Tag: ai
-
Malicious Agent Skills Can Steal Credentials, Exfiltrate Source Code, and Install Backdoors
Malicious AI agent skills can be packaged to steal credentials, exfiltrate source code, and install backdoors while still bypassing many current skill-auditing systems. The paper finds that static scanners are especially weak against payload-preserving evasions, while runtime behavior auditing is far more resilient. The core threat is simple but serious: an agent skill is not…
-
Check Point warnt: Securitygetriebener Alarmflut
Tags: aiFür Sicherheitsteams heißt das: Priorisierung wird zur Kernkompetenz. Unternehmen, die Exposure Management konsequent umsetzen, können ihre Ressourcen fokussieren, Reaktionszeiten verkürzen. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/check-point-warnt-security-teams-kaempfen-mit-ki-getriebener-alarmflut/a45679/
-
How to prioritize AI agent security by business impact
Your CEO calls about an AI agent security incident in finance. He wants to know whether money moved, whether financial data was exposed, who owned the agent and why it had … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/06/prioritize-ai-agent-security-business-impact/
-
SkillCloak Lets Malicious AI Agent Skills Evade Static Scanners with Self-Extracting Packing
Scanners meant to catch malicious add-on “skills” for AI coding agents can be fooled by a few simple changes that leave the malware working, according to a new study from researchers at the Hong Kong University of Science and Technology.Their strongest trick slipped past every scanner tested more than 90% of the time, and the…
-
Omnigent: Open-source AI agent framework and meta-harness
Plenty of developers now keep several coding agents close at hand, reaching for Claude Code on one task and Codex or Cursor on the next. Each tool arrives with its own command … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/06/omnigent-open-source-ai-agent-framework/
-
KI-Exploit durch Prompt Injection – Cursor-Schwachstellen hebeln Sandbox aus
First seen on security-insider.de Jump to article: www.security-insider.de/cursor-ide-duneslide-sicherheitsluecken-prompt-injection-sandbox-bypass-a-92a2a3d25ac1c9726ae9afde76020cd1/
-
The context gap: Building trusted agents in the age of AI-accelerated exploitation
First seen on scworld.com Jump to article: www.scworld.com/resource/the-context-gap-building-trusted-agents-in-the-age-of-ai-accelerated-exploitation
-
When Too Much Security Data Becomes the Risk
Rapid growth turned routine firewall logs into a security and budget liability. One CISO used artificial intelligence to filter what data truly belongs in the SIEM. First seen on darkreading.com Jump to article: www.darkreading.com/cyber-risk/too-much-security-data-risk
-
AI Agent Pulls Off a Ransomware Attack Without Human Help
Researchers Say the Attack Combined AI Decision-Making With Known Software Flaws. An autonomous AI agent has executed what researchers describe as the first agentic ransomware attack, exploiting vulnerabilities, stealing credentials and encrypting a production database without human intervention. Cloud security firm Sysdig attributed it to a threat actor it tracks as Jadepuffer. First seen on…
-
Week in review: SimpleHelp vulnerability exploited, Oracle EBS Payments flaw under attack
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Companies keep bolting AI onto their products, and the security bill is … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/05/week-in-review-simplehelp-vulnerability-exploited-oracle-ebs-payments-flaw-under-attack/
-
Neuer Job als Senior AI Scientist gesucht? Schau dir unsere Top Jobs an
First seen on t3n.de Jump to article: t3n.de/news/unsere-jobs-der-woche-1175973/
-
JadePuffer ransomware used AI agent to automate entire attack
Researchers identified what they believe is the first documented case of a ransomware operation, JadePuffer, conducted entirely by a large language model (LLM) agent. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/jadepuffer-ransomware-used-ai-agent-to-automate-entire-attack/
-
The Lean Expansion Playbook AI Startups Are Using to Build Global Teams
Learn how AI startups use global hiring, EOR partners, and remote systems to access talent, stay compliant, and extend runway efficiently for sustainable growth. First seen on hackread.com Jump to article: hackread.com/lean-expansion-playbook-ai-startups-global-teams/
-
BlueVoyant startet Sicherheitsdienst für KI-Agenten in Microsoft-Umgebungen
BlueVoyant stellt den Microsoft Agent 365 Security Deployment Service vor. Der Dienst soll KI-Agenten in Microsoft-Umgebungen sichtbar, steuerbar und sicherer machen. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/bluevoyant-startet-sicherheitsdienst-fuer-ki-agenten-in-microsoft-umgebungen/a45674/
-
Avalon Malware Uses Legal Document Lure to Deliver CrownX Ransomware Capabilities
A previously undocumented malware framework, tracked as Avalon, that uses a spoofed legal-document lure and a multi-stage, fileless-oriented chain to deliver a ransomware component internally labeled CrownX. The campaign demonstrates a shift toward consolidation of multiple offensive capabilities into a single recovered payload and highlights how modern development practices including likely AI assistance are lowering…
