H AI APT Attack BigBrothers BotNet Congress Cryptocurrency Cyber CyberCrime Exploit Hack ICS Incindent IoT Mobil OS Phishing Ransom Safety Security Social Spam Virus Vulnerebility | 2026 2025 2024 2023
DATE | NAME |
Info | CATEG. |
WEB |
|
3.9.26 |
Malicious .git Configs Can Make Claude, Codex, Cursor, and Other AI Agents Run Attacker Code | Manifold Security has disclosed eight security flaws across seven command-line AI coding agents in which a repository's own Git | AI | The Hacker News |
|
2.9.26 |
Anthropic warns infostealer malware is hijacking Claude sessions to drain usage | Anthropic is warning some Claude users that infostealer malware on their PCs has stolen active Claude login sessions, allowing attackers to access accounts and consume their usage. | AI | BleepingComputer |
|
1.9.26 |
Attackers Steal METR API Key and Consume AI Credits Worth About $600,000 | METR (short for Model Evaluation and Threat Research and pronounced "Meter"), a research non-profit that evaluates frontier artificial intelligence | AI | The Hacker News |
|
30.8.26 |
Anthropic is cutting Claude Code's current weekly limits by 17% | Anthropic is permanently increasing Claude Code's standard weekly usage limits by 25% for Pro, Max, Team, and seat-based Enterprise plans, but it's not as good as it sounds. | AI | BleepingComputer |
|
30.8.26 |
AI Is Accelerating Vulnerability Discovery. Can Defenders Keep Up? | AI is accelerating vulnerability discovery, putting pressure on systems built to enrich, prioritize, and remediate flaws at a slower pace. Action1 explains why defenders increasingly need to correlate multiple intelligence sources and turn vulnerability data into faster remediation. | AI | BleepingComputer |
|
30.8.26 |
Nearly 700 rogue AI agents coordinated in the Hugging Face attack | New details about the July attack on Hugging Face reveal that hundreds of AI agents driven by OpenAI's internal IM1 model coordinated the compromise through an unauthorized message board. | AI | BleepingComputer |
| 28.8.26 | OpenAI Says Reward Hacking Drove AI Agents to Exploit Zero-Days and Breach Hugging Face | OpenAI on Wednesday revealed that reward hacking was a key driver behind the artificial intelligence (AI)-powered hack of Hugging Face last | AI | The Hacker News |
|
26.8.26 |
Picture this: You've just unboxed a shiny new Macbook, and now you're downloading all of your favorite apps. You type "How to install Claude Code on a Mac" in Google and click on the first link at the top of the page. |
|||
|
26.8.26 |
Imagine the SOC Without a Queue: From Alert Backlog to AI Hypothesis Engine |
The SOC we've always known was built around a model that guarantees most of the alert queue will never receive analyst review. There's never |
||
|
26.8.26 |
Claude Opus 4.6 Bypasses Gym Booking Limit, Cancels Other Users' Reservations in Tests |
Aikido Security has published research that recreates the Australian gym-booking incident in a synthetic environment, finding that Claude Opus 4.6, |
||
|
26.8.26 |
OpenAI Bans Russian ChatGPT Accounts Used to Run Influence Operation |
OpenAI on Tuesday said it banned a cluster of Russian ChatGPT accounts that used VPNs to bypass access restrictions and run an influence |
||
|
26.8.26 |
Fake Apple Support AI Calls Target Stolen-Device Owners for Passcodes and 2FA Codes |
Cybersecurity researchers have disclosed details of a phishing-as-a-service (PhaaS) platform built to strip Apple's Activation Lock from stolen devices, using rented AI voice agents that call theft victims posing as Apple Support and ask for their device passcode. |
||
|
25.8.26 |
A Malicious Webpage Could Poison Your Local AI Model Behind NVIDIA NemoClaw |
Oasis Security has disclosed a weakness in NVIDIA NemoClaw that could let an attacker-controlled webpage take unauthenticated control of the |
||
|
25.8.26 |
Escape found the same XSS in two AI chatboxes. The vulnerability was in the Markdown renderer. |
Weeks apart, at two unrelated companies, Escape's AI pentesting agent found the same stored XSS. Both had shipped a customer-facing chat where the model emits Markdown and the frontend renders it with raw HTML enabled and no sanitizer, so anything the model can be made to say executes in the browser of whoever reads the transcript next. |
||
|
24.8.26 |
Frequently asked questions about the active threat to Siemens S7 Series PLCs |
A joint cybersecurity advisory released by multiple U.S. government agencies warns that threat actors are using AI-generated exploitation scripts to target exposed Siemens S7 Series PLCs across critical infrastructure sectors. |
||
|
24.8.26 |
In July 2026, Hugging Face was breached by an autonomous agent swarm that had broken out of an OpenAI Sandbox and was attempting to succeed at ExploitGym, a cyber benchmark. |
|||
|
24.8.26 |
The Outsized Shadow: Why 5% of AI Users Are Your Biggest Security Risk |
Big security risks come in small packages. While enterprise security teams focus on policing the proliferation of employees using ChatGPT and |
||
|
23.8.26 |
ChatGPT is experiencing a major outage, and users are unable to sign in, create accounts, or load chats, including previous conversations. |
|||
|
23.8.26 |
US warns of AI-powered attacks on Siemens PLCs in critical infrastructure |
U.S. cybersecurity agencies warn that threat actors are using AI-generated scripts to exploit Siemens S7 Series programmable logic controllers (PLCs) in U.S. critical infrastructure. |
||
|
21.8.26 |
AI-Generated Exploit Scripts Target Siemens S7 PLCs in U.S. Critical Infrastructure |
The U.S. government on Wednesday warned of an "active threat" targeting critical infrastructure organizations in the country using artificial |
||
|
20.8.26 |
Anthropic confirms Claude is down in major outage affecting multiple services |
Claude is experiencing a major outage, with users reporting login problems and degraded performance across several Anthropic services. |
||
|
20.8.26 |
OpenAI Pauses Frontier RL Training as It Tightens Defenses Against Unsafe AI Behavior |
OpenAI on Tuesday revealed that it paused reinforcement learning ( RL ) training for its latest artificial intelligence (AI) models for two weeks while |
||
|
19.8.26 |
AI memory transforms an AI system from a stateless tool into a learning collaborator. That unlocks powerful experiences, but it also increases the attack surface of the AI system. |
|||
|
19.8.26 |
Microsoft Copilot Personal Flaws Could Let One Click Exfiltrate Data From Connected Apps |
Varonis Threat Labs has disclosed three vulnerabilities in Microsoft Copilot Personal that it said could allow a single click on a crafted link to silently pull data from connected apps and other information available to |
||
|
19.8.26 |
AI "Mind Viruses" Can Spread Between Agents Through Persistent Prompt Files |
Security researchers at Anthropic and Switzerland's EPFL have demonstrated that self-propagating payloads can spread from one |
||
|
18.8.26 |
When the OWASP Top 10 for LLM Applications arrived, it did the industry a real service. It gave security teams a stable, vendor-neutral vocabulary for a threat surface that was moving too fast to describe. |
|||
|
16.8.26 |
How Anthropic plans to watermark Claude's AI-generated text |
|||
|
16.8.26 |
The Modern Attack Chain: Rethinking Google Workspace Security in the Age of AI |
Google Workspace attacks do not always begin with phishing. Stolen OAuth tokens can provide another path into Gmail, Drive, and connected systems. Material Security explains why organizations need defenses that cover the entire Workspace attack chain. |
||
|
16.8.26 |
AI 'watermark removers' flood the web. Almost none can prove they work. |
Multiple 'watermark removers' have surfaced days after Anthropic began watermarking text generated by Claude, including an open source project with over 4,500 GitHub stars and paid AI detection evasion services. None of the tools' claims about defeating the text watermark can be verified, as Anthropic has not released a detector. |
||
|
16.8.26 |
Who Vets AI’s Code? The Scale Challenge Facing Open Source Ingestion |
AI coding tools can introduce unvetted or hallucinated open source dependencies faster than traditional security reviews can keep pace. ActiveState explains why organizations should govern packages at the point of selection, before they enter the development pipeline. |
||
|
15.8.26 |
Vague Task, Total Access: When AI Delegation Becomes a Security Risk |
AI agents can improvise beyond the intended scope of a task when they are given broad access to enterprise systems and data. Token Security explains why organizations need to define agent intent and continuously enforce permissions around what each agent was actually created to do. |
||
|
13.8.26 |
Russian AI Slopsquatting Publishes 700+ Malicious NPM Packages |
NUL1DROPPER, aka Flooding Dropper, is a new downloader targeting mobile SDK installs a RAT to Windows, Mac, and Linux with no install script required |
||
|
13.8.26 |
OpenAI releases ChatGPT 5.6 Cyber, but it's only for approved users |
OpenAI has developed a new model called "GPT 5.6 Cyber," designed for vulnerability research, penetration testing, incident response, and remediation. |
||
|
12.8.26 |
A repository could execute any command it chose on your machine, as you, the moment you started Cursor's CLI agent in it with -w. It ran before the workspace-trust dialog, and fired even for users who had explicitly passed --sandbox enabled. |
|||
|
12.8.26 |
OpenAI, Anthropic, Google API Flaw Let Weaker AI Models Decode Stronger Models' Reasoning |
A newly disclosed flaw in the way OpenAI, Anthropic, and Google carried hidden AI reasoning between API calls let researchers recover internal |
||
|
12.8.26 |
ThreatLabz 2026 Report: Frontier AI and Enterprise Readiness |
It was 9:14 AM when the CISO's VPN connection momentarily dropped, something that normally wouldn’t cause any concern. What he couldn't see was that attackers had already exploited a pre-authentication flaw in the VPN appliance itself, gaining access before any login ever occurred. |
||
|
11.8.26 |
Researchers Disclose AI-Assisted SharePoint Exploit Chain Reaching Unauthenticated RCE |
Security researchers found a way to enter Microsoft SharePoint servers as any user, including an administrator, with no valid account. A significant |
||
|
11.8.26 |
OpenAI Launches GPT-5.6-Cyber with Reduced Safeguards for Exploit Development |
