Tag: ai
-
Focus on infrastructure resilience, not AI hype, Western government leaders warn
U.S. and allied officials said companies should start preparing now for a cyberattack that changes how they provide essential services. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/ai-cybersecurity-resilience-black-hat-government-panel/827137/
-
The Most Dangerous AI Hacking Techniques Still Have Humans in the Loop
Security researcher James Kettle tried to push the limit of AI’s hacking abilities”, and discovered how effective it can be when combined with human expertise. First seen on wired.com Jump to article: www.wired.com/story/the-most-dangerous-ai-hacking-techniques-still-have-human-input/
-
Mini Shai-Hulud npm Attack: More Than 2,200 Components Impacted
Tags: access, ai, attack, breach, cloud, container, control, credentials, data, data-breach, github, guide, infection, intelligence, kubernetes, malicious, malware, microsoft, open-source, risk, sbom, service, software, threat, update<div cla TL;DR A new wave of the Shai-Hulud malicious package campaign emerged on npm, with 2,225 software component versions impacted. The malware executes through a malicious preinstall hook, steals npm, GitHub, cloud, Kubernetes, Vault, CI/CD, and other credentials, then uses stolen publishing access to compromise additional packages. Organizations that installed an affected version should…
-
7AI Launches Federated SIEM and Build Tools Ahead of Black Hat USA 2026
7AI has launched 7AI Federated SIEM and 7AI Build, two capabilities designed to give security teams a distributed foundation for AI-assisted operations. The company said both will be showcased at Black Hat USA 2026. 7AI Federated SIEM connects to security data across existing SIEMs, data lakes and cloud platforms. It lets teams query, investigate and..…
-
Cycode Opens Early Access to Agentic Workflows for Application Security
Cycode is making Agentic Workflows available in early access, giving AI agents the ability to detect, prioritize and fix application-development risks as they appear. The company is demonstrating the capability at Black Hat USA 2026 in Las Vegas. Agentic Workflows operate across the application development lifecycle. Security teams define the triggers, actions and confidence thresholds,..…
-
Assail Updates Ares With New Harness and AI Model for Autonomous Red Teaming
Assail has introduced Ares v2, a redesigned version of its autonomous offensive security platform, with a new interface, purpose-built model and rebuilt agentic harness. The company is tying the update to its Black Hat 2026 program, where founder and CEO Alissa Knight is scheduled to discuss how organizations should evaluate offensive AI systems. The new..…
-
Cobalt Launches Autonomous Pentest for Continuous Application Testing
Cobalt is launching Cobalt Autonomous Pentest, a service designed to bring continuous offensive security testing to an organization’s full application portfolio. The product debuts at Black Hat USA 2026 and is scheduled for general availability in August. The offering combines AI-driven testing with direction from Cobalt penetration testers. Its model-agnostic engine handles chain prediction, prioritization..…
-
CrowdStrike Warns AI Adoption Is Creating ‘Underdefended’ Attack Surfaces
CrowdStrike warns that AI adoption, rapid vulnerability exploitation, cloud attacks, and malicious npm packages are creating new enterprise security risks. The post CrowdStrike Warns AI Adoption Is Creating ‘Underdefended’ Attack Surfaces appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-crowdstrike-ai-underdefended-attack-surfaces/
-
Flaws in Google APK for Python Unlock AgentAgent Attack
Google has fixed the issues, which exploited a trust boundary between two AI agents with different privilege levels to trigger automation that could compromise the supply chain. First seen on darkreading.com Jump to article: www.darkreading.com/vulnerabilities-threats/flaws-google-apk-python-agent-to-agent-attack
-
OpenAI Disrupts Poipet Scam Network Using ChatGPT Across Multiple Fraud Schemes
OpenAI said it disrupted a Cambodia-based scam operation that used its generative artificial intelligence (AI) chatbot ChatGPT to facilitate a wide range of investment, romance, gambling, and law enforcement impersonation schemes.To that end, it banned a coordinated network of ChatGPT accounts likely originating from Southeast Asia and operating from the city of Poipet, a region…
-
Paperclip AI Flaws Let Attackers Run Host Commands via Malicious Agent Imports
Two security flaws in Paperclip could let attackers execute commands on a network server or a developer’s computer. Paperclip is an open-source control plane for teams of artificial intelligence (AI) agents, and both paths rely on importing a malicious agent and starting it.A third flaw could expose sensitive data and control-plane details through application programming…
-
5 Best AI Detection Response Platforms for 2026
Compare AI detection response platforms for 2026, including Dash, Lakera, Operant AI, HiddenLayer and Prisma AIRS, for runtime threat protection and response. First seen on hackread.com Jump to article: hackread.com/best-ai-detection-response-platforms-2026/
-
Meta Ran Ads That Contained AI-Generated Child Sexual Abuse Imagery
Tags: aiMore than 50 offending image and video ads were published across Facebook, Instagram, Messenger, or Threads, according to Meta’s ad library data. Some ran as recently as this week. First seen on wired.com Jump to article: www.wired.com/story/meta-ran-ads-that-contained-ai-generated-child-sexual-abuse-imagery/
-
Salt Security Launches Industry-First AWS WAF Managed Ruleset for AI Agents and API Protection
Salt Security has unveiled what it says is the industry’s first AWS WAF managed ruleset designed specifically to protect both APIs and AI agents, extending native AWS Web Application Firewall (WAF) capabilities to address emerging threats driven by agentic AI. Announced at Black Hat USA 2026, the new Salt Managed Rules for AWS WAF are…
-
Poison Claude Sells Discounted Claude Access While Its Operator Sees Every Customer Prompt
