CSO Online

CSO Online

Publication
1 followers

Publication for security executives focusing on cybersecurity management and risk.

The Cyber Perimeter Was Never Dead. We Just Abandoned It.
NewsMar 13, 2026

The Cyber Perimeter Was Never Dead. We Just Abandoned It.

The article argues that the network perimeter is not dead, but has been neglected as organizations focus on cloud‑native identities. Federal actions—FBI’s Winter SHIELD operation and CISA’s BOD 26‑02 directive—force a hard look at weak authentication, excessive privileges, and unsupported edge...

By CSO Online
AWS Expands Security Hub for Multicloud Security Operations
NewsMar 11, 2026

AWS Expands Security Hub for Multicloud Security Operations

Amazon Web Services has broadened AWS Security Hub into a centralized multicloud security operations platform. The enhanced service aggregates risk signals from AWS and third‑party tools, delivering near‑real‑time analytics, automated analysis, and prioritized insights across multiple cloud providers. New capabilities...

By CSO Online
Threat Intelligence by ESET Is a Game Changer
NewsMar 10, 2026

Threat Intelligence by ESET Is a Game Changer

ESET reports a mixed security outlook for India, with overall threat detections falling 12 % YoY while ransomware incidents jumped 70 % between late‑2024 and early‑2025. Phishing remains the most common attack vector, and AI‑driven deep‑fake and ransomware threats are intensifying. The...

By CSO Online
The OT Security Time Bomb: Why Legacy Industrial Systems Are the Biggest Cyber Risk Nobody Wants to Fix
NewsMar 10, 2026

The OT Security Time Bomb: Why Legacy Industrial Systems Are the Biggest Cyber Risk Nobody Wants to Fix

Legacy operational technology (OT) in energy and pharma plants still relies on outdated operating systems like Windows XP and insecure protocols such as Modbus, creating a hidden cyber‑risk. While IT teams adopt zero‑trust and AI‑driven defenses, OT environments remain unpatched...

By CSO Online
OpenAI to Acquire Promptfoo to Strengthen AI Agent Security Testing
NewsMar 10, 2026

OpenAI to Acquire Promptfoo to Strengthen AI Agent Security Testing

OpenAI announced it will acquire Promptfoo, an AI testing startup whose tools detect adversarial prompts, jailbreak attempts, and safety violations in large language model applications. Promptfoo’s technology, already deployed by more than a quarter of Fortune 500 firms, will be integrated...

By CSO Online
When AI Safety Constrains Defenders More than Attackers
NewsMar 10, 2026

When AI Safety Constrains Defenders More than Attackers

Security teams are encountering AI safety guardrails that block legitimate defensive tasks such as threat modeling, phishing simulations, and red‑team code generation. Research shows open‑weight models can be bypassed in multi‑turn attacks with success rates up to 93%, while enterprise‑approved...

By CSO Online
Challenges and Projects for the CISO in 2026
NewsMar 6, 2026

Challenges and Projects for the CISO in 2026

CISOs face a 2026 threat landscape where AI‑driven attacks are faster, cheaper, and more credible, forcing a shift from prevention to rapid response. Experts warn that a growing internet monoculture and quantum decryption threats will magnify breach impact. Identity verification...

By CSO Online
The 10-Hour Problem: How Visibility Gaps Are Burning Out the SOC
NewsMar 4, 2026

The 10-Hour Problem: How Visibility Gaps Are Burning Out the SOC

According to a Forrester Consulting study commissioned by NETSCOUT, 61% of SOC analysts spend more than ten hours each week in the analysis phase due to fragmented visibility. Inadequate network analysis and visibility (NAV) forces analysts to manually stitch logs...

By CSO Online
Anthropic AI Ultimatums and IP Theft: The Unspoken Risk
NewsMar 4, 2026

Anthropic AI Ultimatums and IP Theft: The Unspoken Risk

Anthropic’s Claude AI is caught between a massive Chinese extraction campaign and a U.S. government ban that forces the model out of federal systems. China‑based firms generated over 16 million interactions to map Claude’s reasoning, tool use and coding abilities, while...

By CSO Online
How to Know You’re a Real-Deal CSO — and Whether that Job Opening Truly Seeks One
NewsMar 4, 2026

How to Know You’re a Real-Deal CSO — and Whether that Job Opening Truly Seeks One

Recruiters struggle to find genuine Chief Security Officers (CSOs) because the role now demands deep technical expertise, business acumen, and executive communication. Title inflation leads firms to hire or promote candidates who excel in architecture but lack governance, risk‑prioritization, and...

