Tag: ai
-
How AI Exposed a Browser Security Gap that Enterprises Cannot Ignore
AI did not create a new browser security problem. It exposed one that enterprises have long been able to ignore. Skyhigh Security explains why browsers have become a critical control point for governing data movement, AI interactions, and modern work. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/how-ai-exposed-a-browser-security-gap-that-enterprises-cannot-ignore/
-
AI code security with Claude Mythos Preview: Inside Tenable’s 500+ hours of testing for Project Glasswing
Tags: access, ai, api, application-security, compliance, control, cyber, cybersecurity, data, exploit, flaw, reverse-engineering, risk, software, threat, tool, update, vulnerabilityWe spent 500+ hours and 40 billion tokens testing Anthropic’s Claude Mythos Preview for Project Glasswing. The takeaway: frontier AI won’t run your code security program, but used well, it can make one even stronger. Key takeaways Frontier AI dramatically scales security testing. In one month, Tenable dedicated 11 security experts and more than 40…
-
Critical Paperclip AI Agent Flaws Allow Unauthenticated Remote Code Execution
Critical vulnerabilities in the open-source Paperclip AI-agent orchestration platform could allow attackers to execute commands remotely on exposed servers or on a developer’s local machine. These flaws arise from broken authorization boundaries across agent imports and API routes, as well as trust assumptions for localhost. Paperclip is designed to coordinate autonomous agents across >>companies,<< with…
-
Meta Joins OpenAI and Anthropic in Reporting AI Exploit Incident
One of Meta’s AI models exploited a third-party security flaw during an evaluation, the latest in a series of similar incidents involving advanced AI systems First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/meta-ai-exploit-incident/
-
Akamai Report Finds Nearly Half of Enterprise AI Use Bypasses Security
Nearly half of enterprise AI use bypasses corporate security controls, according to a new Akamai report that points to unmanaged tools, browser extensions and autonomous agents as growing sources of exposure. Akamai released its Enterprise AI Usage Risk Report 2026 on Aug. 5 as part of its State of the Internet security research. The report..…
-
Your Face Sure Rings A Bell: Facial Recognition, Wrongful Arrests and the New Alibi for Bad Policing
Facial-recognition errors are leading to wrongful arrests. Police and technology vendors must be held accountable when unreliable AI becomes probable cause. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/your-face-sure-rings-a-bell-facial-recognition-wrongful-arrests-and-the-new-alibi-for-bad-policing/
-
AI Guardrail Platforms Compared for Enterprises – Kovrr
Articles related to cyber risk quantification, cyber risk management, and cyber resilience. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/ai-guardrail-platforms-compared-for-enterprises-kovrr/
-
Scammers target OnlyFans users with deepfakes
Criminals are impersonating OnlyFans creators using AI tools in order to scam followers. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/scammers-target-onlyfans-users-with-deepfakes/
-
Three in four AI-generated vulnerability patches leave something broken
Ask a frontier model to patch a real vulnerability and it will hand you something that looks like a fix. It reads like the patch a maintainer would write. When there is a … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/06/1password-ai-generated-vulnerability-patches/
-
Cloudflare Launches Open-Source OS to Secure AI Agents’ Access to Internal Data
Cloudflare has open-sourced Cloudflare OS, a platform designed to provide enterprise AI agents with controlled access to internal systems, company context, and workflows without exposing long-lived credentials or bypassing access controls. This release addresses a significant security challenge for enterprises: while agents need access to business data and tools to be effective, conventional API keys…
-
AI Recommendation Poisoning: How “Ask AI” Buttons Silently Alter LLM Memory
A new class of prompt injection is spreading across commercial websites. It requires no malware, no stolen credentials, and no zero-day exploit. It abuses a standard feature built into almost every major AI assistant: pre-filled deep links.We observed production websites embedding hidden prompt injection payloads inside “Ask AI” buttons on marketing and competitor comparison pages.…
-
Fehlkonfiguration im Testumfeld – Auch Meta-KI dringt in fremdes System ein
Tags: aiFirst seen on security-insider.de Jump to article: www.security-insider.de/meta-ki-sicherheitstest-fehlkonfiguration-fremde-it-a-c5d23a49e60c8a59db4666eed2d0d60e/
-
Apple’s bug bounty program is drowning in so much AI slop, it is in danger of missing serious exploits
