AI Security — Page 12

AutoJack: When the AI Browser Becomes the Initial Access Broker
Microsoft researchers describe an exploit chain that turns an agentic browser into a one-click path from web page to host process execution.

The SOC Triangle Was Always a Lie We Accepted. AI Is Changing the Math.
Security operations have run on a structural compromise for decades — quality, consistency, or cost: pick two. That constraint is finally starting to bend.

AutoJack Exploit in Web-Enabled AI Agents: Bypassing Localhost Security
Microsoft uncovers RCE vulnerability in AutoGen Studio through local AI agent misuse.

Tool Sprawl Meets Agentic AI: Why SOCs Are Rethinking the Triage Stack
Forty tools, forty-three day dwell times. Vendors are pitching agentic AI as the fix. Analysts have questions.

Security Protocols for SMBs Adopting Claude
Understanding and managing security risks with Claude’s AI solutions for small and medium-sized businesses.

SearchLeak Shows How a Single Crafted URL Can Drain Your M365 Tenant
Varonis researchers chained three weaknesses in Copilot Enterprise Search into a full data-exfiltration path. Microsoft patched it. The attack class isn't going anywhere.

The Agents Nobody Owns: AI Identities Are Quietly Becoming Your Worst Insider Risk
Orphaned AI agents and standing privileges are accumulating across enterprise environments. Most security teams can't tell you who authorized them — or revoke them quickly when they go wrong.

AI Breaks the Assumption Cybersecurity Was Built On
Modern security programs were engineered around deterministic systems. Agentic AI isn't one.

The AI-SOC Is Maturing Fast. Here Are the Human Roles It Actually Creates.
Autonomous triage agents are already displacing Tier 1 analyst work. But the agentic SOC depends on a new class of human specialists — and those roles are filling now.

Bucket Squatting in Vertex AI SDK Opened Cross-Tenant RCE Window
A staging-bucket naming flaw in two versions of Google's Vertex AI Python SDK let attackers pre-register a victim's expected bucket and swap in a malicious pickle model before the platform could retrieve the original.

Fifteen Rogue JetBrains Plugins Posed as DeepSeek Assistants to Siphon AI Keys
A coordinated campaign on the JetBrains Marketplace dressed up credential stealers as LLM-powered coding helpers. The payload? Your provider keys.

Old Risk Frameworks Can't Handle AI. Here Are the New Ones That Try.
From ISO 42001 to NIST's AI RMF and ENISA's layered playbook, a clutch of frameworks is competing to define how organizations govern AI risk — each targeting a different gap.

Someone Wallpapered the @mastra npm Namespace With Malicious Builds
A hijacked maintainer account pushed 144 booby-trapped packages across the Mastra AI framework before anyone noticed. The attacker called it 'easy-day-js.' It was.

AI in Cybersecurity: What Security Leaders Actually Need to Know
Dozens of experts weigh in on how artificial intelligence is reshaping both offense and defense — and why the gap between the two may be widening faster than policy can close it.

Ent Raises $100 Million Seed Round to Build Intent-Aware Endpoint Security
The stealth-mode startup says its platform reads behavioral intent before risky actions execute — a bet that pre-action inference can replace post-breach detection.