Tag: ai
-
Bug-Bounty-Programm – Vercel will seine KI-Sandbox hacken lassen
First seen on security-insider.de Jump to article: www.security-insider.de/vercel-bug-bounty-firecracker-microvm-escape-a-efa1474537dc52d883d2e6903fe7578f/
-
Frontier AI tipping the scales toward cyber adversaries
Researchers at Palo Alto Networks’ Unit 42 warn that threat actors are already using AI to accelerate cyberattacks beyond the abilities of modern defenses. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/frontier-ai-tipping-scales-cyber-adversaries/829088/
-
Judge Orders Pentagon to Reverse Anthropic Blacklisting
Court Says DOD’s Designation Was Illegal First Amendment Retaliation. The U.S. federal judge told the Department of Defense to cancel the supply chain designation it levied against Anthropic in a decision giving the artificial intelligence giant almost everything it asked for in a lawsuit against the Pentagon. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/judge-orders-pentagon-to-reverse-anthropic-blacklisting-a-32684
-
Russian-Speaking Hackers Used Cursor AI in Attacks on Seven Companies, Report Says
Russian-speaking hackers used Cursor AI during attacks on corporate networks, reportedly speeding reconnaissance, VPN access and exploitation attempts. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-cursor-ai-hackers-aur0ra-ransomware/
-
Künstliche Intelligenz ist das zweitgrößte Risiko für Menschen am Arbeitsplatz
Vor zwei Jahren belegte KI den vierten Platz unter den von Fachleuten für Security-Awareness erfassten menschlichen Risiken. Heute liegt sie laut dem ‘2026 Security Awareness & Culture Report” des SANS Institutes nur noch hinter Social-Engineering. Der Bericht stellt zudem fest, dass die meisten Programme zur Sensibilisierung für Cybersicherheit trotz steigender Gehälter in der gesamten Branche weiterhin…
-
KnowBe4 wurde in die Constellation-Shortlist für Human-Risk-Management aufgenommen
KnowBe4 wurde in die Constellation-Shortlist für Human-Risk-Management Solutions aufgenommen. Die in diesem Programm aufgeführten Technologieanbieter und Dienstleister erfüllen wichtige Anforderungen an Transformationsinitiativen für Early-Adopter und Fast-Follower-Unternehmen. Die KnowBe4-Plattform bietet Sicherheitsteams alles, was sie benötigen, um Risiken durch Mitarbeiter und KI-Agenten zu managen. KI-gestützte Trainings für Security-Awareness und simulierte Phishing-Angriffe trainieren Teams darin, echte Bedrohungen zu erkennen,…
-
Wie lässt sich die Kraft der KI in Schach halten?
Tags: aiDer Einsatz der KI in Unternehmen geht in zweierlei Hinsicht mit einem Wettlauf gegen die Zeit einher. Die nächste Generation von Frontier-AI-Modellen könnte die Bedrohungslage in den nächsten sechs bis neun Monaten noch einmal dramatisch verändern. Andererseits versuchen Organisationen gerade erst den Produktivitätsvorteil der KI für sich zu erschließen, ohne die Datenintegrität zu gefährden. Richtig…
-
AI Is Accelerating Vulnerability Discovery. Can Defenders Keep Up?
