Category: AI Security
Carbonato Botnet Weaponizes AI Agent Framework on Hacked Docker Hosts
A new botnet called Carbonato compromises exposed Docker daemons to install the open source Hermes Agent AI framework, letting attackers issue commands…
Claude Opus 5.5 Cuts Em Dash Use by 95%, But Answers Grow Longer
New analysis from AI benchmarking tool Arena shows Anthropic's Claude Opus 5.5 is shedding telltale AI writing patterns like em dashes and…
US and China Agree to Set Up AI Incident Communication Channel
Following a summit between Presidents Trump and Xi, Washington and Beijing agreed to establish a mechanism for coordinating on AI-related incidents and…
‘SalesBleed’ Bugs in Salesforce Agentforce Allowed Zero-Click CRM Data Theft
Zenity Labs found three flaws in Salesforce Agentforce that let attackers poison Web-to-Lead forms to silently exfiltrate CRM data and hijack the…
OpenAI Research Agents Breached Australian Medicare Portal, Probed Other Data Sites
Australian PM Anthony Albanese confirmed OpenAI agents bypassed security blocks to access a Services Australia Medicare statistics portal, while a separate research…
Outerlimit Emerges With $16M to Rein In Rogue AI Agents
Startup Outerlimit launched from stealth with $16 million in pre-seed funding, building a decentralized authorization layer meant to discover, watch, and stop…
Viral AI Actress’ Hotline Face-Scans Every Caller to Check Age and Mood
Talking Tilly, the video-call service behind viral AI actress Tilly Norwood, quietly added a mandatory biometric age check and always-on emotion tracking…
Researchers Break Out of OpenAI Codex Sandbox to Reach the Host
Two sandbox escapes in OpenAI's Codex coding agent, one triggerable just by asking about a malicious repository, let attackers run unsandboxed commands…
TigerByte Cyber Launches With $3M to Harden Edge and AI Devices
The Hanover, NH startup is bringing hardware-enforced security, including post-quantum encryption, to legacy and mission-critical edge systems across military and commercial sectors.
Researchers Use Claude Opus 5 to Chain Flaws, Hijack OpenAI Staff Accounts
Security firm Hacktron used Anthropic's Claude Opus 5 to chain a help forum bug with an OpenAI login weakness, taking over employee…
BragJack: Malicious Extension Hijacks AI Browser Agents in Chrome, Edge, Comet, Opera Neon
Researcher Gal Weizman demonstrated how a single browser extension can seize control of built-in AI assistants across five Chromium based browsers, earning…
UN Launches Open-Source Data Commons Platform Built on Google’s AI-Ready Knowledge Graph
The UN System Data Commons unifies previously siloed statistics from across UN agencies into a single searchable, natural-language platform, with AI agents…