Tag: automation
-
Agentic AI for Cyber Defenders: What Security Teams Built at Black Hat USA 2026
Tags: ai, automation, conference, control, credentials, cve, cyber, cybersecurity, data, data-breach, defense, detection, exploit, flaw, group, iam, intelligence, ISO-27001, mitigation, network, nvidia, offense, open-source, RedTeam, risk, skills, soc, technology, threat, tool, usa, vulnerabilityAgentic AI armed attackers first, but it also put real building power in defenders’ hands. Here’s what security practitioners built in two days at Black Hat USA 2026, and how the CyberAgents Exchange keeps that work compounding long after the event. Key takeaways Building defensive cybersecurity tooling no longer requires a developer. Agentic tooling drove…
-
Critical Flaws in Claude Code, Gemini CLI, and OpenAI Codex Enable RCE and Supply Chain Attacks
Tags: ai, attack, automation, breach, cyber, flaw, google, openai, rce, remote-code-execution, supply-chain, theft, tool, vulnerabilitySecurity researchers have disclosed a vulnerability affecting AI coding-agent workflows from Anthropic, Google, and OpenAI. Their research highlights how an attacker-controlled issue or zero-privilege input can breach trust boundaries in an agent “harness”, which includes the permissions, tools, sandbox, filesystem, and automation surrounding the model, and result in code execution, secret theft, or workflow compromise.…
-
Over 4,400 Rockwell PLCs Exposed Online, 22 Found in Water Attack Cities
Forescout found 22 internet-facing Rockwell Automation programmable logic controllers (PLCs) in cities hit by recent cyberattacks on US water utilities. Nineteen used the same mobile carrier network.Its August 3 scan counted 4,407 exposed Rockwell controllers worldwide, including 2,844 in the United States, but Forescout could not confirm any were compromised. That figure counts exposed First…
-
How to Automate Code Signing with Jenkins, Azure Key Vault, and AzureSignTool?
Professional software distribution dictates that software maintainability, assurance, and protection against tampering are achieved through code signing; it is a must. It takes time and effort to manually sign everything with certificates, is prone to mistakes, and introduces security risks if certificates are copied from one system to another. That’s where automation comes in. This”¦…
-
Flooding Dropper Hits npm With 850 Malicious Packages
Tags: attack, automation, cloud, container, control, credentials, cvss, data-breach, detection, dns, endpoint, github, guide, infrastructure, linux, macOS, malicious, malware, monitoring, software, threat, windows<div cla TL;DR Sonatype Research Labs is tracking an active malicious package campaign, dubbed ‘Flooding Dropper,’ spreading on npm, currently impacting 846 software components. The attacker appears to be automating parts of the npm account and package creation process, combining terms such as bigops and bnpl with other words and recurring version patterns, such as releases…
-
Flaws in Google APK for Python Unlock AgentAgent Attack
Google has fixed the issues, which exploited a trust boundary between two AI agents with different privilege levels to trigger automation that could compromise the supply chain. First seen on darkreading.com Jump to article: www.darkreading.com/vulnerabilities-threats/flaws-google-apk-python-agent-to-agent-attack
-
Unlock AI GRC Automation via Continuum Cybersecurity Audits 2026
In 2026, organizations face mounting pressure to integrate AI automation into governance, risk, and compliance (GRC) programs while maintaining rigorous cybersecurity audit standards. AI Automation in GRC is no longer experimental; it is a strategic necessity for CISOs and compliance officers seeking to reduce manual overhead, close control gaps, and achieve continuous compliance across frameworks”¦…
-
Adobe fixed a maximum-severity vulnerability flaw in Campaign Classic
Adobe fixed a maximum severity vulnerability in Campaign Classic that could let attackers run code remotely without user interaction. Adobe has addressed a critical vulnerability, tracked as CVE-2026-48449 (CVSS score of 10.0), in Adobe Campaign Classic, the company’s enterprise marketing automation platform. The flaw is caused by incorrect authorization and could allow attackers to execute…
-
Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction
Adobe has released security updates to address a maximum-severity security flaw in Campaign Classic (ACC), its enterprise-focused marketing automation platform, that could result in arbitrary code execution.The vulnerability, tracked as CVE-2026-48449, carries a severity score of 10.0 on the CVSS scoring system.It has been described as a case of incorrect authorization that could result in…
