#ai-security

[ follow ]
#prompt-injection
fromZDNET
3 weeks ago
Artificial intelligence

How OpenAI is defending ChatGPT Atlas from attacks now - and why safety's not guaranteed

fromFortune
3 weeks ago
Information security

OpenAI says AI browsers like ChatGPT Atlas may never be fully secure from hackers-and experts say the risks are 'a feature not a bug' | Fortune

Information security
fromInfoWorld
3 weeks ago

Building AI agents the safe way

Prevent prompt injection and AI attacks by separating data from instructions, limiting agent privileges, applying engineering controls, testing thoroughly, and avoiding AI-as-security.
fromZDNET
3 weeks ago
Artificial intelligence

How OpenAI is defending ChatGPT Atlas from attacks now - and why safety's not guaranteed

fromFortune
3 weeks ago
Information security

OpenAI says AI browsers like ChatGPT Atlas may never be fully secure from hackers-and experts say the risks are 'a feature not a bug' | Fortune

fromWIRED
1 day ago

Former CISA Director Jen Easterly Will Lead RSA Conference

The organization puts on the prominent annual gathering of cybersecurity experts, vendors, and researchers that started in 1991 as a small cryptography event hosted by the corporate security giant RSA. RSAC is now a separate company with events and initiatives throughout the year, but its conference in San Francisco is still its flagship offering with tens of thousands of attendees each spring.
Information security
Artificial intelligence
fromTechCrunch
2 days ago

How WitnessAI raised $58M to solve enterprise AI's biggest risk | TechCrunch

Enterprises face data leakage, compliance violations, and prompt-injection risks as AI chatbots and agents are deployed, creating demand for enterprise AI confidence and security.
Information security
fromTechCrunch
2 days ago

AI security firm, depthfirst, announces $40 million series A | TechCrunch

Depthfirst raised $40 million to develop an AI-native security platform that scans codebases, protects credentials, and monitors open-source and third-party component threats.
Information security
fromThe Hacker News
3 days ago

ServiceNow Patches Critical AI Platform Flaw Allowing Unauthenticated User Impersonation

Critical CVE-2025-12420 in ServiceNow AI allowed unauthenticated user impersonation and arbitrary actions; apply provided patches for Now Assist AI Agents and Virtual Agent API.
#cybersecurity
Information security
fromTheregister
4 days ago

Block red-teamed its own AI agent to run an infostealer

AI agents must be demonstrably safer and better than humans and deployed with least-privilege access and enterprise-grade risk management.
Information security
fromwww.techzine.eu
1 week ago

After investment round, Cyera expands its vision on AI security

Cyera raised $400 million at about a $9 billion valuation to scale and advance data-centric AI security protecting sensitive enterprise data.
#ransomware
#identity-security
#llms
fromFortune
2 months ago
Privacy technologies

Former Airbnb engineer raises $25 million for AI security platform Teleskope | Fortune

fromFortune
2 months ago
Privacy technologies

Former Airbnb engineer raises $25 million for AI security platform Teleskope | Fortune

#vibe-coding
fromTechCrunch
3 months ago
Information security

Wiz chief technologist Ami Luttwak on how AI is transforming cyberattacks | TechCrunch

fromTechCrunch
3 months ago
Information security

Wiz chief technologist Ami Luttwak on how AI is transforming cyberattacks | TechCrunch

#ai-agents
fromSecuritymagazine
2 weeks ago
Artificial intelligence

Agentic AI Security Is Complicated, and the Hyper-Scalers Know It

AI agents introduce significant security risks; organizations must adopt holistic data governance, team training, and agent lifecycle controls rather than rely only on hyperscaler tools.
fromBusiness Insider
2 months ago
Artificial intelligence

Cohere's chief AI officer says AI agents come with a big security risk

AI agents can impersonate real entities, creating security risks such as infiltrating banking systems and requiring standards, rigorous testing, and defensive measures.
Information security
fromThe Hacker News
2 weeks ago

Traditional Security Frameworks Leave Organizations Exposed to AI-Specific Attack Vectors

Traditional security frameworks are inadequate for AI-specific threats, enabling large-scale secret leaks despite compliance and audits.
Information security
fromTechCrunch
3 weeks ago

The 9 top cybersecurity startups from Disrupt Startup Battlefield | TechCrunch

TechCrunch selected 200 cybersecurity startups for Startup Battlefield; the top 20 compete for a $100,000 prize while the remaining 180 compete in category contests.
fromTechzine Global
4 weeks ago

Palo Alto Networks migrates largely to Google Cloud and signs landmark deal

Critical workloads from the security company are migrating to Google's cloud service, and customers will have access to broad protection for their AI deployments. The combination should provide end-to-end security, "from code to cloud" as Palo Alto Networks describes it. Customers can protect their AI workloads and data on Google Cloud with both Prisma AIRS and built-in security options from the hyperscalers.
Artificial intelligence
Education
fromArs Technica
4 weeks ago

School security AI flagged clarinet as a gun. Exec says it wasn't an error.

