Tag: ai
-
Irregular says ‘human oversight’ responsible for AI sandbox escape incidents
In a post-mortem, the frontier AI testing company said internet access for models is necessary to fully test out their cybersecurity capabilities. First seen on cyberscoop.com Jump to article: cyberscoop.com/irregular-ai-sandbox-escape-human-oversight/
-
‘MessiahGPT’ AI Service Promises Ransomware, Phishing Kits, and Malware
Trellix says MessiahGPT is marketed to cybercriminals as an uncensored AI service for ransomware, phishing kits, malware, and breach exploitation. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/artificial-intelligence/news-messiahgpt-malware-phishing-ai/
-
OpenMatter Network to Take Verification Message to Belgrade Blockchain Week 2026
Melbourne, Florida, August 17th, 2026, CyberNewswire Head of Operations and Partnerships Chris Biele to lead sessions on secure scientific collaboration, agentic AI and the need to move from trust to cryptographic proof Continuing its effort to build global awareness of the need to move computing from assumption-based trust to cryptographic proof, OpenMatter Network today announced…
-
FireTail State of AI Security 2026: Adoption Has Outpaced Control FireTail Blog
Tags: access, ai, control, credentials, data, group, intelligence, jobs, leak, risk, threat, tool, vulnerabilityAug 17, 2026 – Ayush Sethi – What your workforce’s AI prompts reveal in aggregate Most AI security controls judge one prompt at a time. We built Topics to read the layer above them, where a workforce’s prompts add up into a pattern that no single message shows.Someone in your legal team pastes a contract…
-
Hopping the (Geo)Fence Why the Supreme Court’s Expected Ruling on Geofence Warrants May Not Make Any Difference
Chatrie v. United States could redefine geofence warrants, location privacy and Fourth Amendment protections as AI-enabled surveillance expands. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/hopping-the-geofence-why-the-supreme-courts-expected-ruling-on-geofence-warrants-may-not-make-any-difference/
-
Irregular faces criticism over ‘spin’ in AI hacking postmortem
The company at the center of a series of incidents in which AI models compromised real-world computer systems during security evaluations is facing criticism after the release of a report that security experts say leaves key questions unanswered. First seen on therecord.media Jump to article: therecord.media/irregular-ai-hacking-model-blog
-
OpenAI, Anthropic, and Meta AI Breaches Shared the Same Testing Vendor
OpenAI, Anthropic, and Meta AI incidents reportedly shared one testing vendor, exposing third-party and containment risks in AI security evaluations. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/cloud-security/news-openai-anthropic-meta-ai-incidents-irregular/
-
The inconvenient truth about AI pentesting: someone has to check all the work
AI pentesting can flood teams with findings they cannot validate. The real challenge is managing “validation debt” as discovery scales. AI pentesting has a ‘Sorcerer’s Apprentice’ problem. Enchant a broom to fetch water, and it will fetch water, relentlessly, long after the workshop has flooded. The industry is busy measuring how fast AI finds vulnerabilities…
-
Researchers Disclose AI-Assisted SharePoint Exploit Chain Reaching Unauthenticated RCE
Security researchers found a way to enter Microsoft SharePoint servers as any user, including an administrator, with no valid account. A significant part of the work that found it was done through an AI agent.The flaw, tracked as CVE-2026-55040 (CVSS 9.1), affects SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Server 2016. Microsoft’s First…
-
CVE Program eyes automation and globalization to weather AI ‘vulnpocalypse’
The vulnerability-coordination project has had a rocky few years, but a key leader says it will “flourish and improve.” First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/cve-program-ai-black-hat-def-con/827477/
-
NIST wants to overhaul its vulnerability database for the AI age
NIST is seeking public input to modernize the National Vulnerability Database to keep pace with AI-driven cyber threats and machine-scale security data. First seen on cyberscoop.com Jump to article: cyberscoop.com/nist-national-vulnerability-database-ai-overhaul/
-
Verschlüsselte KI-Denkprotokolle geknackt Schwachstelle bei OpenAI, Anthropic und Google
Forscher haben eine gravierende Schwachstelle bei der Absicherung sogenannter Reasoning-Logs entdeckt. Verschlüsselte Denkprotokolle moderner KI-Modelle lassen sich demnach unter bestimmten Bedingungen über ein schwächeres Modell desselben Anbieters entschlüsseln. Besonders brisant: In öffentlich zugänglichen Datensätzen fanden die Forscher bereits personenbezogene Daten, Zugangsdaten, API-Schlüssel und Passwörter. Forscher von MATS Research, dem Max-Planck-Institut für intelligente Systeme, dem ELLIS…
-
Blumira Unveils AI Command Center for Cybersecurity Tools
