Signal Desktop now blocks screenshots on Windows 11 by default to protect against Microsoft Recall, which periodically captures screen content. The move uses DRM flags to prevent sensitive messages from being recorded without consent.

Signal Desktop now blocks screenshots on Windows 11 by default to protect against Microsoft Recall, which periodically captures screen content. The move uses DRM flags to prevent sensitive messages from being recorded without consent.
Mind-bending AI fact: Your innocent-looking translation tool could be tricked into opening malicious files or leaking private docs from your system. #AISecurity #Tech
https://archive.is/gFr9J
Hadn't seen this, from early April
#aisecurity #ai
Reasoning models don't always ...
Microsoft Launches Entra Agent ID for Secure Enterprise AI Agents
#AI #MicrosoftBuild #Build2025 #AIsecurity #EntraAgentID #AIagents #IdentityManagement #ZeroTrust #EnterpriseAI #Microsoft #AICopilot #DevOps #AIgovernance
I wrote a brief Playbook, how to get started with securing the Azure AI Service's in your environment. Azure AI services provides multiple layers of security that you should consider when implementing a solution, which I present in this blog post:
https://vasenius.fi/example-playbook-to-secure-your-azure-ai-services/
A new GitHub #Copilot coding agent takes on tasks asynchronously in #GitHubActions. Microsoft Azure #AI Foundry updates this week hint at future #GitHub #AIsecurity and model management controls. #MSBuild https://www.techtarget.com/searchsoftwarequality/news/366623845/New-GitHub-Copilot-agent-edges-into-DevOps
Think your AI chatbot is harmless? A cybersecurity firm broke into a *candle shop's* AI, finding it could potentially spill company secrets or even give instructions on how to burn a house down! Definitely makes you think. #AISecurity #TechRisk
https://archive.is/CCDEc
At the recent #RSAC2025 conference, LMG Security's @sherridavidoff and @MDurrin drew packed crowds with their sessions on how hackers use AI to exploit stolen source code and a hands-on tabletop lab exploring deepfake cyber extortion.
We’ve received a lot of inquiries about these sessions! If you couldn’t attend RSA and you're interested in these topics, we also offer custom training and tabletop exercises to help your team prepare for the next generation of AI-powered cyber threats.
Contact us to learn more: https://www.lmgsecurity.com/contact-us/
Stress-testing AI systems through red teaming is crucial for uncovering weaknesses before they are exploited. AVID's recent blog post emphasizes the value of involving diverse expertise to develop AI models that are robust, secure, and ethical. Read more here: https://avidml.org/blog/red-teaming-1/
This is about to happen! Join us!
How To Detect And Mitigate Non-Human Identity And Crytographic Vulnerabilities — An ITSPmagazine Webinar With SandboxAQ
Thursday, May 15, 2025 | 1:00 PM 2:00 PM EST
Unmanaged cryptographic assets and non-human identities have left security teams blind to critical risks. These gaps have fueled vulnerabilities, breaches, compliance challenges, and operational drag across enterprise environments.
Join us to see how #AQtiveGuard transforms this landscape.
More than just visibility, AQtive Guard unifies your non-human identities and cryptographic assets into a single inventory to deliver end-to-end visibility, deeper risk analysis, and streamlined compliance in a single pane of glass—with automated discovery, real-time threat detection, and root cause analysis powered by their unique LQM.
Seamlessly integrated into your existing stack, it’s the AI-driven SaaS platform built to secure today’s systems—and tomorrow’s.
By attending, you will get to:
Discover how to gain unified visibility into cryptographic assets and non-human identities —including API keys, certificates and service accounts—in cloud environments
Explore how AQtive Guard empowers security teams with automated discovery, threat detection, and root cause analysis—enabling faster remediation, reduced risk, and stronger compliance without disrupting existing workflows.
Learn how to future-proof your security posture, with a platform designed for AI Security Operations, Post-Quantum Cryptography readiness, and seamless integration into your existing security stack.
PANELISTS
Marc Manzano
General Manager of Cybersecurity, SandboxAQ
MODERATORS
Sean Martin, CISSP Co-Founder, ITSPmagazine
Marco Ciappelli Co-Founder, ITSPmagazine
Can’t attend the live webinar? All registrants get exclusive access with a link to rewatch the recording.
Register To Attend: https://www.crowdcast.io/c/how-to-detect-and-mitigate-non-human-identity-and-crytographic-vulnerabilities-an-itspmagazine-webinar-with-sandboxaq
#cybersecurity, #cryptography, #AIsecurity, #infosec, #webinar, #securitytools, #threatdetection, #cloudsecurity, #sandboxAQ, #ITSPmagazine #tech #technology #quantum
AI-powered features are the new attack surface! Check out our new blog in which LMG Security’s Senior Penetration Tester Emily Gosney @baybedoll shares real-world strategies for testing AI-driven web apps against the latest prompt injection threats.
From content smuggling to prompt splitting, attackers are using natural language to manipulate AI systems. Learn the top techniques—and why your web app pen test must include prompt injection testing to defend against today’s AI-driven threats.
At Giskard, we've integrated LMEval into our Phare LLM benchmark (phare.giskard.ai) to independently evaluate popular models' security and safety dimensions - through rigorous testing.
Read the announcement: https://opensource.googleblog.com/2025/05/announcing-lmeval-an-open-ource-framework-cross-model-evaluation.html
Thanks to Kyle Wiggers for this article. We're honored to see our research covered by TechCrunch.
