Tag: ai
-
Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign
A malware operator left its delivery server wide open, and Rapid7 pulled down the whole toolkit: 1,048 files spanning lure templates, filename-spoofing tests, execution experiments, droppers, builder notes, and two campaign chains. One was already live against Windows users in Mexico, delivering an infostealer through a fake government ID-lookup site over WebDAV.What makes it more…
-
Hugging Face Discloses Autonomous AI Agent Attack
Hugging Face disclosed an autonomous AI agent attack that breached its production infrastructure. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/hugging-face-discloses-autonomous-ai-agent-attack/
-
Banks and Telecoms Are Struggling to Share Scam Data
Canadian Cyber Exchange’s Jennifer Quaid on Privacy Hurdles, Real-Time Fraud Intel. Banks, telecoms and tech platforms all want to share scam data faster, but privacy rules and regulatory limits are standing in the way, said Jennifer Quaid at the Canadian Cyber Threat Exchange. AI-driven fraud could make matters even worse in the next 12 to…
-
KnowBe4 erhält internationale Auszeichnungen für KI, Innovation und Security Content
Die Bandbreite der Auszeichnungen reicht damit von KI und E-Mail-Security über Security Awareness bis hin zu Unternehmenskultur und Diversität. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/knowbe4-erhaelt-internationale-auszeichnungen-fuer-ki-innovation-und-security-content/a45810/
-
Why blocking AI models won’t stop the cyber threats they create
AI companies can find vulnerabilities and write patches. But only the government can build the long-term defense strategy America needs. First seen on cyberscoop.com Jump to article: cyberscoop.com/why-blocking-ai-models-wont-stop-cyber-threats-op-ed/
-
ServiceNow pre-auth RCE exploited in the wild (CVE-2026-6875)
Tags: ai, authentication, cve, exploit, intelligence, rce, remote-code-execution, threat, vulnerabilityAttackers have begun exploiting CVE-2026-6875, a critical pre-authentication vulnerability in the ServiceNow AI Platform, according to threat intelligence firm Defused. About … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/20/servicenow-cve-2026-6875-exploited/
-
An AI SOC Evaluation Guide for Security Leaders
Choosing an AI SOC platform requires understanding how it will perform in your own environment, not just during an evaluation. Prophet Security shares a practical framework for assessing AI SOC solutions, including how to validate accuracy, operating models, long-term reliability, and production readiness. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/an-ai-soc-evaluation-guide-for-security-leaders/
-
JadePuffer Returns With Ransomware Designed to Wipe AI Models
JadePuffer follow-up campaign deployed ENCFORGE locker built to destroy AI model artifacts First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/jadepuffer-ai-model-ransomware/
-
OpenAI Warns GPT-5.6 File Deletions Stem From Full-Access Mode
Persistent AI Coding Model Prompted Safeguard Changes After Rare File Loss. OpenAI is tightening safeguards after some GPT-5.6 users reported that Codex accidentally deleted local files while operating in full-access mode. The company said the incidents were rare but acknowledged the model’s persistence led it to take unintended actions without seeking user confirmation. First seen…
-
What Does the Cyber Industry Want to See From the New UK Government?
Today (20 July 2026), Andy Burnham became Prime Minister of the UK, succeeding Sir Keir Starmer. While there is not yet a detailed ‘Burnham tech strategy’, pre-transition briefings and reports over recent weeks suggest a strong focus on AI, including plans for a dedicated AI Minister, the scrapping of the hotly debated digital ID programme,…
-
Salt Security tackles AI governance challenge with 100 pre-built agentic security policies
Salt Security has expanded its Policy Hub to include 100 pre-built security policies, as organisations look for practical ways to govern AI agents across enterprise environments. The company says the milestone creates one of the industry’s largest libraries of governance policies for agentic AI, covering APIs, Model Context Protocol (MCP) servers, authentication, access controls, compliance…
-
New Continuous Runtime Security Validation service aims to strengthen fintech cyber resilience
Fintech organisations across the UK and Ireland can now access a new service designed to provide ongoing assurance over production security following a strategic partnership between Critical Cloud and Tarian Labs. The Continuous Runtime Security Validation offering helps businesses continuously verify that their security controls remain effective as cloud environments, applications and AI capabilities evolve.…
-
Hugging Face warns an autonomous AI agent hacked its network
The Hugging Face artificial intelligence repository disclosed that attackers gained access to internal datasets and credentials after breaching its production infrastructure using an autonomous AI agent system. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/hugging-face-breach-autonomous-ai-agent-system-internal-datasets-credentials/
-
âš¡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More
Tags: ai, attack, breach, data-breach, malware, rce, remote-code-execution, service, wordpress, zero-dayA single request should not be able to do this much. But this week, small inputs led to code execution, memory loss, stolen keys, and disabled security tools.The paths were often simple: exposed systems, weak checks, old drivers, fake prompts, and public code used for malware delivery. Some bugs were new. Others were already being…
-
The Hidden Risk in Enterprise AI Agents: Ungoverned Context
Enterprises are handing AI agents real access to customer records, financial systems, internal documents, and the tools that… First seen on hackread.com Jump to article: hackread.com/hidden-risk-enterprise-ai-agents-ungoverned-context/
-
Hugging Face discloses breach linked to autonomous AI agent
The Hugging Face artificial intelligence repository disclosed that attackers gained access to internal datasets and credentials after breaching its production infrastructure using an autonomous AI agent system. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/hugging-face-breach-autonomous-ai-agent-system-internal-datasets-credentials/
-
Mythos Didn’t Break Your Security Program. Your Exposure Window Could.
