#Zero Trust

Every story tagged Zero Trust, curated for CIOs and IT leaders — ranked by source credibility, engagement, and freshness.

34 stories · open in the command center

  • Security & PrivacyCIO Online4m

    Why mainframe security requires continuous verification

    Mainframes remain critical infrastructure for 71% of Fortune 500 companies and 97% of global banks, yet many organizations inadequately protect them with outdated annual security assessments rather than continuous verification. As AI accelerates vulnerability discovery and hybrid architectures expand the attack surface, treating mainframes as isolated systems is no longer viable—CIOs must implement continuous visibility and risk monitoring across z/OS environments equivalent to the rest of the enterprise. The cost of delayed detection has compressed dramatically, making periodic assessments insufficient and requiring real-time security controls validation to prevent breaches of high-value transactional data.

  • Security & PrivacyTechMemeKyle Alspach2m

    ThreatLocker raised a $190M Series F led by Elephant as it looks to extend its zero-trust enterprise security platform to protect against AI-related risks (Kyle Alspach/CRN)

    ThreatLocker's $190M Series F funding signals strong market confidence in zero-trust security models and indicates that AI-related cybersecurity threats are becoming a critical business priority for enterprises. For IT leaders, this reflects an industry shift toward comprehensive security platforms that address both traditional threats and emerging AI-driven attack vectors, requiring organizations to evaluate whether their current security architecture can adequately protect against AI-related risks. The investment underscores that zero-trust frameworks are evolving from optional security enhancements to essential infrastructure components in the enterprise security stack.

  • Security & PrivacyHacker News3m

    Authorize, don't authenticate

    This article proposes a fundamental shift in how web applications manage user data: moving from authentication-based access (where users prove identity to applications) to authorization-based access (where users control their own databases and grant applications permission to use them). By decoupling applications from data storage through open protocols like OAuth2, users gain ownership and control of their data while reducing the risk of vendor lock-in, data breaches, and unauthorized data exploitation. For IT organizations, this represents an emerging architectural pattern that could reshape data governance, reduce security surface areas, and shift liability away from application providers toward user-controlled or federated database custodians.

  • Security & PrivacyVulners1m

    CVE-2026-6540: Calico's Application Layer Policy (disabled by default), which enforces HTTP rules through Dikastes, fails to perform UR... (CVSS 7.9)

    Calico's Application Layer Policy (disabled by default), which enforces HTTP rules through Dikastes, fails to perform URL path normalization. As a result, HTTP requests using path-traversal segments, encoded slashes, or repeated slashes are not correctly evaluated by Prefix path rules. Dikastes authorizes the request under the permitted prefix while the downstream workload or a fronting proxy normalizes the path and serves the restricted endpoint. An attacker with network access and no special RBAC can potentially reach HTTP endpoints the policy was intended to restrict.

  • Security & PrivacyPeople & VoicesGeorge Finney1m

    Zero Trust and the Parable of the Oranges

    Zero Trust security requires IT teams to adopt an 'assume breach' mindset where every member proactively identifies vulnerabilities and understands the broader business context of their work, rather than simply executing tasks without strategic awareness. This cultural shift from reactive to proactive security—exemplified by limiting access privileges, hardening systems, and asking clarifying questions—creates accountability and prevents costly security gaps that result from cutting corners or operating in silos. For CIOs, implementing Zero Trust team principles means investing in security culture and communication as much as technical controls, ultimately reducing breach risk and operational inefficiencies.

  • Security & Privacy9to5MacArin Waichulis2m

    Security Bite Podcast: Data brokers are breaking the internet

    Data brokers are systematically collecting and monetizing personal data at scale, creating significant security and privacy risks that are amplified by AI integration and deceptive data harvesting practices. IT organizations must recognize that employee and customer data vulnerabilities extend beyond traditional network security into third-party data ecosystems where information is being bought, sold, and weaponized. This emerging threat requires organizations to implement comprehensive data governance strategies, conduct digital footprint audits, and advocate for regulatory compliance while educating stakeholders about the expanding attack surface created by uncontrolled data brokerage.