Read the article here: https://techcrunch.com/2025/05/08/asking-chatbots-for-short-answers-can-increase-hallucinations-study-finds/
Monday news from ITSPmagazine #happymonday!
Join Marc Manzano, Sean Martin, CISSP and me on this week SandboxAQ Webinar!
After an incredible conversation with Marc on the #RSAC floor in San Francisco — where Sean and I used every second of our time and still had more to explore — I knew the #Sandbox Story couldn’t stop there.
If you missed that on-location episode from #RSAC2025, catch it here:
Security at the Edge of Change – A Brand Story with Marc Manzano from SandboxAQ
Now, we’re keeping the momentum going with a live ITSPmagazine webinar you don’t want to miss — and I won’t either.
How To Detect And Mitigate Non-Human Identity And Cryptographic Vulnerabilities | An ITSPmagazine Webinar with SandboxAQ
Join Marc, Sean, and me as we dig deeper into how SandboxAQ is tackling one of today’s most urgent security challenges.
Unmanaged cryptographic assets and non-human identities have left security teams blind to critical risks. These gaps have fueled vulnerabilities, breaches, compliance challenges, and operational drag across enterprise environments.
By attending, you’ll:
Gain visibility into cryptographic assets and non-human identities like API keys, certificates, and service accounts
See how #AQtiveGuard enables automated discovery, threat detection, and root cause analysis without disrupting workflows
Learn how to future-proof your security with Post-Quantum Cryptography readiness and AI-powered #SecOps
Learn more:
REGISTER NOW:
Can’t attend the live webinar? All registrants get exclusive access with a link to rewatch the recording.
Share the news and join us!
See you live on Thursday!
Indirect prompt injection attacks exploit LLMs by embedding malicious instructions in external content. Learn how they work & how to protect AI systems: https://jpmellojr.blogspot.com/2025/05/indirect-prompt-injection-attacks.html #AIsecurity #LLM #PromptInjection
Ever wondered what really makes those powerful AI language models tick? Andrej Karpathy offers a clear explanation, revealing the secrets behind their training and architecture. Discover how they're evolving and the key security hurdles we need to overcome. A must-read for anyone curious about the behind-the-scene aspects AI! https://www.alanbonnici.com/2025/05/demystifying-llms-with-andrej-karpathy.html #ArtificialIntelligence #NLP #LanguageModels #AISecurity #TechInsights #FutureofAI #TTMO
When AI writes code, builds models, and simulates threats… who checks the checker?
In this last On Location Conversation from #RSAC2025, Alex Kreilein and John Sapp Jr. join Sean Martin, CISSP to explore what trust actually means in the age of AI-generated security tooling — and how modern #AppSec teams must rethink validation, #resiliency, and #risk.
This episode cuts deep into:
Why “trust the output” is not enough in AI-driven workflows
How #AI security debt is becoming the new tech debt
Why we need #zerotrust thinking applied to models and agents
The real shift: from patching CVEs to building resilient architecture
The role of traceability, governance, and context-driven decision-making
If you’re serious about secure AI, application security, and shifting AppSec left (the right way), this conversation will challenge what you think you know — and help reframe what secure development actually looks like.
Watch the full video:
https://youtu.be/kJdQz9LmT6s
Listen to the audio podcast:
https://eventcoveragepodcast.com/episodes/why-we-cant-completely-trust-the-intern-even-if-its-ai-an-rsac-conference-2025-conversation-with-alex-kreilein-and-john-sapp-jr-on-location-coverage-with-sean-martin-and-marco-ciappelli
Thank you to our Full Coverage Sponsors:
ThreatLocker https://itspm.ag/threatlocker-r974
Akamai Technologies https://itspm.ag/akamailbwc
BLACKCLOAK https://itspm.ag/itspbcweb
SandboxAQ https://itspm.ag/sandboxaq-j2en
Archer Integrated Risk Management https://itspm.ag/rsaarchweb
ISACA https://itspm.ag/isaca-96808
Object First https://itspm.ag/object-first-2gjl
Edera https://itspm.ag/edera-434868
Explore more RSAC 2025 coverage:
https://www.itspmagazine.com/rsa-conference-usa-2025-rsac-san-francisco-usa-cybersecurity-event-infosec-conference-coverage
Catch all of our event conversations:
https://www.itspmagazine.com/technology-and-cybersecurity-conference-coverage
Want to tell your Brand Story Briefing as part of our coverage?
https://itspm.ag/evtcovbrf
Want Sean Martin, CISSP and Marco Ciappelli to cover your event or moderate your panel?
https://www.itspmagazine.com/contact-us
Thank you @labs_ig for being a Gold sponsor of #BSidesAugusta 2025. Your innovation and insight inspire the entire cyber community!
#ZeroTrust #AIsecurity #InfoSec #CyberAwareness
Microsoft Copilot for SharePoint just made recon a whole lot easier.
Read it here: www.pentestpartners.com/security-blo...
#RedTeam #OffSec #AIsecurity #Microsoft365 #SharePoint #MicrosoftCopilot #InfoSec #CloudSecurity
The Dark Side of Multimodal AI: Unveiling New Security Risks
As multimodal AI systems evolve, they bring not only groundbreaking capabilities but also unprecedented safety risks. Recent findings reveal alarming vulnerabilities in these models that can be exploi...
https://news.lavx.hu/article/the-dark-side-of-multimodal-ai-unveiling-new-security-risks