Connect with us

Infosecurity

SANS Report: AI Adoption Surges Among Security Teams, But Governance Is Playing Catch-Up

Published

on

AI governance gap

Security Teams Are Moving Faster Than Their AI Policies

A new survey from the SANS Institute paints a stark picture: cybersecurity professionals are racing to deploy artificial intelligence, but the safety nets meant to keep that deployment under control aren’t keeping up.

The 2026 SANS AI Survey Insights report, based on responses from 536 global cybersecurity and IT practitioners plus 57 security leaders, found that 78% of organizations now actively use AI in their cybersecurity strategy. That’s a jump from 50% just a year earlier. But the same survey reveals a troubling parallel trend: 63% of respondents reported “significant shortcomings” in threat detection and response — up sharply from 45% in 2025.

“For two years now, we’ve asked security teams where they actually stand with AI,” said Matt Bromiley, the report’s author and a SANS certified instructor. “Both years, the honest answer has been some version of moving fast and working it out as we go. What’s changed in 2026 is how much weight is now sitting behind that answer.”

The AI governance gap is real — and it’s widening.

Trust in AI Decisions Hits a Wall

One of the report’s most striking findings: trust in AI decisions (40%) has replaced “wiring AI into existing systems” as the top barrier to deeper integration. Teams aren’t just struggling to plug AI into their workflows anymore. They’re questioning whether they can rely on the outputs.

That trust deficit is compounded by a governance vacuum. Only half (50%) of the cybersecurity leaders surveyed said their organization has a formal AI governance program in place. Meanwhile, 44% described themselves as being in the early stages of drafting policy — and some respondents claimed to be in both categories at once, suggesting confusion over what “governance” actually means in practice.

AI governance isn’t just a buzzword. Without clear rules on data access, model validation, and incident response, organizations are essentially flying blind with powerful — and fallible — tools.

Where AI Is Actually Helping (and Where It’s Not)

It’s not all bad news. The survey identified two areas where AI is delivering clear value for network defenders: behavioral detection (48% of respondents reported effective use) and user awareness training (45%). These are practical, measurable wins.

But the threat landscape is shifting just as fast. 78% of organizations reported confirmed or suspected AI-enabled attacks in the past year. The most common incidents involved deepfakes, vulnerability exploitation, phishing, and adversarial attacks on AI models themselves. Attackers are weaponizing the same technology defenders are trying to harness.

The Upskilling Crunch

Perhaps the most urgent finding concerns the workforce. Three-quarters of respondents (73%) said AI has changed their training requirements, up from 51% in 2025. That’s a massive shift in just 12 months.

“You can’t fix these gaps without people who can catch what the tools miss,” Bromiley said. “The teams that invest in upskilling now are also the ones positioned to get more out of the AI they have already bought, because the people running it know when to trust it and when to step in.”

SANS argues the next year is critical. The report recommends a three-point investment plan:

  • AI validation infrastructure — focusing on “precision, recall, and continuous comparison” rather than simply buying more tools
  • Operationalizing governance — treating sensitive-data access and AI data exposure as core controls, not afterthoughts
  • Workforce development — handled as an immediate operational need, not a medium-term hiring goal

Closing the Gap Means Slowing Down — Just a Little

The numbers tell a clear story. Adoption is surging. Threats are evolving. And too many organizations are still making up their AI policies as they go.

For security teams, the path forward isn’t about abandoning AI — it’s about building the governance, trust, and skills to use it responsibly. That means investing in people as much as technology, and treating AI upskilling as a here-and-now priority rather than a future project.

As Bromiley put it: “Moving fast is fine — but you need to know where you’re going.”

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Infosecurity

Opera GX Zero-Click Flaw Allowed Websites to Auto-Install Mods and Steal User Data

Published

on

Opera GX flaw

No Clicks, No Permissions: How a Critical Opera GX Flaw Worked

A serious security hole in Opera GX, the gaming-focused browser from Opera, allowed any website to silently install a customization mod — and then use that mod to siphon data from sites the victim had visited. The attack required zero user interaction. No clicking. No permission prompts. Just a hidden frame loading a file.

Discovered by an independent researcher known as zhero_web_security, the Opera GX flaw exploited the browser’s GX Mods system. Unlike standard browser extensions, GX Mods are supposed to be lightweight — they customize the browser’s look, sounds, and website styling, but carry no permissions and can’t execute JavaScript. That’s what made the discovery so unsettling: the mods weren’t supposed to be dangerous. Yet the researcher found a way to weaponize them.

Auto-Install: The Core of the Opera GX Vulnerability

Here’s the mechanical problem. When a user downloads a GX Mod file, it installs automatically. No dialogue box asks for approval. No permission request pops up. The researcher realized that an attacker could place a mod file inside a hidden HTML frame on a malicious website. As soon as the page loads, the mod lands in the browser — completely silent.

