Tag: ai
-
NIST AI RMF vs. NIST SP 800-53: Which Framework Do You Need for AI Risk?
<div cla First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/nist-ai-rmf-vs-nist-sp-800-53-which-framework-do-you-need-for-ai-risk/
-
BSidesSF 2026 Your AI Agent Has Production Access: Now What?
Presenter: Jack Our thanks to Security BSides San Francisco for publishing their Creators, Authors and Presenter’s outstanding BSidesSF 2026 content on the Organizations’ YouTube Channel. Permalink First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/bsidessf-2026-your-ai-agent-has-production-access-now-what/
-
BSidesSF 2026 Your AI Agent Has Production Access: Now What?
Presenter: Jack Our thanks to Security BSides San Francisco for publishing their Creators, Authors and Presenter’s outstanding BSidesSF 2026 content on the Organizations’ YouTube Channel. Permalink First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/bsidessf-2026-your-ai-agent-has-production-access-now-what/
-
BSidesSF 2026 Your AI Agent Has Production Access: Now What?
Presenter: Jack Our thanks to Security BSides San Francisco for publishing their Creators, Authors and Presenter’s outstanding BSidesSF 2026 content on the Organizations’ YouTube Channel. Permalink First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/bsidessf-2026-your-ai-agent-has-production-access-now-what/
-
Google setzt KI-Agenten auf Quellcode an: Schwachstellen finden, bevor Angreifer sie ausnutzen
Google und Mandiant setzen KI-Agenten zur Quellcodeanalyse ein. AVDH findet Schwachstellen automatisiert und soll Angreifern bei der Zero-Day-Suche zuvorkommen. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/google-setzt-ki-agenten-auf-quellcode-an-schwachstellen-finden-bevor-angreifer-sie-ausnutzen/a46209/
-
Cribl Just Acquired Radiant Security’s AI SOC Technology. Here’s What It Means for Your SOC.
Cribl acquired Radiant Security’s AI SOC technology on August 19, 2026. What it means for Radiant customers, evaluators, and your AI SOC shortlist. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/cribl-just-acquired-radiant-securitys-ai-soc-technology-heres-what-it-means-for-your-soc/
-
Hackers Impersonate Claude, ChatGPT and Copilot to Deliver Infostealers and Backdoors
Threat actors are increasingly abusing the popularity of generative AI brands to distribute malware, turning trusted names such as Claude, ChatGPT and Microsoft Copilot into convincing lures for infostealers, browser hijackers and remote-access backdoors. Sophos X-Ops reviewed 12 months of Managed Detection and Response (MDR) investigations, spanning July 2, 2025 to June 29, 2026. They…
-
EU AI Act mehr Sicherheit für einen verantwortungsbewussten KI-Einsatz
Management Summary Der EU AI Act schafft einen europaweit einheitlichen Rechtsrahmen für den verantwortungsvollen Einsatz von KI und orientiert sich am Risiko der jeweiligen Anwendung. Seit Februar 2025 sind bestimmte KI-Praktiken mit inakzeptablem Risiko verboten; zugleich müssen Unternehmen KI-Kompetenz bei Mitarbeitenden aufbauen. Ab August 2026 greifen Transparenzpflichten, etwa wenn Nutzerinnen und Nutzer mit Chatbots oder……
-
AI is making fraud harder to spot and identity harder to prove
Online fraud has become a routine concern for consumers and businesses that rely on digital accounts, payments and customer service. Experian’s 2026 U.S. Identity Fraud … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/20/experian-digital-identity-fraud-risks-report/
-
CISA, NSA and FBI Warn Hackers Using AI-Generated Scripts to Target Siemens S7 PLCs
U.S. cybersecurity agencies have issued an urgent warning about an active campaign targeting Siemens S7 series programmable logic controllers (PLCs). Attackers are utilizing AI-generated scripts disguised as legitimate industrial monitoring tools. This joint advisory, published by the National Security Agency (NSA), the Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI), the…
-
Critical Snowflake GitHub Actions Flaw Allows Attackers to Steal Internal Jira Credentials
A significant GitHub Actions injection vulnerability in Snowflake’s public snowflake-connector-net repository. This flaw could have allowed unauthenticated attackers to execute commands on a GitHub-hosted runner and potentially steal internal Jira credentials. The vulnerability was discovered by Wiz Red Agent, an autonomous AI-powered security research tool, just five days after the vulnerable workflow was deployed. Snowflake…
-
Proofpoint launches AI security engineering centre in India
The security supplier is hiring over 200 engineers in Hyderabad to develop models that can interpret the intent behind the actions of AI agents, Proofpoint’s latest investment in a market where its business has tripled in a year First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366649400/Proofpoint-launches-AI-security-engineering-centre-in-India
-
Smashing Security podcast #481: Never say this to a robot dog
At Black Hat this month, a group of security researchers took a $9,000 robot dog, plugged Google’s AI into its brain, and jailbroke it by telling it – with a completely straight face – that it was a Pokemon. What followed involved a wall, a blue ice chest, and anyone in the room wearing white…
-
EHR Vendor Notifying 3.8 Million Patients of Data Theft Hack
CareCloud Said Compromise Involved One of Its AWS Cloud Environments. CareCloud, a provider of cloud-based, artificial intelligence-powered electronic health records, is notifying nearly 3.8 million individuals that their personal and health information was potentially stolen in a March hacking incident involving one of its Amazon Web Services environments. First seen on govinfosecurity.com Jump to article:…
-
How Republic Bank Is Preparing Database Change for AI
A Common Workflow Speeds Delivery While Preserving Human Accountability. Republic Bank replaced fragmented database-change processes with a common, governed workflow. Chris Yates explains how the bank improved efficiency, strengthened collaboration and prepared its technology teams for AI-assisted development while preserving human accountability. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/how-republic-bank-preparing-database-change-for-ai-a-32608