The industry spent the initial months after Anthropic’s April 7 Mythos reveal focused on volume. How many new CVEs would Mythos add to an already overloaded pipeline? How quickly would the flood of AI-driven discovery overwhelm triage capabilities? How long would it take adversaries to weaponize Mythos findings at scale? Those questions were and remain…
-
Hugging Face breached by autonomous AI agent
Hugging Face, the widely used platform for sharing open-source machine learning models and datasets, has disclosed a security breach it says was carried out by an autonomous … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/20/hugging-face-breached-by-autonomous-ai-agent/
-
Cyberangriff auf Hugging Face: KI-Angriff auf KI-Plattform mittels KI aufgedeckt
Hugging Face hat einen von KI-Agenten ausgeführten Cyberangriff per KI entdeckt. Der Zugriff gelang durch Sicherheitslücken in der KI-Plattform. First seen on golem.de Jump to article: www.golem.de/news/cyberangriff-auf-hugging-face-ki-erkennt-ki-angriff-auf-ki-plattform-2607-211057.html
-
The ACLU Is Arming Lawyers to Expose State Surveillance Secrets
Tags: aiA new toolkit for attorneys in Massachusetts targets the technologies police use”, and conceal”, to build criminal cases, from facial recognition to AI-written police reports. First seen on wired.com Jump to article: www.wired.com/story/the-aclu-is-arming-lawyers-to-expose-state-surveillance-secrets/
-
Russian-Speaking Hacker Uses Google Gemini CLI to Control Botnet of Eight Dental Clinic PCs
A solo Russian-speaking threat actor known as “bandcampro” outsourced a chunk of their operations to Google’s open-source Gemini CLI artificial intelligence (AI) and commandeered a live botnet.The findings come from an analysis of 200 Gemini CLI session logs between March 19 and April 21, 2026, which found the threat actor using AI, among other things,…
-
Cyberangriff auf Hugging Face: KI erkennt KI-Angriff auf KI-Plattform
Hugging Face hat einen von KI-Agenten ausgeführten Cyberangriff per KI entdeckt. Der Zugriff gelang durch Sicherheitslücken in der KI-Plattform. First seen on golem.de Jump to article: www.golem.de/news/cyberangriff-auf-hugging-face-ki-erkennt-ki-angriff-auf-ki-plattform-2607-211057.html
-
How agentic endpoint security shuts down IDE-based supply chain attacks
Attention shifts from EDR to Agentic Endpoint Security to close visibility gaps that AI can exploit. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/spons/how-agentic-endpoint-security-shuts-down-ide-based-supply-chain-attacks/825550/
-
The secret problem in AI infrastructure: Why MCP security starts with secrets
AI changes how infrastructure is accessed. Here’s what to secure. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/spons/the-secret-problem-in-ai-infrastructure-why-mcp-security-starts-with-secre/825210/
-
Critical ServiceNow code execution flaw now exploited in attacks
Attackers have begun exploiting a critical vulnerability (CVE-2026-6875) in the ServiceNow AI Platform, according to threat intelligence company Defused. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/critical-servicenow-code-execution-flaw-now-exploited-in-attacks/
-
AI Agents Turned Into Attackers: Hugging Face Reveals Autonomous Intrusion Campaign
Hugging Face says an autonomous AI agent breached part of its production infrastructure and accessed internal data and service credentials. Hugging Face is one of the world’s leading open-source AI companies. It provides a platform where developers and organizations can build, share, and deploy machine learning and generative AI models. Hugging Face disclosed that an…
-
KI-Betrug im Sommer erkennen: Vier Tipps von Experten
Management Summary KI-gestützte Betrugsversuche werden durch täuschend echte Stimmen, Videos und Gesprächsskripte immer schwerer erkennbar. Der Beitrag zeigt vier unmittelbar anwendbare Prüfmethoden: spontane Folgefragen stellen, die reale Umgebung im Video einbeziehen, Augen- und Lippenbewegungen kontrollieren sowie mit Ironie oder unerwartetem Humor testen, ob das Gegenüber den Kontext versteht. Für potenzielle Opfer lautet die zentrale… First…
-
Singapore spells out how personal data can be used in GenAI
New advisory guidelines clarifying when organisations can scrape and reuse personal data to build GenAI models are among a raft of announcements at the inaugural Singapore Data Festival First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366645910/Singapore-spells-out-how-personal-data-can-be-used-in-GenAI
-
Wenn KI Stimmen imitiert – Fraunhofer entwickelt personenzentrierte Deepfake-Erkennung
First seen on security-insider.de Jump to article: www.security-insider.de/padse-audio-deepfakes-stimmprofile-erkennen-a-d61680b8b2fbc9653c42d963bfbc549f/

