Tag: ai
-
KI-Agent von OpenAI greift auf australisches Medicare-Portal zu
Ein KI-Agent von OpenAI hat sich nach Angaben der australischen Regierung unberechtigt Zugang zu einem Statistikportal von Medicare, Australiens staatlichem Krankenversicherungssystem, verschafft. Der Vorfall wirft konkrete Sicherheitsfragen für Unternehmen auf: Wie lässt sich verhindern, dass KI-Agenten ihre vorgesehenen Berechtigungen überschreiten? Und wie sollten Organisationen reagieren, wenn es dennoch zu einem Vorfall kommt? Laura Ellis, Senior…
-
Vibe-Coding schafft Risiken
Der zunehmende Einsatz von KI-Kodierungstools kurz Vibe-Coding beschleunigt zwar die Softwareentwicklung erheblich. Allerdings verändert die Nutzung dieser Tools unbemerkt die Zusammensetzung von Entwicklungsumgebungen und schafft damit ein Sicherheitsproblem, das klassische Patch- und Compliance-Prozesse übersehen können. Besonders betroffen sind Entwicklerrechner mit zahlreichen .NET-SDK- und Runtime-Versionen. Generative KI und agentenbasierte Entwicklungswerkzeuge sind inzwischen fester Bestandteil […] First…
-
Warum Unternehmen KI-Souveränität und Performance zusammendenken sollten
Tags: aiKI-Souveränität und KI-Performance werden oft als Widerspruch gesehen. Doch wer Modelle frei wählen, Unternehmenswissen gezielt nutzbar machen und den Handlungsspielraum von KI-Agenten kontrollieren kann, schafft die Grundlage für bessere Leistung. Nico Bäumer, Vorstand und CTO der d.velop AG, erklärt, wie das gelingt. Künstliche Intelligenz (KI) entwickelt sich rasant weiter: Neue Modelle versprechen immer bessere Leistungen…
-
Prompt-Injection Bug Hits $4B Agentic AI App ‘Manus’
AI apps that interpret external data (read: most AI apps) need exceptionally rigorous security filters, or attackers can take advantage. First seen on darkreading.com Jump to article: www.darkreading.com/application-security/prompt-injection-bug-agentic-ai-app-manus
-
Prompt-Injection Bug Hits $4B Agentic AI App ‘Manus’
AI apps that interpret external data (read: most AI apps) need exceptionally rigorous security filters, or attackers can take advantage. First seen on darkreading.com Jump to article: www.darkreading.com/application-security/prompt-injection-bug-agentic-ai-app-manus
-
Cybersicherheitsplattform erkennt, bewertet und minimiert KI-Risiken
<> von Bitdefender verschafft Unternehmen und Managed-Service-Providern (MSPs) die Sichtbarkeit über die Nutzung von KI-Tools durch Mitarbeiter und gibt ihnen die Möglichkeit, die damit verbundenen Risiken proaktiv zu minimieren. Die Lösung ist darauf ausgerichtet, eine der am schnellsten wachsenden Angriffsflächen zu schützen und eine sichere Einführung von KI zu ermöglichen, ohne […] First seen on…
-
Meta locks itself out of user data on its AI glasses
Meta is expanding Private Processing to its AI glasses, extending their security protections into cloud data centers. The system runs AI models inside confidential virtual … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/24/meta-private-processing-for-ai-glasses/
-
OpenAI agent breached Australia’s Medicare portal and nobody noticed for three months
An autonomous AI agent built by OpenAI gained unauthorised access to non-public files on an Australian government Medicare portal in June, but Canberra was only told about it in September, in what is being described as the first known case of an AI agent hacking a government system. Prime Minister Anthony Albanese, speaking in New…
-
Secrets Sprawl Is an Identity Problem That AI Just Made Impossible to Ignore
AI coding agents are changing how quickly developers can build and ship software as well as how quickly credentials can become exposed. According to GitGuardian’s 2026 State of Secrets Sprawl Report, commits identified as AI-assisted are leaking secrets at approximately twice the rate of human-written ones. Most of the fastest-growing categories of leaked credentials are…
-
OpenAI Agent Bypassed an Australian Government Health Portal During Internal Research
OpenAI’s AI agent bypassed controls on an Australian health portal, accessed non-public files and triggered a government investigation. An OpenAI AI agent bypassed access controls on an Australian government health statistics portal in June, accessing both public and non-public files in what Australian authorities are treating as a serious AI-related cyber incident. The case was…
