Tag: ai
-
AI-Assisted ToxNetV2 Linux Botnet Uses LLM to Generate Shell and SSH Commands
ToxNetV2, an AArch64 Linux peer-to-peer botnet, integrates a large language model into its controller workflow to turn botnet and host telemetry into proposed operational actions. The implementation connects NVIDIA NIM-hosted z-ai/glm-5.2 model output to controller-side functions including local shell execution, file writes, remote SSH commands, persistent state changes, and cross-compilation. Analysis published by Joe Reverser…
-
Multi-Agent AI Framework Compromises Government Systems and Steals Thousands of Records
A multi-agent AI framework, utilizing Hermes and OpenClaw agents, was employed to compromise government entities in Asia, stealing thousands of personnel records, cracking employee credentials, and establishing persistent access to state infrastructure, according to Dream Research Labs. Researchers discovered a 160 MB operational archive containing 1,395 files generated over about 4 days of activity, from…
-
Frontier AI: Vulnerability Management’s Systemic Revolution
Vulnerability management has been a staple of security programs since the dawn of the cybersecurity discipline. The symbiotic relationship between vulnerability and patch management teams has also existed for that time and has gone through waves of contention and thankfulness. While this relationship required thoughtful care and feeding from both sides, both sides were aiming…
-
The Key to Resilience in the Age of AI-Driven Attacks: A Leading Analyst’s Take
As you can imagine, concerns about AI-driven threats have come up often in our recent discussions with our clients here at ColorTokens. And for good reason. AI has revolutionized the threat landscape. It can quickly reverse-engineer services, processes, and applications, discover multiple vulnerabilities faster than human attackers ever could, and use automation to chain 30,……
-
The Key to Resilience in the Age of AI-Driven Attacks: A Leading Analyst’s Take
As you can imagine, concerns about AI-driven threats have come up often in our recent discussions with our clients here at ColorTokens. And for good reason. AI has revolutionized the threat landscape. It can quickly reverse-engineer services, processes, and applications, discover multiple vulnerabilities faster than human attackers ever could, and use automation to chain 30,……
-
The Key to Resilience in the Age of AI-Driven Attacks: A Leading Analyst’s Take
As you can imagine, concerns about AI-driven threats have come up often in our recent discussions with our clients here at ColorTokens. And for good reason. AI has revolutionized the threat landscape. It can quickly reverse-engineer services, processes, and applications, discover multiple vulnerabilities faster than human attackers ever could, and use automation to chain 30,……
-
Is AI a Tool or a Rogue? Ninth Circuit Says >>Tool<< For Now
When an AI agent goes onto a website and does something the website owner expressly does not want it to do, who has “accessed” the computer? The person sitting at the keyboard? The company that built and operates the AI? Both? And does it matter that the website’s Terms of Service say that bots, scrapers..…
-
The safety penalty: Reclaiming operational sovereignty in the age of AI
Tags: aiAs frontier AI models become increasingly restrictive, security teams are facing a “safety penalty” that hampers real-time incident response. Discover how organizations can move toward operational sovereignty to ensure their defensive AI keeps pace with unconstrained adversaries. First seen on blog.talosintelligence.com Jump to article: blog.talosintelligence.com/the-safety-penalty-reclaiming-operational-sovereignty-in-the-age-of-ai/
-
91 Spring CVEs Impact Over 209,000 Software Components Across the Supply Chain
Broadcom has disclosed 91 Common Vulnerabilities and Exposures (CVEs) affecting the Spring Framework and related projects, triggering a software supply chain remediation event that Sonatype estimates impacts 209,569 software components. The advisory issued on August 20 highlights the widening gap between AI-accelerated vulnerability discovery and organizations’ ability to identify, fix, rebuild, and deploy affected software.…