  • Security & PrivacyVentureBeattaryn.plumb@venturebeat.com8m

    Brex built its AI agent policy by watching what agents actually do, not by writing rules first

    Brex developed CrabTrap, a network-layer AI agent governance platform that shifts security enforcement from traditional SDK guardrails to a centralized HTTP/HTTPS proxy using LLM-as-judge decision-making, enabling IT organizations to safely deploy capable agents while maintaining control. Rather than pre-defining rigid policies, CrabTrap learns governance rules from observed agent behavior in production, dramatically improving policy effectiveness and reducing the dangerous tradeoff between agent capability and safety. This approach represents a fundamental architectural shift for enterprise IT: moving from preventive rule-based controls to adaptive, traffic-based enforcement that scales with agent complexity.

  • Security & PrivacyVentureBeatAndre Durand6m

    Zero trust must now move at agent speed

    As AI agents operate at speeds far exceeding human capabilities, enterprises must immediately implement zero trust security architecture rather than treating it as a future initiative—traditional identity management granting broad, long-lived permissions creates unacceptable risk exposure when agents can execute thousands of actions in minutes. CIOs must redesign access control to move from login-time verification to real-time decision-making at every action, eliminate shared credentials and cloned human accounts in favor of individual agent identities, and enforce policies at API gateways and agent control points. Additionally, organizations need to establish multi-agent review frameworks where independent agents verify each other's outputs, since human review cannot scale to agentic speed while maintaining the efficiency gains that justify AI agent deployment.

  • Security & PrivacyArs TechnicaDan Goodin2m

    The US government warns that Russia state hackers are coming after your router

    Russian state-sponsored hackers are systematically compromising home and small office routers worldwide to create proxy networks for attacking critical infrastructure in government, defense, energy, and financial sectors, exploiting poorly configured SNMP protocols and default credentials. This threat creates significant supply chain and network perimeter risks for enterprises, as compromised third-party devices can be weaponized to obscure attack origins and bypass corporate security defenses. IT organizations must treat residential network security as part of their broader threat surface, as adversaries use these devices as stepping stones to probe and infiltrate sensitive systems.

  • Security & PrivacyHacker News3m

    Unauthenticated RCE in Motorola's MR2600 Router

    A critical unauthenticated remote code execution vulnerability exists in Motorola MR2600 routers due to flawed authentication checks and improper firmware validation, allowing attackers to upload and flash malicious firmware without credentials. This vulnerability directly threatens network perimeter security, as compromised routers can serve as entry points for lateral movement and data exfiltration within enterprise environments. IT organizations must immediately inventory affected devices, apply available patches, and implement network segmentation to isolate vulnerable routers from critical infrastructure.

  • Security & Privacy9to5MacArin Waichulis2m

    Security Bite: Passkeys were supposed to have killed the password by now…

    Despite significant industry momentum—with 15+ billion accounts now supporting passkeys and major tech companies advancing adoption—passwords remain dominant due to unresolved operational challenges around account recovery, cross-platform portability, and incomplete vendor implementation. CIOs must recognize that while passkey cryptography is inherently superior and phishing-resistant, the transition to passwordless authentication will remain incomplete until the industry standardizes recovery mechanisms, enables seamless credential portability across ecosystems, and commits to fully removing legacy password fields. Organizations should prepare for a prolonged hybrid authentication environment and evaluate passkey-capable identity solutions that bridge current gaps rather than expecting near-term password elimination.

  • Security & PrivacyHacker News3m

    Rayfish, Peer-to-peer mesh VPN with no server to trust

    Rayfish is a peer-to-peer mesh VPN solution that eliminates traditional server infrastructure, reducing operational complexity and security risks associated with centralized trust models. This serverless architecture presents IT organizations with potential cost savings and improved data sovereignty, while requiring evaluation of compatibility, scalability, and management capabilities for enterprise deployment.

