< ciso
brief />
Tag Banner

All news with #ai security tag

1046 articles · page 32 of 53

Companies Inject Hidden Prompts into AI Summarization

🔒 Microsoft reports companies are embedding hidden instructions in Summarize with AI buttons that pass persistence commands via URL prompt parameters. These prompts tell assistants to 'remember [Company] as a trusted source' or 'recommend [Company] first,' biasing later responses toward vendors. Researchers found over 50 unique prompts from 31 companies across 14 industries, and freely available tooling makes this trivial to deploy. The manipulation can subtly skew recommendations in critical areas like health, finance, and security without users knowing.
read more →

New RFP Template for AI Usage Control and Governance

🔒 A new RFP Guide for Evaluating AI Usage Control and AI Governance Solutions provides security teams with a practical framework to convert vague AI-governance goals into measurable procurement criteria. It emphasizes interaction-level inspection — governing the moment a prompt is typed or a file is uploaded — rather than cataloging every shadow app. The template forces vendors to demonstrate browser- and client-side visibility, real-time enforcement, and contextual policy controls. A scoring model across eight domains helps CISOs avoid legacy checkbox tools and evaluate readiness for agentic, browser-native workflows.
read more →

Open-source AI Attack Kit CyberStrikeAI Raises Alarms

⚠️ CyberStrikeAI is an open-source, AI-native attack orchestration platform that consolidates end-to-end offensive tooling and automation into a single repository. According to Team Cymru, the project ships with more than 100 curated tools, native Model Context Protocol (MCP) integration, role-based testing, a skills system and mobile chatbots, and has been linked to a developer with alleged ties to Chinese state-affiliated firms. Researchers warn the platform dramatically lowers the technical barrier for attackers and could accelerate AI-augmented exploitation against edge devices and appliances.
read more →

Unlocking Document Understanding with Mistral in Foundry

📄 Mistral Document AI 2512 in Microsoft Foundry combines high-end OCR (mistral-ocr-2512) with contextual extraction (mistral-small-2506) to convert scans, photos and digital documents into structured JSON and markup while preserving layout, tables and handwritten notes. It emphasizes enterprise-grade accuracy, multilingual coverage and private/secure inference. Paired with the ARGUS accelerator, organizations can deploy end-to-end pipelines quickly and switch OCR providers at runtime.
read more →

Kaspersky Adds OpenAI API Support to Container Security

🔒 Kaspersky has extended Kaspersky Container Security with support for the OpenAI API, allowing organizations to connect local or third‑party large language models that implement that API. The integrated AI assistant analyzes uploaded container images, describes their contents and behavior, performs independent risk assessments, and suggests mitigations to speed investigations and decision-making. The update also brings single sign‑on and multi‑domain Active Directory support, faster image scanning, and enhanced security policy capabilities to the Kaspersky Cloud Workload Security suite.
read more →

CyberStrikeAI Adopted by Hackers for AI-Powered Attacks

🔍 Researchers warn that the open-source platform CyberStrikeAI was observed on infrastructure linked to a recent campaign that compromised hundreds of Fortinet FortiGate devices. Team Cymru analysts identified the service banner on port 8080 at 212.11.64[.]250 and saw communications between that host and targeted FortiGate appliances. The platform integrates over 100 security tools with AI agents to automate end-to-end attack chains, enabling lower-skilled operators to carry out complex exploitation.
read more →

ClawJacked: Local WebSocket Flaw Gives Remote Control

⚠️ Researchers have revealed a high-severity "ClawJacked" vulnerability in OpenClaw that can allow a malicious webpage to take full control of the AI assistant platform. The issue arises because the gateway binds to localhost and treats local connections as trusted, permitting a script to brute-force credentials and auto-register as a trusted node. Once authenticated, an attacker can enumerate devices, read logs and dispatch commands. Users are urged to upgrade to 2026.2.25 or later immediately.
read more →

Secure-by-Design Framework for CISO-Led Innovation

🔒 CISOs should treat innovation as a control: enable safe experimentation while reducing exposure across AI, IoT and cloud. The article urges leaders to remove toil, standardize repeatable patterns, and provide golden paths so secure options are also the fastest. It recommends guardrails, mandatory exit criteria for pilots, and measurable outcomes to prevent innovation debt. The goal is to accelerate business velocity while demonstrably reducing risk.
read more →

Building a Resilient Cybersecurity Workforce for CISOs

🔒 CISOs face persistent skills gaps, workload stress and rapidly changing roles as AI adoption accelerates. Leaders such as Stephen Ford (Rockwell Automation) and ISC2 executives argue that workforce sustainability must be treated as a risk-management priority, backed by data to quantify workload and justify resourcing. The recommended approach combines AI-driven automation as a force multiplier with deliberate upskilling, human-in-the-loop processes, early-career pipelines and hiring from adjacent disciplines to preserve institutional knowledge and reduce burnout.
read more →

Telecom Service Providers Must Build Secure AI Factories

🔒 Service providers face a generational opportunity to become AI factories, hosting high-performance, low-latency AI for enterprises while meeting sovereignty and compliance needs. Palo Alto Networks argues that securing these environments requires layered defenses from physical infrastructure through models and agents, combining ML-led NGFWs, Prisma AIRS, CyberArk and Cortex. The aim is real-time governance of data, nonhuman identities and autonomous agents to prevent poisoning, prompt injection and credential theft.
read more →

