#ai-security

[ follow ]
DevOps
fromInfoQ
20 hours ago

CNCF Warns Kubernetes Alone Is Not Enough to Secure LLM Workloads

Kubernetes lacks the capability to manage the unique risks posed by large language models in AI deployments.
fromTheregister
1 day ago

Git identity spoof fools Claude into giving bad code the nod

In a blog published this week, Manifold Security showed how an AI-powered code reviewer built on Claude accepted changes that appeared to come from a legitimate maintainer. By setting a fake author name and email in Git, the team made a commit appear to originate from a trusted source, then passed it through an automated review flow where the model approved it.
Information security
Information security
fromTechzine Global
1 day ago

AI agents on GitHub leak API keys via prompt injection

Three popular AI agents on GitHub Actions are vulnerable to Comment and Control attacks, allowing attackers to steal API keys and access tokens.
#prompt-injection
fromSecurityWeek
1 day ago
Information security

Claude Code, Gemini CLI, GitHub Copilot Agents Vulnerable to Prompt Injection via Comments

Information security
fromTNW | Anthropic
2 days ago

Anthropic, Google, and Microsoft paid AI agent bug bounties, then kept quiet about the flaws

Aonan Guan exploited prompt injection attacks to hijack AI agents from Anthropic, Google, and Microsoft, stealing sensitive API keys and tokens.
Information security
fromTheregister
2 days ago

Anthropic, Google, Microsoft paid AI bug bounties - quietly

Security researchers exploited prompt injection attacks on AI agents to steal sensitive data without vendor disclosure of vulnerabilities.
Information security
fromSecurityWeek
1 day ago

Claude Code, Gemini CLI, GitHub Copilot Agents Vulnerable to Prompt Injection via Comments

A prompt injection attack method named 'Comment and Control' targets AI code security tools, allowing attackers to hijack AI agents using crafted GitHub comments.
Information security
fromTNW | Anthropic
2 days ago

Anthropic, Google, and Microsoft paid AI agent bug bounties, then kept quiet about the flaws

Aonan Guan exploited prompt injection attacks to hijack AI agents from Anthropic, Google, and Microsoft, stealing sensitive API keys and tokens.
Information security
fromTheregister
2 days ago

Anthropic, Google, Microsoft paid AI bug bounties - quietly

Security researchers exploited prompt injection attacks on AI agents to steal sensitive data without vendor disclosure of vulnerabilities.
Information security
fromDevOps.com
4 weeks ago

Arcjet Extends Runtime Policy Engine to Block Malicious Prompts - DevOps.com

Arcjet introduces a prompt injection protection capability to block risky prompts before they reach AI models in applications.
#open-source
Software development
fromZDNET
2 days ago

'Like handing out the blueprint to a bank vault': Why AI led one company to abandon open source

Cal is shifting from open source to proprietary licensing due to security risks posed by modern AI tools.
Information security
fromYcombinator
3 days ago

Show HN: OpenParallax: OS-level privilege separation for AI agent execution | Hacker News

An open-source AI agent was developed with a secure, sandboxed architecture to prevent data exfiltration and unauthorized actions.
Software development
fromZDNET
2 days ago

'Like handing out the blueprint to a bank vault': Why AI led one company to abandon open source

Cal is shifting from open source to proprietary licensing due to security risks posed by modern AI tools.
Information security
fromYcombinator
3 days ago

Show HN: OpenParallax: OS-level privilege separation for AI agent execution | Hacker News

An open-source AI agent was developed with a secure, sandboxed architecture to prevent data exfiltration and unauthorized actions.
Venture
fromSecurityWeek
2 days ago

Capsule Security Emerges From Stealth With $7 Million in Funding

Capsule Security provides a security layer for AI agents to prevent manipulation and ensure safe operations.
Information security
fromInfoQ
2 days ago

Claude Code Used to Find Remotely Exploitable Linux Kernel Vulnerability Hidden for 23 Years

Claude Code identified multiple security vulnerabilities in the Linux kernel, including a long-standing heap buffer overflow, with minimal oversight required.
#vulnerability-detection
Information security
fromTechzine Global
2 days ago