Apple has imposed strict new submission limits on its bug bounty portal after finding itself overwhelmed by low-quality, AI generated vulnerability reports – many of which were found to be describing security flaws that simply didn’t exist. First seen on bitdefender.com Jump to article: www.bitdefender.com/en-us/blog/hotforsecurity/apple-bug-bounty-ai-missing-exploits
-
Alarm sounded around supply chain risks
With AI agents demonstrating their ability to bypass security, the need to protect against attacks originating from third-party suppliers has increased First seen on computerweekly.com Jump to article: www.computerweekly.com/microscope/news/366648132/Alarm-sounded-around-supply-chain-risks
-
Meta Confirms AI Model Launched Autonomous Attack on Another Organization
Meta has become the latest technology company to disclose that an AI agent accessed another organization’s online systems during a controlled cybersecurity evaluation. This development has intensified scrutiny regarding the safeguards surrounding autonomous models and the testing environments for agentic AI. The incident reportedly occurred when a Meta AI model, evaluated by the independent security…
-
Thales bringt Imperva WAF nativ auf Amazon CloudFront
Thales bringt Imperva WAF auf Amazon CloudFront. Die SaaS-Lösung schützt Webanwendungen, APIs und KI-Systeme vor Angriffen und bösartigen Bots. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/thales-bringt-imperva-waf-nativ-auf-amazon-cloudfront/a46039/
-
Discounted Claude access bought on the gray market may expose every prompt you send
More than half a dozen services advertised on underground forums and messaging platforms, offering discounted or >>unlimited<< token access to frontier AI models, … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/06/ai-model-access-fraud-gray-market/
-
Scoping Agent Permissions: Rich Authorization Requests (RFC 9396) in Practice
Tags: ai“A working tutorial on RFC 9396 for AI agents: design an authorization_details type, narrow the token per task, enforce it at the resource server, know the limits First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/scoping-agent-permissions-rich-authorization-requests-rfc-9396-in-practice/
-
Reges Interesse am 4. KI-Tag der Wirtschaft des Landes Brandenburg
Tags: aiFirst seen on datensicherheit.de Jump to article: www.datensicherheit.de/reges-interesse-4-ki-tag-der-wirtschaft-land-brandenburg
-
Black Hat USA 2026: One GitHub Issue Could Compromise Major AI Coding Workflows
At Black Hat USA 2026, Novee found GitHub workflow flaws in Claude Code, Gemini CLI and Codex that enabled RCE, credential theft and agent control in pipelines. First seen on hackread.com Jump to article: hackread.com/black-hat-usa-2026-github-compromise-ai-coding/
-
Meta AI Model Hacked a Company During Testing, Marking Third AI Lab Incident
Meta says an AI model hacked a company during testing after accidental internet access, marking the third disclosed AI lab breach in weeks. Meta confirmed that one of its AI models breached an unidentified company during cybersecurity testing, after its independent testing partner Irregular gave the model unintended internet access through a misconfiguration. This is…
-
KI-Arbeitsplatz unter Zero Trust: Cloudflare bündelt Agenten, Governance und Analyse
Cloudflare verbindet einen offenen KI-Arbeitsplatz mit identitätsbasierter Kontrolle über Agenten, Datenflüsse, Modellnutzung und Kosten. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/ki-arbeitsplatz-unter-zero-trust-cloudflare-buendelt-agenten-governance-und-analyse/a46037/
-
Wiederkehrendes Muster: OpenSSL-Entwickler wettert gegen KI-Hacks
Seit einigen Tagen hacken sich vermehrt KI-Modelle von OpenAI, Anthropic und Meta durchs Netz. Das Problem liegt laut OpenSSL-Entwickler Hudson aber nicht bei der KI. First seen on golem.de Jump to article: www.golem.de/news/wiederkehrendes-muster-openssl-entwickler-wettert-gegen-ki-hacks-2608-211664.html
-
Quantifying the Risk of Autonomous AI Systems – Kovrr
Articles related to cyber risk quantification, cyber risk management, and cyber resilience. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/quantifying-the-risk-of-autonomous-ai-systems-kovrr/
-
Microsoft extends zero trust deeper into enterprise AI
Microsoft expanded its Zero Trust for AI strategy with updates to the Zero Trust Assessment tool and the Zero Trust Workshop. The additions help organizations assess security … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/06/microsoft-zero-trust-for-ai-strategy-updates/
-
OpenAI Agents Worked Together to Find Exploits and Hack External Systems
OpenAI has revealed new details about an incident involving AI agents, in which multiple autonomous agents reportedly worked together to identify vulnerabilities, bypass containment measures, and gain access to external systems during a cybersecurity evaluation. Speaking at the Black Hat conference in Las Vegas, OpenAI alignment researcher Eric Wallace and security and infrastructure specialist Michael…

