Normal view

There are new articles available, click to refresh the page.
Today — 13 September 2026IT Security

Anthropic CEO Dario Amodei Says AI Industry Needs to Give Safety Measures Time to Catch Up

13 September 2026 at 09:27

Dario Amodei warned that within six to 12 months AI could be capable of leading a swarm of agents that could take over the entire internet.

The post Anthropic CEO Dario Amodei Says AI Industry Needs to Give Safety Measures Time to Catch Up appeared first on SecurityWeek.

Before yesterdayIT Security

Users in Houthi-Held Yemen Tried to Develop Advanced Weapons With AI, Anthropic Says

11 September 2026 at 21:50

Anthropic said the users did not succeed in “fielding an operational device” but did carry out a failed test of a guided rocket.

The post Users in Houthi-Held Yemen Tried to Develop Advanced Weapons With AI, Anthropic Says appeared first on SecurityWeek.

Trezor Says 347,000 Users Received Phishing Emails After Brevo Hack

11 September 2026 at 08:48

Hackers compromised the Brevo marketing platform and used that access to send phishing emails to users of Trezor, BitBox, and CoinTracking.

The post Trezor Says 347,000 Users Received Phishing Emails After Brevo Hack appeared first on SecurityWeek.

Anthropic Says Russian Hackers Used Claude AI to Automate Malware Evasion

11 September 2026 at 04:47

Anthropic reveals how criminal groups are increasingly targeting AI vendors' own infrastructure, including to steal a pre-release Claude model.

The post Anthropic Says Russian Hackers Used Claude AI to Automate Malware Evasion appeared first on SecurityWeek.

Why hostile state cyber activity is now a day-to-day business risk

9 September 2026 at 10:53

Christopher Clark, Cyber Security Incident Response Team Director, Thrive 

Geopolitical escalation can become a cyber security problem for businesses far more quickly than many boards expect.

The National Cyber Security Council (NCSC) has warned that UK critical infrastructure faced more than 200 cyber incidents over the past year, with around three-quarters believed to be linked to state actors. Analysis of the conflict involving Iran has also found cyber retaliation following military escalation within hours, bringing events overseas much closer to the day-to-day reality of UK organisations.

That risk has already been demonstrated on UK soil. In July, a cyber-attack reportedly linked to Iranian hackers forced a small UK power generator offline for four days. The government said there was no risk to the wider energy system, but the incident shows how quickly geopolitical cyber activity can translate into operational disruption.

Energy, healthcare, water and telecoms remain obvious targets because disruption can affect essential services. Yet, hostile state activity does not stop at the boundary of critical infrastructure.

Hostile state risk extends beyond critical infrastructure

A business does not have to be an obvious target to become one. It may be connected to a larger customer, supplier, regulator or public body that an attacker ultimately wants to reach. In other words, you do not have to be the objective. You just have to be the way in.

There is also the risk of spillover. Targeting can follow politics rather than the size of a company or its balance sheet. If an organisation has operations or suppliers connected to a live conflict, it can become collateral even when nobody set out specifically to target it.

Businesses also need to reconsider what hostile state activity is likely to look like inside their own environments. The most significant intrusions are not necessarily the noisiest.

Security teams may be watching for malware, failed logins or a sudden increase in DDoS activity. Capable attackers increasingly use valid credentials and legitimate administration tools, allowing malicious behaviour to resemble normal activity.

There may also be no obvious warning to investigate. If the plan is to wait for one, the organisation may already be too late by the time it appears.

A better working assumption is that a capable actor could already be inside, or could get in without immediately triggering an alert. The question then becomes what they can actually do once they have that foothold.

Trusted technology can create the same problem. Management platforms and legitimate system tools can be repurposed by attackers, while compromised software packages can provide access to many organisations at once. Activity entering through a tool or supplier that the business already trusts may attract less scrutiny because it appears legitimate.

The same principle applies to suppliers. If a connected partner has been compromised, one of the first questions should be what has been done to separate that organisation from your own environment. Continuing normal access without understanding what happened risks transferring their exposure into your network.

Organisations should know how they would isolate an affected supplier and what evidence would be required before connectivity resumed. They may need confirmation of how the attacker entered and which systems were affected, alongside assurance that the access has been removed. Shared applications or other connections may have to remain unavailable until that information is clear.

That can be uncomfortable for the business, but restoring connectivity too quickly can create a much bigger problem later.

The time available to make these decisions is shrinking. Threat actors can analyse newly disclosed vulnerabilities and move to exploitation quickly, with AI making parts of that process faster. In some cases, organisations can be exposed within hours of a vulnerability becoming known.

Patch management therefore cannot always wait for the normal maintenance cycle. Teams need to know which vulnerable systems create the greatest risk and be ready to prioritise them when a new vulnerability emerges.