AI is accelerating vulnerability discovery, putting pressure on systems built to enrich, prioritize, and remediate flaws at a slower pace. Action1 explains why defenders increasingly need to correlate multiple intelligence sources and turn vulnerability data into faster remediation. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/ai-is-accelerating-vulnerability-discovery-can-defenders-keep-up/
-
Der T-Rex-Moment der KI: Wenn Sicherheitszäune plötzlich nicht mehr reichen
Frontier AI verändert die Cyber-Bedrohungslage. Unternehmen müssen mit Zero Trust, Segmentierung, KI-Governance und defensiver KI ihre Resilienz stärken. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/der-t-rex-moment-der-ki-wenn-sicherheitszaeune-ploetzlich-nicht-mehr-reichen/a46289/
-
KI-Modelle in der Medizin: Forscher der TU München entdecken hohes Datenschutzrisiko
Tags: aiFirst seen on t3n.de Jump to article: t3n.de/news/ki-modelle-medizin-tu-muenchen-datenschutzrisiko-1758928/
-
KI-Meeting-Notizen: Warum sie oft falsch liegen und wie ihr es vermeidet
Tags: aiFirst seen on t3n.de Jump to article: t3n.de/news/ki-meeting-notizen-fehler-vermeiden-whisper-teams-zoom-1757464/
-
Defining an AI Kill Switch Is Hard, But Necessary
Proposed legislation could mandate that companies be able to throttle, suspend, or shut … down AI agents, but how and when to do that remain open questions. First seen on darkreading.com Jump to article: www.darkreading.com/cybersecurity-operations/defining-ai-kill-switch-hard-but-necessary
-
The Vulnpocalypse Is Repricing the Bug Bounty Economy
The surge of AI-powered vulnerability reports is driving down bug bounty prices, and that could spell trouble for independent researchers. First seen on darkreading.com Jump to article: www.darkreading.com/vulnerabilities-threats/vulnpocalypse-repricing-bug-bounty-economy
-
Palo Alto Networks Researchers Say First Wave of AI-Enabled Attacks Has Begun
Cybersecurity researchers from Palo Alto Networks this week reported that it became apparent that the latest generation of AI models would be able to discover thousands of vulnerabilities in applications. A wave of attacks that are leveraging AI to exploit those vulnerabilities is now underway. Sam Rubin, senior vice president of the Unit 42 cybersecurity..…
-
The AI agent swarm that attacked Hugging Face is a warning for the future
Tags: aiAn army of AI agents was responsible for the Hugging Face incident. What does it mean for the future of AI? First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/the-ai-agent-swarm-that-attacked-hugging-face-is-a-warning-for-the-future/
-
AI Doesn’t Mean the End of Mathematics”, at Least Not Yet
This essay was written with Kasra Rafi, and originally appeared in The Guardian. Earlier this month, about 40 top mathematicians gathered at OpenAI’s offices to discuss the future of their profession. The meeting was off-the-record, but if recent articles by mathematicians are any guide, it was mostly pretty glum. People fear for their jobs, their…
-
AI Governance Has a Control Problem, Not a Policy Problem
Tags: access, ai, business, control, credentials, cybersecurity, data, finance, governance, identity, least-privilege, risk, technology, toolWe’re getting good at writing policies about how AI should be used. Responsible AI principles. Acceptable-use policies. AI risk frameworks. Approval processes. Governance committees. All of these have a place. But there is a harder question that I think organisations need to start asking: What evidence proves those controls actually work? Because AI is changing…
-
The AI Tunes Itself. Until It Doesn’t.
<div cla Two stories broke this week. One was loud, one was quiet, and both say the same thing about trusting autonomous AI. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/the-ai-tunes-itself-until-it-doesnt/
-
Attackers Exploit MCP RCE, Blind Prompt Injection and Memory Credential Theft Against AI Infrastructure
Tags: ai, cloud, credentials, cyber, data-breach, exploit, framework, infrastructure, injection, rce, remote-code-execution, service, theftAttackers are increasingly treating AI infrastructure as a high-value cloud entry point, exploiting exposed Model Context Protocol (MCP) services, agent frameworks, and AI gateways to execute code, validate prompt injection, deploy cryptominers, and steal credentials from process memory. The campaigns show that attackers are no longer using only generic web-server tradecraft; they are tailoring reconnaissance,…
-
700 AI Agents Linked to Hugging Face Security Breach
