Tag: ai
-
Urlaubszeit Sommerzeit Vorfallzeit: Sechs Ratschläge für Zeiten mit geringer Personalstärke
Management Summary Urlaubszeit ist Risikobetrieb: Reduzierte Personalstärke, höhere Abhängigkeit von IT-Systemen und wachsende Angriffsflächen machen die Sommermonate zu einer Phase mit erhöhtem Kontrollbedarf. KI verändert das Schwachstellenmanagement: Frontier-KI-Modelle beschleunigen die Entdeckung und Veröffentlichung von Verwundbarkeiten; Patch-, CERT- und Threat-Feed-Prozesse müssen deshalb auch in Ferienzeiten aktiv bleiben. Klare Rollen verhindern Wissensmonopole: Ein offiziell definierter Reduced Staff……
-
Keepit AI Truth Cloud: Verifizierte Backup-Daten sollen Enterprise-KI absichern
Keepit stellt AI Truth Cloud vor: Unveränderliche Backup-Daten, MCP-Integration und AI Safe Room sollen eine vertrauenswürdige Basis für Enterprise-KI schaffen. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/keepit-ai-truth-cloud-verifizierte-backup-daten-sollen-enterprise-ki-absichern/a46059/
-
Webmail CSS Attacks Expose a New Risk for AI-Powered Email Tools
CSS attacks on major webmail services can steal credentials, hijack sessions and manipulate AI tools connected to users’ inboxes. PortSwigger researcher Gareth Heyes demonstrated something that should make every webmail team a little nervous: plain CSS, the styling language that’s supposed to just make text look nice, can be weaponized to steal passwords, hijack sessions, and…
-
EU AI Act Compliance Roadmap: What to Document – Kovrr
Articles related to cyber risk quantification, cyber risk management, and cyber resilience. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/eu-ai-act-compliance-roadmap-what-to-document-kovrr/
-
Astra: OpenAI will neues KI-Modell vorerst nicht veröffentlichen
Wie gefährlich darf eine KI werden, bevor sie zur Waffe wird? OpenAI kann diese Frage bei seinem Modell Astra derzeit nicht mehr sicher beantworten. First seen on golem.de Jump to article: www.golem.de/news/astra-openai-will-neues-ki-modell-vorerst-nicht-veroeffentlichen-2608-211738.html
-
Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers
Attacker-controlled instructions can make Atlassian’s Rovo assistant collect Jira or Confluence data that a signed-in user can access, then send it to an outside server. Two security firms found that behavior independently, by different routes. Only one of those routes is confirmed closed.PromptArmor, an AI security firm, hid the instructions in content Rovo reads. It…
-
New CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens
New research shows content inside an email can escape its message boundary and interfere with the webmail interface.Across attack chains spanning Outlook, Gmail, Fastmail, Proton Mail, Yahoo Mail, and AOL Mail, the techniques can capture passwords, take over third-party accounts, leak tokens, hijack trusted UI actions, and manipulate AI tools that read email.PortSwigger researcher Gareth…
-
Nach OpenAI und Anthropic: Auch chinesisches KI-Modell aus Testumgebung ausgebrochen
First seen on t3n.de Jump to article: t3n.de/news/chinesisches-ki-modell-kimi-k3-aus-testumgebung-ausgebrochen-1757100/
-
„Ein Problem, das grundsätzlich unlösbar ist”: Warum KI-Modelle vielleicht nie sicher sein werden
Tags: aiFirst seen on t3n.de Jump to article: t3n.de/news/problem-unloesbar-ki-modelle-sicher-1755811/
-
AI chat bots are sliding into League of Legends friend requests
Chat bots are sending friend requests in Riot immediately after ending your game. What are the scammers up to now? First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/ai-chat-bots-are-sliding-into-league-of-legends-friend-requests/
-
Imperva Customers Protected Against Novel HTTP Desync Attacks
TL;DR: Recent Portswigger research introduced novel HTTP desync techniques discovered through an AI-assisted research system called the HTTP Terminator. The findings expand the range of unusual HTTP behaviors that can cause front-end and back-end systems to interpret the same traffic differently. Imperva Cloud WAF and On-Prem WAF customers are protected against practical attack patterns described in the research. Imperva’s existing security engine already blocked malicious……
-
Account-Farming für Claude & Co.: Wie billige KI-Tokens zum Security-Risiko werden
Graumärkte verkaufen Zugänge zu Frontier-KI bis zu 90 Prozent günstiger. Okta zeigt die Risiken durch Account-Farming, Proxies und statische API-Keys. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/account-farming-fuer-claude-co-wie-billige-ki-tokens-zum-security-risiko-werden/a46052/