-
Google plans to give Private AI Compute a memory that follows users across devices
Google plans to add private, server-side memory to Private AI Compute, enabling AI assistants to maintain continuity across devices while providing privacy protections … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/24/google-private-ai-compute-server-side-memory/
-
Datenklau mit KI: Angreifer infiltrieren Webshops und stehlen Kreditkartendaten
Mithilfe von KI-Tools sind Angreifer an mindestens 600.000 gültige Kreditkartendaten aus mehreren Webshops gelangt. Die Angriffe dauern an. First seen on golem.de Jump to article: www.golem.de/news/datenklau-mit-ki-angreifer-infiltrieren-webshops-und-stehlen-kreditkartendaten-2609-213393.html
-
Over 75% of Organizations Experience Microsoft 365 Governance Issues
ShareGate study claims to reveal a governance ‘crisis’ as AI usage grows First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/75-organizations-microsoft-365/
-
KI-Angriff auf Australien: OpenAI-Agent hat sich in Regierungsportal gehackt
Ein KI-Agent von OpenAI sollte australische Gesundheitsstatistiken recherchieren. Dabei ist er aber zu weit gegangen und hat geschützte Daten abgerufen. First seen on golem.de Jump to article: www.golem.de/news/australien-openai-agent-hat-sich-in-regierungsportal-gehackt-2609-213388.html
-
OpenAI AI Agent Breaches Australian Government Website, Albanese Demands Answers
Australian Prime Minister Anthony Albanese has demanded answers from OpenAI chief executive Sam Altman after an AI agent broke into an Australian government website. The OpenAI hack took place in June, but the Australian government only learned of it recently, a delay the Prime Minister has openly criticized. First seen on thecyberexpress.com Jump to article:…
-
Microsoft Rebuilds the SOC With AI Agents to Fight Machine-Speed Cyberattacks
An Integrated Security Operations Center (ISOC) in Microsoft Defender, unifying security information and event management (SIEM) and threat-protection capabilities in a platform designed for AI-assisted, continuous defense. The company’s premise is direct: traditional SOC architectures cannot match adversaries that use AI agents to automate reconnaissance, intrusion execution, lateral movement, and operational decision-making at machine speed.…
-
OpenAI Agent Bypassed Australian Medicare Portal Controls to Access Non-Public Files
An AI agent on an internal OpenAI research task bypassed access controls on an Australian government Medicare statistics portal in June, Prime Minister Anthony Albanese said.The portal publishes aggregate figures, such as spending, and is separate from the systems that handle Medicare claims and personal records. The agent reached files on it that were not…
-
Australien: OpenAI-Agent hat sich in Regierungsportal gehackt
Ein KI-Agent von OpenAI sollte australische Gesundheitsstatistiken recherchieren. Dabei ist er aber zu weit gegangen und hat geschützte Daten abgerufen. First seen on golem.de Jump to article: www.golem.de/news/australien-openai-agent-hat-sich-in-regierungsportal-gehackt-2609-213388.html
-
Whitepaper: Der Perimeter hat sich aufgelöst, Identitäten sind der neue Kontrollpunkt
Identitäten sind der neue Kontrollpunkt der IT-Sicherheit. In hybriden Architekturen entscheidet nicht mehr der Netzwerkstandort, sondern eine belastbare Kette aus Verifikation, Authentifizierung, Autorisierung und laufender Bewertung. Das gilt für Menschen ebenso wie für Workloads und KI-Agenten und wird mit EUDI-Wallet, Schweizer E-ID und wachsender Agenten-Autonomie zur Managementaufgabe. Management Summary Der Perimeter ist zur Identitätsfrage… First…
-
Whitepaper: Der Perimeter hat sich aufgelöst, die Fristen laufen
Identitäten sind der neue Kontrollpunkt der IT-Sicherheit. In hybriden Architekturen entscheidet nicht mehr der Netzwerkstandort, sondern eine belastbare Kette aus Verifikation, Authentifizierung, Autorisierung und laufender Bewertung. Das gilt für Menschen ebenso wie für Workloads und KI-Agenten und wird mit EUDI-Wallet, Schweizer E-ID und wachsender Agenten-Autonomie zur Managementaufgabe. Management Summary Der Perimeter ist zur Identitätsfrage… First…
