AI compliance issues hit 2 in 5 large companies, and legacy workflows are a big factor

Forty percent of large companies had an AI-related compliance or governance issue in the past 12 months, according to 1,000 senior IT, operations, and transformation leaders surveyed by Sapio Research. Those leaders said process-related problems contri… Continue reading AI compliance issues hit 2 in 5 large companies, and legacy workflows are a big factor→

Android apps can now check security patches down to individual device components

New AndroidX Security State libraries provide a more granular way to determine how securely patched an Android device is. The stable Security State v1.1.0 and Security State Provider v1.0.0 libraries allow developers to check the security status of ind… Continue reading Android apps can now check security patches down to individual device components→

Hardcoded MCP credentials found in public GitHub files

Hardcoded API keys, access tokens and other credentials used by AI coding tools have been found in publicly accessible MCP configuration files on GitHub, according to research from Hush Security’s The State of MCP Configuration: The Identity Security G… Continue reading Hardcoded MCP credentials found in public GitHub files→

98% of fraudulent hires have company credentials by the time they’re caught

A 90-day period between hiring and onboarding is creating a blind spot in enterprise identity security, according to HYPR’s State of HR Identity Fraud Detection report. “Adversaries no longer need to breach a network when they can pass a remote intervi… Continue reading 98% of fraudulent hires have company credentials by the time they’re caught→

New infosec products of the week: September 18, 2026

Here’s a look at the most interesting products from the past week, featuring releases from Akuity, Bitsight, Cohesity, Dataminr, Nozomi Networks, and Tuskira. Dataminr uses agentic AI to predict and verify security threats Dataminr has announced Datami… Continue reading New infosec products of the week: September 18, 2026→

A fake ChatGPT billing email is after your OpenAI password

A fake ChatGPT billing email is steering users to a copy of the OpenAI login page that keeps whatever username and password they type. Josh Varden of Cofense’s Phishing Defense Center traced the email’s payment button through a Google redir… Continue reading A fake ChatGPT billing email is after your OpenAI password→

Google’s new agent security system detects tool misuse, loops and rogue behavior

Google’s Agent Anomaly Detection is a reasoning-based oversight and audit layer for autonomous agents deployed on Agent Runtime in the Gemini Enterprise Agent Platform and built with the Agent Development Kit (ADK) for Python 1.2 or later. Google recom… Continue reading Google’s new agent security system detects tool misuse, loops and rogue behavior→

Fake AI trading agent steals crypto wallet passwords

Attackers built a website for a fake AI crypto trading agent and used it to install Needle Stealer, malware that replaces a victim’s browser wallet with a copy that sends the wallet password to the attacker. HP caught the campaign between April a… Continue reading Fake AI trading agent steals crypto wallet passwords→

One runaway AI agent racked up a $50,000 cloud bill

Organizations are deploying autonomous AI systems that execute API calls, optimize production configurations, and analyze telemetry across hybrid cloud environments. At the same time, attacks are expanding from direct prompts to indirect prompt injecti… Continue reading One runaway AI agent racked up a $50,000 cloud bill→