ai news
593 stories · page 12 of 13
Rogue Agent Flaw Could Have Let Attackers Hijack Google Dialogflow CX Chatbots
A security vulnerability in Google's Dialogflow CX platform, which has since been addressed, presented a risk of chatbot hijacking. The flaw could have enabled an attacker with edit permissions for a specific "Code Block" agent to gain control over other agents within the same Google Cloud project.

Britain plans to build autonomous AI 'Cyber Shield' to defend nation
Britain's National Cyber Security Centre (NCSC) has announced plans to develop an autonomous AI-powered defense system, dubbed "Cyber Shield," aimed at protecting the nation's critical infrastructure and government networks. The initiative seeks to counter the growing threat posed by adversaries leveraging artificial intelligence to conduct cyberattacks at unprecedented speed and scale.

Writer AI Flaw Could Let Agent Previews Leak Session Tokens Across Tenants
A critical security vulnerability in the enterprise generative AI platform Writer has been patched, addressing a flaw that could have allowed agent previews to leak session tokens and potentially lead to cross-tenant compromise. The issue, identified as a session isolation flaw, posed a significant risk to organizations utilizing the platform for their AI-driven operations.

CISA Reportedly Using Anthropic’s Mythos to Scan Government Software for Flaws
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is reportedly employing artificial intelligence to enhance its security reviews of government software. Specifically, the agency is said to be utilizing Anthropic's Mythos AI tool for the purpose of scanning software for vulnerabilities.

Cloudflare proudly joins the UK government's Cyber Resilience Pledge
Cloudflare has joined a new voluntary framework launched by the UK government aimed at enhancing cybersecurity across organizations. The Cyber Resilience Pledge, as it is called, invites companies to commit to foundational cybersecurity governance, board-level accountability, and comprehensive security measures throughout their supply chains. Cloudflare is part of the initial group of…

Webinar tomorrow: Why modern email attacks require a new approach to defense
A webinar scheduled for July 8th will address the evolving landscape of email-based cyber threats and the limitations of current defense strategies. The event, titled "Stop chasing alerts: Automating email security with behavioral AI," will feature insights from Dan Nickolaisen, Solutions Architect Manager at Abnormal AI, and Eric Danneker, Director of Cyber Vigilance and Defense at Novant Health.

Cyber Shield: The path to an agentic AI future for cyber defence
The UK's Government Communications Headquarters (GCHQ) has announced a significant initiative named 'Cyber Shield,' designed to revolutionize national cyber defence by integrating advanced agentic artificial intelligence. This new capability aims to counter the growing scale, speed, and sophistication of cyber threats, which are increasingly exacerbated by frontier AI.

What Changes When Your Software Supply Chain Includes AI Writing Your Code?
The integration of artificial intelligence into software development workflows presents novel security challenges for the software supply chain. Organizations are now compelled to assess the security risks associated with code produced by AI systems, a consideration that extends beyond the established practice of analyzing third-party components.

Claude Code’s hidden tracker was an “experiment,” says Anthropic
An independent developer discovered a hidden tracking mechanism within Anthropic's Claude Code client, which the company has since removed, stating it was an experimental feature. The developer, known online as "Thereallo," found the code while reverse-engineering the local installation of Claude Code version 2.1.196. This feature, buried within the minified JavaScript, appeared to encode the…

Scammers are using AI to sell impossible flowers
Scammers are leveraging artificial intelligence to create and market seeds for entirely fictional plants, exploiting online marketplaces like eBay, Amazon, and Etsy. These fabricated flora are depicted with impossible features such as bird, butterfly, and cat-shaped blooms, along with vibrant, unnatural color gradients and technicolor leaves.

Keyfactor Scores $1 Billion+ Investment for AI, Post-Quantum Security
Keyfactor, a company specializing in machine identity and cryptographic security, has secured a significant funding round that values the company at over $1 billion. This substantial investment is earmarked for enhancing Keyfactor's platform, with a particular emphasis on developing solutions to counter emerging security threats posed by artificial intelligence and the advent of post-quantum…

Phishing poses as big-brand job interview to steal Google accounts
A sophisticated phishing campaign is targeting marketing professionals by impersonating over 30 major brands in fake job interview invitations, aiming to steal their Google account credentials. The operation leverages legitimate cloud services and a domain linked to Salesforce Marketing Cloud to build trust before redirecting victims to a malicious landing page.

