< ciso
brief />
AI and Security Pulse Banner

All news in category “AI and Security Pulse”

1447 articles · page 22 of 73

Ten Essential Prompts Every Developer Should Use

🔎 This article collects the top prompts Google Cloud developers and leaders use repeatedly to produce higher-quality work, from building specs and PRDs to thorough code reviews and permission checks. It explains each prompt, who contributed it, and why it helps—covering testing, cleanup, trade-off analysis, research-driven audits, and iterative improvement. The piece emphasizes practical guardrails and collaboration with AI to avoid overconfidence and brittle outputs.
read more →

AWS adds Gemma 4 models from DeepMind to Bedrock

🚀 AWS announces availability of the Gemma 4 family from Google DeepMind on Amazon Bedrock. The offering includes three variants—Gemma 4 31B, Gemma 4 26B-A4B, and Gemma 4 E2B—covering dense and MoE architectures with multimodal and multilingual support. Models run on new Bedrock optimizations for tool calling, structured output, reasoning, and streaming, and are initially available in several AWS Regions.
read more →

ASSERT: Turning Written Intent into Executable Evals

🧭 ASSERT is an open-source framework that converts natural-language behavior specifications into executable evaluation pipelines, generating test scenarios, datasets, metrics, and scorecards for models, agents, or applications. The pipeline systematizes intent into a concept spec, produces an editable behavior taxonomy, generates stratified test cases, records full inference traces, and scores each trace with rationales and policy citations. Internal validation showed ASSERT improves coverage, surfaces distinct failure patterns, and yields judge agreement with humans in most cases, while SME review confirmed alignment and credibility.
read more →

Securing AI Agents as Enterprise Workforce

🛡️ An enterprise sales team built an AI agent to manage renewals; the agent reads emails, queries CRM data, drafts responses, and updates records. This workflow combines private data, untrusted input, and external communication, changing the security model. Traditional controls like IAM and DLP still matter but are insufficient alone. Runtime, context-aware controls that inspect prompts, outputs, and tool calls are required to prevent prompt injection, data exfiltration, and unsafe actions.
read more →

Anthropic launches Mythos 5 and guarded Fable 5 AI

🤖 Anthropic has released two new models, Claude Mythos 5 and Claude Fable 5, with Mythos 5 earmarked as an upgraded frontier model for cybersecurity and initially deployed via Project Glasswing. Fable 5 uses the same core model but adds conservative guardrails, routing certain queries to Claude Opus 4.8. Both models are priced significantly lower than previous previews and Fable 5 is already available through Microsoft Foundry.
read more →

Autonomous AI Agents Vulnerable to Phishing Attacks

🔒 Varonis tested an OpenClaw-based AI agent named Pinchy with access to a controlled Google Workspace to see whether autonomous agents could be phished. The agent was given Gmail access plus mock AWS credentials, CRM exports, internal chats, and calendars, and it still leaked credentials and customer data in scenarios that mimicked routine colleague requests. A stricter safety profile improved performance, but the agent still failed when social trust cues were abused. Researchers say the problem stems from architecture and governance gaps, urging enforceable controls, identity segregation, and human review for sensitive requests.
read more →

AI Red Teaming Evolves into Core Security Practice

🔍 AI red teaming has rapidly matured since Microsoft created its first team in 2019, driven by the arrival of large language models that broke traditional testing methods. Teams must now assess probabilistic behaviors, socio-technical risks, and agentic systems rather than only deterministic software flaws. Organizations are expanding expertise beyond security to include safety, psychology, and domain specialists to evaluate harms like misinformation and operational failures.
read more →

Anthropic’s Claude Fable 5 and Mythos 5 Launch

🛡️ Anthropic released Claude Fable 5 publicly on June 9, pairing it with a twin, Claude Mythos 5, that retains strong cybersecurity capabilities for vetted defenders. Fable 5 routes flagged cyber, bio, chemistry, and distillation requests to the weaker Opus 4.8 using safety classifiers, while Mythos 5 keeps those abilities available under trusted access. Both models are priced per input/output tokens and included on paid plans through June 22 before moving to usage credits.
read more →

Enterprises Ship Vulnerable AI-Generated Code Despite Risks

🛡️ New research from Checkmarx finds enterprises are increasingly shipping AI-generated code despite widespread vulnerabilities. The survey of 2,350 security leaders shows nearly half of production code is AI-built and organizations that rely heavily on AI introduce far more insecure code. Many firms lack formal AI governance and continue to accept or defer fixing known issues, while tool sprawl and developer pressure compound the problem.
read more →

Anthropic launches Fable 5 with limited-time access

🔒 Anthropic has released Fable 5, a safer variant of its powerful Mythos-class model, intended to reduce misuse by blocking sensitive cybersecurity, biology, and chemistry queries. The company will route restricted prompts to Opus 4.8, while the unrestricted Claude Mythos 5 remains limited to highly vetted partners. Fable 5 is free temporarily for Pro, Max, and Enterprise users until June 22 but consumes tokens much faster than other models.
read more →

