< ciso
brief />
Tag Banner

All news with #ai security tag

1046 articles · page 31 of 53

Cloudflare AI Security for Apps Now Generally Available

🛡️ Cloudflare’s AI Security for Apps is now generally available, providing discovery, detection, and mitigation tailored for AI-powered web endpoints. The release introduces custom topics detection and enhanced prompt extraction to spot business-specific sensitive content across varied JSON payloads. Cloudflare is making AI endpoint discovery free for all plans and couples detections with the WAF rule engine so teams can block, log, or return custom responses at the edge. Integrations with IBM Cloud and Wiz extend procurement and unified posture visibility for customers.
read more →

ESET Threat Intelligence Emerges as Strategic Game-Changer

🔍 ESET positions its threat intelligence and telemetry as essential tools for organizations facing increasingly sophisticated cyber threats, including AI-enabled attacks and convincing deepfakes. ESET Telemetry reports a 12% decline in overall detections in India (Jan–Aug 2025), but ransomware surged 70% from H2 2024 to H1 2025 and phishing remains the most common vector. The vendor bundles endpoint, XDR, identity protection, MDR, and analyst-driven APT reporting to help CIOs and CISOs stay ahead.
read more →

CISO Role Evolves Rapidly with AI in Cyber Defense

🔐 AI is reshaping cyber defense strategies and executive responsibilities. Organizations face a dual-use threat where AI empowers attackers and defenders; security teams must combine human expertise with automated capabilities. Human + AI approaches, informed by threat intelligence and comprehensive asset mapping, are critical. Vendors like ESET emphasize global, 24/7 coverage and say CISOs must secure board-level buy-in, regulatory alignment, and a clear, cost-effective AI roadmap to improve detection, response, and remediation.
read more →

AWS at RSAC 2026: Unifying Security and Data for AI

🔒 Visit AWS at booth S-0466 in South Expo to experience interactive demos, partner integrations, and an AI-powered Humanoid Security Guardian that generates customized well-architected guides via QR code. AWS security specialists will present sessions on privacy-by-design, trusted identity for autonomous agents, container supply-chain protection, and preparing for AI-native incidents. Join hands-on workshops and CTF challenges in Cloud Village, March 23–26, and use a Partner Passport to collect booth stamps, earn swag, and enter daily raffles.
read more →

OpenAI Acquires Promptfoo to Boost Agentic AI Security

🔐OpenAI has acquired Promptfoo, a startup that provides open source tools to test and evaluate LLMs and AI agents. The deal aims to close a growing security gap in agentic AI by integrating automated testing, red‑teaming and traceability directly into OpenAI Frontier. Promptfoo's suite — used by over 25% of Fortune 500 firms — will remain open source. The move follows warnings from security advisors about 'human‑language malware' and complements OpenAI's recent security hires and tools.
read more →

Amazon Connect boosts AI predictive insights for CX

🤖 Amazon Connect has enhanced its AI-powered predictive insights to support up to 40 million product catalog items (an 8× increase), integrate recommendations into message templates for trigger-based campaigns, and improve model accuracy by up to 14%. These updates, built on the five recommendation algorithms from re:Invent 2025, reduce training and deployment time so businesses can deliver automated, personalized outreach faster. Public preview is available across multiple AWS regions and Amazon Connect Customer Profiles remains pay-as-you-go.
read more →

Amazon Connect Adds AI-Powered Manager Assistance (Preview)

🤖 Amazon Connect introduces a preview AI assistant that enables contact center managers to ask operational questions in natural language and receive answers in seconds. The assistant supports queries across 150+ Connect metrics with historical context, eliminating hours of manual data gathering. It can also diagnose issues—such as queues at risk of missing service levels—and recommend targeted recovery actions. Preview access is limited; customers must request access through their AWS account team.
read more →

Fuzzing AI Judges: Stealth Triggers Enable Policy Bypass

🔍 This research introduces AdvJudge-Zero, an automated fuzzer that discovers stealthy input sequences capable of flipping AI judge decisions and bypassing safety gates. Tests show low-perplexity, benign-looking tokens—such as markdown markers, role labels, and context-shift phrases—can reliably convert block outcomes into allows. The report documents a roughly 99% attack success rate across diverse models and recommends adversarial fuzzing, retraining with discovered examples, and operational monitoring using products like Prisma AIRS and Cortex AI-SPM.
read more →

Palo Alto Networks Launches Prisma AIRS in Singapore

🔒 Palo Alto Networks has launched Prisma AIRS in the Singapore cloud region to provide locally hosted, AI-native cybersecurity for organizations adopting generative AI and agentic workflows. The regional landing delivers capabilities across AI Model Security, AI Red Teaming, AI Runtime Security, and AI Agent SSPM, addressing risks such as prompt injection, model tampering and sensitive data leaks. Local hosting supports data residency, regulatory alignment and improved performance for enterprises in Singapore.
read more →

WEF Global Cybersecurity Outlook 2026: CISO Takeaways

🤖 The World Economic Forum’s Global Cybersecurity Outlook 2026 warns that AI is accelerating the cyber arms race: 94% of leaders expect it to be the top change driver and 87% say AI vulnerabilities are the fastest‑growing risk. The report notes organizations are improving AI tool security evaluation (from 37% to 64%), yet CEOs and CISOs display different risk priorities. It also highlights widening resilience gaps across organization sizes and calls for harmonized regulation and stronger public‑private collaboration.
read more →

