HackMyIP

网络安全资讯

来自顶级安全媒体的最新动态

2026-06-27BleepingComputer
Clean GitHub Repos Trick AI Coding Agents Into Running Malware

Researchers at Mozilla's Zero Day Investigative Network (0DIN) have disclosed a novel attack technique that exploits agentic AI coding tools, demonstrating how a seemingly benign G...

AI SecuritySupply ChainMalware
Read More → Use Tool →
2026-06-27The Hacker News
OpenAI Launches GPT-5.6 Sol Preview With Hardened Cyber Safeguards

OpenAI on Friday rolled out a limited preview of GPT-5.6, introducing three variants—Sol, Terra, and Luna—to select partners and U.S. government agencies. Sol serves as the new fla...

AI SecurityLLM SecurityVulnerability
Read More → Use Tool →
2026-06-25BleepingComputer
Anthropic Tests Mobile Claude Cowork: AI Agent Goes Remote-Control

Anthropic is preparing to bring its agentic Claude Cowork experience to mobile devices, according to screenshots shared on X. Claude Cowork, the desktop-focused agentic mode introd...

AI SecurityPrivacy
Read More → Use Tool →
2026-06-25The Hacker News
Why NDR Beats Alerts in the Mythos Era: Bejtlich's Case for Network Interdiction

Despite the growing abundance of security telemetry, most SOC teams still struggle with fundamental questions during incident investigation: What actually happened? What evidence s...

Threat IntelIncident ResponseAI Security
Read More → Use Tool →
2026-06-25The Hacker News
Gaslight macOS Malware Uses Prompt Injection to Trick AI Analysts

Security researchers at SentinelOne have uncovered a previously undocumented Rust-based macOS implant dubbed Gaslight, attributed with high confidence to North Korea-aligned threat...

MalwareAPTAI Security
Read More → Use Tool →
2026-06-24SecurityWeek
Anthropic Mythos AI Uncovers Flaws in Classified US Government Systems

A senior U.S. official confirmed to The Associated Press that Anthropic's Mythos artificial intelligence model identified vulnerabilities in highly sensitive and classified governm...

AI SecurityAI ThreatsVulnerability
Read More → Use Tool →
2026-06-23The Hacker News
Fake AI Agent Skill Bypasses Scanners, Hits 26,000 Agents

Security researchers at AIR have demonstrated a stark gap in AI agent supply chain defenses by publishing a malicious-looking skill that sailed past every scanner it was tested aga...

AI SecuritySupply ChainAI Threats
Read More → Use Tool →
2026-06-23The Hacker News
OpenAI's GPT-5.5-Cyber Aims to Clear the Vulnerability Patching Bottleneck

OpenAI announced on Monday the release of GPT-5.5-Cyber, an upgraded version of its cybersecurity-focused large language model, made available to trusted defenders through the Dayb...

AI SecurityVulnerabilitySupply Chain
Read More → Use Tool →
2026-06-22The Hacker News
DifyTap: Critical Flaws in Dify Expose AI Chats Across Tenants

Cybersecurity researchers at Zafran Security have disclosed four vulnerabilities in Dify, the open-source agentic workflow platform boasting more than 146,000 GitHub stars, that co...

VulnerabilityAI SecurityCloud Security
Read More → Use Tool →
2026-06-19The Hacker News
AutoJack Flaw Lets Malicious Web Pages Hijack AI Agents for Code Execution

Microsoft researchers have disclosed AutoJack, an exploit chain that weaponizes an AI browsing agent into a remote code execution vector. By luring a local agent to render an attac...

AI SecurityVulnerabilitySupply Chain
Read More → Use Tool →
2026-06-19The Hacker News
From Assistive to Agentic: How AI Is Redefining Enterprise Threat Management

The average enterprise security team juggles 40 or more security tools, generating massive amounts of internal telemetry and asset data. Yet these tools operate in silos, producing...

