❌

Normal view

There are new articles available, click to refresh the page.
Before yesterdayIT Security Guru

4 Ways Organisations Create Non-Human Insider Risk

By: The Gurus
10 September 2026 at 11:55

As AI agents become embedded across business operations, they are also creating a new category of insider risk. Unlike traditional insiders, these non-human identities can act at machine speed, operate continuously and access multiple systems without direct human oversight.

The danger rarely stems from one obvious security failure. Instead, it emerges when several weaknesses overlap. Here are four common ways organisations inadvertently create non-human insider risk:

1. Persistent access

Long-lived API keys, OAuth tokens, service accountsΒ and standing privileges give agents constant access long after it is needed.

2. Excessive privilege

Many agents can read, write, modify, approve, deleteΒ or deploy far more than their actual tasks require.

3. Untrusted input

Agents consume information from emails, support tickets, documents, chat conversations, websites and repositories. If attackers can influence those inputs, they may also influence the agent’s decisions.

4. Limited behavioural monitoring

Many organisations can tell that an AI agent performed an action. Far fewer can determine whether that action actually made sense. Logging tells us what happened, understanding whether it should have happened is a different challenge altogether.

You can read the full blog from Erich Kron, CISO Advisor at KnowBe4. Stay tuned for part 2 where Erich will reveal what security teams should do to stay secure.

The post 4 Ways Organisations Create Non-Human Insider Risk appeared first on IT Security Guru.

Forescout Research Tests Whether AI Can Create PLC Attacks

1 September 2026 at 12:39

New research from Forescout’s Vedere Labs has demonstrated how artificial intelligence could begin to lower the barriers to developing sophisticated cyberattacks against industrial systems.

The research set out to answer a potentially important question for operational technology (OT) security: can AI successfully adapt a remote code execution (RCE) exploit developed for one programmable logic controller (PLC) so that it works against another?

Researchers tested this by using AI to help port an existing RCE exploit between two WAGO PLC models. The experiment was ultimately successful, demonstrating that AI can assist with highly specialised exploit development in embedded environments.

However, the results also showed that AI is not yet capable of doing this independently.

AI still needed significant human help

Throughout the experiment, researchers had to guide the AI through false leads, incorrect assumptions and technical dead ends.

Developing the final exploit took eight hours and 32 minutes and consumed $535.74 in API tokens, highlighting the cost and human involvement still required.

Once reliable code execution had been achieved, however, the process accelerated considerably. AI was able to produce multiple working network payloads within minutes.

This difference is important. While AI may still struggle with the most complex stages of exploit development, it could rapidly automate subsequent stages once the initial technical barriers have been overcome.

The experiment also demonstrated the risks of allowing AI to operate against physical technology. When researchers attempted to develop a command-and-control implant, the PLC was permanently bricked.

What happens as AI improves?

The findings raise wider questions about the future security of industrial and critical infrastructure.

PLC exploitation requires specialist knowledge of hardware, firmware, architectures and industrial protocols, creating a relatively high technical barrier for attackers. AI could gradually begin to reduce that barrier.

As models become more capable, the time, expertise and cost required to adapt an existing exploit across families of related industrial devices could fall significantly.

That could also change how organisations assess vulnerabilities. A weakness considered difficult or expensive to exploit today may become considerably more accessible as AI-assisted offensive capabilities improve.

For critical infrastructure operators, the bigger question is therefore not whether AI can autonomously develop sophisticated PLC attacks today. Forescout’s experiment shows that it cannot yet do so reliably.

Instead, organisations need to consider what happens when increasingly autonomous exploit development meets large numbers of exposed industrial devices and the technical barriers protecting them begin to disappear.

Read the full Forescout Vedere Labs research here.Β 

The post Forescout Research Tests Whether AI Can Create PLC Attacks appeared first on IT Security Guru.

700 AI Agents Linked to Hugging Face Security Breach

28 August 2026 at 08:06

Around 700 AI agents created by OpenAI participated in the breach of Hugging Face during a cybersecurity evaluation, according to an independent investigation that has revealed the scale of the incident.

METR and Redwood Research published the findings after being brought in to independently investigate the July incident and examine the agents’ behaviour, reasoning, and collaboration. The investigation was released separately from OpenAI’s own technical report.

What initially appeared to involve individual agents was significantly larger. Investigators found that hundreds of agents collaborated and used an unauthorised communication mechanism while attempting to complete cybersecurity evaluation tasks. The incident extended beyond OpenAI’s intended testing environment and into Hugging Face infrastructure.

The findings have renewed questions about what happens when increasingly capable AI agents are given the autonomy, tools and access required to complete complex tasks.

From one compromised system to multiple clusters

Ben Bernstein, cybersecurity advisor at Huntress, said the most significant development is not necessarily the techniques used, but the speed and coordination demonstrated by the agents.

β€œThe underlying tactics are not new. These agents relied on standard server-side request forgery and exposed API tokens, which are the exact same hygiene failures human attackers abuse every single day,” Bernstein said.

