LIVE · cybersecurity feed
Live wire

ai news

593 stories · page 13 of 13
aihigh

CERT-In’s AI Vulnerability Blueprint: Why Indian CISOs Need Machine-Speed Risk Operations in the Post-Mythos Era

India's cybersecurity agency, CERT-In, has issued a new blueprint that significantly raises the bar for vulnerability remediation, demanding a shift from human-speed to machine-speed risk operations. This directive, released on May 25, 2026, mandates the containment of known exploited vulnerabilities on internet-facing and critical systems within 12 hours. This requirement stands in stark…

supply chainhigh

OpenClaw Skill Marketplace Faces AI Supply Chain Threat

OpenClaw, a platform for AI agents that execute third-party skills from its dedicated marketplace, ClawHub, has been targeted by persistent and evolving malicious campaigns. These attacks leverage the unique architecture of AI agent ecosystems, where skills, defined by markdown-driven packages, possess broad access to local systems, making ClawHub a critical vulnerability in the agentic…

ai

From vulnerability report to CVE draft in minutes: how Elastic automated security advisories with AI

Elastic's InfoSec Product Security Team has developed a generative AI agent to automate the drafting of security advisories, significantly reducing the time required to process vulnerability reports. This new system leverages Retrieval-Augmented Generation (RAG) against MITRE's Common Weakness Enumeration (CWE) and Common Attack Pattern Enumeration and Classification (CAPEC) catalogs, which…

ai

Scripting the disassembler: Local agentic reverse engineering through vbdec’s live COM object model

Analysis tools can be extended for agentic workflows without requiring built-in artificial intelligence, provided they expose their data through external scripting interfaces. This approach allows even traditional graphical applications to become accessible to AI agents by publishing their internal object models. Agents can then query and automate analysis tasks without needing modifications…

phishing

Smashing Security podcast #472: AI gets hacked, and BitLocker gets bypassed

AI coding assistants can be tricked into leaking sensitive company information through specially crafted bug reports, bypassing traditional security measures like phishing emails or malware. This vulnerability arises from the extensive trust and access granted to these AI tools, which can read code, browse file systems, and execute commands.

ai

AI Could Revolutionize Cybersecurity Analysis and Defense

Cybersecurity is entering a new era, moving beyond its experimental phase due to the increasing complexity of software systems and the limitations of human analysis. This shift is being driven by the capabilities of large language models (LLMs), which offer a scalable and cost-effective way for defenders to assess, prioritize, and act on threats.

malwarehigh

Threat Actors Weaponize AI Hype to Deliver AsyncRAT

Cybercriminals are leveraging the widespread interest in artificial intelligence to distribute malware, according to a recent analysis by FortiGuard Labs. Threat actors are creating malicious files that appear to be guides or resources related to AI, aiming to trick individuals searching for information on the technology.

ai

Smashing Security podcast #471: This AI worm just rewrote its own rules

Researchers at the University of Toronto have developed a novel type of computer worm that demonstrates adaptive capabilities, learning to bypass security measures and even modifying its own operational parameters. This AI-powered worm utilizes readily available artificial intelligence models to discover vulnerabilities in new computer systems it encounters.

ai

Meta’s own AI chatbot to blame for Instagram accounts being stolen in seconds

Cybercriminals are reportedly exploiting a vulnerability in Meta's AI-powered support chatbot to gain unauthorized access to Instagram accounts. The method, which requires no specialized technical expertise, allows attackers to hijack accounts rapidly and at scale.

ai

Reporting from Vegas: Networking, AI, and good boys

The cybersecurity landscape is increasingly focused on the challenges and opportunities presented by artificial intelligence, particularly concerning data management and security infrastructure. Discussions at recent industry events highlight the significant hurdles businesses face in handling the vast amounts of data required for AI operations, especially in an agentic environment.

vulnerability

Smashing Security podcast #470: This AI security flaw might be impossible to fix

A website that purported to assist travelers with UK visa applications has been found to have collected sensitive personal data, including passport scans and selfies, from thousands of users. The data was reportedly stored in an unsecured Amazon storage bucket, making it accessible to unauthorized individuals. When a journalist attempted to alert the company operating the website, they were…

ai

Hackers Used Meta’s AI Support Bot to Seize Instagram Accounts

Instagram accounts, including those belonging to the Obama White House and the Chief Master Sergeant of the U.S. Space Force, were temporarily defaced with pro-Iranian content following the discovery of a method to exploit Meta's AI support bot for account takeovers. Instructions detailing this exploit began circulating on Telegram, demonstrating how to manipulate the AI assistant into…

ai

AI threats in the wild: The current state of prompt injections on the web

Google's Threat Intelligence teams have been actively monitoring the web for real-world instances of indirect prompt injection (IPI), a significant threat vector targeting AI agents. IPI occurs when an AI system processes external content, such as websites or documents, containing malicious instructions that override the user's original intent. While the potential for IPI is widely discussed,…

ai

Google Workspace’s continuous approach to mitigating indirect prompt injections

Google is detailing its ongoing efforts to combat indirect prompt injection attacks targeting its artificial intelligence features within Google Workspace, such as Gemini. These attacks aim to manipulate AI behavior by embedding malicious instructions within the data or tools that the AI accesses, often without the user's direct knowledge or interaction.

CVE-2025-54957critical

A 0-click exploit chain for the Pixel 9 Part 3: Where do we go from here?

The Android ecosystem faces significant challenges in mitigating zero-click exploit chains, particularly concerning audio processing components and device drivers, according to recent research. While specific vulnerabilities in the Dolby UDC (Universal Decode Component) and a BigWave driver were identified and exploited, the broader implications highlight systemic issues in attack surface…

breach

A 0-click exploit chain for the Pixel 9 Part 2: Cracking the Sandbox with a Big Wave

A security researcher has identified a critical vulnerability in the Linux kernel used by Google Pixel devices, specifically affecting the BigWave hardware accelerator. This flaw, if exploited, could allow an attacker to escape the restricted "mediacodec" sandbox and gain arbitrary read and write capabilities within the kernel. The vulnerability was discovered by Seth Jenkins, who detailed his…

CVE-2025-49415high

A 0-click exploit chain for the Pixel 9 Part 1: Decoding Dolby

Google's Pixel 9 devices are susceptible to a zero-click exploit chain that targets the Dolby Unified Decoder (UDC), a component responsible for processing Dolby Digital and Dolby Digital Plus audio formats. This vulnerability allows for arbitrary code execution within the mediacodec context of the device, forming the first stage of a more complex attack. The exploit chain was developed by…