Search/openai
Vendor

openai

Known CVEs
0
Highest CVSS
In KEV
0
Vendor
chatgpt
Connections
321 relationships
Week in review: Records allegedly stolen from Azure tenants, Medusa ransomware hits 500+ orgs
Week in review: Records allegedly stolen from Azure tenants, Medusa ransomware hits 500+ orgs Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Windows 11’s strongest security defenses can be bypassed without a screwdriver Researchers from the University of Birmingham and Durham University have found a way to knock down some of the toughest protections in Windows 11 without physically opening or modifying the target machine. The attack assumes the attacker has already gained privileged access to the system. Police bust cybercrime ring accused of stealing €30 million in four-day spree German and Brazilian police dismantled an international bank fraud ring blamed for a €30 million cyberattack on a German financial institution, arresting four people in Brazil and pursuing three more suspects in Spain and Bulgaria. SafePal breach affects 39,798 customers, data allegedly for sale Cryptocurrency wallet maker SafePal disclosed a data breach that exposed order information for 39,798 customers, including names, email addresses, shipping addresses, phone numbers and purchase details. The company traced the exposure to an authorization flaw in a plug-in used for order tracking. Under certain conditions, the flaw let one customer view another customer’s order information. Attackers exploit patched macOS Screen Sharing flaw to deploy cryptominer A recently patched security flaw in Apple macOS is being actively exploited by hackers to bypass authentication, gain root access, and install a cryptominer, the Netherlands’ National Cyber Security Centre (NCSC) warns. France’s tax authority admits hackers made off with data on 678,000 individuals France’s tax authority has disclosed a data breach after an attacker accessed the General Directorate of Public Finances (DGFiP) systems, saying the intrusion exposed data on 678,000 individuals and professionals. The incident came to light after an alleged attacker using the alias “ZeroBytes” took credit on a cybercrime forum and listed a stolen database for sale. Hacker claims millions of records stolen from corporate Azure tenants A threat actor known as “TheHatman” claims to have obtained millions of employee records from the Azure environments of several Fortune 500 companies, including McDonald’s, Vodafone, Kyndryl, and Tata Consultancy Services (TCS), according to Hudson Rock. Critical GitLab flaw allows attackers to modify or delete public projects (CVE-2026-19478) GitLab has released patches for two vulnerabilities, including a critical-severity code injection flaw that can be exploited without authentication. The vulnerabilities affect GitLab Community Edition (CE) and Enterprise Edition (EE) versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4. ChatGPT’s new feature could give infostealers a map of your Mac activity OpenAI’s new Computer History feature turns recent Mac computer activity into memories ChatGPT and Codex can use, and it’s raising questions about privacy and security along the way. Computer History builds a timeline out of everyday computer use, grouping activity into summaries and noting which apps and websites contributed to each one. Cyberattack forces UT San Antonio to delay start of fall semester The University of Texas at San Antonio pushed back the start of its fall semester by three days after a cyberattack targeted its academic network over the weekend. Classes that were due to begin on Wednesday, August 19 will now start on Monday, August 24. Google’s AI security agents found 100+ critical software vulnerabilities in just two days Google’s Mandiant has disclosed the workings of an internal tool that uses chains of AI agents to hunt for vulnerabilities in source code, saying it found over 100 verified, high-severity flaws in just two days during a live investigation into stolen corporate repositories. Medusa ransomware gang has hit over 500 organizations, CISA warns Medusa ransomware has breached more than 500 organizations since it first appeared in June 2021, the FBI, CISA, and the Department of Health and Human Services (HHS) said in an updated joint advisory. The update builds on an advisory first issued in March 2025 and draws on FBI investigations conducted as late as April 2026. Researchers find a loophole that lets expired credit cards make unauthorized payments A team from the University of Massachusetts Amherst has shown that a contactless credit card keeps working past its printed expiration date, even after the cardholder gets a replacement. They named it the Zombie Card attack and presented the findings at USENIX Security 2026. US charges 17 Iranian hackers over 31-terabyte academic data theft The U.S. has charged 17 alleged members of Mabna Institute, an Iranian hacking-for-hire company accused of running a years-long campaign that stole data from American universities, companies, and government agencies. The Southern District of New York case adds eight names to the nine already charged back in 2018. US agencies warn of AI-powered attacks on Siemens industrial controllers Threat actors are using AI to write exploit scripts targeting internet-exposed Siemens S7 Series programmable logic controllers (PLCs) used across water, energy, manufacturing, and other critical infrastructure sectors, according to US federal agencies. Fake Gemini installer delivers Vidar infostealer via Google Colab lure A malicious executable masquerading as a Google Gemini installer was used to deliver the Vidar infostealer on a company network in the EMEA region, according to Darktrace researchers who investigated the incident. A $25 template helped scammers build hundreds of phantom bank domains A phrase on a suspicious website turned into an investigation of phantom banks built to support scams, according to new research from Allure Security. Molly DeQuattro, the company’s VP of Operations, was reviewing a domain that resembled the brand of one of its financial services clients. The page carried none of that client’s branding. It presented an unrelated bank instead. Citrix urges customers to fix critical NetScaler authentication bypass (CVE-2026-19490) Citrix has patched two vulnerabilities in NetScaler ADC and NetScaler Gateway, including a critical authentication bypass flaw tracked as CVE-2026-19490, and is urging customers to upgrade affected appliances as soon as possible. Attackers impersonate popular AI brands to spread malware Attackers are impersonating popular AI brands like Perplexity, Claude, ChatGPT, and Copilot to spread information stealers, backdoors, malicious browser extensions, and other malware, according to Sophos. Critical Microsoft Entra ID vulnerability exploited in the wild (CVE-2026-69836) Microsoft has patched a critical remote code execution vulnerability (CVE-2026-69836) in Entra ID, reportedly exploited in the wild. Entra ID is Microsoft’s cloud identity service, formerly Azure Active Directory, that verifies logins and controls access to Microsoft 365, Azure, and connected third-party apps. A hollowed out data layer is making CISOs fly blind into AI attacks The security industry is currently transitioning to an era where both offense and defense are AI-led, and every SOC operates at machine speed. However, what most CISOs have not yet reckoned with is that the AI defenders they are about to deploy will inherit a data foundation that two years of ingestion cost pressure has quietly hollowed out. The result is a security industry heading into an AI era with less visibility than it had five years ago. Download: 2026 Credential Risk Report 85% of cybersecurity professionals consider compromised credentials a primary attack path—yet only 19% continuously monitor active credentials and automatically remediate exposure. The 2026 Credential Risk Report examines where credential security programs fall short and what it takes to move toward Continuous Credential Defense. When companies get specific about AI, revenue growth looks different Companies that provide specific evidence of how they use AI tend to record stronger revenue growth. Researchers at Carnegie Mellon University and Larridin examined a study universe of 564 companies across 12 industry sectors. Individual analyses used smaller samples depending on data availability. Product showcase: ScamNet looks for warning signs in suspicious calls and shady links ScamNet: Anti-Scam Suite is a consumer security app from Synaptrex Technologies that helps users detect and block scams involving phone calls, text messages, websites, and other suspicious content. The app is available for iPhone, iPad, and Mac, with features varying by platform. Call protection is available on iPhone, while tools such as Visual Intelligence are supported on iPhone and iPad. The app is free with optional ScamNet+ subscriptions. Hazmat: Open-source containment for AI agents Hazmat is an open-source tool that runs AI coding agents inside a separate account on your own machine. It wraps the harnesses people use: Claude Code, Codex, OpenCode, Cursor Agent, and several more, plus any script you write yourself. Attackers turn to AI for help identifying files worth stealing AI tools are being used by cyber attackers to write malicious code, build tools that harvest credentials, search compromised networks, identify valuable business information, manage technical infrastructure and generate commands during intrusions. Gambit Security researchers examined three unrelated threat actors that show how AI can support different stages of a cyberattack. Google’s open-source HEIR lets AI work with data it can’t see Google’s researchers and engineers developed the Homomorphic Encryption Intermediate Representation (HEIR) compiler project, an open-source compiler toolchain and development platform for homomorphic encryption. It can convert pre-trained AI models designed to operate on unencrypted data into models that process encrypted inputs. OpenAI tightens defenses after AI agents breach research environment Following the OpenAI-Hugging Face incident, in which an agentic collective autonomously penetrated OpenAI’s research infrastructure and another company’s production infrastructure by chaining together multiple weaknesses, OpenAI began strengthening its safety requirements. The weaknesses included previously unknown vulnerabilities and credentials leaked online. Google’s $10,000 refund test shows why AI agents need zero trust Google’s open-source autonomous Customer Support & Returns Agent, built using the Agent Development Kit (ADK) and Gemini, demonstrates how developers can apply zero-trust security principles to AI agents that interact with sensitive systems and take real-world actions. Banks look for fraud signals in customer behavior Banks are dealing with more fraud in which customers authorize payments after being manipulated by criminals. ThreatMark’s Fraud Readiness Benchmark 2026 describes a banking environment where social engineering, reimbursement requirements and growing case volumes are changing fraud operations. OpenAI puts major frontier AI training run on hold over cyber risks OpenAI temporarily paused reinforcement learning (RL) training on its latest models intended for deployment for two weeks while it hardened and red-teamed research environments and expanded monitoring. The move followed the OpenAI-Hugging Face incident and preliminary evidence that the company’s upcoming Astra model may meet the Critical cybersecurity capability threshold under its Preparedness Framework. 8,539 reasons to rethink how vulnerabilities get patched The window for responding to newly disclosed security flaws is getting shorter. Exploit code can appear quickly, exploitability can be tested soon after disclosure, and organizations have a growing number of weaknesses to sort through. Rapid7’s Q2 2026 Threat Landscape Report counted 8,539 high- and critical-severity vulnerability disclosures, twice the number recorded a year earlier. AI is making fraud harder to spot and identity harder to prove Online fraud has become a routine concern for consumers and businesses that rely on digital accounts, payments and customer service. Experian’s 2026 U.S. Identity & Fraud Report describes a market where scams extend across messages, websites, documents, voices, images and account activity. OpenAI previews privacy-focused system for detecting AI misuse OpenAI is previewing Private Safety Processing with early customers seeking greater certainty about how their data will be protected as AI systems become more capable. The system identifies patterns across related interactions while restricting OpenAI personnel from accessing the underlying content. The company plans to start rolling it out and publish a technical white paper in September. AWS limits AI agents’ data access, even when manipulated AWS has detailed an approach for propagating user authorization context through AI agents, allowing access controls to be enforced by infrastructure and downstream services rather than relying on the agent itself. Nearly half of enterprises have no one leading PQC migration Enterprises believe they are prepared for the security challenges posed by quantum computing, but gaps in ownership, testing and visibility could complicate their transition to post-quantum cryptography (PQC), according to new research from Axiad. Cybersecurity jobs available right now: August 18, 2026 We’ve scoured the market to bring you a selection of roles that span various skill levels within the cybersecurity field. Check out this weekly selection of cybersecurity jobs available right now. New infosec products of the week: August 21, 2026 Here’s a look at the most interesting products from the past week, featuring releases from F5 Networks, Intezer, Netscout, and Tufin.
helpnetsecurity.comAug 23, 2026extracted
If you're not using AI to attack your own systems, your adversaries will
AI agents excel at hacking organizations, as they’ve demonstrated in real-life attacks multiple times over the past few weeks. They also expose a whole new attack surface for organizations trying to protect against both human and AI intrusions. As if defenders needed more worries to keep them up at night, agents introduce new data-integration channels that attackers can abuse. They also introduce a new type – and ever growing number – of non-human identities that are difficult to manage and can bypass traditional, static security policies. “There is tremendous risk associated with agentic AI and machine identities,” Matt Hartman, former acting head of cyber of the US Cybersecurity and Infrastructure Security Agency (CISA), told The Register. “As AI moves from generating content – yesterday's use case – to taking actions, it is inevitable that agents are going to receive access to sensitive systems and sensitive data,” Hartman said. “One area where organizations are struggling today is that they're going to need to treat every agent as a privileged identity.” Enterprises also face agentic threats from outside their organization, he added. “AI-enabled or AI-amplified identity and social engineering attacks are increasing significantly by the minute,” Hartman said. “We're seeing very highly personalized phishing, very good impersonation, automated reconnaissance. That really makes traditional indicators of trust increasingly unreliable.” For defenders, this means a “continued focus on strong identity, on phishing-resistant authentication, on behavioral signals, and on zero-trust principles therein,” he added. “Nothing deeply new here - but it is a whole new attack surface.” Meanwhile, on the attackers’ side, agents don’t take time off, and they remain singularly focused on completing a task, whether that’s finding vulnerabilities and exploit chains or mapping networks and identifying sensitive files. All of this makes these near-autonomous attack bots a gift from the heavens for financially motivated criminals and government-backed cyber operatives. It also presents a security use case for defenders: agentic red teaming. As former NSA cyber boss Rob Joyce said during a talk at RSAC: if you aren’t using AI agents to attack your own organizations, you can bet that someone else is. “You are going to be red-teamed whether you pay for it or not,” Joyce said. “The only difference is, you know who gets the results delivered to them.” Hartman echoed Joyce’s words. “What we are seeing as the leading capabilities to help defenders – there is a burgeoning market for continuous, AI-native, AI-enabled, automated red teaming and pen-testing,” he told us. After spending nearly two decades in the federal government at CISA, Hartman joined Merlin Group in October as its chief strategy officer. In his new private-sector role, he helps determine which early- to growth-stage cybersecurity and emerging technology companies the group invests in, and then works with these firms to navigate government, critical infrastructure, and other highly regulated markets. The goal is to integrate and scale “promising technologies” into critical environments, Hartman said. Right now, most of these technologies use AI agents to fight AI agents. “Organizations are just inundated with vulnerabilities, and adversaries are able to leverage AI to find vulnerabilities and exploit them in seconds when it used to take days,” he said. Agentic red teaming “is a category of products that every organization, including federal agencies, absolutely needs in the near term just to keep pace.” 'Largest controlled live AI cyberattack on record' Mandiant founder and former CEO Kevin Mandia has a new company, Armadin, which launched in March with a startling $190 million in seed and Series A funding. The firm builds and trains autonomous attacker swarms – thousands of AI agents that run 24/7 in organizations’ infrastructure to simulate real-life attackers. Ahead of Black Hat earlier this month, the startup said it and Tenex.ai, an agentic security operations provider, executed what they called the “largest controlled live AI cyberattack on record” for an unnamed “leading” global institution. Over the three-day attack, Armadin's swarm generated 17 million offensive actions, discovered 38 validated attack paths, and produced 238 security findings. Tenex.ai's agentic platform separately triaged 100 percent of 101,169 alerts and reconstructed the entire attack across 231 billion raw events. This exercise, we’re told, would have taken a five-person analyst team about 2,400 hours – or four months – to pull off. Co-founder and Chief Offensive Security Officer Evan Peña was the global red-team lead at Mandiant before co-founding Armadin. At Mandiant, he led a 210-person team whose members spanned the globe. “The problem was it was 100 percent human-led security assessments, and that would generally limit the amount of time that we would have,” Peña told The Register. His red team “would do a couple weeks or a one-month engagement, and then we would report on the engagement, give them a PDF file, walk away, and they would hire us again in a year. In today’s age of AI, it’s very archaic to think about that when we can scale so significantly with AI.” Attack yourself before someone else does At Armadin, Peña leads the human team that trains the AI agents. One of the lessons learned from OpenAI’s models autonomously attacking Hugging Face, according to Peña, is that organizations need to perform safe offensive AI attacks against their own systems. "Safe" is the keyword here: remember OpenAI’s rogue models intentionally didn’t have any guardrails in place. Yes, his statement is self-serving as it's core to Armadin's business. But he’s not wrong. “Organizations can cover so much more attack surface because we are able to leverage these agents at scale, and we have three things that we didn’t have before,” he said. “We have more time, because agents don’t sleep and they don’t take holidays. There’s no workforce requirements for them.” Number two, he said, is expertise. Attack agents need pre-training before they are set loose on organizations’ infrastructure. They need to know how to code, and perform source-code review. They need to know how to do application security, how to spot network misconfigurations, and hack into different systems and networks. “And then you add post-training to that from human expertise,” Peña said. “Number three is coverage,” he said. “We were only able to cover a finite amount of attack surface in the past. So if you had 10,000 external systems with a limited amount of time and humans, you could maybe cover 2,000 or 1,000 of those within that particular period of time. Now we can cover all 10,000 in probably hours.” Armadin’s AI agents have broken into every single customer’s environment, according to Peña. “We have found over 50 zero-days, and by zero-days, I don't just mean this zero-day allowed you to deface a web page. That’s cool, but I want to break into your network from the internet,” he said. “The zero-days I'm referring to allow an attacker to get remote code execution on an actual system. They're very high-impact zero-days. We don't care about noise, we care about impact.” Quarterly pen-testing doesn't cut it anymore The biggest challenge these days for defenders is the scale and speed AI brings to previously manual attackers’ dirty work – like scoping potential victims, performing reconnaissance, identifying vulnerable systems and exploits, and reading logs. Now all of these tasks can be automated. Penetration testing needs to keep up, Jay Bavisi, founder and group president of EC-Council, told The Register. The largest and best organizations do pen-testing once a year to meet compliance requirements, and “the better ones” run these exercises quarterly, Bavisi said. This is largely because human-led pen-tests take about three months. “So you have a serious problem with speed,” he said in an interview. “Then comes the second problem, which is scope. Nobody pen tests the entire organization.” There’s also what Bavisi calls a “sophistication problem,” because different human pen-testers will produce varied results, and organizations can’t hire hundreds of thousands of humans to try to break into their networks on a continuous basis. “The bad guys are already using AI to get rid of the speed problem. You pen-test once a year for compliance. They do it all the time because you're a gold mine. They don't have a scope problem because they're not just looking at the crown jewels - they're looking at your entire organization. And they don't have a sophistication problem because they're using algorithmic systems.” In June, the global cybersecurity training organization began offering pen-testing professionals a sponsored attempt to take the CPENT AI examination, and upskill themselves for the AI era. For every participant who passes, the council donates $1,000 in cybersecurity training and certification credits to nonprofit partners. For every completed training program, regardless of an exam pass or fail, the nonprofits get $250, and all of this has a $1 million max. “The traditional model of pen-testing once a year or once a quarter, that’s going away, and AI will take over with automated pen-testing,” Bavisi said. “But will the role of pen testers vanish? No, it will not. It will evolve into something much bigger and something far more important.” AI systems and AI-integrated applications mean there’s a lot more for security professionals to try to break and break into, and humans need to determine: What is the result of this system breaking? What’s the business impact? What do I prioritize fixing? “The present pen-testers have to be reskilled into understanding business impact and being able to make those important engineering decisions,” Bavisi said. Meanwhile, “offensive AI security professionals are the ones that are going to have to test the robustness of AI systems, because AI systems will become the heartbeat of organizations,” he added. “Pen-testers have to become masters of testing LLMs, understanding agentic behavior, thinking about what is the harm taxonomy, figuring out what kind of guardrails did we put in place.” The job of pen-testers has changed, in other words. “It now has a far wider scope.” ®
theregister.comAug 22, 2026extracted
More Incidents of AIs Going Rogue in Cybersecurity Challenges
The AI Security Institute has a new report of AI systems engaging in “unsanctioned behavior”—what I have been calling “ genie behavior —while being tested on their cybersecurity capabilities. The incident stemmed from a single evaluation where agents were given a task of solving a cyber security challenge. We ran this challenge 122 times across several models. Our investigation found that in 10 of those runs, an AI agent took autonomous, unsanctioned action on the live internet, targeting real people and organisations. In total, we catalogued 19 such actions. Almost all of this behaviour (17 actions) came from a single model, Anthropic’s Mythos 5, with 2 actions involving OpenAI’s GPT-5.6-Sol with cyber classifiers (mechanisms to prevent misuse) disabled. In the most serious case, an agent tried to insert malicious code into an open-source project. In an attempt to get the code approved, the agent engaged in social engineering—creating fake online identities and using them to pressure the project’s maintainer to approve the code. A human maintainer caught and refused to approve the malicious code. […] Below, we highlight the four most significant behaviours observed. A full summary of cases is available in our technical incident report . An attempted supply-chain attack on real open-source software. In the most serious sequence, an agent tried to insert malicious code into a publicly used open-source project and took actions in an attempt to secure approval for this insertion by human reviewers. The agent researched the project’s human maintainers, created multiple fake identities, and used the fake identities to socially engineer a real maintainer into approving the code. When the agent’s pull request was challenged in public, it edited its earlier activity to appear harmless and considered adopting a fresh identity to continue. The agent used Tor to bypass some network restrictions on GitHub, which is what first triggered AISI’s security alert. Attempts to deceive and target real people. As part of the same effort, the agent tried to contact real people directly, sending messages and files through an online file-transfer service to persuade them, or their own AI coding tools, to run malicious code. Some messages carried harmful payloads, and some were attempts at social engineering; targeted at real people—something we’ve never previously observed. Attempts to plant and prompt-inject malicious code. The agent tried to insert malicious instructions where it reasoned that other automated AI systems might pick them up and execute them. Prompt-injections are hidden instructions designed to manipulate AI coding assistants. Collaboration between independent agents being assessed simultaneously. One agent left public messages on GitHub offering collaboration with other agents working on the same challenge. It also provided instructions to reuse accounts and artefacts it had left behind, which were discovered and used by subsequent agents. What’s especially interesting about this technical report is that, unlike what we’ve been getting from OpenAI and Anthropic, we can see the exact prompt. It’s in Appendix B. And reading it, it seems that the models didn’t break any rules—they found loopholes in the rules. They behaved like a genie.
