Industry News & Insights
A collection of current security news and analysis for the Microsoft, biotech, and legal industries.
Microsoft Security
Anthropic founder and CEO Dario Amodei made his views clear about open-weight models and China's growing AI capabilities.
Just don’t call the WinRT projection for Node.js a lock-in
A proof-of-concept exploit for "Certighost," a Windows Active Directory Certificate Services vulnerability, has been released that can allow authenticated attackers to potentially compromise a Windows domain. [...]
MDASH stuffed with MAI-Cyber-1-Flash and a side of GPT-5.4
Microsoft bolstered its AI cybersecurity offerings this week with the launch of its first AI security model and a new security platform.
The Open Security AI Alliance says the Hugging Face/OpenAI mess proves frontier labs can't be trusted to properly secure sensitive systems
Shadow AI agents are rapidly spreading across enterprise platforms, often without IT or security visibility. Nudge Security explains how organizations can discover, assess, and govern AI agents before unmanaged permissions and autonomous actions create securi…
One bug disabled the security service on restart, another blocked installation on hardened RHEL systems
If you think OpenAI and Anthropic are the only ones with these capabilities, think again
Trump's unpredictability is pushing governments and businesses toward open source while Britain remains glued to US tech
Biotech & Healthcare Security
The massive seed round was led by Index Ventures and Ribbit Capital, with participation from Sarah Guo's Conviction Partners.
The long-held understanding among security researchers and network defenders is that it's impossible to negotiate in good faith with an extortion racket because there's no incentive for the other side to actually walk away.
Glow is targeting a new class of endpoint risks created by the rapid adoption of AI agents and developer tools inside enterprises.
Edinburgh-based tech firm Craneware said customer data was stolen during a cyberattack. The company makes software that thousands of U.S. hospitals, pharmacies, and clinics rely on for billing patients, potentially exposing health data.
As age verification laws expand worldwide, organizations face growing pressure to protect users' privacy while meeting regulatory requirements. Incode explains how on-device age estimation verifies age without transmitting or storing facial images, reducing b…
Cybersecurity agencies from the United States and eight other countries have issued a joint warning that Russian state hackers are targeting vulnerable and poorly configured routers to infiltrate critical infrastructure networks. [...]
A 34-year-old Armenian man has pleaded guilty to hacking U.S. companies and deploying the infamous Ryuk ransomware to encrypt their systems. [...]
A third ransomware negotiator has been jailed for helping a notorious ransomware group to extort American victim companies into paying the hackers.
View CSAF Summary Successful exploitation of these vulnerabilities could allow attackers to overwrite critical files, forge or inject malicious log data, gain unauthorized account access, trigger denial‑of‑service conditions, truncate or alter logging informa…
View CSAF Summary Successful exploitation of these vulnerabilities could disclose information and allow a malicious user to execute arbitrary code on affected installations. The following versions of Labcenter Proteus 9 are affected: <ul> <li>Proteus 9.1_SP4_…
Legal Tech & Security
Generative artificial intelligence has proven to be a truly disruptive technology. In just a few short years, AI’s effects have been felt in every industry and across most professions. It has impacted financial markets, company structures and the way that wor…
Several BigLaw firms that have built their own artificial intelligence tools have initiated plans to share them with clients or other firms. Among them, Cooley…