Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

The Price of a Deal: How Scammers are Hijacking Amazon Prime Day

As millions of shoppers prepare their wishlists and await discounts for Amazon’s Prime Big Deal Days starting October 6, cybercriminals are gearing up for their own payday. In the weeks leading up to major shopping events, Amazon impersonation campaigns reach an annual peak.

ISO 42001 Gap Analysis: What to Check Before Starting Certification

An ISO 42001 gap analysis compares how you govern AI today with what ISO/IEC 42001:2023 requires. Do it before you commit to audit dates. You’ll learn what’s missing, what you can’t yet prove and what to fix first. Quick answer What it is: a structured review of your AI management system (AIMS) against ISO/IEC 42001:2023 clauses 4–10 and the applicable Annex A controls. Is it mandatory? No. The standard requires an internal audit and management review, not a gap analysis.

Warning: Tech Support Scams Are Abusing Google Ads

Researchers at Netskope are tracking a phishing kit that hijacks users’ browser windows to display fake security alerts. The malicious websites are distributed via Google Ads, and pose as normal online stores. Once a user clicks a link on the page, however, the site will present them with an urgent-looking security warning.

AI Governance Evidence That Costs Nothing to Produce

The usual case for governance return is that it speeds up enterprise sales, because buyers ask security questions and a prepared answer closes faster. It is true and it is the weaker argument. ‍ The stronger one is loss avoidance, and almost nobody makes it, because it needs a loss figure that most governance programs do not have. What makes it affordable is a distinction between two kinds of evidence. ‍

AI Governance Where the Regulator Also Runs the Market

AI governance evidence is usually prepared for a neutral reader. A regulator with no stake in the market, an auditor with no competing product, an examiner who gains nothing from what the documentation contains. ‍ In securities and derivatives markets that assumption does not hold. Exchanges and clearing organizations register as self-regulatory organizations, and most of them operate the market while regulating its participants. The reader of your evidence is also an operator. ‍

What an AI Correlation Rule Cannot See

A correlation rule can be tuned. The window can be widened, the join key improved, a source promoted from optional to required. Each of those is a parameter with a defensible setting. ‍ What remains after all of it is the residual, meaning the events that would produce a finding if a source existed for them, which is a form of residual risk expressed in detection terms. Naming it is the question an auditor asks after being shown a detection, and the answer is not a tuning exercise. ‍

The Cyber Risk Number That Goes to Three Different Committees

An exposure figure is produced once and read three times. The audit committee sees it, the risk committee sees it, and the board sees it, and each is answering a different oversight question. ‍ The figure travels well and the reasoning behind it does not. What arrives at the third reading is a number with no assumptions attached, and by then it reads as a fact. ‍

A One-in-Hundred-Year Cyber Loss Is Not a Schedule

A quantification exercise reports a one-in-hundred-year loss and the figure travels well. It sounds precise, it sounds severe, and everybody in the room believes they understand it. ‍ Most of them do not. The phrasing describes an annual probability and it reads as a statement about timing, and the two produce different decisions from the same number. ‍

Strengthening Network Security for Modern Organizations

Organizations today face a common challenge: networks are growing, wireless connectivity is supporting more users and devices, and security threats continue to evolve. At the same time, IT teams are expected to deliver stronger protection, better performance, and greater visibility without increasing operational complexity. To help organizations meet these demands, WatchGuard is introducing three new additions to its Network Security portfolio: Firebox T175, Prime Security Suite, and AP340 Wi‑Fi 7.