< ciso
brief />
Tag Banner

All news with #ai security tag

900 articles · page 6 of 45

Security Priorities and Risks in the AI Era

🔐 At a recent Information Security Day seminar, white-hat hacker and Steelion CEO Park Chan-am outlined how AI is accelerating attacks and reshaping security priorities. He emphasized that access control, supply chain security, and human verification remain central even as AI shortens vulnerability discovery from weeks to hours. Park warned that AI agents and local testing environments widen attack surfaces and urged new approaches to vulnerability prioritization and behavioral defenses.
read more →

Context bombing: a new defensive AI deception tactic

🛡️ Security researchers are testing a tactic called context bombing, which plants decoy files containing prompts that trigger LLM safety guardrails to stop rogue AI agents. These AI canaries act as tripwires that both alert defenders and often cause malicious agents to refuse actions, significantly reducing attack success. Tracebit’s experiments showed dramatic drops in compromise rates when context bombs were present.
read more →

Amazon GuardDuty Investigation Agent Public Preview

🔍 The Amazon GuardDuty investigation agent, now in public preview, delivers on-demand, AI-assisted assessments of GuardDuty findings across AWS accounts and Regions. It returns structured outputs including risk level, confidence scores, MITRE ATT&CK mapping, resource context, and prioritized remediation actions. Accessible via AWS Console, CLI, APIs, SDKs, and the AWS MCP server, it supports natural-language triggers and integrates into existing security pipelines to reduce investigation time from hours to minutes.
read more →

AI Increases SOC Strain, Forcing Operational Change

🔍 Security operations centers (SOCs) are confronting rising alert volumes, faster AI-enabled vulnerability discovery, and increasing machine-generated outputs that create new cognitive burdens for analysts. Experts warn AI amplifies existing weaknesses—staffing shortages, alert fatigue, and technical debt—while also offering tools to manage scale. Mature SOCs with robust processes may adapt, but less-prepared teams risk burnout and overwhelm.
read more →

Anthropic’s Claude Mythos and Cybersecurity Impacts

🛡️ Anthropic’s Claude Mythos is a frontier AI model optimized for cybersecurity and healthcare, released initially to vetted partners via Project Glasswing to discover vulnerabilities at scale. Partners reported thousands of high-severity findings, prompting restricted access, export-control scrutiny, and the release of a guarded variant, Claude Fable. Vendors and defenders are adapting AI-driven workflows, while critics highlight guardrail limits, false positives, and the need to fix remediation gaps.
read more →

Microsoft at Black Hat USA 2026: Defending Trust

🔒 At Black Hat USA 2026, Microsoft Security highlights how threat actors exploit trusted systems—software, developer workflows, identities, and AI—to scale attacks. Sessions and briefings across August 4–6 focus on supply chain compromises, AI security, and practical defense strategies. Visit booth #2144 for demonstrations, expert-led services, and community events including a reception on August 5.
read more →

Senior executives driving shadow AI risk in enterprises

🔒 Senior leaders increasingly use unapproved AI tools despite clear security and privacy concerns, creating major headaches for CISOs and IT teams. TrustedTech’s survey found nearly two-thirds of senior decision-makers use shadow AI, often because sanctioned tools are slower or inadequate. Experts say this is a culture and usability problem rather than simple ignorance, and that governance must be modeled from the top while offering secure, usable alternatives.
read more →

Unit 42 2026 IR Report: AI as an Attack Multiplier

🔍 Unit 42’s 2026 Global Incident Response Report examines how AI is accelerating and streamlining attacker operations. Drawing on hundreds of engagements, the report finds AI shortens development cycles and automates reconnaissance while core attack techniques remain consistent. It stresses defenders can apply existing controls but should prioritize prevention and AI-aware skills.
read more →

AI as a Force Multiplier in Incident Response

🔍 Unit 42’s 2026 Global Incident Response Report examines how threat actors integrate AI to accelerate attacks. Drawing on hundreds of engagements, the report finds AI shortens development cycles, automates content generation and streamlines reconnaissance, compressing attack lifecycles. Despite this speed, adversaries continue to rely on established TTPs like credential theft, phishing and ransomware, meaning defenders can apply existing controls while adapting to AI-driven efficiencies.
read more →

Cloud CISO Perspectives: AI and deep context defense

🛡️ Francis deSouza outlines how deep context gives defenders an AI-driven advantage by unifying enterprise telemetry, vulnerability management, and agentic automation. The post introduces Google AI Threat Defense, combining Gemini, Wiz, CodeMender, and Mandiant into a prepare–scan–remediate–monitor lifecycle. It emphasizes human oversight, Zero Trust for AI, and real-world impact such as Morgan Stanley’s rapid detection improvements.
read more →