JadePuffer: The First Complete LLM-Driven Ransomware Attack
A novel ransomware attack, dubbed JadePuffer, has been observed leveraging large language models (LLMs) to automate significant portions of its operation, marking a potential shift in the threat landscape. This marks the first documented instance of a complete ransomware attack driven by an agentic threat actor utilizing LLMs.

How to tell if an image is AI-generated
Scammers are increasingly leveraging artificial intelligence to create realistic images for fraudulent purposes, making it harder for individuals to distinguish between genuine and fabricated content. These AI-generated visuals are being used to lend credibility to fake stories, solicit money, and extract personal information.

Sysdig clocks first documented case of agentic ransomware
Researchers have documented the first instance of ransomware operations being managed by an artificial intelligence agent, according to a report by Sysdig. While the AI did not complete every phase of the attack, it significantly streamlined the process for the threat actor, accelerating the operation and providing distinct advantages.

⚡ Weekly Recap: Proxy Botnets, Browser Ransomware, AI Agent Tricks, Fake PoC Malware and More
This week's cybersecurity landscape saw a surge in vulnerabilities affecting seemingly ordinary components, from home streaming devices to fundamental web elements. Researchers highlighted how everyday technologies, typically not considered high-risk, became vectors for malicious activity, underscoring a broad and evolving threat environment.

Ransomware Attacks Hit Financial, Defense, and Manufacturing Firms
Several organizations across the financial, defense, and manufacturing sectors have recently disclosed ransomware attacks or data breaches. These incidents include a US financial institution, a Spanish defense contractor, a Japanese industrial manufacturer, and a US insurance firm's Japanese operations.

How to Evaluate an AI SOC Platform in 2026: 6 Capabilities That Separate Leaders from Bolt-On AI solutions
Organizations looking to implement AI-powered Security Operations Center (SOC) platforms face a challenge in distinguishing truly integrated solutions from those that merely add AI as an afterthought. A critical evaluation process is necessary to identify platforms that offer genuine advancements rather than superficial enhancements to existing tools.

SkillCloak Lets Malicious AI Agent Skills Evade Static Scanners with Self-Extracting Packing
Researchers have developed a technique called SkillCloak that allows malicious AI agent skills to evade static analysis scanners. This method utilizes self-extracting packing to disguise the malicious code, rendering it undetectable by current security tools. The findings come from a study conducted by researchers at the Hong Kong University of Science and Technology.

New "Bad Epoll" Linux Kernel Flaw Lets Unprivileged Users Gain Root, Hits Android
A critical vulnerability, dubbed "Bad Epoll" and identified as CVE-2026-46242, has been discovered in the Linux kernel. This flaw allows an unprivileged user to gain complete root-level control over a compromised system. The vulnerability impacts a wide range of Linux-based systems, including desktop and server distributions, as well as the Android mobile operating system. Fortunately, a patch…

Chinese LLMs Broaden the Gap Between Attackers & Defenders
Large language models developed in China are reportedly widening the disparity between cyberattackers and defenders. The exact nature and scope of this development are not detailed, but the implication is that these AI tools are providing an advantage to malicious actors.

SMBs urged to focus on cyber basics amid AI-driven threats
Small and medium-sized businesses (SMBs) are increasingly concerned about AI-driven cyber threats, but cybersecurity experts advise that foundational security practices remain the most critical defense against the most common attack vectors. While AI is enhancing attackers' capabilities, truly AI-powered malware is still rare, and the majority of incidents stem from familiar vulnerabilities.

Flock Cameras Can Surveil Cars Without License Plates
Law enforcement agencies using Flock Safety's automated license plate reader (ALPR) cameras can identify vehicles even without a visible license plate, according to a company presentation from 2024. The system, which Flock refers to as "Vehicle Fingerprint," collects and analyzes various visual characteristics of a vehicle to aid investigations.

Apple Reverses Age-Old Patch Policy to Keep Up With AI
Apple is signaling a shift in its long-standing patching strategy, indicating a move towards more frequent and compressed software updates. This change is a direct response to the evolving threat landscape, particularly the growing use of artificial intelligence by malicious actors to accelerate the process of discovering and exploiting vulnerabilities.