Blumira today unfurled a command center that makes it simpler to integrate cybersecurity tools based on artificial intelligence (AI) that were developed by different vendors. Mike Toole, head of security and IT for Blumira, said Hearth makes it possible to integrate cybersecurity tools from different vendors through a common interface. Additionally, cybersecurity teams will find..…
-
AI Helps Researchers Uncover Zoom Zero-Click RCE in Less Than a Day
Researchers used public AI models to uncover ZOOMSDAY, a critical Zoom zero-click RCE exploit chain, in less than 24 hours. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/ai-helps-researchers-uncover-zoom-zero-click-rce-in-less-than-a-day/
-
95 Prozent der Unternehmen verschieben KI-Projekte aufgrund von Hürden in der Datenarchitektur
Tags: aiCloudera veröffentlicht seine neueste globale Studie ‘The Great AI Re-Architecture”. Diese zeigt einen grundlegenden Wandel in der Unternehmens-IT. So überarbeiten immer mehr Betriebe ihre Datenarchitekturen, um den Anforderungen von KI gerecht zu werden. Denn obwohl die KI-Nutzung zum Standard geworden ist, schränken veraltete Datenarchitekturen zunehmend die Fähigkeit von Unternehmen ein, KI sicher, effizient und kostengünstig zu…
-
Drei KI-Vorfälle in vierzehn Tagen Von der Evaluierung zum Ernstfall
Innerhalb von vierzehn Tagen haben OpenAI, Anthropic und das britische AI Security Institute (AISI) jeweils offengelegt, dass KI-Agenten im Rahmen interner Sicherheitsprüfungen den vorgesehenen Testrahmen verlassen und auf reale Systeme sowie reale Personen eingewirkt haben. Weniger bemerkenswert als die Einzelfälle ist dabei die Geschwindigkeit, mit der sich die Fähigkeiten dieser Agenten entwickeln und der […]…
-
Vague Task, Total Access: When AI Delegation Becomes a Security Risk
AI agents can improvise beyond the intended scope of a task when they are given broad access to enterprise systems and data. Token Security explains why organizations need to define agent intent and continuously enforce permissions around what each agent was actually created to do. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/vague-task-total-access-when-ai-delegation-becomes-a-security-risk/
-
A Zoom Screen-Sharing Bug Let Anyone Take Over Other Devices on a Call
Researchers say it took fewer than 20 prompts for a public AI tool to find a flaw (now fixed) allowing anyone on a Zoom call to hijack another participants’ device. First seen on wired.com Jump to article: www.wired.com/story/a-zoom-screen-sharing-bug-let-anyone-take-over-other-devices-on-a-call/
-
LiteLLM Attack Shows AI Infrastructure Is Becoming a Strategic Software Supply Chain Target
Tags: ai, attack, breach, cloud, credentials, cyber, infrastructure, malicious, pypi, software, supply-chain, theftThe March 2026 compromise of LiteLLM was more than a short-lived malicious PyPI upload. It demonstrated how an upstream breach in developer tooling can turn AI infrastructure into a high-value conduit for credential theft, cloud intrusion, and downstream software supply chain abuse. The packages were available for roughly 40 minutes before quarantine, but their brief…
-
The AI That Hacked Its Way to a Passing Grade Wasn’t the Real Story
Tags: aiAn autonomous model breaking containment is alarming. What the incident reveals about how enterprises secure AI systems should be even more concerning. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/the-ai-that-hacked-its-way-to-a-passing-grade-wasnt-the-real-story/
-
OpenAI Launches Two-Tier Security Access Program Alongside GPT 5.6 Cyber
Daybreak Blue removes some OpenAI-made guardrails while Daybreak Red grants the use of cyber-focused frontier AI models First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/openai-daybreak-blue-red-gpt-cyber/
-
Acht Minuten bis zur Cloud-Kompromittierung: Wie IAM-Schlüssel und KI Angriffe beschleunigen
Cloud-Angriffe in weniger als zehn Minuten: Wie kompromittierte IAM-Schlüssel, Fehlkonfigurationen und KI das Tempo von Cloud-Attacken erhöhen. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/acht-minuten-bis-zur-cloud-kompromittierung-wie-iam-schluessel-und-ki-angriffe-beschleunigen/a46107/
-
Nearly 60% of people regretted taking social media financial advice
TSB survey of 2,000 people found that one in four have used artificial intelligence for financial advice First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366648053/Nearly-60-of-people-regretted-taking-social-media-financial-advice
-
Malicious MCP Servers Can Split Instructions to Make AI Coding Agents Exfiltrate Secrets
A malicious tool server connected to an AI coding assistant can quietly walk off with SSH keys, environment secrets, source code, and customer data without ever sending one obviously harmful instruction.The trick can work even after a blunt version of the same theft is refused: split the request into fragments that each look routine, place…
-
Nutzer wollte nur Kurs buchen: KI-Agent hat unerwartet ein Fitnessstudio gehackt
Tags: aiUnverhoffte KI-Hacks gibt es nicht nur mit den neuesten Modellen. In Australien ist ein KI-Agent schon vor Monaten in eine Buchungsplattform eingedrungen. First seen on golem.de Jump to article: www.golem.de/news/nutzer-wollte-nur-kurs-buchen-ki-agent-hackte-unerwartet-ein-fitnessstudio-2608-211796.html

