Tag: intelligence
-
OpenAI Pauses Development on Powerful Astra Model Over Autonomous Cyberattack Risks
OpenAI has halted select internal development on its unreleased flagship model, Astra, after safety evaluations revealed the system had achieved unprecedented autonomous cyberattack capabilities. The move comes as the artificial intelligence (AI) industry grapples with a wave of containment failures, where increasingly autonomous models have repeatedly breached sandbox environments and accessed live targets on the..…
-
Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication
Tags: access, authentication, business, cve, data, exploit, flaw, intelligence, software, sql, vulnerability, zero-dayMetabase has warned that a maximum-severity security flaw impacting its business intelligence and data visualization software package has been exploited in the wild as a zero-day.The vulnerability (CVSS score: 10.0), which does not carry a CVE identifier, allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, enabling them to gain…
-
Storm-1175 Launches StormEncryptor Ransomware Attacks Using N-able Security Flaw
Microsoft Threat Intelligence has identified a new ransomware campaign attributed to the financially motivated threat actor Storm-1175 that began deploying a previously undocumented ransomware strain, StormEncryptor, on August 2, 2026. The activity represents Storm-1175’s first observed operation since April 2026 and signals a notable shift in its ransomware tooling. The group was previously associated with…
-
AI Sandbox Failures Expose Need for Continuous Monitoring
Recent AI Incidents Show Sandbox Security Cannot Be Assumed. The fallout from the Hugging Face security incident continues with more artificial intelligence labs revealing that their models and agents either accessed the internet or escaped isolated test environments to hack into other companies. Frontier model labs can’t take sandbox containment as a given. First seen…
-
Kimi K3 Bypasses Cyber Test With Answer From GitHub
Test Flaw Allowed Moonshot AI’s Model to Reach the Internet. Moonshot AI’s open-weight model Kimi K3 jumped its sandbox during a test of its cybersecurity abilities to locate an already worked-out solution on GitHub – behavior perfectly normal for coders but that raises red flags for artificial intelligence models. First seen on govinfosecurity.com Jump to…
-
Agentic AI for Cyber Defenders: What Security Teams Built at Black Hat USA 2026
Tags: ai, automation, conference, control, credentials, cve, cyber, cybersecurity, data, data-breach, defense, detection, exploit, flaw, group, iam, intelligence, ISO-27001, mitigation, network, nvidia, offense, open-source, RedTeam, risk, skills, soc, technology, threat, tool, usa, vulnerabilityAgentic AI armed attackers first, but it also put real building power in defenders’ hands. Here’s what security practitioners built in two days at Black Hat USA 2026, and how the CyberAgents Exchange keeps that work compounding long after the event. Key takeaways Building defensive cybersecurity tooling no longer requires a developer. Agentic tooling drove…
-
AI-Assisted HTTP Terminator Finds Novel HTTP Desync Techniques and Apache Zero-Day
PortSwigger says HTTP Terminator, an artificial intelligence (AI)-assisted research system built by James Kettle, generated and proved new HTTP desynchronization techniques after exploring 30,000 candidate attack vectors.PortSwigger said a separate human-guided discovery cascade also exposed a zero-day in Apache Traffic Server. Kettle said HTTP Terminator tested 30,000 websites where scanning First seen on thehackernews.com Jump…
-
Beyond Cyber: How CTI Teams Are Solving Converged Threat Use Cases
In this post we explain how cyber threat intelligence teams are being expected to take on physical risk, how tradecraft overlaps, and how Flashpoint bridges the gap. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/beyond-cyber-how-cti-teams-are-solving-converged-threat-use-cases/
-
How Agentic AI Scales Cybercrime
Google’s Hultquist on Autonomous Attacks and Behavioral Defense. Cybercriminals are using agentic AI to automate intrusions, rewrite malware and scale operations with stolen access to artificial intelligence services. Google’s John Hultquist explains why signature-based defenses are losing ground and how behavioral detection can help security teams respond. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/how-agentic-ai-scales-cybercrime-a-32449
-
Cyber Risk Now Needs a Business Translator
Dataminr’s Balaji Yelamanchili on Risk Prioritization, AI and Cyber Resilience. Security teams face more signals than they can act on, and boards now demand answers in business terms, not technical ones. Balaji Yelamanchili of Dataminr explains how combining threat intelligence with risk quantification helps organizations prioritize what actually matters. First seen on govinfosecurity.com Jump to…