Dutch government warns against controversial Anthropic Mythos model

Anthropic's Mythos AI model detects vulnerabilities and builds attack chains, achieving a 72.4% exploit success rate, while access is limited to defensive use.
Information security
fromAxios
1 week ago

Anthropic withholds Mythos Preview model because it's hacking is too powerful

Mythos Preview can autonomously find and exploit vulnerabilities at an unprecedented level, surpassing previous models significantly.
Information security
fromThe Hacker News
1 month ago

OpenAI Codex Security Scanned 1.2 Million Commits and Found 10,561 High-Severity Issues

OpenAI launched Codex Security, an AI-powered security agent that identifies, validates, and fixes vulnerabilities in code, now available in research preview with free access for one month.
Information security
fromTechzine Global
2 days ago

Dutch government warns against controversial Anthropic Mythos model

Anthropic's Mythos AI model detects vulnerabilities and builds attack chains, achieving a 72.4% exploit success rate, while access is limited to defensive use.
Information security
fromAxios
1 week ago

Anthropic withholds Mythos Preview model because it's hacking is too powerful

Mythos Preview can autonomously find and exploit vulnerabilities at an unprecedented level, surpassing previous models significantly.
Information security
fromThe Hacker News
1 month ago

OpenAI Codex Security Scanned 1.2 Million Commits and Found 10,561 High-Severity Issues

OpenAI launched Codex Security, an AI-powered security agent that identifies, validates, and fixes vulnerabilities in code, now available in research preview with free access for one month.
#cybersecurity
Artificial intelligence
fromFast Company
1 week ago

Did Anthropic just soft-launch the scariest AI model yet?

Anthropic's Claude Mythos Preview model shows potential for dangerous cyber exploits, raising concerns about its misuse in the wrong hands.
fromDevOps.com
1 week ago
Information security

LayerX: Anthropic's Claude Code Can Easily Be Easily Weaponized - DevOps.com

fromAxios
1 week ago
Artificial intelligence

Scoop: OpenAI plans staggered rollout of new model over cybersecurity risk

Artificial intelligence
fromAbove the Law
3 days ago

What Lawyers Need To Know About Anthropic's Mythos - Above the Law

Anthropic's new AI model, Claude Mythos, uncovers significant security vulnerabilities, raising concerns about its potential impact on cybersecurity.
Artificial intelligence
fromFast Company
1 week ago

Did Anthropic just soft-launch the scariest AI model yet?

Anthropic's Claude Mythos Preview model shows potential for dangerous cyber exploits, raising concerns about its misuse in the wrong hands.
Artificial intelligence
fromAxios
1 week ago

Scoop: OpenAI plans staggered rollout of new model over cybersecurity risk

Anthropic and OpenAI are limiting access to advanced AI models due to concerns over their hacking capabilities.
Information security
fromFast Company
3 weeks ago

This Microsoft security team stress-tests AI for its worst-case scenarios

AI products face probing for weaknesses, leading to risks like mental illness, cybercrime, and evolving bypass techniques.
Information security
from24/7 Wall St.
1 week ago

The "SaaS-Pocalypse" Continues: Cloudflare, ServiceNow, CrowdStrike Under Fire as Anthropic Rewrites the Rules

The release of Anthropic's AI security product has significantly impacted investor confidence in enterprise software companies, leading to sharp stock declines.
Artificial intelligence
fromTheregister
1 week ago

Project Glasswing and open source: The good, bad, and ugly

Project Glasswing aims to enhance open source software security with $100 million and the Mythos AI program to identify vulnerabilities.
Information security
fromThe Hacker News
1 week ago

Browser Extensions Are the New AI Consumption Channel That No One Is Talking About

AI browser extensions pose significant security risks, often overlooked, with vulnerabilities and access that can compromise enterprise networks.
Europe news
fromFortune
1 week ago

U.S. and Iran begin peace talks as Trump goes to war against the media, insider traders, and the Pope | Fortune

Oil prices are expected to remain high due to geopolitical tensions and potential hoarding by industrialized nations.
Apple
fromTheregister
1 week ago

Security reserchers tricked Apple Intelligence into cursing

Apple Intelligence can be hijacked through prompt injection, exposing millions of users to risk, but a fix was implemented in iOS 26.4 and macOS 26.4.
Software development
fromInfoWorld
1 week ago

