search

Sections

Cyber Security

2432 articles

Designing for the inevitable: System prompt leakage and mitigations in generative AI applications
cybersecurity

Designing for the inevitable: System prompt leakage and mitigations in generative AI applications

System prompts form the foundation of generative AI applications. A system prompt is a collection of instructions and operational context provided to a large language model (LLM) that shapes how the model behaves and interacts with users and tools. System prompts often contain proprietary information, including role definitions, behavioral guidelines, tool descriptions and usage instructions,

AWS Security Blog ·
Protecting Microsoft at AI speed: How SFI proactively hardens our cloud
cybersecurity

Protecting Microsoft at AI speed: How SFI proactively hardens our cloud

Microsoft’s Secure Future Initiative (SFI) aims to define and meet security requirements for a well-defended cloud service. This involves not only setting the standards but also continuously assessing live services to ensure they comply, particularly in the context of rapidly evolving artificial intelligence. The initiative emphasizes proactive measures to strengthen cloud security against emerging threats.

Cloud security Insights | Microsoft Security Blog ·
The CISO’s guide to post-quantum mandates and migrations
cybersecurity

The CISO’s guide to post-quantum mandates and migrations

Over a dozen major economies have now published post-quantum cryptography (PQC) adoption guidance. As a CISO, you’re probably well into your migration plan and know the most difficult part has little to do with changing algorithms. The real leadership challenge is driving coordinated change across a large, complex organization where asymmetric cryptography is embedded in

AWS Security Blog ·
Secure AI Workflows: The Identity and Access Management (IAM) Checklist
cybersecurity

Secure AI Workflows: The Identity and Access Management (IAM) Checklist

AI agents and large language models (LLMs) are transforming software development by building, analyzing, and deploying code throughout the lifecycle. As AI increasingly shapes software supply chains, it is crucial to implement proactive security measures and access controls. To govern authentication and permissions effectively without hindering development speed, organizations must revise their access management strategies, ensuring the security of AI-driven processes.

From the Frog's mouth - JFrog Blog ·
Enforce zero data retention on Amazon Bedrock with Bedrock Projects and service control policies
cybersecurity

Enforce zero data retention on Amazon Bedrock with Bedrock Projects and service control policies

With the introduction of models that require data sharing with third-party providers—such as Claude Fable 5—organizations need a way to centrally enforce data retention policies. Amazon Bedrock gives you control over whether your prompts and model outputs are retained after an inference request completes. You might need a way to enforce your retention settings across

AWS Security Blog ·
Beyond Tokens SF: Best Ideas of the Evening
cybersecurity

Beyond Tokens SF: Best Ideas of the Evening

AI agents are changing how software gets built, but the infrastructure around them hasn’t caught up. Agents burn through tokens on noise. They take actions they shouldn’t. Context evaporates between releases. And most delivery pipelines were never designed for the pace and volume of agentic development. On June 11th we brought together developers in San

From the Frog's mouth - JFrog Blog ·
CISA Adds One Known Exploited Vulnerability to Catalog
cybersecurity

CISA Adds One Known Exploited Vulnerability to Catalog

CISA has added a new vulnerability, CVE-2026-48282, related to Adobe ColdFusion, to its Known Exploited Vulnerabilities (KEV) Catalog due to signs of active exploitation. This type of vulnerability is often targeted by cybercriminals and poses significant risks for federal agencies. Binding Operational Directive (BOD) 26-04 mandates federal agencies to prioritize high-risk vulnerabilities in their remediation efforts. Although this directive is for federal agencies, CISA urges all organizations to adopt similar risk-based vulnerability management strategies. Organizations can also submit exploited vulnerabilities for potential inclusion in the KEV Catalog.

All CISA Advisories ·
Hitachi Energy e-mesh EMS
cybersecurity

Hitachi Energy e-mesh EMS

Hitachi Energy has identified a buffer overflow vulnerability in their e-mesh EMS products, specifically in versions 4.1.6, 4.4.2, and 4.7.0. Exploiting this vulnerability could lead to denial of service or arbitrary code execution. The issue arises from an NGINX vulnerability linked to the ngx_http_rewrite_module, affecting systems with ASLR disabled. Users are advised to update NGINX to version 1.30.2 or newer and follow specific mitigation steps. This advisory is part of an ongoing effort to improve cybersecurity in critical infrastructure sectors, particularly in the energy domain.

All CISA Advisories ·
Hitachi Energy PROMOD V
cybersecurity

Hitachi Energy PROMOD V

Hitachi Energy has identified a vulnerability in the PROMOD V product line that relies on insecure HTTP communication instead of HTTPS. This flaw allows potential attackers to intercept sensitive data, risking credential theft and unauthorized access. Versions affected include PROMOD V 1.0.10 and older. Users are urged to upgrade to version 1.0.11 and implement HTTPS on the Digipede server for remediation. CISA recommends minimizing network exposure and implementing strong cybersecurity practices to safeguard these systems.

All CISA Advisories ·