnerabilities. Human-written code has always contained vulnerabilities....
Your Employees Are Adopting AI Faster Than You Can See It

Your Employees Are Adopting AI Faster Than You Can See It

Oct 05, 2026
For the past decade, cybersecurity has been built on assuming the breach. AI is now pushing the industry to focus on what has to happen before one. Attackers can create, adapt, and launch attacks faster than before. Frontier AI can speed up vulnerability discovery and shorten the time to exploitation. At the same time, employees in nearly every department, along with developers, are bringing in chatbots, coding assistants, local models, agents, and AI integrations across the business. For most organizations, especially those with lean security teams, this adds up to AI security overload: machine-speed attacks, more internal exposure, and more tools competing for limited attention. How Is Internal AI Adoption Expanding the Attack Surface? Internal AI adoption widens the attack surface through tools, endpoints, integrations, and data connections that security teams may not know exist. AI comes in through web and desktop applications, browser extensions, developer environments, ...
What to Look for in an Insider Risk Management Platform

What to Look for in an Insider Risk Management Platform

Sept 28, 2026
Insider risk used to be the line item nobody fought for in the security budget. That's changed. The annual cost of insider incidents at $19.5 million per organization - and that number keeps climbing. Money like that has pulled a lot of vendors into this space, and "insider risk management" now covers a wide range of products: some are barely more than activity logs with a dashboard, others are genuinely sophisticated. The label doesn't tell you much on its own. As National Insider Threat Awareness Month comes to a close, it's worth looking at how we evaluate the technical landscape. Here's what actually separates a platform worth buying from one that just looks good in a demo. Does it actually see the whole picture? People don't cause problems in one place. They email something from a personal account, then upload a file to a cloud drive, then plug in a USB stick two weeks later. If your platform only watches one of those channels, you're not ma...
Enterprise Mobile AI: The Security Trade-Offs You Can't Ignore

Enterprise Mobile AI: The Security Trade-Offs You Can't Ignore

Sept 21, 2026
It feels like every AI conversation starts the same way: "We need an AI strategy!" Leadership wants the productivity gains. Employees want the convenience. And IT is expected to make it all happen—securely, of course. AI can summarize meetings, translate conversations, draft emails, and surface information in seconds. It promises to eliminate the kind of repetitive work that quietly steals hours from every week. But beneath all the excitement lies a question that needs more attention. Before AI can help you work smarter, it needs access to your information. That could be a calendar invite, next quarter's product roadmap, or IP. Think of AI like hiring the world's smartest intern. It can research, summarize, and help organize your otherwise disorganized meeting notes. In other words, you have to hand it your notebook full of your confidential information. The real question is what happens to that notebook after you've handed it over. Shadow AI isn't a...
Beyond ISO 27001: Building a Risk Program That Can Keep Up With AI

Beyond ISO 27001: Building a Risk Program That Can Keep Up With AI

Sept 21, 2026
There are two common mistakes you might be making with ISO 27001: treating certification as the finish line, and treating certification as proof that your controls will keep working.   Neither of these assumptions works well as AI becomes a bigger part of business operations.  ISO 27001 helps set up the right processes, ownership, controls, and risk methods for an organization. But AI systems now connect to more data, applications, and business processes, and they often act with less human oversight.  Meanwhile, businesses aren't slowing down.  OneTrust's latest research shows that 86% of organizations had at least one AI-related incident last year, but only 27% slowed or paused their AI rollout.  For CISOs and risk leaders, just showing that controls exist isn't enough anymore. Teams now need to check if those controls still work, what risks remain as things change, and who is responsible if risks go beyond what the organization can accept.  Th...
The Login Worked. That Was the Attack.

The Login Worked. That Was the Attack.

