Tag: ai
-
OAuth 2.0 Token Exchange (RFC 8693) for Agent Delegation: A Worked Example
Tags: aiA worked RFC 8693 token exchange for AI agent delegation: actor_token, the act claim, downscoping, nested delegation chains, and what the spec does not cover. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/oauth-2-0-token-exchange-rfc-8693-for-agent-delegation-a-worked-example/
-
OpenAI Says Its AI Hacked Another Company on Its Own
OpenAI disclosed an unusual AI security incident involving a frontier model evaluation and Hugging Face, but the episode cuts through the hype: was this true autonomous intent, an agent following bad scope boundaries, or a warning about giving AI systems real tools and permissions? Tom, Scott, and Kevin discuss why anthropomorphizing AI makes the story……
-
What the Minnesota Water Attacks Reveal About Securing Remote Access to Critical Infrastructure
Tags: access, ai, attack, authentication, cisa, control, corporate, credentials, cyberattack, data-breach, exploit, Hardware, identity, infrastructure, Internet, law, least-privilege, malware, mfa, monitoring, network, password, risk, router, supply-chain, technology, vpn, zero-day, zero-trustWhen headlines break about cyberattacks targeting critical infrastructure, the conversation often turns immediately to zero-day exploits, advanced malware, and other sophisticated techniques. The recent attacks on municipal water systems across at least seven US states, including more than 30 Minnesota water and wastewater utilities, illustrate why this assumption can be misleading. As a “recovering CISO” who…
-
Hugging Face Diffusers Flaws Could Let Model Repositories Execute Arbitrary Code
Three high-severity security flaws have been disclosed in Hugging Face’s Diffusers library that could allow crafted model repositories to stealthily execute arbitrary code on machines that load it, opening the artificial intelligence (AI) supply chain to security risk.”These vulnerabilities are bypassing trust_remote_code, the safeguard designed to stop unreviewed code from running in the First seen…
-
AI is now both the weapon and the target in cyberattacks
AI generates 2.5 signals for every human-triggered signal CrowdStrike has to assess. Meanwhile, attackers are using AI to weaponize vulnerabilities faster than companies can patch them. First seen on cyberscoop.com Jump to article: cyberscoop.com/crowdstrike-annual-threat-hunting-report-2026/
-
SkillSpector: NVIDIA’s open-source security scanner for AI agent skills
SkillSpector is an open-source scanner from NVIDIA that reads an agent skill and tells you whether to install it. Point it at a directory, a zip file, a single SKILL.md, or a … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/03/skillspector-open-source-agent-skill-security-scanner/
-
Mapping the malware blast radius a single alert won’t show you
In this interview with Help Net Security, Mike Wiacek, founder and CTO of Stairwell, explains Backstory, an AI agent that takes a single alert and works outward to map how far … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/03/mike-wiacek-stairwell-backstory-malware-blast-radius/
-
AI cut phishing from hours to seconds, which is where DMARC and BIMI come in
In this Help Net Security video, Mike Boyle, VP of Business Units at GMO GlobalSign, and Rahul Powar, CEO and founder of Red Sift, unpack the evolution of email security and … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/03/dmarc-and-bimi-video/
-
KI-Systeme: Wer testet, haftet für die Folgen
Tags: aiFirst seen on datensicherheit.de Jump to article: www.datensicherheit.de/ki-systeme-test-haftung-folgen
-
Entwicklung zur verlässlichen Geschäftstechnologie: KI-Kennzeichnung gemäß EU AI Act erst der Anfang
Tags: aiFirst seen on datensicherheit.de Jump to article: www.datensicherheit.de/entwicklung-verlass-geschaeftstechnologie-ki-kennzeichnung-anfang
-
OpenAI teases Astra, its next major AI model, after it solves 10 long-standing math problems
OpenAI has revealed Astra, an unreleased model designed to tackle complex, long-running tasks, after an internal version produced ten significant advances in mathematics and theoretical computer science. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/artificial-intelligence/openai-teases-astra-its-next-major-ai-model-after-it-solves-10-long-standing-math-problems/
-
The Massive AI Security Hole Your CISO Doesn’t Know About
Your AI security review passed and still missed the real attack surface. EchoLeak, over-permissioned agents, shadow AI: the AI-specific vectors most CISOs never test for, and the five moves that close them. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/the-massive-ai-security-hole-your-ciso-doesnt-know-about/
-
Why a Payments Company Wants an AI Model Router: Tokens Are Acting Like Currency
OpenRouter was worth .3 billion in May. Stripe is reportedly discussing billion in July. The routing layer turned out to be the valuable part. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/why-a-payments-company-wants-an-ai-model-router-tokens-are-acting-like-currency/
-
SabPaisa Partners with AccuKnox for Zero Trust AI-Powered Cloud Security to Secure Its Payments Platform
CALIFORNIA, USA, August 2nd, 2026, CyberNewswire AccuKnox, a leading Zero Trust Security platform, today announced that SabPaisa, an RBI-authorised digital payments company, has selected its AI-powered cloud security platform to ensure robust security of its payments platform. SabPaisa joins a growing roster of financial services leaders using AccuKnox to meet stringent compliance requirements while defending…
