No Perfect Fix for AI Browser Prompt Injection Flaws
AI browsers from top vendors remain vulnerable to prompt injection attacks despite multiple security guardrails, according to new research.
AI browsers from top vendors remain vulnerable to prompt injection attacks despite multiple security guardrails, according to new research.
AI in healthtech: Practical tips for healthtech owners, operators, and investors Nixon Peabody
A Canadian man pleaded guilty today to his role in accessing company accounts at cloud storage provider Snowflake and stealing data from at least 165 organizations in a scheme to extort millions of dollars from victims. [...]
O encerramento de contratos é um dos principais pontos cegos na gestão de fornecedores, segundo a Tripla, companhia nacional de cibersegurança, tecnologia e compliance. Falhas no offboarding podem manter ativos acessos a sistemas, integrações e dados corporativos mesmo após o fim…
A Veridas, companhia global de identidade digital, consolida sua expansão no Brasil após a fusão com a Fourthline, líder europeia em verificação de identidade e conformidade regulatória. O acordo cria uma das maiores plataformas globais de identidade digital, com presença em mais…
A CrowdStrike publicou o Relatório de Caça a Ameaças 2026, revelando que a IA agora está incorporada às operações dos adversários modernos. O documento aponta que grupos vinculados à China exploraram vulnerabilidades críticas em até 24 horas após a divulgação pública da prova de …
Medtronic’s George Murgatroyd says an advanced computing platform that works with the company’s Hugo robot will power AI algorithms that can assist surgeons as they operate.
Anthropic and OpenAI models’ unprompted actions forced halt to UK cyber tests.
O Instituto de Segurança da Inteligência Artificial do Reino Unido (AISI) divulgou um relatório de incidente em que agentes de IA, durante uma avaliação de rotina, executaram ações autônomas e não autorizadas, direcionadas a pessoas e organizações reais. O episódio, que ocorreu e…
Hackers exploited a SQL injection vulnerability to install a post-exploitation toolkit directly inside an Oracle database that was used to breach a corporate network. [...]
CSS was once just about design. Now researchers warn it's powerful enough to exfiltrate data from webmail — and some vendors aren't prepared.
Kaspersky links OctLurk and SilkLurk to cyberespionage attacks stealing passwords, emails and files from government systems in six countries since January 2025.
Researchers are calling attention to the risks inherent in automated network device provisioning, using a world-leading device manufacturer as a case study.
A macOS ClickFix operation spanning more than 250 front-end domains now fingerprints visitors before deciding whether to show them a malware lure, a change Microsoft Threat Intelligence tracked on infrastructure it had been watching for weeks. The server-side gate hides the mali…
OpenAI said it disrupted a Cambodia-based scam operation that used its generative artificial intelligence (AI) chatbot ChatGPT to facilitate a wide range of investment, romance, gambling, and law enforcement impersonation schemes. To that end, it banned a coordinated network of …
Google has fixed the issues, which exploited a trust boundary between two AI agents with different privilege levels to trigger automation that could compromise the supply chain.
Organized crime is convincingly scamming at scale, making billions thanks to AI-enabled voice cloning, deepfake real-time video overlays, LLM-driven persona management, and automated translation.
A phishing campaign is exploiting fears surrounding the recently disclosed COLDCARD wallet vulnerability and suspected $88.6 million Bitcoin theft to trick users into installing ScreenConnect remote access software. [...]
By Matt Fisher - The biggest recent news for HIPAA is the quiet reveal that updates to the Security Rule are now delayed until sometime in the middle of 2027. The update was made on an Office of Management and Budget webpage, which now shows expected final action as an undefined …
Compare AI detection & response platforms for 2026, including Dash, Lakera, Operant AI, HiddenLayer and Prisma AIRS, for runtime threat protection and response.