Výsledky hledání

téma: AI× v celém archivu zrušit filtry

240 karet z 240 položek · strana 1 z 4 CZ · EN/orig

1

Microsoft Azure, Cloud and AI Services — Multiple Vulnerabilities

Classification: Severe, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 10.0, CVEs: CVE-2026-62874, CVE-2026-68791, CVE-2026-69399, CVE-2026-70009, CVE-2026-69843, CVE-2026-69865, CVE-2026-70200, CVE-2026-83944, CVE-2026-77903, CVE-2026-78501, CVE-2026-83946, CVE-2026-85878, CVE-2026-85885, CVE-2026-85887, CVE-2026-85889, CVE-2026-85917, CVE-2026-87701, CVE-2026-55946, Summary: Microsoft has addressed multiple vulnerabilities affecting Azure, Microsoft Fabric, Azure AI Foundry,…

CVSS 10.0 Microsoft FI

tg: zranitelnost tp: AI

· NCSC-FI · Microsoft Azure, Cloud and AI Services — Multiple Vulnerabilities

7

New Android malware uses AI to steal bank logins and PINs

Researchers at Zimperium’s zLabs have analyzed an Android Trojan that uses an automated, multi-stage infection process. What’s new is that RatHat gives a live AI assistant the keys to the accessibility tree of the infected device and uses it to determine where to tap or scroll, rather than following a hardcoded script. The variable attack path makes it harder for signature- and rule-based mobile security tools to detect this Trojan. It also abuses Android Debug Bridge (ADB), a legitimate tool…

Google finance US

tg: rozbor tg: propagace tp: malware tp: podvod tp: AI tp: identita

· Malwarebytes Labs · New Android malware uses AI to steal bank logins and PINs

Did an AI really try to break free from human control?

Amid discussions about slowing down AI development, the Telegraph ran the headline: “OpenAI sounds alarm after bot tries to break free from human control.” That headline is slightly misleading, in my opinion. The Telegraph headline overstates what happened, although the underlying behavior is still genuinely concerning. The article reports that OpenAI has disclosed rare but troubling cases in which an unreleased model generated its own instructions that appeared to reject developer control.…

OpenAI US

tg: názor tg: propagace tp: AI

· Malwarebytes Labs · Did an AI really try to break free from human control?

A Vault with a Heap-View: The Uncomfortable Space Between AgentCore Harness and Identity

Analysis of how default configurations in AWS AgentCore Harness allow prompt injection to exfiltrate credentials, and key steps to secure your agents. The post A Vault with a Heap-View: The Uncomfortable Space Between AgentCore Harness and Identity appeared first on Unit 42.

US

tg: rozbor tg: návod tp: AI tp: identita

· Palo Alto Unit 42 · A Vault with a Heap-View: The Uncomfortable Space Between AgentCore Harness and Identity

The End of Point-in-Time Compliance: Why Continuous Audit Readiness Matters to You in the AI Era 

Key Takeaways Periodic audits provide a point-in-time assessment, but they cannot demonstrate whether controls remain effective between audit cycles. Qualys platform data shows 10.5 billion configuration findings across customer environments but only 1.6% represent meaningful exposure and under 1% are prioritized, business-critical findings. Verizon’s 2026 DBIR found the median time to resolve weak passwords and misconfigured permissions is about 8 months. Across 1 billion misconfiguration…

US

tg: rozbor tg: návod tg: propagace tp: ransomware tp: AI tp: identita

· Qualys · The End of Point-in-Time Compliance: Why Continuous Audit Readiness Matters to You in the AI Era 

18

Should you care about an “AI slowdown?”

Welcome to this week’s edition of the Threat Source newsletter. There’s been a lot of talk recently about slowing down the pace of AI development. And yes, there are legitimate moral, ethical, geopolitical, and safety concerns with the use of AI. It’s not clear yet whether an AI slowdown could happen, let alone whether it should (hat tip to Dr. Ian Malcolm). I admit, I’m not really qualified to opine on the impacts unrestricted AI might have on bioterrorism, the balance of international power,…

US

tg: názor tg: přehled tp: ransomware tp: AI

· Cisco Talos · Should you care about an “AI slowdown?”