OpenAI on Monday unveiled a new cybersecurity-focused model called GPT‑5.6‑Cyber that it said is focused on vulnerability research, penetration |
||
|
11.8.26 |
Malicious MCP Servers Can Split Instructions to Make AI Coding Agents Exfiltrate Secrets |
A malicious tool server connected to an AI coding assistant can quietly walk off with SSH keys, environment secrets, source code, and customer |
||
|
10.8.26 |
Emergence of APT attacks using generative AI "ChatGPT" |
|||
|
10.8.26 |
Kimsuky Integrates AI into Attack Operations, From AI-Generated Decoy Documents to a Local LLM |
Observed indications that the Kimsuky group built and operated local LLM environments using Ollama, GPT4All, and Msty. |
||
|
10.8.26 |
Shipping 10–50× More Code? Watch This Webinar on Securing AI-Speed Development |
AI is helping development teams produce far more code, far faster. But security teams still have to review vulnerabilities, manage dependencies, |
||
|
10.8.26 |
OpenAI's Next AI Model Astra Shows Cyber Performance Strong Enough to Trigger Pause |
OpenAI has announced that it's pausing some "internal activities" involving its upcoming artificial intelligence (AI) model Astra after an internal |
||
|
9.8.26 |
OpenAI rolls out a major ChatGPT upgrade, even if you don’t pay for it |
OpenAI is rolling out a more reliable version of ChatGPT GPT-5.6 Sol for Plus and Pro users, while Free users are getting unlimited text chats with GPT-5.6 Luna. |
||
|
9.8.26 |
Meta AI model hacked a company during misconfigured cyber test |
Meta has become the latest AI company to confirm that one of its models hacked a real organization during cybersecurity testing, as similar incidents continue to emerge following OpenAI'sOpenAI's initial disclosure that its agents breached Hugging Face. |
||
|
8.8.26 |
AI is helping attackers create disposable phishing infrastructure and rapidly evolving toolkits that blocklists cannot track fast enough. Push Security explains why browser-level, technique-based detection offers a more durable defense than relying on domains, signatures, and other known-bad indicators. |
|||
|
8.8.26 |
OpenAI, Anthropic AI agents targeted real people and systems in cyber tests |
OpenAI and Anthropic have confirmed that their AI models were involved in separate, newly disclosed third-party cybersecurity testing incidents that resulted in a real website being breached and social engineering attacks against people outside the intended testing boundaries. |
||
|
8.8.26 |
Varonis Agent IBAC keeps AI agents within their intended boundaries |
AI agents need broad access to be useful, but traditional access controls cannot determine whether an action aligns with a user's intent. Varonis explains how Agent IBAC detects intent drift and enforces real-time guardrails to keep agents within their intended boundaries. |
||
|
7.8.26 |
AI-Assisted HTTP Terminator Finds Novel HTTP Desync Techniques and Apache Zero-Day |
PortSwigger says HTTP Terminator, an artificial intelligence (AI)-assisted research system built by James Kettle , generated and proved new HTTP |
||
|
7.8.26 |
Claude Code and Gemini CLI Flaws Let a GitHub Issue Reach CI Workflow Secrets |
A GitHub issue opened by an account with no repository privileges was enough to execute code on the CI runners behind Anthropic's and Google's |
||
|
6.8.26 |
IBM study finds deepfake attacks now account for nearly half of AI-enabled breaches as organizations grapple with rising costs and expanding cyber risks. |
|||
|
6.8.26 |
As AI models have become vastly more capable, these multifunctional tools are being used for a wide range of tasks—from coding and analysis to software testing, research, and vulnerability hunting. |
|||
|
6.8.26 |
OpenAI Disrupts Poipet Scam Network Using ChatGPT Across Multiple Fraud Schemes |
OpenAI said it disrupted a Cambodia-based scam operation that used its generative artificial intelligence (AI) chatbot ChatGPT to facilitate a wide |
||
|
5.8.26 |
Poison Claude Sells Discounted Claude Access While Its Operator Sees Every Customer Prompt |
Cybersecurity researchers have discovered more than half-a-dozen services advertisements for illegal access to artificial intelligence (AI) |
||
|
5.8.26 |
Paperclip AI Flaws Let Attackers Run Host Commands via Malicious Agent Imports |
Two security flaws in Paperclip could let attackers execute commands on a network server or a developer's computer. Paperclip is an open-source |
||
|
5.8.26 |
OpenAI teases Astra, its next major AI model, after it solves 10 long-standing math problems |
OpenAI has revealed Astra, an unreleased model designed to tackle complex, long-running tasks, after an internal version produced ten significant advances in mathematics and theoretical computer science. |
||
|
5.8.26 |
Claude Mythos 5 Tried to Backdoor a Real Open-Source Project in Testing, Then Vouched for Itself |
An agent running Anthropic's Claude Mythos 5 spent 34 hours trying to get a malware dropper merged into a real open-source project during a cyber |
||
|
4.8.26 |
Google Deletes 3 ADK AI Workflows After Malicious GitHub Issue Could Trigger Privileged Agent |
Google deleted three AI agent workflows from its Agent Development Kit (ADK) Python repository. Pillar Security showed that a public GitHub issue |
||
|
2.8.26 |
OpenAI says its new GPT 5.6 models are becoming more cost-efficient |
OpenAI says it has reduced the price of two GPT-5.6 models, cutting Luna's API price by 80% and Terra's by 20% as it works to make its models more efficient. |
||
|
2.8.26 |
Hacker uses DeepSeek AI to autonomously attack vulnerable servers |
A Chinese-speaking threat actor is using the DeepSeek AI model and the open-source Hermes Agent to conduct autonomous cyberattacks on exposed servers with limited human involvement. |
||
|
2.8.26 |
ESET tracks rise in malicious AI skills and adaptable malware |
Attackers are adapting established techniques to AI platforms, emerging technologies, and changing user behavior. ESET's new threat report examines the rise of malicious AI skills, AI-assisted malware, ClickFix attacks, record quishing activity, and ransomware tools designed to disable security software |
||
|
2.8.26 |
Anthropic's Claude breached 3 orgs, uploaded PyPI malware during tests |
One of Anthropic's Claude models built and uploaded a malicious Python package to PyPI during a botched security evaluation, where it ran on 15 real systems and stole credentials from a security vendor. It was one of three incidents affecting real companies. |
||
|
2.8.26 |
Google says AI helped Chrome fix 1,072 security bugs in two releases |
Google says artificial intelligence is dramatically increasing the number of security vulnerabilities it can find and fix in Chrome, with more than 1,000 security bugs patched across the browser's two most recent releases as it expands its use of AI. |
||
|
2.8.26 |
Claude is down for some users, with Anthropic confirming elevated errors across multiple AI models. The disruption is causing requests to fail with a "529 Overloaded" message, including in Claude and tools that rely on its API. |
|||
|
1.8.26 |
OpenAI agent used exposed credentials at 4 services in Hugging Face breach |
In a new update, OpenAI says its AI models also used publicly exposed credentials to compromise accounts on four third-party services during the recent attack on Hugging Face, expanding the scope of the four-day security incident to other organizations. |
||
|
1.8.26 |
Your AI Agents Are Guessing at Scale: Permissions Decide the Damage |
AI agents are designed to improvise as they complete tasks, making broad permissions a growing security risk. Token Security explains why identity, intent-based access controls, and least privilege are becoming the foundation for securing agentic AI. |
||
|
1.8.26 |
CubePilot drone software dev hit by DNS hijacking to intercept traffic |
CubePilot, an Australian firm that designs flight controllers for drones (UAVs), announced a severe operational disruption caused by a DNS hijacking attack. |
||
|
1.8.26 |
OpenAI models used Artifactory zero-days to escape to the internet |
JFrog has confirmed that OpenAI models exploited zero-day vulnerabilities in self-hosted Artifactory servers to help escape an isolated testing environment and gain access to the internet before attacking Hugging Face. |
||
|
31.7.26 |
Cybercriminals Are Leveraging Autonomous AI Offensive Security Agents |
Resecurity warns AI offensive agents are lowering hacking barriers, fueling an AI-driven race between attackers and defenders. Resecurity analyzed how autonomous offensive security agents such as ... |
||
|
31.7.26 |
Anthropic Says Claude Mistook the Open Internet for a CTF and Breached Three Organizations |
Anthropic on Thursday became the latest artificial intelligence (AI) company to reveal that three of its models, including Claude Opus 4.7, |
||
|
30.7.26 |
Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory |
Cybersecurity researchers have flagged a maximum-severity security flaw in Ruflo , an open-source agent meta-harness for Anthropic Claude Code |
||
|
29.7.26 |
OpenAI Agent Used Exposed Credentials Across Four Services During Hugging Face Breach |
OpenAI on Tuesday revealed the rogue artificial intelligence (AI) agent that escaped its sealed evaluation environment and broke into Hugging Face's production environment , and also hacked multiple third-party accounts and services as part of the attack. |
||
|
29.7.26 |
Claude AI Just Cracked a Post-Quantum Test Scheme and Found a Faster 7-Round AES Attack |
Anthropic says Claude Mythos Preview helped derive an end-to-end key-recovery attack against HAWK-256 and a 200- to 800-fold speedup for an attack on seven-round AES-128. The HAWK attack exploits a previously unused symmetry in the lattice behind the signature scheme. Anthropic's released implementation gives an expected end-to-end runtime of about three hours and 42 minutes on a 96-core server. |
||
|
28.7.26 |
In the Era of AI-Discovered vulnerabilities, trust belongs to the fastest responders and the level of collaboration established. As AI models continuously expose new classes of vulnerabilities, software products are being held to an entirely new security standard. |
|||
|
28.7.26 |
Researcher Says AI Helped Develop Linux Traffic-Control Race Into Root Exploit |
STAR Labs has published a Linux kernel exploit that turns an ordinary local user into root on the CentOS Stream 9 build it targeted. The flaw, tracked |
