< ciso
brief />
Tag Banner

All news with #ai security tag

903 articles · page 12 of 46

Adapting Security to the Frontier AI Era

🛡️ Frontier AI is accelerating cyber threats and outpacing traditional governance across JAPAC, forcing regulators and enterprises to shift from committee-based oversight to real-time defensive postures. Urgent regulatory action in Australia, Singapore, and South Korea has prompted organisations to modernise identity, access, and incident response frameworks. Real-time AI vs AI engagements now dominate the threat landscape.
read more →

Security shifts to the human layer as AI scams surge

🛡️ Microsoft and Google warn that cybercriminals are repurposing familiar social-engineering tactics around AI tools and trusted cloud services, impersonating platforms like ChatGPT, Copilot, and Claude to distribute malware, steal credentials, and run investment scams. Both advisories note attackers rely on longstanding techniques—urgency, trusted-brand abuse, and redirection chains—while adapting lures to where AI is embedded in daily workflows. The trend shifts the threat surface from code to employee behavior, demanding resilience beyond blocking single phishing campaigns.
read more →

AI-powered worm highlights urgent enterprise risk

🛡️ Researchers at the University of Toronto built an AI-driven worm prototype that autonomously discovered and exploited vulnerabilities across a simulated enterprise network. Using a locally hosted, free LLM and a custom agentic harness, the worm self-replicated to multiple systems by chaining old and recent CVEs and common misconfigurations. Over several days it spread to most targets, demonstrating that attackers do not need cutting-edge models to mount damaging, adaptive attacks. The findings underscore the need for faster patching, AI-assisted defensive testing, and improved architecture such as segmentation and zero trust.
read more →

Defending Applications Against Frontier Model Threats

🔒 Cloudflare describes an architectural approach to defend applications and internal systems from high-speed attacks enabled by frontier AI models. The post explains how layered controls — including WAF, ML-based scoring, API Shield, Bot Management, Zero Trust, IdP federation, MCP server controls, and AI Gateway — work together to reduce discovery, limit exploit adaptation, and contain impact. It emphasizes deploying inspection ahead of public apps, defining valid API traffic, restricting automated probing, and enforcing per-request identity for internal tools.
read more →

OpenAI Lockdown Mode: Limits, Risks, and Governance

🔒 OpenAI’s Lockdown Mode aims to reduce AI-enabled data exfiltration by disabling web browsing, image support, Deep Research, Agent Mode, network access from generated code, and file downloads while still permitting manually uploaded file analysis. Experts say the feature is a pragmatic but imperfect mitigation that still allows side-channel exfiltration, complicates governance across multiple AI vendors, and shifts responsibility between providers and enterprise security teams.
read more →

Apple adds AI to automatically fix compromised passwords

🔒 Apple announced at WWDC 2026 an Apple Intelligence-powered capability that can automatically detect and update weak, duplicate, or compromised passwords in Safari and the built-in Passwords app. The feature, arriving with iOS 27, uses on-device and Private Cloud Compute foundation models co-developed with Google to perform agentic actions that update eligible accounts to strong credentials. Apple emphasizes privacy-first design, saying personal data handled in the cloud is not stored or accessible to Apple.
read more →

AWS May 2026 Security Digest and Updates

🛡️ This monthly AWS Security Blog digest highlights May 2026 posts on AI security, network protection, identity management, compliance guides, and supply chain defense. It summarizes new capabilities, hands-on samples, and workshops that demonstrate practical controls — from Cedar-based policy for agentic AI to URL category filtering in Network Firewall and post-quantum readiness checks.
read more →

AWS adds AI cost-investigation with Amazon Q

🧭 AWS Cost Anomaly Detection now includes AI-powered cost investigation using Amazon Q to analyze root causes of detected cost anomalies. The feature delivers plain-language explanations in minutes by correlating cost data with CloudTrail events and resource activity, identifying whether changes are usage- or rate-driven and pinpointing contributing services, accounts, regions, API calls, and IAM principals. Cross-account investigations work automatically for organizations with an organization CloudTrail trail, and the capability is available in all commercial AWS Regions at no extra charge, though CloudWatch Logs Insights charges may apply for data scanned.
read more →

Fortinet Q1 2026 Results and Strategic Momentum

📈 Fortinet reported a strong Q1 2026 driven by broad-based demand across Secure Networking, Unified SASE, and AI-Driven Security Operations. Leadership highlighted 31% billings growth, 20% total revenue growth, record non-GAAP operating margin, and $1.01B free cash flow, attributing performance to platform integration, FortiASIC technology, and FortiOS innovation. Executives noted large AI, OT, and distributed infrastructure wins and raised full-year guidance.
read more →

Anthropic’s Project Glasswing: Status and Concerns

📰 Anthropic launched Project Glasswing in April to let companies use its Mythos model to discover and remediate software vulnerabilities. The project produced a status report claiming many findings, including some dangerous issues, yet most reported vulnerabilities appear unpatched. Anthropic’s reluctance to release detailed data and methodology — instead asking the public to "trust us" — raises questions about the accuracy and interpretation of the results.
read more →

