Tag: ai
-
Apple’s bug bounty program is drowning in so much AI slop, it is in danger of missing serious exploits
Apple has imposed strict new submission limits on its bug bounty portal after finding itself overwhelmed by low-quality, AI generated vulnerability reports – many of which were found to be describing security flaws that simply didn’t exist. First seen on bitdefender.com Jump to article: www.bitdefender.com/en-us/blog/hotforsecurity/apple-bug-bounty-ai-missing-exploits
-
Alarm sounded around supply chain risks
With AI agents demonstrating their ability to bypass security, the need to protect against attacks originating from third-party suppliers has increased First seen on computerweekly.com Jump to article: www.computerweekly.com/microscope/news/366648132/Alarm-sounded-around-supply-chain-risks
-
Meta Confirms AI Model Launched Autonomous Attack on Another Organization
Meta has become the latest technology company to disclose that an AI agent accessed another organization’s online systems during a controlled cybersecurity evaluation. This development has intensified scrutiny regarding the safeguards surrounding autonomous models and the testing environments for agentic AI. The incident reportedly occurred when a Meta AI model, evaluated by the independent security…
-
Thales bringt Imperva WAF nativ auf Amazon CloudFront
Thales bringt Imperva WAF auf Amazon CloudFront. Die SaaS-Lösung schützt Webanwendungen, APIs und KI-Systeme vor Angriffen und bösartigen Bots. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/thales-bringt-imperva-waf-nativ-auf-amazon-cloudfront/a46039/
-
Scoping Agent Permissions: Rich Authorization Requests (RFC 9396) in Practice
Tags: ai“A working tutorial on RFC 9396 for AI agents: design an authorization_details type, narrow the token per task, enforce it at the resource server, know the limits First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/scoping-agent-permissions-rich-authorization-requests-rfc-9396-in-practice/
-
Reges Interesse am 4. KI-Tag der Wirtschaft des Landes Brandenburg
Tags: aiFirst seen on datensicherheit.de Jump to article: www.datensicherheit.de/reges-interesse-4-ki-tag-der-wirtschaft-land-brandenburg
-
Black Hat USA 2026: One GitHub Issue Could Compromise Major AI Coding Workflows
At Black Hat USA 2026, Novee found GitHub workflow flaws in Claude Code, Gemini CLI and Codex that enabled RCE, credential theft and agent control in pipelines. First seen on hackread.com Jump to article: hackread.com/black-hat-usa-2026-github-compromise-ai-coding/
-
Meta AI Model Hacked a Company During Testing, Marking Third AI Lab Incident
Meta says an AI model hacked a company during testing after accidental internet access, marking the third disclosed AI lab breach in weeks. Meta confirmed that one of its AI models breached an unidentified company during cybersecurity testing, after its independent testing partner Irregular gave the model unintended internet access through a misconfiguration. This is…
-
Discounted Claude access bought on the gray market may expose every prompt you send
More than half a dozen services advertised on underground forums and messaging platforms, offering discounted or >>unlimited<< token access to frontier AI models, … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/06/ai-model-access-fraud-gray-market/
-
Wiederkehrendes Muster: OpenSSL-Entwickler wettert gegen KI-Hacks
Seit einigen Tagen hacken sich vermehrt KI-Modelle von OpenAI, Anthropic und Meta durchs Netz. Das Problem liegt laut OpenSSL-Entwickler Hudson aber nicht bei der KI. First seen on golem.de Jump to article: www.golem.de/news/wiederkehrendes-muster-openssl-entwickler-wettert-gegen-ki-hacks-2608-211664.html
-
KI-Arbeitsplatz unter Zero Trust: Cloudflare bündelt Agenten, Governance und Analyse
Cloudflare verbindet einen offenen KI-Arbeitsplatz mit identitätsbasierter Kontrolle über Agenten, Datenflüsse, Modellnutzung und Kosten. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/ki-arbeitsplatz-unter-zero-trust-cloudflare-buendelt-agenten-governance-und-analyse/a46037/
-
Quantifying the Risk of Autonomous AI Systems – Kovrr
Articles related to cyber risk quantification, cyber risk management, and cyber resilience. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/quantifying-the-risk-of-autonomous-ai-systems-kovrr/
-
Microsoft extends zero trust deeper into enterprise AI
Microsoft expanded its Zero Trust for AI strategy with updates to the Zero Trust Assessment tool and the Zero Trust Workshop. The additions help organizations assess security … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/06/microsoft-zero-trust-for-ai-strategy-updates/
-
OpenAI Agents Worked Together to Find Exploits and Hack External Systems
OpenAI has revealed new details about an incident involving AI agents, in which multiple autonomous agents reportedly worked together to identify vulnerabilities, bypass containment measures, and gain access to external systems during a cybersecurity evaluation. Speaking at the Black Hat conference in Las Vegas, OpenAI alignment researcher Eric Wallace and security and infrastructure specialist Michael…
-
NVIDIA Group Proposes SAFE Initiative for Agentic Threat Intel Sharing
The Open Secure AI Alliance has announced plans for the Shared AI Findings Exchange (SAFE) First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/safe-initiative-agentic-threat/
-
Anthropic-KI manipuliert Menschen per E-Mail, um Schadcode in Software einzuschleusen
First seen on t3n.de Jump to article: t3n.de/news/anthropic-ki-manipuliert-menschen-per-e-mail-um-schadcode-in-software-einzuschleusen-1756393/
-
Why Post-Quantum Security Is Climbing the Enterprise Agenda