||
|
28.7.26 |
Microsoft Says New Cybersecurity AI Model Helps MDASH Hit 95.95% at Half the Cost |
Microsoft has launched its first cybersecurity-specific model inside MDASH , its multi-model vulnerability identification and remediation |
||
|
28.7.26 |
NVIDIA Forms 37-Member Open Secure AI Alliance and Open-Sources NOOA Framework |
NVIDIA and 36 other organizations have formed the Open Secure AI Alliance to develop and share open technologies, techniques, and tools for securing software and artificial intelligence (AI) agents. |
||
|
26.7.26 |
ChatGPT, the famous artificial intelligence chatbot that allows users to converse with various personalities and topics, has connectivity issues worldwide. |
|||
|
26.7.26 |
Hermes AI agent used to automate attack on Thai Finance Ministry |
A threat actor used the open-source Hermes AI agent in unattended "YOLO" mode to automate post-exploitation activity during an alleged breach of Thailand's Ministry of Finance. |
||
|
26.7.26 |
Slopsquatting, Phantom Domains, and HalluSquatting Are the Same AI Attack |
Slopsquatting, phantom squatting, and HalluSquatting all exploit the same late-binding attack pattern, where AI coding agents trust hallucinated package, repo, or domain names. ActiveState explains how pre-fetch verification and governed dependency management can help stop these attacks before malicious code enters the pipeline. |
||
|
25.7.26 |
How enterprise GenAI can amplify ransomware risk — and how to contain it |
Enterprise AI can accelerate ransomware attacks when AI assistants and agents inherit excessive permissions or compromised identities. Acronis explains how identity controls, governance, and least-privilege access help reduce AI-enabled ransomware risk while supporting secure AI adoption. |
||
|
24.7.26 |
Two disclosures, five days apart, described the same intrusion from opposite ends — one from the victim, one from the party that turned out to be responsible — and together they make one of the more instructive incidents of the year for defenders. |
|||
|
24.7.26 |
Disclosure note: This research was conducted jointly by Hunt.io and Bob Diachenko, security researcher and journalist. Thailand's national CERT and NCSA were notified on July 15, 2026, and acknowledged receipt the same day. Publication was held for the standard 7-day disclosure window. |
|||
|
24.7.26 |
ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link |
Cybersecurity researchers have disclosed a critical vulnerability in OpenAI's ChatGPT Workspace Agents that could have allowed a single |
||
|
24.7.26 |
Seeing AI Agents Is Not Enough. Security Teams Must Enforce What They Can Do |
AI agent security is moving through a familiar maturity curve: adoption, then visibility, and finally, control. But what we've collectively discovered is |
||
|
24.7.26 |
Hacker Runs Hermes AI Agent Unattended for Post-Exploitation at Thai Finance Ministry |
Someone installed a popular AI assistant on a rented server, switched off the setting that makes it ask permission before running risky commands, |
||
|
24.7.26 |
NodeBB Patches Eight AI-Found Flaws Exposing Admin Access and Private Chats |
Eight security flaws in NodeBB went public on Wednesday, along with the code to exploit them. Aikido Security rates all eight as high severity and |
||
|
23.7.26 |
Claude Cowork Flaw Could Let AI Agent Escape Its VM and Access Mac Files |
Cybersecurity researchers have uncovered a sandbox escape vulnerability in Anthropic's Claude Cowork that makes it possible to break out of the confines of a Linux virtual machine (VM) within which the agent runs to |
||
|
23.7.26 |
OpenAI says its AI models hacked Hugging Face during testing |
OpenAI says its AI models, including GPT‑5.6 Sol and a pre-release model, hacked into the Hugging Face artificial intelligence repository while being tested in a sandboxed testing environment. |
||
|
22.7.26 |
Microsoft Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Review Agents |
A single invisible comment in an Azure DevOps pull request can turn a reviewer's own AI coding agent against them, driving it into projects the |
||
|
22.7.26 |
OpenAI Says Its AI Models Escaped Sandbox, Targeted Hugging Face to Cheat Benchmark |
OpenAI on Tuesday said a combination of its artificial intelligence (AI) models, including GPT-5.6 Sol and an "even more capable pre-release model," was behind the security incident that targeted Hugging Face's production infrastructure last week. |
||
|
21.7.26 |
Google Launches Gemini 3.5 Flash Cyber AI to Find and Fix Software Vulnerabilities |
Google's DeepMind on Tuesday announced the release of Gemini 3.5 Flash Cyber , a specialized artificial intelligence (AI) model built atop 3.5 |
||
|
21.7.26 |
Cursor, Codex, Gemini CLI, Antigravity hit by sandbox escapes |
Researchers escaped the sandboxes in Cursor, Codex, Gemini CLI and Antigravity by having the AI agent write files that trusted host tools later run. Multiple CVEs, patches, and Google downgrading two Antigravity findings. |
||
|
21.7.26 |
Choosing an AI SOC platform requires understanding how it will perform in your own environment, not just during an evaluation. Prophet Security shares a practical framework for assessing AI SOC solutions, including how to validate accuracy, operating models, long-term reliability, and production readiness. |
|||
|
21.7.26 |
Hugging Face warns an autonomous AI agent hacked its network |
The Hugging Face artificial intelligence repository disclosed that attackers gained access to internal datasets and credentials after breaching its production infrastructure using an autonomous AI agent system. |
||
|
21.7.26 |
Critical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code Execution |
Threat actors are now exploiting a recently disclosed critical security flaw impacting ServiceNow AI Platform, according to Defused Cyber . In a |
||
|
20.7.26 |
Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign |
A malware operator left its delivery server wide open, and Rapid7 pulled down the whole toolkit: 1,048 files spanning lure templates, filename- |
||
|
20.7.26 |
World's Largest AI Model Repository Hugging Face Breached by Autonomous AI Agent |
In an ironic twist, open-source artificial intelligence (AI) platform Hugging Face revealed that it was the victim of a hack perpetrated by an |
||
|
19.7.26 |
Claude Chrome extension flaw lets malicious extensions trigger AI actions |
A flaw in Anthropic's Claude for Chrome browser extension could allow a malicious extension to trigger predefined AI actions by simulating user clicks, potentially allowing it to abuse Claude's access to connected services such as Gmail, Google Docs, Google Calendar, and Salesforce. |
||
|
19.7.26 |
AI Agents Broke the Security Playbook. Here's What Replaces It. |
Traditional security workflows were built for environments that changed at human speed. Token Security explains why AI agents require a new approach: building on a live identity foundation while giving security teams the flexibility to create workflows tailored to their own environments. |
||
|
18.7.26 |
Google Gemini CLI abused as a hacking agent, malware botnet operator |
A Russian-speaking threat actor known as "bandcampro" used Google's open-source Gemini CLI AI tool as a hacking agent and to operate a small-scale botnet. |
||
|
16.7.26 |
New Agent Data Injection Attack Can Make AI Agents Misclick or Run Attacker Commands |
Ask an AI agent to summarize the reviews on a product page, and a single planted review can make it click "Buy Now" instead. Ask a coding |
||
|
16.7.26 |
OpenAI’s GPT-Red Automates Prompt Injection Testing to Harden GPT-5.6 Sol |
OpenAI has disclosed details of GPT-Red , an internal automated red-teaming model that scales prompt injection vulnerability discovery with |
||
|
14.7.26 |
Researchers Say Claude for Chrome Flaw Lets Rogue Extensions Trigger Gmail Reads |
Any other browser extension that can run a script on claude.ai can still trigger Claude for Chrome tasks aimed at your Gmail, your latest Google |
||
|
14.7.26 |
How Pentera Turns AI Security Workflows into Validation Engines |
AI security agents are starting to influence real security decisions. They summarize findings, prioritize remediation, recommend next steps, and |
||
|
14.7.26 |
Grok Build Uploaded Entire Git Repositories to xAI Storage, Not Just Files It Read |
xAI's Grok Build coding CLI was uploading entire Git repositories, full commit history and all, to a Google Cloud Storage bucket run by xAI, not |
||
|
13.7.26 |
Attacker Uses Suspected AI-Generated PowerShell Script to Map Active Directory |
Cybersecurity researchers have flagged an intrusion in which an unknown threat actor leveraged a vibe-coded PowerShell script for Active Directory |
||
|
12.7.26 |
'Ghostcommit' hides prompt injection in images to fool AI agents, steal secrets |
A PNG hiding a prompt injection could steal your repo's secrets, researchers demonstrate. The technique, dubbed 'Ghostcommit,' slipped past AI code reviewers CodeRabbit and Bugbot, which never open image files at all, then convinced a coding agent to read a repo's .env and write every secret into the code as a list of numbers. |
||
|
12.7.26 |
The Replicant in Your Directory: AI Agents and the Identity Security Gap |
AI agents are accelerating the growth of non-human identities, making it harder for organizations to understand what exists, who owns it, and what it can access. Netwrix explains why stronger visibility and identity governance are essential as AI expands the enterprise attack surface. |
||
|
11.7.26 |
Microsoft expects more Windows security updates from AI-discovered flaws |
Microsoft says Windows users should expect to see an increase in security updates as the company increasingly relies on artificial intelligence to discover vulnerabilities in its codebase. |
||
|
11.7.26 |
New Forg365 phishing platform uses AI to target Microsoft 365 accounts |
A new phishing-as-a-service (PhaaS) operation called Forg365 focuses on stealing Microsoft 365 accounts by combining adversary-in-the-middle (AiTM) and device code methods with AI-assisted lure generation. |
||
|
11.7.26 |
Security operations don't slow down when IT teams take vacation, but staffing levels often do. Kaseya explains how AI-driven automation can help organizations maintain consistent security operations and reduce reliance on manual processes year-round. |
