Tag: ai
-
US bank discloses security lapse after sharing customer data with AI app
Community Bank, which operates in Pennsylvania, Ohio, and West Virginia, disclosed a cybersecurity incident that exposed customers’ names, dates of birth, and Social Security numbers. First seen on techcrunch.com Jump to article: techcrunch.com/2026/05/12/us-bank-discloses-security-lapse-after-sharing-customer-data-with-ai-app/
-
Webinar: Fixing the gaps in network incident response
IT teams often struggle to quickly coordinate responses across disparate systems during network incidents. This upcoming webinar explores how automation and AI-assisted workflows can reduce response times and help prevent outages. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/webinar-fixing-the-gaps-in-network-incident-response/
-
OpenAI Unlocks Cybersecurity Model for Europe
German Financial Regulator Warns Sector to Step Up Defenses. OpenAI is stepping up to do what arch-rival Anthropic still won’t. The AI firm will give European authorities and companies access to its new vulnerability-finding AI model, so they can beef up their cybersecurity. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/openai-unlocks-cybersecurity-model-for-europe-a-31664
-
Guardrail Technologies launches Traffic Light for Code & AI; first security technology to verify & secure AI code and the people creating it
PARK CITY, Utah (May 5, 2026);—;Guardrail Technologies, the leading provider of AI security and governance software for enterprises building with AI,;today announced the launch of Traffic Light for Code & AI™, which verifies both the code AI generates and the people… First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/spons/guardrail-technologies-launches-traffic-light-for-code-aitm-first-securit/819953/
-
Mistral AI SDK, TanStack Router hit in npm software supply chain attack
Tags: ai, api, attack, breach, cloud, credentials, data, data-breach, exploit, github, kubernetes, malicious, malware, network, open-source, password, router, service, software, supply-chain, switch, vulnerabilitypull_request_target. This allows third-party workflows to run automatically, a way of avoiding maintainer approval fatigue, but means that the maintainer’s short-lived OIDC tokens become vulnerable to scraping.Armed with these tokens, the attacker were able to compromise the packages by injecting the malicious Mini Shai-Hulud malware, which propagated to other projects.The purpose is to steal developer…
-
AI-Built Zero-Day Nearly Powered Mass Attack
Google Says Criminals Used AI to Discover and Code Exploit. A cybercriminal group came close to launching a mass attack earlier this year, armed with a software exploit that an AI model had built from scratch, said Google researchers. Google said it worked with the affected vendor to patch the flaw before an attack could…
-
U.S. bank disclose security lapse after sharing customer data with AI app
The bank said the security lapse was due to the use of an “unauthorized” AI software app. First seen on techcrunch.com Jump to article: techcrunch.com/2026/05/12/u-s-bank-disclose-security-lapse-after-sharing-customer-data-with-ai-app/
-
Pwn2Own Berlin 2026 Hits Capacity as Rejected Hackers Release 0-Days
Pwn2Own Berlin 2026 reportedly reached full capacity for the first time, prompting rejected researchers to publicly disclose zero-day exploits targeting Firefox, NVIDIA, and AI platforms. First seen on hackread.com Jump to article: hackread.com/pwn2own-berlin-2026-hits-capacity-hackers-0-days/
-
Banks Face a Growing AI Risk at the Database Layer
Researchers warn that banks may be overlooking AI risks at the database layer. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/banks-face-a-growing-ai-risk-at-the-database-layer/
-
KI und Cybersecurity: Curl-Entwickler sieht keine Gefahr durch Mythos
Nachdem Anthropics KI-Modell Mythos Curl auf Sicherheitslücken überprüft hatte, kam laut dessen Entwickler eine sehr kurze Liste zurück. First seen on golem.de Jump to article: www.golem.de/news/ki-und-cybersecurity-curl-entwickler-sieht-keine-gefahr-durch-mythos-2605-208595.html
-
Exaforce raises $125M Series B to build AI for catching and stopping cyberattacks as they happen
The round valued the three-year-old startup at $725 million. First seen on techcrunch.com Jump to article: techcrunch.com/2026/05/12/exaforce-raises-125m-series-b-to-build-ai-for-catching-and-stopping-cyberattacks-as-they-happen/
-
The world’s most >>Dangerous<< AI, Anthropic's Mythos, found only one flaw in curl
Anthropic’s AI found five vulnerabilities in curl, but only one low-severity issue proved to be a real vulnerability. In April, Anthropic made considerable noise announcing Mythos, a new artificial intelligence model described as so effective at identifying vulnerabilities in code as to be, in the company’s own words, >>dangerously good.<< So good, in fact, that…
-
News brief: Security worries and warnings as AI use expands
Check out the latest security news from TechTarget SearchSecurity’s sister sites, Cybersecurity Dive and Dark Reading. First seen on techtarget.com Jump to article: www.techtarget.com/searchsecurity/news/366642881/News-brief-Worries-and-warnings-as-AI-use-expands
-
Amazon Quick authorization bypass let users reach blocked AI chat agents
Enterprises running Amazon Quick, the AWS business intelligence and agentic AI service, rely on a feature called custom permissions to restrict who inside an account can use … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/05/12/fog-security-amazon-quick-authorization-bypass/
-
Hugging Face Packages Weaponized With a Single File Tweak
Tags: aiA tokenizer library file present in Hugging Face AI models can be manipulated to hijack the model’s outputs and exfiltrate data. First seen on darkreading.com Jump to article: www.darkreading.com/cloud-security/hugging-face-packages-weaponized-single-file-tweak