Once installed, the mod’s CSS (cascading style sheets) applies to every single tab and page the victim opens. Ordinary CSS injection is usually confined to one page. This was different. The Opera GX vulnerability gave the attacker a persistent foothold across the entire browser session.

Gmail Addresses and Browser Crashes: Proof of Concept

CSS cannot read a page’s content directly. But it can be cleverly crafted to trigger network requests based on what a page contains. That technique, known as an XS-Leak (cross-site leak), lets an attacker extract data bit by bit, character by character.

Using this method, the researcher built a zero-click exploit that recovered a victim’s full Gmail address. The attack silently redirected the browser to a Google account page, then used the injected CSS to leak the email address character by character. The researcher noted the method is not limited to Gmail — any data rendered on a page could theoretically be targeted.

The same auto-install behavior also enabled a denial-of-service (DoS) attack against both Opera and Opera GX. Chromium-based browsers block extensions in private or Incognito windows. Forcing a mod to install in Incognito mode caused the browser to crash — and wiped all open tabs in the process. Any file with a .crx extension triggered the crash, whether or not it was a legitimate mod.

From Low Priority to Critical: Opera’s Bug Bounty Response

The researcher reported the Opera GX flaw in February 2024 through Opera’s Bugcrowd bug bounty program. Initially, the team triaged it as low priority. That changed quickly. Opera’s security team reassessed the issue and reclassified it as critical.

A patch shipped on May 8, 2024, and the researcher received a $5,000 bounty payment. The full proof of concept was published on July 3, tested against Opera GX version 127.0.5778.41 — after the fix had already been distributed.

What This Means for Browser Security and Users

This isn’t the first time browser customization features have opened unexpected attack surfaces. But the Opera GX vulnerability is a sharp reminder that even permissionless systems can be dangerous. GX Mods were designed to be safe because they lack extension-level privileges. But CSS injection, combined with auto-installation, turned that safety assumption into a liability.

For users, the fix is straightforward: update Opera GX to the latest version. The browser should update automatically, but it’s worth checking. Anyone running a version prior to the May 8 patch is still exposed.

For the broader security community, the case raises questions about how browsers handle file-based installations and whether similar flaws exist in other Chromium-based browsers. The researcher’s work demonstrates that even a seemingly harmless mod can become a data theft tool — as long as it arrives without a click.

Continue Reading

Infosecurity

23andMe Hit With $18m Settlement and Strict New Security Mandates After 2023 Breach

Published

on

23andMe data breach settlement

A Landmark Settlement for Genetic Privacy

More than two years after cybercriminals stole the genetic profiles of over six million people, 23andMe has agreed to pay $18 million and submit to a sweeping set of new security mandates. A bipartisan coalition of 42 US state attorneys general, led by New York Attorney General Letitia James, finalized the deal in July 2025.

The settlement is not just about the money. It forces the company—and its new owner, TTAM Research—to adopt a far stricter data protection regime. New York alone will receive more than $705,000 from the payout.

“Companies have a duty to protect their customers’ personal information from hackers, but 23andMe put millions of its customers at risk with its flimsy security measures,” James said in a statement. “New Yorkers trusted 23andMe with their sensitive and personal genetic data, only to find that data stolen and put up for sale on the dark corners of the internet.”

How the 23andMe Data Breach Happened

The October 2023 incident was not a sophisticated hack of 23andMe’s core servers. It was a credential stuffing attack—a brute-force method where attackers use usernames and passwords leaked from other sites to break into accounts.

The company admitted at the time that the breach was enabled by customers’ weak password habits and the widespread absence of multi-factor authentication (MFA). Once inside, the attackers scraped profile information tied to ancestry results, eventually accessing data from 6.9 million users.

The fallout was immediate and lasting. By March 2025, 23andMe filed for Chapter 11 bankruptcy protection. In June, James and 27 other attorneys general sued the company to safeguard Americans’ genetic information during the bankruptcy process.

What the $18m Settlement Requires

The settlement imposes several binding security requirements on 23andMe and TTAM Research, the nonprofit formed by former CEO Anne Wojcicki that purchased the customer data.

  • Mandatory risk analysis: The company must conduct regular, documented assessments of its security posture.
  • An Advisory Board on data security: A new oversight body will monitor compliance and recommend improvements.
  • Consumer right to delete: Customers must retain a clear, easy-to-use option to erase their genetic data from the company’s systems.

These measures are designed to prevent a repeat of the 2023 disaster. The settlement also prohibits misleading statements about data protection practices.

This is not the only financial penalty 23andMe faces. A US bankruptcy judge approved a separate $46.75 million fund on July 7, 2025, to compensate victims directly. However, on July 10, the same judge ruled that California cannot seek additional damages from the company due to the Chapter 11 reorganization plan, though the state has 14 days to amend its lawsuit to remove monetary claims.

