Tag: ai
-
Beware cut-price AI services that read your every word
f someone offered you 90% off the official price to access Claude, the powerful AI model from Anthropic, would you be tempted? It turns out that around 900 people were, and they may be regretting their decision. First seen on fortra.com Jump to article: www.fortra.com/blog/beware-cut-price-ai-services-read-your-every-word
-
AI-Generated Patches Fail Half the Time
Tags: aiA study of more than 6,000 patches found that even working patches can introduce new bugs, break something else, or are open to bypass. First seen on darkreading.com Jump to article: www.darkreading.com/application-security/ai-generated-patches-fail-half-time
-
Déjà Vu? Meta’s AI Escapes Testing Lab in Hacking Joyride
In the span of three weeks, OpenAI, Anthropic, and Meta have all disclosed AI agent sandbox escape events affecting real organizations. First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/meta-ai-escapes-lab-hacking-joyride
-
Chinese AI model Kimi escaped its cybersecurity testing environment, researchers say
In the Kimi test, the sandbox designed to contain the experiment was not properly configured. First seen on techcrunch.com Jump to article: techcrunch.com/2026/08/07/chinese-ai-model-kimi-escaped-its-cybersecurity-testing-environment-researchers-say/
-
Irregular, firm behind AI hacking incidents, won’t say if there were more
A spokesperson said Irregular’s investigation into what happened with Anthropic, OpenAI and Meta’s AI models was ongoing and that they could not “go into further details.” First seen on therecord.media Jump to article: therecord.media/irregular-ai-security-company-incidents
-
Das Geschäft mit kostenlosen KI-Tokens auf Graumärkten
Die beiden Sicherheitsforscher Jeremy Kirk und Mathew Woodyard von Okta haben einen Blick auf das Geschäft mit kostenlosen KI-Token für Frontier-AI-Modelle mittels Graumärkten geworfen. Die beiden fanden mehr als ein halbes Dutzend Anzeigen für solche Dienste in Untergrundforen und auf Messaging-Plattformen, was jedoch nur einen Bruchteil ausmacht. Der Erfolg von KI-Modellen und deren Kosten führt…
-
Offene Türen für KI-Agenten schließen
Diese Woche nun also auch Meta. Inzwischen häufen sich die Berichte von KI-Anbietern, deren KI-Agenten aus den Testumgebungen ausbrechen und andere Software-Anbieter hacken. Um dies zu verhindern, gilt es für alle Unternehmen die Grundlagen der Absicherung vor Angriffen zu verinnerlichen. Diese und andere bekannt gewordene Vorfälle bereiten Sicherheitsteams rund um den Globus Sorgenfalten. Denn die…
-
Agentic AI for Cyber Defenders: What Security Teams Built at Black Hat USA 2026
Tags: ai, automation, conference, control, credentials, cve, cyber, cybersecurity, data, data-breach, defense, detection, exploit, flaw, group, iam, intelligence, ISO-27001, mitigation, network, nvidia, offense, open-source, RedTeam, risk, skills, soc, technology, threat, tool, usa, vulnerabilityAgentic AI armed attackers first, but it also put real building power in defenders’ hands. Here’s what security practitioners built in two days at Black Hat USA 2026, and how the CyberAgents Exchange keeps that work compounding long after the event. Key takeaways Building defensive cybersecurity tooling no longer requires a developer. Agentic tooling drove…
-
Anstieg der Hardware-Preise in Folge KI-getriebener Halbleiter-Nachfrage
First seen on datensicherheit.de Jump to article: www.datensicherheit.de/anstieg-hardware-preise-ki-antrieb-halbleiter-nachfrage
-
Nicht KI ist das größte Risiko, sondern ihre Identitäten
‘Aus einer Testumgebung heraus erlangten KI-Modelle von Anthropic unautorisierten Zugriff auf Echtdaten realer Systeme von Organisationen. Das Eklatante daran: Im Rahmen einer Sicherheitsanalyse zeigte sich, dass über unzureichend abgesicherte Identitäten Zugriffe auf produktive Systeme möglich waren und diese auf diesem Weg kompromittiert wurden. Ein Statement von Elmar Eperiesi-Beck, CEO bei Bare.ID. Zum Vergleich: Noch vor…
-
15 AI Security Lessons From Black Hat and Ai4 2026
Black Hat and Ai4 2026 highlighted gaps in AI agent security, identity controls, software supply chains, monitoring, and incident response. The post 15 AI Security Lessons From Black Hat and Ai4 2026 appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-black-hat-ai4-2026-ai-security-takeaways/
-
AI-Assisted HTTP Terminator Finds Novel HTTP Desync Techniques and Apache Zero-Day
PortSwigger says HTTP Terminator, an artificial intelligence (AI)-assisted research system built by James Kettle, generated and proved new HTTP desynchronization techniques after exploring 30,000 candidate attack vectors.PortSwigger said a separate human-guided discovery cascade also exposed a zero-day in Apache Traffic Server. Kettle said HTTP Terminator tested 30,000 websites where scanning First seen on thehackernews.com Jump…
-
Deemed Export, Deemed Impossible: The Government Discovers That AI Has No Border
Anthropic’s reported AI model shutdown highlights how U.S. export controls could collide with frontier AI, cybersecurity, identity management and global cloud access. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/deemed-export-deemed-impossible-the-government-discovers-that-ai-has-no-border/
-
AI firms know policymakers won’t ‘let you make a Terminator factory,’ DHS official says
Leading AI companies have learned important lessons from recent incidents, the official said, and regulation isn’t necessary to preserve those lessons. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/ai-security-regulation-innovation-us-government-black-hat/827296/
-
The Hugging Face Incident Is a Warning: Every Enterprise Needs AI Agents Watching AI Agents
The Hugging Face incident shows why enterprises must treat autonomous AI agents as privileged identities, with continuous monitoring, behavioral telemetry and strict controls. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/the-hugging-face-incident-is-a-warning-every-enterprise-needs-ai-agents-watching-ai-agents/
