Tag: risk
-
OpenAI Pauses Development on Powerful Astra Model Over Autonomous Cyberattack Risks
OpenAI has halted select internal development on its unreleased flagship model, Astra, after safety evaluations revealed the system had achieved unprecedented autonomous cyberattack capabilities. The move comes as the artificial intelligence (AI) industry grapples with a wave of containment failures, where increasingly autonomous models have repeatedly breached sandbox environments and accessed live targets on the..…
-
The AI safety test is becoming a safety risk
AI agents are escaping cybersecurity testing environments and reaching real-world systems, raising questions about whether safety infrastructure, industry standards and regulation can keep pace with increasingly powerful models. First seen on techcrunch.com Jump to article: techcrunch.com/2026/08/09/the-ai-safety-test-is-becoming-a-safety-risk/
-
Webmail CSS Attacks Expose a New Risk for AI-Powered Email Tools
CSS attacks on major webmail services can steal credentials, hijack sessions and manipulate AI tools connected to users’ inboxes. PortSwigger researcher Gareth Heyes demonstrated something that should make every webmail team a little nervous: plain CSS, the styling language that’s supposed to just make text look nice, can be weaponized to steal passwords, hijack sessions, and…
-
Secure SDLC principles explained for SaaS founders
Key takeaways Secure SDLC helps SaaS founders reduce breach risk, rework, and customer trust damage by building security into normal delivery. The most effective controls are simple and repeatable across planning, design, build, test, release, and maintenance. Small teams can make real progress with clear ownership, peer review, automated checks, and a basic release checklist….…
-
EU AI Act Compliance Roadmap: What to Document – Kovrr
Articles related to cyber risk quantification, cyber risk management, and cyber resilience. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/eu-ai-act-compliance-roadmap-what-to-document-kovrr/
-
Continuous Control Monitoring vs Annual Testing – Kovrr
Articles related to cyber risk quantification, cyber risk management, and cyber resilience. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/continuous-control-monitoring-vs-annual-testing-kovrr/
-
The Hidden Risks of Ignoring API Security During Mobile Application Security Testing
Mobile applications don’t operate in isolation. Behind every login screen, payment flow, and push notification sits a network of APIs quietly moving data between the app, the backend, and third-party services. Yet when organizations plan mobile application security testing, API security is often treated as an afterthought, something to “get to later” once the app’s……
-
Account-Farming für Claude & Co.: Wie billige KI-Tokens zum Security-Risiko werden
Graumärkte verkaufen Zugänge zu Frontier-KI bis zu 90 Prozent günstiger. Okta zeigt die Risiken durch Account-Farming, Proxies und statische API-Keys. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/account-farming-fuer-claude-co-wie-billige-ki-tokens-zum-security-risiko-werden/a46052/
-
Island’s Michael Leland on the hidden risks of the AI supply chain
First seen on scworld.com Jump to article: www.scworld.com/resource/islands-michael-leland-on-the-hidden-risks-of-the-ai-supply-chain
-
How AI Agents Widen the Enterprise Blast Radius
AWS’s Matt Girdharry and Varonis’ Matt Radolec on Data Security, Machine-Speed Risk. Agentic AI can act at machine speed across data, APIs and cloud services, expanding enterprise risk beyond traditional controls. AWS’ Matt Girdharry and Varonis’ Matt Radolec explain why AI governance, least privilege and runtime visibility now matter more than ever for security teams.…
-
China Opens Cybersecurity Review of Palo Alto Networks Products
China has opened a cybersecurity review of Palo Alto Networks products, raising potential risks for critical infrastructure customers and foreign vendors. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/cybersecurity/news-china-palo-alto-networks-cybersecurity-review/
-
Security researchers scanned the Polish web and found courts, hospitals, and airports at risk of hacks
Researchers found common points of failure, like software used to organize and display web content, could have allowed hackers to run riot through government websites. First seen on techcrunch.com Jump to article: techcrunch.com/2026/08/07/security-researchers-scanned-the-polish-web-and-found-courts-hospitals-and-airports-at-risk-of-hacks/
-
Mapping One Control Set to Multiple Frameworks – Kovrr
Articles related to cyber risk quantification, cyber risk management, and cyber resilience. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/mapping-one-control-set-to-multiple-frameworks-kovrr/
-
AI Generated Code Risks: Why Business Owners Should Never Trust Software That Simply Works
AI can now generate working software in minutes. Ask Claude, GitHub Copilot, ChatGPT, or another AI coding tool to create an API, authentication flow, admin…Read More First seen on securityboulevard.com Jump to article: https://securityboulevard.com/2026/08/ai-generated-code-risks-why-business-owners-should-never-trust-software-that-simply-works/
-
OnePlus 10T Is Out of Security Support: Should You Keep Using Yours?