By CSO Online
How CISOs Can Build a Resilient Workforce
NewsMar 2, 2026

How CISOs Can Build a Resilient Workforce

Cybersecurity leaders face mounting workforce challenges as skill gaps, burnout, and unpredictable threat spikes strain limited budgets. CISOs like Stephen Ford and Jon France emphasize data‑driven staffing, AI‑augmented workflows, and early‑career pipelines to sustain teams. The 2025 ISC2 study shows...

By CSO Online
Why Application Security Must Start at the Load Balancer
NewsFeb 27, 2026

Why Application Security Must Start at the Load Balancer

Application security should begin at the load balancer, not deeper in the stack. Organizations often treat load balancers solely as performance devices, leaving encryption, protocol hygiene, and abuse controls to downstream tools. This architectural gap lets attackers exploit weak TLS...

By CSO Online
Boards Don’t Need Cyber Metrics — They Need Risk Signals
NewsFeb 25, 2026

Boards Don’t Need Cyber Metrics — They Need Risk Signals

Security teams flood boards with counts of attacks, patches, and alerts, but executives need signals that translate those numbers into business risk. Experts argue that time‑based metrics like detection and containment speed, and financial exposure indicators, better reveal whether risk...

By CSO Online
Fake Zoom Meeting Silently Installs Surveillance Software, Says Malwarebytes
NewsFeb 25, 2026

Fake Zoom Meeting Silently Installs Surveillance Software, Says Malwarebytes

Malwarebytes uncovered a new fake‑Zoom meeting scam that silently installs a covert build of the Teramind employee‑monitoring tool on Windows workstations. Victims are lured by a realistic Zoom waiting room, then an automatic “Update Available” countdown triggers a silent download...

By CSO Online
What Does Business Email Compromise Look Like?
NewsFeb 24, 2026

What Does Business Email Compromise Look Like?

Business email compromise (BEC) continues to surge, costing $2.7 billion in 2022—a 12.5% increase over the prior year. Attackers masquerade as CEOs, HR staff, or trusted vendors, using deep reconnaissance, AI‑generated voice cloning, fake invoices, QR codes, and conversation hijacking to...

By CSO Online
What Are the Types of Ransomware Attacks?
NewsFeb 24, 2026

What Are the Types of Ransomware Attacks?

Ransomware has evolved into a multi‑strain ecosystem, ranging from classic crypto ransomware that encrypts data to double‑extortion variants that also threaten public leaks. Newer models such as encryption‑less, locker, scareware, and Ransomware‑as‑a‑Service (RaaS) broaden the attack surface and lower the...

By CSO Online
US Dominance of Agentic AI at the Heart of New NIST Initiative
NewsFeb 19, 2026

US Dominance of Agentic AI at the Heart of New NIST Initiative

The U.S. National Institute of Standards and Technology (NIST) has launched the AI Agent Standards Initiative under the Center for AI Standards and Innovation (CAISI) to develop industry‑led standards for autonomous AI agents. The effort aims to cement U.S. leadership,...

By CSO Online
A New Approach for GenAI Risk Protection
NewsFeb 18, 2026

A New Approach for GenAI Risk Protection

Generative AI’s rapid consumer adoption has exposed enterprises to data leakage risks, prompting security teams to reassess protection strategies. Traditional DLP solutions are expensive and cumbersome, limiting their use to large organizations. Two viable paths emerge: purchasing enterprise‑grade GenAI licenses...

By CSO Online
The New Paradigm for Raising up Secure Software Engineers
NewsFeb 18, 2026

The New Paradigm for Raising up Secure Software Engineers

AI‑assisted coding is set to dominate enterprise development, with Gartner projecting 90% of engineers using AI assistants by 2028. As AI automates line‑level vulnerability detection, security teams face a surge in code volume and reduced review windows. This forces a...

By CSO Online
Cyber Attacks Enabled by Basic Failings, Palo Alto Analysis Finds
NewsFeb 17, 2026

Cyber Attacks Enabled by Basic Failings, Palo Alto Analysis Finds

Palo Alto Networks’ 2026 Global Incident Response Report shows cyber‑attack timelines have collapsed, with the fastest breaches moving from initial access to data exfiltration in just 72 minutes, down from nearly five hours in 2024. The acceleration is largely driven...