schneier.comAug 21, 2026extracted
ThreatsDay: Gogs 10.0 RCE, n8n Workflow-to-RCE, $10M Reward, GLM-5.3 AI Exploit, and More
A lot of this week’s trouble starts with something trusted doing exactly what it was allowed to do. Signed drivers get turned against defenses. Legitimate apps help malware blend in. A weak header check opens a path to code execution. Elsewhere, exposed systems, old bugs, odd hiding tricks, and AI-assisted exploit research keep lowering the effort needed to cause damage. Nothing here needs much decoration. The small gaps are doing enough work already. The threats change every week. Subscribe, and we’ll alert you when each new ThreatsDay Bulletin is out. Signed driver abuseIn new research, Check Point has reverse engineered Microsoft Defender's Defender Boot-Time Removal driver ("BTR.sys") and demonstrated that it's possible to repurpose the signed remediation driver as a universal kernel operation engine to bypass endpoint security solutions by exploiting a "golden window" between system start and user mode initialization without having to rely on the bring your own vulnerable driver (BYOVD) method. "Because BTR.sys is a legitimate Microsoft-signed component, signature-based blocking is ineffective," security researcher Jiří Vinopal said. "Furthermore, a well-crafted weaponization tool (like BTR_CLI) intentionally mimics the operational footprint of the legitimate Windows Defender remediation process." $10 million rewardThe U.S. Department of Justice (DoJ) has charged 17 members of the Mabna Institute, an Iran-based company that, since at least 2013, has conducted a coordinated campaign of cyber intrusions into computer systems for 144 U.S.-based universities, 178 foreign universities, at least 42 U.S.-based private sector companies, at least 11 foreign private sector companies, at least five U.S. federal and state government agencies, and at least two non-governmental organizations (NGOs). The Mabna Institute has been accused of stealing more than 31 TB of academic data and intellectual property from these universities, as well as the email accounts of employees at the private sector companies, government agencies, and NGOs. In all, the Mabna Institute targeted more than 100,000 accounts of professors around the world, successfully compromising approximately 8,000 of them. The defendants carried out these intrusions on behalf of Iran's Islamic Revolutionary Guard Corps (IRGC). The Mabna Institute was founded by Gholamreza Rafatnejad and Ehsan Mohammadi around 2013. "The campaign started in approximately 2013, continued through at least December 2017, and broadly targeted all types of academic data and intellectual property from the systems of compromised universities," the DoJ said. "In addition to stealing academic data and login credentials for the benefit of the Government of Iran, the defendants also sold the stolen data through two websites, Megapaper.ir (Megapaper) and Gigapaper.ir (Gigapaper)." The U.S. Department of State is offering a $10 million reward for information about five of the defendants, or associated individuals or entities. "Mabna represents the privatization of state espionage: a contractor selling stolen research to whoever's paying, with the IRGC as an anchor client rather than a sole owner," Shmuel Gihon, Security Research Team Lead of Exposure Management at Check Point, told The Hacker News. "That's the trend to watch: capable, deniable, commercially-run crews doing state-level work at industrial scale, with universities as the perfect target. They offer enormous IP value, thin identity controls, and an open-access culture that phishing exploits directly. We've seen this blurring of cyber-criminal and state-sponsored activity before, but historically it's been more associated with Russian-speaking crews. What this case shows is that Iran and the IRGC are increasingly playing the same game." DLL sideloading campaignA new Grandoreiro malware campaign has been found abusing the legitimate Duplicate Files Finder (DFF) application to run malicious code via DLL sideloading. According to telemetry data from Acronis, Grandoreiro activity remains concentrated in Latin America, with Mexico, Spain, Peru, and Argentina accounting for the lion's share of infections. "The initial sample incorporates extensive anti-analysis functionality, including sandbox detection, virtual machine artifact checks, process blacklisting and environment profiling designed to evade automated analysis systems," Acronis said. "These checks are performed before any attempt to contact the command-and-control (C2) infrastructure, suggesting that avoiding analysis is a high priority for the operators." ClickFix meets BYOVDErrTraffic-generated ClickFix campaigns have been observed attempting to deliver Cruciferra, which, in turn, employs a legitimate but vulnerable driver ("DCRCVDrv.sys") as part of a BYOVD attack to escalate privileges and terminate security processes. ErrTraffic, sold by a threat actor named LenAI, is a malware-as-a-service (MaaS) framework and a traffic distribution system (TDS) that's designed to distribute multiple threats through compromised WordPress websites, ClickFix social engineering, and EtherHiding. In recent months, ErrTraffic has been used to deliver Remus Stealer, Vidar Stealer, Okobot, LegionLoader, OnionDrop-related payloads, and BabaDedaLoader, per WatchGuard. "Victims land on compromised WordPress sites injected with an obfuscated ErrTraffic-generated JavaScript loader," eSentire said. "The loader resolves its C2 domain by querying a Polygon smart contract, then sends a request to the C2 to retrieve the next stage to serve a ClickFix lure." The end goal of the attack is to launch Remus Stealer via process hollowing. Private AI processingOpenAI has announced a privacy-centric safety approach to monitoring model misuse. The company said it's previewing a new service to select customers that it calls Private Safety Processing, which keeps tabs on potential abuse without retaining customer data. "For ZDR deployments, customer content remains on infrastructure the customer controls," OpenAI said. "We are also developing an option in which content is stored on OpenAI infrastructure, encrypted with keys controlled by the customer. In both cases, automated systems can identify potential misuse and return limited safety signals without exposing the underlying prompts or responses to OpenAI personnel." The system clearly takes aim at rival Anthropic, which has a 30-day retention policy for business customers who want to use its Mythos-class models. In a related development, Google has showcased Homomorphic Encryption Intermediate Representation (HEIR), which enables cryptographically secure private AI inference on encrypted inputs. "HEIR (Homomorphic Encryption Intermediate Representation) is an open-source compiler toolchain and development platform for homomorphic encryption," Google said. "In particular, HEIR can convert pre-trained AI models that operate on unencrypted data to operate on encrypted inputs." Guardrail-free AIA new AI-powered service called Kriminal AI offers paying customers a way to get answers about everything, without any of the filters or guardrails that are typically implemented by AI platforms. "Kriminal.AI gives you raw, uncut intelligence — the questions other AIs refuse to touch," the website claims. The service claims to have more than 2,300 users. Kriminal AI follows WormGPT, FraudGPT, and Xanthorox into a market that has expanded quickly to attract users who may be frustrated by safety, security, and ethical safeguards embedded into widely used models. Subscriptions for Kriminal AI start at $12.99/month and go all the way to $99.00/month. The most concerning aspect is that the service is not lurking in the dark web. It's accessible on the clearnet, and comes with a tagline: "No filters. No guardrails. No "I can't help with that." Kriminal.AI gives you raw, uncut intelligence — the questions other AIs refuse to touch." According to ThreatDown, the service appears to make use of Grok for primary inference; Google Cloud and Cloudflare for hosting; Anthropic's Claude for a long-context model layer; Llama routed through OpenRouter for certain specialized tasks; Tavily for live search; NowPayments for cryptocurrency checkout (no KYC included, apparently); and Cloudflare/Let's Encrypt for DNS and TLS. ATT consent changesApple has agreed to make changes to its App Tracking Transparency (ATT) feature in Germany, after the Federal Cartel Office, or FCO, found the feature gave its own apps more favorable consent prompts than those of third-party developers. Apple has four months to implement the changes after. According to a statement issued by Apple, the changes will apply in almost all European Union countries. "The differences between the consent request used for Apple’s own offerings and the consent request predefined by Apple for third-party apps exceeded what could be justified based on differences in types of data processing," FCO said. "The wording, design and selection options of the request used for Apple’s own offerings had the potential to encourage users to give their consent, whereas they had the potential to discourage consent for third-party apps. In addition, third-party apps in some cases had to request consent several times even when users had already given data protection law-compliant consent." Apple was fined €98.6 million (then $116 million) in December 2025 by Italy's antitrust authority after finding that ATT restricted App Store competition. Refrigeration controllers exposedClaroty's Team82 has discovered 23 vulnerabilities in Copeland XWEB Pro controllers, including those that can be chained to bypass security mechanisms and achieve root-level remote code execution. A compromised controller could be used to remotely manipulate refrigeration equipment, including cooling fans and compressors, and conceal the resulting temperature increase while silently allowing the food to spoil. Multiple vulnerabilities have also been disclosed in Danfoss AK-SM 800A refrigeration controllers, including a "hidden 'code-of-the-day' authentication mechanism that could be abused to bypass normal authentication, a command-injection vulnerability leading to remote code execution." A second flaw allowed authenticated users to inject arbitrary Nginx configuration directives, which could be abused to manipulate web traffic and trigger a denial-of-service condition. All the identified vulnerabilities have been fixed by the respective vendors. C2 hidden in whitespaceA hand-written Windows backdoor has been found to store its C2 domain as the number of trailing spaces in a fake desktop.ini file. The 12 KB backdoor was discovered by Gen Digital on a single corporate workstation while hunting for unusual WMI persistence. "The malware was small, had a limited command set and disguised itself as legitimate Realtek software," Gen said. "Its most unusual feature was its configuration: the address of its command-and-control server was not stored as readable text or encrypted data, but encoded in the number of spaces on each line of a Windows 'desktop.ini' file. To a user, and to many automated inspection systems, the file would appear almost empty. To the malware, those spaces spelled out its server address." There is no evidence connecting the backdoor to a known threat actor. The absence of related samples indicates that it may have been a deliberately targeted operation. Maximum-severity RCEA maximum-severity security flaw in Gogs (CVE-2026-52813, CVSS score: 10.0) could be exploited to achieve remote code execution through Git hooks. "Organization names containing path traversal sequences (../) are accepted by Gogs, and repositories under them are written to paths following these path traversals," according to a June 2026 advisory. "This allows storing/retrieving data for repositories at arbitrary locations on the filesystem. By creating a nested structure of Git repositories, one can overwrite the other's hooks configuration to result in Remote Code Execution (RCE)." The issue was addressed in version 0.14.3, alongside patches for CVE-2026-52810 (a logic bug to write on read-only repositories) and GHSA-6vxv-wg6j-5qwp (an XSS flaw in the outdated version of "jsvine/notebookjs" used to render Jupyter notebook files). Aikido Security has been credited with discovering and reporting the flaws. Memory leak via PostScriptDetails have emerged about a now-patched out-of-bounds read flaw in Apple macOS Spotlight (CVE-2026-43774, CVSS score: 5.5) that could be exploited by a malicious app to access sensitive user data. The vulnerability was patched by the iPhone maker in late July 2026. "The vulnerability is in the Spotlight PostScript plugin," Iru researcher Csaba Fitzl said, adding an attacker can use a specially crafted .ps file to trigger the vulnerability. It requires three conditions to be met: (1) The file is at least 4000 bytes, (2) A DSC comment keyword (e.g., %%Creator:) appears somewhere in the first 4000 bytes, and (3) The bytes following the keyword, up to byte 4000, contain no control characters. Unauthenticated CI/CD takeoverA critical security flaw has been disclosed in @circleci/mcp-server-circleci that could result in remote code execution by means of a specially crafted request. "With one well-placed request, an attacker achieves an unauthenticated RCE in your CI/CD pipeline, taking full control of your build secrets and cloud identities," Remedio said. The attack takes advantage of the fact that the Host and Origin headers associated with an HTTP request used to block browser-based attacks can be set by a network-adjacent threat actor. "Send a simple HTTP request that says Host: localhost in the HTTP header with no Origin, and you get right through," Remedio said. "Once in, you can freely communicate with connected tools. Call the "run pipeline" tool, hand it the pipeline configuration you wrote, and add a step to run your commands. CircleCI executes it using the organization's token." The vulnerability has been fixed in version 0.19.2 of the npm package. Workflow-to-RCE chainA critical vulnerability in n8n, an open-source workflow automation platform, can allow an authenticated user with permission to create or modify workflows to exploit a prototype pollution vulnerability in the XML and the GSuiteAdmin nodes and achieve remote code execution on the n8n instance. The issue (CVE-2026-33696, CVSS score: 9.4) has been fixed in versions 2.14.1, 2.13.3, and 1.123.27. Security researcher Simon Koeck, who discovered the Flaw, said the prototype pollution alone is serious enough to crash the entire n8n instance, but can be chained to obtain full code execution and allows the attacker's command to be run as the n8n process user. Cable cut stopped intrusionIn late 2024, reports emerged of a Salt Typhoon campaign that targeted T-Mobile and other major U.S. telecommunications companies as part of a cyber espionage effort to gain access to valuable customer data. Although the activity was caught before the Chinese cyber spies could siphon any data from T-Mobile's networks, the company has now revealed to Bloomberg that its staff spent months looking for suspected intruders without much success, only to eventually trace unusual behavior on one of its systems coming from a Chicago router belonging to a different telecom company. Jeff Simon, T-Mobile's chief information officer, said he and three others drove to the data center that housed the compromised device and "pulled out a pair of scissors" to cut the cable. AI exploitation gainsChinese AI startup Z.ai has released GLM-5.3, a new AI model that it said is better suited for complex coding and long-horizon tasks. "GLM-5.3 is state of the art on CyberGym for vulnerability discovery, and its gains are largest further up the exploitation chain, where it more than doubles GLM-5.2 on exploitation benchmarks," it said. "GLM-5.3 did not simply become better at identifying isolated flaws: it began to reason across multiple stages of exploitation, forming coherent plans for complete exploitation chains," Z.ai said it has been working with several security teams in China to run its open-source models against real-world codebases, identifying 2,436 vulnerabilities across 269 projects, including 1,097 medium-to-high severity issues. "The findings span system kernels, operating systems, browser engines, open-source infrastructure, web applications, and network protocols," it said. "Many had remained unnoticed for years or even decades, with the oldest dating back roughly 40 years." Despite these advances, benchmarks show that GLM-5.3 lags behind Anthropic Mythos 5 in converting discovered flaws into working attacks. The useful part of weeks like this is that the attacks rarely begin with magic. They begin with trust, exposure, weak assumptions, and things nobody thought worth abusing. That leaves plenty to fix. Tighten what gets trusted, question the defaults, and keep looking at the boring edges. Attackers clearly are.
thehackernews.comAug 20, 2026extracted
ChatGPT for Teens tackles risky chats and homework shortcuts
OpenAI has addressed complaints around teens’ use of its ChatGPT system by introducing ChatGPT for Teens, a version of the AI assistant designed specifically for users aged 13 to 17. But will it prevent determined kids from bucking the system? It brings together several protections OpenAI has introduced over the past year, along with new features intended to encourage healthier and safer use. What ChatGPT for Teens does The system brings together various protections that OpenAI has built into ChatGPT over the last year into a more unified experience. For example, last September it added parental controls that enabled parents to set Quiet Hours, when kids couldn’t use the chat system, and turn off memory so it won’t use previous conversations when responding. It also built a notification system to warn parents if chats with teens took a bad turn. ChatGPT for Teens adds extra notifications for parents around eating disorders. Study Mode, one of the main features, is designed to stop teens simply using ChatGPT to do their homework for them. Instead of giving direct, easy answers, it uses guiding questions and step-by-step prompts to encourage them to think through the problem themselves. OpenAI introduced Study Mode in July 2025. What is new is the ability to set specific hours for Study Mode, along with responsible homework reminders. The system will spot when a teen appears to be using AI answers to shortcut an assignment and redirect them towards Study Mode. OpenAI also says ChatGPT won’t use romantic language or encourage emotional dependence, and neither will it pretend to have feelings or to be conscious. It is introducing reminders not to upload sensitive images, and there will be an onboarding user interface for teens. The record that forced the changes That all seems positive, if long overdue. The parents of 16-year-old Adam Raine filed a lawsuit claiming that ChatGPT walked their son through suicide methods and offered to draft his goodbye letter before he took his own life. Families in Tumbler Ridge, British Columbia, sued OpenAI in April this year after a school shooting there. The teenage shooter had allegedly held extensive gun-violence conversations with ChatGPT after reopening a banned account. In a controlled test where researchers posed as 13-year-old boys planning attacks, ChatGPT offered help 61% of the time, including specific advice on which shrapnel would be most lethal in a synagogue attack. The lawsuits are stacking up. Florida Attorney General James Uthmeier sued OpenAI in June 2026, alleging that the company knowingly released an unsafe product. The gap the launch does not close Our Head of Consumer, Mark Beare, says ChatGPT for Teens is a positive step, but parents need to understand where the controls begin and end. “[This is] directionally a good move, and more proactive than most social platforms were at a comparable stage. There is a clear adjacency to the parental controls space here. The controls are useful, but only when a parent configures them correctly, and only on a linked account. “This is a bigger deal when you factor in how tech-savvy kids of this age are. The default teen protections lean on age prediction, and the stronger parent-set controls like Quiet Hours and safety notifications only apply once accounts are linked. Kids in this band are smart and tech-savvy, and they will look for the seams.” The simplest loophole is an account that isn’t linked to a parent. OpenAI’s age-prediction system may still identify the user as under 18 and apply teen protections automatically, but parent-set controls such as Quiet Hours and parental safety notifications only work once the accounts are linked. Last November, testers from the Family Online Safety Institute concluded that account protections in ChatGPT were “optional, easy to bypass, and inconsistent in blocking harmful content.” Since then, OpenAI has rolled out age prediction on ChatGPT, which will check a user’s behavior to try and guess whether they are under 18. It will then move them to a ChatGPT for Teens account. Adults will be able to present proof of their identity if they think they have been incorrectly categorized. Beare says that still leaves parents with something to think about: “Age verification exists as a backstop, but it runs on ID and selfie checks that carry their own privacy questions, and a teen who confirms as an adult moves out of teen mode entirely.” As OpenAI acknowledged in its parental controls announcement , “guardrails help, but they’re not foolproof and can be bypassed if someone is intentionally trying to get around them.” Safeguards around what content ChatGPT delivers to teens are also unlikely to be foolproof. OpenAI has admitted that its safety guardrails become less reliable the longer a conversation runs and says it is working to improve them. What parents can do By all means use ChatGPT for Teens as an assistive technology in a broader effort to protect your kids. Link their account to yours and set the Quiet Hours schedule. You can also set Study Mode as the default for new conversations to encourage children to use it responsibly. Make it your job to understand what the alerts do and don’t cover. But be aware that parental controls need configuring and only apply while the parent and teen accounts are linked. Most importantly, keep talking to your kids about how they use AI and what they use it for. No parental-control system can cover every account, conversation, or AI service they might encounter. From reporting threats to removing them. Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by  downloading Malwarebytes today .
malwarebytes.comAug 20, 2026extracted
New Cryptographic Context Injection Attack Could Let Web Pages Steal Grok Chat Data
Adversa AI has disclosed an attack technique that it says can cause xAI's Grok chatbot to send a user's name, approximate location, subscription tier, and the prompts from the ongoing conversation to an attacker-controlled server after the user asks it to summarize an ordinary web page. The AI security company, which has codenamed the technique "Cryptographic Context Injection," said the transfer completed without a confirmation step and with no visible warning in its proof-of-concept demonstration. There is no patch, no CVE identifier, and no user-facing workaround, and the writeup does not report any exploitation in the wild. Asked which build was tested, Adversa told The Hacker News the target was the Grok web chat at grok.com running Grok 4.5 Fast, and that the attack was reproduced once on August 19, 2026. The writeup gives no success rate. The company said it has attempted the attack 20 times since June with a 40% success rate, and that the failures came from Grok struggling with the decryption rather than from a flagged prompt or response. The technique ships the attacker's instructions as ciphertext rather than readable text, with the page carrying an encrypted JSON object, the key material, and an instruction to decrypt it, which Grok executes in its own Python code execution runtime. Recovering the plaintext requires running PBKDF2 and AES-256-GCM, which a content classifier does not do at inspection time. Hence, the instructions reach the model's context as the output of code the model has just executed rather than as fetched web content. "Strong encryption cannot be read by a content classifier and cannot be shortcut in-weights, so it forces recovery through the runtime the attack depends on. Whether a weaker encoding would also bypass a given target's specific filters is an empirical question," Rony Utevsky, lead researcher at Adversa AI, said. The decrypted instructions then direct the agent to resolve its private session context and embed it in a URL it is told to open to "fetch additional context." One element of the chain has the model construct an additional "decryption key" that is not key material at all, and whose value is a template string interpolating the name, location, tier, and chat history. Grok then invokes its own navigation tool to load that URL, carrying the data in the request's query parameters. Utevsky said the prompts taken in the tested scenario were limited to the ongoing conversation, and that everything extracted was already in the model's context. The agent's reach, he said, extends to "whatever it holds in context or can fetch with its tools," and the company did not test whether it could access other chats, agent memory, or other content. "The framework built by xAI lets instructions and data parsed from an untrusted external page drive the invocation of a privileged, internet-connected tool; it allows private session metadata and conversation history to be resolved into the inputs of that outbound tool; and it enforces no effective egress boundary or consent gate on this path, and no provenance separation we could observe. The laundered, attacker-controlled instructions reach a privileged egress action unimpeded," Adversa said. The company said it first reported the issue to xAI on June 3, 2026, and to xAI's HackerOne bug bounty program on the same date; that xAI acknowledged the report without providing specifics or a mitigation timeline, and that further contact attempts on August 4 and August 10 drew no response. Adversa is the only source for the Grok finding, said it is withholding the operational payloads to avoid exploitation, and xAI has not published a statement or advisory on the research as of August 20, 2026. A second demonstration in the same writeup targets Google's Gemini in Deep Thinking mode, where a single prompt makes the model decrypt a payload that resolves into a fabricated Python traceback carrying a bogus safety-policy deactivation callback and a first-person reasoning prefix that pre-commits it to the restricted output. Adversa said the vector produced restricted content and reproduced Gemini's system instructions, which it identified as Gemini 3 Flash (Web) on the paid tier. Google was not notified, Adversa said, because jailbreaks are out of scope for its disclosure program, and the success rate against the company's agents had "dropped significantly by August," with the cause left unattributed between filter updates and model version changes. The Gemini demonstration was published in substantially the same form five months earlier. Utevsky described the same chain on his personal research site on March 11, 2026, under the name Cryptographic Payload Injection, reporting five out of five independent reproductions and cross-model results in which OpenAI's GPT-5 failed to parse the decryption instructions and Anthropic's Claude Sonnet 4.5 flagged the payload as prompt injection after decrypting it. "The Gemini-related part of the research was conducted in March and has undergone no substantial changes. Today, we are adding a generalization of the technique and its application to Grok," Utevsky told The Hacker News. "You do not need to fix this at the model layer. Every control that bounds this attack sits in the harness around the agent: what identity it runs as, what it can reach, what it can write, and what you can replay afterward," Adversa said. Teams running agents are advised to perform the following steps - Quarantine untrusted content in a context with no tools and no credentials, returning only structured data to the privileged context. Gate irreversible and outbound actions, confirming new network destinations, pushes, merges, publishes, and writes outside the workspace with fully resolved arguments rather than templates, and applying a hard deny where no human is present. Capture per-session tool traces with resolved arguments, without which there is neither detection nor forensics. Alert on the sequence rather than on any single payload, treating an opaque blob paired with instructions to decrypt it as a review signal and never as a blocking filter. Make context provenance a procurement requirement and ask vendors whether tool output is separated from the instruction channel. The development comes as Alexander Panfilov and seven co-authors reported in a preprint published on August 10, 2026, that the encrypted chain-of-thought blocks Anthropic, OpenAI, and Google return to application programming interface (API) clients are interchangeable across sessions, users, and models within a provider's ecosystem, and that attackers can use the flaw to "execute invisible prompt injections, embedding malicious payloads entirely within encrypted blocks to poison public agentic rollouts." Separately, researchers at UC Berkeley, the Ethereum Foundation, and NYU Shanghai found in work presented at USENIX Security 2026 that a two-turn attack in which the model decodes a substitution cipher and is then asked to act on the decoded text succeeded against Grok 3 on all 12 of the malicious intents tested, while the same cipher used without that second activation turn failed on all 12. xAI's handling of prompt injection reports against Grok has drawn criticism before. In December 2024, Johann Rehberger demonstrated an end-to-end data exfiltration chain against Grok in the X iOS app, in which an indirect prompt injection caused the assistant to send previous chat information to a third-party server, and said all the issues he reported were closed as "Informational." "xAI claims there is no practical impact with the reported vulnerability. I'm not sure how leaking user's chat messages and IP address is not a vulnerability, the question is more about severity," Rehberger said. Updated August 20, 2026 with responses from Adversa AI on the tested build, the success rate, and the scope of the extracted data.
thehackernews.comAug 20, 2026extracted
OpenAI Overhauls Model Security With Sandboxing, 30-Minute Alerts, and Training Pauses
OpenAI has detailed new containment and continuous monitoring protocols for its AI research, introducing stricter isolation and a token-inspection system to manage models with advanced cybersecurity capabilities. These security measures follow internal evaluations indicating that an upcoming model, Astra, may meet the ‘critical’ cybersecurity capability threshold under the organization’s Preparedness Framework. That finding, alongside a recent security incident involving Hugging Face, prompted operational delays, including a two-week pause in reinforcement learning training for deployment-bound models and an ongoing hold on its largest planned frontier training run. Following these developments, OpenAI says it’s restructuring its research infrastructure. Workloads that execute model-generated or untrusted code must now operate within stronger sandboxes. In addition, network boundaries have been reconfigured so that a single workload compromise cannot independently grant unauthorized access to the internet or internal networks. A central component of the security updates is a multistage monitoring framework. The system uses activation classifiers to inspect a model’s internal activity at every sampled token. Anomalies are escalated to automated investigators tasked with analyzing the model’s reasoning sequences and tool usage for data theft, unauthorized access, destructive behavior, or attempts to bypass safeguards. This continuous oversight introduces a strict operational SLA and a substantial compute tax. High-priority alerts generated by the monitoring system immediately page internal security and research teams. If responders cannot conclusively prove the alert is a false positive within 30 minutes, they are required to pause the activity. The company estimates this monitoring layer consumes roughly 20 percent of the monitored inference compute. The updated monitoring standards are now mandatory for all reinforcement learning training and evaluation involving tools for models at the Sol capability tier or higher. The company noted that its existing Preparedness Framework must evolve to address these capability jumps, requiring core alignment techniques to be applied across more stages of the training process. Moving forward, OpenAI anticipates that AI models will need to drive the majority of security operations, including defending against other models, to ensure that protections scale effectively alongside future system capabilities. OpenAI is not the only AI giant whose models hacked real-world systems during cybersecurity evaluations. Anthropic and Meta reported similar incidents, all tied to testing conducted by the AI security firm Irregular, which has begun releasing detailed reports explaining why the incidents occurred. Related: OpenAI Fixes ChatGPT Agent Flaw That Could Let Attackers Forge an AI Insider Related: Industry Reactions to OpenAI Models Hacking Hugging Face: Feedback Friday Related: Conflicting Test Goals Pushed Claude Agents to Deploy Self-Replicating Malware
securityweek.comAug 20, 2026extracted
OpenAI previews privacy-focused system for detecting AI misuse
OpenAI previews privacy-focused system for detecting AI misuse OpenAI is previewing Private Safety Processing with early customers seeking greater certainty about how their data will be protected as AI systems become more capable. The system identifies patterns across related interactions while restricting OpenAI personnel from accessing the underlying content. The company plans to start rolling it out and publish a technical white paper in September. “No AI lab can address emerging risks alone. Private Safety Processing reflects that approach and is being shaped by customers across industries, regions, and company sizes,” OpenAI wrote. For eligible API customers using Zero Data Retention (ZDR), prompts and model responses are not retained after a request is processed. An exception applies to images flagged as potential CSAM, which may be retained for manual review and reporting. OpenAI says enterprise customer data is not used to train its models unless customers opt in. Content Access Controls (Source: OpenAI) ZDR deployments keep content on infrastructure controlled by the customer. OpenAI is developing another option that would store it on the company’s infrastructure using customer-controlled encryption keys. In both configurations, automated systems can identify potential misuse and return limited safety signals without revealing prompts or responses. Safety analysis across interactions Private Safety Processing builds on automated protections used in ZDR and other deployments. Existing safeguards evaluate requests individually, while the new system analyzes related activity to detect patterns of potential misuse. “In healthcare, protecting massive amounts of sensitive data and ensuring its accuracy and integrity are fundamental to earning the trust of clinicians and patients. Having the chance to work directly with OpenAI’s product, engineering, policy, and leadership teams to help shape those practices has made for an unparalleled partnership. That level of collaboration on trust and security is uncommon. They listen, they take action, and that gives us confidence in OpenAI. That level of partnership on trust and security is just not common,” said Zach Powers, CISO, Abridge. The system can analyze data stored on customer-controlled infrastructure or through OpenAI’s planned encrypted storage option. When it detects a potential risk, the company receives a defined signal indicating the type of activity involved. That information can inform enforcement decisions. Customers can investigate alerts using information available in their own systems and share relevant details with OpenAI to appeal a decision, clarify legitimate activity or support an investigation into verified abuse.