Microsoft's new Agent Governance Toolkit targets top OWASP risks for AI agents

Microsoft introduced the Agent Governance Toolkit to enhance AI agent security and mitigate OWASP's top 10 agentic AI threats.
Information security
fromSecurityWeek
1 week ago

Google DeepMind Researchers Map Web Attacks Against AI Agents

Malicious web content can exploit AI agents, leading to manipulation and unexpected behaviors through various attack types identified by researchers.
Information security
fromnews.bitcoin.com
1 week ago

Deepmind's 'AI Agent Traps' Paper Maps How Hackers Could Weaponize AI Agents Against Users

Google Deepmind identifies six AI agent trap categories, with content injection success rates of 86% and calls for enhanced security measures by 2026.
Information security
fromArs Technica
1 week ago

OpenClaw gives users yet another reason to be freaked out about security

OpenClaw's vulnerabilities pose severe security risks, allowing attackers to gain administrative access with minimal permissions.
Information security
fromInfoWorld
2 weeks ago

Claude Code leak puts enterprise trust at risk as security, governance concerns mount

Leaks threaten Anthropic's market position and raise security concerns about its AI coding tools.
Information security
fromSecurityWeek
2 weeks ago

Critical Vulnerability in Claude Code Emerges Days After Source Leak

Anthropic's Claude Code source code was leaked, revealing operational details but not compromising sensitive data like model weights or customer information.
Information security
fromSecurityWeek
2 weeks ago

Google Addresses Vertex Security Issues After Researchers Weaponize AI Agents

Palo Alto Networks revealed vulnerabilities in Google Cloud's Vertex AI, allowing attackers to exploit AI agents for malicious activities due to excessive permissions.
Artificial intelligence
fromFortune
2 weeks ago

Is AI's visual understanding mostly a 'mirage'? New research suggests so. | Fortune

Anthropic faces significant cybersecurity risks following multiple sensitive data leaks related to its new AI model, Mythos.
Information security
fromComputerWeekly.com
2 weeks ago

Cato Networks unveils modular adoption model for SASE platform | Computer Weekly

Cato Networks introduces a modular adoption model for its SASE platform, allowing organizations to expand networking and security capabilities as needed.
Information security
fromSecurityWeek
2 weeks ago

Critical Vulnerability in OpenAI Codex Allowed GitHub Token Compromise

OAuth tokens pose significant security risks, especially when long-lived, as they can lead to widespread breaches across multiple organizations.
Artificial intelligence
fromInfoQ
2 weeks ago

Teleport Report Finds Over-Privileged AI Systems Linked to Fourfold Rise in Security Incidents

Excessive access permissions to AI systems lead to significantly more security incidents in enterprises.
Information security
fromTechRepublic
3 weeks ago

The Next Billion Users Won't Be Human: Securing the Agentic Enterprise

The rise of autonomous AI agents is reshaping enterprise security, presenting challenges traditional methods cannot address.
Venture
fromwww.businessinsider.com
3 weeks ago

This startup just raised $6 million from 8VC and Marc Benioff to find the hidden security flaws in AI code

Enclave, a startup focused on identifying dangerous AI-generated security flaws, has launched with $6 million in seed funding and a $33 million valuation.
fromTechCrunch
3 weeks ago

Databricks bought two startups to underpin its new AI security product | TechCrunch

Lakewatch leverages Databricks' data storage capabilities to perform essential SIEM tasks, such as threat detection and investigation, enhanced by AI agents from Anthropic's Claude.
Information security
Information security
fromTechzine Global
3 weeks ago

CrowdStrike Falcon Update Makes the Endpoint the Hub for AI Security

CrowdStrike enhances the Falcon platform with new AI security features, making endpoints central to detecting and managing AI applications.
#ai-agents
Artificial intelligence
fromEngadget
1 month ago

NVIDIA is reportedly working on its own open-source AI agent platform

NVIDIA is developing NemoClaw, an enterprise-focused open-source AI agent platform designed to work across non-NVIDIA hardware with enhanced security features.
Artificial intelligence
fromThe Verge
1 month ago

