Tag: ai
-
Avalara-Studie zeigt: Governance hält mit dem Einsatz von KI-Agenten im Finanzwesen nicht Schritt
Besonders wertvoll: Eine prüfungssichere Dokumentation jeder KI-gesteuerten Aktion sowie die automatische Überwachung regulatorischer Veränderungen mit Aktualisierungen in Echtzeit. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/avalara-studie-zeigt-governance-haelt-mit-dem-einsatz-von-ki-agenten-im-finanzwesen-nicht-schritt/a45813/
-
Kanishka Narayan takes on AI sovereignty in Burnham cabinet
Tags: aiAI minister will attend cabinet meetings held by UK prime minister Andy Burnham, with focus on ownership of UK tech First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366646018/Kaniskha-Narayan-takes-on-AI-sovereignty-in-Burnham-cabinet
-
Hackers Exploit ServiceNow AI Platform Flaw to Gain Unauthenticated Remote Code Execution
Tags: advisory, ai, authentication, cve, cyber, exploit, flaw, hacker, remote-code-execution, threat, vulnerabilityThreat actors are actively exploiting CVE-2026-6875, a critical pre-authentication remote code execution vulnerability in the ServiceNow AI Platform. This vulnerability allows attackers to escape a restricted server-side script sandbox and execute code without valid credentials. Reports from Defused indicate observed exploitation activity targeting this flaw. Initially, ServiceNow’s advisory stated it was not aware of any…
-
JADEPUFFER Deploys ENCFORGE Ransomware Built to Destroy AI Models and Training Data
JADEPUFFER has escalated from automated database extortion to purpose-built AI model destruction, deploying a custom Go ransomware dubbed ENCFORGE to encrypt and effectively wipe high”‘value AI and ML artifacts across an entire stack. A missing”‘authentication bug in the /api/v1/validate/code endpoint that enables unauthenticated arbitrary Python execution on the host. That initial operation chained reconnaissance, credential…
-
95% of Security Teams Blindsided by Vulnerabilities Between Tests
The vast majority of enterprise security teams are being blindsided by vulnerabilities that scheduled testing never catches, according to new research from Synack, which describes itself as the provider of the first AI-powered continuous pentest for enterprises. The company’s new report, The State of Continuous Security Validation, surveyed enterprise security leaders and practitioners and found…
-
AWS wants GuardDuty to automate the first steps of threat investigations
Amazon GuardDuty investigation agent is now in public preview. The feature provides AI-powered investigations of GuardDuty findings, AWS accounts and AWS organizations, … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/21/amazon-guardduty-investigation-agent-on-demand/
-
25 Years After Code Red: What the Worm Era Can Teach Us About AI Security
Marc Maiffret reflects on Code Red’s legacy and the security lessons helping organizations navigate AI risk today. First seen on darkreading.com Jump to article: www.darkreading.com/vulnerabilities-threats/25-years-after-code-red-what-the-worm-era-can-teach-us-about-ai-security-2
-
AgentBaiting Uses Fake AI Skills and MCP Servers to Deliver SmartLoader and StealC Malware
AgentBaiting is the clearest sign yet that AI agents and their capability ecosystems have become a first”‘class malware delivery surface, with FakeGit’s 7,600″‘repo operation pushing SmartLoader and StealC directly into AI Skills and MCP workflows. By turning agent”‘readable READMEs, public AI registries, and GitHub trust signals into a weaponized “AI capability supply chain,” attackers now…
-
New ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attack
Researchers at Sysdig have linked a second attack on the same Langflow server to JADEPUFFER, the AI-agent-driven operator it first documented earlier this month.The same operator has now been spotted deploying ENCFORGE, a new compiled Go ransomware designed to encrypt model weights, vector indexes, training datasets, and other AI infrastructure files across the host filesystem.The…
-
Critical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code Execution
Threat actors are now exploiting a recently disclosed critical security flaw impacting ServiceNow AI Platform, according to Defused Cyber.In a post shared on X, the threat intelligence firm said it’s observing in-the-wild exploitation of CVE-2026-6875 (CVSS score: 9.5), a sandbox escape vulnerability that could allow an unauthenticated user to run arbitrary code.Patches for the flaw…
-
Attackers Exploit Critical ServiceNow RCE Flaw CVE-2026-6875
Attackers are exploiting critical ServiceNow flaw CVE-2026-6875, allowing unauthenticated remote code execution on self-hosted instances. Searchlight Cyber researchers disclosed a critical pre-authentication remote code execution vulnerability, tracked as CVE-2026-6875, in the ServiceNow AI Platform on July 14. The same day, ServiceNow released patches for self-hosted instances. Since July 17, attackers have started exploiting it in…
-
Bit2Watt Attack Turns AI Data Centers Into Cyber-Physical Threats to Local Power Grids
Bit2Watt is a newly disclosed cyber”‘physical attack class that weaponizes AI and GPU workloads in modern data centers to destabilize nearby power grids, turning compute infrastructure itself into a grid”‘scale threat surface. Measurements on NVIDIA accelerators show sub”‘millisecond power ramps where a single Volta V100 or RTX”‘series GPU swings from low-load phases to near”‘TDP draw,…
-
Autonomer KI-Agent hackt Hugging Face