By CSO Online
Leaky Chrome Extensions with 37M Installs Caught Divulging Your Browsing History
NewsFeb 16, 2026

Leaky Chrome Extensions with 37M Installs Caught Divulging Your Browsing History

Security researcher Q Continuum identified 287 Chrome extensions that secretly transmit users' browsing histories, affecting an estimated 37 million installations worldwide. The extensions span categories such as VPNs, productivity utilities, and shopping add‑ons, and many request broad host permissions that enable...

By CSO Online
10 Years Later, Bangladesh Bank Cyberheist Still Offers Cyber-Resiliency Lessons
NewsFeb 16, 2026

10 Years Later, Bangladesh Bank Cyberheist Still Offers Cyber-Resiliency Lessons

A decade after the Bangladesh Bank heist, the 2016 cyberattack that attempted to steal $951 million via the SWIFT network remains a benchmark for nation‑state hacking. Attackers used spear‑phishing malware to obtain valid SWIFT credentials, executing 35 fraudulent payment orders, of...

By CSO Online
CISOs Must Separate Signal From Noise as CVE Volume Soars
NewsFeb 11, 2026

CISOs Must Separate Signal From Noise as CVE Volume Soars

The FIRST forecast predicts 2026 will see roughly 59,000 CVEs, with extreme scenarios approaching 118,000, far exceeding the 48,000 reported in 2025. The surge stems from more CVE Numbering Authorities, expanded bug‑bounty programs, and AI‑driven discovery, not a sudden drop...

By CSO Online
Windows Shortcut Weaponized in Phorpiex-Linked Ransomware Campaign
NewsFeb 10, 2026

Windows Shortcut Weaponized in Phorpiex-Linked Ransomware Campaign

Forcepoint X‑Labs uncovered a Phorpiex‑driven phishing campaign that weaponizes Windows shortcut (LNK) files to deliver Global Group ransomware. The emails use a double‑extension lure such as "Document.doc.lnk" and hide the true file type behind Windows’ default extension hiding. Once opened,...

By CSO Online
Single Prompt Breaks AI Safety in 15 Major Language Models
NewsFeb 10, 2026

Single Prompt Breaks AI Safety in 15 Major Language Models

Microsoft researchers uncovered a novel attack called GRP‑Obliteration that uses a single benign‑sounding prompt to strip safety guardrails from 15 major language and image models. By hijacking the Group Relative Policy Optimization training loop, the method rewards harmful completions, driving...

By CSO Online
Never Settle: How CISOs Can Go Beyond Compliance Standards to Better Protect Their Organizations
NewsFeb 9, 2026

Never Settle: How CISOs Can Go Beyond Compliance Standards to Better Protect Their Organizations

CISOs are urged to move past traditional compliance checklists and adopt a risk‑first strategy that anticipates emerging threats such as AI‑driven attacks, third‑party vulnerabilities, and future quantum risks. While standards like HIPAA, SOC 2, and ISO 27001 provide a useful baseline, they...

By CSO Online
Schrödinger’s Cat and the Enterprise Security Paradox
NewsFeb 9, 2026

Schrödinger’s Cat and the Enterprise Security Paradox

Security leaders often operate under a paradox: dashboards show compliance while unseen breaches may exist. The article likens this to Schrödinger’s cat, arguing that without direct observation, an organization is simultaneously secure and compromised. It distinguishes the “paper company” of...

By CSO Online
NIS2: Supply Chains as a Risk Factor
NewsFeb 9, 2026

NIS2: Supply Chains as a Risk Factor

The EU’s NIS2 directive expands cybersecurity obligations beyond a company’s own network to include every external partner in the supply chain. It mandates that firms systematically identify, assess, and continuously monitor risks from service providers, cloud vendors, and subcontractors. The...

By CSO Online
The Silent Security Gap in Enterprise AI Adoption
NewsFeb 5, 2026

The Silent Security Gap in Enterprise AI Adoption

Enterprises are rapidly integrating generative AI into core workflows, but security models have not kept pace. Sensitive data now flows through AI inference requests—prompts containing source code, contracts, PII, and strategic logic—yet these streams sit outside traditional visibility and control...

By CSO Online
Software Supply Chain Risks Join the OWASP Top 10 List, Access Control Still on Top
NewsFeb 5, 2026

Software Supply Chain Risks Join the OWASP Top 10 List, Access Control Still on Top

The 2025 OWASP Top 10 introduces software supply chain failures and mishandling of exceptional conditions as new entries, while broken access control retains the top spot after 20 years. Security misconfiguration rises to second place, and AI‑generated code is highlighted in the...

