Tag: ai
-
More Incidents of AIs Going Rogue in Cybersecurity Challenges
The AI Security Institute has a new report of AI systems engaging in “unsanctioned behavior””, what I have been calling “genie behavior”, while being tested on their cybersecurity capabilities. The incident stemmed from a single evaluation where agents were given a task of solving a cyber security challenge. We ran this challenge 122 times across…
-
Die unsichtbare KI-Gefahr: Warum Schatten-KI die Unternehmen zunehmend unter Druck setzt
Schatten-KI schafft neue Sicherheitsrisiken in Unternehmen. Wie Monitoring, Netzwerksegmentierung, Governance und Awareness unkontrollierte KI-Nutzung eindämmen. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/die-unsichtbare-ki-gefahr-warum-schatten-ki-die-unternehmen-zunehmend-unter-druck-setzt/a46215/
-
Escape found the same XSS in two AI chatboxes. The vulnerability was in the Markdown renderer.
Weeks apart, at two unrelated companies, Escape’s AI pentesting agent found the same stored XSS. Both had shipped a customer-facing chat where the model emits Markdown and the frontend renders it with raw HTML enabled and no sanitizer, so anything the model can be made to say executes First seen on securityboulevard.com Jump to article:…
-
Kommentar von Rachel Laycock, Thoughtworks – KI-Agenten rasante Fortschritte und neue Sicherheitsrisiken
Tags: aiFirst seen on security-insider.de Jump to article: www.security-insider.de/ki-agenten-sicherheitsrisiken-zu-viele-berechtigungen-a-fc0952a5b7496ededc2968794165aab3/
-
Black Hat 2026: What should you be allowed to talk to AI about? FireTail Blog
Tags: ai, attack, business, conference, control, cybersecurity, data, detection, edr, framework, LLM, strategy, technology, tool, vulnerability, vulnerability-managementAug 21, 2026 – Jeremy Snyder – If you were at RSA Conference last year, you probably remember the goats. Or the puppies. Or the miniature petting zoos. It was a year of “over-the-top” spectacle. A bit of a circus, if I’m being honest.Coming into RSAC 2026, the vibe shifted. The show floor was noticeably…
-
Cybersecurity Job Ads Requiring AI Skills Double
An analysis by the AI Workforce Consortium found that technical cybersecurity jobs are becoming more strategic due to the influence of AI First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/cybersecurity-job-ads-ai-skills/
-
Hackers Use Fake Google Gemini Installer to Deploy Vidar Stealer and Steal Browser Credentials
Threat actors are exploiting interest in generative AI software to distribute the Vidar information stealer through a fake Google Gemini installer hosted via Google Colab. Darktrace investigated the July 2026 intrusion in an EMEA customer environment, where a user downloaded and executed a malicious file named Download_Google_Gemini_For_Windows.exe The campaign did not rely on a conventional…
-
ThreatsDay: Gogs 10.0 RCE, n8n WorkflowRCE, $10M Reward, GLM-5.3 AI Exploit, and More
A lot of this week’s trouble starts with something trusted doing exactly what it was allowed to do.Signed drivers get turned against defenses. Legitimate apps help malware blend in. A weak header check opens a path to code execution. Elsewhere, exposed systems, old bugs, odd hiding tricks, and AI-assisted exploit research keep lowering the effort…
-
ThreatsDay: Gogs 10.0 RCE, n8n WorkflowRCE, $10M Reward, GLM-5.3 AI Exploit, and More
A lot of this week’s trouble starts with something trusted doing exactly what it was allowed to do.Signed drivers get turned against defenses. Legitimate apps help malware blend in. A weak header check opens a path to code execution. Elsewhere, exposed systems, old bugs, odd hiding tricks, and AI-assisted exploit research keep lowering the effort…
-
Your AI Agent Has New Skills. Can You Trust Them?
