OnlyFans Models Are Accidentally Making Hacked Government Websites Disappear

Scammers are hijacking government websites to upload ads for “leaked” OnlyFans content. Thousands of copyright complaints from adult creators are helping people avoid malicious links.

AI has collapsed the cyber response window — resilience now starts before the attack

Presented by Rubrik


Enterprise cybersecurity is facing a fundamental speed problem. Frontier AI models are now enabling autonomous attacks that can move from initial access to full system breakout in as little as 27 seconds. That’s faster than any human-operated security workflow can detect, escalate, and respond.

As a result, security operations can no longer assume there is time for humans to respond between breach and damage.

The security posture that enterprises need for the AI era centers on cyber resilience: continuously identifying clean recovery states, mapping critical data and identity dependencies, and automating restoration so that operations can recover in hours not days.

“Everything that relied on process or human-in-the-loop intervention is no longer going to be able to execute at the speed of the attacks,” says Dev Rishi, GM of AI at Rubrik. “If the attacks are happening in 27 seconds, it means I need my recovery to happen just as quickly.”

Traditional detection and prevention are failing against AI-driven attacks

The rules-based logic that has defined enterprise security for decades, such as static access controls, known signature detection and deterministic behavioral policies, was engineered for deterministic software. AI agents behave differently. They’re non-deterministic, capable of pursuing the same objective through many different paths, and increasingly capable of circumventing static guardrails by finding alternative routes when one is blocked.

The deeper problem is that conventional security logic checks identity, permissions, and access, and asks whether each individual access is permitted. But it can’t evaluate whether a sequence of permitted actions, taken across multiple applications, constitutes either a data leak, a destructive operation, or an attack.

“You need a system that can understand context,” Rishi says. “You need to use AI to look at what an agent is doing and say, ‘it looks like what you’re doing might be a risk of leaking sensitive data externally.’”

How AI agents are blurring the line between internal and external cyber threats

Enterprise security has historically maintained a meaningful distinction between external and internal threat vectors. External threats can be multidimensional, lightning fast, and come from a variety of vectors. On the other hand, internal threats were traditionally bounded by what a single human actor could accomplish before detection, constrained in speed, scope, and scale, but that distinction is falling apart as AI agents operate inside enterprise environments.

These agents have access to multiple systems simultaneously and move at speeds no human employee can match. When an agent makes a mistake, such as a hallucination, misread instruction, or an unintended data transfer, the resulting damage can look operationally identical to a malicious insider attack. And when an external attacker compromises an internal agent, they inherit its full access profile across every connected application.

“Whether or not the agent is an internal threat because of an inadvertent mistake or because it’s been maliciously compromised, you need runtime guardrails that enforce your organizations policies consistently across agents,” Rishi says. “The practical answer is an AI-native guardian layer that monitors agent behavior semantically, understands intent across actions, and can block or terminate a misbehaving agent at machine speed, then trigger recovery immediately.”

Preparing for a world of inevitable compromise

Frontier AI models, including those capable of discovering and operationalizing zero-day vulnerabilities autonomously, are changing the economics of attacks.

As a result, interest in Mythos readiness is growing. Enterprises are increasingly operating under two assumptions: that attacks are inevitable, not exceptional, and that investment in resilience and rapid recovery must be treated as strategically as investment in prevention has been. The shift reframes recovery from a post-incident activity into a capability that is deliberately designed, tested, and continuously validated.

“The idea that you can recover quickly from an attack is going to become one of the most important facets of security,” Rishi says. “It’s the insurance policy that organizations now have to treat as a first-class citizen.”

Why AI-powered cyber resilience depends on small models

True cyber resilience is a two-sided coin: it demands both real-time intelligent enforcement to intercept threats in motion, and automated recovery to restore operations immediately. While having backups is a baseline, organizations need workflows that can continuously monitor systems at machine speed, and instantly determine the most recent clean state under attack conditions.

