
Shady AI: The Next Big Governance Problem in Cybersecurity
The increasing use of approved AI tools in unapproved ways is creating a new governance problem for cybersecurity teams, known as 'shady AI'
Every Cybersecurity story tagged Regulation & compliance.

The increasing use of approved AI tools in unapproved ways is creating a new governance problem for cybersecurity teams, known as 'shady AI'

Cybersecurity researchers have disclosed a remote Spectre attack against Cloudflare Workers that leaked a JSON Web Token (JWT) from a co-located Worker in the production environment at up to 12 bits per second.

Cybersecurity researchers have disclosed details of a previously undocumented Python implant framework dubbed TWINLOOT, which abuses SharePoint and Teams to steal credentials and move across networks.

Cybersecurity researchers have discovered a new typosquatting campaign targeting RubyGems users with a Windows-based information stealer. The campaign, dubbed StubMaker, has been tracked by OpenSourceMalware and has been found to harvest browser credentials, cryptocurrency wallets, seed phrases, and Telegram data.

A single attacker has been scraping records from both Salesforce and ServiceNow customer portals across multiple industries for over a year.