-
Who’s Accountable When an AI Agent Fails? – Kovrr
Articles related to cyber risk quantification, cyber risk management, and cyber resilience. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/whos-accountable-when-an-ai-agent-fails-kovrr/
-
BeyondTrust Extends Pathfinder to AI Agents and Other Nonhuman Identities
BeyondTrust is extending its Pathfinder platform to cover AI agents, workloads and other nonhuman identities that can hold or exercise privileged access. The company announced the first wave of native Pathfinder capabilities at Black Hat USA 2026 on Aug. 3. The package includes PathfinderAI and a new MCP Server, AI Agent Security, NHI Governance and..…
-
AI Deepfakes Used to Impersonate OnlyFans Creators in New Scam
Scammers use AI deepfakes to impersonate OnlyFans creators, trick fans into sending money, then disappear after payment. Criminals are building fake identities using AI-generated deepfakes of real OnlyFans creators, luring their followers with promises of live chats, and then disappearing after collecting payment. The scheme runs on social platforms that most people consider harmless, TikTok…
-
Claude in Chrome Exploit Lets Attackers Steal Gmail Codes and Take Over Slack, X, and Claude.ai Accounts
Security researchers have demonstrated an indirect prompt-injection chain affecting Claude in Chrome that can transform a standard request, such as summarizing recent emails, into a cross-account takeover scenario. The research reveals how untrusted content viewed by an AI browser agent can exploit authenticated browser sessions to steal email-delivered verification secrets and compromise accounts on services…
-
On-Behalf-Of vs. Service Account: Choosing an Agent Identity Model
A decision guide for AI agent identity: when to delegate with RFC 8693, when to use a client-credentials service account, and the spec rules that make the choice for you. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/on-behalf-of-vs-service-account-choosing-an-agent-identity-model/
-
Frontier AI Has a Cybersecurity Expertise Problem
First OpenAI’s model went rogue and broke out of testing containment to hack real systems, then Anthropic, and now Meta AI. Do you see a trend? Here is what it means: Although these frontier AI companies employ some of the world’s brightest engineers, architects, and developers, technical excellence is not the same as deep cybersecurity…
-
Check Point Puts AI Traffic Controls Into Its Existing Firewalls
Check Point has launched an AI Network Firewall that brings visibility and enforcement for AI applications, agents and Model Context Protocol traffic into the physical and virtual firewalls organizations already operate. Introduced July 30 ahead of Black Hat USA 2026, the product is delivered through Check Point’s AI Defense Plane and firewall software release R82.20……
-
1Password Adds Privileged Access Controls for Human and AI Identities
1Password has launched Privileged Access, extending its Unified Access platform into privileged access management with controls designed to remove standing permissions from human and AI identities. The July 28 launch came ahead of Black Hat USA 2026, where identity security and AI-agent controls are major themes. 1Password said Privileged Access provisions permissions when they are..…
-
Stress-Testing Your SIEM: Is Your Environment Actually Catching the Bad Guys?
In today’s security landscape, we have more tools than ever (EDR, XDR, SOAR, SIEM) and very little time to learn each one fully. Every tool out there advertises “we use MITRE” and “we are a Gartner top X” and now since 2025 “We have AI!”. All of these are well and good, however they […]…
-
Sophos, OpenAI Partner to Bring Frontier Models to Managed Service Providers
Sophos said it is partnering with OpenAI to bring OpenAI frontier models to managed service providers through Sophos Fusion, the company’s connected cyber defense system. Announced Aug. 6 during Black Hat USA 2026, the partnership is intended to give MSPs a way to deliver AI security services and build offerings around detection, investigation and response……
-
Guardrails, Red Teaming und Laufzeitschutz für die sichere KI-Einführung – Manipulierte Skills machen KI-Agenten zum Einfallstor
First seen on security-insider.de Jump to article: www.security-insider.de/ki-agenten-sicher-einfuehren-guardrails-security-by-design-a-a316ae17b65bc278dc61c961b30dbc29/
-
Europa stark bei der Sicherheit, doch schwach bei der KI-Governance
29 % der europäischen Unternehmen nennen die KI-Regulierung ihre größte Compliance-Sorge, der höchste Wert aller Regionen. Kiteworks hat seinen 2026 Data Security and Compliance Risk: Annual Survey Report veröffentlicht [1]. Die Analyse wurde zum fünften Mal in Folge durchgeführt und basiert auf einer Befragung von 459 Sicherheits-, Compliance-, Risiko- und IT-Fachleuten in zehn Branchen… First…
-
What the first year of EU AI Act transparency enforcement could look like
In this Help Net Security interview, Edwin Weijdema, Field CTO at Veeam, answers questions on Article 50 of the EU AI Act and what the first year of enforcement might bring. … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/07/edwin-weijdema-veeam-eu-ai-act-transparency/
-
Critical Flaws in Claude Code, Gemini CLI, and OpenAI Codex Enable RCE and Supply Chain Attacks
Tags: ai, attack, automation, breach, cyber, flaw, google, openai, rce, remote-code-execution, supply-chain, theft, tool, vulnerabilitySecurity researchers have disclosed a vulnerability affecting AI coding-agent workflows from Anthropic, Google, and OpenAI. Their research highlights how an attacker-controlled issue or zero-privilege input can breach trust boundaries in an agent “harness”, which includes the permissions, tools, sandbox, filesystem, and automation surrounding the model, and result in code execution, secret theft, or workflow compromise.…

