Tag: ai
-
‘Dangerous’ vulnerability in GitLab Ultimate Enterprise Edition
Tags: access, ai, attack, authentication, best-practice, ceo, communications, control, cve, cvss, data, flaw, github, gitlab, incident response, injection, malicious, mfa, password, risk, service, vulnerabilityCVE-2025-2254, a cross-site scripting issue, which, under certain conditions, could allow an attacker to act like a legitimate user by injecting a malicious script into the snippet viewer.All GitLab CE/EE versions from 17.9 before 17.10.8, 17.11 before 17.11.4, and 18.0 before 18.0.2 are impacted;CVE-2025-0673, a vulnerability that can cause a denial of service by triggering…
-
First Known Zero-Click AI Exploit: Microsoft 365 Copilot’s ‘EchoLeak’ Flaw
Security researchers uncovered “EchoLeak,” a zero-click flaw in Microsoft 365 Copilot, exposing sensitive data without user action. Microsoft has mitigated the vulnerability. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-microsoft-365-copilot-flaw-echoleak/
-
Zero-Click Flaw in Microsoft Copilot Illustrates AI Agent, RAG Risks
Aim Security researchers found a zero-click vulnerability in Microsoft 365 Copilot that could have been exploited to have AI tools like RAG and AI agents hand over sensitive corporate data to attackers simply by issuing a request for the information in a specially worded email. Microsoft fixed the security flaw. First seen on securityboulevard.com Jump…
-
Identiverse 2025: Trust, Delegation, and the Era of Continuous Identity
Identiverse 2025 exposed the urgent need for NHI governance. From AI agents to orphaned credentials, NHIs and their sprawling secrets are today’s most overlooked risks. First seen on securityboulevard.com Jump to article: securityboulevard.com/2025/06/identiverse-2025-trust-delegation-and-the-era-of-continuous-identity/
-
[Webinar] Securing AI-driven applications with DAST
Join us for a live webinar with application security experts and Escape clients – Seth Kirschner (DoubleVerify), Nathan Byrd (Applied Systems), Nick Semyonov (PandaDoc), as they break down how their teams are rethinking testing strategies to keep up with AI-influenced codebases. First seen on securityboulevard.com Jump to article: securityboulevard.com/2025/06/webinar-securing-ai-driven-applications-with-dast/
-
10.000 Blackwell-GPUs – Nvidia baut deutsche KI-Fabrik mit der Telekom
Die für Deutschland von Nvidia geplante KI-Fabrik mit 10.000 GPUs wird bis 2026 in Kooperation mit der Deutschen Telekom aufgebaut. First seen on computerbase.de Jump to article: www.computerbase.de/news/wirtschaft/10-000-blackwell-gpus-nvidia-baut-deutsche-ki-fabrik-mit-der-telekom.93142
-
ISMG Editors: Gartner Security & Risk Management Summit Recap
Security Leadership in Focus – From AI Risks to Cloud Responsibility. AI fragmentation, non-human identities and nation-state threats dominated conversations at the Gartner Security & Risk Management Summit. ISMG editors discuss how the event stood out for its vendor-neutral focus and strategic discussions tailored for senior security decision-makers. First seen on govinfosecurity.com Jump to article:…
-
First Known ‘Zero-Click’ AI Exploit: Microsoft 365 Copilot’s EchoLeak Flaw
Security researchers uncovered “EchoLeak,” a zero-click flaw in Microsoft 365 Copilot, exposing sensitive data without user action. Microsoft has mitigated the vulnerability. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-microsoft-365-copilot-flaw-echoleak/
-
Arsen Launches AI-Powered Vishing Simulation to Help Organizations Combat Voice Phishing at Scale
Paris, France, 13th June 2025, CyberNewsWire First seen on securityboulevard.com Jump to article: securityboulevard.com/2025/06/arsen-launches-ai-powered-vishing-simulation-to-help-organizations-combat-voice-phishing-at-scale/