Sept 21, 2026
Session theft has been productized. The control most organizations still treat as the finish line does not touch it. Somewhere in your environment this quarter, an employee is going to authenticate correctly. Right password, right second factor, right device, no failed attempts, no alert. And an attacker is going to be inside that account seconds later, holding a session your identity provider considers entirely legitimate. That is the documented operating model of at least two commercial phishing services running right now, one of them a $320-a-month kit called NovaCookies, and it is what happened to a set of customers at one of the most security-literate software companies in the industry within the last month. What makes these attacks uncomfortable is not just their sophistication, but also that they are cheap, rented, and specifically engineered to produce a sign-in event that looks ordinary. The $320 Phishing Kit Selling Session Theft as a Service Researchers at Island di...
Why Deepfake Legislation Won't Save the 2026 Elections

Why Deepfake Legislation Won't Save the 2026 Elections

Sept 21, 2026
As the 2026 election cycle hits full stride with midterms approaching, the threats that voters, campaigns, and candidates are coming face-to-face with have completely changed from even two years ago. In 2024, most synthetic media and generative AI attacks were still unpolished, easy to spot, and deployed in isolated experiments.  Fast forward to today, and AI tools have grown up fast. What used to be scrappy proof-of-concept attacks are now slick, automated operations running at scale. That shift changes everything about what election security actually means. It's no longer just about locking down voter rolls or hardening voting machines. The real fight has moved upstream, into the channels where public trust gets shaped in the first place. If you're a security leader, a campaign staffer, or someone running digital infrastructure, the old perimeter-defense playbook won't cut it anymore.  For campaign security teams, that means the job has expanded well beyond protec...
How to Evaluate a Unified Security Platform Using a One-Incident Test

How to Evaluate a Unified Security Platform Using a One-Incident Test

Sept 14, 2026
A software dashboard can look unified even when the incident workflow remains fragmented. The fastest way to expose the difference between a unified platform and a unified dashboard is to run one representative incident from the first alert through containment to clean restoration, counting every console switch, every time information has to be manually carried from one tool into another, and every ownership handoff. Acronis Cyber Protect is designed to combine cyber security, backup, recovery and endpoint management within a unified operational model, helping in-house IT teams reduce the number of disconnected tools and workflows involved in detecting, responding to and recovering from incidents. Available capabilities depend on the selected edition, deployment model and licensed components. But integration should be demonstrated, not inferred from a feature list. Treat a proof of concept like an incident drill: compare the proposed solution with the current operational workflow...
Stop Trying to Control AI Behavior. Control What AI Can Reach

Stop Trying to Control AI Behavior. Control What AI Can Reach

Sept 14, 2026
You cannot reliably predict what an AI agent is going to do. That is a feature, not a flaw.  When things go well, developers can save a lot of time and effort. When it goes wrong, it can be disastrous. For example, in April 2026, a Cursor agent working on a staging task for PocketOS encountered a credential mismatch, found an unrelated Railway API token with blanket GraphQL permissions , and used it to delete the production database and its volume-level backups in nine seconds.  Unlike deterministic scripts, which produce fixed outcomes given the same input, we use agents because they can take a loosely defined objective and determine the steps themselves. An agent can read context, choose tools, query systems, revise its plan, and take a path nobody explicitly programmed. Security teams can decide afterward whether those actions were acceptable, but fully enumerating them in advance is not only antithetical to using an agent but also practically impossible. On the ot...
What Happens to Data Inside AI Agents

What Happens to Data Inside AI Agents

Sept 08, 2026
AI agents have become incredibly useful across many industries by their ability to reach inboxes, documents, and financial information, then search, summarize, or act on what they find. But that access creates a data-in-use problem: conventional encryption protects information in storage and transit, but an agent generally needs it decrypted in memory while processing it, where sensitive material can be exposed to application code, logs and debugging systems, infrastructure operators, or a compromised host. Conan Yu's work offers one practical response to that problem. He is co-founder of Rena Labs , which develops infrastructure for confidential AI training and inference using trusted execution environments (TEEs), hardware-isolated environments designed to limit the surrounding host's access while code and data are processed. Over roughly two years, Yu has worked across hardware and cloud TEE deployments, privacy-preserving financial-data analysis, and private AI inference. He a...
Why Are So Many Security Professionals Keeping Breaches Quiet?

Why Are So Many Security Professionals Keeping Breaches Quiet?

