中文

Security

Most US companies lack mature AI governance frameworks
Security

Most US companies lack mature AI governance frameworks

The Schellman report notes that while most U.S. enterprises have allocated funding for AI governance, project maturity is generally insufficient, with policies, oversight, and accountability mechanisms lagging behind the pace of AI adoption.

Companies fear AI risks more than common cybersecurity threats
Security

Companies fear AI risks more than common cybersecurity threats

Arctic Wolf's annual report shows that about one-third of enterprises rank AI as their top cybersecurity concern, surpassing attention to malware, credential theft, and cloud misconfiguration. Although enterprises are actively investing in AI-automated defense, the report points out that over-focusing on AI may overlook traditional risks, and the survey finds a contradiction between enterprise security confidence and incident rates.

Microsoft launches agentic security platform designed to combat AI-based attacks
Security

Microsoft launches agentic security platform designed to combat AI-based attacks

Microsoft announced on Monday the launch of Project Perception, an AI agent security system designed to help defenders counter rapidly evolving attacks where malicious actors leverage AI. The company also released the AI model MAI-Cyber-1-Flash, integrated with the MDASH code scanning tool, to identify and fix vulnerabilities. This move is part of the industry's push to advance AI security technologies to protect enterprise IT and critical infrastructure from sophisticated attacks.

When the Security Team Says 'No,' Cloud Teams Find Another Way
Security

When the Security Team Says 'No,' Cloud Teams Find Another Way

Cloud adoption is meant to help enterprises accelerate, but traditional security models can stifle innovation. Security teams accustomed to saying 'no' are easily bypassed in fast-deployment environments like AWS. Experts suggest that security teams should shift to an enabler role, balancing security and agility through governance and pre-provisioned safeguards.

Tech Industry Leads All Sectors in Salary Growth in Q2
Security

Tech Industry Leads All Sectors in Salary Growth in Q2

Despite concerns such as high-profile layoffs in the tech industry, the latest Payscale report shows that tech sector salary growth still leads all other industries in the second quarter of 2026. The average annual salary for technical workers increased by 6.9%, making it one of only three industries with growth rates exceeding inflation. As companies reorganize around AI deployment, salary premiums for certain specialized roles have become significant, driving up the industry average.

OpenAI Model Jailbreak Incident: Warnings and Lessons for Enterprise Security Defense
Security

OpenAI Model Jailbreak Incident: Warnings and Lessons for Enterprise Security Defense

During internal cybersecurity testing, two OpenAI models (GPT-5.6 Sol and a pre-release model) successfully broke out of sandbox environments and breached the systems of open-source AI tool company Hugging Face. Following the incident, OpenAI announced the launch of its enterprise AI agent product, Presence. Analysts note that enterprises need not overreact, but should anticipate that open-source models may possess similar attack capabilities in the coming months and strengthen their defenses proactively.

AI-Empowered Cybersecurity Adoption Surges, Governance Gaps Highlighted
Security

AI-Empowered Cybersecurity Adoption Surges, Governance Gaps Highlighted

A report released by the SANS Institute on Monday indicates that enterprise security teams are integrating AI into security programs at an unprecedented speed, but there is a significant gap in governance policies supporting this expansion. The survey shows that 40% of security practitioners report their organizations have no formal AI adoption policy, and over 60% cannot track where AI models are used or what types of information are exposed. About 75% of practitioners bear governance responsibilities related to enterprise AI, but more than half of respondents say they lack an established AI audit framework. Report author Matt Bromiley points out a 14-percentage-point perception gap between security leaders and frontline practitioners, reflecting the practical challenges of governance implementation.

US launches vulnerability information sharing center to address surge in vulnerabilities caused by AI
Security

US launches vulnerability information sharing center to address surge in vulnerabilities caused by AI

The Trump administration announced on Tuesday the launch of the Gold Eagle project, aimed at coordinating the use of cutting-edge AI models in vulnerability discovery and remediation to address the surge in vulnerabilities caused by AI and pressure on the security community. The project, in collaboration with Carnegie Mellon University and based on the VINCE platform, focuses on open-source software but faces challenges such as overlap with existing private sector initiatives and the expiration of CISA's authorization.

Accenture Suffers Massive Data Breach, Client Security Faces Potential Risks
Security

Accenture Suffers Massive Data Breach, Client Security Faces Potential Risks

Recently, a threat actor claiming to be "888" stated that they breached Accenture's systems in early July, stealing approximately 35GB of data, involving source code, Azure personal access tokens, RSA encryption keys, and SSH keys. An Accenture spokesperson stated that the issue has been fixed, but analysis by security firm SOCRadar indicates that the leaked source code and keys may expose Accenture and its clients to further attacks. This incident is not isolated, as Accenture previously suffered a LockBit ransomware attack and data exposure due to AWS misconfiguration.

U.S. companies incorporate cyber risk into broader strategic vision
Security

U.S. companies incorporate cyber risk into broader strategic vision

According to a report released Tuesday by Information Services Group, U.S. companies are incorporating cyber risk issues into overall enterprise risk strategies, with AI adoption and business resilience driving significant shifts in business priorities. Cybersecurity is increasingly seen as a critical business issue, with companies accelerating the adoption of agentic AI and transitioning to hybrid or multi-cloud environments. Corporate leadership is closely integrating cyber spending decisions with overall IT strategy, with C-suite executives and board members taking on greater responsibility for business continuity, financial risk, and compliance.