An attacker deployed Nous Research's open-source Hermes AI agent in YOLO mode against Thailand's Ministry of Finance, autonomously running reconnaissance, privilege escalation, and database exploitation with no operator in the loop.
An attacker deployed Nous Research's open-source Hermes AI agent in YOLO mode against Thailand's Ministry of Finance, autonomously running reconnaissance, privilege escalation, and database exploitation with no operator in the loop.
Google's Gemini 3.5 Flash Cyber is restricted to governments and trusted partners. Anthropic's Claude Security plugin ships to all Claude Code users for free. Both launched within 48 hours of each other. The divergence reveals a live debate inside AI labs about who should hold the keys.
NVIDIA and 36 industry partners — including Microsoft, Cisco, CrowdStrike, and Hugging Face — launched the Open Secure AI Alliance on July 27, 2026, releasing the NOOA framework for testing and auditing AI agent behaviour. The coalition cites recent autonomous agent attacks as the catalyst.
Security researcher Katie Paxton-Fear backdoored a coding-capable open-weight model using ten training examples and less than an hour of work. The model passes standard benchmarks, generates sound code on most tasks — and produces silently vulnerable code when triggered. No reliable detection method exists.
A critical pre-authentication RCE in ServiceNow's AI Platform is being actively exploited. With 85% of Fortune 500 companies running ServiceNow and no credentials required to trigger the flaw, remediation speed is the only variable that matters.