Innovation in healthcare: A hacker's dream and CISO's nightmare?
Opinion piece argues AI could transform healthcare but warns the sector's surging cyber threats demand security-by-design and workforce awareness.
The commentary highlights AI's healthcare potential, citing Stanford's deep learning algorithm matching dermatologists at skin cancer detection and a UK review claiming full automation could save the NHS nearly £13bn annually. It notes healthcare experienced the largest year-over-year increase in cyber attacks, including targeting by state-sponsored groups such as Hidden Cobra. The piece urges organizations to build security in from the outset, hire cyber talent, address insider threats, and protect patient trust when rolling out AI.
The inconvenient truth about AI pentesting: someone has to check all the work
Survey of 158 practitioners shows AI pentesting floods teams with findings, creating 'validation debt' most teams cannot process.
The article argues AI pentesting creates 'validation debt': discovery scales far faster than teams' ability to verify AI-generated findings. In a survey of 158 practitioners, only 20.3% had workflows to triage more than 500 AI-generated candidates per engagement, while 29.7% called such volume unmanageable. One respondent spent two days validating 300 AI findings, of which 250 were duplicates, non-exploitable, or nonexistent. The author recommends capacity planning, ruthless deduplication, and risk-based prioritization before adopting AI pentesting tools.
The hidden work of modernizing Malwarebytes
Malwarebytes details its migration of Windows product managed components to .NET 10, citing security, supportability, diagnostics, and performance benefits.
Malwarebytes says it migrated the managed portions of Malwarebytes for Windows to .NET 10 while leaving native drivers and the detection engine untouched. The vendor cites a supported runtime, safer defaults, stronger cryptography, better diagnostics, and JIT/GC performance improvements as benefits. The migration also deprecated Windows 7 support, and the company applies staged rollouts and automated validation because its code runs with elevated privileges on millions of endpoints. No vulnerabilities or incidents are described.
Dataminr uses agentic AI to predict and verify security threats
Dataminr launches agentic AI capabilities for corporate security, adding automated event corroboration, context, and near-term threat prediction.
Dataminr Advanced for Corporate Security introduces Agentic Corroboration, Agentic Context, and Near-Term Predictive Intelligence, now generally available, moving the company from real-time alerting to what it calls Autonomous Real-Time Intelligence. The product relies on more than 60 fine-tuned task-specific LLMs trained on a 10+ year proprietary event archive rather than general-purpose frontier models. Upcoming releases include ReGenAI Tailored Live Briefs, a Watchlist Agent, Agentic Search, and an Advanced API suite.