#1 Trusted Cybersecurity News Platform
Followed by 5.20+ million
The Hacker News Logo
Subscribe – Get Latest News

The Hacker News | Expert Insights

How AI-Assisted Attacks Are Breaking Legacy SIEM Tools

How AI-Assisted Attacks Are Breaking Legacy SIEM Tools

Aug 03, 2026
Somewhere right now, malware running on a compromised machine is checking in with an AI model, asking it for a new version of itself. Google's Threat Intelligence Group caught this happening in late 2025. The malware, nicknamed PROMPTFLUX, does this every hour it runs, and each version comes back looking different from the last. By the time a security tool learns to recognize it, it has already changed shape again. This isn't a rare glitch or a lab experiment. It's a preview of how a growing share of attacks work today and why legacy SIEM platforms built to detect known patterns are starting to fall behind. Legacy security tools were built to detect, not to adapt A SIEM is a system that collects logs from every part of a company's network and looks for signs of an attack. For years, it worked like a security guard with a very long memory. The guard learns what a break-in looks like - a certain kind of file, a pattern of behavior, a code signature, and watches fo...
Claude Runs Across Six Surfaces in Your Company. Your Security Team Sees One.

Claude Runs Across Six Surfaces in Your Company. Your Security Team Sees One.

Jul 27, 2026
We had an enterprise customer tell us their entire AI footprint was Copilot. That was the whole answer. One tool, one line item, done. We ran the first scan. Copilot wasn't even close to number one. Claude was. OpenAI came in second. Copilot was third. Nobody on the security team knew because Claude doesn't show up the way a SaaS app used to show up. There's no single login screen, no single admin console, no one place to look. That's the part most security teams miss. Claude isn't one surface. It's six. The six places Claude actually runs Claude Enterprise and Connected Apps. This is the surface everyone pictures: employees typing into Claude, OAuth'd into Google Drive, GitHub, Slack, and Jira, asking Claude to act on what's inside. The audit log shows that a connection happened. It does not show what got pulled into the prompt or what came back out. A finance analyst can drop a quarter of board materials into a conversation in ten second...
A Look Inside Lasso's AI Security Platform

A Look Inside Lasso's AI Security Platform

Jul 27, 2026
Security is fundamentally about knowing what a system is supposed to do, then catching it when it does something else. For software with deterministic execution paths, that is a tractable problem. For AI agents, it is not. An agent does not follow a fixed code path. It reasons toward a goal, selects tools based on that reasoning, and adapts its next action based on what those tools return. The same input can produce a different sequence of actions depending on context, session history, and what an external tool happened to return. Behavior is the attack surface, and behavior changes. Traditional proxies and AI firewalls were built to inspect content: what a user sent, what a model returned. Intent security asks a different question: is this agent doing what it was built to do, in this context, for this user, right now? Answering that requires building a behavioral baseline for every agent and measuring deviation from it continuously. That is the problem Lasso was built to solve....
How to Make Social Engineering Unprofitable

How to Make Social Engineering Unprofitable

Jul 22, 2026
For a long time, the cybersecurity industry has framed social engineering as a psychological problem. We treat it as a battle of wits between a charismatic con artist and an unsuspecting employee. The prevailing wisdom says that if we just train our people to better identify scams or tear down malicious infrastructure slightly faster, we can stay ahead of scammers. But looking at the threat landscape from a purely threat-intelligence perspective tells us something entirely different: Modern social engineering is more than a psychological game. It's a highly optimized, industrialized deception economy. Attackers run campaigns like hyper-efficient businesses. They have Customer Acquisition Costs, operational budgets, and strict Return on Investment (ROI) targets. This is the part the industry doesn't like to sit with: If we want to truly break the social engineering attack chain , we have to stop focusing exclusively on building higher walls or executing reactive takedowns...
The New Insider Has No Pulse: Securing Privilege When the Actor Is an AI Agent

The New Insider Has No Pulse: Securing Privilege When the Actor Is an AI Agent

Jul 20, 2026
When I work on an incident, the first question I ask is almost never "what malware ran." It's "whose credentials did it use, and what was that account allowed to touch." Nine times out of ten, the interesting part of the story isn't the exploit. It's the access. The exploit gets you in the door. The privilege is what lets you walk through the building. For thirty years, that question had a human-shaped answer. A person clicked something, a person got phished, a person reused a password, an admin left a service account sitting on a domain controller with a password from 2014. The identity at the center of the incident belonged to somebody with a badge and a manager. That assumption is quietly dying, and most enterprises have not adjusted their controls to match. The actor on your network is increasingly not a person at all. It is a workload, a script, a bot, an API (application programming interface) client, and now an AI agent that can reason, plan...
Cybersecurity Resources