Tag: ai
-
Seeing AI Agents Is Not Enough. Security Teams Must Enforce What They Can Do
AI agent security is moving through a familiar maturity curve: adoption, then visibility, and finally, control. But what we’ve collectively discovered is that enforcing least privilege for AI agents is harder than we ever imagined. This is why there are so many approaches, from prompt filtering to identity-layer access controls. Where we’ve collectively landed is…
-
Github reagiert auf KI-Flut: Hohe Bug-Bounty-Prämien bald nur noch für Profis
Github überarbeitet sein Bug-Bounty-Programm. Wer sich nur auf KI verlässt und sich wenig Mühe gibt, bekommt künftig geringere Prämien. First seen on golem.de Jump to article: www.golem.de/news/github-reagiert-auf-ki-flut-hohe-bug-bounty-praemien-bald-nur-noch-fuer-profis-2607-211255.html
-
New Dolphin X Malware Uses AI Profiler to Rank High-Value Victims
Dolphin X malware targets more than 300 apps and includes an AI Profiler that scores infected Windows PCs to help criminals identify high-value victims quickly. First seen on hackread.com Jump to article: hackread.com/dolphin-x-malware-ai-profiler-rank-victims/
-
Hacker Runs Hermes AI Agent Unattended for Post-Exploitation at Thai Finance Ministry
Someone installed a popular AI assistant on a rented server, switched off the setting that makes it ask permission before running risky commands, and pointed it at Thailand’s Ministry of Finance, which runs the country’s treasury and tax collection.The agent then worked through the ministry’s network on its own, checking hosts for ways to gain…
-
Die neue Risiken durch agentische KI im Fokus – Warum LLM-Observability zum Sicherheitsfaktor für KI-Systeme wird
First seen on security-insider.de Jump to article: www.security-insider.de/warum-llm-observability-zum-sicherheitsfaktor-fuer-ki-systeme-wird-a-bd9def5d1852e535db0558409c91e25f/
-
The AI Trust Paradox: Businesses Are Racing Ahead, but Consumers Are Hesitating
Artificial intelligence adoption is soaring, but consumer trust lags. Transparency, human oversight, and clear AI use cases are key to closing the trust gap. Businesses are rapidly adopting AI, with 93% planning deployment, but consumer trust lags far behind: only 23% trust companies to use AI with their data, revealing a major “AI trust gap.”…
-
Russian APT Laundry Bear perfects zero-click phishing attack
A newly identified Russian state threat actor is using a novel zero-click phishing technique, likely developed with the help of an AI, to target Western users of Zimbra software products First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366645968/Russian-APT-Laundry-Bear-perfects-zero-click-phishing-attack
-
Why embodied AI security extends beyond the robot
As AI moves into robots, autonomous vehicles and industrial systems, attackers are likely to target the credentials, cloud services and update channels that control them First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366646180/Why-embodied-AI-security-extends-beyond-the-robot
-
Google gives developers an AI bug hunter that also writes patches
Google has launched a preview of CodeMender, an AI agent built to scan code for security flaws, confirm they are exploitable, and generate fixes for developers to review. … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/24/google-codemender-ai-agent-code-security/
-
NodeBB Patches Eight AI-Found Flaws Exposing Admin Access and Private Chats
Eight security flaws in NodeBB went public on Wednesday, along with the code to exploit them. Aikido Security rates all eight as high severity and says its AI pentest agents found them in a six-hour review of the forum software’s source code.Every version before 4.14.0 is affected. NodeBB has fixed them all, and administrators should…
-
Neue Okta for AI Agents-Funktionen steuern Zugriffe und Verbindungen von KI-Agenten
Zugriffszertifizierungen für KI-Agenten tragen durch automatisierte Zugriffsprüfungen dazu bei, dass jede Agentenverbindung im Laufe der Zeit angemessen dimensioniert bleibt. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/neue-okta-for-ai-agents-funktionen-steuern-zugriffe-und-verbindungen-von-ki-agenten/a45865/
-
Europe’s Multilingual Reality Exposes AI Security Gaps
Tags: aiThe AI security layer and guardrails for many AI products don’t evenly protect against jailbreaking and unsafe actions in every single language. First seen on darkreading.com Jump to article: www.darkreading.com/cybersecurity-operations/europes-multilingual-reality-exposes-ai-security-gaps
-
Governing Al agents at scale: Lessons from the leaders who’ve done it
Tags: aiEnterprise AI leaders from ZoomInfo, Docusign and AppViewX share what it took to build AI Centers of Excellence and govern agent identities inside two companies operating at … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/24/governing-al-agents-at-scale-video/
-
Claude Cowork Sandbox Escape Flaw Lets Attackers Access SSH Keys and Cloud Credentials
A newly revealed sandbox escape vulnerability affecting Anthropic’s Claude Cowork could allow untrusted content processed by the AI agent to access sensitive files on a macOS host. This includes SSH private keys, cloud credentials, and other data that are available to the logged-in user. Security researcher Oren Yomtov from Accomplish has named this attack path…
-
KI macht Ransomware-Angriffe gefährlicher
Künstliche Intelligenz verändert die Vorgehensweise von Cyberkriminellen und erhöht die Erfolgsquote von Ransomware-Angriffen deutlich. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/ki-ransomware-angriffe-gefaehrlicher
-
How AI guardrails are impeding the work of offensive cybersecurity researchers
