Tag: ai
-
Malicious MCP Servers Can Split Instructions to Make AI Coding Agents Exfiltrate Secrets
A malicious tool server connected to an AI coding assistant can quietly walk off with SSH keys, environment secrets, source code, and customer data without ever sending one obviously harmful instruction.The trick can work even after a blunt version of the same theft is refused: split the request into fragments that each look routine, place…
-
Nutzer wollte nur Kurs buchen: KI-Agent hat unerwartet ein Fitnessstudio gehackt
Tags: aiUnverhoffte KI-Hacks gibt es nicht nur mit den neuesten Modellen. In Australien ist ein KI-Agent schon vor Monaten in eine Buchungsplattform eingedrungen. First seen on golem.de Jump to article: www.golem.de/news/nutzer-wollte-nur-kurs-buchen-ki-agent-hackte-unerwartet-ein-fitnessstudio-2608-211796.html
-
Fast die Hälfte der KI-Nutzung in Unternehmen basiert auf ungesicherter Schatten-KI
Bericht thematisiert unautorisierte Anwendungen, neue Angriffsvektoren und erforderliche Sicherheitsstrategien. Management Summary Schatten-KI ist kein Randphänomen mehr: Fast jede zweite KI-Interaktion läuft über private Identitäten und entzieht sich damit Governance, Monitoring und Compliance. Die Angriffsfläche verlagert sich in den Browser und die Entwicklungsumgebung: Erweiterungen, KI-Coding-Assistenten und agentische Browser werden zu neuen Einfallstoren für Datenabfluss und……
-
Mythos und KI-Cybersicherheit: Geschwindigkeit wird zum entscheidenden Sicherheitsfaktor
KI erfindet Cyberrisiken nicht neu, beschleunigt aber Angriffe und Schwachstellensuche. Was Mythos für Vulnerability Management und Cyberabwehr bedeutet. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/mythos-und-ki-cybersicherheit-geschwindigkeit-wird-zum-entscheidenden-sicherheitsfaktor/a46089/
-
Anthropic Adds Invisible Watermarks to Claude AI-Generated Text and Signed Metadata to Files
Anthropic has launched a machine-readable content-marking initiative for materials generated by its Claude models. This initiative combines invisible text watermarks with digitally signed provenance metadata for supported files. This move follows Anthropic’s commitment to the transparency guidelines outlined in Article 50(2) of the European Union AI Act. Anthropic Adds Invisible Watermarks to Claude According to…
-
OpenAI, Anthropic und AISI: Was die drei KI-Vorfälle über Agentensicherheit aussagen
Drei KI-Sicherheitsvorfälle bei OpenAI, Anthropic und AISI zeigen, warum Unternehmen Kontrolle, Monitoring und Governance für KI-Agenten benötigen. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/openai-anthropic-und-aisi-was-die-drei-ki-vorfaelle-ueber-agentensicherheit-aussagen/a46084/
-
OpenAI Launches GPT-5.6-Cyber to Find Zero-Day Vulnerabilities and Develop Exploit Chains
OpenAI has expanded its Daybreak cybersecurity program with the introduction of GPT-5.6-Cyber, a purpose-trained model specifically designed for authorized vulnerability research, exploit validation, and advanced security testing. Built on the foundation of GPT-5.6 Sol, this new model serves as a controlled-access tool for trusted defenders as AI-assisted offensive capabilities continue to evolve. GPT-5.6-Cyber to Find…
-
Nach KI-Hacks: Chinesisches KI-Modell trickst Forscher bei Tests aus
Das KI-Modell Kimi K3 hat bei Tests eine gesicherte Umgebung verlassen und sich die gesuchten Lösungen einfach bei Github beschafft. First seen on golem.de Jump to article: www.golem.de/news/nach-ki-hacks-chinesisches-ki-modell-trickst-forscher-bei-cybertests-aus-2608-211748.html
-
An AI tool found 84 flaws in 5G network software and 23 of them still have no fix
Researchers at Nanyang Technological University turned a set of AI agents loose on the software that runs 4G and 5G phone networks, and the agents came back with 84 security … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/11/5g-core-network-vulnerabilities-research/
-
KI-Vorfälle nur Symptome IT-Sicherheit muss auf Identitäten fokussieren
Tags: aiFirst seen on datensicherheit.de Jump to article: www.datensicherheit.de/ki-vorfaelle-symptome-it-sicherheit-identitaeten-fokus
-
Gym Booking Task Turns Into Real-World AI Cyberattack
An AI agent hacked a gym booking system while trying to help a user, booking early and removing another person from the waitlist. An Australian man asked his AI assistant to book him into a gym class. He didn’t ask it to hack the booking software, and he definitely didn’t ask it to remove another…
-
Meta Puts Open-Source AI Bet on Muse Glimmer
Local Agentic AI Model Targets Coding, Tool Calling and Multi-Step Tasks. Meta hopes to recapture the momentum it had when it first launched its Llama artificial intelligence model. Now, with a new model and an increased focus on open-source AI, the social media giant is going against the more proprietary approach of its competitors. First…
-
‘GhostJacking’ Exposes Identity Governance Gaps in AI Agents
New research shows how attackers can use security alerts and blocked events to manipulate and hijack AI agents. First seen on darkreading.com Jump to article: www.darkreading.com/cyber-risk/ghostjacking-identity-governance-gaps-ai-agents
-
The FTC wants to regulate AI for ideological bias
The commission is mulling whether to begin regulating bias in AI systems. Critics say they’re overstepping their legal authority and infringing on free speech. First seen on cyberscoop.com Jump to article: cyberscoop.com/ftc-regulating-ai-ideological-bias/
-
Obsidian Secures $85M to Control AI Agents in SaaS Apps
