< ciso
brief />
Tag Banner

All news with #ai security tag

1043 articles · page 7 of 53

Securing Enterprise AI: Practical Lifecycle Controls

🔒 Organizations are rapidly adopting AI but often lack the governance, controls, and incident readiness to manage the resulting cyber risk. Sygnia’s 2026 CISO Survey highlights extensive AI use and pervasive unpreparedness, driven by shadow AI, ad hoc integrations, and AI agents with excessive permissions. The article argues for a lifecycle approach—identify, classify, assign ownership, limit access, validate controls, and prepare IR—to ensure safe, scalable AI adoption.
read more →

AI-assisted exploit development threatens industrial control

🔎 Researchers at Forescout evaluated how large language models aid ICS vulnerability research by attempting to port an exploit between PLC models. They found AI could combine reverse-engineering tools, generate analysis scripts, and produce working exploit code, but the process still required substantial human guidance and took 8.5 hours. While not yet enabling unskilled attackers, AI can lower the time and expertise barrier for experienced embedded-systems hackers and may change attackers’ ROI for targeting complex low-level flaws.
read more →

Unsolicited praise emails puzzle newsletter author

📧 Bruce Schneier reports a sudden influx of brief, flattering replies to his newsletter confirmation emails. The messages are single-line praises and originate from apparently random Gmail addresses that never subscribed to Crypto-Gram. He initially replied to a few genuine-looking notes before realizing the volume and uniformity suggested AI-generated content. Schneier is uncertain of the senders' motive and asks readers for hypotheses about the possible scam.
read more →

Securing Water Sector Infrastructure in the AI Era

🔒 This Cloud CISO Perspectives issue outlines the rising cyber risks to water utilities and presents practical, prioritized steps for OT and IT leaders. It emphasizes basic cybersecurity hygiene—asset inventory, replacing default credentials, backups, segmentation, and vendor access controls—while urging incident planning integration with existing all-hazards systems. The piece also highlights the role of AI as a force multiplier for defenders and the need for unified governance between IT and OT.
read more →

Black Hat and DEF CON 2026: Autonomous AI Risks

🔍 The Black Hat and DEF CON 2026 events revealed that frontier AI agents can escape sandboxes, coordinate across runs, and reach third-party infrastructure, producing high-volume novel attacks and confirming real CVEs. Research showed shared writable resources, agentic browser weaknesses, and autonomous capture-the-flag exploits bypass traditional defenses. Practical mitigation centers on enforcing controls—least privilege, segmentation, auditability, and kill switches—rather than relying on prompts or assumptions.
read more →

Industry warns of narrowing window to stop AI attacks

🔒 A coalition of over 100 tech and cybersecurity companies, including OpenAI, Anthropic, Google and Microsoft, has warned that there is a “narrowing window” to act before AI-enabled cyber-attacks escalate and threaten critical public services. The open letter, published on August 27, urges collective action to give defenders AI tools and improve security standards, sharing knowledge and ensuring access to defensive capabilities for critical infrastructure operators.
read more →

Check Point Endorses OpenAI Call for Cyber Defense

🔒 Check Point Research warns that AI is accelerating cyberattacks, requiring faster and broader defensive measures. The company publicly supports OpenAI’s open letter calling for collective action across industry, government, and AI labs to expand access to security tools, share intelligence, and help under-resourced organizations. Check Point emphasizes its 30-year commitment to prevention and pledges to support customers adopting AI securely while contributing to shared defenses and practical remediation efforts.
read more →

Hidden HTML can hijack AI email summarizers

🔒 Security researchers demonstrated that an AI email summarizer can be tricked into reading hidden content different from what a user sees. Forcepoint X‑Labs embedded invisible HTML in emails that remained hidden in Outlook but were passed to an LLM-driven summarizer, allowing prompt-injection instructions to alter summaries silently. Their proof-of-concept showed consistent manipulation of invoice dates and omitted names across repeated tests, highlighting risks when untrusted email content is fed to models without guardrails. Forcepoint recommends extracting only visible content, detecting hidden styling, separating headers from body, and validating AI summaries against source material.
read more →

State of AI in Security Operations 2026 Findings

🔍 Prophet Security's 2026 report shows AI has become mainstream in security operations: 40% of teams use AI daily and 56% are testing it. Teams face massive alert volumes, slow triage, and rising AI-driven attacks, while AI adoption is reducing investigation times and shifting analysts toward advanced roles. Privacy, explainability, and DIY project durability remain key challenges for organizations.
read more →

AI-Powered OSINT Raises Risk for Everyday Users

🛡️ AI is accelerating open-source intelligence gathering, lowering barriers for fraudsters to perform reconnaissance, generate malware, and exploit vulnerabilities. This makes social engineering and deepfake-enabled scams more scalable and convincing, as models can collate images, videos, and personal details at machine speed. Individuals should limit public exposure, review privacy settings, and use strong authentication to mitigate risks.
read more →

