"The next generation of enterprise attacks may not focus solely on deceiving humans, they may increasingly target the AI systems acting on behalf of humans." An email can carry hidden instructions inside its HTML or metadata, invisible to any human reader. The AI assistant summarizing, replying, or managing that inbox reads the hidden content, and acts without the human knowing. That's the idea behind X-Labs team's newest proof-of-concept research, PromptSpy, an emerging form of phishing that targets AI systems instead of humans. Nothing hacked. The AI just did what it was told. https://bit.ly/3RCzf8S
Forcepoint
Software Development
Austin, TX 182,371 followers
Data Security Everywhere
About us
Forcepoint simplifies security for global businesses and governments. The company’s Data Security Everywhere architecture makes it easy to adopt Zero Trust and prevent the theft or loss of sensitive data and intellectual property no matter where people are working. Based in Austin, Texas, Forcepoint creates safe, trusted environments for customers and their employees in more than 150 countries.
- Website
-
https://bit.ly/4g08Jy4
External link for Forcepoint
- Industry
- Software Development
- Company size
- 1,001-5,000 employees
- Headquarters
- Austin, TX
- Type
- Privately Held
- Founded
- 1994
- Specialties
- DSPM, data security, DLP, data protection, cloud security, web security, mobile security, SSE, AI, ML, SASE, and AI mesh
Locations
-
Primary
Get directions
10900-A Stonelake Blvd.
Ste. 350, 3rd Floor
Austin, TX 78759, US
Employees at Forcepoint
Updates
-
Forcepoint reposted this
𝗧𝗲𝗮𝗺𝗣𝗖𝗣'𝘀 𝗧𝗿𝗶𝘃𝘆/𝗟𝗶𝘁𝗲𝗟𝗟𝗠 𝗵𝗮𝗰𝗸 𝗿𝗲𝘀𝘂𝗹𝘁𝘀 𝗶𝗻 𝘁𝗵𝗲 𝘀𝗶𝗻𝗴𝗹𝗲 𝗯𝗶𝗴𝗴𝗲𝘀𝘁 𝗔𝗜 𝗦𝘂𝗽𝗽𝗹𝘆 𝗖𝗵𝗮𝗶𝗻 𝗕𝗿𝗲𝗮𝗰𝗵 𝗼𝗳 𝟮𝟬𝟮𝟲 TeamPCP compromised Trivy's (open-source vuln scanner) release process via a leaked automation token that had been rotated but not fully revoked, letting them force-push malicious code over Trivy's published version tags for ~20 days. -> the 'not fully' is doing a lot of work in that sentence! 😉 LiteLLM's CI/CD pipeline pulled Trivy unpinned from apt, so the poisoned scanner flowed into LiteLLM's build automatically and published malicious versions of the LiteLLM package to PyPI. -> apt install trivy (unpinned) - one line, several thousand incident reports later.. 😬 2.5k orgs potentially exposed, with high-confidence links to major firms incl. Volkswagen, FedEx, Deloitte, Bosch, Kroger, Deutsche Bahn, Siemens, Samsung, Airbus, Orange, Boeing, TomTom, BT, etc. with separate independent analyses of the dumps pointing to ~2.5k domains. The breach risked cloud creds, source-code repos, K8s secrets, and AI provider keys. A large share of the dumped secrets carry no identifiable domain or org name at all, so plenty of affected companies likely have live creds exposed without knowing it. Affected parties should treat any creds accessible during CI/CD execution as potentially compromised and rotate them regardless of confirmed attribution. -> no doubt IT teams will be rotating and (fully) revoking creds furiously in the coming days 🫡 I know I'll be asked, so here's where Forcepoint's AI Data Security would have helped: 1) AI Agent Gateway brokers agent creds to apps rather than letting static long-lived keys sit in env variables or process memory. If LiteLLM's gateway config had been brokered this way instead of stored as a raw key, the stolen creds alone wouldn't have granted downstream access. 2) Even with a stolen key, least-privilege restriction and requiring approval on high-risk actions would have limited what an attacker could actually do against connected business apps, rather than simply inheriting full permissions. 3) A centralised AI asset inventory covering sanctioned and shadow AI tool usage would surface an unmonitored LLM gateway dependency as a visibility gap before it became an unmanaged exposure. 4) Every AI-to-app transaction logged with full ID attribution, down to field-level inspection & audit trails, would have sped up the hardest part of this incident of figuring out which creds were used, from where, after the fact. It wouldn't stop the Trivy or LiteLLM compromises, but it shrinks blast radius and speeds response. #SupplyChainSecurity #CICD #DevSecOps #AISecurity 𝗦𝗼𝘂𝗿𝗰𝗲𝘀 A) https://lnkd.in/eYhRThmb CloudSEK B) https://lnkd.in/eyCtBwRD Hudson Rock
-
-
