RSS Amplifier

News source

SecurityBrief New Zealand

Technology news for CISOs & cybersecurity decision-makers

securitybrief.co.nzSource feed ↗20 articles

Live Last read · last published · next check

Written by

Latest articles

Cohesity adds partner incentives & services specialisation

Partners will get higher rebates and simpler certification rules as Cohesity shifts its channel push towards services-led security sales.

AI is testing the limits of Zero Trust

Breaches are rising as AI tools widen access inside firms, leaving security teams struggling to spot data flows that Zero Trust was built to limit.

Google adds Antigravity to Gemini Enterprise subscriptions

Enterprises can now give developers the coding agent via Google Cloud controls, with pooled budgets, audit logs and IDE support included.

GitLab adds enterprise controls for agentic AI tools

Regulated teams can now keep AI processing inside GitLab Dedicated, with new secret handling, spending caps and security fixes added in 19.3.

Barracuda finds average web app has 20 security flaws

Basic security lapses are leaving web apps exposed, with Barracuda saying routine misconfigurations account for most of 20 flaws per site.

Google Cloud previews quantum-safe key import in KMS

The preview aims to reduce the risk of intercepted keys being cracked later by quantum computers, especially in bring your own key deployments.

Google named Gartner leader for cloud-native platforms

The recognition underlines Google Cloud's push to keep developers on one platform as enterprises move AI agents from prototypes into production.

Google Cloud warns startups on AI scaling pitfalls

Startups risk leaked keys, quota throttling and surprise bills unless they tighten controls as AI prototypes move into production.

Fortinet buys Virtue AI to boost AI security tools

The deal extends Fortinet's reach into AI runtime protection as companies race to secure agents, models and tools across production systems.

Asia Pacific leaders urge overhaul of scam defences

Australia's new scams rules are adding pressure on firms to detect fraud faster as AI-powered attacks expose weak governance and identity controls.

Allure Security uncovers 2,200 phantom bank domains

Hundreds of users could be exposed to fake banking portals built from a low-cost template, as researchers linked 2,200 suspect domains.

Cudy router flaws could allow root command execution

Owners of certain Cudy WR3000 routers face a root takeover risk unless they update firmware to patch two chained flaws.

The hidden security risk in document redaction

Unredacted archive copies can expose personal data long after extraction, increasing compliance risk for firms using AI and high-volume document workflows.

Strike Graph launches Atlas AI adviser for compliance

Compliance teams may gain a new way to spot gaps between audits, as Strike Graph's Atlas uses AI to recommend remedial action with human approval.

PlanRadar launches AI agents for project workflows

Manual follow-up on construction and property projects could be cut from hours to minutes as the software rolls out automated task agents.

Merchants face internal fraud blind spot, report warns

Fewer than four in ten affected merchants are monitoring employee fraud, leaving seasonal hiring spikes to widen losses from chargebacks and refunds.

Canon Singapore launches cyber suite amid threat surge

More than two-thirds of Singapore firms suffered a major cyber incident last year, sharpening demand for faster detection and response.

Abnormal joins OpenAI's Daybreak cyber partner programme

The tie-up will push AI defences into existing enterprise workflows as security teams try to monitor autonomous agents and limit risk.

Endor Labs adds buildless C support to AI SAST tool

Developers can now scan C code earlier in the process, as Endor Labs says its buildless AI SAST found 96 of 102 known bugs in tests.

Professional services face highest cyber intrusion volume

Firms in law, consulting and accountancy are being hit hardest, with attackers exploiting old flaws to reach sensitive client data and networks.