Tag: ai
-
Nearly 1 in 10 Exposed LiteLLM Gateways Accepted the Example “sk-1234” Admin Key
Nearly one in ten of the internet-facing LiteLLM servers that Wiz Research scanned in February accepted sk-1234, the example admin key in LiteLLM’s own setup guide.LiteLLM is an open-source AI gateway, the software a company puts between its applications and the model providers it pays for. That key is the gateway’s administrator credential.Anyone who holds…
-
Anthropic Discloses Fourth AI Hacking Incident Involving Claude Opus 4.6
Anthropic on Wednesday disclosed a fourth incident in which its artificial intelligence (AI) model broke into real third-party systems, marking the latest in a growing list of cases that have raised concerns about the security risks posed by autonomous AI agents.The AI company said the incident dates back to January 2026 and involved an early…
-
New AI Workflow Identity Hijacking Attack Lets Hackers Exfiltrate Sensitive Data
Security researchers have recently disclosed a new enterprise AI attack technique known as Workflow Identity Hijacking. This method enables external attackers to exfiltrate sensitive corporate information by submitting seemingly harmless requests to AI-powered automations. Research published by Noma Labs researcher Sasi Levi reveals that this attack does not rely on prompt injection, stolen credentials, or…
-
Vertrauen ist keine Compliance – KI-Reife: Veeam will Unternehmen den Spiegel vorhalten
First seen on security-insider.de Jump to article: www.security-insider.de/veeam-data-ai-trust-maturity-model-ki-governance-a-a1e244c485c7bf075869c29faf3eecdf/
-
Vertrauen ist keine Compliance – KI-Reife: Veeam will Unternehmen den Spiegel vorhalten
First seen on security-insider.de Jump to article: www.security-insider.de/veeam-data-ai-trust-maturity-model-ki-governance-a-a1e244c485c7bf075869c29faf3eecdf/
-
Innovator Coffee Black Hat Special: Which Security Assumptions Is AI Starting to Change?
Black Hat has always been one of the clearest windows into how cybersecurity is evolving. But the most useful signals do not always come from keynotes or product launches. This year, in a conversation with a CISO, a cybersecurity investor,… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/innovator-coffee-black-hat-special-which-security-assumptions-is-ai-starting-to-change/
-
Innovator Coffee EP-43 2026 Blackhat: What’s Crowded and What’s New
Welcome to the Innovator Coffee, a podcast that bridges the gap between people and the world of AI and innovation. This is Wickey. Follow us to explore the top AI products, ecosystem insights, and the emerging trends.This episode of Innovator… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/innovator-coffee-ep-43-2026-blackhat-whats-crowded-and-whats-new/
-
Four Nation-State Actors Used the Same Chrome Zero-Day Exploit Kit Within 12 Days
Four espionage groups used the BlueMoon Chrome+Windows exploit kit within 12 days. Researchers suspect AI development. Proofpoint published a detailed analysis of a Chrome-and-Windows exploit kit it tracks as BlueMoon that four nation-state actors adopted within roughly two weeks of the first observed use. Google’s Threat Intelligence Group, Microsoft’s MSTIC, and Volexity all contributed to…
-
Hackers Use LLMs to Generate Exploit Scripts and Automate Post-Exploitation Across Latin America
Threat actors targeting organizations across Latin America are increasingly embedding commercial large language models (LLMs) into intrusion workflows, using AI-assisted scripting, troubleshooting, and proxy deployment to accelerate post-exploitation and data theft. The campaigns show that AI is no longer limited to phishing, content generation, or reconnaissance. Instead, attackers appear to be using LLMs as an…
-
Vertrauliche Geschäftsinformationen schützen – KI im Vorstand: Change oder Gefahr?
