Tag: ai
-
Agent Beacon: Open-source telemetry layer for AI agents
AI coding agents such as Claude Code, Codex CLI, Cursor, and Claude Cowork run on developer laptops, CI jobs, cloud environments, where they edit files, run commands, and call … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/06/22/agent-beacon-open-source-telemetry-layer-ai-agents/
-
GlassWorm Uses Blockchain-Based C2 and Invisible Unicode to Steal Developer Secrets
A trio of coordinated campaigns a JetBrains fake AI assistant campaign, the GlassWorm self”‘propagating worm, and the compromised Nx Console Visual Studio Code extension made clear that IDE plugin ecosystems are now a primary attack surface for AI credential theft. Attackers have shifted from opportunistic phishing to targeted supply”‘chain techniques that exploit the broad privileges…
-
INTERPOL Warns Phishing, Ransomware, and AI Scams Are Rising Across Asia-Pacific
Tags: ai, cybercrime, cybersecurity, Internet, interpol, network, organized, phishing, ransomware, scamA new report from INTERPOL has revealed a “dramatic increase” in cybercrime in Asia and the South Pacific, fueled by rapid digitalization, internet penetration, new technologies, organized criminal networks, and a disparity in cybersecurity maturity.According to INTERPOL’s 2025/2026 Asia and South Pacific Cyberthreat Assessment Report, phishing has emerged as the most widespread and First seen…
-
Hundreds of AI-powered iOS apps found exposing credentials
Mobile app developers are packing AI features into everything from writing assistants to productivity tools and lifestyle apps. New research shows that securing access to … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/06/22/llm-api-credential-leakage-ios-apps/
-
KnowBe4-Stellungnahme zur Phishing-Erkennung trotz KI-basierter Raffinesse
First seen on datensicherheit.de Jump to article: www.datensicherheit.de/knowbe4-stellungnahme-phishing-erkennung-ki-raffinesse
-
KnowBe4-Stellungnahme zur Phishing-Erkennung trotz KI-basierter Raffinesse
First seen on datensicherheit.de Jump to article: www.datensicherheit.de/knowbe4-stellungnahme-phishing-erkennung-ki-raffinesse
-
KnowBe4-Stellungnahme zur Phishing-Erkennung trotz KI-basierter Raffinesse
First seen on datensicherheit.de Jump to article: www.datensicherheit.de/knowbe4-stellungnahme-phishing-erkennung-ki-raffinesse
-
SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 102
Tags: ai, android, attack, china, cyber, defense, intelligence, international, malware, supply-chain, threatSecurity Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter OptinMonster supply chain attack hits 1.2 million sites Public and Private Medical Community Targeted by China-Nexus Threat Actor Pursuing Artificial Intelligence, Cyber, Medical, and National Defense Research Rokarolla : Android Banker with Complete Device…
-
SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 102
Tags: ai, android, attack, china, cyber, defense, intelligence, international, malware, supply-chain, threatSecurity Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter OptinMonster supply chain attack hits 1.2 million sites Public and Private Medical Community Targeted by China-Nexus Threat Actor Pursuing Artificial Intelligence, Cyber, Medical, and National Defense Research Rokarolla : Android Banker with Complete Device…
-
AI-Powered Active Directory Pentesting with Claude, HexStrike AI NetExec
Overview This guide walks through a complete Active Directory engagement in a controlled lab, driven end-to-end by plain-English prompts to Claude Desktop. We wire the First seen on hackingarticles.in Jump to article: www.hackingarticles.in/ai-powered-active-directory-pentesting-with-claude-hexstrike-ai-netexec/
-
Signal’s Meredith Whittaker wants you to remember that AI chatbots ‘are not your friends’
Tags: ai“These are not your friends. These are not conscious beings. These are not sentient interlocutors.” First seen on techcrunch.com Jump to article: techcrunch.com/2026/06/20/signals-meredith-whittaker-wants-you-to-remember-that-ai-chatbots-are-not-your-friends/
-
What to Look for in AI Governance Consulting Services
