Tag: ai
-
‘Voice of the CISO”-Report 2026 von Proofpoint – CISOs sollen KI-Sicherheit ohne zusätzliche Ressourcen managen
First seen on security-insider.de Jump to article: www.security-insider.de/proofpoint-report-77-prozent-ciso-genai-sicherheitsrisiko-a-489cf371816d204a46073c5e10bc596e/
-
Shadow AI and the permissions problem: what to check before handing AI the keys
AI tools have moved from novelty to daily habit with remarkable speed, and for many people they are now as much a part of the working day as email. For Corey Nachreiner, CSO at WatchGuard Technologies, that makes a few simple questions more urgent than ever. “People are already using AI for everyday questions, work…
-
SASE im KI-Zeitalter: Absicherung der weltweiten Konnektivität
Jede neue Region, in die ein Unternehmen expandiert, bringt ihre eigenen regulatorischen Rahmenbedingungen, infrastrukturellen Grenzen und Leistungsherausforderungen mit sich. Kombiniert man genug davon, entsteht eine Flickwerk-Architektur, die eher durch Ausnahmen als durch ein einheitliches Design zusammengehalten wird. Die Einführung von KI bringt dieses Flickwerk an seine Grenzen. Hinzu kommen die wachsenden Anforderungen durch verteilte SaaS-Lösungen,…
-
Cybersecurity Awareness Month: AI agents are users too, and they need governing like it
For more than two decades, Cybersecurity Awareness Month has centered on people: the employee who might click a malicious link, reuse a password or approve a suspicious login. This October, as the campaign runs under the banner “Don’t Make It Easy for Them”, identity specialists say the conversation must widen to include a fast-growing population…
-
AI is giving attackers a head start, Microsoft warns
Threat actors are using AI to find bugs, build malware and run intrusions faster than defenders can keep up. Microsoft’s 2026 Digital Defense Report, covering July 2025 … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/10/02/ai-cybersecurity-threats-microsoft-report/
-
Management-Plattform für die sichere Orchestrierung und Nutzung generativer KI
Künstliche Intelligenz ist ein wesentlicher Treiber für mehr Leistungsfähigkeit und Effizienz in Unternehmen. Doch um das Potenzial von generativer KI vollumfänglich auszuschöpfen, ist eine sichere und produktive IT-Umgebung essenziell. Die Plattform <> des Sysob-Partners Avency wurde gezielt für diese Anforderungen entwickelt und ermöglicht einen Compliance-konformen KI-Einsatz in Unternehmen. Reseller aus der DACH-Region können die […]…
-
Cyberangriff auf die Ludwig-Maximilians-Universität München
Vom Cyberangriff auf die Ludwig-Maximilians-Universität München sind rund 600.000 aktuelle und ehemalige Studierende betroffen. Sven Janssen, VP Sales DACH bei Sophos, ordnet ein, warum die eigentliche Gefahr jetzt erst kommt, etwa durch KI-gestützte Phishing-Angriffe auf Basis echter Daten, und was der Vorfall über die Cybersicherheit im gesamten Bildungswesen aussagt. Eine aktuelle Sophos-Umfrage unter 200 IT-Verantwortlichen…
-
OpenAI Blocks 15,000 Requests Trying to Extract Protected Model Reasoning
OpenAI has disrupted a coordinated campaign to extract protected internal reasoning from its AI models on a large scale. The company took action against activity linked to more than 15,000 user accounts. The company described the operation as an adversarial model-distillation effort, in which attackers systematically sought model outputs or reasoning traces that could help…
-
Malicious Email Could Hijack AI Agent and Access Connected Accounts
Security researchers have uncovered a now-fixed vulnerability in agentic AI platform Manus that could have allowed attackers to hijack an AI agent through a single malicious email and potentially access a user’s connected accounts. Researchers at Salt Labs, the research arm of Salt Security, found that Manus could interpret malicious instructions embedded within an incoming…
-
Chinese spies impersonate White House, Anthropic figures to phish AI policy experts
A China-aligned espionage group has been posing as a former White House official and a prominent economist to get into the cloud accounts of AI policy experts in the US, … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/10/02/china-aligned-ta419-phishing-ai-policy-experts/
-
A Flaw in ChatGPT’s Mac App Could Have Let Hackers Grab Sensitive Data
While the focus has been on AI agents’ hacking capabilities, a recently patched vulnerability in a ChatGPT app shows that AI software is itself an inviting”, and vulnerable”, target. First seen on wired.com Jump to article: www.wired.com/story/a-flaw-in-chatgpts-mac-app-could-have-let-hackers-grab-sensitive-data/
-
12 Best IGA Tools Compared (2026): Features Pricing
SailPoint remains the best overall IGA platform for certification depth and AI-assisted reviews, with Saviynt the best converged alternative when ERP-grade SoD must ship cloud-native. Evaluating the broader landscape across the top Identity and Access Management (IAM) companies shows how access governance has evolved from static audit checklists into dynamic risk-control planes. The market’s real…
-
China-Linked TA419 Hackers Target US AI Policy Experts With Credential Phishing Attacks
Tags: ai, attack, china, control, credentials, cyber, hacker, infrastructure, intelligence, microsoft, phishing, regulation, threatA China-linked threat actor known as TA419 has targeted U.S. artificial intelligence policy specialists through highly customized credential-phishing operations. This campaign, which involves impersonation, adversary-in-the-middle infrastructure, and a modified Browser-in-the-Browser toolkit, aims to steal Microsoft 365 sessions. This activity indicates a focused effort to collect intelligence on individuals who influence U.S. AI regulation, export controls,…
-
Two Zero-Days Exploited in Attack on Dutch Institute for Vulnerability Disclosure
The Dutch Institute for Vulnerability Disclosure reveals agentic AI-powered attack using Zammad zero-days First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/zerodays-dutch-institute/
-
Daybreak OpenAI nimmt Ukraine in KI-Cyberabwehr-Programm auf
