惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

V
Visual Studio Blog
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
G
Google Developers Blog
J
Java Code Geeks
爱范儿
爱范儿
Microsoft Azure Blog
Microsoft Azure Blog
美团技术团队
人人都是产品经理
人人都是产品经理
Martin Fowler
Martin Fowler
IT之家
IT之家
博客园_首页
B
Blog RSS Feed
Google DeepMind News
Google DeepMind News
B
Blog
U
Unit 42
Apple Machine Learning Research
Apple Machine Learning Research
L
LangChain Blog
Stack Overflow Blog
Stack Overflow Blog
罗磊的独立博客
N
Netflix TechBlog - Medium
T
Tailwind CSS Blog
博客园 - 聂微东
腾讯CDC
A
About on SuperTechFans

Cybersecurity Dive - Latest News

Dozens of Red Hat npm packages targeted in supply chain attack Turning tension into collaboration: How CIOs and CISOs can lead together Trump signs EO seeking early government access to powerful AI models Anthropic shares Mythos with 150 more organizations, including critical infrastructure operators Without strong governance, companies put credit ratings at risk in AI era CISA adds critical Palo Alto Networks firewall flaw to KEV as company, researchers warn of exploitation How Canva scaled to 260+M users while elevating security and productivity Top 4 data security best practices for the AI-enabled enterprise CISA urges security teams to check for software development compromises How CISOs can manage sovereign-cloud security risks IBM’s new $5B initiative will help enterprises rapidly patch open-source vulnerabilities Enterprise data is creeping its way into shadow AI tools Coordinated operation takes down Glassworm botnet Leading AI models are more vulnerable to malicious prompts than vendors claim Iranian government, not hacktivist group, breached LA Metro system, security firm says FBI warns about PhaaS platform used to access Microsoft 365 environments Iran-linked hackers target key US, allied sectors with sophisticated spear-phishing messages New York regulator calls for additional cyber mitigation amid heightened threat environment CISA asks cybersecurity community to alert it to vulnerability exploitation Grafana Labs links GitHub environment breach to TanStack npm supply chain attack 7-Eleven hit by data breach Microsoft disrupts cybercrime operation that hid behind legitimate software Compromised coding tool helped hackers breach thousands of GitHub repositories Telecom sector launches its own private ISAC Patch bypass allows hackers to exploit prior flaw in SonicWall SSL-VPN Grafana Labs says hacker gained access to codebase through leaked token How a government contest launched a revolution in AI-based bug hunting Attackers exploit critical flaw in Cisco Catalyst SD-WAN Controller MSPs need AI to fight AI-fueled cyberthreats: Guardz More money is going to physical security, but it’s often CISOs that oversee it: EY
Businesses eager but unprepared for AI to transform their...
Eric Geller · 2026-05-06 · via Cybersecurity Dive - Latest News

An article from site logo

Dive Brief

Meanwhile, a new report found, companies are neglecting other basic security tools.

Published May 6, 2026

A smartly-dressed businessman is resting in his office in front of his computer.

Getty Images

Dive Brief:

  • Businesses are confident that AI will improve their cybersecurity posture, even as they neglect more fundamental security tools like identity management and zero-trust networking, according to a “State of Workforce Password Security” report that the business software provider Zoho published on Tuesday.
  • AI confidence also doesn’t match implementation readiness, the report found, with a massive gap between the share of companies expecting AI to help them with security and the share of companies ready to act on that potential.
  • The report also contains data on the share of companies that experienced recent cyberattacks and the business world’s security spending plans.

Dive Insight:

The gap between AI eagerness and AI readiness was one of the top findings Zoho highlighted in its report. While 90% of survey respondents said AI could strengthen their cyber defenses, only 8% said they were currently ready to deploy AI-powered security tools.

“An 82-point gap between belief and deployment readiness defines the most critical inflection point in workforce security,” Zoho said.

At the same time, many businesses don’t have a handle on core cybersecurity practices. Roughly three-quarters of respondents said they lacked complete visibility into their identity ecosystem, meaning they don’t know who has access to which systems. While 36% reported partial visibility, 38% reported limited visibility and 14% said they had no visibility at all.

“This ‘identity visibility gap’ is not a peripheral concern,” Zoho warned. “It is the central vulnerability enabling unauthorised access, insider threats, and compliance failures.”

On the important metric of zero-trust networking — the design of systems to anticipate compromise and limit its impact — roughly two-thirds of businesses said they had no strategy for implementing it. Roughly half of those businesses said they planned to adopt a strategy within the next three years, which Zoho said created “a critical window of vulnerability for credential-based attacks.”

More than half of businesses said zero-trust networking was difficult because of "unmanageable" growth in their identity ecosystems, while another one-third of respondents said they lacked the right processes and tools.

The report, based on a survey of 3,300 cybersecurity professionals in nine regions and six industries worldwide, also found that one-third of businesses experienced a cyberattack in the past year, with an additional 7% “not certain whether they had been attacked.”

On the AI-for-security front, companies are most interested in the technology’s ability to detect anomalous activity and threats (68% cited this as a desired feature), automatically enforce policies (61%) and analyze employee behavior (54%). But multiple factors are holding back their AI adoption, with outdated technology, concerns about the complexity of migration and budget constraints topping the list.