By CSO Online
Threat Actors Hijack Web Traffic After Exploiting React2Shell Vulnerability: Report
NewsFeb 4, 2026

Threat Actors Hijack Web Traffic After Exploiting React2Shell Vulnerability: Report

Researchers at Datadog Security Labs report that threat actors are exploiting the React2Shell vulnerability (CVE‑2025‑55182) in React Server Components to compromise NGINX servers managed via Boato Panel, hijacking web traffic and redirecting users to malicious sites. The attacks target a...

By CSO Online
Zero Trust in Practice: A Deep Technical Dive Into Going Fully Passwordless in Hybrid Enterprise Environments
NewsFeb 4, 2026

Zero Trust in Practice: A Deep Technical Dive Into Going Fully Passwordless in Hybrid Enterprise Environments

Eliminating passwords in hybrid Active Directory and Microsoft Entra ID environments requires a complete redesign of identity architecture, not a simple switch. Success hinges on three prerequisites—cloud Kerberos trust, device registration, and Conditional Access policies—forming a prerequisite triangle. Organizations must...

By CSO Online
From Credentials to Cloud Admin in 8 Minutes: AI Supercharges AWS Attack Chain
NewsFeb 3, 2026

From Credentials to Cloud Admin in 8 Minutes: AI Supercharges AWS Attack Chain

Threat actors used a publicly exposed AWS credential to launch an AI‑assisted attack that achieved full administrative control in under eight minutes. Large language models generated malicious Lambda code, enabling rapid privilege escalation, lateral movement across 19 principals, and costly...

By CSO Online
Shai-Hulud & Co.: The Software Supply Chain as Achilles’ Heel
NewsFeb 3, 2026

Shai-Hulud & Co.: The Software Supply Chain as Achilles’ Heel

Supply‑chain attacks have evolved from passive typosquatting to active worms, exemplified by the Shai‑Hulud malware. Shai‑Hulud steals developer credentials, republishes infected npm packages, and can trigger a dead‑man switch that erases evidence. The worm’s ability to move across languages and...

By CSO Online
This Stealthy Windows RAT Holds Live Conversations with Its Operators
NewsFeb 2, 2026

This Stealthy Windows RAT Holds Live Conversations with Its Operators

Point Wild researchers uncovered a new Windows campaign deploying the Pulsar RAT, a .NET‑based remote access trojan that lives entirely in memory. The infection chain starts with a per‑user Registry Run key that launches a PowerShell loader, which decodes Donut‑generated...

By CSO Online
When Responsible Disclosure Becomes Unpaid Labor
NewsFeb 2, 2026

When Responsible Disclosure Becomes Unpaid Labor

Responsible disclosure is increasingly failing as organizations delay acknowledgment, dispute severity, and provide little compensation, turning ethical research into unpaid labor. The recent React2Shell (CVE-2025-55182) case shows coordinated response can work, yet exploitation still spread quickly. In contrast, unbacked open‑source...

By CSO Online
Startup Amutable Plotting Linux Security Overhaul to Counter Hacking Threats
NewsJan 30, 2026

Startup Amutable Plotting Linux Security Overhaul to Counter Hacking Threats

Berlin‑based startup Amutable, founded by former Red Hat and Microsoft engineers including systemd creator Lennart Poettering, announced a mission to bring determinism and verifiable integrity to Linux systems. The company plans to replace heuristic security with cryptographic verification of boot processes and...

By CSO Online
The CSO Guide to Top Security Conferences
NewsJan 30, 2026

The CSO Guide to Top Security Conferences

The CSO editorial team compiled a calendar of security conferences slated for February through May 2026, covering more than 30 events across Asia, Europe, North America and Australia. Highlights include multiple Gartner Security & Risk Management Summits, the BSides community...

By CSO Online
Human Risk Management: CISOs’ Solution to the Security Awareness Training Paradox
NewsJan 30, 2026

Human Risk Management: CISOs’ Solution to the Security Awareness Training Paradox

Human risk management (HRM) is emerging as a solution to the security awareness training (SAT) paradox, where 70‑90% of breaches originate from employee actions despite billions spent on training. While SAT spending is projected to grow 15% annually, its efficacy...