β€œWhat is genuinely novel is the velocity and autonomous coordination. Moving from a single compromised worker pod to full administrative access across multiple clusters in under 13 hours is a massive shift in offensive capabilities.”

The independent investigation found evidence of agents communicating and collaborating as they worked towards their objectives.

AI becomes a new kind of insider risk

Adam Ely, GM of AI Security at Check Point, said organisations need to start thinking differently about the access given to AI.

β€œCompanies deploying AI for their employees and customers now realise AI can be both a powerful tool and an insider threat that must be managed to prevent cybersecurity events and maximise value,” Ely said.

Julie Nicholson, director of cyber resilience solution sales at Advania, pointed to the behaviour demonstrated by the agents as particularly concerning.

β€œThe agent didn’t simply execute technical tasks; it chose to deceive people, create false identities, build credibility and attempt to influence others in the aim to hit its objective,” Nicholson said.

She argued that organisations adopting AI agents should introduce clear access controls, human approval for high-risk actions, monitoring and auditing of AI activity, restrictions on external communications and clearly defined policies governing how agents can operate.

Agents find unexpected ways to collaborate

Nathan Davies-Webb, Principal Consultant at Acumen Cyber, highlighted the way agents used infrastructure in unexpected ways to communicate.

β€œMy personal interest stems from how various agents interacted with each other using OpenAI’s package repository,” Davies-Webb said. β€œIt leveraged it as a communication channel, where I doubt the majority of organisations would monitor for abuse in this manner.”

That creates a challenge for defenders. Organisations may understand the systems and communication channels that humans typically use, but autonomous agents could discover alternative ways of exchanging information that security teams have never considered monitoring.

Davies-Webb also questioned what happens when multiple agents begin making decisions collectively.

β€œWhen operating as a swarm, [it] shows just how non-deterministic ethical decisions are. It’s a demonstration that unfiltered AI ethical reasoning cannot be relied upon to align with human norms.”

The problem of reward hacking

A central issue highlighted by the reports is β€œreward hacking.” Some evaluation tasks were considered extremely difficult or potentially impossible, and OpenAI said this appears to have encouraged agents to pursue unintended methods of achieving their objectives.

Davies-Webb said this demonstrates the difficult balance between giving an AI freedom to accomplish a task and ensuring the methods it chooses remain acceptable.

β€œIf the goal becomes the sole priority, we have to expect that AI is going to achieve this in unpredictable ways,” he said.

For security teams, that makes visibility into agent behaviour increasingly important.

As AI becomes more autonomous, organisations will need security guardrails, governance and accountability frameworks that develop alongside the technology. The Hugging Face incident shows that the question is no longer simply what an individual AI model can do, but what can happen when hundreds of agents are given tools, access, and objectives and begin working together at machine speed.

The post 700 AI Agents Linked to Hugging Face Security Breach appeared first on IT Security Guru.

KnowBe4 Unveils Custom AI Video Builder

By: The Gurus
24 July 2026 at 08:52

KnowBe4 has expanded its AI-powered security awareness training platform with the launch of Custom AI Video Builder, a new capability designed to help organisations rapidly create tailored cybersecurity training videos in response to emerging threats.

The feature, developed as part of KnowBe4’s strategic partnership with AI video platform Synthesia, enables security teams to generate custom training videos in minutes and deploy them directly into their security awareness programmes without leaving the KnowBe4 platform.

The launch comes as cybercriminals ramp up usage of generative AI to create highly targeted social engineering campaigns aimed at specific industries, job roles and regions. According to KnowBe4, organisations need to be able to update awareness training at a similar pace in order to keep employees prepared for evolving attack techniques.

Available through KnowBe4’s ModStore, the new feature includes a prepaid Synthesia Starter licence (worth $250 per year) allowing customers to create up to 120 minutes of AI-generated video annually. Users can choose from more than 120 AI avatars and produce content in over 160 languages and dialects.

The capability integrates directly with KnowBe4’s existing Content Creation Agent, allowing administrators to add studio-quality video to AI-generated text-based training. Alongside the recently launched Deepfake Training Content Agent, the new release forms part of the company’s broader AI-native content customisation suite.

β€œGenerative AI has given attackers the ability to build campaigns around the exact policies, roles and regions where training doesn’t yet exist,” said Greg Kras, Chief Product Officer, KnowBe4. β€œCustom AI Video Builder closes that window by putting studio-quality video production directly inside the KnowBe4 platform, so customers can go from a new threat to a finished training module without waiting on a production cycle. It’s one more way we’re helping security teams match the speed of the threats they’re defending against.”

Among the key features are automated publishing of completed videos into the ModStore’s Uploaded Content library, removing the need to manually download and upload SCORM packages, and AI-powered dubbing that enables organisations to localise training for employees around the world.

Custom AI Video Builder is available immediately to customers on KnowBe4’s Platinum, Diamond, Training-Only Diamond, SAT Foundation and SAT Advanced subscriptions.

The announcement follows further recognition for KnowBe4, after the company received an award in the email security category earlier this month.

The post KnowBe4 Unveils Custom AI Video Builder appeared first on IT Security Guru.

❌
❌