Tag: ai
-
Balancing AI Innovation with GDPR and EU AI Act Guardrails in Europe
Enterprise adoption of agentic AI is moving at breakneck speed, but governance is struggling to keep pace. Gartner projects that AI regulatory violations will drive a spike in tech-related litigation within the next few years. Yet, only 23% of GRC… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/balancing-ai-innovation-with-gdpr-and-eu-ai-act-guardrails-in-europe/
-
Papercut AI Swarm Attack Heralds Changes for Cyber Kill Chain
From creating lab environments for staging and testing agentic attacks to reconnaissance to lateral movement and exfiltration, the most innovative attackers are widely incorporating AI. First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/papercut-ai-swarm-attack-cyber-kill-chain
-
Claude Used to Automate Exploitation and Data Theft Across Multiple Victims
Anthropic has warned that cybercriminals and state-sponsored hackers alike are using its Claude models for cyber attacks, weapons design, propaganda, and mass surveillance between December 2025 and August 2026.The threat actors, which the artificial intelligence (AI) company has branded Generative Threat Groups (GTGs), span state-sponsored groups, financially motivated criminals, commercial First seen on thehackernews.com Jump…
-
Russian State-Sponsored Hackers Use Claude to Rebuild Malware After Detection
Anthropic on Thursday revealed it disrupted a campaign mounted by a Russian state-sponsored threat actor that abused Claude for developing an AI-assisted workflow to get ahead of the detection curve.The operation has been attributed to a cyber espionage group it calls GTG-20006 (where “GTG” stands for Generative Threat Group), which aligns with broader reporting linking…
-
Your Newest Privileged Identity Is An AI Agent
Agentic AI turns software into an actor with credentials, tools and reach. Security programs built around human and service-account assumptions need a new identity model. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/your-newest-privileged-identity-is-an-ai-agent/
-
Accountability, oversight and AI: Inside Microsoft’s security transformation
Stung by years of embarrassing hacks, the tech giant overhauled how it approached cybersecurity. Company leaders now say they’re seeing results. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/microsoft-cybersecurity-culture-accountability-software-development/830048/
-
EU Gets Access to Anthropic Cyber AI, But Not Its Newest Model
ENISA has gained access to Anthropic’s Mythos 5, giving EU officials a chance to independently test the cyber AI after months of negotiations. The post EU Gets Access to Anthropic Cyber AI, But Not Its Newest Model appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-enisa-anthropic-mythos-5-cyber-ai-access-europe-emea/
-
The Next Agentic Security Failure May Begin With Permission
The Hugging Face incident did not show an AI escaping from nowhere. It showed how a permitted route, loosely separated authority and reachable infrastructure can turn goal-seeking software into an intrusion path. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/the-next-agentic-security-failure-may-begin-with-permission/
-
The Next Agentic Security Failure May Begin With Permission
The Hugging Face incident did not show an AI escaping from nowhere. It showed how a permitted route, loosely separated authority and reachable infrastructure can turn goal-seeking software into an intrusion path. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/the-next-agentic-security-failure-may-begin-with-permission/
-
The SOC was Never Designed to See Everything
I recently had the chance to moderate an online discussion between two experienced CISOs and a Founder about what is the reality that Security Leaders see when it comes to AI in the SOC.The conversation between Petri Kuivala (former CISO… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/the-soc-was-never-designed-to-see-everything/
-
How Threat Actors Are Turning Trusted AI Platforms Into an Attack Surface
Threat actors are abusing trusted AI platforms to host malicious content, poison search results, and trick users into installing malware. Huntress examines campaigns targeting AI users through weaponized Claude Artifacts, shared AI conversations, sponsored search results, and ClickFix-style lures. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/how-threat-actors-are-turning-trusted-ai-platforms-into-an-attack-surface/
-
Wenn KI ihre Grenzen überschreitet Kontrollverlust beginnt bei Berechtigungen und Zugriffen
KI-Forscher warnen aktuell vor den möglichen Gefahren unkontrollierter KI und einem langfristigen Kontrollverlust. Während die Debatte über existenzielle Risiken an Fahrt aufnimmt, stellen sich für Unternehmen bereits heute konkrete Sicherheitsfragen: Was passiert, wenn KI-Systeme ihre vorgesehenen Berechtigungen überschreiten, auf sensible Daten zugreifen oder außerhalb bestehender Kontrollmechanismen agieren? Laura Ellis, SVP of Artificial Intelligence bei […]…
-
How Do You Test an AI Product When the Same Input Can Produce Different Answers?
