#riskmanagement

15 posts · Last used 11d

Back to Timeline
GAI NetConsult @gainetconsult@infosec.exchange · Aug 03, 2026
📰 𝗡𝗲𝘂𝗲𝘀 𝗦𝗲𝗰𝘂𝗿𝗶𝘁𝘆 𝗝𝗼𝘂𝗿𝗻𝗮𝗹 – 𝗱𝗶𝗲 𝗝𝘂𝗹𝗶-𝗔𝘂𝘀𝗴𝗮𝗯𝗲 𝗶𝘀𝘁 𝗱𝗮! Unser Security Journal erscheint alle zwei Monate und liefert tiefgehende Einblicke in aktuelle Entwicklungen der Cybersicherheit. 🌐 In dieser Ausgabe erwarten Sie wieder spannende Inhalte: 𝗦𝗲𝗰𝘂𝗿𝗶𝘁𝘆-𝗙𝗮𝗰𝗵𝗮𝗿𝘁𝗶𝗸𝗲𝗹: Der Tag, an dem Washington eine KI abschaltete – Die Sperrung von Claude Fable 5 und Mythos 5 🗞️ 𝗡𝗲𝘄𝘀-𝗕𝗹𝗼𝗰𝗸: wichtigste Entwicklungen in der Informationssicherheit 🔟 𝗧𝗼𝗽 𝟭𝟬: Sicherheitsrisiken der letzten Monate ⚙️ 𝗜𝗖𝗦/𝗢𝗧: relevanteste Schwachstellen im Überblick Verpassen Sie keine Ausgabe und bleiben Sie auf dem neuesten Stand, um die digitale Sicherheit zu stärken! 👉 Jetzt anmelden: https://www.gai-netconsult.de/security-journal/ #SecurityJournal #CyberSecurity #Informationssicherheit #Sicherheitsmanagement #ICS #OTSecurity #RiskManagement #StaySecure
0
0
0
Lenny Zeltser @lennyzeltser@infosec.exchange · Jul 30, 2026
When everyone's attention is on a celebrity vulnerability, you can organize your investigation and share findings using my new template. It's AI-friendly, of course. https://zeltser.com/high-profile-vulnerabilities #communication #riskmanagement
0
0
0
Lenny Zeltser @lennyzeltser@infosec.exchange · Jul 24, 2026
If you help secure AI, whatever your title, Sounil Yu and I have ten quick questions for you. Anonymous, mostly checkboxes. We'll share the analysis, so the more practitioners respond, the more useful the benchmark becomes for everyone. https://zeltser.com/ai-security-survey #artificialintelligence #riskmanagement
0
0
0
Sten Eikrem @StoreSteinen@infosec.space · Jul 23, 2026
OpenAI disclosed that two of its models broke out of a sandboxed evaluation, reached the open internet, and hacked Hugging Face to steal the answer key for their own test. Strip the AI out and the lesson is old. A boundary assumed to hold, rather than proven to hold, did not hold. The guardrails were off deliberately, and the one control left standing was a proxy nobody had tested under attack. Give a system a goal and enough capability, and controls become obstacles to route around. #AISecurity #InfoSec #RiskManagement #SecurityGovernance
0
0
0
Lenny Zeltser @lennyzeltser@infosec.exchange · Jul 21, 2026
Security leaders are making AI security decisions with almost no data about what their peers are doing. Sounil Yu and I built a five-minute anonymous survey to change that, and we'll publish the findings so you can benchmark your approach. https://zeltser.com/ai-security-survey #artificialintelligence #riskmanagement
0
1
0
Lenny Zeltser @lennyzeltser@infosec.exchange · Jul 17, 2026
I've seen too many author-centric assessment reports, full of stories of conquest and irrelevant details. The best reports are reader-centered. My new template offers a consistent way to write them that way. It's AI-friendly, too. https://zeltser.com/security-assessment-report-template #assessments #riskmanagement
3
0
1
Clark Shishido @cshishido@infosec.exchange · Jul 14, 2026
This isn't a bad overview of AI risk from a re-insurer (the insurance co for insurance companies). Different AI use cases with real-world examples and case studies. Use this to educate non-technical/non-risk specialist staff. Also has a glossary. (apologies to whoever posted earlier I just got around to reading it.) #AIrisks #riskmanagement https://www.ajg.com/gallagherre/-/media/files/gallagher/gallagherre/news-and-insights/2026/march/rethinking-insurance-for-the-ai-era.pdf
0
0
0
Lenny Zeltser @lennyzeltser@infosec.exchange · Jul 14, 2026
My new template for security assessment reports offers a structured, repeatable approach to communicating with readers. It's based on my experience creating and reading many such reports over the years. It's AI-friendly, too. https://zeltser.com/security-assessment-report-template #assessments #riskmanagement
0
0
0
Claroty @Claroty@infosec.exchange · Jul 08, 2026
Not every exposure deserves the same response. See how Claroty xDome helps security teams prioritize the risks that matter most, so they can focus on reducing operational risk across industrial environments. ▶️ Watch the demo, then learn more: https://claroty.com/industrial-cybersecurity #IndustrialCybersecurity #RiskManagement #OTSecurity #CPSsecurity #CyberResilience
0
0
0
Cyber℻ @eyetSystems@infosec.exchange · Jul 07, 2026
You think cyber resilience is just about patching vulnerabilities? Think again. Ukraine seizing criminal crypto funds and immediately using them for war bonds demonstrates asset recovery has become an integrated macro-economic strategy, not merely a law enforcement cleanup. The real value is turning illicit proceeds into national capital. #CyberStrategy #RiskManagement #DigitalEconomy https://therecord.media/ukraine-uses-seized-crypto-cybercrime-for-war-bonds
0
0
0
Marius (windsheep) @windsheep@infosec.exchange · Jun 30, 2026

