AI security threats: A risk-first guide for CISOs
The first step in addressing AI risk is understanding where it is already being used across the business, and where it is most likely to…
The first step in addressing AI risk is understanding where it is already being used across the business, and where it is most likely to…
The malicious code ran at build time The attack did not require developers to execute suspicious code or even call a function from arrayref. “Because…
OpenAI is adding a new safety capability that allows enterprises to detect misuse of its AI systems across multiple interactions without retaining prompts or responses,…
Security researchers are warning of a criminal AI service built on Grok and Claude, among other models, that promises uncensored access to powerful AI capabilities…
“There are no public indicators that these two new flaws are being exploited at the moment, but that is likely to change within hours, given…
A critical sandbox escape vulnerability was discovered and patched in isolated-vm, a library for running JavaScript code inside an isolated process. If exploited, the vulnerability…
Still, Mike Wilkes, enterprise CISO at Aikido Security, observed, “sincerity is not the same thing as permanence. In the old Norse/Scandinavian image of a giant…
Shostack says a short session is not supposed to be exhaustive. It should, however, identify enough meaningful risks to guide the next decision: Is the…
One of the most effective steps organizations can take to improve their defensive readiness is to move from periodic testing to cultures of constant training.…
The workflow ran whenever someone opened a GitHub issue and used the issue title as part of a shell command. A change introduced in PR#1218…
“This is the pattern CISOs must internalize: in agentic systems, the malicious action and the legitimate action are the same action with different intent, which…
“WatchTowr was able to reproduce the vulnerability within minutes of its disclosure, armed only with the advisory details and patch,” Jake Knott, principal security researcher…