-
Why AI Governance Requires Continuous Compliance Assurance
Schellman CEO Avani Desai on Building Governance Before Technology Enforcement. Artificial intelligence governance must evolve as agentic AI systems make decisions at machine speed. Schellman CEO Avani Desai explains why organizations need continuous auditing, unified controls and multiple frameworks to prove AI trustworthiness without slowing innovation. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/ai-governance-requires-continuous-compliance-assurance-a-32438
-
OSINT collection techniques using legitimate tools
Open source intelligence, usually shortened to OSINT, is the practice of collecting and analysing information that is already publicly available. In a defensive context, that can include company websites, social media posts, public registers, DNS records, certificate logs, archived web pages, document metadata, and other sources that are accessible without bypassing controls or impersonating anyone….…
-
Why Post-Quantum Security Is Climbing the Enterprise Agenda
Tags: ai, attack, computer, computing, conference, container, crypto, cryptography, cybersecurity, data, google, government, hacker, Hardware, ibm, infrastructure, intelligence, risk, technology, threat, toolWhy Post-Quantum Security Is Climbing the Enterprise Agenda andrew.gertz@t“¦ Thu, 08/06/2026 – 04:56 Learn why post-quantum security is becoming an enterprise priority, how AI and quantum computing are reshaping cryptography, and how Thales Luna 8 helps organizations prepare. Data Security Key Management Encryption Key Management Bree Fowler – Journalist More About This Author > At…
-
How AI Agents Helped Seal Visa’s $2.4B BioCatch
Behavioral Biometrics Vendor Is Latest in Payment Network Sector Buying Spree. Visa, the world’s largest card payment network, is acquiring behavioral intelligence firm BioCatch in an all-cash deal valued at $2.4 billion. It’s the company’s largest acquisition to date and the latest in a string of payment sector M&As aimed at fraud and cybersecurity solutions.…
-
Intel 471 Adds MCP Connector and Native AI Analyst to Verity471
Intel 471 has added two AI capabilities to its Verity471 cyber intelligence platform: MCP471, a connector for Model Context Protocol workflows, and Agent471, a native AI analyst. The capabilities are being demonstrated at Black Hat USA 2026 from Aug. 4 to 6. Intel 471 said the additions are designed to bring pre-attack intelligence and threat-hunting..…
-
Mini Shai-Hulud npm Attack: More Than 2,200 Components Impacted
Tags: access, ai, attack, breach, cloud, container, control, credentials, data, data-breach, github, guide, infection, intelligence, kubernetes, malicious, malware, microsoft, open-source, risk, sbom, service, software, threat, update<div cla TL;DR A new wave of the Shai-Hulud malicious package campaign emerged on npm, with 2,225 software component versions impacted. The malware executes through a malicious preinstall hook, steals npm, GitHub, cloud, Kubernetes, Vault, CI/CD, and other credentials, then uses stolen publishing access to compromise additional packages. Organizations that installed an affected version should…
-
Over 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Lures
A macOS ClickFix operation spanning more than 250 front-end domains now fingerprints visitors before deciding whether to show them a malware lure, a change Microsoft Threat Intelligence tracked on infrastructure it had been watching for weeks.The server-side gate hides the malicious page from crawlers and sandboxes while presenting selected Mac users with a fake software…
-
OpenAI Disrupts Poipet Scam Network Using ChatGPT Across Multiple Fraud Schemes
OpenAI said it disrupted a Cambodia-based scam operation that used its generative artificial intelligence (AI) chatbot ChatGPT to facilitate a wide range of investment, romance, gambling, and law enforcement impersonation schemes.To that end, it banned a coordinated network of ChatGPT accounts likely originating from Southeast Asia and operating from the city of Poipet, a region…
-
Poison Claude Sells Discounted Claude Access While Its Operator Sees Every Customer Prompt
Cybersecurity researchers have discovered more than half-a-dozen services advertisements for illegal access to artificial intelligence (AI) models on underground cybercrime forums and messaging platforms.One such service, Poison Claude, claims to offer access to Anthropic’s large language models (LLMs), including Opus 4.8, Opus 4.7, Opus 4.6, and Sonnet 4.6.”Advertisements for Poison Claude First seen on thehackernews.com…
-
Paperclip AI Flaws Let Attackers Run Host Commands via Malicious Agent Imports
