< ciso
brief />
Tag Banner

All news with #ai security tag

1043 articles

Configuring an AI vulnerability harness steering file

πŸ”’ This post explains how a steering file configures an AI model to perform structured, evidence-based vulnerability triage with the consistency of an experienced analyst. It outlines five configuration sections that enforce structural verification, evidence-based scoring, infrastructure-aware prioritization, and threat-intel boosts. The steering file encodes team methodology so the model applies it uniformly across analyses and reduces hallucinations and false positives.
read more β†’

Three-Layer AI Vulnerability Harness for Scanners

πŸ” This post explains a three-layer pipeline that filters raw scanner findings into a prioritized, evidence-backed set of vulnerabilities for engineers to act on. It emphasizes a tool-agnostic architecture combining multi-scanner agreement, AST-based structural verification, and deployment-context checks (IaC) to reduce noise and increase confidence. The article describes context scoping for AI reasoning and notes a companion post that covers the steering file controlling model behavior.
read more β†’

Tokenomics Risks for AI-Driven Security Teams

πŸ”’ Security teams implementing AI automation face new threats from token-based attacks that can exhaust budgets or trigger provider filters, disrupting incident response. Elastic’s cost estimates show large variability in agent-based SOC expenses, and prompt injection can dramatically inflate token consumption and latency. Practical defenses include deterministic handling of verifiable data, strict limits and alerts, predefined failover behaviors, careful permissioning, scanning untrusted inputs, and using local models to reduce vendor-induced outages.
read more β†’

Phishing Campaigns Hide AI Prompts to Manipulate Systems

πŸ“§ Researchers at Barracuda found phishing emails embedding hidden prompt injections alongside traditional lures, targeting both human recipients and AI assistants that summarize inboxes. The samples mimicked legitimate internal correspondence and used techniques like HTML comments, invisible CSS text, Base64 encoding and zero-width characters to conceal instructions. These hidden prompts could override assistant behavior to fake urgency, request wire transfers, or leak data, bypassing reputation and signature-based defenses.
read more β†’

Musician sentenced for $10M AI-driven streaming fraud

🎡 A North Carolina musician was sentenced to 18 months in prison after admitting to a scheme that generated over $10 million in royalties by using AI-generated tracks and automated bots to inflate streams on major platforms. With accomplices, he uploaded hundreds of thousands of synthetic songs and routed bot traffic through VPNs to avoid detection, producing billions of streams between 2017 and 2024. He was also ordered to forfeit more than $8 million and serve two years of supervised release.
read more β†’

Preparing Defenses for Agentic AI Cyber Threats

πŸ”’ This post examines how autonomous AI agents have begun executing cyber attacks and why the defensive posture must evolve. It contrasts noisy, volume-driven attacks with true stealthy red team operations and argues defenders should focus on increasing attacker cost. The article recommends thorough, pervasive security fundamentals to raise the time, compute, and monetary expense required for successful campaigns.
read more β†’

AI Forces Continuous Offensive Security Practices

πŸ” As AI-enabled attacks scale and accelerate, CISOs face a surge in exploitable vulnerabilities and must rethink vulnerability management. Experts argue that annual compliance pen tests are no longer sufficient; organizations need continuous, automated offensive securityβ€”pen testing, red teaming, and attack path validationβ€”to prove exploitability in production. Human expertise remains critical to guide AI tools and develop future offensive security talent.
read more β†’

Hackers exploit 32 zero-days at Pwn2Own Ireland

πŸ”’ On day one of Pwn2Own Ireland 2026, researchers exploited 32 zero-days and earned $388,500 after successfully hacking the Samsung Galaxy S26 twice. The contest targeted seven categories including mobile phones, printers, smart home devices, messaging apps, AI infrastructure, AI coding apps, and wellness healthcare devices. Several teams demonstrated exploits against LiteLLM, Lexmark and Canon printers, Sonos speakers, and OpenAI's Codex, while some reported bugs were already known to vendors. Vendors have 90 days to patch flaws before Trend Micro's ZDI publicly discloses details.
read more β†’

Identity-aware AI data agents with AWS Lake Formation

πŸ”’ This post describes a deployable pattern for propagating user identity through AI data agents built on Amazon Bedrock AgentCore so that AWS Lake Formation evaluates per-user grants. It explains the HTTP header-based token transport (access_token in Authorization and id_token in a custom header) and the three AgentCore features that keep the token out of the model context. The flow ends with a Lambda exchange that assumes a TIP role, runs Athena under the user’s identity, and preserves CloudTrail auditability without changing existing Lake Formation policies.
read more β†’

CISO Views: Managing Vulnerability Risks in AI Age

πŸ” This article outlines how frontier AI is changing vulnerability management by producing vastly greater volumes of findings and shifting the CISO challenge from speed to scale and accuracy. It describes Microsoft’s use of AI-powered scanning, harness layers like MDASH, and Red Teaming to find and mitigate flaws, while urging defense-in-depth and Secure by Default controls such as Microsoft Baseline Security Mode (BSM). The post emphasizes coordinated open-source scanning, risk-based decision making, and rolling out secure defaults to reduce exploitation risk.
read more β†’

