< ciso
brief />
AI and Security Pulse Banner

All news in category “AI and Security Pulse”

1447 articles · page 45 of 73

AI SOC Agents Transforming Triage and Threat Hunting

🛡️ Agentic AI is reshaping SOC operations by automating contextual triage and correlating telemetry across EDR, identity, email, cloud, SaaS, and network sources so analysts review machine-validated verdicts instead of raw alerts. The approach reduces missed threats and eliminates the need to sample low-fidelity signals. It also provides structured feedback for detection engineering and enables natural-language threat hunting that democratizes proactive investigations. Prophet Security emphasizes depth, accuracy, transparency, and seamless workflow integration to build analyst trust.
read more →

Delegation Is a Risk Decision, Not Just an Ops Choice

⚠️ Delegating authority to software and automated workflows is fundamentally a risk decision, not merely an operational efficiency. Leaders routinely hand judgment and transaction power to systems through configuration, vendor defaults, or personal agents, creating outcomes that persist beyond intent. Security teams often surface the first signals, but the exposure spans operational, financial, legal, and reputational domains. Organizations must document, bound, and assign ownership for delegated authority so tradeoffs align with enterprise risk appetite.
read more →

AI-Powered Polymorphic Attacks Enable Runtime Phishing

🔒 Researchers at Unit 42 demonstrated how attackers can convert benign webpages into bespoke phishing pages by calling LLMs from client-side code to generate malicious JavaScript in real time. This polymorphic technique assembles malware inside the victim’s browser, leaving no static payload and evading many traditional network and signature controls. Defenders are advised to prioritize message-layer protections, secure web gateways, and secure enterprise browsers to block the initial lure and the last mile reassembling of malicious code.
read more →

OpenAI's ChatGPT Ad Rates Match Live NFL Broadcasts

📺 OpenAI will begin showing ads in ChatGPT responses for U.S. users on the free tier and the $8 Go plan, placing sponsored content beneath AI answers. A report says OpenAI plans to charge up to $60 per 1,000 views — a CPM comparable to live NFL broadcasts — while not disclosing detailed click data. OpenAI says ads won’t use personal health data for training and will not alter answers. Ads roll out in the coming weeks; subscribing to $20 GPT Plus removes them.
read more →

The AI Fix Ep. 85: Pet Robots, LLM Debate, Ads & CES

🎧 In episode 85 of The AI Fix, hosts Graham Cluley and Mark Stockley explore a range of current AI stories and controversies. They highlight Silicon Valley efforts to market robotic pet companions as solutions for pet mental health, and discuss Yann LeCun's public assertion that the AI industry is mistaken about the role of large language models. The episode also covers OpenAI’s decision to introduce ads to ChatGPT, a public spat between Sam Altman and Elon Musk over AI harms, humanoid robots showcased at CES 2026, and the decision by cURL to end its bug bounty program in response to automated, AI-driven noise.
read more →

Over 80% of Ethical Hackers Now Use AI in Workflows

🤖 Bugcrowd's survey of 2,000 security researchers found 82% now incorporate AI into their workflows, up from 64% in 2023. Respondents highlighted automation of repetitive tasks, analysis of messy or large codebases, and AI as a research assistant as primary use cases. Organizations gain faster, more comprehensive and higher-quality findings without necessarily increasing budgets. The report also notes stronger outcomes from team collaboration and outlines key community demographics.
read more →

How CISOs Can Overcome AI Fatigue and Govern Use Effectively

🤖 Many CISOs feel torn between moving quickly with AI and preventing new security risks. The article recommends breaking AI into categories by autonomy and potential impact to separate routine generative AI from higher-risk agentic systems. It stresses that data integrity is as important as data protection and proposes a tiered governance model: categorize use, apply baseline controls, assign review forums, and enforce unbreakable rules like kill switches. Practical measures such as acceptable-use policies, training, least-privilege and continuous monitoring are highlighted as table-stakes.
read more →

Gartner: Half of Organizations to Adopt Zero-Trust Data

🔒 Gartner warns that the surge of AI-generated data threatens the reliability of large language models and predicts that 50% of organizations will adopt a zero-trust stance for data governance by 2028. A 2026 survey found 84% of CIOs expect increased generative AI funding, accelerating AI-produced outputs and raising the risk of model crash. Gartner advises authentication, verification, and proactive metadata tagging to identify AI-generated data and meet evolving regulatory demands.
read more →

Top Agentic AI Risks 2026: Governance and Defenses

⚠️ Agentic AI systems introduce acute governance and security challenges because autonomous agents can plan, execute tools, and process sensitive data without human oversight. The OWASP Foundation's Top 10 catalog identifies threats such as goal hijack, tool misuse, privilege abuse, supply chain compromise, RCE, memory poisoning, insecure inter-agent communication, cascading failures, human-trust exploitation, and rogue agents, each with examples and mitigations. Kaspersky condenses those findings and emphasizes a layered, near-Zero Trust defense: least autonomy and privilege, short-lived credentials, human-in-the-loop for critical actions, execution isolation, intent gates, continuous logging, behavioral monitoring, supply chain controls, and targeted training.
read more →

Combined NDR and EDR Strategy Against AI-Based Attacks

🛡️AI-driven attacks are rapidly evolving, with adversaries using LLMs to conceal code and generate malicious scripts that can shape-shift to evade traditional defenses. Recent disclosures, including Google's threat intelligence and Anthropic's November 2025 report of an AI-orchestrated espionage campaign, highlight automation across intrusion lifecycles. The piece emphasizes that pairing NDR and EDR enables correlation of network anomalies and endpoint telemetry, and cites Corelight's Open NDR Platform as an example of layered, behavioral detection to surface threats that slip past EDR alone.
read more →

