Sabine Frömling
- Indexed articles, last 90 days
- 5
- Latest publication
- Sep 8, 2026
- Outlet visibility, for CSO Online
- Top 5M sites
- Earliest in this view
- Jul 9, 2026
Latest articles
CISA tells operators to harden Siemens S7 PLCs. Here’s how to do it without disrupting production (opens the original)
Read excerpt
On a conventional server, disabling an unused service is usually a routine hardening task. On a Siemens S7 controller, the supposedly unused service may carry remote I/O traffic, supply process values to an HMI or provide the maintenance team’s only path to diagnostics. Close it without checking those dependencies and the security team may cause the outage it intended to prevent. That is the implementation problem inside joint cybersecurity advisory AA26-231A, issued on August 19 by the NSA, CIS
When the patch tsunami meets the maintenance window (opens the original)
Read excerpt
In April 2026, the balance between finding software flaws and fixing them broke. Frontier AI models released by Anthropic and OpenAI can now autonomously identify exploitable vulnerabilities in production software — work that used to take experienced human researchers roughly sixty days now takes about four hours, as Melissa Hathaway documents in a recent Cyber Defense Review perspective. According to the same paper, at least 40 of the largest software and hardware vendors already have access to
The Minnesota attackers may hold a better backup of your plant than you do (opens the original)
Read excerpt
More than 30 Minnesota community water systems were hit by coordinated cyber activity against their operational technology on July 26 and 27; several lost remote control or deliberately cut it while operators contained the intrusion. The reporting since — including CSO’s own news analysis — has rightly chased two open questions: Who did it, and whether a shared weakness in Rockwell Automation MicroLogix 1400 controllers tied dozens of small utilities together. Both questions matter. Neither chan
The containment paradox: Why your ransomware playbook has the wrong people in charge (opens the original)
Read excerpt
I have sat in on a version of the same incident post-mortem in three sectors over the past two years. The script does not vary much. At 4:47 a.m. on a Saturday, an on-duty SOC analyst sees a ransomware payload spreading across three servers in the data center. The playbook says isolate. They hit the switch. Sixteen minutes later the CFO is on the phone: Those three servers were the production payment gateway. The malware would likely have reached a dozen more endpoints. The isolation took down r
Agentic AI identity: A 6-stage maturity model for non-human identities (opens the original)
Read excerpt
In a client engagement last year, an LLM-based deployment agent with standing access to a production Kubernetes cluster triggered a four-hour outage through a malformed configuration push. In the IAM, the agent appeared as a service account with a long-lived API key, no MFA, no scoped revocation path. When the incident review team asked which human had authorized the agent’s last action, no one in the room could answer. I have watched a version of that question go unanswered in three engagements
Publishing over time
Last 90 days. Choose a month to open its work.
Recurring subjects
Named in the text we hold. One piece can cover several.
Audience
Top 5M sites
For CSO Online, the outlet · Measured Aug 1, 2026
Website popularity band, not a count of readers or article views.
About this data
Counts cover the work we have indexed. Tone needs enough text and a confident classification. Excerpts and episode notes are not full articles or transcripts.
Identity or attribution wrong? Suggest a correction.