< ciso
brief />
Tag Banner

All news with #ai security tag

900 articles · page 7 of 45

OpenAI’s GPT‑Red Scales Prompt Injection Red‑Teaming

🛡️ OpenAI revealed GPT‑Red, an internal automated red‑teaming model that simulates human adversaries to discover prompt injection vulnerabilities at scale. GPT‑Red iteratively probes and refines attacks against production models, helping harden GPT‑5.6 Sol and reduce prompt injection failures by 6× versus GPT‑5.5. OpenAI uses self‑play reinforcement learning to train both attacker and defender models while keeping GPT‑Red segregated to avoid misuse.
read more →

CISOs Must Rethink Vulnerability Management Now

🔍 Security experts urge enterprises to shift from scheduled patch cycles to risk-based, continuous approaches such as just-in-time patching, citing AI-driven vulnerability discovery and exploitation that outpace traditional models. Vendors warn that AI tools can rapidly surface and validate flaws, widening the gap between discovery and remediation and overwhelming teams. Compensating controls like virtual patching can help, but they are stopgaps; organizations need continuous asset visibility, real-time exploitation intelligence, and prioritization based on exposure and exploitability.
read more →

Continuous AI Red Teaming as Ongoing Security

🔍 AI security cannot be treated as a one-time certification; it requires an ongoing cycle of adversarial discovery, hardening, and operational resilience. NIST research shows no finite set of guardrails can guarantee permanent robustness, so teams must continuously test, remediate, and monitor systems as models, prompts, and integrations evolve. Effective programs tie red teaming to runtime protection and governance so findings become durable improvements.
read more →

Fortinet and INTERPOL Strengthen Cybercrime Response

🔍 Fortinet reinforced its decade-long partnership with INTERPOL at the INTERPOL Partners’ Conference in Lyon, stressing the need for faster, trust-based intelligence sharing to counter AI-accelerated cybercrime. Panel discussions highlighted how AI and agentic systems amplify threats across phishing, fraud, and cybercrime-as-a-service while underscoring the role of FortiGuard Labs in supporting coordinated disruption. The piece calls for sustained public-private collaboration, shared detection methods, and resource support for global law enforcement.
read more →

White House launches AI clearinghouse for vulnerabilities

🛡️ The White House has launched Gold Eagle, an AI-driven centralized clearinghouse to help government agencies, open-source communities, and critical infrastructure operators identify, prioritize, validate, and remediate software vulnerabilities faster. The program, directed by a June executive order on advanced AI innovation and security, aims to reduce duplicative scanning, coordinate reporting and validation, and deliver prioritized remediation guidance while preserving human judgment and enterprise context. Officials say Gold Eagle has already started receiving reports and coordinating remediation efforts across industries.
read more →

Seven Essential Traits of Elite Security Engineers

🔒 Elite security engineers combine technical depth with business awareness and continuous learning. They must be proficient with AI-powered defense tools while understanding how adversaries use AI for phishing, malware, and model attacks. Top engineers think in systems, bridge cross-domain stacks, manage third-party and machine identity risk, and communicate risk clearly to leaders. Adaptability and continuous learning remain critical.
read more →

Microsoft issues record July security update batch

🔒 Microsoft released updates addressing a record 570 security vulnerabilities in July’s Patch Tuesday, attributing the surge to AI-assisted discovery. Nearly 60 of the flaws are rated critical, and three are confirmed zero-days already exploited in the wild. The fixes include numerous elevation-of-privilege bugs and a BitLocker security bypass; vendors warn that AI speeds both discovery and exploit development.
read more →

Security Hub expands to AI protections and Azure

🔒 Security Hub now adds native AI workload protection and Microsoft Azure monitoring to centralize enterprise security across clouds. It discovers Azure resources, evaluates posture against CIS benchmarks, and prioritizes findings alongside AWS signals using the same formats and workflows. New GuardDuty AI Protection detects anomalous model invocations and cost-harvesting, while AI-powered investigations accelerate triage. A continuous AI inventory catalogs models and agents across accounts, and Security Hub Extended integrates 21 curated partners to broaden coverage.
read more →

Amazon GuardDuty adds AI Protection for AWS AI

🛡️ Amazon GuardDuty introduces AI Protection to extend threat detection to AWS AI services such as Amazon Bedrock and Amazon SageMaker. The feature continuously monitors AI workloads for threats like anomalous invocations, cost harvesting attacks, and prompt injection, using CloudTrail management and data events to surface suspicious activity. Findings integrate with AWS Security Hub for centralized triage and can be enabled per account or centrally via AWS Organizations, with a 30-day trial available for GuardDuty customers.
read more →

AWS Security Hub adds AI inventory for visibility

🛡️ AWS Security Hub now offers an AI inventory that gives central security teams a continuously updated, organization-wide view of AI assets and their security posture. It automatically discovers AI workloads via managed-service integration, SBOM analysis for self-hosted workloads, and GuardDuty DNS telemetry for external API endpoints. Discovered assets are mapped to underlying infrastructure and correlated with security findings to help prioritize remediation. The feature is included with Security Hub Essentials at no additional cost and is available in all commercial AWS Regions where Security Hub is offered.
read more →

