Security Point Break
Online/Digital
Cybersecurity news and analysis with clarity, candor, and human intelligence. Source
Actions
Media Outlet details
| Scope | Trade/B2B |
|---|---|
| Language | English |
| Country | United States of America |
|
Similarweb UVM |
Request pricing |
|
Comscore UVM |
Request pricing |
Recent Articles
Search ArticlesCrikey! OpenAI Agent Hacks Medicare Portal
An OpenAI agent doing internal research got past the portal’s blocks, reached non-public files and wrote files to an internal server. OpenAI took nearly three months to say so, and independent researchers say OpenAI-linked agents were probing other Australian health sites. The incident was disclosed publicly by Prime Minister Anthony Albanese during a press conference Thursday in New York.
Okta CEO Lays Out AI Agent Security Push at Oktane 2026
LAS VEGAS — On Wednesday, Okta CEO Todd McKinnon outlined a plan to adapt Okta’s core identity technology to manage AI agents and push the company deeper into cybersecurity, beyond its 17-year core business helping users securely access business accounts. “We’re in the perfect position to help match security and innovation by solving the challenges of our industry,” McKinnon said during the Oktane keynote.
Cyber Threat Report: How EU Attacks Compare With the US
DDoS attacks were the most common cyberattack in the European Union last year, but the EU’s own cybersecurity agency says they were mostly noise. The attacks that did the damage came from ransomware and data-theft crews. That’s the core finding of the ENISA Threat Landscape 2026, released Tuesday. The agency analyzed 8,257 incidents recorded during calendar year 2025. DDoS attacks made up 51.3 percent of them, and unauthorized access came second at 39.5 percent.
Okta, 11 Rivals Launch AI Agent ‘Blueprint Alliance’
Twelve companies that spend most days competing for the same security budgets are asking the industry to believe they can govern AI agents as one.
Cheaper Tokens, Bigger Bills: The Real Cost of AI Agents
Imagine spinning up an AI out-of-office reply for your boss and discovering it costs $10,000 a day. That’s what happened to Retool CEO David Hsu when a well-intentioned employee learned the hard way what unchecked AI automation can cost. The mistake? Instead of the autoreply simply stating that Hsu was away, the automation repeatedly scanned Microsoft Teams channels asking, in effect: Do I need to reply to this? Do I need to reply to that? The agent chewed through millions of AI tokens.
Poisoned Plug-ins for AI Coding Agents Open Attack Door
Leading AI coding agents Claude Code, Codex, GitHub Copilot, and Gemini CLI were vulnerable to a zero-click remote code execution flaw that let attackers silently swap a trusted plug-in for a malicious one – no user interaction required. The Air Security team of Or Nevo, Dor Granat, and Niv Hoffman disclosed the flaw, which they’ve named Plugin4Shell. The bug is tied to how coding agents verify plug-ins pinned to a specific, reviewed commit.
Post-Quantum Crypto Could Break OpenID Logins
The race to protect the internet from future quantum attacks is about a specific danger. Today’s online security, namely public-key cryptography, including encryption and digital signatures, relies on mathematical problems that ordinary computers cannot solve fast enough to be useful to an attacker. A sufficiently powerful quantum computer could change that.
Email Marketing Platform Brevo Blamed for ClickFix Scam Targeting Shopify
Brevo, an email marketing and CRM platform, has been implicated in a ClickFix malware operation that rode through its own tracker and form scripts onto customer Shopify sites, exposing visitors to a fake verification prompt that tried to trick them into running malicious commands on their own machines. Brevo hasn’t publicly addressed the Sept. 14 ClickFix/tracker incident researchers at ADAMnetworks documented. But it did admit to a separate, related breach four days earlier. In a Sept.
Immutable Backups vs. Snapshots vs. Everything Else
A recent Cohesity REDLab test detonated 53 ransomware strains against live backup infrastructure – and its own findings show why not all snapshots are immutable backups, and why the difference matters. Get it wrong, and one mistake carries dire consequences. As ransomware increasingly targets backup systems, questions swirl around how an organization can truly protect and preserve its critical data to render minimal disruption and maintain operational continuity as well as preserve its reputation.
God Save the Passkey: UK Kills Passwords for 23 Million Citizens
The United Kingdom is rolling out a new authentication scheme aiming to secure the way citizens sign in to government programs. The country that gave the world beans on toast says that it will now allow citizens to use fingerprint, PIN, or facial recognition to log into online platforms for government services. This will be a full release following an extended pilot program in which more than 300,000 Brits switched to passkeys during the trial.