15 Sources
[1]
Rolling out AI? 5 security tactics your business can't get wrong - and why
Professionals must develop tactics to embrace AI without risk. The same capabilities that make AI useful also make it exploitable. In fact, the rate at which emerging technologies are advancing intensifies that uncomfortable reality by the minute. While professionals might not want to expose
[2]
Open-Source CyberStrikeAI Deployed in AI-Driven FortiGate Attacks Across 55 Countries
The threat actor behind the recently disclosed artificial intelligence (AI)-assisted campaign targeting Fortinet FortiGate appliances leveraged an open-source, AI-native security testing platform called CyberStrikeAI to execute the attacks. The new findings come from Team Cymru, which detected its
[3]
CyberStrikeAI tool adopted by hackers for AI-powered attacks
Researchers warn that a newly identified open-source AI security testing platform called CyberStrikeAI was used by the same threat actor behind a recent campaign that breached hundreds of Fortinet FortiGate firewalls. Last month, BleepingComputer reported on an AI-assisted hacking operation that
[4]
Why enterprise AI agents could become the ultimate insider threat
Agent sprawl could mirror the VM explosion era.Excessive agent agency increases breach blast radius.Treat AI agents like employees with credentials. Ever since October, I've been happily vibe-coding a series of apps using Claude Code. Every so often, I would give them an instruction, and they
[5]
AI threats will get worse: 6 ways to match the tenacity of your digital adversaries
Experts recommend best practices for avoiding catastrophe. When was the last time you wondered if that mysterious phone caller who hung up after you answered "hello" made a recording of your voice in a way that could be used against you? The FCC warned us about such scams nearly a decade ago,
[6]
AI powers innovation - but it's also powering the next wave of cyber attacks
Achieving cyber resiliency in the face of AI-powered cyber attacks According to the National Cyber Security Centre (NCSC), the UK is experiencing four 'nationally significant' cybersecurity attacks every week. A record 204 nationally significant attacks were handled by the NCSC in the year to
[7]
AI Tools Are Supercharging Hackers
Can't-miss innovations from the bleeding edge of science and tech It's no secret that AI models have come a long way, from tools that can complete high school students' homework to "vibe coding" assistants that can build entire apps in a fraction of the time it would take for human
[8]
Will AI make cybersecurity obsolete or is Silicon Valley confabulating again?
Can you trust the companies that are building AI to make the technology safe for the world to use? That is one of the most pressing questions you face this year as a user of AI, and it is not an academic question. As real-world deployments of the technology proliferate, novel kinds of risks are
[9]
'The total industrialization of cyber threats': Cloudflare report outlines how hackers are 'weaponizing the Internet'
Cloudflare says there is a "fundamental rewiring of the modern cyberattack" going on * Cloudflare warns GenAI is reshaping cyberattacks * Report highlights AI-driven supply chain and espionage threats * DDoS and social engineering form critical attack trio Generative Artificial Intelligence
[10]
Zero Trust World 2026 - don't trust AI to secure your business or replace your juniors, warns ThreatLocker CEO
ThreatLocker CEO Danny Jenkins is in ebullient if edgy mood, as well he might be just minutes after delivering a complex keynote on Day Two of the Zero Trust World conference in Orlando. The entertaining, hour-long presentation, in tandem with with sidekick and Chief Product Officer Rob Allen, saw
[11]
Hackers are turning to easy, fast AI solutions to roll out attacks - so how can your business stay safe?
* Cybercriminals leverage GenAI to accelerate attack creation * Campaigns prioritize speed and scale over sophistication * Report shows basic tactics still bypass defenses Cybercriminals are "vibe-hacking" their way into enterprise environments, using Generative Artificial Intelligence (GenAI)
[12]
Zero Trust World 2026 - cybercrime is world's third largest economy, says ex-White House CIO. Who's to blame?
First the good news - for AI vendors. Every minute of every day, $1.21 million is spent on AI, up 312% year on year, valuing the global market at $630.72 billion, by my calculations. Also in every minute, 1.9 million AI chips are sold, thirty-five custom AI agents are created, and 23,611 images are
[13]
Automating More Security Decisions Key To Keeping Up With AI Attacks: Experts
Many security decisions may need to be automated in a way that many organizations have thus far been uncomfortable with -- due to the risk of business disruption, experts tell CRN. While AI and agentic capabilities are transforming how cyber defense is done, it's widely recognized that the same is
[14]
AI innovation itself introduces new attack vectors: Philippa Cogswell of Palo Alto Networks
Philippa Cogswell, Managing Partner, JAPAC, Unit 42, Palo Alto Networks AI has reduced the cost of launching sophisticated cyberattacks. Coordinating an attack, which earlier took weeks, can now be automated and executed in a matter of hours. This means that even attackers with limited skillsets
[15]
'Cybersecurity response is moving slower than AI adoption, creating more issues'
The rapid pace of AI adoption has magnified the structural weaknesses within the cybersecurity industry. Tool sprawl and fragmented security layers have created a huge vulnerability gap and are hindering the ability to deal with emerging threats triggered by rapid AI adoption. According to Gartner,
Share
Copy Link
An open-source AI security testing platform called CyberStrikeAI was used to breach over 600 Fortinet FortiGate devices across 55 countries in a sophisticated AI-powered attack. Meanwhile, enterprise AI agents are emerging as potential insider threats, with rogue agents capable of accessing credentials, modifying databases, and initiating unauthorized communications on behalf of companies.
