Tag: ai
-
New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens
A Go botnet called NadMesh turned up in early July hunting exposed AI services, and the operator’s own dashboard claims 3,811 unique AWS keys.A Shodan harvester keeps the scan queue stocked with ComfyUI, Ollama, n8n, Open WebUI, Langflow, and Gradio: the image generators, local model runners, and workflow builders that teams stand up fast and…
-
Continuous Red Teaming: Warum KI-Systeme permanent getestet werden müssen
Continuous Red Teaming: Einmalige Sicherheitstests reichen für KI nicht aus. NIST zeigt, warum Continuous Red Teaming und Runtime Protection zum neuen Standard werden. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/continuous-red-teaming-warum-ki-systeme-permanent-getestet-werden-muessen/a45790/
-
Zero-Days, AI Governance Gaps, and Global Cybercrime Define This Week’s Security Landscape in July 2026
Weekly summary of Cybersecurity Insider newsletters in July 2026. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/weekly-roundup/zero-days-ai-governance-gaps-and-global-cybercrime-define-this-weeks-security-landscape-in-july-2026/
-
Zero-Days, AI Governance Gaps, and Global Cybercrime Define This Week’s Security Landscape in July 2026
Weekly summary of Cybersecurity Insider newsletters in July 2026. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/weekly-roundup/zero-days-ai-governance-gaps-and-global-cybercrime-define-this-weeks-security-landscape-in-july-2026/
-
Cybersicherheit als KI-natives Verteidigungssystem
Sophos hat Sophos-Fusion vorgestellt das umfassendste KI-native Cybersicherheits-Verteidigungssystem der Branche. Es wurde entwickelt, um koordinierte Reaktionen auf Bedrohungen im KI-Zeitalter zu ermöglichen. Entwickelt für eine durch KI veränderte Bedrohungslandschaft vereint Sophos-Fusion Security-Operations, Endpunktschutz, Netzwerksicherheit, Identitäts-, E-Mail- und Cloud-Sicherheit in einem einzigen Verteidigungssystem, das Bedrohungen mit KI-Geschwindigkeit verhindert, erkennt, untersucht und darauf reagiert. Ein Cybersicherheits-Verteidigungssystem […]…
-
Cybersicherheit als KI-natives Verteidigungssystem
Sophos hat Sophos-Fusion vorgestellt das umfassendste KI-native Cybersicherheits-Verteidigungssystem der Branche. Es wurde entwickelt, um koordinierte Reaktionen auf Bedrohungen im KI-Zeitalter zu ermöglichen. Entwickelt für eine durch KI veränderte Bedrohungslandschaft vereint Sophos-Fusion Security-Operations, Endpunktschutz, Netzwerksicherheit, Identitäts-, E-Mail- und Cloud-Sicherheit in einem einzigen Verteidigungssystem, das Bedrohungen mit KI-Geschwindigkeit verhindert, erkennt, untersucht und darauf reagiert. Ein Cybersicherheits-Verteidigungssystem […]…
-
Warum KI-gestützte Schwachstellensuche das Patchen unter Druck setzt
Der Juli-Patchday von Microsoft fällt außergewöhnlich umfangreich aus. Insgesamt wurden 570 Schwachstellen behoben, davon 57 als kritisch und 510 als wichtig eingestuft. Darunter befinden sich drei Zero-Day-Lücken, von denen zwei bereits aktiv in Angriffen ausgenutzt werden und eine öffentlich bekannt gemacht wurde. Auffällig ist zudem die enorme Zahl von 468 Schwachstellen in Microsoft-Edge/Chromium, von denen…
-
Veeam erhält 2026 die <> in 25 Ländern
Das Unternehmen für Data- und AI-Trust, Veeam Software, gab bekannt, dass es die <> in allen 25 teilnahmeberechtigten Ländern erhalten hat, was die globale Belegschaft in Nord- und Südamerika, Europa und im asiatisch-pazifischen Raum abdeckt. Die Auszeichnung basiert auf den Erfahrungen der Mitarbeiter bei ihrer Arbeit für Veeam, wobei 83 % […] First seen on…
-
Gold Eagle Clearinghouse Targets Security Gap, But How Is Unclear
The White House launched Gold Eagle to coordinate vulnerability response in a new AI world, but multiple questions linger over how it’s being implemented. First seen on darkreading.com Jump to article: www.darkreading.com/vulnerabilities-threats/gold-eagle-clearinghouse-targets-security-gap
-
Google Bets ‘Agentic Defense’ Strategy Can Outpace Attackers
