Threat modelling stories
Security teams under pressure to prove real exploitability can now test live production systems for attack paths rather than theoretical flaws.
The public test could bolster or undermine claims that VEIL can anonymise sensitive AI data without letting outsiders recover the original records.
JupiterOne rolls out AI attack surface and vulnerability tools to help security teams map links, prioritise flaws and cut through alert overload.
Organisations using AI in software development will get training on secure coding and governance as vulnerabilities and data risks mount.
Vetted security teams will get fewer refusals on authorised tasks as OpenAI tightens access around its most permissive cyber model.
A flaw in a widely watched Microsoft repository could have let attackers run code and steal secrets through GitHub Actions, Tenable said.
Banks could face undetected ledger and pricing changes as autonomous AI attacks exploit poorly governed databases, Liquibase warns.
Patching delays now carry greater risk as Google says AI is helping attackers scale intrusions, speed up breaches and automate operations.
Reporters face rising risks from phishing, spyware and device compromise as Bitdefender urges tighter source protection and account security.
Customers gain broader visibility into AI risks as Wiz adds cloud, edge and coding-tool coverage, with Red Agent now in public preview.
The framework is designed to expose hidden risks in production AI systems that can be missed by conventional one-off tests.
Businesses relying on obfuscation and embedded secrets in mobile apps may face easier API attacks as AI can mimic legitimate traffic.
Delaying preparation could leave large firms racing to retrofit encryption before 2029 deadlines set by Google, Cloudflare and India.
Security teams now have a beta tool to probe large language model apps for prompt injection, jailbreaks and data theft before attackers do.
BeyondTrust warns a surge of unsupervised AI agents is creating a hidden “shadow workforce” with admin-level access inside enterprises.
NetSPI unveils an AI-powered overhaul of its pentesting platform UX, promising two-click workflows and sharper risk-based remediation focus.
Organisations using AI-assisted development can now get specialist secure coding training as KnowBe4 expands its library for technical teams.
Researchers can now train on live attack traffic after a new open-source dataset adds 100 million labelled security records from production systems.
UK regulators are racing to assess whether Anthropic’s Mythos model could speed up attacks on banks and unsettle financial stability.
Australian firms risk shifting bottlenecks from coding to testing and security as AI boosts developer output but leaves workflows fragmented.