The latest red team research from Barracuda shows how, in a controlled simulation, researchers took over a Copilot-enabled account and used the assistant against its own organization.
Cyber resilience
Detection speed has often been used as the ultimate metric of cyber preparedness. However, new research from ManageEngine reveals an uncomfortable truth: catching an attacker quickly does not guarantee a swift recovery. VimalRaj explores why the gap between detection and recovery is widening.
According to IBM’s 2026 Cost of a Data Breach Report, one in four malicious breaches was AI-enabled during the 12-month period covered by the report.
Security teams remain overly committed to keeping humans in the loop and it isn’t a sustainable approach says Ashley Leonard.
Cyber security agencies from Australia, the US, the United Kingdom, and Canada have published new guidance to help critical infrastructure operators isolate vital operational technology (OT) and enabling systems during a major cyber incident or geopolitical crisis.
The Cloud Security Alliance has worked with the SANS Institute, RSAC, FIRST, [un]prompted, and Knostic to quickly develop a post incident review for the recent Hugging Face AI attack incident.
The quantum threat is global and a long-term resilience programme is needed in response. However, post-quantum cryptography migration timelines are fragmented, increasing the complexity of preparatory actions.
Chris Newton-Smith explores how the UK Government’s Cyber Resilience Pledge is strengthening board accountability for this area.
In what OpenAI describes as an unprecedented security incident, a combination of its advanced models escaped a highly restricted testing environment and compromised parts of Hugging Face’s production infrastructure.
Sophos has released its seventh annual ‘State of Ransomware 2026’ report, based on a survey of IT and cyber security leaders across 17 countries whose organizations had experienced ransomware during the previous 12 months.









