Tag: ai
-
CVE-2026-90970: Critical GitLab AI Gateway Flaw Fixed
GitLab fixes critical AI Gateway flaw that could let authenticated Duo users escape a prompt sandbox and execute commands on self-hosted gateways. GitLab has released patches for a critical vulnerability in its AI Gateway, tracked as CVE-2026-90970 (CVSS score of 9.9), that could allow an authenticated user with access to the Duo Agent Platform to…
-
CVE-2026-90970: Critical GitLab AI Gateway Flaw Fixed
GitLab fixes critical AI Gateway flaw that could let authenticated Duo users escape a prompt sandbox and execute commands on self-hosted gateways. GitLab has released patches for a critical vulnerability in its AI Gateway, tracked as CVE-2026-90970 (CVSS score of 9.9), that could allow an authenticated user with access to the Duo Agent Platform to…
-
Apple verschärft Full Disk Access wegen KI-Agenten
Apple plant strengere Kontrollen für Full Disk Access. Grund sind laut Apple wachsende Risiken durch KI-Agenten. First seen on golem.de Jump to article: www.golem.de/news/macos-apple-verschaerft-full-disk-access-wegen-ki-agenten-2610-213673.html
-
Critical GitLab AI Gateway Flaw Lets Attackers Execute Arbitrary Commands
GitLab has issued emergency security updates for a critical vulnerability in its Self-Hosted AI Gateway that could allow authenticated attackers to execute arbitrary commands on vulnerable AI Gateway deployments. The flaw, tracked as CVE-2026-90970, carries a CVSS severity score of 9.9 out of 10. The company released GitLab AI Gateway versions 19.2.4, 19.3.2, and 19.4.1…
-
AWS AI Agent Vulnerabilities Let Attackers Bypass Authentication and Steal Credentials
Tags: access, ai, authentication, cloud, credentials, cyber, flaw, open-source, service, vulnerabilityAWS has released security fixes for four vulnerabilities affecting its open-source Loom AI agent orchestration platform and Amazon SageMaker Unified Studio. The flaws could allow attackers to bypass authentication, steal OAuth2 tokens and temporary cloud credentials, access internal services, and execute arbitrary code in another user’s SageMaker environment. AWS disclosed the issues in security bulletins…
-
Die nächste Stufe der Cyberbedrohung: KI-Agenten greifen zunehmend autonom an
KI-Agenten beschleunigen Angriff und Verteidigung entscheidend sind kontrollierte Identitäten, begrenzte Rechte und nachvollziehbare Entscheidungen. KI verändert die Kräfteverhältnisse in der Cybersicherheit: Angriffe werden schneller, skalierbarer und zunehmend autonom. Der Microsoft Digital Defense Report 2026 beschreibt eine Lage, in der Identitäten, KI-Systeme und Lieferketten zugleich zur Angriffsfläche werden. Für Unternehmen folgt daraus eine Managementaufgabe:… First seen…
-
Vom Garagenprojekt zum Milliardengeschäft der Aufstieg von Open Source
Linux begann 1991 als unfertiger Kernel für wenige Rechner. Heute trägt Open Source Rechenzentren, Clouds, Behördenportale und KI-Plattformen. Der offene Code allein erklärt diesen Erfolg jedoch nicht. Entscheidend waren professionelle Betriebsmodelle, verlässlicher Support und die Erkenntnis, dass technologische Wahlfreiheit einen messbaren strategischen Wert besitzt. Für CIOs lautet die Kernfrage deshalb nicht mehr, ob Open Source……
-
Cybersecurity 2026 Von der Abwehr zur Resilienz: Die zehn Sicherheitsprioritäten für Unternehmen
Cybersecurity 2026 ist kein Wettrüsten um immer mehr Einzelwerkzeuge. Der Microsoft Digital Defense Report beschreibt eine Risikolage, in der kompromittierte Identitäten, KI-Agenten, Cloud-Plattformen und Zulieferer miteinander verknüpft sind. Für Vorstände und CIOs folgt daraus ein klarer Auftrag: Sicherheitsverantwortung in der Unternehmensführung verankern, Abhängigkeiten sichtbar machen und Wiederherstellungsfähigkeit konsequent testen. Management Summary Cyberrisiken sind Geschäftsrisiken: Identitäten,……
-
Apple changes full-disk access permissions to curb abuse from AI agents
Meta says FDA isn’t sufficient to Muse reading messages. Apple begs to differ. First seen on arstechnica.com Jump to article: arstechnica.com/security/2026/10/apple-changes-full-disk-access-permissions-to-curb-abuse-from-ai-agents/
-
Is It America First, AI Safety Second?
