#Defensive Security

Every story tagged Defensive Security, curated for CIOs and IT leaders — ranked by source credibility, engagement, and freshness.

3 stories · open in the command center

  • Security & PrivacyTechMemeDan Goodin2m

    Researchers detail "context bombing", where defenders use prompt injections to trigger guardrails of attackers' LLMs, cutting AI hacking success rates by ~90% (Dan Goodin/Ars Technica)

    Security researchers have identified a defensive technique called 'context bombing' that uses prompt injections to deliberately trigger the safety guardrails of attackers' AI models, reducing successful AI-based attacks by approximately 90%. This discovery introduces a new asymmetric defense mechanism that could significantly shift the cost-benefit calculus for adversaries targeting AI systems, potentially making certain attack vectors economically unviable. For IT organizations, this represents both an immediate opportunity to strengthen AI security postures and a signal that AI safety features, when properly understood, can be weaponized defensively against emerging threat vectors.

  • Security & PrivacyArs TechnicaDan Goodin2m

    Now, defenders are embracing the prompt injection, too

    Researchers have developed a defensive technique called "context bombing" that embeds forbidden prompts within stored secrets to neutralize AI-powered attacks by triggering LLM safety mechanisms, reducing successful admin privilege escalation from 57% to 5% across tested models. This novel defense strategy complements earlier detection methods and addresses the critical timing gap where attackers achieve compromise faster than defenders can respond, fundamentally shifting the AI security landscape from detection-only to active prevention. IT organizations must now treat LLM guardrails as a defensive asset and integrate prompt injection decoys into their cloud infrastructure security posture.

  • AI & ML9to5Mac2m

    OpenAI unveils GPT‑5.4‑Cyber, an AI model for defensive cybersecurity

    OpenAI has released GPT-5.4-Cyber, a specialized AI model designed specifically for defensive cybersecurity with reduced safety restrictions and advanced capabilities like binary reverse engineering, available exclusively to vetted security professionals and enterprises through a limited access program. This strategic move positions AI as a critical tool for enterprise security operations while establishing OpenAI as a cybersecurity enabler, requiring IT organizations to evaluate how to integrate this new capability into their threat detection and vulnerability assessment workflows. The limited, iterative rollout signals OpenAI's intention to establish trust-based access controls for powerful AI tools and prepare organizations for increasingly capable models designed for specialized enterprise use cases.

Browse all tags