15 Tough Cybersecurity Questions Every CISO Must Answer

🔍 Security leaders outline 15 critical questions CISOs should ask to ensure security programs adapt to evolving threats and business needs. These prompts focus on demonstrating ROI, aligning defenses with critical business processes, measuring detection and response speed, and addressing AI-driven risks like nonhuman identities and automated attacks. The guidance also stresses vendor risk, shadow AI, application security for widespread coding, and preparing security for future business growth.
read more →

OpenAI introduces Lockdown Mode to limit ChatGPT tools

🔒 OpenAI has started rolling out a new Lockdown Mode for eligible ChatGPT personal accounts to reduce the risk of data exfiltration from prompt injection attacks. The optional security setting restricts capabilities that can connect to the web or external services, including live web browsing, image support, agent mode, deep research, Canvas networking, and file downloads. Lockdown Mode is available across Free, Go, Plus, Pro, and self-serve ChatGPT Business plans but cannot be used simultaneously with Developer Mode. OpenAI warns the feature reduces but does not eliminate exfiltration risk and also launched enhanced account session management to help detect and terminate unauthorized access.
read more →

Prototype AI-Powered Worm Raises New Security Risks

🔒 Researchers have demonstrated a prototype AI-powered internet worm that autonomously propagates and carries its own local LLM to run on compromised machines. The prototype echoes early theoretical concepts of self-replicating code and shows how generative models can be embedded into malware to extend functionality. This proof-of-concept highlights evolving threats and the need for updated defensive strategies and policy responses.
read more →

Healthcare must shift from reactive to AI-driven security

🔍 Experts at Infosecurity Europe warned that healthcare organizations must adopt AI-powered security to detect and contain threats faster. Legacy devices, hyper-connectivity and alert fatigue are creating a high-risk environment where ransomware and other attacks can endanger patient safety. Speakers urged proactive measures including full device visibility, clinical-risk-based prioritization, AI-driven signal correlation and segmentation to reduce exposure.
read more →

Cisco Live report: AI, networking, and wellbeing

🐶 At Cisco Live U.S. in Las Vegas, the author describes the conference pace, the value of quiet spaces and noise-canceling gear, and the welcome presence of therapy dogs sponsored by Splunk. Discussions at the event centered on AI from an infrastructure and security lens, including the daunting scale of data and associated defense challenges. Cisco Talos highlights expansion of its Threat Hunting program using AI-driven telemetry plus expert validation to find advanced intrusions like a recent KongTuke C2 discovery.
read more →

Microsoft warns on AI-enabled malware risks

🔒 Microsoft’s Detection and Response Team (DART) warns that AI adoption has introduced new attack surfaces, with threat actors weaponizing AI tools in social engineering and supply chains. A highlighted campaign, ‘JustAskJacky’, disguised a malicious AI assistant that installed a Java backdoor and persistence tasks. Experts urge organisations to assess nonstandard AI apps, enforce security reviews, and make AI risk a board-level priority.
read more →

Security teams warned: prepare for 'son of Mythos'

🛡️ Security experts at Infosecurity Europe warned that expanding access to frontier AI tools for vulnerability discovery — notably Anthropic’s Project Glasswing and OpenAI’s reported GPT-5.5 Cyber pilot — heralds a structural shift in cybersecurity. Speakers advised organisations to harden controls, run incident response exercises, and accelerate adoption to avoid falling behind attackers. The panel stressed that AI augments, not replaces, human expertise; combined use improves validation and remediation of AI-discovered issues.
read more →

Konvu wins Infosecurity Europe Cyber Startup award

🏆 Konvu, an AI-native vulnerability triage platform, won the inaugural Infosecurity Europe Cyber Startup competition live on stage at Infosecurity Europe 2026. The startup beat four rivals and receives an exhibition stand at Infosecurity Europe 2027, PR support from Origin Communications and a branding workshop from Dusted. CEO Lucas Masson highlighted Konvu's agent-driven checks and evidence-backed exploitability decisions that integrate into existing workflows.
read more →

AI Applied to Decrypt Medieval Ciphers

🧭 The post considers how historical plaintext-hiding techniques, traditionally done by hand, created patterns such as short key phrases that made ciphers vulnerable to statistical analysis. It argues that modern AI and LLMs, being fundamentally statistical models with some randomness, can exploit ciphertext statistics to reconstruct plaintext. The author notes this capability does not automatically make decryption trivial, but highlights the potential for AI to invert statistical patterns in encrypted text.
read more →

AI-driven urgency reshapes enterprise cybersecurity budgets

🔒 The rapid rise of frontier and agentic AI is creating board-level urgency that may finally unlock sustained cybersecurity funding. Industry leaders at recent conferences noted that autonomous AI systems expose operational risk, widen attack surfaces, and outpace traditional security architectures. CISOs are reframing cybersecurity as an operational enabler for safe AI adoption, pushing for investments in visibility, identity, monitoring, and AI-specific controls. Vendors and experts caution that budget requests need clear business cases tied to measurable outcomes.
read more →