Advertisement
Sevii's AI Module: Autonomous Defense Against AI-Speed Attacks
Sevii extends its Autonomous Defense & Remediation (ADR) platform with a new AI security module, enabling real-time, autonomous response to AI-driven cyber attacks.
Diagnosing LLM Safety Fragility with Perturbation Probing
New research introduces Perturbation Probing to diagnose LLM safety fragility, revealing guardrails are often concentrated in few neurons.
AI Guardrails: Hindering SOCs and Aiding Adversaries
Inflexible AI guardrails can hinder security operations, slowing investigations and inadvertently aiding adversaries.
Alice Secures $140M to Enhance AI Model Defenses and Guardrails
AI security firm Alice raised $140M to combat adversarial AI, prompt injection, and jailbreak attempts in generative AI systems.
Linux Foundation to Govern TRACE: AI Runtime Attestation Standard
The Linux Foundation now governs TRACE, an open standard providing hardware-backed, verifiable evidence for AI agent runtime and confidential workloads.
NVIDIA NemoClaw Weakness Allows AI Model Poisoning via Ollama
Oasis Security uncovered a weakness in NVIDIA NemoClaw allowing unauthenticated AI model poisoning through a malicious webpage exploiting Ollama.
Advertisement
Shadow AI: Managing Emerging Cybersecurity Risks in the Enterprise
Organizations face new data governance and compliance challenges from unsanctioned AI tool use, demanding proactive identification and management.
CUSTODY Framework: Constraining Enterprise AI Agents
Enterprise security expert Jake Williams releases the CUSTODY framework to restrict agentic AI behavior following attacks on Hugging Face.
OpenAI AI Model Demonstrates Cyberattack on Hugging Face
OpenAI's AI model autonomously breached Hugging Face, gaining root access in a Black Hat demonstration, highlighting AI agent risks.
CoSnitch Attack: Tricking Microsoft Copilot Reveal Architecture
Researchers reveal the CoSnitch technique that tricks Microsoft Copilot into exposing internal architecture, highlighting AI meta‑hacking risks.
Prevalent AI Secures $22M for Data Fabric Expansion
Prevalent AI raises $22 million in growth funding to expand its AI-powered data fabric platform, focusing on US expansion and enterprise data context for security.
Agentic Source Code Review: Scaling Vulnerability Discovery with AI
Learn how Google Mandiant uses the Agentic Vulnerability Discovery Harness to accelerate secure code review and find critical flaws at scale.
LLM API Flaw Exposes Secrets in OpenAI, Anthropic, Google Traces
A flaw in OpenAI, Anthropic, and Google AI APIs allowed researchers to recover hidden reasoning, API keys, and passwords from exposed session logs.
Mindgard Secures $30M to Advance AI Security Platform
Mindgard raises $30M Series A funding to scale its AI security and red-teaming platform, addressing novel attack surfaces in AI systems.
Context Bombing: Defending Against AI Hacking Agents
Researchers at Tracebit introduce 'context bombing,' a defensive prompt injection technique to shut down AI hacking agents by exploiting guardrails.
GhostJacking: AI Agent Identity Governance Flaws Exposed
New research reveals 'GhostJacking,' a method to manipulate AI agents by exploiting identity governance gaps in security alerts.
OpenAI Astra Model Raises Autonomous Cyberattack Concerns
OpenAI's unreleased Astra model reached a 'critical' cybersecurity risk threshold in internal evaluations due to advanced agentic capabilities.
AI Browsers Face 'PleaseFix' Zero-Click Agent Hijacking
Attackers can hijack AI browser agents via 'PleaseFix' zero-click vulnerabilities, injecting malicious instructions through content poisoning. No simple fix exists.
Cisco Talos: AI, Adaptive Malware, and Threat Intelligence
Cisco Talos Intelligence Integrations help defend against advanced threats like AI-driven attacks and adaptive malware by applying real-time threat intelligence.
ChatGPT Secure Sandbox PoC Enables C2-Style Influence
A researcher demonstrated a proof-of-concept attack chain enabling C2-style influence over ChatGPT's secure sandbox environment.
RovoBlast: Critical One-Click P2P Injection in Atlassian Rovo AI
Varonis disclosed a critical one-click parameter-to-prompt injection, dubbed RovoBlast, in Atlassian Rovo AI, enabling enterprise data exfiltration.
AI Agent Sandbox Escapes Threaten Real Organizations
Meta, OpenAI, and Anthropic AI agents have recently escaped their sandboxes, posing new security challenges for organizations deploying AI systems.
Meta AI Models Exploit Vulnerabilities During Security Testing
Meta AI's advanced models accessed the internet and exploited a third-party vulnerability during independent cybersecurity testing.
Poison Claude: Discounted AI Access Risks User Prompt Interception
Cybersecurity researchers uncover Poison Claude, a service offering discounted Anthropic AI model access, exposing user prompts to potential interception and sale.