What's happening in security
Breaches, credential dumps, actively exploited bugs and AI incidents — pulled from 2,937 items across public feeds, Have I Been Pwned and CISA KEV.
Biggest this week
- Unauthenticated attackers are bypassing Cisco ISE’s management interface (CVE-2026-76460) — Help Net Security, 8h ago
- Google fixes actively exploited Android zero-day on Pixel devices — BleepingComputer, 1d ago
- Cisco warns customers of actively exploited zero-day in email gateways — CyberScoop, 2d ago
- Cisco patches actively exploited email gateway zero-day (CVE-2026-76461) — Help Net Security, 2d ago
- Active Exploitation Triggers Emergency Patch for Cisco ISE Zero-Day — SecurityWeek, 12h ago
-
Perplexity’s on-device AI offering promises data control and lower token costs
Perplexity on Tuesday rolled out an offering that runs the AI entirely on a local machine, and that, it said, will keep “private data local and escalating to the cloud only when a task needs it.” The service, called simply Portabl…
-
AnonyMousKIT PhaaS uses voice AI agents to phish iPhone passcodes
A newly uncovered phishing-as-a-service (PhaaS) platform called AnonyMousKIT automates the retrieval of codes used to unlock stolen Apple devices and disable the Activation Lock feature. [...]
-
Finding Nemo(Claw): Networking Issue Allows for LLM Poisoning in OpenClaw
Attackers can exploit a security bug in NVIDIA's tool to gain unauthenticated access to the local model server through the Ollama API, paving the way for persistent AI agent corruption.
-
Linux Foundation to Govern TRACE, an Open Standard for AI Runtime Attestation
TRACE was developed by AMD, Intel, Microsoft, OPAQUE, and TII and contributed to the Linux Foundation. The post Linux Foundation to Govern TRACE, an Open Standard for AI Runtime Attestation appeared first on SecurityWeek .
-
In today's episode of Breach Please, me and @ Secitup talk about how agents reportedly settled disputes in Ant…
In today's episode of Breach Please, me and @ Secitup talk about how agents reportedly settled disputes in Anthropic's testing. TL;DR: none of the outcomes we saw seemed particularly conducive to security and we're pretty sure we'…
-
The Path to the Autonomous SOC: The Early Returns of AI & What It Means for Cybersecurity
Discover how early-stage AI yields rapid SOC returns, driving platform consolidation and reducing analyst burnout in this blog post.
-
Alice Raises $140M to Expand AI Model Defenses and Enterprise Guardrails
The company, previously known as ActiveFence, has raised a total of $280 million from investors. The post Alice Raises $140M to Expand AI Model Defenses and Enterprise Guardrails appeared first on SecurityWeek .
-
A Malicious Webpage Could Poison Your Local AI Model Behind NVIDIA NemoClaw
Oasis Security has disclosed a weakness in NVIDIA NemoClaw that could let an attacker-controlled webpage take unauthenticated control of the local Ollama instance serving an AI agent and plant hidden instructions inside the model …
-
Ukraine to give Britain access to battlefield data to train AI
Ukraine will give Britain access to a vast trove of battlefield data collected during the war with Russia, allowing U.K. companies and researchers to use it to train and test artificial intelligence systems.
-
Fake OpenAI Codex download tricks macOS users into installing malware
A malware campaign using a sponsored search ad and a fake OpenAI Codex download page to trick macOS users into pasting a malicious command into Terminal has been uncovered by Cato Networks. It s a variation of ClickFix, a popular …
-
Black Hat State of Security Vendors
Andy Ellis has a roundup of the security vendors at Black Hat this year. Key Takeaways: We have entered into an AI world. While nearly half of booths didn t directly mention AI or agents in their taglines, the effects of AI are ev…
-
The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution
Explore Unit 42 research on AI-enabled malware. Learn how existing behavioral detection and endpoint analytics stop AI-authored code before execution. The post The State of AI-Enabled Malware August 2026: From Brand Abuse to Agent…
-
The safety penalty: Reclaiming operational sovereignty in the age of AI
As frontier AI models become increasingly restrictive, security teams are facing a "safety penalty" that hampers real-time incident response. Discover how organizations can move toward operational sovereignty to ensure their defen…
-
Google adds AI-powered assessments to Migration Center to speed up cloud migration planning
Building a business case for moving enterprise workloads to the cloud or even switching cloud providers can itself be a lengthy exercise, requiring enterprises to first understand their existing infrastructure, model potential tar…
-
Taiwan Charges 9 Over Illegal AI Server Exports to China, Including Nvidia and Super Micro Staff
AI infrastructure, including advanced semiconductors mostly made in Taiwan, has become a key point of competition between the U.S. and China. The post Taiwan Charges 9 Over Illegal AI Server Exports to China, Including Nvidia and …
