The risk of guardrail-free AI isn’t a future concern — it’s a current-day threat. Researchers from ThreatDown discovered the AI tools that fuel today’s cyber incidents are increasingly open, mainstream and challenging to monitor. The first major finding from the research is that AI without guardrails has become mainstream. Some may assume that malicious AI is exclusively ..
Categoria : Security
Gli attacchi informatici si sviluppano ormai con una rapidità che lascia alle organizzazioni margini decisionali sempre più ridotti. In una crisi cyber, sapere che cosa fare, chi deve intervenire e quali attività proteggere per prime può determinare la portata dell’impatto operativo. La consapevolezza del rischio, tuttavia, non è sufficiente. Un’impresa può investire in tecnologie avanzate ..
Il codice generato dall’AI ha smesso di essere una curiosità da laboratorio ed è entrato nel flusso di lavoro quotidiano di gran parte degli sviluppatori, spesso senza che l’organizzazione se ne sia accorta davvero. La promessa è evidente e reale: scrivere più in fretta, delegare le parti ripetitive, abbassare la barriera d’ingresso a chi programma ..
Zenity Labs has found and disclosed a critical vulnerability in OpenAI’s ChatGPT Workspace Agents, which it names AgentForger; a tailored cross-site request forgery (CSRF). With a single successful phish, an unsuspecting employee could be tricked into launching an invisible autonomous agent that is remotely controlled by the attacker. Zenity explains in two blogs (Part 1 ..
On July 14, 2026, the White House launched Gold Eagle: a federal clearinghouse that uses frontier AI to identify, rank, and coordinate the remediation of software vulnerabilities across government and critical infrastructure before attackers reach them. Bringing together the Treasury, DHS, DoD, open-source software partners, and operators of American critical infrastructure, Gold Eagle’s engine relies ..
Hackers have stolen tens of millions of records from AI music generator Suno and gig-work platform Paidwork, according to data breach notification service Have I Been Pwned (HIBP). Suno was targeted in November 2025, and the intrusion came to light earlier this month, when 404 Media reported that hackers had obtained source code and user ..
Palo Alto Networks (NASDAQ: PANW) on Tuesday announced its intent to acquire Embrace, a provider of user-focused observability, in a move to add Real User Monitoring (RUM) capabilities to its Observability platform. Financial terms of the deal were not disclosed. Alongside the acquisition, the company introduced Synthetics, a new capability developed in-house by its Autonomous ..
A highly popular Chrome extension made by Adobe was affected by a vulnerability that could have been exploited to silently steal a user’s WhatsApp chats and contacts. According to web and browser security firm Guardio, whose researchers discovered and reported the vulnerability to Adobe, an attacker could have stolen users’ WhatsApp data simply by tricking ..
For years, organizations have encouraged users to enable multi-factor authentication (MFA), use one-time passwords (OTPs), and protect their accounts with passcodes. Those controls remain important. However, a recent attack against my own wireless services account demonstrated that point-in-time authentication is no longer sufficient against determined identity-focused adversaries. What began as a seemingly routine customer service ..
Vibe-coding is increasing. Vibe-coded apps tend to be buggy. Is this a worrying sign for the future? Vibe coding, the use of AI to assist or perform code generation, is increasing dramatically. In May 2026, Hostinger reported, “90% of developers regularly use at least one AI tool at work as of January 2026.” This is ..