Geopolitical risk can also outlast the immediate conflict.  A ceasefire does not automatically remove access established during a period of heightened activity, nor does it mean proxy groups will stop operating. Attackers have good reason to preserve a foothold that may be useful later. I have seen access remain available inside an environment for three years or more.

That is why an easing of geopolitical tension should not automatically be treated as a reduction in cyber risk.

Containment depends on preparation and experience

Preparation has to focus on containing an attacker as well as keeping them out. Standing privileges should be kept to a minimum, networks should be segmented so an attacker cannot move freely towards critical systems or backups, and offline backups need to be regularly tested.

Organisations also need a clear view of their external attack surface and where their greatest points of exposure lie. Regular tabletop exercises should use realistic scenarios informed by current threat intelligence.

If an attacker gained access through a VPN or compromised supplier, what could they reach next? How far could the incident spread? And who has the authority to cut them off?

That authority needs to be clear before an incident. Time can be lost when technical teams know what needs to happen but must wait for decisions on whether systems can be disconnected or business processes interrupted.

Experience is equally important. Frameworks provide structure, but serious incidents rarely follow a script. Responders who have handled repeated compromises understand where investigations can stall, which decisions cannot wait and what needs to be secured before systems are safely returned to service.

For many organisations, maintaining that level of incident response experience entirely in-house is difficult. What matters is having access to people who have dealt with incidents under real operational pressure and can apply that experience quickly when normal assumptions no longer hold.

Hostile state cyber activity should now be treated as a routine business risk rather than something considered only when international tensions make the headlines.

Organisations should be asking a more immediate question: if something gets through today, how far can it spread before we stop it?

Answering that question before an attack happens can make the difference between a contained security incident and a prolonged operational crisis.

The post Why hostile state cyber activity is now a day-to-day business risk appeared first on IT Security Guru.

US Agencies Warn China Is Systematically Extracting Frontier AI Capabilities

9 September 2026 at 08:32

Distillation is an ‘attack’ against an AI model designed to capture outputs, understand reasoning processes, and subsequently train a different model.

The post US Agencies Warn China Is Systematically Extracting Frontier AI Capabilities appeared first on SecurityWeek.

New Phishing Attack Creates Malicious Pages Inside the Victim’s Browser

9 September 2026 at 06:00

Attackers are using trusted Microsoft services and blob URLs to generate stealthy phishing pages that leave defenders with no static website to detect or block.

The post New Phishing Attack Creates Malicious Pages Inside the Victim’s Browser appeared first on SecurityWeek.

Microsoft Patches Record 974 Vulnerabilities, Including Two Exploited Zero-Days

8 September 2026 at 15:20

The record-breaking September security update fixes two exploited privilege-escalation zero-days and 20 potentially wormable vulnerabilities.

The post Microsoft Patches Record 974 Vulnerabilities, Including Two Exploited Zero-Days appeared first on SecurityWeek.

OpenAI Pledges $1 Billion to Bring Frontier AI to Critical Infrastructure Defenders

4 September 2026 at 12:07

The Daybreak initiative will provide subsidized AI cyber capabilities, training and technical assistance, though OpenAI has disclosed few details about costs and eligibility.

The post OpenAI Pledges $1 Billion to Bring Frontier AI to Critical Infrastructure Defenders appeared first on SecurityWeek.

AI is finding vulnerabilities faster. Who is funding the people expected to fix them?

4 September 2026 at 12:33

Artificial intelligence is changing vulnerability discovery. At OpenSSL, we are seeing that change first-hand. A year ago, our security address received around nine separate reports and enquiries a month. It now receives around 70. AI tools can examine source code and identify potential security issues at a scale that would previously have required significant human effort.

In many ways, that’s positive. Finding vulnerabilities is an essential part of making software more secure. But there is another side to this that deserves much more attention. Every vulnerability report has to go somewhere.

Someone needs to assess whether the issue is genuine. If it is, engineers need to understand its severity, develop a fix, test that fix and manage disclosure appropriately. AI can increase the speed at which potential problems are discovered. It does not automatically increase the number of experienced engineers available to deal with them. That imbalance could become a serious issue for open-source security.

Finding a vulnerability is only the beginning

There is an understandable tendency to treat vulnerability discovery as the success story. An AI system finds something humans missed. That makes a compelling headline. But identifying a potential weakness and resolving it are very different tasks.

A report might represent a serious vulnerability. It might be something already understood. It might be technically correct but have limited real-world security impact. It might simply be wrong. Working out which of those is true requires expertise. Then, if there is a genuine vulnerability, somebody has to fix it.

