Data exfiltration stories
Misconfigured test setups let three Claude models touch live systems, exposing production data and credentials during security exercises.
Defenders now face a 48-hour window after proof-of-concept code appears, as attackers use AI to speed exploits and hit software chains.
Undisclosed attacks now dominate ransomware activity, with 2,027 incidents logged in the quarter and data theft reported in 97% of disclosed cases.
Faster digital payments are leaving fintech firms exposed as regulators and attackers pressure weak controls and resilience across the sector.
Many AI agents can already reach far more sensitive corporate data than staff, prompting Bedrock Data to add real-time access controls.
Organisations face a growing risk of silent data theft as criminals exploit cloud identities and credentials for extortion instead of encryption.
Malicious packages are now spreading faster across code repositories, with Google saying open source ecosystems face the sharpest rise in risk.
It aims to close a security gap as firms grapple with prompt injection and shadow AI across existing firewall estates.
Proofpoint says underground forums are advertising tools that use indirect prompt injection across emails, PDFs, calendar invites and web pages.
KnowBe4 has backed the Open Secure AI Alliance, arguing AI security depends on governing agent behaviour as well as models.
Greater exposure to remote attacks is worrying carmakers, as high-severity automotive cybersecurity flaws jumped to 161 in the second quarter.
Email fraud is now the top incident type, accounting for 45% of cases as attackers bypass multi-factor authentication with stolen credentials.
Security experts warn defences are lagging after an AI system allegedly escaped testing and stole credentials in a live breach.
Supply chain attacks are pushing cyber risk upstream, putting managed service providers under pressure from customers and regulators over shared access.
Customers face heightened scam risks as Origin Energy investigates claims that a hacker accessed two million records and alerted regulators.
The new controls aim to stop unauthorised tool calls, data leaks and prompt injection as firms deploy more autonomous software.
Security teams can now map hidden AI agent links on employee devices to spot overprivileged tools before they expose data or credentials.
Security chiefs face a widening breach risk as most firms plan to use AI agents, yet barely a third feel ready to secure them properly.
Mid-market firms in financial, insurance and consulting services face the highest ransomware risk, with attacks now striking faster and costing far more.
Data theft and repeat extortion are hitting Australian businesses harder as AI helps attackers make ransomware lures more convincing.