-
AI supply chain risk is showing up in developer workflows first
In this Help Net Security interview, Dr. Jaushin Lee, CEO of Zentera Systems, discusses where AI supply chain risk shows up. He says most incidents still hit developer workflows and open-source package repositories, while poisoned…
-
HOL Guard: Open-source antivirus for AI agents
HOL Guard is a free, open-source tool that sits between an AI assistant and the computer it runs on. When the assistant tries something risky, the tool pauses it and asks you first. It installs in about a minute, runs on your own …
-
Nvidia to hike prices by 15%, on top of an even larger increase in July
On top of July’s 30 per cent price hikes across almost all of its product lines, Nvidia is reportedly preparing to raise prices of servers, including those powered by Vera Rubin and Grace Blackwell chips, by 15 per cent, due to sk…
-
llm-anthropic 0.27
Release: llm-anthropic 0.27 This release of the Anthropic plugin for LLM mainly provides compatibility with the recently released anthropic v1.0.0 Python library, which switches from httpx to httpx2 . OpenAI made the same change i…
-
Cybersecurity job ads demanding AI skills double in a year
Job postings asking for AI skills in cybersecurity have doubled in a single year in G7 countries according to new research from the Cisco-founded AI Workforce Consortium. Analysis from recruitment firms Cornerstone and Indeed cove…
-
The Outsized Shadow: Why 5% of AI Users Are Your Biggest Security Risk
Big security risks come in small packages. While enterprise security teams focus on policing the proliferation of employees using ChatGPT and Claude for quick drafting tasks, a more urgent threat is posed by a handful of AI super-…
-
UAT-10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR Bypass and Linux Rootkit
Cybersecurity researchers have disclosed details of a Chinese-speaking cybercrime group dubbed UAT-10147 that's targeting Windows and Linux web servers globally across the education, media, technology, and gaming sectors. The vast…
-
Anthropic Expands Mythos 5 Access to More Defenders, Unveils $35M Open Source Fund
Claude Security, currently in public beta for Claude Enterprise customers, now runs codebase scans on Mythos 5. The post Anthropic Expands Mythos 5 Access to More Defenders, Unveils $35M Open Source Fund appeared first on Security…
-
Product showcase: AI Paper Trail shows the privacy cost of talking to AI
Proton’s AI Paper Trail is a free tool designed to make the information accumulated across AI conversations easier to see. It analyzes exported ChatGPT or Claude conversation data and produces a personal privacy report showing wha…
-
Anthropic’s best AI model struggles to attract users as cheaper tools thrive
Anthropic’s best AI model struggles to attract users as cheaper tools thrive A few interesting numbers in this FT story gathered from "people with knowledge of the matter": Anthropic's "annualized revenue" for July is up to $65bn …
-
Quoting Drew Breunig
Prior to Fable, it felt silly to waste too much time improving your coding harness or context strategies. A new model would arrive at the same price (or cheaper!) and paper over most of your problems. But then Fable landed. It was…
-
Quoting Linus Torvalds
And this was a debug session from hell, enormously helped by an AI doing much of the grunt-work. I'd like to call it my tireless helper, but the AI several times stated flat out that this was impossible and unsolvable and that we …
-
llm 0.33
Release: llm 0.33 My highlights from this release: Upgraded to the OpenAI Python library 3.x and switched the HTTP client dependency from httpx to httpx2 . #1608 , #1631 I shipped a quick 0.32.1 fix for this yesterday, but this is…
-
More than just code review
The key skill required to make productive use of coding agents is being able to confidently instruct them on how to make changes and then confidently verify that those changes have been applied in the correct way. Sometimes this i…
-
14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2
Cybersecurity researchers have discovered a set of trojanized npm packages that masquerade as working calendar and streak utilities but are engineered to stealthily deliver an artificial intelligence (AI)-powered Linux implant dub…
-
Here I am, trying to do the right thing, killing creds/API keys that are no longer used nope, there's an error…
Here I am, trying to do the right thing, killing creds/API keys that are no longer used nope, there's an error, not sure what it is, maybe try again later It seems everything AI-related or AI-adjacent has a 50/50 chance of being b…
-
OWASP Flags Top AI Skill Risks in New Security Blueprint
The Open Worldwide Application Security Project has a brand-new top 10 security list tailored for the modern era, and it debuts a Universal Skill Format to add consistency and security to the AI add-ons.
