Tag: ai
-
Chatbots, APIs und die verborgenen Risiken in modernen Application-Stacks
Was passiert, wenn eine Legacy-Anwendung unbemerkt bleibt und plötzlich im Zentrum eines Sicherheitsvorfalls mit KI und APIs steht? Für ein globales Unternehmen wurde dieses Szenario Realität, als ein Recruiting-Chatbot ungewöhnliches Verhalten zeigte und damit den Blick auf eine unterschätzte Plattform lenkte. Die anschließende Untersuchung brachte eine ganze Reihe von Risiken ans Licht. Der Fall zeigt,…
-
KI-gestützte Phishing-Angriffe auf Krankenhäuser werden zunehmen
Unter Zuhilfenahme generativer KI-Tools können Angreifer schnell, unkompliziert, überzeugend und skalierend E-Mails erstellen First seen on infopoint-security.de Jump to article: www.infopoint-security.de/ki-gestuetzter-phishing-angriffe-auf-krankenhaeuser-wird-zunehmen/a41979/
-
Default Cursor setting can be exploited to run malicious code on developers’ machines
An out-of-the-box setting in Cursor, a popular AI source-code editor, could be leveraged by attackers to covertly run malicious code on users’ computers, researchers … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2025/09/11/cursor-ai-editor-vulnerability/
-
KI-gestützter Phishing-Angriffe auf Krankenhäuser wird zunehmen
Unter Zuhilfenahme generativer KI-Tools können Angreifer schnell, unkompliziert, überzeugend und skalierend E-Mails erstellen First seen on infopoint-security.de Jump to article: www.infopoint-security.de/ki-gestuetzter-phishing-angriffe-auf-krankenhaeuser-wird-zunehmen/a41979/
-
Welche Rolle die Cloud bei Wächter-KIs hat – Wenn KI über KI wachen soll
First seen on security-insider.de Jump to article: www.security-insider.de/wenn-ki-ueber-ki-wachen-soll-a-9cb806ffab846a3c5723324c186eb415/
-
Vibe Coding-Fail: Drama in Brasilien, Dating-App für Lesben legt Daten offen
Von Protagonisten wird gerade “Vibe Coding” als Stein der Weisen und Revolution in der Software-Entwicklung gefeiert. Entwickler braucht es keine mehr, jedermann lässt seinen Code von KI stricken. In Basilien zeigt dieser Trend seine böse Fratze. Eine populäre Dating-App für … First seen on borncity.com Jump to article: www.borncity.com/blog/2025/09/11/vibe-coding-fail-drama-in-brasilien-dating-app-fuer-lesben-legt-daten-offen/
-
Cursor AI Code Editor RCE Flaw Allows Malicious Code to Autorun on Machines
A critical vulnerability in the Cursor AI Code Editor exposes developers to stealthy remote code execution (RCE) attacks when opening code repositories, security researchers warn. The flaw, discovered by Oasis Security, allows attackers to deliver and run harmful code automatically, with no warning prompt, putting vital secrets and cloud access at risk. Vulnerability Breakdown Cursor,…
-
Shift from Reactive to Proactive: Leveraging Tenable Exposure Management for MSSP Success
Tags: access, ai, api, application-security, attack, best-practice, breach, business, cloud, compliance, control, cyber, cybersecurity, data, endpoint, exploit, framework, guide, identity, infrastructure, iot, mitre, mssp, risk, risk-management, service, technology, threat, tool, vulnerability, vulnerability-managementAn Exposure Management as a Service offering allows MSSPs to unify security visibility, insight and action across the attack surface to prioritize exposure and enable innovation that is secure and compliant. Whether you’re already leveraging Tenable Vulnerability Management as a Service or you’re just starting a service offering, we’ve got guidance for you. Key takeaways…
-
OT security: Why it pays to look at open source
Tags: access, ai, attack, compliance, control, data, defense, detection, edr, endpoint, Hardware, intelligence, iot, microsoft, ml, monitoring, network, open-source, PCI, service, strategy, threat, tool, vulnerabilityOT security at the highest level thanks to open-source alternatives: Commercial OT security solutions such as those from Nozomi Networks, Darktrace, Forescout or Microsoft Defender for IoT promise a wide range of functions, but are often associated with license costs in the mid to high six-figure range per year. Such a high investment is often…
