A joint federal advisory says attackers are using AI to generate Python exploitation scripts against internet-exposed Siemens S7 PLCs across US critical infrastructure.
A joint federal advisory says attackers are using AI to generate Python exploitation scripts against internet-exposed Siemens S7 PLCs across US critical infrastructure.
Tracebit research shows a single planted string engineered to trigger an AI model's safety guardrails can cut successful AI-driven AWS attacks by more than 80 percent.
Adversa AI researchers found that encrypting malicious instructions inside a webpage lets attackers slip past Grok's content filters and pull chat history straight out of a conversation.
A critical improper-authorization flaw in Microsoft Copilot Cowork, tracked as CVE-2026-59118 and scoring 9.3, let attackers elevate privileges over the network. Microsoft fixed it in the August 2026 Patch Tuesday round, roughly two months after the agent went GA.
Rapid7 used a heavily supervised AI agent to find a JWT forgery flaw and an unsafe .NET deserialization bug in SharePoint, chaining them into unauthenticated RCE. CVE-2026-55040 is now under active attack.