-
OpenAI Launches ‘Daybreak’ to Help Build Secure By Design Software
With Daybreak, OpenAI wants its frontier AI models to be used to deploy secure by design software from the ground up First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/openai-daybreak-secure-by-design/
-
Datensouveränität im Zeitalter der KI
In den vergangenen zehn Jahren hat die Cloud die Technologiestrategie vieler IT-Entscheider geprägt. Heute verschiebt sich der Fokus hin zu mehr Datensouveränität insbesondere in Behörden und regulierten Branchen. Datensouveränität erfordert die Fähigkeit, eine substanzielle und nachweisbare Kontrolle über Daten, Technologien, Betriebsprozesse und rechtliche Risiken zu behalten unabhängig davon, wo sich diese befinden. Sie hat […] First…
-
Google Says Hackers Used AI to Build Zero-Day Exploit
Google says hackers used AI to help build a zero-day exploit targeting 2FA, raising concerns about AI-assisted hacking. The post Google Says Hackers Used AI to Build Zero-Day Exploit appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-google-hackers-ai-zero-day-exploit/
-
Report von Ivanti – Wachsendes Vertrauen in Agentic AI
First seen on security-insider.de Jump to article: www.security-insider.de/agentic-ai-cybersicherheit-akzeptanz-reifegraddefizit-a-133837fd8ddda33a7adb9d2037ae7e49/
-
OpenAI introduces Daybreak cyber platform, takes on Anthropic Mythos
Tags: access, ai, cisco, crowdstrike, cyber, cybersecurity, defense, detection, fortinet, framework, government, malware, network, openai, oracle, penetration-testing, RedTeam, risk, software, strategy, technology, update, vulnerabilityOpenAI’s cybersecurity model stack: OpenAI is pursuing a scalable cyber defense platform strategy with Daybreak and is rolling out the initiative through three different model tiers: GPT-5.5 (default), GPT-5.5 with Trusted Access for Cyber, and GPT-5.5-Cyber.The standard GPT-5.5 model is positioned for general-purpose enterprise use cases, including developer assistance and knowledge work. GPT-5.5 with Trusted…
-
Download: The IT and security field guide to AI adoption
Security and IT teams are under pressure to adopt AI, but many are seeing the opposite of what was promised. Tools that demo well don’t hold up in real workflows. Complexity … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/05/12/tines-download-ai-adoption-guide/
-
Threat Actors Abuse Vercel AI Tools to Mass-Produce Realistic Phishing Sites
Threat actors are rapidly adopting generative AI platforms to scale phishing operations, and Vercel has emerged as a powerful enabler in this shift. Vercel is a cloud-based platform designed to help developers build and deploy modern web applications quickly. Its GenAI-powered tool, v0[.]dev, allows users to generate fully functional websites using simple text prompts. While…
-
AI and an absent government: Takeaways from RSAC 2026
Cybersecurity professionals spent the recent conference discussing the balance between autonomy and oversight. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/ai-cybersecurity-government-partnerships-rsac-conference/817451/
-
Warum eingebaute KI-Leitplanken für Agentic-AI nicht ausreichen
KI-Agenten entwickeln sich rasant zu zentralen Werkzeugen der Automatisierung. Um ihre Aufgaben erfüllen zu können, benötigen sie umfangreiche Zugriffsrechte auf Tools, Datenbanken, SaaS-Anwendungen und das Internet. Ein aktueller Bericht unserer Okta Threat Intelligence warnt nun davor, diesen Systemen unreguliert die Schlüssel zum Stadttor wie Anmeldedaten, API-Schlüssel, persönliche Access-Tokens und OAuth-Tokens zu überreichen. Jüngste […] First…
-
Why Agentic AI Is Security’s Next Blind Spot
Agentic AI is already running in production environments across many organizations today. It is executing tasks, consuming data, and taking actions, most likely without meaningful involvement from the security team. The industry conversation has largely framed this as a question of policy: allow it, restrict it, or monitor it? However, that framing misses the point.…
-
AI is separating the companies built to scale from the ones built to sell
Startups are scaling faster, attackers are getting smarter, and investors are getting more selective. The cybersecurity industry is in the middle of a reset. First seen on cyberscoop.com Jump to article: cyberscoop.com/ai-cybersecurity-market-trends-2026-op-ed/
-
UAE launches sovereign AI-driven Cyber Factory security initiative
UAE Cyber Security Council and CPX unveil national cyber manufacturing initiative aimed at strengthening digital sovereignty, AI-powered defence and critical infrastructure resilience First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366642771/UAE-launches-sovereign-AI-driven-Cyber-Factory-security-initiative
-
Sicherheitsbedenken durch Claude Mythos – Einsatz von Schwachstellen-KI zu riskant?
First seen on security-insider.de Jump to article: www.security-insider.de/einsatz-von-schwachstellen-ki-zu-riskant-a-0b06f99fdc44dcf8332165d0d122fa4a/
-
Okta Studie zeigt: Eingebaute KI-Guardrails reichen nicht aus
In einem Szenario genügte bereits ein simples Webformular auf einer präparierten Website, um ein unzensiertes LLM dazu zu bringen, seinen kompletten Credential-Store offenzulegen. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/okta-studie-zeigt-eingebaute-ki-guardrails-reichen-nicht-aus/a45091/
-
Pwn2Own versus KI: Zero Day Initiative kann Flut an Anmeldungen nicht bewältigen
Der Hackerwettbewerb Pwn2Own in Berlin stößt an seine Kapazitätsgrenzen. Zahlreichen Teams wurde bereits abgesagt. Das dürfte vor allem an KI liegen. First seen on golem.de Jump to article: www.golem.de/news/pwn2own-versus-ki-zero-day-initiative-kann-flut-an-anmeldungen-nicht-bewaeltigen-2605-208572.html

