Why Businesses Should Test What Happens When Their Defenses Fail
A new offensive security startup, RemoteThreat, argues that traditional red teaming no longer reflects the advanced tactics real attackers use.
A new offensive security startup, RemoteThreat, argues that traditional red teaming no longer reflects the advanced tactics real attackers use.
A China-linked hacking group is using a newly discovered backdoor called Antino, which disguises its communications as normal Outlook and OneDrive traffic, to spy on government and policy organisations across Asia.
Dell has patched multiple critical vulnerabilities in Container Storage Modules that could let attackers bypass authentication and take over storage systems and Kubernetes nodes.
Two vendor incidents show inconsistent and sometimes confusing responses to active zero-day exploitation, leaving customers exposed.
Analysts warn organisations face a looming reckoning on AI governance, security, and value as accountability standards tighten.
Security experts warn that calling AI 'rogue' when it causes security failures wrongly shifts blame away from vendors and weak controls.
A California business owner has been arrested and charged with allegedly routing hundreds of millions of dollars in advanced Nvidia AI chips to China via Malaysia and Singapore to evade US export controls.
Microsoft's 2026 Digital Defense Report warns that AI is allowing attackers to compress post-compromise activity, like stealing data and moving through networks, from days down to minutes.
Vicksburg, Mississippi shut down its computer systems after a ransomware attack disrupted utility payments, though emergency services remain unaffected.
A China-linked group is exploiting unpatched Microsoft SharePoint vulnerabilities to deploy Warlock ransomware against critical infrastructure in Portuguese- and Spanish-speaking regions.
OpenAI dismissed three safety team members for sharing confidential company information with an outside AI-safety group, amid wider concerns about AI model security and testing practices.
Security teams often struggle to answer basic board questions about risk because their data is scattered across disconnected tools that measure activity, not actual exposure.
The Dutch Institute for Vulnerability Disclosure was breached via two chained zero-day flaws in its Zammad helpdesk platform, in what it believes was an AI-powered attack.
Free health check. Which breaches hold your address, and what your browser gives away. Under five minutes.
Run the check →Every brief as JSON, tagged by topic. One endpoint, one token, no scraping. Around 28 a day.
See the plans →A virtual data room sealed in your browser, so the platform cannot read the deal. Staged disclosure and guest reviewers.
Open a data room →Seen by the security and risk people who came for the briefings. Labelled, never mixed into the reporting.
Take this spot →Your own colours, not ours. A tile looks like your product, not like our page.
What it costs →No carousel and no rotation. What is here is here every time the page opens.
Enquire →Each spot belongs to one company. Nothing is resold to a network.
Enquire →The people reading the briefings are the ones who sign off on security spend.
Enquire →Directly under the feed, where the reader already is rather than on a page they have to find.
Enquire →Written for Australian business, and read by the people who have to act on it.
Enquire →A plain link we place ourselves. No network, no pixel, nothing following anyone between sites.
Enquire →Taken by the month. Longer runs are cheaper, and nothing renews without you saying so.
Enquire →Get trusted-source cyber intelligence by email, written to be scanned quickly and followed back to the original reporting when needed.
Plain-language summaries of the week's major advisories, campaigns, research notes and vendor reporting, each linked back to the reporting it came from.
Our own analysis opens the email when we have published a piece, and up to three video briefings close it, each with a link straight to the source.
Short, direct and in context. Fast enough for leaders, detailed enough for practitioners, with the source lineage to drill deeper only when you need to.
By subscribing you agree to receive briefing emails from CISO AI. You can unsubscribe at any time.
Listed with permission. Supporters have no influence over what is covered, and links carry no endorsement.