Applying AI to the first half of that equation—real-time enforcement—creates a fundamental technical and economic challenge. Relying on massive frontier models to monitor every agent action introduces crippling latency overhead and exorbitant computing costs. A guardian AI system that slows down operations or costs as much as the systems it monitors is simply not viable for widespread adoption.

“It has to be a fast, small, and cheap AI model,” Rishi says. “No one wants to sign up for a secure solution that doubles their cost or latency.”

This is why small language models (SLMs) are critical for real-time enforcement. Rubrik’s approach, anchored by its acquisition of Predibase, is to build this frontline defense layer on small models optimized specifically for speed and efficiency. Unlike heavy frontier models, SLMs can semantically evaluate agent behavior at machine speed and at a fraction of the cost, acting as a real-time checkpoint.

That hyper-efficient enforcement layer is what enables a tighter, seamless connection to recovery. When the system observes an agent taking a destructive action—such as deleting a database, corrupting a critical file, or exfiltrating sensitive data—the small model detects it immediately, halts the damage, identifies the most recent clean snapshot from before the incident, and initiates recovery in a single, automated workflow.

The shift from incident response to architectural resilience

The broader implication of Mythos and similar frontier AI systems is a shift in how organizations think about security. As AI compresses the gap between attack and impact, resilience and recovery become architectural requirements rather than operational considerations.

Rubrik’s view is that security systems can no longer stop at detection. As AI agents gain greater autonomy, observability, identity context, and recovery must operate as a coordinated resilience layer. The goal is not simply to identify when something has gone wrong, but to shorten the gap between detection and restoration.

“The same thing that’s introducing the threats, the frontier capabilities of models like Mythos, can also be used to help us combat the threat,” Rishi says. “Positioning yourself for the AI era means closing the gap between detecting that something has gone wrong and restoring the systems that were affected, before the cost of that gap compounds.”


Sponsored articles are content produced by a company that is either paying for the post or has a business relationship with VentureBeat, and they’re always clearly marked. For more information, contact sales@venturebeat.com.

Bitdefender Identity Theft Protection review
Bitdefender Identity Theft Protection review

In our Bitdefender Identity Theft Protection review, we thoroughly examine the pros and cons of the platform relative to other top identity theft protection services.

DeepSeek accidentally built a working ransomware strain, experts note, ‘What we are witnessing is a fundamental shift in how novel cyber attacks are born’
DeepSeek accidentally built a working ransomware strain, experts note, ‘What we are witnessing is a fundamental shift in how novel cyber attacks are born’

DeepSeek accidentally created a working browser ransomware technique targeting Android photos, Check Point Research found, without human guidance involved.

The real cost, security, and culture problems behind enterprise AI agents

Presented by Red Hat


At VentureBeat’s recent AI Impact event, where the discussion centered on what separates enterprises that scale agentic AI from those that stall in pilot mode, Brian Gracely, senior director of portfolio strategy at Red Hat, detailed what companies actually run into once agents reach production.

He dove into cost discipline, the security blind spots unique to autonomous systems, and the organizational friction that determines whether agent adoption spreads beyond early champions.

Enterprises are overestimating how far behind they are on AI agents

Many enterprise leaders, especially those following industry keynotes and AI announcements, worry that they’re already falling dangerously behind competitors deploying agents at scale. But according to Gracely, much of that anxiety reflects a misconception about how quickly organizations learn once they begin building. Teams often move up the learning curve far faster than they expect.

That rapid progress creates a different challenge, however. As agent usage expands, AI costs rise just as quickly, turning cost management from an engineering concern into a recurring boardroom discussion.

Agentic AI usage is orders of magnitude higher than during the chatbot era, making AI costs a growing concern for enterprises. At the same time, organizations are becoming increasingly aware of their dependence on a small number of model providers. According to Gracely, that combination is driving many enterprises to explore alternatives that give them greater control over costs and infrastructure.

