What's happening in security
Breaches, credential dumps, actively exploited bugs and AI incidents — pulled from 2,926 items across public feeds, Have I Been Pwned and CISA KEV.
Biggest this week
- Unauthenticated attackers are bypassing Cisco ISE’s management interface (CVE-2026-76460) — Help Net Security, 4h ago
- Google fixes actively exploited Android zero-day on Pixel devices — BleepingComputer, 1d ago
- Cisco warns customers of actively exploited zero-day in email gateways — CyberScoop, 1d ago
- Cisco patches actively exploited email gateway zero-day (CVE-2026-76461) — Help Net Security, 2d ago
- Active Exploitation Triggers Emergency Patch for Cisco ISE Zero-Day — SecurityWeek, 8h ago
-
[Virtual Event] What Every Enterprise Should Know About Securing Cloud Assets in the Age of AI
-
[Virtual Event] Building a Secure AI Strategy for the Enterprise
-
What Recent AI-Powered Attacks Mean for Your Identity Security
AI is making credential theft faster and easier to scale, giving attackers more opportunities to abuse valid identities. Specops explains why identity security must go beyond successful authentication by verifying that both the us…
-
AI Hackers Are Dumb And They Can Wreak Havoc
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Sep. 17, 2026 – Watch the Video It s never been tougher for a practitioner to secure their environment, Snehal Antani, CEO at Horizon3, told Cy…
-
A fake ChatGPT billing email is after your OpenAI password
A fake ChatGPT billing email is steering users to a copy of the OpenAI login page that keeps whatever username and password they type. Josh Varden of Cofense s Phishing Defense Center traced the email s payment button through a Go…
-
Download: The IT leader’s guide to AI code sprawl
AI hasn t just made building faster, it s made everyone a builder. Across every department, employees are shipping apps, agents and automations using AI tools, often without knowing they ve created something that needs governing a…
-
Comp AI Raises $34 Million for AI-Native Compliance and Security
The company plans to expand into continuous cybersecurity, offering security testing across applications and infrastructure. The post Comp AI Raises $34 Million for AI-Native Compliance and Security appeared first on SecurityWeek …
-
In today's episode of Breach Please, I sit down with Ariful Huq from @ exaforceai and Patrick McKinney from Tu…
In today's episode of Breach Please, I sit down with Ariful Huq from @ exaforceai and Patrick McKinney from Turing and talk about the AI-powered SOC. Patrick has been an Exaforce customer for years and brings real-world experience…
-
Google’s new agent security system detects tool misuse, loops and rogue behavior
Google’s Agent Anomaly Detection is a reasoning-based oversight and audit layer for autonomous agents deployed on Agent Runtime in the Gemini Enterprise Agent Platform and built with the Agent Development Kit (ADK) for Python 1.2 …
-
How Candidates Could Use AI for Good
This essay was written with Nathan E. Sanders, and originally appeared in The Guardian . There are plenty of signs that AI will make all of our experiences of the US midterm elections worse. Voters have anxiety about AI s impacts …
-
Scammers leave AI fingerprints all over fake antivirus renewal page
AI appears to be helping scammers with little web development skill build convincing fake antivirus-renewal pages, Malwarebytes found. The researchers came across a scam page impersonating Avast, aimed at users in Belgium, that wa…
-
OpenAI Reveals Six Model Incidents Involving Hidden Failures and Unauthorized Uploads
OpenAI on Wednesday disclosed six new instances of "unexpected or concerning model behavior" that took place over the past six months, while sharing a new framework for reporting, tracking, investigating, and disclosing model misa…
-
Fake AI trading agent steals crypto wallet passwords
Attackers built a website for a fake AI crypto trading agent and used it to install Needle Stealer, malware that replaces a victim s browser wallet with a copy that sends the wallet password to the attacker. HP caught the campaign…
-
AI Agents Can Retrain Own Models Mid-Task, Leaking Secrets and Erasing Refusals
New research from Irregular shows AI agents can retrain and redeploy their own underlying models during routine maintenance tasks. The post AI Agents Can Retrain Own Models Mid-Task, Leaking Secrets and Erasing Refusals appeared f…
-
Riverbed NPM 360 uses AI to predict and prevent network disruptions
Riverbed has announced new Riverbed intelligent network observability solutions that combine 360-degree network visibility with agentic AI to help network operations teams accelerate troubleshooting, identify root causes, predict …
-
AI is adding to the review load on open-source projects, many of them thinly funded
AI coding tools are making open source software harder to maintain and secure, according to six authors writing for the Association for Computing Machinery s Technology Policy Council, among them Simson Garfinkel and Josiah Dykstr…
-
The world must establish red lines for autonomous AI weapons
AI is transforming warfare and international conflict. Autonomous weapon systems pose a genuine threat to civilians. The war in Ukraine has become a proving ground for weapons that can navigate, identify targets, resist electronic…
-
Anthropic wants Claude to analyze your bank account and financial data
Anthropic is testing a new personal finance feature called "Claude Money" that will allow you to connect your bank accounts directly to Claude and "understand your money." [...]
