Tag: tool
-
Cybersicherheitsplattform erkennt, bewertet und minimiert KI-Risiken
<> von Bitdefender verschafft Unternehmen und Managed-Service-Providern (MSPs) die Sichtbarkeit über die Nutzung von KI-Tools durch Mitarbeiter und gibt ihnen die Möglichkeit, die damit verbundenen Risiken proaktiv zu minimieren. Die Lösung ist darauf ausgerichtet, eine der am schnellsten wachsenden Angriffsflächen zu schützen und eine sichere Einführung von KI zu ermöglichen, ohne […] First seen on…
-
Datenklau mit KI: Angreifer infiltrieren Webshops und stehlen Kreditkartendaten
Mithilfe von KI-Tools sind Angreifer an mindestens 600.000 gültige Kreditkartendaten aus mehreren Webshops gelangt. Die Angriffe dauern an. First seen on golem.de Jump to article: www.golem.de/news/datenklau-mit-ki-angreifer-infiltrieren-webshops-und-stehlen-kreditkartendaten-2609-213393.html
-
Malicious npm Package Poses as Twilio Bug-Bounty Probe, Can Exfiltrate Credentials
Cybersecurity researchers have disclosed details of a malicious npm package named “tw-pkgprobe-7731” that masquerades as a security tool targeting developers integrating Twilio into their applications, while stealthily attempting to harvest sensitive data.The package, named “tw-pkgprobe-7731,” was first uploaded to the npm registry in mid-August 2026 by an npm account named “twdepprobe7731.” First seen on thehackernews.com…
-
Malicious npm Package Poses as Twilio Bug-Bounty Probe, Can Exfiltrate Credentials
Cybersecurity researchers have disclosed details of a malicious npm package named “tw-pkgprobe-7731” that masquerades as a security tool targeting developers integrating Twilio into their applications, while stealthily attempting to harvest sensitive data.The package, named “tw-pkgprobe-7731,” was first uploaded to the npm registry in mid-August 2026 by an npm account named “twdepprobe7731.” First seen on thehackernews.com…
-
Researcher Drops BigDiskBuster Zero-Day PoC That Blocks Microsoft Defender Updates
A zero-day proof-of-concept tool that stops Microsoft Defender from installing platform and signature updates by filling all available disk space was published on GitHub on September 19.The tool, called BigDiskBuster, has no patch, no CVE, and no Microsoft advisory. Its author, Abdelhamid Naceri, is a former Microsoft security researcher whose earlier Defender exploits were used…
-
Two arrested in UK after Microsoft takedown of ‘Eviltokens’ AI-chatbot for cybercriminals
Available on Telegram for a $1,500 initiation fee and a recurring monthly $500 subscription, EvilTokens provided cybercriminals with artificial intelligence tools enabling them to compromise accounts, analyze breached inboxes and find the best methods for monetizing their access through fraud. First seen on therecord.media Jump to article: therecord.media/two-arrested-in-uk-after-microsoft-takedown-eviltokens
-
Salt Security adds native AI detection and response to agentic security platform
Salt Security has expanded its Agentic Security Platform with native AI Detection and Response (AI-DR) capabilities designed to connect attacks targeting large language models with subsequent activity across MCP servers, tools and APIs. The new capabilities provide real-time protection against direct and indirect prompt injection, jailbreak attempts, unsafe model behaviour and other threats that emerge…
-
Red Hat OpenShift Flaw Lets Attackers Poison Disconnected Registries With Malicious Releases
Red Hat disclosed an important OpenShift vulnerability that could let attackers bypass release-image signature checks and introduce malicious payloads into disconnected registries. This issue, tracked as CVE-2026-75939, affects the `openshift/oc-mirror` tool and has a preliminary CVSS v3.1 score of 7.4. Administrators use `oc-mirror` to retrieve release images from upstream sources and then copy them to…
-
A New Tool Found Malware That’s Guided by an AI Hive Mind”, No Humans in Sight
Cisco Talos researchers created a new framework for identifying malware and hacking tools that rely on AI chatbots”, and quickly discovered something unusual. First seen on wired.com Jump to article: www.wired.com/story/a-tool-for-tracking-ai-integrated-malware-uncovered-an-autonomous-command-system/
-
NTU uses AI agents to uncover flaws in mobile networks
Nanyang Technological University’s agentic AI tool checks mobile core network code against 3GPP specifications and has found 84 vulnerabilities, including one that lets an attacker hijack a subscriber’s internet session First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366650777/NTU-uses-AI-agents-to-uncover-flaws-in-mobile-networks
