AI Security
Shadow AI, agentic SOC, and governing AI inside the security function. What we see and what we do.
CrowdStrike's new PhantomRaven report connects likely AI-written malware, npm packages and bug bounty activity. Here is what the findings establish.
Falcon Data Security aims to recognise confidential information in ordinary text. Here is how classification on the PC works.
Agentic IdP gives AI agents verifiable identities and connects their access to the person or system behind them. Here is how it relates to Guardian and Continuous Identity.
SafeMind combines offensive and defensive AI models with software that runs security tasks. Here is how Red Tempest, Blue Solano and the testing loop fit together.
All 14 capabilities in CrowdStrike's AIDR-to-Guardian comparison explained, from shadow AI discovery to agent controls, investigations and cost analytics.
Visual prompt-injection research exposes a practical boundary: an agent reading customer images should not be able to change its own operating instructions.
CrowdStrike's Fal.Con 2026 announcements connect AI activity, agent identities and AI-powered defence. Here is what Guardian, SafeMind and Agentic IdP each add.
CrowdStrike is extending AI security into agent activity. Here is what Guardian adds and what we would check before a rollout.
RubyGems removed more than 500 malicious packages in May. New research attributes the campaign to AI agents and highlights risks in automated documentation builds.
The September report describes AI-assisted intrusions with varying human involvement. The response should focus on access and observable behaviour.
An agent-assisted campaign moved from planning to credential theft in hours. Check how quickly your cloud response can contain unauthorised activity.
Check Point demonstrated a cross-account channel combined with prompt injection. The channel was closed, but connector permissions still deserve review.
Researchers reconstructed about 18,000 agent posts on DSEwiki. The findings raise practical questions about writable websites and agent network controls.
ESET describes malware comments intended to derail AI-assisted analysis. Your pipeline needs an explicit path for incomplete or refused results.
Researchers describe an Aurora operator using Cursor during attacks. Focus on the actions and access, rather than treating the tool's name as a verdict.
The industry calls for faster cyber defense. For business leaders, the next step is to turn that commitment into funded, accountable work.
OpenAI's investigation describes unauthorised agent communication and uneven safeguards. Shared storage and test environments need explicit security boundaries.
Aikido's lab recreation shows an agent bypassing a booking restriction. The result is a reminder to enforce permissions on the server.
Only 12 of 405 samples appeared in Unit 42's endpoint dataset. That is useful evidence, but not a measure of every AI-assisted attack.
An NSA-led advisory describes reconnaissance against Siemens PLCs. Review exposure and remote access with the people responsible for the process.
Adversa demonstrated a Grok attack using encrypted webpage content. Transforming external data must not turn it into trusted instructions.
OpenAI reported a training pause and stricter controls after signs of critical cyber capability. The announcement also makes the cost of agent oversight visible.
A preprint shows instructions propagating between agents. Its warning-prompt result is promising, but should not replace access controls.
OpenAI's cyber model responds to more advanced security requests. Its 95 percent completion figure measures refusals, not a universal exploit success rate.
Dream's research describes a four-day intrusion using AI agents. The findings show why weak authentication and exposed APIs still matter.
Researchers recovered sensitive data from published reasoning blocks. Treat agent traces as potentially confidential before sharing them.
JFrog describes malicious hooks and editor tasks in the August campaign. Review executable project settings as well as package dependencies.
Tenet's research shows how attacker-controlled log content can steer an agent. Reading an event should not give that event authority to change systems.
AI agents breached Hugging Face during a security evaluation. What does it mean for a model to find weaknesses and act on its own?
Three incidents reached real systems from an evaluation setup with unintended internet access. A prompt describing a sandbox cannot enforce its boundaries.
Agents left the intended boundaries of an OpenAI evaluation and compromised Hugging Face. The incident puts shared infrastructure and agent permissions in focus.
Fredrik Standahl's Digi.no op-ed argues for approved AI tools and clear rules for handling business information.
In E24, Fredrik Standahl discusses the gap between employees' AI use and the controls their employers have put in place.
Start with the AI tools people use, agree what data they may handle, and test the controls. A practical approach using CrowdStrike.
Unapproved AI use can expose business data and give agents excessive access. Start by understanding the work people are trying to do.
Fredrik Standahl's Shifter commentary asks startup teams to make security checks part of releasing AI-generated code.