Security

ServiceNow and IBM Expand Partnership, Focusing on Legacy IT System Modernization
ServiceNow and IBM announced an expanded partnership on Thursday, combining IBM's AI, data, and automation capabilities with ServiceNow's AI platform to address challenges related to legacy systems and data readiness in enterprise-scale AI deployment. The collaboration focuses on application modernization, enterprise data governance, and autonomous infrastructure operations, with related joint capabilities expected to be available in the second half of 2026.

Building an Agentic AI Framework: A Four-Step Action Guide for CIOs
In a keynote address on Tuesday, Info-Tech Research Group CEO Tom Zehren stated that although agentic AI has transformative potential for enterprises, technology leaders such as CIOs still face deployment challenges. He proposed a four-step framework based on surveys and industry research to help technology leaders develop an AI strategy that measures value, and emphasized that security measures, IT budgets, AI strategy, and employee buy-in are key factors.

AI accelerates identity impersonation attacks, enterprises unprepared in protection
Outtake's latest report indicates that AI not only enhances hackers' abilities to analyze vulnerabilities and write malware but also poses a serious threat in identity impersonation. This year, 53% of organizations have faced impersonation attacks targeting executives or frontline employees, and 47% have encountered confirmed or suspected synthetic media impersonation incidents. However, 75% of surveyed enterprises only conduct limited monitoring or post-incident response, and only 43% carry out executive identity deception simulations. The lack of oversight for AI agents also poses a hidden risk, with only 4% of enterprises fully monitoring AI agents. Governance fragmentation is widespread, with 21% of enterprises lacking a dedicated team responsible for digital trust risks.

Gartner Security Summit: Under AI Impact, CISO's Top Priority Is to 'Stay Calm'
At the Gartner Security & Risk Management Summit, multiple analysts reminded CISOs that, in the face of threats from new AI models such as Anthropic Claude Mythos and OpenAI Daybreak, they should return to security fundamentals, avoid being misled by hype, and be wary of AI investments eroding budgets and talent reserves.

Trump's AI Regulatory Executive Order: Five Key Points for CIOs to Watch
U.S. President Trump established a voluntary review mechanism for frontier AI models through an executive order, with the Department of Homeland Security, the Department of the Treasury, the Office of the National Cyber Director, and NIST tasked to develop standards within 60 days. The order does not impose mandatory licensing, but CIOs should be wary of potential impacts from alternative mechanisms such as the Defense Production Act.

AI Agents Pose New Challenges to Cybersecurity Frameworks
Enterprises are rapidly adopting AI agents, but the resulting security risks and governance issues are drawing attention. Gartner predicts related spending will increase by $6 billion in 2026, while Okta reports that over half of enterprises experienced AI-related security incidents last year. Experts point out that the autonomy of agents requires stricter permission controls, and security responsibility is shifting from the CISO to cross-departmental sharing, with governance and security strategies needing to evolve in tandem.

Non-production data is becoming the biggest blind spot in enterprise compliance
The spread of sensitive data to non-production environments is not a new phenomenon, but DevOps, analytics, and AI training pipelines are dramatically expanding its scale and exposure. According to the Perforce Delphix report, 60% of enterprises experienced data breaches in non-production environments last year, and 84% still allow compliance exceptions. This article explores the causes of the risk and closed-loop governance solutions.

OpenAI Releases Frontier Governance Framework in Response to Emerging AI Regulatory Requirements
OpenAI released a frontier governance framework on Thursday, responding to emerging regulatory requirements such as California's Frontier AI Transparency Act and the EU AI Act's general-purpose AI code of practice. The document details the company's safety practices in areas such as cyberattack assessments, risk management, and incident response, and commits to continuous updates in line with national and international AI risk management standards.

Frontier AI models are more vulnerable to malicious prompts than vendors claim
Cisco researchers reported on Wednesday that major AI developers' safety claims are based on incorrect assumptions about hacker behavior. Tests on 15 frontier models showed that multi-turn malicious prompt attack success rates ranged from 8% to 88%, while single-turn attacks ranged from only 2% to 65%. The study also found that vendors that publicly emphasize model capabilities showed a larger vulnerability gap under multi-turn attacks.

Corporate data quietly flows into shadow AI tools
An Okta survey released Wednesday shows that despite most executives' confidence in employees' responsible use of AI, shadow AI is quietly infiltrating enterprises. More than half of employees admit to using personal AI tools without approval and allowing them access to internal messages, HR information, and confidential files. 58% of executives reported AI-related security incidents or near misses in the past year. Experts recommend that companies adopt a collaborative approach and provide compliant alternatives.