  • Security & PrivacyCIO Online3m

    La resiliencia de identidad empieza donde termina el ‘backup’

    Identity has become the new corporate perimeter, and traditional backup strategies are insufficient for business continuity—organizations must shift focus from prevention to recovery resilience of identity systems like Active Directory, which require specialized recovery procedures different from standard infrastructure. Cyberattacks increasingly target identity infrastructure for persistence and privilege escalation, meaning compromised systems can remain vulnerable even after restoration unless recovery processes incorporate cyber-forensic validation. CIOs must measure preparedness not by backup capabilities alone, but by demonstrable recovery effectiveness through continuous testing and secure restoration procedures that restore business-critical processes, not just technical components.

  • Security & PrivacyTechMemeJoseph Cox2m

    A researcher says a vulnerability in Apple's Hide My Email tool lets anyone discover a real email address; first reported in June 2025, Apple is yet to fix it (Joseph Cox/404 Media)

    A critical vulnerability in Apple's Hide My Email feature, reported since June 2025 and still unpatched, allows attackers to discover users' real email addresses, undermining a core privacy protection mechanism. This disclosure highlights the risk of relying on third-party privacy tools and raises questions about Apple's vulnerability remediation timelines, which could impact enterprise security posture and employee trust in company-approved privacy solutions. IT organizations must reassess their email privacy strategies and consider the broader implications of unresolved security issues in widely-used Apple services.

  • Security & PrivacyVentureBeatlouiswcolumbus@gmail.com9m

    Copilot searched your mailbox. LiteLLM handed out admin keys. Run this 5-check audit before your stack is next

    Recent critical vulnerabilities in enterprise AI tools (Microsoft Copilot, LiteLLM, Langflow) exploit a common architectural failure: the absence of trust boundaries between AI systems and external inputs, enabling privilege escalation, data exfiltration, and remote code execution at scale. This represents a systemic security gap across the AI stack that the market is already pricing in—CrowdStrike's AI detection revenue grew 250% sequentially—demanding immediate governance and architectural redesign. IT organizations must treat AI security as a foundational infrastructure concern spanning development, runtime, identities, and cloud, rather than siloed technology deployments without proper access controls or input validation.

  • Security & PrivacyCIO Online3m

    Why most zero-trust programs stall after year one

    Most zero-trust implementations fail to sustain momentum beyond year one due to operational complexity, proliferating exceptions, and fragmented ownership across security, infrastructure, and application teams—not technology limitations. The hidden operational costs and lack of disciplined governance transform what appears as successful early wins into unsustainable sprawl, requiring organizations to shift from project-based thinking to treating zero-trust as an ongoing operational discipline with standardized processes and centralized monitoring.

  • Security & Privacy9to5MacArin Waichulis2m

    Security Bite Podcast: WWDC26 security and privacy rundown, big changes coming for users and admins

    Apple's WWDC26 announcements introduce significant security and privacy changes including new iPhone recovery modes, enhanced Find My privacy, agentic AI features in Passwords, and stricter parental controls that will require IT organizations to reassess their device management and compliance strategies. These updates, particularly the new privacy architecture for Apple Intelligence and AI-powered features, have direct implications for enterprise administrators managing both personal and work accounts on managed devices. CIOs must evaluate how these changes impact their current Mobile Device Management (MDM) strategies, security posture, and the need for updated policies around the new capabilities.

  • Enterprise TechThe VergeTom Warren2m

    Microsoft restricts Claude Fable for employees over data retention concerns

    Microsoft has restricted internal employee access to Anthropic's new Claude Fable 5 model due to data retention requirements that conflict with Microsoft's zero-data-retention policies, creating legal compliance concerns around customer data and confidential information handling. This restriction signals that enterprises must carefully evaluate third-party AI models' data governance practices before adoption, as safety-focused architectures may introduce unacceptable data residency and retention risks. The situation highlights a critical tension between AI capability advancement and enterprise security/compliance requirements that will likely affect broader AI procurement decisions across the industry.

