Tag: ai
-
18-Year-Old Linux Kernel SCTP Vulnerability Lets Attackers Gain Root and Escape Containers
SCTPhantom, tracked as CVE-2026-64564, is a high-severity Linux kernel use-after-free vulnerability in the Stream Control Transmission Protocol (SCTP) Dynamic Address Reconfiguration implementation. Researchers at Tencent Zhuque Lab’s Corvus AI project reported that a local attacker could leverage the flaw to escalate privileges to root and, in certain configurations, to escape from containers to the host.…
-
Russian Hackers Use AI Slopsquatting to Publish 700+ Malicious npm Packages
A large-scale supply chain attack has hit the npm registry, with a suspected Russian threat actor publishing more than 700 malicious packages in just 48 hours. Researcher Paul McCarty documented the campaign, tracked as WEL1DROPPER, and the package count has since grown past 1,000. WEL1DROPPER marks an evolution in AI slopsquatting, where attackers register randomly…
-
Keyfactor’s Ellen Boehm on enterprise AI at scale
Tags: aiFirst seen on scworld.com Jump to article: www.scworld.com/resource/keyfactors-ellen-boehm-on-enterprise-ai-at-scale
-
MSSP Market News: AI in security hits two big questions revenue and responsibility
First seen on scworld.com Jump to article: www.scworld.com/news/mssp-market-news-ai-security-platforms-take-on-more-of-the-soc-ahead-of-black-hat-2026-1
-
MSSP Market News: AI in security hits two big questions revenue and responsibility
First seen on scworld.com Jump to article: www.scworld.com/news/mssp-market-news-ai-security-platforms-take-on-more-of-the-soc-ahead-of-black-hat-2026-1
-
AI coding tools vulnerable to malicious GitHub issues
First seen on scworld.com Jump to article: www.scworld.com/brief/ai-coding-tools-vulnerable-to-malicious-github-issues
-
Channel Brief: The MSP AI challenge: Sell it, price it, make it profitable
First seen on scworld.com Jump to article: www.scworld.com/news/channel-brief-ai-native-is-the-new-pitch-msps-are-still-working-out-the-pricing
-
How we can apply lessons from The Odyssey to the AI challenge
Tags: aiFirst seen on scworld.com Jump to article: www.scworld.com/perspective/how-we-can-apply-lessons-from-the-odyssey-to-the-ai-challenge
-
F5’s Sean Murphy on securing frontier AI as attack and defense accelerate
First seen on scworld.com Jump to article: www.scworld.com/resource/f5s-sean-murphy-on-securing-frontier-ai-as-attack-and-defense-accelerate
-
Orca’s Gil Geron on securing the AI-powered enterprise
Tags: aiFirst seen on scworld.com Jump to article: www.scworld.com/resource/orcas-gil-geron-on-securing-the-ai-powered-enterprise
-
Island’s Michael Leland on the hidden risks of the AI supply chain
First seen on scworld.com Jump to article: www.scworld.com/resource/islands-michael-leland-on-the-hidden-risks-of-the-ai-supply-chain
-
Black Hat 2026: Open-source tool makes red teaming AI agents up to 125x cheaper
First seen on scworld.com Jump to article: www.scworld.com/news/black-hat-2026-open-source-tool-makes-red-teaming-ai-agents-up-to-125x-cheaper
-
Approved software is creating a new shadow AI blind spot
First seen on scworld.com Jump to article: www.scworld.com/perspective/approved-software-is-creating-a-new-shadow-ai-blind-spot
-
Forcepoint’s Ronan Murphy on securing the data layer AI just set on fire
First seen on scworld.com Jump to article: www.scworld.com/resource/forcepoints-ronan-murphy-on-securing-the-data-layer-ai-just-set-on-fire
-
KI als Produktivitätstreiber: Beschäftigte gewinnen bis zu acht Stunden pro Woche
Tags: aiFirst seen on datensicherheit.de Jump to article: www.datensicherheit.de/ki-produktivitatstreiber-zeitgewinn-mitarbeiter
-
AI Sandbox Failures Expose Need for Continuous Monitoring
Recent AI Incidents Show Sandbox Security Cannot Be Assumed. The fallout from the Hugging Face security incident continues with more artificial intelligence labs revealing that their models and agents either accessed the internet or escaped isolated test environments to hack into other companies. Frontier model labs can’t take sandbox containment as a given. First seen…
-
Horizon3 Raises $250M to Prove What Attackers Can Exploit
Startup Says Autonomous Testing Can Demonstrate Business Impact Without Disruption. San Francisco-based Horizon3 raised a $250 million Series E funding round at a $2 billion valuation to expand autonomous testing across infrastructure, identity and web applications as AI gives attackers new ways to discover, exploit and traverse enterprise weaknesses at machine speed. First seen on…
-
ISMG Editors: AI Is Supercharging Attackers
