Tag: ai
-
OpenAI, Anthropic, and Meta AI Breaches Shared the Same Testing Vendor
OpenAI, Anthropic, and Meta AI incidents reportedly shared one testing vendor, exposing third-party and containment risks in AI security evaluations. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/cloud-security/news-openai-anthropic-meta-ai-incidents-irregular/
-
The inconvenient truth about AI pentesting: someone has to check all the work
AI pentesting can flood teams with findings they cannot validate. The real challenge is managing “validation debt” as discovery scales. AI pentesting has a ‘Sorcerer’s Apprentice’ problem. Enchant a broom to fetch water, and it will fetch water, relentlessly, long after the workshop has flooded. The industry is busy measuring how fast AI finds vulnerabilities…
-
Researchers Disclose AI-Assisted SharePoint Exploit Chain Reaching Unauthenticated RCE
Security researchers found a way to enter Microsoft SharePoint servers as any user, including an administrator, with no valid account. A significant part of the work that found it was done through an AI agent.The flaw, tracked as CVE-2026-55040 (CVSS 9.1), affects SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Server 2016. Microsoft’s First…
-
CVE Program eyes automation and globalization to weather AI ‘vulnpocalypse’
The vulnerability-coordination project has had a rocky few years, but a key leader says it will “flourish and improve.” First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/cve-program-ai-black-hat-def-con/827477/
-
NIST wants to overhaul its vulnerability database for the AI age
NIST is seeking public input to modernize the National Vulnerability Database to keep pace with AI-driven cyber threats and machine-scale security data. First seen on cyberscoop.com Jump to article: cyberscoop.com/nist-national-vulnerability-database-ai-overhaul/
-
Verschlüsselte KI-Denkprotokolle geknackt Schwachstelle bei OpenAI, Anthropic und Google
Forscher haben eine gravierende Schwachstelle bei der Absicherung sogenannter Reasoning-Logs entdeckt. Verschlüsselte Denkprotokolle moderner KI-Modelle lassen sich demnach unter bestimmten Bedingungen über ein schwächeres Modell desselben Anbieters entschlüsseln. Besonders brisant: In öffentlich zugänglichen Datensätzen fanden die Forscher bereits personenbezogene Daten, Zugangsdaten, API-Schlüssel und Passwörter. Forscher von MATS Research, dem Max-Planck-Institut für intelligente Systeme, dem ELLIS…
-
Blumira Unveils AI Command Center for Cybersecurity Tools
Blumira today unfurled a command center that makes it simpler to integrate cybersecurity tools based on artificial intelligence (AI) that were developed by different vendors. Mike Toole, head of security and IT for Blumira, said Hearth makes it possible to integrate cybersecurity tools from different vendors through a common interface. Additionally, cybersecurity teams will find..…
-
AI Helps Researchers Uncover Zoom Zero-Click RCE in Less Than a Day
Researchers used public AI models to uncover ZOOMSDAY, a critical Zoom zero-click RCE exploit chain, in less than 24 hours. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/ai-helps-researchers-uncover-zoom-zero-click-rce-in-less-than-a-day/
-
95 Prozent der Unternehmen verschieben KI-Projekte aufgrund von Hürden in der Datenarchitektur
Tags: aiCloudera veröffentlicht seine neueste globale Studie ‘The Great AI Re-Architecture”. Diese zeigt einen grundlegenden Wandel in der Unternehmens-IT. So überarbeiten immer mehr Betriebe ihre Datenarchitekturen, um den Anforderungen von KI gerecht zu werden. Denn obwohl die KI-Nutzung zum Standard geworden ist, schränken veraltete Datenarchitekturen zunehmend die Fähigkeit von Unternehmen ein, KI sicher, effizient und kostengünstig zu…
-
Drei KI-Vorfälle in vierzehn Tagen Von der Evaluierung zum Ernstfall