-
CLOSEDQUORUM, the malware that asks four AI models what to do next
Cisco Talos finds CLOSEDQUORUM, malware that lets four commercial AI models vote on its next move, with no human operator required. Cisco Talos found malware, dubbed CLOSEDQUORUM, that holds a vote before deciding what to steal from you. Four AI models vote on its next move, without any human interaction. CLOSEDQUORUM is the first Windows…
-
After water attacks, Capitol Hill offers its own proposal for an AI-cyber test program
A key House Democrat and his bipartisan sponsors want to see a $100 million DHS pilot to help critical infrastructure owners and operators, separate from another administration-proposed pilot program. First seen on cyberscoop.com Jump to article: cyberscoop.com/gottheimer-ai-cyber-defense-act-cisa-pilot/
-
Microsoft disrupts AI-assisted platform that compromised 12,000 accounts
EvilTokens provided an end-to-end platform that makes mass compromises faster and easier. First seen on arstechnica.com Jump to article: arstechnica.com/security/2026/09/microsoft-disrupts-ai-assisted-platform-that-compromised-12000/
-
Angreifer machen mehr Tempo: Wie KI den Cyberdruck auf KMU erhöht
KI schafft neue Angriffsflächen und verstärkt zugleich bekannte Cyberbedrohungen. Für kleine IT-Teams wird es damit schwieriger, Risiken früh zu erkennen und mit begrenzten Ressourcen richtig zu reagieren. First seen on welivesecurity.com Jump to article: www.welivesecurity.com/de/business-security/angreifer-machen-mehr-tempo-wie-ki-den-cyberdruck-auf-kmu-erhoht/
-
Angreifer machen mehr Tempo: Wie KI den Cyberdruck auf KMU erhöht
KI schafft neue Angriffsflächen und verstärkt zugleich bekannte Cyberbedrohungen. Für kleine IT-Teams wird es damit schwieriger, Risiken früh zu erkennen und mit begrenzten Ressourcen richtig zu reagieren. First seen on welivesecurity.com Jump to article: www.welivesecurity.com/de/business-security/angreifer-machen-mehr-tempo-wie-ki-den-cyberdruck-auf-kmu-erhoht/
-
New Optiv CRO: AI Is Disrupting Security In A ‘Compressed Timeframe’
The unprecedented pace of the AI revolution is creating massive opportunities for cybersecurity powerhouse Optiv to become even more essential to customers”, particularly when it comes to helping customers to navigate security challenges that are changing more rapidly than in the past, according to new Optiv CRO Sean Forkan. First seen on crn.com Jump to…
-
Dubai Unveils Open-Source Deepfake Detection AI
Cybersecurity Regulator Says Saraab AI Model Can Spot Deepfakes With 91% Accuracy. The Dubai Electronic Security Center, the Middle Eastern emirate’s cybersecurity regulator, has built an AI model called Saraab that detects deepfake videos, and plans to open source it by the end of the year so it can be improved by researchers, AI companies…
-
New ClosedQuorum Windows malware uses AI for attack decisions
A new Windows malware named ClosedQuorum uses Google Gemini, DeepSeek, Qwen, and Mistral AI models to autonomously determine the actions to take during post-compromise stages of an attack. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/new-closedquorum-windows-malware-uses-ai-for-attack-decisions/
-
Microsoft Takes Down EvilTokens Device-Code Phishing Service Tied to 12,000 Inbox Compromises
Microsoft on Tuesday announced the takedown of the EvilTokens device code phishing service that it said used artificial intelligence (AI) “at every step of the attack chain.”The action, carried out with authorization from the U.S. District Court for the Eastern District of Virginia, involved the efforts of Health-ISAC, alongside Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, The…
-
Critical Bifrost AI Gateway Flaw Lets Attackers Run Commands Without Credentials
A critical vulnerability in Bifrost, an open-source AI gateway that routes requests to more than 20 LLM providers, allows an unauthenticated attacker to run arbitrary commands on the gateway server with a single HTTP request.The flaw, tracked as CVE-2026-90898 (CVSS score: 9.8), affects all versions of the Bifrost HTTP transport before 2.1.0 when management authentication…

