< ciso
brief />
Tag Banner

All news with #zero trust tag

235 articles · page 2 of 12

Google Cloud VPC-SC Policy Intelligence Enhancements

🔒 Google Cloud introduces enhanced VPC Service Controls policy intelligence features — the Violation Analyzer and Violation Dashboard — to simplify perimeter management and reduce MTTR for access denials. BlackLine uses these tools to protect sensitive financial data, troubleshoot violations with a single token, and adapt perimeters via ingress/egress and access-level adjustments. The tools provide unified visibility, contextual reports, and filtering to support deployment, monitoring, investigation, and policy refinement.
read more →

Defending Water and OT Systems from Internet Risk

🔒 Recent cyberattacks against U.S. water and wastewater systems show that OT impact extends beyond data loss to public health, environment, and community functions. Distributed architectures, legacy controllers, remote cellular sites, and accumulated third-party access increase the attack surface. Government advisories document exploitation of internet-facing PLCs and HMIs, while new legislation seeks to expand EPA cybersecurity authority. Fortinet recommends unified OT architectures, secure cellular connectivity, ZTNA, and IEC 62443-4-2–certified solutions for consistent protection.
read more →

Extend data perimeter to AWS Management Console

🔒 AWS announces general availability of AWS Management Console Private Access, enabling VPCs with no internet connectivity to access supported service consoles via AWS PrivateLink endpoints. This routes authentication, static assets, console-only APIs, and service API calls through interface VPC endpoints, removing the need for an internet gateway or NAT. The feature is available in all AWS commercial Regions for a select set of consoles and integrates with sign-in resource control policies, VPC endpoint policies, and service control policies to enforce identity, resource, and network perimeters.
read more →

Why Identity Fabric Matters for Modern Security

🔍 An Identity Fabric unifies fragmented identity systems to provide runtime visibility across applications, APIs, and infrastructure. It bridges design-time policies with runtime behavior to reveal identity drift, orphaned credentials, and unobserved attack paths. The approach is essential for hybrid and multi-cloud environments, especially to govern non-human and AI identities and enable continuous least-privilege enforcement.
read more →

Designing Systems to Earn Customer Trust

🔒 Over years of building large-scale personalization and commerce systems, the author argues that compliance alone does not create customer trust. Real trust comes from ensuring customer intent is respected across distributed services, caches, pipelines and AI systems. The piece highlights five priorities: consistent customer intent, privacy as a distributed-systems problem, data minimization, designing for failure, and understanding AI's expanding trust boundary. Security leaders are urged to treat trust as an architectural and operational priority, with observability and metadata-driven controls.
read more →

The patch window is collapsing: a new control plane

🔒 Modern vulnerability timelines are compressing as disclosures, exploit research, and AI-assisted workflows accelerate attacks while enterprise remediation remains slow due to operational constraints. Visibility and prioritization improve awareness but don’t reduce exposure quickly enough. Network-enforced, context-aware controls can provide rapid, targeted protections to limit exploitability during the interval between disclosure and patching.
read more →

CISO View: Security Fundamentals in the AI Era

🔒 Chris Betz argues that as AI amplifies both attacker and defender capabilities, organizations must reinforce core security controls rather than abandon them. He emphasizes layered defenses—MFA, Zero Trust, patching, and detection and response—and describes how AI accelerates vulnerability discovery, threat modeling, and remediation. CISOs should combine technical rigor with strategic leadership to align security with business goals.
read more →

Amazon Quick introduces deny-by-default governance

🔒 Amazon Quick now offers a deny by default governance setting for custom permissions, automatically blocking new AI capabilities until administrators explicitly allow them. Previously, new capabilities were enabled for all users on release, requiring reactive controls. Administrators can apply the restriction per custom permissions profile for users, roles, or the entire account via the Amazon Quick console or AWS CLI. The setting is available in all Regions where Amazon Quick is offered and also restricts existing capabilities within a restricted category.
read more →

Protect Workers with Cloudflare Access by Default

🔐 Cloudflare now lets you apply Access directly to a Worker or to all Workers in an account so applications are protected by your company login by default. When enabled, Access enforces authentication before any request reaches Worker code, regardless of domain, route, or preview URL. Policies can be set per hostname, per Worker, or account-wide, with the most specific policy taking priority. Developers can also access authenticated user details through ctx.access.getIdentity() for personalization and logging.
read more →

A practical access model for software agents

🛡️ This article argues that existing Zero Trust controls designed for human principals fail when applied to software agents. It proposes the Agent Access Model (AAM), which enforces short-lived, task-scoped, sender-constrained credentials, inline enforcement in the harness and network, and a Trust Ratchet that only reduces capabilities. The piece outlines architecture components—Agent Identity Broker, Task-Scoped Access Engine, Mediation Layer—and operational loops for logging and grant review to keep agent authority tightly bounded.
read more →

