< ciso
brief />
Tag Banner

All news with #ai security tag

1047 articles · page 20 of 53

Security teams warned: prepare for 'son of Mythos'

🛡️ Security experts at Infosecurity Europe warned that expanding access to frontier AI tools for vulnerability discovery — notably Anthropic’s Project Glasswing and OpenAI’s reported GPT-5.5 Cyber pilot — heralds a structural shift in cybersecurity. Speakers advised organisations to harden controls, run incident response exercises, and accelerate adoption to avoid falling behind attackers. The panel stressed that AI augments, not replaces, human expertise; combined use improves validation and remediation of AI-discovered issues.
read more →

Konvu wins Infosecurity Europe Cyber Startup award

🏆 Konvu, an AI-native vulnerability triage platform, won the inaugural Infosecurity Europe Cyber Startup competition live on stage at Infosecurity Europe 2026. The startup beat four rivals and receives an exhibition stand at Infosecurity Europe 2027, PR support from Origin Communications and a branding workshop from Dusted. CEO Lucas Masson highlighted Konvu's agent-driven checks and evidence-backed exploitability decisions that integrate into existing workflows.
read more →

AI Applied to Decrypt Medieval Ciphers

🧭 The post considers how historical plaintext-hiding techniques, traditionally done by hand, created patterns such as short key phrases that made ciphers vulnerable to statistical analysis. It argues that modern AI and LLMs, being fundamentally statistical models with some randomness, can exploit ciphertext statistics to reconstruct plaintext. The author notes this capability does not automatically make decryption trivial, but highlights the potential for AI to invert statistical patterns in encrypted text.
read more →

AI-driven urgency reshapes enterprise cybersecurity budgets

🔒 The rapid rise of frontier and agentic AI is creating board-level urgency that may finally unlock sustained cybersecurity funding. Industry leaders at recent conferences noted that autonomous AI systems expose operational risk, widen attack surfaces, and outpace traditional security architectures. CISOs are reframing cybersecurity as an operational enabler for safe AI adoption, pushing for investments in visibility, identity, monitoring, and AI-specific controls. Vendors and experts caution that budget requests need clear business cases tied to measurable outcomes.
read more →

AI-Driven Exploitability Forces Faster Patching

🔒 As AI models like GPT5.5 and Claude Mythos accelerate exploit discovery, organisations face shrinking windows to patch vulnerabilities. Industry experts at Infosecurity Europe warn mean time to exploit has fallen from days to hours, prompting regulatory responses such as India’s 12-hour patch expectation. Analysts contrast vendor-centric EU rules with market-driven US approaches and recommend exploit-intelligence led patching, automation, segmentation and stronger producer SLAs.
read more →

The AI Defense Plane: Securing Enterprise AI

🛡️ This article explains why AI requires a unified security architecture — the AI Defense Plane — to discover, protect, govern, and assure AI behavior across employees, applications, and agents. It describes how AI becomes an execution layer that can retrieve data, call tools, and take actions, creating risks that traverse traditional security boundaries. The piece emphasizes runtime protection, coordinated enforcement, and continuous testing to prevent prompt-based attacks, data exposure, and unsafe agent behavior.
read more →

AI-Driven Cybercrime Tools Surge Over 3800%

🔍 Halcyon research reveals a dramatic rise in AI-powered cybercrime tooling across underground markets, jumping from 38 mentions in December to 1,486 in February. Cynthia Kaiser, SVP of Halcyon’s Ransomware Research Center, detailed four product categories: weaponized LLMs, AI-enabled identity fraud, AI-augmented malware/infrastructure, and jailbroken or stolen AI services. She warned that automated distribution, freemium models and redundant channels have lowered the financial barrier to entry and increased resilience against takedown efforts.
read more →

When AI Support Workflows Become an Authorization Risk

🔒 Reporting suggests attackers used Meta’s AI support chatbot to change recovery emails on high-profile Instagram accounts, leading to notable takeovers. The core issue isn’t just prompt injection or a model jailbreak but that the AI operated within a sensitive account recovery workflow with insufficient independent verification. Organizations must treat AI-driven support actions as part of the security boundary and constrain authority, permissions, and verification around such agents.
read more →

Building an Agentic Enterprise System for AI

🧭 Microsoft outlines a shift from isolated AI tools to a unified, enterprise-grade agent platform that runs real work. The post emphasizes a single integrated system spanning Azure, GitHub, Microsoft IQ, Foundry, Agent 365, and Microsoft 365 to build, contextualize, run, govern, and improve agents. It stresses secure-by-design governance, model choice, continuous improvement through feedback and tuning, and production-grade runtimes. The approach centers developers and enterprise context to make agents trustworthy and scalable.
read more →

Foundry IQ: Unified knowledge and serverless retrieval

🔎 Foundry IQ streamlines bringing enterprise and external knowledge into agent workflows by unifying content, improving ingestion, and offering a serverless model for retrieval. The service provides a Model Context Protocol (MCP) server, integrates Microsoft Web IQ for low-latency external context, and includes GA security and compliance features. Serverless Developer tier is in public preview with CU-based billing estimates and scale-to-zero capacity.
read more →

