Tag: tool
-
FireTail State of AI Security 2026: Adoption Has Outpaced Control FireTail Blog
Tags: access, ai, control, credentials, data, group, intelligence, jobs, leak, risk, threat, tool, vulnerabilityAug 17, 2026 – Ayush Sethi – What your workforce’s AI prompts reveal in aggregate Most AI security controls judge one prompt at a time. We built Topics to read the layer above them, where a workforce’s prompts add up into a pattern that no single message shows.Someone in your legal team pastes a contract…
-
QA: Ransomware is now a ‘fully fledged industry’, says cybercrime journalist Geoff White
Cybercrime no longer divides neatly between lone hackers, organised gangs and state-backed operations. These groups exchange tactics and tools, while stolen data gives them an asset that can be sold, used for fraud, held to ransom or weaponised for political damage. Geoff White is an award-winning investigative journalist whose reporting has taken him inside global…
-
Blumira Unveils AI Command Center for Cybersecurity Tools
Blumira today unfurled a command center that makes it simpler to integrate cybersecurity tools based on artificial intelligence (AI) that were developed by different vendors. Mike Toole, head of security and IT for Blumira, said Hearth makes it possible to integrate cybersecurity tools from different vendors through a common interface. Additionally, cybersecurity teams will find..…
-
A Zoom Screen-Sharing Bug Let Anyone Take Over Other Devices on a Call
Researchers say it took fewer than 20 prompts for a public AI tool to find a flaw (now fixed) allowing anyone on a Zoom call to hijack another participants’ device. First seen on wired.com Jump to article: www.wired.com/story/a-zoom-screen-sharing-bug-let-anyone-take-over-other-devices-on-a-call/
-
Malicious MCP Servers Can Split Instructions to Make AI Coding Agents Exfiltrate Secrets
A malicious tool server connected to an AI coding assistant can quietly walk off with SSH keys, environment secrets, source code, and customer data without ever sending one obviously harmful instruction.The trick can work even after a blunt version of the same theft is refused: split the request into fragments that each look routine, place…
-
OpenAI Launches GPT-5.6-Cyber to Find Zero-Day Vulnerabilities and Develop Exploit Chains
OpenAI has expanded its Daybreak cybersecurity program with the introduction of GPT-5.6-Cyber, a purpose-trained model specifically designed for authorized vulnerability research, exploit validation, and advanced security testing. Built on the foundation of GPT-5.6 Sol, this new model serves as a controlled-access tool for trusted defenders as AI-assisted offensive capabilities continue to evolve. GPT-5.6-Cyber to Find…
-
An AI tool found 84 flaws in 5G network software and 23 of them still have no fix
Researchers at Nanyang Technological University turned a set of AI agents loose on the software that runs 4G and 5G phone networks, and the agents came back with 84 security … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/11/5g-core-network-vulnerabilities-research/
-
Meta Puts Open-Source AI Bet on Muse Glimmer
Local Agentic AI Model Targets Coding, Tool Calling and Multi-Step Tasks. Meta hopes to recapture the momentum it had when it first launched its Llama artificial intelligence model. Now, with a new model and an increased focus on open-source AI, the social media giant is going against the more proprietary approach of its competitors. First…
-
BdThemes plugins supply-chain hack creates rogue WordPress admins
A threat actor compromised the upstream infrastructure of BdThemes, a developer of premium WordPress web-design tools, and modified a remote JSON feed delivered to administrators’ browsers to create rogue admin accounts. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/bdthemes-plugins-supply-chain-hack-creates-rogue-wordpress-admins/
-
Kimsuky Builds Offline AI Stack to Boost Phishing and Automate Malware Development
North Korea’s state hackers are no longer content to type prompts into public chatbots. One of the country’s main espionage groups has begun running artificial intelligence (AI) offline on its own servers, connecting document-search tools to files in its possession, and collecting the software parts needed to build AI into its malware.South Korean security firm…
-
China-linked hackers turning popular cybersecurity tool into ransomware launchpad, Microsoft warns
Tags: china, cybersecurity, exploit, hacker, microsoft, ransomware, software, threat, tool, vulnerabilityA China-linked threat actor is believed to be exploiting a critical vulnerability affecting cybersecurity software from the company N-able. First seen on therecord.media Jump to article: therecord.media/china-hackers-ransomware-microsoft
-
Browser unter Beschuss: Die unterschätzte Angriffsfläche im Unternehmen
Mitarbeiter schätzen die Flexibilität, mit verschiedenen Geräten über den Browser auf alles zuzugreifen von kollaborativen Meeting-Tools bis hin zu Cloud-Dateien. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/browser-unterschaetzte-angriffsflaeche
-
Chainloop: Open-source evidence store and policy engine for the software supply chain
Chainloop is an open source evidence store for the software supply chain. A command line tool runs inside a GitHub Actions, GitLab, Jenkins, or Dagger pipeline, picks up what … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/10/chainloop-open-source-supply-chain-security/
-
Claude Code Child Process Can Read Its Own OAuth Token From macOS Keychain
A macOS Keychain implementation weakness in Anthropic’s Claude Code CLI could allow any process running as the logged-in user including a Claude Code-spawned child process to retrieve the tool’s OAuth credential bundle silently. The issue underscores how trusted AI coding-agent ancestry can mask high-impact credential access and persistence activity on developer endpoints. However, the CLI…
-
The Best Intrusion Detection Prevention (IDS/IPS) Tools, Compared and Priced (2026)