-
Grip AI Security Platform First AI Security
Discover the Grip AI Security Platform. Gain visibility into AI applications, agents, identities, and permissions with identity-first AI governance. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/grip-ai-security-platform-identity-first-ai-security/
-
AI Security Incident Response Framework – Kovrr
Articles related to cyber risk quantification, cyber risk management, and cyber resilience. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/ai-security-incident-response-framework-kovrr/
-
SabPaisa Partners with AccuKnox for Zero Trust AI-Powered Cloud Security to Secure Its Payments Platform
CALIFORNIA, USA, 2nd August 2026, CyberNewswire First seen on hackread.com Jump to article: hackread.com/sabpaisa-partners-with-accuknox-for-zero-trust-ai-powered-cloud-security-to-secure-its-payments-platform/
-
Weekly Cybersecurity Newsletter Top 50 Biggest Cybersecurity Stories of the Week Hugging Face, Iranian ICS Attacks, EY, Hyundai, AI Agent Breaches
Welcome to this week’s edition of the GBHackers cybersecurity newsletter, your weekly cybersecurity bulletin covering the 50 most important stories from July 27August 1, 2026. The week’s throughline was AI on both sides of the fight: an autonomous agent escaped its sandbox and breached Hugging Face, a DeepSeek agent drove autonomous attacks, and Google […]…
-
KI-Vorfälle rund um Anthropic und OpenAI: Warum die Regeln des EU AI Act genau zur richtigen Zeit kommen
Mit dem zweiten August werden Teile der verbleibenden Elemente des EU AI Act, der ersten KI-Regulierung der EU, anwendbar und sollen für mehr Disziplin und Sicherheit sorgen. Die Reglementierungen kommen wohl zur richtigen Zeit, wie die jüngsten Vorfälle bei den beiden US-Entwickler OpenAI und Anthropic zeigen. KI reißt Sicherheitslücken und kann Daten kompromittieren. Was bedeuten die……
-
Transparenzpflichten für künstliche Intelligenz starten im regulatorischen Blindflug
Tags: aiAb Sonntag den 02.08.2026 gelten in der Europäischen Union die Transparenzpflichten aus Artikel 50 des AI-Act. Unternehmen aller Größen und Branchen müssen künftig unter anderem kenntlich machen, wenn Nutzerinnen und Nutzer mit einem Chatbot oder Sprachassistenten interagieren. Auch für KI-generierte und bearbeitete Inhalte gelten neue Kennzeichnungs- und Informationspflichten. »Transparenz schafft Vertrauen und ist eine… First…
-
Week in review: Claude breached three companies during tests, AD CS domain-takeover PoC released
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Nono: Open-source sandbox for AI agents AI coding agents run with the same … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/02/week-in-review-claude-breached-three-companies-during-tests-ad-cs-domain-takeover-poc-released/
-
CEO Jensen Huang setzt sich für offene KI-Modelle ein welche Vorteile er darin sieht
First seen on t3n.de Jump to article: t3n.de/news/nvidia-jensen-huang-offene-ki-modelle-1755752/
-
Unlock AI GRC Automation via Continuum Cybersecurity Audits 2026
In 2026, organizations face mounting pressure to integrate AI automation into governance, risk, and compliance (GRC) programs while maintaining rigorous cybersecurity audit standards. AI Automation in GRC is no longer experimental; it is a strategic necessity for CISOs and compliance officers seeking to reduce manual overhead, close control gaps, and achieve continuous compliance across frameworks”¦…
-
Chinesischer Hacker steuert DeepSeek über Telegram für autonome Angriffe
Ein chinesischsprachiger Angreifer ließ das KI-Modell DeepSeek über das Framework Hermes Agent weitgehend selbstständig Angriffe ausführen. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/hacker-deepseek-autonome-angriffe
-
AI chatbots outperform humans in building trust for scams
First seen on scworld.com Jump to article: www.scworld.com/brief/ai-chatbots-outperform-humans-in-building-trust-for-scams
-
MSSP Market News: AI security platforms take on more of the SOC ahead of Black Hat 2026
First seen on scworld.com Jump to article: www.scworld.com/news/mssp-market-news-ai-security-platforms-take-on-more-of-the-soc-ahead-of-black-hat-2026
-
Acronis pushes MSPs toward autonomous IT with AI service desk and cloud infrastructure
First seen on scworld.com Jump to article: www.scworld.com/news/acronis-pushes-msps-toward-autonomous-it-with-ai-service-desk-and-cloud-infrastructure
-
Channel Brief: AI-native is the new pitch. MSPs are still working out the pricing.
First seen on scworld.com Jump to article: www.scworld.com/news/channel-brief-msps-are-all-in-on-ai-the-revenue-still-hasnt-followed-1
-
AI Act: Ab 2. August 2026 weitere Regeln in Kraft indes noch viele offene Fragen
Tags: aiFirst seen on datensicherheit.de Jump to article: www.datensicherheit.de/ai-act-2-august-2026-regeln-kraft-fragen-offen
-
When AI Hackers Meet Machine Identity: The Ignored Attack Surface
The Salesloft Drift breach hit 700+ companies with stolen OAuth tokens and never touched a password. Machine identities now outnumber humans 80 to 1, and AI-powered attackers are harvesting them at machine speed. Here is why human-shaped IAM cannot protect AI agents, and what to fix in 90 days. First seen on securityboulevard.com Jump to…

