Tag: ai
-
AI Browsers Vulnerable to ‘PleaseFix’ Zero-Click Agent Hijacking
Attackers can take control of agents through malicious instructions hidden in content supplied to AI browsers, and there’s no simple fix for the threat. First seen on darkreading.com Jump to article: www.darkreading.com/cyber-risk/ai-browsers-zero-click-agent-hijacking
-
No Perfect Fix for AI Browser Prompt Injection Flaws
AI browsers from top vendors remain vulnerable to prompt injection attacks despite multiple security guardrails, according to new research. First seen on darkreading.com Jump to article: www.darkreading.com/application-security/no-perfect-fix-ai-browser-prompt-injection-flaws
-
Western government leaders call for a focus on infrastructure resilience, not AI hype
U.S. and allied officials said companies should start preparing now for a cyberattack that changes how they provide essential services. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/ai-cybersecurity-resilience-black-hat-government-panel/827137/
-
Secret White House AI Safety Framework Draws Criticism
Watchdogs Say Public Accountability Suffers When AI Oversight Stays Hidden. The White House declined to publicly release its voluntary AI safety framework, prompting criticism from technology watchdogs and lawmakers who say secret oversight undermines accountability. Critics argue transparency is essential as the government expands its review of frontier AI models. First seen on govinfosecurity.com Jump…
-
Why Healthcare AI Use Demands Transparency to Manage Risks
Anne Snowdon of SCAN Health on AI Governance, Supply Chains. Healthcare organizations adopting AI must prioritize transparency, measurable outcomes and vendor accountability. Anne Snowdon of SCAN Health explains why AI governance, supply-chain visibility, cyber preparedness and patient trust determines whether emerging tech deliver value or create new risks. First seen on govinfosecurity.com Jump to article:…
-
AI Sends Global Crime Syndicates Into Fraud Nirvana
Organized crime is convincingly scamming at scale, making billions thanks to AI-enabled voice cloning, deepfake real-time video overlays, LLM-driven persona management, and automated translation. First seen on darkreading.com Jump to article: www.darkreading.com/threat-intelligence/ai-global-crime-syndicates-fraud-nirvana
-
How AI Agents Helped Seal Visa’s $2.4B BioCatch
Behavioral Biometrics Vendor Is Latest in Payment Network Sector Buying Spree. Visa, the world’s largest card payment network, is acquiring behavioral intelligence firm BioCatch in an all-cash deal valued at $2.4 billion. It’s the company’s largest acquisition to date and the latest in a string of payment sector M&As aimed at fraud and cybersecurity solutions.…
-
OpenAI Rejects Apple’s Trade Secrets Lawsuit
AI Company Calls Injunction Request ‘False’ as Hardware Dispute Escalates. OpenAI denied Apple’s allegations that it misappropriated trade secrets to accelerate its AI hardware ambitions, calling the claims false and unnecessary. Apple is seeking a preliminary injunction after accusing former employees of taking proprietary information tied to its AI device development. First seen on govinfosecurity.com…
-
Phoenix Security Launches Exploit Hunt to Validate Vulnerabilities With AI-Generated Exploits
Phoenix Security has launched Exploit Hunt, an AI red-team capability that works from a live threat model and reports a vulnerability only after generating and validating a runnable proof-of-concept exploit. Announced Aug. 5 and timed to Black Hat USA 2026, Exploit Hunt is available now in Phoenix Purple. It can run continuously, on every pull..…
-
Intel 471 Adds MCP Connector and Native AI Analyst to Verity471
Intel 471 has added two AI capabilities to its Verity471 cyber intelligence platform: MCP471, a connector for Model Context Protocol workflows, and Agent471, a native AI analyst. The capabilities are being demonstrated at Black Hat USA 2026 from Aug. 4 to 6. Intel 471 said the additions are designed to bring pre-attack intelligence and threat-hunting..…
-
Anthropic’s AI used fake identities, malware in rogue attack on GitHub project
Anthropic and OpenAI models’ unprompted actions forced halt to UK cyber tests. First seen on arstechnica.com Jump to article: arstechnica.com/security/2026/08/anthropics-ai-used-fake-identities-malware-in-rogue-attack-on-github-project/
-
Apple Caps Open Bug-Bounty Reports After Surge in Unvalidated AI Findings
Apple is limiting some bug-bounty submissions after unvalidated AI findings increased the volume of reports in its review queue. Introduced in June, the restriction limits how many vulnerability reports each researcher can keep open at once. Researchers who reach the undisclosed cap reportedly face a 30-day wait before filing again, although they may request capacity…
-
Trustmi Launches AI Investigation Agent for Collaborative Payment Fraud Reviews
Trustmi has launched an AI Investigation Agent that connects security, finance and business teams during investigations of suspected payment fraud. The agent is part of an expanded portfolio of specialized AI agents that Trustmi said is built for business-to-business fraud detection. The company announced the product ahead of a Black Hat 2026 showcase, where it..…
-
Metasploit Opens Its Exploit Engine to LLMs via New MCP Integration
If there was any reason to patch your systems, this would be it: The release of Metasploit 6.5, which brings the penetration testing framework into the AI age. Now, script kiddies and sophisticated foreign operatives don’t even have to cut and paste their code to break into your systems. They can just ask Metasploit to..…
-
The OpenAI and Anthropic Incidents Mark a Turning Point for AI Governance
