Tag: ai
-
Horizon3 Raises $250M to Prove What Attackers Can Exploit
Startup Says Autonomous Testing Can Demonstrate Business Impact Without Disruption. San Francisco-based Horizon3 raised a $250 million Series E funding round at a $2 billion valuation to expand autonomous testing across infrastructure, identity and web applications as AI gives attackers new ways to discover, exploit and traverse enterprise weaknesses at machine speed. First seen on…
-
ISMG Editors: AI Is Supercharging Attackers
Also: CIOs Rethink Data in AI Rollouts, ShinyHunters Hits Biotech. In this week’s panel, four ISMG editors discussed new research showing how AI is making cyberthreat actors more capable, why the technology is forcing CIOs to rethink data platforms they spent years modernizing and a string of attacks in the biotech sector. First seen on…
-
AI Phishing Now Frighteningly Normal, Hard to Detect
StrongestLayer’s Alan LeFort on Personalization, Evasion and First-Seen Attacks. AI-generated phishing no longer looks unusual or obviously malicious, lending legacy filters ineffective. StrongestLayer CEO Alan LeFort explains how personalization, trusted infrastructure and evasion techniques are making first-seen attacks harder to detect. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/ai-phishing-now-frighteningly-normal-hard-to-detect-a-32466
-
How AI Agents Widen the Enterprise Blast Radius
AWS’s Matt Girdharry and Varonis’ Matt Radolec on Data Security, Machine-Speed Risk. Agentic AI can act at machine speed across data, APIs and cloud services, expanding enterprise risk beyond traditional controls. AWS’ Matt Girdharry and Varonis’ Matt Radolec explain why AI governance, least privilege and runtime visibility now matter more than ever for security teams.…
-
Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer
A cluster of nearly 800 malicious packages has been published to the npm registry as part of a new campaign designed to deliver cross-platform malware targeting Windows, Mac, and Linux systems.”These packages appear to use AI slop squatted, or randomly generated typo-squatting package names, but all of them deliver a powerful RAT and infostealer payload,”…
-
Why ‘America First’ in AI Shouldn’t Mean ‘America Only’
Former US Cyber Director on Cooperation, AI Supply Chains and National Security. U.S. leadership in AI requires more than protecting domestic technology. Former U.S. National Cyber Director Chris Inglis says national security will depend on outperforming competitors, strengthening global supply chains and working with allies against shared AI risks. First seen on govinfosecurity.com Jump to…
-
Kimi K3 Bypasses Cyber Test With Answer From GitHub
Test Flaw Allowed Moonshot AI’s Model to Reach the Internet. Moonshot AI’s open-weight model Kimi K3 jumped its sandbox during a test of its cybersecurity abilities to locate an already worked-out solution on GitHub – behavior perfectly normal for coders but that raises red flags for artificial intelligence models. First seen on govinfosecurity.com Jump to…
-
More than half of AI-generated patches are broken
Research finds your AI generated security patch is more likely to fail than fully fix a vulnerability. It might even introduce brand new flaws to exploit along the way. First seen on cyberscoop.com Jump to article: cyberscoop.com/ai-code-patching-security-risks/
-
AI Agents, Supply Chain Attacks, and Critical Flaws Define the Week in August 2026
Weekly summary of Cybersecurity Insider newsletters for August 2026, including Def Con and Black Hat conference coverage First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/weekly-roundup/ai-agents-supply-chain-attacks-and-critical-flaws-define-the-week-in-august-2026/
-
ThreatLabz 2026 Report: Frontier AI and Enterprise Readiness
Tags: access, ai, attack, authentication, breach, cisa, ciso, control, credentials, cyberattack, data, data-breach, endpoint, exploit, flaw, governance, identity, Internet, kev, login, malicious, privacy, radius, resilience, strategy, switch, threat, update, vpn, vulnerability, zero-trustThe BreachIt was 9:14 AM when the CISO’s VPN connection momentarily dropped, something that normally wouldn’t cause any concern. What he couldn’t see was that attackers had already exploited a pre-authentication flaw in the VPN appliance itself, gaining access before any login ever occurred. From there, they extracted stored credentials, forged an identity as his…