Google Cloud incorporates key Wiz capabilities into an agentic defense platform to automate threat detection and remediation against AI attacks. First seen on darkreading.com Jump to article: www.darkreading.com/cloud-security/google-bets-agentic-defense-strategy-outpace-attackers
-
Agentic AI: Taming the Unpredictable
Agentic artificial intelligence is creating enough risks for organizations to demand a security reframe. First seen on darkreading.com Jump to article: www.darkreading.com/cybersecurity-operations/agentic-ai-untamable-ask-the-right-security-questions
-
E.U. Orders Google to Open Android Mic, Camera and Screen to Rival AI Assistants
The European Commission on Thursday ordered Google to give rival AI assistants the same reach into Android that Gemini already has: the camera, the microphone, whatever is on screen, a wake word that fires with the display off, and the ability to drive other apps in the background by imitating taps and typing.Google has to…
-
Qualys: KI beschleunigt die Schwachstellensuche und setzt das Patchmanagement massiv unter Druck
KI beschleunigt nicht nur Angriffe, sondern auch die legitime Sicherheitsforschung. Dadurch werden mehr Schwachstellen früher entdeckt. Gleichzeitig schrumpft das Zeitfenster. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/qualys-ki-beschleunigt-die-schwachstellensuche-und-setzt-das-patchmanagement-massiv-unter-druck/a45786/
-
New NadMesh Botnet Uses 20+ RCE Vectors to Hijack AI and MCP Infrastructure
NadMesh is a new, industrial”‘grade Go”‘based botnet that weaponizes more than 20 RCE vectors to hijack AI and MCP infrastructure at scale, combining autonomous scanning, exploit delivery, and credential harvesting in a single closed”‘loop platform. In early July 2026, researchers identified NadMesh as a high”‘volume Go-written botnet that was aggressively deploying bot agents across internet”‘facing…
-
Claude can now sign into websites with 1Password without exposing your credentials
1Password has introduced 1Password for Claude, a beta integration that lets Anthropic’s AI assistant complete browser tasks requiring authentication without accessing … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/17/1password-anthropic-claude-integration/
-
San Francisco Demands Apple and Google Delete AI ‘Nudify’ Apps From App Stores
The City Attorney’s Office sent the tech giants cease-and-desist letters this week telling them to stop profiting from 13 “face-swap” apps that are overwhelmingly used to target women and girls. First seen on wired.com Jump to article: www.wired.com/story/san-francisco-demands-apple-and-google-delete-ai-nudify-apps-from-app-stores/
-
CISOs say boardrooms still don’t grasp the human cyber risk AI is supercharging
More than three-quarters of European CISOs believe their C-suite doesn’t fully understand the cyber risk posed by their own employees, a gap that’s widening just as AI makes attacks on human judgement faster, more convincing and harder to spot. That’s according to new research from MetaCompliance, the human cyber risk management firm, which polled 200…
-
Check Point builds homegrown AI model as attack barriers collapse
The company is training a security-only small language model as AI hands attackers industrial-scale capabilities and pushes cyber defence towards full automation First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366645879/Check-Point-builds-homegrown-AI-model-as-attack-barriers-collapse
-
GPT-5.6 Codex Reportedly Wipes Files From Home Directories
Recent reports indicate that GPT-5.6 Codex has unintentionally deleted files in users’ home directories under certain configurations, raising concerns about the risks of running advanced AI coding agents with unrestricted access to the system. This issue, brought to light by researcher Tibo Sottiaux, appears to be linked to edge-case behavior when the model operates in…
-
The script, not the voice, is what makes AI voice phishing work
The call comes in at 4:40 on a Friday. The voice belongs to a senior manager, or sounds close enough, and she needs a password reset before a flight. She is polite, she is in … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/17/research-ai-voice-phishing/
-
Linux Creator Linus Torvalds Rejects Anti-AI Push and Defends LLM Tools
