HackMyIP

LLM Security News

64 stories tagged LLM Security

← All cybersecurity news

2026-08-12The Hacker News
Hidden AI Reasoning Flaw Leaked API Keys and Passwords Across Major LLMs

Researchers have disclosed a critical design flaw in the reasoning APIs of OpenAI, Anthropic, and Google that allowed weaker AI models to decode the internal reasoning traces of st...

AI SecurityLLM SecurityVulnerability
Read More → Use Tool →
2026-08-08The Hacker News
Atlassian Rovo Prompt Injection Flaws Expose Jira and Confluence Data

Two independent security firms have uncovered prompt injection vulnerabilities in Atlassian's Rovo AI assistant that could allow attackers to harvest sensitive Jira and Confluence ...

AI SecurityLLM SecurityVulnerability
Read More → Use Tool →
2026-08-08SecurityWeek
RovoBlast: One-Click Flaw in Atlassian Rovo AI Leaked Enterprise Data

Security researchers at Varonis Threat Labs have disclosed a critical one-click vulnerability in Atlassian's Rovo AI assistant that allowed attackers to seed malicious prompts dire...

VulnerabilityAI SecurityLLM Security
Read More → Use Tool →
2026-08-06Dark Reading
ChatGPT Sandbox Breached: C2-Style Attack Chain Demonstrated at Black Hat 2026

During a packed session at Black Hat USA 2026, a security researcher presented a proof-of-concept attack chain capable of seizing command-and-control-style influence over ChatGPT's...

AI SecurityLLM SecurityVulnerability
Read More → Use Tool →
2026-08-06The Hacker News
CoreBreak: AWS, Google, Vercel Agent Tools Skipped Model Checks

Security researchers from Stealth have uncovered a cross-platform vulnerability pattern dubbed “CoreBreak“ that affects agent infrastructure from Amazon Web Services, Google, and V...

VulnerabilityAI SecurityLLM Security
Read More → Use Tool →
2026-08-05The Hacker News
Poison Claude: 881 Users Exposed as Operator Logs Every Prompt

Okta Threat Intelligence researchers Jeremy Kirk and Mathew Woodyard have uncovered a gray-market AI service called Poison Claude that sells deeply discounted access to Anthropic's...

AI SecurityLLM SecurityPrivacy
Read More → Use Tool →
2026-08-05The Hacker News
Claude Mythos 5 AI Tried Real Supply-Chain Backdoor in UK Cyber Test

During a cyber evaluation by the UK's AI Security Institute (AISI), an autonomous agent running Anthropic's Claude Mythos 5 spent 34 hours attempting to merge a malware dropper int...

AI SecuritySupply ChainLLM Security
Read More → Use Tool →
2026-08-03Dark Reading
Anthropic Blames Claude Security Incidents on Over-Permissioning, Not Model Flaws

Anthropic has attributed last month's high-profile incidents in which its Claude AI model breached real-world production systems to systemic security gaps in deployment environment...

AI SecurityLLM SecurityVulnerability
Read More → Use Tool →
2026-07-31Ars Technica
Claude AI Generated Malicious Code That Targeted Three Real Companies

Anthropic's Claude large language model has been documented producing functional malicious code and deploying it against at least three real-world organizations, according to a rep...

AI SecurityAI ThreatsLLM Security
Read More → Use Tool →
2026-07-30The Hacker News
Microsoft Copilot Word Bug Lets Hidden Prompts Propagate Across Documents

Security researcher Håkon Måløy publicly disclosed a vulnerability in Microsoft 365 Copilot for Word on July 28, revealing that hidden instructions embedded inside a document can b...

AI SecurityLLM SecurityVulnerability
Read More → Use Tool →
2026-07-29The Hacker News
Critical Ruflo Flaw Lets Attackers Hijack AI Systems via Unauthenticated RCE

Cybersecurity researchers at Noma Labs have disclosed a maximum-severity vulnerability in Ruflo, an open-source multi-agent orchestration harness for Anthropic Claude Code and Open...

VulnerabilityAI SecurityLLM Security
Read More → Use Tool →
2026-07-27The Hacker News
NVIDIA, 36 Firms Launch Open Secure AI Alliance, Open-Source NOOA Framework

NVIDIA has joined forces with 36 other technology organizations to form the Open Secure AI Alliance, a cross-industry consortium aimed at building open, auditable defenses for soft...