-
ThreatLabz 2026 Report: Frontier AI and Enterprise Readiness
Tags: access, ai, attack, authentication, breach, cisa, ciso, control, credentials, cyberattack, data, data-breach, endpoint, exploit, flaw, governance, identity, Internet, kev, login, malicious, privacy, radius, resilience, strategy, switch, threat, update, vpn, vulnerability, zero-trustThe BreachIt was 9:14 AM when the CISO’s VPN connection momentarily dropped, something that normally wouldn’t cause any concern. What he couldn’t see was that attackers had already exploited a pre-authentication flaw in the VPN appliance itself, gaining access before any login ever occurred. From there, they extracted stored credentials, forged an identity as his…
-
AI Generated Code Risks: Why Business Owners Should Never Trust Software That Simply Works
AI can now generate working software in minutes. Ask Claude, GitHub Copilot, ChatGPT, or another AI coding tool to create an API, authentication flow, admin…Read More First seen on securityboulevard.com Jump to article: https://securityboulevard.com/2026/08/ai-generated-code-risks-why-business-owners-should-never-trust-software-that-simply-works/
-
1Password Research Finds AI-Generated Vulnerability Patches Often Leave Bugs Behind
1Password’s Off-by-1 Labs has released research showing that large language models frequently produce vulnerability patches that look plausible but fail to fix the underlying flaw. The study, titled Frontier Models’ Vulnerability Patches are Often F.L.A.W.E.D., evaluated two cyber-capable reasoning models against six recently disclosed vulnerabilities in open-source software. Researchers generated 6,080 patches across the test..…
-
Beware cut-price AI services that read your every word
f someone offered you 90% off the official price to access Claude, the powerful AI model from Anthropic, would you be tempted? It turns out that around 900 people were, and they may be regretting their decision. First seen on fortra.com Jump to article: www.fortra.com/blog/beware-cut-price-ai-services-read-your-every-word
-
AI-Generated Patches Fail Half the Time
Tags: aiA study of more than 6,000 patches found that even working patches can introduce new bugs, break something else, or are open to bypass. First seen on darkreading.com Jump to article: www.darkreading.com/application-security/ai-generated-patches-fail-half-time
-
Déjà Vu? Meta’s AI Escapes Testing Lab in Hacking Joyride
In the span of three weeks, OpenAI, Anthropic, and Meta have all disclosed AI agent sandbox escape events affecting real organizations. First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/meta-ai-escapes-lab-hacking-joyride
-
Irregular, firm behind AI hacking incidents, won’t say if there were more
A spokesperson said Irregular’s investigation into what happened with Anthropic, OpenAI and Meta’s AI models was ongoing and that they could not “go into further details.” First seen on therecord.media Jump to article: therecord.media/irregular-ai-security-company-incidents
-
Chinese AI model Kimi escaped its cybersecurity testing environment, researchers say
In the Kimi test, the sandbox designed to contain the experiment was not properly configured. First seen on techcrunch.com Jump to article: techcrunch.com/2026/08/07/chinese-ai-model-kimi-escaped-its-cybersecurity-testing-environment-researchers-say/
-
Das Geschäft mit kostenlosen KI-Tokens auf Graumärkten
Die beiden Sicherheitsforscher Jeremy Kirk und Mathew Woodyard von Okta haben einen Blick auf das Geschäft mit kostenlosen KI-Token für Frontier-AI-Modelle mittels Graumärkten geworfen. Die beiden fanden mehr als ein halbes Dutzend Anzeigen für solche Dienste in Untergrundforen und auf Messaging-Plattformen, was jedoch nur einen Bruchteil ausmacht. Der Erfolg von KI-Modellen und deren Kosten führt…
-
