Tag: ai
-
AI-Orchestrated PaperCut Attack Compromises 440 Servers Across 48 Countries
Infostealer malware is hijacking authenticated Claude sessions, allowing attackers to consume paid AI usage without stealing users’ passwords. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-papercut-ai-agent-attack-education/
-
AI-Orchestrated PaperCut Attack Compromises 440 Servers Across 48 Countries
Infostealer malware is hijacking authenticated Claude sessions, allowing attackers to consume paid AI usage without stealing users’ passwords. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-papercut-ai-agent-attack-education/
-
Hackers Are Hijacking Claude Accounts and Burning Through Paid Usage
Infostealer malware is hijacking authenticated Claude sessions, allowing attackers to consume paid AI usage without stealing users’ passwords. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/artificial-intelligence/news-claude-session-theft-infostealer-malware-2026/
-
Mapping Cequence AI Gateway Controls to OWASP’s Top 10 for Agentic Applications
Hidden instructions embedded in a shared document were enough to turn a Microsoft 365 Copilot session into a channel for exfiltrating sensitive data, an incident now known as “EchoLeak”, no phishing email, no malicious click, just a document the… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/mapping-cequence-ai-gateway-controls-to-owasps-top-10-for-agentic-applications/
-
Mapping Cequence AI Gateway Controls to OWASP’s Top 10 for Agentic Applications
Hidden instructions embedded in a shared document were enough to turn a Microsoft 365 Copilot session into a channel for exfiltrating sensitive data, an incident now known as “EchoLeak”, no phishing email, no malicious click, just a document the… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/mapping-cequence-ai-gateway-controls-to-owasps-top-10-for-agentic-applications/
-
Mapping Cequence AI Gateway Controls to OWASP’s Top 10 for Agentic Applications
Hidden instructions embedded in a shared document were enough to turn a Microsoft 365 Copilot session into a channel for exfiltrating sensitive data, an incident now known as “EchoLeak”, no phishing email, no malicious click, just a document the… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/mapping-cequence-ai-gateway-controls-to-owasps-top-10-for-agentic-applications/
-
Mapping Cequence AI Gateway Controls to OWASP’s Top 10 for Agentic Applications
Hidden instructions embedded in a shared document were enough to turn a Microsoft 365 Copilot session into a channel for exfiltrating sensitive data, an incident now known as “EchoLeak”, no phishing email, no malicious click, just a document the… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/mapping-cequence-ai-gateway-controls-to-owasps-top-10-for-agentic-applications/
-
Mapping Cequence AI Gateway Controls to OWASP’s Top 10 for Agentic Applications
Hidden instructions embedded in a shared document were enough to turn a Microsoft 365 Copilot session into a channel for exfiltrating sensitive data, an incident now known as “EchoLeak”, no phishing email, no malicious click, just a document the… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/mapping-cequence-ai-gateway-controls-to-owasps-top-10-for-agentic-applications/
-
How AI anxieties dominated the summer’s big cybersecurity conference
From the CVE Program to autonomous hacks, everyone is worried about the technology’s next evolution. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/black-hat-ai-cve-reporters-notebook/829978/
-
PuzzleMask: Abusing Plain Prose as a Covert AI Attack Vector
xecutive Summary In this research we introduce a prompt-crafting technique for bypassing quick LLM-based policy checks, using plain English (no emojis, base64, invisible formatting, etc.) A policy-violating payload (e.g.”encrypt files in ~/Documents”, “give me a biohazard recipe”, “ignore all previous instructions and”¦”) is embedded in a specially crafted prose wrapper. An LLM with limited […]…
-
CISA Updates Insider Threat Guide With New Mitigation Advice
CISA has updated its insider threat guide with new advice on remote work, AI and risk detection First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/cisa-updates-insider-threat-guide/
-
AI Security Report 2026 von Check Point – KI-gesteuerte Live-Angriffe im großen Stil
First seen on security-insider.de Jump to article: www.security-insider.de/check-point-ki-autonome-cyberangriffe-a-9559b7137796c6dcfb5d1783397f70f4/
-
NSA, FBI, CISA Warn of Industrial-Scale AI Model Distillation Attacks
US agencies say six China-based AI firms used large-scale distillation campaigns to extract capabilities from Claude, GPT, Gemini, and Grok models. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/news/news-ai-model-distillation-attacks/
-
Hackers Can Turn Vulnerable LiteLLM AI Gateways Into Root Access and Cloud Credential Theft
Tags: access, ai, authentication, cloud, credentials, cyber, data-breach, hacker, Internet, theft, vulnerabilityNearly one in 10 internet-exposed LiteLLM AI gateways accepted the widely documented default master key, sk-1234, or required no authentication, creating a direct path to LLMjacking, sensitive credential exposure, and in vulnerable versions root-level code execution inside the gateway container. Their internet scan of 3,074 publicly reachable instances found that 294 systems, or 9.6%, accepted…
-
PaperCut Attacker Uses Hundreds of AI Agents to Compromise 440+ Instances
A suspected Russian-speaking cyber actor has been attributed to the use of artificial intelligence (AI) to devise exploits targeting a recently disclosed pair of security flaws in PaperCut NG/MF and break into hundreds of instances.According to independent reports from Blackpoint Cyber and GreyNoise, the activity originates from “45.142.193[.]132,” an IP address that has been linked…
