惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

F
Full Disclosure
Recorded Future
Recorded Future
T
Tenable Blog
S
Securelist
C
CERT Recently Published Vulnerability Notes
T
Threatpost
S
Schneier on Security
A
Arctic Wolf
The Hacker News
The Hacker News
C
CXSECURITY Database RSS Feed - CXSecurity.com
Know Your Adversary
Know Your Adversary
P
Privacy International News Feed
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
The Register - Security
The Register - Security
Cisco Talos Blog
Cisco Talos Blog
AWS News Blog
AWS News Blog
K
Kaspersky official blog
T
True Tiger Recordings
T
Threat Research - Cisco Blogs
V
Vulnerabilities – Threatpost
P
Palo Alto Networks Blog
T
The Exploit Database - CXSecurity.com
小众软件
小众软件
B
Blog
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Microsoft Azure Blog
Microsoft Azure Blog
Cyberwarzone
Cyberwarzone
C
Cybersecurity and Infrastructure Security Agency CISA
T
Tor Project blog
Spread Privacy
Spread Privacy
Malwarebytes
Malwarebytes
P
Proofpoint News Feed
F
Fox-IT International blog
F
Fortinet All Blogs
P
Privacy & Cybersecurity Law Blog
G
GRAHAM CLULEY
量子位
Latest news
Latest news
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
博客园 - 叶小钗
Project Zero
Project Zero
T
Tailwind CSS Blog
N
Netflix TechBlog - Medium
Martin Fowler
Martin Fowler
IntelliJ IDEA : IntelliJ IDEA – the Leading IDE for Professional Development in Java and Kotlin | The JetBrains Blog
IntelliJ IDEA : IntelliJ IDEA – the Leading IDE for Professional Development in Java and Kotlin | The JetBrains Blog
I
Intezer
博客园_首页
腾讯CDC
H
Hackread – Cybersecurity News, Data Breaches, AI and More
D
Darknet – Hacking Tools, Hacker News & Cyber Security

