Skip to content Skip to sidebar Skip to footer

Why AI Code-Patching Agents Often Mislead Security Metrics — and How to Automate Safe, Verifiable Fixes

What Happened Recent evaluations of AI-driven code-patching agents exposed methodological and operational weaknesses that produce misleading headline results and hidden security risk. A reanalysis of a high-profile patching benchmark shows that restrictive protocols and skewed samples produced an exaggerated failure rate; when agents were allowed to run code and not instructed to apply wrong fixes,…

Read More

Use Behavioral Clustering on Cloud Audit Logs to Find Risky Identities — and Turn Detections into SQL-First Alerts

What Happened Unit 42 published a practical detection pattern that maps cloud identity behavior by clustering audit-log activity and converting those behavioral patterns into standard SQL queries for continuous threat detection. The method uncovers anomalous or risky accounts by grouping identities by role-like behavior and operationalizing those groups as repeatable, queryable detections rather than one-off…

Read More

Stop AI-Assisted Invoice Fraud and Service-Identity Spoofing: Practical Defenses for Email and Workload Identities

What Happened Two recent security research streams illustrate converging AI-assisted and infrastructure-level threats. First, Microsoft observed a large-scale AI-assisted executive-impersonation campaign that sent over one million malicious emails impersonating CEOs/CFOs to induce ACH payments using fabricated invoices and third‑party mail services; artifacts pointed to template reuse and generative‑AI signatures in message content and HTML structure…

Read More

Prevent Cloud App Takeovers and Identity-Driven Exfiltration — Practical Defenses for Web, Serverless and CI/CD

What Happened Recent defensive research and incident investigations show three converging patterns attackers use to compromise cloud-hosted web and serverless applications: mapped technique sets targeting cloud web apps, identity‑first social engineering that enables broad Graph/mail/Drive collection, and commodity third‑party infrastructure abused to blend in and evade tracing. Microsoft published a Cloud Web Applications…

Read More

Secure Edge AI: Prevent Prompt Injection, Model Tampering and Data Exfiltration in Customer‑Owned Environments

What Happened Research across the AI security community has converged on a concrete set of vulnerabilities that become critical when models and tooling run on customer‑owned edge infrastructure: prompt injection, poisoned retrievals, model tampering, malicious firmware and supply‑chain compromises, and expanded attack surface from agents and tool integrations. These findings emphasize a shifted trust model—customers…

Read More

How AI-Assisted Attackers Evade Detection — and Practical Defenses Every Business Must Deploy

What Happened Recent security research and incident telemetry show three converging trends attackers are using to increase success and scale: obfuscation to bypass content defenses, AI-assisted data theft at scale, and social‑engineering that leverages legitimate collaboration tooling for hands‑on compromise. Obfuscation adapted from prompt injection to phishing A high‑volume phishing campaign used invisible Unicode Tag…

Read More

How AI-Driven Agentic Attacks and Deceptive Installers Break Networks — Practical Defenses for Enterprises

What Happened Two recent investigations illustrate complementary modern threats: autonomous, agentic adversaries that rapidly discover and exploit network weaknesses, and sophisticated counterfeit-software delivery campaigns that gain persistent, privileged footholds. Unit 42 documented an attack where autonomous AI agents accelerated network compromise, chaining reconnaissance, exploitation and lateral movement into an automated campaign that breached…

Read More

AI Security & Cybersecurity — September 1, 2026

What Happened Over the last three years independent security teams (Project Zero, Trail of Bits, Unit 42), specialist AI-security vendors (HiddenLayer, Lakera, Protect AI), and standards projects (OWASP AI, MITRE ATLAS) have published coordinated defensive research identifying recurring AI vulnerabilities and real-world exploit techniques. Their work documents attacks across the ML lifecycle: data poisoning and…

Read More

How AI-Driven Attackers Exploit Collaboration Platforms and Models — Practical Defenses for Enterprises

What Happened Unit 42 documented a voice-phishing (vishing) campaign — dubbed "Spring Ring" — that abused Microsoft Teams calling features to impersonate trusted internal contacts, socially engineer employees, deliver malware, and escalate to domain controllers, enabling broad network compromise [1]. The campaign leveraged platform-native trust signals (caller identity, in-app presence) to bypass traditional email-centric defenses…

Read More

How to Detect and Stop Stealth Reverse‑Tunnel Intrusions — Lessons from the TerminalFix Campaign

What Happened Microsoft observed a multistage intrusion campaign (TerminalFix / ClickFix variant) that combined social engineering, signed‑binary abuse, steganography and a Python‑based reverse tunnel to enable silent pivoting and reconnaissance inside target networks [1]. Initial access: victims were lured to paste a malicious PowerShell command from a fake Cloudflare Turnstile CAPTCHA; that command…

Read More

Why LLM Internal Safety Can Be Fragile — and How to Harden Production AI with Defense-in-Depth

What Happened Unit 42 introduced a diagnostic called perturbation probing and used it to show that safety refusals in large language models are often concentrated in a thin, localized neural layer rather than distributed across the model. The practical takeaway is that internal model defenses (the model's own refusal behavior) can be highly brittle: small…

Read More

AI Security & Cybersecurity — August 27, 2026

What Happened Microsoft announced expanded security and governance controls aimed at organizations deploying AI agents and integrating third‑party telemetry. Key points include: Extended managed detection and response: Microsoft Defender Experts MDR (P2) now ingests third‑party data through Microsoft Sentinel, enabling 24/7 MDR and threat hunting across non‑Microsoft sources such as Palo Alto Networks,…

Read More