AI SecurityThreat IntelIncident Response
Read More → Use Tool →
2026-06-19The Hacker News
Shadow AI: Why Access Control, Not Data Leakage, Is the Real Enterprise Threat

The enterprise AI risk landscape has fundamentally shifted. Security teams initially focused on employees pasting sensitive data into public AI tools, responding with usage policie...

AI SecurityAI ThreatsCloud Security
Read More → Use Tool →
2026-06-18The Hacker News
Orphaned AI Agents: Hidden Access Risks in Enterprise Networks

When an autonomous AI agent interacts with a company's core intellectual property, most security teams cannot instantly name the person who authorized it. The rush to deploy intern...

AI SecurityAuthenticationCloud Security
Read More → Use Tool →
2026-06-18BleepingComputer
OpenAI Tests ChatGPT for Science Subscription for Research Use

OpenAI is reportedly developing a new subscription tier called "ChatGPT for Science," according to references discovered on the web build by users on X. The new offering appears ai...

AI SecurityRegulation
Read More → Use Tool →
2026-06-17The Hacker News
15 Malicious JetBrains Plugins Caught Stealing AI API Keys from Developers

Cybersecurity researchers at Aikido Security have uncovered a coordinated malware campaign on the JetBrains Marketplace involving at least 15 malicious plugins designed to steal ar...

Supply ChainAI SecurityMalware
Read More → Use Tool →
2026-06-17The Hacker News
Mastra npm Supply Chain Attack Hits 144 Packages via Hijacked Account

A single compromised npm contributor account ("ehindero") was used to mass-publish more than 144 malicious packages across the @mastra/* scope on June 17, 2026, in an 88-minute aut...

Supply ChainMalwareAI Security
Read More → Use Tool →
2026-06-16The Hacker News
Google Vertex AI SDK Bug Let Attackers Hijack AI Model Uploads

A critical vulnerability in Google Cloud's Vertex AI SDK for Python allowed attackers to hijack machine learning model uploads and execute arbitrary code inside Google's serving in...

Cloud SecurityVulnerabilityAI Security
Read More → Use Tool →
2026-06-16BleepingComputer
Malicious JetBrains Plugins Steal AI API Keys in Supply Chain Attack

At least 15 malicious plugins discovered on the JetBrains Marketplace have been stealing AI API keys from developers in a coordinated supply chain campaign that has accumulated clo...

Supply ChainMalwareAI Security
Read More → Use Tool →
2026-06-15Dark Reading
Copilot SearchLeak Bug Enabled 1-Click Data Theft via Hidden URLs

Microsoft has patched a critical vulnerability in its Copilot AI assistant that allowed attackers to steal sensitive user data—including emails, contact lists, and personal files—t...

AI SecurityAI ThreatsLLM Security
Read More → Use Tool →
2026-06-15The Hacker News
Critical LiteLLM Flaw Chain Lets Low-Privilege Users Hijack AI Gateways

Researchers at Obsidian Security have disclosed a three-vulnerability chain in LiteLLM, a widely deployed open-source AI gateway that brokers calls to more than 100 model providers...

VulnerabilityAI SecurityLLM Security
Read More → Use Tool →
2026-06-15The Hacker News
SearchLeak: One-Click Microsoft 365 Copilot Flaw Exposed Emails

Researchers at Varonis Threat Labs have disclosed a critical chain of three vulnerabilities in Microsoft 365 Copilot's Enterprise Search feature that, if exploited, would have allo...

VulnerabilityAI SecurityPhishing
Read More → Use Tool →
2026-06-13The Hacker News
U.S. Orders Anthropic to Halt Fable 5 and Mythos 5 Access for Foreign Users

Anthropic announced on Friday that it will abruptly disable its most advanced AI models, Claude Fable 5 and Mythos 5, for all users after the U.S. government issued an export contr...

AI SecurityRegulationLLM Security
Read More → Use Tool →
2026-06-13BleepingComputer
Anthropic Suspends Fable 5 and Mythos 5 Globally After US Export Control Order

Anthropic has pulled the plug on its two most powerful AI models, Fable 5 and Mythos 5, for every user worldwide after receiving a US government export control directive on June 12...