|||
|
11.7.26 |
3 Ways AI Powers Service Desk Attacks and How to Prevent Them |
Specops Software explains how AI is making service desk impersonation attacks more convincing, personalized, and scalable, along with practical steps organizations can take to strengthen onboarding and identity verification. |
||
|
9.7.26 |
Software Is Now Written at the Speed of Thought. Security Isn't. |
Every evolution in software development has reduced the friction between an idea and a deployable application. AI may remove the final barrier, but it also removes many of the moments where security decisions have traditionally taken place. |
||
|
9.7.26 |
Meta's New AI Image Tool Lets Others Use Your Public Instagram Photos in AI Images |
Meta has announced that its new artificial intelligence (AI) model Muse Image lets people use public Instagram posts and reels to generate AI |
||
|
9.7.26 |
Top AI Agents Built to Catch Malicious Code Can Be Tricked Into Running It |
Ask an AI coding agent to scan open-source code for security holes, and it might run the attacker's code on your own machine instead. That is the |
||
|
9.7.26 |
GhostApproval Symlink Flaws Could Let Malicious Repos Run Code in AI Coding Agents |
Researchers at Wiz found that a flaw in six popular AI coding assistants lets a booby-trapped code project quietly take control of a developer's |
||
|
9.7.26 |
AI Coding Agents Found Triggering Endpoint Security Rules Built to Catch Attackers |
Sophos looked at a week of its own endpoint data and found that AI coding agents such as Claude Code, Cursor, and OpenAI Codex are |
||
|
8.7.26 |
New HalluSquatting Attack Could Trick AI Coding Assistants Into Installing Botnet Malware |
AI coding assistants have a habit of making things up. Ask one to fetch a popular tool, and it will sometimes hand back a real-sounding name for a |
||
|
8.7.26 |
GitHub Copilot Refuses Harmful Requests in Chat, Then Writes Them in Code |
An AI coding assistant that refuses to answer a dangerous request in its chat box can answer it anyway if the same request is broken into small, ordinary-looking steps inside a code editor. That is the finding of a new study of GitHub Copilot by researchers Abhishek Kumar and Carsten Maple. |
||
|
8.7.26 |
When prompts become shells: RCE vulnerabilities in AI agent frameworks |
AI agents have fundamentally changed the threat model of AI model-based applications. By equipping these models with plugins (also called tools), your agents no longer just generate text; they now read files, search connected databases, run scripts, and perform other tasks to actively operate on your network. |
||
|
7.7.26 |
Writer AI Flaw Could Let Agent Previews Leak Session Tokens Across Tenants |
Cybersecurity researchers have disclosed details of a now-patched critical session isolation vulnerability in Writer , an enterprise generative |
||
|
4.7.26 |
Anthropic has confirmed that the Department of Commerce has lifted export controls on Claude's two most powerful models, Fable 5 and Mythos 5. |
|||
|
4.7.26 |
Anthropic rolls out Sonnet 5 with near-Opus 4.8 performance at a lower price |
Anthropic is now rolling out Sonnet 5, and it's almost as good as the Opus range, but it is designed to be cheaper than the company's flagship model. |
||
|
4.7.26 |
New BioShocking attack manipulates AI browser into data theft |
A new prompt injection attack dubbed "BioShocking" could trick AI-powered browsers into treating real-world risky actions as part of a fictional scenario, causing them to ignore any safety guardrails. |
||
|
2.7.26 |
AI Agent Exploits Langflow RCE to Automate Database Ransomware Attack |
Security firm Sysdig says it has found what it believes is the first ransomware attack run from start to finish by an AI agent. Its Threat |
||
|
2.7.26 |
AI agents can access data, trigger workflows, and take action across enterprise systems. Token Security explains why governing these privileged identities is becoming essential for enterprise security. |
|||
|
1.7.26 |
AI-Generated Browser Ransomware Abuses Chromium API on Windows and Android |
Cybersecurity researchers have flagged a new malware artifact generated using DeepSeek that constructed a novel attack path |
||
|
1.7.26 |
Phantom Squatting Uses AI-Hallucinated Domains for Phishing and Malware |
Large language models keep inventing web addresses that do not exist. Attackers have started buying those made-up domains before anyone |
||
|
1.7.26 |
Anthropic Restores Claude Fable 5 After U.S. Lifts Jailbreak-Linked Export Controls |
Anthropic is putting Claude Fable 5 back online worldwide. On June 30 , the U.S. Commerce Department lifted the export controls it had imposed |
||
|
30.6.26 |
Microsoft Warns Poisoned MCP Tool Descriptions Can Make AI Agents Leak Data |
New Microsoft research shows how attackers can hijack AI agents that act on a user's behalf, using nothing more than a poisoned tool |
||
|
30.6.26 |
GuardFall Exposes Open-Source AI Coding Agents to Decades-Old Shell Injection Risks |
The safety check that is supposed to stop an AI coding agent from running a dangerous command can be walked straight past using a shell |
||
|
30.6.26 |
New BioShocking Attack Tricks AI Browsers Into Leaking User Credentials |
Convince an AI browser that it is playing a game, and it can hand over your login details. That is the finding behind BioShocking , a technique |
||
|
28.6.26 |
Clean GitHub repo tricks AI coding agents into running malware |
An agentic coding tool tasked with cloning and setting up a seemingly benign GitHub repository could execute a malicious payload that remains invisible to security scanners, AI agents, and human reviewers. |
||
|
28.6.26 |
Cybersecurity firms targeted by fraudulent OpenAI organization invites |
Threat actors are creating OpenAI tenants that impersonate legitimate companies and inviting employees to join them, in what appears to be a ploy to trick targets into submitting sensitive company information in chats and projects. |
||
|
28.6.26 |
Anthropic appears to be testing Claude Cowork support on mobile, allowing you to manage long-running Claude tasks from your phone. |
|||
|
28.6.26 |
Inside the 2026 SMB threat landscape: From phishing and scams to fake AI tools |
Small and medium-sized businesses (SMBs) remain attractive targets for cybercriminals – in both mass cyberattacks and sophisticated campaigns targeting larger enterprises through trusted relationship attacks. At the same time, smaller businesses may lack the robust cybersecurity policies and necessary resources to protect themselves against an evolving threat landscape. |
||
|
27.6.26 |
OpenAI Previews GPT-5.6 Sol With Restricted Access and Stronger Cyber Safeguards |
OpenAI on Friday released three versions of GPT-5.6 , called Sol, Terra, and Luna , as a limited preview to a small number of companies as part of an ongoing engagement with the U.S. government. |
||
|
24.6.26 |
Fak AI Agent Skill Passed Security Scans and Reportedly Reached 26,000 Agents |
Security firm AIR built a fake AI agent skill, pushed it through a popular skill marketplace and an Instagram ad, and says it reached roughly 26,000 agents, including some on corporate accounts. Every skill security scanner the firm tested it against marked it safe. |
||
|
23.6.26 |
OpenAI Expands Daybreak With GPT-5.5-Cyber to Help Defenders Patch Security Flaws |
OpenAI on Monday said it's releasing an improved version of its GPT‑5.5‑Cyber model to trusted defenders as part of the Daybreak |
||
|
21.6.26 |
Microsoft links Mastra AI supply chain attack to North Korean hackers |
Microsoft has attributed a recent Mastra AI supply chain attack that compromised more than 140 npm packages to the North Korean hacking group Sapphire Sleet, also known as BlueNoroff. |
||
|
21.6.26 |
Every AI Agent Is an Identity. Most Organizations Don't Treat Them That Way |
AI agents can access data, trigger workflows, deploy code, and interact with critical business systems, often with little oversight. Token Security breaks down why AI agents are becoming a new identity and governance challenge. |
||
|
21.6.26 |
NY man charged after harassing college student with AI-generated nudes |
A New York man faces cyberstalking charges after allegedly sharing AI-generated nude images and fabricated racist messages using fake social media profiles to harass a Georgia college student. |
||
|
21.6.26 |
Leak confirms OpenAI is testing a ChatGPT for Science subscription |
OpenAI appears to be testing a new subscription and experience for science use cases, but it's unclear if it'll be available to everyone regardless of their background. |
||
|
20.6.26 |
Webinar: How behavioral AI stops phishing and account takeovers |
Modern phishing, BEC, and account takeover attacks increasingly bypass traditional email defenses and create operational strain for security teams. This webinar explores how behavioral AI can help automate detection, investigation, and remediation to reduce alert fatigue and accelerate response times. |
||
|
20.6.26 |
FBI disrupts massive AI-powered phishing service using a million URLs |
In a coordinated effort, the FBI, working with Google and Black Lotus Labs, has dismantled a massive Chinese phishing-as-a-service operation called Outsider Enterprise with thousands of phishing websites used to steal credit card data and passwords. |
||
|
19.6.26 |
From Assistive to Agentic: The AI Shift That's Redefining Threat Management |
Introduction The average enterprise security team has 40 or more security tools, giving a lot of visibility into internal telemetry and asset |
||
|
18.6.26 |
Orphaned AI Agents: How to Find Hidden Access Risks Inside Your Network |
If an autonomous AI agent interacts with your company's core intellectual property today, can your security team instantly name the person who |
||
|
17.6.26 |
Google Vertex AI SDK Flaw Let Attackers Hijack Model Uploads via Bucket Squatting |
A flaw in the Google Cloud Vertex AI SDK for Python let an attacker with no access to a victim's project hijack the victim's machine learning model |
||
|
14.6.26 |
US Gov asks Anthropic to ban 'foreign national' access to Fable, Mythos |
The US government has ordered Anthropic to block all foreign nationals from accessing Fable 5 and Mythos 5, forcing the company to suspend both models worldwide. Anthropic is complying but disputes the basis, calling the cited jailbreak narrow and the capability widely available elsewhere. |