From guidance to action: Security fundamentals that materially reduce risk 

AI has already made fundamental changes to the operating environment for cybersecurity. Cyberattackers are testing more paths, adapting their techniques, and moving across digital environments with greater speed and persistence. The weaknesses they exploit remain familiar: excessive permissions, unprotected authentication flows, unpatched systems, exposed execution paths, and gaps between controls. What has changed is how quickly these weaknesses can combine into attack paths that cross…

Microsoft US

tg: rozbor tg: návod tg: propagace tp: malware tp: phishing tp: AI tp: identita

· Microsoft Security Blog · From guidance to action: Security fundamentals that materially reduce risk 

Improving email security outcomes with real-world Microsoft Defender insights

Every benchmark tells a story. The most valuable ones tell us where to improve next. For five consecutive quarters Microsoft has published email security benchmarking reports to provide greater transparency into real-world protection outcomes. The results have shown strong Microsoft Defender performance across pre-delivery and post-delivery scenarios, while revealing where threats and defenses continue to evolve. This quarter’s benchmark examines how continuous measurement informs protection…

Microsoft US

tg: rozbor tg: propagace tp: AI

· Microsoft Security Blog · Improving email security outcomes with real-world Microsoft Defender insights

SPOJENO PŘES CVE LiteLLM: rilevato sfruttamento in rete della CVE-2026-59822

Rilevato lo sfruttamento in rete di una vulnerabilità, identificata tramite la CVE-2026-59822, in LiteLLM di BerriAI, server proxy impiegato come gateway per l'accesso a modelli linguistici di grandi dimensioni (LLM). La vulnerabilità consente a un attaccante remoto non autenticato di eludere i meccanismi di autenticazione e accedere agli strumenti MCP senza disporre di credenziali valide.

KEV ✓ EPSS 0.01 CVE-2026-59822 BerriAI IT US

tg: zneužíváno tg: zranitelnost tp: AI tp: identita

· CSIRT Itálie (ACN) · LiteLLM: rilevato sfruttamento in rete della CVE-2026-59822 · CISA KEV · BerriAI LiteLLM Improper Authentication Vulnerability (CVE-2026-59822)

AI Threat Landscape Digest: July–August 2026

The defining development of the period came not from attackers but from the AI labs themselves, whose models broke out of controlled evaluations and reached real systems. In the wild, the criminal and state use of AI continued to mature along the lines tracked in earlier editions: models now act as attack operators, an underground market supplies the access, and AI systems have themselves become a target. The substantial distance between what the strongest models demonstrated under evaluation…

OpenAI Hugging Face Anthropic Meta IL

tg: rozbor tg: přehled tp: ransomware tp: AI

· Check Point Research · AI Threat Landscape Digest: July–August 2026

12 celebrity deepfake websites seized by Manhattan DA

The Manhattan District Attorney’s Office has seized the domains of 12 deepfake websites in what it called the largest known seizure of celebrity deepfake sites in history. The sites, which marketed themselves as deepfake pornography platforms, hosted AI-generated videos of over 1,200 people, including those in the public eye, ranging from politicians to actors, musicians, and social justice advocates. At least one allowed users to create their own deepfakes by grafting real faces and bodies…

média veřejná správa US

tg: vymáhání práva tp: AI tp: soukromí

· Malwarebytes Labs · 12 celebrity deepfake websites seized by Manhattan DA

Ransomware incidents in Japan in the first half of 2026: Investigation of The Gentlemen’s infrastructure and evidence of Qilin's AI use

Compared with the same period last year, ransomware incidents in Japan increased slightly by approximately 4.7%, indicating that ransomware continues to pose a significant threat.In Japan, The Gentlemen was the most active ransomware group in the first half of 2026.Attackers continue to primarily target small- and medium-sized enterprises, with organizations capitalized at less than JPY 1 billion accounting for approximately 80% of the total — an increase of around 13% from the previous year…

EPSS 0.00 CVE-2025-2479 výroba a průmysl US

tg: rozbor tp: ransomware tp: AI

· Cisco Talos · Ransomware incidents in Japan in the first half of 2026: Investigation of The Gentlemen’s infrastructure and evidence of Qilin's AI use

MLflow dspy and statsmodels flavors bypass pickle deserialization control

Classification: Severe, Solution: Temporary Fix, Exploit Maturity: Not Defined, CVSSv3.1: None, CVEs: , Summary: A vulnerability in MLflow’s dspy and statsmodels model flavors allows unauthorized pickle deserialization executions despite a safety control. Specifically, the dspy flavor conditionally applies the control based on the model path’s file extension, and the statsmodels flavor does not apply the control. Exploitation of this vulnerability allows for arbitrary remote code execution…

