The guidelines are the work of the recently launched Open Secure AI Alliance, which now includes 120 organizations.
Tag: securityweek
AI Security Institute Reports Anthropic and OpenAI Models Going Rogue Against Organizations
In one instance, an unsanctioned model attempted to inject malicious code into an open source repository.
CISA Warns of Exploited Langflow, N-central, and Tomcat Vulnerabilities
The flaws can be exploited for remote code execution, authentication bypass, and EncryptInterceptor bypass.
Over 400 NPM Packages Infected in ChainDrop Supply Chain Attack
The malware was designed to steal and exfiltrate secrets, and to propagate itself via stolen NPM and GitHub credentials.
Water Sector Cyberattacks Reportedly Hit at Least 12 States
Georgia has been confirmed as one of the attacked states after Clayton County reported a pump station disruption.
Rethinking AI Security: Why CASB and DLP Need an Interaction-Aware Layer
Build your strategy around answering these questions to ensure employees use AI productively while keeping sensitive data, IP, and agent behavior within…
Black Hat USA 2026 – Summary of Vendor Announcements (Part 2)
Many companies are showcasing their products and services this week at the 2026 edition of the Black Hat conference in Las Vegas.
CISO Conversations: Russ Kirby – Passion Is the Antidote to Burnout
Russ Kirby, CISO at Ping Identity, shares how passion, courage, and “good enough” thinking shaped his path from HP to the C-suite—and what keeps him up at…
Oligo Raises $60 Million for Runtime Security
The company will use the investment to accelerate product innovation and expand go-to-market operations.
CISO Conversation: Russ Kirby – Passion Is the Antidote to Burnout
Russ Kirby, CISO at Ping Identity, shares how passion, courage, and “good enough” thinking shaped his path from HP to the C-suite—and what keeps him up at…
Weaponized Email AI Assistants Could Help Attackers Hijack Accounts
Researchers demonstrate how attackers could abuse built-in email chatbots to evade detection, impersonate trusted employees, compromise executive…
Zenity Raises $125 Million in Series C Funding
The AI security company will invest in product innovation, global expansion, and customer experience.
Obsidian Security Raises $85 Million at $1.1 Billion Valuation
Obsidian Security has developed a platform for governing AI agents across third-party applications.
TP-Link Omada ZTP Vulnerabilities Chain Into Full Network Takeover
Forescout researchers have found 15 new vulnerabilities in the TP-Link Omada networking ecosystem.
Gemini Agent-to-Agent Attack Method Exposed Secrets, Enabled Pull Request Tampering
A crafted prompt to a low-privilege Google ADK agent could be used to pass a malicious hand-off comment to a privileged agent.
Decades-Old BMC Vulnerability Exposes Thousands of Data Centers to Attacks
Over 24,000 internet-accessible server-management interfaces disclose authentication hashes before login.
150,000 Impacted by Madera Community Hospital Data Breach
An extortion group stole personal, financial, and medical information from the hospital’s network.
Microsoft Bug Bounty Program: $20 Million Paid to 500 Researchers
The biggest single reward paid out by Microsoft between July 1, 2025, and June 30, 2026, was $200,000.
New York Awards $9 Million to Strengthen Cybersecurity at 153 Water Systems
The grants will help local governments assess and improve cyber defenses amid a multistate campaign targeting water and wastewater infrastructure.
Cyberattack Hits Liechtenstein’s Register of People Behind Companies and Foundations
The list of people behind companies, foundations and trusteeships is part of efforts to combat money laundering and terror financing.