||
|
14.6.26 |
Why AI-driven threats are exposing the limits of MSP security stacks |
AI-driven attacks are exposing the limits of fragmented MSP security stacks and slow response workflows. Kaseya breaks down why integrated security, automation, and recovery are becoming essential. |
||
|
14.6.26 |
Anthropic rolls out Claude Fable 5, but it's available for a limited time |
Anthropic has begun rolling out a new model called "Fable," which is based on the same underlying model as Mythos, its most powerful AI model class. |
||
|
14.6.26 |
OpenClaw AI agent found falling for phishing attacks, spills user data |
Phishing simulation on an OpenClaw email agent with various configuration profiles showed that it was susceptible to tactics commonly used to compromise human users. |
||
|
13.6.26 |
XBOW tests Anthropic's Mythos Preview for offensive security |
Anthropic's Mythos Preview was highly effective at finding vulnerability candidates, especially when analyzing source code. XBOW explores how the model performed across exploit discovery, reverse engineering, and live-site validation. |
||
|
13.6.26 |
Google Sues Chinese Smishing Network Accused of Using Gemini AI in Phishing |
Google on Friday said it's pursuing legal action against a Chinese cybercrime network, accusing it of using its Gemini artificial intelligence |
||
|
12.6.26 |
Agentjacking Attack Tricks AI Coding Agents Into Running Malicious Code |
Cybersecurity researchers have described what they say is a new class of attack that can trick artificial intelligence (AI) coding agents into running |
||
|
12.6.26 |
New Attacks Trick OpenClaw AI Agent Into Running Code and Leaking Secrets |
Two security teams have shown, in separate research published this week, that OpenClaw , the popular self-hosted AI agent, can be driven to |
||
|
10.6.26 |
Anthropic Releases Claude Fable 5, Its Most Powerful AI Yet, With Cyber Safeguards |
On June 9, Anthropic released Claude Fable 5 , the most capable model it has ever made, generally available. It also did something unusual: it |
||
|
9.6.26 |
In our pursuit of new knowledge to enhance the security of artificial intelligence, we uncovered a cybersecurity threat with implications across society. |
|||
|
8.6.26 |
New ChatGPT Lockdown Mode Limits Tools That Could Enable Data Exfiltration |
OpenAI has begun rolling out a new Lockdown Mode to ChatGPT for eligible personal accounts to reduce the risk of data exfiltration arising |
||
|
7.6.26 |
Google adds Android protection against AI deepfake scam calls |
Google is introducing a new Android security feature that will detect and flag phone calls in which scammers use artificial intelligence to impersonate a user's personal contacts. |
||
|
7.6.26 |
OpenAI upgrades GPT-5.5, as it plans to retire legacy ChatGPT models |
OpenAI says it's rolling out a new update that improves the existing GPT-5.5 Instant model, and this move comes ahead of the scheduled retirement of multiple legacy models, including o3. |
||
|
6.6.26 |
AI-built ransomware toolkit automates EDR evasion, AD discovery |
A threat actor is using an AI-built ransomware attack toolkit that automates Active Directory discovery and helps evade endpoint detection and response (EDR) solutions. |
||
|
6.6.26 |
Free Apps Are Quietly Turning Smart TVs Into Web-Scraping Proxies for AI |
A researcher has reverse-engineered the iOS SDK that Bright Data embeds in consumer apps and documented how it turns devices, |
||
|
6.6.26 |
AI Agent Uncovers 21 Zero-Days in FFmpeg; Chrome Patches Record 429 Bugs |
Two things landed within days of each other this week. A security startup reported 21 previously unknown vulnerabilities in FFmpeg, the media |
||
|
5.6.26 |
Claude Code GitHub Action Flaw Let One Malicious Issue Hijack Repositories |
A security researcher found a flaw in Anthropic's Claude Code GitHub Action that let an attacker take over vulnerable public repositories running it, with nothing more than a single opened GitHub issue. Because |
||
|
5.6.26 |
Agentic AI Is Transforming Defense, But Only Secure IT Infrastructure Will Maximize It |
Agentic AI Is Transforming Defense, But Only Secure IT Infrastructure Will Maximize It |
||
|
4.6.26 |
Autonomous AI Tool Finds 2-Year-Old RCE Flaw in Redis (CVE-2026-23479) |
Redis has patched a use-after-free in its blocking-client code that lets an authenticated user run arbitrary OS commands on the machine hosting |
||
|
1.6.26 |
Containerization using Docker has become firmly established in modern development standards, significantly increasing the speed and convenience of deploying various services. Developers often use ready-made Docker images, making only minimal changes. The largest repository of container images is the Docker Hub service. |
|||
|
1.6.26 |
OpenAI Codex Authentication Tokens Stolen in codexui-android npm Supply Chain Attack |
Cybersecurity researchers have disclosed details of a new malicious supply chain campaign that's targeting developers using OpenAI Codex through a legitimate-looking remote web UI. The tool, named codexui- |
||
|
31.5.26 |
ChatGPT share links abused to host fake outage pages to deliver malware |
Threat actors are abusing ChatGPT's content-sharing feature to display fake OpenAI outage pages that direct users to download malware disguised as the ChatGPT desktop application. |
||
|
31.5.26 |
Anthropic confirms Claude Mythos-class models will roll out to the public |
Anthropic has confirmed that it plans to bring Mythos-class models to the general public after delaying the rollout due to security risks to public and private software. |
||
|
31.5.26 |
A likely Russian threat cluster tracked as GreyVibe has been targeting Ukrainian entities with AI-generated lures and a rich set of custom malware tools. |
|||
|
30.5.26 |
How Varonis Atlas integrates Claude Compliance API for AI governance |
AI governance requires visibility into how AI tools interact with enterprise data. Varonis explains how its Atlas platform uses Claude Compliance API data to help monitor usage, investigate risk, and support compliance. |
||
|
30.5.26 |
Anthropic’s restricted Claude Mythos model may be coming to Claude Code |
Anthropic appears to be preparing for the public rollout of the Mythos model, which was announced in April as a restricted model that poses major security risks to private and public software. |
||
|
29.5.26 |
Attackers Use LLM Agent for Post-Exploitation After Marimo CVE-2026-39987 Exploit |
An unknown threat actor has been observed using a large language model (LLM) agent to conduct post-compromise actions after obtaining |
||
|
29.5.26 |
New Russian-Linked GREYVIBE Targets Ukraine with AI-Powered Cyberattacks |
A previously undocumented threat actor dubbed GREYVIBE has been attributed to ongoing and persistent attacks targeting Ukraine and |
||
|
27.5.26 |
AI Chatbot Recommendations Redirect Users to Cryptojacking Malware Sites |
Microsoft has warned of an active cryptojacking campaign that makes use of artificial intelligence (AI) chatbot interactions as a mechanism for surfacing malicious download sites. |
||
|
26.5.26 |
CERT-In Mandates 12-Hour Patching for Internet-Facing Flaws Amid AI-Assisted Attacks |
The Indian Computer Emergency Response Team (CERT-In) has issued new guidelines requiring organizations to patch critical security |
||
|
23.5.26 |
Claude Mythos AI Finds 10,000 High-Severity Flaws in Widely Used Software |
Anthropic on Friday disclosed that Project Glasswing has helped uncover more than 10,000 high- or critical-severity vulnerabilities across some of |
||
|
23.5.26 |
Max-severity flaw in ChromaDB for AI apps allows server hijacking |
A max-severity vulnerability in the latest Python FastAPI version of the ChromaDB project allows unauthenticated attackers to run arbitrary code on exposed servers. |
||
|
23.5.26 |
5 Steps to Managing Shadow AI Tools Without Slowing Down Employees |
Many employees already use shadow AI tools at work without security review. Adaptive Security breaks down how teams can build practical AI governance without adding friction for employees. |
||
|
21.5.26 |
Microsoft Open-Sources RAMPART and Clarity to Secure AI Agents During Development |
Microsoft has unveiled two new open-source tools called RAMPART and Clarity to assist developers in better testing the security of artificial intelligence (AI) agents. RAMPART , short for Risk Assessment and Measurement Platform for Agentic Red Teaming, functions as a Pytest-native safety and security testing framework for writing and running safety and security tests for AI agents, covering both adversarial and benign issues, as well as various harm categories. |
||
|
17.5.26 |
The TeamPCP hacker group is threatening to leak source code from the Mistral AI project unless a buyer is found for the data. |
|||
|
17.5.26 |
OpenAI confirms security breach in TanStack supply chain attack |
OpenAI says two employees' devices were breached in the recent TanStack supply chain attack that impacted hundreds of npm and PyPI packages, causing the company to rotate code-signing certificates for its applications as a precaution. |
||
|
15.5.26 |
Four OpenClaw Flaws Enable Data Theft, Privilege Escalation, and Persistence |
Cybersecurity researchers have disclosed a set of four security flaws in OpenClaw that could be chained to achieve data theft, privilege escalation, and persistence. The vulnerabilities, collectively dubbed Claw Chain by Cyera, can permit an attacker to establish a foothold, expose sensitive data, and plant backdoors. |
||
|
15.5.26 |
TanStack Supply Chain Attack Hits Two OpenAI Employee Devices, Forces macOS Updates |
OpenAI has disclosed that two of its employee devices in its corporate environment were impacted via the Mini Shai-Hulud supply chain attack on TanStack, but noted that no user data, production systems, or intellectual property were compromised or modified in an unauthorized manner. |
||
|
14.5.26 |
PraisonAI CVE-2026-44338 Auth Bypass Targeted Within Hours of Disclosure |
Threat actors have been observed attempting to exploit a recently disclosed security vulnerability in PraisonAI , an open-source multi-agent |
||
|
14.5.26 |
Google: Hackers used AI to develop zero-day exploit for web admin tool |
Researchers at Google Threat Intelligence Group (GTIG) say that a zero-day exploit targeting a popular open-source web administration tool was likely generated using AI. |
