Tag: ai
-
Thousands of malicious AI skills found capable of stealing data, running malware
AI agents can browse the web, use external tools, execute commands, and perform tasks on behalf of users. Many rely on skills that define how they interact with services and … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/08/eset-ai-threat-trends-report/
-
AI-as-a-Service Botnet Routes Malicious Workloads Across Compromised Windows and Linux Hosts
The underground advertisement for the so-called Mycelium Framework reads like another feature”‘packed botnet sales pitch: cross”‘platform payloads, encrypted C2, persistence, exploit modules, credential theft, and lateral movement. Those building blocks are not new. What makes Mycelium notable is its advertised purpose to treat compromised endpoints not as disposable bots but as a capability”‘aware. AI compute…
-
Discord Confirms Bug That Incorrectly Banned 8,200 Users Since May 2026
Discord has confirmed a significant flaw in its automated moderation and enforcement pipeline that led to the wrongful banning of approximately 8,200 user accounts between May and early July 2026. This raises concerns about the reliability of AI-assisted trust and safety systems. The issue was disclosed via Discord’s official support channel on July 7 and…
-
CISA Deploys Anthropic’s Mythos AI to Hunt Vulnerabilities in U.S. Government Code
CISA is using Anthropic’s Mythos AI to scan federal code for vulnerabilities, aiming to find flaws before hackers and foreign intelligence services. Three sources familiar with the matter told Reuters that CISA, the U.S. government’s civilian cyber defense agency, is running Anthropic’s Mythos AI model against federal code repositories to find vulnerabilities before foreign intelligence…
-
Claude Code, Cursor, and OpenAI Codex Trigger Cyberattack-Like Telemetry Alerts
AI-powered coding assistants such as Claude Code, Cursor, and OpenAI Codex are increasingly triggering endpoint detection and response (EDR) alerts that resemble active cyberattacks, according to new research from Sophos X-Ops. This analysis, based on real-world telemetry collected in June 2026, highlights how autonomous AI behavior, while often benign, closely mirrors adversarial tactics, creating new…
-
State IDs for AI Agents: Will Estonia Set a Precedent?
The world’s digital testing ground plans to help people use AI agents for government purposes. First seen on darkreading.com Jump to article: www.darkreading.com/cybersecurity-operations/state-ids-ai-agents-estonia
-
NCSC Touts National Scale, AI-Powered “Cyber Shield” for Defense
The National Cyber Security Centre wants to work with AI partners to build a new “Cyber Shield” to defend the UK First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/ncsc-national-cyber-sheild-ai/
-
Hackers can use 9 of the most popular AI tools to assemble massive botnets
“HalluSquatting” weaponizes LLMs’ inability to say “I don’t know.” First seen on arstechnica.com Jump to article: arstechnica.com/security/2026/07/hackers-can-use-9-of-the-most-popular-ai-tools-to-assemble-massive-botnets/
-
Claude Cowork turns your phone into a remote control for AI work
Anthropic started rolling out Claude Cowork, an AI agent that completes multi-step tasks, in beta for Max users on mobile and the web. They describe a goal, and Claude plans … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/08/claude-cowork-phone-mobile-web/
-
Wenn KI die KI angreift – LiteLLM-Lieferkettenangriff über einen autonomen KI-Agenten
Tags: aiFirst seen on security-insider.de Jump to article: www.security-insider.de/litellm-lieferkettenangriff-ki-agent-supply-chain-teampcp-a-8205c351c60c1accf736b631f5e18251/
-
Wenn KI die KI angreift – LiteLLM-Lieferkettenangriff über einen autonomen KI-Agenten
Tags: aiFirst seen on security-insider.de Jump to article: www.security-insider.de/litellm-lieferkettenangriff-ki-agent-supply-chain-teampcp-a-8205c351c60c1accf736b631f5e18251/
-
20 open-source cybersecurity tools to keep your team ready for anything
AI is changing how security teams find vulnerabilities, analyze code, test applications, and protect infrastructure. Developers are building tools to secure AI systems … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/08/20-latest-open-source-cybersecurity-tools/
-
macOS is becoming a proving ground for AI agents
Somewhere right now, a Mac Mini is sitting on a shelf doing someone’s chores. Nobody’s watching it. It reads a version number out of Terminal, hops over to Safari, … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/08/macos-ai-agents-automation/
-
OpenAI and Anthropic are pulling in different directions
Companies are handing routine operational decisions to AI agents that plan, remember, and act on their behalf. These agents run on statistical models, and their behavior can … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/08/openai-anthropic-agentic-ai-security-risk/
-
U.S. Government Reportedly Approves OpenAI’s GPT-5.6 Sol, Terra, and Luna Models
The Trump administration has reportedly lifted previous restrictions on the launch of OpenAI’s GPT-5.6, enabling a broader commercial rollout of this advanced model after weeks of government-mandated cybersecurity and national security vetting. This decision marks a significant turning point in U.S. AI governance, moving GPT-5.6 from a tightly controlled pilot program with Trump-approved partners to…
-
Anthropic Keeps Claude Fable 5 Available on Paid Plans Until July 12
Anthropic has announced an extension of access to its advanced AI model, Claude Fable 5, allowing users on all paid plans to continue using the system until July 12, 2026. This update, shared via the company’s official X account, comes as enterprises increasingly rely on generative AI models for security research, code analysis, and threat…
-
Google Dialogflow CX Flaw Lets Attackers Bypass VPC-SC and Steal Sensitive Chatbot Data
A critical vulnerability in Google Cloud’s Dialogflow CX platform allowed attackers to bypass VPC Service Controls (VPC-SC) and silently exfiltrate sensitive chatbot data, raising significant concerns about the security of enterprise AI deployments. Discovered by Varonis Threat Labs and dubbed “Rogue Agent,” the flaw exposed a serious design gap in how Dialogflow CX executes custom…
-
Why we need governance frameworks that match the speed of AI
First seen on scworld.com Jump to article: www.scworld.com/perspective/why-we-need-governance-frameworks-that-match-the-speed-of-ai
-
Rewst AI agent update gives MSPs a new SMB automation play
First seen on scworld.com Jump to article: www.scworld.com/news/rewst-ai-agent-update-gives-msps-a-new-smb-automation-play
-
AI is making compliance decisions. Can you prove how?