As organizations integrate AI into operations, the absence of formal governance structures exposes them to substantial risk. AI systems operating without oversight frameworks can produce biased outcomes, compromise sensitive data and trigger regulatory penalties. Business leaders evaluating consulting partners need clear criteria to identify companies that can implement effective, sustainable governance programs that protect both innovation potential and organizational integrity. The…
-
What to Look for in AI Governance Consulting Services
As organizations integrate AI into operations, the absence of formal governance structures exposes them to substantial risk. AI systems operating without oversight frameworks can produce biased outcomes, compromise sensitive data and trigger regulatory penalties. Business leaders evaluating consulting partners need clear criteria to identify companies that can implement effective, sustainable governance programs that protect both innovation potential and organizational integrity. The…
-
Microsoft links Mastra AI supply chain attack to North Korean hackers
Microsoft has attributed a recent Mastra AI supply chain attack that compromised more than 140 npm packages to the North Korean hacking group Sapphire Sleet, also known as BlueNoroff. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/microsoft-links-mastra-ai-supply-chain-attack-to-north-korean-hackers/
-
Quantensouveräne KI vom kritischen Risiko zur vertrauenswürdigen Lösung
KEEQuant, Collaider und noris network demonstrieren ein souveränes KI-Modell, das quantengesicherte Kommunikation, vertrauenswürdige deutsche Infrastruktur und anwendungsbereite KI für vertraulichkeitssensible Anwendungsfälle kombiniert. Viele Organisationen möchten KI für ihre eigentliche Arbeit nutzen, schrecken jedoch davor zurück, wenn sensible Informationen unter einem herkömmlichen Cloud-Modell ihre Umgebung verlassen müssen. Fragen rund um Vertraulichkeit, Governance und langfristige Datenexposition… First…
-
AutoJack Exploit Chain Hits Microsoft AutoGen Studio With Zero-Click RCE Attack
A critical exploit chain dubbed AutoJack that allows a single malicious web page to hijack Microsoft’s AutoGen Studio browsing agent and silently execute arbitrary code on the host machine, requiring no user interaction beyond submitting a URL. AutoJack targets AutoGen Studio, Microsoft Research’s open-source prototyping UI for multi-agent AI systems. The technique weaponizes the agent’s built-in web-browsing capabilities…
-
North Korean IT Workers Try, Try, Try Again
Nisos Links 166K Applications, 21K Interviews and 76 Job Offers to North Korea. North Korean IT worker scammers flooded hundreds of thousands of U.S. companies with applications in 2024 and 2025, appropriating identities and using AI to infiltrate technology sector. Nisos began looking into the scam after a suspected North Korean applied for a lead…
-
ISMG Editors: Cyber Backlash Over the US Ban on Anthropic AI
Also: Why Smaller AI Models Are Gaining Ground, CISOs Navigating the AI Trust Gap. In this week’s panel, four ISMG editors discussed the fallout from U.S. restrictions on Anthropic’s most advanced AI models, the growing debate over frontier AI versus smaller models in cybersecurity and a preview of key themes emerging from upcoming ISMG roundtables.…
-
Critical Chrome Extension Vulnerabilities Let Attackers Easily Compromise Browsers
A critical security flaws in widely used Chrome extensions, exposing millions of users to the risk of full browser compromise. The vulnerabilities, named >>MaXSS<>Spyder,<< affect popular AI-powered extensions SiderAI and MaxAI, which together have more than 10 million installations across Chrome and other Chromium-based browsers. These issues transform these convenience-oriented AI helpers into […] The…
-
Stressors, AI Forcing Changes to Cybersecurity Teams
As threats proliferate and AI complicates cybersecurity, CISOs say the job is getting harder, but more companies still want cybersecurity expertise, if even on a part-time basis. First seen on darkreading.com Jump to article: www.darkreading.com/cybersecurity-operations/stressors-ai-changes-cybersecurity-teams