ICYMI: "Water is where power was 15 years ago" Former Acting Principal Deputy National Cyber Director Jake Braun joined To The Point Cybersecurity for a two-part conversation on America's water security, the DEF CON community's role in hardening under-resourced utilities and the widening gap between policymakers and technologists. Both parts linked below. 🎧 Part 1: https://bit.ly/4g7K3nG 🎧 Part 2: https://bit.ly/3TSa3Mj
-
Machine-speed cyberattacks are nothing new to the industry. DDoS and botnets gave attackers enormous scale and force, but the intelligence always stayed with the human. Now, Agentic AI takes traditional DDoS attacks from a computational force to adaptive intelligence. Instead of a million machines repeatedly doing what a human told them, they are now observing their environment, reasoning about their encounters, and changing their tactics to achieve the objective. The attack geometry shifting to dynamic is what the recent shift the recent cyberattack on Taiwan's government signals. One that doesn’t need human direction to adapt. Forcepoint VP of AI and Business Transformation David Giambruno on what this means for the future of cyber defense.
-
Every prompt is a data transfer. Can your security keep up ? Agents act without asking. Shadow AI spreads stealthily. And most security tools are still built for humans accessing approved applications. AI moves fast. With Forcepoint, YOU move first. First to see shadow AI, data leaks, AI access and autonomous agents. First to know the risk. First to adapt. First to protect. Stop locking AI down. Start securing it where the risk lives — in the data and prove it. Forcepoint AI Data Security in action. https://bit.ly/4x2mcfX
-
"The oxygen that makes [AI] tools effective is your data." Which means getting the most out of AI takes feeding it your most valuable data: your trade secrets, your IP, the work that sets you apart. The data you can least afford to expose. So you need protection that travels with your data, reaching it everywhere AI does and staying out of the way until it's needed. That's the shift Ronan Murphy, Chief Data Strategy Officer at Forcepoint, lays out in his full conversation with CyberRisk TV on SC Media. 📺 https://bit.ly/4z89JsQ
-
Tomorrow's the day. Did anyone actually approve what your AI tool can access? Most security teams find out the answer is no, usually after something's already gone wrong. Tomorrow, get ahead of the conversation with Gregory Crabb and Ronan Murphy. 🌎 NAM: https://bit.ly/4fuAcsT 🌏 APAC: https://bit.ly/4fDi4vK 🌍 EMEA: https://bit.ly/4w1H3Px
Your team approved the AI tool, but did anyone approve what it can access? When controls built for humans meet AI, the rules stop working. Agents inherit permissions, touch every system they can reach, and move data faster than anyone can track, compounding risk with every step. On August 12, we sit down with Gregory Crabb, CISO-in-Residence at Ballistic Ventures and former CISO of the U.S. Postal Service, to discuss where the gaps live in existing controls, how to govern the data AI touches, and how to do it without slowing the productivity AI creates. 🌎 NAM: https://bit.ly/4fuAcsT 🌏 APAC: https://bit.ly/4fDi4vK 🌍 EMEA: https://bit.ly/4w1H3Px
-
-
Data security and AI security used to be separate problems, but not anymore. At GISEC, see how Forcepoint's AI-powered data security platform protects your data everywhere it lives, moves and gets used, including in AI applications. You can find us at Stand D182, Hall 10 during the event or reserve a meeting or demo here: https://bit.ly/3RGGo8b
-
-
"When an AI agent remembers attacker-controlled information as a trusted context, the attacker has gained persistence inside the agent's decision-making process." A malicious actor plants false information somewhere an AI agent will read, so it gets stored and trusted as a fact. Later on, the agent retrieves and acts on it like normal. That’s the idea behind X-Labs team’s newest proof-of-concept research on persistent memory poisoning, an emerging attack that is an evolution of prompt injection. No exploit required. Just an agent trusting something it shouldn't have. https://bit.ly/4hRflkT
-
-
Organizations spent the last decade moving everything to the cloud. Now, quietly but unmistakably, some of that infrastructure is moving back on-premises — and AI is the reason. Learn why this trend is emerging in this article by Michael Leach, Director of Global Compliance at Forcepoint.