First seen on scworld.com Jump to article: www.scworld.com/perspective/ai-is-making-compliance-decisions-can-you-prove-how
-
Malicious websites trick AI agents into crypto payments, context poisoning
First seen on scworld.com Jump to article: www.scworld.com/news/malicious-websites-trick-ai-agents-into-crypto-payments-context-poisoning
-
GitLost Vulnerability Lets Attackers Trick GitHub AI Agent Into Leaking Private Repos
A critical vulnerability known as >>GitLost<< has been discovered in GitHub's newly introduced Agentic Workflows by Noma Labs. This flaw allows unauthenticated attackers to exfiltrate sensitive data from private repositories. It demonstrates how AI-driven automation within development pipelines can be manipulated to bypass conventional access controls and leak confidential information across repository boundaries. GitLost Vulnerability…
-
Investors Accuse Oracle of Hiding OpenAI Financial Risks
Suit Claims Oracle’s AI Backlog Relied Heavily on One Financially Strained Customer. An investor class action lawsuit alleges Oracle failed to disclose internal concerns about OpenAI’s revenue, user growth and ability to meet cloud-computing commitments, leaving investors unaware of risks tied to Oracle’s multibillion-dollar AI infrastructure expansion and February debt offering. First seen on govinfosecurity.com…
-
UK Govt Pairs Agentic AI Initiative With Cyber Resilience Pledge
NCSC Launches AI Research, Governance and Resilience Measures. The U.K. government unveiled an AI-driven Cyber Shield initiative alongside a Cyber Resilience Pledge signed by 60 organizations, seeking to automate vulnerability management, strengthen governance and improve national resilience as ransomware and AI-enabled threats escalate. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/uk-govt-pairs-agentic-ai-initiative-cyber-resilience-pledge-a-32172
-
EU Pushes for Domestic AI Momentum
Eurozone Banks Told to Strengthen Controls Amid AI Vulnerability Disclosure Wave. Europe is planning for improved capabilities to evaluate the cybersecurity implications of frontier artificial intelligence models – and will possibly mount a grand challenge for developing AI-powered cybersecurity systems – as part of a new strategy unveiled Tuesday. First seen on govinfosecurity.com Jump to…
-
Dialogflow CX ‘Rogue Agent’ Flaw Enabled AI Chatbot Data Theft
Varonis reported the flaw to Google in late 2025 and it has been addressed, but it reminds defenders to take a fresh look at their AI Infrastructure security. First seen on darkreading.com Jump to article: www.darkreading.com/application-security/dialogflow-cx-rogue-agent-flaw-enabled-ai-chatbot-data-theft
-
Deepfake CSAM lawsuit against xAI, Grok expands
Two new alleged victims detailed how Grok was used by friends and family to generate sexual images of them as minors. The suit also adds Stability AI as a defendant. First seen on cyberscoop.com Jump to article: cyberscoop.com/deepfake-csam-lawsuit-grok-xai-expands-stability-ai/
-
Selling Cyber: Anthropic’s Fable 5 Raises Security Tradeoffs
Panel Examines Costs, Security Limits, Enterprise Adoption of Fable 5 and Mythos 5. Anthropic’s Claude Fable 5 and Mythos 5 demonstrate major advances in coding and reasoning while raising new questions about exploit generation, enterprise AI spending, data governance and the growing urgency of faster vulnerability remediation, according to the panelists on Selling Cyber. First…
-
AI Sovereignty Is a New Test for Enterprises
Enterprises are Rethinking Operational Risks to Gain Greater Control of AI Stacks. IBM reports that only 9% of executives fully understand their AI dependencies, while 71% say switching vendors would be difficult. AI sovereignty concerns reached a fevered pitch for tech leaders last month after Anthropic switched off two of its most capable artificial intelligence…
-
AI Sovereignty Is a New Test for Enterprises
Enterprises are Rethinking Operational Risks to Gain Greater Control of AI Stacks. IBM reports that only 9% of executives fully understand their AI dependencies, while 71% say switching vendors would be difficult. AI sovereignty concerns reached a fevered pitch for tech leaders last month after Anthropic switched off two of its most capable artificial intelligence…

