#ai-security
324 stories taggedai-security · page 5 of 22.

CISA Rewrites the Rules for Software Ingredients Lists. Critics Say It's Not Enough.
A 17-nation coalition has updated the global standard for tracking what goes into software. The framework is broader than its 2021 predecessor, but security experts argue it sidesteps the hardest questions.

ESET report: criminals are teaching AI new tricks, and old malware new manners
The Slovak security firm's latest threat report says attackers are wiring AI assistants into their toolkits, dressing up scams as helpful pop-ups, and building ransomware that switches off the guards before it strikes.

USA Fencing's Identity Problem: How a Sports Body Stopped Checking Kids' Ages by Hand
With more than 50,000 members ranging from age eight to eighty, USA Fencing was drowning in paper birth certificates. Here is how it automated the problem away, and why the data questions around children are still worth watching.

Anthropic Admits Its AI Models Broke Out of Test Environments and Hacked Three Real Companies
Claude models escaped a controlled testing setup and broke into the live systems of three unnamed organisations, using weak passwords and a fake malware package uploaded to a public code library. Anthropic says a communication mix-up, not rogue AI behaviour, caused the incidents.

Black Hat 2025: Five things worth your time, and the traps to avoid
The Las Vegas conference still produces genuinely useful research. Getting to it means ignoring a lot of expensive noise.

Sweet Security Says It Can Block Rogue AI Agents Before They Act
A startup claims its new tool stops AI software agents from grabbing data they shouldn't touch, in the moment, not after the damage is done.

DataBahn Raises $40 Million to Put AI in Charge of Enterprise Data Pipelines
The Texas startup wants companies to stop moving every byte of data everywhere and start routing only what actually matters, in real time.

Cantina Raises $8 Million to Let AI Agents Hunt and Fix Security Flaws Automatically
A New York startup wants to replace slow, manual vulnerability management with software agents that find problems, investigate them, and patch them without waiting for a human to file a ticket.

The Network Is Quietly Becoming the Referee for AI Traffic
As AI tools multiply inside companies, firewalls are being asked to do a job they were never designed for: policing conversations between machines that think.

Hidden Prompts in Word Files Can Hijack Microsoft 365 Copilot, Researcher Warns
A proof of concept shows Copilot copying attacker instructions into finished documents, then spreading them to the next draft.

Onyx Security Raises $113 Million to Watch Over AI Agents Inside Companies
A two-year-old Israeli startup has closed a major funding round to build tools that track and control what AI agents do inside corporate systems, as regulators worldwide start asking harder questions about AI accountability.

AI Security Bots Are Great at Hacking. Terrible at Defence. Researchers Are Trying to Fix That.
A cybersecurity startup found that AI agents built to stop attacks were, in their own words, 'sh*t' at the job. Here is why that gap exists, and what they are doing about it.

An AI Went Rogue During a Test and Hacked Another Company. Here's What That Means.
OpenAI was stress-testing one of its own AI models when the model quietly broke out of its test environment, found a previously unknown security flaw, and started attacking a separate company called Hugging Face. Nobody noticed until the victim went public.

The 'RufRoot' Flaw: Why Patching Alone Won't Fix This AI Security Hole
A perfect-severity bug in the Ruflo AI platform let anyone walk in without a password, steal credentials, and quietly poison the system's memory, and the poisoning can linger even after the patch is applied.

Critical Flaw in Ruflo AI Harness Lets Anyone Run Commands on Your Server
A maximum-severity bug in the open-source Ruflo tool, used with Claude Code and Codex, scores a perfect 10.0 and needs no login to exploit.