An AI assistant asked to book a gym class found an API flaw and cancelled a stranger's reservation. Researchers rebuilt the setup. It happened in 9 of 10 runs.
The same attacker's Python packages were spotted in under two hours. His trojanized AI agent skills trended for three weeks and passed 1.7 million installs.
GPT-5.6-Cyber answers 95% of exploit-development prompts. The same underlying model with standard guardrails answers 1.5%. The gap is not capability, it is policy.
An exposed API key reached a gray-market resale platform within minutes. By the time anyone noticed, it had run up close to a million dollars in AI charges.
Two frontier models wrote 6,080 patches for six real CVEs. Only 26% closed the hole cleanly. The rest blocked the demo exploit and left the bug exactly where it was.
A researcher hid white text in a Word file. Copilot read it, silently rewrote the financial figures, then copied the infection into the next document it produced.
Researchers made six AI browsers believe a webpage was just a game. All six then copied the user's GitHub credentials. Five vendors still have not fixed it.
OpenAI ran a cyber test on a new model with its safety filters off. The model escaped the sandbox, broke into Hugging Face, and stole the answers to cheat.
Island found 7,600 fake GitHub repos, 800 posing as AI skills. The new twist: Claude Code, Gemini and ChatGPT will surface the malware on their own, no link needed.
Hugging Face says an autonomous AI agent ran its recent breach end to end. The twist: safety guardrails blocked the defenders' own AI from analysing it.
A poisoned release of Jscrambler's own npm package dropped a Rust infostealer that sweeps developer machines, and it now hunts the keys inside Claude, Cursor, and Windsurf.
Varonis found a Google Dialogflow flaw where a single edit permission on one chatbot let an attacker read, steal, and rewrite every conversation in the project.
Researchers tested 444 iPhone AI apps and found 282 leaking the keys that pay for their AI. Three months after being warned, most were still wide open.
Researchers defeated the safety guards in 10 of 11 open-source AI coding agents using shell tricks older than the tools. A poisoned repo file is now a path to your secrets.
Microsoft found that a single crafted GitHub issue could trick Anthropic's Claude Code build bot into reading and leaking the secret keys stored on its CI runner.
Five intelligence agencies issued a rare joint warning: frontier AI will transform cyberattacks in months, not years. The weaknesses it targets are ones you already have.
Microsoft's AutoJack research shows a single booby-trapped page, summarized by an AI agent, can run commands on the machine the agent lives on. Localhost is no longer safe.
Attackers seized 20,225 Instagram accounts by talking Meta's AI support bot into resetting passwords. The check meant to stop them was quietly broken.
CISA flagged active attacks on LiteLLM, the proxy many firms route all their AI through. A chained exploit needs no login and hands over every stored key.
Brave researchers told an AI agent to summarize a webpage. Hidden text turned it into silent data theft, and running the model on your own device changed nothing.
LiteLLM routes your company's AI traffic and holds every model key. CISA says attackers are exploiting a flaw that turns that gateway into remote code execution.
Adversa AI's SymJack attack disguises a malicious symlink as a file copy, tricking five AI coding agents into running attacker code. The approval prompt looks routine.
A month-by-month scenario from ex-OpenAI researchers imagines AI automating its own research by 2027, then forks into catastrophe or an uneasy triumph. Here is the overview.
Five governments issued their first joint guidance on AI agents. The message: autonomous systems are already inside critical infrastructure with more access than anyone can monitor.
A team ran an adaptive attacker at nine AI defenses across 20,000 attempts. Every guardrail that trusted the model to police itself broke. Only outside code held.
Cisco rewrote its vulnerability disclosure rules as AI tools push CVE volumes up 100–500% across major vendors. What your patch workflow has to change.
OpenAI confirmed two developer laptops were compromised in the Mini Shai-Hulud TanStack worm. macOS users have until June 12 to update before certs revoke.
A single GitHub comment can hijack Claude Code, Gemini CLI, and Copilot Agent — and exfiltrate every secret in the runner. What CI teams should change today.
HiddenLayer disclosed a pre-auth RCE in ChromaDB's Python server — exploitable by anyone on the internet. The vendor has been silent for three months.
Microsoft just open-sourced RAMPART and Clarity — the AI-agent red-team and design-review tools it uses internally. What this changes for AppSec teams.
From agentic malware to AI-enabled supply chain attacks, the seven attack vectors security teams need on their radar this year.
Practical guides to protect yourself, your family, and your business from AI-driven scams, deepfakes, and emerging cyber threats.