-
Three-Prong Ghost Hacker Scam Targets Seniors, Others
The FBI warns of the “Phantom Hacker” scam that has stolen over $1B by tricking victims”, often seniors”, into moving funds to fake “safe” accounts. Experts say AI will make such scams more convincing and scalable, underscoring the need for stronger safeguards and user vigilance. First seen on securityboulevard.com Jump to article: securityboulevard.com/2025/09/three-prong-ghost-hacker-scam-targets-seniors-others/
-
SANS Institute unterstützt mit AI-Blueprints die Einführung von KI
Der AI Blueprint bietet Führungskräften strukturierte Leitlinien zur Abstimmung von Sicherheit, Betrieb und Compliance bei der Einführung von KI in Unternehmen First seen on infopoint-security.de Jump to article: www.infopoint-security.de/sans-institute-unterstuetzt-mit-ai-blueprints-die-einfuehrung-von-ki/a41973/
-
Ordner öffnen reicht: Beliebter KI-Code-Editor führt automatisch Schadcode aus
Wer den KI-Code-Editor Cursor verwendet, sollte beim Öffnen fremder Repos vorsichtig sein. Es kann unbemerkt Malware ausgeführt werden. First seen on golem.de Jump to article: www.golem.de/news/ordner-oeffnen-reicht-beliebter-ki-code-editor-fuehrt-automatisch-schadcode-aus-2509-199986.html
-
Chrome Extension Scam Exposed: Hackers Stealing Meta Accounts
Tags: ai, browser, business, chrome, credentials, cyber, cybercrime, data-breach, hacker, malicious, scam, service, toolA sophisticated campaign targeting Meta advertisers through fake AI-powered ad optimization tools has been uncovered, with cybercriminals deploying malicious Chrome extensions to steal credentials and hijack business accounts. Cybereason Security Services has identified an evolving malicious Chrome extension campaign that specifically targets Meta (Facebook/Instagram) advertisers through a deceptive platform called >>Madgicx Plus.
-
Studie: Cybersicherheit in Deutschland 2025/2026 – KI und Fachkräftemangel machen deutsche Unternehmen unsicher
First seen on security-insider.de Jump to article: www.security-insider.de/gdata-cybersicherheit-in-zahlen-deutschland-2025-a-571f9be0b40d9863ee5736e9badeafce/
-
AI is everywhere, but scaling it is another story
Tags: aiAI is being adopted across industries, but many organizations are hitting the same obstacles, according to Tines. IT leaders say orchestration is the key to scaling AI. They … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2025/09/11/ai-enterprise-orchestration-scaling/
-
KI-Echtzeit-Lagebild stärkt Schutz kritischer Infrastrukturen
Integration heterogener Datenströme in rollenbasiertes Dashboard überwacht sensible IT-Umgebungen kontinuierlich. KI-gestützte Prognosen und Handlungsempfehlungen. Fachlich übertragbar auf andere essenzielle Versorgungssysteme. Telekom-Lösung in Kooperation mit dem Universitätsklinikum Bonn. Cyberattacken, Systemausfälle oder unentdeckte Schwachstellen in hochvernetzten Organisationen wie gerade im Gesundheitswesen können solche Störungen dramatische Folgen haben. Entscheidend ist, jederzeit den Überblick zu behalten, in… First seen…
-
House moves ahead with defense bill that includes AI, cyber provisions
The policy roadmap’s digital security text is tame in comparison to the last two years, when the idea of studying a U.S. Cyber Force dominated the debate. First seen on therecord.media Jump to article: therecord.media/house-passes-defense-policy-bill-ai-cyber
-
Smashing Security podcast #434: Whopper Hackers, and AI Whoppers
