Tag: ai
-
Cyber field doubts promise of Cyber Shield
The NCSC has shared more details of its national AI Cyber Shield initiative, but experts say the project faces serious delivery challenges First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366645655/Cyber-field-doubts-promise-of-Cyber-Shield
-
AI Gateways Offer Attackers the Keys to the Kingdom
A cryptomining incident highlights how AI gateways can provide access to AI models, cloud infrastructure, and identity and access management (IAM) data. First seen on darkreading.com Jump to article: www.darkreading.com/cyber-risk/ai-gateways-keys-kingdom
-
Fast die Hälfte des Datenverkehrs auf Reise-Websites stammt von bösartigen Bots
Reiseunternehmen stehen unter Druck, das Vertrauen und die Treue ihrer Kunden vor Cyberkriminellen zu schützen. Ausgeklügelte KI-gestützte Bots nehmen zunehmend Buchungssysteme, Treuekonten und kritische Reise-APIs ins Visier. Die Ergebnisse des ‘Thales Bad Bot Reports 2026″ zeigen, dass mittlerweile 49 Prozent des gesamten Datenverkehrs auf Reise-Portalen von bösartigen Bots generiert werden. Dadurch gehört die Reisebranche zu…
-
AI Attacks Move in Minutes. Join This Webinar on Building a Defense That Keeps Up
AI has changed how fast attacks move. Work that once took an attacker days now takes minutes. Using models like Mythos, attackers write tailored bait, pick targets, test what lands, and jump to the next host before your team clears the first alert.That is the gap, and it is not your fault. The tools and…
-
Warum preemptive Security kein Trend ist
Die klassische Sicherheitslogik beruhte lange auf einer stillschweigenden Annahme: Ein Angriff wird entdeckt, analysiert und dann in Regeln, Signaturen und Playbooks übersetzt. Was gestern noch ein vernünftiges Prinzip war, wirkt unter den Bedingungen des KI-Zeitalters wie ein Modell aus einer langsameren Epoche. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/preemptive-security-kein-trend
-
GhostApproval Flaws Let Top AI Coding Tools Write Outside Workspaces
Wiz found GhostApproval symlink flaws in major AI coding assistants that could hide sensitive file targets, bypass approval checks and enable system access too. First seen on hackread.com Jump to article: hackread.com/ghostapproval-flaws-ai-coding-tools-outside-workspace/
-
GhostApproval Flaw Hits Six Major AI Coding Assistants
Wiz discovered GhostApproval, a symlink flaw in six major AI coding assistants that bypasses approval First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/ghostapproval-flaw-ai-coding/
-
GhostApproval Attack Impacts Amazon Q, Claude Code, Cursor, Google Antigravity, and Windsurf
A newly disclosed vulnerability pattern known as >>GhostApproval<< is exposing significant flaws in the trust boundary of leading AI coding assistants, including Amazon Q Developer, Anthropic Claude Code, Cursor, Google Antigravity, Augment, and Windsurf. This issue demonstrates how attackers can exploit symbolic links (symlinks) to bypass workspace isolation and manipulate Human-in-the-Loop safeguards, potentially resulting in…
-
Kommentar von Mathias Widler, Netskope – Agentic AI warum Netzwerksicherheit neu gedacht werden muss
Tags: aiFirst seen on security-insider.de Jump to article: www.security-insider.de/autonome-ki-agenten-sicherheitsrisiken-machine-to-machine-kommunikation-a-f35970d7976116f39cfa9688fce3d055/
-
New AI Security Charter Backed by Over 70 Cyber Firms
Over 70 cybersecurity organizations have signed the CREST AI Charter detailing responsible use of AI for security First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/crest-ai-security-charter-cyber/
-
HalluSquatting Attack Lets Hackers Turn AI Coding Assistants Into Botnet Installers
A newly disclosed attack technique called “HalluSquatting” is raising serious concerns in the AI security landscape. This technique demonstrates how attackers can exploit large language model (LLM) hallucinations to covertly compromise systems and potentially create botnets on a large scale. The research introduces “adversarial hallucination squatting,” a novel method that exploits AI models that generate…
-
Cybercriminals Plant Malicious AI Agents in Open Source Tool Repositories
Cybersecurity researchers at ESET identify big rise in suspicious and malicious toolsets which put users at risk from cyber-attacks First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/cybercriminals-plant-ai-agents/
-
Meta’s New AI Image Tool Lets Others Use Your Public Instagram Photos in AI Images
Meta has announced that its new artificial intelligence (AI) model Muse Image lets people use public Instagram posts and reels to generate AI content, and it’s enabled by default.”You can also @-mention Instagram accounts in the Meta AI app to bring specific Instagram profiles right into your images,” the social media giant said in a…
-
Sovereign Cortex with T Security – KI-gestützte Cyberabwehr von Palo Alto Networks und Telekom
First seen on security-insider.de Jump to article: www.security-insider.de/ki-gestuetzte-cyberabwehr-von-palo-alto-networks-und-telekom-a-981ed6be227f2edc2fea4f5584b4caf9/
-
Malicious AI agent skills can slip past the scanners built to stop them
Developers who build with AI coding agents grab capabilities off public marketplaces the same way they grab packages from npm or PyPI. The add-ons are called agent skills. … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/09/malicious-ai-agent-skills-scan/
-
ESET Threat Report H1 2026: Cyberkriminelle machen bekannte Angriffe effizienter
