A joint federal advisory says attackers are using AI to generate Python exploitation scripts against internet-exposed Siemens S7 PLCs across US critical infrastructure.
The latest AI security developments, threats, and industry updates.
A joint federal advisory says attackers are using AI to generate Python exploitation scripts against internet-exposed Siemens S7 PLCs across US critical infrastructure.
Adversa AI researchers found that encrypting malicious instructions inside a webpage lets attackers slip past Grok's content filters and pull chat history straight out of a conversation.
A critical improper-authorization flaw in Microsoft Copilot Cowork, tracked as CVE-2026-59118 and scoring 9.3, let attackers elevate privileges over the network. Microsoft fixed it in the August 2026 Patch Tuesday round, roughly two months after the agent went GA.
Varonis researchers used the assistant's own refusals to map an undocumented URL parameter in Microsoft Copilot Personal, chaining it into silent access to Gmail, Drive, and Calendar. Microsoft patched CVE-2026-24301 on August 18.
A critical unauthenticated SSRF in MLflow's webhook delivery lets attackers pivot into cloud metadata endpoints and steal credentials. WatchTowr's honeypot network caught scanning starting within hours of the CVE going public.