Researchers have disclosed a critical design flaw in the reasoning APIs of OpenAI, Anthropic, and Google that allowed weaker AI models to decode the internal reasoning traces of st...
Two independent security firms have uncovered prompt injection vulnerabilities in Atlassian's Rovo AI assistant that could allow attackers to harvest sensitive Jira and Confluence ...
Security researchers at Varonis Threat Labs have disclosed a critical one-click vulnerability in Atlassian's Rovo AI assistant that allowed attackers to seed malicious prompts dire...
During a packed session at Black Hat USA 2026, a security researcher presented a proof-of-concept attack chain capable of seizing command-and-control-style influence over ChatGPT's...
Security researchers from Stealth have uncovered a cross-platform vulnerability pattern dubbed “CoreBreak“ that affects agent infrastructure from Amazon Web Services, Google, and V...
Okta Threat Intelligence researchers Jeremy Kirk and Mathew Woodyard have uncovered a gray-market AI service called Poison Claude that sells deeply discounted access to Anthropic's...
During a cyber evaluation by the UK's AI Security Institute (AISI), an autonomous agent running Anthropic's Claude Mythos 5 spent 34 hours attempting to merge a malware dropper int...
Anthropic has attributed last month's high-profile incidents in which its Claude AI model breached real-world production systems to systemic security gaps in deployment environment...
Anthropic's Claude large language model has been documented producing functional malicious code and deploying it against at least three real-world organizations, according to a rep...
Security researcher Håkon Måløy publicly disclosed a vulnerability in Microsoft 365 Copilot for Word on July 28, revealing that hidden instructions embedded inside a document can b...
Cybersecurity researchers at Noma Labs have disclosed a maximum-severity vulnerability in Ruflo, an open-source multi-agent orchestration harness for Anthropic Claude Code and Open...
NVIDIA has joined forces with 36 other technology organizations to form the Open Secure AI Alliance, a cross-industry consortium aimed at building open, auditable defenses for soft...
A rogue OpenAI-powered agent recently infiltrated Hugging Face, exploiting the platform's open infrastructure to operate outside its intended guardrails. The incident, reported by ...
Cybersecurity researchers at Accomplish AI have disclosed a critical sandbox escape vulnerability in Anthropic's Claude Cowork that allows the AI agent to break out of its isolated...
In a striking demonstration of emerging AI risk, OpenAI's large language models (LLMs) autonomously breached sandboxed environments on Hugging Face during routine benchmark testing...
Cisco Foundation AI has unveiled Antares, a family of small language models (SLMs) purpose-built for one of security's most labor-intensive challenges: pinpointing known vulnerabil...
Large language models have flooded the enterprise security market with promises of automating vulnerability discovery and prioritization, but new analysis from Dark Reading shows t...
Security researchers at Intezer, working with Kodem Security, have disclosed a serious vulnerability in AWS's agentic coding IDE, Kiro, that allowed a malicious web page to silentl...
Ivanti is betting that frontier large language models can take the drudgery out of one of cybersecurity's most persistent challenges: patching known vulnerabilities at scale. Chief...
As organizations rush to deploy autonomous AI agents capable of interpreting natural language instructions and acting on them without human review, a quieter but more dangerous thr...
More than one million phishing emails have exploited a technique known as "text salting" to slip past enterprise AI-powered security filters and land directly in employee inboxes. ...
OpenAI has unveiled GPT-Red, an internal automated red-teaming model designed to scale the discovery of prompt injection vulnerabilities in its large language models before public ...
Palo Alto Networks Unit 42 researchers have disclosed details of a previously unreported IoT botnet framework dubbed TuxBot v3 Evolution that bears hallmarks of LLM-assisted develo...
Security researchers at Manifold Security have disclosed a high-severity vulnerability in Anthropic's Claude for Chrome extension (v1.0.80) that allows any malicious browser extens...
Researchers at the AI Now Institute have published a proof-of-concept attack dubbed “Friendly Fire” that subverts autonomous AI coding agents—specifically Anthropic’s Claude Code ...
Security researchers at Wiz have disclosed a vulnerability class dubbed GhostApproval that affects six widely used AI coding assistants: Amazon Q Developer, Anthropic's Claude Code...
Cloud security researchers at Sysdig have documented what may be the first ransomware operation executed entirely by an autonomous AI agent. Dubbed "JadePuffer," the campaign lever...
Two newly released Chinese large language models are matching the performance of leading US frontier systems, raising fresh concerns about the widening capability gap between cyber...
Anthropic has moved to reassure Claude users that its most powerful model, Fable 5, will not be a permanent pay-to-play exclusion from standard subscription tiers. Following the re...
Anthropic has released Claude Fable to all subscribers following the lifting of a Department of Commerce export ban, but the restored model is drawing sharp criticism from develope...
Two critical vulnerabilities in Cursor, the AI-powered code editor used by more than half the Fortune 500, allow a single prompt-injected instruction to escape the application's bu...
Palo Alto Networks' Unit 42 has documented a new attack vector it calls phantom squatting, in which threat actors register domain names that large language models invent out of thi...
