GPT-6 Astra Asked Permission. An Automated Reply Said Use Your Best “Judgement.”

Cyber Insurance News story on an AI agent supply chain attack showing a chat window with a glowing automated reply above a network with one red node

The model asked before it acted. The reply came from a script. “Please proceed to the next step using your best [judgement].” That is the automated reply the UK AI Security Institute’s harness sends whenever an agent asks a question. OpenAI’s GPT-6 Astra sometimes read it as a yes. What followed, in simulation, was unsanctioned … Read more

Stolen Credentials Outlive The Malware That Stole Them

Cyber Insurance News story on infostealer credential exposure showing a password prompt echoing across time

In June, a stream went live on IGN’s official Twitch channel. Nobody at IGN had started it. A self-identified white hat hacker had taken over a senior video director’s Restream account. He launched the broadcast himself. The account’s credentials had been sitting in an infostealer dump for more than a month before anyone used them. … Read more

Four In Ten CISOs Have Met A Deepfake On A Work Call

Cyber Insurance News story on deepfake social engineering showing a video call grid with one tile dissolving into digital lines.

CISOs, beware of deepfake social engineering! Four in ten chief information security officers have now sat through a deepfake on a work audio call. More than a third have seen one on video. Security awareness training taught people to spot a bad link and a wrong domain. It never taught them to doubt a familiar … Read more

One AI Failure, Four Policies: AXA XL Names The Scenarios

Cyber Insurance News story on AI risk insurance showing one line of light splitting into four separate strands.

A carrier has put the question in writing. AI-related losses “may not fall neatly into one category of risk.” AXA XL and S-RM published Building Resilient AI on 23 September. The report names four loss scenarios that will test that sentence. A deepfake-enabled payment fraud. An AI-related data breach. A defective output causing third-party loss. … Read more

Eighty-Eight Percent Have A Plan. Twenty-One Percent Have An Inventory.

Cyber Insurance News story on OT cybersecurity showing an industrial plant at night with one tower unlit and invisible illustrative of industrial cyber risk.

Eighty-eight percent of industrial security leaders describe their OT security program as planned or design-led. Twenty-one percent report a complete asset inventory. A program cannot protect equipment nobody has counted. Honeywell Technologies has now put a number on what that gap costs in hours. Its inaugural OT Cybersecurity Benchmark Report surveyed 603 respondents across critical … Read more

×