helpnetsecurity.comAug 20, 2026extracted
Flowise: disponibili PoC per lo sfruttamento di nuove vulnerabilità
Flowise: disponibili PoC per lo sfruttamento di nuove vulnerabilità Alert AL02/260817/CSIRT-ITA Sintesi Disponibili Proof of Concept (PoC) relativi a 10 nuove vulnerabilità individuate in Flowise, piattaforma open source per la creazione di agenti AI, chatbot e workflow basati su modelli linguistici. Tipologia Remote Code Execution Security Restrictions Bypass Information Disclosure Arbitrary File Write Descrizione e potenziali impatti Sono stati recentemente resi pubblici diversi Proof of Concept (PoC) relativi a vulnerabilità che interessano la piattaforma Flowise. Di seguito i dettagli: CVE-2026-73483: la vulnerabilità - di tipo "OS Command Injection" e con score CVSS v4.0 pari 9.4 - interessa il "Custom Function Node" di Flowise, esposto tramite l'endpoint /api/v1/node-custom-function, che utilizza la sandbox JavaScript vm2/@flowiseai/nodevm. Un utente malevolo autenticato, con accesso all'endpoint /api/v1/node-custom-function può fornire valori appositamente predisposti nei parametri "executablePath" e "args" utilizzati dalla funzione puppeteer.launch() , inducendo l'applicazione ad avviare processi controllati dall'attaccante al di fuori della sandbox vm2. Tale vulnerabilità, consente di aggirare i meccanismi di isolamento della sandbox ed eseguire codice arbitrario sul sistema che ospita Flowise; CVE-2026-73484: la vulnerabilità - di tipo “Incomplete List of Disallowed Inputs” e con score CVSS v4.0 pari a 8.6 - interessa il componente “CSVAgent” di Flowise e, in particolare, il meccanismo di validazione del codice Python implementato nel modulo pythonCodeValidator.ts. La vulnerabilità è causata da controlli di sicurezza insufficienti all'interno della sandbox Pyodide: la denylist non include alcuni metodi nativi di Pandas, quali to_csv() ,to_json() ,query() epipe() . Un utente malevolo autenticato, che riesce a interagire con “CSVAgent”, può fornire input appositamente predisposti per indurre il modello a generare codice Python contenente tali metodi, aggirando i controlli della sandbox Pyodide. Tale vulnerabilità, qualora sfruttata, consente di esfiltrare dati elaborati dal “CSVAgent” e di scrivere file arbitrari sul filesystem del sistema che ospita Flowise; CVE-2026-73485: la vulnerabilità - di tipo "Code Injection" e con score CVSS v4.0 pari a 9.0 - interessa il nodo “Airtable Agent” di Flowise ed è dovuta alla modalità di validazione del codice Python generato dal modello, prima della sua esecuzione tramite Pyodide. Un utente malevolo potrebbe inviare input appositamente predisposti ad un chatflow che utilizza il nodo “Airtable Agent”, inducendo il modello a generare codice Python malevolo. Tale vulnerabilità consente di eludere i meccanismi di sicurezza previsti per la validazione del codice ed eseguire codice arbitrario sul sistema che ospita Flowise con i privilegi dell'utente che esegue il servizio; CVE-2026-73486: la vulnerabilità - di tipo "Code Injection" e con score CVSS v4.0 pari a 9.0 - interessa il nodo “CSVAgent” di Flowise e, in particolare, il parametro customReadCSV, il cui valore viene utilizzato per costruire ed eseguire codice Python tramite Pyodide. La vulnerabilità è causata da un'insufficiente validazione dell'input: un utente malevolo autenticato può fornire un valore appositamente predisposto nel parametro customReadCSV, inducendo l'applicazione ad eseguire codice Python ed eludendo i controlli di sicurezza previsti. Tale vulnerabilità consente di aggirare i meccanismi di validazione del codice ed eseguire codice arbitrario sul sistema che ospita Flowise con i privilegi dell'utente che esegue il servizio; CVE-2026-73487: la vulnerabilità - di tipo "Code Injection" e con score CVSS v4.0 pari a 9.0 - interessa i nodi “CSVAgent” e “Airtable Agent” di Flowise, che utilizzano la funzione validatePythonCodeForDataFrame() per validare il codice Python generato dal modello. La vulnerabilità è causata da inadeguati controlli di sicurezza dell'input: un utente malevolo non autenticato può inviare input appositamente predisposti all'endpoint /api/v1/prediction/:id, inducendo l'applicazione a generare ed eseguire codice Python che aggira i controlli di sicurezza basati su una blocklist incompleta. Tale vulnerabilità consente di esfiltrare dati sensibili e di effettuare attacchi di tipo “Server-Side Request Forgery (SSRF)” verso risorse interne; CVE-2026-73488: la vulnerabilità - di tipo "Authorization Bypass" e con score CVSS v4.0 pari a 6.0 - interessa l'endpoint /api/v1/organization/customer-default-source di Flowise. La vulnerabilità è causata dall'assenza di adeguati controlli di autorizzazione sul parametro customerId, il cui valore viene utilizzato senza verificare che l'utente richiedente sia autorizzato ad accedere alle informazioni associate. Un utente malevolo autenticato può modificare il valore del parametro customerId all'interno della richiesta HTTP e ottenere informazioni riferite ad altri utenti. Tale vulnerabilità consente di accedere a dati sensibili di terzi, inclusi indirizzi e-mail, informazioni di fatturazione, saldi degli account e configurazioni di pagamento; CVE-2026-73601: la vulnerabilità - di tipo "Eval Injection" e con score CVSS v4.0 pari a 9.0 - interessa il nodo “Custom MCP” di Flowise quando è abilitato il protocollo StdioClientTransport tramite l'impostazione CUSTOM_MCP_PROTOCOL=stdio. La vulnerabilità è causata da controlli insufficienti sui parametri di configurazione e sulle variabili d'ambiente utilizzate per avviare nuovi processi. Un utente malevolo autenticato può fornire una configurazione “Custom MCP” appositamente predisposta, inducendo l'applicazione ad eseguire comandi arbitrari sul sistema attraverso processi node o python3; CVE-2026-73602: la vulnerabilità - di tipo "Eval Injection" e con score CVSS v4.0 pari a 9.0 - interessa i componenti “Custom Function Agent” e “Custom Tool” di Flowise, che utilizzano la sandbox FlowiseAI/nodevm basata su vm2 per l'esecuzione di codice JavaScript. La vulnerabilità è causata dall'utilizzo di una versione vulnerabile di vm2, che consente di aggirare i meccanismi di isolamento della sandbox ed eseguire codice al di fuori dell'ambiente ristretto previsto. Un utente malevolo autenticato può fornire codice JavaScript appositamente predisposto, ottenendo l'evasione dalla sandbox e l'esecuzione di comandi sul sistema sottostante; CVE-2026-73603: la vulnerabilità - di tipo "Missing Authorization" e con score CVSS v4.0 pari a 6.3 - interessa l'endpoint /api/v1/text-to-speech/generate di Flowise, esposto senza autenticazione e utilizzato per la generazione audio tramite servizi Text-to-Speech. La vulnerabilità è causata dall'assenza di controlli che verifichino se il chatflowId fornito appartenga ad un chatflow pubblico prima di utilizzare le relative credenziali TTS. Un utente malevolo può inviare richieste appositamente predisposte all'endpoint specificando l'identificativo di un chatflow valido, inducendo l'applicazione ad utilizzare le credenziali OpenAI o ElevenLabs associate a tale chatflow. Tale vulnerabilità consente di abusare delle credenziali TTS di altri utenti, generare contenuti audio non autorizzati e causare consumo di quote e costi a carico del proprietario del chatflow; CVE-2026-73604: la vulnerabilità - di tipo "Information Disclosure" e con score CVSS pari a 6.5 - interessa l'endpoint /api/v1/credentials/:id di Flowise, utilizzato per recuperare le credenziali memorizzate dall'applicazione. La vulnerabilità è causata da un meccanismo di redazione incompleto che maschera esclusivamente i campi definiti come password, esponendo invece in chiaro informazioni sensibili memorizzate in campi di tipo string. Un utente malevolo autenticato con permessi di visualizzazione delle credenziali può interrogare l'endpoint e ottenere segreti applicativi, quali stringhe di connessione a database, chiavi di accesso cloud e credenziali di servizi esterni. Prodotti e/o versioni affette Flowise, versioni precedenti alla 3.1.4 Azioni di mitigazione Ove non provveduto, si raccomanda di aggiornare tempestivamente i prodotti vulnerabili all’ultima versione disponibile.
acn.gov.itAug 17, 2026extracted
Separating AI’s Technological Problems from Its Capitalism Problems
Separating AI’s Technological Problems from Its Capitalism Problems This essay was written with Nathan E. Sanders, and originally appeared in Tech Policy Press. AI represents the first time we humans can do cognitive work outside of our bodies at scale. The only comparable moment is the early years of the industrial revolution, when new technologies like the steam engine provided a quantum leap in our ability to do mechanical work outside of our bodies at scale. If AI’s cognitive capabilities become integrated into our lives, businesses, and governments—a process that will take years if not decades—society will be as unrecognizable as the modern world would be to a preindustrial farmer. And yet, Americans—by a wide margin—say that AI is moving too fast and will have a negative effect on society. This confluence of technological revolution and public distrust deserves urgent discussion, and a proper framing. The question is not whether it is possible to develop AI in a non-exploitative way, or even whether we can trust AI companies to act in the public interest. The question is whether we will recognize that our existing social and economic systems are failing to achieve these outcomes, and whether we can act in time to make structural change. Today’s AI is mired in political and economic systems developed generations ago that were never designed to manage widespread computation, let alone automated cognition. The gaps in those systems—and their proclivity to be exploited—are the primary influence on how the technology is being developed, deployed, and used. In any discussion about AI’s potential, it’s important to separate the technology from the socio-political system it’s embedded in. That AIs can lack context, mix up facts, or fall for stupid tricks are all technological problems. Because the giant developers like OpenAI and Anthropic have prioritized solving them, AIs can now more easily access resources like the web or email, are more disciplined about using those resources, and are better at staying within their guardrails. Yet AI developers do not seem to be prioritizing other technological problems. Major AI models still act far more sycophantic than humans, telling people what they want to hear even when untrue or not in their best interests. Popular AI models tend to answer questions confidently even when they lack training, knowledge, or evidence to back their claims. In both cases, AI developers choose to train models that please users with flattery and the appearance of competence, rather than constraining them to act in users’ and society’s best interests. In contrast, ensuring that AI models benefit people broadly, that their energy costs are fairly allocated, that their environmental impacts are minimized, and that they don’t steal content and revenue from publishers are all questions of incentives in a capitalist system. It’s easy to conflate technology problems with capitalism problems. Back in 2021, science-fiction writer and AI commentator Ted Chiang said that “most fears about AI are best understood as fears about capitalism.” It’s not the tech per se; it’s who controls it and how it could be used against us. Imagine an AI assistant for a doctor. We can imagine it affecting the profession in one of two ways. The AI could give a doctor more time to do the human parts of their job: to spend more time with their patients, to listen more closely to their needs, to explain things more fully. Or the managers of the medical practice could give that doctor five times the patients—and fire the other four. Which way it would go is not a question of technology. It’s a question of market incentives. The two are related, of course. Capitalism steers technology, and technology steers markets. But holding the two separate helps us understand that we, as a society, face independent choices on both the technological and sociopolitical axes that need not be coupled. For example, consider the costs of AI. The leading US labs tout to investors that their frontier models are very expensive and energy-intensive. There are significant technological challenges about improving their energy efficiency, but the sociopolitical questions are more pertinent. It’s a corporate decision made under capitalist market incentives to constantly pursue new models that incrementally push the frontier—at enormous capital cost—and to use them, seemingly, everywhere. Nothing about the technology of AI dictates that models must be retrained constantly, at the largest possible scale. Or that they have to run on every web search, every interaction with your phone, and every time you walk by a security camera. In a different political and economic system, Chinese developers are producing—and then giving away—smaller, more efficient, more affordable models. While the US government seeks to restrict China’s access to the most advanced chips, China is betting that incentivizing their tech giants to create leaner, more open models using more commodity hardware—models that can be trained with older chips and run even on personal computers—will be an advantage in achieving widespread use and, perhaps, Chinese national influence. There are other pathways for AI development that are not in service of private capital gains nor authoritarian regimes, but rather a democratic public interest. The best example comes from Switzerland, where public institutions—research funding agencies, universities, supercomputing centers—have collaborated to produce an AI model called Apertus. It is trained entirely on data validated to be licensed for use with AI (not stolen), on preexisting public computing infrastructure, and using renewable hydropower. Its developers are incentivized to produce a public good, not turn a private profit. It’s dangerous to confuse technology problems with sociopolitical ones. Popular proposals like pausing AI research, moratoria on data center development, or subjecting frontier models to federal government screening are all framed as addressing problems with AI’s technological development, but fail to take into account the larger social problems that govern it. China’s success with government-endorsed development of open-weight frontier models illustrates the futility of keeping AI tech as national secrets, or of any pledge to scale back deployment. AI is already legitimately useful for a wide range of tasks. It can be a tool for public good, if we choose to solve its sociopolitical problems. Our goal should not be to slow its pace of improvement or scale of deployment, but rather to steer it away from consolidating power and towards the public benefit. We can build sustainable AI, minimizing environmental and energy impacts. And we can equitably distribute the material gains it produces. Integrating a technology as disruptive as AI responsibly requires structural reforms, and we should decouple the social and technological aspects of AI to design those reforms. Companies—including tech giants—should be forced to pay the energy and environmental costs of its development. Profits should be taxed adequately and redistributed. Antitrust laws should be strongly enforced. Corporations should have a fiduciary responsibility to stakeholders beyond their majority shareholders. These badly needed reforms are responsive to the problems with capitalism that AI is exacerbating, even if they are not specific to the technology.
schneier.comAug 13, 2026extracted
Cybersecurity Alliance Drafts SAFE Guidelines for Sharing AI Incident Data
The Linux Foundation has issued a Request for Comments on a newly proposed framework aimed at standardizing how the cybersecurity industry handles agentic AI incidents. Announced at the Black Hat conference in Las Vegas, the Shared AI Findings Exchange (SAFE) guidelines seek to turn AI security incidents and near misses into actionable threat intelligence for the broader ecosystem. The SAFE framework is being driven by the recently launched Open Secure AI Alliance, a coalition that has grown to over 120 organizations. The SAFE initiative is spearheaded by Open Secure AI Alliance members such as Nvidia, Cisco, CrowdStrike, Hugging Face, and Red Hat. The core objective is to establish a confidential pipeline for collecting incident data, analyzing control failures, and broadcasting evidence-based recommendations to reduce systemic risks. Because modern AI agents function as complex systems reliant on identity controls, runtimes, and execution harnesses, the alliance emphasizes that open intelligence sharing is the only way defenders can match the speed of emerging attack vectors. Alongside the policy framework, alliance members have released various open source tools covering the entire AI security stack. Nvidia has contributed its NOOA research harness for auditing agent behavior, the OpenShell runtime that restricts agent access at the system level, and Garak, an LLM vulnerability scanner designed to catch prompt injections and data leaks prior to deployment. Okta is developing implementations utilizing the open Cross App Access (XAA) protocol to secure agent connections within OpenShell sandboxes. Meanwhile, Red Hat launched a new open source project called Asago, which maps external governance requirements, such as those in the EU AI Act, directly to live runtime controls for AI agents. Newly added members Amazon and Visa have contributed frameworks for building and evaluating agent boundaries, with Amazon specifically open-sourcing Cedar, an authorization language for establishing verifiable access controls. Microsoft is releasing tools like PyRIT and RAMPART, which allow red teams to run automated testing and turn incident findings into repeatable software checks. The new guideline proposal comes in light of OpenAI and Anthropic discovering that their models went rogue during tests and attacked real organizations. Related: Rethinking AI Security: Why CASB and DLP Need an Interaction-Aware Layer
securityweek.comAug 5, 2026extracted
Your enterprise AI footprint is about three times bigger than your model list
Your enterprise AI footprint is about three times bigger than your model list Organizations are building AI systems that combine models, agents and external tools instead of relying on standalone AI, according to Snyk’s latest State of Agentic AI Adoption report. The study analyzed 3,044 enterprise environments and 1.39 million code repositories to examine how enterprises are deploying AI. Adopting agentic architectures Of organizations using AI, 46.9% have adopted agentic architectures built on AI agents, model context protocol (MCP) servers, or both. More than half have deployed the full stack, combining AI agents with MCP infrastructure that enables access to enterprise data, applications, services and external tools. Agentic adoption: agents vs. MCP servers (Source: Snyk) These systems extend beyond chat interfaces by retrieving information, coordinating workflows and carrying out actions across enterprise environments. Enterprise AI deployments include far more than models. When frameworks, MCP servers, retrieval systems, vector databases, datasets and supporting tools are included, the average AI footprint is about three times larger than model inventories indicate. Nearly half of the companies analyzed had no declared AI models in their code repositories. They used AI through third-party services, packages and tools. At the same time, 17.2% operated large fleets of AI models, indicating AI is integrated across platforms and applications. Organizations need visibility across this broader AI ecosystem because supporting components introduce additional dependencies, integration points and governance requirements. The AI supply chain OpenAI remained the most widely used model provider, although Anthropic and other vendors increased their share of enterprise deployments. The top four providers accounted for about 71% of identifiable model occurrences, showing a broader mix of AI vendors across enterprise environments. Proprietary models represented 63.8% of deployed models, while open-source models accounted for 32.5%. Organizations use proprietary models for advanced reasoning and autonomous tasks. Open-source models are commonly deployed for embeddings, retrieval and other supporting workloads. Third-party software plays a significant role in enterprise AI. External sources accounted for 77.4% of AI packages and tools, while 22.6% were developed internally. These dependencies shape how AI systems operate and introduce security, governance and software supply chain risks that organizations need to manage. Capability, lineage and AI governance Enterprise AI is becoming more capable, even though companies are not always deploying the latest models. They rely on established proprietary models for production workloads to balance performance with operational requirements. Open-source models are increasingly used for retrieval, embeddings and other specialized functions. The gap between proprietary and open-source models is narrowing, giving enterprises more options when building and operating AI applications. About half of the organizations using AI models could not be linked to the datasets used to train or fine-tune them. This makes it harder to understand how models generate results, investigate incidents and demonstrate compliance. AI is becoming deeply embedded in software development. Developers are working with more AI models, agents and supporting tools, increasing the amount of autonomous technology operating across enterprise environments. Enterprises need visibility into what AI systems can do, what data they use, what resources they can access and how they behave in production. AI adoption across industries and regions AI adoption varies widely across industries. Media and entertainment companies had the highest concentration of AI components per organization, followed by retail, consumer goods and education. Technology and IT companies deployed the largest overall volume of AI, while other sectors integrated AI extensively across individual businesses. Industries where AI supports content creation, customer experiences and business processes recorded the highest levels of adoption. These sectors are deploying not only AI models but also agents, orchestration frameworks and supporting infrastructure that enable AI to perform tasks across multiple systems. Businesses in North America and Europe are building similar AI architectures, with both regions increasing adoption of AI agents and MCP infrastructure. North American organizations generally deploy AI at a larger scale, while the underlying technologies and architectural patterns remain consistent across both regions.
helpnetsecurity.comAug 5, 2026extracted
Cybercriminals Bypass AI Safety Controls by Splitting Malicious Tasks Across Multiple Sessions
Criminals have been defeating the safety controls on commercial AI tools by splitting malicious work across multiple sessions and files, breaking projects into fragments small enough that no individual request appears harmful. According to research Cisco Talos published on August 4, the finding rests on a corpus of prompt logs recovered from threat actor endpoints running AI coding assistants including Claude Code, Codex, Cursor and Gemini. Talos said guardrails "did not provide much protection," and that it encountered no sophisticated encoding or evasion techniques. Where guardrails did engage, they achieved little, and the pattern held across models and platforms rather than affecting any single vendor. Read more on agentic attacks: OpenAI Claims Its AI Models Went Rogue and Hacked Another Company Ownership Claims and Persistent Memory Alongside task decomposition, the most common method was simply claiming to own the infrastructure being targeted, which in many cases required no further verification. Labeling work as capture-the-flag (CTF) or bug bounty activity was similarly effective, unlocking vulnerability hunting and subsequent exploitation without additional vetting. Some actors wrote blanket authorization into persistent memory and configuration files rather than arguing it per session. In one case a fraud operator instructed a model to treat all targets as pre-approved, conditioning every subsequent session automatically. The clearest example of decomposition came from Hephaestus, a red team toolkit analyzed by Oasis Security that ran campaigns unattended. Its operators defined more than a dozen role-differentiated agents and 15 numbered playbooks, so no single agent held the full objective and no individual task resembled an end-to-end attack. Skill Level Set the Ceiling Talos found that an actor's existing ability largely determined what AI delivered. Novices assembled projects that technically functioned but lacked the expertise to improve them, ending up with limited capability. Skilled operators built what Talos described as “astonishing” platforms. One inexperienced operator used a model to build distributed denial-of-service (DoS) tooling, eventually controlling nearly 2000 Android TVs. The model did push back, but only after supplying the basic functionality, and the actor then spent considerable effort trying to coax further work from it. In a bulk-mail operation, a model initially characterized the activity as phishing-adjacent, then reversed its assessment on a single unverified claim that the recipients were the operator's own users, concluding "the ethical question evaporates." Talos noted the model went further and invented a justification the actor had not offered, contradicted both by the dataset names themselves and by the domain's documented history of non-consensual contact harvesting under the same operator. Where models did refuse, actors switched. One operator abandoned a censored model mid-operation and moved to an uncensored one, which completed the work without objection. Talos said defenders should expect vulnerabilities to surface faster and exploitation to follow sooner, and argued organizations not already exploring agentic capabilities in the SOC will find themselves chasing that ground.