-
Arsen Launches AI-Powered Vishing Simulation to Help Organizations Combat Voice Phishing at Scale
Paris, France, 13th June 2025, CyberNewsWire First seen on hackread.com Jump to article: hackread.com/arsen-launches-ai-powered-vishing-simulation-to-help-organizations-combat-voice-phishing-at-scale/
-
Datenschutz und KI-Nutzung – Kyndryl und Microsoft bündeln Kräfte für mehr Datensicherheit
First seen on security-insider.de Jump to article: www.security-insider.de/kyndryl-und-microsoft-buendeln-kraefte-fuer-mehr-datensicherheit-a-9c0a648e517da3e01b1f333cf800b539/
-
Datadog AI agent observability, security seek to boost trust
As AI agents mature, new tools aim to bolster their reliability and security with fresh visibility into automation workflows and more detailed troubleshooting. First seen on techtarget.com Jump to article: www.techtarget.com/searchitoperations/news/366625992/Datadog-AI-agent-observability-security-seek-to-boost-trust
-
Policymakers assess nuclear energy for AI data centers
Big tech vendors are recognizing the energy demands of their AI services, causing them to make significant energy investments. First seen on techtarget.com Jump to article: www.techtarget.com/searchcio/news/366625953/Policymakers-assess-nuclear-energy-for-AI-data-centers
-
Malware attack disguises itself as DeepSeek installer
Cybercriminals are exploiting the growing interest in open source AI models by disguising malware as a legitimate installer for DeepSeek. First seen on grahamcluley.com Jump to article: grahamcluley.com/malware-attack-disguises-itself-as-deepseek-installer/
-
EchoLeak: Erste AI 0-Click-Sicherheitslücke in Microsoft Copilot
Sicherheitsforscher sind auf die erste Zero-Click-Schwachstelle in einer KI-Anwendung gestoßen. Wenig überraschend für mich betrifft dies Microsoft 365 Copilot. Angreifer könnten Microsoft 365 Copilot über diese, als EchoLeak bezeichnete, Schwachstelle zu einer Datenexfiltration zwingen. Microsoft “stülpt” ja allen Office-Anwendern den … First seen on borncity.com Jump to article: www.borncity.com/blog/2025/06/13/echoleak-erste-ai-0-click-sicherheitsluecke-in-microsoft-copilot/
-
Microsoft 365 Copilot: New Zero-Click AI Vulnerability Allows Corporate Data Theft
Researchers have found a flaw in Microsoft 365 Copilot that allows the exfiltration of sensitive corporate data with a simple email First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/microsoft-365-copilot-zeroclick-ai/
-
Check Point kommentiert EU-Förderung zu mehr Cybersicherheit im Gesundheitswesen
Europa hat nun die Chance, eine Führungsrolle bei vertrauenswürdiger, transparenter KI für Cyber-Sicherheit zu übernehmen. Dazu muss der Schwerpunkt auf der Beschleunigung bewährter Lösungen, der Förderung sektorübergreifender Partnerschaften und der Entwicklung der nächsten Generation von Cyber-Talenten liegen. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/check-point-kommentiert-eu-foerderung-zu-mehr-cybersicherheit-im-gesundheitswesen/a41130/
-
Major Outage Hits Google Cloud and Linked Cloudflare Services, Thousands Affected
Tags: ai, authentication, cloud, cyber, google, infrastructure, Internet, monitoring, service, vulnerabilityOn June 12, 2025, concurrent infrastructure failures at Cloudflare and Google caused widespread service disruptions, highlighting vulnerabilities in modern cloud dependencies. The outages impacted critical services ranging from authentication systems to AI platforms, underscoring the fragility of interconnected internet ecosystems. Cloudflare Outage: Cloudflare’s outage began at 17:52 UTC when internal monitoring detected failures in device…
-
TokenBreak Exploit Tricks AI Models Using Minimal Input Changes