Advancing Zero Trust for AI: New Tools and Guidance

🔒 Microsoft expands its Zero Trust for AI strategy with an automated Zero Trust Assessment and a new DevSecOps pillar in the Zero Trust Workshop to help organizations secure AI agents, developer workflows, and CI/CD pipelines. The Assessment evaluates tenant configuration and activity across Identity, Devices, Network, Data, AI, Security Operations, and Infrastructure, producing prioritized recommendations and executive-ready reports. The DevSecOps pillar maps Zero Trust principles into 15 control groups and 91 tasks covering source code, pipelines, dependencies, artifacts, and infrastructure-as-code. Together, the Assessment and Workshop convert findings into a phased 12–24 month remediation roadmap.
read more →

Deutsche Bank’s API-First Transformation with Apigee

🧩 Deutsche Bank adopted Google Cloud's Apigee to transform monolithic systems into a governed, scalable API ecosystem. The platform centralizes documentation, security policies, and governance while enabling discoverability and reuse across teams. Apigee enforces least-privilege access, rate limiting, and observability, and supports resilience, auto-scaling, and caching for high performance. This API-first foundation positions the bank for AI-ready, low-latency services and emerging standards.
read more →

Malware Bypassing DNS: Direct-to-IP Threats Rise

🔎 Analysis of 4 million dynamic reports shows nearly half (45.32%) of malware with C2 activity connects directly to IP addresses, bypassing DNS. This behavior—seen in ransomware droppers, P2P botnets and IoT threats—evades DNS-based defenses. The article introduces zero trust IP (ZT-IP), a network-level enforcement model that permits only DNS-sanctioned outbound IP connections and validates its efficacy against real-world samples and traffic.
read more →

Zero Networks adds network controls for AI agents

🔒 Zero Networks has introduced Least Agency Enforcement, a network-layer capability to implement OWASP’s emerging Least Agency principle for enterprise AI. Built on the company’s identity-based micro-segmentation platform, it restricts which systems AI agents can contact, what resources they can access, and when human approval is required. The feature uses automated policy generation and just-in-time MFA to block lateral movement and sensitive actions even after an agent authenticates.
read more →

AI Elevates Need for Cybersecurity Fundamentals

🔒 AI-driven tools are exposing long-standing security gaps while accelerating familiar attack techniques. Experts stress that core practices—identity management, patching, configuration hygiene, multifactor authentication, and zero-trust—remain essential and must be applied consistently. AI increases speed, scale, and customization of attacks, but does not eliminate the need for human oversight, judgment, and accountability.
read more →

CISA's Six-Step Blueprint for Infrastructure Isolation

🔒 The US CISA and Five Eyes partners published CI Fortify, a six-step guide to isolate and protect critical infrastructure during cyber incidents. The guide outlines identifying vital systems and customers, classifying trust levels, mapping interconnections, and building separation points. It emphasizes physical isolation and phased isolation plans while acknowledging operational constraints and the need for encryption and robust risk management.
read more →

Fortinet expands FortiGate with SASE-enabled 1200G

🔒 Fortinet introduced the midrange FortiGate 1200G series running FortiOS 8.0, offering 10G–100G connectivity and 397 Gbps firewall throughput for campus, data center, and hybrid environments. The appliances can operate as a local SASE POP via FortiSASE Outpost, extending cloud-managed policy enforcement, visibility, and zero-trust controls to on-premises sites while keeping logs and traffic within customer boundaries. Availability is slated for Q3 2026.
read more →

Amazon EKS adds PrivateLink for OIDC endpoints

🔒 Amazon EKS now supports AWS PrivateLink for the cluster OIDC discovery and JWKS endpoint, allowing access to the OIDC endpoint used by IAM Roles for Service Accounts (IRSA) privately from your VPC without internet egress. Tools such as eksctl, Terraform, or custom token validators can reach the discovery document and JWKS via an interface VPC endpoint for the com.amazonaws..oidc-eks service. This ensures correct DNS resolution when the EKS management VPC endpoint uses private DNS. The feature is available in all Regions where Amazon EKS is offered at standard AWS PrivateLink pricing.
read more →

Hardening Google Cloud access with IAM conditions

🔐 In Google Cloud, IAM enforces the Principle of Least Privilege by combining predefined and custom roles with Allow and Deny policies across resource hierarchies. When resource-level bindings are not possible, IAM conditions let you scope broad roles to specific APIs, services, MCP servers, tools, or time windows. Use conditions alongside Deny policies to surgically remove excessive permissions and strengthen defense-in-depth.
read more →

Cloudflare Launches Internal DNS for Enterprises

🔒 Cloudflare Internal DNS is now generally available, providing authoritative and recursive DNS for private networks on the same control plane used for public DNS, Zero Trust, and networking. It consolidates public and private DNS management, simplifies split-horizon setups, and extends Zero Trust enforcement to DNS. Enterprise customers get this capability included with Cloudflare Gateway, with Terraform support and integration across Cloudflare connectivity methods.
read more →