By CSO Online
EU’s Answer to CVE Solves Dependency Issue, Adds Fragmentation Risks
NewsJan 29, 2026

EU’s Answer to CVE Solves Dependency Issue, Adds Fragmentation Risks

The European Union has launched the Global Cybersecurity Vulnerability Enumeration (GCVE.eu) database, aggregating advisories from over 25 public sources into a single, searchable platform hosted by Luxembourg’s CIRCL and co‑funded by the EU’s FETTA project. The initiative aims to mitigate...

By CSO Online
NIST’s AI Guidance Pushes Cybersecurity Boundaries
NewsJan 29, 2026

NIST’s AI Guidance Pushes Cybersecurity Boundaries

NIST’s Center for AI Standards and Innovation released a formal Request for Information targeting secure practices for autonomous AI agents, signaling a shift from broad, principle‑based AI risk guidance to concrete, operational controls. The agency highlighted the limits of treating...

By CSO Online
Sicarii Ransomware Locks Your Data and Throws Away the Keys
NewsJan 28, 2026

Sicarii Ransomware Locks Your Data and Throws Away the Keys

Sicarii ransomware generates a fresh RSA key pair on each victim system and discards the private key, making encrypted data unrecoverable even after ransom payment. This defect breaks the standard ransomware‑as‑a‑service model that relies on attacker‑held private keys for decryption....

By CSO Online
Always-On Privileged Access Is Pervasive — and Fraught with Risks
NewsJan 28, 2026

Always-On Privileged Access Is Pervasive — and Fraught with Risks

Enterprises are plagued by pervasive always‑on privileged access, with 91 % of users remaining logged in at their highest privilege level. Legacy governance, mergers, cloud migrations and rapid fixes have left dormant privileged accounts embedded in critical workflows, creating a massive...

By CSO Online
Delegation Is a Risk Decision Every Leader Makes, Not an Ops Choice
NewsJan 28, 2026

Delegation Is a Risk Decision Every Leader Makes, Not an Ops Choice

Leaders increasingly delegate decision‑making authority to software, turning routine operational choices into enterprise‑level risk decisions. When systems automatically issue credits, payments, or pricing adjustments, the underlying authority often lacks explicit ownership, exposing organizations to financial, legal, and reputational fallout. Security...

By CSO Online
4 Issues Holding Back CISOs’ Security Agendas
NewsJan 27, 2026

4 Issues Holding Back CISOs’ Security Agendas

CISOs increasingly view a breach as inevitable, with 76% expecting a material cyberattack within the next year and 58% deeming their organizations unprepared. Four core issues impede progress: insufficient training and empowerment of security teams, lagging AI governance, limited AI...

By CSO Online
Microsoft Handed over BitLocker Keys to Law Enforcement, Raising Enterprise Data Control Concerns
NewsJan 26, 2026

Microsoft Handed over BitLocker Keys to Law Enforcement, Raising Enterprise Data Control Concerns

Microsoft complied with an FBI search warrant in early 2025, providing BitLocker recovery keys stored on its cloud to law‑enforcement for three laptops linked to a Guam unemployment fraud case. The keys were automatically backed up to Microsoft Entra ID,...

By CSO Online
NETSCOUT Recognized for Leadership in Network Detection and Response
NewsJan 23, 2026

NETSCOUT Recognized for Leadership in Network Detection and Response

NETSCOUT has been named a leader in network detection and response (NDR) by Quadrant Knowledge Solutions’ 2025 SPARK Matrix. The company’s Omnis Cyber Intelligence platform leverages Adaptive Service Intelligence to inspect packets at up to 100 Gbps, delivering deep, context‑rich metadata...

By CSO Online
Smarter DDoS Security at Scale
NewsJan 23, 2026

Smarter DDoS Security at Scale

NETSCOUT introduced Arbor Edge Defense (AED), a selective decryption solution that inspects only suspicious encrypted traffic to mitigate DDoS attacks hidden in TLS 1.3 sessions. Traditional full‑traffic decryption is resource‑intensive, creating blind spots for security teams. AED combines known‑source blocking,...

By CSO Online
Vulnerability Prioritization Beyond the CVSS Number
NewsJan 21, 2026

Vulnerability Prioritization Beyond the CVSS Number

The article argues that relying solely on CVSS scores misguides vulnerability prioritization. Real‑world incidents like Equifax, SolarWinds, and Log4Shell show that medium‑scoring flaws can cause outsized damage when they propagate through interconnected systems. It introduces the Unified Linkage Model (ULM)...

By CSO Online