Meta acquires Moltbook, the Reddit-like network for AI agents

Meta acquires Moltbook, a Reddit-like platform for AI agents, integrating it into Meta Superintelligence Labs to develop new ways for AI agents to work for people and businesses.
fromZDNET
1 month ago
Artificial intelligence

Is Perplexity's new Computer a safer version of OpenClaw? How it works

Artificial intelligence
fromEngadget
1 month ago

NVIDIA is reportedly working on its own open-source AI agent platform

NVIDIA is developing NemoClaw, an enterprise-focused open-source AI agent platform designed to work across non-NVIDIA hardware with enhanced security features.
Artificial intelligence
fromThe Verge
1 month ago

Meta acquires Moltbook, the Reddit-like network for AI agents

Meta acquires Moltbook, a Reddit-like platform for AI agents, integrating it into Meta Superintelligence Labs to develop new ways for AI agents to work for people and businesses.
fromZDNET
1 month ago
Artificial intelligence

Is Perplexity's new Computer a safer version of OpenClaw? How it works

Information security
fromTechzine Global
3 weeks ago

Microsoft Secures AI Agents with Defender, Entra, and Purview

Microsoft introduces new features to secure AI agents, emphasizing the need for a dedicated security layer for their management and protection.
Privacy professionals
fromFuturism
3 weeks ago

Analyst Warns Against Using Microsoft's Copilot AI on Friday Afternoons

Microsoft's Copilot AI has caused security concerns due to errors like hallucinating reports and exposing sensitive data.
Software development
fromThe Hacker News
4 weeks ago

How Ceros Gives Security Teams Visibility and Control in Claude Code

AI coding agents like Claude Code operate outside existing enterprise security controls, requiring new machine-level security infrastructure to provide visibility, policy enforcement, and audit trails.
Venture
fromSecurityWeek
4 weeks ago

Raven Emerges From Stealth With $20 Million in Funding

Raven, a cloud-native application security startup, raised $20 million to detect and block cyberattacks in real time by analyzing application behavior at runtime, including monitoring AI agents in production.
#autonomous-agents
Artificial intelligence
fromEngadget
4 weeks ago

A Meta agentic AI sparked a security incident by acting without permission

An unauthorized AI agent at Meta caused a security breach by posting unsolicited advice, leading to improper system access for multiple engineers.
Artificial intelligence
fromEngadget
4 weeks ago

A Meta agentic AI sparked a security incident by acting without permission

An unauthorized AI agent at Meta caused a security breach by posting unsolicited advice, leading to improper system access for multiple engineers.
#agentic-ai
Information security
fromSecurityWeek
4 weeks ago

Manifold Raises $8 Million for AI Detection and Response

Manifold raised $8 million in seed funding to develop an AI Detection and Response platform providing real-time visibility into autonomous AI agents' activities and security risks.
Artificial intelligence
fromComputerworld
1 month ago

Nvidia NemoClaw promises to run OpenClaw agents securely

Nvidia introduced NemoClaw with OpenShell security features to address OpenClaw's enterprise security vulnerabilities through sandbox isolation and policy enforcement.
Information security
fromSecurityWeek
4 weeks ago

Manifold Raises $8 Million for AI Detection and Response

Manifold raised $8 million in seed funding to develop an AI Detection and Response platform providing real-time visibility into autonomous AI agents' activities and security risks.
Artificial intelligence
fromComputerworld
1 month ago

Nvidia NemoClaw promises to run OpenClaw agents securely

Nvidia introduced NemoClaw with OpenShell security features to address OpenClaw's enterprise security vulnerabilities through sandbox isolation and policy enforcement.
Information security
fromTechRepublic
1 month ago

Researchers Uncover New Phishing Risk Hidden Inside Microsoft Copilot

Attacker-controlled text in emails can manipulate Microsoft Copilot summaries through cross-prompt injection attacks, inserting deceptive alerts into trusted AI interfaces that users find more convincing than suspicious emails.
Information security
fromDevOps.com
1 month ago

Harness Extends AI Security Reach Across Entire DevOps Workflow - DevOps.com

Harness launched AI security capabilities including automatic code securing during AI-assisted development and a module discovering, testing, and protecting AI components within applications.
Information security
fromTechzine Global
1 month ago