  • Security & Privacy9to5MacArin Waichulis2m

    Security Bite Q1 Review: May 2026

    Q1 2026 threat analysis reveals that social engineering techniques—specifically ClickFix attacks—have become the dominant macOS attack vector, accounting for nearly 47% of initial access incidents, with threat actors increasingly targeting developers as high-value entry points for deeper compromise. Apple's reactive security measures, while improving, are being rapidly circumvented by attackers adapting techniques to bypass new defenses, creating an ongoing arms race that requires organizations to prioritize user awareness and behavioral controls alongside endpoint protections. IT leaders must recognize that traditional perimeter and signature-based security are insufficient against these socially engineered attacks, demanding a shift toward Zero Trust architectures and comprehensive EDR solutions tailored to Apple ecosystems.

  • Security & PrivacyCIO Online3m

    AI 보안, 이제는 모델이 아니라 시스템 중심으로 접근해야

    Organizations must shift AI security strategy from focusing solely on model vulnerabilities to comprehensive system-level protection, as autonomous AI systems operate differently from traditional software and require defense mechanisms beyond conventional guardrails. This paradigm shift demands IT leaders evaluate their entire AI infrastructure—including data pipelines, APIs, infrastructure, and operational environments—to address security risks that span the complete AI system lifecycle. The research indicates that the first five years of AI deployment will be critical; organizations that fail to implement holistic, system-centric security frameworks now risk significant vulnerabilities as AI systems become more autonomous and integrated into business operations.

  • Security & PrivacyCIO OnlineLori Robinson3m

    Real-time governance: The key to proactive security

    Real-time governance replaces static, periodic access reviews with continuous, context-aware evaluation of identity and access requests, enabling organizations to adapt security controls as rapidly as threats and business conditions change. This shift from role-based provisioning to dynamic risk assessment—incorporating device posture, location, behavior, and threat signals—aligns with zero trust principles while reducing friction by granting seamless access when risk is low and escalating controls only when necessary. IT organizations must begin modernizing their identity infrastructure now, as traditional access certification models are failing to scale in environments with ephemeral, non-human identities.

  • Security & PrivacyVentureBeatlouiswcolumbus@gmail.com7m

    MFA verifies who logged in. It has no idea what they do next.

    Multi-factor authentication alone is insufficient for modern security—it verifies identity at login but provides no visibility into post-authentication behavior, leaving enterprises blind to lateral movement and privilege escalation by attackers using stolen credentials. With average breach dwell time dropping to 29 minutes and 82% of attacks deploying no malware, adversaries have shifted to credential theft and social engineering (accelerated by AI-generated phishing at 54% click-through rates), exploiting a critical architectural gap where session token governance falls between IAM and SecOps ownership. CIOs must treat post-authentication session management as a business-critical risk requiring cross-domain visibility, rapid token revocation, and continuous behavioral validation rather than relying on a perimeter-based security model.

  • Cloud & InfrastructureCIO Online2m

    Why physical security belongs in the hybrid cloud

    Hybrid cloud architectures for physical security—combining on-premises systems, edge analytics, and cloud orchestration—are emerging as the strategic standard, with IT adoption expected to nearly double from 27% to 44% over the next two years. This shift delivers significant business value including reduced total cost of ownership, regulatory compliance, real-time threat detection, and a stronger cybersecurity posture through shared responsibility models with vendors and system integrators. CIOs should recognize that true cloud security solutions are inherently hybrid, requiring deep technical expertise and potentially third-party integration support to balance feature richness, regulatory constraints, and scalability needs.

  • Security & PrivacyCIO Online6m

    The zero-trust paradox: Why systems built to eliminate trust may be destroying it

    Zero-trust security architectures effectively reduce technical risk but paradoxically erode organizational trust by treating employees as continuous threats, creating surveillance-like experiences that increase risk aversion and reduce innovation. When combined with AI-mediated decision-making systems, zero-trust logic extends beyond infrastructure into HR and customer-facing applications, creating technically secure but experientially corrosive environments that undermine institutional trust at a time when it is already critically low. IT leaders must balance security verification with human trust-building, recognizing that cryptographic assurance and audit compliance cannot substitute for transparency, accountability, and the psychological safety required for organizational effectiveness.

  • Enterprise TechCIO Online2m

    Agentic AI won’t scale on ambition. It will scale on infrastructure.

