Tag: framework
-
AI Autonomy: How to Find the Autonomy Your Agents Already Have
TL;DRA framework for measuring autonomy: The Cloud Security Alliance’s six-level model (Level 0 to Level 5) gives security teams language for how independently an AI agent can act, from human-executed tasks to full autonomy.Credentials reveal an agent’s real reach: Intended… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/ai-autonomy-how-to-find-the-autonomy-your-agents-already-have/
-
BambooToken malware controls Windows and Linux systems via MQTT
A previously unknown malware framework called BambooToken, active since at least 2023, is now using the Message Queuing Telemetry Transport (MQTT) protocol to communicate with Windows and Linux systems. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/bambootoken-malware-controls-windows-and-linux-systems-via-mqtt/
-
Hackers Deploy Agentic AI to Automate Exploitation and Mass Credential Harvesting
Threat actors are moving from using artificial intelligence as a productivity aid to deploying autonomous agentic systems that can execute major portions of an intrusion with minimal human intervention. Google Threat Intelligence Group (GTIG) has documented a financially motivated actor that used a multi-agent framework to plan, build, and run a mass credential-harvesting operation in…
-
AI Agent Identity and Access Control: A Framework for B2B SaaS
An AI agent needs four things human IAM does not provide: an identity of its own rather than a borrowed one, delegation semantics that keep the human’s authority visible without impersonating them, authorization scoped to a task rather than a… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/ai-agent-identity-and-access-control-a-framework-for-b2b-saas/
-
Is Your Organization Mature Enough for AI?
CyberEdBoard Webinar to Explore CMU SEI AI Adoption Maturity Model. The CyberEdBoard will host a virtual webinar Sept. 24 to explore a new framework developed by the Carnegie Mellon Software Engineering Institute and Accenture to help organizations assess their AI adoption maturity and build a road map for achieving predictable, repeatable and scalable results. First…
-
Autonomous AI Agents Compromise Thousands of Credentials in Under Six Hours
Threat actors are continuing to leverage artificial intelligence (AI) to streamline their operations, with one financially motivated hacking group employing an autonomous, multi-agent attack framework to carry out a large-scale credential harvesting campaign within six hours.Google Threat Intelligence Group (GTIG) said it has observed attackers with diverse motivations targeting proprietary AI First seen on thehackernews.com…
-
Hackers build AI frameworks for widescale credential theft
Threat actors are increasingly switching from AI-powered coding assistants to multi-agent frameworks that automate every stage of an attack. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/hackers-build-ai-frameworks-for-widescale-credential-theft/
-
BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations
A phishing-as-a-service framework called BigBear 2.0 has been used to bypass multi-factor authentication at 258 organizations and steal more than 5,000 Microsoft 365 credentials. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/bigbear-microsoft-365-phishing-service-bypassed-mfa-at-258-organizations/
-
How to Build a Shared AI Engineering Framework Without Killing Developer Autonomy
Every engineering leader is running the same experiment right now, whether they admit it or not. Developers are already using AI. The only open question is whether leadership knows about it, controls it, and gets value from it, or whether… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/how-to-build-a-shared-ai-engineering-framework-without-killing-developer-autonomy/
-
CrowdStrike Launches SafeMind Agentic AI Cybersecurity System Built With NVIDIA Nemotron
Tags: ai, attack, crowdstrike, cyber, cybersecurity, defense, framework, mitigation, nvidia, technologyCrowdStrike has launched SafeMind, an AI-driven cybersecurity system developed using NVIDIA’s Nemotron models. This new technology is designed as an automated red-versus-blue defense loop within the Falcon platform. Announced at Fal.Con 2026, SafeMind merges security-specific models with operational frameworks to identify attack paths, implement defensive measures, and continuously assess whether these mitigations hold up against…
-
OpenAI confirms ‘wiki incident,’ says it’s ‘working on a framework’ for more disclosure
OpenAI acknowledged its role in a recently reported incident where AI agents took over a German wiki forum. First seen on techcrunch.com Jump to article: techcrunch.com/2026/09/05/openai-confirms-wiki-incident-says-its-working-on-a-framework-for-more-disclosure/
