Daily Recap, Organizations are facing a surge in shadow AI agents, with guidance on discovery and security as Nvidia and other tech giants push an AI security alliance to protect expanding AI systems and agent deployments. Meanwhile, attackers continue to evade detection with MedusaHVNC, supply-chain defenses were strengthened by GitHub and PyPI using time-based protections, and new breach disclosures from Coca-Cola and MCBS keep ransomware and large-scale exposure in focus.
#ShadowAI #Nvidia #AIAlliance #MedusaHVNC #GitHub #PyPI #CocaCola #Fairlife #MCBS #Wyden #ZeroTrust #VPN
#ShadowAI #Nvidia #AIAlliance #MedusaHVNC #GitHub #PyPI #CocaCola #Fairlife #MCBS #Wyden #ZeroTrust #VPN
AI Security
- Shadow AI agents are proliferating across organizations, prompting new guidance on how to discover and secure them as vendors and enterprises tighten governance β AI Agents, AI Alliance
- Nvidia and other tech giants launched an AI security alliance to strengthen protections for rapidly expanding AI systems and agent deployments β AI Alliance
Malware & Evasion
- MedusaHVNC malware is abusing hidden Windows desktops to avoid detection, underscoring attackersβ continued use of stealth techniques to hide malicious activity β MedusaHVNC
Supply Chain
- GitHub and PyPI introduced time-based defenses to blunt supply chain attacks, adding friction for malicious package and repository abuse β GitHub Defense, PyPI Defense
Breach Updates
- Coca-Cola confirmed a data breach tied to a Fairlife ransomware incident, adding another high-profile victim to the ransomware landscape β Coca-Cola Breach
- MCBS disclosed a breach affecting 1.2 million individuals, highlighting the scale of ongoing exposure in large data incidents β MCBS Breach
Policy & Infrastructure
- Sen. Wyden urged federal agencies to retire older, insecure, public-facing VPNs in favor of stronger zero-trust approaches for government access β Legacy VPNs