When executives use unapproved AI tools, they undermine governance by example and force CISOs to choose between stricter policies or better tools — policies alone do not work.
An unpatched vulnerability in Cursor enables attackers to execute arbitrary malicious code when a developer opens a prepared repository with a manipulated git.exe.
GPT-Red detects indirect prompt injections with 84 percent success rate — significantly higher than the 13 percent achieved by human experts — and contributes to developing safer model generations.
Vulnerabilities in the Bouncy Castle cryptographic library allow decryption of data and forgery of digital signatures; immediate patching is necessary.
76 percent of companies experienced disruptions caused by external partners with damages sometimes exceeding 10 million dollars, yet only 31 percent conduct joint tests with critical third-party providers.
The BSI has identified security deficiencies in Windows Hello for Business that require a critical reassessment of this authentication solution for enterprise deployments.
Agentic AI systems create security risks through their autonomy, which classical threat models do not cover and which require different control mechanisms.
A structured evaluation protocol with multiple complex test environments and LLM-powered vulnerability detection enables more realistic assessment of AI pentesting agents beyond classical benchmark scenarios.
Text-salting techniques enable attackers to circumvent AI-driven email filters by embedding hidden text passages in messages that remain undetected by LLMs.
A security vulnerability in the Claude Chrome Extension allows malicious extensions to trigger AI actions and access connected services such as Gmail and Google Docs.