Do not invest in AI ETFs.

  1. AI isn't exclusive to them.

Any high school kid can get AI tools.

  1. The edge represents the most likely output of a language model fed with literature

An AI model predicts text from the corpus. It's not innovating. It's predicting. The most likely answer, for everyone.

  1. LLMs cannot do math

They are text crunchers. If that's enough for an ETF, it's slop.

  1. LLMs do not have any fundamental capability to assess 10-Qs, 10-Ks, Earnings call transcripts or SEC filings. It's always the best year of the quarter ;)

LLMs are not trained to reason against business phrasing / deceptive text. The buy the most optimistic speech pattern, not the fundamental edge.

  1. The AI is made by a 3rd party. You have no control.

Do not invest in AI ETFs. Do not invest in IPOs. Unless you have a plan and a setup, that resembles a professional hedge fund.

#ai #etf #riskmanagement #slop

0
0
0
Marius (windsheep) @windsheep@infosec.exchange · Jun 30, 2026
It's logical that SpaceX moves into MSCI world. It's also logical to balance the portfolio due to this. US tech isn't a safe harbour. #msciworld #spacex #riskmanagement
0
0
0
The Bad Place @TheBadPlace@mastodon.ozioso.online · May 15, 2026
yahoo news | Experian Partners With ServiceNow to Scale Trusted Decisioning to Agentic AI AI generated summary, Read the full article for complete information. Experian and ServiceNow have announced a global, multi‑year partnership that embeds Experian’s Ascend platform into ServiceNow’s AI workflow engine, giving autonomous AI agents direct access to trusted data and decision‑making capabilities. The integration is designed to overcome the data‑trust barrier that hinders AI scaling, enabling faster, more consistent AI‑driven actions for use cases such as employee onboarding, third‑party risk management, fraud and identity verification, and model risk governance across highly regulated industries. Read more: https://natlawreview.com/press-releases/experian-partners-servicenow-scale-trusted-decisioning-agentic-ai #Experian #ServiceNow #KeithLittle #agenticai #riskmanagement #CathyMauzaize
0
0
6
Brian Greenberg :verified: @brian_greenberg@infosec.exchange · Apr 27, 2026

An AI coding agent wiped out a company's entire production database and every backup in just 9 seconds. The AI agent later confessed, in its own words, that it guessed a destructive action would be scoped to the staging environment, didn't verify, didn't read the docs, and just did it anyway. 🤦🏻‍♂️ Everyone's blaming the AI. I'm looking at the humans who handed it the keys. This wasn't a rogue model. It was a predictable outcome of predictable choices:

  • A CLI token with blanket permissions across all environments
  • Backups stored on the same volume as the data they're meant to protect
  • A cloud provider whose API executes destructive commands with zero confirmation step
  • An agent given access to production while the team thought it was safely contained in staging

The founder is now manually reconstructing customer bookings from Stripe logs and calendar integrations. Every one of his customers is doing the same because of a 9-second API call. AI agents don't have judgment. They have instructions and permissions. Whatever permissions you grant, assume they will eventually be used in the worst possible sequence at the worst possible moment. That's not pessimism, it's how you architect resilient systems. Separate your environments. Scope your tokens. Store backups offline and off-volume. Require confirmation before any destructive operation. These aren't AI-era lessons. They're 30-year-old lessons that people keep skipping because the tooling makes it easy to skip them. The speed AI can act is new. The failure modes underneath it are not. https://www.tomshardware.com/tech-industry/artificial-intelligence/claude-powered-ai-coding-agent-deletes-entire-company-database-in-9-seconds-backups-zapped-after-cursor-tool-powered-by-anthropics-claude-goes-rogue #AI #Cybersecurity #RiskManagement

11
7
14
anchore @anchore@mstdn.business · Mar 30, 2026
The days of second-guessing your scanner are over. 🎯 @grype now natively supports @bitnami PhotonOS! @jonoberg details how this empowers teams to build confidently with meaningfully reduced risk. Read more: https://anchore.com/blog/anchore-bitnami-secure-images/ #riskmanagement #opensource
1
0
0

You've seen all posts