Tag: ai
-
A Reported Log4j RCE Is More Complicated Than It Looks
<div cla TL;DR A recently circulated Log4j finding demonstrates a reproducible bypass of a defense-in-depth deserialization control involving FilteredObjectInputStream. Sonatype does not currently consider this a clear-cut Log4j vulnerability. Apache explicitly warns that deserializing untrusted data is unsafe and treats these filters as hardening measures rather than complete security boundaries. Exploitation requires uncommon, legacy-style application…
-
CrowdStrike Is ‘Cybersecurity’s Infrastructure Layer’ For AI Era: CEO George Kurtz
CrowdStrike has all the right elements to position its comprehensive Falcon platform as the go-to way to secure the usage of AI and agentic tools going forward, CrowdStrike CEO George Kurtz said Wednesday. First seen on crn.com Jump to article: www.crn.com/news/security/2026/crowdstrike-is-cybersecurity-s-infrastructure-layer-for-ai-era-ceo-george-kurtz
-
Nucleus Security unveils AI engine to enhance exposure management
Tags: aiFirst seen on scworld.com Jump to article: www.scworld.com/brief/nucleus-security-unveils-ai-engine-to-enhance-exposure-management
-
Nvidia NemoClaw vulnerability allows full control of AI agent’s local model server
First seen on scworld.com Jump to article: www.scworld.com/brief/nvidia-nemoclaw-vulnerability-allows-full-control-of-ai-agents-local-model-server
-
Nvidia NemoClaw vulnerability allows full control of AI agent’s local model server
First seen on scworld.com Jump to article: www.scworld.com/brief/nvidia-nemoclaw-vulnerability-allows-full-control-of-ai-agents-local-model-server
-
Linux Foundation to govern TRACE specification for AI agent security
First seen on scworld.com Jump to article: www.scworld.com/brief/linux-foundation-to-govern-trace-specification-for-ai-agent-security
-
14 manipulierte npm-Pakete verbreiten Linux-Backdoor RedC2 4.0
Sicherheitsforscher haben manipulierte npm-Pakete entdeckt, die sich als Kalenderwerkzeuge tarnen, jedoch eine KI-gestützte Linux-Hintertür installieren. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/linux-backdoor-npm-pakete
-
OpenAI Agents Coordinated Hugging Face Breach at Scale
Probe Finds 1,200 Agents Communicated Outside Sandboxes, With 700 Targeting Hugging Face. OpenAI and its third-party advisors found new information about the OpenAI-Hugging Face incident, in which artificial intelligence agents hacked the model repository to access internal datasets and steal credentials. OpenAI agents had already begun planning similar breaches as early as May. First seen…
-
Cyber Novice Takes Top Prize in SANS AI Forensics Contest
Find Evil! Contest Winners Show That Evidence Controls Matter More Than AI Speed. SANS challenged participants to turn an experimental AI forensic agent into a trustworthy open-source tool. Entries had to investigate digital evidence autonomously while restricting system access, documenting their actions and correcting unsupported conclusions. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/cyber-novice-takes-top-prize-in-sans-ai-forensics-contest-a-32662
-
What We Still Don’t Know About OpenAI’s Hugging Face Hack
The AI giant acknowledges that it could have done far more to prevent its AI agents from going rogue. But it still fails to explain why it didn’t see this fiasco coming. First seen on wired.com Jump to article: www.wired.com/story/openais-hugging-face-hack-debrief-raises-more-questions-than-it-answers/
-
Okta COO: Partners Helping To Drive Identity Security Surge Amid Agentic Shift
Okta partners played a role in each of the vendor’s 20 largest deals during its latest quarter”, underscoring the massive opportunity for solution and service providers across both core identity security and emerging areas such as securing AI agents, Okta President and COO Eric Kelleher tells CRN. First seen on crn.com Jump to article: www.crn.com/news/security/2026/okta-coo-partners-helping-to-drive-identity-security-surge-amid-agentic-shift
-
Ransomware surges as criminals deploy AI tools