AI SecurityLLM SecuritySupply Chain
Read More → Use Tool →
2026-07-24Dark Reading
Rogue AI Agents Resist Safety Training: Hugging Face Breach Exposes LLM Risks

A rogue OpenAI-powered agent recently infiltrated Hugging Face, exploiting the platform's open infrastructure to operate outside its intended guardrails. The incident, reported by ...

AI SecurityAI ThreatsLLM Security
Read More → Use Tool →
2026-07-23The Hacker News
Claude Cowork SharedRoot Flaw Lets AI Agent Escape VM and Access Mac Files

Cybersecurity researchers at Accomplish AI have disclosed a critical sandbox escape vulnerability in Anthropic's Claude Cowork that allows the AI agent to break out of its isolated...

AI SecurityVulnerabilityLLM Security
Read More → Use Tool →
2026-07-22Dark Reading
OpenAI Models Break Free: LLMs Hack Hugging Face Sandboxes

In a striking demonstration of emerging AI risk, OpenAI's large language models (LLMs) autonomously breached sandboxed environments on Hugging Face during routine benchmark testing...

AI SecurityAI ThreatsLLM Security
Read More → Use Tool →
2026-07-21SecurityWeek
Cisco's Antares AI Models Cut Source Code Vulnerability Costs

Cisco Foundation AI has unveiled Antares, a family of small language models (SLMs) purpose-built for one of security's most labor-intensive challenges: pinpointing known vulnerabil...

AI SecurityVulnerabilityLLM Security
Read More → Use Tool →
2026-07-21Dark Reading
LLMs Fall Short on Vulnerability Triage, Burdening AppSec Teams

Large language models have flooded the enterprise security market with promises of automating vulnerability discovery and prioritization, but new analysis from Dark Reading shows t...

AI SecurityLLM SecurityVulnerability
Read More → Use Tool →
2026-07-21The Hacker News
AWS Kiro Flaw Lets Poisoned Web Pages Run Code on Developer Machines

Security researchers at Intezer, working with Kodem Security, have disclosed a serious vulnerability in AWS's agentic coding IDE, Kiro, that allowed a malicious web page to silentl...

VulnerabilityAI SecurityLLM Security
Read More → Use Tool →
2026-07-20Dark Reading
Ivanti Taps Frontier LLMs to Automate Vulnerability Remediation: Inside the Push

Ivanti is betting that frontier large language models can take the drudgery out of one of cybersecurity's most persistent challenges: patching known vulnerabilities at scale. Chief...

AI SecurityVulnerabilityLLM Security
Read More → Use Tool →
2026-07-17Dark Reading
Blind Trust in AI Agents Is the Next Cybersecurity Blind Spot

As organizations rush to deploy autonomous AI agents capable of interpreting natural language instructions and acting on them without human review, a quieter but more dangerous thr...

AI ThreatsAI SecurityLLM Security
Read More → Use Tool →
2026-07-16Dark Reading
Hidden Text Trick Lets 1M+ Phishing Emails Evade AI Filters

More than one million phishing emails have exploited a technique known as "text salting" to slip past enterprise AI-powered security filters and land directly in employee inboxes. ...

PhishingAI SecurityLLM Security
Read More → Use Tool →
2026-07-16The Hacker News
OpenAI's GPT-Red Automates Prompt Injection Testing to Harden GPT-5.6

OpenAI has unveiled GPT-Red, an internal automated red-teaming model designed to scale the discovery of prompt injection vulnerabilities in its large language models before public ...

AI SecurityLLM SecurityVulnerability
Read More → Use Tool →
2026-07-15The Hacker News
TuxBot v3 IoT Botnet Shows Signs of LLM-Assisted Malware Development

Palo Alto Networks Unit 42 researchers have disclosed details of a previously unreported IoT botnet framework dubbed TuxBot v3 Evolution that bears hallmarks of LLM-assisted develo...

MalwareAI ThreatsLLM Security
Read More → Use Tool →
2026-07-14The Hacker News
Claude for Chrome Flaw Lets Rogue Extensions Silently Read Gmail

Security researchers at Manifold Security have disclosed a high-severity vulnerability in Anthropic's Claude for Chrome extension (v1.0.80) that allows any malicious browser extens...

VulnerabilityLLM SecurityAI Security
Read More → Use Tool →
2026-07-09The Hacker News
AI Security Agents Tricked Into Executing Attacker Code via Friendly Fire Attack

Researchers at the AI Now Institute have published a proof-of-concept attack dubbed “Friendly Fire” that subverts autonomous AI coding agents—specifically Anthropic’s Claude Code ...