First seen on security-insider.de Jump to article: www.security-insider.de/openai-ki-ukraine-russische-cyberangriffe-daybreak-a-87564843e2c798cf94a5861eda428383/
-
SASE im KI-Zeitalter: Globale Konnektivität braucht eine einheitliche Sicherheitsarchitektur
Tags: aiKI verschärft die Anforderungen an globale Netzwerke. Warum SASE Sicherheit, Konnektivität und Richtlinien über Ländergrenzen hinweg vereinheitlichen kann. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/sase-im-ki-zeitalter-globale-konnektivitaet-braucht-eine-einheitliche-sicherheitsarchitektur/a46598/
-
Investigators trace an AI agent ‘s path from research task to reconnaissance
Asymmetric Security traces rogue OpenAI AI agent activity that probed government sites, accessed staging servers, and evaded sandbox limits. Researchers at Asymmetric Security spent 48 hours over the last weekend reconstructing reported rogue OpenAI AI agent activity that hit the Australian government and other organizations between March and September this year. They worked from public…
-
FTC Investigates OpenAI and Anthropic Over Consumer Risks From Advanced AI Models
The U.S. Federal Trade Commission (FTC) has initiated a broad investigation into OpenAI, Anthropic, and other leading artificial intelligence developers to examine potential consumer harm arising from advanced AI systems. This inquiry will assess whether the companies’ development, deployment, safety claims, and management of agentic AI risks could violate the FTC Act’s prohibition on unfair…
-
Botnets, adversarial attacks and data poisoning top leaders’ AI threat list
Companies are putting more money into AI while naming attacks on AI systems as the threat they are least ready to face. PwC surveyed 3,934 business and technology leaders in … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/10/02/pwc-attacks-on-ai-systems/
-
AI agents keep access to company data after their work is done
IT teams responsible for identity security are concerned about AI agents’ ongoing access to company systems and the actions they take on users’ behalf, according to a … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/10/02/delinea-ai-policy-adoption-enforcement-report/
-
New infosec products of the week: October 2, 2026
Here’s a look at the most interesting products from the past week, featuring releases from BlackFog, Genea, Vega, and Thales. Vega II brings security-trained AI and lasting … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/10/02/new-infosec-products-of-the-week-october-2-2026/
-
Google Enters Cyber AI Race With Gemini 4 Argon
Phased Rollout Gives Trusted Defenders Unrestricted Access to Google’s Most Capable Cyber Model. Google has been seen as lagging behind the frontier AI model race as its competitors release cyber-capable models. The company followed Anthropic and OpenAI’s example with a phased rollout of Gemini 4. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/google-enters-cyber-ai-race-gemini-4-argon-a-33003
-
Omada Purchases EmpowerID to Govern AI Agents at Runtime
EmpowerID Technology Controls What AI Agents Can Execute in Real Time. Omada acquired boutique Ohio-based vendor EmpowerID to add AI agent identity governance and runtime authorization, giving enterprises controls to discover agents, restrict their tools and permissions, govern actions as they occur and create auditable records of execution. First seen on govinfosecurity.com Jump to article:…
-
Autonomous AI agents tried to hack US, Canadian government websites
Autonomous AI agents using aggressive strategies attempted to hack U.S. and Canadian government websites to find school and divorce statistics. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/autonomous-ai-agents-tried-to-hack-us-canadian-government-websites/
-
Breach Roundup: Cisco SD-WAN Flaw Under Attack
OpenAI Agents Target Canada, ShinyHunters Suspect Arrested. This week: Cisco SD-WAN, OpenAI agents target Canada, ShinyHunters suspect arrested in Amsterdam, Japanese railway ransomware, AI labs investigated, an accused Chinese hacker misses his cellphone. Russian hackers, an ATM jackpotting network sanctioned and former airmen sentenced for BEC. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/breach-roundup-cisco-sd-wan-flaw-under-attack-a-33001
-
Federal Researchers Ramp Up AI for Faster Clinical Trials
HHS Research Arm Backs Using AI, Predictive Models and Automation to Speed Research. ARPA-H, the federal government’s health research innovation agency, is launching several projects to ramp up efforts for the use of AI, predictive modeling, automation and related technologies to advance how U.S. clinical trials are designed and conducted. First seen on govinfosecurity.com Jump…
-
Microsoft says threat actors are ahead in the early AI race
Microsoft says cyberattackers are currently benefiting from artificial intelligence faster than defenders, allowing threat actors to speed up vulnerability discovery, malware development, and post-compromise activity while security teams struggle to keep pace. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/microsoft-says-threat-actors-are-ahead-in-the-early-ai-race/
-
National cyber director: Government-industry collaboration vital to managing AI risks, competition with nations
Sean Cairncross talked about regulations, China, pilot projects and more Thursday. First seen on cyberscoop.com Jump to article: cyberscoop.com/sean-cairncross-ai-security-china-industry-collaboration/
-
Researchers find Chinese hacking campaigns targeting AI firms, Asian governments
Two separate reports by cybersecurity companies highlight China-linked hacking operations, including a phishing campaign that impersonated Western experts. First seen on therecord.media Jump to article: therecord.media/china-linked-phishing-scheme-backdoor-taiwan
-
ThreatsDay: AI-Powered Zero-Day Chain, 543K Live Secrets, Model Inspection RCE and 13 More Stories
This week, the useful words are boring ones: inspect, cache, compile, store, trust. Each sounds harmless. Each can become an attack path when a system does a little more than people expect. A model check can run code. A cache can mix up requests. A public secret can stay useful for years.That is the lesson…