OnePlus 10T security support has ended. Here’s how owners can check their patch level, understand the risks, and decide when to replace the phone. The post OnePlus 10T Is Out of Security Support: Should You Keep Using Yours? appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-oneplus-10t-security-support-ended/
-
Agentic AI for Cyber Defenders: What Security Teams Built at Black Hat USA 2026
Tags: ai, automation, conference, control, credentials, cve, cyber, cybersecurity, data, data-breach, defense, detection, exploit, flaw, group, iam, intelligence, ISO-27001, mitigation, network, nvidia, offense, open-source, RedTeam, risk, skills, soc, technology, threat, tool, usa, vulnerabilityAgentic AI armed attackers first, but it also put real building power in defenders’ hands. Here’s what security practitioners built in two days at Black Hat USA 2026, and how the CyberAgents Exchange keeps that work compounding long after the event. Key takeaways Building defensive cybersecurity tooling no longer requires a developer. Agentic tooling drove…
-
The Cyber Express Weekly Roundup: Ransomware Surge, Government Data Breaches, Logistics Disruptions, and Third-Party Security Risks
This weekly roundup highlights the growing cybersecurity risks affecting businesses, government agencies, and critical service providers. From the continued dominance of ransomware operations to government database breaches and third-party supply chain incidents, recent events demonstrate how attackers are increasingly targeting trusted systems and external service providers to maximize disruption and data exposure. First seen on thecyberexpress.com Jump…
-
Nicht KI ist das größte Risiko, sondern ihre Identitäten
‘Aus einer Testumgebung heraus erlangten KI-Modelle von Anthropic unautorisierten Zugriff auf Echtdaten realer Systeme von Organisationen. Das Eklatante daran: Im Rahmen einer Sicherheitsanalyse zeigte sich, dass über unzureichend abgesicherte Identitäten Zugriffe auf produktive Systeme möglich waren und diese auf diesem Weg kompromittiert wurden. Ein Statement von Elmar Eperiesi-Beck, CEO bei Bare.ID. Zum Vergleich: Noch vor…
-
Researchers Discover Hidden Backdoor in 20 Router Models Allowing Remote Root Access
A hidden backdoor in 20 router models lets remote servers execute commands as root, putting affected devices at risk of takeover. Jacob Baines had a router on his desk that kept trying to call home, and it wasn’t supposed to. VulnCheck researchers found a backdoor baked into Zbtlink routers, and it’s not the kind of…
-
MTA Market Shifts: What Domain Owners Should Know
No SPF record found doesn’t mean email stops working, but it removes a layer of sender authorization. Here’s how to assess risk and remediate safely. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/mta-market-shifts-what-domain-owners-should-know/
-
MTA Market Shifts: What Domain Owners Should Know
No SPF record found doesn’t mean email stops working, but it removes a layer of sender authorization. Here’s how to assess risk and remediate safely. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/mta-market-shifts-what-domain-owners-should-know/
-
MTA Market Shifts: What Domain Owners Should Know
No SPF record found doesn’t mean email stops working, but it removes a layer of sender authorization. Here’s how to assess risk and remediate safely. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/mta-market-shifts-what-domain-owners-should-know-2/
-
Who’s Accountable When an AI Agent Fails? – Kovrr
Articles related to cyber risk quantification, cyber risk management, and cyber resilience. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/whos-accountable-when-an-ai-agent-fails-kovrr/
-
Beyond Cyber: How CTI Teams Are Solving Converged Threat Use Cases
In this post we explain how cyber threat intelligence teams are being expected to take on physical risk, how tradecraft overlaps, and how Flashpoint bridges the gap. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/beyond-cyber-how-cti-teams-are-solving-converged-threat-use-cases/
-
What Is Cyber Security Risk Assessment? A Complete Guide (2026)
A cyber security risk assessment is a structured process for identifying, analyzing, and prioritizing the risks to an organization’s information systems, data, and operations. It works by pairing each threat and vulnerability with the likelihood it will be exploited and the business impact if it is”, so leaders can decide which risks to fix, transfer,…
-
Europa stark bei der Sicherheit, doch schwach bei der KI-Governance
29 % der europäischen Unternehmen nennen die KI-Regulierung ihre größte Compliance-Sorge, der höchste Wert aller Regionen. Kiteworks hat seinen 2026 Data Security and Compliance Risk: Annual Survey Report veröffentlicht [1]. Die Analyse wurde zum fünften Mal in Folge durchgeführt und basiert auf einer Befragung von 459 Sicherheits-, Compliance-, Risiko- und IT-Fachleuten in zehn Branchen… First…
-
Mimecast’s Leslie Nielsen on why human risk doesn’t stop at people
Tags: riskFirst seen on scworld.com Jump to article: www.scworld.com/resource/mimecasts-leslie-nielsen-on-why-human-risk-doesnt-stop-at-people
-
Black Hat USA 2026: Solving insider risk in the agentic AI era
First seen on scworld.com Jump to article: www.scworld.com/perspective/black-hat-usa-2026-solving-insider-risk-in-the-agentic-ai-era
-
Agentic anarchy: Why using AI browsers just isn’t worth the risk
First seen on scworld.com Jump to article: www.scworld.com/news/agentic-anarchy-why-using-ai-browsers-just-isnt-worth-the-risk
-
AI Accelerates Financial Services Fraud
Coinbase’s Lunglhofer on Deepfakes, Supply-Chain Risk and Human Expertise. AI is helping criminals clone voices, exploit software flaws and guide fraud schemes in real time. Coinbase Chief Security Officer Jeff Lunglhofer explains why faster attacks demand AI-enabled defense backed by cybersecurity experts. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/ai-accelerates-financial-services-fraud-a-32450