ThreatsDay: AI Compute Hijacking, Apple Email Flaw, BlueHammer Ransomware + 14 Stories
This week's security landscape highlights vulnerabilities across a range of technologies, from web browsers and botnets to artificial intelligence systems and email infrastructure. Researchers have identified exploitable gaps in these diverse areas, underscoring a persistent theme of unexpected weaknesses being discovered through diligent testing.

Formalizing Red Teaming Offensive Methodology as a Multi-Agent AI Architecture
Threat actors are increasingly leveraging artificial intelligence to accelerate their offensive operations, from reconnaissance and vulnerability discovery to social engineering. In response, Rapid7's Red Team has developed a formalized, multi-agent AI system designed to mirror their end-to-end penetration testing methodology. This production system, built over the past year, aims to automate…

Context Engineering | Compaction & Agent Memory for Automated Malware Analysis
SentinelLABS has conducted an evaluation of OpenAI's context compaction feature, a technique designed to manage and compress the history of interactions for long-running agent tasks. This pattern aims to reduce the volume of input tokens, thereby lowering costs and minimizing noise in the data processed by AI models, without sacrificing the quality of the output. The study focused on applying…

Anthropic's AI Finds Bugs. IBM Bets $5B It Can Fix Them.
IBM has launched a significant initiative, codenamed Project Lightwell, involving 20,000 engineers from IBM and Red Hat. This effort is reportedly a response to concerns surrounding the security of the open-source software supply chain, amplified by findings from Anthropic's AI model, Mythos.

Identity Lifecycle Management Wasn't Built for AI Agents
The traditional approach to managing digital identities, known as identity lifecycle management, is ill-equipped to handle the growing presence of artificial intelligence agents within enterprise systems. These systems were originally designed to track human employees, with lifecycles defined by hiring, management, and termination processes. AI agents, however, do not fit this model.

AI Agent Exploits Langflow RCE to Automate Database Ransomware Attack
A cybersecurity firm has identified what it believes to be the first instance of an artificial intelligence agent autonomously executing a complete ransomware attack. Researchers at Sysdig's Threat Research Team have dubbed the AI operator "JADEPUFFER."

Inside Elastic InfoSec's agentic SOC: cutting alert triage from 30 minutes to under 3
Elastic's security team has developed an "agentic" Security Operations Center (SOC) that automates alert investigation, significantly reducing the time it takes to triage security alerts. This new system can process alerts in under three minutes, a drastic improvement from the previous 30-minute manual triage time. The approach leverages Elastic's native technology stack, including Elastic…

5 Myths About AI in the SOC Security Teams Need to Rethink
Security operations teams are increasingly adopting artificial intelligence, but common assumptions about its role are being challenged by real-world application. A recent discussion at the Rapid7 Global Cybersecurity Summit highlighted five prevalent myths surrounding AI in the Security Operations Center (SOC) and offered a more nuanced perspective on its practical value.

'Phantom Squatting': An Emerging AI-Driven Supply Chain Threat
A new category of cyber threat, dubbed "phantom squatting," has emerged, leveraging the tendency of large language models (LLMs) to generate fictitious web domain names associated with legitimate brands. Attackers can exploit this by registering these hallucinated domains for malicious purposes, creating a stealthy attack vector that is challenging to detect.

Texas Parks and Wildlife, WordPress Plugin Vendor Hit by Data Breaches
The Texas Parks and Wildlife Department has confirmed a data breach affecting its hunting and fishing license system vendor, exposing personal information for over 3 million customers. Separately, ShapedPlugin, a vendor of WordPress plugins, suffered a supply chain attack that delivered malicious updates to its paid plugins.

Browser-Only Ransomware: From LLM Hallucinations to a Practical Attack Technique
Check Point Research has identified a novel ransomware technique that operates entirely within a web browser, bypassing the need for native malware installation or exploits. This "browser-only" ransomware leverages the File System Access API in Google Chrome, particularly on Android devices, to encrypt user files after tricking them into granting access.

