Black Hat USA kicked off over the weekend and company announcements followed the marketing focus on agentic AI products and services. However, there was more hash than corned beef in these announcements. Most were repackaged current product offerings.
A handful of announcements targeted at Black Hat focused on AI-generated or agentic threats. Most of the announcements repeated announcements prior to the RSA conference,for "agentic AI security" marketing. These include Tenable, Bedrock Data, Cycode, LimaCharlie, Flint AI, GTB Technologies, Strike48, Alice, Menlo Security and Adaptive Security.
Among more interesting legitimate announcements were Backslash Security, and Lineaje.
houlder surfing is probably the easiest security vulnerability to overcome, except to the companies selling solutions for it. In fact, there has been a lively debate CSO Online over whether those who buy a solution might not be intelligent enough to use digital tools.
When AI burst upon the scene a few years ago, it became a boon to the cybersecurity industry. The AI sector pushed a narrative that AI was not just a tool, but a way to replace human workers. Cyber threats exploded and there was greater demand for tools and services. The security industry glommed onto that narrative with AI-driven services. That had the expected result of destroying any goodwill available to AI technology.
However, recent revelations about the effectiveness of AI replacements are making proponents change their tune. What changed? Let’s start with human fertility.
Most businesses and the MSPs who support them have built a reasonably solid security stack. Email filters catch most phishing attempts before they land. Endpoint tools monitor devices around the clock. Security awareness training teaches employees what to watch for. For most organizations, that covers the obvious bases.
For decades, cybersecurity strategy has revolved around a shared assumption: zero-day vulnerabilities are rare, expensive to find, and difficult to exploit at scale. That assumption is now breaking down. The emergence of Mythos, the advanced AI system developed by Anthropic, marks a turning point in how vulnerabilities are discovered, weaponized, and defended against—and it forces security leaders to rethink long-held priorities.
Collaboration tools have fueled configuration drift facilitating phishing attacks since they became widespread during the COVID pandemic. The core of the problem is, as usual, human failure, or more accurately, human procrastination.
Configuration drift happens when vendors and customers join corporate networks with supposedly temporary credentials. When those credentials are not revoked quickly after the collaboration, system settings gradually, almost imperceptibly, diverge from a secure baseline state.
Collaboration tools, beginning with email in the 1970s, were largely clunky, on premises and limited to technically sophisticated organizations. Through the 20 years following the turn of the century they became more sophisticated and allowed inclusion of users outside the networks, like vendors, consultants, and customers. Approximately 400 to 600 million people in professional contexts today use Microsoft Teams, Slack, Google Workspace, Zoom, and dozens of others collaboration tools. Gartner said 90% of Fortune 500 companies standardize on Teams. Moreover, every team that uses collaboration tools configures every collaboration tool differently with no central enforcement.
“Configuration drift is one of the most under-recognized risks in modern cybersecurity,” said Garrett Hamilton, CEO and founder of Reach Security. “Security tools are constantly changing due to updates, new features, and operational adjustments. Over time, those changes create drift that quietly weakens defenses. Organizations need a continuous way to validate that the controls they depend on are still working as intended.”
A public relations firm in the United Kingdom said the quiet part out loud about cybersecurity marketing: that much of it is fiction if not outright fraudulent.
Whiteoaks International surveyed 152 senior marketing, PR and communications professionals in the country, working in cybersecurity. The results found 30% said they helped produce content that was excessive, misleading, or unsubstantiated. More than half (51%) said they had seen this type of messaging in the sector.
Many shady practices on the internet are scams, but some seem "scammy." Cyber Protection Magazine came across one such operation.
While ordering food on Grubhub recently, a pop-up appeared telling us we “earned a reward!” Clicking on the link it offered a $20 rebate on my next purchase. Sounds good, doesn’t it? Not really.
Note: All the companies involved in this transaction will be named in this article. All were contacted for comment. Only Grubhub responded with a request for additional information and then went silent.
Even though the transaction was occurring within the Grubhub mobile app, the pop-up was from an organization called Cashback-Now. The company name is relatively common for several companies, all apparently running the same type of business. In this case the URL is cashback-now.com.
We use cookies on our website to give you the most relevant experience by remembering your preferences and repeat visits. By clicking “Accept”, you consent to the use of ALL the cookies.
This website uses cookies to improve your experience while you navigate through the website. Out of these cookies, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may have an effect on your browsing experience.
Necessary cookies are absolutely essential for the website to function properly. This category only includes cookies that ensures basic functionalities and security features of the website. These cookies do not store any personal information.
Any cookies that may not be particularly necessary for the website to function and is used specifically to collect user personal data via analytics, ads, other embedded contents are termed as non-necessary cookies. It is mandatory to procure user consent prior to running these cookies on your website.