LLMs

LLMs are automating the human part of romance scams

LLMs are automating the human part of romance scams 2025-12-29 at 09:03 By Sinisa Markovic Romance scams succeed because they feel human. New research shows that feeling no longer requires a person on the other side of the chat. The three stages of a romance-baiting scam Romance scams depend on scripted conversation Romance baiting scams […]

LLMs are automating the human part of romance scams Read More »

LLMs can assist with vulnerability scoring, but context still matters

LLMs can assist with vulnerability scoring, but context still matters 2025-12-26 at 08:26 By Sinisa Markovic Every new vulnerability disclosure adds another decision point for already stretched security teams. A recent study explores whether LLMs can take on part of that burden by scoring vulnerabilities at scale. While the results show promise in specific areas,

LLMs can assist with vulnerability scoring, but context still matters Read More »

Governance maturity defines enterprise AI confidence

Governance maturity defines enterprise AI confidence 2025-12-24 at 08:17 By Anamarija Pogorelec AI security has reached a point where enthusiasm alone no longer carries organizations forward. New Cloud Security Alliance research shows that governance has become the main factor separating teams that feel prepared from those that do not. Governance separates confidence from uncertainty Governance

Governance maturity defines enterprise AI confidence Read More »

DIG AI: Uncensored darknet AI assistant at the service of criminals and terrorists

DIG AI: Uncensored darknet AI assistant at the service of criminals and terrorists 2025-12-22 at 13:00 By Help Net Security Resecurity has identified the emergence of uncensored darknet AI assistants, enabling threat actors to leverage advanced data processing capabilities for malicious purposes. One of these – DIG AI – was identified on September 29 of

DIG AI: Uncensored darknet AI assistant at the service of criminals and terrorists Read More »

Browser agents don’t always respect your privacy choices

Browser agents don’t always respect your privacy choices 2025-12-22 at 08:49 By Sinisa Markovic Browser agents promise to handle online tasks without constant user input. They can shop, book reservations, and manage accounts by driving a web browser through an AI model. A new academic study warns that this convenience comes with privacy risks that

Browser agents don’t always respect your privacy choices Read More »

AI isn’t one system, and your threat model shouldn’t be either

AI isn’t one system, and your threat model shouldn’t be either 2025-12-19 at 09:02 By Mirko Zorz In this Help Net Security interview, Naor Penso, CISO at Cerebras Systems, explains how to threat model modern AI stacks without treating them as a single risk. He discusses why partitioning AI systems by function and impact matters,

AI isn’t one system, and your threat model shouldn’t be either Read More »

LLMs work better together in smart contract audits

LLMs work better together in smart contract audits 2025-12-19 at 08:42 By Sinisa Markovic Smart contract bugs continue to drain real money from blockchain systems, even after years of tooling and research. A new academic study suggests that large language models can spot more of those flaws when they work in coordinated groups instead of

LLMs work better together in smart contract audits Read More »

Privacy risks sit inside the ads that fill your social media feed

Privacy risks sit inside the ads that fill your social media feed 2025-12-18 at 08:34 By Sinisa Markovic Regulatory limits on explicit targeting have not stopped algorithmic profiling on the web. Ad optimization systems still adapt which ads appear based on users’ private attributes. At the same time, multimodal LLMs have lowered the barrier for

Privacy risks sit inside the ads that fill your social media feed Read More »

AI might be the answer for better phishing resilience

AI might be the answer for better phishing resilience 2025-12-16 at 08:44 By Sinisa Markovic Phishing is still a go-to tactic for attackers, which is why even small gains in user training are worth noticing. A recent research project from the University of Bari looked at whether LLMs can produce training that helps people spot

AI might be the answer for better phishing resilience Read More »

LLM privacy policies keep getting longer, denser, and nearly impossible to decode

LLM privacy policies keep getting longer, denser, and nearly impossible to decode 2025-12-12 at 08:30 By Sinisa Markovic People expect privacy policies to explain what happens to their data. What users get instead is a growing wall of text that feels harder to read each year. In a new study, researchers reviewed privacy policies for