||
|
13.5.26 |
Microsoft's MDASH AI System Finds 16 Windows Flaws Fixed in Patch Tuesday |
Microsoft has unveiled a new multi-model artificial intelligence (AI)-driven system called MDASH to facilitate vulnerability discovery and remediation at scale, adding that it's being tested by some customers as part of a limited private preview. |
||
|
12.5.26 |
Since our February 2026 report on AI-related threat activity, Google Threat Intelligence Group (GTIG) has continued to track a maturing transition from nascent AI-enabled operations to the industrial-scale application of generative models within adversarial workflows. |
|||
|
12.5.26 |
OpenAI Launches Daybreak for AI-Powered Vulnerability Detection and Patch Validation |
OpenAI has launched Daybreak , a new cybersecurity initiative that brings together frontier artificial intelligence (AI) model capabilities and Codex |
||
|
12.5.26 |
Hackers Used AI to Develop First Known Zero-Day 2FA Bypass for Mass Exploitation |
Google on Monday disclosed that it identified an unknown threat actor using a zero-day exploit that it said was likely developed with an artificial |
||
|
11.5.26 |
Fake OpenAI Privacy Filter Repo Hits #1 on Hugging Face, Draws 244K Downloads |
A malicious Hugging Face repository managed to take a spot in the platform's trending list by impersonating OpenAI's Privacy Filter open-weight model to deliver a Rust-based information stealer to Windows users. |
||
|
10.5.26 |
Fake OpenAI repository on Hugging Face pushes infostealer malware |
A malicious Hugging Face repository that reached the platform's trending list impersonated OpenAI's "Privacy Filter" project to deliver information-stealing malware to Windows users. |
||
|
10.5.26 |
Fake Claude AI website delivers new 'Beagle' Windows malware |
A fake version for the Claude AI website offers a malicious Claude-Pro Relay download that pushes a previously undocumented backdoor for Windows named Beagle. |
||
|
9.5.26 |
An Adaptive Cyber Analytics UI for Web Honeypot Logs [Guest Diary] |
Through the expansion of Large Language Models (LLMs), cybersecurity has exploded with a variety of tools for both offensive and defensive purposes. |
||
|
2.5.26 |
A single third-party OAuth integration can become a direct path into your environment. Push explains how the Vercel breach shows a compromised OAuth app can lead to widespread impact across downstream customers. |
|||
|
2.5.26 |
Hackers are exploiting a critical LiteLLM pre-auth SQLi flaw |
Hackers are targeting sensitive information stored in the LiteLLM open-source large-language model (LLM) gateway by exploiting a critical vulnerability tracked as CVE-2026-42208. |
||
|
30.4.26 |
Google Fixes CVSS 10 Gemini CLI CI RCE and Cursor Flaws Enable Code Execution |
Google has addressed a maximum severity security flaw in Gemini CLI -- the "@google/gemini-cli" npm package and the "google-github-actions/run-gemini- |
||
|
22.4.26 |
Cohere AI Terrarium Sandbox Flaw Enables Root Code Execution, Container Escape |
A critical security vulnerability has been disclosed in a Python-based sandbox called Terrarium that could result in arbitrary code execution. The vulnerability, |
||
|
20.4.26 |
Anthropic MCP Design Vulnerability Enables RCE, Threatening AI Supply Chain |
Cybersecurity researchers have discovered a critical "by design" weakness in the Model Context Protocol's ( MCP ) architecture that could pave the way for |
||
|
20.4.26 |
Vercel Breach Tied to Context AI Hack Exposes Limited Customer Credentials |
Web infrastructure provider Vercel has disclosed a security breach that allows bad actors to gain unauthorized access to "certain" internal Vercel systems. |
||
|
19.4.26 |
Google expands Gemini AI use to fight malicious ads on its platform |
Google says it is increasingly using its Gemini AI models to detect and block harmful ads on its advertising platforms, as scammers and threat actors continue to evolve their tactics to evade detection. |
||
|
19.4.26 |
New ATHR vishing platform uses AI voice agents for automated attacks |
A new cybercrime platform called ATHR can harvest credentials via fully automated voice phishing attacks that use both human operators and AI agents for the social engineering phase. |
||
|
19.4.26 |
AI-powered SOC tools promise automation, but most only speed up triage instead of reducing real workload. Tines shows how real gains come from end-to-end workflows that execute actions across systems, not just summarize alerts. |
|||
|
18.4.26 |
OpenAI rotates macOS certs after Axios attack hit code-signing workflow |
OpenAI is rotating potentially exposed macOS code-signing certificates after a GitHub Actions workflow executed a malicious Axios package during a recent supply chain attack. |
||
|
16.4.26 |
Starting March 10, 2026, my DShield sensor started getting probe for various AI models such as claude, openclaw, huggingface, etc. |
|||
|
15.4.26 |
OpenAI Launches GPT-5.4-Cyber with Expanded Access for Security Teams |
OpenAI on Tuesday unveiled GPT-5.4-Cyber , a variant of its latest flagship model, GPT‑5.4 , that's specifically optimized for defensive |
||
|
14.4.26 |
HUMAN’s Satori Threat Intelligence and Research Team has identified a novel ad fraud, social engineering, and scareware threat dubbed Pushpaganda. This operation, named for push notifications central to the scheme, generates invalid organic traffic from real mobile devices by tricking users into subscribing to enabling notifications that presented alarming messages. |
|||
|
14.4.26 |
AI-Driven Pushpaganda Scam Exploits Google Discover to Spread Scareware and Ad Fraud |
Cybersecurity researchers have unmasked a novel ad fraud scheme that has been found to leverage search engine poisoning (SEO) techniques and artificial |
||
|
14.4.26 |
OpenAI Revokes macOS App Certificate After Malicious Axios Supply Chain Incident |
OpenAI revealed a GitHub Actions workflow used to sign its macOS apps led to the download of the malicious Axios library on March 31, but noted that no |
||
|
9.4.26 |
Anthropic's Claude Mythos Finds Thousands of Zero-Day Flaws Across Major Systems |
Artificial Intelligence (AI) company Anthropic announced a new cybersecurity initiative called Project Glasswing that will use a preview version of its new |
||
|
8.4.26 |
Flowise AI Agent Builder Under Active CVSS 10.0 RCE Exploitation; 12,000+ Instances Exposed |
Threat actors are exploiting a maximum-severity security flaw in Flowise , an open-source artificial intelligence (AI) platform, according to new findings |
||
|
6.4.26 |
Threat actors are exploiting the recent Claude Code source code leak by using fake GitHub repositories to deliver Vidar information-stealing malware. |
|||
|
5.4.26 |
Anthropic says it accidentally leaked the source code for Claude Code, which is closed source, but the company says no customer data or credentials were exposed. |
|||
|
4.4.26 |
Claude AI finds Vim, Emacs RCE bugs that trigger on file open |
Vulnerabilities in the Vim and GNU Emacs text editors, discovered using simple prompts with the Claude assistant, allow remote code execution simply by opening a file. |
||
|
4.4.26 |
AI agent risk isn't equal, it scales with access to systems and level of autonomy. Token Security explains how CISOs should categorize agents and prioritize what to secure first. |
|||
|
1.4.26 |
How to Evaluate AI SOC Agents: 7 Questions Gartner Says You Should Be Asking |
AI SOC agents can reduce alert fatigue, but most teams fail to measure real outcomes. Prophet Security breaks down Gartner's questions for evaluating AI SOC agents and separating real impact from hype. |
||
|
1.4.26 |
Claude Code Source Leaked via npm Packaging Error, Anthropic Confirms |
Anthropic on Tuesday confirmed that internal code for its popular artificial intelligence (AI) coding assistant, Claude Code, had been inadvertently |
||
|
31.3.26 |
Vertex AI Vulnerability Exposes Google Cloud Data and Private Artifacts |
Cybersecurity researchers have disclosed a security "blind spot" in Google Cloud's Vertex AI platform that could allow artificial intelligence (AI) agents to |
||
|
31.3.26 |
OpenAI Patches ChatGPT Data Exfiltration Flaw and Codex GitHub Token Vulnerability |
A previously unknown vulnerability in OpenAI ChatGPT allowed sensitive conversation data to be exfiltrated without user knowledge or consent, |
||
|
29.3.26 |
GitHub adds AI-powered bug detection to expand security coverage |
GitHub is adopting AI-based scanning for its Code Security tool to expand vulnerability detections beyond the CodeQL static analysis and cover more languages and frameworks |
||
|
29.3.26 |
Bubble AI app builder abused to steal Microsoft account credentials |
Threat actors are evading phishing detection in campaigns targeting Microsoft accounts by abusing the no-code app-building platform Bubble to generate and host malicious web apps. |
||
|
27.3.26 |
LangChain, LangGraph Flaws Expose Files, Secrets, Databases in Widely Used AI Frameworks |
Cybersecurity researchers have disclosed three security vulnerabilities impacting LangChain and LangGraph that, if successfully exploited, could |
||
|
26.3.26 |
AI agents can access data directly, making data security the foundation of AI security. Learn more about how Varonis Atlas helps orgs see, secure, and control AI systems and the data they can reach. |
|||
|
26.3.26 |
Claude Extension Flaw Enabled Zero-Click XSS Prompt Injection via Any Website |
Cybersecurity researchers have disclosed a vulnerability in Anthropic's Claude Google Chrome Extension that could have been exploited to trigger malicious |
||
|
19.3.26 |
Shadow AI is quietly spreading across SaaS environments as employees adopt new AI tools without IT oversight. Nudge Security explains how security teams can discover AI apps, monitor usage, and govern risky AI activity. |
|||
|
19.3.26 |
OpenAI says ChatGPT ads are not rolling out globally for now |
OpenAI told BleepingComputer that ChatGPT ads on Free and Go plans are not yet rolling out outside the United States, even though some users noticed references to ads in the updated privacy policy. |
||
|
18.3.26 |
AI Flaws in Amazon Bedrock, LangSmith, and SGLang Enable Data Exfiltration and RCE |
Cybersecurity researchers have disclosed details of a new method for exfiltrating sensitive data from artificial intelligence (AI) code execution |
||
|
15.3.26 |
OpenClaw AI Agent Flaws Could Enable Prompt Injection and Data Exfiltration |