Sept 07, 2026
More than half of IT & cybersecurity professionals who experienced a breach in the past 12 months say they were told to keep it confidential, even when it was reportable. That finding comes from the 2026 Bitdefender Cybersecurity Assessment , a study Bitdefender has run for several years running. Disclosure rules have expanded significantly since the question was first asked in 2023, but the pressure to hide breaches continues. How Many Organizations Hide Breaches? Roughly half of 1,200 IT and security professionals surveyed reported a breach or security incident in the last 12 months. Of that group, 55.2% said they had been asked to keep a breach confidential even when it should have been disclosed. That's a snapshot. Here's the trendline: In 2023, 42.0% of respondents said they'd been asked to keep a breach quiet. By 2025 that number had climbed to 57.6%. In 2026 it settled back to 55.2%, which appears to be a plateau, not a reversal. IT & security pr...
Blind Spots and Backdoors: Practical Advice for Identity Risk Reduction

Blind Spots and Backdoors: Practical Advice for Identity Risk Reduction

Sept 07, 2026
Check your expanding identity attack surface Identity has become the new perimeter, and attackers know it. According to new research from CrowdStrike, 80% of modern cyberattacks are identity-driven , leveraging compromised credentials.  This substantial volume is driven by the widespread use of well-known directories such as Active Directory, and the vulnerabilities associated with compromised privileged accounts that are overprivileged or unmanaged, not network intrusion.  The explosion of privileged credentials and lack of adequate visibility or oversight can be attributed to growth, whether due to migration to the cloud, mergers and acquisition, the increased use of contractors, or simple organic business growth. This growth outpaces the ability to adequately govern the environment, leaving exploitable vulnerabilities.
The Economics of Dwell Time and Why AI Native SIEM Changes the Equation

The Economics of Dwell Time and Why AI Native SIEM Changes the Equation

Sept 07, 2026
Most security teams know that dwell time matters. The harder question is what to do about it. Dwell time is the period between an attacker gaining access and the security team containing the threat. During that window, a threat actor has time to learn the environment, steal credentials, move between systems, and reach sensitive data. For years, security teams have tried to reduce this window by adding more detection tools. The problem is that more alerts do not necessarily mean faster detection.  A recent industry incident response report puts the global median dwell time at 14 days, up from 11 the year before, quietly reversing a run of steady improvement that had held for close to a decade. The better way to think about it is as an operational problem. Two numbers matter most. Mean time to detect (MTTD) tells you how quickly the team recognizes a real threat, while mean time to respond (MTTR) tells you how quickly the team investigates and contains it. An AI native SIEM...
The Invisible Cybersecurity Challenge Transforming Advanced Power Grids: How Enterprise Asset Visibility Is Strengthening Critical Infrastructure Stability

The Invisible Cybersecurity Challenge Transforming Advanced Power Grids: How Enterprise Asset Visibility Is Strengthening Critical Infrastructure Stability

Sept 06, 2026
Why Cyber Asset Visibility Matters More Than Ever The California wildfire crisis reshaped the utility industry's approach to risk. Investigations into major wildfire events underscored the need for strong infrastructure, asset maintenance, operational oversight, vegetation management, and timely risk identification. Litigation and regulatory actions led utilities to invest billions in grid modernization, advanced monitoring, asset management, inspection technologies, and operational resilience. Suchismita Chatterjee, a cybersecurity product specialist who works on governance, risk, and compliance for a large U.S. electric utility, approached the problem from a different angle. "My work did not focus directly on wildfire prevention," she said. "It addressed an equally critical question." Working within the U.S. utility sector, Chatterjee has supported cybersecurity initiatives for North American Electric Reliability Corporation (NERC) regulated environmen...
April's $621 Million in DeFi Hacks Traced Mostly to Stolen Keys and Permissions

April's $621 Million in DeFi Hacks Traced Mostly to Stolen Keys and Permissions

Sept 03, 2026
April 2026 produced $621 million in decentralized finance hacks, the sector's worst month since March 2022, with 66% of the damage traced to compromised access controls rather than smart-contract flaws, according to Binance Research. The losses were not caused by code that failed. They were caused by permissions that ended up in the wrong hands. A Record Number of Incidents, and Almost None of the Damage Contracts have got harder to break, and that is the point. Years of audits and hardened engineering pushed the attack outward, onto the keys and credentials and the infrastructure a team logs into every morning. Most months bury that shift inside a single headline number. April did the opposite: its internal composition points the other way from its total. DL News counted 29 separate incidents across the month, the highest count it has recorded, and 24 of those came from ordinary code bugs. Those two dozen contract bugs produced about $42 million between them, which ...
The AI Agent in Your Stack Is a Privileged User. Most Small Companies Have No Way to Govern It

The AI Agent in Your Stack Is a Privileged User. Most Small Companies Have No Way to Govern It