AI Security Dominates IT-Harvest's Cyber 150 Cohort

🔐 IT-Harvest has published its 2026 Cyber 150 list, noting that AI security vendors make up 22% of the cohort. The annual ranking highlights mid-sized cybersecurity firms (50–500 staff) chosen on funding, 2025 growth and market traction. 33 companies were classified as AI security, including fast growers like Tenex.ai (318% growth) and well-funded names such as 7AI and Noma Security. The list also shows broad category distribution and geographic concentration in the US and Israel.
read more →

Microsoft: Hackers Using AI at Every Stage of Attacks

🤖 Microsoft’s Threat Intelligence report warns that threat actors are increasingly using generative AI across all stages of cyberattacks to accelerate execution and lower technical barriers. Attackers employ models to draft phishing lures, generate realistic fake identities and resumes, produce or debug malware, and scaffold infrastructure. Groups like Jasper Sleet and Coral Sleet have used AI in remote IT worker schemes, while operators test jailbreaking and agentic techniques. Microsoft advises treating these campaigns as insider risks and strengthening identity controls, credential monitoring, and protections around AI systems.
read more →

AI-Assisted Automation Enables Large-Scale Password Spraying

🔐 Fortinet investigated recent reports of AI-assisted attacks and found no exploitation of FortiGate vulnerabilities; attackers instead exploited exposed management ports and weak single-factor credentials using automated password spraying. The novel concern is that conversational AI prompts and cloud resources can now automate target discovery, credential guessing, vulnerability assessment, and exploitation at scale with no coding required. Fortinet stresses defense-in-depth and rapid remediation.
read more →

AI as Tradecraft: How Threat Actors Operationalize AI

⚠️ Threat actors are integrating AI across the cyberattack lifecycle to speed and scale operations, using LLMs to draft phishing, generate and debug malware, fabricate identities, and maintain persistent fraudulent access. Microsoft observed groups such as Jasper Sleet and Coral Sleet abusing generative models and jailbreaking techniques to bypass safeguards. Early experiments with agentic AI could enable semi‑autonomous workflows, increasing operational resilience. Defenders should combine identity controls, telemetry, and AI‑aware detection tools to mitigate risk.
read more →

Transparent Tribe Mass-Produces AI-Assisted Malware

⚠️ Bitdefender reveals that the Pakistan-aligned actor Transparent Tribe (APT36) has adopted AI-assisted coding to mass-produce disposable malware implants using niche languages like Nim, Zig, Crystal and Rust. The campaign targets Indian government entities and embassies while abusing trusted platforms such as Slack, Discord, Supabase, Google Sheets and Firebase to hide C2. Phishing via ZIP/ISO attachments or PDF lures delivers LNK shortcuts that run PowerShell in memory and fetch backdoors, often followed by deployment of Cobalt Strike and Havoc for post-compromise activity.
read more →

Targeted Online Ads Emerging as Primary Malware Vector

🛡️ The Media Trust reports that online advertisements are increasingly exploited to deliver malware, and malvertising now surpasses email and direct hacks as the leading global delivery vector. Millions of infected creatives or scripts can propagate across publishers in seconds, and attackers are leveraging AI to produce adaptive malware that changes by location, browser, or device. Notable examples include Ghost Cat, Click Fix and SocGholish, while the company warns of emerging AI-assisted evasion and the abuse of adtech infrastructure.
read more →

CISO Priorities for 2026: AI, Identity, and Resilience

🔐 2026 will bring faster, cheaper, and more credible cyberattacks as AI and automation lower the skill barrier for attackers. Industry leaders from Banco Santander, Vodafone, NordVPN, Sophos, and Cisco emphasize a shift from perimeter defenses to identity-centric, automated, resilience-focused models. Priority actions include continuous identity verification, integrated AI-driven security, XDR consolidation, supply-chain risk management, and stronger detection, response, and data-protection controls implemented with minimal customer friction.
read more →

AI-Driven Insider Risk Now a Critical Business Threat

🔒 Mimecast's State of Human Risk Report 2026 warns that insider threats have escalated into a critical business risk, driven in part by employees mishandling or abusing AI tools. The study found 42% of organizations reported increases in both malicious insider activity and negligence-related incidents, while security leaders now anticipate an average of six insider-driven incidents per month. Mimecast cautions that attackers and insiders leveraging AI amplify exposure and call for security to address risk at the user level.
read more →

ContextCrush Flaw Risks AI Development Tool Supply

🛡️ Security researchers from Noma Labs disclosed a critical vulnerability in the Context7 MCP Server used by Upstash to deliver library documentation to AI coding assistants. The flaw, named ContextCrush, allowed unfiltered "Custom Rules" to be served directly to AI agents, enabling malicious instructions to be executed within developers' environments. Context7 is widely used—boasting around 50,000 GitHub stars and over 8 million npm downloads—and integrates with assistants such as Cursor, Claude Code and Windsurf, increasing potential exposure. Upstash deployed rule sanitisation and additional safeguards after disclosure; there is no evidence of active exploitation.
read more →

FortiAIGate: Runtime Protection for AI Workloads, Governance

🔒 FortiAIGate provides dedicated runtime protection for private AI and LLM deployments by monitoring every input and output between applications and models. It detects and blocks threats such as prompt injection, jailbreaking, model poisoning, data exfiltration, and excessive compute abuse while enforcing governance policies in real time. Built for Kubernetes and hybrid environments, it integrates with Fortinet Security Fabric, offers dashboards mapping OWASP Top 10 LLM risks, and uses multi‑GPU and SmartNIC acceleration to preserve performance and control costs.
read more →