Tag: ai
-
ISMG Editors: Oops! AI Just Escaped the Sandbox
Also: Lessons From Scattered Spider Sentencing, Controlling Enterprise AI Costs. In this week’s panel, four ISMG editors discussed the implications of OpenAI’s sandbox escape and Hugging Face hack, the sentencing of two Scattered Spider members and what it means for the future of cybercrime, and the growing debate over the cost of enterprise AI. First…
-
Tego AI Discloses Second Claude Flaw in a Week: Hidden Link Silently Sends Files to Attackers
Tel Aviv, Israel, July 24th, 2026, CyberNewswire One week after disclosing that Anthropic’s Claude Tag Slack integration could be driven by plain >>@Claude<< text, Tego AI today published a second piece of research on the Claude ecosystem. This one focuses on Claude Code, Anthropic's agentic command-line coding tool. Cloning an ordinary repository and starting Claude…
-
OpenAI Hugging Face Hack Shows Autonomous Threats Are ‘No Longer Theoretical’: Accenture Exec
An autonomously executed hack carried out by rogue OpenAI frontier models is underscoring the potential risk from deploying AI without appropriate security and governance, executives at two top solution providers told CRN. First seen on crn.com Jump to article: www.crn.com/news/security/2026/openai-hugging-face-hack-shows-autonomous-threats-are-no-longer-theoretical-accenture-exec
-
Microsoft, tech companies throw weight behind spread of open-source AI
Other signatories of the letter include Meta, Palantir, Perplexity, Mistral, NVIDIA, Mozilla, The Linux Foundation, Hugging Face, Dell Technologies and IBM. First seen on cyberscoop.com Jump to article: cyberscoop.com/tech-leaders-open-source-ai-cybersecurity/
-
Slopsquatting, Phantom Domains, and HalluSquatting Are the Same AI Attack
Slopsquatting, phantom squatting, and HalluSquatting all exploit the same late-binding attack pattern, where AI coding agents trust hallucinated package, repo, or domain names. ActiveState explains how pre-fetch verification and governed dependency management can help stop these attacks before malicious code enters the pipeline. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/slopsquatting-phantom-domains-and-hallusquatting-are-the-same-ai-attack/
-
MCTTP 2026 – Wo Angriffe auf Agentic-AI wirklich stattfinden
First seen on security-insider.de Jump to article: www.security-insider.de/mcttp-2026-fuenf-zonen-modell-ki-agenten-rag-mcp-tools-a-805b088390515448f0b6f164e059f7f7/
-
The most vulnerable AI products are also some of the most commonly exposed online
It is becoming increasingly easy for hackers to target vulnerable AI tools on companies’ networks, even as those companies come to depend on them for more tasks. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/industrial-control-systems-ai-internet-exposure-censys-report-preview/826133/
-
KI-Trojaner Dolphin X nimmt wertvolle IT-Ziele automatisiert ins Visier
Die Schadsoftware Dolphin X nutzt einen KI-Profiler zur automatischen Bewertung infizierter Systeme. Das Tool filtert besonders wertvolle Ziele heraus. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/ki-trojaner-dolphin-x
-
Meta tackles AI-generated accounts with a free Facebook verification badge
Meta has introduced Facebook Verified, a free badge meant to show that a person behind a profile has completed identity verification through a selfie check. (Source: Meta) The … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/24/meta-facebook-verified-badge-selfie-verification/
-
KnowBe4’s Unveils Custom AI Video Builder
KnowBe4, the global leader in digital workforce security, securing both AI agents and humans, today announced the launch of Custom AI Video Builder, a new capability that lets security admins create custom, AI-generated training videos and deploy them directly into their security awareness training (SAT) programs in minutes. The innovation is the latest addition to…
-
ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link
Cybersecurity researchers have disclosed a critical vulnerability in OpenAI’s ChatGPT Workspace Agents that could have allowed a single phishing link to stealthily build, authorize, and deploy an autonomous artificial intelligence (AI) agent inside a victim’s organization.The vulnerability has been codenamed AgentForger by Zenity Labs. The issue has since been addressed by OpenAI as of June…
-
Warum wir künstliche Intelligenz erst schützen und dann schätzen sollten
Tags: aiKI hat verändert, wie wir Code schreiben, Bedrohungen analysieren und Aufgaben erledigen und das schneller, als es noch vor wenigen Jahren jemand für möglich gehalten hätte. Zum AI-Appreciation-Day am 16. Juli rief dessen Initiator dazu auf, künstliche Intelligenz ‘menschlich zu behandeln, durchdacht zu entwickeln und bewusst zu würdigen>>. Doch im Kern ist KI eine […]…
-
Thailand’s Ministry of Finance Targeted With Hermes AI Agent Running Unattended, Hades Implant Staged
Hunt.io uncovered a cyber-espionage attack on Thailand’s Finance Ministry using Hermes AI agent and Hades malware for reconnaissance and persistence. Researchers at Hunt.io have uncovered an intrusion targeting Thailand’s Ministry of Finance that offers a rare look inside a live cyber-espionage operation. Instead of recovering malware after the fact, the team found exposed staging servers…
-
Github reagiert auf KI-Flut: Hohe Bug-Bounty-Prämien bald nur noch für VIPs
Github überarbeitet sein Bug-Bounty-Programm. Wer sich nur auf KI verlässt und sich wenig Mühe gibt, bekommt künftig geringere Prämien. First seen on golem.de Jump to article: www.golem.de/news/github-reagiert-auf-ki-flut-hohe-bug-bounty-praemien-bald-nur-noch-fuer-profis-2607-211255.html
-
Tego AI Discloses Second Claude Flaw in a Week: Hidden Link Silently Sends Files to Attackers
