Applications average 22 critical vulnerabilities while teams fix just 3.4 per month, exposing a widening AppSec gap that AI is making harder to close.
Featured
CYBR.SEC.CON LaunchPad finalist VisionHeight is building a pre-attack intelligence layer designed to give AI-driven SOCs the external threat data they need to move from reactive detection to proactive defense.
Dragos CEO Robert M. Lee has repeatedly warned that under-resourced water utilities cannot defend themselves against growing cyber threats alone. A new federal-state-industry initiative in Texas aims to start closing that gap.
Community Corner
See allFrom the CYBR.SEC.Community
What Radio Jamming Taught Me About DDoS
From Army signal intelligence and radio jamming to modern DDoS defense, the same lessons in reconnaissance, timing, disruption and adaptation reveal how attackers overwhelm networks — and how defenders can stay ahead.
The Agent Died. The Delegation Didn't.
Once the work can move from agent to agent, killing the agent is no longer the same thing as stopping the work.
Returning Continuity: What AI Is Teaching Us About Cybersecurity
Yesterday's me made a move. Today's me inherits the consequences. Tomorrow's me will inherit a different world again.
The Human Factor in IAM: Why Identity Programs Succeed or Fail
Most IAM failures don't start with a broken platform. They start with a person making a reasonable decision under bad conditions.
AI Created the Vulnpocalypse. AI Will Also Fix It.
AI has broken traditional vulnerability management by accelerating vulnerability discovery and exploitation, but it may also be the only technology fast enough to help defenders regain the advantage.
Latest Articles
See all
LaunchPadCYBR.SEC.CONAI and Insider Risk
Above Security Takes on Insider Risk With AI at CYBR.SEC.CON LaunchPad
CYBR.SEC.CON LaunchPad finalist Above Security is using AI-driven behavioral analysis and real-time employee coaching to prevent insider risk before it becomes a security incident.
AI SOCSOCCISA
CISA’s ‘Tale of Two SOCs’ Shows Why AI Guardrails Need Humans in the Loop
CISA’s “Tale of Two SOCs” red team research shows why SOC automation, AI guardrails and human authority to contain attacks must evolve together.
Cybersecurity influenceHuman Risk ManagementCYBR.Minded
Cybersecurity Influence Starts With Explaining Risk Clearly
Cybersecurity leaders can have the right technical answer and still fail to influence business decisions when they cannot translate cyber risk into language executives understand, trust and act on.
Indicators of CompromiseAI security risks
AI Is Breaking the Indicators of Compromise Model
AI-powered attacks are moving faster than traditional IOC sharing can keep up, forcing security teams to rethink how they detect threats and share threat intelligence.
CYBR.SEC.CONLaunchPointCISO
CISOs: Stop Buying Security Tools Without Your Practitioners
Cybersecurity tool selection works better when CISOs give security practitioners a voice in buying decisions, improving adoption, security outcomes and team retention.
CYBR.SEC.CONLaunchPointCybersecurity Startups
Cybersecurity Has a Startup Discovery Problem
Security leaders need emerging cybersecurity technology faster than ever, but finding the startups actually worth their time is getting harder as AI accelerates both innovation and cyber threats. Starting with CYBR.SEC.CON, we plan to do something about it.
Hacking BackTrump AdministrationOffensive Security
Trump's 'Hack Back' Memo Lets (Some) Private Companies Strike Back Against Cybercrime Gangs
Many believe cybercriminal asymmetry allows foreign cybercrime gangs to operate with near impunity, and that decades of legislative fixes, like the repeatedly stalled Active Cyber Defense Certainty Act, have gone nowhere. Others are concerned that the doctrine may create more mayhem than it solves.
Podcasts & Video
See all
Video
From AI Hacking Hype to Enterprise Reality: What Mythos Actually Changes
Justin “Hutch” Hutchens examines the gap between sensationalized narratives around “AI hacking” and the pragmatic, risk-informed reality of AI adoption in enterprise environments.
Video
Stealing Trust: Modern Social Engineering from Phishing to AI-Powered Vishin
The talk “Stealing Trust: Modern Social Engineering from Phishing to AI-Powered Vishing” by Chris Russell explores the evolution and increasing sophistication of social engineering attacks, emphasizing how adversaries now leverage artificial intelligence to automate and personalize deception.
Video
Offense for Defense
Tim Medin’s talk “Offense for Defense” is a practical, engaging, and humorous guide for blue teamers, defenders, and IT professionals on leveraging offensive security tools and mindsets to proactively strengthen their organizations—without needing to become full-time red teamers.
Video
Hacking Transit: Repurposing Surplus Devices for Fun and Shenanigans
Transit hardware hacking shows how surplus public transportation devices can be reverse engineered, repurposed and explored to uncover how real-world systems work — and where unexpected security weaknesses may hide.
Video
A Brief Introduction to Cognitive Warfare
Cognitive warfare turns the human mind into an attack surface, using disinformation, emotion, identity and social manipulation to exploit cognitive biases, erode trust and shape how people perceive reality.
Video
Building Hackbots
AI-powered hackbots are reshaping cybersecurity by automating reconnaissance, vulnerability discovery and attacks at machine speed, forcing defenders to rethink how they detect and respond to threats.
Podcast