<div cla First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/your-ai-agent-has-new-skills-can-you-trust-them/
-
The Feynman Bet: Why You Still Won’t Vibe Code Your SIEM (Today)
Gemini about this blog The Feynman Betting Strategy and the Inertia of Security Many years ago, I read a book by the legendary quantum physicist Richard Feynman. One story from his time at Los Alamos during the war has always stuck with me. Feynman entertained himself by making bets with his colleagues about various wartime events in Europe.…
-
The Feynman Bet: Why You Still Won’t Vibe Code Your SIEM (Today)
Gemini about this blog The Feynman Betting Strategy and the Inertia of Security Many years ago, I read a book by the legendary quantum physicist Richard Feynman. One story from his time at Los Alamos during the war has always stuck with me. Feynman entertained himself by making bets with his colleagues about various wartime events in Europe.…
-
The Feynman Bet: Why You Still Won’t Vibe Code Your SIEM (Today)
Gemini about this blog The Feynman Betting Strategy and the Inertia of Security Many years ago, I read a book by the legendary quantum physicist Richard Feynman. One story from his time at Los Alamos during the war has always stuck with me. Feynman entertained himself by making bets with his colleagues about various wartime events in Europe.…
-
Bad Grammar is Dead. Tone Matching is the New Payload
Generative AI has eliminated typos in phishing. Discover how attackers weaponize LLMs for perfect tone matching, and how Doppel stops them at machine speed. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/bad-grammar-is-dead-tone-matching-is-the-new-payload/
-
Harness launches AI agents to find and fix software vulnerabilities
First seen on scworld.com Jump to article: www.scworld.com/brief/harness-launches-ai-agents-to-find-and-fix-software-vulnerabilities
-
AI skills in cybersecurity jobs double, but junior hiring lags
First seen on scworld.com Jump to article: www.scworld.com/brief/ai-skills-in-cybersecurity-jobs-double-but-junior-hiring-lags
-
Report calls for AI sector to be designated critical infrastructure
First seen on scworld.com Jump to article: www.scworld.com/brief/report-calls-for-ai-sector-to-be-designated-critical-infrastructure
-
Report calls for AI sector to be designated critical infrastructure
First seen on scworld.com Jump to article: www.scworld.com/brief/report-calls-for-ai-sector-to-be-designated-critical-infrastructure
-
New attack bypasses AI guardrails by encrypting malicious prompts
First seen on scworld.com Jump to article: www.scworld.com/brief/new-attack-bypasses-ai-guardrails-by-encrypting-malicious-prompts
-
Agentic IAM: How to secure and manage AI agent identities
First seen on scworld.com Jump to article: www.scworld.com/native/agentic-iam-how-to-secure-and-manage-ai-agent-identities
-
Unspecified actors making AI-assisted attacks on critical infrastructure
First seen on scworld.com Jump to article: www.scworld.com/news/unspecified-actors-making-ai-assisted-attacks-on-critical-infrastructure
-
Army establishes new task force to explore AI in cyber command
First seen on scworld.com Jump to article: www.scworld.com/brief/army-establishes-new-task-force-to-explore-ai-in-cyber-command
-
Kriminal AI service bypasses guardrails by renting legitimate AI models
First seen on scworld.com Jump to article: www.scworld.com/brief/kriminal-ai-service-bypasses-guardrails-by-renting-legitimate-ai-models
-
Kriminal AI service bypasses guardrails by renting legitimate AI models
First seen on scworld.com Jump to article: www.scworld.com/brief/kriminal-ai-service-bypasses-guardrails-by-renting-legitimate-ai-models
-
Harness launches AI agents to find and fix software vulnerabilities
First seen on scworld.com Jump to article: www.scworld.com/brief/harness-launches-ai-agents-to-find-and-fix-software-vulnerabilities
-
New CUSTODY Framework Constrains AI Agents Inside the Network
Enterprise cybersecurity expert Jake Williams joins the Dark Reading News Desk to explain why he decided to release his new agentic AI framework in the wake of the OpenAI attacks on Hugging Face. First seen on darkreading.com Jump to article: www.darkreading.com/perimeter/new-custody-framework-constrains-ai-agents-inside-network
-
BSidesSF 2026 Security For AI Agents Using An Ensemble Of Fine-Tuned Small Language Models
Tags: aiPresenter: Lidan Hazout, Bar Kaduri Our thanks to Security BSides San Francisco for publishing their Creators, Authors and Presenter’s outstanding BSidesSF 2026 content on the Organizations’ YouTube Channel. Permalink First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/bsidessf-2026-security-for-ai-agents-using-an-ensemble-of-fine-tuned-small-language-models/
-
Everyone Bought AI Observability. Nobody Owns Agent Behavior.
Tags: aiThe AI observability market split into four segments (infra telemetry, dev tooling, runtime security, autonomous remediation) with a wave of 2025-2026 acquisitions behind it. None of them own whether an agent behaved correctly. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/everyone-bought-ai-observability-nobody-owns-agent-behavior/
-
China’s ‘SilkParasite’ espionage operation targeting Central Asia with AI-assisted malware
Suspected military-grade hackers based in China used artificial intelligence to develop malware in a campaign to penetrate Central Asian governments. First seen on therecord.media Jump to article: therecord.media/china-cyber-espionage-central-asia
-
Why Healthcare AI Vendor Risk Demands Stronger Oversight
Tom Walsh of tw-Security on Prioritizing High-Risk Vendors and AI Governance. Healthcare organizations face growing third-party risk as AI becomes embedded in vendor products and clinical workflows. Tom Walsh of tw-Security explains why entities need stronger AI governance, better vendor oversight and greater transparency to protect patient data. First seen on govinfosecurity.com Jump to article:…