    Agentic AI adoption is accelerating across enterprises, but 62% of organizations lack the secure infrastructure, identity management, and data protection needed to scale safely—making robust networks and observable security the critical differentiator for competitive advantage. CIOs must shift infrastructure from a back-office function to a strategic business priority, as 96% of executives recognize that real-time AI depends on resilient networks that can support agents operating across applications, clouds, and data centers. With organizations investing 37% of technology budgets into agentic AI and 55% of employees expected to collaborate with AI agents within 24 months, the companies that win will be those that build secure, observable, and governable infrastructure—not those with the largest AI budgets.

  • Security & PrivacyCIO Online4m

    Solving healthcare’s unique security challenges: The role of zero trust and SASE

    Healthcare organizations face exponentially expanded attack surfaces due to distributed workforces, shared devices, and uncontrolled shadow AI adoption, with breach costs averaging $9.77 million—the highest across industries. Zero Trust combined with SASE architecture enables healthcare IT leaders to replace fragmented legacy security tools with AI-powered, context-aware platforms that enforce adaptive access policies based on real-time risk signals, allowing secure care delivery without friction or performance bottlenecks. This consolidated approach addresses healthcare's unique challenges including shadow AI, remote care, and shared workstations while maintaining compliance and clinician productivity.

  • Security & PrivacyArs TechnicaDan Goodin2m

    Zero-day exploit completely defeats default Windows 11 BitLocker protections

    A critical zero-day exploit (YellowKey) completely bypasses default Windows 11 BitLocker encryption protections, allowing attackers with physical device access to gain full drive access in seconds by exploiting Transactional NTFS vulnerabilities. This represents a fundamental security failure for organizations that depend on BitLocker for regulatory compliance and data protection, requiring immediate remediation across enterprise deployments. The vulnerability exposes a deeper cross-volume manipulation risk in Windows file systems that extends beyond BitLocker and demands urgent patching and architectural review.

  • Security & PrivacyHacker News3m

    Stop MitM on the first SSH connection, on any VPS or cloud provider

    A new open-source technique using cloud-init protects SSH connections to new VMs from man-in-the-middle attacks on first connection by injecting a temporary SSH host key that is immediately replaced with permanent keys, eliminating the security gap that exists with traditional Trust-On-First-Use approaches. This provider-agnostic solution addresses a critical vulnerability in cloud infrastructure provisioning where attackers can intercept initial SSH connections before host key verification, protecting both administrator workstations and VM integrity while preventing exposure of sensitive key material through cloud metadata services. IT organizations deploying VMs across any cloud provider can now eliminate a significant attack surface during the most vulnerable initialization phase without relying on proprietary vendor solutions.

  • Security & PrivacyCIO Online4m

    While you embrace AI, fix this fast

    Organizations rapidly deploying AI risk amplifying security vulnerabilities if foundational network architecture is not secured first; reducing attack surface and eliminating lateral movement through Zero Trust principles are critical prerequisites before scaling AI initiatives. Without these controls, AI-powered attacks can discover and exploit infrastructure at machine speed, and compromised AI agents can spread breaches across systems exponentially faster than traditional threats. IT leaders must prioritize architectural redesign around Zero Trust before accelerating AI deployments to ensure innovation proceeds with containment and risk mitigation in place.

  • Enterprise TechCIO Online4m

    How NOV is moving from FOMO to calculated scaling

    NOV's CIO shares how the company shifted from AI experimentation driven by FOMO to a disciplined, enterprise-scale deployment of generative AI across 25,000 employees, achieving 50% adoption and measurable productivity gains while maintaining human accountability and safety-critical controls. By implementing zero-trust security architecture and establishing clear guardrails around shadow AI, NOV demonstrates that industrial-grade AI requires balancing innovation velocity with rigorous governance, particularly in safety-critical operations where AI serves as advisor, not decision-maker. The strategic imperative for IT leaders is recognizing that LLMs will become foundational infrastructure like email, requiring organizations to reframe their talent development strategies and investment justification from traditional ROI calculations to capability enablement.

Browse all tags