Tag: control
-
Cloud Security Alliance Starts Initiative to Define Controls for Catastrophic AI Risks
The Cloud Security Alliance has launched an initiative to define auditable controls for catastrophic AI risks, along with a research center focused on how frontier AI is changing cybersecurity. Announced Wednesday in Las Vegas, the Catastrophic Risk Annex will extend CSA’s AI Controls Matrix with controls for mitigating catastrophic AI risks. CSA said the controls..…
-
Jscrambler Launches Unified Client-Side Security Platform
Jscrambler has launched a Unified Client-Side Security Platform that combines software integrity and data governance through a browser runtime architecture. The platform is built on Jscrambler’s Behavioral Enforcement Core, which continuously monitors browser behavior, analyzes activity and enforces policy through a single deployment. The company said the goal is to extend security controls to the..…
-
AI governance is the missing security control
First seen on scworld.com Jump to article: www.scworld.com/perspective/ai-governance-is-the-missing-security-control
-
AI Browsers Vulnerable to ‘PleaseFix’ Zero-Click Agent Hijacking
Attackers can take control of agents through malicious instructions hidden in content supplied to AI browsers, and there’s no simple fix for the threat. First seen on darkreading.com Jump to article: www.darkreading.com/cyber-risk/ai-browsers-zero-click-agent-hijacking
-
Flooding Dropper Hits npm With 850 Malicious Packages
Tags: attack, automation, cloud, container, control, credentials, cvss, data-breach, detection, dns, endpoint, github, guide, infrastructure, linux, macOS, malicious, malware, monitoring, software, threat, windows<div cla TL;DR Sonatype Research Labs is tracking an active malicious package campaign, dubbed ‘Flooding Dropper,’ spreading on npm, currently impacting 846 software components. The attacker appears to be automating parts of the npm account and package creation process, combining terms such as bigops and bnpl with other words and recurring version patterns, such as releases…
-
Mini Shai-Hulud npm Attack: More Than 2,200 Components Impacted
Tags: access, ai, attack, breach, cloud, container, control, credentials, data, data-breach, github, guide, infection, intelligence, kubernetes, malicious, malware, microsoft, open-source, risk, sbom, service, software, threat, update<div cla TL;DR A new wave of the Shai-Hulud malicious package campaign emerged on npm, with 2,225 software component versions impacted. The malware executes through a malicious preinstall hook, steals npm, GitHub, cloud, Kubernetes, Vault, CI/CD, and other credentials, then uses stolen publishing access to compromise additional packages. Organizations that installed an affected version should…
-
Paperclip AI Flaws Let Attackers Run Host Commands via Malicious Agent Imports
Two security flaws in Paperclip could let attackers execute commands on a network server or a developer’s computer. Paperclip is an open-source control plane for teams of artificial intelligence (AI) agents, and both paths rely on importing a malicious agent and starting it.A third flaw could expose sensitive data and control-plane details through application programming…
-
Trojanized npm Packages Employ NullReceiver Tactic to Decode C2 IP from Blockchain
Cybersecurity researchers have flagged an evolution of the EtherHiding blockchain-based command-and-control (C2) technique that conceals the C2 server IP address inside a made-up destination address of a completely empty Ethereum transfer.The new dead drop resolver approach, observed in two trojanized npm packages “bianira-ui” and “fluid-type-ui,” has been codenamed NullReceiver by First seen on thehackernews.com Jump…
-
Menlo Security Extends MARS to Protect AI Assistants and Coding Agents
Menlo Security has expanded Menlo Agent Runtime Security, or MARS, with controls aimed at protecting AI assistants and coding agents from prompt injection, malware and data loss as they browse the web, use applications and process files. The company is highlighting the update at Black Hat USA 2026. MARS is a cloud-based capability in Menlo’s..…
-
Trojanized npm Packages Decode C2 IP From Ethereum Recipient Addresses
Cybersecurity researchers have flagged an evolution of the EtherHiding blockchain-based command-and-control (C2) technique that conceals the C2 server IP address inside a made-up destination address of a completely empty Ethereum transfer.The new dead drop resolver approach, observed in two trojanized npm package “bianira-ui” and “fluid-type-ui,” has been codenamed NullReceiver by First seen on thehackernews.com Jump…
-
Terra Security Adds Prevention Rules to Its Offensive Security Platform
Terra Security has launched Prevention, a capability that turns confirmed exploit findings into targeted Web Application Firewall or firewall rules while a permanent fix is still in progress. The feature is part of Terra Platform. When Terra confirms that a finding is exploitable, its AI agents test whether existing compensating controls stop that attack path……
-
JetStream Launches AI Kill Switch for Individual Agents
JetStream Security has launched an AI Kill Switch that can shut down a single compromised or malfunctioning AI agent without affecting other AI operations. The control is part of JetStream’s AI governance platform. The company said it combines the person who invoked an action, the agent identity carrying it out, the system’s stated intent and..…
-
Bedrock Data Launches Agent DLP for Runtime AI Data Controls
Bedrock Data has launched Agent DLP, a runtime data loss prevention capability for AI agents that inspects tool calls and responses as they happen. Agent DLP is available as part of Bedrock Data’s ArgusAI platform. The company said it checks requests an agent sends to a tool and the responses that come back, then allows,..…
-
From Inspection to Authorization: Securing Networks for AI Agents
Tags: access, ai, api, business, ceo, cloud, communications, control, crowdstrike, cryptography, data, encryption, endpoint, finance, firewall, identity, infrastructure, login, network, office, risk, saas, service, usa, vpn<div cla An Industry Perspective By Rajiv Pimplaskar, CEO, Dispersive Holdings, Inc. Agentic AI changes the network security problem from inspection to authorization. As more traffic is generated by agents, models, and workloads operating at machine speed, the network has to make trust decisions continuously, evaluate policy in real time, revoke access automatically, and keep…
