Tag: ai
-
Ransomware Hacker Uses AI to Plan Attacks and Compromises More Than 20 Organizations
A Russian-speaking affiliate of the Aurora ransomware operation compromised more than 20 organizations across nine countries between April and July 2026, using the AI coding assistant Cursor to plan intrusion activity and Active Directory escalation. The exposed server offered an unusually complete view of a ransomware affiliate’s operational workflow. It contained victim-specific directories, shell history,…
-
AccuKnox Launches AgentZ to Help Enterprises Build, Run, and Govern AI Agents at Scale
Menlo Park, California, USA, August 27th, 2026, CyberNewswire AccuKnox today announced the launch of AgentZ, a platform for building, running, and governing AI agents across teams and workflows. AgentZ brings the agent, its execution environment, tools, workflows, permissions, and governance into a single platform, so organizations can move agents from experiment to production without assembling…
-
AccuKnox Launches AgentZ to Help Enterprises Build, Run, and Govern AI Agents at Scale
Menlo Park, California, USA, August 27th, 2026, CyberNewswire AccuKnox today announced the launch of AgentZ, a platform for building, running, and governing AI agents across teams and workflows. AgentZ brings the agent, its execution environment, tools, workflows, permissions, and governance into a single platform, so organizations can move agents from experiment to production without assembling…
-
GitLab Duo Claude AI Agent Flaw Lets Attackers Execute Arbitrary Commands in CI Pipelines
GitLab has released security updates for both its Community Edition and Enterprise Edition, addressing seven vulnerabilities, including a high-severity flaw in its Duo Claude AI agent. This vulnerability could allow authenticated developers to execute arbitrary commands within a CI (Continuous Integration) context. GitLab Duo Claude AI Agent Flaw The issue, tracked as CVE-2026-18252, arises from…
-
Angriff auf Hugging Face: Brisante neue Details zum KI-Hack von OpenAI enthüllt
KI-Agenten von OpenAI haben im Juli Systeme von Hugging Face infiltriert. Jetzt ist bekannt geworden, was sie dort wollten und wie sie sich koordinierten. First seen on golem.de Jump to article: www.golem.de/news/angriff-auf-hugging-face-brisante-neue-details-zum-ki-hack-von-openai-enthuellt-2608-212350.html
-
Wenn KI ihre Leitplanken verliert: Abliteration und Vektorrisiken werden zur neuen Angriffsfläche
Abliteration, manipulierte Embeddings und RAG-Angriffe schaffen neue Risiken für LLMs und KI-Agenten. Warum Unternehmen mehr Kontrolle über KI brauchen. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/wenn-ki-ihre-leitplanken-verliert-abliteration-und-vektorrisiken-werden-zur-neuen-angriffsflaeche/a46269/
-
AI agents will try every door and find the ones left unlocked
Enterprises are working out how to give AI agents identities of their own, says Ping Identity CEO Andre Durand, just as frontier models start finding vulnerabilities faster than anyone can patch them First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366649703/AI-agents-will-try-every-door-and-find-the-ones-left-unlocked
-
Innovator Coffee EP-42 Powering The AI Compute Boom
AI infrastructure is becoming an energy problem as much as a compute problem. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/innovator-coffee-ep-42-powering-the-ai-compute-boom/
-
Innovator Coffee EP-42 Powering The AI Compute Boom
AI infrastructure is becoming an energy problem as much as a compute problem. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/innovator-coffee-ep-42-powering-the-ai-compute-boom/
-
KI-Governance auf mobilen Endgeräten: Die alten Regeln gelten nicht mehr
KI-Funktionen wandern zunehmend vom Chatfenster in Apps, Agenten und mobile Endgeräte. Für Unternehmen bedeutet das: Klassische KI-Governance greift zu kurz, wenn sie mobile Nutzung, App-Updates, Netzwerkwechsel und rollenbasierte Risiken nicht gezielt berücksichtigt. Management Summary Klassische KI-Governance reicht für mobile Endgeräte nicht mehr aus: KI steckt heute zunehmend in nativen Apps, Updates und Agenten statt nur……
-
AI will not fix a governance problem in your camera estate
Camera systems often outlive the companies that install them. In this Help Net Security interview, Rob Janssens, EMEA Cyber Security Director at Hikvision Europe, discusses … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/27/rob-janssens-hikvision-europe-surveillance-camera-security/
-
OpenAI banned Russian ChatGPT accounts backing covert influence operation
OpenAI banned Russian ChatGPT accounts backing a fake think tank, IBI, that used AI posts and a fake “sovereignty” index to push pro”‘Russia narratives. OpenAI says it has banned a cluster of ChatGPT accounts that likely originated in Russia and were used to support a covert influence operation. The campaign promoted an organisation called the…
-
AnonyMousKIT PhaaS Automates Apple ID, Device Passcode, and Live 2FA Harvesting Across Five Channels
AnonyMousKIT, an AI-enabled Phishing-as-a-Service (PhaaS) platform built to turn stolen Apple devices into monetizable assets. The service automates the collection of an owner’s device passcode, Apple ID credentials and live two-factor authentication (2FA) codes information that can enable criminals to remove Activation Lock and resell a stolen device. Rather than relying on a single phishing…
-
The best human hacking team still out-solved the best AI team
Bring an AI agent to a hacking competition and you would expect to find it propping up the teams who were struggling. In the 2026 Global Cyber Skills Benchmark, agents showed … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/27/ai-ctf-security-teams/
-
CrowdStrike Is ‘Cybersecurity’s Infrastructure Layer’ For AI Era: CEO George Kurtz
