Tag: ai security
144 articles

Lloyds Banking Group Unveils Hands-On Approach to Securing Agentic AI
Lloyds Banking Group is taking a proactive approach to securing agentic AI, recognizing that understanding AI itself is crucial to embedding security into its adoption. The bank has made security a top priority, framing it as a deliberate technical strategy that spans the entire AI lifecycle.

Secure Infrastructure Unlocks AI's Defense Potential
As Dave Wajsgras, chairman and CEO of Everfox, aptly puts it, AI's trustworthiness is only as strong as the security of its underlying data, networks, and access controls. A recent incident involving Anthropic's Claude Mythos model serves as a stark reminder of the risks, with an unauthorized group reportedly gaining access in mere hours.

Pentagon Integrates Cyber into Operations, Prioritizes AI Security
The Pentagon is revolutionizing its approach to cyber operations, shifting away from treating it as a separate entity and instead weaving it into every military operation from the ground up. By doing so, the Defense Department aims to harness the full power of information on the battlefield, with AI security at the forefront of this strategic evolution.

Browser Becomes Front Line in AI Security Battle
The battle for AI security is heating up, and the browser has become the front line - with security teams facing a double threat of AI-powered attacks converging in this critical space. Attackers are leveraging AI to supercharge phishing techniques, including device code phishing kits that have surged 18x in just one year.

OWASP Launches Agentic Research Council to Tackle AI Security Gap
OWASP's new Agentic Research Council is set to revolutionize AI security by bridging the gap between rapidly evolving AI capabilities and lagging security research, bringing expert-backed solutions to the forefront. By uniting research and practice, the council aims to empower cybersecurity practitioners, developers, and leaders to stay ahead of emerging threats.

ChatGPT Vulnerability Exposes Users to Phishing Attacks via Web Summaries
Beware of ChatGPhish, a vulnerability in ChatGPT's web summarization feature that lets hackers disguise phishing attacks as harmless links and images. This security flaw could put you at risk of falling prey to scams via web summaries.

ChatGPT Exposes Users to Prompt Injection Attacks via Browser Content
Researchers have uncovered a vulnerability in ChatGPT that leaves users open to prompt injection attacks, where malicious content is embedded into web pages and then summarized by the AI system as legitimate information. This loophole could put users at risk of falling prey to spoofed security alerts and other online threats.

Snowflake Bolsters AI Security with Natoma Acquisition
Snowflake is supercharging its AI security with the acquisition of Natoma, empowering users to tackle everyday tasks like sending emails and checking calendars without leaving Snowflake Intelligence or Coco. This move is part of Snowflake's vision for an "agentic control plane," where AI agents can take actions across business systems while keeping security controls firmly in place.

OpenAI Bolsters Cybersecurity, Election Integrity with 2026 Midterm Safeguards
OpenAI is stepping up its game to safeguard the 2026 midterm elections with a robust five-part plan to combat AI-driven interference and bolster cybersecurity. The company is committed to protecting digital infrastructure and promoting election integrity by spreading reliable information, watermarking deepfakes, and more.

Executives' Blind Spot: Shadow AI Use Exposes Security Risks
Most organizations have a blind spot when it comes to AI usage, leaving them vulnerable to security risks - and the truth is, you can't protect what you can't see. A recent study by Okta and Apprize360 found that shadow AI use is rampant, exposing companies to potential breaches, data exposures, and system disruptions.

Russian Hacker Exploits Jailbroken AI in Crypto Fraud Scheme
A solo Russian hacker, known as bandcampro, has orchestrated a massive crypto fraud scheme, reaching 17,000 subscribers on Telegram with AI-generated content that convincingly mimicked popular conspiracy styles. This alarming development marks a turning point in cybercrime conspiracies, with AI-powered threats on the rise.

Trump Delays AI Security Order Amid Industry Competition Concerns
President Donald Trump has delayed an executive order aimed at regulating frontier AI models, citing concerns over certain aspects of the proposal, which would have required a 90-day testing and vetting regime for new AI models. The order would have allowed federal agencies to study new models before public release and facilitated access for cybersecurity testers.