-
Gefälschte Perplexity-Erweiterung spioniert Suchanfragen aus
Eine gefälschte Chrome-Erweiterung für Perplexity AI hat Suchanfragen abgefangen und Nutzerdaten gesammelt. Google hat das Add-on inzwischen entfernt. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/chrome-gefaelscht-perplexity
-
New “Bad Epoll” Linux Kernel Flaw Lets Unprivileged Users Gain Root, Hits Android
A newly disclosed Linux kernel flaw called Bad Epoll (CVE-2026-46242) lets an ordinary user with no special access take full control of a machine as root. It affects Linux desktops, servers, and Android, and a fix is out.Bad Epoll sits in the same small stretch of kernel code where Anthropic’s most powerful AI model, Mythos,…
-
AI Agents Are Creating a New Enterprise Security Gap
Tags: aiFive independent security disclosures in a single week point to the same gap: AI agent permissions, not AI agent capabilities, are the problem enterprises haven’t solved. The post AI Agents Are Creating a New Enterprise Security Gap appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-ai-agents-enterprise-security-gap/
-
AI Oversight, Security Flaws, and Industry Shifts Define This Week in Tech
See what you missed in Daily Tech Insider from June 29July 2. The post AI Oversight, Security Flaws, and Industry Shifts Define This Week in Tech appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/ai-oversight-security-flaws-and-industry-shifts-define-this-week-in-tech/
-
The Elephants in the Technology Room – Part 4
Why IT and Security Teams Can No Longer See What They’re Supposed to Protect Shadow IT has evolved into shadow SaaS, shadow AI, shadow data and autonomous agents that operate beyond security’s view. Traditional governance models can no longer keep pace. Organizations must transition from blocking technology to making its use visible, monitored and data-controlled.…
-
Mangelnde Governance bei KI-Nutzung: Schatten-KI bedroht Sicherheit in Unternehmen
Deutsche Firmen nutzen KI-Agenten ohne ausreichende Regelung. Sicherheitsverantwortliche sehen eine wachsende Gefahr für Unternehmensdaten. First seen on golem.de Jump to article: www.golem.de/news/mangelnde-governance-bei-ki-nutzung-schatten-ki-bedroht-sicherheit-in-unternehmen-2607-210496.html
-
GitLab-Studie zur KI-Softwareentwicklung – KI-Code wächst schneller als Governance
First seen on security-insider.de Jump to article: www.security-insider.de/gitlab-studie-ki-code-governance-traceability-a-756d92548ad404f84685561b14d4829d/
-
GitLab-Studie zur KI-Softwareentwicklung – KI-Code wächst schneller als Governance
First seen on security-insider.de Jump to article: www.security-insider.de/gitlab-studie-ki-code-governance-traceability-a-756d92548ad404f84685561b14d4829d/
-
GitLab-Studie zur KI-Softwareentwicklung – KI-Code wächst schneller als Governance
First seen on security-insider.de Jump to article: www.security-insider.de/gitlab-studie-ki-code-governance-traceability-a-756d92548ad404f84685561b14d4829d/
-
Warum Internet-Intelligence so wichtig für Security-Operations ist
Künstliche Intelligenz verändert die Bedrohungslage in der Cybersecurity grundlegend. KI-gestützte Angriffe beschleunigen Kampagnen und machen bekannte Angriffsmuster noch skalierbarer, gezielter und schwerer berechenbar. Dadurch entstehen nicht unbedingt neue Angriffsmethoden. Vielmehr werden bestehende Angriffsformen verstärkt, effizienter und haben eine deutlich größere Reichweite. Und selbst technisch weniger versierte Akteure können automatisierte Angriffe durchführen, für die bislang deutlich…
-
JADEPUFFER: First EndEnd AI-Driven Ransomware Operation
Sysdig reports an AI agent ran a full ransomware attack end-to-end, exploiting flaws, stealing creds, moving laterally, and encrypting data without humans. Sysdig’s Threat Research Team has documented what it assesses to be the first ransomware operation driven end-to-end by a large language model. The operator, which Sysdig calls JADEPUFFER, broke into a server, harvested…
-
Angriff per USB-Stick: KI findet gefährliche Lücke in populärem FatFs-Treiber
Das bloße Anschließen eines USB-Sticks reicht aus, um auf vielen Embedded- und IoT-Geräten Schadcode einzuschleusen. Einen Patch gibt es bisher nicht. First seen on golem.de Jump to article: www.golem.de/news/angriff-per-usb-stick-ki-findet-gefaehrliche-luecke-in-populaerem-fatfs-treiber-2607-210484.html
-
Wenn Modelle der künstlichen Intelligenz in die Irre führen Drei Fallen und wie man sie erkennt
Tags: aiEin KI-Modell wurde entwickelt, die Genauigkeit sieht hervorragend aus und alle sind beeindruckt. Doch was, wenn die Ergebnisse auf eine Weise irreführend sind, die nicht sofort ins Auge springt? Die gefährlichsten Fehler bei der Arbeit mit Daten und KI sind diejenigen, die jedes Meeting und alle Überprüfungen unbeschadet überstehen nur um Monate später ans […]…
-
Veeam ernennt Mika Yamamoto zur Chief Marketing und Customer AI Officer
Veeam hat Mika Yamamoto zur Chief Marketing und Customer AI Officer ernannt. Yamamoto wird die weltweite Marketingorganisation von Veeam leiten und dafür sorgen, dass der Mehrwert des Unternehmens für Kunden deutlich wird, wenn diese Daten und KI unternehmensweit einsetzen. Sie wird zudem das Customer-AI-Framework von Veeam verantworten und sicherstellen, dass jede Kundeninteraktion relevant ist und…