-
XRP Volatility Surges as Cybersecurity Threats and Market Changes Raise New Concerns
XRP volatility drives faster crypto trading as AI tools gain traction, while phishing, exchange attacks and automation risks test digital asset safeguards. First seen on hackread.com Jump to article: hackread.com/xrp-volatility-cybersecurity-threats-market-changes/
-
Two Tools, Two Bills: The Consolidation Hiding In Your SOC Budget
Most SOCs pay two bills, a SOAR and an alert-automation tool, to do one job. Here is the cleanest consolidation in the 2026 stack, and how the math works. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/07/two-tools-two-bills-the-consolidation-hiding-in-your-soc-budget/
-
Top 7 Enterprise IT Asset Management Software for 2027
Compare 7 enterprise IT asset management platforms for 2027, covering security, automation, cost, compliance, lifecycle tracking and business requirements. First seen on hackread.com Jump to article: hackread.com/top-it-asset-management-software-2027/
-
n8n Sandbox Escape Lets Workflow Editors Run OS Commands as the n8n Process
n8n has patched a high-severity expression-sandbox escape that could let an authenticated workflow editor execute operating-system commands on the server running the automation platform. Security Joes found the flaw while probing n8n’s February fix for CVE-2026-27577 for another bypass.The affected ranges are <2.31.5 and >=2.32.0,<2.32.1. n8n fixed the flaw in versions 2.31.5 and First seen…
-
Iranian Hackers Exploit Rockwell, Schneider and Siemens PLCs Across U.S. Critical Infrastructure
Tags: advisory, automation, cisa, cyber, cybersecurity, exploit, hacker, infrastructure, Internet, iran, technology, threatIranian-affiliated advanced persistent threat (APT) actors are actively exploiting internet-connected programmable logic controllers (PLCs) from major industrial vendors, including Rockwell Automation, Schneider Electric, and Siemens, targeting U.S. critical infrastructure sectors. A joint cybersecurity advisory (AA26-097A) released by the FBI, CISA, NSA, DOE, EPA, Treasury, and U.S. Cyber Command highlights sustained exploitation activity against operational technology…
-
Marathon Petroleum’s CISO on OT security automation, supply chain risk
In this interview with Help Net Security, Mary Rose Martinez, CISO at Marathon Petroleum, talks about what happens to security when automation reaches deep into refineries, … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/27/mary-rose-martinez-marathon-petroleum-ot-security-automation/
-
PyPI Blocks New File Uploads to Old Releases to Prevent Package Poisoning Attacks
PyPI has introduced a new supply-chain security control that prevents publishers from uploading additional files to package releases older than 14 days, reducing the risk of attackers poisoning previously trusted versions after compromising project credentials, automation workflows, or publishing tokens. The Python Package Index (PyPI) has begun rejecting new distribution files uploaded to releases that…
-
Default Azure Automation Setting Enables Cross-Tenant Identity Takeover
Microsoft addressed a public-by-default configuration and chain of code flaws in Azure Automation which could have let attackers seize another tenant’s identity and access other tenants’ data, credentials, and cloud workloads. First seen on darkreading.com Jump to article: www.darkreading.com/cloud-security/default-azure-automation-setting-cross-tenant-identity-takeover
-
How AI-Driven Robotics Expands Industrial Cyber Risk
CEO: Connected Factories and Hospitals Expose Legacy OT Systems to Modern Threats. Claroty CEO Yaniv Vardi says physical AI will accelerate robotics and industrial automation while making cyber-physical security a strategic priority as connected operational technology exposes critical infrastructure to attacks with real-world consequences. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/how-ai-driven-robotics-expands-industrial-cyber-risk-a-32303
-
Remediating Vulnerabilities With LLMs: Inside Ivanti’s Automation Push
Ivanti CSO Daniel Spicer says frontier models have shown surprising effectiveness in early stages; but cost and human-in-the-loop viability remain open questions. First seen on darkreading.com Jump to article: www.darkreading.com/cybersecurity-operations/remediating-vulnerabilities-llms-ivanti-automation
-
Check Point builds homegrown AI model as attack barriers collapse
The company is training a security-only small language model as AI hands attackers industrial-scale capabilities and pushes cyber defence towards full automation First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366645879/Check-Point-builds-homegrown-AI-model-as-attack-barriers-collapse