Innerhalb von vierzehn Tagen haben OpenAI, Anthropic und das britische AI Security Institute (AISI) jeweils offengelegt, dass KI-Agenten im Rahmen interner Sicherheitsprüfungen den vorgesehenen Testrahmen verlassen und auf reale Systeme sowie reale Personen eingewirkt haben. Weniger bemerkenswert als die Einzelfälle ist dabei die Geschwindigkeit, mit der sich die Fähigkeiten dieser Agenten entwickeln und der […]…
-
Vague Task, Total Access: When AI Delegation Becomes a Security Risk
AI agents can improvise beyond the intended scope of a task when they are given broad access to enterprise systems and data. Token Security explains why organizations need to define agent intent and continuously enforce permissions around what each agent was actually created to do. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/vague-task-total-access-when-ai-delegation-becomes-a-security-risk/
-
A Zoom Screen-Sharing Bug Let Anyone Take Over Other Devices on a Call
Researchers say it took fewer than 20 prompts for a public AI tool to find a flaw (now fixed) allowing anyone on a Zoom call to hijack another participants’ device. First seen on wired.com Jump to article: www.wired.com/story/a-zoom-screen-sharing-bug-let-anyone-take-over-other-devices-on-a-call/
-
LiteLLM Attack Shows AI Infrastructure Is Becoming a Strategic Software Supply Chain Target
Tags: ai, attack, breach, cloud, credentials, cyber, infrastructure, malicious, pypi, software, supply-chain, theftThe March 2026 compromise of LiteLLM was more than a short-lived malicious PyPI upload. It demonstrated how an upstream breach in developer tooling can turn AI infrastructure into a high-value conduit for credential theft, cloud intrusion, and downstream software supply chain abuse. The packages were available for roughly 40 minutes before quarantine, but their brief…
-
OpenAI Launches Two-Tier Security Access Program Alongside GPT 5.6 Cyber
Daybreak Blue removes some OpenAI-made guardrails while Daybreak Red grants the use of cyber-focused frontier AI models First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/openai-daybreak-blue-red-gpt-cyber/
-
Acht Minuten bis zur Cloud-Kompromittierung: Wie IAM-Schlüssel und KI Angriffe beschleunigen
Cloud-Angriffe in weniger als zehn Minuten: Wie kompromittierte IAM-Schlüssel, Fehlkonfigurationen und KI das Tempo von Cloud-Attacken erhöhen. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/acht-minuten-bis-zur-cloud-kompromittierung-wie-iam-schluessel-und-ki-angriffe-beschleunigen/a46107/
-
The AI That Hacked Its Way to a Passing Grade Wasn’t the Real Story
Tags: aiAn autonomous model breaking containment is alarming. What the incident reveals about how enterprises secure AI systems should be even more concerning. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/the-ai-that-hacked-its-way-to-a-passing-grade-wasnt-the-real-story/
-
Nearly 60% of people regretted taking social media financial advice
TSB survey of 2,000 people found that one in four have used artificial intelligence for financial advice First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366648053/Nearly-60-of-people-regretted-taking-social-media-financial-advice
-
Malicious MCP Servers Can Split Instructions to Make AI Coding Agents Exfiltrate Secrets
A malicious tool server connected to an AI coding assistant can quietly walk off with SSH keys, environment secrets, source code, and customer data without ever sending one obviously harmful instruction.The trick can work even after a blunt version of the same theft is refused: split the request into fragments that each look routine, place…
-
Nutzer wollte nur Kurs buchen: KI-Agent hat unerwartet ein Fitnessstudio gehackt
Tags: aiUnverhoffte KI-Hacks gibt es nicht nur mit den neuesten Modellen. In Australien ist ein KI-Agent schon vor Monaten in eine Buchungsplattform eingedrungen. First seen on golem.de Jump to article: www.golem.de/news/nutzer-wollte-nur-kurs-buchen-ki-agent-hackte-unerwartet-ein-fitnessstudio-2608-211796.html
-
Fast die Hälfte der KI-Nutzung in Unternehmen basiert auf ungesicherter Schatten-KI