-
A cheap fake base station can still track 5G subscribers
Researchers from the i2CAT Foundation, the University of Murcia, and NEC Laboratories Europe built a low-cost tool called 5G-Shark that lures a target phone onto a fake base … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/22/5g-subscriber-tracking-research/
-
Analyse zu KI-gestützten Cyberangriffen und Modell-Ausbrüchen
Management Summary KI wird zur neuen Angriffsoberfläche: Der aktuelle »AI Threat Landscape Digest« von Check Point Research zeigt, wie Testmodelle aus isolierten Umgebungen ausbrechen, Cyberkriminelle KI-Tools für autonome Angriffsketten nutzen und Unternehmen mit einer rasant wachsenden Patch- und Governance-Komplexität konfrontiert werden. Für Entscheider wird damit klar: KI-Sicherheit ist nicht länger ein Spezialthema der IT, sondern……
-
Schatten-KI bleibt trotz wachsender KI-Reife ein verbreitetes Problem
Management Summary Der AI Governance Benchmark 2026 zeigt: Unternehmen bringen KI zwar zunehmend produktiv in zentrale Prozesse, doch die Steuerungsmechanismen halten mit dieser Dynamik nur bedingt Schritt. Besonders Schatten-KI wird zum Management-Thema, weil nicht freigegebene GenAI-Tools operative Effizienz versprechen, zugleich aber Datenschutz, Sicherheit und Compliance unterlaufen können. Schatten-KI ist kein Randphänomen: In 42 Prozent der……
-
Integrating AI Tools Into Research Teams: Productivity Benefits and Risks
AI tools are finding a place in research workflows, particularly for tasks such as transcription, summarization, and qualitative… First seen on hackread.com Jump to article: hackread.com/integrating-ai-tools-into-research-teams/
-
New Rapuncel Infostealer Abuses Microsoft-Signed Driver to Disable 145 Security Tools
Tags: antivirus, credentials, crypto, cyber, data, detection, endpoint, exploit, intelligence, microsoft, mitigation, threat, tool, windowsA newly identified information-stealing campaign, tracked as Rapuncel, is exploiting a Microsoft-attested kernel driver to terminate up to 145 antivirus (AV) and endpoint detection and response (EDR) processes. This allows attackers to steal browser credentials, cryptocurrency wallet data, chat tokens, and Windows credentials. Researchers from the LastPass Threat Intelligence, Mitigation, and Escalation team, in collaboration…
-
New Rapuncel Infostealer Abuses Microsoft-Signed Driver to Disable 145 Security Tools
Tags: antivirus, credentials, crypto, cyber, data, detection, endpoint, exploit, intelligence, microsoft, mitigation, threat, tool, windowsA newly identified information-stealing campaign, tracked as Rapuncel, is exploiting a Microsoft-attested kernel driver to terminate up to 145 antivirus (AV) and endpoint detection and response (EDR) processes. This allows attackers to steal browser credentials, cryptocurrency wallet data, chat tokens, and Windows credentials. Researchers from the LastPass Threat Intelligence, Mitigation, and Escalation team, in collaboration…
-
Now AI Puts Financial Crime Within Anyone’s Reach
Eliminate Silos to Better Combat AI-Driven Crime, Says Global Payments’ Shola Akeju. Financial crime might be nothing new, but artificial intelligence is making it faster to execute and harder to detect by putting sophisticated tools within reach of almost anyone, said Shola Akeju, director of global financial crime program implementation at Global Payments First seen…
-
DARPA Seeks AI Tools to Transform Battlefield Medical Care
Competitions Focus on Surgical Robotics, Clinical Decision Support, Documentation. Traumatic injuries in combat environments can turn deadly if field surgeons aren’t near, or if medical care documentation for split-second clinical decisions goes unrecorded. DARPA is launching two competitions to harness AI, robotics and automation to tackle critical gaps in trauma care. First seen on govinfosecurity.com…
-
Transparent Tribe Deploys New Rust Backdoor Using Private GitHub Repositories for C2
The Pakistan-aligned threat group tracked as Transparent Tribe (aka APT36 and Earth Karkaddan) has been attributed to a fresh set of cyber attacks targeting government and defense entities in India and Afghanistan.The attacks, per Zscaler ThreatLabz, involve the use of previously undocumented tools called RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCH. The activity has been codenamed Operation…