Two security flaws in Paperclip could let attackers execute commands on a network server or a developer’s computer. Paperclip is an open-source control plane for teams of artificial intelligence (AI) agents, and both paths rely on importing a malicious agent and starting it.A third flaw could expose sensitive data and control-plane details through application programming…
-
Uppsala Security Becomes First Blockchain Intelligence Company to Join Cyber Threat Alliance
SIngapore, Singapore, August 5th, 2026, CyberNewswire Uppsala Security, a Singapore-based blockchain intelligence and crypto forensics company, announced today that it has joined the Cyber Threat Alliance (CTA) as an Affiliate Member, becoming the first blockchain intelligence company to join the alliance. CTA is a nonprofit organization that brings cybersecurity organizations together to share actionable threat…
-
Commvault Adds Google Threat Intelligence to Threat Scan Recovery Workflows
Commvault is adding Google Threat Intelligence data and scanning capabilities to Threat Scan workflows, a move aimed at helping organizations identify compromised recovery points and choose clean data after a cyberattack. Announced during Black Hat USA 2026, the integration combines Commvault Threat Scan with intelligence from Google’s Mandiant, VirusTotal and Google threat teams. Customers will..…
-
What Gold Eagle Validates, and What Your Organization Still Has to Own (July 2026)
Tags: ai, business, compliance, data, finance, framework, government, intelligence, open-source, update, vulnerabilityWhat Gold Eagle Validates, and What Your Organization Still Has to Own (July 2026) The federal government just stood up a clearinghouse to find and validate vulnerabilities faster, with AI doing the finding. That is not the same thing as a clearinghouse that owns the consequence when a patch does not land in time. Key…
-
Menlo Security Extends Platform Reach to AI Agents
Menlo Security today at the Black Hat USA conference extended its cloud platform to secure artificial intelligence (AI) agents at runtime by sanitizing the web pages and files they read to neutralize prompt injection attacks and block data exfiltration. Company CEO Bill Robbins said the Menlo Agent Runtime Security (MARS) platform created to isolate browsers..…
-
Researchers Document Instance of AI Agent Being Used to Hack Other Agents
Pilar Security researchers have documented what they describe as the first instance of an artificial intelligence (AI) agent that could be used to exploit another AI agent. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/researchers-document-instance-of-ai-agent-being-used-to-hack-other-agents/
-
Anthropic AI agent faked identities, phished real developers in UK government hacking test
An artificial intelligence agent built by Anthropic independently planted malicious code in a real software project and sent phishing emails to developers during a U.K. government security evaluation, according to Britain’s AI Security Institute. First seen on therecord.media Jump to article: therecord.media/anthropic-ai-hacking-uk
-
Uppsala Security Becomes First Blockchain Intelligence Company to Join Cyber Threat Alliance
SIngapore, Singapore, 5th August 2026, CyberNewswire First seen on hackread.com Jump to article: hackread.com/uppsala-security-becomes-first-blockchain-intelligence-company-to-join-cyber-threat-alliance/
-
Robin Sage 2.0: How LinkedIn Became a Counterintelligence Battlefield
Five Eyes governments warn that foreign intelligence services are using fake recruiters, professional networks and paid consulting offers to extract sensitive information. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/robin-sage-2-0-how-linkedin-became-a-counterintelligence-battlefield/
-
How to Build an AI Business Case When ROI Is Hard to Measure: A CFO’s Framework for Justifying AI Investments
Primary keyword: AI ROI model Artificial intelligence has created a new problem inside the boardroom. Everyone agrees AI has value. Very few organizations agree on…Read More First seen on securityboulevard.com Jump to article: https://securityboulevard.com/2026/08/how-to-build-an-ai-business-case-when-roi-is-hard-to-measure-a-cfos-framework-for-justifying-ai-investments/
-
News alert: Mallory links threat intelligence to governed response as exploit timelines shrink
Las Vegas, United States, August 4th, 2026, CyberNewswire Mallory, the AI-native Threat and Exposure Management platform, today introduced a unified context and intelligence layer for security teams. The architecture has three parts: a context graph that correlates attack… (more”¦) First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/news-alert-mallory-links-threat-intelligence-to-governed-response-as-exploit-timelines-shrink/

