Red Teaming stories
AI wellbeing coaches face persistent probing, and the company says health tools must be monitored daily as attacks grow more sophisticated.
AI is speeding up attacks as well as defence, with high-risk prompts and unsupervised agents exposing firms to new security gaps.
The new safety model slashes prompt-injection risks in GPT-5.6, as OpenAI says it found flaws faster than human testers and then fed fixes back into production.
Tests on five models found a planted text string sharply reduced successful AI-led intrusions, cutting full compromise to 1% in an AWS range.
Attackers can now probe Entra ID accounts and passwords at scale without a real app, leaving defenders with little sign-in telemetry.
Security teams are being pressed to prove their defences work in live attacks, as spending scrutiny shifts from tools to real-world response.
Weak public trust and tighter oversight are pushing Australian and New Zealand firms to add live AI security controls before systems go into production.
Businesses could see faster, cheaper AI coding and office workflows as OpenAI rolls out GPT-5.6 with stronger safeguards.
Malicious AI skills are helping criminals steal data and run malware, while QR-code phishing climbed 146% in the latest ESET report.
The AWS badge could help XBOW win more enterprise deals as buyers seek continuous testing that shows which vulnerabilities are exploitable.
Buyers will gain a clearer signal on autonomous AI, as certified providers can now display a trustmark in the widely used STAR Registry.
Hidden tracking markers and a US standoff over a vulnerability-finding model are fuelling fears that AI now carries cyber and national security risks.
New safeguards will let Fable 5 block more harmful cyber prompts, as Anthropic also seeks a common scale for jailbreak risk.
Missed intrusions could cost more than false alarms, as Secure.com says AI tools in security operations can miss real attacks in live use.
Enterprises may gain safer, more portable AI deployments as Google Cloud adds an open knowledge standard, Apple privacy work and Claude availability.
Organisations risk missed exposures as cloud, APIs and AI systems change far faster than annual security checks can keep up.
The plan could speed defences across government and vital sectors, but experts warn weak basics and policy gaps may blunt its impact.
A financial services cloud was taken over in seconds in a test, highlighting how approved permissions can still let attackers reach full AWS control.
False negatives from automated scanning tools are fuelling a shift towards human-led AI security testing across large organisations.
The certifications may help reassure UK customers and public-sector buyers as cyber breaches remain widespread and scrutiny of suppliers intensifies.