AI SecurityRegulationPrivacy
Read More → Use Tool →
2026-06-13SecurityWeek
Anthropic Takes Fable 5 and Mythos 5 Offline Over US Export Controls

Anthropic announced Friday that it has taken its latest artificial intelligence models, Fable 5 and Mythos 5, offline to comply with a directive from the Trump administration aimed...

AI SecurityRegulationAI Threats
Read More → Use Tool →
2026-06-12The Hacker News
Agentjacking Attack Exploits Sentry MCP to Hijack AI Coding Agents

Cybersecurity researchers at Tenet Security have uncovered a new attack class dubbed “Agentjacking” that tricks AI coding agents into executing arbitrary code on developer machines...

AI SecurityAI ThreatsVulnerability
Read More → Use Tool →
2026-06-12Dark Reading
Anthropic's Claude Mythos 5 & Fable 5: What Security Teams Need to Know

Anthropic has clarified the distinction between its latest large language model releases, confirming that Claude Mythos 5 does not represent a fundamental shift in the security pos...

AI SecurityLLM SecurityRegulation
Read More → Use Tool →
2026-06-12SecurityWeek
Google Cybersecurity Layoffs, $400M Coupang Fine & LiteLLM Patch

This week in cybersecurity saw a wave of high-impact developments spanning government accountability, corporate breaches, and AI security. A former IBM cybersecurity executive has ...

Data BreachRegulationAI Security
Read More → Use Tool →
2026-06-12SecurityWeek
Claude Fable 5 Launch Sparks Debate on AI Cyber Risks and Defenses

Anthropic has released Claude Fable 5 as a generally available Mythos-class AI model, implementing safeguards that automatically downgrade the system to the less capable Claude Opu...

AI SecurityAI ThreatsLLM Security
Read More → Use Tool →
2026-06-12The Hacker News
LangGraph Flaw Chain Enables Remote Code Execution in Self-Hosted AI Agents

Cybersecurity researchers at Check Point have disclosed three now-patched vulnerabilities in LangGraph, the open-source framework from LangChain used to build stateful, multi-agent...

AI SecurityVulnerabilityAI Threats
Read More → Use Tool →
2026-06-11The Hacker News
OpenClaw AI Agent Flaws Let Attackers Run Code and Steal Data

Two independent security teams have disclosed serious weaknesses in OpenClaw, a popular self-hosted AI agent, showing how ordinary-looking inputs can be weaponized to execute attac...

AI SecurityLLM SecurityVulnerability
Read More → Use Tool →
2026-06-11The Hacker News
2026 Cybersecurity Stars Awards: 95 Categories Honor Top Security Innovators

The 2026 Cybersecurity Stars Awards have officially announced winners across 95 subcategories spanning four main award pillars, spotlighting the often-unseen work that keeps organi...

AI SecuritySupply Chain
Read More → Use Tool →
2026-06-10BleepingComputer
Hackers Actively Exploit Path Traversal Flaw in AI Platform Langflow

Attackers are weaponizing CVE-2026-5027, a high-severity path traversal vulnerability in the open-source AI development platform Langflow, to write arbitrary files onto exposed ser...

VulnerabilityAI SecurityZero-Day
Read More → Use Tool →
2026-06-10The Hacker News
Langflow CVE-2026-5027 Exploited: Unauthenticated RCE via Path Traversal

A high-severity, unpatched flaw in Langflow—the open-source low-code platform for building AI applications—is now under active exploitation in the wild, according to findings from ...

VulnerabilityAI SecurityZero-Day
Read More → Use Tool →
2026-06-10BleepingComputer
Anthropic Rolls Out Claude Fable 5 With New AI Safeguards

Anthropic has begun rolling out Claude Fable 5, a new AI model built on the same foundation as its powerful Mythos class. When Anthropic first unveiled Mythos, the company warned t...

AI SecurityLLM SecurityVulnerability
Read More → Use Tool →
2026-06-09The Hacker News
Meta Expands Off-Site Data Use to Feeds and AI Personalization

Meta announced on Tuesday that it will broaden its use of cross-site business data to personalize user experiences across Facebook and Instagram feeds, as well as responses generat...