This market runs from $0 to seven figures, and the free options power half the paid ones, so price comparisons here reward honesty. The verdict up front: Snort and Suricata are the best-value detection engines on earth (free, production-grade, industry-embedded), Zeek is the evidence standard, and among commercial platforms Fortinet delivers the strongest inline-prevention […]…
-
Cybersecurity Newsletter Weekly Top 50 Biggest Cybersecurity Stories $70M Bitcoin Heist,Google Passkey Theft, Copilot CEO Fraud,Chrome 151 Claude Exploits More
Welcome to this week’s edition of the GBHackers cybersecurity newsletter, your weekly cybersecurity bulletin covering the 50 most important stories from August 37, 2026. It was a brutal week for trust in the tools we rely on: a Coldcard firmware flaw drained $70 million in Bitcoin, malware learned to steal Google’s synced passkeys, and […]…
-
Webmail CSS Attacks Expose a New Risk for AI-Powered Email Tools
CSS attacks on major webmail services can steal credentials, hijack sessions and manipulate AI tools connected to users’ inboxes. PortSwigger researcher Gareth Heyes demonstrated something that should make every webmail team a little nervous: plain CSS, the styling language that’s supposed to just make text look nice, can be weaponized to steal passwords, hijack sessions, and…
-
Roblox-Cheater werden selbst zu Betrogenen
Cyberkriminelle nutzen die Suche vieler Gamer nach Cheats und Hilfsprogrammen gezielt aus. Nach Erkenntnissen der Bitdefender Labs verbreiten Angreifer manipulierte Roblox-Tools, die Schadsoftware installieren und den vollständigen Zugriff auf infizierte Computer ermöglichen. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/malware-roblox-cheater-betrug
-
New CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens
New research shows content inside an email can escape its message boundary and interfere with the webmail interface.Across attack chains spanning Outlook, Gmail, Fastmail, Proton Mail, Yahoo Mail, and AOL Mail, the techniques can capture passwords, take over third-party accounts, leak tokens, hijack trusted UI actions, and manipulate AI tools that read email.PortSwigger researcher Gareth…
-
Detecting Cobalt Strike beacons with JA3 and JARM fingerprinting
Cobalt Strike remains a common post-compromise tool in intrusion sets because it gives an operator a flexible command-and-control channel, tasking framework, and a way to blend into normal network traffic. For defenders, the challenge is not just spotting malware on an endpoint. It is identifying the beaconing pattern that sits behind the traffic, especially when……
-
AI coding tools vulnerable to malicious GitHub issues
First seen on scworld.com Jump to article: www.scworld.com/brief/ai-coding-tools-vulnerable-to-malicious-github-issues
-
Black Hat 2026: Open-source tool makes red teaming AI agents up to 125x cheaper
First seen on scworld.com Jump to article: www.scworld.com/news/black-hat-2026-open-source-tool-makes-red-teaming-ai-agents-up-to-125x-cheaper
-
AI Generated Code Risks: Why Business Owners Should Never Trust Software That Simply Works
AI can now generate working software in minutes. Ask Claude, GitHub Copilot, ChatGPT, or another AI coding tool to create an API, authentication flow, admin…Read More First seen on securityboulevard.com Jump to article: https://securityboulevard.com/2026/08/ai-generated-code-risks-why-business-owners-should-never-trust-software-that-simply-works/
-
Cogent Launches VR-1 Cyber Reasoning Model for Enterprise Attack Paths
Cogent Security has introduced Cogent VR-1, a frontier reasoning model trained to investigate enterprise environments and prove whether multi-step attack paths are reachable. The model starts with a foothold and an objective, then maps the surrounding environment and connects weaknesses across systems. Cogent said VR-1 can work across cloud infrastructure, identity systems and internal tools,..…
-
Agentic AI for Cyber Defenders: What Security Teams Built at Black Hat USA 2026
Tags: ai, automation, conference, control, credentials, cve, cyber, cybersecurity, data, data-breach, defense, detection, exploit, flaw, group, iam, intelligence, ISO-27001, mitigation, network, nvidia, offense, open-source, RedTeam, risk, skills, soc, technology, threat, tool, usa, vulnerabilityAgentic AI armed attackers first, but it also put real building power in defenders’ hands. Here’s what security practitioners built in two days at Black Hat USA 2026, and how the CyberAgents Exchange keeps that work compounding long after the event. Key takeaways Building defensive cybersecurity tooling no longer requires a developer. Agentic tooling drove…
-
Stress-Testing Your SIEM: Is Your Environment Actually Catching the Bad Guys?
In today’s security landscape, we have more tools than ever (EDR, XDR, SOAR, SIEM) and very little time to learn each one fully. Every tool out there advertises “we use MITRE” and “we are a Gartner top X” and now since 2025 “We have AI!”. All of these are well and good, however they […]…
-
Frontier AI Has a Cybersecurity Expertise Problem
First OpenAI’s model went rogue and broke out of testing containment to hack real systems, then Anthropic, and now Meta AI. Do you see a trend? Here is what it means: Although these frontier AI companies employ some of the world’s brightest engineers, architects, and developers, technical excellence is not the same as deep cybersecurity…
-
Critical Flaws in Claude Code, Gemini CLI, and OpenAI Codex Enable RCE and Supply Chain Attacks
Tags: ai, attack, automation, breach, cyber, flaw, google, openai, rce, remote-code-execution, supply-chain, theft, tool, vulnerabilitySecurity researchers have disclosed a vulnerability affecting AI coding-agent workflows from Anthropic, Google, and OpenAI. Their research highlights how an attacker-controlled issue or zero-privilege input can breach trust boundaries in an agent “harness”, which includes the permissions, tools, sandbox, filesystem, and automation surrounding the model, and result in code execution, secret theft, or workflow compromise.…