Pentera Integrates Validation Into AI Security Workflows

🛡️Pentera enables AI assistants to use validated attack evidence rather than fragmented risk signals, helping teams prioritize and remediate real exploit paths. The platform emulates attacker techniques across environments, generating concrete attack paths with proof of techniques, credentials, privileges, and assets at risk. An MCP Server exposes Pentera validation data to AI workflows locally, preserving enterprise controls and auditability. This approach shifts workflows from inference to evidence-driven action, improving prioritization, ticketing, and revalidation.
read more →

AI-Driven Breaches Force Rethink of Incident Response

🛡️ Enterprises face a new class of attacks as threat actors leverage AI agents to automate entire intrusion chains, dramatically compressing the time from initial access to deep compromise. Reports from Sygnia and Sysdig document AI-enabled campaigns that harvest credentials, map services, and persist across cloud environments, often exploiting known vulnerabilities rather than zero-days. Experts warn that traditional, human-speed incident response and hunting are often too slow, and emphasize the need for integrated, AI-assisted defenses and rigorous hygiene: fast patching, secrets rotation, least privilege, segmentation, and automated response playbooks.
read more →

Check Point Research: AI Security Threats 2026

🛡️ The Check Point AI Security Report 2026 documents how AI has shifted from an assistant to an operator in cyberattacks, running multi-step intrusions with minimal human direction. It highlights collapsed vulnerability response windows, widespread probing of exposed AI infrastructure, and a doubling of sensitive data leakage through approved AI use. The report recommends visibility, machine-speed defenses, and governance to protect AI systems and manage workforce AI.
read more →

Behavior-First Security Training for AI-Driven Risks

🔒 AI has increased employee awareness of cyber risks, but understanding threats is not the same as being ready to respond. The 2025 Security Awareness and Training report shows high awareness but a clear readiness gap: only 40% of organizations say employees are highly prepared for AI-based threats. Fortinet advocates behavior-first, role-based training with short scenario-driven modules to help employees apply judgment, verify requests, protect data, and use AI tools safely.
read more →

Forg365 PhaaS Targets Microsoft 365 Accounts

🛡️ A new phishing-as-a-service operation named Forg365 targets Microsoft 365 by combining device-code phishing, AitM tactics, antibot evasion, AI-assisted lure creation, and post-compromise mailbox operations. Distributed via Telegram and offered as a subscription, the kit uses legitimate delivery infrastructure like Amazon SES and SendGrid to blend into normal email flows before redirecting victims to attacker-controlled domains. The platform includes a clearnet operator panel, OAuth and token handling, and a Chromium extension called ForgCookie that automates cookie refresh and sustained access to compromised accounts.
read more →

Kaspersky introduces AI BEC detection for email

🛡️ Kaspersky explains a new capability to detect AI-generated business email compromise (BEC) messages by identifying both BEC-specific phrases and linguistic patterns typical of machine-generated text. The company notes that cybercriminals increasingly use large language models to craft persuasive phishing and BEC campaigns, and this detection works across eight languages. The feature is integrated into Kaspersky Secure Mail Gateway and available with the KSMS Plus license after the KSMG 3.1 update.
read more →

Designing SOCs That Mirror Human Decision Modes

🧠 The article argues that effective AI-enabled SOCs should mirror Kahneman’s dual-system model: a fast, autonomous layer handling ~98% of alerts and a slow, deliberative layer for the small fraction needing human judgment. It warns against asking analysts or large language models to perform repetitive triage and emphasizes in-house investigation to retain the knowledge base. The right architecture frees analysts to supervise and improves detection over time.
read more →

Jurassic Park and the Myth of Cyber Control

🦖 The article compares Jurassic Park’s failed containment to modern cybersecurity, arguing that visibility is often mistaken for control. It asserts that tooling, dashboards, and backups provide friction but not guaranteed survivability, and that dynamic cloud and AI-driven change invalidate static recovery assumptions. The piece recommends continuous resilience engineering, dependency awareness, and validation to operate through inevitable disruptions rather than assume they can be prevented.
read more →

Can AI Narrow Cybersecurity’s Class Divide?

🔒 At AWS and other large vendors, AI is compressing months of security work into minutes by automating red-team findings, generating detections, and accelerating remediation. Experts debate whether this will widen an existing security class divide—where large organizations have talent, data, and infrastructure while smaller ones struggle—or democratize advanced capabilities. Key concerns include costs, privacy tradeoffs, token pricing, and the operational depth needed to safely run AI in production.
read more →

EMR on EKS Adds Spark Troubleshooting Agent

🛠️ Amazon EMR on EKS now integrates an Apache Spark troubleshooting agent that provides automated root cause analysis and PySpark recommendations through natural language, simplifying diagnosis of job failures. The agent inspects Spark History Server data, executor logs, and cluster configs to detect issues like memory errors, data skew, resource contention, and connectivity problems. Accessible via a "Troubleshoot with AI" option in the EMR on EKS console and via MCP with compatible AI coding agents, the feature is read-only, IAM-authenticated, logged in CloudTrail, and available in Regions with SageMaker Unified Studio.
read more →