Left alone, autonomous fixes often fail to fully remediate flaws
Tag: AI Security
Why “AI Pentesting” is the Wrong Term (And Why We Need AI Red Teaming)
Recently, I read a great post by Melvin Tan Zhi Xian sharing his thoughts halfway through the OffSec OSAI+ course. He touched on something crucial that…
Accelerating Enterprise AI from Proof of Concept to Production
Discover how Akamai AI Professional Services helps enterprises bridge the gap from proof of concept to secure, scalable, and manageable production AI.
Humans in the loop miss a third of dangerous AI coding agent requests
You wouldn’t let Claude Code cat your AWS credentials or Kubernetes config on request, would you?
1Password Finds AI Security Patches Fail More Than Half the Time
A 1Password study found AI-generated security patches failed to fully fix vulnerabilities in more than half of tested cases.
Meta AI Agent Exploited Third-Party Flaw During Cybersecurity Test
Meta is investigating after an AI model hacked another company during testing, raising concerns over agent containment and enterprise security safeguards.
OpenAI and Anthropic AI Agents Crossed Testing Boundaries During Cybersecurity Evaluations
A separate cybersecurity evaluation conducted by OpenAI and Anthropic revealed that artificial intelligence models were behaving in unexpected ways…
Meta Joins OpenAI and Anthropic in Reporting AI Exploit Incident
One of Meta’s AI models exploited a third-party security flaw during an evaluation, the latest in a series of similar incidents involving advanced AI…
Critical Paperclip AI Agent Flaws Allow Unauthenticated Remote Code Execution
Critical vulnerabilities in the open-source Paperclip AI-agent orchestration platform could allow attackers to execute commands remotely on exposed…
Cloudflare Launches Open-Source OS to Secure AI Agents’ Access to Internal Data
Cloudflare has open-sourced Cloudflare OS, a platform designed to provide enterprise AI agents with controlled access to internal systems, company…
AI Recommendation Poisoning: How “Ask AI” Buttons Silently Alter LLM Memory
A new class of prompt injection is spreading across commercial websites. It requires no malware, no stolen credentials, and no zero-day exploit. It abuses…
Zero-Click AI Browser Hacking: Claude and ChatGPT Atlas Hijacked via Emails, X Posts
Zenity researchers reported the findings to Anthropic and OpenAI in late 2025 and early 2026, but they remain unpatched.
OWASP Releases GenAI LLM Top 10 2026 for Building and Securing Modern AI Apps
The Open Web Application Security Project (OWASP) has officially released the Top 10 for LLM Applications 2026, a foundational security guide targeting…
Anthropic’s Mythos AI used social engineering to target real people
Testers found that Anthropic’s AI agent Mythos attempted to social engineer Github developers into accepting malicious code.
Meta AI Model Gained Internet Access and Hacked Another Organization’s Network
Meta has disclosed that one of its AI models gained unintended access to the internet during a cybersecurity evaluation and then exploited a vulnerability…
Meta Confirms AI Model Launched Autonomous Attack on Another Organization
Meta has become the latest technology company to disclose that an AI agent accessed another organization’s online systems during a controlled…
Token Jacking: Cybercriminals Could Be Stealing Your AI Resources
Discover how attackers hijack AI tokens to fuel gray market transfer stations by stealing developer API keys.
Black Hat USA 2026: One GitHub Issue Could Compromise Major AI Coding Workflows
At Black Hat USA 2026, Novee found GitHub workflow flaws in Claude Code, Gemini CLI and Codex that enabled RCE, credential theft and agent control in…
Meta AI Model Hacked a Company During Testing, Marking Third AI Lab Incident
Meta says an AI model hacked a company during testing after accidental internet access, marking the third disclosed AI lab breach in weeks. Meta confirmed…
Meta AI Model Hacked Outside System During Test
AI model developed by Facebook parent Meta accessed internet due to configuration issue, hacked outside system