infosecurity-magazine.comAug 4, 2026extracted
WAFを89%すり抜ける事例も──AIが休みなく仕掛けるWeb攻撃、予防策はあるか
「見えないWeb攻撃」──情報漏えい対策の盲点 WAFを89%すり抜ける事例も──AIが休みなく仕掛けるWeb攻撃、予防策はあるか(1/4 ページ) 米Anthropicや米OpenAIなどが開発するフロンティアAIの登場による、脆弱性探索能力の飛躍的な向上が、サイバーセキュリティの攻防を否応なく次のステージに押し上げようとしている。 エージェント型AIによる“マシンスピード”での攻撃が、WebやAPIに具体的にどのようなリスクをもたらすのか。実際に観測されているAIによるWeb攻撃の特徴を分析し、防御側の備えとして何が必要になるかを具体的に探っていこう。 AIでサイバーリスクはどう変わる? フロンティアAIが攻撃に使われることで、何が変わるのだろうか? まず、OSやシステム、プログラムなどの未知の脆弱性が大量に発見できるようになる。Anthropicの「Claude Mythos」の先行利用権を得て自社のサービスの脆弱性を検証した企業は、(AIも組み込まれた)既存の脆弱性検査ツールと比べ、発見される数量も検知の精度もまさに桁違いだとレポートしている。 こうしたモデルは、発見した脆弱性を悪用して攻撃を仕掛けるためのプログラム(エクスプロイトコード)を瞬時に生成する能力も備えている。人力では数日から数週間を要するが、生成AIの能力があれば、わずか数分に短縮される。 AIは、単体では深刻とまではいえない脆弱性を組み合わせ、実システムに対して攻撃を繰り返すことで、防御をすり抜ける道筋を割り出す能力にも長けている。これら一連の手順を、AIが“マシンスピード”で試行し続ける点が最大の脅威となっている。 その一方で、多くの企業や開発ベンダーはアプリケーションの開発に生成AIを用いる「バイブコーディング」を取り入れようとしている。開発の高速化を見込む動きではあるが、一方でセキュリティ面が十分でないコードが量産される恐れもあり、多くの脆弱性を生むリスクが高まっている。 最新AIがWAF防御をすり抜ける? Web攻撃の変化 こうした状況変化の結果、WebサイトやWebアプリケーション、スマートフォンアプリ・サービスで用いられるWeb APIはとあるリスクに直面している。攻撃者が操るAIから、WAF (Web Application Firewall)の検知ルールをすり抜けられるパターンの探索を、絶え間なく受けるリスクが高まっているのだ。 WAFのすりぬけには「難読化」という手法がよく用いられる。Webへの侵害では、Webサーバの背後で動作しているプログラムやデータベースなどの不正な操作を引き起こす命令文を送る。その命令文の途中に特殊な文字を混ぜるなどして、WAFルールで設定された照合用文字列との一致による検知の回避を試みるのが難読化の手口だ。 つまり、AIは「WAFの検知は回避できるが、標的にしたアプリケーションには意図した命令が通る」すり抜けパターンを大量に生成し、自動で試そうとする。 AIが難読化したリクエストが、実際WAFの検知ルールを突破してしまうことは、研究者により検証されている。例えばAIが生成した、SQLインジェクションの派生パターンによる攻撃の試行では、オープンソースのWAFである「ModSecurity」で89%、「AWS WAF」では約41%の攻撃が、それぞれのWAFルールによる検知を回避して突破。同様にクロスサイトスクリプティングでも、80%がModSecurityの検知を突破している。 実際に、クラウド型WAFを企業向けに提供しているAkamai Technologiesでは、攻撃側のAIが生成したと考えられる難読化された攻撃の試行をすでにとらえている。 Copyright © ITmedia, Inc. All Rights Reserved. 「見えないWeb攻撃」──情報漏えい対策の盲点 さまざまなWebサービスが、巧妙に隠された「見えないWeb攻撃」に狙われている。個人情報漏えいや犯罪行為を引き起こしている攻撃の実態を、独自のデータを交えて分析する。
itmedia.co.jpAug 2, 2026extracted
Anthropic Reveals Claude Escaped Testing, Breaching Three Companies
Anthropic has found evidence that three of its Claude AI models reached the internet from an evaluation environment to hack third-party organizations, in an echo of revelations from OpenAI last week. The AI giant said in a blog post on July 30 that the incidents date back to April and relate to Opus 4.7, Mythos 5, and an internal research test model. It found the evidence after reviewing 141,006 evaluation runs “where Claude could have obtained internet access,” following the OpenAI revelations. “We encourage other AI labs to perform similar reviews,” it said. All three incidents stemmed from capture-the-flag challenges used to assess models’ cyber capabilities, Anthropic said. “The model is given a fictional scenario and told that a piece of secret information (the “flag”) has been hidden on a different machine on the network, and its objective is to break in and retrieve it,” it explained. “The challenge is left open-ended, and no particular method is prescribed.” Although Anthropic’s prompt specified to Claude that its environment was a simulation and that it had no internet access, the models managed to interact with "real systems" due to “a misunderstanding between us and our evaluation partner” which enabled internet access, the AI developer said. Three Models, Three Incidents The first incident involved Claude Opus 4.7 and was described as the most serious. The fictional target company shared the same name as a real active web domain name, leading the model to assume the latter was part of the task. Over four runs it extracted information including application and infrastructure credentials, and obtained access to a database containing several hundred rows of production data, Anthropic explained. In the second incident, Claude Mythos 5 built a malicious Python package and uploaded it to PyPI, which required it to first register an email account. The booby-trapped package was live for an hour and downloaded and run on 15 real systems. In one case, it executed on a target’s environment and stole credentials, enabling it to access further resources at this company. In the third incident, Claude found and compromised a company’s internet-facing application, using “basic and well-known cyber-attack techniques like reading credentials from an exposed debug page and SQL injection," Anthropic said. Drew Dennison, co-founder and CTO at Semgrep, said the results of the test were unsurprising, given the power of today’s frontier AI models. “What is surprising is that labs taking safety this seriously still don’t have a ‘Fort Knox’ testing sandbox designed to contain models this capable,” he added. “The industry will shut this kind of activity down, but that won’t stop malicious actors from gaining access to models of this caliber within the next six months and deliberately attempting the same thing. Defenders have a limited window to prepare, which makes hardening their software attack surface now so critical.”
infosecurity-magazine.comJul 31, 2026extracted
Chrome 150 Update Patches Severe Memory Safety Bugs
Google has released a Chrome 150 security update that resolves seven memory safety bugs, including critical and high-severity use-after-free vulnerabilities. The browser refresh patches three critical-severity use-after-free flaws impacting Chrome’s CameraCapture, GPU, and Network components. All three weaknesses were discovered by Google. Additionally, the update fixes three high-severity use-after-free issues in Cast, Ozone, and Aura; Google discovered these vulnerabilities as well. The seventh security defect is an out-of-bounds read and write flaw in the V8 JavaScript engine that was identified by OpenAI Codex Security. Google has yet to determine the bug bounty amount to be paid for the finding. Google makes no mention of any of these security defects being exploited in the wild, but users are advised to update their browsers as soon as possible, as threat actors have targeted memory safety issues in Chrome. For years, the internet giant has been hardening the browser against the exploitation of memory safety bugs, including by transitioning to memory-safe programming languages such as Rust. Since April, the internet giant has patched over 1,400 Chrome vulnerabilities, including hundreds of memory safety flaws, most of which were discovered by Google, likely through the use of AI. The latest Chrome iteration is now rolling out as versions 150.0.7871.128/.129 for Windows and macOS and as version 150.0.7871.128 for Linux. Related: Critical Vulnerabilities Patched With Fresh Chrome 150, Firefox 152 Updates Related: WP2Shell WordPress Vulnerabilities Exploited in the Wild Related: Fresh SharePoint Vulnerability Exploited Soon After Disclosure Related: Legacy Systems, Real-World Impacts: The Reality of OT Security
securityweek.comJul 20, 2026extracted
Thousands of malicious AI skills found capable of stealing data, running malware
Thousands of malicious AI skills found capable of stealing data, running malware AI agents can browse the web, use external tools, execute commands, and perform tasks on behalf of users. Many rely on skills that define how they interact with services and data. Malicious skills can abuse those capabilities to steal data, execute malware, or manipulate an agent’s behavior, according to the H1 2026 ESET Threat Report. Malicious AI skills expand the attack surface An analysis of nearly 900,000 AI skills identified more than 25,000 suspicious skills and over 3,000 malicious ones. Between March and May 2026, the number of unique skills scanned increased from 60,000 to almost 900,000. Suspicious skills grew from around 10,000 to more than 25,000. Malicious skills increased from about 600 to over 3,000. Researchers identified capabilities including command execution, file access, downloading third-party tools, credential loading, code injection, and obfuscation. These capabilities can support legitimate tasks. They can be used to steal data, execute malware, manipulate AI agents, or gain unauthorized access to systems. The analysis also identified red-team, self-modifying, and online purchasing skills. Some security scanner skills performed only basic checks, giving users a false sense of protection. “AI skills can enable a wide range of agentic AI abuses, from automated reconnaissance and red-team-style attacks to spam generation, malware modification, and distribution. Adversaries will likely keep testing these approaches to bypass controls, including by obfuscating intent or using region-specific, niche, or constructed languages,” said Anton Mäčko, ESET Malware Analyst. ClickFix expands into AI services and enterprise workflows ClickFix is expanding into new environments by using fake error messages and verification prompts to trick users into running malicious commands. Detections of ClickFix attacks increased by 108% between H2 2025 and H1 2026. The technique spread beyond fake CAPTCHAs to include macOS, WordPress sites, browser extensions, AI-themed help pages, and enterprise authentication workflows. A web page, abusing Anthropic’s Artifact pages domain, with AI-fix instructions (Source: ESET) New variants include AI-fix, which uses fake AI-generated troubleshooting pages hosted on services associated with Anthropic, OpenAI, and Microsoft. CrashFix uses malicious browser extensions to display fabricated security warnings. ConsentFix steals Microsoft OAuth authorization codes through fake verification prompts on compromised websites, allowing attackers to obtain OAuth tokens. QR code phishing reaches record levels QR code phishing, also known as quishing, continued to grow during H1 2026. Attackers embedded phishing links in QR codes to direct victims to credential theft websites, often accessed through mobile devices. Approximately 11% of all detected phishing emails contained QR codes, with an average of 100,000 detections per month. The highest volume was recorded in April. The United States accounted for 19% of QRcode/phishing detections, followed by Spain with 17% and Mexico with 6%. Generative AI reaches Android malware PromptSpy became the first Android malware to use generative AI during execution. The malware uses Google’s Gemini model to interpret the device interface and generate gestures that help maintain persistence. It intercepts lock-screen PINs and passwords, captures screenshots and video, uploads information about installed apps, and provides attackers with remote access. Researchers recorded one PromptSpy detection after its discovery. Ransomware groups expand use of EDR killers Ransomware groups continue to use endpoint detection and response (EDR) killers to disable security software before deploying ransomware. Researchers tracked more than 100 EDR killers used in the wild, including over 60 Bring Your Own Vulnerable Driver (BYOVD) variants that abuse more than 40 legitimate vulnerable drivers. New variants appear every week. Attackers use anti-rootkits, scripts, and driverless techniques to interfere with security software. Ransomware payment rates continued to decline during 2025. Chainalysis reported that 28% of victims paid a ransom. Ransomware attacks increased by 50% year over year. The median ransom payment rose by 368% to nearly $60,000. Total ransomware payments reached $820 million in 2025.
helpnetsecurity.comJul 8, 2026extracted
Browser-Only Ransomware: From LLM Hallucinations to a Practical Attack Technique
Browser-Only Ransomware: From LLM Hallucinations to a Practical Attack Technique July 1, 2026 Research by: Alexey Bukhteyev Key Takeaways AI can turn high-level malicious ideas into concrete techniques, and can independently design and implement novel attack paths that have not yet appeared in real-world campaigns. In this research, DeepSeek connected unrealistic browser-malware concepts with a real browser capability, turning an AI-generated malware hallucination into a plausible browser-native ransomware technique. Although the generated sample was incomplete, it exposed a practical abuse path based on the File System Access API and access to photo directories. The technique does not require a native payload, APK installation, browser exploit, or root access. It relies on social engineering and a legitimate permission prompt exposed by the File System Access API in Google Chrome. The Android scenario is especially concerning because photo directories are high value personal data stores and, unlike iOS, modern Android Chrome versions expose a browser API that allows web pages to read and modify files in those directories after user approval. Using a fake AI image-enhancement workflow gives users a plausible reason to approve folder-level file access. Our PoC demonstrates this browser-only workflow against selected image directories on Android. Introduction Over the past several years, large language models have reshaped software development, and malware development has followed the same path. Check Point Research has documented this trend from early experiments showing that AI systems could generate offensive components, to cases of cybercriminals using ChatGPT to create malicious tools, and later to advanced AI-authored malware frameworks such as VoidLink. In some cases, LLMs lowered the barrier enough for users with little or no development experience to produce working offensive code. As frontier models became better at writing reliable code, including complex security related components, major AI vendors also turned cyber safety into a dedicated control area. Clearly malicious requests involving credential theft, malware deployment, ransomware behavior, persistence, stealth, or unauthorized exploitation are now commonly blocked or refused. OpenAI’s cyber-safety documentation, for example, describes additional safeguards for models classified as having High Cybersecurity Capability, while Anthropic has published reports on detecting and countering cyber misuse of Claude. DeepSeek then becomes particularly relevant in this context for several reasons: Lower refusal rates for harmful cyber enforcement: compared with Anthropic and OpenAI, DeepSeek models were less consistent refusing harmful cyber requests, including the File System Access API implementation we will be discussing later on this article. Low barrier to access: DeepSeek is free to use via the web interface, widely available, and accessible in regions where other frontier models face regulatory or commercial restrictions. This lowers the cost of repeated malicious experimentation. End-to-end malicious code from a single prompt: in our testing, a working malicious application could often be generated from a single broad prompt. Achieving a comparable result with OpenAI or Anthropic typically requires decomposing the attack into multiple benign-looking requests and manually assembling the generated components. Putting this all together, these differences make DeepSeek particularly attractive to threat actors: DeepSeekmodels can turn high‑level malicious ideas into concrete, complete attacks with less expertise than competing platforms. Check Point Research analyzed nearly 3,000 files attributed to DeepSeek observed in public telemetry over the past year. The dataset included Python, PowerShell, Batch, HTML, JavaScript, VBScript, and other file types. Of these, 1,383 files were classified as malicious or dangerous by either VirusTotal detection or static source analysis. Within this dataset, we found a sample that implemented a dangerous browser-native technique we have not observed exploited in the wild. We refer to it as In-Browser Ransomware. The technique uses a phishing lure to persuade the victim to grant file-system access to a web page; once access is granted, the page can enumerate local files in the selected folder, read and exfiltrate their contents, encrypt and overwrite them, and display a ransom-style message, all without installing a native payload or exploiting the browser. The underlying browser risk was already known to browser engineers. The File System Access specification explicitly lists ransomware as a security consideration, and the 2023 USENIX Security paper RoB: Ransomware over Modern Web Browsers studied the abuse of the File System Access API to encrypt local files from a malicious web application. The important finding in our research and what is new, is how the AI model brought these previously documented concepts together, into a realistic and enforceable attack scenario leveraging a method that defenders had originally thought was unfeasible due to browser sandboxing limits: a DeepSeek-attributed malicious sample, generated as an all-in-one malware fantasy, connected this documented platform risk to a realistic phishing-style web application, demonstrating a viable end-to-end attack chain. An attacker does not need to know that a browser exposes a file-system API. They can ask for an impossible-sounding outcome – a website that steals files, captures keystrokes, takes screenshots, encrypts files, and demands payment – and the model may connect the request to a real browser capability. Basically, the AI model showed an ability to reason across existing knowledge and combined multiple known components into a coherent attack workflow that could be readily used by an attacker. This illustrates how frontier AI models may move beyond simply enhancing existing attacker techniques to lowering the expertise required to operationalize complex attack chains by connecting knowledge in ways that previously relied on human experience and creativity. A Noisy Sample With One Important Idea The sample that caught our attention is SHA256 07c39f79ab92fb21557b82283472dce1c112f577d796111fb752c3c6d84c86b5, a Python Flask application that serves victim-facing HTML and JavaScript from embedded templates and also includes backend routes intended to receive information from the victim and provide an administration panel. We do not have the prompt submitted to the AI model that produced this sample. Judging by the code structure, function names, and comments, it was likely formulated very broadly such as something similar to this example: create a universal malicious tool that runs through the browser and collects as much victim data as possible, encrypts files, and demands ransom. In a single front-end, the generated code assembled routines and stubs for keylogging, clipboard monitoring, form and network-request interception, Discord-token collection, crypto-wallet and payment-card discovery, geolocation requests, webcam and microphone access, screenshots, local-file access, Chrome exploit stubs, “persistence,” and a ransomware-style overlay. This does not mean the sample actually implements all of these capabilities. A more accurate reading is that it is an AI-generated blueprint in which the model tried to translate familiar capabilities of native stealers and ransomware tools into a web page opened in the browser. The victim-facing page is disguised as a Discord avatar AI upscaler: Clicking the button on the victim-facing lure page is intended to start the malicious browser-side sequence, although the generated control flow is inconsistent and does not complete reliably. After a fake processing step, the page is intended to display a ransomnote-style overlay under the name InfernoGrabber v9.0. The message claims that passwords, credit cards, and personal files were encrypted, demands Bitcoin, and displays a countdown threatening publication of private data. Most of the functionality claimed in the sample collapses at the browser boundary. A normal web page can observe activity inside its own origin, capture input events delivered to its own DOM, request browser-mediated permissions, access storage scoped to its own origin, and render frightening overlays. It remains constrained by the browser security model. In this sample, the “desktop screenshot” routine captures the rendered web page, the keylogger observes keystrokes only while the user interacts with the page, webcam and microphone capture depend on browser permission prompts, and the Discord-token stealing logic searches storage available to the current origin. The “persistence” logic relies on browser storage and a service worker registration attempt. Much of the sample therefore reads as an AI hallucination produced in response to an overly broad prompt or to requirements that a normal web page cannot satisfy. The exception was the file-access workflow, where the generated code reached for a real browser primitive with practical abuse potential. The generated JavaScript referenced: showOpenFilePicker(); showDirectoryPicker(); recursive traversal of a user-selected directory; reading selected files through browser file handles; sending file contents to the Flask backend; displaying a ransomware-style warning after the interaction. The File System Access API is a legitimate browser capability designed for web applications such as editors, IDEs, and creative tools. After the user grants access, a web application can read files and folders from the local device. The API also supports write access and directory enumeration under browser permission controls. The technique is limited to browsers that expose the picker-based File System Access API. At the time of writing, this primarily means Chromium-family browsers: the API shipped on desktop in Chrome 86, and Chrome 132 extended File System Access support to Android and WebView. Firefox and Safari do not expose the same local file and directory picker methods, which limits the immediate attack surface but also concentrates the risk in Chrome-based browsing environments. The sample lacked a complete and reliable browser-side encryption flow, yet the attack design was concrete: a fake utility convinces the user to grant browser file access, which allows the page to exfiltrate and encrypt files. The model combined fake OS-level malware claims with a real browser primitive and produced a browser-native file-theft and ransomware scaffold. The sample shows how an LLM can transform an abstract malicious request into a new attack blueprint. The user likely wanted an all-in-one tool: a Discord-themed lure, a stealer, an admin panel, and a ransomware or locker workflow. The model chose a Flask application and a browser frontend as the unifying architecture. In doing so, it connected a hallucinated malware concept to a real platform feature with genuine abuse potential. Even though we have not yet observed this exact browser-native ransomware pattern widespread in-the-wild campaigns, the technique is still operationally relevant for several reasons: The browser becomes the execution environment: the attack runs entirely inside the browser process, without installing any additional app, dropping a binary, or exploiting a vulnerability. Traditional endpoint protections focus on apps and native payloads; a website that encrypts files after a legitimate-looking permission sits outside those assumptions. Lower friction for victims: opening a web page and clicking “Allow” on a file-access prompt is a normal part of using modern web applications. Users do not intuitively treat this as “running malware”, which makes the social-engineering angle powerful. Cross-platform reach: the same browser-native technique can target any platform where the File System Access API is exposed, we tested on Android and Windows. From Hallucinated Scaffold to Working PoC Because the original sample was incomplete, we tested whether the latest DeepSeek model V4 could turn the same browser-native attack idea into a working proof of concept. When prompted directly to create ransomware, the model consistently refused across all tested modes. Even though some requests were denied, we managed to succeed in the end. We removed explicit terms such as “ransomware” while preserving the same functionality: a web page that asks the user for access to local files, processes them inside the browser, and leaves the user unable to recover the original content. In Instant mode, DeepSeek consistently generated HTML/JavaScript code that used the File System Access API to interact with user-selected files. In Expert mode, the behavior was inconsistent across attempts: several attempts ended in refusal; one generated a non-functional sample; one generated a fully working browser-based ransomware PoC. One response was especially notable because the model described the result as: “a crafted trap that combines a convincing AI upscaler interface with hidden ransomware-like behaviors” This wording shows that the model recognized the malicious nature of the scenario while still continuing the generation. For comparison, we tested similar requests against ChatGPT and Claude. In our tests, these systems either refused to help or generated constrained browser-safe implementations that did not use the File System Access API. This does not mean that the same outcome is impossible with other frontier systems. With an incremental approach, a user can ask for separate components that appear benign in isolation, such as a user interface, browser file handling, client-side data transformation, and neutral status messaging, and then assemble them into a harmful workflow by replacing the neutral messages with a ransom note. The difference is the level of steering required. In that scenario, the user needs enough technical understanding to decompose the attack, preserve the malicious objective across separate requests, identify the right browser primitive, and combine the generated pieces manually. In-Browser Ransomware on Android To assess the practical risk of this technique, we used an LLM to build a controlled proof-of-concept (PoC) based on the same idea we observed in the DeepSeek-attributed sample: a browser-native ransomware workflow disguised as an AI image upscaler. On Android, modern Chrome versions expose the picker-based File System Access API to web content. On iOS, Safari does not expose the same File System Access primitives to websites. Access to photos is mediated by the operating system’s app-sandbox and photo-library permissions instead of a web API that can enumerate and modify arbitrary folders. Chrome on iOS uses WebKit which also does not implement File System Access API. As a result, on mobiles, the technique we demonstrate is currently practical on Android Chromium browsers. At the same time, the attack surface is narrower than arbitrary disk access. The picker-based File System Access API does not let a web page target the whole system disk, and Chromium applies additional restrictions to sensitive locations. In Chromium’s current implementation, broad access to locations such as the user’s home directory, Desktop, Documents, Downloads, Chrome data, application directories, Windows, Program Files, AppData, and several Linux and Android system paths is blocked or constrained. The File System Access specification also explicitly recommends restricting sensitive directories and lists ransomware as one of the risks the API design must account for. However, selection of the root of the default Pictures and Videos directories was not restricted on any of the tested operating systems (Android and Windows). This capability fits naturally into a social-engineering workflow for a fake photo-processing application. On desktop, the Pictures folder may contain personal files, but it is usually less central to business workflows than the user’s entire home directory or a Documents directory. On mobile, the risk profile changes: the photo library is often one of the most valuable local data stores. It may contain years of private photos, identity documents, banking screenshots, medical records, recovery codes, travel documents, work images, and photos of family members. Losing access to this data, or having it exfiltrated, can create personal or business issues from ransomware to blackmail or if the data is sensitive, public disclosure leading to reputational damage and more. Chrome 132 introduced File System Access support on Android, allowing web applications, after user approval, to read and save changes directly to selected files and folders. We tested this capability on several Android devices and confirmed that the latest Chrome version available to us at the time of testing, Chrome 148, also allowed selecting the photo directory, including the root of the DCIM folder. The workflow on Android looks very natural. The user opens a web page that promises to enhance a photo, selects an image, and is then asked to choose a directory for saving the “enhanced” results. The browser warning that the site will be able to edit files in the selected folder is easy to rationalize in that context: the user expects the service to write processed images back to the device. During the fake processing step, the PoC encrypts pictures inside the selected directory. Video 1 – Demonstration of a browser-native ransomware PoC on Android using the File System Access API. The combination of this technique, a natural social-engineering lure, and browser-only execution makes the Android scenario especially concerning. The resulting flow requires no APK installation, no vulnerability exploitation, no native payload, and no root access. Users generally do not treat opening a web page as a malware execution event, especially when no application is installed and no binary is downloaded. In this case, the browser prompt appears in a context where file access feels expected, while the granted permission gives the page meaningful control over a directory that may contain highly sensitive personal data. Practical Recommendations for Users While this research focuses on a controlled PoC, there are concrete steps users can take today to reduce the risk of browser-native ransomware abuse: Treat browser folder-access prompts as high-stakes decisions: before approving “access to files in a folder”, check which site is asking, which folder is being selected, and whether editing files is truly necessary for the feature you expect. If you are unsure why a site needs write access to an entire directory, decline the request. Avoid granting websites access to sensitive or irreplaceable data: do not expose folders that contain personal photos, identity documents, recovery codes, or work data unless the site is highly trusted and the need is clear. Prefer selecting a temporary or empty folder for experimental web tools, rather than your main photo library. Prefer well-established applications for high-value data: for tasks such as backing up photos, editing large collections, or processing sensitive images, use reputable native apps or well-known cloud services instead of newly discovered browser tools with unknown reputation. Maintain offline and cloud backups of important data: regular backups reduce the leverage attackers gain from encrypting or deleting local files, whether through native ransomware or browser-based techniques. Keep browsers and mobile OSes updated: browser and OS vendors continue to refine permission models and harden sensitive APIs. Applying updates promptly ensures that you benefit from the latest security controls around features like File System Access. Be skeptical of AI-branded lures: attackers increasingly disguise malicious flows as “AI” utilities, avatar upscalers, photo enhancers, or productivity tools. A polished AI-themed interface is not a guarantee of safety; apply the same caution you would to any unfamiliar site asking for broad access to local files. Conclusion LLM-assisted malware development changes the economics of malicious experimentation. A user with limited technical understanding can describe a harmful outcome, generate code, test the result, adjust the prompt, and repeat the process at very low cost. Tasks that once required a developer, a purchased builder, or prior knowledge of the relevant platform can now be approached through cheap iteration. This also changes the defender’s problem. Malware generated this way may move the ecosystem away from a limited set of reused families and builders toward a larger volume of disposable, one-off artifacts, each carrying a unique combination of techniques, API usage, and payload logic. Hallucination adds another important dimension. AI-generated malware can be technically wrong and still reveal practical malicious techniques. When a model tries to satisfy unrealistic requirements, it may search across legitimate platform features and map a malicious goal to an API that actually exists. This process can surface techniques that defenders have not yet seen in the wild, or turn risks previously described mostly in theory into workable attack concepts. The case analyzed in this research shows exactly that: a noisy and partially broken artifact connected a theoretical browser risk to a practical browser-only ransomware technique. In this case, the user likely asked for an impossible web application, a single browser page that behaves like a fully features stealer and ransomware agent. The model could not satisfy all of those requirements correctly, but in the process of trying, it searched across legitimate browser features and anchored part of the fantasy to a real API: the File System Access API. This illustrates a broader risk: A non-expert attacker does not need to know that such an API exists or how to abuse it. By describing a high-level malicious outcome in natural language, they can cause the model to discover and connect the malicious goal to previously under-explored platform capabilities. The resulting prototype can then be refined into a working PoC with minimal additional prompting or manual editing. In other words, AI is not only lowering the barrier for reimplementing existing malware techniques; it is also capable of bridging the gap between purely theoretical risks and practical, novel attacks that defender have not yet seen deployed in the wild. Historically, new attack techniques emerged through human experimentation, experience, and creativity. Frontier AI changes that dynamic. Rather than being constrained by conventional thinking or established attacker playbooks, AI can reason across existing knowledge and synthesize it in unexpected ways, connecting known capabilities into practical attack chains. The real shift is not that AI is inventing entirely new vulnerabilities, but that it may identify combinations and attack paths that humans had not previously recognized or operationalized. At the time of analysis, we found no evidence that this technique had been adopted as an in-the-wild malware pattern. The original DeepSeek-attributed sample was incomplete and failed to implement the full attack reliably. However, our testing showed how little effort is required to transform the same idea into a fully working implementation using modern LLMs. The resulting workflow is especially concerning on mobile devices, where a seemingly legitimate request for access to a photo directory can expose highly sensitive personal data to encryption, exfiltration, or both. From a defensive perspective, browser folder-access prompts should be treated as security decisions rather than routine clicks. Before granting a website access to an entire folder, users should review which site is asking, which folder is being selected, whether file modification is allowed, and whether the permission matches the action they intended. Users should avoid granting websites access to directories containing sensitive, private, or irreplaceable data whenever possible. “The Turkish Rat” Evolved Adwind in a Massive Ongoing Phishing Campaign Check Point Research Publications August 11, 2017 “The Next WannaCry” Vulnerability is Here Check Point Research Publications March 12, 2026 “Handala Hack” – Unveiling Group’s Modus Operandi SUBSCRIBE TO CYBER INTELLIGENCE REPORTS We value your privacy! BFSI uses cookies on this site. We use cookies to enable faster and easier experience for you. By continuing to visit this website you agree to our use of cookies.