ClawJacked vulnerability lets websites hijack OpenClaw

🔒 Security researchers disclosed a high-severity ClawJacked vulnerability in OpenClaw that allowed a malicious website to silently brute-force a locally running gateway and take control. Oasis Security reported the issue and OpenClaw released a fix in version 2026.2.26 on February 26. The update hardens WebSocket checks, removes unsafe localhost exemptions, and closes avenues for silent device pairing and credential theft. Administrators should update immediately.
read more →

OpenClaw 'ClawJacked' Flaw Lets Webpages Take Control

🔒OpenClaw addressed a high‑severity vulnerability codenamed ClawJacked that allowed attacker‑controlled webpages to connect to a local OpenClaw gateway, brute‑force its password (no rate limiting), and register as a trusted device with admin privileges because localhost registrations were silently approved. The vendor released 2026.2.25 on Feb 26, 2026, and urges immediate updates, access audits, and stronger governance for agent identities.
read more →

Accelerating Data Center Modernization for AI Era Now

🔍 Data center modernization has become a strategic imperative as organizations accelerate deployment of AI and other compute-intensive applications. Success requires coordinated investment across servers, storage, networking, software, and security, and strong partnerships with vendors and integrators. IT leaders need clear roadmaps, measurable milestones, and solutions that balance performance, cost, and operational resilience to enable rapid, secure adoption.
read more →

Accelerating Data Center Modernization for AI Readiness

⚙️Data centers must evolve quickly to support AI workloads and deliver measurable business outcomes. This Spotlight report explains the technical and organizational shifts required to bring infrastructure into the AI age, spanning servers, storage, high-performance computing, networking, software, and security. IT leaders will find actionable guidance on roadmaps, partner selection, and prioritization to accelerate modernization and reduce deployment risk.
read more →

Automating Security Decisions to Counter AI-Driven Attacks

🔒 Security experts warn that defenders must embrace greater automation to keep pace with AI-powered attacks that operate at machine speed. Recent research, including CrowdStrike findings showing average breakout times falling to 29 minutes (and as fast as 27 seconds), highlights the urgency. Industry leaders recommend automating routine SOC work and responses to known threats while reserving humans for novel, high-risk incidents. Cultural shifts and revised risk appetites will be required to enable faster, autonomous mitigations.
read more →

AWS Security Agent: Multi-Agent Penetration Testing

🔒 AWS describes a multi-agent penetration testing capability in AWS Security Agent that pairs LLM-driven reasoning with specialized scanners and browser-based sign-in to automate complex assessments. The design combines baseline scanning, managed static tests, and a guided explorer that dynamically generates contextual attack tasks. A swarm of risk-focused worker agents executes tests and submits structured findings, which are then validated via deterministic checks and LLM-assisted exploit attempts and scored with CVSS to produce actionable remediation reports.
read more →

Adapting Threat Modeling for AI Applications at Scale

🛡️ The Microsoft Security Blog explains why threat modeling must be retooled for AI systems, noting that probabilistic behavior and complex input spaces require reasoning about ranges of likely outcomes rather than single execution paths. It identifies three core drivers — nondeterminism, instruction‑following bias, and system expansion through tools and memory — which widen attack surfaces and surface human‑centered risks like erosion of trust. The post advises starting from assets, mapping untrusted inputs, setting clear 'never do' boundaries, and embedding architectural mitigations, observability, and response plans to limit blast radius and sustain trust.
read more →

Top CISO Priorities for RSA 2026: AI, CTEM, Resilience

🔐 RSA 2026 will spotlight how AI agents, CTEM, cyber resilience, identity, and AI security are reshaping CISO agendas. Expect demonstrations of AI-SOC capabilities, expanded CTEM platforms, and renewed emphasis on identity as the perimeter, alongside warnings about hallucinations, data quality, and vendor overreach. Arrive prepared with prioritized requirements, cleaned data, and a plan to upskill teams for effective human–agent teaming.
read more →

Android expands AI-powered scam protections to devices

🔒 Android is expanding its AI-driven Scam Detection protections for calls and messages, bringing on-device Gemini models to more Pixel and Samsung Galaxy devices. A real-world example describes a Pixel user who avoided a convincing bank scam after receiving a timely Scam Detection warning during the call. Google Messages protections now cover 20+ countries and multiple languages and have improved detection for sophisticated threats like job-offer and romance “pig butchering” scams. Processing occurs on-device, data aren’t stored or shared, and the feature is off by default and excluded for contacts.
read more →

Agentic SOC: Cortex Embeds AI Across Security Operations

🤖 Palo Alto Networks has rolled out a major Cortex release that embeds context-aware, agentic AI throughout the security operations lifecycle, promising faster detection, investigation and response. An expanded AI-ready data foundation, Cortex XDL 2.0, and new purpose-built agents — including Case Investigation, Cloud Posture and Automation Engineer — aim to slash response times and automate complex playbooks. The launch also introduces the standalone Cortex Agentix orchestration platform and signals intent to acquire Koi to strengthen endpoint protection for AI-driven threats.
read more →