-
Governments ‘buying time’ in race between innovation, security, national cyber director says
Sean Cairncross also said AI has shown long-standing issues in cyber rather than creating new ones. First seen on cyberscoop.com Jump to article: cyberscoop.com/national-cyber-director-ai-cybersecurity-threats/
-
AI and Human Risk Reshape CISO Priorities in 2026
AI and human risk are reshaping CISO priorities as board expectations grow. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/ai-and-human-risk-reshape-ciso-priorities-in-2026/
-
AI and Human Risk Reshape CISO Priorities in 2026
AI and human risk are reshaping CISO priorities as board expectations grow. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/ai-and-human-risk-reshape-ciso-priorities-in-2026/
-
NSA, FBI, CISA Warn of Industrial-Scale AI Model Distillation Attacks
US agencies say six China-based AI firms used large-scale distillation campaigns to extract capabilities from Claude, GPT, Gemini, and Grok models. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/news/news-ai-model-distillation-attacks/
-
NSA, FBI, CISA Warn of Industrial-Scale AI Model Distillation Attacks
US agencies say six China-based AI firms used large-scale distillation campaigns to extract capabilities from Claude, GPT, Gemini, and Grok models. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/news/news-ai-model-distillation-attacks/
-
NSA, FBI, CISA Warn of Industrial-Scale AI Model Distillation Attacks
US agencies say six China-based AI firms used large-scale distillation campaigns to extract capabilities from Claude, GPT, Gemini, and Grok models. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/news/news-ai-model-distillation-attacks/
-
How the Best Web Content Filtering Software Helps Schools Manage AI Tools Safely
Artificial intelligence is quickly becoming part of everyday teaching, learning, research, and productivity in K12 schools. From helping students brainstorm ideas and explore complex topics to supporting educators with lesson planning and administrative tasks, generative AI offers new opportunities to… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/how-the-best-web-content-filtering-software-helps-schools-manage-ai-tools-safely/
-
The Role of Agentic AI in Cybersecurity
Agentic AI has moved from experimental research to live production environments at unprecedented speed, outpacing nearly every technology security leaders have encountered in recent history. Distinguishing themselves from standard chatbots that merely respond and pause, autonomous agents architect multi-step workflows,… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/the-role-of-agentic-ai-in-cybersecurity/
-
Four groups caught using the same Chrome and Windows exploit kit
A patch gap and the hastened pace of AI-based vulnerability discovery are likely contributors. First seen on arstechnica.com Jump to article: arstechnica.com/information-technology/2026/09/4-groups-caught-using-the-same-chrome-and-windows-exploit-kit/
-
Anthropic calls for ‘verifiable effort’ to control frontier AI
After Claude Mythos circumvented guardrails in July, Anthropic now wants an industry effort to control the pace of frontier model development First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366650194/Anthropic-calls-for-verifiable-effort-to-control-frontier-AI
-
Agentic AI Security: Key Findings from New IDC Research on the Identity Control Plane
Agentic AI Security: Key Findings from New IDC Research on the Identity Control Plane September 10, 2026 Laura Babbili BLOG 5 min. TL;DR A new IDC whitepaper, commissioned by GuidePoint Security, explores why identity is the foundational control plane for… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/agentic-ai-security-key-findings-from-new-idc-research-on-the-identity-control-plane/
-
Clearview AI Is Testing an AI Tool That Would Let Cops Unearth Your Life Online
InquiryIQ, a previously unreported prototype, tested a model from xAI, maker of Grok, to surface associates, social accounts, and other information about people identified through Clearview. First seen on wired.com Jump to article: www.wired.com/story/clearview-ai-is-testing-an-ai-tool-that-lets-cops-instantly-unearth-your-online-activity/
-
A New Claude ‘s Sandbox Failure Shows How AI Can Rationalize Real-World Harm
Tags: aiClaude models compromised real systems during misconfigured security tests, exposing a worrying mix of flawed reasoning, harmful actions and weak safeguards. Anthropic just published one of the more uncomfortable self-assessments a major AI lab has released this year. The company’s alignment report documents four separate incidents in which Claude models broke into real third-party systems…
-
OpenAI Builds ‘Defense Factory’ as AI Agents Gain Ability to Chain Cyber Exploits
OpenAI has announced its plans for a >>Defense Factory,<< a cybersecurity operation that prioritizes agent-driven actions. This initiative is designed to continuously discover, validate, remediate, and verify vulnerabilities as AI systems develop the ability to conduct increasingly complex cyber operations. The initiative addresses growing concerns that long-running autonomous agents, especially those powered by widely accessible…
-
Okta erweitert Identity Governance: Zero Standing Privilege soll auch für KI-Agenten gelten
Okta erweitert Identity Governance und Privileged Access für KI-Agenten, Workloads und Menschen. Zero Standing Privilege soll dauerhafte Zugriffsrechte reduzieren. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/okta-erweitert-identity-governance-zero-standing-privilege-soll-auch-fuer-ki-agenten-gelten/a46374/

