#AIsecurity

AI MCP servers have a glaring security hole: long-lived, static credentials are putting data, code, and production systems at risk. jpmellojr.blogspot.com/2025/10 #AIsecurity #CredentialSecurity #MCP #APISecurity #SecretsManagement #Astrix

Annual Computer Security Applications ConferenceACSAC_Conf@infosec.exchange
2025-10-16

First up in the session was Yadav & Wilson's "R+R: Security Vulnerability Dataset Quality Is Critical" which revealed the impact of dataset issues on LLMs in vulnerability detection. (acsac.org/2024/program/final/s) 2/6
#AIsecurity #LLM #Cybersecurity

Yadav & Wilson's "R+R: Security Vulnerability Dataset Quality Is Critical"
2025-10-16

Join Recon and SideChannel for a 𝘯𝘰-𝘩𝘺𝘱𝘦, 𝘱𝘪𝘵𝘤𝘩-𝘧𝘳𝘦𝘦, 𝘱𝘳𝘢𝘤𝘵𝘪𝘵𝘪𝘰𝘯𝘦𝘳-𝘭𝘦𝘷𝘦𝘭 conversation about AI cybersecurity 📆 Wed, Oct 22nd. 𝗥𝗲𝗴𝗶𝘀𝘁𝗲𝗿 𝗻𝗼𝘄: reconinfosec.com/events/buildi #AISecurity #Cybersecurity #SecurityOperations #CyberDefense

Xygeni Securityxygeni
2025-10-16

🚀 𝐅𝐢𝐱 𝐒𝐦𝐚𝐫𝐭𝐞𝐫, 𝐁𝐫𝐞𝐚𝐤 𝐋𝐞𝐬𝐬, 𝐒𝐡𝐢𝐩 𝐅𝐚𝐬𝐭𝐞r! Discover what’s new in @xygeni built to help developers remediate faster, automate fixes, and secure the entire

𝐓𝐋;𝐃𝐑: this release is about smarter remediation, better automation, and deeper coverage.

👉 Full changelog: docs.xygeni.io/changelog/versi

2025-10-13

Researchers have found that OpenAI’s new Guardrails can be bypassed using a simple prompt injection, tricking its AI “judges” and allowing harmful outputs

Read: hackread.com/openai-guardrails

#OpenAI #AISecurity #Guardrails #Cybersecurity #ChatGPT

"Jail break prompts"

You are welcome.

#Infosec #aisecurity

2025-10-12

AI có thể bị tấn công 'jailbreak' chỉ bằng một từ, khiến nó bỏ qua các biện pháp bảo vệ. Ngôn ngữ đa dạng và chi phí đào tạo khiến phòng thủ đơn lẻ không hiệu quả. Các nền tảng lớn đang triển khai phòng thủ nhiều lớp. Cảnh giác liên tục là chìa khóa để giữ AI an toàn.
#AISecurity #BảoMậtAI #Jailbreaking #TấnCôngAI #AI #Vulnerability #LỗHổngBảoMật

reddit.com/r/programming/comme

2025-10-11

🧠 Weekly Cyber Wrap-Up:
Cloud & AI security gaps, ransomware takedowns, and government data breaches dominate this week’s headlines.

Experts like Gary Brickhouse and Bob Maley warn: awareness is only step one - true defense comes from resilience and visibility.

💬 What’s your view - is the cybersecurity community keeping up with AI-driven threats?

Follow @technadu for your weekly global cyber intelligence.

#CyberSecurity #Infosec #CyberAwarenessMonth #ThreatIntel #DataBreach #AIsecurity #Ransomware #CloudSecurity #Privacy #DigitalSafety #CyberResilience #TechNadu

Security Gaps, Law Enforcement Wins, and AI Challenges Dominate the Weekly Cyber News
Offensive Sequenceoffseq@infosec.exchange
2025-10-11

🔒 CRITICAL vuln in AI browser agents + 1Password integration: Potential credential leaks if exploited—no patch yet. Restrict agent access, enforce MFA, and monitor for unusual activity. European orgs especially at risk. More: radar.offseq.com/threat/1passw #OffSeq #1Password #AIsecurity

Critical threat: 1Password Addresses Critical AI Browser Agent Security Gap
2025-10-10

🚨 Cybersecurity Weekly Roundup – October 3–10, 2025 🚨

From Cisco’s latest zero-day to AI-powered phishing and Europol’s crackdown on a global phishing network, this week was packed with major developments in the cyber landscape.

🧩 Highlights include:
🔹 Critical Cisco VPN exploit under active attack
🔹 “SteelJack” ransomware targeting manufacturers
🔹 AI-generated phishing adapting in real time
🔹 Apple patches new spyware zero-day
🔹 Quantum-safe encryption gains traction

Each story includes concise expert insights to help you understand the impact and defensive priorities.

👉 Read the full roundup here: 🔗 kylereddoch.me/blog/cybersecur

#CyberSecurity #InfoSec #ThreatIntel #Ransomware #Phishing #AIsecurity #WeeklyUpdate

2025-10-10

Dự án mới: Lớp bảo mật runtime cho các tác nhân AI, hoạt động như một tường lửa. Nó chặn các hành động nguy hiểm như lệnh shell, truy cập file hay gọi mạng trái phép theo thời gian thực, dựa trên các quy tắc tùy chỉnh. Mục tiêu là coi đầu ra của tác nhân AI như dữ liệu người dùng không tin cậy, áp dụng các giới hạn khi chạy. Có demo tương tác và phiên bản Python hỗ trợ LangChain, AutoGPT.

#AISecurity #RuntimeSecurity #AIProtection #BaoMatAI #BaoMatRuntime #AI

reddit.com/r/SideProje

2025-10-10

The lophiid honeypot can now also emulate MCP servers. I just added an example of an MCP server that allows commands to be executed (it emulates them via the build-in LLM shell).

github.com/mrheinen/lophiid/pu

#mcp #llm #aisecurity #dfir #infosec

Just 250 poisoned docs can backdoor a 13B-parameter LLM and no need to control a percentage of the training data! Big models? Small models? Same risk. Time to rethink our defenses. Great work, @anthropic.com, @theturing.bsky.social and UK AI Security Institute. #AISecurity #LLM #Cybersecurity

A small number of samples can ...

2025-10-10

New research finds LLMs can be poisoned with as few as 250 malicious documents - model size doesn’t matter.

Hidden backdoors trigger gibberish or manipulated output.

Details: technadu.com/llm-data-poisonin

#AIsecurity #DataPoisoning #LLM #Anthropic #TechNadu

LLM Data Poisoning Risk: LLMs Can Be Poisoned by Small Samples, Research Shows
NERDS.xyz – Real Tech News for Real Nerdsnerds.xyz@web.brid.gy
2025-10-08

1Password and Browserbase partner to secure credential access for AI agents

web.brid.gy/r/https://nerds.xy

OWASP Foundationowasp@infosec.exchange
2025-10-08

We’re excited to welcome Daniel Miessler as a keynote speaker at OWASP Global AppSec US 2025!

📅 November 3–7, 2025 in Washington, D.C.
👉 Register to attend now: owasp.glueup.com/event/131624/

Daniel is an AI/Security researcher, entrepreneur, and Founder/CEO of Unsupervised Learning. He’s been shaping conversations at the intersection of AI, security, and human impact for more than two decades.

#OWASP #AppSec #Cybersecurity #Infosec #ApplicationSecurity #WashingtonDC #AISecurity

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst