Tag: ai
-
AI Agents Are Now Emailing Me with Their Security Concerns
I received the two emails below earlier in the month. They’re vaguely coherent. I suppose I shouldn’t be surprised that the corpus that AIs are training on contain data suggesting that I am someone to write to with random computer… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/ai-agents-are-now-emailing-me-with-their-security-concerns/
-
How to Evaluate AI SOC Agent Claims: Ask for the Failure Log
Sep 2, 2026 How to Evaluate AI SOC Agent Claims: Ask for the Failure Log Kevin Mata 4 Minute Read How to Evaluate AI SOC Agent Claims: Ask for the Failure Log Every AI SOC vendor demo I’ve seen, including… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/how-to-evaluate-ai-soc-agent-claims-ask-for-the-failure-log/
-
Google, Anthropic, and OpenAI Unveil Cyber AI Models, Safeguards, and Access Programs
Google on Wednesday announced Gemini 3.8 Flash Cyber, which it described as its most capable cybersecurity model, and has made it available to a set of trusted defenders via a new initiative called the Fairwind Program.”The Fairwind Program gives high-priority defenders (like governments, healthcare providers, and telecommunications services) early access to advanced models that help…
-
Shadow AI: What Clients Aren’t Telling Their MSPs
MSPs are expected to understand their clients’ technology environments. They know which endpoints are managed, which applications are business-critical, which systems require patching or maintenance, where sensitive data resides and who has access to it. Increasingly, however, critical technology decisions… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/shadow-ai-what-clients-arent-telling-their-msps/
-
Shadow AI: What Clients Aren’t Telling Their MSPs
MSPs are expected to understand their clients’ technology environments. They know which endpoints are managed, which applications are business-critical, which systems require patching or maintenance, where sensitive data resides and who has access to it. Increasingly, however, critical technology decisions… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/shadow-ai-what-clients-arent-telling-their-msps/
-
Hackers Steal Metr API Key, Burn $600K in AI Credits
Separate Database Flaw Could Have Exposed Sensitive Model Data. Attackers in March stole a Metr API key and used it for three weeks to consume about $600,000 worth of AI model credits. In a separate May campaign, hackers probed a public Metr service with a bug that could have exposed unpublished and sensitive model data.…
-
Wiz Finds Active LiteLLM and MCP Attacks Targeting AI Infrastructure
Wiz observed active attacks on LiteLLM and MCP servers, including credential theft, cryptomining, command execution, and prompt injection. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/news/news-litellm-mcp-server-attacks/
-
Black Duck brings AI-powered vulnerability scanning into Claude with new Signal integration
Application security vendor Black Duck has launched its Signal vulnerability scanning engine as an MCP server in the Claude Directory, giving developers using Anthropic’s Claude Desktop a way to check code for security flaws without switching tools. The integration is built on the Model Context Protocol (MCP), the open standard that lets AI assistants like…
-
OpenAI Reveals Astra, Its First AI Model to Reach ‘Critical’ Cybersecurity Risk Threshold
OpenAI announced Tuesday that its upcoming artificial intelligence (AI) model, codenamed Astra, is the company’s first to reach the highest threat level under its internal risk framework, triggering an initial development pause to implement stricter safeguards before its public rollout. Astra attained a >>critical<< designation for cybersecurity capabilities after internal evaluations revealed it could independently..…
-
Find, score and scan every AI model across code and cloud FireTail Blog
Sep 02, 2026 – Ayush Sethi – Find, score and scan every AI model across code and cloudEvery model running from your code to your cloud is your risk, whether or not anyone told you it was there. FireTail finds… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/find-score-and-scan-every-ai-model-across-code-and-cloud-firetail-blog/
-
JFrog bringt SoftwareChain-Kontrolle bis an den Netzwerkrand
JFrog bringt Software-Supply-Chain-Security an den Netzwerkrand und kontrolliert Open-Source-Pakete von Entwicklern und KI-Agenten über SASE-Plattformen. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/jfrog-bringt-software-supply-chain-kontrolle-bis-an-den-netzwerkrand/a46307/
-
Palo Alto Acquires Console to Expand Cortex Agentic Security
Palo Alto Networks announced it has acquired the AI automation startup Console to expand what AI agents can do inside its Cortex security platform. Financial terms of the deal were not disclosed. The company said it plans to bring Console’s technology into Cortex to help security teams investigate activity, prioritize work and take action across..…
-
Frontier AI helps exploit flaws in tests using key industrial devices
A report showed that Claude could help hackers develop attack strategies targeting PLCs used by water utilities and other industries. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/frontier-ai-exploit-flaws-water-PLCs-industrial-devices/829307/
-
HiddenLayer nabs $100M as enterprises rush to secure their AI deployments
HiddenLayer has raised a $100M Series B from Delta-v Capital, Ten Eleven Ventures, Morgan Stanley, Microsoft’s M12, Booz Allen Hamilton, and others. First seen on techcrunch.com Jump to article: techcrunch.com/2026/09/02/hiddenlayer-nabs-100m-as-enterprises-rush-to-secure-their-ai-deployments/
-
Capsule Security Partners with NVIDIA to Secure AI Agents
Capsule Security and NVIDIA today revealed they have teamed up to prevent artificial intelligence (AI) agents from going rogue by evaluating an agent’s intent in real time before an action is executed and then applying appropriate controls. Based on Nemotron, a small language model (SLM) developed by NVIDIA, Capsule Security claims it has achieved 98%..…
-
Malicious .git Configs Can Make Claude, Codex, Cursor, and Other AI Agents Run Attacker Code