Traditional software testing starts with a comforting assumption: Input A should produce Output B. If the output changes unexpectedly, something is probably broken. AI products destroy that assumption. Ask the same large language model the same question twice and you… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/how-do-you-test-an-ai-product-when-the-same-input-can-produce-different-answers/
-
Anthropic caught Russia-linked spies using Claude in hacking operations
Anthropic detected and disrupted a Russia-linked cyber-espionage group that used its AI tool Claude in a hacking campaign targeting more than 20 government, intelligence, diplomatic and defense organizations. First seen on therecord.media Jump to article: therecord.media/anthropic-russia-hackers-claude
-
The Cyber Express Weekly Roundup: Iranian Bounty, Airline Data Leak, and AI-Model Prompt Injection
This weekly roundup covers a bounty offer targeting an alleged Iranian cyber official, a massive data-exposure incident affecting airline travelers, a breach of an education platform used by students, a flaw exposing ChatGPT users’ Gmail data, and a new EU compliance deadline for connected-product manufacturers. First seen on thecyberexpress.com Jump to article: thecyberexpress.com/weekly-roundup-iran-bounty-airline-leak/
-
Check Point wurde im Gartner-Magic-Quadrant 2026 für Hybrid-Mesh-Firewalls als Leader ausgezeichnet
Check Point Software Technologies wurde im Gartner-Magic-Quadrant 2026 für Hybrid-Mesh-Firewalls als ‘Leader” ausgezeichnet. Diese Anerkennung erfolgt vor dem Hintergrund, dass Check Point seine Strategie für hybride Mesh-Netzwerksicherheit kontinuierlich weiterentwickelt. Zuletzt wurde die <> vorgestellt, die Unternehmen dabei unterstützt, den Einsatz von KI sicher zu gestalten. Mit dieser Innovation ist Check Point das erste […] First seen on…
-
KI-Zugänge werden zur Ware: Wie gestohlene Session-Tokens einen Schwarzmarkt für Frontier-Modelle antreiben
Gestohlene Session-Tokens und missbrauchte KI-Credits treiben einen Schwarzmarkt für KI-Zugänge an. Okta zeigt neue Risiken für Identity Security und MFA. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/ki-zugaenge-werden-zur-ware-wie-gestohlene-session-tokens-einen-schwarzmarkt-fuer-frontier-modelle-antreiben/a46386/
-
Veeam-Studie zeigt Shadow Agents werden zum Governance-Risiko Workflows
Veeam warnt vor Shadow Agents: 81 Prozent deutscher Führungskräfte melden unkontrollierte KI-Workflows mit sensiblen Daten und wachsende Governance-Risiken. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/veeam-studie-zeigt-shadow-agents-werden-zum-governance-risiko-unternehmen-kaempfen-mit-kontrolle-ueber-ki-workflows/a46383/
-
Sicher in die Zukunft – Moderne KI-Infrastruktur braucht Post-Quanten-Kryptographie als Fundament
First seen on security-insider.de Jump to article: www.security-insider.de/moderne-ki-infrastruktur-braucht-post-quanten-kryptographie-als-fundament-a-12d555b1efe6b24a922572ea6c9cd3a9/
-
Siri Recap und Live Rewind: Lauschangriff durch die Apple Watch
Die neuen Apple Watches kommen mit automatischer KI-Transkription von Gesprächen in der Umgebung. Apple trifft Vorkehrungen, um die Belauschten schützen – aber reicht das? First seen on golem.de Jump to article: www.golem.de/news/siri-recap-und-live-rewind-lauschangriff-durch-die-apple-watch-2609-212916.html
-
AWS AI Symposium: Public sector must shape AI, use open source
As frontier models outpace cyber defences, two public sector voices set out different answers to the same security question transparency and procurement leverage First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366650031/AWS-AI-symposium-Public-sector-must-shape-AI-use-open-source
-
AI agents exploited PaperCut flaws to breach 395 organizations
A threat actor built a working exploit for PaperCut print management software, then handed the job of breaking into hundreds of organizations to AI agents that did most of the … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/11/ai-agents-papercut-ng-mf-attack-campaign/
-
Hackers Weaponize AI Safety Guardrails to Hide Malware From LLM-Powered Security Scanners
Threat actors are adapting malware not only for conventional endpoint defenses and sandboxes, but also for large language model-powered tools increasingly used to triage suspicious code. ESET researchers linked the activity to Russia-aligned threat actor UAC-0099, which used the method during an attack against an organization in Ukraine. The group inserted a safety-sensitive, weapon-related request…
-
Sicher in die Zukunft – Moderne KI-Infrastruktur braucht Post-Quanten-Kryptographie als Fundament
First seen on security-insider.de Jump to article: www.security-insider.de/moderne-ki-infrastruktur-braucht-post-quanten-kryptographie-als-fundament-a-12d555b1efe6b24a922572ea6c9cd3a9/
-
Most Organizations Skip Permissions Reviews Before Deploying AI Tools
A new Syskit study has shown that only 43% of organizations with AI agents deployed in Microsoft 365 environments completed a permission review before doing so First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/organizations-skip-permissions-ai/
-
Enisa: Anthropic öffnet Mythos-Modell für EU-Cyberagentur
Tags: aiNach monatelangen Verhandlungen gibt Anthropic der EU-Agentur Enisa Zugang zu seinem KI-Modell Mythos. Doch die neueste Version gibt es nicht. First seen on golem.de Jump to article: www.golem.de/news/enisa-anthropic-oeffnet-mythos-modell-fuer-eu-cyberagentur-2609-212904.html
-
Hackers Use AI-Assisted CEO Emails to Trick Finance Teams Into Sending $50,000 Payments.
Threat actors are using AI-assisted phishing templates, executive impersonation, fake ServiceNow invoices, and fabricated email threads to pressure finance teams into authorizing fraudulent ACH payments worth nearly $50,000. Microsoft detected more than one million messages in the campaign, demonstrating how business email compromise (BEC) operations are becoming more polished, scalable, and difficult to spot. The…
-
Hackers Use AI-Assisted CEO Emails to Trick Finance Teams Into Sending $50,000 Payments.
Threat actors are using AI-assisted phishing templates, executive impersonation, fake ServiceNow invoices, and fabricated email threads to pressure finance teams into authorizing fraudulent ACH payments worth nearly $50,000. Microsoft detected more than one million messages in the campaign, demonstrating how business email compromise (BEC) operations are becoming more polished, scalable, and difficult to spot. The…
-
Institut für die Sicherheit von Künstlicher Intelligenz – Deutsches KI-Sicherheitsinstitut startet in Berlin
Tags: aiFirst seen on security-insider.de Jump to article: www.security-insider.de/deutsches-ki-sicherheitsinstitut-startet-in-berlin-a-ff9cc7e5e7ebdfcd3f6fdadb3d4f4e6e/