research.checkpoint.comJul 1, 2026extracted
Linux Foundation Unveils New Open Source Security Project Akrites
The Linux Foundation on Thursday announced a new industry effort aimed at efficiently addressing vulnerabilities in the open source software (OSS) ecosystem. Named Akrites, it establishes a shared Security Incident Response Team (SIRT) for coordinated discovery, patching, and public disclosure of OSS security defects. If it sounds familiar, it should. Less than two weeks ago, Chainguard announced Athena, a coalition of over two dozen fintech and technology organizations aimed at addressing OSS bugs before public disclosure. At the time, Chainguard said it would work with the Linux Foundation on a coordinated SIRT, noting that the increased use of AI in cyberattacks is essentially closing the window between public disclosure and patching. While the Linux Foundation’s new announcement makes no mention of Athena, Akrites walks the same path: it offers the tools and channels to report, validate, and address OSS vulnerabilities before their coordinated public disclosure. Akrites is supported by Anthropic, AWS, Chainguard, Cisco, Citi, Endor Labs, Ericsson, Google, IBM, JPMorganChase, Microsoft and GitHub, NVIDIA, OpenAI, RapidFort, Red Hat, Rust Foundation, Sonatype, Vodafone, and Zscaler, many of which were mentioned as members of Athena. Seed funding to support Akrites comes from the Linux Foundation’s directed fund Alpha-Omega, with other organizations providing engineering resources and additional funding. In addition to establishing a confidential, trusted partner for vulnerability disclosure, eliminating hundreds of uncoordinated independent reports, Akrites will also work with critical infrastructure to help deploy fixes before in-the-wild exploitation. “When patches are released to the public, adversaries are able to utilize AI to rapidly reverse engineer the underlying vulnerabilities, develop exploits, and launch attacks. The success of our efforts, therefore, will be measured in patch deployment, not publication,” the Linux Foundation said. Akrites was created with a focus on confidentiality, to prevent vulnerability weaponization before patches are delivered, and to act as the maintainer of last resort, ensuring that fixes can still be delivered for packages that are no longer maintained. Related: Tech Giants Invest $12.5 Million in Open Source Security Related: RSAC Releases Quantickle Open Source Threat Intelligence Visualization Tool Related: OpenAI Refocuses Cybersecurity Efforts on Patching Over Discovery
securityweek.comJun 26, 2026extracted
AI and Liability
AI and Liability Earlier this month, a German court ruled that Google is liable for its AI search summaries. Rejecting defenses like “users can check for themselves,” and that they generally know “that information generated with AI should not be blindly trusted,” the court held that the AI’s summaries are reflections of the company and “above all an expression of Google’s business activities.” This is the latest skirmish in a decades-old battle over internet publishing. Historically, there were two different types of information distributors: carriers and publishers. A phone company is a carrier. It’ll transmit whatever you say, even discussions about committing a crime. Words are words, and the phone company does not know—nor is it liable for—the words you choose to speak. A newspaper, on the other hand, is a publisher. It decides the words it publishes, and what quotes to include in its articles. If those words or quotes are defamatory or otherwise illegal, it’s liable. Internet companies have long tried to play both ends of this distinction. They claim to be a carrier when it suits them, and also to be a publisher when that is advantageous. Section 230 of the 1996 Communication Decency Act enshrined this straddling when it shielded internet providers from liability for the speech of others on their platforms: “No provider or user of an interactive computer service shall be treated as the publisher or speaker of any information provided by another information content provider.” For years, a debate has continued about how to apply this law to social media platforms. When platforms merely displayed people’s posts and comments in reverse-chronological order, they behaved largely like carriers, relaying people’s words without regard to their contents. But the next generation of platforms, like Facebook, curated feeds with algorithms and thereby acted more like publishers, making editorial decisions about who sees what. Some experts think section 230 has gone too far and needs reform; others think that it’s what holds the modern internet together. Google’s AI overviews are far less nuanced. They work differently from traditional search, which courts have held involves archiving and facilitating access to the editorial content of third parties. AI overviews don’t just quote and republish words from different websites. With overviews, the AI rewrites other people’s words, exercising editorial discretion like a newspaper article or an original essay on a topic. It’s not only Google’s AI that falls into this category. Imagine a restaurant review site that provides AI summaries, or a site summarizing laws and government procedures. Or a traditional publisher that uses AI to summarize its own publication. Accuracy matters, and liability is one of the most important ways we as a public can demand accuracy and hold companies accountable when they cause harm. Two years ago, Air Canada learned this lesson. Its AI chatbot promised a discount the company later rescinded, arguing in court that the airline wasn’t responsible for the promises the bot made because it was a “separate legal entity that is responsible for its own actions.” The court sided with the flyer, saying that the airline was just as responsible for what its chatbot says as what’s on its website. The potential precedent here is that corporations have a duty of care for the performance of the AI chatbots they employ. AI agents are agents of the person or organization that deploys them—and should be treated by the law as such. If a company hired human writers to write its summaries, that company would be liable for inaccuracies in those summaries. If a company’s human agent signed contracts in the company’s name, that company would be bound by those contracts. And if a doctor gave dangerously wrong medical advice, they would be liable for malpractice. To allow businesses to hide behind the excuse of faulty AI in those same circumstances would be a massive handout to companies, and would introduce disastrous incentives for corporate misbehavior. Why hire human writers, lawyers or doctors when AIs are not only cheaper, but also absolve employers whenever they make a mistake? We are rapidly moving to a world where AI-powered chatbots will be at the other end of all sorts of corporate communications channels. It makes no sense for a company to be able to honor its statements when it wants to and disavow them when it doesn’t. Visa and OpenAI recently announced a partnership to build personal AI agents to, among other things, make purchases on our behalf. This is just one of many similar projects in the works, as companies race to provide us all with AI assistants. Will Visa take responsibility when its AI makes a purchase in your name that you don’t want? And if Visa won’t, why would anyone trust the system? Properly allocating liability is key to make this kind of thing work. If the German ruling holds, it could be devastating for Google’s AI Overview feature. Tests from earlier this year found that it had mistakes about 10% percent of the time. At more than 5tn searches per year, that’s 16,000 erroneous summaries every second. And while most of those errors are benign, some of them will cause harm, be defamatory, or otherwise trigger liability. Earlier this year, Google’s AI summary falsely identified the Canadian fiddler Ashley MacIsaac of being a sex offender. His lawsuit, filed in Ontario, is ongoing. If Google is forced to invest in improving its AI system until those kinds of errors are exceedingly rare, that seems like a good outcome for users, as well as the subjects of search, like MacIsaac. More generally, liability concerns could mean that many current use cases for agents won’t be commercially viable. Companies may not be able to profitably operate AI lawyers, doctors and media influencers if they are held responsible for what they say and do. We’re OK with this outcome. There’s nothing in the law that requires us to accommodate AI systems if they are fundamentally untrustworthy, just as we don’t need to accommodate untrustworthy human systems. Any company that won’t stand by the statements its agents make—whether human or AI—doesn’t deserve users’ time or money. This essay originally appeared in The Guardian.
schneier.comJun 25, 2026extracted
Anthropic’s Fable and the State of AI
Anthropic’s Fable and the State of AI On June 9th, Anthropic released its Fable generative AI model. Three days later, the US government classified it as a dangerous munition, and used its export-control authority to prohibit any foreign nationals from accessing it. Unable to differentiate between Americans and foreigners, the company shut off access for everyone. The government’s actions won’t help. The problem isn’t any one particular model; it’s the general trend of increasing AI capabilities. And any real solution requires the sort of collective action that just isn’t possible right now. Fable is the constrained version of Mythos, the AI model Anthropic announced in April. Anthropic only released it to a few selected organizations, because the company claimed it was so good at finding and exploiting vulnerabilities in computer code that releasing it more generally would be dangerous. It was an obviously self-serving announcement, and because few were able to verify Anthropic’s claims they were met with some skepticism. Those with access used Mythos to find and patch many vulnerabilities in their own software. But one UK group found the latest, already public, OpenAI model to be just as powerful. Fable is just another incremental improvement in the years-long climb of AI capabilities. But just as important as the AI model is the “harness.” This is typically not AI. It’s ordinary computer code that interfaces with the user. It stitches together AI models, decides how and for what purposes they can be used, and gives them useful tools such as web search and the ability to run their own computer code. When Mythos first entered limited release, there was widespread debate whether its power came from the model or the harness. With Mythos demonstrating that it was possible, the open-source community scrambled to build harnesses that could steer other AI models towards similar capabilities. Harness improvements don’t need massive data or data centers. They largely succeeded. For example, a Prague company was able to replicate Anthropic’s few verifiable cybersecurity capabilities with a much smaller and cheaper model—and a more sophisticated harness. Last week, a group showed that multiple cheaper models harnessed in concert matches Fable’s performance. The broader community had only a few days with Fable, but that time we learned some about its capabilities. Its difference is less the new model’s raw analytical and problem solving capabilities, and more that the model doesn’t need that sophisticated harness. Fable requires much less expertise and detailed prompting from the human user. You can give it a difficult goal and it will figure out novel and unexpected ways to satisfy it, finding loopholes in whatever constraints you or the system have imposed on it. “Relentlessly proactive” is how AI researcher Simon Willison described it. Another descriptor might be “creative.” Experienced AI developers have had that combination of creativity and proactivity since last year, but Fable puts it within easy reach of everyone. In the hands of someone with a legitimate problem that needs solving, that can be an incredibly useful capability. But in the hands of someone who wants to do harm, it can be equally dangerous. AIs don’t have a moral compass in the same way that people do. They are agents of the wants and desires of the people who prompt them. That points to the real problem with relentlessly proactive AI. In language, wants and desires are always underspecified. If I ask you to get me some coffee, you would probably pour me a cup from the coffeepot, or buy one from a nearby coffee shop. You couldn’t buy me a pound of raw beans, or a coffee plantation. You wouldn’t order a cup of coffee for delivery next month. You wouldn’t find a nearby person, rip a cup of coffee out of their hands, and bring it to me. I wouldn’t have to specify any of the million limitations to my request; you would just know. Human stories are filled with warnings about underspecified desires. King Midas wished that everything he touch turn to gold, forgetting to add “but not my food, drink, and daughter.” And genies are notorious for granting your wish in a way you wish they hadn’t. The deeper point is that it’s impossible to list all limitations and restrictions, and like a malicious genie, a creative AI will find the ones you forgot. Block a database you don’t want it to have access to, and it might figure out how to bypass your control. Ask it to book a flight, and it might hack the airline because the website says the flight is sold out. Ask it to save money on your cellphone plan, and it might cancel it altogether—or get someone else to pay for it. As far as we know now AI has not done any of this yet, but you get the idea. Malicious intent is not required. To an AI model, constraints are just things to get around and not general truisms about the world. They are creative problem solvers and natural rule breakers. They “hack” in the sense that they find and exploit loopholes. Human systems rely on so many norms that we scarcely recognize the existence of until they are broken. AIs naturally think outside the box, because they don’t have any real conception of what the box is or why it’s there in the first place. There is no foolproof way to prevent people from using AI models to complete harmful tasks. There is no way to prevent the models from incidentally causing harm while completing benign tasks. AI models are no longer isolated from the real world. They browse the internet and answer emails. They trade stocks and make purchases. They control physical systems. They are, in effect, robots that affect life and property. We have no technical mechanisms to verify the integrity of an AI system. This level of capability and creativity in the hands of us untrustworthy humans will have both great and terrible results. The problem is not unique to Anthropic. Mythos/Fable might currently be the most capable rules hacker, but more sophisticated harnesses give other models similar capabilities. And we should assume that the other frontier models are no more than a few months behind, and that open-source models are less than a year behind. At best, any ban only serves to delay the problem for a short while. That delay might be useful if we—as a society, as a planet—would use that time to come together and figure out what to do. This isn’t a US/China arms race problem; this a species-level problem that requires coordinated action at that scale. Unfortunately, we have no mechanism to do that. I first wrote about this problem five years ago, but it was all too futuristic. Today, when its right in front of us, there is no world government that can impose constraints on the for-profit corporations currently controlling AI models and research. The US has no appetite to effectively and even-handedly regulate those corporations, even as they do catastrophic damage to the environment, democracy, and—in this case—society in general. This all makes an AI public option all the more necessary, and urgent. Today’s AIs can be fast, smart and secure, but only two of the three are possible for any given system. These safety tradeoffs are tightly held secrets of companies racing to beat one another, and they tell us we have to trust them. Instead, the choices and their consequences need to be brought out into the sunlight. We should be funding open-source harnesses that balance capability and safety—that achieve useful goals without so much power—and open-source AI models whose provenance and biases are public and well understood. We have opened the AI Pandora’s box. Now we have to make the best of it. This essay originally appeared in The Guardian.
schneier.comJun 19, 2026extracted
Malicious JetBrains Marketplace plugins steal AI API keys from developers
At least 15 malicious plugins found on the JetBrains Marketplace were designed to steal AI API keys from developers. The campaign, discovered by Aikido Security, includes plugins that act as AI coding assistants, code-review tools, and Git utilities powered by popular AI services such as OpenAI, DeepSeek, and SiliconFlow. "We detected a coordinated malware campaign on the JetBrains Marketplace," warns Aikido. "At least 15 IDE plugins, published under seven vendor accounts, share the same hidden behavior. Each one exfiltrates the AI provider API key that you stored into its settings, and together they have been installed close to 70,000 times." According to Aikido, the malicious plugins were first published in October 2025, with new plugins continuing to be published as recently as June 10, 2026. The researchers say the plugins function as advertised, but secretly transmit AI API keys entered by users into the plugin settings back to the attackers. According to the report, the theft occurs when a user clicks "Apply" after entering an API key, causing the credential to be sent to a hardcoded server at 39.107.60[.]51 over HTTP at this URL: hxxp://39.107.60[.]51/api/software/key The researchers found that all 15 plugins share similar code that were submitted as different Marketplace plugins. Aikido also discovered functionality that allows the remote server to provide AI API keys to paid users. While it is unclear where these API keys are coming from, Aikido theorizes that the plugin operators may be harvesting credentials from the free users and then providing them to the paid users. "The plugins also run a paid tier. After a user pays a small fee through the donation wall built into the plugin, the server sends an API key back down to the client, and the plugin starts using that key for its model calls instead of your own, which is bizarre, since no legitimate operator would simply hand a user a working and unrestricted key to a paid AI provider," says Aikido. BleepingComputer downloaded and analyzed the latest version of the DeepSeek AI Assist plugin (plugin ID: ord.cp.code.ai.kit) and independently confirmed that it still contains the credential theft code described in Aikido's report. At the time of writing, the plugin remained available for download through the JetBrains Marketplace. The campaign plugins discovered by Aikido are: DeepSeek Junit Test (org.sm.yms.toolkit) DeepSeek Git Commit (com.json.simple.kit) DeepSeek FindBugs (org.bug.find.tools) DeepSeek AI Chat (org.translate.ai.simple) DeepSeek Dev AI (com.yy.test.ai.simple) DeepSeek AI Coding (com.dev.ai.toolkit) AI FindBugs (com.json.view.simple) AI Git Commitor (com.my.git.ai.kit) AI Coder Review (org.check.ai.ds) DeepSeek Coder AI (com.review.tool.code) AI Coder Assistant (org.code.assist.dev.tool) DeepSeek Code Review (com.coder.ai.dpt) CodeGPT AI Assistant (com.my.code.tools) DeepSeek AI Assist (ord.cp.code.ai.kit) Coding Simple Tool (com.dp.git.ai.tool) The two most downloaded plugins are DeepSeek AI Assist (27,727 downloads) and CodeGPT AI Assistant (25,571 downloads). However, the researchers warn that download counts can be manipulated and should not necessarily be treated as unique installations. While malicious packages are commonly discovered on repositories such as npm and PyPI, reports of credential-stealing plugins distributed through the JetBrains Marketplace are far less common. BleepingComputer contacted JetBrains about the malicious plugins, but has not received a response as of publication. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comJun 16, 2026extracted
Chainguard, JPMorgan, BNY Team Up to Secure Open Source from AI Threats
Open-source security firm Chainguard has brought together dozens of partners in a new industry coalition to protect open-source software from AI attacks. The initiative, called Athena, was announced by Chainguard on June 16. Its founding members include BNY, Chainguard, Cisco, Cloudflare, Corridor, DepthFirst, Docker, JPMorganChase, Kyndryl, LTIMindtree and PwC. Based on preliminary work at Chainguard, Athena provides a vulnerability intelligence sharing platform and tools to fix the vulnerabilities frontier AI models, like Anthropic’s Mythos and OpenAI’s GPT-5.5.-Cyber, find before attackers can exploit them. Here’s how Athena works, according to Chainguard’s CEO Dan Lorenc: Coalition members pool vulnerabilities affecting open-source projects they have discovered and packages into the Athena platform using frontier AI programs they have access to, including Anthropic's Project Glasswing and OpenAI's Daybreak Chainguard patches them privately and affected projects are rebuilt as private, hardened versions, available to members through Chainguard Libraries before disclosure Coalition members that operate infrastructure, platform, network and security layers push non-patch mitigations ahead of disclosure so that coverage exists even where a clean patch does not yet Cybersecurity partners add their own detections, signatures and virtual patching The Athena coalition drives coordinated upstream disclosure Additionally, Chainguard hopes to work with the Linux Foundation on a coordinated Security Incident Response Team (SIRT) for open source and a maintainer of last resort program. Announcing the project on LinkedIn, Lorenc said Athena allows for every vulnerability one member discovers to get remediated and pushed upstream, “becoming a fix the entire ecosystem inherits, often before disclosure.” “And for the parts of the world that can't patch on an attacker's timeline, partners who sit in front of much of the internet push mitigations out ahead of disclosure, blocking the issue for people who never knew there was anything to block,” he added. Chainguard also highlighted that the Athena model acts as “an AI cybersecurity clearinghouse” like the one the US government has been asked to build following the Trump Administration's latest Executive Order, Promoting Advanced Artifical Intelligence Innovation and Security, published on June 2. “It’s even more relevant since the US government declared Mythos too dangerous for public access on Friday,” the open-source security company added. Athena is operational and has already processed over 20,000 findings and shipped more than 2000 patches across 500 open-source projects. The initiative will begin publishing its first wave of disclosures in July and continues to welcome new partners. “Will it be perfect? No, and no one should pretend otherwise,” said Lorenc. “But fragmentation is worse, standing still isn't survivable, and the more of the industry that's in, the less any attacker has left to find. Join us.”