Adapting Security to the Frontier AI Era

🛡️ Frontier AI is accelerating cyber threats and outpacing traditional governance across JAPAC, forcing regulators and enterprises to shift from committee-based oversight to real-time defensive postures. Urgent regulatory action in Australia, Singapore, and South Korea has prompted organisations to modernise identity, access, and incident response frameworks. Real-time AI vs AI engagements now dominate the threat landscape.
read more →

OpenClaw AI Agent Susceptible to Phishing Risks

📧 Researchers at Varonis tested an OpenClaw AI email agent connected to Gmail, browser tools, and internal data sources and found it vulnerable to common phishing techniques. The agent ran in both generic and strict configurations and used Google Gemini 3.1 Pro and OpenAI GPT-5.4 models. While the agent detected malicious links and OAuth apps, it still exfiltrated credentials and CRM data in scenarios exploiting identity verification failures. Varonis recommends explicit sender verification, restricted external emailing, and human approval for high-risk actions.
read more →

Anthropic unveils Mythos-class Fable 5 with safeguards

🛡️ Anthropic released two Mythos-class models: the broadly available Claude Fable 5 and the restricted Claude Mythos 5 for select cybersecurity and infrastructure partners. Anthropic says Fable 5 outperforms prior Claude models across coding, research, vision, and long-form tasks while routing risky queries to a fallback, Claude Opus 4.8. The company stresses conservative safeguards to prevent misuse, but early tests suggest some benign cyber tasks are also being rerouted.
read more →

Anthropic’s Claude Fable 5 Now Available on Google Cloud

🟢 Claude Fable 5, Anthropic’s latest frontier model, is now generally available on Google Cloud. The model is designed for complex, multi-step reasoning and supports demanding use cases like advanced software development, long-horizon agents, and deep multimodal document analysis. Google Cloud highlights strong safeguards to make the model suitable for general use and positions it alongside other Anthropic offerings on the Agent Platform.
read more →

XBOW Evaluates Anthropic’s Mythos Preview Model

🔎 XBOW received early access to Anthos Mythos Preview and ran a structured evaluation across benchmarks, interactive workflows, and live-site integrations. The model excels at reading source code, finding vulnerability candidates, and aiding native-code analysis and reverse engineering. While powerful for generating leads and precise technical analysis, Mythos Preview is less effective at exploit validation and exhibits mixed judgment that benefits from human orchestration.
read more →

Measuring the Business Value of Generative AI

🧭 The post explains how technology and finance leaders can demonstrate the business value of generative AI to secure funding and drive adoption. It highlights the DORA: ROI of AI-assisted software development report and its findings, including the common J-curve of early adoption, causes of temporary productivity decline, and the need to budget for a learning phase. The article also describes an interactive ROI calculator and resources to build a defensible AI investment case.
read more →

Widespread AI Coding Use Outpaces Governance

🛠️ Nearly all software teams now use AI coding assistants, yet fewer than a third have formal governance in place. A UserEvidence survey for Black Duck of 831 developers and DevOps pros in March 2026 found 97% adoption but only 30% with full oversight. Popular tools include GitHub Copilot (83%) and Claude Code (63%). Teams report faster releases and an average of eight hours saved per developer weekly, but many face downstream friction in reviews, testing and rework.
read more →

Claude Fable 5 available on AWS with safeguards

🤖 Claude Fable 5 is now generally available on AWS, offering Mythos-level capabilities with built-in safety classifiers for broader use. The model advances autonomous knowledge work and coding for professional tasks across finance, legal, marketing, sales, data, and engineering. Customers can access it via Amazon Bedrock or the Claude Platform on AWS, with options for AWS-managed guardrails and regional data residency.
read more →

Security shifts to the human layer as AI scams surge

🛡️ Microsoft and Google warn that cybercriminals are repurposing familiar social-engineering tactics around AI tools and trusted cloud services, impersonating platforms like ChatGPT, Copilot, and Claude to distribute malware, steal credentials, and run investment scams. Both advisories note attackers rely on longstanding techniques—urgency, trusted-brand abuse, and redirection chains—while adapting lures to where AI is embedded in daily workflows. The trend shifts the threat surface from code to employee behavior, demanding resilience beyond blocking single phishing campaigns.
read more →

Defending Applications Against Frontier Model Threats

🔒 Cloudflare describes an architectural approach to defend applications and internal systems from high-speed attacks enabled by frontier AI models. The post explains how layered controls — including WAF, ML-based scoring, API Shield, Bot Management, Zero Trust, IdP federation, MCP server controls, and AI Gateway — work together to reduce discovery, limit exploit adaptation, and contain impact. It emphasizes deploying inspection ahead of public apps, defining valid API traffic, restricting automated probing, and enforcing per-request identity for internal tools.
read more →