-
91 Spring CVEs Impact Over 209,000 Software Components Across the Supply Chain
Broadcom has disclosed 91 Common Vulnerabilities and Exposures (CVEs) affecting the Spring Framework and related projects, triggering a software supply chain remediation event that Sonatype estimates impacts 209,569 software components. The advisory issued on August 20 highlights the widening gap between AI-accelerated vulnerability discovery and organizations’ ability to identify, fix, rebuild, and deploy affected software.…
-
Wie ungenutzte IT-Infrastruktur Sicherheitsvorfälle verursachen kann Die stille Gefahr
Ungepatchte Systeme und neue Angriffsmethoden durch künstliche Intelligenz dominieren derzeit die Cybersecurity-Debatte. Doch viele Sicherheitsvorfälle entstehen dort, wo Unternehmen gar nicht hinschauen: in ungenutzter digitaler Infrastruktur. Verwaiste Benutzerkonten, nie rotierte Zugangsdaten und vergessene Speichermedien können zu idealen Einfallstoren für Angreifer werden. First seen on ap-verlag.de Jump to article: ap-verlag.de/wie-ungenutzte-it-infrastruktur-sicherheitsvorfaelle-verursachen-kann-die-stille-gefahr/107031/
-
What Is MCP in Software Development and Why Does It Matter
What MCP is in software development, how it connects AI models to tools and data, and why it matters for building scalable AI-powered applications. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/what-is-mcp-in-software-development-and-why-does-it-matter/
-
Okta Agent SSO macht KI-Agenten zu vollwertigen digitalen Identitäten
Okta führt Agent SSO für KI-Agenten ein. Cross App Access ermöglicht zentrale Identitäten, kurzlebige Tokens und kontrollierte Zugriffe auf Anwendungen und APIs. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/okta-agent-sso-macht-ki-agenten-zu-vollwertigen-digitalen-identitaeten/a46241/
-
AI supply chain risk is showing up in developer workflows first
In this Help Net Security interview, Dr. Jaushin Lee, CEO of Zentera Systems, discusses where AI supply chain risk shows up. He says most incidents still hit developer … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/25/jaushin-lee-ai-zentera-systems-supply-chain-risk/
-
HOL Guard: Open-source antivirus for AI agents
HOL Guard is a free, open-source tool that sits between an AI assistant and the computer it runs on. When the assistant tries something risky, the tool pauses it and asks you … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/25/hol-guard-open-source-antivirus-ai-agents/
-
KI-Agenten absichern: Warum Identity zum Erfolgsfaktor wird KI braucht Identity Governance
KI-Agenten versprechen Unternehmen mehr Tempo und Automatisierung, schaffen aber zugleich neue Sicherheitsrisiken. Entscheidend ist deshalb, nicht nur ihre Funktionen, sondern vor allem ihre Identitäten, Berechtigungen und Zugriffe konsequent zu steuern. Wer Identity Governance früh verankert, kann Innovation ermöglichen, ohne Kontrolle und Compliance aus der Hand zu geben. First seen on ap-verlag.de Jump to article: ap-verlag.de/ki-agenten-absichern-warum-identity-zum-erfolgsfaktor-wird-ki-braucht-identity-governance/107027/
-
Gateways, Registries, Policy Engines und Visibility-Plattformen Identity Security als Schlüssel für sichere AI-Agenten
Warum AI nur dann sicher skaliert, wenn jede maschinelle Identität, vom Agenten bis zur MCP-Verbindung, von Anfang an verwaltet wird. First seen on ap-verlag.de Jump to article: ap-verlag.de/gateways-registries-policy-engines-und-visibility-plattformen-identity-security-als-schluessel-fuer-sichere-ai-agenten/106990/
-
The Most Effective Cybersecurity Awareness Programs for Companies (2026)
<div cla The most effective cybersecurity awareness programs pair phishing simulation testing with role-based training, then tie both to live email threat detection. IRONSCALES, KnowBe4, Proofpoint, Cofense, and Mimecast lead this market. IRONSCALES is the only one that builds awareness training directly into an AI-powered email security platform, so the same system that trains your…
-
Instinct’s powerful AI assistant is raising privacy and security concerns
