Tag: ai
-
CLOSEDQUORUM, the malware that asks four AI models what to do next
Cisco Talos finds CLOSEDQUORUM, malware that lets four commercial AI models vote on its next move, with no human operator required. Cisco Talos found malware, dubbed CLOSEDQUORUM, that holds a vote before deciding what to steal from you. Four AI models vote on its next move, without any human interaction. CLOSEDQUORUM is the first Windows…
-
After water attacks, Capitol Hill offers its own proposal for an AI-cyber test program
A key House Democrat and his bipartisan sponsors want to see a $100 million DHS pilot to help critical infrastructure owners and operators, separate from another administration-proposed pilot program. First seen on cyberscoop.com Jump to article: cyberscoop.com/gottheimer-ai-cyber-defense-act-cisa-pilot/
-
Microsoft disrupts AI-assisted platform that compromised 12,000 accounts
EvilTokens provided an end-to-end platform that makes mass compromises faster and easier. First seen on arstechnica.com Jump to article: arstechnica.com/security/2026/09/microsoft-disrupts-ai-assisted-platform-that-compromised-12000/
-
Angreifer machen mehr Tempo: Wie KI den Cyberdruck auf KMU erhöht
KI schafft neue Angriffsflächen und verstärkt zugleich bekannte Cyberbedrohungen. Für kleine IT-Teams wird es damit schwieriger, Risiken früh zu erkennen und mit begrenzten Ressourcen richtig zu reagieren. First seen on welivesecurity.com Jump to article: www.welivesecurity.com/de/business-security/angreifer-machen-mehr-tempo-wie-ki-den-cyberdruck-auf-kmu-erhoht/
-
Angreifer machen mehr Tempo: Wie KI den Cyberdruck auf KMU erhöht
KI schafft neue Angriffsflächen und verstärkt zugleich bekannte Cyberbedrohungen. Für kleine IT-Teams wird es damit schwieriger, Risiken früh zu erkennen und mit begrenzten Ressourcen richtig zu reagieren. First seen on welivesecurity.com Jump to article: www.welivesecurity.com/de/business-security/angreifer-machen-mehr-tempo-wie-ki-den-cyberdruck-auf-kmu-erhoht/
-
New Optiv CRO: AI Is Disrupting Security In A ‘Compressed Timeframe’
The unprecedented pace of the AI revolution is creating massive opportunities for cybersecurity powerhouse Optiv to become even more essential to customers”, particularly when it comes to helping customers to navigate security challenges that are changing more rapidly than in the past, according to new Optiv CRO Sean Forkan. First seen on crn.com Jump to…
-
Dubai Unveils Open-Source Deepfake Detection AI
Cybersecurity Regulator Says Saraab AI Model Can Spot Deepfakes With 91% Accuracy. The Dubai Electronic Security Center, the Middle Eastern emirate’s cybersecurity regulator, has built an AI model called Saraab that detects deepfake videos, and plans to open source it by the end of the year so it can be improved by researchers, AI companies…
-
New ClosedQuorum Windows malware uses AI for attack decisions
A new Windows malware named ClosedQuorum uses Google Gemini, DeepSeek, Qwen, and Mistral AI models to autonomously determine the actions to take during post-compromise stages of an attack. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/new-closedquorum-windows-malware-uses-ai-for-attack-decisions/
-
Microsoft Takes Down EvilTokens Device-Code Phishing Service Tied to 12,000 Inbox Compromises
Microsoft on Tuesday announced the takedown of the EvilTokens device code phishing service that it said used artificial intelligence (AI) “at every step of the attack chain.”The action, carried out with authorization from the U.S. District Court for the Eastern District of Virginia, involved the efforts of Health-ISAC, alongside Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, The…
-
Critical Bifrost AI Gateway Flaw Lets Attackers Run Commands Without Credentials
A critical vulnerability in Bifrost, an open-source AI gateway that routes requests to more than 20 LLM providers, allows an unauthenticated attacker to run arbitrary commands on the gateway server with a single HTTP request.The flaw, tracked as CVE-2026-90898 (CVSS score: 9.8), affects all versions of the Bifrost HTTP transport before 2.1.0 when management authentication…
-
RatHat Android Malware Uses AI to Target Banking Credentials in Real Time
RatHat Android malware uses generative AI to navigate infected devices, steal banking credentials, intercept OTP codes and reinstall itself after removal again. First seen on hackread.com Jump to article: hackread.com/rathat-android-malware-ai-banking-credentials/
-
Operational Technology Scope Expands as Security Matures
Resilience Focus Driven by Major Attacks, Geopolitical Tensions, Fresh Regulations. While technology-driven thinking once dominated operation technology security planning, a more mature and business-driven discussion focused on resilience and cautious AI adoption is fast becoming the norm, finds Honeywell Technologies’ 2026 Operational Technology Cybersecurity Benchmark Report. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/operational-technology-scope-expands-as-security-matures-a-32890
-
Aembit Launches Support for Okta Cross App Access, Extending Enterprise Identity Controls to AI Agents
Silver Spring, Maryland, USA, September 22nd, 2026, CyberNewswire Aembit, the identity and access management (IAM) company for AI agents, today announced support for Cross App Access (XAA), an open protocol introduced by Okta that lets a user’s existing enterprise identity authorize access to downstream applications without a separate consent step for each connection. Launching this…
-
Amid Ongoing Rogue Incidents, Debate Over AI Safety Gets Real
As more reports of misalignment incidents underscore AI risks, large AI labs, regular businesses, and even nations are searching for better ways to keep control and be secure. First seen on darkreading.com Jump to article: www.darkreading.com/cyber-risk/rogue-incidents-debate-ai-safety-gets-real
-
Insurance sector begins to offer clarity on AI-related cyber claims