Manifold Security has disclosed eight security flaws across seven command-line AI coding agents in which a repository’s own Git configuration names a command that the agent runs on the developer’s machine, four of them still unpatched at publication.The command executes as the user, outside the agent’s sandbox and without an approval prompt, and exploitation requires…
-
OpenMatter Network Expands Platform with New Capabilities for Secure AI, Computing and Data Collaboration
Melbourne, Florida, 2nd September 2026, CyberNewswire First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/openmatter-network-expands-platform-with-new-capabilities-for-secure-ai-computing-and-data-collaboration/
-
AI-basierte Security-Operations-Center erkennen Ransomware nicht von selbst
Wie viele Analysten braucht das SOC-Team noch angesichts des Einzugs von künstlicher Intelligenz? Die Frage suggeriert die Antwort: Das AI-basierte Security-Operations-Center erfordert weniger Menschen. Leider sind die Unternehmen, die diese Frage stellen, meist genau diejenigen, die ihre Telemetrielücken, ihre ungesicherten Endgeräte oder ihre unzureichende MFA-Abdeckung noch nicht angegangen sind. Sie stellen sich vor, dass künstliche…
-
Download: The Agentic Software Development Guide
AI makes it easy to ship more code. It does not make that code easier to trust. Most teams don’t fail because their developers can’t use AI. They fail because the dev’s job … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/02/download-the-agentic-software-development-guide/
-
Claude AI Develops Working RCE Exploit Against WAGO PLC With Researcher Assistance
Researchers have demonstrated that Anthropic’s Claude AI can assist in porting a remote code execution exploit between vulnerable models of WAGO programmable logic controllers (PLCs). However, this process requires significant human guidance, lengthy analysis sessions, and more than $500 in API usage. The experiment focused on CVE-2021-31886, a pre-authentication buffer overflow flaw in the Nucleus…
-
Critical Langflow Vulnerability Exploited as Attacks on AI Platform Rise
The attacks targeting CVE-2026-0768 are the latest threat against the low-code AI development platform, which is receiving more attention from adversaries this year. First seen on darkreading.com Jump to article: www.darkreading.com/vulnerabilities-threats/critical-langflow-flaw-exploited-attacks-rise
-
Flamingo Looks To Build Autonomous MSPs With Open Source, AI And $4.5M In New Funding
Flamingo expects its new $4.5 million seed round will help advance an AI-native, open-source IT security platform to help MSPs automate service delivery and support. First seen on crn.com Jump to article: www.crn.com/news/security/2026/flamingo-looks-to-build-autonomous-msps-with-open-source-ai-and-4-5m-in-new-funding
-
$536 and 8 Hours: AI Learns to Attack a Different PLC
Experts got Claude to port a PLC exploit, but it cost $536 and 8 hours, and a later AI-generated payload accidentally destroyed the hardware. Forescout researchers just answered a question that’s been hanging over industrial security for a while: can AI actually port a working exploit from one PLC to a different model with no…
-
Palo Alto Networks Acquires Console to Add Agentic AI Workflows to Cortex
Palo Alto Networks has acquired Console, an AI-native platform designed to enable agentic workflows across enterprise operations. This acquisition expands the autonomous capabilities of Palo Alto Networks’ Cortex security operations platform. Announced on September 1, 2026, the deal aims to help security teams investigate signals, prioritize tasks, and respond to operational issues at machine speed.…
-
How to Secure Enterprise AI: From Adoption to Incident Readiness
The debate about whether AI delivers business value is over. The challenge now is implementing it at scale and securely across every function while meeting board-level pressure to move fast. Organizations must focus on adopting AI at business speed without losing control of cyber risk. Download the full eBook here. The Business Reality In Sygnia’s…
-
Iran-linked APT Mirage Kitten Uses Fake Job Tests to Spread Malware
Mirage Kitten used fake LinkedIn coding tests to spread NodeRabbit and PollCat, even banning AI tools that could have spotted the malware. Iran-linked Mirage Kitten hackers just found a genuinely clever way to make their own malware harder to detect: telling job candidates not to use AI tools while reviewing the trojanized code they were…
-
KI agierte eigenständig – OpenAI stärkt nach KI-Hacks Schutzvorkehrungen bei Tests
First seen on security-insider.de Jump to article: www.security-insider.de/openai-verschaerft-ki-sicherheit-nach-test-hack-a-bfdcd02eb24ed2593ae4a63d0f725c52/
-
Claude Fable 5.1 und Mythos 5.1 – Neue KI-Modelle sollen vor allem Forschung verbessern
Tags: aiMit Claude Fable 5.1 und Mythos 5.1 will Anthropic Fortschritte bei Programmierung, Wissensarbeit und lang laufenden Aufgaben erzielen. First seen on computerbase.de Jump to article: www.computerbase.de/news/apps/claude-fable-5-1-und-mythos-5-1-neue-ki-modelle-sollen-vor-allem-forschung-verbessern.99188
-
Hackers Target Langflow in CVE-2026-0768 Attacks
Hackers are exploiting a critical Langflow flaw that lets unauthenticated attackers remotely execute Python code on vulnerable systems. Hackers have started exploiting a critical vulnerability, tracked as CVE-2026-0768 (CVSS score of 9.8), in the AI-focused low-code platform Langflow. The flaw affects the code validator in Langflow’s custom component editor, it impacts all Langflow versions up…
-
Palo Alto: Security Debt Exposes Firms to AI-Powered Attacks
CEO Nikesh Arora Says Years of Deferred Upgrades Could Enable Major Breaches. Palo Alto Networks CEO Nikesh Arora warned that roughly $1 trillion in accumulated cybersecurity technical debt could leave enterprises vulnerable to AI-enabled threats as model proliferation expands attack surfaces faster than companies can modernize defenses. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/palo-alto-security-debt-exposes-firms-to-ai-powered-attacks-a-32719