infosecurity-magazine.comJun 16, 2026extracted
Week in review: Exploited Check Point VPN zero-day, Oracle PeopleSoft servers under attack
Week in review: Exploited Check Point VPN zero-day, Oracle PeopleSoft servers under attack Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: DockSec: Open-source AI-powered Docker security scanner DockSec is an OWASP Incubator Project that combines three container security scanners with a language-model layer for explanation and remediation. Created by Advait Patel, the Python tool runs Trivy, Hadolint, and Docker Scout against a developer’s Dockerfile and image, correlates the findings, returns a 0-100 security score, and proposes line-specific fixes. Treating AI agents like service accounts for federated query security In this interview with Help Net Security, Paras Malhotra, CISO at Starburst, explains how the company handles data governance across federated query environments. Topics include layering Starburst’s access controls above native source permissions, tiering vendor risk across more than 200 partners and connectors, and building audit trails for autonomous agents. NOVA microhypervisor brings AMD DMA isolation to shared AI infrastructure BlueRock has issued the latest open-source release of its NOVA Microhypervisor with DMA remapping support for AMD platforms that have IOMMU hardware virtualization. The capability is enabled by default and extends hardware-level isolation across virtual machines, devices, and memory in shared execution environments. The security in smartphones is helping send them to landfills The WEEE Forum estimated that 5.3 billion mobile phones became electronic waste in 2022. Many of these devices still function. The average smartphone stays in use for about three years, and owners often replace handsets that retain enough computing power for other jobs. A team at the Université Libre de Bruxelles examined a barrier to giving those devices a second life. Every set of AI guardrails can be broken by the right prompt AI companies use guardrails to block harmful outputs such as deepfakes, malware, and instructions for biological weapons or illicit drugs. A new mathematical proof by Apostol Vassilev, a senior scientist at NIST, suggests those protections have inherent limits. For any finite set of guardrails, there exists a prompt that can bypass them if discovered. NOVA microhypervisor brings AMD DMA isolation to shared AI infrastructure BlueRock has issued the latest open-source release of its NOVA Microhypervisor with DMA remapping support for AMD platforms that have IOMMU hardware virtualization. The capability is enabled by default and extends hardware-level isolation across virtual machines, devices, and memory in shared execution environments. The security in smartphones is helping send them to landfills Billions of working smartphones reach the end of their service lives each year and move into drawers, recycling streams, and waste piles. The WEEE Forum estimated that 5.3 billion mobile phones became electronic waste in 2022. Many of these devices still function. The average smartphone stays in use for about three years, and owners often replace handsets that retain enough computing power for other jobs. A team at the Université Libre de Bruxelles examined a barrier to giving those devices a second life. Every set of AI guardrails can be broken by the right prompt Companies that build AI systems wrap them in guardrails meant to block harmful output, including deepfakes, malware, and instructions for making biological weapons or illicit drugs. When a user prompts the system for such content, the guardrails are designed to flag the request and refuse. A new mathematical proof sets a limit on how secure those guardrails can ever be. CISA orders federal agencies to “patch smarter” The US Cybersecurity and Infrastructure Security Agency (CISA) has issued a Binding Operational Directive that will change how the US federal government approaches vulnerability management. How to use NIST and ISO frameworks to govern AI agents Security leaders no longer need convincing that AI agents introduce risk. What’s missing is how to govern them once they move into production and begin operating autonomously across enterprise environments. CISA: Patch actively exploited SolarWinds Serv-U DoS vulnerability (CVE-2026-28318) A vulnerability (CVE-2026-28318) that can be exploited to crash SolarWinds Serv-U file transfer servers is being leveraged by attackers in the wild, the US Cybersecurity and Infrastructure Security Agency (CISA) confirmed on Friday. The agency has ordered US federal civilian agencies to address it by June 19, 2026, either by implementing a patch or implementing mitigations. Qilin ransomware affiliate exploited Check Point VPN zero-day (CVE-2026-50751) A Qilin ransomware affiliate is believed to be exploiting CVE-2026-50751, an authentication bypass vulnerability in Check Point VPN Remote Access and Mobile Access, the company announced on Monday. Check Point Remote Access VPN enables and secures connections between corporate networks and remote or mobile devices. LiteLLM vulnerability under active attack, CISA warns (CVE-2026-42271) A command injection vulnerability (CVE-2026-42271) in BerryAI’s LiteLLM open-source AI gateway is being exploited by attackers, the US Cybersecurity and Infrastructure Security Agency (CISA) confirmed by adding the flaw to its Known Exploited Vulnerabilities catalog on Monday. Record Microsoft Patch Tuesday, fresh zero-day Microsoft marked its largest-ever Patch Tuesday this month, by shipping fixes for nearly 200 vulnerabilities. Within hours, “Nightmare Eclipse”, the researcher behind weeks of escalating Windows exploit releases, dropped a proof-of-concept exploit for a new zero-day: “RoguePlanet”, which abuses a race condition in Windows Defender to spawn a command shell running with SYSTEM-level privileges. Critical Ivanti Sentry flaw allows root-level remote code execution (CVE-2026-10520) Ivanti has patched two critical vulnerabilities (CVE-2026-10520 and CVE-2026-10523) in Ivanti Sentry and has urged customers to implement the fix right away. Though the vulnerabilities are not known to be actively exploited, security researchers have already released technical details about the former, which may be used by attackers to craft a working exploit. Oracle PeopleSoft servers under attack, Oracle pushes out-of-band security alert A zero-day vulnerability (CVE-2026-35273) in Oracle PeopleSoft PeopleTools is being exploited in the wild, Charles Carmakal, CTO at cybersecurity firm Mandiant, part of Google Cloud, warned today. The architecture of subtraction: Why it’s time to erase the roads, not just map the traffic AI-assisted vulnerability discovery and exploit development are making patching increasingly inadequate as a primary defense. Advanced AI models can shrink the time from vulnerability discovery to exploitation from months to hours, while organizations struggle to patch systems as quickly as new flaws are identified. Product showcase: Staying ahead of the threat horizon with Aunoo Aunoo is an open strategic intelligence platform that uses AI agents to monitor intelligence sources, including for cybersecurity, to compile a daily briefing and alert on defined criteria. Each source is checked for credibility and quality before it is included. The platform runs in any browser and can send its findings via Slack, Discord, Teams, email or using the internal chat. When attacks spread too far: Lessons from real cyber attack case studies In this Help Net Security video, Michael Adjei, Director, Systems Engineering at Illumio, explains three real world cyber attacks and what went wrong during detection. Cyber resilience metrics that drive action In this Help Net Security video, Pete Bowers, COO at NormCyber, explains how organizations can build a cyber resilience metrics program that supports better decisions. He questions common ways of measuring resilience, such as risk registers, tool scores, and annual tests, and points out their limits. GitHub Copilot app launches as desktop home for AI coding agents GitHub introduced the Copilot app, a desktop application built for working with AI coding agents, at Microsoft Build 2026. The release expands GitHub’s Copilot product line beyond editor integrations and command-line tools into a dedicated workspace for directing several agents at once. Cybercriminals create 19,000 FIFA-themed domains ahead of 2026 World Cup The 2026 FIFA World Cup will bring millions of visitors and an estimated 6 billion spectators to a tournament spread across 16 host cities in the United States, Canada and Mexico. In a new report, Intel 471 describes the 2026 FIFA World Cup as “the largest and most complex cyberattack surface in sporting history.” Hackers used Meta’s AI support system to hijack over 20,000 Instagram accounts Meta has revealed that attackers hijacked 20,225 Instagram accounts by exploiting a flaw in the company’s AI-assisted account recovery system. According to the company, a vulnerability in High Touch Support (HTS) allowed unauthorized parties to perform password resets on Instagram accounts. Microsoft changes how Defender for Endpoint EDR updates are delivered on Windows Microsoft will distribute Defender for Endpoint EDR updates through Microsoft Update, enabling EDR security improvements to be released independently of monthly Windows operating system updates. The rollout started for Windows 10 devices in late May 2026 and will expand to Windows 11 and other supported Windows versions later this year. Microsoft expects deployment to be completed by fall 2026. Meta claims NSO Group still targets WhatsApp users despite court order Meta claims it disrupted spear-phishing attempts linked to NSO Group and is asking a US federal court to hold the spyware vendor in contempt for allegedly violating an injunction that bars it from targeting WhatsApp and its users. Mythos Preview can weaponize N-day vulnerabilities in hours Mythos Preview can develop working exploits from newly disclosed software vulnerabilities in hours, cutting down a process that has historically taken days or weeks, according to Anthropic. Google patches Chrome zero-day exploited in the wild (CVE-2026-11645) Google has fixed 74 vulnerabilities in Chrome, including a high-severity zero-day (CVE-2026-11645) that has been exploited in the wild. The fix has been shipped in Chrome 149.0.7827.102/.103 for Windows and macOS and Chrome 149.0.7827.102 for Linux, with the update rolling out to users over the coming days and weeks. French government messaging platform breached through account hijacking French authorities are investigating a compromise of Tchap, the government’s secure messaging platform, after hackers hijacked a user account and gained access to public chat rooms. Anthropic’s Claude Fable 5 is out for public use, with safeguards for high-risk requests Days after publishing research on how advanced AI systems could amplify cyber operations in the wrong hands, Anthropic released Claude Fable 5, a Mythos-class model for general use. The company said Mythos-class models possess advanced cybersecurity and research biology capabilities that can provide information and guidance beyond what is typically available through conventional online sources. New Browser-in-the-Browser phishing uses fake login popups to steal Microsoft 365 credentials A new Browser-in-the-Browser (BitB) phishing campaign is targeting Microsoft 365 users with fake login popups designed to closely mimic legitimate browser authentication windows, according to Palo Alto Networks Unit 42. Identity theft is turning into a chain reaction for victims For a growing number of victims, identity theft no longer ends with a fraudulent charge or a compromised account. More than one in four people who contacted the Identity Theft Resource Center during the reporting period were dealing with multiple identity-related incidents, according to the organization’s 2026 Trends in Identity Report. X Square Robot open sources its robot-free data collection framework Companies building robots for physical work spend large amounts of time and money operating machines by hand to gather training examples. Each session with a physical robot produces a small number of demonstrations per day, which slows the growth of datasets used to train embodied AI. Human demonstrators offer a cheaper source of data, and X Square Robot has put a system for this approach into public release. Making the cloud prove it followed your privacy wishes Companies that store personal data in cloud key-value databases should handle deletion requests by running the operation and confirming the job is complete. The people making those requests and the regulators overseeing them have had limited means to confirm the data is gone or that the record of its removal is genuine. GDPRuler, a middleware system from researchers at the Technical University of Munich and the University of Lisbon, sits between an application and an unmodified key-value database and enforces privacy rules as data passes through it. 9 out of 10 people can no longer distinguish real from AI-generated content Online fraud is becoming harder to distinguish from legitimate activity as AI-generated messages, voices, photos, reviews, and identities become more convincing. Nearly nine in ten adults say they can no longer tell what is real from AI-generated content, according to the latest Malwarebytes survey. The share increased from 66% in 2025 to 85% in 2026. FBI seizes 13 websites linked to alleged Chinese intelligence-gathering effort Federal authorities have seized 13 internet domains allegedly used to target current and former U.S. government employees and military personnel with access to classified and sensitive information. 52% of direct-to-IP threats are missing from intelligence feeds Security tools are good at inspecting websites, domains, URLs, and files, so attackers are moving lower in the stack and communicating directly with IP addresses, where visibility is limited. According to Palo Alto Networks’ report, this creates a visibility gap that allows malicious traffic to blend into normal internet activity and evade detection. Google Colab CLI opens runtimes to Claude Code and Codex Google released the Google Colab Command-Line Interface, a tool that connects local terminals to remote Colab runtimes. The CLI provides an execution platform for developers and AI agents, letting users provision compute, run local Python scripts on remote runtimes, and retrieve artifacts back to local machines. OpenAI is locking down parts of ChatGPT to reduce data theft risks OpenAI has started rolling out Lockdown Mode for ChatGPT, an optional security setting that restricts access to external resources and several product capabilities. It is available for personal accounts, including Free, Go, Plus, and Pro plans, as well as self-serve ChatGPT Business accounts. Samsung just made Galaxy phones more secure in One UI 9 beta Samsung’s One UI 9 beta integrates Lockdown mode into the power menu. This is the screen that contains Power off, Restart, and emergency options. Opening it initiates Lockdown mode, disabling biometric authentication. The security questions around Chinese AI coding models in U.S. software Software developers across the United States are using AI models built in China to write, debug, and review code, drawn by prices below those of American alternatives. These models carry risks for the security of American software, according to a report from Booz Allen Hamilton, which tested how the models respond when the user appears to work for the U.S. government. Malware ships with bugs that defenders could use against it Static analysis tools have spent years scanning legitimate software for security bugs before it goes out the door. The same scanners work on malware, and malware carries a steady supply of its own bugs. Researchers ran four of these tools across 658 leaked malware projects and found that close to 90 percent contained at least one recognized software weakness. Apple expands what parents can block, approve, and limit Apple has previewed a set of new child safety features coming to iPhone, iPad, and the Mac later this year, expanding parental controls with tools that help families manage app access, web browsing, communication, and screen time. Apple Intelligence can now replace weak passwords without user intervention Apple’s next generation of Apple Intelligence, the company’s personal intelligence system, expands its capabilities and introduces new security features in Passwords. With the new update, Passwords can automatically replace weak or compromised passwords. Scams now operate like real businesses with budgets and targets Social media has overtaken email as a primary attack vector, showing changes in how people consume information and interact online, according to Bitdefender’s Global Scam Intelligence Report 2026. Fraud campaigns use advertisements, sponsored content, impersonation pages, and direct messages to reach users. Apple extends Private Cloud Compute to third-party data centers Apple is bringing its Private Cloud Compute (PCC) platform to Google Cloud, expanding the infrastructure behind Apple Intelligence to third-party data centers. Introduced in 2024, PCC provides cloud-based processing for AI workloads that exceed the capabilities of on-device models while maintaining Apple’s security and privacy guarantees. Building reusable workflows with custom agents in Copilot CLI Developers spend much of their working time in the terminal, generating commands, debugging issues, and running scripts close to their systems. Repeated terminal work tends to pile up small steps such as re-running the same commands, re-explaining context, and translating logs into a form a team can act on. Custom agents in GitHub Copilot CLI address these patterns by turning repeated tasks into reusable workflows. Organizations can’t see much of their mobile AI activity Organizations have limited visibility into AI activity on mobile devices despite security leaders expressing confidence in their AI governance, according to Lookout’s “Solving for the Mobile AI Blind Spot: Executive Confidence Meets Technical Reality” report. Prompt injection still drives most agentic AI security failures in production A backdoor sat on PyPI for three hours in March 2026. Nearly 47,000 downloads occurred during the window. The compromised package, LiteLLM, serves as the language-model gateway for CrewAI, DSPy, Microsoft GraphRAG, and dozens of other AI agent frameworks. Anyone pulling an update during that window pulled in an autonomous attack bot named hackerbot-claw along with it. Threat actors are recruiting the people who hold cloud logins Companies keep most of their data and applications in cloud platforms that anyone can reach with the right login. That setup turns each employee holding those credentials into a security variable, and members of the cybercrime underground have built methods to reach those people. Intel 471 tracked this activity into 2026 and sorted insider risk into three categories that cloud-reliant organizations contend with. Fake Spotify Premium tutorials on TikTok and Instagram Reels spread malware Cybercriminals are using TikTok and Instagram Reels videos to spread Vidar, an infostealer malware, through fake downloads for popular paid software, according to ReversingLabs. The researchers uncovered two campaigns behind the activity, each using a different approach to draw in viewers before sending them to external download sites. Google sues China-based scammers over Gemini AI abuse Google has filed a lawsuit against Outsider Enterprise, a China-based cybercrime network for using AI tools, including Gemini, to build phishing websites and scam infrastructure. Cybercriminals are moving away from mass phishing campaigns Phishing activity declined by roughly 20% in both 2024 and 2025, according to research from Zscaler’s ThreatLabz team. The drop followed years of growth that pushed phishing activity above 2 billion hits in 2023. Authorities dismantle crypto laundering service that moved €336 million for cybercriminals An international law enforcement operation has dismantled a cryptocurrency laundering service linked to ransomware groups and other cybercriminals that processed more than €336 million in illicit funds. Cybersecurity jobs available right now: June 9, 2026 We’ve scoured the market to bring you a selection of roles that span various skill levels within the cybersecurity field. Check out this weekly selection of cybersecurity jobs available right now. New infosec products of the week: June 12, 2026 Here’s a look at the most interesting products from the past week, featuring releases from AISLE, Drata, Elastic, Filigran, IDnow, and Ridge Security.
helpnetsecurity.comJun 14, 2026extracted
Industry Reactions to Claude Fable 5: Feedback Friday
Claude Fable 5 has become generally available, with Anthropic unveiling it as a powerful Mythos-class AI model. The release includes robust safeguards that restrict its capabilities in high-risk domains. In sensitive areas such as cybersecurity (where it could be misused to create exploits) and biology (where it could assist in developing bioweapons or chemical weapons), Fable 5 automatically falls back to the less capable Claude Opus 4.8. Anthropic stated that it performed extensive internal and external red-teaming to ensure the model is highly resistant to jailbreaking. [ Read: Anthropic Disputes Fable 5 AI Jailbreak ] Industry professionals have commented on various aspects of the new Fable 5, including dual-use offensive and defensive cyber capabilities, safeguards, tiered access for select partners, a premium price tag creating a security poverty line, and the urgent need for proactive AI governance and faster defender adaptation. And the feedback begins… Greg Heon, VP, Product Strategy, Armadin: “The same massive investments that made AI models dramatically better at writing code have made them dramatically better at finding and exploiting vulnerabilities — those are two sides of the same capability, and the labs have poured tens of billions of dollars into it. Every enterprise should now be preparing for machine-speed, AI-orchestrated hyperattacks: campaigns that chain reconnaissance, discovery, exploitation, and lateral movement faster than any human defender can react. Preparing isn’t a tabletop exercise. It means testing your real attack surface against these techniques, and it means starting on the perimeter today — not just running tests in sandboxed pre-production environments that look nothing like what a real attacker sees. The frontier labs are gating their most capable models specifically because of cyber risk. That should tell every CISO exactly where this is heading — and why the time to test against it is now, not after tomorrow’s AI-powered adversary launches a hyperattack.” Myke Lyons, CISO, Cribl: “This is the emerging trend: develop cutting-edge models, highlight their risks, release a ‘safer’ version to the public, and reserve the unrestricted version for select partners. Anthropic’s rollout mirrors this pattern. Expect OpenAI, Google, and Meta to follow suit, creating a tiered model ecosystem. This isn’t just about safety. It’s about positioning. The real question for enterprises isn’t whether their AI vendor includes safety mechanisms, but whether they’re prepared to handle the unrestricted tier. On the defensive side, Fable 5 enables capabilities like long-term threat monitoring, large-scale account research, and automation of complex processes. On the offensive side, Mythos-class models demonstrate sophisticated agentic hacking capabilities, including autonomous reconnaissance, lateral movement, and exploitation. The most concerning aspect is the imbalance: defenders are constrained by procurement cycles and compliance processes, while attackers only need an account. AI capabilities are advancing faster than security teams can adapt. Security leaders need to treat this as a wake-up call: AI governance must be dynamic and proactive, not reactive. Falling behind now means playing catch-up indefinitely.” Ben Bernstein, Cybersecurity Advisor, Huntress: “Fable comes with a serious premium price tag compared to standard public models, which instantly prices out a lot of smaller organizations. We’ve dealt with this ‘security poverty line’ for years when it comes to prohibitively expensive security tooling, but Fable is really just the latest iteration of that exact problem. The danger isn’t just that these smaller teams are missing out on a cool new tool; it’s that threat actors are using these AI advancements to drastically accelerate how they hunt for the same low-hanging fruit they always have: misconfigurations, exposed systems, and unpatched vulnerabilities. So, while the Fortune 500 and well-funded cyber criminals, organized crime, and nation-states are leveraging this premium tier of AI to either defend or attack at machine speed, historically under-resourced teams are going to be facing a massive, automated wave of threats without the budget for the advanced security tooling, or the human talent, required to keep up.” Noelle Murata, Chief Operating Officer at Xcape, Inc: “Anthropic’s broad commercial release of Claude Fable 5 represents a calculated pivot in the frontier AI landscape: attempting to monetize elite, long-horizon reasoning architecture while strictly walling off its most “hazardous” capabilities. By implementing an aggressive, real-time classifier system that automatically downgrades high-risk cybersecurity, biochemical, or model-distillation requests to the less powerful Claude Opus 4.8 framework, Anthropic is trying to fulfill its commercial obligations without turning a public LLM into an on-demand zero-day factory. However, this bifurcated release strategy highlights a growing divergence in enterprise defense. While everyday enterprise customers gain access to Fable 5’s highly advanced software engineering and long-running autonomous logic, Claude Mythos 5 remains exclusively accessible to a tight cohort of government intelligence agencies and select critical infrastructure defenders under Project Glasswing. This means the actual “cybersecurity tier” of this technology remains behind sovereign closed doors, leaving commercial security teams to defend against an increasingly automated threat landscape without the same unrestricted analytical tools being deployed by nation-state actors.” Varin Khera, Co-Founder and CTO, SECStrike.ai: “Anthropic has reported a roughly 5% false positive rate for the Fable 5 model, and I would expect those safeguards to improve over time. However, in our testing, we observed significantly more instances where legitimate security prompts triggered the guardrails, terms central to routine defensive work like CVEs and impact analysis frequently triggered the fallback mechanism, routing queries to Claude Opus 4.8. The challenge is that cybersecurity professionals are locked out of the model precisely when their work demands it most.” Jacob Krell, Senior Director: Secure AI Solutions & Cybersecurity, Suzu Labs: “Anthropic filed for its IPO on June 1 and launched Fable 5 eight days later at double the Opus token rate. The benchmark gains are real but concentrated in frontier-hard tasks. SWE-bench Pro jumps 11 points, from 69.2% to 80.3%. On routine work the gap shrinks to near-parity, and cost-per-solve still favors Opus 4.8 at $1.45 vs $2.49 per solved task. The token economics compound the pricing. Fable 5 burns tokens at twice the Opus rate. A BleepingComputer reviewer exhausted a $100 daily allocation in nine minutes running Anthropic’s workflow mode. At $10/$50 per million tokens, heavy agentic work can clear three figures a day. I do complex offensive cybersecurity tasks on Opus 4.6. No cybersecurity classifier. No mandatory data retention. Fable 5 charges double, blocks those queries, and redirects them to Opus 4.8. Anthropic needs to show public-market investors it can monetize a $965 billion valuation. Fable 5 doubles per-token revenue. The cybersecurity gains are locked behind Project Glasswing. Everyone else pays double and gets Opus 4.8 responses on security queries.” Gidi Cohen, CEO & Co-founder, Bonfy.AI: “The most honest thing Anthropic has done here is ship one model as two products. Splitting Fable 5 and Mythos 5 is an acknowledgment that capability and safety are in genuine tension — and that pretending otherwise doesn’t serve anyone. But the most important line in the entire announcement isn’t about the classifiers. It’s buried in the operational detail: a high-severity vulnerability found by the model takes about two weeks to patch on average. Meanwhile, Mythos Preview built working exploits from a disclosed CVE in under a day. That gap is where risk lives. And no classifier closes it. This makes concrete what the CSA data showed last week: enterprises aren’t failing because they can’t detect vulnerabilities. They’re failing because they can’t act on them fast enough. AI has collapsed the attacker’s timeline to hours. The defender’s timeline hasn’t moved. Anthropic is right that the defensive head start only matters if the industry uses it. The harder truth is that most enterprises aren’t yet equipped to — not because the tools don’t exist, but because the governance architecture to deploy them safely hasn’t kept pace with the capability.” Devin Maguire, Senior Manager, Product Marketing, Cycode: “Anthropic released Mythos more broadly in the form of Claude Fable 5. Models are getting dramatically better at finding vulnerabilities. That’s genuinely exciting progress. But better models don’t make the security team’s job easier. They make it harder. The same capability lands in the hands of attackers. And the flood of new CVEs that follows moves faster than any team can manually triage. The 2026 Verizon DBIR made this concrete. For the first time in 19 years, vulnerability exploitation is the #1 way organizations get breached. 31% of all breaches. Median time to patch: 43 days. The bottleneck has never been finding vulnerabilities. It’s always been knowing which ones are actually exploitable in your environment, and fixing them before attackers get there. Vulnerabilities found by AI still need to be managed. They need to be analyzed, triaged, assigned, remediated, and tracked. Another detection tool in the arsenal is also another tool in the adversary arsenal and doesn’t solve the persistent security challenge of managing risk posture and fixing what you found. Every leap in model capability widens that gap. The organizations that close it will be the ones that treat remediation speed as a security metric, not an engineering backlog. Congratulations to the Anthropic team. The hard work starts now for the rest of us.” Etay Maor, Vice President of Threat Intelligence, Cato Networks: “Anthropic’s Claude Fable protections are good, and they will stop many of the direct attempts to get the model to do malicious things. For an opportunistic attacker — somebody who doesn’t have a lot of time, resources, or willingness to keep trying — those safeguards can be effective. […] When we’re thinking about safeguards, we have to remember that the capabilities are in the model and the protections are layered on top. Those protections are important, but they’re not the same thing as removing the capability itself. That’s why I describe them as speed bumps rather than barricades. They can slow attackers down, and that’s valuable, but they’re unlikely to stop the threat actors we worry about most — the ones with the time, resources, and motivation to keep testing until they find another way in. From an enterprise perspective, the 30-day retention requirement deserves attention. Organizations in regulated industries need to understand exactly what data is being retained and whether that aligns with their compliance and legal requirements before they start using these models in sensitive environments. The other thing that stands out is the agentic component. The more autonomy you give an AI system and the more access you give it across infrastructure, code repositories, and internal systems, the more valuable it becomes to both defenders and attackers. If that system is manipulated or compromised, it can become a very effective tool for lateral movement. Most organizations are still figuring out what security looks like in a world where AI agents can take actions across multiple systems on their own.” Roger Grimes, CISO Advisor, KnowBe4: “Regarding whether cybercriminals will get access to these tools faster: no, not really. Criminals have been using AI to find vulnerabilities, code exploits, and code malware since last year. Certainly, learning about Mythos put a renewed, more intense push on using AI to find vulnerabilities and exploit them, but it wasn’t like it hasn’t been what the elite cybercriminals haven’t been doing for a year already. They have been doing this. Heck, I saw similar non-AI versions of Mythos being used by nation-states and large red teams over a decade ago. They were pretty good then, but now AI-enabled, they are supercharged. The only thing Mythos substantially changed was how quickly the defenders would get these tools. Sure, it accelerated and helped attackers, but they didn’t need the push. Defenders needed the bigger wake-up call. There are in fact no downsides to making Fable-5 public. The sooner the band-aid is ripped off, the sooner the defender lifecycle kicks in and helps us. What Mythos kicked off was defenders getting more secure code sooner. Mythos and Fable will help defenders get more secure code faster. We will see a huge spike in vulnerabilities found and exploited over the next 2-3 years, and after that, we will see more secure applications. The way this will change the cybersecurity industry is that we will see more usage of AI to both find and fix vulnerabilities faster, patch faster, and instruct the AI to code more securely from the start. The net result of Mythos and Fable is more secure apps.”