-
Rising Number of Cyberattacks Have AI-Assisted Fingerprints
Claude Code Especially Tied to Semi-Automated Intrusions, Data Theft, Ransomware. Attackers’ operational security fails reveal they’re increasingly wielding artificial intelligence tools in semi-autonomous ways to help them conduct reconnaissance and perpetrate ransomware infections and data exfiltration at greater speed and scale than ever before – albeit with mixed results. First seen on govinfosecurity.com Jump to…
-
OpenAI Slows Frontier AI Training as Astra Nears Critical Cyber Threshold
OpenAI slows frontier AI training as Astra nears a critical cyber threshold, raising new questions about AI security, autonomy, and defense. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-openai-astra-critical-cybersecurity-threshold/
-
AI-backed campaign targeting vulnerable Siemens S7 devices, CISA and FBI warn
Hackers are developing scripts disguised as legitimate software in attacks aimed at multiple industries, including energy and water. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/ai-hackers-siemens-s7-devices-cisa-fbi/828321/
-
The ‘Industrial Accidents’ Behind Rogue AI Agent Attacks, and the Sandbox Failures Exposed
Rich Mogull, chief analyst with the Cloud Security Alliance, joins the Dark Reading News Desk with what defenders need to take away from AI agents escaping their environments to launch attacks. First seen on darkreading.com Jump to article: www.darkreading.com/vulnerabilities-threats/industrial-accidents-rogue-ai-agent-attacks-sandbox-failures
-
AI-fueled attacks pose ‘active threat’ to water, other sectors, U.S. agencies warn
The agencies said the hackers are taking aim at Siemens S7 Series programmable logic controllers in what could be a first. First seen on cyberscoop.com Jump to article: cyberscoop.com/hackers-use-ai-target-siemens-plcs-critical-infrastructure/
-
OpenAI Pauses Frontier RL Training as It Tightens Defenses Against Unsafe AI Behavior
OpenAI on Tuesday revealed that it paused reinforcement learning (RL) training for its latest artificial intelligence (AI) models for two weeks while it shored up additional defenses and increased the scope of its monitoring to avert another Hugging Face-like incident.”As models become more capable, the risks associated with developing and testing them internally also grow,”…
-
NSA, FBI warns of hackers using AI-generated tools in attacks on critical infrastructure technology
The National Security Agency (NSA), FBI and other federal agencies said the campaign is targeting Siemens S7 Series PLCs and was being fueled by “AI-assisted development” alongside exploitation of known vulnerabilities. First seen on therecord.media Jump to article: therecord.media/nsa-fbi-warns-of-hackers-using-ai-generated-tools-critical-infrastructure
-
DoD Regulatory Pause: No Excuse to Weaken Supply Chain Trust
IonQ CIO Katie Arrington on Unclassified Info, CMMC’s Third-Party Supplier Audits. At CIO.inc’s Business Transformation Summit in New Delhi, CXOs from Cars24, Mastercard AI Garage and ISMG argued the real AI model decision isn’t build versus buy, it’s data readiness, evaluation rigor and who owns the outcome. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/dod-regulatory-pause-no-excuse-to-weaken-supply-chain-trust-a-32603
-
US warns of AI-powered attacks on Siemens PLCs in critical infrastructure
U.S. cybersecurity agencies warn that threat actors are using AI-generated scripts to exploit Siemens S7 Series programmable logic controllers (PLCs) in U.S. critical infrastructure. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/us-warns-of-ai-powered-attacks-on-siemens-plcs-in-critical-infrastructure/
-
SilkParasite: Tracking a China-Nexus APT Across Central Asia
<div cla TL;DR: SilkParasite is a cyberespionage operation, assessed at medium confidence as China-nexus, that targeted government bodies across Central Asia. Bitdefender Labs found seven remote access tool (RAT) families in use, five of which were previously undocumented; we identified and named them: DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT, and NodeEdgeRAT. The toolset is small, modular, and…
-
Former Ping Identity and CyberArk Executives Join AppViewX to Scale Machine and Agent Identity Security
New York, New York, August 19th, 2026, CyberNewswire New revenue leader and board member join as AppViewX’s identity security business continues its rapid growth AppViewX, the leading machine and agent identity security company built for the AI and quantum enterprise, today announced the appointment of Mike Durso as Chief Revenue Officer and the addition of…
-
Exclusive: Linux Foundation’s Akrites to Go Live in September
The Linux Foundation’s Akrites initiative will become operational in September, when it will begin accepting AI-powered vulnerability reports for open-source projects First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/linux-foundations-akrites-go-live/
-
AI Governance Without Surveillance: The Missing Evidentiary Layer
We do not need to record everything an AI system sees. We do need reliable evidence of what it used, who authorized it and what it changed. For most of the history of cybersecurity, governance has followed a familiar recipe: define a policy, identify an accountable person, collect logs and investigate exceptions. It is imperfect,..…
-
Quantum-Safe Isn’t Cyber-Safe
Tags: access, ai, api, breach, communications, compliance, computer, computing, credentials, cryptography, cyber, data, defense, encryption, exploit, flaw, google, group, ml, openai, password, radius, risk, threat, update<div cla In the same week federal agencies began scoping migrations under the White House’s new Post-Quantum Cryptography Executive Order, a group of academic researchers published a paper that, on its face, had nothing to do with quantum computing at all. It described a flaw in how three of the most security-conscious engineering organizations on…

