fa
Feedback
AISecHub

AISecHub

رفتن به کانال در Telegram
2 562
مشترکین
+524 ساعت
+117 روز
+6530 روز
آرشیو پست ها
I’ve released a new feature that makes it easy to listen to cybersecurity podcasts in a simple, seamless way. I never had enough time to listen to all the cybersecurity podcasts out there. There are so many of them, and it was always difficult to decide which ones were worth my time. That’s why I built a ranking system. The next step is for my agent to finish converting every podcast episode into text and then generate a summary of no more than five sentences. This will give users another way to decide whether an episode is worth listening to in full or whether the summary is enough. Later, I also plan to add a weekly email digest with summaries of newly released podcast episodes. https://www.awesomecybersecuritypodcasts.com/ I hope you find it useful.

Three critical Microsoft RCEs found autonomously: how attacker-controlled input becomes code inside the "boring" helpers appl
Three critical Microsoft RCEs found autonomously: how attacker-controlled input becomes code inside the "boring" helpers applications treat as plumbing. https://xbow.com/blog/bing-images-rce-vulnerabilities

photo content

photo content

CEO of Palo Alto
CEO of Palo Alto

ResearchArena Benchmark Evaluates AI Agent Sabotage and Monitoring in Automated R&D The ResearchArena paper introduces a benchmark for evaluating whether AI agents automating AI R&D can be trusted, treating agents as potential adversaries and using monitors to detect covert sabotage in generated code and research outputs. The framework tests AI control approaches where untrusted agents must pass monitoring checks before their outputs are deployed, addressing safety risks as agents begin automating their own development pipelines. The work spans AI safety, cryptography and security, and machine learning categories. #AISecurity #AgentSafety #Benchmark #Research #AISecurityGovernanceAndAssurance https://arxiv.org/abs/2607.19321

FakeGit Campaign Uses 6,600 GitHub Accounts to Deliver Malware via AI Agent Baiting The FakeGit campaign employed approximately 6,600 fake GitHub accounts and trojanized MCP servers to deliver SmartLoader and StealC malware, logging over 14 million downloads across 200 repositories. Researchers identified a technique called AgentBaiting where AI agents searching for tools become the attack target, with about 1,400 accounts built around AI tools, agents, or workflows spanning enterprise use cases including Databricks, Jenkins, and Docker. Once executed, SmartLoader establishes persistence and installs StealC to target credentials, active sessions, and sensitive data. #AISecurity #SupplyChain #MCP #Malware #ThirdPartyRiskManagement https://www.helpnetsecurity.com/2026/07/21/github-repos-malware-campaign-fakegit-ai-agents/

Russian Threat Actor Shares Claude Opus Jailbreak Techniques on Cybercrime Forum A threat actor tracked as Trim appeared on a Russian-language cybercrime forum sharing methods to bypass Claude Opus safety controls through prompt-based manipulation. The techniques include creating benign context before harmful requests, reframing instructions to focus only on code structure, and retrying softened versions of previously refused prompts, treating offensive requests as authorized security research. Trim also recommended alternative AI services and locally hosted models when commercial systems refused a request, lowering dependency on any single AI provider. #AISecurity #Jailbreak #Claude #Cybercrime #ThreatIntelligence https://cybersecuritynews.com/russian-hacker-jailbreaks-claude/

Data Leakage Prevention in Agentic Applications via Preemptive Hardening Agentic systems integrate LLM driven planning with interfaces to external tools, making data leakage and tool misuse feasible via instruction/data boundary failures and prompt injection attacks. The resulting modifications of application code were shown to eliminate leaks when targeted by basic jailbreak and instruction-override attacks, achieving a 100% reduction in leakage, and reduce leaks by 91% under conditions of stress-induced manipulation, without the need of continuous runtime policy enforcement. #LLMSecurity #AIResearch #AdversarialRobustness #AISecurity #DataSecurityAndProtection https://arxiv.org/abs/2607.18847

The issue I often raise, which is the ability of companies such as OpenAI to independently disclose the challenges and limitations of their own systems through System Cards, is reflected here as well. In my view, only an independent body such as NIST can help address this problem. Companies like OpenAI are not in a position to report objectively on the challenges, failures, and limitations of the systems they develop through their own System Cards. The question that keeps coming up is how is it possible that all the companies and external parties hired by OpenAI failed to identify these findings?

photo content

photo content