“The two or three top providers are already telling the market that they’re losing money, and they’re trying to go public to make up those gaps,” he explained. “At some point, the dependency on that means you’re either going to buy at a very high-cost level, or you’re going to figure out alternatives to control what you’re doing.”

Right-sizing AI models is the fastest lever for cutting agent costs

The biggest cost issue is that enterprises overspend by defaulting to the most capable model available regardless of task complexity.

“If I’m simply trying to resolve an insurance claim, I don’t need to know about the history of Western civilization in my model, I don’t need to know World Cup soccer scores,” Gracely said.

Semantic routing is the mechanism many companies use to make that judgment automatically, classifying requests and sending each to a model sized for the task without requiring users to choose, while infrastructure techniques like caching repetitive queries cut how often a request needs to reach GPU compute at all. Together, he said, these tools remove the assumption that efficiency and innovation pull in opposite directions.

“There’s a lot you can do at a GPU infrastructure level, and quite a bit you can do in terms of flexibility of models,” he explained. “Those give excellent choices in terms of the levers you’re trying to pull, whether you need efficiency or you need innovation. That shouldn’t be a binary choice.”

The financial discipline needed for token spend is similar to the FinOps practices that took years to mature in order to take control of cloud compute spending. Those underlying frameworks will transfer even as the vocabulary changes, Gracely said, especially as organizations push for internal education on model selection so teams stop defaulting to the most prominent option for tasks that don’t need it.

“The same way we first had to teach the financial people what an EC2 instance is and what an S3 bucket is, you’re going to have to start explaining tokens to them,” he said. “We don’t always need a Rolls-Royce. We don’t always need caviar, because we’re trying to do basic types of things.”

Patch speed is now critical as AI tools find vulnerabilities faster

AI-powered vulnerability discovery is forcing enterprises to rethink how quickly they can identify, validate and deploy patches. Long-established patch management cycles may no longer be fast enough in an environment where AI can uncover — and attackers can exploit — new vulnerabilities much more quickly.

“Most companies are probably going to have a window of somewhere between seven and 14 days to stay ahead,” he said. “There are groups, Red Hat included, that are going to build patches for these, but the embargo window is going to be short.”

AI is also changing what defenders need to look for. Rather than simply uncovering isolated critical flaws, AI security tools can identify combinations of seemingly minor vulnerabilities that become dangerous only when chained together. As both software complexity and vulnerability discovery accelerate, Gracely argued that the ability to rapidly manage and update software is becoming a strategic capability rather than simply an operational one.

Subject matter experts and compliance teams decide whether agents scale

In the end, organizational adoption comes down to the need for deep, sustained involvement from the subject matter experts whose knowledge the agent is meant to encode, which makes earning their buy-in a prerequisite rather than an afterthought.

“You have to think about the incentives, what you do for people who participate in this work so they don’t feel threatened that it’s going to take away their job, and how you incentivize people in the long run to cooperate with that innovation,” he said.


Sponsored articles are content produced by a company that is either paying for the post or has a business relationship with VentureBeat, and they’re always clearly marked. For more information, contact sales@venturebeat.com.

Why hackers are targeting your digital supply chain, not just your systems
Why hackers are targeting your digital supply chain, not just your systems

Hackers are constantly looking for new ways to gain access to businesses and it’s rare that it’s through the front door. For most organisations cybersecurity still focuses on protecting internal systems and preventing unauthorised access through measur…

Hacktivists call out Trump by hacking and defacing US Army websites

The U.S. Army has fixed two of its websites that were hacked to display messages calling President Trump a “pedophile” and a “thief.”

Savi’s app aims to protect consumers from realistic AI scams like kidnappers demanding ransom

The company just raised $7 million in seed funding, and is launching its app for iPhone and Android on Tuesday.

‘No single organisation can tackle it alone’: VodafoneThree says its new security process blocked two million SMS fraud messages
‘No single organisation can tackle it alone’: VodafoneThree says its new security process blocked two million SMS fraud messages

VodafoneThree and Barclays prevent 25% more banking scams by using combined intelligence – more banks to come.