Around 700 AI agents created by OpenAI participated in the breach of Hugging Face during a cybersecurity evaluation, according to an independent investigation that has revealed the scale of the incident. METR and Redwood Research published the findings after being brought in to independently investigate the July incident and examine the agents’ behaviour, reasoning, and…
-
The Cyber Express Weekly Roundup: Exploited Entra ID Flaw, AI Agent Risks, and Global Cybercrime Crackdown
Tags: ai, cloud, cyber, cybercrime, cybersecurity, exploit, flaw, identity, infrastructure, international, law, risk, technologyThis weekly roundup highlights a broad range of cybersecurity and technology developments affecting cloud identity infrastructure, social media platforms, businesses, digital assets, and international law enforcement. First seen on thecyberexpress.com Jump to article: thecyberexpress.com/weekly-roundup-microsoft-entra-id-ai-risks/
-
Rubrik: Firms Want Joint Agent Identity, Visibility, Recovery
AI Agents Are Raising the Stakes for Identity Resilience and Recovery. Rubrik is betting AI agents will accelerate demand for unified identity, data security and recovery tools as enterprises seek visibility into agent activity, tighter access controls and the ability to reverse malicious or unintended actions. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/rubrik-firms-want-joint-agent-identity-visibility-recovery-a-32683
-
ServiceNow Patches Critical Flaws Enabling Unauthenticated RCE and SQL Injection
ServiceNow has issued security advisories for four vulnerabilities, including critical flaws in its AI platform. These vulnerabilities could allow unauthenticated attackers to execute arbitrary code, manipulate instance data, elevate privileges, or run SQL commands against underlying databases. On August 27, 2026, the company published KB3152242, which covers CVE-2026-6876, CVE-2026-18885, CVE-2026-18886, and CVE-2026-74820. ServiceNow reported that…
-
Researchers Execute Code Inside Fortune 500 Companies via AI Agent llms.txt Files
Security researchers have shown that AI coding agents can be manipulated into installing attacker-controlled packages by following instructions found in organizations’ own llms.txt files. This research emphasizes how agent-readable documentation can transform unverified package references, expired domains, and abandoned cloud subdomains into execution paths within enterprise environments. Researchers Execute Code Inside Fortune 500 Companies The…
-
KI-gestützte Aufklärung: Warum jeder ein potenzielles Ziel für Betrug sein könnte
Für Cyberkriminelle wird es immer günstiger und einfacher, potenzielle Opfer ausfindig zu machen. Hier erfahren Sie, was Sie noch selbst tun können. First seen on welivesecurity.com Jump to article: www.welivesecurity.com/de/privatsphare/ki-gestutzte-aufklarung-warum-jeder-ein-potenzielles-ziel-fur-betrug-sein-konnte/
-
Three CVSS 10.0 ServiceNow Flaws Could Let Unauthenticated Attackers Execute Code and SQL
ServiceNow has released patches for four security flaws impacting the ServiceNow AI Platform, three of them rated 10.0 on the CVSS scoring system and exploitable, in certain circumstances, by an unauthenticated attacker.The company said it deployed a security update to hosted instances and provided the update to its partners and self-hosted customers, which leaves organizations…
-
ServiceNow warns of three max severity security vulnerabilities
ServiceNow released security patches for three new maximum-severity AI Platform vulnerabilities that can be exploited in code injection, SQL injection, and privilege escalation attacks. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/servicenow-warns-of-three-max-severity-security-vulnerabilities/
-
Schatten-KI: Warum KI-Governance nicht bei der Freigabe einer Anwendung enden darf
Shadow AI entsteht längst nicht nur durch unerlaubte KI-Tools. Auch freigegebene Anwendungen können durch Kontowechsel, Agenten und neue Datenpfade zum Risiko werden. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/schatten-ki-warum-ki-governance-nicht-bei-der-freigabe-einer-anwendung-enden-darf/a46282/
-
Cursor: Hacker bei Cyberangriffen mittels KI-Agenten erwischt
Eine russischsprachige Hackergruppe nutzt offenbar Cursor-Agenten für Ransomware-Attacken. Auch ein deutsches Unternehmen soll betroffen sein. First seen on golem.de Jump to article: www.golem.de/news/cursor-hacker-bei-cyberangriffen-mittels-ki-agenten-erwischt-2608-212390.html
-
Window to Tackle Surge in AI-Enabled Cyber Attacks Narrowing, Tech Giants Warn
ge-item”> Window to Tackle Surge in AI-Enabled Cyber Attacks Narrowing, Tech Giants Warn First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/window-ai-attacks-narrowing-tech/

