AI

CISA lays out new guidance for using open-source software

CISA lays out new guidance for using open-source software 2026-08-03 at 14:53 By Anamarija Pogorelec The US Cybersecurity and Infrastructure Security Agency (CISA) has published the Open Source Software: Security Principles and Practices guide, which provides federal agencies with recommendations for managing the security of open source software, contributing to OSS projects, and evaluating open […]

CISA lays out new guidance for using open-source software Read More »

Mapping the malware blast radius a single alert won’t show you

Mapping the malware blast radius a single alert won’t show you 2026-08-03 at 09:00 By Mirko Zorz In this interview with Help Net Security, Mike Wiacek, founder and CTO of Stairwell, explains Backstory, an AI agent that takes a single alert and works outward to map how far a malware campaign spread. He walks through

Mapping the malware blast radius a single alert won’t show you Read More »

Google AI Uncovers 13-Year-Old Chrome Flaw Amid Record Patching Pace

Google AI Uncovers 13-Year-Old Chrome Flaw Amid Record Patching Pace 2026-07-31 at 13:28 By Ionut Arghire The internet giant has built an agent harness to find vulnerabilities across Chrome’s codebase. The post Google AI Uncovers 13-Year-Old Chrome Flaw Amid Record Patching Pace appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original

Google AI Uncovers 13-Year-Old Chrome Flaw Amid Record Patching Pace Read More »

EU to Crack Down on AI Deepfakes, Illicit Imagery and Hacking With New Team in Brussels

EU to Crack Down on AI Deepfakes, Illicit Imagery and Hacking With New Team in Brussels 2026-07-31 at 13:00 By Associated Press When the AI Act comes into force, AI companies will be required to make clear to consumers with labels or digital watermarks that chatbots or imagery are generated with AI. The post EU

EU to Crack Down on AI Deepfakes, Illicit Imagery and Hacking With New Team in Brussels Read More »

Anthropic’s Claude breached three companies during security tests

Anthropic’s Claude breached three companies during security tests 2026-07-31 at 12:41 By Sinisa Markovic Anthropic has disclosed that its AI model Claude gained unauthorized access to the systems of three different organizations during cybersecurity evaluations. The disclosure follows OpenAI’s July 21 announcement that some of its models had escaped an isolated testing environment by exploiting

Anthropic’s Claude breached three companies during security tests Read More »

Prompted by OpenAI Disclosure, Anthropic Finds Its Own Models Hacked 3 Organizations

Prompted by OpenAI Disclosure, Anthropic Finds Its Own Models Hacked 3 Organizations 2026-07-31 at 12:39 By Eduard Kovacs A security company’s systems were hacked after it installed a malicious Python package deployed by Claude.  The post Prompted by OpenAI Disclosure, Anthropic Finds Its Own Models Hacked 3 Organizations appeared first on SecurityWeek. This article is

Prompted by OpenAI Disclosure, Anthropic Finds Its Own Models Hacked 3 Organizations Read More »

Companies push AI, sysadmins keep it on a short leash

Companies push AI, sysadmins keep it on a short leash 2026-07-31 at 08:00 By Anamarija Pogorelec In 2024, sysadmins expected AI to automate patch management optimization, vulnerability prioritization, infrastructure monitoring, and incident response within two years. Action1’s 2026 Survey Report: AI Impact on Sysadmins found that those expectations proved overly optimistic. The largest shortfalls appeared

Companies push AI, sysadmins keep it on a short leash Read More »

AI agents are changing where cybersecurity seed funding lands

AI agents are changing where cybersecurity seed funding lands 2026-07-31 at 07:30 By Anamarija Pogorelec Founders pitching a cybersecurity seed round this summer are joining a line that keeps getting longer. Product Hunt launches hit their highest level since late 2023 last quarter, and the Census Bureau’s count of high-propensity business applications kept climbing. Seed

AI agents are changing where cybersecurity seed funding lands Read More »

AI takes on a bigger role in finding Chrome vulnerabilities

AI takes on a bigger role in finding Chrome vulnerabilities 2026-07-30 at 20:01 By Sinisa Markovic Google has expanded the use of AI in Chrome’s security workflow, using it to find vulnerabilities, triage bug reports, generate patches, and review code to shorten the time between discovering software flaws and delivering security updates. “Historically, triaging a

AI takes on a bigger role in finding Chrome vulnerabilities Read More »

Timeless Compliance: Why Better Questions Beat Bigger Frameworks

Timeless Compliance: Why Better Questions Beat Bigger Frameworks 2026-07-30 at 18:46 By Matt Honea The best compliance programs aren’t the biggest ones. They’re the ones built on a short list of questions that can actually be answered, and that still hold true when the models change. The post Timeless Compliance: Why Better Questions Beat Bigger

