Tag: ai
-
MediaTek Fixes 31 Security Flaws Affecting Modem, Video and AI Components
MediaTek has released its October 2026 Product Security Bulletin, which addresses 31 vulnerabilities across modem, video, AI processing, display, trusted execution, and system components used in a wide range of its chipsets. The fixes include two critical modem out-of-bounds write vulnerabilities and nine high-severity flaws that could potentially lead to memory corruption, privilege escalation, or…
-
Google Tightens Open-Source Bug Bounty Rules After Surge in AI-Generated Vulnerability Reports
Google has stopped accepting new >>product vulnerability<< reports through its Open Source Software Vulnerability Reward Program (OSS VRP) due to a significant increase in automated submissions that are predominantly invalid. This restriction took effect on October 1, 2026, and Google plans to provide an update regarding this part of the program in the first quarter…
-
AWS Fixes AI Agent Flaws Enabling Authentication Bypass and Credential Theft
Tags: access, ai, authentication, credentials, cyber, flaw, open-source, theft, update, vulnerabilityAWS released security updates for three vulnerabilities in its open-source Loom platform, used for AI agent orchestration. These vulnerabilities could allow unauthenticated administrative takeover, disclosure of OAuth2 credentials, and access to internal services. The company strongly urges users to upgrade all Loom deployments and forks to version 1.7.0. AWS announced these issues in Security Bulletin…
-
Google Suspends Open-Source Bug Bounty Due to AI Vulnerability Reports
Google has paused its Open Source Vulnerability Rewards Program due to a flood of AI submissions First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/google-suspends-opensource-bug/
-
Google Suspends Open Source Bug Bounty Over AI-Generated Reports
Google has suspended its Open Source Software Vulnerability Rewards Program (OSS VRP), a vulnerability search initiative that paid researchers for finding flaws in the company’s open-source software. The pause took effect on October 1, 2026. Google blamed a “significant rise” in automated and AI-generated reports, most of which turned out to be invalid. First seen…
-
Why permissions must be the foundation for next-gen identity security
Authentication isn’t enough. Monitor access across humans, machines and AI agents. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/spons/why-permissions-must-be-the-foundation-for-next-gen-identity-security/831732/
-
Modernizing data security with DSPM, AI and fewer tools
For organizations, the proper safeguards—such as controls or restrictions—must be put in place. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/spons/modernizing-data-security-with-dspm-ai-and-fewer-tools/831578/
-
Defending against AI-fueled cyberattacks requires focus on identity, data governance, Microsoft says
The company’s latest report previews how AI is changing threat activity, including by automating ransomware attacks. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/ai-cyberattacks-automation-identity-data-microsoft-report/832020/
-
Another OpenAI Safety Expert Quits and Raises New AI Safety Concerns
OpenAI safety veteran David Robinson resigns, warning that the company’s culture and fast AI development model could create bigger risks. OpenAI safety veteran David Robinson knows how his resignation looks. He starts his essay by calling himself “something of a cliché”: an AI company employee who quits and then raises concerns about the company. But…
-
Apple tightens macOS disk access as AI agents become more powerful
Apple plans to introduce additional controls for Full Disk Access in macOS, citing growing privacy risks as AI agents become more capable and autonomous. Users will need to … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/10/05/macos-full-disk-access-updates/
-
AI slop submissions force Google to freeze its open-source bug bounty
Google has stopped accepting new product vulnerability reports through its Open Source Software Vulnerability Reward Program (OSS VRP), after a wave of invalid, AI-generated … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/10/05/google-ai-generated-vulnerability-reports-pause/
-
Google halts open-source bug bounty program amid AI spam surge
Google has now suspended submissions to its Open Source Software Vulnerability Rewards Program (OSS VRP) after being flooded by AI-generated reports. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/google/google-halts-open-source-bug-bounty-program-amid-ai-spam-surge/
-
Autonomous AI Agent Chains Two Zammad Zero-Days in Machine-Speed Cyberattack
An autonomous AI agent breached the Dutch Institute for Vulnerability Disclosure (DIVD) after chaining two previously undisclosed vulnerabilities in the Zammad helpdesk platform, turning an initial application compromise into root access within seconds. The incident, first detected on September 22 after the attacker accessed DIVD systems a day earlier, offers a stark example of how…
-
Von der Risikoerkennung zum aktiven Datenschutz: Thales stärkt DSPM für das KI-Zeitalter
Thales erweitert CipherTrust DSPM, um sensible Daten in Cloud-, On-Premises- und Hybridumgebungen vor neuen Risiken durch KI und autonome Agenten zu schützen. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/von-der-risikoerkennung-zum-aktiven-datenschutz-thales-staerkt-dspm-fuer-das-ki-zeitalter/a46601/
-
Code-Sicherheit mit Frontier-KI – Rubrik-Dienst für KI-gestütztes Red-Teaming von Kundencode
First seen on security-insider.de Jump to article: www.security-insider.de/rubrik-dienst-fuer-ki-gestuetztes-red-teaming-von-kundencode-a-7d88338ea39c2cbd279084ff35c5018e/
-
KI-Agenten: Metas Muse legt Profile über Freunde und Familie an
Tags: aiMetas KI-Assistent Muse führt Seiten über Familie, Partner und Freunde. Forscher haben die Anweisungen dafür ausgelesen. First seen on golem.de Jump to article: www.golem.de/news/ki-agenten-metas-muse-legt-profile-ueber-freunde-und-familie-an-2610-213693.html