Help Net Security

Franklin Access adds three-layer security system to Wi-Fi routers Jetico expands BestCrypt Data Shelter with zero-trust file access controls AppOmni’s Marlin AI automates SaaS threat analysis, triage, and remediation at scale Novee’s Agentic Fix turns validated exploits into fixes through AI coding agents Vigolium: Open-source vulnerability scanner The alert economy is driving security analyst burnout European AI adoption hits 99% with regulated data driving most policy violations Anthropic: Claude Mythos identified 10,000+ software flaws Chinese phishing gangs grow into a force to be reckoned with Detectify brings AppSec automation to AI agents with MCP Server and continuous testing Actively exploited Trend Micro Apex One flaw gets CISA warning (CVE-2026-34926) Conifers rolls out AI-powered SOC for unified security operations and automated response Personal information of 185,000 people exposed after cyberattack on 7-Eleven Tamnoon introduces skill-based AI orchestration for autonomous cloud defense High-severity SharePoint RCE bug patched by Microsoft (CVE-2026-45659) What happens when security teams inherit identity Product showcase: F-Secure Internet Security blocks phishing sites, fake stores, and SMS scams Manage machine identities: The hidden privileged access layer you need to manage Cybersecurity jobs available right now: May 26, 2026 Anthropic adds 28 security and compliance integrations for Claude Cisco refines its risk-based vulnerability disclosure for the AI era Authorities seize 800 servers used for cyberattacks and disinformation US states step up cyber defenses to protect local communities Lessons for organizations from the Verizon 2026 Data Breach Investigations Report OpenHack: Open-source AI-powered vulnerability research Boards want cyber risk in dollars, not CVE counts Turns out the C-suite loves shadow AI Week in review: GitHub breached via poisoned VS Code extension, critical NGINX flaw exploited $20 per zero-day is already the WordPress plugin reality Deleted Google API keys keep working for up to 23 minutes, researchers warn Kore.ai unveils AI-native platform for enterprise multiagent systems Suspected KimWolf botnet admin arrested over DDoS-for-hire operation Versa extends zero trust principles to AI agents and MCP workflows GitLab 19.0 adds AI workflows, secrets management, and self-hosted model support Proton Pass adds monitored credential sharing for AI agents Keepnet contributes voice and SMS phishing data to the 2026 Verizon DBIR CISA’s new KEV nomination form opens reporting to vendors and researchers Microsoft 365 users targeted by new phishing threat that bypasses MFA Meet Fractal, an OS made for microarchitecture reverse engineering Downtime has become a $600 billion business problem The new economics of fraud: Cheaper, faster, more convincing New infosec products of the week: May 22, 2026 Microsoft open-sources tools for designing and testing AI agents Authorities dismantle First VPN, used by ransomware actors GitHub, Grafana Labs breaches traced back to TanStack supply chain compromise Microsoft Defender vulnerabilities exploited in the wild (CVE-2026-41091, CVE-2026-45498) Virtru centers file collaboration around data-level protection ASAPP expands adversarial testing for enterprise AI systems Tenable Hexa AI automates remediation across attack surfaces Riverbed introduces new Aternity tools for autonomous IT operations Forward launches Predict to test network changes before deployment CTERA brings AI insights and automation for unstructured data Terra adds continuous network exploitation validation to its platform Why AI changed the threat model for travel technology Most dark web activity revolves around a handful of topics AI red teaming agents change how LLMs get tested Product showcase: Bitdefender Mobile Security for iOS protects privacy where scams begin Cyber threats push SMBs to spend more on security Webworm APT targets European government organizations with new backdoors Verizon DBIR: Vulnerability exploitation is the dominant initial access vector NanoCo lands $12 million seed funding, launches enterprise assistant built on NanoClaw FBI: $388 million lost in crypto ATM scams in 2026 ArmorCode gives security teams AI workers for exposure and remediation Novata uses AI to map risk across portfolios and supply chains TeamPCP breached GitHub’s internal codebase via poisoned VS Code extension Trust3 AI focuses on AI agent risks with MCP Security layer Encryption Consulting launches CertSecure Manager v3.3 with zero-touch certificate renewals Darwinium updates mobile SDKs to detect remote access scam activity Microsoft provides mitigation for “YellowKey” BitLocker bypass flaw (CVE-2026-45585) Communicating cyber risk in dollars boards understand CVE Lite CLI: Open-source dependency vulnerability scanner When your AI assistant has the keys to production 7 hard truths security pros should know: 2026 DevOps Threats Report What happens when your identity provider becomes the kill chain PureLogs infostealer is stealing credentials worldwide Selector extends AI-driven observability into multi-cloud environments LaunchDarkly adds real-time controls for AI agents in production Canonical ships Ubuntu Core 26 with 15 years of security maintenance New macOS infostealer impersonates Apple, Microsoft, and Google in a single attack chain The end of unencrypted Discord calls is here Babel Street targets AI-driven threats with new agentic investigation capabilities iProov brings identity verification to video meetings to reduce fraud risks Egnyte unveils Email Capture and AI features to unify fragmented data Public Instagram posts provide raw material for AI phishing campaigns Earbud sensors can authenticate users by their heartbeat, study finds AI infrastructure is cracking under sovereignty demands Cybersecurity jobs available right now: May 19, 2026 AI is drowning software maintainers in junk security reports Game over for 74 suspected scammers after Dutch cops plastered their faces on billboards Attackers are exploiting critical NGINX vulnerability (CVE-2026-42945) SmartBear expands ReadyAPI with AI-powered API testing capabilities Attackers accessed, downloaded code from Grafana Labs’ GitHub 201 arrested in INTERPOL disruption of phishing and fraud networks The AI backdoor your security stack is not built to see Lyrie: Open-source autonomous pentesting agent AI shrinks vulnerability exploitation window to hours Product showcase: McAfee + ChatGPT integration turns doubt into a scam check When ransomware hits, confidence doesn’t restore endpoints Debian 13.5 point release lands with security fixes, bug patches Week in review: Cisco patches SD-WAN 0-day, unpatched Microsoft Exchange Server flaw exploited
Coinflow CISO on crypto payments security under AI pressure
Mirko Zorz · 2026-05-27 · via Help Net Security