Linux creator and top-level kernel maintainer Linus Torvalds has made it clear that the Linux kernel project will not adopt an anti-AI stance. He believes that large language models and related tools should be assessed based on their technical value rather than dismissed outright. His comments were part of a discussion on the Linux Media…
-
KI außer Kontrolle? Deepmind-Chef fordert Aufsichtsbehörde unter Leitung der USA
First seen on t3n.de Jump to article: t3n.de/news/ki-ausser-kontrolle-deepmind-chef-fordert-aufsichtsbehoerde-unter-leitung-der-usa-1752945/
-
Agentische KI: Produktivität mit hohem Risiko
Management Summary Agentische KI eröffnet Unternehmen erhebliche Produktivitätspotenziale, erweitert aber zugleich die Angriffsfläche, da KI-Agenten selbstständig auf Systeme, Daten und Anwendungen zugreifen können. Schatten-KI entsteht, wenn Mitarbeitende private oder nicht freigegebene Tools nutzen; dadurch können vertrauliche Informationen unkontrolliert an externe Dienste gelangen. Besonders kritisch sind Erweiterungen, Skills und Plugins, die manipuliert sein können und mit……
-
New infosec products of the week: July 17, 2026
Here’s a look at the most interesting products from the past week, featuring releases from Cloudflare, Lineation.ai, Nudge Security, and Polygraf AI. Polygraf AI Meeting Guard … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/17/new-infosec-products-of-the-week-july-17-2026/
-
Oak Lands $60M Seed to Reinvent Identity Governance With AI
Israeli Startup Maps Enterprise Entitlements Beyond Traditional Identity Providers. Oak emerged with a $60 million seed round to build an AI-native identity governance platform that continuously manages human, machine and AI identities, aiming to automate access decisions, improve visibility into enterprise entitlements and reduce identity-driven security risk. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/oak-lands-60m-seed-to-reinvent-identity-governance-ai-a-32248
-
HHS Wants Input on Cyber, AI for Regulations on Clinical Labs
Experts Say Clinical Laboratory Improvement Amendments Are Seriously Outdated. The Department of Health and Human Services is seeking public feedback pertaining to cybersecurity matters and the use of artificial intelligence for potentially updating decades-old, rules-of-the-road regulations for U.S. clinical laboratories that test human specimens for health conditions. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/hhs-wants-input-on-cyber-ai-for-regulations-on-clinical-labs-a-32246
-
Agentic AI Is Untamable: Ask the Right Security Questions
Forget about attackers. Agentic artificial intelligence is creating enough risks for organizations and demands a security reframe. First seen on darkreading.com Jump to article: www.darkreading.com/cybersecurity-operations/agentic-ai-untamable-ask-the-right-security-questions
-
Cryptohack Roundup: Ostium Pauses Trading After $18M Exploit
Also: AscendEX Shuts Down; Ethereum Foundation on AI Bug Hunting. This week, Ostium paused trading, AscendEX shut down, Ethereum said AI hastens bug hunting, not verification, the United States charged an inmate over seized transfer, ex-Sheriff’s deputy jailed for extortion, Tangem card security, Iran-linked wallets sanctions and the U.S. may drop BitClub charges. First seen…
-
1M+ Emails Use Hidden Text to Dupe AI Security Filters
Artificial intelligence and LLMs can be surprisingly ineffective against text salting, allowing phishing emails to slide right into your inbox. First seen on darkreading.com Jump to article: www.darkreading.com/threat-intelligence/1m-emails-hidden-text-dupe-ai-security-filters
-
Claude Chrome extension flaw lets malicious extensions trigger AI actions
A flaw in Anthropic’s Claude for Chrome browser extension could allow a malicious extension to trigger predefined AI actions by simulating user clicks, potentially allowing it to abuse Claude’s access to connected services such as Gmail, Google Docs, Google Calendar, and Salesforce. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/claude-chrome-extension-flaw-lets-malicious-extensions-trigger-ai-actions/