PrivacyAI Security
Read More → Use Tool →
2026-06-09The Hacker News
The Hidden Security Risk: Work Between Tools Slows Response

Despite record investment in SIEM platforms, firewalls, IAM systems, and AI-driven detection, enterprise network security teams are still struggling with the same fundamental probl...

Incident ResponseAI SecurityThreat Intel
Read More → Use Tool →
2026-06-09The Hacker News
CISA Adds LiteLLM Command Injection Flaw to KEV After Wild Exploitation

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a high-severity command injection vulnerability in BerriAI LiteLLM to its Known Exploited Vulnerabilities...

VulnerabilityLLM SecurityAI Security
Read More → Use Tool →
2026-06-07BleepingComputer
Microsoft's Intelligent Terminal Brings AI Agents to Windows Command Line

Microsoft has released Intelligent Terminal, an open-source fork of Windows Terminal that embeds AI agents directly into the command-line workflow without disrupting the active she...

AI SecurityLLM Security
Read More → Use Tool →
2026-06-07SecurityWeek
Emphere Raises $2.1M to Fix Open-Source Vulnerabilities With AI

Seattle-based cybersecurity startup Emphere has secured $2.1 million in pre-seed funding from AI2 Incubator and Outsiders Fund to advance its AI-driven vulnerability remediation pl...

AI SecurityVulnerabilitySupply Chain
Read More → Use Tool →
2026-06-06The Hacker News
OpenAI Rolls Out ChatGPT Lockdown Mode to Block Data Exfiltration

OpenAI has begun deploying a new Lockdown Mode for ChatGPT, targeting personal accounts on Free, Go, Plus, Pro, and self-serve ChatGPT Business plans. The feature is designed for u...

AI SecurityLLM SecurityPrivacy
Read More → Use Tool →
2026-06-06The Hacker News
AI Agent Finds 21 FFmpeg Zero-Days as Chrome 149 Patches Record 429 Bugs

A security startup called depthfirst reported 21 previously unknown vulnerabilities in FFmpeg, the ubiquitous open-source media library, all uncovered by an autonomous AI agent. Th...

Zero-DayVulnerabilityAI Security
Read More → Use Tool →
2026-06-04BleepingComputer
Brave Origin: Paid Minimalist Browser Strips Out Crypto, AI Features

Brave Software has publicly launched Brave Origin, a $59.99 paid version of its privacy-focused browser that removes cryptocurrency wallets, AI integrations, rewards programs, and ...

PrivacyAI Security
Read More → Use Tool →
2026-06-04The Record
CISA to Issue Binding AI Directive This Week, Acting Director Says

The Cybersecurity and Infrastructure Security Agency (CISA) will release a binding operational directive (BOD) to federal agencies by the end of the week, directing them on how to ...

AI SecurityRegulationVulnerability
Read More → Use Tool →
2026-06-03The Hacker News
Poisoned Notifications Could Hijack Google Gemini on Android

A single malicious notification pushed through WhatsApp, Slack, SMS, Signal, Instagram, or Messenger was enough to hijack Google Gemini's voice assistant on Android, according to r...

AI SecurityAI ThreatsVulnerability
Read More → Use Tool →
2026-06-03The Hacker News
Autonomous AI Uncovers 2-Year-Old Redis RCE Flaw (CVE-2026-23479)

Redis has patched a use-after-free vulnerability in its blocking-client code that allows an authenticated user to execute arbitrary OS commands on the host running the database. Tr...

VulnerabilityCloud SecurityAI Security
Read More → Use Tool →
2026-06-03The Hacker News
IVIP: Closing the Identity Dark Matter Gap in Enterprise IAM

Enterprise identity and access management is approaching a structural breaking point. As organizations scale, identity data fragments across thousands of applications, decentralize...

AuthenticationAI SecurityCloud Security
Read More → Use Tool →
2026-06-02The Hacker News
AI-Driven Exploitation Is Breaking Vulnerability Management in 2026

The window between vulnerability disclosure and indiscriminate exploitation has collapsed from days to hours, driven by AI-powered tooling that automates discovery, reproduction, a...

