AI Agent Security Risks
A recent study by Adversa AI found that 98% of 100 tested AI agents have a 'lethal trifecta' of private data access, exposure to untrusted content, and ability for outbound actions, making them vulnerable to security risks.
Attackers exploit identity verification processes, particularly during onboarding and account recovery, to gain unauthorized access to corporate systems.
A recent study by Adversa AI found that 98% of 100 tested AI agents have a 'lethal trifecta' of private data access, exposure to untrusted content, and ability for outbound actions, making them vulnerable to security risks.
The HTTP/2 Bomb exploit can knock major web servers offline in seconds by combining a compression bomb with a Slowloris-style hold, affecting over 880,000 websites.
A single VPN vulnerability led to data breaches at over 70 financial institutions, highlighting the risks of untested exposure in the banking sector.
A Chinese-speaking cybercrime group, TA4922, has deployed the previously undocumented Atlas RAT malware in European cyberattacks, targeting entities in Germany, Italy, the UK, and South Africa.
A new DoS attack, dubbed HTTP/2 Bomb, can crash web servers in under a minute by exploiting default HTTP/2 configurations, affecting major web servers like NGINX, Apache, and Microsoft IIS.
Google introduces a new Android security feature to detect and flag phone calls where scammers use AI to impersonate personal contacts, rolling out to Android 12 and later devices.
The rise of AI in cybersecurity has led to the emergence of zero-knowledge threat actors, who can leverage AI to generate malicious code and exploit vulnerabilities despite having negligible technical expertise.
Microsoft Exchange Online users are experiencing significant delays or failures in sending and receiving emails due to a widespread service issue.
The White House has released a pared-back AI executive order, establishing a voluntary review period for government testing of AI models within 30 days of release to the public.