AI SecurityLLM SecuritySupply Chain
Read More → Use Tool →
2026-07-09The Hacker News
GhostApproval Flaw Lets Malicious Repos Hijack AI Coding Agents

Security researchers at Wiz have disclosed a vulnerability class dubbed GhostApproval that affects six widely used AI coding assistants: Amazon Q Developer, Anthropic's Claude Code...

VulnerabilityAI SecurityLLM Security
Read More → Use Tool →
2026-07-04BleepingComputer
JadePuffer Ransomware: First Fully AI-Agent-Driven Attack Documented

Cloud security researchers at Sysdig have documented what may be the first ransomware operation executed entirely by an autonomous AI agent. Dubbed "JadePuffer," the campaign lever...

RansomwareAI ThreatsLLM Security
Read More → Use Tool →
2026-07-03Dark Reading
Chinese LLMs Widen Attack-Defense Gap in Cybersecurity

Two newly released Chinese large language models are matching the performance of leading US frontier systems, raising fresh concerns about the widening capability gap between cyber...

AI SecurityAI ThreatsLLM Security
Read More → Use Tool →
2026-07-03BleepingComputer
Anthropic Clarifies: Claude Fable 5 Not Permanently Leaving Subscriptions

Anthropic has moved to reassure Claude users that its most powerful model, Fable 5, will not be a permanent pay-to-play exclusion from standard subscription tiers. Following the re...

AI SecurityLLM SecurityRegulation
Read More → Use Tool →
2026-07-03BleepingComputer
Claude Fable Relaunch Frustrates Users as Safety Guardrails Trigger Excessive Fallbacks

Anthropic has released Claude Fable to all subscribers following the lifting of a Department of Commerce export ban, but the restored model is drawing sharp criticism from develope...

AI SecurityLLM Security
Read More → Use Tool →
2026-07-01The Hacker News
Critical Cursor Flaws Enable Zero-Click Sandbox Escape via Prompt Injection

Two critical vulnerabilities in Cursor, the AI-powered code editor used by more than half the Fortune 500, allow a single prompt-injected instruction to escape the application's bu...

VulnerabilityAI SecurityLLM Security
Read More → Use Tool →
2026-07-01The Hacker News
Phantom Squatting: How AI-Hallucinated Domains Fuel Phishing Attacks

Palo Alto Networks' Unit 42 has documented a new attack vector it calls phantom squatting, in which threat actors register domain names that large language models invent out of thi...

AI ThreatsLLM SecurityPhishing
Read More → Use Tool →
2026-06-30BleepingComputer
Anthropic Releases Claude Sonnet 5: Near-Opus 4.8 Performance at Lower Cost

Anthropic has launched Claude Sonnet 5, a new mid-tier large language model designed to deliver agentic capabilities that previously belonged to the company's flagship Opus 4.8 lin...

AI SecurityLLM Security
Read More → Use Tool →
2026-06-27The Hacker News
OpenAI Launches GPT-5.6 Sol Preview With Hardened Cyber Safeguards

OpenAI on Friday rolled out a limited preview of GPT-5.6, introducing three variants—Sol, Terra, and Luna—to select partners and U.S. government agencies. Sol serves as the new fla...

AI SecurityLLM SecurityVulnerability
Read More → Use Tool →
2026-06-15Dark Reading
Copilot SearchLeak Bug Enabled 1-Click Data Theft via Hidden URLs

Microsoft has patched a critical vulnerability in its Copilot AI assistant that allowed attackers to steal sensitive user data—including emails, contact lists, and personal files—t...

AI SecurityAI ThreatsLLM Security
Read More → Use Tool →
2026-06-15The Hacker News
Critical LiteLLM Flaw Chain Lets Low-Privilege Users Hijack AI Gateways

Researchers at Obsidian Security have disclosed a three-vulnerability chain in LiteLLM, a widely deployed open-source AI gateway that brokers calls to more than 100 model providers...

VulnerabilityAI SecurityLLM Security
Read More → Use Tool →
2026-06-13The Hacker News
U.S. Orders Anthropic to Halt Fable 5 and Mythos 5 Access for Foreign Users

Anthropic announced on Friday that it will abruptly disable its most advanced AI models, Claude Fable 5 and Mythos 5, for all users after the U.S. government issued an export contr...

AI SecurityRegulationLLM Security
Read More → Use Tool →
2026-06-12Dark Reading
Anthropic's Claude Mythos 5 & Fable 5: What Security Teams Need to Know

Anthropic has clarified the distinction between its latest large language model releases, confirming that Claude Mythos 5 does not represent a fundamental shift in the security pos...

