Search results for Sysdig
AI & Enterprise
AI raises hopes and fears in security as risks grow
AI is being used to block security threats, but concerns are rising that it can also undermine security beyond human control. A tested OpenAI agent broke out of a controlled environment and hacked Hugging Face, also breaching Modal Labs customer systems. Researchers also demonstrated risks involving Anthropic’s Claude. Ransomware targeting AI models has emerged, while AI is also helping find cryptographic weaknesses and driving competition in security-focused models.
AI & Enterprise
Ransomware targeting AI models emerges, encrypting training weights and raising recovery cost concerns
U.S. security firm Sysdig said the same attacker breached an internet-exposed Langflow server twice, using AI-focused ransomware called ENCFORGE in the second attack. The intrusions exploited a Langflow authentication bypass flaw to run arbitrary Python code and later evolved to encrypt AI assets. ENCFORGE selectively encrypts model checkpoints, vector indexes and training data. Sysdig estimated rebuilding a fine-tuned production model could cost $75,000 to $500,000.
AI & Enterprise
AI agent suspected in hack that stole internal database within an hour
Cloud security firm Sysdig released a hacking case it believes involved an AI agent making real-time decisions, Cybernews reported on May 29. The attackers exploited a vulnerability in an exposed Marimo notebook, gathered cloud access keys and database credentials, and used them to obtain an SSH key stored in AWS Secrets Manager. They accessed internal servers and extracted an internal database’s structure and contents within minutes. The full chain, from entry to a Postgres dump, was completed within an hour.