Tag: ai
-
‘Yellow Teams’ Are Defining the Future of AI Security
In some companies, engineers are building defense and attack tools to test the potential of artificial intelligence for cybersecurity, and its threat. First seen on darkreading.com Jump to article: www.darkreading.com/cybersecurity-operations/yellow-teams-defining-future-ai-security
-
The AI Supply Chain Is Your Latest Unguarded Attack Surface
When You Consume AI, You Inherit Every Upstream Risk You Can’t See Most enterprises don’t build AI, they consume it through APIs, open-source models and orchestration frameworks. Each layer inherits upstream risk with little visibility. This piece maps the four-layer AI supply chain and the existing security disciplines that bring it under control. First seen…
-
Torq and Criminal IP Partner to Deliver Decision-Ready Threat Intelligence for Autonomous SOC Operations
Torrance, California, USA, July 13th, 2026, CyberNewswire Criminal IP, the cyber threat intelligence search engine and attack surface management platform, today announced a new partnership and integration with Torq, the established agentic security operations leader. The partnership integrates Criminal IP’s decision-ready threat intelligence with the Torq AI SOC Platform that helps security teams triage, investigate,…
-
KI-gestützte Bot-Abwehr ersetzt CAPTCHAs durch kontinuierliche Verhaltensanalyse
Cloudflare hebt die Bot-Abwehr auf eine neue Stufe. Mit <> präsentiert der Connectivity-Cloud-Anbieter eine neue Sicherheitslösung, die automatisierte Angriffe anhand des Nutzerverhaltens erkennt und dabei vollständig auf klassische CAPTCHAs verzichten kann. Statt einzelne Anfragen zu prüfen, analysiert Precursor das Verhalten von Besuchern während einer kompletten Sitzung und soll so auch hochentwickelte KI-Bots und automatisierte […]…
-
How to Defend Against AI-Powered Identity Fraud
e=4>Discover how deepfakes, voice cloning, and AI-powered phishing are reshaping digital deception”, and learn practical strategies to strengthen identity security with real-time, AI-driven defenses. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/how-to-defend-against-ai-powered-identity-fraud-a-32211
-
New MemGhost Attack Plants Persistent False Memories in AI Agents Through One Email
Give an AI assistant a memory and access to your inbox, and you hand an attacker a way to rewrite what it thinks it knows about you. A single email can trick that agent into saving a false “fact” about the user, hide the change, and quietly steer its answers in later sessions.When it works,…
-
âš¡ Weekly Recap: ShareFile Threat, Citrix Bleed 2 Ransomware, AI Coding Attacks, and More
Somewhere right now, a security tool is quietly finding bugs faster than any human can fix them. That’s supposed to be the good news. The catch is that the attackers have the same tools, pointed the other way, and they don’t file tickets.That’s the shape of this week. Trusted code turns on the people who…
-
Forg365 PhaaS Targets Microsoft 365 with Device Code and AitM Session Theft
A new phishing-as-a-service (PhaaS) operation called Forg365 is using a combination of device code phishing, adversary-in-the-middle (AitM) tactics, antibot evasion, artificial intelligence (AI)-assisted lure creation, and post-compromise mailbox operations targeting Microsoft 365 accounts.Distributed via Telegram and costing $400 a month (or $3,800 per year), attack chains leverage phishing First seen on thehackernews.com Jump to article:…
-
US-amerikanische Modelle der künstlichen Intelligenz herrschen auch in deutschen KI-Unternehmen vor
In einer neuen Studie analysiert GreenPT, auf welche KI-Modell-Anbieter deutsche KI-Unternehmen setzen und wie sich Deutschland im europäischen Vergleich positioniert. Hierfür wurden 514 in Deutschland ansässige KI-Unternehmen untersucht. Bei 221 Unternehmen konnte anhand öffentlich verfügbarer Informationen mindestens ein Modellanbieter eindeutig identifiziert werden. Die am häufigsten genutzten KI-Modell-Anbieter deutscher Unternehmen: Kategorie Anteil der offenlegenden Unternehmen Mindestens…
-
Attackers Combine MCP Recon With Cloud Metadata SSRF to Steal Service Account Tokens
Internet-wide reconnaissance is expanding beyond conventional application targets to include Model Context Protocol (MCP) services, AI assistant configuration files, and locally exposed LLM endpoints. A 14-day review of Apache and ModSecurity logs from a small, low-traffic shared host found roughly 200 requests tied to AI-agent reconnaissance, alongside routine WordPress, .env, Git, and Spring Boot Actuator…
-
Adaptive Malware Could Evade Signature Detection by Regenerating Its Attack Capabilities
Adaptive, AI-driven malware could challenge a foundational assumption in enterprise defense: that a malicious program’s exploitation logic remains fixed after deployment. New research on adaptive computer worms argues that a self-replicating agent paired with an onboard reasoning loop could assess different environments, select target-specific attack paths, and regenerate capabilities as older methods become less effective.…
-
Turning the Tables on Email Scammers With ‘ScamBuster’
An open source, AI-driven system adopts victim personas to engage with phishing attackers, allowing organizations and law enforcement to gather relevant data on cybercriminal operations. First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/turning-tables-email-scammers-scambuster
-
Attacker Uses Suspected AI-Generated PowerShell Script to Map Active Directory
Cybersecurity researchers have flagged an intrusion in which an unknown threat actor leveraged a vibe-coded PowerShell script for Active Directory (AD) enumeration.”The script looked for the Domain Controller (DC) and mapped users, computers, and domains, before creating a directory and exporting out a number of files, and finally creating AD_Report.html to measure the success of…
-
Meta Files Patent for AI That Can Listen All Day and Track How You’re Feeling