AI SecurityAI ThreatsVulnerability
Read More → Use Tool →
2026-06-01The Hacker News
MSPs Move Beyond vCISO to Security Growth Platforms in 2026

The managed service provider (MSP) cybersecurity landscape is undergoing a significant transformation as traditional vCISO platforms fail to meet the demands of modern security pra...

Cloud SecurityAI SecurityRegulation
Read More → Use Tool →
2026-05-29The Hacker News
Shadow Builders: 2,000+ Vibe-Coded Apps Expose Corporate Data

Security researchers at Red Access have uncovered a alarming trend in enterprise data exposure through what they term the 'Shadow Builders' phenomenon. In a comprehensive investiga...

AI SecurityData BreachVulnerability
Read More → Use Tool →
2026-05-25The Hacker News
Agentic AI Transforms Network Detection & Response

Network Detection and Response (NDR) has long carried a reputation for being noisy and overwhelming security operations center (SOC) teams with alert fatigue. However, the emergenc...

AI SecurityThreat IntelIncident Response
Read More → Use Tool →
2026-05-23The Hacker News
Anthropic's Claude Mythos Finds 10,000 High-Severity Flaws in Software

Anthropic's Project Glasswing initiative has uncovered more than 10,000 high- or critical-severity vulnerabilities across systemically important software globally since its launch ...

VulnerabilityAI SecurityZero-Day
Read More → Use Tool →
2026-05-21The Hacker News
Identity is the Attack Path: Cloud Security Risks in 2025

A threat actor recently obtained an AWS access key cached on a developer's workstation through standard browser behavior—no misconfiguration or policy violation required. This sing...

Cloud SecurityAuthenticationAI Security
Read More → Use Tool →
2026-05-21Dark Reading
Enterprises Boost AI Agent Identity Security Budgets as Omdia Reveals Shifting Priorities

Organizations are dramatically increasing investments in AI agent identity management as enterprise deployments accelerate, according to new research from Omdia. The study reveals ...

AI SecurityAuthenticationCloud Security
Read More → Use Tool →
2026-05-20The Hacker News
Microsoft Open-Sources RAMPART and Clarity for AI Agent Security Testing

Microsoft has unveiled two new open-source security tools—RAMPART and Clarity—to help developers identify and mitigate vulnerabilities in AI agents during the development lifecycle...

AI SecurityLLM Security
Read More → Use Tool →
2026-05-19BleepingComputer
ChromaDB Max-Severity Flaw CVE-2026-45829 Allows Server Hijacking

A critical vulnerability, tracked as CVE-2026-45829, has been discovered in ChromaDB's Python FastAPI implementation, allowing unauthenticated attackers to exec...

VulnerabilityZero-DayAI Security
Read More → Use Tool →
2026-05-18Dark Reading
AI Agents Expose New Vulnerability Risks in Generated Code

Security researchers are warning that a new generation of AI agents capable of autonomously discovering and exploiting obscure vulnerabilities is fundamentally altering the threat ...

AI SecurityVulnerabilitySupply Chain
Read More → Use Tool →
2026-05-15The Hacker News
OpenAI Supply Chain Attack Hits TanStack Malware, Forces macOS App Updates

OpenAI has disclosed that two employee devices were compromised via the Mini Shai-Hulud supply chain attack targeting TanStack, an open-source software library ecosystem. The breac...

Supply ChainIncident ResponseAI Security
Read More → Use Tool →
2026-05-11The Hacker News
Fake OpenAI Privacy Filter Hits Hugging Face, Steals Data from 244K Users

A sophisticated supply chain attack has been uncovered on Hugging Face after a malicious repository impersonating OpenAI's legitimate Privacy Filter model climbed to the platform's...

Supply ChainMalwareAI Security
Read More → Use Tool →
2026-05-09BleepingComputer
Fake OpenAI Repo on Hugging Face Spreads Info-Stealer to Windows

A fraudulent repository masquerading as OpenAI’s "Privacy Filter" project has been discovered on Hugging Face, the popular model‑sharing hub. The repo, which briefly made the platf...