CrowdStrike has all the right elements to position its comprehensive Falcon platform as the go-to way to secure the usage of AI and agentic tools going forward, CrowdStrike CEO George Kurtz said Wednesday. First seen on crn.com Jump to article: www.crn.com/news/security/2026/crowdstrike-is-cybersecurity-s-infrastructure-layer-for-ai-era-ceo-george-kurtz
-
Nucleus Security unveils AI engine to enhance exposure management
Tags: aiFirst seen on scworld.com Jump to article: www.scworld.com/brief/nucleus-security-unveils-ai-engine-to-enhance-exposure-management
-
Nvidia NemoClaw vulnerability allows full control of AI agent’s local model server
First seen on scworld.com Jump to article: www.scworld.com/brief/nvidia-nemoclaw-vulnerability-allows-full-control-of-ai-agents-local-model-server
-
Nvidia NemoClaw vulnerability allows full control of AI agent’s local model server
First seen on scworld.com Jump to article: www.scworld.com/brief/nvidia-nemoclaw-vulnerability-allows-full-control-of-ai-agents-local-model-server
-
Linux Foundation to govern TRACE specification for AI agent security
First seen on scworld.com Jump to article: www.scworld.com/brief/linux-foundation-to-govern-trace-specification-for-ai-agent-security
-
Instinct AI assistant faces privacy concerns
First seen on scworld.com Jump to article: www.scworld.com/brief/instinct-ai-assistant-faces-privacy-concerns-amid-praise
-
Alabama attorney general subpoenas OpenAI over AI breach
First seen on scworld.com Jump to article: www.scworld.com/brief/alabama-attorney-general-subpoenas-openai-over-ai-data-breach
-
CrowdStrike Flex Model Adapts Deals to Evolving AI Threats
Enterprises Want Visibility Into What AI Agents Access, Spend and Execute. CrowdStrike added a record $333 million in annual recurring revenue as enterprises expanded Falcon Flex to secure AI agents, control non-human identities and track AI spending while consolidating legacy security tools. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/crowdstrike-flex-model-adapts-deals-to-evolving-ai-threats-a-32665
-
A Reported Log4j RCE Is More Complicated Than It Looks
<div cla TL;DR A recently circulated Log4j finding demonstrates a reproducible bypass of a defense-in-depth deserialization control involving FilteredObjectInputStream. Sonatype does not currently consider this a clear-cut Log4j vulnerability. Apache explicitly warns that deserializing untrusted data is unsafe and treats these filters as hardening measures rather than complete security boundaries. Exploitation requires uncommon, legacy-style application…
-
A Reported Log4j RCE Is More Complicated Than It Looks
<div cla TL;DR A recently circulated Log4j finding demonstrates a reproducible bypass of a defense-in-depth deserialization control involving FilteredObjectInputStream. Sonatype does not currently consider this a clear-cut Log4j vulnerability. Apache explicitly warns that deserializing untrusted data is unsafe and treats these filters as hardening measures rather than complete security boundaries. Exploitation requires uncommon, legacy-style application…
-
A Reported Log4j RCE Is More Complicated Than It Looks
<div cla TL;DR A recently circulated Log4j finding demonstrates a reproducible bypass of a defense-in-depth deserialization control involving FilteredObjectInputStream. Sonatype does not currently consider this a clear-cut Log4j vulnerability. Apache explicitly warns that deserializing untrusted data is unsafe and treats these filters as hardening measures rather than complete security boundaries. Exploitation requires uncommon, legacy-style application…
-
A Reported Log4j RCE Is More Complicated Than It Looks
<div cla TL;DR A recently circulated Log4j finding demonstrates a reproducible bypass of a defense-in-depth deserialization control involving FilteredObjectInputStream. Sonatype does not currently consider this a clear-cut Log4j vulnerability. Apache explicitly warns that deserializing untrusted data is unsafe and treats these filters as hardening measures rather than complete security boundaries. Exploitation requires uncommon, legacy-style application…
-
14 manipulierte npm-Pakete verbreiten Linux-Backdoor RedC2 4.0
Sicherheitsforscher haben manipulierte npm-Pakete entdeckt, die sich als Kalenderwerkzeuge tarnen, jedoch eine KI-gestützte Linux-Hintertür installieren. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/linux-backdoor-npm-pakete
-
OpenAI Agents Coordinated Hugging Face Breach at Scale
Probe Finds 1,200 Agents Communicated Outside Sandboxes, With 700 Targeting Hugging Face. OpenAI and its third-party advisors found new information about the OpenAI-Hugging Face incident, in which artificial intelligence agents hacked the model repository to access internal datasets and steal credentials. OpenAI agents had already begun planning similar breaches as early as May. First seen…
-
Cyber Novice Takes Top Prize in SANS AI Forensics Contest
Find Evil! Contest Winners Show That Evidence Controls Matter More Than AI Speed. SANS challenged participants to turn an experimental AI forensic agent into a trustworthy open-source tool. Entries had to investigate digital evidence autonomously while restricting system access, documenting their actions and correcting unsupported conclusions. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/cyber-novice-takes-top-prize-in-sans-ai-forensics-contest-a-32662
-
What We Still Don’t Know About OpenAI’s Hugging Face Hack
The AI giant acknowledges that it could have done far more to prevent its AI agents from going rogue. But it still fails to explain why it didn’t see this fiasco coming. First seen on wired.com Jump to article: www.wired.com/story/openais-hugging-face-hack-debrief-raises-more-questions-than-it-answers/