-
Reco Expands AI Runtime With Browser Controls and Prompt Blocking
Reco is expanding its AI Runtime capability with browser-based enforcement, real-time prompt analysis and blocking, and automated remediation. The company said the update is designed to act on the risk posed by AI agents without requiring security teams to route traffic through a new gateway or proxy. Reco’s Smart Remediation feature turns findings into proposed..…
-
BigID Adds Agentic Access Controls and Intent Monitoring for AI Agents
BigID has introduced two capabilities aimed at governing what AI agents can access and checking whether their actions match the tasks they were assigned. Announced Aug. 4 in a release tied to Black Hat USA 2026, Agentic Access Control and Intent-Based Activity Monitoring are designed to address the gap between an agent’s permissions and its..…
-
Keyfactor will Cofide übernehmen, um verifizierte Identitäten für KI-Agenten und Cloud-Workloads bereitstellen zu können
Keyfactor gibt seine Absicht bekannt, das in Großbritannien beheimatete Unternehmen Cofide, eine Identitätsplattform, die Software-Workloads und KI-Agenten in modernen Cloud-Umgebungen schützt, zu übernehmen. Durch die Übernahme wird die Keyfactor-Trust-Control-Plane auf Workloads und KI-Agenten ausgeweitet werden. Sicherheitsteams werden über ein einziges System verfügen, mit dem sie unternehmensweit nicht-menschliche Identitäten verwalten und steuern können werden. Unternehmen setzen zunehmend…
-
Is Your AI Infrastructure Quantum-Ready? Evaluating Threat Detection and Access Control
Is your AI infrastructure quantum-ready? Discover how to defend against Harvest Now, Decrypt Later threats and secure your Model Context Protocol deployments. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/is-your-ai-infrastructure-quantum-ready-evaluating-threat-detection-and-access-control/
-
SOC 2 + SSO Checklist for Legal Tech SaaS Selling to Law Firms
A SOC 2 SSO checklist for legal tech SaaS: map CC6 criteria to SAML and SCIM controls, gather evidence, and pass law firm security reviews faster. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/soc-2-sso-checklist-for-legal-tech-saas-selling-to-law-firms/
-
Cloudflare gives AI agents wallets with built-in spending controls
Cloudflare’s Wallets will give AI agents running on its platform a human-readable wallet handle for paying APIs and online content within limits set by their creator. … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/05/cloudflare-wallets-for-ai-agents/
-
Why AI Agents Challenge Identity Governance
CIOs Need New Controls for Discovery, Intent and Token Costs. AI agents can operate within legitimate permissions and still take actions their creators never intended. Saviynt Chief Product Officer Vibhuti Sinha explains why CIOs need stronger discovery, runtime oversight, identity data and cost controls to scale agents safely. First seen on govinfosecurity.com Jump to article:…
-
Airlock Digital Unveils Agentic AI Control Governance to Extend Preventative Endpoint Security
Atlanta, GA, August 4th, 2026, CyberNewswire Airlock Digital announces Agentic AI Control & Governance, extending its preventative endpoint security solution with visibility into trusted AI agent behavior and governance over what trusted agents are allowed to do on endpoints. Airlock Digital, a leader in preventative endpoint security, today announced Agentic AI Control & Governance at…
-
Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens
The commercial phishing-as-a-service (PhaaS) toolkit known as Greatness has become the latest crimeware solution to add support for device code phishing, a rapidly growing cyber threat that abuses the legitimate OAuth 2.0 Device Authorization Grant to bypass Multi-Factor Authentication (MFA) and seize control of user accounts.”Greatness supports AiTM [adversary-in-the-middle] credential and First seen on thehackernews.com…
-
Airlock Digital Unveils Agentic AI Control Governance to Extend Preventative Endpoint Security
Atlanta, GA, 4th August 2026, CyberNewswire First seen on hackread.com Jump to article: hackread.com/airlock-digital-unveils-agentic-ai-control-governance-to-extend-preventative-endpoint-security/
-
Varonis Agent IBAC keeps AI agents within their intended boundaries
AI agents need broad access to be useful, but traditional access controls cannot determine whether an action aligns with a user’s intent. Varonis explains how Agent IBAC detects intent drift and enforces real-time guardrails to keep agents within their intended boundaries. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/varonis-agent-ibac-keeps-ai-agents-within-their-intended-boundaries/
-
Cybercriminals Bypass AI Safety Controls by Splitting Malicious Tasks Across Multiple Sessions
Talos read attacker prompt logs and found guardrails fell to task splitting and ownership claims First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/talos-attackers-split-tasks-evade/
-
Nvidia-backed Open Secure AI Alliance puts AI security and sovereignty in focus for Middle East
Tags: ai, control, cyber, data, government, infrastructure, intelligence, middle-east, nvidia, risk, toolIndustry coalition aims to develop open tools for securing artificial intelligence systems, a model that could resonate strongly in the UAE and Saudi Arabia as governments and enterprises seek greater control over AI infrastructure, data and cyber risk First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366646515/Nvidia-backed-open-secure-AI-alliance-puts-AI-security-and-sovereignty-in-focus-for-Middle-East
-
OWASP Introduces Subtractive Security Top 10 to Eliminate Attack Paths and Reduce Cyber Risk
OWASP has launched the Subtractive Security Top 10 project, a security engineering initiative that shifts the focus from adding more detection controls to removing the architectural conditions that enable cyberattacks. The project, led by Christopher Frenz, promotes a straightforward premise: attackers can only exploit attack paths that exist. Instead of relying primarily on monitoring, alerting,…

