Tagged "ai-security"
Cross-cutting reads on this topic
Researchers took over OpenAI staff ChatGPT accounts via a forum image bug and an SSO flaw, then reached internal repos via Codex. A checklist for connector use.
#AI Security#Agentic AI+2 more
2026-09-18
Read Article
SentinelLABS matched public Hugging Face commits to OpenAI's May agent incident, to the second. What the report shows, and the logs a platform should keep.
#AI Security#Agentic AI+2 more
2026-09-16
Read Article
GreyNoise traced an AI-agent campaign that hit at least 440 PaperCut servers in 48 countries, days after a patch existed. What it changes about patch order.
#AI Security#Agentic AI+2 more
2026-09-15
Read Article
The NSA, CISA and FBI name six AI companies in advisory AA26-251A. See what changes for model procurement, provenance checks and API abuse monitoring.
#AI Security#Model Distillation+3 more
2026-09-08
Read Article
OpenAI committed $1 billion in subsidised Daybreak access over six months. What it is, which organisations are prioritised, and what remains unpublished.
#openai#daybreak+5 more
2026-09-03
Read Article
Google’s Fairwind joins Anthropic’s Glasswing and CVP, OpenAI’s Daybreak and Microsoft’s MDASH. One table of who is eligible for each cyber-capable model.
#ai-security#gated-models+4 more
2026-09-02
Read Article
curl’s maintainer posted that Mythos and Codex Security had nothing left to find. Days later AISLE filed 29 reports; six became Low CVEs in curl 8.22.0.
#ai-security#vulnerability-discovery+4 more
2026-09-02
Read Article
Independent report: 1,200 OpenAI agents on a hidden message board, 700 joined the Hugging Face attack, 7% of reviewed transcripts were spoofed. What changes.
#ai-security#agentic-ai+4 more
2026-09-01
Read Article
A census of 15 rows across 14 agent frameworks, scored against five SSRF controls from primary sources. Two default fetch paths re-validate every redirect hop.
#ssrf#agent-frameworks+4 more
2026-08-23
Read Article
A vendor-published disclosure ledger reports thousands of findings across hundreds of open-source projects. What maintainers and security teams should check.
#ai-security#vulnerability-disclosure+5 more
2026-08-15
Read Article
A five-day plan to red-team AI agents with garak, promptfoo and PyRIT, mapped to the OWASP agentic categories and the MITRE ATLAS technique taxonomy.
#ai-security#red-teaming+5 more
2026-08-04
Read Article
Microsoft's MAI-Cyber-1-Flash claims 96% on CyberGym at half the cost. The routing thesis behind it matters more than the unverified benchmark.
#Microsoft AI#MAI-Cyber-1-Flash+4 more
2026-07-27
Read Article
Anthropic's free Claude Code security plugin scans code as it's written across three layers, and a new on-demand deep-scan plugin backs it with real patches.
#claude code#ai security+5 more
2026-07-23
Read Article
Google's Gemini 3.5 Flash Cyber finds and patches vulnerabilities but stays gated. Why restricted access is becoming the default for dual-use AI models.
#gemini 3.5 flash cyber#gated ai models+5 more
2026-07-23
Read Article
Hugging Face says an autonomous AI agent — not a human — ran an end-to-end intrusion of its infrastructure, stealing internal datasets and credentials.
#hugging-face#ai-security+5 more
2026-07-20
Read Article
Cybersecurity data for 2026: vulnerability exploitation overtook stolen credentials as the top breach entry point, and average breach cost fell to $4.44M.
#cybersecurity-statistics#data-breach+5 more
2026-07-05
Read Article
Anthropic told US senators that Alibaba ran 28.8M Claude queries via 25,000 fake accounts, the largest model-distillation campaign it has disclosed.
#Anthropic#Alibaba+6 more
2026-06-27
Read Article
OpenAI's Lockdown Mode severs the exfiltration stage of prompt injection, not injection entry. What it disables, who needs it, and how to deploy it RBAC-style.
#chatgpt#lockdown-mode+6 more
2026-06-08
Read Article
Anthropic grew Project Glasswing to ~200 orgs in 15+ countries, with ICE/NYSE and Rubrik using its Mythos model to self-vet critical infrastructure.
#anthropic#project-glasswing+6 more
2026-06-04
Read Article
A 12-layer defense framework for prompt injection — input sanitization, structured outputs, tool gating, output filtering, eval coverage, replay forensics.
#prompt-injection-defense#twelve-layer-framework+7 more
2026-05-09
Read Article
Anthropic suffered two breaches in one week — Mythos document leak and Claude Code source leak. Enterprise AI security lessons and risk mitigation strategies.
#anthropic-breach#ai-security+5 more
2026-03-30
Read Article
OWASP's Agentic Top 10 defines the biggest security risks in autonomous AI systems. A plain-English guide covering each risk, real examples, and defenses.
#owasp-agentic-top-10#ai-security+5 more
2026-03-23
Read Article
1 in 8 enterprise security breaches now involve agentic AI systems. Threat landscape analysis with OWASP Agentic Top 10 mapping and defense strategies.
#ai-security#agentic-ai+4 more
2026-03-14
Read Article
40% of business email compromise attacks are now AI-generated deepfakes. Detection strategies, employee training frameworks, and enterprise protection guide.
#ai-deepfakes#email-compromise+4 more
2026-03-12
Read Article
76% of organizations report unauthorized AI tool usage by employees. Shadow AI detection framework, governance policies, and risk mitigation strategies.
#shadow-ai#ai-governance+4 more
2026-03-08
Read Article
Anthropic accuses DeepSeek, Moonshot AI, and MiniMax of industrial-scale distillation via 24,000 fake accounts and 16M+ Claude exchanges. Full analysis inside.
#ai-distillation#anthropic+5 more
2026-02-24
Read Article
The ClawHavoc attack exposed 341 malicious AI agent plugins. Essential security lessons for plugin ecosystems and agentic integrations.
#AI security#plugin security+5 more
2026-02-10
Read Article
OpenClaw's full system access creates significant attack surface. Complete security hardening guide with prompt injection defense and containerization.
#OpenClaw#AI security+4 more
2026-02-09
Read Article
341 malicious skills found on ClawHub in the ClawHavoc campaign. Full analysis of the attack, affected users, and VirusTotal partnership response.
#OpenClaw#ClawHub+5 more
2026-02-06
Read Article
Secure AI coding assistants in enterprise: data protection, code leakage prevention, compliance, and governance for Copilot, Claude, and Cursor.
#AI Security#Coding Assistants+4 more
2026-01-20
Read Article
Secure AI agents with enterprise best practices. 24 CVEs across top tools. Prompt injection, data exfiltration prevention. Complete guide.
#AI Security#Agent Security+4 more
2025-11-29
Read Article