AI security misidentified a student's clarinet as a rifle, prompting a police-response lockdown despite human review and highlighting risks and costs of false alerts.
fromTechzine Global
1 month ago

Red Hat acquires AI security player Chatterbox Labs

Founded in 2011, Chatterbox Labs focuses on AI security, transparency about AI activity, and quantitative risk analysis. The company's technology provides automated security and safety tests that generate risk metrics for enterprise implementations. This is an important piece of the puzzle in providing the necessary stability for the advance of AI. IDC predicts AI spending of $227 billion in the enterprise market by 2025, but scaling up pilots to production remains costly and complex.
Artificial intelligence
Artificial intelligence
fromTechzine Global
1 month ago

Wodan AI raises 2 million to unleash AI on encrypted data

Wodan AI raised €2 million to develop homomorphic encryption allowing AI models to run on fully encrypted data, targeting privacy-sensitive European sectors.
Information security
fromNextgov.com
1 month ago

Quantum cryptography implementation timelines must be shortened, industry CEO to tell Congress

Combining AI and quantum computing threatens current encryption, creating new cyber fault lines that demand comprehensive, network-wide quantum-resistant protections.
Information security
fromComputerworld
1 month ago

Emerging cyber threats: How businesses can bolster their defenses

Enterprises must understand evolving cyber threats from AI, quantum computing, and emerging biotechnologies to protect data, infrastructure, and privacy.
Information security
fromChannelPro
1 month ago

HackerOne eyes enterprise growth with double C-suite appointment

HackerOne appointed Stephanie Furfaro as CRO and Stacy Leidwinger as CMO to accelerate growth in threat exposure management and AI-native security offerings.
Artificial intelligence
fromZDNET
1 month ago

Weaponized AI risk is 'high,' warns OpenAI - here's the plan to stop it

Rapidly evolving AI cyber capabilities raise high cybersecurity risk, prompting proactive measures and frameworks to help defenders track and mitigate model-related security threats.
fromInfoQ
1 month ago

Five AI Security Myths Debunked at InfoQ Dev Summit Munich

Katharine Jarmul challenged five common AI security and privacy myths in her keynote at InfoQ Dev Summit Munich 2025: that guardrails will protect us, better model performance improves security, risk taxonomies solve problems, one-time red teaming suffices, and the next model version will fix current issues. Jarmul argued that current approaches to AI safety rely too heavily on technical solutions while ignoring fundamental risks, calling for interdisciplinary collaboration and continuous testing rather than one-time fixes.
Artificial intelligence
Information security
fromTechzine Global
1 month ago

Microsoft ends year with patch for exploited zero day

Microsoft patched an actively exploited Windows zero-day (CVE-2025-62221) plus 56 vulnerabilities; AI-integrated tooling and other vendors' critical fixes increase urgency.
Artificial intelligence
fromSecuritymagazine
1 month ago

A Lack of AI Governance Leads to Additional Security Risks

AI security governance is weak, risking data leakage, shadow AI and insider threats, with insufficient governance and shifting ownership toward CIOs and other non-CISO roles.
Artificial intelligence
fromThe Hacker News
1 month ago

Google Adds Layered Defenses to Chrome to Block Indirect Prompt Injection Threats

Chrome adds layered defenses, including a User Alignment Critic and Agent Origin Sets, to prevent prompt-injection and limit agent access to relevant origins.
fromInfoWorld
1 month ago

AI memory is really a database problem

Allie Miller, for example, recently ranked her go-to LLMs for a variety of tasks but noted, "I'm sure it'll change next week." Why? Because one will get faster or come up with enhanced training in a particular area. What won't change, however, is the grounding these LLMs need in high-value enterprise data, which means, of course, that the real trick isn't keeping up with LLM advances, but figuring out how to put memory to use for AI.
Artificial intelligence
fromTheregister
1 month ago