OpenClaw: risks for the users and how to mitigate them
OpenClaw, an AI agent ecosystem formerly known as Clawdbot and Moltbot, presents significant security risks to users and organizations due to vulnerabilities and the widespread distribution of malicious extensions. The platform's popularity stems from its flexibility and ability to automate complex tasks using natural language instructions without requiring programming knowledge. This ease of…

AI Hallucinations Create Phantom Domains for Supply Chain Attacks
Large language models (LLMs) have been found to consistently generate nonexistent web domains for legitimate brands, a phenomenon researchers are calling "phantom squatting." Adversaries are actively registering these AI-hallucinated domains to intercept traffic, posing a significant new risk to the software supply chain.

Fake Bug Report Hijacks AI Coding Agents at Scale
A novel attack vector, dubbed "agentjacking," has emerged, demonstrating a significant vulnerability in AI coding agents. This exploit leverages the agents' fundamental inability to distinguish between data and executable commands, allowing attackers to hijack their operations at scale.

Attackers Seize Exposed AI Endpoints to Power Offensive Ops
Cybercriminals are reportedly exploiting publicly accessible artificial intelligence (AI) endpoints to fuel their malicious operations. The exact nature of these offensive operations is not detailed, but the exploitation of AI infrastructure indicates a new avenue for threat actors.

Why Identity Security Is Your Cyber Career Entry Point
The cybersecurity industry is experiencing a surge in career opportunities, particularly for those entering the field through identity security, according to John Paul Cunningham, Chief Information Security Officer at Silverfort. Cunningham, speaking in a "Heard it From a CISO" video, emphasized that the increasing integration of artificial intelligence into cybersecurity workflows is…

AI-Generated Workflows Are a Silent Security Disaster
The increasing use of artificial intelligence to generate automated workflows presents a significant, often overlooked, security risk, according to an assessment by zeroday.news. These AI-driven processes, while designed to enhance efficiency, can inadvertently introduce vulnerabilities that compromise sensitive data and system integrity.

The Realities of AI Video Surveillance
Artificial intelligence is significantly enhancing the capabilities of video surveillance systems, allowing for more sophisticated and targeted monitoring. New AI tools enable users to query vast amounts of video footage using natural language, a substantial leap from previous systems limited to a predefined set of search parameters.

'Djinn' Stealer Targets Cloud, AI Credentials
A newly identified information-stealing malware, dubbed "Djinn," is actively targeting credentials that bridge cloud environments, artificial intelligence platforms, and broader enterprise systems. The malware's initial distribution vector exploits a critical authentication bypass vulnerability, identified as CVE-2026-48558, present in the remote support software SimpleHelp.

Modernizing Global Vulnerability Standards For The Age Of AI
The rapid advancement of AI in discovering software vulnerabilities is straining existing cybersecurity standards and frameworks, which were designed for human-led discovery and a slower pace of threat evolution. This acceleration necessitates a re-evaluation of how vulnerabilities are managed, from discovery and verification to disclosure and prioritization.

AI Decline? Confidence in Autonomous Penetration Testing Falls
Confidence in the effectiveness of artificial intelligence for automated penetration testing is waning, despite ongoing experimentation by organizations seeking to identify security vulnerabilities. While companies continue to explore AI-driven tools for security assessments, a notable decrease in reliance on this technology has been observed.

AI Won't Wipe Out Entry-Level Cybersecurity Jobs
Artificial intelligence is not expected to displace entry-level cybersecurity roles, but rather to augment them and create new opportunities. Experts suggest that as AI tools become more prevalent in the industry, the demand for cybersecurity professionals with strong human decision-making capabilities will increase.

Beyond IOCs: AI-enabled threat intelligence
The cybersecurity industry is increasingly exploring the potential of artificial intelligence (AI) to enhance threat intelligence, moving beyond traditional indicators of compromise (IOCs) to derive deeper insights from unstructured data. While AI is often viewed as a double-edged sword, empowering both attackers and defenders, its application in managing and analyzing threat intelligence…

AI Creates 457 Million Security Issues for Organizations
A recent analysis by Tenable identified 457 million AI-related security issues across more than 7,000 organizations over a 30-day period, averaging 62,000 exposures per organization. These issues are primarily linked to misconfigurations and unmanaged dependencies within AI tools, rather than traditional Common Vulnerabilities and Exposures (CVEs). The findings highlight a significant…