CEO Hasan Imam Says AI Agents Are Already Modifying and Deleting Enterprise Data. Obsidian Security raised $85 million at a $1.1 billion valuation to expand real-time monitoring and enforcement as enterprises give autonomous AI agents access to sensitive data and the ability to modify or delete information inside SaaS and other third-party applications. First seen…
-
AI Moves From Cheating in Theory to Hacking the Real World
Why Zero Trust for AI and Enforced Hard Constraints Beat Easily Ignored Rules Among the many lessons learned from the OpenAI sandbox escape/Hugging Face hack and the more recent Claude accidental escape is that artificial intelligence cheats: It breaks rules then denies it. These aren’t anomalies. They’re fundamental systemic failures. First seen on govinfosecurity.com Jump…
-
NATO and an AI startup can now name and track software vulnerabilities
Tags: ai, communications, cyber, cybersecurity, defense, flaw, intelligence, software, startup, vulnerabilityNATO’s cyber defense arm and a startup that uses artificial intelligence to find software flaws can now issue the ID numbers the industry uses to track those flaws, the European Union Agency for Cybersecurity announced last week. The NATO Cyber Security Centre, part of the NATO Communications and Information Agency, and AISLE, a cybersecurity company…
-
Kimi K3 Reached GitHub During Cybersecurity Test, Exposing Sandbox Gap
Kimi K3 reached GitHub during a cybersecurity test, prompting a dispute over AI guardrails, sandbox configuration, and agent containment. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/artificial-intelligence/news-kimi-k3-github-sandbox-security-test/
-
DEF CON 34: 10 Vulnerabilities Put Local AI at Risk
DEF CON 34 research revealed 10 vulnerabilities in llama.cpp, exposing critical memory-safety flaws. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/def-con-34-10-vulnerabilities-put-local-ai-at-risk/
-
âš¡ Weekly Recap: AI Goes Rogue, Metabase 0-Day, MCP Supply-Chain Attacks, and Router Backdoors
A lot of security problems still begin with someone doing a completely normal thing. Cloning a repo. Answering a call. Leaving a box exposed. Trusting the default.That pretty much covers the mood this week. Old bugs are back, supply chains are getting stranger, and some exploit paths are so short you wonder what was supposed…
-
Frontier AI Is Driving Urgency for Application Resilience and Security
Frontier AI models are challenging organizations to respond to AI-fueled attacks at unprecedented speed. At the same time, the rapid deployment of AI-powered services, automated processes, and real-time decision systems leveraging Kubernetes-based environments puts new pressures on digital infrastructure. The urgency has never been greater, and application delivery and security must keep pace. Traffic patterns..…
-
AI Threat Intelligence vs. Traditional Threat Intelligence: A Practical Guide for CISOs
Most CTI programs aren’t failing because analysts lack skill. They’re failing because signal volumes have outpaced what any manual workflow can process. Thousands of newly registered domains, phishing kit variants, and brand impersonation attempts surface daily. Human teams can’t triage all of it. Threat intelligence automation addresses the throughput problem by automating collection, enrichment and..…
-
Secure development can help turn the tables as AI alters cyber landscape
A top Microsoft executive says a shift toward memory safety and other preventative measures can limit the ability to exploit flawed software. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/secure-development-ai-cyber-vulnerabilities-Black-Hat/827435/
-
Claude-Powered Agent Exploits Australian Gym API, Removes Waitlisted Member
A Claude-powered AI agent exploited an Australian gym API flaw, removed a member from a waitlist, and exposed new risks from autonomous agents. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-claude-ai-agent-australian-gym-api-flaw-apac/
-
Researchers Uncover RovoBlast Vulnerability in Atlassian AI Assistant
Atlassian fixed a flaw letting one crafted link make its Rovo AI assistant exfiltrate company data First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/rovoblast-atlassian-rovo-url/
-
Margarita Howard’s HX5 Operationalizes CMMC Compliance Before AI Rules Arrive
Margarita Howard has spent two decades running a company in a government contracting market where the rules rarely hold still. HX5, the defense and aerospace services firm she founded in 2004 and still leads, supports Department of Defense and NASA missions and has employed over 1,000 people across 34 states and 90 government locations over…
-
Kimsuky Builds Offline AI Stack to Boost Phishing and Automate Malware Development
North Korea’s state hackers are no longer content to type prompts into public chatbots. One of the country’s main espionage groups has begun running artificial intelligence (AI) offline on its own servers, connecting document-search tools to files in its possession, and collecting the software parts needed to build AI into its malware.South Korean security firm…
-
Cloud- und Netzwerkprobleme: Verbindungsfehler kosten mehr als einen Arbeitstag pro Woche
Viele IT-Entscheider halten ihre Netzwerke für Cloud- und KI-Dienste geeignet. Dennoch muss viel Zeit in die Fehlerbehebung investiert werden. First seen on golem.de Jump to article: www.golem.de/news/cloud-und-netzwerkprobleme-verbindungsfehler-kosten-mehr-als-einen-arbeitstag-pro-woche-2608-211777.html
-
Why transparent AI agents matter more than you think
The difference between a prompt injection attack you’ll catch and one you won’t might just be whether your AI agent can explain itself. First seen on cyberscoop.com Jump to article: cyberscoop.com/transparent-ai-agent-security-op-ed/