Cybersecurity researchers have discovered more than half-a-dozen services advertisements for illegal access to artificial intelligence (AI) models on underground cybercrime forums and messaging platforms.One such service, Poison Claude, claims to offer access to Anthropic’s large language models (LLMs), including Opus 4.8, Opus 4.7, Opus 4.6, and Sonnet 4.6.”Advertisements for Poison Claude First seen on thehackernews.com…
-
Menlo Security Extends MARS to Protect AI Assistants and Coding Agents
Menlo Security has expanded Menlo Agent Runtime Security, or MARS, with controls aimed at protecting AI assistants and coding agents from prompt injection, malware and data loss as they browse the web, use applications and process files. The company is highlighting the update at Black Hat USA 2026. MARS is a cloud-based capability in Menlo’s..…
-
BSidesSF 2026 Pwning And Defending AI Agent Code Interpreters
Tags: aiPresenter: Kinnaird McQuade Our thanks to Security BSides San Francisco for publishing their Creators, Authors and Presenter’s outstanding BSidesSF 2026 content on the Organizations’ YouTube Channel. Permalink First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/bsidessf-2026-pwning-and-defending-ai-agent-code-interpreters/
-
What Gold Eagle Validates, and What Your Organization Still Has to Own (July 2026)
Tags: ai, business, compliance, data, finance, framework, government, intelligence, open-source, update, vulnerabilityWhat Gold Eagle Validates, and What Your Organization Still Has to Own (July 2026) The federal government just stood up a clearinghouse to find and validate vulnerabilities faster, with AI doing the finding. That is not the same thing as a clearinghouse that owns the consequence when a patch does not land in time. Key…
-
White House walks tightrope on securing AI without stifling tech innovation
National Cyber Director Sean Cairncross said the administration wants to work collaboratively with the private sector. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/administration-securing-ai-stifling-tech-innovation/827088/
-
New Research: The Confidence Gap Between CISOs and Their Boards Is Real, and It’s Measurable
Las Vegas, United States, August 5th, 2026, CyberNewswire Pulse Security AI calls for boards and security leaders to define cyber risk appetite in new report: The CISO-Board Communication Gap Boards of directors believe they understand their company’s security posture and what it means for the business. The security leaders presenting to them are far less…
-
From Inspection to Authorization: Securing Networks for AI Agents
Tags: access, ai, api, business, ceo, cloud, communications, control, crowdstrike, cryptography, data, encryption, endpoint, finance, firewall, identity, infrastructure, login, network, office, risk, saas, service, usa, vpn<div cla An Industry Perspective By Rajiv Pimplaskar, CEO, Dispersive Holdings, Inc. Agentic AI changes the network security problem from inspection to authorization. As more traffic is generated by agents, models, and workloads operating at machine speed, the network has to make trust decisions continuously, evaluate policy in real time, revoke access automatically, and keep…
-
AI Agents Are Really Starting To Get This Hacking Thing: Analysis
An incident disclosed by the AI Security Institute revealed that an AI agent attempted to socially engineer real people”, without actually been told to do so. First seen on crn.com Jump to article: www.crn.com/news/security/2026/ai-agents-are-really-starting-to-get-this-hacking-thing-analysis
-
Reco Expands AI Runtime With Browser Controls and Prompt Blocking
Reco is expanding its AI Runtime capability with browser-based enforcement, real-time prompt analysis and blocking, and automated remediation. The company said the update is designed to act on the risk posed by AI agents without requiring security teams to route traffic through a new gateway or proxy. Reco’s Smart Remediation feature turns findings into proposed..…
-
“I’m Allowed”: Hackers Use Simple Claims to Bypass AI Guardrails
Cisco Talos found hackers using simple authorization claims to bypass AI guardrails, build DDoS attack tools, steal credentials and access live camera services. First seen on hackread.com Jump to article: hackread.com/im-allowed-hackers-use-claims-bypass-ai-guardrails/
-
Arctic Wolf gibt CyberReadiness-Accelerator für Partner bekannt
Arctic Wolf gibt die Verfügbarkeit des <> bekannt. Das neue, partnergeführte Programm unterstützt Unternehmen dabei, Cyberrisiken besser zu verstehen und ihre Widerstandsfähigkeit in einer zunehmend von KI beschleunigten Bedrohungslandschaft zu stärken. Trotz Vulnerability- und Patch-Management bleiben Unternehmen unbekannten Risiken durch blinde Flecken innerhalb ihrer Angriffsfläche ausgesetzt, Tendenz steigend. Laut dem weltweiten Verizon-2026-Data-Breach- […] First seen…
-
How AI-powered phishing killed blocklists for good
AI is helping attackers create disposable phishing infrastructure and rapidly evolving toolkits that blocklists cannot track fast enough. Push Security explains why browser-level, technique-based detection offers a more durable defense than relying on domains, signatures, and other known-bad indicators. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/how-ai-powered-phishing-killed-blocklists-for-good/
-
Paperclip AI Flaws Let Unauthenticated Attackers Run Commands
3 Paperclip flaws exposed data & allowed unauthenticated command execution in two deployment modes First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/paperclip-ai-vulnerabilities-rce/
-
Bold Security Extends Endpoint Data Protection Across AI Interactions
Bold Security has added an endpoint data protection layer for AI interactions, covering prompts, clipboard activity, file access, Model Context Protocol payloads and commands issued by autonomous agents. The company said the layer is designed to monitor activity locally on the device as data moves through web-based copilots, desktop AI applications and command-line workflows. It..…
-
Optiv Debuts Agentic Security Operations, Overhauling Its Managed Detection Service
Optiv unveiled Optiv Agentic Security Operations on Wednesday at Black Hat USA 2026, a major expansion of its managed security services and a substantial overhaul of the offering formerly known as Optiv MDR. The new service combines Google Security Operations technology, already central to the prior offering, with deeply integrated cloud and AI security capabilities..…