Over the past 12 months we received a little over 400 vulnerability reports. 43 resulted in a published CVE. Roughly one in ten. The other nine still had to be read, understood, reproduced where we could, and answered. A report that turns out not to be a vulnerability consumes much the same expert attention as one that is — sometimes more, because establishing that something cannot be exploited is often harder than confirming that it can.

For a commercial software company with large security teams, increasing the number of reports may be manageable. For an open-source project with limited resources, a sudden increase can create a very different problem. The technology for finding possible vulnerabilities is becoming cheaper and more accessible. However, the expertise required to investigate them is not.

Businesses depend on projects they may barely know exist

This connects to a much older problem with open-source. Most technology companies know they use open-source software. What is less clear is whether they understand exactly which projects their products and services depend upon. That distinction matters.

Open-source components can sit deep inside software stacks. They work quietly, so organisations may have little reason to think about the people maintaining them. Then something goes wrong.

Heartbleed was an important moment for OpenSSL because it exposed the gap between the importance of open-source infrastructure and the resources available to support it. The industry responded. Investment increased and organisations began paying much more attention to the sustainability of critical open-source projects.

My concern is that some of those lessons are beginning to fade, and AI could make the consequences of that particularly visible.

AI changes the economics of vulnerability discovery

There is an asymmetry developing. The cost of searching code for potential security weaknesses is falling. The volume of reports can therefore rise significantly. But the other side of the process remains stubbornly human. Experienced engineers still need to understand the code. They need to judge whether the finding matters and decide how it should be fixed without creating another problem somewhere else.

Those people are a scarce resource. This means the question organisations should be asking about AI and cybersecurity isn’t only: “What can AI find?” It should also be: “Who is going to deal with everything it finds?”

For open-source projects, that leads directly to questions about sustainable funding. If businesses depend on a project as part of their critical infrastructure, supporting the health of that project should be viewed as part of resilience, not philanthropy.

Regulation only gets us part of the way

Governments are understandably looking at how regulation can improve cyber resilience. That matters, but regulation cannot maintain software. Europe provides some interesting examples of a different approach. OpenSSL Foundation has received support from Germany’s Sovereign Tech Agency, which invests directly in open digital infrastructure.

That recognises something important: if technology is critical to the functioning of the digital economy, somebody needs to invest in the people maintaining it. I’d like to see more of that conversation in the UK. Cyber resilience isn’t only about telling organisations what standards they should meet. We also need to consider the health of the technology underneath the services we’re trying to protect.

Organisations need to know what they depend on

There is something businesses can do immediately. Understand your open-source dependencies. If a critical vulnerability appeared tomorrow in a project your organisation relies on, could you identify where that software was being used?

Would you know which products and services were affected? Would you know who maintains the project? And would you have any relationship with the community responsible for fixing it? If the answer is no that is a resilience gap.

Organisations don’t necessarily need to contribute code themselves. There are other ways to support projects, including funding, engineering resources and participation in the communities maintaining the technology they depend upon. The important shift is recognising open source as infrastructure rather than free software that simply appears.

We need to talk about the people behind the code

AI will continue getting better at analysing software. That’s exciting, and it has the potential to make technology significantly more secure. But more findings do not automatically produce more security. The benefit comes when we have the expertise and resources to act on what those tools discover. That makes this a human question as much as a technology question.

How do we sustain the communities maintaining critical open-source infrastructure? How should businesses support the projects they depend on? What happens when vulnerability discovery accelerates faster than our ability to respond?

The post AI is finding vulnerabilities faster. Who is funding the people expected to fix them? appeared first on IT Security Guru.

Q&A: Viasat Tests Satellite Resilience With AI as Cyber Expert Warns an Attack Could ‘Hurt an Entire Country’

4 September 2026 at 12:25

An AI-assisted platform has been used to test whether Viasat’s satellite communications links can meet operational thresholds under interference and adversarial jamming. 

Announced this month, the work with Atalanta has renewed scrutiny of the vulnerabilities exposed by Russia’s 2022 attack on Viasat’s KA-SAT network, which disrupted communications across Ukraine and several European countries. 

Gil Baram, PhD, is a cybersecurity strategy and policy researcher specialising in cyber warfare, intelligence and space security. She is a Senior Lecturer and Associate Professor at Bar-Ilan University and formerly led the Cyber and Space Research Group at Tel Aviv University. 

In this exclusive interview for the IT Security Guru conducted by the Cyber Security Speakers Agency, Gil explains how states use cyber operations to compete below the threshold of open war, why long-life satellites present a distinct security challenge, and how an attack on space-based communications could disrupt everyday life on Earth. 

How have state cyber capabilities blurred the threshold between strategic competition and armed conflict? 

Gil Baram: “I think the greatest change that cyber warfare and cyber capabilities have created is that states can compete without crossing this imaginary red line: if you cross it, then it’s a war. 

