CSO Online

CSO Online

Publication
1 followers

Publication for security executives focusing on cybersecurity management and risk.

The Gentlemen Are Coming for Your Files, and Then Your Network
NewsMay 29, 2026

The Gentlemen Are Coming for Your Files, and Then Your Network

Microsoft warned that the Gentlemen ransomware now employs a self‑propagating Go‑based encryptor that moves laterally across networks via SMB and harvested credentials before encrypting files. First observed in mid‑2025, the malware transitioned to a ransomware‑as‑a‑service model in September 2025, recruiting...

By CSO Online
Indian CERT Urges Firms to Contain Exploited Internet-Facing Flaws Within 12 Hours
NewsMay 28, 2026

Indian CERT Urges Firms to Contain Exploited Internet-Facing Flaws Within 12 Hours

India’s cybersecurity agency CERT‑In issued a 38‑page blueprint urging firms to patch, mitigate, or isolate exploited internet‑facing "crown jewel" systems within 12 hours where feasible. The framework sets one‑day remediation for critical external flaws, three days for critical internal vulnerabilities, and...

By CSO Online
Employees Are Unknowingly Inviting Tech Support Impersonators Into Firms, Says FBI
NewsMay 28, 2026

Employees Are Unknowingly Inviting Tech Support Impersonators Into Firms, Says FBI

The FBI’s latest Flash report warns that the Silent Ransom Group (also known as Luna Moth, Chatty Spider, UNC3753) has begun sending impostor IT support personnel into U.S. law firms. The attackers gain physical access, plug malicious USB devices into...

By CSO Online
The NSA, ‘Mythos’ and the Quiet Emergence of AI Cyber Doctrine
NewsMay 27, 2026

The NSA, ‘Mythos’ and the Quiet Emergence of AI Cyber Doctrine

The U.S. government and leading tech firms are rapidly integrating frontier AI models, such as Anthropic's Claude Mythos, into offensive cyber operations, shifting the threat landscape from tool‑centric to autonomous agent‑centric. Mythos demonstrated autonomous discovery and exploitation of thousands of...

By CSO Online
Microsoft Previews Automatic Device Isolation in Defender for Endpoint
NewsMay 27, 2026

Microsoft Previews Automatic Device Isolation in Defender for Endpoint

Microsoft is previewing an automatic device isolation feature in Defender for Endpoint’s auto attack disruption tool, allowing the platform to sever a compromised device’s network connections while keeping it linked to security services. The capability aims to halt lateral movement,...

By CSO Online
TrapDoor Malware Campaign Puts Developer Workstations in CISO Spotlight
NewsMay 26, 2026

TrapDoor Malware Campaign Puts Developer Workstations in CISO Spotlight

Researchers at Socket have identified a coordinated malware campaign, dubbed TrapDoor, that has published more than 34 malicious packages across npm, PyPI and Crates.io, affecting over 384 versions. The packages are engineered to harvest a wide range of developer secrets—including...

By CSO Online
Stop Treating AI Governance as a Review Layer. Make It Release Infrastructure
NewsMay 26, 2026

Stop Treating AI Governance as a Review Layer. Make It Release Infrastructure

The article argues that AI governance must move from a post‑deployment review layer to an integral part of the release pipeline. Traditional compliance models, which audit static software after it ships, fail because AI models and their data sources evolve...

By CSO Online
Security Experts Caution MFA Alone Can No Longer Stop Threat Actors
NewsMay 26, 2026

Security Experts Caution MFA Alone Can No Longer Stop Threat Actors

Security experts warn that multifactor authentication (MFA) alone can no longer stop phishing campaigns that steal Microsoft 365 OAuth tokens. New services such as EvilTokens and the FBI‑alerted Kali365 provide ready‑made, AI‑generated phishing kits that capture device‑code tokens, allowing attackers...

By CSO Online
AI Security Needs a Shift From Models to Systems, Researchers Argue
NewsMay 25, 2026

AI Security Needs a Shift From Models to Systems, Researchers Argue

Researchers from Google, UC San Diego, and UW‑Madison argue that enterprises must stop treating AI agents as trusted software and instead secure them as untrusted systems. Their new paper shows that model‑level defenses like prompt guardrails fail when agents access...

By CSO Online
As AI Speeds Coding, CVE Lite CLI Keeps Security Deliberately AI-Free
NewsMay 25, 2026

As AI Speeds Coding, CVE Lite CLI Keeps Security Deliberately AI-Free

The OWASP‑backed CVE Lite CLI offers a local‑first vulnerability scanner for JavaScript and TypeScript projects, analyzing npm, pnpm and Yarn lockfiles directly on a developer’s machine. By surfacing dependency risks at the moment code is written, it aims to replace...

By CSO Online
To Pay, or Not to Pay: 58% of CISOs Say They Would Pay the Ransom for Their Data
NewsMay 25, 2026

To Pay, or Not to Pay: 58% of CISOs Say They Would Pay the Ransom for Their Data

A survey of 750 CISOs in the US and UK shows 58% would pay a ransomware ransom to recover data. Law‑enforcement agencies in both countries warn against payment, citing no guarantee of data return and the encouragement of attackers. IDC...

By CSO Online
Google Leaks Details for Chromium Bug that Can Turn Browsers Into Bots
NewsMay 23, 2026

Google Leaks Details for Chromium Bug that Can Turn Browsers Into Bots

A long‑standing vulnerability in Chromium’s Service Worker and Background Fetch APIs allows malicious sites to keep a service worker alive indefinitely and run JavaScript across browser restarts. Reported three years ago by researcher Lyra Rebane, the flaw lets attackers hide background...

By CSO Online
Why Your AI Strategy Stops Where the PLC Starts: Hard Lessons From the OT Frontlines
NewsMay 22, 2026

Why Your AI Strategy Stops Where the PLC Starts: Hard Lessons From the OT Frontlines

C‑level executives are racing to embed AI in operational‑technology security, but the effort stalls because critical telemetry never reaches the models. Legacy devices—often an unpatched Windows 7 laptop that alone talks to protection relays—create a massive visibility gap. AI trained on...

By CSO Online
Identity as the Primary Attack Surface: What Modern Breaches Are Really Exploiting
NewsMay 22, 2026

Identity as the Primary Attack Surface: What Modern Breaches Are Really Exploiting

Modern breaches increasingly exploit identity rather than network perimeters. As enterprises migrate to cloud, SaaS, and hybrid work, authentication becomes the gatekeeper for financial systems, data, and admin controls. Attackers now rely on credential stuffing, OAuth consent phishing, and adversary‑in‑the‑middle...

By CSO Online
CSO Online | Pulse