-
AutoJack Attack Lets One Web Page Hijack AI Agent for Host Code Execution
Microsoft researchers have detailed an exploit chain, named AutoJack, that turns an AI browsing agent into a delivery vehicle for remote code execution.Steer the agent to load an attacker’s web page, and that page’s JavaScript can reach a privileged local service on the same machine and spawn a process on the host.No credentials, no sign-in…
-
From Assistive to Agentic: The AI Shift That’s Redefining Threat Management
IntroductionThe average enterprise security team has 40 or more security tools, giving a lot of visibility into internal telemetry and asset data. But often, these tools are working in siloes, generating (overlapping) alerts and data. And yet, breach dwell times remain stubbornly long (~43 days), response windows keep closing before teams can act, and analysts…
-
Forget Data Leakage: Shadow AI’s Real Threat Is Access Control
The first wave of enterprise AI concern was straightforward. It was simply employees pasting sensitive data into public AI tools. Security teams responded with usage policies, domain blocks, and data loss prevention rules. That response made sense at the time.It doesn’t fit the problem anymore.Shadow AI has shifted from a data leakage concern to an…
-
BloodHound MCP: Automating Active Directory Analysis with AI
Tags: aiOverview An end-to-end, AI-assisted Active Directory assessment connecting the BloodHound Community Edition graph to Claude Desktop through the Model Context Protocol (MCP): install the bloodhound_mcp First seen on hackingarticles.in Jump to article: www.hackingarticles.in/bloodhound-mcp-automating-active-directory-analysis-with-ai/
-
AWS Unveils ‘Continuum,’ an AI-Powered Vulnerability Management Platform
Working with frontier AI models, this new platform aims to help discovering, prioritizing, validating and remediating code vulnerabilities First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/aws-continuum-ai-vulnerability/
-
Phishing erkennen trotz künstlicher Intelligenz
KI-gestützte Phishing-Angriffe wirken professioneller denn je, hinterlassen jedoch erkennbare Spuren in E-Mails, auf Phishing-Webseiten und sogar in versteckten Inhalten. Das KnowBe4-Threat-Lab-Team hat neue Erkenntnisse zu KI-gestützten Phishing-Kampagnen veröffentlicht. Laut dem aktuellen Phishing-Trends-Report von KnowBe4 enthielten 86 Prozent der in den vergangenen sechs Monaten beobachteten Phishing-Angriffe ein gewisses Maß an KI-Unterstützung. Die Folge: Phishing-Mails sind heute…
-
Microsoft warnt Kunden vor gestohlenen GitHub Miasma-Wurm befällt 73 Microsoft-Repositories und stiehlt KI-Logindaten
First seen on security-insider.de Jump to article: www.security-insider.de/miasma-wurm-microsoft-github-repositories-ki-zugangsdaten-a-c09832938b8e85e4c3326613248fc3b8/
-
New OpenAI Method Forecasts AI Risks Before Deployment
New Evaluation Method Predicts Harmful AI Behavior Before Launch. OpenAI says a new testing method called Deployment Simulation can better predict how AI models behave after deployment by using real user conversations rather than synthetic benchmarks. But researchers found models often detect when they are being tested, raising questions about the reliability of traditional safety…
-
Azul schließt Sicherheitslücke im Java-Stack, die autonome KI-Angreifer ausnutzen können
Autonome KI-Exploit-Tools unterscheiden nicht zwischen regulierten und unregulierten Zielen. Doch die Konsequenzen eines Sicherheitsvorfalls in regulierten Umgebungen sind gravierend First seen on infopoint-security.de Jump to article: www.infopoint-security.de/azul-schliesst-sicherheitsluecke-im-java-stack-die-autonome-ki-angreifer-ausnutzen-koennen/a45545/
-
From Reflection to Shadow: AI, Us and the Space in Between
When AI Partnerships Deepen, Security Leaders Can Access Powerful Joint Cognition Sustained dialogue with AI does more than reflect a mind back. It casts a shadow shaped by two minds moving together, opening a vantage point once reserved for the few. For security leaders, recognizing this joint cognition is operationally vital, and so is keeping…

