enterprise security5 articles
The 5% Problem: Why Your AI Power Users Are Your Biggest Security Headache
New research from Akamai reveals that the top 5% of enterprise AI "power users" interact with AI tools at 12 times the rate of average employees, creating disproportionate security risks through shadow AI, data leakage, and unvetted autonomous tools operating outside corporate oversight. Nearly half of all enterprise AI conversations occur through personal rather than corporate-managed accounts, and 16% of AI browser extensions contain known security vulnerabilities, expanding the attack surface significantly. Security teams are urged to shift focus from broadly policing mainstream AI tools to identifying where AI is most deeply embedded in operations and whether those systems fall within established guardrails.
n8n's JWT Login Bug Let the Wrong Issuer Vouch for the Wrong User
A flaw in n8n's Enterprise token exchange feature (CVE-2026-59208) allowed attackers to log in as another user by presenting a valid JWT from one trusted issuer that shared a matching `sub` claim with an account registered under a different issuer, because n8n matched users on `sub` alone rather than the correct `iss` + `sub` pairing. The vulnerability only affects Enterprise instances with token exchange enabled and at least two external issuers configured. n8n patched the issue on June 24 in versions 2.27.4 and 2.28.1, though the fix was not mentioned in either release's changelog.
Shadow AI Is Already In Your Organisation. Here's How to Deal With It.
Employees aren't waiting for IT to approve an AI tool. They're already using it. ChatGPT for drafting emails, Claude for summarising documents, some random browser extension that claims to boost productivity. By the time your security team hears about it, the data's already been pasted somewhere you don't control.
Claude Gets 28 Enterprise Security Integrations Because Apparently That's What It Takes to Trust an AI at Work
Anthropic has integrated Claude with 28 enterprise security and compliance platforms — including CrowdStrike, Microsoft, Okta, and Palo Alto Networks — to make the AI assistant easier to govern within corporate IT environments. Central to this rollout is the Claude Compliance API, which gives security teams programmatic access to conversation content and activity logs, allowing them to apply existing monitoring policies to Claude just as they would other workplace software. Organizations already using one of the supported platforms can connect Claude with minimal setup, with data flowing automatically into their existing dashboards and workflows.
Five Reasons Your Cybersecurity Strategy Is Already Behind
Cybercriminals in 2025 have become increasingly sophisticated, using AI, automation, and corporate-style structures to launch faster, larger-scale attacks, with governments, finance, and technology sectors among the most targeted. Enterprises face a complex cybersecurity landscape shaped by five key factors: rising user expectations, financial pressures, complex multi-vendor IT infrastructure, unpredictable geopolitics, and evolving cyber threats. To counter these challenges, HPE advocates for a "self-driving network" approach that uses AI-driven platforms and built-in security capabilities — such as zero trust enforcement and automated threat monitoring — to provide dynamic, comprehensive protection.