Die Open-Source-Plattform Hugging Face wurde Opfer eines Angriffs durch einen autonomen KI-Agenten. Interne Datensätze und Zugangsdaten waren betroffen. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/hugging-face-von-ki-agent-gehackt
-
AI agents are still logging in as humans
Most large companies run more than one AI platform at the same time. Developers pull up coding assistants, marketing teams lean on writing tools, and analysts query enterprise … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/21/report-enterprise-ai-identity-risk/
-
AI-generated reports push GNOME to shorten its disclosure window
Volunteer maintainers of open source projects now receive a steady flow of security vulnerability reports produced with AI tools. Many arrive with no mention that a language … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/21/gnome-security-disclosure-update/
-
Hugging Face Says Autonomous AI Agent System Breached Production Infrastructure
An AI-led cyberattack breached limited Hugging Face datasets and service credentials, while public models, Spaces and published packages showed no signs of tampering. First seen on hackread.com Jump to article: hackread.com/hugging-face-ai-agent-breach-production-system/
-
Neo Launches With $100M to Guard Agentic Enterprise Software
Agentic Security Startup Identifies AI Capabilities Embedded Across Enterprise Apps. Neo emerged from stealth with $100 million in funding to help enterprises discover, analyze and govern AI-enabled software, arguing that agentic applications, plug-ins and AI skills have created a fast-growing security blind spot that traditional endpoint tools weren’t built to address. First seen on govinfosecurity.com…
-
Cursor, Codex, Gemini CLI, Antigravity hit by sandbox escapes
Researchers escaped the sandboxes in Cursor, Codex, Gemini CLI and Antigravity by having the AI agent write files that trusted host tools later run. Multiple CVEs, patches, and Google downgrading two Antigravity findings. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/cursor-codex-gemini-cli-antigravity-hit-by-sandbox-escapes/
-
JadePuffer agentic attacks now target AI model data with ransomware
The JadePuffer autonomous AI agent has upgraded with custom malware called EncForge that focuses on encrypting AI assets, such as training datasets, vector databases, and model checkpoints. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/jadepuffer-agentic-attacks-now-target-ai-model-data-with-ransomware/
-
KI-generierter Quellcode bei neuem Botnetz TuxBot v3 entdeckt
Sicherheitsforscher haben das IoT-Botnetz-Framework TuxBot v3 Evolution entdeckt. Es wurde nachweislich unter Einsatz von künstlicher Intelligenz entwickelt. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/ki-generierter-quellcode-botnetz
-
F5 CEO On Massive AI Security Opportunity: LLMs Are ‘A Vulnerable Technology Today’
F5 is doubling down on enabling solution and service providers to capitalize on surging AI adoption through the recent launch of its unified platform for discovering, testing and securing AI models, according to F5 CEO François Locoh-Donou. First seen on crn.com Jump to article: www.crn.com/news/security/2026/f5-ceo-on-massive-ai-security-opportunity-llms-are-a-vulnerable-technology-today
-
Hugging Face Says Autonomous AI Agents Breached Data, Credentials
Tags: access, ai, cloud, credentials, cyberattack, data, exploit, flaw, framework, infrastructure, vulnerabilityAttackers Exploited Dataset Processing Flaws to Access Internal Clusters. Hugging Face said an autonomous AI agent framework exploited dataset processing vulnerabilities to compromise internal infrastructure, harvest cloud credentials and move laterally across clusters, exposing both the rise of agentic cyberattacks and the limits of AI safety guardrails during incident response. First seen on govinfosecurity.com Jump…
-
US Cedes Its AI Governance Responsibilities to Others
While US Government Vacillates on AI Regs, China and Big Tech Are Stepping Up U.S. tech firms are once again at the forefront of innovation, with a handful of companies leading the rise of artificial intelligence. But now America appears to be ceding its leadership role in managing the risks of AI to Silicon Valley…
-
CISOs Feel the Heat Over AI Risk
Job pressures have increased as companies run headlong into AI adoption, causing 26% of top security executives to consider leaving their position. First seen on darkreading.com Jump to article: www.darkreading.com/cybersecurity-operations/cisos-feel-heat-ai-risk
-
FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware
Cybersecurity researchers have discovered nearly 7,600 malicious GitHub repositories, out of which more than 800 pose as artificial intelligence (AI) skills or Model Context Protocol (MCP) servers to deliver a malware family known as SmartLoader as part of an ongoing campaign codenamed FakeGit.”FakeGit uses copied projects, lookalike developer profiles, convincing READMEs, and malicious ZIP First…
-
10 Hot Security Products For MSPs In 2026
As the massive industry-wide push for AI security continues, many emerging vendors in the space are taking the strategy of working with solution and service provider partners from an early stage. First seen on crn.com Jump to article: www.crn.com/news/security/2026/10-hot-security-products-for-msps-in-2026
-
Director of Commerce AI standards office out after three months
The Center for AI Standards and Innovation has quietly become a key hub for the federal government to assess potential threats and harms that AI systems pose. First seen on cyberscoop.com Jump to article: cyberscoop.com/director-of-commerce-ai-standards-office-out-after-three-months/