-
Warum wir die Return-Taste für KI-Agenten brauchen
Die Innovationsgeschwindigkeit künstlicher Intelligenz ist zwar weitläufig bekannt, doch das macht sie nicht weniger bemerkenswert. So manch beliebtes KI-Tool aus dem letzten Jahr wirkt im Vergleich zu den heute verwendeten geradezu prähistorisch. Gleichzeitig entwickeln sich auch die KI-Risiken weiter und die beschränken sich nicht mehr nur auf die Modelle, sondern auf die gesamte Datengrundlage. Damit…
-
Four AI Agent Security Risks Organisations Can’t Afford to Ignore
AI agents are quickly moving from experimentation into everyday business operations. Unlike traditional generative AI tools that wait for a user to ask a question, agents can take action: accessing systems, processing information, communicating with applications and completing tasks with varying degrees of autonomy. That ability creates enormous opportunities for productivity. It also changes the…
-
12 Best SSPM Tools Compared (2026): Features Pricing
Quick Answer: SSPM bills two ways per employee (predictable, punishes big headcount) or per connected app (bounded, punishes SaaS sprawl) and your estate’s shape decides which is cheaper. AppOmni and Obsidian quote enterprise depth; CrowdStrike (Adaptive Shield) turned the pioneer into a Falcon module; Nudge, Wing, and Grip run discovery-led free/low tiers that reset entry…
-
Hardcoded MCP credentials found in public GitHub files
Hardcoded API keys, access tokens and other credentials used by AI coding tools have been found in publicly accessible MCP configuration files on GitHub, according to research … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/18/hush-security-mcp-credential-exposure-report/
-
How Pentest Companies Adapt In The Era of AI
Every penetration testing firm is facing the same pressure right now. AI tools are faster, cheaper, andincreasingly capable, and testers are using them whether the company has a policy on it or not. There’s ahigh change AI has already entered your workflow the question is whether it has entered on your terms oryour employee’s personal…
-
ThreatsDay: Self-Rewriting Agents, 800+ Flaws Patched, Insider SIM Swaps and 22 More New Stories
Attackers keep finding new keys. The funny part is that defenders keep inventing where to store them.This week, those keys sit in AI tools, exposed services, old bugs, weak logins, and software sold like a monthly subscription. Some attacks use new tricks. Others just reuse what was already lying around. Both work often enough.So the…
-
Microsoft showcases AI-powered cyber defence tools at GISEC
The company highlights new security capabilities as businesses across the UAE look to secure growing artificial intelligence deployments First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366650430/Microsoft-showcases-AI-powered-cyber-defence-tools-at-GISEC
-
Download: The IT leader’s guide to AI code sprawl
AI hasn’t just made building faster, it’s made everyone a builder. Across every department, employees are shipping apps, agents and automations using AI tools, … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/17/tines-ai-code-sprawl-guide/
-
Google’s new agent security system detects tool misuse, loops and rogue behavior
Google’s Agent Anomaly Detection is a reasoning-based oversight and audit layer for autonomous agents deployed on Agent Runtime in the Gemini Enterprise Agent Platform and … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/17/google-agent-anomaly-detection-audit-layer/
-
12 Best DSPM Tools Compared (2026): Features Pricing
Quick Answer: DSPM has the scariest pricing curve in security bills track data volume, and data only grows. Microsoft Purview publishes pay-as-you-go rates (the anchor); Cyera leads the independents; BigID and Varonis bring privacy and on-prem lineage; CrowdStrike (Flow) and Tenable (Eureka-lineage) mark the consolidation wave. Negotiate volume caps before your data does the negotiating.…
-
12 Best DSPM Tools Compared (2026): Features Pricing
Quick Answer: DSPM has the scariest pricing curve in security bills track data volume, and data only grows. Microsoft Purview publishes pay-as-you-go rates (the anchor); Cyera leads the independents; BigID and Varonis bring privacy and on-prem lineage; CrowdStrike (Flow) and Tenable (Eureka-lineage) mark the consolidation wave. Negotiate volume caps before your data does the negotiating.…