Research from NCC Group and a partnership between Axis Communications and Palo Alton underline how artificial intelligence is impacting customers First seen on computerweekly.com Jump to article: www.computerweekly.com/microscope/news/366649752/Ransomware-surges-as-criminals-deploy-AI-tools
-
OpenAI’s Hugging Face Hack Debrief Raises More Questions Than It Answers
The AI giant acknowledges that it could have done far more to prevent its AI agents from going rogue. But it still fails to explain why it didn’t see this fiasco coming. First seen on wired.com Jump to article: www.wired.com/story/openais-hugging-face-hack-debrief-raises-more-questions-than-it-answers/
-
Stop Building a 2003 SOC with AI: Local Context, Failure Modes and Your Path (Part 3)
In Part 1 of this series, we dumped a pile of uncomfortable questions on you and promised answers. In Part 2 of the series, we talked about why 1990s-2000s alert triage must die. The core thesis, if you recall: if you add AI agents into a legacy, swivel-chair SOC structure, you are essentially building a robotic…
-
Secrets Management in the Age of AI: Why Vaults Fall Short and What Replaces Them
Machine identities now outnumber human ones 109 to 1, and four 2026 acquisitions worth $26.6B prove vaults can’t keep up. What ephemeral secrets and workload identity replace them with. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/secrets-management-in-the-age-of-ai-why-vaults-fall-short-and-what-replaces-them/
-
From Forward Deployed Engineers to AI Refactoring: How ISHIR Modernizes Legacy Systems Faster
Your legacy system is not a technology problem. It is a business decision you keep postponing because the alternative feels riskier than the status quo….Read More First seen on securityboulevard.com Jump to article: https://securityboulevard.com/2026/08/from-forward-deployed-engineers-to-ai-refactoring-how-ishir-modernizes-legacy-systems-faster/
-
Mate Unveils Gamebooks for Trusted Agentic Investigations
Tags: aiMate Security has introduced Gamebooks, a new layer in its platform that gives AI agents structured investigation procedures to follow while they reason, pivot, and act on live security events. The launch, first reported by SiliconANGLE, represents an architectural shift in how security investigations are designed and carried out, and Mate Security’s Gamebooks are generally…The…
-
The Toolchain Is the Target: Securing Software Development in the Agentic Era
JFrog finds AI development tools are expanding the software supply chain and creating new attack paths for organizations. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/the-toolchain-is-the-target-securing-software-development-in-the-agentic-era/
-
AnonyMousKIT phishing-as-a-service uses AI voice calls to steal iPhone passcodes
A phishing-as-a-service (PhaaS) platform called AnonyMousKIT is automating the theft of Apple ID credentials needed to remove Activation Lock from stolen iPhones, SOCRadar … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/26/anonymouskit-phishing-stolen-iphone/
-
Russia-Linked Operators Used ChatGPT to Run a Secretive Online Influence Campaign
OpenAI has disrupted a covert influence operation that used ChatGPT to promote a purported Israeli think tank, spread Russia-favorable narratives, and manufacture the appearance of academic legitimacy across major social platforms. The company banned a cluster of accounts it assessed as very likely originating in Russia after tracing AI-generated posts to a broader network built…
-
Four in Five AI Tools Run with No IT Oversight, New Research Finds
Reco report reveals growing shadow AI problem and surge in vulnerability disclosures First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/four-in-five-ai-tools-no-it/
-
(g+) Opinion Business Insight: AI has opened up big holes in cyber security
It is too late to stop the technology being used as a damaging weapon, so great investment in defences is urgently needed First seen on golem.de Jump to article: www.golem.de/news/opinion-business-insight-ai-has-opened-up-big-holes-in-cyber-security-2608-212328.html