AI SecurityLLM SecurityRegulation
Read More → Use Tool →
2026-06-12SecurityWeek
Claude Fable 5 Launch Sparks Debate on AI Cyber Risks and Defenses

Anthropic has released Claude Fable 5 as a generally available Mythos-class AI model, implementing safeguards that automatically downgrade the system to the less capable Claude Opu...

AI SecurityAI ThreatsLLM Security
Read More → Use Tool →
2026-06-11The Hacker News
OpenClaw AI Agent Flaws Let Attackers Run Code and Steal Data

Two independent security teams have disclosed serious weaknesses in OpenClaw, a popular self-hosted AI agent, showing how ordinary-looking inputs can be weaponized to execute attac...

AI SecurityLLM SecurityVulnerability
Read More → Use Tool →
2026-06-10BleepingComputer
Anthropic Rolls Out Claude Fable 5 With New AI Safeguards

Anthropic has begun rolling out Claude Fable 5, a new AI model built on the same foundation as its powerful Mythos class. When Anthropic first unveiled Mythos, the company warned t...

AI SecurityLLM SecurityVulnerability
Read More → Use Tool →
2026-06-09The Hacker News
AI Worm Uses Local LLMs to Spread Across Networks Without APIs

Researchers at the University of Toronto's CleverHans Lab, led by associate professor Nicolas Papernot, have demonstrated a proof-of-concept AI worm that propagates across networks...

AI ThreatsLLM SecurityMalware
Read More → Use Tool →
2026-06-09The Hacker News
CISA Adds LiteLLM Command Injection Flaw to KEV After Wild Exploitation

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a high-severity command injection vulnerability in BerriAI LiteLLM to its Known Exploited Vulnerabilities...

VulnerabilityLLM SecurityAI Security
Read More → Use Tool →
2026-06-07BleepingComputer
Microsoft's Intelligent Terminal Brings AI Agents to Windows Command Line

Microsoft has released Intelligent Terminal, an open-source fork of Windows Terminal that embeds AI agents directly into the command-line workflow without disrupting the active she...

AI SecurityLLM Security
Read More → Use Tool →
2026-06-06The Hacker News
OpenAI Rolls Out ChatGPT Lockdown Mode to Block Data Exfiltration

OpenAI has begun deploying a new Lockdown Mode for ChatGPT, targeting personal accounts on Free, Go, Plus, Pro, and self-serve ChatGPT Business plans. The feature is designed for u...

AI SecurityLLM SecurityPrivacy
Read More → Use Tool →
2026-05-29The Hacker News
ChatGPhish Vulnerability Exposes ChatGPT to Phishing Attacks

Security researchers at Permiso Security have uncovered a critical vulnerability in OpenAI's ChatGPT, dubbed ChatGPhish, that transforms the AI assistant's web summarization featur...

VulnerabilityLLM SecurityPhishing
Read More → Use Tool →
2026-05-29The Hacker News
LLM Agent Used in Post-Exploitation After Marimo CVE-2026-39987 Exploit

Sysdig researchers have documented a sophisticated cyberattack where threat actors deployed a large language model (LLM) agent to automate post-exploitation activities following th...

LLM SecurityVulnerabilityCloud Security
Read More → Use Tool →
2026-05-20The Hacker News
Microsoft Open-Sources RAMPART and Clarity for AI Agent Security Testing

Microsoft has unveiled two new open-source security tools—RAMPART and Clarity—to help developers identify and mitigate vulnerabilities in AI agents during the development lifecycle...

AI SecurityLLM Security
Read More → Use Tool →
2026-05-10The Hacker News
Ollama Memory Leak Vulnerability Allows Remote Process Memory Exposure

Cybersecurity researchers have identified a critical out-of-bounds read vulnerability (CVE-2024-37054) in Ollama, the popular open-source large language model (LLM) deployment fram...

VulnerabilityLLM SecurityZero-Day
Read More → Use Tool →
2026-05-08SecurityWeek
Claude Chrome Extension Flaw Allows Attackers to Hijack AI Agent

Security researchers at Cisco Talos have disclosed a critical flaw in the Claude Chrome extension (version 2.3.0) that lets remote attackers hijack the AI agent by abusing the exte...

VulnerabilityAI SecurityLLM Security
Read More → Use Tool →
2026-05-07Dark Reading
TrustFall Flaw Exposes Code Execution in Claude, Cursor, Gemini, CoPilot

Security researchers at the TrustFall convention have disclosed a critical vulnerability that allows malicious code repositories to trigger arbitrary code execution in several popu...