HiddenLayer’s security research team has uncovered TokenBreak, a novel attack technique that bypasses AI text classification models by exploiting tokenization strategies. This vulnerability affects models designed to detect malicious inputs like prompt injection, spam, and toxic content, leaving protected systems exposed to attacks they were meant to prevent. Technical Breakdown of TokenBreak According to the…
-
What CISOs need to know about agentic AI
GenAI has been the star of the show lately. Tools like ChatGPT impressed everyone with how well they can summarize, write, and respond. But something new is gaining ground: … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2025/06/13/ciso-agentic-ai/
-
Guardian Agents werden bis 2030 10 bis 15 % des Marktes für agentenbasierte KI einnehmen
Guardian Agents gewährleisten die Zuverlässigkeit und Sicherheit von KI-Prozessen besonders im Hinblick auf steigende Risiken. Laut Einschätzung von Gartner werden Guardian-Agent-Technologien bis zum Jahr 2030 mindestens 10 bis 15 % des Marktes für agentenbasierte Künstliche Intelligenz ausmachen. Guardian Agents sind KI-basierte Technologien, die speziell für vertrauenswürdige und sichere Interaktionen mit KI-Systemen entwickelt wurden. Sie… First…
-
Why hybrid deployment models are crucial for modern secure AI agent architectures
As enterprises embrace AI agents to automate decisions and actions across business workflows, a new architectural requirement is emerging, one that legacy IAM systems (even SaaS IAM!) were never built to handle. The reality is simple: AI agents don’t live in just one place. They operate across clouds, on-premises infrastructure, edge devices, and sometimes… First…
-
OffensiveCon25 Keynote: Automating Your Job? The Future Of AI and Exploit Development
Author/Presenter: Perri Adams Our sincere appreciation to OffensiveCon by Binary Gecko, and the Presenters/Authors for publishing their outstanding OffensiveCon 2025 video content. Originating from the conference’s events located at the Hilton Berlin; and via the organizations YouTube channel. Thanks and a Tip O’ The Hat to Verification Labs :: Penetration Testing Specialists :: Trey Blalock…
-
Tamnoon Launches Managed CDR and AI Agent to Streamline Cloud Security Response Across Multi-Cloud Environments
First seen on scworld.com Jump to article: www.scworld.com/news/tamnoon-launches-managed-cdr-and-ai-agent-to-streamline-cloud-security-response-across-multi-cloud-environments
-
Kyndryl and Databricks Partner to Fast-Track AI and Data Modernization
First seen on scworld.com Jump to article: www.scworld.com/news/kyndryl-and-databricks-partner-to-fast-track-ai-and-data-modernization
-
Veza Expands Identity Platform to Secure Non-Human Identities Across Hybrid and AI-Driven Environments
First seen on scworld.com Jump to article: www.scworld.com/news/veza-expands-identity-platform-to-secure-non-human-identities-across-hybrid-and-ai-driven-environments
-
Making AI Work for Everyone: The Channel Partner’s Guide to Accessible AI
First seen on scworld.com Jump to article: www.scworld.com/perspective/making-ai-work-for-everyone-the-channel-partners-guide-to-accessible-ai
-
Why AI Needs Stronger Laws, Not Just Smarter Tech
Andrea Isoni of AI Technologies on Certifications, Deepfakes and ISO 42001. AI misuse – from deepfakes to cyber incidents – continues to outpace regulation. Andrea Isoni, chief AI officer at AI Technologies discusses why stronger cyber laws, certification frameworks like ISO 42001 and risk-based prioritization are necessary to manage AI risks safely and compliantly. First…
-
Will New AI Browser Dia Redefine How We Use the Web?
Dia, a new AI browser from the makers of Arc, is available in beta on macOS, and only to existing Arc members or individuals they’ve invited. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-arc-dia-the-browser-company/

