← heapsort-ai

cybersecurity

132 items

RESEARCHDEV.to AI·26d ago

The Convergence of Cloud Secrets & AI Risk

The 2025-2026 SentinelOne report identifies the adoption of AI and LLMs as the primary driver of modern cloud risk, with a 140% increase in AI-specific secrets and the rise of "shadow AI." This sprawl creates unique attack vectors like prompt injection and unauthorized data access, while traditional vulnerabilities also facilitate critical cloud compromises.

27
NEWSDEV.to AI·27d ago

Inside CrowdStrike Automated Leads: A Transformative Approach to Threat Detections

CrowdStrike has launched Automated Leads, a new threat detection capability leveraging self-learning AI models within its Signal engine. This system shifts focus from traditional rule-based alerts to prioritizing events based on their aggregate impact on specific hosts, enabling detection of sophisticated adversary behavior and anomalous RMM tool usage.

27
ARTICLEDEV.to AI·4/15/2026

Enterprise AI Security in 2026: A Practical Guide for Modern Organizations

This article discusses how the rapid adoption of artificial intelligence in enterprises necessitates a rethinking of security, as AI systems introduce new attack surfaces not covered by traditional cybersecurity. It addresses challenges such as sensitive data exposure, prompt injection attacks, and model manipulation, emphasizing the need to protect models, data, and decisions in an AI-driven environment.

27
RESEARCHarXiv CS.CL·25d ago

VectraYX-Nano: A 42M-Parameter Spanish Cybersecurity Language Model with Curriculum Learning and Native Tool Use

VectraYX-Nano is a 42M-parameter Spanish language model specifically developed for cybersecurity with a Latin-American focus and native tool invocation. This research details its training from scratch, including a custom 170M-token Spanish corpus, a specific Transformer architecture, and a curriculum learning approach with replay.

27
NEWSThe Verge AI·4/17/2026

Anthropic’s new cybersecurity model could get it back in the government’s good graces

Anthropic's strained relationship with the U.S. government, marked by accusations and ethical red lines regarding surveillance and autonomous weapons, shows signs of improvement. This shift is reportedly due to the company's new cybersecurity-focused AI model, Claude Mythos Preview, which could bring it back into the government's favor.

27
NEWSDEV.to AI·25d ago

Agentic AI Red Teaming Emerges as Defence Against AI-Speed Attack Chains

Sweet Security has launched 'Sweet Attack', a continuous agentic AI red teaming platform designed to counter the growing asymmetry between AI-assisted attackers and human defenders. The platform leverages live runtime telemetry from customer environments to identify genuinely exploitable attack chains, signaling an industry shift towards autonomous AI agents in security.

27
NEWSDEV.to AI·4/9/2026

Anthropic Just Did Something Unprecedented: They Hid Their Best Security Model

A Anthropic desenvolveu o Claude Mythos, um modelo de IA tão avançado na descoberta de vulnerabilidades de segurança que decidiram não o lançar publicamente. Em vez disso, criaram o Project Glasswing, um programa restrito que dá acesso a pesquisadores e empresas selecionadas, destacando a capacidade sem precedentes do modelo em encontrar e encadear exploits complexos, incluindo uma falha de 27 anos no OpenBSD.

27
RESEARCHarXiv CS.AI·5/6/2026

Stable Agentic Control: Tool-Mediated LLM Architecture for Autonomous Cyber Defense

The paper introduces a tool-mediated LLM architecture for autonomous cyber defense, designed to provide formal guarantees for high-stakes decision-making under adversarial pressure. It certifies controllability, observability, and Input-to-State Stability (ISS) robustness through a machine-checked Lyapunov function, demonstrating its effectiveness on real enterprise attack graphs.

27
NEWSThe Verge AI·4/7/2026

A new Anthropic model found security problems ‘in every major operating system and web browser’

A Anthropic está lançando um novo modelo de IA, Claude Mythos Preview, como parte do Project Glasswing, uma parceria de cibersegurança com grandes empresas de tecnologia. O modelo visa identificar vulnerabilidades em sistemas operacionais e navegadores, mas não será lançado publicamente devido a preocupações de segurança.

27