Attackers exploited a CSRF flaw to inject autonomous AI agents with employee privileges into ChatGPT and automate email exfiltration; the vulnerability was patched within three days.
Security researchers demonstrated manipulation of macOS apps through local package tampering without Gatekeeper blocking it, but Apple does not classify this as a security vulnerability.
Decentralized AI endpoints form an independent infrastructure layer that partially escapes traditional security and control mechanisms, thereby redefining governance models.
ISO 27001:2022 requires secure authentication across four dedicated controls, operationalized through strong password policies, Conditional Access, and phishing-resistant MFA.
Azure Automation enables cross-tenant identity takeovers through default configuration; Microsoft also has three critical infrastructure security vulnerabilities.
Attackers use open-source AI tools to industrialize the development of phishing and malware infrastructure, accelerating processes and testing variants against security vulnerabilities.
The NIS2 Directive will require approximately 29,500 German companies to meet enhanced cybersecurity standards with stricter requirements for governance, risk management, and incident reporting beginning in October 2026.