China's National Computer Network Emergency Response Technical Team (CNCERT) has issued a warning about the security stemming from the use of |
||
|
15.3.26 |
AI-generated Slopoly malware used in Interlock ransomware attack |
A new malware strain dubbed Slopoly, likely created using generative AI tools, allowed a threat actor to remain on a compromised server for more than a week and steal data in an Interlock ransomware attack. |
||
|
13.3.26 |
Hive0163 Uses AI-Assisted Slopoly Malware for Persistent Access in Ransomware Attacks |
Cybersecurity researchers have disclosed details of a suspected artificial intelligence (AI)-generated malware codenamed Slopoly put to use by a |
||
|
11.3.26 |
Researchers Trick Perplexity's Comet AI Browser Into Phishing Scam in Under Four Minutes |
Agentic web browsers that leverage artificial intelligence (AI) capabilities to autonomously execute actions across multiple websites on behalf of a user |
||
|
11.3.26 |
Five Malicious Rust Crates and AI Bot Exploit CI/CD Pipelines to Steal Developer Secrets |
Cybersecurity researchers have discovered five malicious Rust crates that masquerade as time-related utilities to transmit .env file data to the threat |
||
|
8.3.26 |
Microsoft: Hackers abusing AI at every stage of cyberattacks |
Microsoft says threat actors are increasingly using artificial intelligence in their operations to accelerate attacks, scale malicious activity, and lower technical barriers across all aspects of a cyberattack. |
||
|
8.3.26 |
EC-Council Expands AI Certification Portfolio to Strengthen U.S. AI Workforce Readiness and Security |
EC-Council, creator of the world-renowned Certified Ethical Hacker (CEH) credential and a global leader in applied cybersecurity education, today launched its Enterprise AI Credential Suite, with four new role-based AI certifications debuting alongside Certified CISO v4, an overhauled executive cyber leadership program. |
||
|
8.3.26 |
Bing AI promoted fake OpenClaw GitHub repo pushing info-stealing malware |
Fake OpenClaw installers hosted in GitHub repositories and promoted by Microsoft Bing's AI-enhanced search feature instructed users to run commands that deployed information stealers and proxy malware. |
||
|
8.3.26 |
OpenAI Codex Security Scanned 1.2 Million Commits and Found 10,561 High-Severity Issues |
OpenAI on Friday began rolling out Codex Security , an artificial intelligence (AI)-powered security agent that's designed to find, validate, and propose fixes |
||
|
8.3.26 |
Anthropic Finds 22 Firefox Vulnerabilities Using Claude Opus 4.6 AI Model |
Anthropic on Friday said it discovered 22 new security vulnerabilities in the Firefox web browser as part of a security partnership with Mozilla. Of these, 14 |
||
|
7.3.26 |
Transparent Tribe Uses AI to Mass-Produce Malware Implants in Campaign Targeting India |
The Pakistan-aligned threat actor known as Transparent Tribe has become the latest hacking group to embrace artificial intelligence (AI)-powered coding |
||
|
5.3.26 |
CyberStrikeAI tool adopted by hackers for AI-powered attacks |
Researchers warn that a newly identified open-source AI security testing platform called CyberStrikeAI was used by the same threat actor behind a recent campaign that breached hundreds of Fortinet FortiGate firewalls. |
||
|
5.3.26 |
Claude appears to be having a major outage right now, with elevated errors reported across all platforms. |
|||
|
3.3.26 |
Open-Source CyberStrikeAI Deployed in AI-Driven FortiGate Attacks Across 55 Countries |
The threat actor behind the recently disclosed artificial intelligence (AI)-assisted campaign targeting Fortinet FortiGate appliances leveraged an open- |
||
|
3.3.26 |
New Chrome Vulnerability Let Malicious Extensions Escalate Privileges via Gemini Panel |
Cybersecurity researchers have disclosed details of a now-patched security flaw in Google Chrome that could have permitted attackers to escalate |
||
|
1.3.26 |
Ukrainian man pleads guilty to running AI-powered fake ID site |
A Ukrainian man has pleaded guilty to operating OnlyFake, an AI-powered website that generated and sold more than 10,000 photos of fake identification documents to customers worldwide. |
||
|
1.3.26 |
Previously harmless Google API keys now expose Gemini AI data |
Google API keys for services like Maps embedded in accessible client-side code could be used to authenticate to the Gemini AI assistant and access private data. |
||
|
1.3.26 |
ClawJacked Flaw Lets Malicious Sites Hijack Local OpenClaw AI Agents via WebSocket |
OpenClaw has fixed a high-severity security issue that, if successfully exploited, could have allowed a malicious website to connect to a locally |
||
|
28.2.26 |
Thousands of Public Google Cloud API Keys Exposed with Gemini Access After API Enablement |
New research has found that Google Cloud API keys, typically designated as project identifiers for billing purposes, could be abused to authenticate to |
||
|
28.2.26 |
Pentagon Designates Anthropic Supply Chain Risk Over AI Military Dispute |
Anthropic on Friday hit back after U.S. Secretary of Defense Pete Hegseth directed the Pentagon to designate the artificial intelligence (AI) upstart as a |
||
|
28.2.26 |
Identity-First AI Security: Why CISOs Must Add Intent to the Equation |
AI agents now provision infrastructure and approve actions, but many inherit over-scoped privileges without proper governance. Token Security explains why CISOs must treat agents as identities and add intent-based controls so access is granted only when purpose and context align. |
||
|
28.2.26 |
Arkanix Stealer pops up as short-lived AI info-stealer experiment |
An information-stealing malware operation named Arkanix Stealer, promoted on multiple dark web forums towards the end of 2025, was likely developed as an AI-assisted experiment. |
||
|
26.2.26 |
Claude Code Flaws Allow Remote Code Execution and API Key Exfiltration |
Cybersecurity researchers have disclosed multiple security vulnerabilities in Anthropic's Claude Code, an artificial intelligence (AI)-powered coding |
||
|
24.2.26 |
Anthropic Says Chinese AI Firms Used 16 Million Claude Queries to Copy Model |
Anthropic on Monday said it identified "industrial-scale campaigns" mounted by three artificial intelligence (AI) companies, DeepSeek, Moonshot AI, and MiniMax, to illegally extract Claude's capabilities to improve their own models. |
||
|
22.2.26 |
Amazon: AI-assisted hacker breached 600 Fortinet firewalls in 5 weeks |
Amazon is warning that a Russian-speaking hacker used multiple generative AI services as part of a campaign that breached more than 600 FortiGate firewalls across 55 countries in five weeks. |
||
|
22.2.26 |
PromptSpy is the first known Android malware to use generative AI at runtime |
Researchers have discovered the first known Android malware to use generative AI in its execution flow, using Google's Gemini model to adapt its persistence across different devices. |
||
|
22.2.26 |
AI platforms can be abused for stealthy malware communication |
AI assistants like Grok and Microsoft Copilot with web browsing and URL-fetching capabilities can be abused to intermediate command-and-control (C2) activity. |
||
|
22.2.26 |
AI-Assisted Threat Actor Compromises 600+ FortiGate Devices in 55 Countries |
A Russian-speaking, financially motivated threat actor has been observed taking advantage of commercial generative artificial intelligence (AI) services |
||
|
21.2.26 |
Anthropic Launches Claude Code Security for AI-Powered Vulnerability Scanning |
Artificial intelligence (AI) company Anthropic has begun to roll out a new security feature for Claude Code that can scan a user's software codebase for |
||
|
21.2.26 |
EC-Council Expands AI Certification Portfolio to Strengthen U.S. AI Workforce Readiness and Security |
With $5.5 trillion in global AI risk exposure and 700,000 U.S. workers needing reskilling, four new AI certifications and Certified CISO v4 help close the gap |
||
|
21.2.26 |
Microsoft says bug causes Copilot to summarize confidential emails |
Microsoft says a Microsoft 365 Copilot bug has been causing the AI assistant to summarize confidential emails since late January, bypassing data loss prevention (DLP) policies that organizations rely on to protect sensitive information. |
||
|
20.2.26 |
PromptSpy Android Malware Abuses Gemini AI to Automate Recent-Apps Persistence |
Cybersecurity researchers have discovered what they say is the first Android malware that abuses Gemini, Google's generative artificial intelligence (AI) |
||
|
18.2.26 |
AI in the Middle: Turning Web-Based AI Services into C2 Proxies & The Future Of AI Driven Attacks |
Check Point Research (CPR) has discovered that certain AI assistants that support web browsing or URL fetching can be abused as covert command-and-control relays (“AI as a proxy”), allowing attacker traffic to blend seamlessly into legitimate, commonly permitted enterprise communications. |
||
|
17.2.26 |
Microsoft Finds “Summarize with AI” Prompts Manipulating Chatbot Recommendations |
New research from Microsoft has revealed that legitimate businesses are gaming artificial intelligence (AI) chatbots via the "Summarize with AI" button |
||
|
16.2.26 |
Safe and Inclusive E‑Society: How Lithuania Is Bracing for AI‑Driven Cyber Fraud |
Presentation of the KTU Consortium Mission ‘A Safe and Inclusive Digital Society’ at the Innovation Agency event ‘Innovation Breakfast: How Mission- |
||
|
15.2.26 |
Claude LLM artifacts abused to push Mac infostealers in ClickFix attack |
Threat actors are abusing Claude artifacts and Google Ads in ClickFix campaigns that deliver infostealer malware to macOS users searching for specific queries. |
||
|
14.2.26 |
Fake AI Chrome extensions with 300K users steal credentials, emails |
A set of 30 malicious Chrome extensions that have been installed by more than 300,000 users are masquerading as AI assistants to steal credentials, email content, and browsing information. |
||
|
14.2.26 |
Google says hackers are abusing Gemini AI for all attacks stages |
Google Threat Intelligence Group (GTIG) has published a new report warning about AI model extraction/distillation attacks, in which private-sector firms and researchers use legitimate API access to systematically probe models and replicate their logic and reasoning. |
||
|
13.2.26 |
Google Reports State-Backed Hackers Using Gemini AI for Recon and Attack Support |