Regulatory Fines Pile Up Globally

The US settlement is just one piece of a much larger global enforcement puzzle. In July 2026, the Spanish privacy watchdog fined 23andMe €2.4 million ($2.75 million) after finding that 2,642 customers residing in Spain were affected by the breach.

A year earlier, in June 2025, the UK’s Information Commissioner’s Office levied a £2.3 million ($3.1 million) fine for failing to protect customers’ special category data—a classification that includes genetic information, which is among the most sensitive types of personal data under UK law.

These overlapping penalties signal that regulators on both sides of the Atlantic are taking genetic privacy breaches with extreme seriousness.

What This Means for the Future of Genetic Testing

The 23andMe case is a cautionary tale for the entire direct-to-consumer genetic testing industry. When customers mail in a saliva sample, they are trusting the company with data that cannot be changed—unlike a password or credit card number. A leaked genetic profile is permanent.

The new security mandates at TTAM Research set a precedent. Other firms in the space, including AncestryDNA and MyHeritage, will be watching closely. If state attorneys general are willing to impose structural reforms—not just fines—on a bankrupt company, the bar for data protection across the industry just got higher.

For consumers, the lesson is blunt: enable MFA on every account that holds sensitive data, and think twice before sharing your DNA with any private company. The settlement may close the legal case, but the questions about trust in the genetic testing industry are far from settled.

Continue Reading

Infosecurity

Former UK privacy chief reportedly preparing legal action against woman who reported him, minister says

Published

on

John Edwards legal action

Minister reveals legal threat against whistleblower

Britain’s former Information Commissioner, John Edwards, is reportedly preparing to serve legal papers on a female employee who raised concerns about his conduct, the science and technology secretary told Parliament on Wednesday. Liz Kendall, speaking before the Science, Innovation and Technology Committee, said she was “absolutely appalled” by the development.

Kendall revealed that an independent investigation at the Information Commissioner’s Office (ICO) had upheld multiple allegations of “sexual harassment and bullying” against Edwards. The specific nature of the complaints had not been publicly disclosed until now.

“I’m also going to be launching an independent review of the culture, accountability and governance of the ICO,” Kendall told the committee. “I take very seriously what’s happened there and I will do everything I can to try and put this right.” She added that “the women who’ve spoken up have been incredibly brave.”

Edwards’ resignation and LinkedIn statement

Edwards formally resigned as Information Commissioner in June, after voluntarily stepping back from his duties in February. That move came amid an internal workplace investigation into what was initially described only as unspecified conduct.

In a LinkedIn post at the time, Edwards acknowledged his position had “become untenable.” He wrote: “From the time the investigation was launched, I have accepted that there have been occasions where I exercised poor judgment and made attempts at humor that were inappropriate and caused offense.”

He added that while he did not agree with how the investigation was conducted, he accepted that resigning was the appropriate course.

Government response and new leadership

Kendall told the committee the government will launch the recruitment process for Edwards’ successor next week. That process will run alongside “the appointment of a new board of non-executive directors, the majority of whom will be women.”

The minister also revealed the legal threat. “It has come to my attention that the former Information Commissioner is preparing to serve legal papers on one of the women at the ICO who raised concern about his behavior earlier this year,” she said.

“I don’t know who this woman is, but by reporting her concerns, she supported the independent investigation that upheld multiple allegations made against him. I have reached out as best I can and said they need to know that they will always be listened to without being put at personal risk. Quite frankly, I’m appalled by that behavior.”

ICO leadership under scrutiny

The ICO, which oversees Britain’s data protection and privacy regulations, has faced growing scrutiny over its internal culture. The independent review Kendall announced Wednesday aims to examine how the organization handles accountability and governance.

Edwards served as Information Commissioner from January 2022. Before that, he was New Zealand’s Privacy Commissioner. His tenure at the ICO included major decisions on WhatsApp HD photo sending and data-sharing rules, but his leadership is now overshadowed by the misconduct allegations.

The Department for Science, Innovation and Technology (DSIT) has not commented on the legal threat beyond Kendall’s remarks. Neither Edwards, the ICO, nor the government immediately responded to requests for comment.

Broader implications for workplace whistleblowing

Kendall’s disclosure raises questions about the protections available to whistleblowers in UK public bodies. The minister made clear she views the legal action as an attempt to intimidate someone who came forward in good faith.

Employment lawyers say that while individuals have a right to defend themselves against allegations, threatening legal action against a complainant can be seen as retaliation. Under UK employment law, whistleblowers are protected from detriment or dismissal for making protected disclosures.

The case could prompt wider discussions about how regulators handle internal complaints. The ICO, which enforces rules on data privacy, is now itself under investigation for its handling of workplace conduct.

For the women who spoke up, Kendall’s public support may offer some reassurance. But the prospect of facing legal proceedings from a former boss — one who once held one of the most powerful regulatory posts in the country — is daunting.

“The women who’ve spoken up have been incredibly brave,” Kendall repeated. “They need to know they will always be listened to without being put at personal risk.”

Continue Reading

Trending