Prompt Injection Attacks Just Learned to Whisper in Cipher

Prompt injection attacks now hide inside encryption itself. See how a hidden cipher fooled Grok and Gemini, and what folkfox tells marketing teams to do next.
Incident Response Services Now Have to Prove They Are Real

A fake recovery firm is re-extorting ransomware victims, so buyers now judge incident response services on proof, not promises, before they ever hire a firm.
NIS2 Compliance Arrives One Day After Brussels Sued for the Wait

NIS2 compliance became compulsory in the Netherlands on 15 August 2026, one day after Brussels sued the same government for the wait. What changes now.
Five Agencies, One Warning, and Not a Single Number

Five US agencies issued an ot cybersecurity alert on Siemens S7 controllers on 19 August 2026, with no incident count and no published evidence of AI use.
Private Equity Bought the Channel, and Every Provider Now Sounds the Same

Outside investors sat in 80% of tracked deals in Q1 2026. What private equity consolidation does to managed security services copy, and how a smaller firm wins.
AI Security Testing Found Four SAML Bypasses. The Fixing Is Where It Stalls

ai security testing found four SAML authentication bypasses carrying CVEs in August 2026, yet Anthropic reports only 75 of 530 serious bugs have been patched.
NIST Just Handed Security Teams a Script for Their Own AI Prompts

NIST compliance just gained an AI QuickStart Guide: structured prompts, three worked scenarios, and a 15 October deadline security teams should track.
AI fraud detection is now a brand problem, not just a bank’s

AI fraud detection just got personal: ASIC removed 19,400 AI-driven scam sites in FY26, up 182 percent. What brand and compliance teams need to know now.
Nobody Exploited a Single Flaw. They Just Used the Password

TheHatman sold 3.64 million records stolen with no exploit at all. Five honest lessons managed detection and response vendors should draw from it now.
The ICO Picked Reprimands Over Fines, and Two Landed in One Month

The ICO reprimanded ACRO and the Met Police over data protection compliance failings. Five honest, sourced fixes before your own GRC file goes stale too.