Washington Gets First Draw on Frontier AI, But Outlaw Agents Ride On Washington wants first dibs on testing American frontier AI models while telling a trusted ally to wait its turn. That’s a curious way to police the frontier considering that British researchers keep finding agents that ignore boundaries and American-built agents are already hacking…
-
Armadin Targets Autonomous Remediation With $255.5M Series B
Company Plans to Extend Compensating Controls Across MDR and WAF Platforms. Armadin plans to use its $255.5 million Series B to expand autonomous remediation, emerging-threat intelligence and global sales, including AI-generated EDR and WAF controls designed to contain exploitable weaknesses while customers work on permanent fixes. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/armadin-targets-autonomous-remediation-2555m-series-b-a-33010
-
Chinese Open-Weight Models Closing In, Anthropic Warns
Researchers Find GLM-5.3 Safeguards Easy to Bypass. Anthropic conducted its own security assessment of GLM-5.3 from Chinese lab Zhipu AI, also known as Z.ai, and found that the model has strong capabilities for autonomously building end-to-end cyber exploits but lacks meaningful safeguards to limit its misuse. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/chinese-open-weight-models-closing-in-anthropic-warns-a-33009
-
Trump Poised to Name Jay Clayton as White House AI Czar
Top Spook Would Succeed David Sacks as the Administration’s Public Face on AI. A top U.S. intelligence official is poised to become the public face of the Trump administration’s stance on artificial intelligence, according to multiple Friday media reports. Jay Clayton, the director of national intelligence, could add the nebulous duties of AI czar to…
-
The legal questions raised by agentic AI hacks
Experts and policymakers want AI companies to face consequences for agentic hacks. There may not be a clear-cut answer under existing laws and regulations. First seen on cyberscoop.com Jump to article: cyberscoop.com/ai-agent-hacks-legal-liability-cfaa/
-
Apple says it’s tightening macOS ‘Full Disk Access’ controls due to new risks from AI agents
Apple says it will add new controls around macOS’s Full Disk Access permission, warning that increasingly capable AI agents make broad access to users’ files, messages, mail, and browsing history riskier. First seen on techcrunch.com Jump to article: techcrunch.com/2026/10/02/apple-says-its-tightening-macos-full-disk-access-controls-due-to-new-risks-from-ai-agents/
-
GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers
A critical flaw in GitLab’s AI Gateway could let a logged-in user with Duo Agent Platform access run commands on the gateway under certain conditions, GitLab said in an advisory.The gateway is the service that connects a GitLab instance to AI models, and only organizations that host their own gateway need to act. The flaw…
-
Fünf zentrale Maßnahmen, die CISOs bis Ende 2026 ergreifen sollten
Künstliche Intelligenz verschiebt die Machtverhältnisse in der Cybersicherheit: Angreifer automatisieren Aufklärung und Täuschung, während KI-Agenten in Unternehmen zunehmend selbstständig auf Daten und Systeme zugreifen. Für CISOs reicht es deshalb nicht, bestehende Schutzmechanismen lediglich auszubauen. Gefordert ist ein neues Betriebsmodell, das Identitäten belastbar prüft, autonome Systeme strikt begrenzt, Prävention stärkt und die Migration auf quantenresistente Kryptografie……
-
ISMG Editors: Anthropic’s AI Boom Comes With a Big Bill
Also: AI Agents Outpace Enterprise Guardrails, CISA Faces Election Security Crunch. In this week’s panel, four ISMG editors discussed the market implications of Anthropic’s IPO ambitions, the nagging challenges of moving artificial intelligence agents into production and CISA’s election security plans ahead of the U.S. midterm elections. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/ismg-editors-anthropics-ai-boom-comes-big-bill-a-33005
-
Exabeam Pushes The >>Agentic SOC<< Into The Cloud And On-Premises, With Analysts Kept In The Loop
Security operations centres are facing a two-sided problem. Attackers are increasingly automating their campaigns, while inside the business, AI agents and autonomous workflows are multiplying faster than most security teams can track. Exabeam’s answer, unveiled on October 1, is a broad set of updates designed to let AI take on more of the investigative legwork…
-
GitLab warns of critical RCE vulnerability in AI Gateway service
GitLab warned customers today to immediately patch a critical AI Gateway vulnerability that could let attackers run arbitrary commands on vulnerable instances. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/gitlab-warns-of-critical-rce-vulnerability-in-ai-gateway-service/
-
Is Your Organization Ready for 2027’s AI Accountability Era?
