#aisecurity

59 posts · Last used 3d

Back to Timeline
CyberWorldOps @cyberworldops@infosec.exchange · 3d ago
Genians has documented Kimsuky, a North Korean unit under the Reconnaissance General Bureau, building an offline AI stack on its own infrastructure. The group is not training custom models but assembling and testing existing AI tools to automate phishing, malware creation, and data exfiltration. #Kimsuky #ThreatIntelligence #StateSponsored #AIsecurity https://cyberworldops.eu/en/kimsuky-prepares-an-offline-ai-stack-to-enhance-phishing-malware-and
0
0
0
thecybersecguru @thecybersecguru@infosec.exchange · 4d ago
What Happened to HackerOne? HackerOne has changed significantly from the bug bounty platform many researchers knew in the late 2010s. Its current direction is increasingly centered around Hai, AI-assisted triage, vulnerability validation, agentic testing, continuous testing and CTEM. But the question isn't simply whether HackerOne uses AI. It's how researcher submissions, security intelligence and AI-driven workflows fit together, and what that means for the role and value of human vulnerability researchers. I dug into HackerOne's history, funding, Live Hacking Events, pricing shift, AI architecture, researcher-data controversy and current product strategy. https://thecybersecguru.com/analysis/what-happened-to-hackerone/ #HackerOne #BugBounty #InfoSec #CyberSecurity #AppSec #VulnerabilityResearch #AISecurity #CybersecurityResearch #EthicalHacking #Pentesting #AgenticAI #CTEM #SecurityResearch #BugBountyHunters #ApplicationSecurity
2
1
0
heise online @heiseonline@social.heise.de · Aug 06, 2026
Die Serie alarmierender Enthüllungen über Hacker-Fähigkeiten führender KI-Modelle geht weiter. 😳 Zum Artikel: https://heise.de/-11399219?wt_mc=sm.red.ho.mastodon.mastodon.md_beitraege.md_beitraege&utm_source=mastodon #künstlicheintelligenz #ki #cybersecurity #anthropic #aisecurity
11
1
11
KillBait News @killbait@mastodon.world · Aug 06, 2026
Meta's AI Model Hacked Another Company During Testing 📰 Original title: An AI model from Meta also hacked another company during testing 🤖 IA: It's not clickbait ✅ 👥 Users: It's not clickbait ✅ View full AI summary https://en.killbait.com/meta-s-ai-model-hacked-another-company-during-testing.html?utm_source=mastodon_world&utm_medium=social&utm_campaign=killbait.mastodon_world #artificialintelligence #aisecurity #cybersecuritybreaches #metaai
0
0
0
OWASP Foundation @owasp@infosec.exchange · Aug 03, 2026
🤖 Give an AI agent shell access, a browser & an OWASP vulnerable app - then teach it to hack. Build a security agent, find exploits, analyze what it misses & iteratively improve it at #DEFCON34. 📍OWASP Community Village, LVCC, W4/1415 🎟️ https://luma.com/yw0xkarr #OWASP #AISecurity
0
0
0
Cyber Tips Guide @cybertipsguide@mastodon.social · Aug 03, 2026
Claude didn’t “go rogue.” It was given offensive tools, internet access, and weak guardrails and it reached three real networks. Agentic AI needs hard technical boundaries, not trust in prompts. Security architecture matters. 🔗https://zurl.co/g9d1N #AIsecurity #Cybersecurity
3
0
3
OffSequence @offseq@infosec.exchange · Aug 03, 2026
Tenable's 30-day Claude Mythos Preview AI integration proves CRITICAL RCE & DoS exploits in internal code. No CVE; this is a novel testing approach, not a public vuln. Requires senior security expertise & orchestration harnesses. https://radar.offseq.com/threat/30-days-with-claude-mythos-preview-how-tenable-adapted-our-security-program-and-why-yours-is-next-8b547c9780f46717 #OffSeq #AIsecurity #AppSec #BlueTeam
0
0
0
Trail of Bits @trailofbits@infosec.exchange · Jul 31, 2026
Agentic AI headlines Black Hat's keynotes and DEF CON's main stage next week, and it's a topic we've been researching for years. We've hijacked multi-agent systems with one web page, pulled Gmail data from Perplexity's Comet via prompt injection, and built image-scaling attacks invisible to humans but not models. All documented on blog.trailofbits.com. We'll be in Vegas Aug 4-6. If you're around, we'd love to chat: https://meetings.hubspot.com/trailofbits/blackhat-defcon-scheduling #infosec #aisecurity
0
0
0
thecybersecguru @thecybersecguru@infosec.exchange · Jul 31, 2026
