Category: AI Security
FakeGit Campaign Weaponizes 7,600 GitHub Repos to Spread SmartLoader and StealC
A sprawling malicious repository network dubbed FakeGit is using fake AI skills and MCP server listings to bait both developers and AI…
OpenAI’s Own AI Models Hacked Hugging Face While Cheating on a Benchmark Test
OpenAI confirms that GPT-5.6 Sol and an unreleased model autonomously breached Hugging Face's production infrastructure during internal testing, chaining a zero-day exploit…
Ivanti’s CSO Tests LLMs to Speed Up Vulnerability Remediation
Ivanti CSO Daniel Spicer says frontier language models are showing early promise in vulnerability triage and remediation, though cost and human oversight…
JadePuffer Agentic Attacker Deploys AI-Targeted Ransomware EncForge
The autonomous JadePuffer agent has added custom Go-based ransomware that specifically encrypts AI model checkpoints, vector databases, and training datasets, escalating an…
Russian-Speaking Hacker Used Gemini CLI to Run Dental Clinic Botnet
A threat actor tracked as bandcampro leaned on Google's open-source Gemini CLI to automate password cracking and botnet management, according to an…
EU Forces Google to Give Rival AI Assistants Same Android Access as Gemini
The European Commission has ordered Google to open Android's camera, microphone, screen contents and background app control to competing AI assistants, with…
Podcast: ICS Security Veteran Reveals Open-Source Agentic AI Project MindStone
In a SecurityWeek interview, industrial cybersecurity expert Clint Bodungen discusses failures in traditional security governance and unveils MindStone Agent, an open-source project…
Google Cloud Folds Wiz Capabilities Into Agentic Defense Platform
Google Cloud is betting that autonomous, AI-driven defense tools can detect and remediate threats faster than human-led security operations, folding Wiz's cloud…
New NadMesh Botnet Scans for Exposed AI Tools to Steal Cloud Keys
A Go-based botnet dubbed NadMesh is scanning the internet for unsecured AI services like ComfyUI, Ollama, and Open WebUI, harvesting AWS keys…
Agentic AI Is Untamable: Security Teams Need New Questions, Not New Tools
Dark Reading argues that agentic AI's core risk isn't external attackers exploiting it, but the technology's own autonomous behavior, demanding a fundamental…
Trump Administration Launches AI-Driven ‘Gold Eagle’ Vulnerability Clearinghouse
A new Treasury-housed initiative uses artificial intelligence, including closed-source models, to detect, validate and coordinate patching of software vulnerabilities across government and…
Threat Actor Turns Google Gemini CLI Into a Botnet Operator
Researchers found a Russian-speaking attacker using Gemini CLI as an autonomous hacking agent, tasking it to run C2 infrastructure, migrate servers, and…