Tag: ai
-
Neue Angriffsmethoden bedrohen Microsoft 365 & Azure-Umgebungen – Wie Angreifer KI nutzen, um Microsoft-365-Konten zu übernehmen
First seen on security-insider.de Jump to article: www.security-insider.de/ki-phishing-angriffe-microsoft-365-azure-a-84e7e0828a8405d2ae9874238a709957/
-
GlassWorm Malware Discovered in Three VS Code Extensions with Thousands of Installs
Cybersecurity researchers have disclosed a new set of three extensions associated with the GlassWorm campaign, indicating continued attempts on part of threat actors to target the Visual Studio Code (VS Code) ecosystem.The extensions in question, which are still available for download, are listed below -ai-driven-dev.ai-driven-dev (3,402 downloads)adhamu.history-in-sublime-merge (4,057 First seen on thehackernews.com Jump to article:…
-
GlassWorm Malware Discovered in Three VS Code Extensions with Thousands of Installs
Cybersecurity researchers have disclosed a new set of three extensions associated with the GlassWorm campaign, indicating continued attempts on part of threat actors to target the Visual Studio Code (VS Code) ecosystem.The extensions in question, which are still available for download, are listed below -ai-driven-dev.ai-driven-dev (3,402 downloads)adhamu.history-in-sublime-merge (4,057 First seen on thehackernews.com Jump to article:…
-
GlassWorm Malware Discovered in Three VS Code Extensions with Thousands of Installs
Cybersecurity researchers have disclosed a new set of three extensions associated with the GlassWorm campaign, indicating continued attempts on part of threat actors to target the Visual Studio Code (VS Code) ecosystem.The extensions in question, which are still available for download, are listed below -ai-driven-dev.ai-driven-dev (3,402 downloads)adhamu.history-in-sublime-merge (4,057 First seen on thehackernews.com Jump to article:…
-
GlassWorm Malware Discovered in Three VS Code Extensions with Thousands of Installs
Cybersecurity researchers have disclosed a new set of three extensions associated with the GlassWorm campaign, indicating continued attempts on part of threat actors to target the Visual Studio Code (VS Code) ecosystem.The extensions in question, which are still available for download, are listed below -ai-driven-dev.ai-driven-dev (3,402 downloads)adhamu.history-in-sublime-merge (4,057 First seen on thehackernews.com Jump to article:…
-
How to adopt AI security tools without losing control
In this Help Net Security video, Josh Harguess, CTO of Fire Mountain Labs, explains how to evaluate, deploy, and govern AI-driven security tools. He talks about the growing … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2025/11/10/ai-driven-security-tools-video/
-
New AI Vulnerability Scoring System Announced to Address Gaps in CVSS
A new vulnerability scoring system has just been announced. The initiative, called the AI Vulnerability Scoring System (AIVSS), aims to fill the gaps left by traditional models such as the Common Vulnerability Scoring System (CVSS), which were not designed to handle the complex, non-deterministic nature of m First seen on thecyberexpress.com Jump to article: thecyberexpress.com/owasp-ai-vulnerability-scoring-system-aivss/
-
New AI Vulnerability Scoring System Announced to Address Gaps in CVSS
A new vulnerability scoring system has just been announced. The initiative, called the AI Vulnerability Scoring System (AIVSS), aims to fill the gaps left by traditional models such as the Common Vulnerability Scoring System (CVSS), which were not designed to handle the complex, non-deterministic nature of m First seen on thecyberexpress.com Jump to article: thecyberexpress.com/owasp-ai-vulnerability-scoring-system-aivss/
-
How to adopt AI security tools without losing control
In this Help Net Security video, Josh Harguess, CTO of Fire Mountain Labs, explains how to evaluate, deploy, and govern AI-driven security tools. He talks about the growing … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2025/11/10/ai-driven-security-tools-video/
-
New AI Vulnerability Scoring System Announced to Address Gaps in CVSS
A new vulnerability scoring system has just been announced. The initiative, called the AI Vulnerability Scoring System (AIVSS), aims to fill the gaps left by traditional models such as the Common Vulnerability Scoring System (CVSS), which were not designed to handle the complex, non-deterministic nature of m First seen on thecyberexpress.com Jump to article: thecyberexpress.com/owasp-ai-vulnerability-scoring-system-aivss/
-
New Whisper-Based Attack Reveals User Prompts Hidden Inside Encrypted AI Traffic
Microsoft researchers have unveiled a sophisticated side-channel attack targeting remote language models that could allow adversaries to infer conversation topics from encrypted network traffic. Despite end-to-end encryption via Transport Layer Security (TLS), the attack exploits patterns in packet sizes and timing to classify the subject matter of user prompts sent to AI chatbots. The research…
-
How to adopt AI security tools without losing control
In this Help Net Security video, Josh Harguess, CTO of Fire Mountain Labs, explains how to evaluate, deploy, and govern AI-driven security tools. He talks about the growing … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2025/11/10/ai-driven-security-tools-video/
-
New Whisper-Based Attack Reveals User Prompts Hidden Inside Encrypted AI Traffic
Microsoft researchers have unveiled a sophisticated side-channel attack targeting remote language models that could allow adversaries to infer conversation topics from encrypted network traffic. Despite end-to-end encryption via Transport Layer Security (TLS), the attack exploits patterns in packet sizes and timing to classify the subject matter of user prompts sent to AI chatbots. The research…
-
AI is rewriting how software is built and secured