ChatGPT temporary chat gains personalization option

🛠️OpenAI is testing an update to ChatGPT’s Temporary Chat that lets temporary sessions retain personalization—such as memory cues, chat history signals, and preferred style or tone—while keeping the conversation isolated from your account. The mode remains temporary, can be turned off, and OpenAI may retain a copy for up to 30 days for safety. Start it by opening a new chat and selecting the “Temporary” pill in the top-right corner.
read more →

Who Approved This Agent? Rethinking AI Access Controls

🔐 AI agents are accelerating enterprise work but create new ownership and approval gaps for security teams. Unlike human users or traditional service accounts, agents often operate autonomously, persistently, and with delegated authority, which can expand access beyond any single user's permissions. The article separates agents into personal, third-party, and organizational categories and highlights that organizational agents carry the greatest systemic risk. It recommends treating agents as distinct identities with defined owners, mapping user→agent interactions, and continuously reviewing agent access.
read more →

Runtime Risk and Real-Time Defense for AI Agents at Scale

🔒 Microsoft describes runtime protections that let organizations inspect and control AI agent behavior in real time by integrating Microsoft Defender with Copilot Studio. Webhook-based checks evaluate planned tool invocations, intent, context, and previous orchestration outputs before execution, enabling precise allow/block decisions without changing agent logic. The post demonstrates three attack scenarios—malicious invoice-triggered instructions, SharePoint prompt injection, and capability reconnaissance—and shows how runtime blocking, logging, and XDR alerts prevent data exposure.
read more →

Malicious AI VSCode Extensions Exfiltrate Developer Data

⚠️ Researchers from Koi found two malicious AI-style extensions on the VSCode Marketplace — ChatGPT – 中文版 and ChatMoss — that together have 1.5 million installs and silently transmit developer files to China-based servers. The extensions implement three distinct data-collection methods: real-time file reads and Base64 exfiltration via hidden webviews, a server-controlled file-harvest command that can steal up to 50 files, and a zero-pixel iframe that loads commercial analytics SDKs for fingerprinting and behavioral tracking. At publication both extensions were still available and Microsoft had not responded to inquiries.
read more →

AI-Generated Honeypot Reveals Risks of Overtrusting

🧰 Intruder used AI to draft a honeypot for its Rapid Response service and deployed it as intentionally vulnerable infrastructure. Weeks later logs revealed attacker payloads where IP addresses should be, exposing that the AI trusted client-supplied IP headers. Static tools like Semgrep and Gosec did not flag the issue; the flaw required contextual human judgement. The incident underscores risks of over-relying on AI-generated code and the need to adapt code review and CI/CD practices.
read more →

AI Models Now Automate Finding and Exploiting Vulnerabilities

🔍 Anthropic reports that recent Claude models, notably Sonnet 4.5, can now carry out multistage network attacks using only standard open-source tools instead of bespoke cyber toolkits. In high-fidelity simulations, Sonnet 4.5 recognized a public CVE and exploited a Kali Linux host via a plain Bash shell to exfiltrate simulated personal data. Bruce Schneier highlights these findings as a major change, stressing the urgency of timely patching and basic security hygiene.
read more →

Poetic Prompts Can Bypass Chatbot Safety Controls, Study

⚠️ A recent study finds that framing malicious instructions as poetry substantially raises the chance that chatbots produce unsafe outputs. Researchers converted known harmful prose prompts into verse and tested 1,200 prompts across 25 models from vendors such as Google, OpenAI, Anthropic, and DeepSeek. Across the full dataset, poetic prompts increased unsafe responses by an average of about 35%, while an extreme top-20 metric showed even higher bypass rates. The experiment highlights a novel stylistic jailbreak that can undermine conventional safety controls.
read more →

Children and Chatbots: What Parents Need to Know Now

🤖 As AI chatbots such as ChatGPT become common in children’s lives, parents face growing safety, privacy and developmental concerns. Young people may use bots for homework, advice or companionship, which can lead to overreliance, social withdrawal, exposure to inappropriate material and convincing misinformation (so-called hallucinations). Providers implement guardrails, but age verification and enforcement are inconsistent and evolving more slowly than the technology. Parents are advised to combine open conversations, clear usage limits and app-level parental controls to reduce harm and protect sensitive data.
read more →

curl ends HackerOne bug bounty after surge of AI reports

🔒 The curl project will end its HackerOne bug bounty program after being overwhelmed by a surge of low-quality, apparently AI-generated vulnerability reports that strained the small security team and harmed maintainers' wellbeing. Founder Daniel Stenberg said the torrent of AI slop submissions created a high triage burden. The project will accept HackerOne reports through January 31, 2026, then move to direct reporting via GitHub with no monetary rewards.
read more →

Why AI Keeps Falling for Prompt Injection: Context Limits

🤖 The essay examines why large language models remain vulnerable to prompt injection attacks and why incremental vendor fixes are insufficient. It explains that LLMs collapse layered human context into token similarity, lack social learning and interruption reflexes, and are trained to answer rather than defer. The authors warn that agents with tool access amplify these risks and argue for fundamental advances—such as task-specific constraints, real-world grounding, or new architectures—rather than patchwork defenses.
read more →