Category: AI Security
Anthropic Extends Free Claude Fable 5 Access for Paid Users to July 19
Anthropic has pushed back the deadline for included Fable 5 usage on paid Claude plans for a second time, giving subscribers another…
Ghostcommit: Researchers Hide Prompt Injection in Images to Loot Secrets via AI Agents
A proof-of-concept attack from UMKC's ASSET Research Group buries data-exfiltration instructions inside a PNG that AI code reviewers never open, then waits…
AI Coding Assistants: Do Hidden Security Costs Erase the Productivity Gains?
Subscription fees of $19 to $200 per user per month are only the visible cost of AI coding tools. Security scanning, remediation,…
AI Agents Are Widening the Machine Identity Security Gap
New research and a real-world OAuth token breach show that identity security programs built for humans are struggling to keep pace with…
Microsoft: AI-Powered Vulnerability Scanning Will Mean More Windows Patches
Microsoft is deploying a multi-model AI scanning system to find bugs in Windows binaries faster, and says customers should expect a higher…
GhostApproval: Symlink Attack Tricks AI Coding Assistants Into Hacking Dev Machines
Wiz researchers demonstrated that a decades-old symbolic link technique can fool popular AI coding assistants into writing to sensitive system files, with…
AI Coding Agents Triggering Endpoint Security Rules Built for Attackers
Sophos analysis of endpoint telemetry found that AI coding tools like Claude Code, Cursor, and OpenAI Codex are firing behavioral detection rules…
Prompt Injection Flaw in GitHub Agentic Workflows Can Expose Private Repos
A vulnerability dubbed GitLost allows unauthenticated attackers to leak private repository contents by hiding malicious instructions inside a public GitHub Issue, requiring…
Google Dialogflow CX Flaw Let Attackers Hijack AI Chatbot Conversations
A vulnerability dubbed Rogue Agent allowed an attacker with edit access to one Dialogflow CX agent to silently compromise all Code Block-enabled…
Pixel 10 Embeds C2PA Content Credentials at Highest Assurance Level
Google's Pixel 10 lineup becomes the first mobile platform to achieve C2PA Assurance Level 2, using hardware-backed security to attach verifiable provenance…
SkillCloak Technique Lets Malicious AI Agent Skills Bypass Static Scanners
Researchers at Hong Kong University of Science and Technology have demonstrated a self-extracting packing technique that evades static security scanners for AI…
Google Details Layered Defense Strategy Against Prompt Injection in Gemini
Google's GenAI Security Team has outlined a multi-layer mitigation framework targeting indirect prompt injection attacks in Gemini, covering model hardening through to…