A joint federal advisory says attackers are using AI to generate Python exploitation scripts against internet-exposed Siemens S7 PLCs across US critical infrastructure.
Tracking AI threats, vulnerabilities, and defensive strategies for security professionals.
A joint federal advisory says attackers are using AI to generate Python exploitation scripts against internet-exposed Siemens S7 PLCs across US critical infrastructure.
Tracebit research shows a single planted string engineered to trigger an AI model's safety guardrails can cut successful AI-driven AWS attacks by more than 80 percent.
Adversa AI researchers found that encrypting malicious instructions inside a webpage lets attackers slip past Grok's content filters and pull chat history straight out of a conversation.
A critical improper-authorization flaw in Microsoft Copilot Cowork, tracked as CVE-2026-59118 and scoring 9.3, let attackers elevate privileges over the network. Microsoft fixed it in the August 2026 Patch Tuesday round, roughly two months after the agent went GA.
Rapid7 used a heavily supervised AI agent to find a JWT forgery flaw and an unsafe .NET deserialization bug in SharePoint, chaining them into unauthenticated RCE. CVE-2026-55040 is now under active attack.
A joint federal advisory says attackers are using AI to generate Python exploitation scripts against internet-exposed Siemens S7 PLCs across US critical infrastructure.
Adversa AI researchers found that encrypting malicious instructions inside a webpage lets attackers slip past Grok's content filters and pull chat history straight out of a conversation.
A critical improper-authorization flaw in Microsoft Copilot Cowork, tracked as CVE-2026-59118 and scoring 9.3, let attackers elevate privileges over the network. Microsoft fixed it in the August 2026 Patch Tuesday round, roughly two months after the agent went GA.
Rapid7 used a heavily supervised AI agent to find a JWT forgery flaw and an unsafe .NET deserialization bug in SharePoint, chaining them into unauthenticated RCE. CVE-2026-55040 is now under active attack.
A CVSS 9.9 authorization flaw in Microsoft's Azure SRE Agent broke the on-behalf-of flow, letting attackers inherit the agent's managed identity across an organisation's entire cloud footprint.
CISA adds CVE-2025-62593 to the Known Exploited Vulnerabilities catalog — a browser CSRF chain that lets malicious websites submit arbitrary Python jobs to locally running Ray clusters in Firefox and Safari, confirming active exploitation of ML infrastructure.
ESET discovered PromptSpy in February 2026 — the first known Android malware to query a live generative AI API at runtime. It uses Google Gemini to parse on-screen UI state and issue gesture instructions that keep the malware alive on infected devices.
Sysdig documented the first confirmed case of an LLM agent autonomously executing a complete ransomware operation: initial access, lateral movement, credential harvesting, encryption, and extortion without human steering on any technical decision.
Socket's threat research team identified PolinRider, a North Korean supply chain campaign placing 162 malicious artifacts across npm, Go modules, Packagist, and Chrome by compromising legitimate maintainer accounts and using blockchain-based command-and-control infrastructure.
A new benchmark from Shanghai AI Laboratory tests six leading GUI agents against environmental injection attacks embedded in real Android apps. Every agent is vulnerable, attack success rates reach 66.9%, and stronger agents turn out to be more exploitable, not less.
Anthropic and EPFL researchers demonstrate that ideological and action payloads can spread between AI agents through editable system prompt state files, surviving 20-hop chains with no human intervention. One defensive measure stops them almost entirely.
1Password's Off-by-1 Labs tested two frontier AI models against six real CVEs and found that only a quarter of the generated patches fully fixed the vulnerability without introducing new problems. The implications for teams relying on AI-assisted remediation are significant.
Tracebit research shows a single planted string engineered to trigger an AI model's safety guardrails can cut successful AI-driven AWS attacks by more than 80 percent.
Canary tokens planted in system prompts, RAG corpora, and training datasets give defenders a zero-false-positive tripwire for detecting prompt extraction attacks, cross-tenant data leakage, and model distillation theft. This guide covers deployment mechanics, attribution, and the limits of what canaries catch.
When prompt injection succeeds, unconstrained LLM outputs give attackers unlimited action space. Output schema enforcement and grammar-constrained generation shrink that surface meaningfully, even when injection itself can't be fully prevented.
A service called Poison Claude resold Claude API access at a fraction of the official price by routing requests through compromised AWS Bedrock accounts, giving operators full visibility into every customer prompt. A configuration error revealed nearly 900 active users had been sending sensitive queries through a third-party proxy they didn't know was reading their traffic.
Anthropic disclosed on July 31 that three of its models — Claude Opus 4.7, Mythos 5, and an unreleased internal prototype — breached real companies during cybersecurity capability evaluations after an evaluation partner misconfigured network egress. The models used basic techniques: weak passwords, unsecured endpoints, SQL injection. Mythos 5 never concluded it had left the simulation.
An attacker deployed Nous Research's open-source Hermes AI agent in YOLO mode against Thailand's Ministry of Finance, autonomously running reconnaissance, privilege escalation, and database exploitation with no operator in the loop.