Please turn on your JavaScript for this page to function normally.
Europe
NIS2 compliance: 7 low-cost steps to secure credentials

Security budgets rarely stretch to cover a full NIS2 programme in one pass. Credential controls are where a constrained team can start, because they make access visible, …

AI
AI agents keep access to company data after their work is done

IT teams responsible for identity security are concerned about AI agents’ ongoing access to company systems and the actions they take on users’ behalf, according to a …

lock
Hardcoded MCP credentials found in public GitHub files

Hardcoded API keys, access tokens and other credentials used by AI coding tools have been found in publicly accessible MCP configuration files on GitHub, according to research …

person
98% of fraudulent hires have company credentials by the time they’re caught

A 90-day period between hiring and onboarding is creating a blind spot in enterprise identity security, according to HYPR’s State of HR Identity Fraud Detection report. …

mSecure password manager
Product showcase: mSecure makes one vault do more than remember passwords

mSecure is a password manager and data vault for storing credentials and other sensitive information. It is available for iOS, Android, macOS, and Windows, with data …

GitGuardian honeytoken decoy service
Product showcase: GitGuardian Honeytoken catches credential theft as it happens

Credential harvesting on developer machines has widened. Earlier infostealers worked from a short list of known targets, mostly browser stores and a few cloud credential …

Doppler secrets management platform
Product showcase: Doppler secures secrets for humans, pipelines, and AI agents

Every engineering team has spent years trying to keep credentials out of source code. Then AI agents moved the problem. Coding agents review code, agents run workflows, and …

NIS2
NIS2 compliance: Fixing IAM and access control before the 2026 audit

The NIS2 Directive places direct obligations on organizations across supply chain risk management, incident reporting, and board-level accountability. October brings a new …

AI
Threat actors are posing as AI crawlers to hunt for exposed credentials

Attackers are disguising automated scanning as traffic from AI crawlers operated by OpenAI, Anthropic, Google, Perplexity and other companies while searching websites for …

attack
Attackers turn to AI for help identifying files worth stealing

AI tools are being used by cyber attackers to write malicious code, build tools that harvest credentials, search compromised networks, identify valuable business information, …

Enpass Password Manager
Product showcase: Enpass Password Manager breaks away from the proprietary cloud model

Enpass is a password manager that stores passwords, passkeys, payment cards, identities, secure notes, software licenses, and other sensitive information in encrypted vaults. …

TikTok
Buying TikTok followers can expose users to scams and account theft

Buying TikTok followers, likes, or views could do more than inflate engagement metrics. According to Malwarebytes, many services selling social media growth operate through …

Don't miss

Cybersecurity news
Daily newsletter sent Monday-Friday
Weekly newsletter sent on Mondays
Editor's choice newsletter sent twice a month
Periodical newsletter released for important security events and breaking news
Weekly newsletter listing new cybersecurity job positions
Monthly newsletter focusing on open source cybersecurity tools