< ciso
brief />
Tag Banner

All news with #ai security tag

1043 articles · page 5 of 53

Hiscox 2026: Cyberattacks Hit Nearly One Third Globally

🔍 The Hiscox Cyber Readiness Report 2026 found 29% of organisations worldwide experienced at least one successful cyber-attack in the past year, with UK firms most affected at 38% and US firms least at 20%. Affected organisations reported an average of four incidents, average downtime of 32.8 hours and an average cost per incident of around $52,000, with Italy highest at $134,138. The study also details wider operational, financial and human impacts and outlines how businesses are investing in resilience, training and AI security measures.
read more →

SMBs Must Accelerate Cyber Readiness Amid AI Risks

🔒 AI is accelerating both the scale and speed of cyberthreats, expanding attack surfaces as businesses rush to adopt the technology. SMBs need security that is simple to operate, combines AI-driven automation with human oversight, and aligns with business outcomes. Effective partnerships and prevention-centric, as-a-service models help smaller teams detect, contain and recover from incidents while minimizing operational disruption.
read more →

How AI Is Reshaping Cybersecurity Operations

🛡️ The rise of AI agents is already transforming security operations, shifting first-level triage and repetitive tasks to automated systems while leaving humans for escalation, oversight, and complex judgment. Experts warn of a surge in discovered vulnerabilities that defenders will struggle to absorb and remediate. Organizations should prepare for machine-speed attacks and containment, flattening team structures, new governance needs, and the use of AI as an interface across fragmented tools.
read more →

Distributed GraphFlow: Scalable GNNs for Telco Networks

🚀 Google Cloud introduces Distributed GraphFlow (DGF), an open-source Python library and framework designed to train and deploy Graph Neural Networks (GNNs) at scale for telecommunications. The post outlines an Autonomous Network Operations architecture built around a real-time network digital twin hosted in Spanner Graph, and explains how DGF integrates with that twin to enable anomaly detection, root cause analysis, predictive maintenance, and what-if simulations. DGF offers composable primitives and a high-level API to simplify GNN lifecycle management and production inference via Gemini Enterprise endpoints.
read more →

AI Tops Net-New Security Spend Priorities

🤖 New research from IANS shows AI is the top target for incremental security budgets, with 69% of US CISOs prioritizing it and roughly a quarter planning significant spend increases next year. The report, based on interviews with 500 security leaders, notes software now represents 35% of security budgets—near parity with staff & compensation. While AI is expected to boost productivity and create new roles, overall median budgets remain flat amid economic headwinds.
read more →

AI Exposes Outdated Security Structures

🔒 Organizations are investing heavily in security but remain stuck in compartmentalized models built for yesterday’s threats. AI-driven impersonation, deepfakes and automated social engineering now traverse digital, physical and operational boundaries, demanding cross-functional verification and unified response pipelines. Without documented processes and integrated tooling across cybersecurity, physical security, HR and legal, response efforts rely on informal relationships and risk critical delays. The next evolution requires threat-driven, integrated programs that pair AI capabilities with human expertise to detect, deter and respond faster.
read more →

Threat actors target enterprise AI assets at scale

🔐 Google’s GTIG reports that state-affiliated groups and cybercriminals are increasingly targeting AI-related assets — from model weights and proprietary source code to API keys and cloud compute — to support espionage, extortion, and resource theft. The quarter’s incidents included exfiltration of proprietary models, distillation campaigns using hundreds of millions of prompts, and cloud compromises that enabled attackers to run unauthorized AI workloads. Attackers also deploy automated, agent-driven frameworks to scale reconnaissance, credential harvesting, and exploitation.
read more →

AI-assisted weaponization risks and developer findings

🔍 Anthropic disclosed that threat actors in northern Yemen used Claude models to support three weapons programs, including guided rockets and long-range missiles. The actors employed Claude Code to replace human engineers for GNC tasks, running multiple instances with divided roles to write, research, and review code. Anthropic’s safeguards blocked many requests but were circumvented through obfuscation and session-splitting. The actors test-fired a guided rocket and returned to Claude after a failure to diagnose issues.
read more →

BigQuery Adds Augmented Analytics Table Functions

🔎 BigQuery introduces six augmented analytics Table-Valued Functions (TVFs) to automate insight discovery and explain patterns using AI, ML and statistical methods. These functions run where data resides, produce structured SQL outputs, and can be chained to diagnose metric shifts, identify drivers, and estimate causal effects. They are integrable into conversational analytics and AI agent workflows for rapid, scalable investigation.
read more →

When an Entire Company Adopts AI: SOC Impact

🔍 Over the past year enterprise SOCs have seen a new class of alerts tied to everyday AI use, from coding agents to employees signing third-party AI tools into corporate accounts. AI-related alerts remain a small share (0.43%) of total alerts but climbed 685% from February to June 2026, making them the fastest-growing subset. The alerts fall into three buckets—noise (94.1%), genuine risk (5.8%), and real attacks (0.02%)—with most incidents resolved as benign developer activity or detection misfires.
read more →