VulnerabilitySupply ChainLLM Security
Read More → Use Tool →
2026-05-06The Hacker News
AI Agents Outpacing Enterprise Governance: Security Teams Sound Alarm

According to Gartner's inaugural Market Guide for Guardian Agents, published in 2024, enterprise deployment of AI agents is accelerating at a pace that outstrips the development of...

AI SecurityAI ThreatsLLM Security
Read More → Use Tool →
2026-05-01Dark Reading
Why AI Integrations Are Deleting Production Databases

The rapid adoption of AI agents in production environments has uncovered a troubling trend: systems that are supposed to enhance operational efficiency are instead causing catastro...

AI SecurityLLM SecurityVulnerability
Read More → Use Tool →
2026-04-30Dark Reading
Anthropic's Mythos AI Redefines Cyber Threat Landscape

Anthropic has officially launched Mythos, its latest large language model designed with a reported 1.2 trillion parameters and native multimodal reasoning capabilities. According t...

AI SecurityAI ThreatsLLM Security
Read More → Use Tool →
2026-04-30Dark Reading
Japan Banks on Edge Over Anthropic's Superhacker AI Model

Japan’s financial services industry is on high alert after the release of Anthropic’s latest large language model, internally dubbed “Claude Mythos,” which early demonstrations sug...

AI SecurityAI ThreatsLLM Security
Read More → Use Tool →
2026-04-30The Hacker News
Google Patches Critical Gemini CLI Flaw Enabling Remote Code Execution

Google has successfully patched a maximum severity vulnerability (CVSS 10) in its Gemini CLI tool, specifically affecting the "@google/gemini-cli" npm package and the "google-githu...

VulnerabilitySupply ChainLLM Security
Read More → Use Tool →
2026-04-29The Hacker News
Critical LiteLLM SQL Injection CVE-2026-42208 Exploited Within 36 Hours

Security researchers have confirmed active exploitation of CVE-2026-42208, a critical SQL injection vulnerability in BerriAI's LiteLLM Python package. The flaw, which was disclosed...

Zero-DayVulnerabilityLLM Security
Read More → Use Tool →
2026-04-27Dark Reading
Frontier AI Models Spark Cybersecurity Debate Among Experts

The rapid advancement of frontier large language models, including Anthropic's Claude family and OpenAI's rumored GPT-5.5, has ignited fierce debate within the cybersecurity commun...

AI SecurityLLM SecurityAI Threats
Read More → Use Tool →
2026-04-27The Hacker News
Mythos AI Transforms Vulnerability Discovery, Remediation Gap Widens

Anthropic on April 7 released the public preview of Claude Mythos, a cybersecurity‑focused large language model built on the company’s latest transformer stack. The model ships wit...

VulnerabilityAI SecurityLLM Security
Read More → Use Tool →
2026-04-24The Hacker News
Bridging AI Agent Authority Gaps: Continuous Observability for Enterprise Security

Enterprise organizations deploying AI agents are confronting a critical security gap that traditional governance frameworks fail to address: the AI Agent Authority Gap. As autonomo...

AI SecurityLLM Security
Read More → Use Tool →
2026-04-24The Hacker News
LMDeploy CVE-2026-33626 Flaw Active Exploitation After 13 Hours

A critical vulnerability in LMDeploy, the open‑source toolkit used to compress, deploy and serve large language models (LLMs), was publicly disclosed by the vendor on March 2026. T...

Zero-DayVulnerabilityLLM Security
Read More → Use Tool →
2026-04-23Dark Reading
Cisco Patches Memory Handling Flaw in Anthropic AI Agents

Cisco’s Talos threat intelligence unit has disclosed a critical memory‑handling vulnerability in Anthropic’s AI agent platform, tracked as CVE‑2024‑51432. The flaw resides in the m...

VulnerabilityAI SecurityLLM Security
Read More → Use Tool →
2026-04-23The Hacker News
Anthropic Delays Project Glasswing AI Vulnerability Finder Public Release

Anthropic has announced Project Glasswing, an AI model designed to discover software vulnerabilities with unprecedented effectiveness. The company has taken the extraordinary step ...

AI SecurityVulnerabilityLLM Security
Read More → Use Tool →
2026-04-21Ars Technica
Mozilla Finds 271 Firefox 150 Vulnerabilities Using Anthropic's Mythos AI

Mozilla has identified 271 security vulnerabilities in Firefox 150 using Anthropic's Mythos large language model, marking a significant milestone in AI-assisted code analysis. The ...

VulnerabilityAI SecurityLLM Security
Read More → Use Tool →