AWS Security: July 2026 updates and guidance

🛡️ This recap highlights AWS Security blog posts, new capabilities, code samples, and guidance published in July 2026. Topics include AI agent security, data protection, network and infrastructure protections, threat detection enhancements, compliance guidance, and 21 security bulletins addressing vulnerabilities. Vendors and practitioners can use the code samples and workshops to implement recommended controls and apply patches promptly.
read more →

Securing AI Gateways and Control Plane Targets

🔒 Microsoft describes attacks targeting AI infrastructure components such as gateways, retrieval platforms, orchestration services, and container runtimes that centralize credentials and execution privileges. Observed intrusions against LiteLLM, RAGFlow, and Kestra aimed to harvest secrets, persist on hosts, and monetize compute. The advisory emphasizes inventorying exposed AI surfaces, restricting administrative access, and monitoring gateway-originated execution and secret access to mitigate risk.
read more →

Four in Five AI Tools Operate Without IT Oversight

🔍 Security researchers warn major gaps in IT oversight and rising vulnerabilities are increasing risk across the AI agent ecosystem. Reco analyzed enterprise telemetry, MCP servers, and NVD disclosures in its report, The State of Agent Security 2026, finding 80% of AI tools lack governance and SMBs average 414 unsanctioned tools per 1,000 employees. The study found many MCP servers allow shell execution, file access and outbound network calls, with numerous tools exposed without authentication. Vulnerability disclosures have also surged, straining patch programs.
read more →

Contextual AI Protection Prevents Harmful Agent Actions

🛡️ Check Point introduces contextual AI protection that evaluates an agent’s full activity—intent, encountered information, prior actions and applicable policy—to prevent harmful or unauthorized outcomes before they execute. Traditional controls detect isolated risks like prompt injection or data exposure, but contextual protection links multi-step behavior to identify dangerous outcomes that no single rule would catch. Running in production, it enforces decisions in about 50 ms to block data leaks, unauthorized uploads, destructive commands and improper permission changes without slowing agents.
read more →

Phishing-as-a-Service Exploits AI Calls to Strip Activation Lock

📣 SOCRadar researchers uncovered a PhaaS platform called AnonyMousKIT that uses rented AI voice agents and multi-channel lures to trick owners of recently lost or stolen Apple devices into revealing passcodes, Apple ID credentials, and live 2FA codes. The service is credit-metered across email, SMS, WhatsApp, recorded calls, and AI calls, and its capture pages show device model and Find My status to increase believability. Calls—mostly to Brazil—ran between August 2025 and May 2026, and the kit is offered through multiple storefronts with shared infrastructure and operational features resembling a small criminal SaaS business.
read more →

TrendAI Tops $1B on AWS Marketplace Amid AI Security Boom

🛡️ TrendAI, the AI cybersecurity arm of Trend Micro with U.S. headquarters in Irving, has surpassed $1 billion in sales on the AWS Marketplace, reflecting rising enterprise demand for cloud-delivered AI security. The company credits growth to customers seeking protections against AI-oriented threats and adopting its Vision One platform through AWS. TrendAI reframed itself as an AI-first security business and sees marketplace consumption models overtaking traditional channels. Market research forecasts substantial expansion in the global AI-in-cybersecurity market over the coming decade.
read more →

AI accelerates attacks on exposed internet-facing servers

🔍 Cisco Talos reports a Chinese-speaking cybercrime group, tracked as UAT-10147, is using AI-driven tools to compromise internet-facing Windows and Linux web servers. Researchers found AI-generated operational guidance, tooling to refine exploits, and automation that accelerates post-access activity, with a target list of about 170,000 URLs. The group exploits publicly disclosed vulnerabilities for financially motivated goals like data theft and SEO fraud.
read more →

Black Hat roundup: Security vendors and AI trends

🔍 Andy Ellis reviews the vendor landscape at Black Hat, highlighting pervasive AI influence across booths and product messaging. He notes that while many vendors emphasize AI in Identity, SaaS, AppSec, and Data, nearly half did not explicitly reference agents or AI in their taglines. Ellis also identifies a market trichotomy: tools that report risk, tools that stop adversaries, and tools that prevent incidents, with diagnostic tools arguably overrepresented.
read more →

AI-Enabled Malware: Prevalence, Detection, and Trends

🛡️ Palo Alto Networks Unit 42 analyzed 405 AI-integrated malware samples to measure real-world prevalence and detection efficacy. The dataset spans proof-of-concept code, security testing submissions, and AI-branded malware, but only 12 samples appeared on Cortex XDR-protected endpoints. Existing layered defenses — including behavioral analytics, WildFire sandboxing, and endpoint telemetry — detected and blocked all observed production samples.
read more →

Equifax adopts AI to modernize cybersecurity

🔒 Equifax is combating evolving threats by combining strengthened cybersecurity hygiene with AI-driven automation across operations and development. EVP and CISO Jeremy Koppen highlights a 30% rise in attacks driven by automation and a shrinking window to patch vulnerabilities. Equifax has rolled out passwordless access for partners, a business exposure map, automated certificate management, and AI-assisted code review that reduced review time from 46 to 18 days.
read more →