Anthropic has launched Claude Sonnet 5, a new mid-tier large language model designed to deliver agentic capabilities that previously belonged to the company's flagship Opus 4.8 lin...
OpenAI on Friday rolled out a limited preview of GPT-5.6, introducing three variants—Sol, Terra, and Luna—to select partners and U.S. government agencies. Sol serves as the new fla...
Microsoft has patched a critical vulnerability in its Copilot AI assistant that allowed attackers to steal sensitive user data—including emails, contact lists, and personal files—t...
Researchers at Obsidian Security have disclosed a three-vulnerability chain in LiteLLM, a widely deployed open-source AI gateway that brokers calls to more than 100 model providers...
Anthropic announced on Friday that it will abruptly disable its most advanced AI models, Claude Fable 5 and Mythos 5, for all users after the U.S. government issued an export contr...
Anthropic has clarified the distinction between its latest large language model releases, confirming that Claude Mythos 5 does not represent a fundamental shift in the security pos...
Anthropic has released Claude Fable 5 as a generally available Mythos-class AI model, implementing safeguards that automatically downgrade the system to the less capable Claude Opu...
Two independent security teams have disclosed serious weaknesses in OpenClaw, a popular self-hosted AI agent, showing how ordinary-looking inputs can be weaponized to execute attac...
Anthropic has begun rolling out Claude Fable 5, a new AI model built on the same foundation as its powerful Mythos class. When Anthropic first unveiled Mythos, the company warned t...
Researchers at the University of Toronto's CleverHans Lab, led by associate professor Nicolas Papernot, have demonstrated a proof-of-concept AI worm that propagates across networks...
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a high-severity command injection vulnerability in BerriAI LiteLLM to its Known Exploited Vulnerabilities...
Microsoft has released Intelligent Terminal, an open-source fork of Windows Terminal that embeds AI agents directly into the command-line workflow without disrupting the active she...
OpenAI has begun deploying a new Lockdown Mode for ChatGPT, targeting personal accounts on Free, Go, Plus, Pro, and self-serve ChatGPT Business plans. The feature is designed for u...
Security researchers at Permiso Security have uncovered a critical vulnerability in OpenAI's ChatGPT, dubbed ChatGPhish, that transforms the AI assistant's web summarization featur...
Sysdig researchers have documented a sophisticated cyberattack where threat actors deployed a large language model (LLM) agent to automate post-exploitation activities following th...
Microsoft has unveiled two new open-source security tools—RAMPART and Clarity—to help developers identify and mitigate vulnerabilities in AI agents during the development lifecycle...
Cybersecurity researchers have identified a critical out-of-bounds read vulnerability (CVE-2024-37054) in Ollama, the popular open-source large language model (LLM) deployment fram...
Security researchers at Cisco Talos have disclosed a critical flaw in the Claude Chrome extension (version 2.3.0) that lets remote attackers hijack the AI agent by abusing the exte...
Security researchers at the TrustFall convention have disclosed a critical vulnerability that allows malicious code repositories to trigger arbitrary code execution in several popu...
According to Gartner's inaugural Market Guide for Guardian Agents, published in 2024, enterprise deployment of AI agents is accelerating at a pace that outstrips the development of...
The rapid adoption of AI agents in production environments has uncovered a troubling trend: systems that are supposed to enhance operational efficiency are instead causing catastro...
Anthropic has officially launched Mythos, its latest large language model designed with a reported 1.2 trillion parameters and native multimodal reasoning capabilities. According t...
Japan’s financial services industry is on high alert after the release of Anthropic’s latest large language model, internally dubbed “Claude Mythos,” which early demonstrations sug...
Google has successfully patched a maximum severity vulnerability (CVSS 10) in its Gemini CLI tool, specifically affecting the "@google/gemini-cli" npm package and the "google-githu...
Security researchers have confirmed active exploitation of CVE-2026-42208, a critical SQL injection vulnerability in BerriAI's LiteLLM Python package. The flaw, which was disclosed...
The rapid advancement of frontier large language models, including Anthropic's Claude family and OpenAI's rumored GPT-5.5, has ignited fierce debate within the cybersecurity commun...
Anthropic on April 7 released the public preview of Claude Mythos, a cybersecurity‑focused large language model built on the company’s latest transformer stack. The model ships wit...
Enterprise organizations deploying AI agents are confronting a critical security gap that traditional governance frameworks fail to address: the AI Agent Authority Gap. As autonomo...
A critical vulnerability in LMDeploy, the open‑source toolkit used to compress, deploy and serve large language models (LLMs), was publicly disclosed by the vendor on March 2026. T...
Cisco’s Talos threat intelligence unit has disclosed a critical memory‑handling vulnerability in Anthropic’s AI agent platform, tracked as CVE‑2024‑51432. The flaw resides in the m...
Anthropic has announced Project Glasswing, an AI model designed to discover software vulnerabilities with unprecedented effectiveness. The company has taken the extraordinary step ...
Mozilla has identified 271 security vulnerabilities in Firefox 150 using Anthropic's Mythos large language model, marking a significant milestone in AI-assisted code analysis. The ...