Home About Black Hat Contact Essays Fireside Chats My Take News Alerts Q&A Reels RSAC Videocasts
 

News Alerts

 

News Alert: SpyCloud survey finds machine identity risks outpace defenses, exposing gaps in oversight

AUSTIN, Tex., Sept. 9, 2026, CyberNewswire – SpyCloud, the leader in identity threat protection, today released its annual SpyCloud Identity Threat Report, a survey-based study finding that non-human identities (NHIs) – the AI agents, service accounts, API keys, and authentication tokens that connect to internal systems – have become the most common route attackers take into the enterprise.

The survey found that compromised NHIs (31%) are nearly 2x as likely to be the primary entry point compared to phishing and social engineering (17%), the second-ranked answer. NHI-related misuse was also the most commonly reported identity-based event type at 42%, yet the vast majority of organizations aren’t watching for them. While 95% of organizations believe they have adequate visibility into AI- and NHI-related exposures, only 36% monitor them, making machine identities the least-watched category of identity risk in the report. Further amplifying the problem, 68% of organizations experienced an identity-based event in the same period, with those affected averaging eight events each.

Organizations typically maintain a clear inventory of their human workforce, but few extend that same visibility to the service accounts, API keys, and AI agents authenticating into their systems every day. These identities are provisioned for convenience and often hold real privilege, yet in most environments nobody owns them: a service account doesn’t get off-boarded, doesn’t rotate its own credentials, and doesn’t fail an MFA challenge, so once one is exposed it can stay usable for months.

News Alert: Reflectiz launches AI website testing, uses site context to find and verify flaws

BOSTON, Sept. 8, 2026, CyberNewswire — Reflectiz, the continuous web exposure management company, today launched a multi-agent penetration testing platform for websites. Multiple specialized AI agents discover, attack, and validate vulnerabilities across complex web environments, and because they start from an existing model of each site, they cover up to ten times more than conventional pentesting tools.

A pentest used to be an event. An engagement, a report, done. The report described a moment. The website kept going: login, checkout, payments, dozens of third-party scripts, all probed by attackers daily.

“Websites change every week and get pentested once or twice a year. That gap is where exposure builds up,” said Idan Cohen, CEO and co-founder of Reflectiz. “Teams need testing that keeps up with releases at a cost they can sustain, and trusted coverage of what was tested.”

Testing with site context

Reflectiz has spent a decade scanning thousands of production websites and holds a live model of each one: pages, scripts, third parties, domains, sensitive inputs, and behaviors. The pentesting agents add the attacker’s perspective to that same model.

News Alert: Link11 reports fewer but stronger DDoS attacks in Europe for the first half of 2026

FRANKFURT, September 3, 2026, CyberNewswire — Link11 has released its European Cyber Report for the first half of 2026, providing an overview of DDoS attack activity targeting European companies.

Although the number of DDoS attacks on the Link11 network decreased by 42 percent, the report records new highs for attack intensity across bandwidth, packet rate and cumulative data volume, indicating that attacks have become more targeted and intense.

Attack intensity hits records

Although the number of attacks decreased by 42 percent, record highs were reached in terms of attack intensity in every category. The highest measured bandwidth attack reached 2.3 Tbit/s—85 percent higher than the previous peak of 1.2 Tbit/s in the first half of 2025.

The packet rate followed the same pattern, reaching a new peak of 322 million packets per second — up 56 percent from 207 million packets per second a year earlier. Cumulative traffic also increased, rising from 438 to 705 terabytes over the six-month period — a 61 percent increase.

News alert: OpenMatter adds secure routing for OpenAI, Anthropic and Google models

MELBOURNE, Fla., Sept. 2, 2026, CyberNewswire — Less than three months after its commercial launch, OpenMatter Network today announced a significant expansion of the platform with new capabilities that make it easier for enterprises, developers and researchers to build, deploy and collaborate using sensitive data and AI while maintaining cryptographic control over how information is accessed, computed and shared.

The new capabilities, available now as part of the commercially available OpenMatter Network platform, span secure application development, AI model management, privacy-preserving machine learning and data collaboration. More importantly, they demonstrate one of the founding principles of the company: the platform is not a fixed solution for today’s computing environment, but an extensible Verification Architecture — a cryptographic foundation that validates what happened without controlling how it happened — capable of incorporating new technologies and capabilities as enterprise computing continues to evolve.

News alert: Bright Security launches AI PT, AI-powered penetration testing that cuts weeks to hours

SAN RAFAEL, Calif., Sept. 1, 2026, CyberNewswire — As AI compresses the gap between vulnerability disclosure and exploitation to nearly zero, the new AI Pentesting Module gives security teams continuous, AI-driven penetration testing built on Bright’s proven dynamic testing engine, at a fraction of traditional cost.Bright Security, the AI-native application security company, today announced AI PT, its new AI penetration testing module. It finds, exploits, and proves real vulnerabilities the way a human tester would, at a fraction of the time and cost of a traditional engagement.

The launch responds to a rapidly closing window between disclosure and exploitation. Frontier AI systems built for security research, including Anthropic’s Claude Mythos and OpenAI’s Aardvark, can now discover and weaponize software flaws with little to no human involvement. Anthropic’s own research team recently used a similarly capable system to uncover more than 500 previously unknown high-severity vulnerabilities in widely used open-source software, flaws that had gone undetected for years. Independent research tracking more than 83,000 CVEs, compiled by Zero Day Clock, found that the typical gap between a vulnerability’s disclosure and its first exploit has fallen from roughly two years in 2018 to a matter of hours today. Separately, vulnerability-intelligence firm VulnCheck reports that more than a quarter of exploited flaws are now weaponized within 24 hours of going public.

NEWS ALERT: Lunar Cyber tracks stolen API keys, ties them to infected employer devices

BNEI BRAK, Israel, Aug. 31, 2026, CyberNewswire — Lunar Cyber today announced Token Exposure Monitoring, a new capability designed to identify, attribute and validate Non-Human Identities (NHI) and machine credentials inside infostealer logs, connect them to the affected organization, and determine which exposures require action.

The rapid adoption of AI development tools, cloud platforms and automated infrastructure has put a new class of credentials on developer machines: API keys, OAuth tokens, personal access tokens, and other machine identities that provide direct access to valuable services.

Security researchers have documented the theft and abuse of AI API credentials for attacks such as LLMjacking, where stolen keys are used to run expensive AI workloads through a victim’s account. Developer credentials can also provide access to source-code repositories, cloud infrastructure, SaaS platforms and corporate data. Lunar’s internal research found that modern infostealers actively collect the local files and application data where these credentials are frequently stored.

NEWS ALERT: SRA makes SOC AI license-free — customers pay only for the Azure compute they use

PHILADELPHIA, Aug. 24, 2026, CyberNewswire — Security Risk Advisors (SRA), the authors of the free VECTR platform, announce today another great free platform launch: SCALR AI. Security teams can get SCALR AI for free, delivered through the Azure Marketplace.

SCALR AI is an agentive workbench that automates time-consuming security work and ships with fully functional incident triage and enrichment, with AI-driven quality review built-in. There are no limits on the free license (such as local use), and the SCALR AI platform is available to CISO teams to deploy in their own Azure private tenant. Teams can build additional workflows with the tools in the platform, including threat hunting, vulnerability management, phishing analysis, and others. Security teams configure multi-agent workflows, agents, tools, and MCP servers working together, instead of building each workflow by hand.