Tags: aiMeta has filed a patent application for an AI that listens to your voice throughout the day, works out how it thinks you are feeling from the way you sound, and keeps a timestamped log of every read.Each read gets pinned to the moment it happened: the time, your location, what you were doing, even…
-
Thinking Fast and Slow in the SOC: The Case for Combining Autonomous AI with Analyst Copilots
A few days ago, I was sitting with the CISO of a Fortune 50 company, walking through how his security team was thinking about AI agents in the SOC. Smart team. Serious program. They had already connected Claude to a few detection tools and were seeing real value in specific investigations. But as we mapped…
-
BusySnake Stealer Uses Reverse SSH Tunnels and AI-Generated Loaders to Evade Detection
Armored Likho, a previously undocumented threat group also tracked as Eagle Werewolf based on circumstantial evidence, is targeting government institutions and electric-power organizations across Russia, Brazil, and Kazakhstan with a new Python-based infostealer named BusySnake. The group’s activity reflects an unusual overlap between cyber-espionage and financially motivated operations. Armored Likho targets organizations for intelligence collection…
-
New Relic startet kostenloses Observability-Programm für Startups bis Series A
Da Startups zunehmend auf LLMs, Agenten und KI-generierten Code setzen, liefern sie neue Funktionen und Änderungen oft in rasantem Tempo über ihren gesamten Tech-Stack hinweg aus. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/new-relic-startet-kostenloses-observability-programm-fuer-startups-bis-series-a/a45727/
-
AI-generated code has made security debt a governance problem
Moving from tool approval to true governance is the only way for CISOs to keep pace with the accelerating velocity of software risk. First seen on cyberscoop.com Jump to article: cyberscoop.com/governing-ai-code-security-risks-op-ed/
-
Heimlicher Spionage-Code in Claude Code entdeckt
Tags: aiEin Sicherheitsforscher hat im KI-Werkzeug Claude Code von Anthropic Code entdeckt, der unbemerkt Daten über Zeitzonen und Proxys von Nutzern erfasst. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/spionage-code-claude-code
-
New VEXAIoT AI Agents Autonomously Exploit IoT Vulnerabilities With 95% Success Rate
VEXAIoT, an autonomous multi-agent framework designed to discover and exploit vulnerabilities in the Internet of Things (IoT) within controlled test environments. In 200 attack trials against the intentionally vulnerable IoTGoat platform, the system completed 189 attacks, achieving an overall success rate of 94.5% (rounded to 95%). New VEXAIoT AI Agents Attack Workflow VEXAIoT, short for…
-
A hardware security AI assistant that checks chips for hidden backdoors
Chip designers license blocks of circuitry from outside vendors and drop them into larger products. A single processor can carry components from a range of suppliers, each … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/13/hardware-security-ai-assistant-hidden-backdoors/
-
99.9% of fixable AI vulnerabilities remain unpatched
Organizations build, deploy, and operate AI in the cloud, but basic cybersecurity hygiene is often sacrificed for speed, according to Orca Security’s 2026 State of AI Security … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/13/ai-infrastructure-security-risks-report/
-
Microsoft Tests AI-Powered Copilot Tool to Diagnose Windows 11 Performance Issues
Microsoft is gradually rolling out an optional Copilot feature called PC Insights, which provides the AI assistant with access to real-time information about Windows 11 hardware and performance. This feature, first reported by Windows Latest, is currently being tested with users in the United States and is not yet widely available. PC Insights aims to…
-
Keysight launches new cybersecurity test platform for AI traffic
First seen on scworld.com Jump to article: www.scworld.com/brief/keysight-launches-new-cybersecurity-test-platform-for-ai-traffic
-
Enterprises are rethinking where their AI applications run
Tags: aiGrowing demand for compute capacity, power, cooling and low-latency connectivity is prompting organizations to reassess where AI applications run, according to CoreSite. … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/13/colocation-for-ai-workloads-report/
-
New GhostCommit Technique Hides Exploits in Images to Evade AI Code Reviewers
Researchers have revealed a technique called >>GhostCommit,<< which involves prompt injection by hiding malicious instructions within images included in pull requests. This technique has the potential to bypass text-only AI code reviewers and later manipulate coding agents into exposing repository secrets. The ASSET Research Group explained that this technique leverages the widening gap between automated…
-
Ransomware ecosystem grows, but ‘four-headed monster’ dominates
AI is helping hackers, a new report finds, but mostly by automating very human behaviors. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/ransomware-concentrated-ai-guidepoint/824828/
-
New Forg365 phishing platform uses AI to target Microsoft 365 accounts
A new phishing-as-a-service (PhaaS) operation called Forg365 focuses on stealing Microsoft 365 accounts by combining adversary-in-the-middle (AiTM) and device code methods with AI-assisted lure generation. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/new-forg365-phishing-platform-uses-ai-to-target-microsoft-365-accounts/
-
The Hidden Security Risks of Reduced Summer IT Coverage
Security operations don’t slow down when IT teams take vacation, but staffing levels often do. Kaseya explains how AI-driven automation can help organizations maintain consistent security operations and reduce reliance on manual processes year-round. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/the-hidden-security-risks-of-reduced-summer-it-coverage/
-
ESET-Warnung: Schadhafte AI Skills bieten KI-Agenten neue Angriffsflächen
First seen on datensicherheit.de Jump to article: www.datensicherheit.de/eset-warnung-schadhaft-ai-skills-ki-agenten-neu-angriffsflaechen