Tel Aviv, Israel, 24th July 2026, CyberNewswire First seen on hackread.com Jump to article: hackread.com/tego-ai-discloses-second-claude-flaw-in-a-week-hidden-link-silently-sends-files-to-attackers/
-
Seeing AI Agents Is Not Enough. Security Teams Must Enforce What They Can Do
AI agent security is moving through a familiar maturity curve: adoption, then visibility, and finally, control. But what we’ve collectively discovered is that enforcing least privilege for AI agents is harder than we ever imagined. This is why there are so many approaches, from prompt filtering to identity-layer access controls. Where we’ve collectively landed is…
-
Github reagiert auf KI-Flut: Hohe Bug-Bounty-Prämien bald nur noch für Profis
Github überarbeitet sein Bug-Bounty-Programm. Wer sich nur auf KI verlässt und sich wenig Mühe gibt, bekommt künftig geringere Prämien. First seen on golem.de Jump to article: www.golem.de/news/github-reagiert-auf-ki-flut-hohe-bug-bounty-praemien-bald-nur-noch-fuer-profis-2607-211255.html
-
New Dolphin X Malware Uses AI Profiler to Rank High-Value Victims
Dolphin X malware targets more than 300 apps and includes an AI Profiler that scores infected Windows PCs to help criminals identify high-value victims quickly. First seen on hackread.com Jump to article: hackread.com/dolphin-x-malware-ai-profiler-rank-victims/
-
Hacker Runs Hermes AI Agent Unattended for Post-Exploitation at Thai Finance Ministry
Someone installed a popular AI assistant on a rented server, switched off the setting that makes it ask permission before running risky commands, and pointed it at Thailand’s Ministry of Finance, which runs the country’s treasury and tax collection.The agent then worked through the ministry’s network on its own, checking hosts for ways to gain…
-
Die neue Risiken durch agentische KI im Fokus – Warum LLM-Observability zum Sicherheitsfaktor für KI-Systeme wird
First seen on security-insider.de Jump to article: www.security-insider.de/warum-llm-observability-zum-sicherheitsfaktor-fuer-ki-systeme-wird-a-bd9def5d1852e535db0558409c91e25f/
-
Why embodied AI security extends beyond the robot
As AI moves into robots, autonomous vehicles and industrial systems, attackers are likely to target the credentials, cloud services and update channels that control them First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366646180/Why-embodied-AI-security-extends-beyond-the-robot
-
Google gives developers an AI bug hunter that also writes patches
Google has launched a preview of CodeMender, an AI agent built to scan code for security flaws, confirm they are exploitable, and generate fixes for developers to review. … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/24/google-codemender-ai-agent-code-security/
-
The AI Trust Paradox: Businesses Are Racing Ahead, but Consumers Are Hesitating
Artificial intelligence adoption is soaring, but consumer trust lags. Transparency, human oversight, and clear AI use cases are key to closing the trust gap. Businesses are rapidly adopting AI, with 93% planning deployment, but consumer trust lags far behind: only 23% trust companies to use AI with their data, revealing a major “AI trust gap.”…
-
Russian APT Laundry Bear perfects zero-click phishing attack
A newly identified Russian state threat actor is using a novel zero-click phishing technique, likely developed with the help of an AI, to target Western users of Zimbra software products First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366645968/Russian-APT-Laundry-Bear-perfects-zero-click-phishing-attack
-
NodeBB Patches Eight AI-Found Flaws Exposing Admin Access and Private Chats
Eight security flaws in NodeBB went public on Wednesday, along with the code to exploit them. Aikido Security rates all eight as high severity and says its AI pentest agents found them in a six-hour review of the forum software’s source code.Every version before 4.14.0 is affected. NodeBB has fixed them all, and administrators should…
-
Neue Okta for AI Agents-Funktionen steuern Zugriffe und Verbindungen von KI-Agenten
Zugriffszertifizierungen für KI-Agenten tragen durch automatisierte Zugriffsprüfungen dazu bei, dass jede Agentenverbindung im Laufe der Zeit angemessen dimensioniert bleibt. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/neue-okta-for-ai-agents-funktionen-steuern-zugriffe-und-verbindungen-von-ki-agenten/a45865/
-
Europe’s Multilingual Reality Exposes AI Security Gaps
Tags: aiThe AI security layer and guardrails for many AI products don’t evenly protect against jailbreaking and unsafe actions in every single language. First seen on darkreading.com Jump to article: www.darkreading.com/cybersecurity-operations/europes-multilingual-reality-exposes-ai-security-gaps
-
Governing Al agents at scale: Lessons from the leaders who’ve done it
Tags: aiEnterprise AI leaders from ZoomInfo, Docusign and AppViewX share what it took to build AI Centers of Excellence and govern agent identities inside two companies operating at … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/24/governing-al-agents-at-scale-video/
-
Claude Cowork Sandbox Escape Flaw Lets Attackers Access SSH Keys and Cloud Credentials
A newly revealed sandbox escape vulnerability affecting Anthropic’s Claude Cowork could allow untrusted content processed by the AI agent to access sensitive files on a macOS host. This includes SSH private keys, cloud credentials, and other data that are available to the logged-in user. Security researcher Oren Yomtov from Accomplish has named this attack path…
-
KI macht Ransomware-Angriffe gefährlicher
Künstliche Intelligenz verändert die Vorgehensweise von Cyberkriminellen und erhöht die Erfolgsquote von Ransomware-Angriffen deutlich. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/ki-ransomware-angriffe-gefaehrlicher