An unknown threat actor recently leveraged an open-source security tool called CyberStrikeAI to execute AI-powered attacks targeting Fortinet FortiGate appliances, compromising over 600 devices across 55 countries
2
. The campaign, which utilized generative AI services like Anthropic Claude and DeepSeek, represents a concerning evolution in how threat actors are deploying offensive AI security tools to automate and scale their operations2
.
Source: Hacker News
Team Cymru researchers traced the attacks to IP address 212.11.64[.]250, which was observed running CyberStrikeAI on port 8080 and communicating with targeted FortiGate devices
3
. The open-source security tool, built in Go and integrating over 100 security tools, enables automation from conversational commands to vulnerability discovery, attack-chain analysis, and result visualization2
. Between January 20 and February 26, 2026, researchers identified 21 unique IP addresses running CyberStrikeAI, with servers primarily hosted in China, Singapore, and Hong Kong3
.While external AI threats escalate, enterprise AI agents are creating new AI security risks from within organizations. These autonomous agents, designed to handle tasks like procurement, communications, and database management, can become the ultimate AI insider threat when they malfunction or are compromised
4
. Unlike external attackers who must breach defenses, rogue AI agents already possess credentials and access to spend money, modify files, and initiate communications on behalf of companies4
.Recent incidents illustrate these AI security risks. In 2022, an Air Canada chatbot promised a discount that wasn't available, leading to a lawsuit the company lost
4
. In 2025, an AI hiring bot exposed personal information from millions of McDonald's job applicants, with the AI company reportedly using the password 1234564
. Security researchers also demonstrated that a prompt-injection attack could expose Salesforce's CRM platform to potential data theft4
.Vulnerabilities in widely-used platforms underscore the scope of the problem. ServiceNow AI Platform contained a flaw allowing unauthenticated users to impersonate authenticated users and drive privileged agentic workflows
4
. Amazon Q's VS Code extension suffered a GitHub token error enabling malicious code injection directly into repositories4
. OpenAI's Codex CLI coding agent was found vulnerable to attacks where embedded harmful instructions in project files could trigger malicious commands on developers' machines4
.Google's Threat Intelligence Group documented a significant shift in how adversaries exploit AI capabilities. While threat actors initially used Gemini for basic productivity tasks like research and troubleshooting code, they now deploy AI-enabled malware in active operations
5
. This marks a new operational phase involving tools that dynamically alter behavior mid-execution5
.
Source: Futurism
Anthropic detected a professional influence-as-a-service operation using Claude not just for content generation, but to decide when social media bot accounts would comment, like, or re-share posts from authentic users
5
. The company also observed credential stuffing operations, recruitment fraud campaigns, and novice actors using AI to enhance their technical capabilities for malware generation beyond their skill level5
.Deepfake technology represents another escalating concern. ByteDance's Seedance 2.0 launch demonstrated video generation capabilities so convincing that distinguishing deepfakes from authentic content becomes nearly impossible
5
. Voice cloning now requires as little as three seconds of audio to replicate someone's voice and conversational tone5
.Related Stories
Business leaders emphasize that effective AI security governance requires cross-functional collaboration. Barry Panayi, group chief data officer at Howden, noted that cybersecurity knowledge must extend beyond IT specialists, with professionals across all roles understanding AI security risks
1
. The multifaceted nature of AI cybersecurity demands new roles and responsibilities, with teams sharing knowledge to create more powerful mitigation strategies1
.
Source: CRN
Nick Pearson, CIO at Ricoh Europe, stressed that managing cybersecurity in an age of AI requires returning to fundamentals: secure by design, established standards, and teams that analyze and balance capabilities
1
. Rather than creating separate frameworks for AI, organizations should integrate AI into existing data governance structures that address issues like data leakage1
.Martin Hardy, cyber portfolio and architecture director at Royal Mail, highlighted the importance of AI governance forums that don't stop AI usage but ensure appropriate oversight
1
. Understanding where data resides and what data feeds AI solutions is key to success, as is recognizing that AI serves as an aid rather than a complete answer1
.John-David Lovelock, chief forecaster at Gartner, noted that organizations cannot yet benefit from measurable, definable, and certifiable AI safety standards
1
. End-user security requirements remain unmet by many AI providers, creating a gap between expectations and reality1
.The CyberStrikeAI developer, who goes by the alias Ed1s0nZ, has published several tools demonstrating interest in exploitation and jailbreaking AI models
2
. The developer's GitHub activities indicate interactions with organizations supporting potentially Chinese government state-sponsored cyber operations, including Chinese private sector firms with known ties to the Ministry of State Security2
. References to receiving a CNNVD 2024 Vulnerability Reward Program award were later scrubbed from the developer's profile3
.As adversaries increasingly embrace AI-native orchestration engines, defenders must prepare for environments where tools like CyberStrikeAI significantly lower the barrier to entry for complex network exploitation
3
. The combination of automation, generative AI capabilities, and integrated security tools enables even low-skilled operators to execute sophisticated attacks3
.Summarized by
Navi
[2]
[3]
02 Jan 2026•Technology

20 Feb 2026•Technology

19 May 2026•Technology

1
Science and Research

2
Technology

3
Technology
