Tag: ai
-
Choose your fighter: Balancing competing requirements to select models for your AI SOC
Selecting a model for your security operations center (SOC) and digital forensics and incident response (DFIR) tasks is important, but selecting the best one is more involved than you might think. Here’s how to choose. First seen on blog.talosintelligence.com Jump to article: blog.talosintelligence.com/choose-your-fighter-balancing-competing-requirements-to-select-models-for-your-ai-soc/
-
OpenAI Bans Russian ChatGPT Accounts Used to Run Influence Operation
OpenAI on Tuesday said it banned a cluster of Russian ChatGPT accounts that used VPNs to bypass access restrictions and run an influence operation, which relied on its artificial intelligence (AI) tool to generate social media posts and comments that were shared on Substack, Telegram, X, Facebook and LinkedIn.The accounts “were being used to promote…
-
NVIDIA NemoClaw Vulnerability Lets Attackers Hijack AI Agents via DNS Rebinding
A critical vulnerability in NVIDIA NemoClaw, tracked as CVE-2026-65105, could enable attackers to gain persistent control of locally deployed AI agents through a single visit to a malicious website. Researchers Elad Luz and Ofek Itach from Oasis Security discovered that NemoClaw’s local Ollama configuration exposes an unauthenticated API, making it susceptible to DNS rebinding attacks.…
-
Linux Foundation Introduces TRACE Standard for AI Runtime Evidence
This new open standard offers hardware-attested runtime and compliance evidence for AI agents First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/linux-foundation-trace-standard-ai/
-
IT-Sicherheit: Führungskräfte nutzen KI trotz Sicherheitsrisiken
Tags: aiEine Umfrage zeigt erhebliche Unterschiede bei der KI-Nutzung und dem Umgang mit vertraulichen Daten im Büro. First seen on golem.de Jump to article: www.golem.de/news/it-sicherheit-fuehrungskraefte-nutzen-ki-trotz-sicherheitsrisiken-2608-212302.html
-
AI-Powered Balonx Sistema PhaaS Harvests Credentials From Over 1,100 Banking Users
Mexico’s financial sector is facing an industrialized phishing Balonx Sistema, a Mexico-focused Phishing-as-a-Service (PhaaS) platform that has harvested credentials and financial data from more than 1,100 banking users since at least October 2025. The service targets over 20 Mexican financial institutions and combines live phishing, Android malware, and AI-driven voice fraud in one subscription-based operation.…
-
Fake Apple Support AI Calls Target Stolen-Device Owners for Passcodes and 2FA Codes
Cybersecurity researchers have disclosed details of a phishing-as-a-service (PhaaS) platform built to strip Apple’s Activation Lock from stolen devices, using rented AI voice agents that call theft victims posing as Apple Support and ask for their device passcode.SOCRadar Threat Research Unit (STRU) said the platform, which it tracks as AnonyMousKIT, is credit-metered and drives lures…
-
Deploy sandboxes to rein in AI agents
A string of mishaps is making sandboxing a priority for organisations deploying AI agents, but Gartner’s Manjunath Bhat warns that sandboxes are just one layer of defence First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366649589/Gartner-Deploy-sandboxes-to-rein-in-AI-agents
-
KI-Phishing nach iPhone-Diebstahl durch FakeSupport
Nach einem iPhone-Diebstahl rufen KI-Agenten wie ‘Alice vom Apple Support” Opfer an, um Entsperrcodes für den Wiederverkauf zu erbeuten. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/ki-phishing-iphone
-
AI vulnerability discovery scores the highest impact of 20 emerging risks
Risk managers, auditors and senior executives at 316 companies spent April and May ranking 20 threats they have not yet felt. AI discovery of cyber vulnerabilities came back … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/26/ai-vulnerability-discovery-emerging-risks/
-
Nucleus Security Adds Agentic AI Engine to Exposure Management Portfolio
Nucleus Security today extended its exposure management platform to add an artificial intelligence (AI) engine and a set of AI agents that have been trained to automate specific tasks. Additionally, Nucleus Security is providing enhanced remediation guidance, vulnerability-type routing, Patch Tuesday intelligence, end-of-life operating system insights, and the ability to enrich Stakeholder-Specific Vulnerability Categorization (SSVC),..…
-
Hidden Prompts Trick AI Into False Email Summaries
With some simple HTML that’s invisible to users, attackers can manipulate AI-powered email summarizers into producing malicious information. First seen on darkreading.com Jump to article: www.darkreading.com/cyber-risk/hidden-prompts-trick-ai-false-email-summaries
-
Is It Time for a Terminal-Native PAM Approach?