-
Your Coding Assistant Is Shipping Security Vulnerabilities
Tags: access, ai, api, application-security, authentication, compliance, credentials, email, endpoint, framework, github, governance, LLM, programming, risk, service, tool, vulnerabilityYour Coding Assistant Is Shipping Security Vulnerabilities. Here’s How to Fix That. AI coding assistants have gotten remarkably good at writing functional code. Syntax correctness rates are approaching 100%. Developers are more productive than ever. And yet the security picture tells a very different story. Veracode recently evaluated over 150 large language models across vendors…
-
Warum KI-Agenten gerade zur neuen Insider-Bedrohung werden
Sprechen Unternehmen von digitalen Identitäten, meinen sie damit schon lange nicht mehr nur ihre menschlichen Angestellten, ihre Dienstkonten, Automatisierungsplattformen und Bots. Denn vor knapp zwei Jahren ist eine neue, ganz andere Art von digitaler Identität hinzugekommen: KI-Agenten. Anders als traditionelle maschinelle Identitäten folgen KI-Agenten keiner starren Befehlsabfolge. Sie operieren eigenständig, autonom. Sie können planen, Tools…
-
Fake Claude Desktop Installer Deploys SectopRAT Using DLL Sideloading and Blockchain C2
A fake Claude Desktop installer campaign is using Bing malvertising to impersonate trusted Claude. ai-hosted content, DLL sideloading, and blockchain-based command-and-control to deploy the SectopRAT remote-access trojan. CyberProof researchers said an agent-led hunt scoped the full intrusion chain across endpoint telemetry in about ten minutes, turning a single suspicious scheduled task into a confirmed multi-stage…
-
Imagine the SOC Without a Queue: From Alert Backlog to AI Hypothesis Engine
The SOC we’ve always known was built around a model that guarantees most of the alert queue will never receive analyst review. There’s never time. In a traditional SOC, the typical progression follows a well-known pattern: an alert arrives; a detection engine assigns a severity score. The issue then waits for a human to decide…
-
Agentische KI in Unternehmen: Wie Governance und EU AI Act kontrollierte Autonomie ermöglichen
Agentische KI verspricht deutschen Unternehmen den nächsten Produktivitätsschub stellt aber klassische Governance-Modelle vor neue Belastungsproben. Wer autonome Systeme in Geschäftsprozesse integriert, muss Kontrolle, Nachvollziehbarkeit und regulatorische Anforderungen technisch verankern, statt sie nur organisatorisch zu beschreiben. Management Summary KI ist in deutschen Unternehmen angekommen; agentische KI steht jedoch erst am Anfang der breiten Skalierung. Der… First…
-
Cyberangriff auf KI- und Daten-Unternehmen
Jüngst wurde das das KI- und Daten-Unternehmen Alation Ziel eines Cyberangriffs. Das Unternehmen, dessen Software von etwa die Hälfte der Fortune-1000-Unternehmen genutzt wird, untersucht den Vorfall derzeit. Er reiht sich ein in einen ansteigenden Trend, bei dem Hacker es auf Anbieter abgesehen haben, die große Mengen an Unternehmensdaten verwahren und verwalten. Ein Kommentar von Raymond…
-
Der Insider der Zukunft ist kein Mensch: Warum KI-Agenten zum Sicherheitsrisiko werden
Tags: aiKI-Agenten handeln autonom und besitzen häufig weitreichende Rechte. Warum sie zur neuen Insider-Bedrohung werden und wie Unternehmen reagieren sollten. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/der-insider-der-zukunft-ist-kein-mensch-warum-ki-agenten-zum-sicherheitsrisiko-werden/a46264/
-
Being Right Is the Easy Part
Tags: ai, banking, business, cloud, compliance, container, control, country, crypto, cryptography, data, email, encryption, endpoint, fraud, ibm, intelligence, jobs, strategy, technologyHome Blog <!– PKWARE Blog, "Being Right Is the Easy Part" – STYLES Design tokens + .pk-article class rules. Paste into a Code Block (or move the token layer to the child theme and keep only the .pk-article rules here). tags included. –> Guest Perspective Being Right Is the Easy Part The question I asked…