Tags: aiFirst seen on security-insider.de Jump to article: www.security-insider.de/ki-im-vorstand-sicher-nutzen-statt-schatten-ki-a-874f1bc45c1d06491bb922b3412063c0/
-
Hackers Deploy Hundreds of AI Agents to Compromise 440 PaperCut Servers
Tags: ai, authentication, cve, cyber, exploit, flaw, hacker, intelligence, russia, threat, vulnerabilityThreat intelligence firm GreyNoise has identified an AI-driven intrusion campaign, likely orchestrated by a Russian-speaking threat actor, that compromised at least 440 PaperCut NG/MF servers across 395 organizations in 48 countries. This campaign began on August 31, 2026, exploiting two vulnerabilities in PaperCut: CVE-2026-81578, an authentication bypass flaw, and CVE-2026-82078, a vulnerability that allows unsafe…
-
AI adoption brings new security headaches for already stretched CISOs
CISOs are taking on AI governance without a matching increase in resources or expertise, adding to an already broad remit spanning data protection, identity, resilience and … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/10/proofpoint-ciso-ai-security-risks-report/
-
A new open standard locks AI weights to approved hardware
OPAQUE, a confidential computing company that runs AI workloads inside hardware-isolated environments so operators cannot inspect them, released an open standard that lets AI … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/10/weight-custody-manifest-open-standard/
-
What Is Agentic MDR? Three Architectures Hide Behind One Label
Agentic MDR is managed detection and response delivered by AI agents that investigate and act on security alerts autonomously, under human-defined governance, in place of analysts working a queue. The service provider still owns the outcome. The work itself shifts… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/what-is-agentic-mdr-three-architectures-hide-behind-one-label/
-
State CIOs Need an Enterprise Identity Strategy
NASCIO’s Eric Sweden on Balancing Security, Privacy and Citizen Access. Fragmented identity systems make government harder to use and can obscure fraud across agencies. NASCIO’s Eric Sweden explains how states can build shared trust, protect privacy and adapt identity infrastructure for digital wallets, deepfakes and AI agents. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/state-cios-need-enterprise-identity-strategy-a-32782
-
How to Catch an AI SOC Analyst Bluffing
The first public demo of Morpheus 2, September 16 An AI analyst that’s confidently wrong is worse than no analyst at all. It feels like decision support, and you act on it. This summer showed what that looks like at… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/how-to-catch-an-ai-soc-analyst-bluffing/
-
San Francisco Orders Meta to Stop ‘Allowing’ AI Child Abuse Ads
The City Attorney’s Office has asked Meta to explain how the harmful ads repeatedly ran on Facebook and Instagram. The company claims the ads are not under the city’s jurisdiction. First seen on wired.com Jump to article: www.wired.com/story/san-francisco-orders-meta-to-stop-allowing-ai-child-abuse-ads/
-
This $50 lifetime VPN adds AI-powered protection to your connection
Get AI-powered threat protection, encrypted connections, and more with this VPN lifetime subscription today. The post This $50 lifetime VPN adds AI-powered protection to your connection appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/ghostshield-vpn-lifetime-subscription/
-
4 groups caught using the same Chrome and Windows exploit kit
A patch gap and the hastened pace of AI-based vulnerability discovery are likely contributors. First seen on arstechnica.com Jump to article: arstechnica.com/information-technology/2026/09/4-groups-caught-using-the-same-chrome-and-windows-exploit-kit/
-
4 groups caught using the same Chrome and Windows exploit kit
A patch gap and the hastened pace of AI-based vulnerability discovery are likely contributors. First seen on arstechnica.com Jump to article: arstechnica.com/information-technology/2026/09/4-groups-caught-using-the-same-chrome-and-windows-exploit-kit/
-
4 groups caught using the same Chrome and Windows exploit kit
A patch gap and the hastened pace of AI-based vulnerability discovery are likely contributors. First seen on arstechnica.com Jump to article: arstechnica.com/information-technology/2026/09/4-groups-caught-using-the-same-chrome-and-windows-exploit-kit/
-
ChatGPT Flaw Let Attackers Secretly Hijack a Victim’s AI Session
Check Point researchers found a ChatGPT flaw that let attackers run hidden tasks and retrieve connected Gmail data through a cross-account channel. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-chatgpt-cross-account-data-leak-flaw/
-
Google Warns Hackers Are Turning AI Agents Into Attack Tools
Google warns that hackers are using AI agents to automate attack stages, harvest credentials, and accelerate cyberattacks with less human direction. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/cybersecurity/news-google-hackers-ai-agents-attack-tools/
-
Stopping Rogue AI Agents in Real Time
Capsule Security CEO Naor Paz joins Alan Shimel to explain why rogue AI agent detection is a runtime problem, not a posture one, and how inspecting intent drift can stop a dangerous tool call before it runs. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/stopping-rogue-ai-agents-in-real-time/
-
US Government Accuses Chinese AI Firms of Distilling Frontier Models
US agencies claim Chinese companies covertly extracted billions of tokens from OpenAI, Anthropic, Google Gemini, and SpaceX’s Grok to reduce development costs. First seen on darkreading.com Jump to article: www.darkreading.com/application-security/us-government-chinese-ai-firms-distilling-frontier-models
-
US Agencies Warn Chinese AI Firms Are Extracting Advanced AI Models
US agencies accuse six Chinese AI firms of extracting billions of tokens from US AI models to accelerate development and copy advanced capabilities. NSA, CISA, and the FBI jointly published an advisory accusing six Chinese AI companies, DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI, of running industrial-scale extraction campaigns against US frontier models since…
-
France’s Mistral AI Touts Its Europeanism, But Faces Limits
Tags: ai‘Made in France’ Can Only Get Mistral So Far in AI Race. Mistral raised 3 billion euros in a funding round that gives Europe’s great hope for a domestic AI leader a valuation of more than 21 billion euros. Mistral is playing up its ability to provide sovereign AI – but the degree of sovereignty…
-
Securing AI Agents at Runtime
Arcjet founder David Mytton joins Alan Shimel to unpack why AI agent runtime security is the new frontier, every tool call as a policy decision, behavior drift as a first-class threat, and what buyers should ask for in a noisy market. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/securing-ai-agents-at-runtime/

