top of page


Enterprise Security Tech
A cybersecurity resource for CxOs
Search


Hackers Manipulated Control Systems at Two Colorado Water Utilities
Foreign threat actors breached two small, privately owned Colorado water utilities in late August and manipulated equipment used to control drinking-water systems, according to information the governor’s office provided to Axios. Each utility serves fewer than 200 people. Colorado officials said the problems were resolved, technical assistance was offered and other water providers were alerted. The state has not identified the attackers, and the FBI declined to comment on the
Sep 22


CrowdSec Says Former Employee Access Exposed 170 Private GitHub Repositories
CrowdSec says attackers used lingering access tied to a former employee to clone roughly 170 private repositories, exposing source code and cloud credentials.
Sep 22


Revolut Data Breach Shows How Trusted Government Email Can Become a Hacker’s Master Key
Hackers allegedly exploited a compromised Italian government email account to impersonate law enforcement and obtain sensitive information about hundreds of Revolut customers, exposing a dangerous weakness in how financial institutions authenticate official data requests. The attackers reportedly gained access to Italy’s certified email system, known as PEC, and used that trusted channel to request customer records from Revolut over several months. According to the Financial
Sep 16


Fake Hires Are Getting Corporate Credentials Before Companies Detect Them
Fraudulent job candidates are slipping through remote hiring systems and gaining legitimate access to corporate networks, exposing a growing identity security gap that conventional screening tools are failing to close. New research from HYPR found that 98% of surveyed HR executives have encountered candidate fraud. Yet 68% of fraudulent hires were ultimately exposed through human observation or intuition, rather than automated security controls. The findings suggest generativ
Sep 16


AI Agents Emerge as the Top Insider Security Risk for Enterprises
AI agents are quickly gaining access to sensitive corporate systems, and security leaders increasingly see that autonomy as a bigger threat than traditional hackers or malicious employees. New research from Exabeam found that 48% of security leaders consider AI agents operating with excessive, compromised, or unintended access their organization’s greatest current threat. By comparison, 28% selected external attackers, while compromised and malicious insiders each received 12
Sep 16


CISA Warns of 17 Active Directory Attack Techniques as AI Expands Identity Risk
The US Cybersecurity and Infrastructure Security Agency and five international cybersecurity agencies have released new guidance on securing Microsoft Active Directory, detailing 17 techniques attackers commonly use to compromise enterprise identity systems. The threat list includes Kerberoasting, AS-REP Roasting, password spraying, DCSync, Golden Ticket attacks, certificate abuse and the exploitation of insecure delegation settings. None of these techniques is particularly n
Sep 16
bottom of page