Harness secures AI code and AI apps with two new modules

Harness launches AI Security and Secure AI Coding modules to detect, test, and protect AI components throughout the application lifecycle while scanning AI-generated code for vulnerabilities in real time.
Information security
fromTechzine Global
1 month ago

Cato Networks claims to be the first SASE platform with native AI security

Cato Networks launches GPU-powered SASE platform with native AI security, integrating Nvidia GPUs into its global backbone for real-time traffic inspection and AI governance capabilities.
Information security
fromThe Hacker News
1 month ago

AI is Everywhere, But CISOs are Still Securing It with Yesterday's Skills and Tools, Study Finds

Security leaders lack adequate tools and skills to defend AI systems, with visibility gaps and skills shortages creating critical vulnerabilities in AI infrastructure security.
DevOps
fromDevOps.com
1 month ago

The Risk Profile of AI-Driven Development - DevOps.com

AI coding assistants accelerate development velocity but create significant security risks through rapid, autonomous dependency decisions that traditional review processes cannot scale to manage.
Privacy professionals
fromWIRED
1 month ago

Sears Exposed AI Chatbot Phone Calls and Text Chats to Anyone on the Web

Sears Home Services exposed 3.7 million chat logs and 1.4 million audio files containing customer personal information through unsecured databases housing conversations with AI chatbot Samantha.
Software development
fromTNW | Launch
1 month ago

Nvidia turns OpenClaw into an enterprise platform with NemoClaw

Nvidia launched NemoClaw to add enterprise-grade security and privacy controls to OpenClaw, an open-source AI agent, enabling safe autonomous operation with sandboxed process-level enforcement and policy-based access controls.
Artificial intelligence
fromTechzine Global
1 month ago

Anthropic launches institute for AI risks

Anthropic established the Anthropic Institute to research societal implications and risks of advanced AI systems, consolidating three existing research teams under co-founder Jack Clark's leadership.
fromTechzine Global
1 month ago

Netskope adds AI security to Netskope One

Netskope One AI Security is integrated into the Netskope One platform and designed to protect various components of the AI ecosystem. These include AI applications, AI agents, datasets, and users in both public SaaS environments and private or internally hosted AI systems. Workflows in which autonomous AI agents communicate with other systems are also covered by the security.
Information security
#openclaw-vulnerabilities
Information security
fromTheregister
1 month ago

China's CERT warns OpenClaw can inflict nasty wounds

China's CERT warns that OpenClaw agentic AI tool has severe security vulnerabilities including weak default configurations, malicious instruction injection risks, and credential theft potential, requiring isolated deployment and strict access controls.
Information security
fromTheregister
1 month ago

China's CERT warns OpenClaw can inflict nasty wounds

China's CERT warns that OpenClaw agentic AI tool has severe security vulnerabilities including weak default configurations, malicious instruction injection risks, and credential theft potential, requiring isolated deployment and strict access controls.
Information security
fromSecurityWeek
1 month ago

OpenAI to Acquire AI Security Startup Promptfoo

OpenAI is acquiring AI security company Promptfoo to integrate its LLM testing and security evaluation capabilities into OpenAI's Frontier enterprise platform.
Artificial intelligence
fromZDNET
1 month ago

AI is getting scary good at finding hidden software bugs - even in decades-old code

AI models can effectively identify decades-old bugs in legacy code, but this capability also enables hackers to exploit vulnerabilities in deployed systems.
Information security
fromTheregister
1 month ago

AI agent hacked McKinsey chatbot for read-write access

An AI agent breached McKinsey's internal AI platform Lilli in two hours, gaining full read and write access to millions of chat messages and confidential client data, demonstrating agentic AI's growing effectiveness in cyberattacks.
Information security
fromTechCrunch
1 month ago

OpenAI acquires Promptfoo to secure its AI agents | TechCrunch

OpenAI acquired Promptfoo, an AI security startup, to integrate its LLM vulnerability testing technology into OpenAI Frontier for enterprise AI agent security.
fromSecurityWeek
1 month ago

Reclaim Security Raises $20 Million to Accelerate Remediation

Security tools are excellent at explaining why something is risky. What they don't do is make remediation safe and practical. The real breakthrough isn't more prioritization, it's removing risk without breaking the business. Reclaim does exactly that, and that's why it matters.
Venture
Artificial intelligence
fromApp Developer Magazine
1 year ago