We spoke with several cybersecurity researchers, who look for unknown vulnerabilities and develop tools to exploit them, about how OpenAI’s and Anthropic’s guardrails affect their work. First seen on techcrunch.com Jump to article: techcrunch.com/2026/07/23/how-ai-guardrails-are-impeding-the-work-of-offensive-cybersecurity-researchers/
-
Zu Hackern in Menschengestalt gesellt sich KI Unternehmen müssen Cyberabwehr neu denken
Tags: aiFirst seen on datensicherheit.de Jump to article: www.datensicherheit.de/hacker-menschen-ki-unternehmen-cyberabwehr-erneuerung
-
IBM Bets on Multi-Billion-Dollar Open-Source Patch Business
IBM Charges Enterprises $1M Annually for Validated Legacy Open-Source Patches. IBM is betting that AI can transform legacy open-source vulnerability remediation into a multibillion-dollar business by delivering validated, backported security patches for software versions enterprises continue to run years after upstream support ends. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/ibm-bets-on-multi-billion-dollar-open-source-patch-business-a-32317
-
Cloudflare CEO: How AI Commerce Is Upending the Web Economy
Matthew Prince: AI Assistants Are Replacing Traditional Search and Commerce Models. Cloudflare’s CEO said AI assistants are replacing traditional search and advertising-driven internet models, arguing that AI firms and search engines must adopt more efficient, event-driven crawling to reduce infrastructure costs while preparing for an AI-first internet powered by autonomous agents. First seen on govinfosecurity.com…
-
Employees’ shadow AI use is poorly monitored, survey finds
Employee behavior has always presented one of the biggest enterprise cybersecurity challenges. Add AI into the equation, and education and governance become even more critical. First seen on techtarget.com Jump to article: www.techtarget.com/searchsecurity/news/366646095/Employees-shadow-AI-use-is-poorly-monitored-survey-finds
-
Employees’ shadow AI use is poorly monitored, survey finds
Employee behavior has always presented one of the biggest enterprise cybersecurity challenges. Add AI into the equation, and education and governance become even more critical. First seen on techtarget.com Jump to article: www.techtarget.com/searchsecurity/news/366646095/Employees-shadow-AI-use-is-poorly-monitored-survey-finds
-
Apiiro CEO: Coding Agents Are the New Enterprise Perimeter
Idan Plotnik: AI Development Tools Have Become Enterprises’ Newest Attack Surface. Apiiro CEO Idan Plotnik says AI coding agents have become the enterprise’s newest security perimeter, prompting organizations to shift from application security posture management to automated protection as AI accelerates both software development and vulnerability exploitation. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/apiiro-ceo-coding-agents-are-new-enterprise-perimeter-a-32314
-
How Purpose-Built AI Can Speed Up Clinical Trials
Amber Hill, CEO of Research Grid, on Safely Overcoming Clinical Trial Bottlenecks. Clinical trial teams lose time to patient sourcing, site selection, manual data entry and other tasks. Amber Hill, CEO of Research Grid, discusses how purpose-built AI can safely automate administrative work, improve data quality and help promising treatments reach patients faster. First seen…
-
New Dolphin X malware uses AI to rank high-value targets
A new Dolphin X remote access trojan claims to use an AI-powered profiling feature to score and rank infected users, helping cybercriminals identify which victims should be targeted first. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/new-dolphin-x-malware-uses-ai-to-rank-high-value-targets/
-
AegisAI, founded by former Google security execs, lands $36M to stop AI-driven spear phishing
The Series A was led by Battery Ventures, bringing AegisAI total funding to $49 million. First seen on techcrunch.com Jump to article: techcrunch.com/2026/07/23/aegisai-founded-by-former-google-security-execs-lands-36m-to-stop-ai-driven-spear-phishing/
-
ThreatsDay: Android Spyware, PLC Attacks, AI Image Prompt Injection + 12 More Stories
Most of this week’s trouble came dressed as something useful.A package stole data. A fake extension opened remote access. A safety app became spyware. An image gave hidden orders to an AI agent. Other threats hid in open systems, weak code, and normal network traffic. The threats change every week. Subscribe, and we’ll alert you…
-
Blockchain Life Returns to Dubai, Featuring the Debut of AI Future
Dubai, UAE, 23rd July 2026, CyberNewswire First seen on hackread.com Jump to article: hackread.com/blockchain-life-returns-to-dubai-featuring-the-debut-of-ai-future/
-
Exclusive signs ServiceNow to bolster AI options
Distributor makes vendor signing as Sophos warns criminals are using the technology to launch more attacks First seen on computerweekly.com Jump to article: www.computerweekly.com/microscope/news/366646176/Exclusive-signs-ServiceNow-to-bolster-AI-options
-
OpenAI’s AI >>goes rogue<< and hacks Hugging Face: what you need to know
You can’t have failed to hear the news headlines about “rogue” OpenAI models hacking into another AI organisation, Hugging Face. First seen on bitdefender.com Jump to article: www.bitdefender.com/en-us/blog/hotforsecurity/openais-hacks-hugging-face
-
Claude Cowork Flaw Could Let AI Agent Escape Its VM and Access Mac Files
Cybersecurity researchers have uncovered a sandbox escape vulnerability in Anthropic’s Claude Cowork that makes it possible to break out of the confines of a Linux virtual machine (VM) within which the agent runs to read or write files anywhere on the Mac.Accomplish AI, which shared details of the vulnerability with The Hacker News ahead of…