MLflow FI

tg: zranitelnost tp: AI

· NCSC-FI · MLflow dspy and statsmodels flavors bypass pickle deserialization control

Sentry Seer vulnerability allows attacker-controlled input to be executed in a privileged environment

Classification: Severe, Solution: Workaround, Exploit Maturity: Not Defined, CVSSv3.1: None, CVEs: CVE-2026-90999, Summary: A vulnerability exists in Sentry Seer when the system is configured to automatically hand issues to a coding agent for remediation. Successful exploitation results in arbitrary code execution within the coding‑agent environment and access to connected source repositories. This vulnerability is tracked as CVE-2026-90999. Successful exploitation may allow arbitrary code…

EPSS 0.00 CVE-2026-90999 Sentry FI

tg: zranitelnost tp: AI

· NCSC-FI · Sentry Seer vulnerability allows attacker-controlled input to be executed in a privileged environment

9

Securing the unpatchable in an age of AI-driven vulnerabilities

AI is accelerating vulnerability discovery, leaving unpatchable operational technology (OT) systems at risk. Hoping for the best is not a viable anti-exploitation strategy. Deploying next-generation firewalls directly upstream allows for virtual patching through deep packet inspection. These systems scan incoming traffic to detect and block exploit attempts before they can impact the vulnerable device.The predictability of legitimate network connections to OT systems can be used to protect…

US

tg: rozbor tg: návod tp: AI tp: průmyslové systémy

· Cisco Talos · Securing the unpatchable in an age of AI-driven vulnerabilities

Agents at Large | Tracing Illicit OpenAI Agent Activity on Hugging Face

Executive Summary OpenAI disclosed that agents used exposed Hugging Face credentials to write a file and deploy proxy Spaces during an unrelated May 2026 research workload, but it did not identify the accounts. SentinelLABS identified two accounts likely used in associated activity, 0Time and Nyx9. Their public histories extend OpenAI’s chronology and preserve previously unreported relay code, document-borne probes, and ChatGPT account-provisioning capability. The public records provide precise…

OpenAI Hugging Face US

tg: incident tg: rozbor tp: AI tp: identita

· SentinelLabs · Agents at Large | Tracing Illicit OpenAI Agent Activity on Hugging Face

AI helps scammers build convincing antivirus renewal pages

Antivirus renewal scams often begin with a message claiming that your subscription has automatically renewed. When you follow the instructions to cancel it, you are taken to a fake page designed to collect your contact details. The renewal charge never existed. Receiving a message that names the antivirus software you use does not necessarily mean the sender has access to your device or account. Scammers impersonate popular brands and send the same message to large numbers of people, knowing…

Avast US

tg: rozbor tg: propagace tp: phishing tp: podvod tp: AI

· Malwarebytes Labs · AI helps scammers build convincing antivirus renewal pages

ZDI-26-706: (0Day) CrewAI crewAI Framework Agent Loading Unsafe Reflection Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of CrewAI crewAI. User interaction is required to exploit this vulnerability in that the target must load a malicious agent configuration from the repository. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-92206.

CVSS 8.8 CVE-2026-92206 CrewAI US

tg: zranitelnost tp: AI

· Zero Day Initiative · ZDI-26-706: (0Day) CrewAI crewAI Framework Agent Loading Unsafe Reflection Remote Code Execution Vulnerability

9

Before You Patch. Why Patch Reliability Matters for Confident Deployment

Executive Summary Microsoft’s September 2026 security updates, KB5124008 and KB5124012, have been linked to USB audio failures on some Windows systems, highlighting the operational risk that can accompany security patching. Qualys TruRisk Eliminate classified both updates as Low Reliability, signaling the need for additional validation before production deployment. Patch Reliability helps IT and security teams focus on deeper testing where needed while allowing high-confidence patches to move…

Microsoft US

tg: zranitelnost tg: návod tg: propagace tp: AI

· Qualys · Before You Patch. Why Patch Reliability Matters for Confident Deployment

How to opt out of AI chatbot training

The tech journalists at 404 Media learned that OpenAI is hiring hundreds of contractors to read and review a massive stream of real users’ ChatGPT prompts and responses. “Project Lily” is reportedly a program that asks contractors to score or critique ChatGPT’s answers to improve the chatbot’s quality and behavior. The fact that prompts may sometimes be reviewed by humans should not come as a complete surprise. AI companies also monitor conversations for safety reasons. Anthropic, for example,…

OpenAI Anthropic Perplexity Malwarebytes US

tg: návod tg: propagace tp: AI tp: soukromí

· Malwarebytes Labs · How to opt out of AI chatbot training

What Zero-Day Response Should Be in the Post-Mythos Era

AI is shrinking the time between vulnerability disclosure and exploitation, leaving defenders less time to wait for patches or public exploits. Picus Security explains how exploitability validation, security control testing, and autonomous pentesting can help teams close exposure gaps before attackers arrive. [...]

