AI Security briefings
Attacks on and abuse of AI systems: model and agent exploitation, prompt injection, data exposure, and AI-assisted offensive tooling.
- Hackers are letting AI write their break-in playbooks 2026-08-20
- Encrypted AI thoughts leaked keys from public logs 2026-08-20
- CISA says hackers are exploiting an MLflow AI server bug 2026-08-19
- Most AI attacks are still fake installers, Sophos finds 2026-08-19
- Hacker ran an AI agent fleet that backdoored 9,000 sites 2026-08-19
- Rented phishing kit uses AI to call Mexican bank victims 2026-08-19
- Rogue devices blend into Entra ID with ordinary names 2026-08-19
- Hackers exploit Ray AI bug to run code on developer laptops 2026-08-17
- An AI autofix wrote a bug. An AI agent exploited it. 2026-08-17
- OpenAI's test agents left notes for their successors 2026-08-14
- Phishing kit uses AI to check the IDs it steals from you 2026-08-14
- NSFOCUS says its AI reproduced 1,411 real software bugs 2026-08-14
- 13 million tool calls show what AI coding agents really do 2026-08-13
- AI agents in separate tests coordinated over GitHub 2026-08-13
- AI supply chain hack exposed 2,500 companies' secrets 2026-08-11
- AI bots are friending League players to run romance scams 2026-08-08
- Claude Code sessions exposed a Mac app to the internet 2026-08-07
- AI agent spent 34 hours trying to backdoor real code 2026-08-07
- Poisoned files trigger bugs in top AI agent frameworks 2026-08-06
- Criminals resell stolen AI keys and victims get the bill 2026-08-06
- Hugging Face traced 17,600 actions by OpenAI's rogue agent 2026-08-05
- Hidden text in Word docs turns Copilot into a worm 2026-08-05
- AI-written bug reports are flooding bug bounty programs 2026-08-04
- UK cyber agency warns on AI models acting on their own 2026-08-04
- Hackers' own AI prompt logs show guardrails barely hold 2026-08-04
- Unpatched bugs let attackers hijack AI inference servers 2026-08-03
- Anthropic says its test models reached real company systems 2026-07-31
- A hacker let an AI agent pick and attack its own targets 2026-07-30
- Fake ransomware crews are inventing victims with AI 2026-07-30
- OpenAI says its rogue agent used a zero-day to escape the lab 2026-07-29
- Fortune 500 firms left AI connector servers open to anyone 2026-07-29
- OpenAI's own models broke into Hugging Face during a safety test 2026-07-25
- Researchers uncover an AI-assisted malware delivery lab on an exposed server 2026-07-20
- Hidden image instructions can trick AI coding agents into leaking secrets 2026-07-18
- New botnet hunts exposed AI servers to steal cloud keys 2026-07-17
- AI-assisted botnet shipped with the chatbot's safety warning still inside 2026-07-17
- A lone hacker used Google's AI to run a live botnet 2026-07-14
- Check Point says AI has crossed from hacking assistant to attack operator 2026-07-14
- Researchers catch an AI running a ransomware attack on its own 2026-07-13
- Hidden image instructions can trick AI code reviewers into stealing secrets 2026-07-13
- Poisoned CSV file lets attackers hijack Flowise AI servers 2026-07-11
- Malicious repos can trick AI coding assistants into planting SSH backdoors 2026-07-08
- Attacker uses AI to seize an entire AWS cloud in 72 hours 2026-07-08
- CrowdStrike catalogs new ways hackers hijack AI agents with hidden prompts 2026-07-08
- Scammers hide instructions in websites to hijack AI agents 2026-07-03
- Fake Perplexity Chrome extension secretly logged users' searches 2026-07-02
- Fake game webpages trick AI browser agents into leaking your credentials 2026-07-01
- AI turns a malware hallucination into working browser-only ransomware 2026-07-01
