CFOtech US - Technology news for CFOs & financial decision-makers

Data exfiltration stories

Flux result f5d018a7 4220 4dc5 8456 e0cf4c8f98ca

DTEX warns Telegram & WhatsApp AI agents risk exfiltration

Last week
#
virtualisation
#
physical security
#
dlp
DTEX warns that AI agents controlled via Telegram and WhatsApp can quietly access files, expose credentials and exfiltrate data from endpoints.
Flux result 142b294a 6c85 4bf1 91a4 f959c806058e

Akto widens AI agent security with new integrations

Last week
#
digital transformation
#
cloud security
#
application security
Akto partners with LangChain, Portkey, TrueFoundry, Arcade and LiteLLM to embed runtime safeguards across the AI agent stack.
Flux result 77e66548 8da3 4d31 8b9c 5f7d65d5e672

Acronis launches AI protection for managed service providers

Last week
#
data protection
#
digital transformation
#
cloud security
Acronis rolls out GenAI Protection for managed service providers to spot shadow AI, curb data leakage and block prompt injection.
Flux result 98c90454 e22b 40d3 87b0 b943c20a210c

Zscaler joins Anthropic Project Glasswing on cyber AI

Last week
#
firewalls
#
vpns
#
network security
Zscaler joins Anthropic's Project Glasswing to test Claude Mythos Preview in software scans, as the firm pushes zero trust against AI-driven attacks.
Flux result ebf65211 8555 4f44 8fa9 1d2df642919d

CIS launches AI security guides for models & agents

Last week
#
digital transformation
#
application security
#
physical security
CIS, Astrix and Cequence publish AI security guides for large language models, autonomous agents and MCP environments.
Flux result cfe2b47e d06e 4554 b1ed 213b9e834f88

Healthcare hit by ransomware every 10 hours, Securin says

Last week
#
firewalls
#
vpns
#
ransomware
Securin says healthcare faces ransomware attacks about every 10 hours, with hospitals repeatedly hit via known flaws, stolen credentials and remote access.
Flux result 808b973b 89ac 4abe 9c99 1ff6fe4ed0a5

LangWatch launches open-source tool for AI red-teaming

Last week
#
data protection
#
devops
#
data analytics
LangWatch releases open-source AI red-teaming framework to expose hidden vulnerabilities in production agents through multi-turn attack simulations.
Rishi

Mythos changes everything: Is your AI agent security ready?

Last week
#
firewalls
#
data protection
#
dr
Anthropic's Mythos spots corporate network attacks in hours, while security experts warn unmanaged AI agents are becoming a critical enterprise risk.
202604   tony burnside   netskope   headshot

Netskope's Tony Burnside - visibility is key to AI security

This month
#
cloud security
#
advanced persistent threat protection
#
socs
Netskope's Tony Burnside warns AI agents are creating hidden east-west traffic, calling for omni-directional controls and smarter DLP to stop data leaks.
Flux result e138c2c7 10d5 44b8 b5f2 1566c9a08fa9

Proofpoint flags mailbox rule abuse in Microsoft 365

This month
#
edutech
#
mfa
#
cloud security
Proofpoint says mailbox rule abuse is becoming a routine Microsoft 365 takeover tactic, helping attackers hide alerts, hijack threads and drive fraud.
Flux result 20e12820 27f4 4e8a 9da9 1c2ee2ea902d

Sonatype warns of surge in trusted open-source malware

This month
#
application security
#
devsecops
#
supply chain
Sonatype flags 21,764 malicious open-source packages in Q1 2026, with npm hit hardest as attackers used trusted workflows to steal secrets.
Flux result f3a23773 f3c5 4ab1 8315 098438942b1a

AI agents expose major API security gap, Salt warns

This month
#
manufacturing
#
digital transformation
#
cloud security
Salt warns AI agents are widening the API security gap, with 92% of organisations still short of advanced defences and 47% delaying releases.
Franklin

From DSPM to data protection: Closing the last mile on sensitive data in the era of AI

This month
#
storage
#
data protection
#
cloud security
AI-era data security needs more than DSPM visibility, as firms must track how sensitive information moves and enforce controls in real time.
Sarah wilkinson

Small alert, big defense: Inside a SOC's early-morning response

This month
#
vpns
#
ransomware
#
mfa
UK SOC spots Monday-morning conditional access failure from Germany, helps reset compromised Microsoft 365 account before attackers can strike.
Flux result 3a2b4af2 8b5c 40e9 ae67 f7ddfcdfbb0b

Nutanix & NetApp launch virtualisation migration tie-up

This month
#
storage
#
virtualisation
#
data protection
Nutanix and NetApp team up on migration tools to help enterprises modernise virtualised systems, cut complexity and bolster ransomware defences.
Flux result 9a5fbf33 4cd5 4f62 a705 c822376a1b61

Claude Code flaw leaves deny rules vulnerable in long workflows

This month
#
cloud security
#
application security
#
socs
Anthropic’s Claude Code is under scrutiny after researchers found deny rules can weaken in long workflows, raising fresh concerns for AI-driven development.
Flux result 2a0e4632 8072 4ed3 9f1d 043e15c75687

Microsoft warns of Storm-1175's rapid Medusa attacks

This month
#
ransomware
#
cybersecurity
#
microsoft
Microsoft says Storm-1175 is exploiting newly disclosed flaws within hours, hitting organisations in the UK and elsewhere with fast-moving Medusa ransomware.
Flux result 8ebd1272 347f 4407 acbc d4999522fad4

Permiso launches sandbox for AI agent skill security

This month
#
firewalls
#
network security
#
cloud security
Permiso launches SandyClaw sandbox to detonate AI agent skills and expose hidden runtime risks before they reach enterprise systems.
Flux result b89f46aa 0edc 4965 9487 cdd46bf5a418

ChatGPT flaw let hackers steal data via DNS queries

This month
#
firewalls
#
data protection
#
devops
ChatGPT flaw may have let attackers siphon sensitive user data via DNS queries, prompting OpenAI to issue a fix after researchers exposed the bug.
Flux result 40d5bcdc 27bf 48a0 8c08 a87cb6325b88

Zscaler flags Xloader malware's tougher obfuscation

This month
#
malware
#
firewalls
#
encryption
Zscaler says Xloader malware has added layered encryption, decoy servers and new obfuscation tricks to hinder analysts.