EPSS 0.00 CVE-2026-1001 US

tg: návod tg: propagace tp: AI

· BleepingComputer · What Zero-Day Response Should Be in the Post-Mythos Era

Australia is replacing the Essential Eight with a new cyber framework. Here’s how exposure management can help you get ahead of it.

Australia’s move from the Essential Eight to an outcomes-based cybersecurity model will push organizations from conducting periodic point-in-time, checklist compliance assessments to having continuous evidence of a solid security posture.Key takeawaysThe Australian Signals Directorate (ASD) is moving from the Essential Eight cybersecurity framework to a new outcomes-focused Essentials series covering enterprise IT, cloud, operational technology (OT), and potentially agentic AI.The Essential…

veřejná správa US

tg: regulace tg: návod tp: AI tp: identita tp: průmyslové systémy

· Tenable Research · Australia is replacing the Essential Eight with a new cyber framework. Here’s how exposure management can help you get ahead of it.

Meta AI builds detailed profiles of children from years of family posts

If you’re still OK with posting pictures of your kids on social media, take a minute to hear from mother of two Kalie Robins. At the start of September, she did something that hundreds of thousands of parents do every day. She posted a video of her young daughter on Facebook. Under the video of Robins and her daughter singing in a car, Facebook’s Meta AI system displayed a suggested question: “Who is the child passenger?” Robins was shocked that Facebook would ask this question about a minor,…

Meta Facebook Instagram US

tg: rozbor tg: návod tp: AI tp: soukromí

· Malwarebytes Labs · Meta AI builds detailed profiles of children from years of family posts

ai research messageboards

<p>This article was first published <a href="https://www.linkedin.com/pulse/messageboards-all-you-need-nash-borges-iav6c" target="_blank">on LinkedIn.</a></p>Categories: AI Research, Threat ResearchTags: AI, AI Cybersecurity, Threat Research

GB

tg: názor tp: AI

· Sophos Threat Research · ai research messageboards

2

14th September – Threat Intelligence Report

For the latest discoveries in cyber research for the week of 14th Setpember, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES IDScan.net, a US identity verification provider, has disclosed a data breach after detecting unauthorized access on September 1. Exposed data included names and government identification numbers, while a criminal marketplace advertised a collection containing millions of identity documents, including driver’s licenses, associated with the…

KEV ✓ EPSS 0.94 CVSS 10.0 CVE-2026-67276 CVE-2026-72898 CVE-2026-81963 CVE-2026-85046 CVE-2026-85706 CVE-2026-85880 CVE-2026-86060 Microsoft GitLab MikroTik Anthropic IL

tg: incident tg: zranitelnost tg: přehled tp: malware tp: únik dat tp: AI

· Check Point Research · 14th September – Threat Intelligence Report

6

The Self-Expanding Stolen Inference Supply Chain: An AI Agent Harvesting and Re-Serving LLM Access, (Fri, Sep 11th)

I identified an attacker using a semi-autonomous coding agent to run an offensive operation: finding poorly secured LLM resale gateways, acquiring API access through ordinary web flaws and account farming, validating the resulting inference capacity, and aggregating it behind a single gateway of their own. What I captured was not simply credential theft, but an inference supply chain — an agent harvesting, validating, and consolidating LLM access into infrastructure that serves it again through…

US

tg: varování tg: rozbor tp: AI tp: identita

· SANS Internet Storm Ctr. · The Self-Expanding Stolen Inference Supply Chain: An AI Agent Harvesting and Re-Serving LLM Access, (Fri, Sep 11th)

How Threat Actors Are Turning Trusted AI Platforms Into an Attack Surface

Threat actors are abusing trusted AI platforms to host malicious content, poison search results, and trick users into installing malware. Huntress examines campaigns targeting AI users through weaponized Claude Artifacts, shared AI conversations, sponsored search results, and ClickFix-style lures. [...]

