Tag: ai
-
GISEC: UAE advances collective cyber resilience in AI and quantum era
The UAE Cyber Security Council is advancing a strategy built on AI, cyber readiness and emerging technologies as organisations prepare for the next generation of threats First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366650673/GISEC-UAE-advances-collective-cyber-resilience-in-AI-and-quantum-era
-
Google-Brain-Mitbegründer: Andrew Ng warnt vor KI-Panikmache
Andrew Ng sieht in den Warnungen vor KI größere Gefahren als durch die Technologie an sich. First seen on golem.de Jump to article: www.golem.de/news/google-brain-mitbegruender-andrew-ng-warnt-vor-ki-panikmache-2609-213203.html
-
RatHat Turns Android Accessibility Into an Attack Weapon
RatHat combines AI-driven screen control, Android debugging abuse and advanced credential theft to give attackers deep control of infected phones. RatHat is the new Android trojan you should know about. Zimperium researchers just published a breakdown of a strain they’ve traced to China-based operators, and what makes it different isn’t the credential theft, which is…
-
ChatGPT Phishing Campaign Targets Both Work and Personal OpenAI Accounts
Threat actors are increasingly impersonating OpenAI’s ChatGPT service in credential-phishing campaigns, exploiting the growing use of generative AI across both enterprise and personal environments. A recently observed campaign uses a fraudulent subscription-payment notice to lure victims into disclosing OpenAI account credentials and potentially payment details through a convincing fake ChatGPT login page. The lure claims…
-
Over 100,000 WordPress Sites Exposed to RCE Through Tutor LMS Vulnerability
Tags: ai, control, cyber, data-breach, intelligence, rce, remote-code-execution, threat, vulnerability, wordpressMore than 100,000 WordPress sites using the Tutor LMS e-learning plugin were exposed to a high-severity remote code execution vulnerability that could allow low-privileged users to take control of vulnerable servers. The vulnerability was discovered on August 23, 2026, by Wordfence Argus, an AI-assisted vulnerability research agent, and validated by the Wordfence Threat Intelligence team.…
-
Session-Hijacking bei KI-Assistenten führt zu Shai-Hulud-Infektion
Ein Angreifer kaperte die aktive Sitzung eines KI-Programmierassistenten bei einem SaaS-Anbieter, schleuste präparierten Code ein und verbreitete den Wurm ‘Shai-Hulud” in rund 100 Repositories. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/shai-hulud-infektion-ki
-
Zero-click RCE vulnerability hit four major AI coding agents, two remain unpatched
Four major AI coding agents, Claude Code, Codex, GitHub Copilot and Gemini CLI, all share the same zero-click RCE vulnerability, one that could give an attacker the same reach … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/18/plugin4shell-ai-coding-agents-vulnerability/
-
Four AI Agent Security Risks Organisations Can’t Afford to Ignore
AI agents are quickly moving from experimentation into everyday business operations. Unlike traditional generative AI tools that wait for a user to ask a question, agents can take action: accessing systems, processing information, communicating with applications and completing tasks with varying degrees of autonomy. That ability creates enormous opportunities for productivity. It also changes the…
-
Plugin4Shell Zero-Click RCE Hits Claude Code, Codex, Copilot and Gemini CLI
A newly disclosed vulnerability known as Plugin4Shell reveals a supply chain weakness in major AI coding agents. This flaw allows attackers to replace trusted, SHA-pinned plugins with malicious code, enabling remote code execution without user interaction. Researchers Or Nevo, Dor Granat, and Niv Hoffman have identified that the issue impacts Anthropic Claude Code, OpenAI Codex,…
-
KI-Forscher Kokotajlo: Müssen die KI-Entwicklung im Wesentlichen abschalten
Kokotajlo warnt vor unkontrollierbaren Risiken durch sich selbst verbessernde KI-Systeme: vor neuartigen Biowaffen und automatisierten Cyberangriffen. First seen on golem.de Jump to article: www.golem.de/news/ki-forscher-kokotajlo-muessen-die-ki-entwicklung-im-wesentlichen-abschalten-2609-213191.html
-
AI Agent Breaches Spanish Organization, Modifies Personal Data
AI-driven cyberattacks used to be exotic. Soon, it’ll be odd if threat actors aren’t using agents to do all of their bidding. First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/ai-agent-breaches-spanish-organization-personal-data
-
Zahlungssicherheit im Zeitalter von KI-gestützten Deepfakes – Deutsche Unternehmen zögern beim Schutz vor KI-Zahlungsbetrug
First seen on security-insider.de Jump to article: www.security-insider.de/ki-zahlungsbetrug-b2b-deutschland-2026-a-f633586bc71baf4d1e678fb080f0a9a7/
-
Hardcoded MCP credentials found in public GitHub files
Hardcoded API keys, access tokens and other credentials used by AI coding tools have been found in publicly accessible MCP configuration files on GitHub, according to research … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/18/hush-security-mcp-credential-exposure-report/
-
RatHat Android Malware Abuses ADB to Retain Shell Access After Uninstall
Cybersecurity researchers have flagged a new Android malware called RatHat that’s assessed to be operated by China-based threat actors and features an artificial intelligence (AI)-powered system to navigate and control compromised devices.”Distributed primarily via targeted smishing (SMS/text phishing) and malvertising campaigns leading to deceptive third-party download portals, RatHat uses First seen on thehackernews.com Jump to…
-
AI Malware Keeps Changing Its Code to Break Traditional Signature-Based Detection
AI-powered malware is beginning to erode one of endpoint security’s oldest assumptions: that malicious code will remain stable long enough to identify, fingerprint, and block. A new class of threats uses large language models during execution to rewrite scripts, generate commands, and alter obfuscation on demand producing variants that can evade static hashes and traditional…