Offene Türen für KI-Agenten schließen
Diese Woche nun also auch Meta. Inzwischen häufen sich die Berichte von KI-Anbietern, deren KI-Agenten aus den Testumgebungen ausbrechen und andere Software-Anbieter hacken. Um dies zu verhindern, gilt es für alle Unternehmen die Grundlagen der Absicherung vor Angriffen zu verinnerlichen. Diese und andere bekannt gewordene Vorfälle bereiten Sicherheitsteams rund um den Globus Sorgenfalten. Denn die…
-
Agentic AI for Cyber Defenders: What Security Teams Built at Black Hat USA 2026
Tags: ai, automation, conference, control, credentials, cve, cyber, cybersecurity, data, data-breach, defense, detection, exploit, flaw, group, iam, intelligence, ISO-27001, mitigation, network, nvidia, offense, open-source, RedTeam, risk, skills, soc, technology, threat, tool, usa, vulnerabilityAgentic AI armed attackers first, but it also put real building power in defenders’ hands. Here’s what security practitioners built in two days at Black Hat USA 2026, and how the CyberAgents Exchange keeps that work compounding long after the event. Key takeaways Building defensive cybersecurity tooling no longer requires a developer. Agentic tooling drove…
-
Anstieg der Hardware-Preise in Folge KI-getriebener Halbleiter-Nachfrage
First seen on datensicherheit.de Jump to article: www.datensicherheit.de/anstieg-hardware-preise-ki-antrieb-halbleiter-nachfrage
-
Nicht KI ist das größte Risiko, sondern ihre Identitäten
‘Aus einer Testumgebung heraus erlangten KI-Modelle von Anthropic unautorisierten Zugriff auf Echtdaten realer Systeme von Organisationen. Das Eklatante daran: Im Rahmen einer Sicherheitsanalyse zeigte sich, dass über unzureichend abgesicherte Identitäten Zugriffe auf produktive Systeme möglich waren und diese auf diesem Weg kompromittiert wurden. Ein Statement von Elmar Eperiesi-Beck, CEO bei Bare.ID. Zum Vergleich: Noch vor…
-
15 AI Security Lessons From Black Hat and Ai4 2026
Black Hat and Ai4 2026 highlighted gaps in AI agent security, identity controls, software supply chains, monitoring, and incident response. The post 15 AI Security Lessons From Black Hat and Ai4 2026 appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-black-hat-ai4-2026-ai-security-takeaways/
-
AI-Assisted HTTP Terminator Finds Novel HTTP Desync Techniques and Apache Zero-Day
PortSwigger says HTTP Terminator, an artificial intelligence (AI)-assisted research system built by James Kettle, generated and proved new HTTP desynchronization techniques after exploring 30,000 candidate attack vectors.PortSwigger said a separate human-guided discovery cascade also exposed a zero-day in Apache Traffic Server. Kettle said HTTP Terminator tested 30,000 websites where scanning First seen on thehackernews.com Jump…
-
Deemed Export, Deemed Impossible: The Government Discovers That AI Has No Border
Anthropic’s reported AI model shutdown highlights how U.S. export controls could collide with frontier AI, cybersecurity, identity management and global cloud access. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/deemed-export-deemed-impossible-the-government-discovers-that-ai-has-no-border/
-
AI firms know policymakers won’t ‘let you make a Terminator factory,’ DHS official says
Leading AI companies have learned important lessons from recent incidents, the official said, and regulation isn’t necessary to preserve those lessons. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/ai-security-regulation-innovation-us-government-black-hat/827296/
-
The Hugging Face Incident Is a Warning: Every Enterprise Needs AI Agents Watching AI Agents
The Hugging Face incident shows why enterprises must treat autonomous AI agents as privileged identities, with continuous monitoring, behavioral telemetry and strict controls. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/the-hugging-face-incident-is-a-warning-every-enterprise-needs-ai-agents-watching-ai-agents/
-
Who’s Accountable When an AI Agent Fails? – Kovrr
Articles related to cyber risk quantification, cyber risk management, and cyber resilience. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/whos-accountable-when-an-ai-agent-fails-kovrr/