-
The Exam Before Enterprise Deployment
Tags: aiWhat it takes to trust an AI agent at work from Yuan (Emily) Xue, Head of Enterprise AI, Scale AI First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/the-exam-before-enterprise-deployment/
-
18-Year-Old Linux Kernel SCTP Vulnerability Lets Attackers Gain Root and Escape Containers
SCTPhantom, tracked as CVE-2026-64564, is a high-severity Linux kernel use-after-free vulnerability in the Stream Control Transmission Protocol (SCTP) Dynamic Address Reconfiguration implementation. Researchers at Tencent Zhuque Lab’s Corvus AI project reported that a local attacker could leverage the flaw to escalate privileges to root and, in certain configurations, to escape from containers to the host.…
-
Russian Hackers Use AI Slopsquatting to Publish 700+ Malicious npm Packages
A large-scale supply chain attack has hit the npm registry, with a suspected Russian threat actor publishing more than 700 malicious packages in just 48 hours. Researcher Paul McCarty documented the campaign, tracked as WEL1DROPPER, and the package count has since grown past 1,000. WEL1DROPPER marks an evolution in AI slopsquatting, where attackers register randomly…
-
Forcepoint’s Ronan Murphy on securing the data layer AI just set on fire
First seen on scworld.com Jump to article: www.scworld.com/resource/forcepoints-ronan-murphy-on-securing-the-data-layer-ai-just-set-on-fire
-
Keyfactor’s Ellen Boehm on enterprise AI at scale
Tags: aiFirst seen on scworld.com Jump to article: www.scworld.com/resource/keyfactors-ellen-boehm-on-enterprise-ai-at-scale
-
MSSP Market News: AI in security hits two big questions revenue and responsibility
First seen on scworld.com Jump to article: www.scworld.com/news/mssp-market-news-ai-security-platforms-take-on-more-of-the-soc-ahead-of-black-hat-2026-1
-
MSSP Market News: AI in security hits two big questions revenue and responsibility
First seen on scworld.com Jump to article: www.scworld.com/news/mssp-market-news-ai-security-platforms-take-on-more-of-the-soc-ahead-of-black-hat-2026-1
-
AI coding tools vulnerable to malicious GitHub issues
First seen on scworld.com Jump to article: www.scworld.com/brief/ai-coding-tools-vulnerable-to-malicious-github-issues
-
Channel Brief: The MSP AI challenge: Sell it, price it, make it profitable
First seen on scworld.com Jump to article: www.scworld.com/news/channel-brief-ai-native-is-the-new-pitch-msps-are-still-working-out-the-pricing
-
How we can apply lessons from The Odyssey to the AI challenge
Tags: aiFirst seen on scworld.com Jump to article: www.scworld.com/perspective/how-we-can-apply-lessons-from-the-odyssey-to-the-ai-challenge
-
F5’s Sean Murphy on securing frontier AI as attack and defense accelerate
First seen on scworld.com Jump to article: www.scworld.com/resource/f5s-sean-murphy-on-securing-frontier-ai-as-attack-and-defense-accelerate
-
Orca’s Gil Geron on securing the AI-powered enterprise
Tags: aiFirst seen on scworld.com Jump to article: www.scworld.com/resource/orcas-gil-geron-on-securing-the-ai-powered-enterprise
-
Island’s Michael Leland on the hidden risks of the AI supply chain
First seen on scworld.com Jump to article: www.scworld.com/resource/islands-michael-leland-on-the-hidden-risks-of-the-ai-supply-chain
-
Black Hat 2026: Open-source tool makes red teaming AI agents up to 125x cheaper
First seen on scworld.com Jump to article: www.scworld.com/news/black-hat-2026-open-source-tool-makes-red-teaming-ai-agents-up-to-125x-cheaper
-
Approved software is creating a new shadow AI blind spot
First seen on scworld.com Jump to article: www.scworld.com/perspective/approved-software-is-creating-a-new-shadow-ai-blind-spot
-
KI als Produktivitätstreiber: Beschäftigte gewinnen bis zu acht Stunden pro Woche
Tags: aiFirst seen on datensicherheit.de Jump to article: www.datensicherheit.de/ki-produktivitatstreiber-zeitgewinn-mitarbeiter
-
AI Sandbox Failures Expose Need for Continuous Monitoring
Recent AI Incidents Show Sandbox Security Cannot Be Assumed. The fallout from the Hugging Face security incident continues with more artificial intelligence labs revealing that their models and agents either accessed the internet or escaped isolated test environments to hack into other companies. Frontier model labs can’t take sandbox containment as a given. First seen…