Crypto payment firms sit near the top of the target list for advanced persistent threat groups, and the workload on their security leaders keeps growing. Malcolm Portelli, CISO at Coinflow, runs the company’s security program from Malta. Coinflow is headquartered in the United States and operates across multiple jurisdictions. Portelli sat down for this interview at the Span Cyber Security Arena conference.

crypto payments security

Portelli says the sector drives his threat model more than the location. “It’s more the industry which we operate in. So, financial services, Web3, and crypto and all that comes with that. Crypto is a big target, especially for the big APTs. They’re always looking at how they can get into crypto firms because that’s their chosen money.”

Malta has become an active fintech and blockchain hub, supported by government incentives aimed at attracting company headquarters to the island. Portelli credits that policy with helping the local economy and the wider tech scene.

Awareness training that stopped working

Portelli dropped monthly security awareness videos from his program after concluding they had become a compliance exercise. “Something that I’ve stopped doing is the regular monthly videos. You know, you go out and get snippets that people watch. It’s a checkbox.” He now prefers training quarterly, capped at 30 minutes of content per quarter, and supplements it with formats designed to hold attention. He also rejects the yearly-only approach as too thin and aims for a middle frequency.

Speaking to the board in numbers

Boards have grown more interested in cyber risk over the past decade, and some members potentially arrive at meetings believing they understand these risks better than they do. Portelli handles disagreements by citing published data. He points to the Verizon Data Breach Investigations Report and the IBM Cost of a Data Breach Report, the second of which prices losses in dollars that board members recognize. He also cites GDPR penalties of up to 4 percent of global revenue when European personal data is involved.

“Numbers are a universal language,” Portelli says. “If you are an accountant, if you are in technology, if you are in operations, you understand numbers.” He says board members who grasp the financial exposure tend to defer to the CISO on execution: “When they understand it, they leave it to you. I hired you. They trust you.”

Coverage of large breaches in mainstream business outlets has helped that conversation. Portelli cites the recent disruption at Marks & Spencer and Co-op, along with the attack on Jaguar Land Rover that drew UK government support, as examples that have moved cybersecurity onto the front pages read by non-technical executives.

A piece of advice he wants retired

Asked which conventional security guidance has outlived its usefulness, Portelli names forced password rotation. The UK’s National Cyber Security Centre and Microsoft moved away from that practice around 2016 to 2018. Some standards and frameworks continue to require it, which Portelli describes as a contradiction of long-settled guidance.

He also voices frustration with the volume of AI-generated content flooding LinkedIn and security blogs. Original posts get rewritten by language models within days and republished across hundreds of sites, diluting attribution and weakening the signal in threat intelligence channels. He runs a personal site dedicated to breaking down security concepts into accessible snippets and prefers to write the posts himself.

API defenses and the fraud shift

Coinflow operates primarily through APIs, which Portelli says simplifies certain controls. The company implements multi-factor authentication mechanisms for API keys utilizing already available data to validate and authenticate the client with minimal adverse effects on operational efficiency. He describes the setup as straightforward for developers to implement, yet highly effective.

Fraud has shifted toward scams that convince customers and staff to authorize payments themselves. Portelli is investing in AI-based anomaly detection and pattern recognition to flag suspicious transactions, paired with continued education for employees and end users. Banks and governments, he says, are now running awareness campaigns at a global scale.

The patching gap

Portelli expects attack volume to keep climbing for the next three years, driven by AI tools that find vulnerabilities at very low cost.

He points to Mythos, an AI vulnerability discovery system that he says surfaced numerous issues in Firefox. Recent research from TrendAI identifying around 300 vulnerabilities in widely used WordPress plugins at roughly $20 per zero-day. Defensive AI has kept up with discovery, he says. Automated patching that preserves application functionality remains an open problem. Enterprise CISOs already sitting on large vulnerability backlogs, he argues, see little benefit from a discovery tool that adds hundreds of items when remediation tooling lags behind.