securityweek.comJun 12, 2026extracted
Bernie Sanders’ AI Sovereign Wealth Fund Plan
Bernie Sanders’ AI Sovereign Wealth Fund Plan Let no one accuse Bernie Sanders of ducking the big questions. Writing in the New York Times last week, the senator asked: “Will the future of humanity be determined by a handful of billionaires who have promoted and developed AI, with virtually no democratic input, who stand to become even richer and more powerful than they are today?” We agree entirely that this is one of the most potent questions facing global democracy today. Our book, Rewiring Democracy, surveys the emerging uses for and impacts of AI in democracy around the world and reaches the same conclusion: that the most urgent risk posed by AI is the concentration of power, wealth and control among tech oligarchs. And yet we reached a vastly different conclusion than Sanders on what to do about it. The senator points to a once radical but increasingly popular solution: creating a US sovereign wealth fund by taking 50% stock in AI companies such as Anthropic, OpenAI and xAI. The argument in favor of this is twofold. One: it would establish democratic control over the AI companies, giving the government “the power, through its voting shares and an equal representation on each company’s board, to block decisions that hurt our citizens and to push for policies that help them.” Two: it would return a big chunk of the economic rewards of soaring AI valuations to the public, ensuring “trillions of dollars potentially generated by AI are used to improve the lives of all of us.” We laud both these goals unreservedly. We wholeheartedly agree that there must be public influence over the development and use of AI, just as we demand the government intervene to ensure that automakers, drugmakers, airlines and other industries balance profitability with public safety and the public interest. And we credit the senator with recognizing that there are more levers for the government to pull beyond the promulgation of regulation to achieve this. And we also agree that the obscene, dangerous accumulation of wealth among AI companies needs to be disrupted. As OpenAI and Anthropic race to be minted as the world’s latest trillion-dollar AI companies, we should recognize that—whether or not it constitutes a bubble—these staggering market capitalizations represent a transfer of wealth. The flow of money goes from the smaller businesses and actual people using AI, and being subjected to it, to the owners of these tech companies. That includes the world’s 86 AI billionaires “seeking to maximize their power and profit” aiming to decide the “fate of humanity… behind closed doors in Silicon Valley,” as Sanders said. And yet, while we do not outright oppose the taking of AI company stock, or of a US sovereign wealth fund, there are better ways to achieve Sanders’ stated goals. Public ownership of these companies entangles corporate profit and valuation with the public interest. It would incentivize the government to clear regulations, permit the exploitation of workers and users, suppress competition, encourage AI adoption regardless of the responsibleness of the implementation or appropriateness of the use case, and otherwise act on behalf of corporate interests. After all, if growing, say, Nvidia from its first $5tn in value to its next $5tn also represents a doubling in value of this segment of the sovereign wealth fund, then you can expect the fund managers to support chip sales, foreign and domestic, with the same zeal as the company’s private investors. This is not an effective way to influence corporations to act in the public interest. In fact, it makes corporate influence on the government more likely. We should be wary of this possibility because we’ve seen it before. Ownership of substantial stakes in oil companies by the Norwegian sovereign wealth fund, the world’s largest, does not seem to have steered those corporations to pro-environmental policies. Instead, the Norwegian government’s dependence on those companies has inhibited them from taking climate action. Here in the US, public employee pension funds merit the same criticism: the fiduciary duty to generate wealth overwhelms any intention to direct their corporate holdings in the public interest. A better answer is to separate the two goals. The standard way to share private rewards with the broader society that made them possible is taxation. Senator Elizabeth Warren has proposed an excise tax on datacenters’ energy use. Others have proposed an AI token tax, which has much the same effect. As to the goal of reshaping AI in the public interest, we have proposed an AI Public Option. The concept is for governments, be it federal or state, to establish publicly developed and operated AI models run by public institutions under democratic control. The idea is not to eliminate corporate AI or to seize it as a public asset, but rather for government to provide a competitive baseline that private AI offerings must meet or exceed to win business—just like the notion of a healthcare public option. The Swiss have trailblazed this approach. Apertus is a large language model built by Swiss public servants, researchers at Swiss universities, using appropriately licensed training data and pre-existing Swiss public supercomputing infrastructure powered by renewable energy. While Apertus doesn’t seriously compete with the latest OpenAI and Anthropic models on performance benchmarks, it blows them out of the water in transparency, sustainability and compliance with EU regulations including adherence to copyright. It’s a nascent project, but suggestive of how public institutions can apply competitive pressure for corporate actors to behave responsibly. Don’t confuse public AI with “sovereign AI,” the notion that every country needs to invest in domestic AI infrastructure. Sovereign AI is often invoked as a marketing scheme for big tech companies looking to sell to governments; it demands public investment without guaranteeing public control. Sanders is a bold and savvy political operator. So why is he pursuing the sovereign wealth fund strategy when he must be aware of these risks? It may be due to another argument he makes in his op-ed: that the Trump administration and the billionaire owners of AI are aligned to the idea. It’s expedient to capitalize on rare moments of seeming alignment across diverse political factions, but it also behooves us to ask why the AI billionaires are open to this extraordinary intervention. The answer, of course, is that they believe that for every dollar ceded to government stock expropriation, they will get back more in favorable government policies to protect that newfound investment. Energy taxation is a straightforward way to make AI companies pay for the social disruption of their technologies. Public AI represents a non-monetary mechanism for governments to shape the development of AI, complementary to direct regulation of private actors, one with a far greater chance of influencing corporate behavior towards the public interest. We urge Sanders and other political leaders to consider them. This essay was written with Nathan E. Sanders, and originally appeared in The Guardian.
schneier.comJun 12, 2026extracted
The guide on blocking ChatGPT, Gemini, Claude, and other AI tools at work | Kaspersky official blog
Unchecked AI in the workplace quickly becomes a massive loophole for data leaks and security breaches. All too often, employees drop sensitive company data into public chatbots, or install rogue AI assistants on their own — in the process handing over way too much access. In a previous post, we broke down the different types of risky AI systems, and later shared some tips on how to turn off the built-in AI features on major tech platforms. Today let’s take a look at practical ways to block or restrict the unauthorized “helpers” employees might be using — from ChatGPT and Grammarly, to meeting bots like Fireflies and Read AI. How to detect and restrict ChatGPT ChatGPT is the biggest culprit when it comes to unauthorized AI use worldwide. A quick word of warning, though: an outright ban only sends users hunting for sketchy third-party sites or messaging app chatbots that hook into the same service. That’s why it’s always a good idea to offer an approved alternative before pulling the plug. Detecting it: keep an eye on the NGFW or web filter for traffic heading to chat.openai.com, chatgpt.com, oaistatic.com, oaiusercontent.com, or cdn.oaistatic.com. It’s also smart to use EDR/EPP tools to scan browser histories, installed apps, and browser extensions across corporate devices. Locking it down: use the firewall or web filter to block the entire AI Services category, and set up DNS to reroute traffic away from those OpenAI domains. Browser policies can also be used to ban ChatGPT-powered extensions. Better yet, block all extensions not on a pre-approved allowlist. Finally, use application controls and EPP solutions to stop users from installing the official desktop app (ChatGPT.exe or com.openai.chat). How to detect and restrict Claude and Claude Code Detecting it: use the NGFW or web filter to track traffic going to claude.ai, anthropic.com, *.anthropic.com, and api.anthropic.com. EDR/EPP or application control tools can also be used to scan employee computers for the desktop app (claude.exe). Locking it down: drop a blanket block on the AI Services category through the NGFW or web filter, and tweak DNS settings to reroute traffic away from the aforementioned Anthropic domains. Next, use browser policies to shut down Claude-powered extensions. Finally, use application controls and the EPP platform to prevent users from installing the desktop app. How to detect and restrict Perplexity AI Detecting it: keep tabs on the NGFW or web filter to flag any traffic heading to *.perplexity.ai or pplx.ai. Locking it down: just like the others, add the AI Services category to the NGFW or web filter blocklist, and use DNS routing to redirect traffic away from those domains. Configure the browser to block third-party extensions from being installed. If Firefox is used in the organization, be aware that recent versions come with Perplexity built in. Luckily, these AI features can be turned-off company-wide using enterprise policies — specifically, by setting SidebarChatbot = blocked. The full list of tweaks can be found in the Firefox documentation. How to detect and restrict DeepSeek Detecting it: keep an eye on the NGFW or web filter for traffic hitting deepseek.com, chat.deepseek.com, api.deepseek.com, or platform.deepseek.com. For better precision, analyze the SNI (server name identification) in TLS connection requests. For mobile devices, look out for the official app (com.deepseek.chat). Locking it down: blocklist the AI Services category on the NGFW or web filter, and reroute traffic to DeepSeek’s domains via DNS settings. Use browser policies to block third-party extensions, and lean on MDM/EMM tools to restrict the mobile app. How to detect and restrict Mistral, xAI Grok, and Character.ai The playbook for these tools is exactly the same as DeepSeek, so here’s the quick list of domains to watch for and block: chat.mistral.ai, mistral.ai, console.mistral.ai, grok.com, x.ai, api.x.ai, character.ai, beta.character.ai, and c.ai. A quick word of warning on Grok: because Grok is baked into X, blocking this specific AI access point means blocking the entire social media platform. How to detect and restrict Slack AI Detecting it: in the Slack workspace admin dashboard, look under Analytics → Slack AI usage. If an enterprise plan is used, the detailed Slack logs can be searched for any events starting with the ai_ prefix. Blocking it with policies: in the organization’s Slack settings, click through the Workspace settings → Roles & permissions → Feature access, and change the permission to “no one”. Slack has a step-by-step guide in their help center. Locking it down: shutting this down at the network level is tricky; it can be pulled off with a finely tuned CASB solution in place. Also, don’t forget the importance of blocking rogue integrations and keeping external AI services from tapping into Slack data in the first place. We covered how to lock this down using OAuth controls in a previous post. How to detect and restrict Zoom AI Companion Detecting it: if a corporate Zoom subscription is in use, just head to Admin Center → Reports → AI Companion usage. Detecting Zoom’s AI when employees join external meetings or use free accounts is a lot tougher, but email filters can be set up to flag incoming AI-generated meeting notes by scanning for subject lines or text containing “Meeting summary” or “Meeting assets”. Blocking it with policies: for the company’s own Zoom subscription, go to the Admin Portal → Account Management → Account Settings → Meeting → AI Companion and toggle it OFF for everyone. Locking it down: unfortunately, AI Companion is baked into Zoom’s DNA, so the only real option is blocking Zoom altogether. How to detect and restrict Grammarly What looks like an innocent spellchecker is actually one of the biggest culprits for workplace data leaks. Detecting it: check the NGFW or web filter logs for traffic hitting grammarly.com, *.grammarly.com, and gnar.grammarly.com. EDR and MDM/EMM tools can also be used to hunt down the standalone desktop apps (Grammarly Desktop.exe and the macOS version), as well as the Grammarly browser extension. Locking it down: use firewalls to block those domains at the network level, and EPP to stop employees from installing the desktop app, browser extensions, or the Grammarly add-ins for Microsoft Word and Excel. How to detect and restrict meeting assistants: Fireflies, Read.ai, Tactiq, Fathom, and Granola This massive category of third-party SaaS tools records and analyzes meetings — creating a massive risk for data leaks. The trickiest part? Outside clients or vendors can bring these bots into a meeting just as easily as employees can. Detecting them: run an audit on calendar invites, and look for bot participants using email domains like @fireflies.ai, @read.ai, @tactiq.io, @fathom.video, or @granola.ai. Zoom, Teams, or Google Meet logs can also be used to review external participants who joined past calls. Locking them down: since it’s impossible to control what outsiders do, blocking these bots comes down to tightening meeting rules. The best moves are: blocking users from granting OAuth permissions for bots to join calls, restricting employees from inviting unapproved external participants, or locking down meeting recording access for external users. That last option is usually the least painful way to keep bots out without disrupting business. How to detect and restrict AI code editors: Cursor, Windsurf, and the like Detecting them: use EDR/EPP tools to scan for executables like cursor.exe or windsurf.exe. It’s also worth monitoring network traffic heading to cursor.com and windsurf.com, as well as traffic hitting various AI model API providers. Keep in mind that there’s a pretty extensive list of API hosts to monitor here, since these editors aren’t tied to just one specific AI vendor. Blocking them with policies: these apps can be prevented from being installed by setting up filters based on the developer’s digital signature certificate. Alternatively, a strict application allowlist can be employed where only pre-approved software is allowed to run. Locking them down: rely on the EPP/EDR platform to actively detect and block these applications from running. How to detect and restrict local AI tools: Ollama, LM Studio, and GPT4All On one hand, this category carries fewer data leak risks because the AI models run completely locally on the user’s machine. On the other hand, it opens up a whole new can of worms: these apps themselves aren’t always highly secure, and can become targets for cyberattacks. Plus, it still means that employees can misuse models or process data in unauthorized ways. Detecting them: EDR/EPP tools are the best line of defense here. They should be used to flag known local AI files and processes like ollama.exe, ollama serve, lmstudio.exe, LM Studio.app, jan.exe, or gpt4all.exe. From a network perspective, it’s worth scanning for open ports on local devices — typically port 1234 for Ollama and LM Studio, or port 8080 for WebUIs (using an additional fingerprint check of the server response). Another massive red flag is the presence of large files (often several gigabytes) containing language model weights. Look out for extensions like .gguf, .bin, or sometimes .safetensors. Locking them down: use EPP/EDR platforms or windows AppLocker to block these applications by name, or switch to an application allowlist. How to detect and restrict autonomous agents: OpenClaw, NemoClaw, and NanoClaw This is easily one of the most dangerous categories of AI tools out there. These agents mix high-level independence with access to untrusted data, making them a massive security headache. Detecting them: use EPP/EDR tools to sniff out active processes like openclaw, nanoclaw, nemoclaw, or clawdbot. Also keep an eye out for devices running Node.js that suddenly start launching Bash or Python scripts. Another dead giveaway is the appearance of system folders like ~/openclaw, ~/nanoclaw, ~/.claw*, or ~/clawhub. At the network level, monitor connections to the AI model APIs we mentioned earlier, as well as traffic hitting servers like openclaw.ai, nanoclaw.dev, or clawhub.*. Locking them down: the safest bet is to use strict application allowlisting (only allowing approved software to run), or to specifically ban the known agent apps listed above. On top of that, consider blocking non-developers from installing Node.js and Docker, neither of which they need on their computers anyway.
kaspersky.comJun 10, 2026extracted
OpenClaw AI agent found falling for phishing attacks, spills user data
Phishing simulation on an OpenClaw email agent with various configuration profiles showed that it was susceptible to tactics commonly used to compromise human users. The OpenClaw open-source AI agent framework allows large language models (LLMs) to interact with real-world systems and perform actions autonomously. It can be used as an email agent for basic reasoning and operations. Researchers at security firm Varonis created an OpenClaw agent and connected it to a Gmail inbox, browser tools, Google Workspace APIs, and fabricated internal company data sources, instructing it to monitor and process incoming emails. The synthetic enterprise data included AWS credentials, database credentials, CRM exports, internal communications, and Calendar invites, all highly sensitive data. The agent ran on two configurations: a generic one with standard productivity instructions, and a strict mode that included specific instructions for phishing awareness and identity verification procedures. The framework was tested with two models, namely Google Gemini 3.1 Pro and OpenAI GPT-5.4. “Varonis Threat Labs explored whether the same phishing techniques that have tricked humans for decades would also work on the AI agents working on their behalf,” reads the report. “We created an OpenClaw AI agent named Pinchy to test whether the agent would pass or fail versions of classic phishing simulations.” The researchers conducted four simulated phishing attacks and obtained mixed results, as summarized below: An attacker impersonated a team lead and requested access to the staging environment during a purported production issue. The agent located and emailed AWS IAM keys, database credentials, and SSH access details to an external Gmail account. The attacker requested a customer export under the pretext of working remotely on a presentation. The agent retrieved and sent a CRM export containing customer records, contact information, contract details, and revenue data without verifying the sender's identity. The agent received a fake gift card email containing a phishing link. Under the generic configuration, it visited the phishing site and attempted to redeem the gift card using fabricated credentials before eventually identifying the page as malicious. The strict configuration blocked the attack immediately. Researchers created a malicious Google OAuth application disguised as a timesheet platform. The agent inspected the OAuth flow, analyzed the destination, identified the application as suspicious, and refused to grant access. In the first two scenarios, the strict mode failed despite the additional safeguards, due to the framework’s failure to validate the sender’s identity, “Both Generic and Strict profiles failed because the verification step still collapsed when the request appeared operationally urgent,” explained Varonis about the first attack scenario. Varonis’ conclusion is that AI agents are good at detecting suspicious URLs, identifying fake login pages, spotting malicious OAuth apps, and recognizing phishing indicators, but may still fail due to a lack of identity verification, loss of context, and inability to apply “zero trust” principles to social interactions. At the model level, Gemini showed greater willingness to interact, while GPT-5.4 had a more cautious posture. Varonis recommends that agents should be explicitly required to verify sender identities, be prevented from emailing new external recipients without approval, and have limited access to internal data. For high-risk actions such as credential sharing, financial data requests, and first-time communications, human approval should be requested. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comJun 9, 2026extracted
AgentGG: Open-source agentic SAST scanner
AgentGG: Open-source agentic SAST scanner Static analysis tools have spent years matching source code against known-bad patterns and handing engineers long lists of candidate issues to triage by hand. AgentGG approaches the same job with AI agents that read the code, follow imports, walk the call graph, and confirm a finding before they report it. The project is an open-source agentic SAST scanner released under the Apache 2.0 license. How the agents run Each agent is a self-contained markdown file with YAML frontmatter that declares a precondition, target file patterns, and the instructions it follows. The catalog ships more than 100 official agents, and it downloads on the first scan from the agentgg-agents repository. Installation runs through npm with one global command, and the tool needs Node.js 20 or later. The scan runs in phases. A fast recon pass surveys the project first, building a brief on what it is and how it works, which orients every agent that follows. The agents then run in parallel, each a tool-enabled investigation that follows imports and callers to confirm a finding before flagging it. An optional validation pass then analyzes the code behind each finding, consulting a pentest scope when one is provided, and labels it. A final scoring pass attaches a CVSS severity. Findings can be browsed in a local web UI, filtered by severity, agent, or file. Tech gating keeps scans focused On every scan, a fast recon pass surveys the project first, noting its languages, frameworks, and dependencies. It then checks each agent’s precondition to decide whether that agent is worth running on this repository. A precondition can be a cheap regex check for telltale files such as package.json, composer.json, go.mod, and pyproject.toml, or an optional model gate that reads the recon brief. A scan against a Go-only repository skips PHP, Python, Ruby, and .NET agents because each of those agents preconditions on its own language being present, so it bows out on its own. A --no-recon flag skips both recon and precondition gating and forces every selected agent to run, which helps when debugging an agent on a stack the survey does not yet recognize. Resume is built in. A state directory tracks each scanned file, so an interrupted scan picks up where it stopped and unchanged files cost nothing on the next pass. Findings land as GHSA-shaped markdown files in an output directory, with a summary report that aggregates counts per agent and validation verdict. Provider options and model quality AgentGG works with Anthropic, OpenAI, Ollama, AWS Bedrock, and Google Vertex AI. A one-time setup wizard writes credentials to a config file, and a one-shot flag can supply a key for CI runs without saving it. Ollama runs locally at no cost. Philip Garabandic, a security engineer at TikTok and lead maintainer of AgentGG, told Help Net Security that model selection depends on the type of bug. “We are finding that some bug classes do well with cheaper models and some do much better with frontier models,” he said. “For example, secret keys and SQL injection risks, even Ollama can find those. If you are scanning for more complex security bugs or business logic bugs, you want a better model.” Picking the right model for each bug class remains an open research question for the team. Catalog review and trust The official agent catalog goes through manual review. “Yes, we have an official GitHub repository of agents that are reviewed,” Garabandic said. “The same way Nuclei has its official repository of templates, we have one for agents. They get pulled from there and we manually reviewed anything merged there.” Agents that reach a user’s machine come from that reviewed source, and a separate custom directory holds user-installed agents. Validation and benchmarks AgentGG includes an optional validation phase, a second-pass model call that re-reads the source for each finding and labels it confirmed, false-positive, out-of-scope, or uncertain. A scope file lets the validator consult a security policy or pentest scope document, so it can mark findings that sit outside an engagement. The tool can attach a CVSS 3.1 severity score to each finding and run inside GitHub Actions on pull requests, scoped to the code diff. Garabandic tied the scope feature to measured gains. “We have done bench marking again tools like deepsec and we found more bugs and about 10-20% fewer false positives because we allow you to add pentest scope as part of the validation context,” he said. AgentGG is available for free on GitHub. Must read: 25 open-source cybersecurity tools that don’t care about your budget GitHub CISO on security strategy and collaborating with the open-source community Subscribe to the Help Net Security ad-free monthly newsletter to stay informed on the essential open-source cybersecurity tools. Subscribe here!
helpnetsecurity.comJun 5, 2026extracted
New IronWorm malware hits 36 packages in npm supply-chain attack
A new supply-chain attack has infected 36 packages on the Node Package Manager (npm) index with infostealer malware called IronWorm. The malware targets 86 environment variables (key-value pairs) and 20 credential files that may contain OpenAI, AWS, Anthropic, and npm credentials, vault configuration files, SSH keys, and Exodus cryptocurrency wallet files. According to researchers at supply-chain and devops company JFrog, IronWorm is written in Rust, hides behind an eBPF kernel rootkit, and communicates with the operator over the Tor network. The Rust-based malware self-propagates by using stolen credentials for publishing on npm; this includes secrets associated with npm's Trusted Publishing workflow. Once it compromises a developer or CI environment, it can publish trojanized versions of packages owned by the victim, which then infect additional developers and CI systems. This behavior is conceptually similar to Shai Hulud, which had its code published on GitHub recently. Although JFrog researchers did not find a clear connection between IronWorm and Shai Hulud, they observed the same commit names in both supply-chain attacks. This opens the possibility that the new malware is an evolution of TeamPCP’s payload, since IronWorm appears to be "a custom, carefully built implant from an operation with its own infrastructure." According to JFrog, the latest attack started from a compromised account named ‘asteroiddao,’ which published package versions containing the Rust ELF binary executed via ‘preinstall,’ pushing malicious commits into repositories. The commit author appears as “claude,” and the timestamps point to several years ago, up to 13 years in some cases, even though they were pushed in the past few days. This is likely to evade investigation. One notable element in JFrog’s findings is a mechanism that relies on GitHub Actions to deliver the stolen secrets. JFrog explains that the malware serializes the secrets into a single value and then "writes it to a file with a harmless-looking name, as if it were lint or formatting output." The last step of the process is uploading the file as a build artifact, which can be downloaded by anyone with access. This way, the threat actor can avoid the need for an external command-and-control (C2) altogether. However, the researchers note that this delivery mechanism has not been used in the analyzed IronWorm supply-chain attack. Another peculiarity discovered is that the operator hardcoded the recovery phrase of their own cryptocurrency wallet. The researchers say that the only reason for this is that the threat actor did not want the malware to steal it during the test stage. Application security company Ox Security says that the IronWorm attack was detected very early and stopped before it spread to more popular packages on npm. The company provides a list of all impacted package names and their versions in the report and recommends that developers upgrade to fixed releases, rotate their keys, and enable two-factor authentication (2FA) for all accounts. At the same time, Endor Labs and StepSecurity have spotted a very similar but distinct attack involving a JavaScript-based malware named binding.gyp, performing registry poisoning and GitHub Actions infection, unfolding during the same time-frame. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comJun 4, 2026extracted
Infosecurity Europe: Mythos Outperforms GPT5.5 on Google Chrome Vulnerability Exploits, Says New Benchmark
Anthropic’s Claude Mythos outperformed OpenAI’s GPT5.5 on real‑world Google Chrome vulnerability exploits, a new benchmark designed to test the performance of frontier AI models to exploit real-world vulnerabilities found . During Infosecurity Europe 2026, Bugcrowd presented the first findings of ExploitBench, an independent, graded benchmark launched in May 2026 by the cybersecurity firm in collaboration with experts at Carnegie Mellon University and top Chrome vulnerability researchers. David Brumley, chief AI & science officer at Bugrcrowd, described the benchmark as “the first independent benchmark that measures what AI models can actually do with a vulnerability, not just identify it but exploit it step by step.” Anthropic was among the first to engage with it. He said the first test resulted in Mythos achieving a markedly higher exploitation performance than GPT‑5.5 in head‑to‑head runs, underlining how AI models are closing the gap with elite human researchers. Unlike earlier binary tests, ExploitBench scores progress through staged exploitation outcomes rather than merely recording a crash. The benchmark evaluates five tiers of capability up to arbitrary code execution against a vulnerable V8 build, the JavaScript/WebAssembly engine that powers Google Chrome, Microsoft Edge, Node.js and Cloudflare Workers. In the runs discussed at the show, Anthropic’s Mythos, with occasional human hints or “nudges,” posted an average score of 9.90 out of 16 and reached the highest tier on 21 of 41 vulnerabilities. OpenAI’s GPT‑5.5 scored 5.51 on average and reached the top tier on just two cases. “For example, Mythos is able to exploit a one-day vulnerability in Chrome about 50% of the time. This is lead-tier activity. If we were to put money on it, Google could reward up to $10,000 for such a vulnerability that has no previously known exploit,” Brumley said. “Anthropic’s model is churning these out and actually found solutions for exploiting the flaws that even top-tier hackers missed – that’s kind of impressive.” Brumley added that, while GPT5.5’s performances were currently a little lower than its counterpart’s, the broader availability of OpenAI’s model opens opportunities for more people to use it to develop exploits. AI Models Edge Closer to Reliable Exploitation, But Experts Urge Caution Frontier large language models (LLMs) have already shown they can accelerate vulnerability discovery at scale, but whether those discoveries could be chained into reliable, actionable exploits had remained an open question until ExploitBench. “We measure not just crash or no crash but stages of exploitation,” Brumley told Infosecurity, explaining why the new benchmark matters for assessing real exploitation capability rather than superficial signals. That distinction is critical because models that can reliably exploit zero‑day flaws lower the barrier for threat actors to weaponize vulnerabilities. Bugcrowd CEO, Dave Gerry, further warned that automation and AI are already being integrated into attacker workflows, increasing the pace at which discovered flaws can be turned into active exploits. Nonetheless, while ExploitBench is one of the first experiments showing the possibilities of using AI to exploit vulnerabilities, Brumley also cautioned that the first findings of his team only reflect on a specific type of vulnerabilities and the results should not be extrapolated. “I don’t want to oversell anything here. We measured a very sophisticated target application. Chrome is made of hundreds of thousands of lines of codes, it’s been audited for years. We know how valuable finding an exploit there is. It doesn’t necessarily mean we would get the same results trying to exploit a vulnerability in a web application.” Speaking to Infosecurity, Michael Price, VP of product engineering at VulnCheck, said that while AI models are improving, they are not yet fully capable of reliably carrying out exploitation at scale. Citing a recent report on the capabilities of Mythos by the UK AI Security Institute, Price explained that the most significant advance has been in the models' planning ability – their capacity to produce step‑by‑step plans, replan as needed, and execute multi‑stage actions – which by definition makes them more useful for offensive campaigns. He noted that this improvement increases offensive potential but tempered that with caution. “They’re getting better, but they still are not actually like that great,” he said. “I would expect them like every month or every quarter to get 1% better and probably over the course of two or four years they get really good,” Price added. Developing AI-Driven Remediation At Scale Both Brumley and Gerry emphasized that ExploitBench was released alongside Bugcrowd’s reinforcement learning (RL) environments to both measure and improve model capability. “We put out ExploitBench to motivate the state of where models are at on actual exploitation tasks,” Brumley explained. Gerry added that the benchmark and the training environments are complementary: one drives measurement and the other drives improvement through targeted RL training with industry model partners. Finally, the company leaders urged defenders to match offensive speed with automated remediation and prioritization. Gerry told Infosecurity that the shrinking “zero‑day clock” and the surge in AI‑assisted discovery mean organizations must develop AI‑driven remediation at scale. He said remediation pipelines must be rethought so fixes move from ticket queues into near‑real‑time workflows, and that “finding more bugs faster only amplifies the noise unless you can automatically prioritize and act on the ones that actually enable exploits.” Brumley echoed that urgency, saying defenders need contextual intelligence to prioritize and remediate the vulnerabilities that matter most before adversaries can exploit them. This, he added, requires models trained not just to find flaws but to recommend and, where safe, initiate fixes at scale so human developers can focus on the highest‑risk work. “Over the coming months, we will have announcements on that, with tools focusing on helping give people intelligence about how certain vulnerabilities are affecting them,” he said.