MalwareSupply ChainAI Security
Read More → Use Tool →
2026-05-08SecurityWeek
Braintrust Data Breach: AWS API Keys Leaked, Prompting Rotation

Braintrust, an AI infrastructure provider, disclosed on March 5 2026 that an unauthorized party had gained access to one of its Amazon Web Services (AWS) accounts. The intrusion, d...

Data BreachCloud SecurityAI Security
Read More → Use Tool →
2026-05-08SecurityWeek
Claude Chrome Extension Flaw Allows Attackers to Hijack AI Agent

Security researchers at Cisco Talos have disclosed a critical flaw in the Claude Chrome extension (version 2.3.0) that lets remote attackers hijack the AI agent by abusing the exte...

VulnerabilityAI SecurityLLM Security
Read More → Use Tool →
2026-05-08BleepingComputer
Why More Analysts Won’t Solve Your SOC Alert Problem

Modern threat actors launch campaigns that generate thousands of alerts per hour, leaving security operations centers (SOCs) drowning in data. Even with a larger team of analysts, ...

AI SecurityIncident ResponseThreat Intel
Read More → Use Tool →
2026-05-07SecurityWeek
Musk Sues OpenAI Over AI Humanity Risks, Calls for AI Regulation

Musk's legal team filed a complaint in the Delaware Court of Chancery on 12 March, alleging that OpenAI's board has abandoned its original mission to develop artificial general int...

AI SecurityRegulationAI Threats
Read More → Use Tool →
2026-05-07BleepingComputer
How Browsers Bypass DLP: AI Prompts and Copy/Paste Create Data Leakage

Organizations investing heavily in data loss prevention (DLP) solutions are discovering a critical blind spot: the browser has become the primary vector for inadvertent data exfilt...

Data BreachAI SecurityPrivacy
Read More → Use Tool →
2026-05-07BleepingComputer
Fake Claude AI Site Spreads Beagle Backdoor Malware on Windows

Security researchers have uncovered a phishing campaign that spoofs the official Anthropic Claude AI portal to distribute a new Windows backdoor dubbed “Beagle.” The fraudulent sit...

MalwarePhishingAI Security
Read More → Use Tool →
2026-05-06The Hacker News
AI Agents Outpacing Enterprise Governance: Security Teams Sound Alarm

According to Gartner's inaugural Market Guide for Guardian Agents, published in 2024, enterprise deployment of AI agents is accelerating at a pace that outstrips the development of...

AI SecurityAI ThreatsLLM Security
Read More → Use Tool →
2026-05-06Dark Reading
From Stuxnet to ChatGPT: 20 Cyber Milestones

Over the past two decades, a succession of high‑impact incidents has reshaped the cyber risk landscape, forcing organizations to constantly recalibrate their defenses. From the rev...

MalwareAI SecurityZero-Day
Read More → Use Tool →
2026-05-05The Hacker News
OAuth Token Exposure in AI Tools: Unclosed Backdoors Threaten Cloud Security

In the past twelve months, enterprises have rushed to embed AI‑powered writing assistants, workflow automations and productivity plugins into their Google Workspace and Microsoft 3...

VulnerabilityCloud SecurityAI Security
Read More → Use Tool →
2026-05-05The Hacker News
1M Exposed AI Services Reveal Alarming Security Gaps

A joint research effort by the Security Research Lab (SRL) and the AI Security Initiative (AISI) scanned over one million publicly reachable AI endpoints across IPv4 space between ...

AI SecurityVulnerabilityPrivacy
Read More → Use Tool →
2026-05-01Dark Reading
Why AI Integrations Are Deleting Production Databases

The rapid adoption of AI agents in production environments has uncovered a troubling trend: systems that are supposed to enhance operational efficiency are instead causing catastro...

