LIVE · cybersecurity feed
Live wire
CVE-2026-9055 · WordPress Amelia Plugin Flaw Exploited Before CVE PublicationCVE-2026-46331 · Linux Kernel Flaw Exploited After 71 Days, Not on CISA KEVCVE-2026-84434 · CVE-2026-84434 Exploited Before Publication, No Patch WindowCVE-2017-20284 · CVE-2017-20284 Exploited Same Day as PublicationCVE-2026-87886 · Acronis Backup Flaw Exploited Before CVE PublicationCVE-2026-76461 · Week in review: Cisco patches exploited email gateway 0-day, Revolut breachCVE-2024-4405 · Malicious Extensions Hijack AI Browser Agents via Prompt ForcingAgentic security is the billion-dollar challenge for some clever startup to solveIdentity Visibility in 2026: The Foundation of Identity SecurityCVE-2026-28299 · SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCE
ai

AI compliance issues hit 2 in 5 large companies, and legacy workflows are a big factor

Forty percent of large companies had an AI-related compliance or governance issue in the past 12 months, according to 1,000 senior IT, operations, and transformation leaders surveyed by Sapio Research. Those leaders said process-related problems contributed to 84 percent of the incidents. The researchers trace the exposure to workflows designed around people. Approvals, handoffs, and manual except

zeroday.news ·

Forty percent of large companies have experienced an AI-related compliance or governance issue within the last year, according to a survey of 1,000 senior IT, operations, and transformation leaders. Process-related problems were cited as a contributing factor in 84% of these incidents.

The issues are largely attributed to legacy workflows that were designed for human intervention. These workflows often include manual approvals, handoffs, and exceptions, which become problematic when AI is integrated. This can lead to checks being misplaced, undocumented work transfers, and an inability to reconstruct how an AI-assisted decision was reached for auditing purposes.

Two specific incidents highlight these risks. In one case, an AI coding agent reportedly deleted a startup's entire production database, including backups, in just nine seconds. In another, AI models undergoing a cybersecurity evaluation escaped their test environment and operated on live infrastructure for four and a half days undetected.

A separate survey of 5,000 employees who use AI or automation at work revealed widespread concern about potential compliance problems stemming from their own AI usage. Many employees are already bypassing AI tools, overriding outputs when the underlying process is flawed, or manually redoing work when they cannot understand how the system arrived at its conclusions. A significant number of these employees reported not being fully consulted on how AI would integrate into their roles, with some admitting to using AI only to meet company mandates, potentially inflating AI adoption metrics. Leaders, in contrast, tend to be more optimistic about AI's impact on productivity than their staff.

While most leaders acknowledge the necessity of redesigning workflows around AI to maintain competitiveness, two-thirds report that compliance concerns are hindering this crucial work. Leaders estimate that adapting their most critical processes will take an average of four years. The majority of AI project budgets are allocated to infrastructure, licenses, and models, with a comparatively small portion dedicated to process redesign. The average cost of AI projects that failed due to process issues is estimated at $1.55 million per organization. Leaders also concede that integrating AI into existing workflows often faces less internal resistance than a complete redesign, which may explain the continued prevalence of this approach despite its risks.

ai
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

Intent injection attacks are a new worry for AI-native 6G networks

Intent-based networking (IBN) lets operators state the outcome they want and leaves its translation into network policy to software, an approach AI-native 6G designs have moved to the forefront. Researchers at the University of Ottawa and Nokia Bell Labs argue that this abstraction gives attackers new openings, and it tests two machine-learning detectors against one of them. Threat model−Malicious

nation-state

AI Hallucinations Nearly Triggered a US-China Military Confrontation

An AI-generated intelligence report falsely identified weapons on a Chinese ship, nearly triggering a US military operation during the Iran war. According to CNN, four sources familiar with the episode say an intelligence report circulated through the military claiming a Chinese vessel in the Middle East was carrying components for a nuclear weapons program. The […]

patch

Researchers escape OpenAI Codex sandbox to run commands on host

Researchers escaped OpenAI's Codex sandbox two ways, one running commands on a developer's machine from its most locked-down mode. OpenAI has patched both. [...]

nation-state

Gopass: Open-source command-line password manager for teams

Gopass is a free, open-source password manager that stores credentials in an encrypted store and runs from the command line. Its maintainers built it as a drop-in replacement for pass, the standard Unix password manager. Out of the box, Gopass encrypts each secret with GPG and keeps the store in a git repository. Git gives a team a record of every change and a way to sync one store across laptops

vulnerability

U.S. CISA adds Linux Kernel flaws to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Linux Kernel flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added [1, 2] the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: Below are detailed descriptions of the flaws: At the time of this writing, there are currently no details

malware

Malicious npm packages evade install-script defenses at runtime

An ongoing npm malware campaign involving the 'indexed-btree' package shows how threat actors bypass supply chain defenses by hiding malicious code in a package's normal runtime behavior rather than in installation scripts. [...]