Bruce Schneier: My Talk at DEF CON on AI Hacking

🎤 Last month I presented a DEF CON talk on AI hacking—examining what happens when AIs become hackers. The talk builds on themes from my 2022 book A Hacker’s Mind and recent observations of AI models performing hacking behaviors. I’m pleased it surpassed 100K YouTube views within days. An interview with me in the AI Village is also available online.
read more →

Anthropic Finds Claude Used in Widespread Cyber Abuse

🛡️ Anthropic reported that between December 2025 and August 2026 its Claude models were abused by diverse threat actors—state-aligned groups, criminal affiliates, commercial vendors, and individuals—for cyberattacks, surveillance, influence operations, and weaponization. The company cataloged multiple Generative Threat Groups (GTGs) using Claude for reconnaissance, exploit development, credential harvesting, data exfiltration, and mass content production. Anthropic says abuses ranged from conversational assistance to fully autonomous multi-agent campaigns, and that it disrupted many operations and influence networks before they gained traction.
read more →

Organizations Deploy AI Without Adequate Permissions Checks

🔍 A Syskit study finds rapid enterprise AI adoption on Microsoft 365 outpaces permission reviews and governance controls. 76% of organizations have deployed or piloted AI tools like Copilot, yet only 43% completed thorough permissions reviews before rollout. The survey highlights widespread misconfigurations, orphaned content and gaps in access reporting, leaving many environments exposed.
read more →

ThreatsDay roundup: extensions, AI, and Android fixes

📢 This week's ThreatsDay Bulletin highlights a string of pragmatic security failures: malicious browser extensions exfiltrate crypto data, AI agents automate intrusions across multiple countries, and Google patches 200 Android flaws including a critical Wi‑Fi RCE. Other notable stories cover shadow AI risks, fake M&A wire fraud, sprawling fake-shop domains, exposed Plex servers, and a Singpass account scheme tied to over 170 victims.
read more →

ChatGPT Computer History for Mac: Risks and Benefits

📝 OpenAI’s Computer History in the ChatGPT Mac app creates plain-text diary summaries of a user’s on-screen activity to provide context-aware assistance. The feature uses macOS Accessibility APIs to log window titles, typed text, clicks, and app switches, stores raw events for up to 48 hours, then generates summaries saved locally and optionally uploaded to OpenAI under existing chat memory rules. It is opt-in, requires Pro, and includes permissions controls and exclusions for apps and sites.
read more →

Detect and Disrupt AI-Themed Attacks with Defender

🛡️ Microsoft Threat Intelligence outlines how attackers are leveraging AI brands like ChatGPT and Copilot to craft convincing phishing, malvertising, and malware campaigns that exploit urgency and trust. Microsoft Defender provides layered defenses—anti-phishing, Safe Links, Safe Attachments, and post-delivery filtering—and correlates signals across email, identities, endpoints, and SaaS to detect and disrupt multi-stage attacks. Attack disruption has contained tens of thousands of compromises monthly, illustrating the value of connected prevention, detection, and response.
read more →

CISA Updates Insider Threat Mitigation Guide

🔒 The Cybersecurity and Infrastructure Security Agency (CISA) has released a revised Insider Threat Mitigation Guide, published on September 9, expanding case studies, statistics and guidance for hybrid and remote work, AI-related risks, and adverse employee separations. The update, originally issued in 2020, aims to help security and HR professionals and leaders at all levels, offering practical resources for organizations regardless of program maturity. CISA emphasized the growing impact of insider threats on critical infrastructure and consolidated the guide into a more streamlined format with new content on access control and visitor screening.
read more →

FBI Releases Strategic Cyber Disruption Plan

🔒 The FBI has published its first Cyber Strategy, outlining how the agency will investigate and disrupt cyber threat actors and impose costs on adversaries. The document, published on September 9, emphasizes proactive disruption of financially motivated criminals and state-sponsored actors, rapid victim support, expanded partnerships, and investment in AI-enabled tools and workforce training. It sets out four pillars: investigate and disrupt, support victims, increase partnerships, and enhance cyber capabilities.
read more →

AI-Accelerated Exploit Discovery Compresses Timelines

🛡️ Researchers demonstrate that minimal hints can enable AI agents to identify software exploits rapidly. The author found that automated agents could locate vulnerabilities with only a rough description, potentially allowing attackers to weaponize flaws before public patches are released. This rapid discovery challenges current open source embargo practices and suggests a need to rethink coordinated disclosure and response processes. Commenters note the urgency of adapting security workflows to protect communities.
read more →

Deception Benchmark: Measuring AI Precision for Security

🔒 AWS releases the Deception Benchmark to measure whether AI models can distinguish real vulnerabilities from safe-but-suspicious code. The dataset contains 14,822 curated samples across 16 languages and 70+ CWE categories, designed through adversarial generation and rigorous multi-review labeling. Evaluations of 12 frontier models show precision clustered in the mid-50s under single-turn prompting, with no model achieving both low false positives and false negatives for production use.
read more →