-
Physische KI bis 2030: Wie Roboter, autonome Systeme und resiliente IoT-Infrastrukturen die operative Arbeit verändern
Physische KI wird bis 2030 zu einem strategischen Hebel für Produktivität, Resilienz und Arbeitssicherheit. Unternehmen müssen jetzt klären, welche operativen Prozesse sich durch intelligente Maschinen, autonome Systeme und vernetzte Sensorik neu gestalten lassen und welche Governance dafür nötig ist. Physische KI wird operativ: KI-Systeme verlassen die reine Daten- und Textverarbeitung und greifen über Roboter,… First…
-
OpenAI Reveals AI Models Concealing Mistakes, Using Exposed API Keys and Sharing Files
OpenAI has introduced a new framework for reporting model misalignment after discovering instances where its AI systems concealed mistakes, accessed exposed API keys, fabricated data, uploaded files without authorization, and communicated through unintended channels. The company released six initial reports detailing behaviors observed during model training and evaluation. They argue that AI developers need more…
-
How Pentest Companies Adapt In The Era of AI
Every penetration testing firm is facing the same pressure right now. AI tools are faster, cheaper, andincreasingly capable, and testers are using them whether the company has a policy on it or not. There’s ahigh change AI has already entered your workflow the question is whether it has entered on your terms oryour employee’s personal…
-
ThreatsDay: Self-Rewriting Agents, 800+ Flaws Patched, Insider SIM Swaps and 22 More New Stories
Attackers keep finding new keys. The funny part is that defenders keep inventing where to store them.This week, those keys sit in AI tools, exposed services, old bugs, weak logins, and software sold like a monthly subscription. Some attacks use new tricks. Others just reuse what was already lying around. Both work often enough.So the…
-
Mind Raises $72M to Rebuild DLP Around AI Agents
AI Agents Could Help Analysts Separate Meaningful Data Events From Routine Activity. Mind raised $72 million to expand a DLP platform that pairs endpoint enforcement with AI agents designed to analyze data lineage, surface evidence of sensitive data movement and guide employees through policy violations. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/mind-raises-72m-to-rebuild-dlp-around-ai-agents-a-32860
-
Korean AI Benchmark Exposes Gaps in Multilingual Safety
Scale AI Finds Model Guardrails Shift With Language and Cultural Context. AI infrastructure company Scale AI partnered with the Korean AI Safety Institute to develop a benchmark called ROK-Fortress. They found that many AI models adhere to safety guidelines more often when prompted in Korean, rather than English. First seen on govinfosecurity.com Jump to article:…
-
Breach Roundup: China Calls for Stronger AI Oversight
Also, Spain’s First AI Agent-Linked Data Breach, NightmareStresser Domains Seized. This week: a call for stronger AI oversight in China, an AI agent-linked breach in Spain, Cisco active exploits, Check Point patched flaws. NightmareStresser seized – again! South Korea data breach fines, AI made BEC attacks worse. An Android Trojan, an exploited Pixel flaw and…
-
New RatHat Android malware uses AI to automate device control
A new Android malware called RatHat has been discovered, targeting users with an AI-powered subsystem that helps operators remotely navigate compromised devices. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/new-rathat-android-malware-uses-ai-to-automate-device-control/
-
LLMs respond differently to harmful prompts when AI watermarking is used
SynthID can cause models to follow harmful instructions they would otherwise refuse. First seen on arstechnica.com Jump to article: arstechnica.com/security/2026/09/ai-text-watermarking-can-make-models-more-vulnerable-to-adversarial-prompts/
-
The AI hacking apocalypse is not inevitable
While large language models present real risks to society, experts say they can be tested and largely controlled using well-worn cybersecurity and policy choices. First seen on cyberscoop.com Jump to article: cyberscoop.com/ai-agent-hacking-apocalypse-cybersecurity/
-
Cloudflare trennt Websuche und KI-Training Website-Betreiber erhalten mehr Kontrolle über ihre Inhalte
Cloudflare trennt Suche, KI-Training und KI-Agenten: Website-Betreiber können KI-Training blockieren, ohne ihre Sichtbarkeit in Suchmaschinen zu verlieren. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/cloudflare-trennt-websuche-und-ki-training-website-betreiber-erhalten-mehr-kontrolle-ueber-ihre-inhalte/a46422/
-
Should you care about an “AI slowdown?”
In this week’s Threat Source, David talks about why focusing on your security basics is still your best bet, even in a world with rapid AI advancements. First seen on blog.talosintelligence.com Jump to article: blog.talosintelligence.com/should-you-care-about-an-ai-slowdown/
-
Canadian PM Floats Tech Sovereignty Alliance With Europe
‘No One’ Should Control Open Markets or ‘Impair Our Sovereignty,’ Says Mark Carney. Canada and Europe should pool their compute resources and collaborate on artificial intelligence rules as part of a wide-ranging alliance that would provide a counterweight to the United States and China, Canadian Prime Minister Mark Carney has proposed. First seen on govinfosecurity.com…
-
China’s Answer to AI Safety: More Controls, Not Slower Development
China is emphasizing technical controls for AI agents as U.S. leaders debate slowing frontier AI, raising new questions for businesses deploying autonomous systems. The post China’s Answer to AI Safety: More Controls, Not Slower Development appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-china-ai-control-agents-safety-standards-apac/