-
n8n Token Exchange Flaw Could Let Attackers Log In as Users From Another Issuer
n8n, the workflow automation platform, handed out the wrong accounts at login. On Enterprise instances configured to trust more than one external token issuer, it matched an incoming JWT to a local user on the sub claim alone and ignored iss.A valid token from issuer A carrying a sub that belongs to someone under issuer…
-
The Hidden Security Risks of Reduced Summer IT Coverage
Security operations don’t slow down when IT teams take vacation, but staffing levels often do. Kaseya explains how AI-driven automation can help organizations maintain consistent security operations and reduce reliance on manual processes year-round. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/the-hidden-security-risks-of-reduced-summer-it-coverage/
-
Rewst AI agent update gives MSPs a new SMB automation play
First seen on scworld.com Jump to article: www.scworld.com/news/rewst-ai-agent-update-gives-msps-a-new-smb-automation-play
-
GitLost Vulnerability Lets Attackers Trick GitHub AI Agent Into Leaking Private Repos
A critical vulnerability known as >>GitLost<< has been discovered in GitHub's newly introduced Agentic Workflows by Noma Labs. This flaw allows unauthenticated attackers to exfiltrate sensitive data from private repositories. It demonstrates how AI-driven automation within development pipelines can be manipulated to bypass conventional access controls and leak confidential information across repository boundaries. GitLost Vulnerability…
-
Adobe patches seven max severity ColdFusion, Campaign flaws
Adobe has released security patches for seven maximum-severity vulnerabilities in the ColdFusion web app development platform and the Campaign Classic marketing automation platform. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/adobe-patches-seven-max-severity-coldfusion-campaign-flaws/
-
AI-Generated Workflows Are a Silent Security Disaster
Teams are dealing with a truly dangerous problem, automation that works, but that no one understands. First seen on darkreading.com Jump to article: www.darkreading.com/cyber-risk/ai-generated-workflows-silent-security-disaster
-
Healthcare Data Collaboration Gets a Boost From AI
Emids’ CAIO on Why Healthcare Leaders Are Treating AI as an Enterprise Investment. Healthcare organizations are moving beyond debating AI’s value and focusing on how to scale it. According to Emids’ State of Healthcare AI in 2026 survey, 65% of healthcare leaders rank AI and automation as their top investment priority, reflecting a shift toward…
-
The Cyber Express Weekly Roundup: Five Eyes AI Warning, KDDI Data Breach, Garfield AI Legal Milestone, and Iranian Hacker Arrest
Tags: ai, automation, breach, cyber, cybersecurity, data, data-breach, hacker, infrastructure, intelligence, international, iran, risk, service, threatThis week’s weekly roundup of cybersecurity developments highlights a rapid shift in global cyber risk conditions driven by artificial intelligence acceleration, large-scale data breaches, and expanding international enforcement actions. Across infrastructure, enterprise systems, public services, and regulated AI applications, organizations are increasingly exposed to faster-moving threats where traditional security assumptions are being challenged by automation…
-
The Cyber Express Weekly Roundup: Five Eyes AI Warning, KDDI Data Breach, Garfield AI Legal Milestone, and Iranian Hacker Arrest
Tags: ai, automation, breach, cyber, cybersecurity, data, data-breach, hacker, infrastructure, intelligence, international, iran, risk, service, threatThis week’s weekly roundup of cybersecurity developments highlights a rapid shift in global cyber risk conditions driven by artificial intelligence acceleration, large-scale data breaches, and expanding international enforcement actions. Across infrastructure, enterprise systems, public services, and regulated AI applications, organizations are increasingly exposed to faster-moving threats where traditional security assumptions are being challenged by automation…
-
Gemini 3.5 Flash Now Supports Agentic Computer Use for Enterprise Automation Tasks
Google has announced a significant enhancement to its AI platform with the release of Gemini 3.5 Flash, which now includes native support for agentic computer use. This new feature enables advanced enterprise automation across web, desktop, and mobile environments. Introduced on June 24, 2026, this capability was previously limited to the standalone Gemini 2.5 computer-use…