-
Hackers Use Frontier AI Agents to Breach Enterprise Network in Under 10 Hours
Tags: ai, attack, automation, breach, cloud, credentials, cyber, framework, hacker, infrastructure, intelligence, network, threatA threat actor used frontier artificial-intelligence models and attack-specific agentic frameworks to breach an enterprise environment, harvest root credentials, and hijack cloud AI infrastructure in less than 10 hours. The investigation, documented by Palo Alto Networks Unit 42, highlights a significant shift in intrusion operations. AI-assisted automation compressed an attack that could otherwise demand several…
-
How Differential Privacy Will Transform Enterprise Data Strategy
For sixteen years I’ve watched enterprise data privacy evolve through three eras: access controls and encryption at rest, then de-identification, and now a third era defined by a mathematical framework most executives have heard of but few truly understand: differential privacy. The shift matters because the previous eras have quietly failed. De-identified datasets have been..…
-
How Differential Privacy Will Transform Enterprise Data Strategy
For sixteen years I’ve watched enterprise data privacy evolve through three eras: access controls and encryption at rest, then de-identification, and now a third era defined by a mathematical framework most executives have heard of but few truly understand: differential privacy. The shift matters because the previous eras have quietly failed. De-identified datasets have been..…
-
BraZetsu Malware Turns Compromised Windows Hosts Into Criminal Marketplace Inventory
Cybersecurity researchers have disclosed details of a sophisticated Python-based Windows malware framework called BraZetsu that fuels an underground marketplace commercializing access to compromised hosts.”Unlike the standard infostealer model, BraZetsu is a comprehensive master toolkit that empowers Initial Access Brokers (IABs) by turning compromised systems into highly valuable commercial First seen on thehackernews.com Jump to article:…
-
SOC 2 vs ISO 27001: Which One Should Your Business Choose?
For growing businesses, especially SaaS companies and tech providers, strong information security is important. It enables you to attract and acquire new customers. It also helps you enter new markets. Two of the most widely recognized frameworks are SOC 2… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/soc-2-vs-iso-27001-which-one-should-your-business-choose/
-
OpenAI Reveals Astra, Its First AI Model to Reach ‘Critical’ Cybersecurity Risk Threshold
OpenAI announced Tuesday that its upcoming artificial intelligence (AI) model, codenamed Astra, is the company’s first to reach the highest threat level under its internal risk framework, triggering an initial development pause to implement stricter safeguards before its public rollout. Astra attained a >>critical<< designation for cybersecurity capabilities after internal evaluations revealed it could independently..…
-
The Gentlemen Ransomware Hackers Use TukTuk C2 to Steal Credentials and Disable EDR Security
Tags: breach, control, credentials, cyber, edr, framework, group, hacker, healthcare, ransomware, technologyThe Gentlemen ransomware operation has been linked to a previously undocumented, cross-platform command-and-control framework named TukTuk, alongside EDR-disabling tooling, DLL sideloading research, and datasets apparently stolen from technology and healthcare organizations. Analysis of a Finland-hosted server identified what researchers assess as the complete TukTuk development project, providing an unusually detailed view into the group’s post-compromise capabilities.…
-
How Keeper Privileged Cloud Delivers Zero Standing Privilege
Keeper Privileged Cloud delivers Zero Standing Privilege (ZSP) by extending KeeperPAM®’s Just-In-Time (JIT) access framework to cloud identity platforms. A user gets elevated permissions only after a request is approved; those permissions last for a set time window, and Keeper… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/how-keeper-privileged-cloud-delivers-zero-standing-privilege/
-
JWT vs. OAuth: Understanding Tokens and Authorization
Tags: frameworkOAuth is an authorization framework that defines how to grant access. JWT is a token format that defines how to package and transmit claims. They solve different problems, and most production systems use both. JWT and OAuth show up together… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/jwt-vs-oauth-understanding-tokens-and-authorization/