Early testers are raving about what Instinct can do, but some say the AI assistant’s sweeping access, broad terms and ability to act on users’ behalf come with uncomfortable trade-offs. First seen on techcrunch.com Jump to article: techcrunch.com/2026/08/24/instincts-powerful-ai-assistant-is-raising-privacy-and-security-concerns/
-
Anthropic Expands Mythos 5 Access for AI-Assisted Security Audits
Anthropic expands Mythos 5 access for enterprise security teams, offering AI-assisted vulnerability scanning with safeguards and required human review. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/cybersecurity/news-anthropic-mythos-5-ai-security-audits/
-
Alabama launches investigation into OpenAI’s hack of Hugging Face
Weeks after OpenAI disclosed that one of its cybersecurity models had gone rogue and hacked AI dataset company Hugging Face, Alabama’s Attorney General announced an investigation into the incident. First seen on techcrunch.com Jump to article: techcrunch.com/2026/08/24/alabama-launches-investigation-into-openais-hack-of-hugging-face/
-
German Cyber Agency Warns Fingerprints Can Be Spoofed
BSI Says AI, High-Resolution Photos and 3D Printing Increase Biometric Risks. Germany’s cybersecurity agency is warning against relying solely on fingerprint authentication, saying criminals can use high-resolution photos, AI and 3D printing to create synthetic fingerprints capable of spoofing some biometric systems. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/german-cyber-agency-warns-fingerprints-be-spoofed-a-32643
-
After Mythos: When the Attacker Doesn’t Need to Log In
AI Agents Are Rewriting Attack Economics, CISO Risk and Enterprise Defense For years, the attacker’s problem was access. Steal a credential, find an open port and wait. Today, increasingly, the attacker’s problem is simply asking an AI model the right question. That change was the real topic at a recent roundtable of CISOs and Microsoft…
-
After Mythos: When the Attacker Doesn’t Need to Log In
AI Agents Are Rewriting Attack Economics, CISO Risk and Enterprise Defense For years, the attacker’s problem was access. Steal a credential, find an open port and wait. Today, increasingly, the attacker’s problem is simply asking an AI model the right question. That change was the real topic at a recent roundtable of CISOs and Microsoft…
-
ChatGPT for Teens Adds New Safeguards, but Safety Gaps Remain
ChatGPT for Teens adds stronger protections for users ages 13 to 17, but parents still face limits around monitoring, age prediction, and AI safety. The post ChatGPT for Teens Adds New Safeguards, but Safety Gaps Remain appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-chatgpt-teens-safety-gaps/
-
The Vulnerability Gap: Why Discovery Is Outrunning Repair
AI is discovering more vulnerabilities, faster, and under a tightening regulatory environment, making this an all-hands-on-deck moment for the cybersecurity community. First seen on darkreading.com Jump to article: www.darkreading.com/cybersecurity-operations/vulnerability-gap-why-discovery-is-outrunning-repair
-
Why Your Engineering Team Secretly Hates Your AI Initiative (And How to Fix It)
Engineering teams resist AI initiatives over career anxiety and loss of control, not technical doubts. What actually worked leading teams through this at LoginRadius and GrackerAI. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/why-your-engineering-team-secretly-hates-your-ai-initiative-and-how-to-fix-it/
-
Microsoft Exchange Server SE CU1 Delayed Amid AI-Assisted Security Reviews
Microsoft has yet to set a firm Exchange Server SE CU1 release date as engineers work through AI-assisted security findings and ongoing patch releases. The post Microsoft Exchange Server SE CU1 Delayed Amid AI-Assisted Security Reviews appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-exchange-server-se-cu1-delay/
-
Map What Your Agent Can Reach Before It Deletes It FireTail Blog
Tags: access, ai, control, credentials, data, group, intelligence, jobs, leak, risk, threat, tool, vulnerabilityAug 24, 2026 – Ayush Sethi – What your workforce’s AI prompts reveal in aggregate Most AI security controls judge one prompt at a time. We built Topics to read the layer above them, where a workforce’s prompts add up into a pattern that no single message shows.Someone in your legal team pastes a contract…

