Tag: intelligence
-
EHR Vendor Notifying 3.8 Million Patients of Data Theft Hack
CareCloud Said Compromise Involved One of Its AWS Cloud Environments. CareCloud, a provider of cloud-based, artificial intelligence-powered electronic health records, is notifying nearly 3.8 million individuals that their personal and health information was potentially stolen in a March hacking incident involving one of its Amazon Web Services environments. First seen on govinfosecurity.com Jump to article:…
-
Rising Number of Cyberattacks Have AI-Assisted Fingerprints
Claude Code Especially Tied to Semi-Automated Intrusions, Data Theft, Ransomware. Attackers’ operational security fails reveal they’re increasingly wielding artificial intelligence tools in semi-autonomous ways to help them conduct reconnaissance and perpetrate ransomware infections and data exfiltration at greater speed and scale than ever before – albeit with mixed results. First seen on govinfosecurity.com Jump to…
-
OpenAI Pauses Frontier RL Training as It Tightens Defenses Against Unsafe AI Behavior
OpenAI on Tuesday revealed that it paused reinforcement learning (RL) training for its latest artificial intelligence (AI) models for two weeks while it shored up additional defenses and increased the scope of its monitoring to avert another Hugging Face-like incident.”As models become more capable, the risks associated with developing and testing them internally also grow,”…
-
SOC 2 + AI Controls: Strengthen Reports with Risk Audits
In 2026, organizations integrating artificial intelligence into core operations face a critical gap: traditional SOC 2 audits often overlook the unique risks introduced by AI systems, leaving reports incomplete and compliance efforts vulnerable to regulatory scrutiny. By expanding SOC 2 assessments with dedicated AI controls and integrated risk audits, firms can produce stronger, more defensible”¦…
-
Google Mandiant AI Agents Find Over 100 Critical Vulnerabilities in Source Code Within Two Days
Tags: ai, breach, corporate, cyber, google, group, incident response, intelligence, mandiant, penetration-testing, RedTeam, threat, vulnerabilityGoogle’s Threat Intelligence Group has announced that its Agentic Vulnerability Discovery Harness (AVDH) identified over 100 critical true-positive vulnerabilities in stolen corporate source code repositories within just two days. This result highlights how agentic AI can significantly accelerate vulnerability discovery during incident response, red teaming, penetration testing, and proactive secure code reviews, especially when adversaries…
-
Ransom Busters Ransomware Affiliate Targets Victims With Fake Data Recovery Extortion
A threat actor calling itself “Ransom Busters” is targeting ransomware victims with a deceptive recovery offer, claiming it can restore encrypted files and delete stolen data from ransomware infrastructure. GuidePoint Security’s Research and Intelligence Team (GRIT) assesses with moderate confidence that the purported recovery service is actually a ransomware affiliate attempting to divert extortion payments…
-
Medusa Ransomware Attacks 300+ Critical Infrastructure Organizations Using Double Extortion
Tags: advisory, attack, cisa, cyber, extortion, infrastructure, intelligence, ransomware, service, updateMedusa ransomware operators have compromised over 500 organizations across critical infrastructure sectors, according to a joint advisory issued by the FBI, CISA, and the U.S. Department of Health and Human Services (HHS) as part of their #StopRansomware initiative. An update released on August 18, 2026, provides expanded intelligence based on FBI investigations conducted as recently…
-
Keeper Security Issues Cybersecurity Guidance for Education IT Teams As Students Return to Campus
Every fall, school districts and universities across the country race to onboard thousands of new students, faculty and staff, provisioning accounts, issuing credentials and connecting a wave of new devices to institutional networks. It is a moment of organized chaos, and cybercriminals know it. Now, with artificial intelligence supercharging phishing campaigns and a hidden layer…
-
FDA Weighing Possible Regs for GenAI Medical Devices
Agency Seeks Public Input on Risk-Based Oversight Approach Across Product Life Cycle. The U.S. Food and Drug Administration is seeking public feedback on the varying risks and other considerations involving generative artificial intelligence-enabled medical devices to inform the agency as it contemplates how to advance a regulatory approach for these evolving products. First seen on…
-
Every Company Now Needs An AI Risk Officer: Accenture Expert
For most companies, it has now become essential to clearly designate a single executive responsible for ensuring that the drive to deploy AI does not outpace cybersecurity and safety, according to Accenture cyber intelligence leader Ryan Whelan. First seen on crn.com Jump to article: www.crn.com/news/security/2026/every-company-now-needs-an-ai-risk-officer-accenture-expert
-
Attackers Exploit MLflow SSRF Flaw to Steal Cloud Credentials and Secrets
Tags: ai, automation, cloud, credentials, exploit, flaw, intelligence, malicious, open-source, software, technology, vulnerabilityTwo critical vulnerabilities impacting MLflow, an open-source artificial intelligence (AI) platform, and FUXA, an open-source, web-based SCADA / HMI software built for operational technology (OT) and industrial automation, are witnessing malicious scanning and exploitation efforts.According to independent reports from watchTowr and VulnCheck, the vulnerabilities in question are as follows – First seen on thehackernews.com Jump…
-
Courts Face New Threat as Litigant Uses Hidden AI Prompt Injection in Filings
In what is believed to be the first decision of its kind in the U.S., a Connecticut state court judge has sanctioned a self-represented litigant for attempting to covertly influence artificial intelligence (AI) systems through hidden text embedded in court documents. In an Aug. 6 ruling in Elliott v. New York Bariatric Group, Superior Court..…
-
AI “Mind Viruses” Can Spread Between Agents Through Persistent Prompt Files
Security researchers at Anthropic and Switzerland’s EPFL have demonstrated that self-propagating payloads can spread from one artificial intelligence (AI) agent to the next through the editable system prompt files that autonomous agent harnesses use to carry state between sessions.The work, released as a preprint on August 10, 2026, tests the technique in a simulated six-agent…
-
Meta’s legal jeopardy is growing by the day
Also: AI’s implications on cybersecurity in an era of private attacksHello, and welcome to TechScape. I’m your host, Blake Montgomery, US tech editor at the Guardian. Today in tech, we’re discussing <a href=”https://www.theguardian.com/technology/meta”>Meta’s legal danger in the US and the implications of <a href=”https://www.theguardian.com/technology/artificialintelligenceai”>artificial intelligence for cybersecurity in an era of private cyberattacks.<a href=”https://www.theguardian.com/us-news/video/2026/aug/11/why-the-us-government-is-trying-to-ban-this-chinese-dancing-robot-video-explainer”>Why the…
-
CISA Warns of Active Exploitation of Ray-Project Ray Code Injection Vulnerability
Tags: ai, cisa, computing, cve, cyber, cybersecurity, data, exploit, flaw, framework, infrastructure, injection, intelligence, kev, open-source, vulnerabilityThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability to its Known Exploited Vulnerabilities (KEV) catalog. This vulnerability, tracked as CVE-2025-62593, is a code injection flaw in the Ray Project, a widely used open-source distributed computing framework often deployed for artificial intelligence workloads, machine learning development, data processing, and scalable Python…
-
CISA Flags Actively Exploited Ray Flaw That Can Trigger Browser-Based RCE
Tags: ai, cisa, computing, cybersecurity, exploit, flaw, framework, github, infrastructure, intelligence, kev, open-source, rce, remote-code-execution, vulnerabilityThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a critical flaw impacting Ray to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.Ray is an open-source, Python-native distributed computing framework designed to scale artificial intelligence and machine learning workloads. As of writing, the GitHub project has more than First seen…