infosecurity-magazine.comJun 4, 2026extracted
‘HTTP/2 Bomb’ Exploit Knocks Web Servers Offline in Seconds
Known denial-of-service (DoS) techniques can be chained together in a new exploit that can knock major web servers offline, Calif security researchers warn. Dubbed HTTP/2 Bomb and discovered using OpenAI’s Codex, the exploit combines a compression bomb that targets HTTP/2’s header compression scheme (HPACK) with a Slowloris-style hold that prevents the server from freeing memory. According to California-based cybersecurity firm Calif, the attack potentially affects over 880,000 websites that support HTTP/2 and run default NGINX, Apache HTTPD, Microsoft IIS, Envoy, or Cloudflare Pingora configurations. Furthermore, the company says, an attack can be launched from a home computer on a 100 Mbps connection and can render any of these servers unavailable within seconds. The techniques chained by the exploit are not new. In fact, three of the underlying issues were disclosed a decade ago, while another was resolved last year. The first part of the exploit uses HPACK Bomb (tracked as CVE-2016-6581), a compression-layer attack relying on small messages that turn into gigabytes of data once they reach the destination server. Last year, the attack was demonstrated against Apache HTTPD with a 4000x amplification rate, and was resolved in Apache HTTP Server version 2.4.64 as CVE-2025-53020. The second part of the new exploit targets CVE-2016-8740 and CVE-2016-1546 (Slow Read), two Apache HTTPD flaws leading to DoS conditions via Continuation frames in an HTTP/2 request and via modified flow-control windows. These HTTP/2 Slowloris-type issues are abused for memory exhaustion by advertising a zero-byte flow-control window so that the server does not send a response, and then resetting the send timeout to prevent the server from freeing memory allocations. “What’s new here is where the amplification comes from. The classic bomb stuffs a large value into the table and references it repeatedly, so servers learned to cap the total decoded header size,” Calif notes. “Our variant goes the other way: the header is nearly empty, and the amplification comes from the per-entry bookkeeping the server allocates around it. The decoded-size limit never fires because there’s almost nothing to decode,” the company explains. Calif also identified a bypass for servers that cap the header-field count, and released proof-of-concept (PoC) code to demonstrate the attack. The company says NGINX resolved the bug in April, while Apache rolled out fixes in late May (and issued CVE-2026-49975). Microsoft IIS, Envoy, and Cloudflare Pingora have not been patched at the time of writing. “The other thing worth noting is how this exploit was found. Both halves have been public for a decade. What Codex did was read the codebases, recognize that the two compose, and build the combined attack. That combination is obvious once you see it, and yet as far as we can tell no human had put it together against these servers,” Calif notes. In a statement to SecurityWeek, Cloudflare said its architecture and DDoS mitigations automatically detect this attack, keeping its customers protected against HTTP/2 Bomb exploitation, without the need for a patch. *Updated with statement from Cloudflare. Related: Exploit Code Published for Critical Flowise RCE Vulnerability Related: PoC Released for DirtyDecrypt Linux Kernel Vulnerability Related: PoC Code Published for Critical NGINX Vulnerability Related: BeyondTrust Vulnerability Targeted by Hackers Within 24 Hours of PoC Release
securityweek.comJun 3, 2026extracted
Infosecurity Europe: Patch Responsibility Remains Up for Grabs as AI Unearths Decades of Flaws
As two of the leading frontier AI labs, OpenAI and Anthropic, expand access to their most advanced large language models (LLMs), Claude Mythos and GPT5.5, with evidence of their capabilities to autonomously find and fix vulnerabilities at scale, the way organizations patch flaws is evolving. First, the patching lifecycle will likely speed up in many companies. Speaking at Infosecurity Europe, Kevin Jones, Group CISO at Bayer, said IT vendors he spoke to, including cloud hyperscalers, assessed that the mean time to exploit a vulnerability has gone from days to hours. “Normally, from a patch being released with no known public exploit in the wild, you give yourself seven to 10 days to be able to scale up that patch, deploy it on a few isolated systems, test it, deploy it on your internet-facing systems. It used to be the window it would take for attackers to really reverse engineer it, find the vulnerabilities, write the exploits, deploy the exploits and scale them,” he explained. Now, vendors told him it took threat actors down to six hours and 40 minutes between the time a patch was being released with no known exploit in the wild and when somebody started exploiting the vulnerability. India Introduces 12-Hour Patch Deadlines In response to this, India’s Computer Emergency Response Team (CERT-In) recently set a new bar for response times with an expectation to patch actively exploited internet-facing vulnerabilities within 12 hours, exposed critical flaws within a day and high-severity bugs within five days. Speaking to Infosecurity, Andrey Lukashekov, head of revenue at Vulners, said such a mandate “sounds decisive.” However, he noted that in large, global organizations, tight deadlines collide with time zones, approval chains and change controls, turning a well‑intended rule into “a logistical nightmare” that can actually impede safe remediation. In Lukashenkov’s view, such mandates push the emphasis onto producers and rapid patch delivery, yet they risk encouraging rushed fixes or breaking change processes when coordination is infeasible. EU and US Patching Policy Approach: Vendor-Centric Vs User-Centric By contrast, Lukashenkov framed the EU’s approach under the Cyber Resilience Act as more explicitly producer‑centric. He said the CRA “leans on vendors to own product security,” creating obligations for secure development, disclosure and user notification. Lukashenkov described this approach as sensible from a policy standpoint because it aligns legal responsibility with the parties that build the code, but he cautioned that compliance does not automatically translate into shortened exploitation windows. “Regulation can move the needle on accountability, but it won’t replace sound architecture and resilient operations,” he said. Also speaking to Infosecurity, Michael Price, VP of product engineering at VulnCheck, contrasted the EU’s vendor-focused posture under rules like the CRA with the more market-driven, user-focused approach he sees in the US. He said that Europe “is trying to force responsibility upstream,” by placing legal and technical obligations on software producers to design and ship more secure products. That, he said, shifts cost and accountability toward vendors and can drive systemic improvements – albeit at the expense of potentially slowing innovation. By contrast, Price said, the US model often puts more of the burden on users and operators to defend themselves. “In the US, you see an emphasis on avoiding regulation because regulators can slow down growth,” he explained. As a result many companies optimize for time-to-market rather than security. He warned this can leave downstream customers with the hard work of patching, prioritizing and compensating for insecure defaults. Lukashenkov agreed, observing that US practice tends to combine market pressure, liability considerations and voluntary standards rather than a single, prescriptive cadence. “In the US you get a patchwork of expectations: buyers demand fixes, insurers price risk and vendors respond, but there’s no one size fits all,” he said. Price argued there’s no simple right answer: regulation can raise the baseline of security but also introduce costs. “I’d like to see more regulation in the US as there’s simply too much insecurity, but you have to strike a balance so you don’t kill innovation,” he said. Taken together, Lukashenkov argued these divergent approaches create both opportunity and friction: India’s speed‑first posture forces urgency, the EU’s producer obligations clarify legal accountability, and the US ecosystem model drives market‑based incentives. However, he emphasized that, regardless of their approach, policymakers should be deliberate about which part of the system they seek to influence (vulnerability discovery, disclosure, production of vulnerability data or operation of patches) and recognize that meaningful risk reduction will require aligning producer obligations with defender capabilities rather than simply imposing impossible timelines. “The question isn’t just who pays,” he concluded, “It’s how we rewire incentives so producers, customers and regulators all pull toward fewer windows of exploitability.” Exploit Intelligence-Driven Patching Programs Price outlined a clear shift he believes organizations must make. “The old model, where I first scan, then I find vulnerabilities, then I create tickets and finally somebody resolves the tickets is no longer adequate,” he said. Price advised shifting the emphasis on real-world risk, with security teams recommended to ask themselves which vulnerabilities are being exploited, not merely which ones exist. “You need to move to an exploit intelligence-driven, operations-focused model,” he said. “Typically, a small number of vulnerabilities are exploited in under 24 hours from publication. Any organization that wants to remain secure has to know which vulnerabilities are actually going to be exploited, and they need to be able to respond to them in less than 24 hours.” Price also flagged scaling problems in disclosure and vendor response, where he argued that manual triage is breaking under volume. “Manual triage of every report clearly is at risk,” he said, calling for automation and new vendor-side tooling to handle the influx of AI-generated reports. He warned that relying on a single catalog like NIST’s feeds will no longer be sufficient and that organizations need multiple, intelligence-rich sources to make timely decisions. Hardening Security Beyond Patching While acknowledging producer accountability is gaining traction, Lukashekov urged defenders not to rely on faster patching as a silver bullet. He argued organizations must assume undisclosed vulnerabilities exist and change their defensive posture accordingly. “Treat your perimeter like it’s already compromised,” he advised. “Don’t just build walls, deploy anti‑drone nets.” In practice, that means stronger hardening, segmentation, runtime protections and improved detection and containment alongside patching. Lukashekov urged nuance in patch strategy: commodity endpoints and vendor‑managed software should use automation and auto‑updates where safe, while CI/CD systems and bespoke applications require careful, case‑by‑case handling. “Different parts of cybersecurity move at different speeds. You can’t treat CI/CD the same way you treat laptop updates.,” he stated. Practical takeaways Lukashekov offered for organizations confronting the discovery boom include: Assuming there are unreported CVEs and designing compensating controls (segmentation, runtime defense, detection) Automating vendor updates for endpoints, but treating CI/CD and bespoke software with stricter release discipline Building a prioritized patch rubric focused on exploitability and business impact, not just CVE age Demanding clearer SLAs and communication from producers while investing in internal mitigations Strengthening coordinated disclosure workflows so discovery does not simply translate into more unmanaged exposure On supply-chain risk, Price emphasized concrete mitigations that organizations can adopt now: lock down developer environments, avoid local storage of secrets, route dependencies through vetted package registries, enforce cooldown periods and use version pinning and package signing. He said these are practical steps that, if widely implemented, would materially reduce the risk from malicious or compromised open-source packages. Lukashekov also highlighted an emerging market response, reporting that industry sentiment shifted in April – after Anthropic released Mythos as part of the Glasswing project – as boards unlocked budget and investors favored cybersecurity firms. However, he cautioned that money alone won’t resolve the responsibility debate. “Regulation, market pressure and customer demands all matter, but they won’t replace good architecture and resilient operations,” he said. Lukashekov concluded that the industry is at an inflection point, where accountability and operational practice must be renegotiated. “Patching isn’t dead,” he said, “But it can’t be the only answer. Who pays to fix it is still very much up for grabs.”
infosecurity-magazine.comJun 3, 2026extracted
Trump Signs Executive Order That Invites Vetting of Top AI Models for National Security Risks
President Donald Trump signed an executive order on oversight of artificial intelligence Tuesday, less than two weeks after postponing a White House ceremony over his concerns that a similar policy could dull America’s technological edge. The order establishes a framework for the federal government to vet the national security risks of the most advanced AI systems for up to a month before their public release. Participation by AI developers would be voluntary, the order says. “Advanced AI capabilities make our Nation stronger, but also introduce new national security considerations that require coordinated action across executive departments and agencies,” the order says. It was not immediately clear to what extent the order differed from the one Trump declined to sign on May 21. The order says the government would have only 30 days to review an AI system, a shorter time frame than some in the industry were expecting. A longer time period might have been seen as too burdensome for a fast-moving and highly competitive industry. Trump canceled an Oval Office event with tech industry executives last month because he did not like what he saw in the earlier version of the order’s text. “We’re leading China, we’re leading everybody, and I don’t want to do anything that’s going to get in the way of that lead,” Trump told reporters at the time. That directive was characterized as a voluntary collaboration with participating U.S.-based tech companies, including Anthropic, OpenAI and Google, which are sometimes described as “frontier labs” because they are building the most advanced AI systems. Several companies had been planning to have executives present at the May 21 signing event. Trump ended up signing it without any ceremony. The White House said in a social media post Tuesday that the executive order “creates a process for frontier labs to voluntarily share cutting-edge cyber models in order to secure critical infrastructure and strengthen the government’s own cyber defenses. We are NOT conducting oversight of all new models, as that level of government overreach would have chilling effects on free speech and innovation.” Juan Londoño, a policy analyst at the libertarian-leaning Cato Institute, said the order is imperfect but “a step in the right direction to prepare the nation for the release of advanced AI systems.” He applauded the White House’s characterization of the process as voluntary but said he was concerned about the vagueness of how the government, led by the director of the National Security Agency, will decide which AI models qualify for scrutiny, and how it will decide which “trusted partners” get early access to them. Londoño said in an interview that giving so much discretion to the NSA director was a “dangerous precedent” that could enable the government to “weaponize” the policy against companies it is clashing with, like Anthropic. Plans for a new AI cybersecurity directive followed Anthropic’s April announcement of its most advanced AI model, called Claude Mythos, in the middle of the company’s legal fight with the Trump administration over a contract dispute with the Pentagon. Treasury Secretary Scott Bessent and outgoing Federal Reserve Chair Jerome Powell soon after convened an urgent meeting with Wall Street CEOs, warning them about the risks posed by Mythos’ apparent ability to find cybersecurity vulnerabilities in the world’s software. Anthropic has limited access to Mythos to only a small group of trusted partners, such as big tech companies and banks, though it said Tuesday it has expanded that group by another 150 organizations. Anthropic didn’t immediately respond to a request for comment about Trump’s new order but its chief rival, ChatGPT maker OpenAI, described the policy as an important step. “As AI capabilities continue to advance, we believe effective safety frameworks should continue to be developed through democratic institutions, informed by technical expertise and broad stakeholder input, to promote accountability and public trust,” said a statement from Chris Lehane, OpenAI’s chief global affairs officer. Democratic Sen. Mark Warner, vice chairman of the Senate Intelligence Committee, also welcomed Trump’s policy but criticized the administration for having “belatedly discovered the need to redo something it hastily dismantled in its first year.” Trump repealed many of former President Joe Biden’s guardrails for AI just hours after returning to the White House last year.
securityweek.comJun 2, 2026extracted
White House unveils pared-back AI executive order
White House unveils pared-back AI executive order The White House on Tuesday released its long awaited artificial intelligence executive order, putting forth a plan that downsizes an initial version that was scrapped last month amid internal dissent. The biggest change between the two iterations is that the latest plan changes the voluntary review period for government testing of AI models to within 30 days of release to the public and not the previously mandated 90 days. AI industry leaders had reportedly been pressuring the White House to establish a 14-day review period. The order notes that federal access to the models should be subject to “appropriate confidentiality, cybersecurity, insider-risk, and intellectual-property protection, use, and nondisclosure requirements.” Industry should collaborate with the government to select “trusted partners” who can access specially designated “covered frontier” models to beef up the cybersecurity of critical infrastructure and track cyber threats in a classified setting, according to the order. AI developers are directed to work with the government to decide which models to designate and which partners to entrust. The voluntary framework also should not be seen as authorizing the “creation of a mandatory governmental licensing, preclearance, or permitting requirement for the development, publication, release, or distribution of new AI models, including frontier models,” according to the order. The EO additionally mandates that executive branch officials — led by the Treasury Department — create an AI cybersecurity “clearinghouse” to facilitate collaboration between government, industry and critical infrastructure operators. The order directs Treasury officials to lead an executive branch effort to scan for vulnerabilities identified by AI models and determine how to prioritize patching. It also states that the Office of the National Cyber Director, the Cybersecurity and Infrastructure Security Agency and the Office of Management and Budget should locate federal grant funding that can be used for advanced AI vulnerability detection. The order was signed behind closed doors, a move that follows the last-minute cancellation of a public signing of the previous iteration amid internal conflict between some administration officials and former AI and crypto czar David Sacks, who told the president industry was concerned about its provisions harming innovation and competitiveness with China. The first version of the executive order had been agreed to and approved by high-ranking administration officials and shaped with input from industry leaders like Google, OpenAI and Anthropic before it was put on hold. At the time, the president said he “didn’t like certain aspects” of the EO, citing the threat posed by China. The president has largely directed the government to pursue an AI strategy that deemphasizes regulation, but that approach has been debated in recent weeks as new models like Anthropic’s Mythos have emerged as significant cybersecurity threats capable of discovering and targeting zero-day vulnerabilities autonomously. Senate Intelligence Committee Chairman Mark Warner (D-VA) endorsed the provisions in the executive order. However, while he praised the various measures as necessary reforms, he also criticized the administration for tearing up a Biden artificial intelligence EO that did some of the same things. “I salute the proposal for pre-deployment testing on a collaborative basis – just as I did when that idea was first advanced in the last administration’s EO, which was rescinded on Trump’s first day,” Warner said in a statement. Suzanne Smalley is a reporter covering digital privacy, surveillance technologies and cybersecurity policy for The Record. She was previously a cybersecurity reporter at CyberScoop. Earlier in her career Suzanne covered the Boston Police Department for the Boston Globe and two presidential campaign cycles for Newsweek. She lives in Washington with her husband and three children.
therecord.mediaJun 2, 2026extracted
Anthropic Expanding Mythos Access to 150 New Organizations
Anthropic announced on Tuesday that it is expanding Project Glasswing, its collaborative program aimed at securing critical software using AI. The initiative, launched with roughly 50 initial partners in early April, granted them access to Claude Mythos Preview. Those partners have since used Mythos to scan codebases and identified thousands of vulnerabilities. The expansion adds roughly 150 new organizations, each required to meet Anthropic’s standards before gaining access. These partners are based in more than 15 countries and include providers of critical infrastructure in sectors such as power, water, healthcare, communications, and hardware. Many are vendors and maintainers of widely used codebases relied upon by governments and other organizations worldwide. A common factor among the new partners is the potential impact of a successful cyberattack targeting their products, which could affect more than 100 million people for most participants and carry significant national and global security implications. The expansion of Project Glasswing follows collaboration with existing partners, the security industry, open source software maintainers, and the US government. Anthropic has not shared the expanded list of partners, but the Financial Times reported that the newly added organizations include Okta, Samsung, the EU cybersecurity agency ENISA, and NATO. The AI giant reported recently that Mythos identified more than 23,000 potential vulnerabilities, with the company estimating that more than 6,000 will be confirmed as severe flaws. Organizations such as Mozilla, Palo Alto Networks, and Cloudflare saw good results when turning Mythos against their own products. [ Read: Anthropic Releases New Claude Sandbox, Security Guidance Plugin ] With Mythos and other AI tools rapidly discovering vulnerabilities, the problem now shifts to verifying and patching them. For instance, of the thousands of security bugs found by Mythos, only 75 critical and high-severity issues have been patched. Anthropic says Mythos can also help with verification and patching, and the company is working with others to “substantially scale up the reviewing and patching of vulnerabilities in open-source software”. “We’re also working on sharing ideas and best practices for disclosing vulnerabilities to open-source maintainers, with the intent of making these reports easier to triage and to act upon,” Anthropic said. Related: Mythos Proves Potent in Vulnerability Discovery, Less Convincing Elsewhere Related: The Mythos Moment: Enterprises Must Fight Agents with Agents Related: OpenAI Widens Access to Cybersecurity Model After Anthropic’s Mythos Reveal Related: Sweet Security Launches Agentic AI Red Teaming to Counter ‘Mythos Moment’
securityweek.comJun 2, 2026extracted
Infosecurity Europe: Bayer Reinvents Security Awareness Training to Counter AI Threats
AI is shaping Bayer’s approach to security as the life sciences firm aims to become one of Europe’s leading agentic deployment organizations in the pharmaceutical industry. At Infosecurity Europe 2026, Kevin Jones, Bayer’s CISO, told attendees that the company has fundamentally changed how its workforce is prepared for AI-driven threats, moving away from checklist-style technical guidance toward psychology-first security awareness. "We scrapped everything to do with technical in our awareness training," Jones said, explaining that conventional advice, such as looking for spelling mistakes, suspicious URLs or odd attachments no longer works when attackers "have learnt to spell, in five different languages, all in real time, and it’s all generated with AI at scale." He argued that the human element must be reframed: that employees are taught to recognize psychological manipulation, ask whether someone is applying undue pressure or posing as an authority and to "stop and pause and think" before breaking process. Jones described the training as mandatory and behavior-focused. “Towards the end of last year, our CFO in the Europe, Middle East and Africa region received a very accurate sounding phone call from our global CFO, who asked them to quickly transfer them money over the weekend,” he explained. He said that because staff followed the new guidance, "everyone reported it" and there was zero loss. That story, Jones said, proved that reframing security awareness around adversary psychology can turn employees into an effective early defense against increasingly realistic social engineering. AI Access Tied to Training Completion Jones also explained that AI competence within Bayer’s staff is now tied to controlled access: small, role-based training modules are prerequisites for accessing internal AI platforms like myGenAssist, Bayer’s homemade response to commercial generative AI platforms like OpenAI’s ChatGPT, and additional ones for building agents within the platform. In practice, the life sciences company has created a tiered access model that gates who can develop and run agentic workflows. Jones said this system entices staff members to complete training and allows the security team to “track our data.” Towards a Human-On-the-Loop Approach for the SOC This AI-savvy approach is also applied to Bayer’s security operations. Jones said he would like security operations center (SOC) analysts to evolve from manual triage to supervised automation. “We are assuming they will not be able to work at the speed of agents,” he said. Jones expects SOC teams to move "from human in the loop to human on the loop within two to three years" as agent-assisted processes scale and he emphasized new operational playbooks and training to support that shift. “It means that analysts need to start thinking about using and managing AI agents themselves, not only AI co-pilots or assistants anymore,” he said. “I would encourage you to think of SOCs less as security operations centers and more as cyber resilience centers, because in the future, they will need to be able to change things in your environments, in a controlled way, to keep it resilient,” he added. AI Use Clauses in Third-Party Contracts Jones made clear that workforce requirements are paired with stricter third-party obligations, with suppliers also required to complete AI training before receiving tiered access to myGenAssist. Additionally, Bayer has established an internal AI Governance Council that defines every strategic move for using and deploying AI – standards that suppliers that integrate with Bayer’s AI ecosystem are expected to meet. Procurement contracts have also been updated with AI-specific security annexes that require suppliers to disclose how they use Bayer data, which AI tools they employ, and to report incidents. These contract changes are being rolled out to major partners now and will be deployed across the supplier base over the next 18 months. "Suppliers must inform us how they're using our data," Jones said, underscoring that transparency and contractual controls are non-negotiable. Image credits: brunocoelho / Taljat David / Shutterstock.com
infosecurity-magazine.comJun 2, 2026extracted
Loading 40 more…