AI SecurityLLM SecurityVulnerability
Read More → Use Tool →
2026-04-30Dark Reading
AI-Powered Scan Uncovers 9-Year-Old Linux Kernel Bug, Patch Ready

Security researchers using an AI-driven static analysis engine called Sentinel have uncovered a nine‑year‑old flaw in the Linux kernel’s netfilter subsystem. The vulnerability, tra...

VulnerabilityAI Security
Read More → Use Tool →
2026-04-30Dark Reading
Anthropic's Mythos AI Redefines Cyber Threat Landscape

Anthropic has officially launched Mythos, its latest large language model designed with a reported 1.2 trillion parameters and native multimodal reasoning capabilities. According t...

AI SecurityAI ThreatsLLM Security
Read More → Use Tool →
2026-04-30Dark Reading
Japan Banks on Edge Over Anthropic's Superhacker AI Model

Japan’s financial services industry is on high alert after the release of Anthropic’s latest large language model, internally dubbed “Claude Mythos,” which early demonstrations sug...

AI SecurityAI ThreatsLLM Security
Read More → Use Tool →
2026-04-30BleepingComputer
Bluekit Phishing Kit Offers AI Assistant, 40+ Templates

Security researchers have uncovered a new phishing-as-a-service platform called Bluekit that advertises more than 40 ready‑made templates targeting popular online services such as ...

PhishingAI ThreatsAI Security
Read More → Use Tool →
2026-04-29Dark Reading
AI Reverse Engineering Exposes Critical GitHub Vulnerability

Security researchers at Wiz have leveraged an AI‑powered reverse‑engineering engine to uncover a high‑severity flaw in GitHub’s continuous integration infrastructure that would hav...

AI SecurityVulnerabilityZero-Day
Read More → Use Tool →
2026-04-29Dark Reading
AI Finds 38 Security Flaws in OpenEMR, Threatening 100K Providers

Security researchers using an AI‑driven code analysis platform identified 38 distinct vulnerabilities in the OpenEMR electronic health record (EHR) system, including 12 rated criti...

VulnerabilityAI SecurityData Breach
Read More → Use Tool →
2026-04-29The Hacker News
AI-Powered Kill Chain Automation Shifts Threat Landscape in 2026

In February 2026, a joint research team from SentinelLabs and the University of Calgary published a report revealing a paradigm shift in cyber‑attack tradecraft. The analysts, led ...

AI ThreatsAI SecurityThreat Intel
Read More → Use Tool →
2026-04-28The Hacker News
Critical Unpatched Flaw in Hugging Face LeRobot Enables Unauthenticated RCE

Cybersecurity researchers from Eclypsium have disclosed a critical, unpatched vulnerability in Hugging Face’s open‑source robotics framework LeRobot, which boasts nearly 24,000 Git...

VulnerabilityZero-DayAI Security
Read More → Use Tool →
2026-04-28The Hacker News
New Zero-Window Playbooks: How NDR Fills the Gap in AI Threat Defense

In the past, security teams could count on a brief, predictable window between the disclosure of a vulnerability and the release of a patch. That buffer has all but vanished as AI-...

Zero-DayAI SecurityIncident Response
Read More → Use Tool →
2026-04-27Dark Reading
Frontier AI Models Spark Cybersecurity Debate Among Experts

The rapid advancement of frontier large language models, including Anthropic's Claude family and OpenAI's rumored GPT-5.5, has ignited fierce debate within the cybersecurity commun...

AI SecurityLLM SecurityAI Threats
Read More → Use Tool →
2026-04-27The Hacker News
Weekly Recap: Fast16 Malware, XChat Launch, Federal Backdoor, AI Tracking

Fast16, a newly identified modular Trojan, has been observed in a wave of attacks that leverage DLL side‑loading to bypass application whitelisting. Discovered by Cisco Talos on 20...

MalwareAI SecuritySupply Chain
Read More → Use Tool →
2026-04-27The Hacker News
Mythos AI Transforms Vulnerability Discovery, Remediation Gap Widens

Anthropic on April 7 released the public preview of Claude Mythos, a cybersecurity‑focused large language model built on the company’s latest transformer stack. The model ships wit...