Measuring AI Security Effectiveness Proves Elusive
Measuring AI security effectiveness is a complex challenge that can't be reduced to a single score or benchmark. Relying on benchmarks alone simply doesn't work when it comes to safeguarding AI systems.

Microsoft Bolsters AI Security with Open-Source RAMPART and Clarity Tools
Microsoft's new open-source tools, RAMPART and Clarity, empower product managers and engineers to stress-test AI security assumptions early on, saving months of potential rework and costly mistakes. With RAMPART, developers can write and run safety tests to identify vulnerabilities in AI agents, covering both adversarial and benign threats.

OpenClaw Flaw Enables Hackers to Hijack AI Agents
A newly discovered flaw in OpenClaw, dubbed the Claw Chain, allows hackers to hijack AI agents and use their privileges to gain persistent control of an environment. By exploiting this vulnerability, attackers can escalate privileges, access sensitive data, and maintain a foothold within the system.

Security Researchers Exploit 47 Zero-Days for $1.3 Million at Pwn2Own Berlin
In a stunning display of cybersecurity prowess, researchers at Pwn2Own Berlin 2026 exploited a whopping 47 zero-day flaws, raking in a total of $1.3 million in just three days. The competition saw contestants disclose and exploit vulnerabilities in top enterprise and AI-facing products, earning daily payouts of $523,000, $385,750, and $389,500.

SecurityScorecard Bolsters Internet Visibility with Driftnet Acquisition
SecurityScorecard has acquired Driftnet, an internet scanning startup, to supercharge its third-party risk management capabilities with deeper, real-time visibility into internet infrastructure and hidden exposures. This strategic move allows SecurityScorecard to directly control data quality and drive future innovation in AI security.

Securing Autonomous AI Requires New Risk Strategies
Autonomous AI agents are revolutionizing enterprise environments with lightning-fast speed, unprecedented autonomy, and access to sensitive systems and data - but many security teams lack the visibility and control to manage the resulting risks. This game-changing technology is rapidly expanding the enterprise attack surface, demanding new risk strategies to stay ahead.

TeamPCP hackers target Mistral AI code repos for sale
Hackers from TeamPCP are demanding $25,000 for nearly 5 gigabytes of stolen Mistral AI code, threatening to leak it for free if they don't find a buyer within a week. The group claims to have snagged around 450 internal repositories, including sensitive source code used for training and model delivery.

OpenAI's GPT-5.5 Matches Mythos in Security Vulnerability Detection
The UK's AI Security Institute just put GPT-5.5 to the test, and the results are impressive: it can detect security vulnerabilities on par with the highly-regarded Claude Mythos. This achievement is especially significant since GPT-5.5 is widely available for use.

Claude Code Attack Persists Through Token Rotation Flaw
A surprising lack of resistance to a proof-of-concept attack has exposed a vulnerability in Claude Code, allowing a five-step attack chain that can turn routine token rotation into a continuous compromise. This exploit requires just one malicious npm package and the ability to run code on a developer's machine, making it a concerning threat.

G7 Guidance Sets AI Security Standards
The G7 has set a new benchmark for AI security with the release of voluntary guidelines, outlining the minimum requirements for transparency around AI system components. This move aims to establish a common baseline for the industry, promoting trust and safety in the rapidly evolving AI landscape.

Security Teams Lag Behind on Agentic AI Risks
The alarming truth is that agentic AI is already live in many production environments, but security teams are largely in the dark about the risks they're facing. This emerging threat can be categorized into three key areas: coding and productivity agents like Claude Code and GitHub Copilot, vendor-built agents, and custom-built agents.

Hugging Face Repository Exploits Typosquatting to Spread Infostealer Malware
Security researchers have uncovered a cunning malware attack on Hugging Face, where a fake repository mimicked a popular AI project, racking up over 244,000 downloads and 667 likes in just 18 hours. The malicious repository used a classic typosquatting trick to deceive users searching for the genuine project.