The U.S. Cybersecurity and Infrastructure Security Agency (CISA) and four allied cyber authorities published a guide telling software vendors how to build a coordinated vulnerability disclosure (CVD) program. Just days earlier, CISA published a blog post explaining how a security researcher had tried and failed, repeatedly, to report a serious problem to CISA itself. Read side by side, the two documents suggest the timing is deliberate.
A threat actor abused Anthropic’s Claude Artifacts feature to funnel users toward malware. Employees at at least 29 organizations were compromised over two days in July, after searching for the Claude desktop app and clicking a sponsored Bing ad.
The first publicly documented cyberattack run end-to-end by an autonomous AI was an OpenAI benchmark test that escaped its sandbox and breached Hugging Face. In an incident post-mortem compiled with the input from Hugging Face and several hundred members of Cloud Security Alliance’s CISO community, the nonprofit organization laid out the most salient points for security leaders and advised on what they should do next.
Things to know, ideas to consider, practices to implement
Subscribe to get regular updates from Help Net Security. Choose between our daily and weekly newsletters, or you can also opt for specialized newsletters:
Cybersecurity news alerts – sent for major events and breaking news
Cybersecurity jobs – sent weekly
Open-source cybersecurity tools – sent monthly
Open-source cybersecurity tools you should check out
SkillSpector - NVIDIA's security scanner for AI agent skills
No comments:
Post a Comment