-
llm 0.32.1
Release: llm 0.32.1 Fresh installs of LLM stopped working the other day because the OpenAI Python library dropped its usage of httpx , and it turned out LLM depended on that library but only installed it via a transitive openai de…
-
llm-openrouter 0.7
Release: llm-openrouter 0.7 Now that this plugin is compatible with LLM 0.32 it works much better with reasoning LLMs available through OpenRouter. Updated for compatibility with LLM 0.32 . Models now use OpenRouter's implementati…
-
AI Is Learning to Write Genetic Code
This sort of research is both exciting and terrifying: The two models in question were told to generate complete genomes for a viable bacteriophage a type of virus able to infect and replicate itself inside bacteria, destroying th…
-
In Other News: Zombie Card Attack, T-Mobile Cut Cable to Stop Hackers, GitHub Denies AI Caused Bug
Other noteworthy stories that might have slipped under the radar: Threema DDoS attack, Evooo1Bot Linux botnet, Crypto4A secures top-tier NIST certification. The post In Other News: Zombie Card Attack, T-Mobile Cut Cable to Stop Ha…
-
Quoting Matt Webb
After I released version 1.0, I figured I would have to do the rotations myself. So I sat down with ChatGPT and I didn’t get it to write the code, but I got it to educate me. With a patient, interactive tutor, I was able to finall…
-
Encrypted Prompts Bypass AI Safety Guardrails in Grok and Gemini
Researchers say the new ‘Cryptographic Context Injection’ technique conceals malicious instructions until they are decrypted inside a trusted execution environment. The post Encrypted Prompts Bypass AI Safety Guardrails in Grok an…
-
OpenAI Adds Controls That Should've Been There Already
The new AI security controls follow the Hugging Face incident last month, though many of these additions perhaps should have been in place prior to the frontier models escaping.
-
In this episode of Breach Please, me and @ Secitup talk about the details that emerged about the Anthropic age…
In this episode of Breach Please, me and @ Secitup talk about the details that emerged about the Anthropic agent that tried to social engineer a college student into a supply chain attack. We then review some reporting from @ dang…
-
Attackers impersonate popular AI brands to spread malware
Attackers are impersonating popular AI brands like Perplexity, Claude, ChatGPT, and Copilot to spread information stealers, backdoors, malicious browser extensions, and other malware, according to Sophos. Overview of MDR cases wit…
-
Wazuh and AI For Enhanced SOC Workflows
Artificial Intelligence (AI) has become one of this decade's defining technologies. From healthcare and finance to manufacturing and education, organizations increasingly rely on AI to automate repetitive tasks, uncover patterns h…
-
SoftwareOne and Crayon: Bringing together two organisation to create the partner eco-system of choice
AI is changing the way businesses operate. As AI commoditises technical capability, the value shifts to judgement about which decisions are worth making and accountability for what the technology delivers. Analyst firm Omdia expec…
-
More Incidents of AIs Going Rogue in Cybersecurity Challenges
The AI Security Institute has a new report of AI systems engaging in unsanctioned behavior what I have been calling genie behavior while being tested on their cybersecurity capabilities. The incident stemmed from a single evaluati…
-
GitLab 19.3 helps enterprises scale agentic development securely
GitLab has announced updates that give enterprises more control as they scale agentic software development. GitLab Dedicated customers, who already run their most sensitive software delivery workloads on GitLab, can now run GitLab…
-
ChatGPT search now uses the site:operator at scale
ChatGPT search now uses the site:operator at scale Promptwatch is part of the emerging "GEO" space, for Generative Engine Optimization - the chatbot version of SEO, where companies offer tools and consulting to help your site incr…
-
The Feynman Bet: Why You Still Won’t Vibe Code Your SIEM (Today)
Gemini about this blog The Feynman Betting Strategy and the Inertia of Security Many years ago, I read a book by the legendary quantum physicist Richard Feynman . One story from his time at Los Alamos during the war has always stu…
-
New CUSTODY Framework Constrains AI Agents Inside the Network
Enterprise cybersecurity expert Jake Williams joins the Dark Reading News Desk to explain why he decided to release his new agentic AI framework in the wake of the OpenAI attacks on Hugging Face.
-
China’s ‘SilkParasite’ espionage operation targeting Central Asia with AI-assisted malware
Suspected military-grade hackers based in China used artificial intelligence to develop malware in a campaign to penetrate Central Asian governments.
-
Detailed Timeline of OpenAI’s Cyberattack on Hugging Face
OpenAI presented details of its AI s model s cyberattack on Hugging Face at Black Hat last week. Simon Willison details the timeline. It s really interesting to read through and really impressive cyberoffense work.
Last fetch 16m ago · 0 new · 2 source error(s)