Defenders Must Adopt AI or Risk Failing

🛡️ Joe Slowik warned at Infosecurity Europe that defenders must adopt AI to keep pace with adversaries. He argued that purely human-driven SOCs cannot match the accelerated timescales enabled by AI, ML and LLMs, leaving organisations exposed. Slowik recommended rethinking security operations to integrate AI agents for rapid intelligence, enrichment and remediation, while keeping humans in the decision loop. He used the React2Shell example to illustrate the speed of modern exploits.
read more →

Encryption Limits and AI’s Impact on Cybersecurity

🔒 Bruce Schneier reflects on his 2010 Dark Reading essay arguing that while cryptography provides strong mathematical advantages, it cannot by itself secure modern, interconnected systems. He traces how crypto has been applied since the 1990s and explains that computer security is an ongoing arms race of fragile defenses. Schneier warns that AI changes the landscape by automating vulnerability discovery and exploit creation, shifting the balance between attackers and defenders.
read more →

AI-assisted toolkit used to evade EDR defenses

🔍 Sophos X-Ops uncovered a lab where a threat actor used AI coding tools to develop and test malware aimed at evading EDR products. The files and Git repository showed Python scripts—many partially AI-generated—used to build and iterate evasion modules against vendors including Sophos, CrowdStrike and Microsoft. Humans retained control of the workflow, using AI to accelerate building, testing and refinement while operating inside an AI-native environment.
read more →

UK Firms Prioritise AI Threats and Preparedness

🔍 New research from ManageEngine reveals UK IT and business leaders view AI-powered cyber-attacks as their top risk over the next 12 months, with 43% identifying it as the single biggest threat. The survey of 1,500 decision-makers across five European markets shows 41% of UK respondents plan to prioritise spending on tackling AI and advanced threats. Despite strong detection rates, UK organisations report increasing incidents, skills gaps and recovery challenges, alongside rising investment in resilience and governance.
read more →

Responsible Vulnerability Disclosure in the AI Era

🛡️ Responsible Disclosure in the Age of AI argues that frontier AI systems now autonomously discover software vulnerabilities at unprecedented speed and scale, exposing long-standing technical debt in the software industry. The piece traces the evolution of assurance practices and disclosure frameworks and highlights growing tension between offensive and defensive cyber equities, particularly in the U.S. and China. It calls for coordinated national and international efforts to accelerate remediation, patch management, and investment in automated repair capabilities to close the narrowing window before adversaries exploit these advances.
read more →

AWS PCS launches PCS‑ready Deep Learning AMI

🔧 AWS Parallel Computing Service (AWS PCS) now offers a PCS‑ready Deep Learning AMI, an AWS‑maintained Amazon Machine Image based on the Deep Learning Base GPU AMI (Ubuntu 24.04). It provides a production‑quality foundation for AI/ML training and HPC with preinstalled, compatibility‑tested infrastructure components such as NVIDIA drivers, CUDA, EFA, Lustre client, PCS Agent, Slurm for PCS, and EFS utilities. Multiple Slurm versions are supported and activate automatically based on cluster configuration, and AWS will regularly update the AMIs for security patches and driver updates. The AMI is available at no additional cost for x86_64 and arm64 in all Regions where AWS PCS is offered.
read more →

AlloyDB Remote MCP Server Now Generally Available

🛡️ The Remote Model Context Protocol (MCP) Server for AlloyDB is now generally available, providing a secure HTTP endpoint that lets AI agents access real-time operational data. This fully managed service simplifies production deployments by centralizing discovery, offering fine-grained IAM-based authorization, audit logging, and integration with Model Armor for prompt and response protection. Developers can join AlloyDB operational data with analytics in BigQuery and use built-in AI functions for low-latency agentic experiences.
read more →

AI Won’t Replace SOCs, It Will Reshape Analyst Roles

🛡️ Vendors at Infosecurity Europe 2026 agree that AI will not eliminate security operations centers but will automate repetitive triage and ticketing. Experts urge treating AI as a glass box, ensuring transparency and human-in-the-loop validation. The shift accelerates junior analysts into supervisory tier-1.5 roles and creates demand for cyber defense engineers who build and tune detection systems.
read more →

OWASP launches Agentic Research Council for AI risks

🧭 At Infosecurity Europe 2026, OWASP will unveil the Agentic Research Council to better align fast‑moving agentic AI capabilities with security research and operational practice. Launched from the GenAI Security Project’s Agentic Security Initiative, the council will prioritize a public research pipeline, convene working groups and connect academic outputs to deployable mitigations. The initiative aims to accelerate runtime‑focused defenses against multi‑agent threats.
read more →

The Great Messaging Heist: Organized Scam Ecosystem

📩 Kaspersky examines how everyday messaging channels like SMS, WhatsApp, and email are being exploited by organized scam cartels that use speed, familiarity, and AI to trick victims. The research shows average losses of $733 per victim, rapid attack timelines often under 30 minutes, and widespread emotional damage eroding trust in digital communications. The post highlights common schemes, platform distribution, and recommendations to protect yourself.
read more →