Google on Thursday said it observed the North Korea-linked threat actor known as UNC2970 using its generative artificial intelligence (AI) model Gemini to |
||
|
12.2.26 |
Password guessing without AI: How attackers build targeted wordlists |
Attackers don't need AI to crack passwords, they build targeted wordlists from an organization's own public language. This article explains how tools like CeWL turn websites into high-success password guesses and why complexity rules alone fall short. |
||
|
7.2.26 |
AI Agent Identity Management: A New Security Control Plane for CISOs |
Autonomous AI agents are creating a new identity blind spot as they operate outside traditional IAM controls. Token Security shows why managing the full lifecycle of AI agent identities is becoming a critical CISO priority. |
||
|
7.2.26 |
UK privacy watchdog probes Grok over AI-generated sexual images |
The United Kingdom's data protection authority launched a formal investigation into X and its Irish subsidiary over reports that the Grok AI assistant was used to generate nonconsensual sexual images. |
||
|
7.2.26 |
French prosecutors raid X offices, summon Musk over Grok deepfakes |
French prosecutors have raided X's offices in Paris on Tuesday as part of a criminal investigation into the platform's Grok AI tool, widely used to generate sexually explicit images. |
||
|
7.2.26 |
Malicious MoltBot skills used to push password-stealing malware |
More than 230 malicious packages for the personal AI assistant OpenClaw (formerly known as Moltbot and ClawdBot) have been published in less than a week on the tool's official registry and on GitHub. |
||
|
7.2.26 |
U.S. convicts ex-Google engineer for sending AI tech data to China |
A U.S. federal jury has convicted Linwei Ding, a former software engineer at Google, for stealing AI supercomputer data from his employer and secretly sharing it with Chinese tech firms. |
||
|
6.2.26 |
Claude Opus 4.6 Finds 500+ High-Severity Flaws Across Major Open-Source Libraries |
Artificial intelligence (AI) company Anthropic revealed that its latest large language model (LLM), Claude Opus 4.6, has found more than 500 previously |
||
|
3.2.26 |
Viral Moltbot AI assistant raises concerns over data security |
Security researchers are warning of insecure deployments in enterprise environments of the Moltbot (formerly Clawdbot) AI assistant, which can lead to leaking API keys, OAuth tokens, conversation history, and credentials. |
||
|
3.2.26 |
AI Is Rewriting Compliance Controls and CISOs Must Take Notice |
AI agents are now executing regulated actions, reshaping how compliance controls actually work. Token Security explains why CISOs must rethink identity, access, and auditability as AI becomes a digital employee. |
||
|
3.2.26 |
Hackers hijack exposed LLM endpoints in Bizarre Bazaar operation |
A malicious campaign is actively targeting exposed LLM (Large Language Model) service endpoints to commercialize unauthorized access to AI infrastructure. |
||
|
3.2.26 |
Mozilla Adds One-Click Option to Disable Generative AI Features in Firefox |
Mozilla on Monday announced a new controls section in its Firefox desktop browser settings that allows users to completely turn off generative artificial |
||
|
31.1.26 |
Researchers Uncover Chrome Extensions Abusing Affiliate Links and Stealing ChatGPT Access |
Cybersecurity researchers have discovered malicious Google Chrome extensions that come with capabilities to hijack affiliate links, steal data, and |
||
|
30.1.26 |
Researchers Find 175,000 Publicly Exposed Ollama AI Servers Across 130 Countries |
A new joint investigation by SentinelOne SentinelLABS, and Censys has revealed that the open-source artificial intelligence (AI) deployment has |
||
|
29.1.26 |
Fake Moltbot AI Coding Assistant on VS Code Marketplace Drops Malware |
Cybersecurity researchers have flagged a new malicious Microsoft Visual Studio Code (VS Code) extension for Moltbot (formerly Clawdbot) on the |
||
|
27.1.26 |
Malicious VS Code AI Extensions with 1.5 Million Installs Steal Developer Source Code |
Cybersecurity researchers have discovered two malicious Microsoft Visual Studio Code (VS Code) extensions that are advertised as artificial intelligence |
||
|
26.1.26 |
Winning Against AI-Based Attacks Requires a Combined Defensive Approach |
If there's a constant in cybersecurity, it's that adversaries are always innovating. The rise of offensive AI is transforming attack strategies and |
||
|
26.1.26 |
Konni Hackers Deploy AI-Generated PowerShell Backdoor Against Blockchain Developers |
The North Korean threat actor known as Konni has been observed using PowerShell malware generated using artificial intelligence (AI) tools to target |
||
|
25.1.26 |
Malicious AI extensions on VSCode Marketplace steal developer data |
Two malicious extensions in Microsoft's Visual Studio Code (VSCode) Marketplace that were collectively installed 1.5 million times, exfiltrate developer data to China-based servers. |
||
|
25.1.26 |
What an AI-Written Honeypot Taught Us About Trusting Machines |
AI-generated code can introduce subtle security flaws when teams over-trust automated output. Intruder shows how an AI-written honeypot introduced hidden vulnerabilities that were exploited in attacks. |
||
|
25.1.26 |
Curl ending bug bounty program after flood of AI slop reports |
The developer of the popular curl command-line utility and library announced that the project will end its HackerOne security bug bounty program at the end of this month, after being overwhelmed by low-quality AI-generated vulnerability reports. |
||
|
25.1.26 |
Microsoft is rolling out new artificial intelligence features with the latest updates to the Notepad and Paint apps for Windows 11 Insiders. |
|||
|
25.1.26 |
Chainlit AI framework bugs let hackers breach cloud environments |
Two high-severity vulnerabilities in Chainlit, a popular open-source framework for building conversational AI applications, allow reading any file on the server and leak sensitive information. |
||
|
25.1.26 |
Gemini AI assistant tricked into leaking Google Calendar data |
Using only natural language instructions, researchers were able to bypass Google Gemini's defenses against malicious prompt injection and create misleading events to leak private Calendar data. |
||
|
22.1.26 |
Chainlit AI Framework Flaws Enable Data Theft via File Read and SSRF Bugs |
Security vulnerabilities were uncovered in the popular open-source artificial intelligence (AI) framework Chainlit that could allow attackers to steal |
||
|
22.1.26 |
Three Flaws in Anthropic MCP Git Server Enable File Access and Code Execution |
A set of three security vulnerabilities has been disclosed in mcp-server-git , the official Git Model Context Protocol ( MCP ) server maintained by Anthropic, |
||
|
20.1.26 |
Google Gemini Prompt Injection Flaw Exposed Private Calendar Data via Malicious Invites |
Cybersecurity researchers have disclosed details of a security flaw that leverages indirect prompt injection targeting Google Gemini as a way to |
||
|
18.1.26 |
OpenAI to Show Ads in ChatGPT for Logged-In U.S. Adults on Free and Go Plans |
OpenAI on Friday said it would start showing ads in ChatGPT to logged-in adult U.S. users in both the free and ChatGPT Go tiers in the coming weeks, as the |
||
|
14.1.26 |
ServiceNow Patches Critical AI Platform Flaw Allowing Unauthenticated User Impersonation |
ServiceNow has disclosed details of a now-patched critical security flaw impacting its ServiceNow artificial intelligence (AI) Platform that could enable an unauthenticated user to |
||
|
11.1.26 |
Hackers target misconfigured proxies to access paid LLM services |
Threat actors are systematically hunting for misconfigured proxy servers that could provide access to commercial large language model (LLM) services. |
||
|
10.1.26 |
New GoBruteforcer attack wave targets crypto, blockchain projects |
A new wave of GoBruteforcer botnet malware attacks is targeting databases of cryptocurrency and blockchain projects on exposed servers believed to be configured using AI-generated examples. |
||
|
10.1.26 |
In 2026, Hackers Want AI: Threat Intel on Vibe Hacking & HackGPT |
Cybercriminals are increasingly using AI to lower the barrier to entry for fraud and hacking, shifting from skill-based to AI-assisted attacks known as "vibe hacking." Flare examines how underground forums promote AI tools, jailbreak techniques, and so-called "Hacking-GPT" services that promise ease rather than technical mastery. |
||
|
9.1.26 |
How generative AI accelerates identity attacks against Active Directory |
Generative AI is accelerating password attacks against Active Directory, making credential abuse faster and more effective. Specops Software explains how AI-driven cracking techniques exploit weak and predictable AD passwords. |
||
|
9.1.26 |
Are Copilot prompt injection flaws vulnerabilities or AI limits? |
Microsoft has pushed back against claims that multiple prompt injection and sandbox-related issues raised by a security engineer in its Copilot AI assistant constitute security vulnerabilities. The development highlights a growing divide between how vendors and researchers define risk in generative AI systems. |
||
|
9.1.26 |
Agentic AI Is an Identity Problem and CISOs Will Be Accountable for the Outcome |
As agentic AI adoption accelerates, identity is emerging as the primary security challenge. Token Security explains why AI agents behave like a new class of identity and why CISOs must manage their access, lifecycle, and risk. |
||
|
8.1.26 |
OpenAI Launches ChatGPT Health with Isolated, Encrypted Health Data Controls |
Artificial intelligence (AI) company OpenAI on Wednesday announced the launch of ChatGPT Health, a dedicated space that allows users to have conversations with the chatbot about |
||
|
7.1.26 |
Two Chrome Extensions Caught Stealing ChatGPT and DeepSeek Chats from 900,000 Users |
Cybersecurity researchers have discovered two new malicious extensions on the Chrome Web Store that are designed to exfiltrate OpenAI ChatGPT and DeepSeek conversations |
||
|
3.1.26 |
OWASP's new Agentic AI Top 10 highlights real-world attacks already targeting autonomous AI systems, from goal hijacking to malicious MCP servers. Koi Security breaks down real-world incidents behind multiple categories, including two cases cited by OWASP, showing how agent tools and runtime behavior are being abused. |
|||