The emergence of agentic AI and frontier models has led to widespread uncertainty for policyholders. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/insurance-sector-begins-to-offer-clarity-on-ai-related-cyber-claims/831028/
-
Two arrested in UK after Microsoft takedown of ‘Eviltokens’ AI-chatbot for cybercriminals
Available on Telegram for a $1,500 initiation fee and a recurring monthly $500 subscription, EvilTokens provided cybercriminals with artificial intelligence tools enabling them to compromise accounts, analyze breached inboxes and find the best methods for monetizing their access through fraud. First seen on therecord.media Jump to article: therecord.media/two-arrested-in-uk-after-microsoft-takedown-eviltokens
-
Datenschutz mit VPN for AIAgenten
Bitdefender hat seinen neuen Stand-Alone-Dienst für den Endverbraucher, Bitdefender <>, als öffentlich verfügbare Beta-Version vorgestellt. Dies soll den Datenschutz beim Einsatz von KI-Agenten, die sich für ihre menschlichen Auftraggeber im Netz bewegen, recherchieren und agieren, sichern. Jede Aufgabe für einen Agenten erhält eine eigene, private und vorübergehende Verbindung in das Internet. KI-Agenten […] First seen…
-
Retailers tamp down shadow AI but struggle to oversee agentic sprawl
The use of AI agents is soaring in the retail sector, but visibility remains a major challenge, with regulated data at risk. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/retail-ai-agents-visibility-data-breaches-netskope/831002/
-
Google AI models broke out of sandbox, hacked three companies
The incidents stemmed from the same testing environment defects that tripped up OpenAI, Anthropic and Meta. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/google-ai-gemini-autonomous-hacks/830884/
-
Citing China, President Trump doubles down on hands-off approach to AI regulation
Following a series of chaotic agentic hacks, Trump and administration officials have consistently expressed fears of Chinese AI dominance in pushing for fewer regulations. First seen on cyberscoop.com Jump to article: cyberscoop.com/trump-hands-off-ai-regulation-china-race/
-
Microsoft and partners disrupt EvilTokens, a comprehensive cybercrime service for financial fraud
The popular phishing-as-a-service platform used AI throughout the attack chain, allowing cybercriminals to steal tokens for account takeover and business email compromise. First seen on cyberscoop.com Jump to article: cyberscoop.com/microsoft-eviltokens-cybercrime-service-takedown/
-
Partners can fill AI security capability gap
Vendor shares research indicating the areas where the channel can assist users with AI, as ISACA research warns that customers are struggling First seen on computerweekly.com Jump to article: www.computerweekly.com/microscope/news/366650828/Cisco-Partners-can-fill-AI-security-capability-gap
-
Researchers uncover malware that uses AI to choose its next move
To help security practitioners catch malware that leans on AI, researchers from Cisco Talos shared an open-source framework that they hope will be used to classify and analyze … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/22/cairn-open-source-framework-ai-malware-closedquorum/
-
Salt Security adds native AI detection and response to agentic security platform
Salt Security has expanded its Agentic Security Platform with native AI Detection and Response (AI-DR) capabilities designed to connect attacks targeting large language models with subsequent activity across MCP servers, tools and APIs. The new capabilities provide real-time protection against direct and indirect prompt injection, jailbreak attempts, unsafe model behaviour and other threats that emerge…
-
AI Agents Are Rewriting the Rules of Lateral Movement
Security teams have spent decades asking whether an identity has too much access. AI agents raise a harder question: how can we determine which paths an autonomous system can discover, given the access it already has?A person may try several ways to complete a task. A deterministic application follows the flow its developer wrote. But…
-
AI Incident Response Readiness Lags Behind AI Adoption, ISACA Finds
A new report by ISACA found that 71% of orgs have not run AI incident response exercises as teams face rising pressure First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/orgs-lack-ai-incident-response/
-
AI is set to help cyber attackers much more than defenders, says UK official
Dave Chismon, the NCSC’s chief technology officer for architecture, said in a blog post that the imbalance in AI means cyberattacks would likely grow as automated defenses struggle to keep pace. First seen on therecord.media Jump to article: therecord.media/ai-set-to-help-attackers-more-than-defenders
-
Aembit Launches Support for Okta Cross App Access, Extending Enterprise Identity Controls to AI Agents
Silver Spring, Maryland, USA, 22nd September 2026, CyberNewswire First seen on hackread.com Jump to article: hackread.com/aembit-launches-support-for-okta-cross-app-access-extending-enterprise-identity-controls-to-ai-agents/
-
Compliance, KI und hybride IT prägen die Anforderungen an modernes Monitoring
Was sind wichtige Themen, die IT-Verantwortliche in Deutschland, Österreich und der Schweiz aktuell beschäftigen? Das zeigt die neue Kundenumfrage von Paessler, eines führenden Anbieters von IT- und IoT-Monitoring-Lösungen. Dafür wurden 262 PRTG-Nutzer und IT-Administratoren im DACH-Raum aus den Bereichen Produktion, IT, Healthcare, Behörden und weiteren Sektoren befragt. Weltweit nahmen insgesamt 1.088 Personen teil. Im internationalen…
-
Vorfall ohne Verbrecher Wie KI-Agenten eigenständig zum Sicherheitsproblem werden können
Ein interner Check-Point-Hackathon zeigt, dass die Sicherheit von KI-Agenten weit über das Abwehren von Angreifern hinausgeht entscheidend sind die Kontrolle interner Abläufe und intelligente Reaktionen auf Fehltritte. Check Point Research (CPR), die Sicherheitsforschungsabteilung von Check Point Software Technologies, veranstaltete im August einen Hackathon mit sämtlichen internen R&D-Teams. Dabei kamen drei unabhängig voneinander durchgeführte Projekte zu derselben […]…