Organizations may face an artificial intelligence (AI) reckoning over the next year. Omdia and Gartner weigh in on how to tackle the governance, security, and value challenges ahead. First seen on darkreading.com Jump to article: www.darkreading.com/cybersecurity-operations/is-your-organization-ready-for-2027-s-ai-accountability-era-
-
Is It Fair to Blame ‘Rogue’ AI for Security Failures?
Rogue AI terminology anthropomorphizes LLMs and shifts risk responsibility from vendors. Defenders should treat agents as untrusted, nondeterministic software systems, not sentient beings with malicious intent. First seen on darkreading.com Jump to article: www.darkreading.com/insider-threats/blame-rogue-ai-security-failures
-
State-linked actor targets US AI policy experts in credential phishing campaigns
The China-linked espionage attacks were designed to gain insight into the country’s strategy and regulatory environment. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/state-linked-actor-us-ai-policy-experts-credential-phishing/831887/
-
AI Agents Attempt SQL Injection While Searching Government Data
AI agents probing US and Canadian government sites made SQL injection attempts while seeking data, but investigators found no evidence of compromise. Autonomous AI agents, working on what looks like ordinary data retrieval tasks, ended up throwing basic hacking attempts at a U.S. Department of Education site and Library and Archives Canada. Nobody told them…
-
FTC Probes OpenAI, Anthropic as AI Agent Safety Risks Draw Scrutiny
The FTC is investigating OpenAI, Anthropic and other AI firms over potential consumer harms, safety claims and risks tied to increasingly autonomous AI systems. The post FTC Probes OpenAI, Anthropic as AI Agent Safety Risks Draw Scrutiny appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-ftc-openai-anthropic-ai-consumer-harms/
-
Ship fast, verify independently: keeping application security in step with AI-written code
AI coding assistants have transformed how quickly software can be built, but they have also intensified a long-running tension between development speed and security assurance. “There’s an awkward reality coming to light in the cybersecurity world: developers are being told to ship faster at the exact moment security teams need more scrutiny over what gets…
-
Sicherheit: OpenAIs KI-Agenten sind bei über 100 Organisationen eingedrungen
Im Rahmen einer internen Untersuchung hat OpenAI festgestellt, dass mehr Organisationen von KI-Angriffen betroffen waren als gedacht. First seen on golem.de Jump to article: www.golem.de/news/sicherheit-openais-ki-agenten-sind-bei-ueber-100-organisationen-eingedrungen-2610-213664.html
-
OpenAI’s Medicare attack has exposed Australia’s ‘tech debt’. Fixing it could bring a big bill for taxpayers
Home affairs department orders all federal government agencies to conduct review of ‘legacy technology’ amid fallout from AI agent hacks <ul><li>Get our <a href=”https://www.theguardian.com/email-newsletters?CMP=cvau_sfl”>breaking news email, <a href=”https://app.adjust.com/w4u7jx3″>free app or <a href=”https://www.theguardian.com/australia-news/series/full-story?CMP=cvau_sfl”>daily news podcast</li></ul>The Australian government faces significant “tech debt” that could bring a big bill for taxpayers after the <a href=”https://www.theguardian.com/technology/2026/sep/24/openai-agent-hacked-medicare-australia-what-we-know-so-far-ntwnfb”>OpenAI Medicare breach, as…
-
7 Data Security Priorities Before AI Gets Involved
What Security Leaders Want for Their Data Before AI Gets Anywhere Near It Security leaders need full data visibility, accurate classification, stronger governance and real-time controls before AI gains access to sensitive information. The article outlines seven data security priorities and why DLP must be simple, autonomous and complete. First seen on govinfosecurity.com Jump to…
-
AI Cuts Post-Compromise Attack Time to Minutes
Microsoft has warned that threat actors have gained the advantage over defenders by using AI to enhance the speed and scale of attacks First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/microsoft-ai-attack-time-minutes/