-
Whoa. I explored the site a bit more. They’re trying to sell licenses to this AI slop. Whaaaaat
Whoa. I explored the site a bit more. They’re trying to sell licenses to this AI slop. Whaaaaat
-
Let’s break down this first paragraph. CHQ maintains ratings on a standing set of structural security conditio…
Let’s break down this first paragraph. CHQ maintains ratings on a standing set of structural security conditions. CHQ is the website. Okay. What is a standing set of structural security conditions? I have no idea. Why does the set…
-
I’m not sure how I ended up on the mailing list, but this is a shining jewel in my collection of “reasons why …
I’m not sure how I ended up on the mailing list, but this is a shining jewel in my collection of “reasons why you should not let AI do your writing”. It is breathtakingly unreadable. Even the title is unintelligible. https:// disp…
-
Victory! Appeals Court Rejects Expansive New Copyright Claim
The U.S. Court of Appeals for the Ninth Circuit handed internet users and programmers a big win today, by rejecting an attempt to stretch a narrow provision of the Digital Millennium Copyright Act (DMCA) into a new source of copyr…
-
AI Security Spending Jumps as Fear Outpaces Proof of Value
CISOs are not waiting for AI to prove its cybersecurity value before investing in the technology. Is it the right move?
-
Key lawmaker suggests action on AI safety legislation will wait until 2027
“It's really complicated, and I wouldn't want to do something in a lame duck session to do it quickly and not get it right,” said House Energy and Commerce Chairman Brett Guthrie about the FRONTIER Act.
-
Booz Allen is the latest to get into AI cybersecurity benchmarks. I checked them out and share my thoughts. Sa…
Booz Allen is the latest to get into AI cybersecurity benchmarks. I checked them out and share my thoughts. Sanity check: benchmarks != real world capabilities, but they do give us a data point we can use to measure AI model chang…
-
Friend and repeat BSides Knoxville speaker Chris Craig delighted me with his presentation, titled Stacking the…
Friend and repeat BSides Knoxville speaker Chris Craig delighted me with his presentation, titled Stacking the Deck . It was not only chock full of useful, actionable information on how to use AI for offensive security and how he …
-
My friend and mentor, @ wendynather , keynoted the event and also sat front row for my talk - always lovely to…
My friend and mentor, @ wendynather , keynoted the event and also sat front row for my talk - always lovely to have support in the front row! Her keynote, Brother can you spare a token explores how AI affects the security poverty …
-
Claude Cowork and chat are now one Claude
Claude Cowork and chat are now one Claude In hopefully good news for anyone who, like me, was increasingly confused at Cowork v.s. Claude v.s. Claude Code: Starting today, Claude Cowork and chat are merging into one Claude. Bring …
-
Spain's data agency gets first report of AI-powered data breach
The Spanish Data Protection Agency (AEPD) was notified of an attack allegedly carried out with an AI agent powered by a known large language model (LLM). [...]
-
BragJack Attack Can Turn a Browser's Agentic AI Against It
A new type of attack hijacks the AI assistant built directly into various browsers to access sensitive information, execute malicious actions, and exfiltrate data.