Ever wondered what would happen if Burger King left the keys to the kingdom lying around for anyone to use? Ethical hackers did – and uncovered drive-thru recordings, hard-coded passwords, and even the power to open a Whopper outlet on the moon. First seen on grahamcluley.com Jump to article: grahamcluley.com/smashing-security-podcast-434/
-
KI-Vishing: Bekannte Stimmen werden zum Sicherheitsrisiko
Tags: aiFirst seen on datensicherheit.de Jump to article: www.datensicherheit.de/ki-vishing-bekannte-stimmen-sicherheitsrisiko
-
Koi Raises $48M to Safeguard AI Models, Code and Extensions
Company Targets Non-Binary Software Blind Spots Left by Endpoint Security Tools. With $48 million in funding, Koi is scaling up efforts to help enterprises secure browser extensions, AI models and package code often missed by legacy tools. CEO Amit Assaraf says Koi is the only firm offering centralized governance for this fast-growing risk category. First…
-
Splunk.conf: Cisco and Splunk expand agentic SOC vision
The arrival of agentic AI in the security operations centre heralds an era of simplification for security pros, Splunk claimed. First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366630521/Splunkconf-Cisco-and-Splunk-expand-agentic-SOC-vision
-
AI Darwin Awards launch to celebrate spectacularly bad deployments
Tags: aiFrom fast food fiascos to botched databases, there are fresh honors for machine learning misadventures First seen on theregister.com Jump to article: www.theregister.com/2025/09/09/ai_darwin_awards/
-
Rethinking Security Data Management with AI-Native Pipelines
In this blog, you’ll learn why legacy pipelines fail modern SOC needs, how AI-native pipelines cut manual work, and how security teams gain cost savings, resilience, and faster threat response with adaptive, context-aware data management. First seen on securityboulevard.com Jump to article: securityboulevard.com/2025/09/rethinking-security-data-management-with-ai-native-pipelines/
-
Rethinking Security Data Management with AI-Native Pipelines
In this blog, you’ll learn why legacy pipelines fail modern SOC needs, how AI-native pipelines cut manual work, and how security teams gain cost savings, resilience, and faster threat response with adaptive, context-aware data management. First seen on securityboulevard.com Jump to article: securityboulevard.com/2025/09/rethinking-security-data-management-with-ai-native-pipelines/
-
Google Pixel 10 adds C2PA to camera and Photos to spot AI-generated or edited images
Pixel 10 adds C2PA to camera and Photos, helping users verify authenticity and spot AI-generated or altered images. Pixel 10 integrates C2PA Content Credentials into the camera and Photos, allowing users to verify whether images are real or AI-generated, or edited. The company announced the integration of the new feature during the Made by Google…
-
Pixel 10 fights AI fakes with new Android photo verification tech
Google is integrating C2PA Content Credentials into the Pixel 10 camera and Google Photos, to help users distinguish between authentic, unaltered images and those generated or edited with artificial intelligence technology. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/pixel-10-fights-ai-fakes-with-new-android-photo-verification-tech/
-
Cursor AI editor lets repos “autorun” malicious code on devices
A weakness in the Cursor code editor exposes developers to the risk of automatically executing tasks in a malicious repository as soon as it’s opened. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/cursor-ai-editor-lets-repos-autorun-malicious-code-on-devices/
-
AI Accelerates Code Development But Fuels New Security Risks
Former CSO Joe Sullivan on Vibe Coding Impact on Software Development. AI is reshaping how software is created, allowing more people to participate in the process through vibe coding. But as development accelerates, security challenges multiply as code is often deployed without thorough review, said Joe Sullivan, former CSO at Cloudflare, Facebook and Uber. First…

