Today’s briefing covers California’s new AI safety law, fears over the lapse of CISA protections, and a passenger data leak at WestJet. Extended context includes risks from unmanaged AI agents, the patching backlog challenge, and Ant’s new AI SHIELD for finance.
Cybersecurity Blog
AI-Enhanced Phishing — Operational Playbook for Defense
AI is making phishing more convincing than ever, from flawless emails to deepfake calls. This playbook explains how attacks work, why they succeed, and how to defend with layered strategies.
AI Security Daily Briefing — September 29, 2025
Today’s briefing warns of critical Cisco ASA zero-days hit by a CISA emergency directive, SOC teams drowning in alerts, and a claimed Comcast breach by Medusa ransomware. AI-powered attack techniques and predictive protection in education signal shifts in both offensive and defensive strategy.
AI-Powered Business Email Compromise — Operational Playbook for Defense
AI is transforming Business Email Compromise into a more convincing and costly threat. This playbook shows how attacks work, why they succeed, and what defenders must do to prevent fraud and data loss.
AI-Powered Data Poisoning — Operational Playbook for Defense
Attackers are using AI to poison training datasets, inserting stealthy manipulations and hidden backdoors that compromise model integrity. This playbook explains how these attacks work, why they matter, and the best practices defenders need to detect, contain, and recover from poisoned models.
AI Security Daily Briefing — September 26, 2025
Today’s briefing highlights a critical Salesforce AgentForce vulnerability (ForcedLeak), and Google’s new Agent Payments Protocol (AP2) that allows AI agents to transact autonomously. Extended coverage includes U.S. policy debates around AI-China tension and Kuwait’s deployment of AI surveillance vehicles.
AI Security Daily Briefing — September 25, 2025
The update outlines significant risks in AI security, highlighting data exposure from generative AI, vulnerabilities in AI-assisted coding, and weaknesses in Model Context Protocols. It emphasizes the need for strict access controls, better code reviews, and enhancing security at the data infrastructure level. Legislative support is also crucial for advancing AI cybersecurity efforts.
AI-Driven Credential Stuffing — Operational Playbook for Defense
Overview Credential stuffing attacks use stolen username and password pairs to gain unauthorized access to accounts. With artificial intelligence, attackers can supercharge these campaigns, automating large-scale testing, bypassing detection, and adapting in real time. The result is faster, stealthier, and… Read More ›
AI Security Daily Briefing — September 24, 2025
A concise, fact-based update for security and risk professionals. This post follows the combined format: core technical stories first, then extended context for governance and broader AI risks. 🔐 Core Security Intelligence 1) SAP & OpenAI launch “OpenAI for Germany”… Read More ›
AI-Powered Supply Chain Attacks — Operational Playbook for Resilient Defense
Overview Supply chain attacks exploit the trust organizations place in their vendors, partners, and software providers. With artificial intelligence, adversaries can now automate reconnaissance of suppliers, generate convincing phishing content, and even modify malicious code to evade detection across diverse… Read More ›