Governance, risk, and compliance for AI.
Classify. Oversee. Prove; before the auditor asks.
AI risk that can be explained to a board and stopped by a person.
Fake AI sites tricked ad account managers into entering login credentials and MFA codes, stealing access to their accounts.
bleepingcomputer.com/news/se…
A former core infrastructure engineer at an industrial company locked thousands of devices on the employer's network, resulting in a ransomware-style attack.
bleepingcomputer.com/news/se…
OX Security went through 15,465 public MCP servers. Six sit on expired domains anyone can buy for $4 to $12 a year. The buyer inherits every agent still set to call that server.
Know which ones yours call?
If an AI model can hack into your infrastructure and modify the audit logs they generated without you noticing, you seriously suck and totally deserve it.
Apple will make macOS Full Disk Access require "very explicit user action."
Reason given: AI agents. Files, mail, messages, browsing history behind one toggle was always a lot. Agents made it louder.
The guy who wrote the launch safety cards quit calling the culture broken the same week the agent review burns half a million a day. Essay and GPU bill are one story.
"We're going to see big incidents." (Michael Sentonas, CrowdStrike)
Same interview: models showing evasion, oversight avoidance, and deception. His fix for agents: kill standing privileges when the task ends.
25,000 Shinhan loan customers, then 119 at KB Kookmin and 89 at Hana. The attackers went for employee and loan-agent systems, not the banking apps. A server tied to the Shinhan attack reportedly hosted an AI pentest console.
koreatimes.co.kr/business/ba…
4 days.
That's how fast attackers exploited a BeyondTrust flaw found by an AI research agent, per Google's threat intel team.
Half of AI-found bugs lead to RCE, versus 26% of the rest.
AI agents hunting 1905 to 1911 divorce records hit a wall at Library and Archives Canada, so 13 of their 899 requests turned into hack attempts.
Nobody has ever wanted genealogy this badly.
theglobeandmail.com/business…
The attempts failed, Ottawa says no sign of compromise, and Transluce/Corridor couldn't definitively tie it to @OpenAI , only to its usual hallmarks.