US

tg: varování tg: rozbor tp: malware tp: phishing tp: AI

· BleepingComputer · How Threat Actors Are Turning Trusted AI Platforms Into an Attack Surface

Linux Detection Engineering - Local Privilege Escalation

Local privilege escalation (LPE) is the step that turns a foothold into full control of a host. An attacker who lands as an unprivileged user rarely stops there. They want root, and Linux keeps offering new ways to get it.In this edition of our "Linux Detection Engineering" series, we’ll cover:The default flow that a Linux LPE produces on the host and the general rules that detect it.The recurring LPE patterns behind the most recent LPEs and how each works, along with how each looks through the…

Linux Elastic US

tg: rozbor tg: návod tp: AI

· Elastic Security · Linux Detection Engineering - Local Privilege Escalation

8

Protecting organizations from AI-assisted executive impersonation and invoice fraud

In this article Attack chain overviewEmail DeliveryDomain registrationGenerative AI usageMitigation and protection guidanceMicrosoft Defender detectionsMicrosoft Security CopilotThreat intelligence reportsMITRE ATT&CK Techniques observedIndicators of compromise (IOC)Learn More Threat actors are increasingly improving their tactics to make suspicious emails look like legitimate email notifications to potential victims, deploying techniques that impersonate internally sent emails from executive…

ServiceNow US

tg: varování tg: rozbor tp: phishing tp: podvod tp: AI

· Microsoft Security Blog · Protecting organizations from AI-assisted executive impersonation and invoice fraud

AI-powered attack exploited PaperCut flaws to hack 395 organizations

A threat actor, likely Russian-speaking, used hundreds of AI agents to develop and launch a global exploitation campaign targeting vulnerable PaperCut NG/MF servers. [...]

KEV ✓ · ransomware EPSS 0.77 CVE-2021-42278 CVE-2021-42287 CVE-2026-81578 CVE-2026-82078 PaperCut US

tg: incident tg: varování tg: zneužíváno tp: AI

· BleepingComputer · AI-powered attack exploited PaperCut flaws to hack 395 organizations

PuzzleMask: Abusing Plain Prose as a Covert AI Attack Vector

Executive Summary In this research we introduce a prompt-crafting technique for bypassing quick LLM-based policy checks — using plain English (no emojis, base64, invisible formatting, etc.) A policy-violating payload (e.g. ”encrypt files in ~/Documents”, “give me a biohazard recipe”, “ignore all previous instructions and…”) is embedded in a specially crafted prose wrapper. An LLM with limited resources and attention fails to realize the payload is there, classifies the prompt as benign and…

IL

tg: rozbor tp: AI

· Check Point Research · PuzzleMask: Abusing Plain Prose as a Covert AI Attack Vector

The agentic harness for Tenable Hexa AI: How Tenable prevents AI agents from going off the rails

Learn why Tenable treats agentic LLMs as untrusted insiders, and how we’ve made sure you can control and monitor the AI agents making changes in your production security environmentKey takeawaysAI models can quickly understand data, but not your business. While modern AI models are great at reasoning, they don’t automatically understand your unique environment or who is allowed to do what. The “harness” is the custom-built layer that translates AI intelligence into safe, controlled actions…

Tenable US

tg: rozbor tg: propagace tp: AI

· Tenable Research · The agentic harness for Tenable Hexa AI: How Tenable prevents AI agents from going off the rails

Will AI kill us all within the next decade?

The Wall Street Journal reports that concerns are rising inside AI labs that competition is pushing tech companies to race toward self-improving models that could spiral out of human control. Jacob Coxon, an AI researcher who has worked at Anthropic and OpenAI, said: “The people building AI earnestly believe that it could kill us all by the end of the decade.” Evan Hubinger, Anthropic’s Alignment Science lead, who also worked at OpenAI, responded in a post on X: “We really do earnestly believe…

US

tg: názor tg: propagace tp: AI

· Malwarebytes Labs · Will AI kill us all within the next decade?

ZDI-26-648: (Pwn2Own) OpenAI Codex External Control of System or Configuration Setting Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of OpenAI Codex. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-19590.

EPSS 0.00 CVSS 7.8 CVE-2026-19590 OpenAI US

tg: zranitelnost tp: AI

· Zero Day Initiative · ZDI-26-648: (Pwn2Own) OpenAI Codex External Control of System or Configuration Setting Remote Code Execution Vulnerability