Incidents at OpenAI, Anthropic, Replit, and PocketOS show AI is acting inside production systems. See why governance now has to start at the database. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/the-openai-and-anthropic-incidents-mark-a-turning-point-for-ai-governance/
-
Focus on infrastructure resilience, not AI hype, Western government leaders warn
U.S. and allied officials said companies should start preparing now for a cyberattack that changes how they provide essential services. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/ai-cybersecurity-resilience-black-hat-government-panel/827137/
-
The Most Dangerous AI Hacking Techniques Still Have Humans in the Loop
Security researcher James Kettle tried to push the limit of AI’s hacking abilities”, and discovered how effective it can be when combined with human expertise. First seen on wired.com Jump to article: www.wired.com/story/the-most-dangerous-ai-hacking-techniques-still-have-human-input/
-
Cobalt Launches Autonomous Pentest for Continuous Application Testing
Cobalt is launching Cobalt Autonomous Pentest, a service designed to bring continuous offensive security testing to an organization’s full application portfolio. The product debuts at Black Hat USA 2026 and is scheduled for general availability in August. The offering combines AI-driven testing with direction from Cobalt penetration testers. Its model-agnostic engine handles chain prediction, prioritization..…
-
CrowdStrike Warns AI Adoption Is Creating ‘Underdefended’ Attack Surfaces
CrowdStrike warns that AI adoption, rapid vulnerability exploitation, cloud attacks, and malicious npm packages are creating new enterprise security risks. The post CrowdStrike Warns AI Adoption Is Creating ‘Underdefended’ Attack Surfaces appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-crowdstrike-ai-underdefended-attack-surfaces/
-
Flaws in Google APK for Python Unlock AgentAgent Attack
Google has fixed the issues, which exploited a trust boundary between two AI agents with different privilege levels to trigger automation that could compromise the supply chain. First seen on darkreading.com Jump to article: www.darkreading.com/vulnerabilities-threats/flaws-google-apk-python-agent-to-agent-attack
-
OpenAI Disrupts Poipet Scam Network Using ChatGPT Across Multiple Fraud Schemes
OpenAI said it disrupted a Cambodia-based scam operation that used its generative artificial intelligence (AI) chatbot ChatGPT to facilitate a wide range of investment, romance, gambling, and law enforcement impersonation schemes.To that end, it banned a coordinated network of ChatGPT accounts likely originating from Southeast Asia and operating from the city of Poipet, a region…
-
Mini Shai-Hulud npm Attack: More Than 2,200 Components Impacted
Tags: access, ai, attack, breach, cloud, container, control, credentials, data, data-breach, github, guide, infection, intelligence, kubernetes, malicious, malware, microsoft, open-source, risk, sbom, service, software, threat, update<div cla TL;DR A new wave of the Shai-Hulud malicious package campaign emerged on npm, with 2,225 software component versions impacted. The malware executes through a malicious preinstall hook, steals npm, GitHub, cloud, Kubernetes, Vault, CI/CD, and other credentials, then uses stolen publishing access to compromise additional packages. Organizations that installed an affected version should…
-
7AI Launches Federated SIEM and Build Tools Ahead of Black Hat USA 2026
7AI has launched 7AI Federated SIEM and 7AI Build, two capabilities designed to give security teams a distributed foundation for AI-assisted operations. The company said both will be showcased at Black Hat USA 2026. 7AI Federated SIEM connects to security data across existing SIEMs, data lakes and cloud platforms. It lets teams query, investigate and..…
-
Cycode Opens Early Access to Agentic Workflows for Application Security
Cycode is making Agentic Workflows available in early access, giving AI agents the ability to detect, prioritize and fix application-development risks as they appear. The company is demonstrating the capability at Black Hat USA 2026 in Las Vegas. Agentic Workflows operate across the application development lifecycle. Security teams define the triggers, actions and confidence thresholds,..…
-
Assail Updates Ares With New Harness and AI Model for Autonomous Red Teaming
Assail has introduced Ares v2, a redesigned version of its autonomous offensive security platform, with a new interface, purpose-built model and rebuilt agentic harness. The company is tying the update to its Black Hat 2026 program, where founder and CEO Alissa Knight is scheduled to discuss how organizations should evaluate offensive AI systems. The new..…
-
5 Best AI Detection Response Platforms for 2026
Compare AI detection response platforms for 2026, including Dash, Lakera, Operant AI, HiddenLayer and Prisma AIRS, for runtime threat protection and response. First seen on hackread.com Jump to article: hackread.com/best-ai-detection-response-platforms-2026/
-
Meta Ran Ads That Contained AI-Generated Child Sexual Abuse Imagery
Tags: aiMore than 50 offending image and video ads were published across Facebook, Instagram, Messenger, or Threads, according to Meta’s ad library data. Some ran as recently as this week. First seen on wired.com Jump to article: www.wired.com/story/meta-ran-ads-that-contained-ai-generated-child-sexual-abuse-imagery/
-
Salt Security Launches Industry-First AWS WAF Managed Ruleset for AI Agents and API Protection
Salt Security has unveiled what it says is the industry’s first AWS WAF managed ruleset designed specifically to protect both APIs and AI agents, extending native AWS Web Application Firewall (WAF) capabilities to address emerging threats driven by agentic AI. Announced at Black Hat USA 2026, the new Salt Managed Rules for AWS WAF are…