-
South Korea Orders Investigation Into AI-Powered Cyberattacks on Major Banks
South Korean President Lee Jae Myung has ordered a comprehensive investigation into a series of data breaches impacting major banks and other financial institutions. Concerns have been raised that attackers may have utilized AI-enabled offensive security tools. These incidents have prompted emergency regulatory action and a sector-wide effort to strengthen defenses against increasingly automated intrusions.…
-
Google PageBreak AI Agent Finds Over 500 XSS Vulnerabilities Across Its Web Applications
Google has disclosed that PageBreak, an internal AI security agent developed by its Product Security team, has identified and validated more than 500 cross-site scripting (XSS) vulnerabilities across the company’s first-party web applications, including sensitive domains. The initiative highlights a shift from AI-assisted vulnerability triage to agentic testing that produces exploit-backed findings rather than noisy…
-
Unsichtbare Zugänge, reales Risiko: So gelingt Governance für Maschinenidentitäten
Service Accounts, API-Schlüssel, Cloud-Workloads und KI-Agenten handeln längst in einer Größenordnung, die klassische IAM-Prozesse überfordert. Die Studie »2026 Identity Security Landscape« beschreibt eine Identitätswelt, in der Maschinen menschliche Nutzer zahlenmäßig weit übertreffen und fragmentierte Kontrollen die Reaktion auf Vorfälle verlangsamen. Der Praxisleitfaden zeigt, wie Unternehmen in 90 Tagen Transparenz schaffen, Verantwortlichkeiten festlegen, langlebige Secrets abbauen……
-
Google froze its open source bug bounty program due to a ‘significant rise’ in AI submissions
AI slop seems to be overwhelming bug bounty programs. First seen on techcrunch.com Jump to article: techcrunch.com/2026/10/04/google-froze-its-open-source-bug-bounty-program-due-to-a-significant-rise-in-ai-submissions/
-
SECURITY AFFAIRS AI-CYBERSECURITY NEWSLETTER ROUND 2
Security Affairs AI-CYBERSECURITY newsletter includes a collection of the best articles and research on AI in the international landscape Artificial intelligence is rapidly changing cybersecurity, reshaping both the techniques used by attackers and the tools available to defenders. AI agents can automate tasks, analyze large amounts of data, discover vulnerabilities and accelerate offensive operations. At…
-
Anthropic asks Claude users to share voice data for AI model training
Anthropic has started asking Claude users to voluntarily share their voice conversations to help train and improve its AI models. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/artificial-intelligence/anthropic-asks-claude-users-to-share-voice-data-for-ai-model-training/
-
David Robinson: Warum OpenAIs Sicherheitschef nun geht
Ein Ex-Mitarbeiter warnt: Bei OpenAI komme Sicherheit im Tempo neuer KI-Produkte oft zu kurz. First seen on golem.de Jump to article: www.golem.de/news/david-robinson-warum-openais-sicherheitschef-nun-geht-2610-213684.html
-
Security Affairs newsletter Round 598 by Pierluigi Paganini INTERNATIONAL EDITION
A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including international press. Fake Zoom installer hides macOS backdoor CloudSyncD CVE-2026-90970: Critical GitLab AI Gateway Flaw Fixed Antino Backdoor Lets…
-
China-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM Phishing
A new China-nexus cyber espionage group known as TA419 has been attributed to multiple credential phishing campaigns targeting artificial intelligence (AI) experts working for U.S. think tanks, universities, and legal sector organizations.The campaigns have impersonated prominent economists and AI policymakers, as well as a prominent Anthropic employee, to single out an AI policy expert at…
-
KI-Betrug setzt Banken unter Druck Verbraucher akzeptieren strengere Kontrollen
Management Summary Sicherheit schlägt Geschwindigkeit: 78 Prozent der Befragten akzeptieren langsamere Identitätsprüfungen, wenn diese das Betrugsrisiko deutlich reduzieren. Transparenz wird zum Erfolgsfaktor: 62 Prozent erwarten eine Erklärung für zusätzliche Sicherheitsmaßnahmen; in Deutschland sind es 71 Prozent. Junge Erwachsene stehen besonders im Fokus: 30 Prozent der 18- bis 24-Jährigen berichten von mutmaßlich KI-generierten Betrugsversuchen. Vertrauen und……
-
87 Prozent betroffen: Wenn KI-Agenten ihre Zugriffsgrenzen überschreiten
KI-Agenten erhalten Zugriff auf Daten, Anwendungen und Entwicklungsumgebungen doch vielerorts endet die Kontrolle nach der Anmeldung. Der Delinea-Report zeigt, wie weit Richtlinien und technische Durchsetzung auseinanderliegen. Für CIOs und CISOs folgt daraus eine klare Priorität: Berechtigungen müssen kurzlebig, kontextbezogen und bis zur einzelnen Aktion nachvollziehbar sein. Management Summary Governance-Lücke: Formale KI-Richtlinien sind nahezu flächendeckend… First…
-
OpenAI safety employee resigns, claiming the company’s ‘culture is broken’
By his own admission, David Robinson is “something of a cliché”: an employee at a leading AI company who issues a dire warning while resigning from their job. First seen on techcrunch.com Jump to article: techcrunch.com/2026/10/03/openai-safety-employee-resigns-claiming-the-companys-culture-is-broken/
-
Dutch Institute for Vulnerability Disclosure Breached via Zammad 0-Days
Dutch Institute for Vulnerability Disclosure was breached through two Zammad 0-days in an AI-powered attack that led to remote code execution and root access. First seen on hackread.com Jump to article: hackread.com/dutch-institute-vulnerability-disclosure-breach-zammad-0-days/
-
Muse Creates Detailed Profiles of All Your Friends and Family
Millions have downloaded Meta’s AI agent Muse. But getting it to do your bidding comes with privacy costs. First seen on wired.com Jump to article: www.wired.com/story/muse-creates-detailed-profiles-of-all-your-friends-and-family/