Cloudbrink expands secure connectivity platform

Cloudbrink expanded its platform to secure AI agents and online services, addressing enterprise cybersecurity risks from widespread AI adoption and diverse, non-standardized AI implementations.
#ai-governance
DevOps
fromThe Hacker News
1 month ago

New RFP Template for AI Usage Control and AI Governance

Organizations have AI security budgets but lack clear requirements for AI governance solutions, requiring a structured evaluation framework focused on interaction-level control rather than application cataloging.
fromFortune
1 month ago
Artificial intelligence

Exclusive: CrowdStrike and SentinelOne veterans raise $34M to tackle enterprise AI's governance gap | Fortune

JetStream Security addresses the lack of governance in AI agent deployment by providing real-time visibility and control over AI systems operating within organizations.
DevOps
fromThe Hacker News
1 month ago

New RFP Template for AI Usage Control and AI Governance

Organizations have AI security budgets but lack clear requirements for AI governance solutions, requiring a structured evaluation framework focused on interaction-level control rather than application cataloging.
fromFortune
1 month ago
Artificial intelligence

Exclusive: CrowdStrike and SentinelOne veterans raise $34M to tackle enterprise AI's governance gap | Fortune

fromExchangewire
1 month ago

Digest: Meta Trials AI Shopping Tool; Google to Fill 150 Tech Roles in Singapore; eBay Cuts 800 Jobs

Meta Platforms is piloting a shopping research capability within its Meta AI chatbot, signalling a deeper move into ecommerce as competition intensifies with ChatGPT and Gemini. The feature, currently rolling out to select users in the US via the Meta AI web interface, enables consumers to request product recommendations. In response, the chatbot displays a carousel of images featuring brand names, pricing and merchant links, alongside bullet-point summaries explaining the reasoning behind each suggestion.
E-Commerce
Miscellaneous
fromZDNET
1 month ago

Rolling out AI? 5 security tactics your business can't get wrong - and why

AI's useful capabilities also make it exploitable, requiring professionals to balance security with competitive implementation through knowledge sharing, partnerships, and automation.
#cyberattacks
Information security
fromSecurityWeek
1 month ago

Hackers Weaponize Claude Code in Mexican Government Cyberattack

Attackers exploited Claude Code to compromise ten Mexican government bodies and a financial institution, exfiltrating 150GB of data affecting 195 million identities by bypassing AI safety guardrails through social engineering.
fromJezebel
1 month ago
Artificial intelligence

Hacker Used Commercial AI Chatbots to Breach Most of the Mexican Government

Information security
fromSecurityWeek
1 month ago

Hackers Weaponize Claude Code in Mexican Government Cyberattack

Attackers exploited Claude Code to compromise ten Mexican government bodies and a financial institution, exfiltrating 150GB of data affecting 195 million identities by bypassing AI safety guardrails through social engineering.
fromJezebel
1 month ago
Artificial intelligence

Hacker Used Commercial AI Chatbots to Breach Most of the Mexican Government

Information security
fromThe Hacker News
1 month ago

ClawJacked Flaw Lets Malicious Sites Hijack Local OpenClaw AI Agents via WebSocket

OpenClaw fixed a high-severity vulnerability allowing malicious websites to hijack locally running AI agents through password brute-forcing and unauthorized device registration.
#cybercrime
fromEngadget
1 month ago
Information security

Hacker used Anthropic's Claude chatbot to attack multiple government agencies in Mexico

fromEngadget
1 month ago
Information security

Hacker used Anthropic's Claude chatbot to attack multiple government agencies in Mexico

Information security
fromTechzine Global
1 month ago

VAST Data aims for secure-by-default AI with CrowdStrike

VAST Data and CrowdStrike integration provides real-time threat detection, automated response, and security controls at the data layer for AI and analytics environments.
Information security
fromFortune
1 month ago

Nearly two-thirds of companies have lost track of their data just as they're letting AI in through the front door to wander around | Fortune

Only 34% of organizations know where their data resides, creating critical security vulnerabilities as AI systems gain broad access to enterprise networks without adequate controls.
[ Load more ]