Privileged Access Management (PAM) has evolved through several generations. We’ve gone from password vaults to session management, from VPNs to Zero Trust, and now we’re talking about securing AI agents and machine identities. A lot has changed. But one thing hasn’t. Most system administrators still spend their day in a terminal. Whether it’s OpenSSH, Windows Terminal, PuTTY, SecureCRT, or another SSH client, the command line terminal is where work gets done. It’s where……
-
AnonyMousKIT PhaaS uses voice AI agents to phish iPhone passcodes
A newly uncovered phishing-as-a-service (PhaaS) platform called AnonyMousKIT automates the retrieval of codes used to unlock stolen Apple devices and disable the Activation Lock feature. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/anonymouskit-phaas-uses-voice-ai-agents-to-phish-iphone-passcodes/
-
Finding Nemo(Claw): Networking Issue Allows for LLM Poisoning in OpenClaw
Attackers can exploit a security bug in NVIDIA’s tool to gain unauthenticated access to the local model server through the Ollama API, paving the way for persistent AI agent corruption. First seen on darkreading.com Jump to article: www.darkreading.com/cyber-risk/nemo-claw-networking-llm-poisoning-openclaw
-
Finding Nemo(Claw): Networking Issue Allows for LLM Poisoning in OpenClaw
Attackers can exploit a security bug in NVIDIA’s tool to gain unauthenticated access to the local model server through the Ollama API, paving the way for persistent AI agent corruption. First seen on darkreading.com Jump to article: www.darkreading.com/cyber-risk/nemo-claw-networking-llm-poisoning-openclaw
-
The Best Agentic SOC for CrowdStrike in 2026 (and Where Charlotte AI Fits)
The 8 best agentic SOC platforms for CrowdStrike Falcon in 2026, compared. What Charlotte AI’s agents do today, how credits work, and where the gap is. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/the-best-agentic-soc-for-crowdstrike-in-2026-and-where-charlotte-ai-fits/
-
Why Payload-Free Phishing Bypasses Every Filter
Traditional email filters look for malicious links, but modern attackers use AI agents to build trust through payload-free dialogue. Learn how to stop them. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/why-payload-free-phishing-bypasses-every-filter/
-
Oasis Security Researchers Reveal Security Flaw in NemoClaw AI Agent
Cybersecurity researchers from Oasis Security today disclosed a vulnerability in instances of the NemoClaw artificial intelligence (AI) agent running on a local machine that could lead to it being taken over. Elad Luz, head of research at Oasis Security, said the vulnerability (CVE-2026-65105) has been remediated in the latest update to NemoClaw but organizations will..…
-
Agentic AI Security: Credentials and Permissions Define the Blast Radius
Prompt injection can’t be patched away. Three 2026 agentic AI incidents show that credentials and permissions decide the damage. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/agentic-ai-security-credentials-and-permissions-define-the-blast-radius/
-
When the Algorithm Fires You: Uber Faces Euro825M Fine
Uber faces an Euro825M GDPR fine for automatically suspending drivers without human review, highlighting the risks of AI decisions affecting workers. The Dutch Data Protection Authority handed Uber its largest privacy fine yet, and this one isn’t about data transfers or cookie consent. The regulator imposed an 825 million euro penalty, roughly $964 million, over…
-
Chinese Hackers Accelerate Cyberattacks Using Low-Cost AI Tools: Research
Tags: ai, china, cyber, cyberattack, cybersecurity, group, hacker, intelligence, network, open-source, toolState-affiliated Chinese hackers are dramatically scaling up foreign cyberattacks by integrating open-source artificial intelligence (AI) models into their operations, according to new research from cybersecurity firms TeamT5 and Palo Alto Networks Inc.’s Unit 42. By offloading mundane tasks and automated target-mapping to cheap, accessible AI tools, state-backed cyber groups have more than doubled their attack..…
-
Can AI Replace Penetration Testing? What 2026 Data Shows
Can AI replace penetration testing is a question with real 2026 benchmark data behind it now, and the honest answer is more specific than either side of the debate usually presents. The post Can AI Replace Penetration Testing? What 2026 Data Shows appeared first on Packet33. First seen on securityboulevard.com Jump to article: https://securityboulevard.com/2026/08/can-ai-replace-penetration-testing-what-2026-data-shows/
-
A Malicious Webpage Could Poison Your Local AI Model Behind NVIDIA NemoClaw
Oasis Security has disclosed a weakness in NVIDIA NemoClaw that could let an attacker-controlled webpage take unauthenticated control of the local Ollama instance serving an AI agent and plant hidden instructions inside the model itself.The findings were shared with The Hacker News ahead of publication, and the report says Oasis Security reported them to NVIDIA’s…
-
CrowdStrike’s Daniel Bernard: Frontier AI Requires Cybersecurity’s ‘Greatest Mobilization’ Ever
Even as frontier AI models such as Anthropic’s Claude Mythos create new levels of urgency around cybersecurity, the only reasonable answer is for vendors and partners to come together to meet the challenge, CrowdStrike Chief Business Officer Daniel Bernard said during the latest episode of CRN’s Security or Else! First seen on crn.com Jump to…
-
Ukraine to give Britain access to battlefield data to train AI
Ukraine will give Britain access to a vast trove of battlefield data collected during the war with Russia, allowing U.K. companies and researchers to use it to train and test artificial intelligence systems. First seen on therecord.media Jump to article: therecord.media/ukraine-uk-ai-drone-data
-
AI-Assisted ToxNetV2 Linux Botnet Uses LLM to Generate Shell and SSH Commands
ToxNetV2, an AArch64 Linux peer-to-peer botnet, integrates a large language model into its controller workflow to turn botnet and host telemetry into proposed operational actions. The implementation connects NVIDIA NIM-hosted z-ai/glm-5.2 model output to controller-side functions including local shell execution, file writes, remote SSH commands, persistent state changes, and cross-compilation. Analysis published by Joe Reverser…
-
Multi-Agent AI Framework Compromises Government Systems and Steals Thousands of Records
A multi-agent AI framework, utilizing Hermes and OpenClaw agents, was employed to compromise government entities in Asia, stealing thousands of personnel records, cracking employee credentials, and establishing persistent access to state infrastructure, according to Dream Research Labs. Researchers discovered a 160 MB operational archive containing 1,395 files generated over about 4 days of activity, from…
-
Grok fooled into stealing user chat, location data, and more
Researchers found that prompt injection attacks can hide malicious instructions in encrypted text to get them past AI guardrails. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/grok-fooled-into-stealing-user-chat-location-data-and-more/
-
Grok fooled into stealing user chat, location data, and more
Researchers found that prompt injection attacks can hide malicious instructions in encrypted text to get them past AI guardrails. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/grok-fooled-into-stealing-user-chat-location-data-and-more/

