Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Open Chroma Databases: A New Attack Surface for AI Apps

Chroma is an open-source vector store–a database designed to allow LLM chatbots to search for relevant information when answering a user’s question–and one of many technologies that have seen adoption grow with the recent AI boom. Like many databases, Chroma can be configured by end users to lack authentication and authorization mechanisms.

Service Account Security: 5 Essential Rules Every Organization Must Follow

While organizations pay close attention to securing regular human accounts, service accounts often lack proper oversight. Yet their high level of access makes them a prime target for attackers seeking entry points into an organization’s network. In this article, we examine the core reasons service accounts may undermine organizational cybersecurity and outline five essential rules to help you secure your service accounts.

How Safe is the ChatGPT Android App? An Appknox Study

Brilliant AI, broken defenses? AI-powered apps are revolutionizing how we search, learn, and communicate, but the rapid pace of innovation has come at a cost: security is often an afterthought. As part of our AI App Security Analysis Series, we’ve been scrutinizing some of the most popular AI tools on Android for hidden vulnerabilities that could put millions of users at risk.

Strategic Signals from Money20/20: Digital Identity, Stablecoins, Open Banking

At this year’s Money20/20 Europe, the focus was clear and pragmatic. Three themes came through consistently: digital identity, stablecoins, and open banking. Each reflects a broader shift underway. Institutions are moving from exploration to implementation. Regulatory frameworks are taking shape. Infrastructure is evolving to meet new demands. These priorities emerged across our discussions with partners, customers, and colleagues—and signal where the market is heading.

Firewalls and VPNs in the Line of Fire: How Exploits Are Evolving

Over the past year, cybercriminal activity has shifted toward exploiting vulnerabilities found in company perimeters and infrastructure systems. Attacks are also being carried out within shorter and shorter timeframes. According to data from Google Threat Intelligence Group (GTIG) in 2024, 44% of zero-day attacks affected enterprise-focused technologies, compared to 37% in 2023.

Arctic Wolf Observes Organizations Receiving Unsolicited Microsoft MFA Messages

Arctic Wolf has recently observed customers receiving unsolicited Microsoft multi-factor authentication (MFA) text messages. These messages originate from legitimate Microsoft short code numbers; however, the source and intent have not been confirmed. This issue appears widespread, affecting organizations across multiple industry verticals. Example of Text Message It is currently unclear whether this activity is due to a systemic issue on Microsoft’s side or part of a malicious campaign.

Cyber Frontlines: Insights from DSEI Japan 2025

Modern conflict is no longer dominated solely by tanks, ships, and fighter jets. The nature of warfare itself has transformed dramatically. Today, battles are increasingly fought—and won—in cyberspace. Historically, military leaders intimately understood their hardware; pilots knew their planes, naval commanders knew their ships, and tank commanders knew their armoured vehicles.

Single Endpoint View - Tanium for Help Desk - Tanium Tech Talks #129

Tanium is known for its ability to get quick results from thousands of endpoints in a flash. But what about when I want to drill down for details on a single endpoint? What if it is offline? A few years ago we released what we simply call "single endpoint view". The response was huge, especially for help desk folks who need a quick glance at everything in one place. And the best part, is that you can customize it to your own needs.