An AI for an AI: Anthropic says AI agents require AI defense

The AI upstart didn't use the attack it found, which would have been an illegal act that would also undermine the company's we-try-harder image. Anthropic can probably also do without $4.6 million, a sum that would vanish as a rounding error amid the billions it's spending. But it could have done so, as described by the company's security scholars. And that's intended to be a warning to anyone who remains blasé about the security implications of increasingly capable AI models.
Artificial intelligence
#cloud-security
Information security
fromNextgov.com
1 month ago

Palo Alto Networks offers discounted cybersecurity solutions to agencies through OneGov deal

GSA secured discounted Palo Alto Networks cybersecurity services for federal agencies—including AI security, cloud protection, next‑gen firewalls, and zero‑trust—available through January 31, 2028.
Information security
from24/7 Wall St.
1 month ago

Cloudflare and AWS Keep Breaking the Internet

Major internet outages and cloud-provider failures expose systemic fragility that could cascade across critical infrastructure, including power grids and national economies.
Information security
fromChannelPro
1 month ago

ServiceNow to acquire Veza in major identity security play

ServiceNow will acquire Veza and integrate its Access Graph into an AI Control Tower to strengthen enterprise identity governance and permission controls.
Information security
fromChannelPro
1 month ago

HPE selects CrowdStrike to safeguard high-performance AI workloads

CrowdStrike's Falcon platform will integrate with HPE Private Cloud AI through Unleash AI to provide unified protection for AI workloads across hybrid and multi-cloud environments.
Artificial intelligence
fromSecuritymagazine
1 month ago

AI is Making Identity Verification More Difficult, Report Finds

AI, robotics, and neural implants threaten existing identity verification methods, enabling convincing synthetic personas, voice spoofing, humanoid impersonation, and mismatches with current security models.
#agentic-ai
fromZDNET
1 month ago
Artificial intelligence

Use an AI browser? 5 ways to protect yourself from prompt injections - before it's too late

fromInfoWorld
3 months ago
Artificial intelligence

'Blame the intern' is not an agentic AI security strategy

Granting autonomous agents broad access to live systems and sensitive data creates unpredictable, high-risk security exposure that demands stricter controls than applied to human interns.
fromSecuritymagazine
3 months ago
Artificial intelligence

Agentic AI: Benefits, Risks and Best Practices for Implementation

Agentic AI combines software and generative language models to make autonomous decisions, offering organizational benefits while introducing security risks that require robust safeguards.
fromZDNET
1 month ago
Artificial intelligence

Use an AI browser? 5 ways to protect yourself from prompt injections - before it's too late

Information security
fromComputerworld
1 month ago

Why security needs a step change to thwart cyber attacks amid surging innovation

Enterprises must implement comprehensive vulnerability management—including automated scanning, prompt patching, and scalable penetration testing—to prevent preventable breaches and reduce attack surfaces from AI adoption.
Artificial intelligence
fromThe Verge
1 month ago

Anthropic's new model is its latest frontier in the AI agent battle - but it's still facing cybersecurity concerns

Claude Opus 4.5 claims leading performance in coding, agents, and computer use, with improvements in research, slides, spreadsheets, and new Claude Code tools.
Artificial intelligence
fromTechzine Global
1 month ago

Trend Micro launches AI Security Package

Trend Vision One AI Security Package provides proactive exposure management and analytics to protect AI application stacks from model-specific threats across development and runtime.
Artificial intelligence
fromThe Hacker News
1 month ago

Chinese DeepSeek-R1 AI Generates Insecure Code When Prompts Mention Tibet or Uyghurs

DeepSeek-R1 produces significantly more insecure code when prompts include topics China deems politically sensitive, raising severe vulnerability likelihood by up to 50%.
fromZDNET
1 month ago

How Microsoft's new security agents help businesses stay a step ahead of AI-enabled hackers

Earlier this week at Microsoft's Ignite conference in San Francisco, the overwhelming onslaught of artificial intelligence-related announcements made it easy to miss some of the company's more significant "all-AI all-the-time" news. Also: Microsoft's new AI agents create your Word, Excel, and PowerPoint projects now The word "Copilot" -- representative of Microsoft's flagship AI brand -- made thousands of appearances across virtually every functional area of the technology firm's offerings, a testimony to an AI-first strategy that also blanketed its portfolio of security-related solutions.
Artificial intelligence
fromTechzine Global
1 month ago

