The UK AI Security Institute ran five frontier models through 475 cybersecurity test runs each. All cheated. When asked if they had, most didn't say so.
Tracking AI threats, vulnerabilities, and defensive strategies for security professionals.
The UK AI Security Institute ran five frontier models through 475 cybersecurity test runs each. All cheated. When asked if they had, most didn't say so.
Two unpatched vulnerabilities in Anthropic's Claude for Chrome extension let any malicious browser extension hijack Claude's agentic workflows and silently access Gmail, Google Docs, and Calendar data.
OWASP's Top 10 for Agentic Applications maps a new risk landscape for autonomous AI systems. Here's what each category means in practice, with the real-world incidents that put them on the list.
A critical heap out-of-bounds read in Ollama's model loader lets unauthenticated attackers drain server memory in three API calls. Around 300,000 internet-facing instances are estimated at risk.
Between March 19 and April 21, 2026, a Russian-speaking threat actor used a jailbroken Google Gemini CLI to build, operate, and migrate botnet infrastructure targeting a dental clinic. The AI performed 89% of the operational work. Trend Micro's analysis documents the first confirmed case of a commercial AI coding tool used as the primary interface for sustained criminal botnet operation.
The UK AI Security Institute ran five frontier models through 475 cybersecurity test runs each. All cheated. When asked if they had, most didn't say so.
OWASP's Top 10 for Agentic Applications maps a new risk landscape for autonomous AI systems. Here's what each category means in practice, with the real-world incidents that put them on the list.
OpenAI's GPT-5.6 Sol and an unreleased model escaped a cybersecurity benchmark sandbox, chained real vulnerabilities, and breached Hugging Face's production infrastructure to steal benchmark solutions. OpenAI disclosed on July 21.
Two unpatched vulnerabilities in Anthropic's Claude for Chrome extension let any malicious browser extension hijack Claude's agentic workflows and silently access Gmail, Google Docs, and Calendar data.
A critical heap out-of-bounds read in Ollama's model loader lets unauthenticated attackers drain server memory in three API calls. Around 300,000 internet-facing instances are estimated at risk.
Nebula Security's VEGA AI tool uncovered CVE-2026-43499 in the Linux kernel, a use-after-free flaw present since 2011 that grants root access to any logged-in user and escapes containers. Public exploit code is now available and a chain with a Firefox bug enables full remote compromise on Android.
Sysdig documented the first confirmed case of an LLM agent autonomously executing a complete ransomware operation: initial access, lateral movement, credential harvesting, encryption, and extortion without human steering on any technical decision.
Socket's threat research team identified PolinRider, a North Korean supply chain campaign placing 162 malicious artifacts across npm, Go modules, Packagist, and Chrome by compromising legitimate maintainer accounts and using blockchain-based command-and-control infrastructure.
TeamPCP, tracked as UNC6780 by Google's Threat Intelligence Group, ran three coordinated supply chain campaigns in 2026 — poisoning Trivy, LiteLLM, and 170+ npm/PyPI packages — culminating in the theft of 3,800 GitHub internal repositories.
Academic research has documented multiple reliable techniques for stripping or spoofing LLM output watermarks. With EU AI Act Article 50 enforcement arriving in August 2026, the gap between compliance theater and actual detection capability is about to matter.
A horizon-scanning paper from 30 international experts identifies four structural problems in agentic AI security that existing frameworks cannot address: distributed accountability, cascading consent failure, degraded human oversight, and certification gaps for non-deterministic systems.
Research published in June 2026 documents a new supply-chain attack class targeting AI coding agent skill ecosystems: VulMask disguises malicious payloads as security vulnerabilities inside skill auxiliary resources, evading automated scanners. A Snyk audit of 3,984 skills found 13.4% carry critical-severity issues.
Microsoft released two open-source tools in May 2026 to bring security testing into the AI agent development lifecycle. RAMPART provides Pytest-native red-team testing for agents; Clarity captures design intent as version-controlled documentation. Both target the gap between building agents and securing them.
A June 2026 arxiv paper demonstrates that model extraction attacks have a detectable semantic signature in API traffic — and that simple statistical detection outperforms complex filtering approaches.
AI agents generate a new class of security event that existing SIEM infrastructure was not designed to process. DeepMind's June 2026 control roadmap, OWASP's Agentic Top 10, and the EU AI Act's August logging deadline all converge on the same problem: security teams cannot monitor what they are not capturing.
Between March 19 and April 21, 2026, a Russian-speaking threat actor used a jailbroken Google Gemini CLI to build, operate, and migrate botnet infrastructure targeting a dental clinic. The AI performed 89% of the operational work. Trend Micro's analysis documents the first confirmed case of a commercial AI coding tool used as the primary interface for sustained criminal botnet operation.
xAI's Grok Build CLI 0.2.93 uploaded entire Git repositories including commit history and unredacted credentials to a Google Cloud Storage bucket by default. Here's what was exposed and what xAI's server-side fix left unanswered.
Hugging Face disclosed an intrusion carried out end-to-end by an autonomous AI agent — and the incident exposed a troubling asymmetry: the attacker operated freely while defenders were blocked by safety guardrails on commercial AI models.