Also: CIOs Rethink Data in AI Rollouts, ShinyHunters Hits Biotech. In this week’s panel, four ISMG editors discussed new research showing how AI is making cyberthreat actors more capable, why the technology is forcing CIOs to rethink data platforms they spent years modernizing and a string of attacks in the biotech sector. First seen on…
-
AI Phishing Now Frighteningly Normal, Hard to Detect
StrongestLayer’s Alan LeFort on Personalization, Evasion and First-Seen Attacks. AI-generated phishing no longer looks unusual or obviously malicious, lending legacy filters ineffective. StrongestLayer CEO Alan LeFort explains how personalization, trusted infrastructure and evasion techniques are making first-seen attacks harder to detect. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/ai-phishing-now-frighteningly-normal-hard-to-detect-a-32466
-
How AI Agents Widen the Enterprise Blast Radius
AWS’s Matt Girdharry and Varonis’ Matt Radolec on Data Security, Machine-Speed Risk. Agentic AI can act at machine speed across data, APIs and cloud services, expanding enterprise risk beyond traditional controls. AWS’ Matt Girdharry and Varonis’ Matt Radolec explain why AI governance, least privilege and runtime visibility now matter more than ever for security teams.…
-
Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer
A cluster of nearly 800 malicious packages has been published to the npm registry as part of a new campaign designed to deliver cross-platform malware targeting Windows, Mac, and Linux systems.”These packages appear to use AI slop squatted, or randomly generated typo-squatting package names, but all of them deliver a powerful RAT and infostealer payload,”…
-
Why ‘America First’ in AI Shouldn’t Mean ‘America Only’
Former US Cyber Director on Cooperation, AI Supply Chains and National Security. U.S. leadership in AI requires more than protecting domestic technology. Former U.S. National Cyber Director Chris Inglis says national security will depend on outperforming competitors, strengthening global supply chains and working with allies against shared AI risks. First seen on govinfosecurity.com Jump to…
-
Kimi K3 Bypasses Cyber Test With Answer From GitHub
Test Flaw Allowed Moonshot AI’s Model to Reach the Internet. Moonshot AI’s open-weight model Kimi K3 jumped its sandbox during a test of its cybersecurity abilities to locate an already worked-out solution on GitHub – behavior perfectly normal for coders but that raises red flags for artificial intelligence models. First seen on govinfosecurity.com Jump to…
-
More than half of AI-generated patches are broken
Research finds your AI generated security patch is more likely to fail than fully fix a vulnerability. It might even introduce brand new flaws to exploit along the way. First seen on cyberscoop.com Jump to article: cyberscoop.com/ai-code-patching-security-risks/
-
AI Agents, Supply Chain Attacks, and Critical Flaws Define the Week in August 2026
Weekly summary of Cybersecurity Insider newsletters for August 2026, including Def Con and Black Hat conference coverage First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/weekly-roundup/ai-agents-supply-chain-attacks-and-critical-flaws-define-the-week-in-august-2026/
-
AI Generated Code Risks: Why Business Owners Should Never Trust Software That Simply Works
AI can now generate working software in minutes. Ask Claude, GitHub Copilot, ChatGPT, or another AI coding tool to create an API, authentication flow, admin…Read More First seen on securityboulevard.com Jump to article: https://securityboulevard.com/2026/08/ai-generated-code-risks-why-business-owners-should-never-trust-software-that-simply-works/
-
1Password Research Finds AI-Generated Vulnerability Patches Often Leave Bugs Behind
1Password’s Off-by-1 Labs has released research showing that large language models frequently produce vulnerability patches that look plausible but fail to fix the underlying flaw. The study, titled Frontier Models’ Vulnerability Patches are Often F.L.A.W.E.D., evaluated two cyber-capable reasoning models against six recently disclosed vulnerabilities in open-source software. Researchers generated 6,080 patches across the test..…
-
Beware cut-price AI services that read your every word
f someone offered you 90% off the official price to access Claude, the powerful AI model from Anthropic, would you be tempted? It turns out that around 900 people were, and they may be regretting their decision. First seen on fortra.com Jump to article: www.fortra.com/blog/beware-cut-price-ai-services-read-your-every-word
-
AI-Generated Patches Fail Half the Time
Tags: aiA study of more than 6,000 patches found that even working patches can introduce new bugs, break something else, or are open to bypass. First seen on darkreading.com Jump to article: www.darkreading.com/application-security/ai-generated-patches-fail-half-time