VulnerabilityAI SecurityLLM Security
Read More → Use Tool →
2026-04-24Dark Reading
Glasswing Secures Code, But Your Stack Still Exposed

Glasswing’s recent announcement that it has secured the core code of its platform is a welcome step toward reducing software vulnerabilities, but security experts warn that the bro...

Supply ChainAI SecurityCloud Security
Read More → Use Tool →
2026-04-24The Hacker News
Bridging AI Agent Authority Gaps: Continuous Observability for Enterprise Security

Enterprise organizations deploying AI agents are confronting a critical security gap that traditional governance frameworks fail to address: the AI Agent Authority Gap. As autonomo...

AI SecurityLLM Security
Read More → Use Tool →
2026-04-23Dark Reading
Cisco Patches Memory Handling Flaw in Anthropic AI Agents

Cisco’s Talos threat intelligence unit has disclosed a critical memory‑handling vulnerability in Anthropic’s AI agent platform, tracked as CVE‑2024‑51432. The flaw resides in the m...

VulnerabilityAI SecurityLLM Security
Read More → Use Tool →
2026-04-23The Hacker News
Anthropic Delays Project Glasswing AI Vulnerability Finder Public Release

Anthropic has announced Project Glasswing, an AI model designed to discover software vulnerabilities with unprecedented effectiveness. The company has taken the extraordinary step ...

AI SecurityVulnerabilityLLM Security
Read More → Use Tool →
2026-04-21Ars Technica
Mozilla Finds 271 Firefox 150 Vulnerabilities Using Anthropic's Mythos AI

Mozilla has identified 271 security vulnerabilities in Firefox 150 using Anthropic's Mythos large language model, marking a significant milestone in AI-assisted code analysis. The ...

VulnerabilityAI SecurityLLM Security
Read More → Use Tool →
2026-04-21Dark Reading
Google Patches Critical RCE Flaw in Antigravity AI Tool

Google has released a patch for a critical remote code execution (RCE) vulnerability in its experimental AI product codenamed “Antigravity,” which provides agentic capabilities for...

VulnerabilityAI SecurityZero-Day
Read More → Use Tool →
2026-04-20Dark Reading
Vercel Employee AI Tool Access Triggered Data Breach via OAuth Tokens

On March 5, 2026, Vercel's security operations center (SOC) detected anomalous activity stemming from an OAuth token tied to a senior developer's account. The token, scoped to the ...

Data BreachAI SecuritySupply Chain
Read More → Use Tool →
2026-04-17Dark Reading
How AI Is Amplifying Legacy Software Vulnerabilities Today

A new analysis published by Dark Reading warns that the most pressing security risk posed by artificial intelligence is not the emergence of novel code flaws, but the rapid amplifi...

VulnerabilityAI SecurityAI Threats
Read More → Use Tool →
2026-04-14Ars Technica
UK Government Mythos AI Tests Cut Cybersecurity Hype, Identify Real Threats

The UK Cabinet Office’s Emerging Technology Cybersecurity Division (ETCD), in close collaboration with the National Cyber Security Centre (NCSC), has publicly released results from...

AI SecurityThreat Intel
Read More → Use Tool →
2026-03-17Ars Technica
World ID Iris Tokens to Secure AI Agents, Prevent Swarms

Worldcoin’s World ID initiative, built by Tools for Humanity, is deploying a biometric authentication system based on iris scanning to assign a unique human identity to every AI ag...

AI SecurityPrivacyAuthentication
Read More → Use Tool →
2026-03-08KrebsOnSecurity
AI Assistants Redefine Cybersecurity Landscape

AI assistants, often marketed as autonomous "agents", are rapidly becoming a staple in developer toolchains, promising to automate everything from code generation to system configu...

AI SecurityAI ThreatsPrivacy
Read More → Use Tool →
2025-07-07Ars Technica
Android Gemini Access to Third‑Party Apps: Privacy Risks in 2024

Starting Monday, Google began rolling out a platform update for Android 14 (API level 34) that expands the capabilities of its on‑device AI assistant, Gemini. The change introduces...

PrivacyAI Security
Read More → Use Tool →