Gemini prompt-injection attacks and real risks

🛡️ Two SafeBreach studies demonstrate how prompt-injection techniques can bypass layers of defenses around Google Gemini, using calendar invites or text messages as entry points. Attackers chain indirect injection, memory poisoning, delayed execution, and fake context alignment to get the assistant to perform unauthorized actions across devices. Even with Google fixes, the research highlights a persistent arms race between attackers and defenders that leaves users needing to restrict assistant access.
read more →

Prisma AIRS AI Gateway Now Generally Available

🔒 Palo Alto Networks has announced the general availability of Prisma AIRS AI Gateway, an AI control plane designed to provide unified governance, identity, and runtime controls for enterprise AI interactions. The gateway sits inline between agents, AI apps, and model providers to deliver observability, policy enforcement, credential scoping, and runtime inspection. Built from Portkey innovations, it targets scale and security gaps as AI usage and outbound data volumes surge across enterprises.
read more →

AI Appreciation Day: Honest View on Risks and Rewards

🤖 Today is AI Appreciation Day, and while AI has transformed coding, threat analysis, and productivity, Check Point’s AI Security Report 2026 warns that those same strengths empower attackers. Researchers observed AI running exploitation workflows autonomously, producing vast volumes of malware code and executing thousands of commands in real intrusions. Organizations are adopting many AI apps rapidly, often without governance, increasing high-risk prompts and exposure.
read more →

Operational Guardrails for AI-Assisted Vulnerability Management

🛡️ This article from Mandiant Consulting outlines practical guidance for safely integrating AI agents into vulnerability discovery and remediation workflows. It emphasizes grounding AI adoption in established frameworks such as NIST RMF, OWASP for LLMs, and Google’s SAIF, and prescribes layered defenses including deterministic policy engines, sandboxed agent workloads, zero data retention agreements, and human-led red teaming. The post also stresses threat modeling, least-privileged machine identities, supply chain vigilance for agent skills, and runtime observability to prevent data exfiltration and prompt-injection risks.
read more →

GKE Blueprint for Securing AI Workloads at Scale

🔒 This article presents a blueprint for securing AI workloads on Google Kubernetes Engine (GKE), consolidating controls across Google Cloud services and GKE features to create a secure-by-default platform. It covers three layers—infrastructure, supply chain, and application—and details capabilities such as Confidential GKE Nodes, Workload Identity Federation, k8s-aibom for AI SBOMs, Model Armor, and the GKE Inference Gateway. The blueprint recommends a three-phase rollout: Deploy, Operate, and Govern, and emphasizes integrating Google Cloud controls to maintain security at enterprise scale.
read more →

AI Helps Find Bugs but Humans Must Prove Them

🛡️ AI is accelerating offensive security by producing many potential findings quickly, but generated reports are not the same as validated evidence. AI tools can read code, generate payloads, and suggest attack paths, yet validation still requires human knowledge of systems, reachability, and exploitability. Low-quality AI submissions are already increasing triage burden, so teams must separate leads from proven findings and apply rigorous validation before driving engineering action.
read more →

The Hunter’s Paradox: Rethinking AI in Threat Hunting

🔍 This post examines whether AI should lead threat hunting, arguing the choice is not binary. The author reframes hunting as a reasoning-driven process rather than a human-only activity and explains why scale, velocity, and capacity force us toward automation. Practical guidance includes scoped hunts, strict access controls, and graduated autonomy while keeping humans responsible for strategy and novel analysis.
read more →

When AI gets a body, it inherits an attack surface

🤖 Embodied AI systems—robots, arms, humanoids—turn models into cyber-physical assets that inherit hardware, firmware, supply-chain and remote-access risks the vendor demo hides. Buyers should evaluate five areas: provenance (hardware/firmware BOM and update authority), access (remote paths and teleoperation), integrity (sensor spoofing and model manipulation), evidence (independent field data) and accountability (contractual responsibility and liability).
read more →

SANS warns of growing AI governance gap

🛡️ The SANS Institute’s 2026 AI Survey Insights shows rapid AI adoption in security, with 78% of organizations using AI versus 50% in 2025, yet confidence and effectiveness lag. The survey of 536 practitioners and 57 leaders found rising shortcomings in detection and response and increased AI-enabled attacks, including deepfakes and adversarial exploits. SANS highlights a governance shortfall—half of leaders report formal programs while many remain in early policy stages—and urges investment in validation infrastructure, operational governance, and immediate workforce upskilling.
read more →

AI-Aggregated Executive Profiles Increase Attack Surface

🔎 AI tools now synthesize publicly available executive information into coherent, queryable profiles that attackers can use for social engineering. These profiles collapse traditional OSINT timeframes from days to minutes and lower the skill needed to target executives. Security teams must monitor AI outputs, reduce unnecessary public exposure, and integrate AI-profile risk into executive protection programs. Training executives to view their own AI-generated profiles and assigning security ownership are essential countermeasures.
read more →