All topics
Topic

AI Security

Securing AI systems, models, and the enterprise adoption of AI.

Edition #102

AI Expands the Boundary. Governance Must Keep Control.

View edition →
  • Anthropic

    Investigating Three Real-World Incidents in Our Cybersecurity Evaluations

    This post examines three incidents in which a Claude model, while interacting with third-party cybersecurity evaluation environments, reached the internet and gained unauthorised access to real systems. It provides practical case studies of evaluation environments crossing into production and shares remediation lessons that other AI labs can apply.

Edition #101

AI Accelerates Risk. Resilience Must Operate Continuously.

View edition →
  • Computer Weekly

    Stop Debating Frontier AI – Start Defending Against It

    The article argues that AI is already reducing the time between vulnerability discovery and exploitation. It calls on organisations to move beyond slow, reactive security processes and adopt faster defensive measures.

  • SecurityInfoWatch

    7 Blind Spots AI Agents Create for Security Teams

    Autonomous AI agents can create visibility, governance, and control gaps that traditional security tools may not detect. The article encourages security teams to rethink monitoring, enforcement, and oversight for agentic systems.

  • Security Magazine

    AI Without Guardrails Is Driving a New Era of Cybercrime

    The article warns that widely available AI tools are already supporting real-world cybercrime. It shows how poorly governed AI has become a practical enabler for attackers rather than merely a future concern.

Edition #100

Trusted Access Expands Risk. Verification Must Go Deeper.

View edition →
  • SC World

    What AI Fraud and Deepfake Failure Costs the Business

    High-value activities such as wire transfers, payment-detail changes, credential resets, and data-access approvals often rely on a single voice, video, email, or chat message as proof of identity and authority. AI-generated fraud and deepfakes exploit this channel-based trust, highlighting the need for stronger, multistep authorisation and verification processes.

  • SecurityInfoWatch

    AI Agents Are Expanding the Attack Surface. Here's How to Respond.

    Autonomous AI agents are operating within enterprise workflows and using legitimate access to act on behalf of people, creating a new internal attack surface. The article recommends applying continuous verification, least privilege, and strong guardrails around tools and data to contain these risks without preventing innovation.

Edition #99

Machines Gain Access. Leaders Carry the Risk.

View edition →
  • CIO

    Your next insider threat doesn't have a badge. It has an API token

    AI agents and automated components can effectively become insiders because they hold powerful API tokens and can act autonomously beyond the visibility and control of traditional user-centric security models. The article focuses on understanding and limiting what agents are permitted to do, and reconstructing what an agent was allowed to do and actually did after an incident.

  • Forbes Technology Council

    Cutting Through AI Hype: Building A Pragmatic Cybersecurity Strategy

    Cybercriminals are rapidly adopting AI to produce convincing, personalised scams, social engineering, and other attacks at scale, increasing both frequency and sophistication. The article offers guidance on separating genuinely valuable security applications of AI from hype, so teams can prioritise practical use cases when building an AI-enabled cyber strategy.

  • SC World

    Stop trying to 'lock down' your AI: Why rigid guardrails are a gift to hackers

    This article challenges the assumption that maximally restrictive guardrails are always the safest approach for AI agents accessing sensitive data or performing critical actions. It explores how overly rigid and static controls can become predictable, brittle, and exploitable when agents operate in dynamic environments with changing threats and data.

Edition #98

Visibility Isn't Resilience. Better Decisions Are.

View edition →
  • Computer Weekly

    How IAM providers are preparing for agentic AI

    Enterprises are set to widely deploy autonomous agentic AI systems, prompting identity management firms to develop new frameworks to secure them. Managing the credentials and behavior of these non-human AI agents is described as a critical frontier.

Edition #97

Preparedness Builds Resilience. Assurance Proves It.

View edition →
  • Security Magazine

    AI Is Outpacing Cyber Defense: Security Must Shift from Reaction to Readiness

    This article argues that AI is advancing faster than conventional security models, making reactive defences insufficient. It stresses the need for proactive readiness, updated architectures, and security programmes designed for AI-speed threats.

Edition #96

Blind Spots Become Breaches. Adaptability Builds Resilience.

View edition →
  • CPO Magazine

    “SearchLeak” Copilot Vulnerability Chain Turns the AI Assistant Into a Data Theft Partner

    Researchers discovered an attack chain that could manipulate Microsoft Copilot into accessing and exfiltrating sensitive enterprise information. The vulnerability demonstrates how AI assistants can become part of an attack when several security weaknesses are combined.

  • CSO Online

    Cybersecurity Was Built for Predictable Systems. AI Changes the Rules

    Traditional cybersecurity controls were designed for systems that behave predictably, whereas AI applications can produce dynamic and unexpected outcomes. The article recommends real-time visibility, runtime monitoring, and adaptive security controls for AI-enabled environments.

Edition #95

AI Expands the Attack Surface. Trust Must Evolve.

View edition →
  • CSO Online

    Frontier AI Models Offer Sneak Peak of Seismic Cyber Shifts Ahead

    Frontier AI models could dramatically accelerate vulnerability discovery and exploit-chain identification. Security leaders should prioritise faster remediation, stronger identity controls, segmentation, and limiting the potential impact of breaches.

  • SecurityInfoWatch

    AI Is Turning Everyday Trust Into the Next Malware Battleground

    Attackers are using AI to conceal malicious activity within trusted tools, familiar workflows, and convincing communications. Organisations must strengthen verification processes, awareness training, and technology-based defences against highly personalised attacks.

Edition #93

Attack Paths Multiply. Ownership Must Be Clear.

View edition →
  • Sysdig

    AI Agent at the Wheel: How an Attacker Used LLMs to Move From a CVE to an Internal Database in 4 Pivots

    Sysdig observed an LLM agent carrying out real-time post-compromise actions after an attacker exploited a vulnerable internet-facing notebook. The attack progressed through cloud credentials and an SSH bastion to the theft of an internal PostgreSQL database in under an hour.

Edition #92

Prevention Isn’t Enough. Recovery Preserves Trust.

View edition →
  • SecurityInfoWatch

    4 AI Security Lessons From the Front Lines of Cybersecurity

    Cybersecurity experts from organisations including Microsoft, OWASP, UnixGuy, and TryHackMe discuss practical lessons for securing AI. The article recommends treating AI security as an evolving professional capability rather than approaching it primarily through fear.

  • Forbes Technology Council

    Four Ways That Generative AI Improved Cybersecurity Forever

    Generative AI is transforming cybersecurity by helping defenders anticipate attacks, interpret identity context, identify sensitive information, and discover complex software vulnerabilities. These capabilities allow threats to be understood and addressed at machine speed.