Category: AI Security
Agentic AI Is Untamable: Security Teams Need New Questions, Not New Tools
Dark Reading argues that agentic AI's core risk isn't external attackers exploiting it, but the technology's own autonomous behavior, demanding a fundamental…
Trump Administration Launches AI-Driven ‘Gold Eagle’ Vulnerability Clearinghouse
A new Treasury-housed initiative uses artificial intelligence, including closed-source models, to detect, validate and coordinate patching of software vulnerabilities across government and…
Threat Actor Turns Google Gemini CLI Into a Botnet Operator
Researchers found a Russian-speaking attacker using Gemini CLI as an autonomous hacking agent, tasking it to run C2 infrastructure, migrate servers, and…
Anthropic Extends Free Claude Fable 5 Access for Paid Users to July 19
Anthropic has pushed back the deadline for included Fable 5 usage on paid Claude plans for a second time, giving subscribers another…
Ghostcommit: Researchers Hide Prompt Injection in Images to Loot Secrets via AI Agents
A proof-of-concept attack from UMKC's ASSET Research Group buries data-exfiltration instructions inside a PNG that AI code reviewers never open, then waits…
AI Coding Assistants: Do Hidden Security Costs Erase the Productivity Gains?
Subscription fees of $19 to $200 per user per month are only the visible cost of AI coding tools. Security scanning, remediation,…
AI Agents Are Widening the Machine Identity Security Gap
New research and a real-world OAuth token breach show that identity security programs built for humans are struggling to keep pace with…
Microsoft: AI-Powered Vulnerability Scanning Will Mean More Windows Patches
Microsoft is deploying a multi-model AI scanning system to find bugs in Windows binaries faster, and says customers should expect a higher…
GhostApproval: Symlink Attack Tricks AI Coding Assistants Into Hacking Dev Machines
Wiz researchers demonstrated that a decades-old symbolic link technique can fool popular AI coding assistants into writing to sensitive system files, with…
AI Coding Agents Triggering Endpoint Security Rules Built for Attackers
Sophos analysis of endpoint telemetry found that AI coding tools like Claude Code, Cursor, and OpenAI Codex are firing behavioral detection rules…
Prompt Injection Flaw in GitHub Agentic Workflows Can Expose Private Repos
A vulnerability dubbed GitLost allows unauthenticated attackers to leak private repository contents by hiding malicious instructions inside a public GitHub Issue, requiring…
Google Dialogflow CX Flaw Let Attackers Hijack AI Chatbot Conversations
A vulnerability dubbed Rogue Agent allowed an attacker with edit access to one Dialogflow CX agent to silently compromise all Code Block-enabled…