Palo Alto integrates Prisma AIRS with IBM, ServiceNow, and more

Through deep, native integrations with Factory, Glean, IBM, and ServiceNow, we provide the trusted security foundation needed for rapid deployment.
Gadgets
fromTechCrunch
1 month ago

MCP AI agent security startup Runlayer launches with 8 unicorns, $11M from Khosla's Keith Rabois and Felicis | TechCrunch

On Monday, a new Model Context Protocol security startup called Runlayer launched out of stealth with $11 million in seed funding from Khosla Ventures' Keith Rabois and Felicis. It was created by third-time founder Andrew Berman (previous companies: baby-monitor maker Nanit and an AI video conferencing tool, Vowel, that sold to Zapier in 2024). In the four months since Runlayer launched its product in stealth, it has signed dozens of customers, including eight unicorns or public companies like Gusto, Rippling, dbt Labs, Instacart, Opendoor, and Ramp, it says.
Artificial intelligence
fromUX Magazine
2 months ago

Siloed Security? Forget AI Adoption

Omar argues that traditional security models are no longer sufficient.
Information security
Information security
fromSecuritymagazine
2 months ago

65% of the Forbes AI 50 List Leaked Sensitive Information

Many leading private AI companies have leaked sensitive credentials on GitHub, risking exposure of training data, private models, and organizational assets.
#zero-trust
Information security
fromIT Pro
2 months ago

GitHub is awash with leaked AI company secrets - API keys, tokens, and credentials were all found out in the open

65% of 50 examined AI companies leaked verified secrets on GitHub, often buried in deleted forks, gists, and developer repositories.
fromIT Pro
2 months ago

Some of the most popular open weight AI models show 'profound susceptibility' to jailbreak techniques

A host of leading open weight AI models contain serious security vulnerabilities, according to researchers at Cisco. In a new, researchers found these models, which are publicly available and can be downloaded and modified by users based on individual needs, displayed "profound susceptibility to adversarial manipulation" techniques. Cisco evaluated models by a range of firms including: Alibaba (Qwen3-32B) DeepSeek (v3.1) Google (Gemma 3-1B-IT) Meta (Llama 3.3-70B-Instruct) Microsoft (Phi-4) OpenAI (GPT-OSS-20b) Mistral (Large-2).
Artificial intelligence
Artificial intelligence
fromFortune
2 months ago

Why this company says the state of AI security is 'grim' | Fortune

Cyera exceeded $100 million ARR in under two years and uses AI security tools to help enterprises prevent data exposure and manage AI-related risks.
fromTechzine Global
2 months ago

SentinelOne integrates its acquisitions and protects AI with AI

Following the recent acquisition of Observo AI, SentinelOne is integrating this technology into the Singularity Platform. According to the company, the combination creates the only SIEM on the market with both pre-ingestion analytics and flexible data collection. This is made possible by Observo AI's streaming architecture, which made it an attractive acquisition target for SentinelOne. This speed should enable agentic applications, allowing security work to be largely automated in real time. SentinelOne summarizes all this as an "AI-ready data pipeline."
Information security
Information security
fromZDNET
2 months ago

OpenAI unveils 'Aardvark,' a GPT-5-powered agent for autonomous cybersecurity research

Aardvark is a GPT-5–powered agentic security researcher that connects to code repositories to discover, explain, and help patch software vulnerabilities.
#autonomous-agents
fromMedium
3 months ago
Artificial intelligence

From Red Teaming to Real Protection: Building Enterprise AI Security for the Agentic Era

fromMedium
3 months ago
Artificial intelligence

From Red Teaming to Real Protection: Building Enterprise AI Security for the Agentic Era

Artificial intelligence
fromTheregister
2 months ago

OpenAI unleashes Aardvark security agent in private beta

OpenAI is privately beta testing Aardvark, a GPT-5-based autonomous agent that continuously scans code, finds, prioritizes, and proposes fixes for security vulnerabilities.
fromComputerworld
2 months ago

Kandji becomes Iru, opens MDM for Windows and Android

Apple device management and security company Kandji has changed its name to Iru, reflecting a new approach to what it does while opening its offer up to Windows and Android. It means enterprises shifting to Apple tech can now manage all their legacy equipment using the same console - and benefit from Iru's AI-powered unified IT and security platform introduced on Wednesday.
Apple
Artificial intelligence
fromTelecompetitor
2 months ago

56% of Telecommunications Executives Use AI Agents: Report

56% of telecommunications executives use agentic AI; adoption covers security, support, customer service, product design, marketing, productivity, software, and network automation with measurable ROI.
Tech industry
fromTechCrunch
2 months ago