“They don’t do that, but they still compete on and on, causing damage to one another, disrupting civilians’ lives and interfering in elections. But still, that doesn’t lead to an open war. That’s something very unique to this type of technology.” 

Why does securing space-based infrastructure present a different cyber challenge from defending terrestrial systems? 

Gil Baram: “When we talk about that, the first thing we have to have in mind is the distance. For many years, security contractors were the ones building big satellites for states and launching them. Have it in mind that these satellites should be in space for 20 or 25 years, and that’s a lot. 

“If you have a cyber risk, it’s very hard to patch a system that is flying far away from you and that was launched a decade ago. It created a lot of questions: how do you deal with cyber security in space? 

“In the past, we started seeing what we call the new space: startups and technology companies that started building satellites and building space capabilities. These are not the big security contractors. 

“We started seeing that these companies do have security by design, or cyber security by design, when they design their products and before they’re launching them to space. That’s a big shift we’ve seen today.” 

How exposed is civilian life to a successful cyberattack on satellite communications infrastructure? 

Gil Baram: “My feeling is that sometimes we don’t realise how much we depend on space capabilities, even for chatting today, using our internet or our cell phones, and navigating with GPS. Many things that we take for granted couldn’t happen without satellites and space satellite communication. 

“I’ll give just one example. In the first day of the Russian invasion to Ukraine, the Russian conducted a cyberattack against Ukraine satellite communication capabilities. 

“The reports coming out from Ukraine: they didn’t have the needed communication at the very critical moments or hours of the beginning of the war. You can damage satellite communication and then hurt an entire country. 

“The main thing I hope audiences will take, and that’s my passion and goal, is to understand or realise that cyber, AI and cyber threats are relevant to our everyday lives. It’s not something that is out there, and not just something that we read in the news, but it’s relevant for everyday lives. 

“We don’t have to be technical people in order to understand that and in order to protect ourselves.”

The post Q&A: Viasat Tests Satellite Resilience With AI as Cyber Expert Warns an Attack Could ‘Hurt an Entire Country’ appeared first on IT Security Guru.

KnowBe4 to Put AI Trust to the Test at Leeds Digital Festival

4 September 2026 at 09:09

KnowBe4 is set to explore the growing challenge of determining what organisations can trust in the age of AI at an exclusive cybersecurity briefing during Leeds Digital Festival 2026.

Taking place on 1 October, CyberSecure Leeds: Who Do You Trust Now? Human Judgement in the Age of AI will examine how the growing role of AI agents in business processes is changing the security landscape and creating new questions around identity, decision making and human oversight.

At the centre of the event will be an unusual real-world experiment from Javvad Malik, lead CISO advisor at KnowBe4, which started with a disputed parking ticket. During the experiment, Malik explored how AI could be used to help create convincing documentation and establish a digital presence that automated systems subsequently treated as legitimate, all within 48 hours.

While the experiment started with a relatively everyday scenario, KnowBe4 believes it highlights a much broader security concern. As organisations integrate AI into workflows, approvals and other business processes, systems may be placed in a position where they are effectively helping to determine what is legitimate and what should be trusted.

This becomes particularly significant as the digital workforce expands beyond human employees to include AI agents capable of accessing information, interacting with applications and influencing decisions.

“AI is rapidly becoming part of how organisations decide what is real, what is legitimate and what should be trusted,” said Malik.

“The problem is that AI can be extremely convincing without necessarily being right. As organisations give these systems greater influence over business processes, we need to think carefully about where human judgement fits and how attackers could exploit that trust. The workforce is now a combination of people and AI agents, and our approach to security has to reflect that reality.”

Phishing Beyond the Inbox

The briefing will also look at how the social engineering landscape is changing as attackers adopt AI-generated content and increasingly target users across multiple communications channels. James Dyer, head of threat intelligence at KnowBe4, will provide an update on current phishing activity, including the growth of phishing-as-a-service and the ways attackers are adapting their techniques to bypass existing security controls.

The session will examine why organisations can no longer treat phishing solely as an email security problem, with social engineering attacks capable of moving across different platforms and exploiting the trust employees place in digital communications.

The event coincides with the beginning of Cybersecurity Awareness Month and forms part of Leeds Digital Festival, which runs from 21 September to 2 October with more than 200 technology events taking place across the region.

The KnowBe4 briefing will run from 8:30am to 11:00am at the company’s Leeds office and is aimed at CISOs, IT leaders, security practitioners and business decision makers.

Attendance is free but limited to 30 places, with advance registration required through the Leeds Digital Festival event programme. Interested delegates can register here: https://web.cvent.com/event/96b273cf-5129-4734-b54c-0dfd0a38aa61/summary

The post KnowBe4 to Put AI Trust to the Test at Leeds Digital Festival appeared first on IT Security Guru.

❌
❌