Red Teaming stories
Security teams are reassessing AI access controls after autonomous models exploited an unknown flaw and moved laterally inside a real system.
Security experts warn defences are lagging after an AI system allegedly escaped testing and stole credentials in a live breach.
Security experts warn the breach shows autonomous AI can exploit old misconfigurations at machine speed, widening enterprise identity and containment risks.
The breach highlights how autonomous AI can turn live testing into a real attack path, exposing internal data and credentials.
The breach shows frontier AI can slip its sandbox and probe production systems, raising fresh concerns over containment and oversight.
As attackers use AI to speed up exploits, the security vendor is adding tools aimed at faster testing and vulnerability fixes for partners.
The episode has sharpened concerns that advanced AI systems can uncover and exploit real-world security flaws during testing, even in restricted environments.
The platform lets security teams run AI pentests without exposing customer infrastructure data to external models.
For thousands of banks and payments firms, the trial could help spot software flaws before they disrupt critical financial systems.
Security teams are being warned to keep humans and strict controls in place as AI agents can miss context and leak sensitive code.
Security teams can now trace how one SAP flaw could spread across finance, payroll and supply chains, with access tightly restricted.
AI is speeding up attacks as well as defence, with high-risk prompts and unsupervised agents exposing firms to new security gaps.
The new safety model slashes prompt-injection risks in GPT-5.6, as OpenAI says it found flaws faster than human testers and then fed fixes back into production.
Tests on five models found a planted text string sharply reduced successful AI-led intrusions, cutting full compromise to 1% in an AWS range.
Attackers can now probe Entra ID accounts and passwords at scale without a real app, leaving defenders with little sign-in telemetry.
Security teams are being pressed to prove their defences work in live attacks, as spending scrutiny shifts from tools to real-world response.
Weak public trust and tighter oversight are pushing Australian and New Zealand firms to add live AI security controls before systems go into production.
Security teams may get findings within 24 hours as Cobalt targets faster testing across sprawling software estates.
The incident has heightened fears that frontier AI could outpace safeguards, leaving smaller firms exposed to faster, more autonomous attacks.
Fast-moving corporate systems are outpacing scheduled checks, leaving many firms with security gaps that can persist for days or weeks.