AI has become part of everyday software development, shaping how code is written and how fast products reach users. A new report from Cycode, The 2026 State of Product … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2025/11/10/ai-product-security-report/
-
AI is rewriting how software is built and secured
AI has become part of everyday software development, shaping how code is written and how fast products reach users. A new report from Cycode, The 2026 State of Product … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2025/11/10/ai-product-security-report/
-
KI-Irrsinn Teil 6: Autohändler gibt Kundendaten zum KI-Training an obskure Firma
Der größte Autohändler in den Benelux-Staaten sowie weitere Firmen sind vor einiger Zeit aufgeflogen, weil sie Kundendaten an eine obskure Analytics Firma weitergegeben haben. Dort wurden sie zum Trainieren von AI verwendet. Es ist ein Vorfall, der bereits im Sommer … First seen on borncity.com Jump to article: www.borncity.com/blog/2025/11/10/ki-irrsinn-teil-6-autohaendler-gibt-kundendaten-zum-ki-training-an-obskure-firma/
-
Policy Meets AI: Why Broken Rules Break Customer Service
AI can streamline how government serves residents, but automating bad processes only accelerates frustration. Here’s why fixing policies is the first step to successful AI in customer service. First seen on securityboulevard.com Jump to article: securityboulevard.com/2025/11/policy-meets-ai-why-broken-rules-break-customer-service/
-
Revolutionize Your B2B AI Company Launch
In this blog, we will discuss the top tools you need to revolutionize your B2B AI company launch and boost your chances of success. First seen on securityboulevard.com Jump to article: securityboulevard.com/2025/11/revolutionize-your-b2b-ai-company-launch/
-
AI chat privacy at risk: Microsoft details Whisper Leak side-channel attack
Microsoft uncovered Whisper Leak, a side-channel attack that lets network snoopers infer AI chat topics despite encryption, risking user privacy. Microsoft revealed a new side-channel attack called Whisper Leak, which lets attackers who can monitor network traffic infer what users discuss with remote language models, even when the data is encrypted. The company warned that…
-
Researchers want to kill the vibe, propose better model for AI coding
MIT researchers offer cure for illegible software First seen on theregister.com Jump to article: www.theregister.com/2025/11/07/researchers_detail_legible_software_model/
-
Microsoft findet Seitenkanalangriff Whisper-Leak in LLMs
Sicherheitsforscher haben eine neue Whisper-Leaks genannte Methode entdeckt, um einen Seitenkanalangriff auf die Kommunikation mit Sprachmodellen im Streaming-Modus durchzuführen. Durch geschicktes Ausnutzung von Netzwerkpaketgrößen und -timings könnten Informationen abgezogen werden. Mit der KI-Welle werden immer häufiger große Sprachmodelle (LLMs), KI-gestützte … First seen on borncity.com Jump to article: www.borncity.com/blog/2025/11/09/microsoft-findet-seitenkanalangriff-whisper-leak-in-llms/
-
KI und Automatisierung befeuern eine neue Welle zielgerichteter Cyberkriminalität
Zwischen Juli und September 2025 hat sich die weltweite Bedrohungslage im Cyberraum deutlich verschärft. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/ki-automatisierung-neue-cyberkriminalitaet
-
Warum beim Einsatz von KI-Agenten eine durchdachte Governance unerlässlich ist
In einem Wettbewerbsumfeld, in dem technologische Führung oft über Erfolg oder Rückstand entscheidet, kann eine robuste Governance den entscheidenden Unterschied machen. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/warum-beim-einsatz-von-ki-agenten-eine-durchdachte-governance-unerlaesslich-ist/a42654/
-
Einsatz von KI-Agenten: Lückenlose Governance für Unternehmen mittlerweile unerlässlich
First seen on datensicherheit.de Jump to article: www.datensicherheit.de/einsatz-ki-agenten-lueckenlos-governance-unternehmen-unerlaesslich
-
AI benchmarks are a bad joke and LLM makers are the ones laughing
Study finds many tests don’t measure the right things First seen on theregister.com Jump to article: www.theregister.com/2025/11/07/measuring_ai_models_hampered_by/
-
Your Security Team Is About to Get an AI Co-Pilot, Whether You’re Ready or Not: Report
The days of human analysts manually sorting through endless security alerts are numbered. By 2028, artificial intelligence (AI) agents will handle 80% of that work in most security operations centers worldwide, according to a new IDC report. But while AI promises to revolutionize defense, it’s also supercharging the attackers. IDC predicts that by 2027, 80%..…
-
Radware: Bad Actors Spoofing AI Agents to Bypass Malicious Bot Defenses
AI agents are increasingly being used to search the web, making traditional bot mitigation systems inadequate and opening the door for malicious actors to develop and deploy bots that impersonate legitimate agents from AI vendors to launch account takeover and financial fraud attacks. First seen on securityboulevard.com Jump to article: securityboulevard.com/2025/11/radware-bad-actors-spoofing-ai-agents-to-bypass-malicious-bot-defenses/
-
Microsoft Uncovers ‘Whisper Leak’ Attack That Identifies AI Chat Topics in Encrypted Traffic
Microsoft has disclosed details of a novel side-channel attack targeting remote language models that could enable a passive adversary with capabilities to observe network traffic to glean details about model”¯conversation”¯topics despite encryption protections under certain circumstances.This leakage of data exchanged between humans and”¯streaming-mode language models could pose serious risks to First seen on thehackernews.com Jump…
-
ChatGPT und Google-Suche: Private KI-Prompts in Google Search Console gefunden
Der Verdacht, dass OpenAI die Google-Suche für ChatGPT-Anfragen verwendet, wird durch diese Erkenntnisse erhärtet. First seen on golem.de Jump to article: www.golem.de/news/chatgpt-und-google-suche-private-ki-prompts-in-google-search-console-gefunden-2511-201985.html