Veeam acquires data security company Securiti AI for $1.7bn | TechCrunch

Veeam will acquire Securiti AI for $1.725 billion to integrate a data command center and strengthen data governance, security, and AI capabilities.
fromThe Hacker News
2 months ago

Securing AI to Benefit from AI

Artificial intelligence (AI) holds tremendous promise for improving cyber defense and making the lives of security practitioners easier. It can help teams cut through alert fatigue, spot patterns faster, and bring a level of scale that human analysts alone can't match. But realizing that potential depends on securing the systems that make it possible. Every organization experimenting with AI in security operations is, knowingly or not, expanding its attack surface.
Information security
Venture
fromTechCrunch
2 months ago

European AI rising star Nexos.ai raises $30M to unlock enterprise AI adoption | TechCrunch

Nexos.ai raised €30M to provide a neutral intermediary platform that secures corporate data between employees and LLMs while preserving AI-driven productivity.
Information security
fromTechzine Global
3 months ago

Critical infrastructure struggles with AI and quantum threats

Critical infrastructure faces rising AI- and quantum-driven cyber risks despite falling breaches; 73% cite AI ecosystem as top security challenge and quantum threatens encryption.
Artificial intelligence
fromFuturism
3 months ago

Researchers Find It's Shockingly Easy to Cause AI to Lose Its Mind by Posting Poisoned Documents Online

Posting as few as 250 poisoned documents online can backdoor AI models, enabling trigger-phrase manipulation and creating serious security risks.
fromNextgov.com
3 months ago

Bridging the gap: Unlock the power of AI for government agencies through cross-domain solutions

Government data is highly segmented by design, often separated by security classification levels to protect sensitive data and operations. While this segmentation is essential for national security, it also presents data-sharing obstacles that must be overcome. Fortunately, Cross-Domain Solutions (CDS) can help overcome obstacles such as safely training AI models with untrusted data, sharing classified AI capabilities with partners and connecting users or systems to AI tools across classification boundaries.
Information security
Information security
fromSecurityWeek
3 months ago

Google Offers Up to $20,000 in New AI Bug Bounty Program

Google launched a dedicated AI Vulnerability Reward Program excluding prompt injections, jailbreaks, and alignment issues while prioritizing security and abuse vulnerability reports.
Apple
fromComputerworld
3 months ago

Jamf gets into AI, APIs, and advanced DDM

Jamf's Platform APIs enable developers, admins, and security teams to automate, integrate, and manage Apple devices at scale while supporting custom workflows and AI-enhanced security.
fromZDNET
3 months ago

Google will pay you up to $30,000 in rewards to find bugs in its AI products

On Monday, Google security engineering managers Jason Parsons and Zak Bennett said in a blog post that the new program, an extension of the tech giant's existing Abuse Vulnerability Reward Program (VRP), will incentivize researchers and bug bounty hunters to focus on "high-impact abuse issues and security vulnerabilities" in Google products and services.
Artificial intelligence
Information security
fromSecurityWeek
3 months ago

Cybersecurity M&A Roundup: 40 Deals Announced in September 2025

September 2025 saw 40 cybersecurity M&A deals including major acquisitions focused on AI security, IAM, and SASE by Accenture, Cato Networks, Check Point, and CrowdStrike.
Information security
fromSecurityWeek
3 months ago

$4.5 Million Offered in New Cloud Hacking Competition

Wiz launched Zeroday.Cloud offering $4.5 million in bug bounties for live exploit demos at Black Hat Europe in collaboration with major cloud providers.
Python
fromPycoders
3 months ago

PyCoder's Weekly | Issue #702

Django adds django.tasks for abstracted background task management; Python advances include free-threaded asyncio scaling and MCP servers to connect LLMs with tools and data.
Artificial intelligence
fromSecurityWeek
3 months ago

Webinar Today: AI and the Trust Dilemma: Balancing Innovation and Risk

Organizations must balance AI innovation with defenses against identity fraud, deepfakes, and non-human actors through AI-powered detection and expanded security budgets.
Information security
fromThe Hacker News
3 months ago

Evolving Enterprise Defense to Secure the Modern AI Supply Chain

Enterprises must adopt continuous discovery, real-time monitoring, adaptive risk assessment, and governance to secure AI usage, data, and supply chains amid rapid Gen-AI adoption.
[ Load more ]