Cyberkriminelle erfinden Angriffe nicht neu, sie machen sie effizienter. Der aktuelle ESET-Bedrohungsbericht zeigt, wie KI, QR-Code-Betrug und Angriffe auf Schutzsoftware die Bedrohungslage verändern. First seen on welivesecurity.com Jump to article: www.welivesecurity.com/de/eset-research/eset-threat-report-h1-2026-cyberkriminelle-machen-bekannte-angriffe-effizienter/
-
Top AI Agents Built to Catch Malicious Code Can Be Tricked Into Running It
Ask an AI coding agent to scan open-source code for security holes, and it might run the attacker’s code on your own machine instead.That is the finding in a proof-of-concept published Wednesday by the AI Now Institute, an attack it calls “Friendly Fire.” It works against Anthropic’s Claude Code and OpenAI’s Codex when either is…
-
Sechs CVSS 10.0 Schwachstellen im Juni – Adobe reagiert auf KI-entdeckte Schwachstellen mit zweitem Patchday
First seen on security-insider.de Jump to article: www.security-insider.de/adobe-coldfusion-updates-zwei-wochen-zyklus-a-14d269a8881b5925842c520d440ce36d/
-
A single malware file can outweigh an entire AI dataset
Antivirus vendors and security startups keep shipping AI features that promise to read malware the way a seasoned analyst would. The results inside security teams tell a … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/09/research-ai-in-cybersecurity/
-
Claude AI Prompt Injection Attack Turns Chatbot Into Stealthy C2 Agent to Achieve Remote Code Execution
Claude Desktop’s synced Personal Preferences feature can be exploited as a covert prompt-injection vector, transforming the AI assistant into a de facto command-and-control (C2) agent. This method allows for remote code execution on a compromised user workstation without the need for phishing emails or traditional malware delivery. In this attack chain, the initial access is…
-
GhostApproval Symlink Flaws Could Let Malicious Repos Run Code in AI Coding Agents
Researchers at Wiz found that a flaw in six popular AI coding assistants lets a booby-trapped code project quietly take control of a developer’s computer. The assistant asks permission to edit one harmless-looking file, but the write lands on a sensitive one instead.The affected tools are Amazon Q Developer, Anthropic’s Claude Code, Augment, Cursor, Google…
-
KI-Agenten brauchen Identitäten sonst werden sie zum Sicherheitsrisiko
KI-Agenten ziehen in Unternehmen ein oft schneller, als IT- und Security-Teams sie kontrollieren können. Im Gespräch mit manage it erklärt Sven Kniest, Vice President Central and Eastern Europe bei Okta, warum KI-Governance ohne kontinuierliche Identitätsprüfung ins Leere läuft und weshalb digitale Identitäten zur Voraussetzung für sichere Agentic Enterprises werden. Die manage it traf… First seen…
-
Smashing Security podcast #475: JadePuffer the AI that ran a ransomware attack all by itself
A 15-year-old boy asked a chatbot for help – and cancelled nearly 47,000 anime streaming subscriptions in under four hours. Meanwhile, researchers have documented the first fully autonomous, agentic AI-driven ransomware attack, “JadePuffer”. What does this tell us about the future of cybersecurity? First seen on grahamcluley.com Jump to article: grahamcluley.com/smashing-security-podcast-475/
-
Drohender Abfluss sensibler Daten im KI-Zeitalter Forcepoint-Tipps für Unternehmen zur Abwehr
Tags: aiFirst seen on datensicherheit.de Jump to article: www.datensicherheit.de/drohung-abfluss-daten-ki-forcepoint-tipps-unternehmen-abwehr
-
Anthropic Sues Abnormal AI Over Alleged Brand Copying
Frontier AI Developer Says Enterprise Customers Could Mistake the Two Brands. Anthropic alleges Abnormal’s 2025 rebrand unlawfully mirrors its visual identity as both companies increasingly compete for enterprise AI security customers, while Abnormal denies any likelihood of customer confusion and says its branding predates Anthropic’s claims. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/anthropic-sues-abnormal-ai-over-alleged-brand-copying-a-32180
-
OpenAI Readies GPT-5.6 for Public Launch After Federal Testing
Delayed Rollout Highlights Enterprise Risk as Frontier AI Becomes Strategic Infrastructure. OpenAI’s GPT-5.6 is slated for public release Thursday after federal testing and a limited preview. The rollout underscores how frontier artificial intelligence access is becoming a governance, cybersecurity and operational risk issue for enterprises. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/openai-readies-gpt-56-for-public-launch-after-federal-testing-a-32178
-
78 Prozent berichten von Vorfällen: KI-Sicherheitsrisiken treffen Unternehmen bereits heute
Tags: aiFirst seen on datensicherheit.de Jump to article: www.datensicherheit.de/78-prozent-bericht-vorfaelle-ki-sicherheitsrisiken-unternehmen
-
78 Prozent berichten von Vorfällen: KI-Sicherheitsrisiken treffen Unternehmen bereits heute
Tags: aiFirst seen on datensicherheit.de Jump to article: www.datensicherheit.de/78-prozent-bericht-vorfaelle-ki-sicherheitsrisiken-unternehmen
-
Lone Attacker Uses AI to Breach AWS Cloud Environment in 72 Hours
The attacker exploited AI workflows, chained cloud weaknesses, and stolen credentials to extort a large Amazon customer. First seen on darkreading.com Jump to article: www.darkreading.com/cloud-security/lone-attacker-ai-breach-aws-cloud-environment
-
OpenAI’s New GPT-5.6 Is Coming Sooner Than You Think
OpenAI is set to launch GPT-5.6 after a US security review, raising new questions for enterprise AI access, safeguards, and governance. The post OpenAI’s New GPT-5.6 Is Coming Sooner Than You Think appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-openai-gpt-5-6-us-security-review/