LLM privacy policies keep getting longer, denser, and nearly impossible to decode Read More »

LLM vulnerability patching skills remain limited

LLM vulnerability patching skills remain limited 2025-12-11 at 08:47 By Sinisa Markovic Security teams are wondering whether LLMs can help speed up patching. A new study tests that idea and shows where the tools hold up and where they fall short. The researchers tested LLMs from OpenAI, Meta, DeepSeek, and Mistral to see how well

LLM vulnerability patching skills remain limited Read More »

LLMs are everywhere in your stack and every layer brings new risk

LLMs are everywhere in your stack and every layer brings new risk 2025-12-10 at 07:52 By Mirko Zorz LLMs are moving deeper into enterprise products and workflows, and that shift is creating new pressure on security leaders. A new guide from DryRun Security outlines how these systems change long standing assumptions about data handling, application

LLMs are everywhere in your stack and every layer brings new risk Read More »

AI agents break rules in unexpected ways

AI agents break rules in unexpected ways 2025-12-09 at 08:31 By Mirko Zorz AI agents are starting to take on tasks that used to be handled by people. These systems plan steps, call tools, and carry out actions without a person approving every move. This shift is raising questions for security leaders. A new research

AI agents break rules in unexpected ways Read More »

NVIDIA research shows how agentic AI fails under attack

NVIDIA research shows how agentic AI fails under attack 2025-12-08 at 09:56 By Sinisa Markovic Enterprises are rushing to deploy agentic systems that plan, use tools, and make decisions with less human guidance than earlier AI models. This new class of systems also brings new kinds of risk that appear in the interactions between models,

NVIDIA research shows how agentic AI fails under attack Read More »

AI vs. you: Who’s better at permission decisions?

AI vs. you: Who’s better at permission decisions? 2025-12-04 at 08:04 By Sinisa Markovic A single tap on a permission prompt can decide how far an app reaches into a user’s personal data. Most of these calls happen during installation. The number of prompts keeps climbing, and that growing pressure often pushes people into rushed

AI vs. you: Who’s better at permission decisions? Read More »

Social data puts user passwords at risk in unexpected ways

Social data puts user passwords at risk in unexpected ways 2025-11-28 at 09:08 By Anamarija Pogorelec Many CISOs already assume that social media creates new openings for password guessing, but new research helps show what that risk looks like in practice. The findings reveal how much information can be reconstructed from public profiles and how

Social data puts user passwords at risk in unexpected ways Read More »

Small language models step into the fight against phishing sites

Small language models step into the fight against phishing sites 2025-11-26 at 08:31 By Sinisa Markovic Phishing sites keep rising, and security teams are searching for ways to sort suspicious pages at speed. A recent study explores whether small language models (SLMs) can scan raw HTML to catch these threats. The work reviews a range

Small language models step into the fight against phishing sites Read More »

DeepTeam: Open-source LLM red teaming framework

DeepTeam: Open-source LLM red teaming framework 2025-11-26 at 07:37 By Sinisa Markovic Security teams are pushing large language models into products faster than they can test them, which makes any new red teaming method worth paying attention to. DeepTeam is an open-source framework built to probe these systems before they reach users, and it takes

DeepTeam: Open-source LLM red teaming framework Read More »

BlueCodeAgent helps developers secure AI-generated code

BlueCodeAgent helps developers secure AI-generated code 2025-11-20 at 08:05 By Sinisa Markovic When AI models generate code, they deliver power and risk at the same time for security teams. That tension is at the heart of the new tool called BlueCodeAgent, designed to help developers and security engineers defend against code-generation threats. Why code generation

BlueCodeAgent helps developers secure AI-generated code Read More »

The long conversations that reveal how scammers work

The long conversations that reveal how scammers work 2025-11-19 at 09:08 By Sinisa Markovic Online scammers often take weeks to build trust before making a move, which makes their work hard to study. A research team from UC San Diego built a system that does the patient work of talking to scammers at scale, and

The long conversations that reveal how scammers work Read More »

Scroll to Top