-
Attacks Targeting Langflow AI Agent-Building Tool Surge
Tags: access, ai, attack, credentials, exploit, framework, ibm, intelligence, open-source, software, tool, vulnerabilityTool’s Access to Compute Resources, Keys and Credentials Make It a Repeat Target. Open-source framework Langflow, designed to build artificial intelligence agents and workflows, is under fire again, with attackers now wielding exploit code for a vulnerability first detailed in January. Outdated versions of the IBM-maintained software with known vulnerabilities appear to abound. First seen…
-
Critical Langflow flaw exploited to steal OpenAI and AWS keys
Tags: ai, credentials, exploit, flaw, framework, open-source, openai, remote-code-execution, threat, vulnerabilityThreat actors are exploiting an unauthenticated remote code execution vulnerability (CVE-2026-0768) in Langflow, an open-source framework for building AI applications, to steal credentials, tokens, and keys. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/critical-langflow-flaw-exploited-to-steal-openai-and-aws-keys/
-
What Does a SOC Look Like When AI Is Part of the Architecture? A Closed-Door Working Session on September 15
Alert volumes are climbing. And in July, the theoretical version of the AI threat stopped being theoretical. An autonomous agent framework driven by OpenAI models ran an end-to-end intrusion against Hugging Face, executing roughly 17,600 recorded actions across a four… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/what-does-a-soc-look-like-when-ai-is-part-of-the-architecture-a-closed-door-working-session-on-september-15/
-
AI-Enhanced BraZetsu Malware Powers Underground Market Selling Access to Corporate Networks
BraZetsu, a Python-based Windows malware framework allegedly operated by the Brazilian threat actor Exilware to identify, profile, and monetize compromised corporate systems. Rather than behaving like a conventional infostealer, BraZetsu appears designed to support an Initial Access Broker operation, converting infected endpoints into cataloged access offerings for an underground marketplace. The framework is reportedly the…
-
Chrome and Edge Extensions Strip CSP and Inject JavaScript to Drain EVM, Solana and Tron Wallets
Research identified 19 malicious browser extensions 18 for Google Chrome and 1 for Microsoft Edge that use a modular malware framework to strip website Content Security Policy protections, inject attacker-controlled JavaScript. Socket determined that 14 extensions were created by the threat actor, while five were acquired from legitimate developers and subsequently weaponized. The most consequential…
-
Metasploit Adds Exploit for PaperCut MF/NG Zero-Day RCE Vulnerabilities
Rapid7’s Metasploit Framework is set to add an exploit module targeting the actively exploited chain of vulnerabilities affecting PaperCut MF and PaperCut NG. This addition will provide public offensive tooling for a security emergency involving print management servers. The proposed module targets CVE-2026-81578 and CVE-2026-82078, two vulnerabilities that attackers can exploit to achieve remote code…
-
Cyber Assessment Framework (CAF) Version 4.0
What is the Cyber Assessment Framework? The Cyber Assessment Framework (CAF) is a cybersecurity and resilience framework developed by the UK National Cyber Security Centre (NCSC). It helps organizations assess how effectively they manage cyber risks to their essential functions and services. CAF 4.0 is primarily relevant to organizations in critical sectors such as energy,……
-
Attackers Exploit MCP RCE, Blind Prompt Injection and Memory Credential Theft Against AI Infrastructure
Tags: ai, cloud, credentials, cyber, data-breach, exploit, framework, infrastructure, injection, rce, remote-code-execution, service, theftAttackers are increasingly treating AI infrastructure as a high-value cloud entry point, exploiting exposed Model Context Protocol (MCP) services, agent frameworks, and AI gateways to execute code, validate prompt injection, deploy cryptominers, and steal credentials from process memory. The campaigns show that attackers are no longer using only generic web-server tradecraft; they are tailoring reconnaissance,…
-
What Enterprise Continuous Compliance Software Misses
<div cla Key Takeaways: What Enterprise Continuous Compliance Software Misses Visibility gaps prevent your security team from detecting control failures until audits expose them months later. Weak control mapping disconnects your framework compliance from actual risk exposure, leaving critical gaps unaddressed. Executive reporting fails when dashboards show activity metrics instead of financial impact your board…