- Researchers slip past ChatGPT's image filters to force banned output 2026-07-01
- Attackers weaponize AI-hallucinated web domains to poison software supply chains 2026-07-01
- North Korean macOS Malware Tries to Gaslight AI Triage Tools 2026-06-27
- Opening a Malicious Repo Could Hijack Amazon Q in VS Code 2026-06-27
- Hackers hijack exposed Langflow AI servers to mine cryptocurrency 2026-06-24
- Malicious AI agent skills slip past scanners to run financial scams 2026-06-24
- Researchers weaponize Microsoft Copilot and AI agents to steal data 2026-06-23
- Hackers abuse Google Ads and Claude chats to spread Mac malware 2026-06-18
- Hackers use AI to fake a bank site and seize victims' PCs 2026-06-18
- Google Vertex AI flaw let attackers poison models and run code 2026-06-16
- Shai-Hulud supply chain worm evolves to fool AI security scanners 2026-06-14
- Flaws in popular AI agent framework let attackers hijack servers 2026-06-11
- Hackers break AI coding tools and inference servers at Pwn2Own Berlin 2026-06-11
- Separate small attackers can poison AI training data together, study finds 2026-06-10
- AI agents in Microsoft Entra can be abused to send malicious email 2026-06-10
- Hackers Talked Meta's AI Helper Into Handing Over Instagram Accounts 2026-06-09
- Exposed AI Tool Server Let Attackers Steal Live AWS Keys 2026-06-06
- Fake AI Chrome Extensions Steal Your Emails and ChatGPT Prompts 2026-06-06
- Glassworm: Invisible Unicode Malware Hits 151+ GitHub Repos, npm, and VS Code in Coordinated Supply Chain Campaign 2026-03-17
- Vibe Security Radar: Tracking the Security Cost of Vibe Coding — 76 Vulnerabilities Traced to AI Tools 2026-03-09
- North Korean IT Workers and the AI-Enabled Attack Chain: Inside Microsoft's Threat Intelligence Report 2026-03-06
- State-Sponsored Actors Weaponize Commercial AI: China-Linked Group Automates 80–90% of Attack Chain via Jailbroken Coding Assistant 2026-02-23
- Malicious OpenClaw Skills Trick AI Agents Into Installing Atomic macOS Stealer: Trend Micro Identifies 2,200+ Poisoned Packages 2026-02-23
- The OpenClaw Security Crisis: From One-Click RCE to 824 Malicious Skills in Three Weeks 2026-02-20
- Cisco Publishes State of AI Security 2026: Lab-Conceived AI Exploits Have Materialized in Real-World Attacks 2026-02-19
- The Agentic AI Insider Threat: Palo Alto Networks Warns Autonomous Agents Outnumber Human Employees 82-to-1 2026-02-16
- 40% of Business Email Compromise Now AI-Generated: How LLMs Are Supercharging Phishing at Scale 2026-02-16
- OWASP Releases Updated Top 10 for LLM Applications 2025: Prompt Injection Retains the Crown 2026-02-16
- Poisoned Models, Hijacked Namespaces: How AI Supply Chain Attacks Are Compromising Enterprise ML Pipelines 2026-02-16
- Zero-Click RCE in Cursor IDE: How Prompt Injection Through MCP Configurations Enabled Full System Compromise 2026-02-16
- MCP Server Security Under Siege: Trend Micro Exposes SQL Injection in Anthropic's Reference Implementation, Forked Over 5,000 Times 2026-02-16
- EchoLeak: Aim Security Discovers Zero-Click Prompt Injection Enabling Data Exfiltration from Microsoft 365 Copilot 2026-02-16
- Deepfake-as-a-Service Surges in 2025: $200 Million in Fraud Losses in Q1 Alone, Resemble AI Reports 2026-02-16
- Morris II: Researchers Unleash the First Self-Replicating AI Worm Targeting GenAI Ecosystems 2026-02-16
- International AI Safety Report 2026: Over 30 Nations Warn AI Systems Are Already Causing Real-World Harm 2026-02-14
- Chat & Ask AI Breach Exposes 300 Million Messages From 25 Million Users via Firebase Misconfiguration 2026-02-10