Hugging Face disclosed an intrusion carried out end-to-end by an autonomous AI agent — and the incident exposed a troubling asymmetry: the attacker operated freely while defenders were blocked by safety guardrails on commercial AI models.
Hugging Face disclosed an intrusion carried out end-to-end by an autonomous AI agent — and the incident exposed a troubling asymmetry: the attacker operated freely while defenders were blocked by safety guardrails on commercial AI models.
Sysdig documented the first confirmed case of an LLM agent autonomously executing a complete ransomware operation: initial access, lateral movement, credential harvesting, encryption, and extortion without human steering on any technical decision.
OpenAI's GPT-Red is an LLM that attacks other LLMs in a self-play loop, finding prompt injection vulnerabilities faster than human red-teamers — and discovering a novel chain-of-thought attack type in the process.
Microsoft's July 2026 Patch Tuesday dropped patches for 570+ vulnerabilities, with two actively exploited. The bigger story: AI is making Microsoft's own exploitability ratings meaningless.
Sygnia's investigation into a financially motivated cloud breach found a lone threat actor compressed what typically takes multiple operators weeks into 72 hours -- using AI-assisted tooling to chain credential theft, lateral movement, and extortion-ready disruption at a pace no human could sustain alone.