Sept 01, 2026
Machine identities already outnumber human ones. For organizations without an identity function, the reachable control sits at the network layer. In access-control terms, an AI assistant that can read a customer database, move files between systems, or call an internal API is a user. It holds credentials, acts on resources, and if it is over-permissioned it becomes one more route into the network that nobody is watching. Small and midsize companies are wiring these agents into daily operations at speed. Very few have a way to decide what a given bot is allowed to touch. The scale is no longer arguable. Palo Alto Networks' 2026 Identity Security Landscape, drawn from a survey of more than 2,900 cybersecurity decision-makers, puts machine identities at 109 for every human. The same research found 96% of respondents reporting that human identities operate with access far beyond what their roles require. 109:1 machine identities to human identities, across 2,900+ organization...
The Missing Context Layer for AI Agents in Large Enterprise Codebases

The Missing Context Layer for AI Agents in Large Enterprise Codebases

Aug 31, 2026
As organizations deploy AI coding agents across large monorepos and microservices environments, a fundamental problem emerges: the model may be capable of making the change, yet still lack the organizational context required to make the right change safely. A developer can ask an AI coding agent to deprecate an API field, update an authentication flow, or modify a service interface. The agent can inspect the code available on the developer's machine and search for references. What it may not know is that the field is consumed by four other services across separate repositories, that one of those services belongs to another team, or that the same field eventually carries sensitive data into a third party integration. This is not simply a context window problem. It is a code context problem: providing AI agents with accurate, current, organization wide evidence about how software actually behaves. One emerging approach is to generate that evidence directly from source code us...
Shadow AI Is Now Hiding Inside Sanctioned AI Tools

Shadow AI Is Now Hiding Inside Sanctioned AI Tools

Aug 31, 2026
AI coding agents are already inside engineering organizations. The problem security teams need to solve is not only that AI-generated code might be vulnerable. You already have ways to catch that: code review, CI, SAST, dependency scanning, and production monitoring. The real problem is that tools such as Claude Code, OpenAI Codex, Claude Cowork, and GitHub Copilot are becoming extensible agent runtimes. Skills, plugins, hooks, repository instructions, and MCP servers can influence what the agent reads, which tools it selects, what commands it runs, and where enterprise data is sent. Most AI governance programs stop at approving the application. Very few can tell you everything that has been installed inside it. That is the supply-chain gap. What changed: Third-party components are no longer participating only at build or deploy. They are participating in the agent's decision loop. From coding assistant to agent runtime The first generation of coding assistants mainly...
The EU CRA Will Make You Report What It Hasn't Yet Made You Fix

The EU CRA Will Make You Report What It Hasn't Yet Made You Fix

Aug 31, 2026
In eleven days, on September 11, manufacturers of products with digital elements sold into the European Union have to tell a regulator within 24 hours of learning that a vulnerability in one of their products is being actively exploited, with a fuller account due at 72 hours. I have a decent idea what the next eleven days look like inside most of those companies, having spent close to thirty years watching software organizations get ready for a date on a calendar. There will be a spreadsheet of products and owners that somebody builds over a weekend, a notification template that goes to legal for review, probably a consultant on a two-week engagement. It will mostly work. By September 10, the majority of them will be able to file inside 24 hours, and they will be right to feel relieved about it, because filing on time is exactly what the regulation asks, and it is not a trivial thing to arrange. What I would gently point out is that almost none of them will come out of the exercise ...
Why Cloud Security Teams Need Risk Context, Not More Alerts

Why Cloud Security Teams Need Risk Context, Not More Alerts

Aug 26, 2026
Alerts in the context of cloud security can be useful, but they require the right procedures in place to effectively act on them. Cloud security posture management (CSPM) is becoming increasingly valuable as more businesses and organizations make use of services like SaaS and IaaS to power their routine operations. The problem is, as modern cloud environments become more complex, traditional alert-by-alert security management processes become less useful. While knowing what problems are out there is useful, without the right context, knowing which problems to prioritize is much harder. One potential solution is to seek out services that are adequately prepared for this issue, thus making the best CSPM vendor one that understands which weaknesses matter together. When Cloud Scale Makes Raw Data Less Useful Modern cloud environments are, in a word, expansive. As companies take on more data, such environments necessarily grow in response. These changes might take the form of infra...
Cybersecurity Resources