Timeless Compliance: Why Better Questions Beat Bigger Frameworks Read More »

CISA sets a new SBOM baseline

CISA sets a new SBOM baseline 2026-07-30 at 15:23 By Anamarija Pogorelec The US Cybersecurity and Infrastructure Security Agency (CISA), together with its co-authoring partners, has released the 2026 Minimum Elements for a Software Bill of Materials (SBOM), replacing the 2021 guidance published by the National Telecommunications and Information Administration (NTIA). An SBOM is a

CISA sets a new SBOM baseline Read More »

Critical Ruflo Flaw Lets Attackers Spawn Rogue AI Swarms 

Critical Ruflo Flaw Lets Attackers Spawn Rogue AI Swarms  2026-07-30 at 12:56 By Ionut Arghire Unauthenticated attackers could send HTTP requests to an exposed endpoint to execute commands inside the MCP bridge container. The post Critical Ruflo Flaw Lets Attackers Spawn Rogue AI Swarms  appeared first on SecurityWeek. This article is an excerpt from SecurityWeek

Critical Ruflo Flaw Lets Attackers Spawn Rogue AI Swarms  Read More »

Data breach cost 2026 averaged $4.99 million, AI attacks ran higher

Data breach cost 2026 averaged $4.99 million, AI attacks ran higher 2026-07-30 at 09:15 By Mirko Zorz More than one in four organizations hit by a malicious attack over the past year say AI drove it. Those breaches averaged about $1 million above the malicious attacks that ran without AI. Defenders bought similar technology and

Data breach cost 2026 averaged $4.99 million, AI attacks ran higher Read More »

OpenAI’s Rogue AI Ventured Beyond Hugging Face

OpenAI’s Rogue AI Ventured Beyond Hugging Face 2026-07-29 at 13:10 By Eduard Kovacs Hugging Face has published an anatomy of the attack and OpenAI has shared additional information from its investigation. The post OpenAI’s Rogue AI Ventured Beyond Hugging Face appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

OpenAI’s Rogue AI Ventured Beyond Hugging Face Read More »

JFrog Zero-Days Exploited in OpenAI-Hugging Face Hack

JFrog Zero-Days Exploited in OpenAI-Hugging Face Hack 2026-07-29 at 11:46 By Ionut Arghire The OpenAI models targeted services beyond Hugging Face as they attempted to solve the tasks they were given. The post JFrog Zero-Days Exploited in OpenAI-Hugging Face Hack appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

JFrog Zero-Days Exploited in OpenAI-Hugging Face Hack Read More »

Your AI agents can reach data no one approved

Your AI agents can reach data no one approved 2026-07-29 at 07:30 By Mirko Zorz A credential expired. An AI agent kept using it anyway, and a mid-sized company’s systems went down for a quarter’s worth of trouble before anyone traced the failure back to a non-human account no one had been logging. That agent

Your AI agents can reach data no one approved Read More »

Microsoft Unveils MAI-Cyber-1-Flash, Its First Cybersecurity AI Model 

Microsoft Unveils MAI-Cyber-1-Flash, Its First Cybersecurity AI Model  2026-07-28 at 14:11 By Eduard Kovacs The company claims MAI-Cyber-1-Flash tops Anthropic’s Mythos and OpenAI’s GPT-5.6 Sol in CyberGym testing. The post Microsoft Unveils MAI-Cyber-1-Flash, Its First Cybersecurity AI Model  appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Microsoft Unveils MAI-Cyber-1-Flash, Its First Cybersecurity AI Model  Read More »

VERITAS project could change the way scientists secure AI

VERITAS project could change the way scientists secure AI 2026-07-28 at 14:02 By Sinisa Markovic The AI models, datasets, and automated systems researchers depend on can be compromised in ways conventional cybersecurity tools aren’t designed to detect. A new project called VERITAS (VERified Infrastructure for Trustworthy AI in Science) aims to close that gap by

VERITAS project could change the way scientists secure AI Read More »

Hush Security Raises $30 Million for AI Agent Governance

Hush Security Raises $30 Million for AI Agent Governance 2026-07-28 at 13:17 By Ionut Arghire The startup will invest in expanding engineering and sales teams, accelerating ecosystem support, and expanding corporate partnerships. The post Hush Security Raises $30 Million for AI Agent Governance appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View

Hush Security Raises $30 Million for AI Agent Governance Read More »

Shadow AI incident response begins with logs that may already be gone

Shadow AI incident response begins with logs that may already be gone 2026-07-28 at 09:00 By Mirko Zorz In this Help Net Security interview, Brandy Wityak, VP of Complex Matters at LevelBlue, explains what happens in the hours after a shadow AI incident. She describes how quickly logs roll over, why firewall records of outbound

Shadow AI incident response begins with logs that may already be gone Read More »

Scroll to Top