Tags: ai, attack, computer, computing, conference, container, crypto, cryptography, cybersecurity, data, google, government, hacker, Hardware, ibm, infrastructure, intelligence, risk, technology, threat, toolWhy Post-Quantum Security Is Climbing the Enterprise Agenda andrew.gertz@t“¦ Thu, 08/06/2026 – 04:56 Learn why post-quantum security is becoming an enterprise priority, how AI and quantum computing are reshaping cryptography, and how Thales Luna 8 helps organizations prepare. Data Security Key Management Encryption Key Management Bree Fowler – Journalist More About This Author > At…
-
Meta-KI greift bei Test fremde Systeme an
Ein Test von Meta hat eine unerwartete Wendung genommen: Ein KI-Modell ist ins Internet gelangt und hat Systeme eines anderen Unternehmens erreicht. First seen on golem.de Jump to article: www.golem.de/news/hacking-meta-ki-greift-bei-test-fremde-systeme-an-2608-211656.html
-
Sicherheitstest mit Mythos 5 – KI-Agent wollte Malware in Open-Source-Projekt einschleusen
Bei einem Sicherheitstest versuchte ein auf Mythos 5 basierender Agent, Malware in ein echtes Open-Source-Projekt einzuschleusen. First seen on computerbase.de Jump to article: www.computerbase.de/news/apps/sicherheitstest-mit-mythos-5-ki-agent-wollte-malware-in-open-source-projekt-einschleusen.98721
-
OWASP 2026 LLM Top 10: >>The model will be fooled<<
The OWASP GenAI Security Project has released the 2026 edition of its Top 10 for LLM Applications and, for the first time, the list was influenced by real-world incidents. The … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/06/owasp-2026-llm-top-10-released/
-
Browser security is where software, data, and AI meet
In this interview with Help Net Security, Rui Ribeiro, CEO of Jscrambler, explains why the browser has become a security problem organizations do not control. Companies do not … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/06/rui-ribeiro-jscrambler-browser-security/
-
Hackers Abuse Cloud Startup Credits to Resell Claude and Gemini AI Access
Threat actors are exploiting free cloud trials and startup credit programs to build gray-market AI proxy services. These services resell discounted access to advanced AI models, including Anthropic Claude and Google Gemini, according to Okta Threat Intelligence. These services rely on fraudulent or synthetic account registrations to accumulate promotional credits offered by cloud providers. The…
-
VanishID Previews AI Exploitability Management at Black Hat USA 2026
VanishID has unveiled AI Exploitability Management, a capability designed to measure what frontier AI could build from publicly exposed information about an organization’s people. The company is demonstrating the capability publicly for the first time at Black Hat USA 2026. VanishID said the system evaluates more than 40 AI-powered attack scenarios, including executive impersonation, real-time..…
-
Novee Brings Continuous AI Pentesting to Mobile Applications
Novee has expanded its AI penetration testing platform to mobile applications, extending continuous testing across mobile, web, APIs, desktop software and AI-enabled applications. The company announced the update ahead of Black Hat USA 2026. Novee said users can upload a mobile application package and receive results within hours, alongside findings from their other application assets……
-
Ridge Security Launches RidgeGen for Continuous Offensive Security Testing
Ridge Security has announced the availability of RidgeGen, an agentic AI platform for continuous offensive security testing. The platform is designed to find unknown and exploitable risks, investigate how vulnerabilities, business logic flaws and misconfigurations could be chained, and validate findings with reproducible evidence before they reach a security team. Ridge Security said the approach..…
-
Suppliers, logins, and AI tools are all becoming attack paths
Cybercriminals and state-backed hacking groups are abusing trusted identities, cloud services, AI tools, and software supply chains to gain access while avoiding detection, … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/06/crowdstrike-cyber-threat-trends-report/
-
Cloud Security Alliance Starts Initiative to Define Controls for Catastrophic AI Risks
The Cloud Security Alliance has launched an initiative to define auditable controls for catastrophic AI risks, along with a research center focused on how frontier AI is changing cybersecurity. Announced Wednesday in Las Vegas, the Catastrophic Risk Annex will extend CSA’s AI Controls Matrix with controls for mitigating catastrophic AI risks. CSA said the controls..…
-
Surf AI Adds Claude Compliance Integration and Exposure Reduction Operations
Surf AI has added an integration with Claude’s Compliance API and made Exposure Reduction Operations generally available, extending its platform to govern AI model connectivity alongside identity, cloud and SaaS exposures. The Claude integration pulls activity logs from an organization’s Claude environment, maps connection and access paths to an accountable owner in Surf’s Context Graph,..…
-
Palo Alto Networks Introduces PAN-OS 12.2 Ceres With AI Security Features
Palo Alto Networks has introduced PAN-OS 12.2 Ceres, a firewall operating system update that adds more than 55 innovations aimed at attacks accelerated by frontier AI. The release centers on Advanced Virtual Patching, Advanced IP Defense and six AI-powered Network Security Agents. Advanced Virtual Patching uses AI to identify unknown vulnerabilities and deliver network protections..…
-
EKonten mit KI-Funktionen könnten zu einer der größten Insider-Bedrohungen werden
Ein von Barracuda inszenierter, kontrollierter Testangriff zeigt, wie Angreifer KI-Assistenten missbrauchen können, um über ein einziges kompromittiertes Konto einen CEO-Betrug mit einer Überweisung in Höhe von 250.000 US-Dollar zu begehen. Das größte Risiko eines kompromittierten Kontos mit KI-Funktionen liegt darin, wie schnell ein KI-Assistent Angreifer dabei unterstützen kann, vertrauliche Informationen aufzuspüren, Ziele zu identifizieren,… First…