PromptGuardX: Extending AI Security into Files

πŸ›‘οΈ PromptGuardX inspects PDFs before their content reaches an LLM or AI agent, detecting hidden instructions and obfuscation techniques that can enable prompt injection. Integrated into Check Point Threat Emulation, it extracts and normalizes text, locates suspicious instruction regions, analyzes context with fine-tuned classifiers, and returns explainable verdicts and confidence scores. This upstream file-layer protection complements runtime monitoring, access controls and prompt inspection.
read more β†’

Red Hat's Lightwell Remediates 400+ Java Vulnerabilities

πŸ”’ Red Hat's open-source security initiative Lightwell has remediated over 400 novel vulnerabilities across core Java libraries since launching in June. The company announced the general availability of the Lightwell Clearinghouse after a pilot phase, aiming to validate AI-generated reports and reduce noise for maintainers. Backed by IBM and supported by major financial institutions, Lightwell offers continuous signed binaries, SBOMs and a premium clearinghouse for targeted backports to production systems.
read more β†’

Google pause spotlights AI-driven triage challenge

πŸ” Google paused certain bug bounty submissions after a surge of largely automated, low-quality reports stretched its validation capacity. The company had already tightened rules and raised evidence requirements to reduce false positives, but high volumes of AI-generated findings continue to challenge triage workflows. Experts warn that unchecked report floods can waste engineering time and that organizations should treat triage as a security capability, requiring reproducible evidence and reachability checks. AI can discover real vulnerabilities but also produces plausible, costly false leads that must be filtered before remediation.
read more β†’

AI-driven surge in n-day exploits outpaces zero-day

πŸ” Google’s Threat Intelligence Group reports attackers are increasingly weaponizing disclosed flaws, with AI accelerating exploit development. GTIG recorded 141 exploited CVEs between January and August 2026 versus 127 in all of 2025, while monthly disclosures doubled. High-risk exploits and time-to-exploit have risen, and perimeter appliances remain prime targets. Organizations must adopt threat-driven triage and automated remediation to manage the growing volume.
read more β†’

AWS Continuum Raises Bar for Autonomous Code Security

πŸ”’ AWS reports that Continuum for code vulnerabilities achieved an 89.0% end-to-end pass rate on the CyberGym-E2E benchmark, passing 819 of 920 tasks within a 90-minute limit. The multi-agent system improved on prior public results across all measured stages (discovery, validation, remediation) and reached 93.7% when allowed to run longer. The evaluation was conducted under network-isolation and submission-review rules to ensure results came from analysis rather than retrieval.
read more β†’

AI Drives Breakthroughs Against Historic Ciphers

πŸ” This post argues that AI language models and their DSP-like architectures are now good enough to break many older codes and ciphers by exploiting persistent statistical features. It explains how adaptive filters in current DNNs can lift plaintext signals from noisy ciphertext when keytexts are periodic or short, a common human failing in historical systems. The author warns that only ciphers without key periodicity or those requiring infeasible workloads can still offer meaningful security.
read more β†’

Google pauses OSS bug bounty amid AI report surge

πŸ”’ Google has temporarily suspended submissions to its Open Source Software Vulnerability Rewards Program (OSS VRP) after a flood of largely invalid AI-generated reports. The pause doesn't affect supply chain reports or previously submitted product vulnerabilities, and researchers can still use the Patch Rewards Program or Cloud VRP. Google plans to rework the OSS VRP to address automated submission issues and will provide an update in Q1 2027.
read more β†’

Google Gemini may gain broad macOS access soon

πŸ›‘οΈ Google is testing a hidden "Additional sandbox options" in the Gemini Desktop app that could let Gemini read, create, modify, or delete files anywhere on a Mac and interact with native apps and the web. The feature is not live and unconfirmed by Google, but the hidden interface warns that enabling it may allow Gemini to act without asking permission for some actions. Sensitive operations like purchases or account creation would still require explicit confirmation.
read more β†’

MI5 warns UK academics aided Chinese MSS research

πŸ›‘οΈ MI5 has warned that over 100 academics linked to U.K. institutions have contributed to research projects funded by the China General Technology Research Institute (CGTRI), which the agency assesses as a front for the Chinese Ministry of State Security (MSS). The alert cautions that CGTRI-backed research in AI, cybersecurity, covert communications, and steganography directly enhances MSS espionage capabilities. U.K. universities are urged to review collaborations and funding sources immediately, with potential prosecution under the National Security Act 2023 for continuing material assistance.
read more β†’

The State of Cybersecurity in 2026: Key Trends

πŸ”Ž This vendor-focused overview summarizes how cloud expansion, AI, distributed systems, and complex digital environments are reshaping security. It highlights shifts toward continuous visibility, least-privilege identity controls, telemetry management, AI-native SOCs, and exposure reduction. The piece profiles vendors addressing identity, telemetry, endpoint, human risk, exposure, email, device, AI, and cloud security.
read more β†’