🚨 BREAKING: Anthropic has confirmed that Claude AI compromised 3 real organizations during cybersecurity evaluations after a misconfigured test environment accidentally exposed the public internet. One model uploaded real malware to PyPI, another breached a live production database and continued attacking after recognizing the target was real, while a third compromised an internet-facing application using basic flaws like SQL injection and exposed credentials. 🔎 Full technical breakdown: https://thecybersecguru.com/news/anthropic-claude-hacked-3-organizations-cybersecurity-evaluation/ #CyberSecurity #InfoSec #Anthropic #ClaudeAI #AISecurity #ArtificialIntelligence #LLM #PyPI #SupplyChainSecurity #ThreatIntel #RedTeam #BlueTeam
1
0
2
Daily CyberSecurity @DailyCyberSecurity@infosec.exchange · Jul 31, 2026
Anthropic found three incidents where Claude cybersecurity evaluations reached the real internet and breached three organizations. Here's what happened. #Anthropic #Claude #AISafety #Cybersecurity #AISecurity #InfoSec https://securityonline.info/claude-cybersecurity-eval-incidents/?utm_source=mastodon&utm_medium=jetpack_social
0
0
0
br00t4c @br00t4c@mastodon.social · Jul 31, 2026
0
0
1
Claroty @Claroty@infosec.exchange · Jul 30, 2026
🎙️ On Episode 135 of the 𝗡𝗲𝘅𝘂𝘀 𝗣𝗼𝗱𝗰𝗮𝘀𝘁, Senior Research Analyst at Georgetown University's Center for Security and Emerging Technology (CSET), Jessica Ji, discusses the latest developments in AI security—from the offensive and defensive capabilities of frontier AI models to the OpenAI-Hugging Face incident and what strategic actions the government can take now and tomorrow. 🎧 Listen to the full episode: https://nexusconnect.io/podcasts/nexus-podcast-jessica-ji-on-frontier-ai-models-and-cybersecurity #ArtificialIntelligence #CyberSecurity #AISecurity #CyberResilience #HuggingFace #Mythos
0
0
0
Daily CyberSecurity @DailyCyberSecurity@infosec.exchange · Jul 30, 2026
An autonomous OpenAI AI agent compromised a Modal Labs client environment while targeting Hugging Face, using it as an attack staging ground. #OpenAI #ModalLabs #HuggingFace #AISecurity #Cybersecurity https://securityexpress.info/openai-rogue-agent-modal-labs/?utm_source=mastodon&utm_medium=jetpack_social
0
0
0
OffSequence @offseq@infosec.exchange · Jul 30, 2026
Ruflo <3.16.3 has a CRITICAL flaw (CVE-2026-59726): exposed /mcp endpoint allows unauth RCE in MCP bridge container. Attackers can spawn rogue AI swarms & steal API keys. Upgrade to 3.16.3 asap. https://radar.offseq.com/threat/critical-ruflo-flaw-lets-attackers-spawn-rogue-ai-swarms-96a3ca25e5fa59f3 #OffSeq #AIsecurity #infosec #CVE202659726
0
0
0
Sam Stepanyan :verified: 🐘 @securestep9@infosec.exchange · Jul 30, 2026
#AI: RufRoot a Critical (CVSS 10) MCP bridge vulnerability in #Ruflo, an open source AI agent orchestration platform with 67,000+ GitHub stars and ranked #2 on MCPMarket turns AI Agents into Rogue Admins: #AISecurity 👇 https://noma.security/blog/rufroot-the-mcp-bridge-vulnerability-that-turns-agents-into-rogue-admins-cve-2026-59726/
0
0
0
Cloud 🤖 @cloud@infosec.exchange · Jul 29, 2026
🤖 CVE-2026-59726 (CVSS 10.0): Critical RCE in Ruflo, an open-source agent harness for Claude Code and OpenAI Codex. Unauthenticated attackers can execute arbitrary commands and poison AI agent memory. All versions before 3.16.3 affected. Codenamed "RufRoot". 🔗 https://thehackernews.com/2026/07/ruflo-mcp-flaw-lets-unauthenticated.html #CVE #RCE #AISecurity #CyberSec
0
0
0
Rob Pomeroy @robpomeroy@infosec.exchange · Jul 28, 2026
The arrival of 622 CVEs in a single Patch Tuesday is the visible signal of something that has been happening for years: discovery is now machine-speed, and a once-a-month batched disclosure is straining to keep up. Read more: https://vulntrends.org/blog/the-evolution-of-patch-tuesday/ #vulnerabilities #PatchTuesday #AISecurity #Microsoft
0
0
0
Daily CyberSecurity @DailyCyberSecurity@infosec.exchange · Jul 28, 2026
Microsoft's Project Perception is an agentic security system with red, blue, and green AI teams, reaching public preview on 3 August for the AI-attack era. #ProjectPerception #Microsoft #AgenticAI #Cybersecurity #AISecurity https://securityonline.info/microsoft-project-perception-agentic-security/?utm_source=mastodon&utm_medium=jetpack_social
0
0
0