Bericht thematisiert unautorisierte Anwendungen, neue Angriffsvektoren und erforderliche Sicherheitsstrategien. Management Summary Schatten-KI ist kein Randphänomen mehr: Fast jede zweite KI-Interaktion läuft über private Identitäten und entzieht sich damit Governance, Monitoring und Compliance. Die Angriffsfläche verlagert sich in den Browser und die Entwicklungsumgebung: Erweiterungen, KI-Coding-Assistenten und agentische Browser werden zu neuen Einfallstoren für Datenabfluss und……
-
Mythos und KI-Cybersicherheit: Geschwindigkeit wird zum entscheidenden Sicherheitsfaktor
KI erfindet Cyberrisiken nicht neu, beschleunigt aber Angriffe und Schwachstellensuche. Was Mythos für Vulnerability Management und Cyberabwehr bedeutet. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/mythos-und-ki-cybersicherheit-geschwindigkeit-wird-zum-entscheidenden-sicherheitsfaktor/a46089/
-
Anthropic Adds Invisible Watermarks to Claude AI-Generated Text and Signed Metadata to Files
Anthropic has launched a machine-readable content-marking initiative for materials generated by its Claude models. This initiative combines invisible text watermarks with digitally signed provenance metadata for supported files. This move follows Anthropic’s commitment to the transparency guidelines outlined in Article 50(2) of the European Union AI Act. Anthropic Adds Invisible Watermarks to Claude According to…
-
OpenAI, Anthropic und AISI: Was die drei KI-Vorfälle über Agentensicherheit aussagen
Drei KI-Sicherheitsvorfälle bei OpenAI, Anthropic und AISI zeigen, warum Unternehmen Kontrolle, Monitoring und Governance für KI-Agenten benötigen. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/openai-anthropic-und-aisi-was-die-drei-ki-vorfaelle-ueber-agentensicherheit-aussagen/a46084/
-
OpenAI Launches GPT-5.6-Cyber to Find Zero-Day Vulnerabilities and Develop Exploit Chains
OpenAI has expanded its Daybreak cybersecurity program with the introduction of GPT-5.6-Cyber, a purpose-trained model specifically designed for authorized vulnerability research, exploit validation, and advanced security testing. Built on the foundation of GPT-5.6 Sol, this new model serves as a controlled-access tool for trusted defenders as AI-assisted offensive capabilities continue to evolve. GPT-5.6-Cyber to Find…
-
Nach KI-Hacks: Chinesisches KI-Modell trickst Forscher bei Tests aus
Das KI-Modell Kimi K3 hat bei Tests eine gesicherte Umgebung verlassen und sich die gesuchten Lösungen einfach bei Github beschafft. First seen on golem.de Jump to article: www.golem.de/news/nach-ki-hacks-chinesisches-ki-modell-trickst-forscher-bei-cybertests-aus-2608-211748.html
-
An AI tool found 84 flaws in 5G network software and 23 of them still have no fix
Researchers at Nanyang Technological University turned a set of AI agents loose on the software that runs 4G and 5G phone networks, and the agents came back with 84 security … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/11/5g-core-network-vulnerabilities-research/
-
KI-Vorfälle nur Symptome IT-Sicherheit muss auf Identitäten fokussieren
Tags: aiFirst seen on datensicherheit.de Jump to article: www.datensicherheit.de/ki-vorfaelle-symptome-it-sicherheit-identitaeten-fokus
-
Gym Booking Task Turns Into Real-World AI Cyberattack
An AI agent hacked a gym booking system while trying to help a user, booking early and removing another person from the waitlist. An Australian man asked his AI assistant to book him into a gym class. He didn’t ask it to hack the booking software, and he definitely didn’t ask it to remove another…
-
Meta Puts Open-Source AI Bet on Muse Glimmer
Local Agentic AI Model Targets Coding, Tool Calling and Multi-Step Tasks. Meta hopes to recapture the momentum it had when it first launched its Llama artificial intelligence model. Now, with a new model and an increased focus on open-source AI, the social media giant is going against the more proprietary approach of its competitors. First…