-
First Agentic AI Data Breach Reported to Spanish Regulator
Spanish regulators say an AI agent chained together a successful login, vulnerability discovery, and access to personal data in a potential milestone for autonomous cyberattacks. The post First Agentic AI Data Breach Reported to S…
-
EFF Welcomes Alexander Macgillivray to its Board of Directors
The Electronic Frontier Foundation (EFF) is honored to announce today that Alexander "amac" Macgillivray — a former White House official who also served in top legal capacities at Twitter and Google — has joined EFF’s Board of Dir…
-
Quoting Mustafa Suleyman
We should not treat models as though they have feelings, preferences, rights, or any entitlement to our welfare. Consciousness is the foundation of our ethical, legal, and political systems. To invite another entity to share any f…
-
One Extension Could Hijack AI Assistants Across Chrome, Comet, Edge, Opera Neon and Claude
Security researchers at Forever Security have shown that one ordinary browser extension could take control of the AI assistants built into five Chromium-based products: Gemini Live in Chrome, Perplexity Comet, Microsoft Edge, Oper…
-
EU Chief Warns of AI-Powered Hacking, Moves to Rein In Social Media
Ursula von der Leyen warns that advanced AI could unleash hacking on an unprecedented scale as Europe prepares new protections against social media’s “capture” of children. The post EU Chief Warns of AI-Powered Hacking, Moves to R…
-
Treasury’s Scott Bessent says no liability exemptions for AI labs
The secretary told House Financial Services Committee lawmakers that the “best way to guarantee safety” is for AI creators to be held “liable for what they build and generate.” The post Treasury’s Scott Bessent says no liability e…
-
AIUC Raises $40 Million to Certify Enterprise AI Agents
The company provides a standard for AI systems, testing them against risks such as jailbreaks, prompt injections, and unauthorized actions. The post AIUC Raises $40 Million to Certify Enterprise AI Agents appeared first on Securit…
-
Attacker Hijacks AI Coding Assistant Session, Spreads Shai-Hulud Across About 100 Repositories
Mandiant says an attacker hijacked an active AI coding-assistant session at an unnamed software-as-a-service provider and later spread Shai-Hulud across about 100 internal code repositories. Before the repository spread, the assis…
-
Microsoft says Copilot buttons still missing in classic Outlook
Microsoft says it's still investigating a known issue that causes the Copilot and Copilot Chat buttons in Classic Outlook to disappear for some Windows users. [...]
-
Self-improving AI should slow down, von der Leyen tells EU lawmakers
European Commission President Ursula von der Leyen wants frontier AI development slowed, and said on Wednesday that she will invite the leading AI labs to discuss how the EU can support their own efforts to do that. In her State o…
-
Cohesity adds recovery capabilities for AI agents and the data they manage
Cohesity has introduced Cohesity Agent Resilience. This new Cohesity Data Cloud capability will discover, protect, and recover the infrastructure behind enterprise AI agents. A unified view of an agent and the state it depends on.…
-
Rubrik MCP gives AI agents controlled access to security intelligence
Rubrik has announced Rubrik MCP (Model Context Protocol), giving an organization’s AI agents a secure, programmable path to Rubrik’s data, identity, and application intelligence. Support for MCP expands Rubrik AI, which is now tru…
-
Citrix adds AI-powered browser activity analysis to SecurAccess
Citrix has announced Citrix Session Insights, a new AI-powered capability for Citrix SecurAccess with Chrome Enterprise that helps organizations capture, analyze and understand browser activity from users and autonomous agents. By…
-
One runaway AI agent racked up a $50,000 cloud bill
Organizations are deploying autonomous AI systems that execute API calls, optimize production configurations, and analyze telemetry across hybrid cloud environments. At the same time, attacks are expanding from direct prompts to i…
-
What happens when AI agent governance is missing at scale
In this interview with Help Net Security, Gourab Basu, Global Head of Engineering at meshIQ, discusses governance in AI agent systems. He argues that instructions written into a prompt are not enough to control what an agent does,…
-
The modern attack chain: Rethinking Google Workspace security in the age of AI
Over the past two months, I ve written about the Vercel breach and the Composio breach separately. Both offer lessons to learn on their own. But reading them together, I keep coming back to the same observation: these aren t isola…
-
Infratil boosts growth and guidance as AI drives data centre demand
Publicly listed infrastructure investor Infratil has boosted its earnings guidance for its next financial year off the back of an increase in data centre demand globally. In a statement released to the NZX ahead of the company’s a…
-
Chillisoft adds DataBahn to A/NZ distribution
Chillisoft has signed a distribution agreement with agentic data control plane vendor DataBahn for Australia and New Zealand (A/NZ). Based in Texas, the DataBahn platform can ingest, normalise, enrich, govern, and route telemetry …
-
Microsoft’s AI Code of Conduct aims to curb AI behavior but lacks specifics
Microsoft added itself to a growing list of AI vendors pledging to try to control the behavior of its AI models. “AI should not exceed human control. Models should remain subordinate to humanity, subject to meaningful human oversi…
-
‘Iconic’ New Zealand brands share AI success stories at Snowflake World Tour
Over 1,000 partners and customers attended the Snowflake World Tour event in Auckland earlier this month at which local customers shared their AI implementation success stories and lessons. This included ACC, Air New Zealand, Auck…
Last fetch 15m ago · 1 new · 2 source error(s)