OpenAI says Astra can autonomously find zero-days and build exploits, marking its first model to reach the “Critical” cyber risk level. Astra is now…
Tag: AI Security
OpenLeash Adds a Human Check to Risky AI Agent Actions
The security tool intercepts potentially dangerous agent actions, blocking clear threats and requesting human approval when intent is uncertain.
Google, Anthropic, and OpenAI Unveil Cyber AI Models, Safeguards, and Access Programs
Google on Wednesday announced Gemini 3.8 Flash Cyber, which it described as its most capable cybersecurity model, and has made it available to a set of…
AI agents carried out every step of this ransomware attack – then left the victim an 80-page security audit
Adding insult to injury
AI Agents Are Now Emailing Me with Their Security Concerns
I received the two emails below earlier in the month. They’re vaguely coherent. I suppose I shouldn’t be surprised that the corpus that AIs are training…
Wiz Finds Active LiteLLM and MCP Attacks Targeting AI Infrastructure
Wiz observed active attacks on LiteLLM and MCP servers, including credential theft, cryptomining, command execution, and prompt injection.
HiddenLayer nabs $100M as enterprises rush to secure their AI deployments
HiddenLayer has raised a $100M Series B from Delta-v Capital, Ten Eleven Ventures, Morgan Stanley, Microsoft’s M12, Booz Allen Hamilton, and others.
Frontier AI helps exploit flaws in tests using key industrial devices
A report showed that Claude could help hackers develop attack strategies targeting PLCs used by water utilities and other industries.
Malicious .git Configs Can Make Claude, Codex, Cursor, and Other AI Agents Run Attacker Code
Manifold Security has disclosed eight security flaws across seven command-line AI coding agents in which a repository’s own Git configuration names a…
Beyond Agent-Washing: The Engineering Principles Behind Production-Ready AI Agents
An AI agent is not defined by how intelligently it talks. It’s defined by what it’s trusted to do. Give a language model a chat window, and you have an…
$536 and 8 Hours: AI Learns to Attack a Different PLC
Experts got Claude to port a PLC exploit, but it cost $536 and 8 hours, and a later AI-generated payload accidentally destroyed the hardware. Forescout…
AI Observability Must Evolve for the Agentic Era
In this article Traditional observability tells you whether software worked. For AI agents, the harder question is whether the system made the right…
Hackers Exploit LiteLLM Admin API Flaw to Steal Secrets and Target AI Gateway Servers
Attackers are actively probing LiteLLM AI gateway deployments for a known authorization flaw that can turn a low-privilege account into full…
Claude AI Builds Pre-Auth RCE Exploit for WAGO PLC to Execute ARM Shellcode Without Credentials
Researchers used Claude AI to help port a pre-authentication remote code execution exploit to a WAGO programmable logic controller, demonstrating how AI…
Palo Alto Networks Acquires Console to Build AI Agents for Autonomous Security Operations
Palo Alto Networks has acquired Console, an AI-native platform that will strengthen Cortex by enabling AI-driven security workflows to investigate,…
Claude AI Develops Working RCE Exploit Against WAGO PLC With Researcher Assistance
Researchers have demonstrated that Anthropic’s Claude AI can assist in porting a remote code execution exploit between vulnerable models of WAGO…
Palo Alto Networks Acquires Console to Add Agentic AI Workflows to Cortex
Palo Alto Networks has acquired Console, an AI-native platform designed to enable agentic workflows across enterprise operations. This acquisition expands…
UK cyber bill targets AI users, not the vendors building it
Ministers reject proposed red lines and emergency shutdown powers, pointing instead to voluntary safeguards
Your AI chats could be used in court
What you tell an AI chatbot could come back to haunt you in court. The Washington Post found chat histories already used in 12 legal cases.
EU Queries Publishers Over Google AI Opt-Out
European Commission reportedly asks publishers whether they plan to take advantage of Google offer to opt-out of AI features