AI · 161 giorni fa
Security teams are now facing a combined input-output problem. AI-written code increases the volume of code that needs review, and indirect prompt injection turns ordinary web content into a way to poison AI agents that read it. The standard response of trusting the model or adding a quick review step misses that both sides of the pipeline can be manipulated.
ProjectDiscovery says only 38% of cybersecurity practitioners feel they are keeping up with the AI-driven code load, and nearly 60% say review is getting harder. Google says indirect prompt injection is a top priority and that it swept the public web for known patterns, because AI systems can silently follow malicious instructions embedded in websites, email, or documents. The report also shows defenders are most worried about corporate secrets, unreliable dependencies, and business logic flaws in AI-generated code.
The risk is not just more bugs. It is more untrusted input reaching both code and agents at machine speed, which raises the odds of poisoned instructions and exploitable application logic landing in the same environment.
11 fonti che coprono questa storia
3 Reasons to Attend Rapid7's Global Cybersecurity Summit: AI, Threats, and Exposure Management
Security teams are dealing with a different kind of pressure now. Threats move across identity and cloud in ways that are difficult to track, exposure data exists but often sits disconnected from response, and AI is being introduced into workflows without a clear role in decision-making. This year’s Rapid7 Global Cybersecurity Summit brings those threads together as part of the same operational solution.
AI is speeding up nation-state cyber programs - Help Net Security
Microsoft's Kaja Ciglic on how nation state cyber programs now drive sanctions evasion, crime, and statecraft across global security fronts.
AI threats in the wild: The current state of prompt injections on the web
We initiated a broad sweep of the public web to monitor for known indirect prompt injection patterns.
AI-written software creates hassles for wary security teams
A new report explains what cybersecurity practitioners need to see before they trust AI coding tools.
UK's NCSC flags widening gap between cyber threats and national resilience, urges action as AI fuels rise in disruptive attacks.
No Exploit Needed: How Attackers Walk Through the Front Door via Identity-Based Attacks
Stolen credentials remain top breach vector as AI speeds phishing and testing, increasing ransomware and persistence risk.
Automation at Machine Speed: Rethinking Execution in Modern Cybersecurity
Machine-speed threats demand machine-speed defense—see how AI and automation cut dwell time and outpace attackers.
Commercial AI Models Show Rapid Gains in Vulnerability Research
AI models are making rapid gains in vulnerability research and exploit development, raising new cybersecurity risks, a Forescout study finds
Your Next Breach Will Look Like Business as Usual
These are the fundamental detection model shifts cybersecurity teams need to make to keep up with the rising number of credential-based attacks.
The New Rules of Engagement: Matching Agentic Attack Speed
The cybersecurity response to AI-enabled nation-state threats cannot be incremental. It must be architectural.
As breakout time accelerates, prevention-first cybersecurity takes center stage
Threat actors are using AI to supercharge tried-and-tested TTPs. When attacks move this fast, cyber-defenders need to rethink their own strategy.
Part of the PlainSec briefing for 2026-04-25