Archives: Security Briefs
Protectt.ai has released an updated version of AppProtectt, its mobile application security solution, featuring advanced Runtime Application Self-Protection (RASP) and AI-driven behavioral monitoring. This update aims to secure high-risk mobile applications in sectors like banking and insurance across the Middle East. The enhancements include device integrity protection and dynamic policy-driven controls, which are crucial for maintaining application integrity and compliance with local regulations.
The article discusses the ongoing privacy divide between the U.S. and Europe, particularly in the context of AI regulation. Europe is adapting its approach with a new digital omnibus package, which aims to simplify compliance and amend the GDPR. This shift highlights a fundamental difference in how personal data is perceived, with Europe emphasizing individual rights while the U.S. operates under a patchwork of state laws. This matters as the evolving AI landscape challenges existing privacy frameworks and user expectations.
Non-human identities, referred to as shadow machines, are increasingly prevalent in cloud and AI environments, often going untracked by traditional Identity and Access Management (IAM) systems. These identities, including API keys and service accounts, can outnumber human identities and pose significant risks due to their lack of visibility and governance. As organizations rely more on automation and AI, the need for effective management of these machine identities becomes critical to prevent unauthorized access and data breaches.
Debt collection agencies are increasingly using AI-driven messaging and automated voice systems to manage consumer calls, offering 24/7 service. A study across 11 European countries found that consumers felt less judged during AI interactions compared to human representatives, with stigma dropping from 19% to 11%. However, while trust remained consistent between both methods, the reliance on AI raises significant cybersecurity and privacy concerns, particularly regarding data security and potential misinformation.
Adidas is investigating a data breach involving a third-party partner that reportedly exposed 815,000 records, including names, email addresses, and passwords. The breach was claimed by the Lapsus$ Group, which announced the incident on February 16. Adidas has stated that its own IT infrastructure and consumer data remain unaffected by this incident.
Organizations are increasingly focusing on Non-Human Identities (NHIs) to secure cloud environments, particularly in industries like financial services and healthcare. NHIs, which include encrypted passwords and tokens, require comprehensive management strategies to mitigate risks. The integration of Agentic AI is gaining traction among cybersecurity professionals, as it enhances threat detection and response capabilities, making it essential for organizations to adopt these advanced technologies for robust security.
Non-Human Identities (NHIs) are transforming cybersecurity by managing machine identities in cloud environments. Effective NHI management involves discovering, classifying, and continuously monitoring these identities to mitigate risks. Organizations can benefit from reduced risk, improved compliance, and increased efficiency by implementing robust NHI strategies, especially in sectors like financial services and healthcare.
Figure Technology Solutions has reported a data breach involving stolen customer information, including names, addresses, and phone numbers. The breach occurred due to a social engineering attack where attackers impersonated a trusted contact to gain access to internal systems. The hacking group ShinyHunters claimed responsibility and released the data after ransom demands were unmet, raising concerns about identity theft and fraud risks for affected individuals.
Agent Goal Hijack is a manipulation technique where attackers alter an AI agent’s objectives. This can lead to unauthorized actions, such as financial transfers or data exfiltration. For instance, the EchoLeak attack can trigger AI to leak confidential files without user interaction, while Goal-Lock Drift uses malicious calendar invites to change agent priorities. As AI agents become more prevalent, understanding these vulnerabilities is crucial for maintaining cybersecurity and privacy.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning about a critical vulnerability in Honeywell CCTV products, tracked as CVE-2026-1670. This flaw, which has a severity score of 9.8, allows unauthorized access to camera feeds and account hijacking by enabling attackers to change recovery email addresses. The affected models include I-HIB2PI-UL 2MP IP and SMB NDAA MVO-3, among others, and as of February 17, 2026, there have been no known public exploitations of this vulnerability.
Navigation
Your 5-Minute Cybersecurity Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.