• contact@grigoryan.info
grigoryan.info
  • GrigoryanInfo
  • Articles
  • Analysis
  • LinkedIn
  • GitHub
  • Resources

Germany's first comprehensive audit framework specifically designed for AI systems

05 August 2026
  • A5
  • AISecurity
  • AIAudit
  • AIAct
  • BSI

The German Federal Office for Information Security (BSI) has published the AI Audit and Assurance Assessment Architecture (A5) as a Community Draft, introducing a new audit framework for AI systems.
A5 is designed to help organizations and public authorities systematically demonstrate the trustworthiness, security, and compliance of AI systems, particularly in light of the EU AI Act, the Cyber Resilience Act (CRA), and future regulatory requirements.
A particularly noteworthy aspect is that the assessment criteria are also published in the OSCAL (Open Security Controls Assessment Language) format. This enables organizations to automate compliance and audit processes more effectively and integrate the framework into existing GRC and security toolchains.
In my opinion, A5 has the potential to become for AI systems what C5 is for cloud services and ISO/IEC 27001 is for information security management.
Professionals who become familiar with this framework at an early stage will gain a valuable advantage in the rapidly evolving fields of AI Security, AI Governance, and AI Auditing.


For more information and to access the Community Draft, visit the official website: Federal Office for Information Security (BSI)

 

AI Can Already Execute Full Cyberattacks. And It’s Happening Now

04 August 2026

A recent incident at Hugging Face shows how capable autonomous AI agents have become. Over 4.5 days, an agent carried out over 17,000 actions, exploiting known vulnerabilities, hopping between internal systems, and hunting for stored credentials. What stands out here isn't zero-day exploits, but speed and persistence. The agent simply chained routine weaknesses together faster than a human operator ever could. The defense side was just as telling. While security teams used AI to parse the attack logs, standard commercial models choked—refusing to analyze the payload data due to safety guardrails. They had to spin up a local open-weight model (GLM 5.2) just to complete the forensics.

A few quick takeaways:

- Zero Trust and Least Privilege aren't optional anymore.

- Hardcoded credentials and loose secrets will get picked apart instantly.

- Safety guardrails in commercial AI can actually hinder incident response when you need raw log analysis.

Going forward, cybersecurity won't just be human vs. human, it's going to be automated systems competing at speeds we can't manually match.

 
Source: https://huggingface.co/

Inside OilRig (APT34): Anatomy of an Iranian Cyber Espionage Group

28 July 2026

OilRig APT34 cyber espionage group briefing This video provides a structured overview of OilRig (APT34), an Iranian state-aligned Advanced Persistent Threat (APT) group known for conducting long-term cyber espionage campaigns targeting government organizations, critical infrastructure, energy, telecommunications, finance, and other strategic sectors.

The briefing examines the group's identity, motivations, capabilities, attack lifecycle, malware ecosystem, command-and-control techniques, victim targeting, and defensive considerations. It also explores OilRig's tradecraft using the MITRE ATT&CK® framework and the Lockheed Martin Cyber Kill Chain®, helping viewers understand how the group operates and how organizations can strengthen their detection and defense capabilities.

This presentation was originally developed as part of a Cyber Threat Intelligence course project and has been further refined into a comprehensive educational briefing using publicly available information from authoritative industry and government sources.

Read more: Inside OilRig (APT34): Anatomy of an Iranian Cyber Espionage Group

DDoS Attack on Meaning

15 May 2026

Modern hybrid warfare no longer targets only infrastructure, territory, or military systems. Increasingly, it targets collective attention itself.

Armenia’s 2026 parliamentary elections provide a revealing case study of how information overload, emotional saturation, and fragmented media ecosystems can erode strategic thinking inside a society facing existential geopolitical challenges.

In cybersecurity terms, the mechanism resembles a Distributed Denial-of-Service (DDoS) attack. Just as a server becomes overwhelmed by massive volumes of fake traffic and loses the ability to process legitimate requests, societies can also lose the ability to distinguish strategic threats from emotional noise when subjected to continuous informational overload. The result is cognitive exhaustion, fragmented public focus, declining institutional trust, and the gradual collapse of long-term analytical capacity.

This article examines modern political processes through the lens of cybersecurity, hybrid warfare, and cognitive pressure in the digital age.

Full article:  DDoS Attacks on Meaning: Cognitive Warfare in the 2026 Armenian Election


#Cybersecurity #HybridWarfare #InformationSecurity #CognitiveWarfare #Geopolitics #Armenia #OSINT #Disinformation #CyberDefense #DigitalSecurity

The New Logic of Attacks: Why Technical Security Alone No Longer Protects

26 April 2026

For weeks, German security authorities have been warning about an ongoing wave of attacks carried out through the Signal messenger app. Germany’s Federal Office for the Protection of the Constitution and the Federal Office for Information Security describe it as a targeted campaign against politicians, military personnel, and journalists. The Federal Public Prosecutor General is now investigating on suspicion of espionage. The key point: these attacks do not exploit a technical vulnerability. Instead, they use social engineering and legitimate app functions to gain access to chats and contacts. The campaign against political decision-makers reveals a clear pattern: the target is not infrastructure, but identity and trust. The attacker does not need zero-day exploits, malware, or network access. A single successful social engineering contact is enough to create legitimate access. This is the real disruption: for decades, security architectures were built around systems: firewalls, EDR, network segments. This attack bypasses all of that completely and targets the human being directly as part of the architecture. Messengers such as Signal effectively function as decentralized identity systems without organizational control. A phone number or username replaces traditional IAM mechanisms, while features such as “device linking” become a new entry point. Security remains technically intact, but is overridden by user decision-making.

Read more: The New Logic of Attacks: Why Technical Security Alone No Longer Protects
  1. Artemis II and IT Security Principles
  2. Anthropic as the “Brain” of Military Command – What Role Does Cybersecurity Play?
  3. Russia’s Domestic RAM Initiative: Cyber Resilience Under Technological Pressure
  4. Cyber Is the New Battlefield: Germany’s Strategic Wake-Up Call

Page 1 of 2

  • 1
  • 2

© 2026 Grigoryan.info

A personal, non-commercial website for cybersecurity learning and analytical notes.

Legal Notice | Privacy Policy

grigoryan.info
  • GrigoryanInfo
  • Articles
  • Analysis
  • LinkedIn
  • GitHub
  • Resources
  • contact@grigoryan.info