Back to Feed

Tag

AI Security

51 items tagged #ai-security

Articles

Montana Empire is an #AI-assisted #phishing kit mimicking a national postal service’s e-commerce...

Montana Empire AI-assisted phishing kit targets postal service customers with card and ID theft.

Grafana Patches AI Bug That Could Have Leaked User Data

Grafana patches AI vulnerability allowing data exfiltration via malicious web instructions.

Max severity Flowise RCE vulnerability now exploited in attacks

Max-severity RCE vulnerability CVE-2025-59528 in Flowise AI platform actively exploited.

The New Rules of Engagement: Matching Agentic Attack Speed

Chinese state-sponsored GTG-1002 deployed autonomous AI agent to conduct large-scale cyberattack with minimal human

GrafanaGhost Vulnerability Allows Silent Data Theft via AI Injection

GrafanaGhost vulnerability in Grafana AI components enables silent data exfiltration via prompt injection.

Critical Flowise Vulnerability in Attacker Crosshairs

Critical Flowise RCE vulnerability CVE-2025-59528 exploited in the wild, affects 12,000+ instances.

Signals from the Cloud Security Forecast 2026: Cloud Risk Is Scaling through Design, Not Disruption

Cloud Security Forecast 2026 identifies identity and permission patterns as predictable drivers of cloud compromise.

GrafanaGhost: Attackers Can Abuse Grafana to Leak Enterprise Data

GrafanaGhost vulnerability allows attackers to bypass Grafana AI safeguards and exfiltrate enterprise data via prompt

‘GrafanaGhost’ bypasses Grafana’s AI defenses without leaving a trace

GrafanaGhost exploits Grafana's AI defenses via prompt injection to exfiltrate sensitive data undetected.

AI Agents and Non-Human Identities Creating Critical Security Gaps, Report

Keeper Security report finds non-human identities and AI agents creating critical security gaps in enterprise

Flowise AI Agent Builder Under Active CVSS 10.0 RCE Exploitation; 12,000+ Instances Exposed

Flowise AI platform CVE-2025-59528 (CVSS 10.0) RCE under active exploitation; 12,000+ instances exposed.

New GPUBreach attack enables system takeover via GPU rowhammer

GPUBreach attack exploits GPU rowhammer to enable privilege escalation and full system compromise.

AI-Assisted Supply Chain Attack Targets GitHub

AI-assisted supply chain attack targets GitHub users via automated misconfiguration exploitation.

1/2‼️ The database of MyLovely[.]AI, an NSFW AI image generation platform, has allegedly been lea...

MyLovely.AI NSFW platform database leaked on cybercrime forum by XTC threat actor.

Inside an AI‑enabled device code phishing campaign

AI-driven device code phishing campaign scales account compromise using automation and dynamic token generation.

Google DeepMind Researchers Map Web Attacks Against AI Agents

Google DeepMind researchers identify six classes of web-based attacks against autonomous AI agents.

‼️ Threat actor Jinkusu advertises sophisticated deepfake and voice manipulation software designe...

Threat actor Jinkusu advertises deepfake and voice manipulation tool for KYC bypass.

Double Agents: Exposing Security Blind Spots in GCP Vertex AI

Unit 42 discovers privilege escalation flaw in GCP Vertex AI allowing compromised agents to exfiltrate data.

AI agents can turn into "double agents" if compromised. Our research found a critical permission...

Google Cloud Vertex AI Agent Engine has critical permission flaw enabling unauthorized access and data exfiltration.

Meta Pauses Work With Mercor After Data Breach Puts AI Industry Secrets at Risk

Meta pauses Mercor work after supply chain breach exposes AI training data secrets.

AI Firm Mercor Confirms Breach as Hackers Claim 4TB of Stolen Data

AI firm Mercor confirms breach linked to LiteLLM supply chain attack; Lapsus$ claims 4TB stolen data.

Drift Loses $285 Million in Durable Nonce Social Engineering Attack Linked to DPRK

Drift loses $285M in sophisticated durable nonce social engineering attack linked to North Korea.

‼️ CVE-2026-5027: Langflow Path Traversal to Remote Code Execution PoC CVSS: 8.8 GitHub: https:...

CVE-2026-5027: Langflow path traversal vulnerability enables remote code execution.

Critical Vulnerability in Claude Code Emerges Days After Source Leak

Critical vulnerability discovered in Claude Code allows bypass of permission system via prompt injection.

One of our researchers built an AI powered supply chain monitoring tool on a Friday afternoon. T...

Elastic Security Labs open-sources AI-powered supply chain monitoring tool that detected Axios npm compromise.

‼️ Chrome Zero-Day CVE-2026-5281: A Use-After-Free in Dawn's WebGPU Layer https://t.co/u4AM1BJjPN

Chrome zero-day CVE-2026-5281 use-after-free vulnerability discovered in Dawn WebGPU layer.

We built an AI-driven pipeline to reverse engineer hundreds of malware samples automatically. Un...

AI pipeline automatically reverse-engineers malware, uncovers Monero mining campaign earning $9K+ since 2023.

FulcrumSec Breaches Unique Computing, ReFocus AI, and Gennet AI Exposing 23,000 Insurance Policyholders, $797M in Premiums, Driver Licenses, SSNs, and Proprietary ML Models From a Single Unpatched AWS Account

FulcrumSec breaches three AI/insurance firms via unpatched CVE, exposes 23K policyholders and $797M in premiums.

Anthropic Leaks 512,000 Lines of Claude AI Code in Major Blunder

Anthropic accidentally leaks 512,000 lines of Claude AI source code via npm package.

Rb. Amsterdam - C/13/783613 / KG ZA 26-120

Dutch court bans X's Grok from generating non-consensual intimate and CSAM imagery in Netherlands.

Google Drive ransomware detection now on by default for paying users

Google Drive ransomware detection now enabled by default for paid workspace users.

Claude Code Source Leaked via npm Packaging Error, Anthropic Confirms

Anthropic's Claude Code source leaked via npm packaging error, triggering typosquat attacks.

Claude AI finds Vim, Emacs RCE bugs that trigger on file open

Claude AI discovers RCE vulnerabilities in Vim and GNU Emacs triggered by file open.

Google's Vertex AI Has an Over-Privileged Problem

Palo Alto researchers reveal over-privileged Vertex AI agents could enable data theft and cloud infrastructure

How SentinelOne’s AI-powered EDR autonomously discovered and stopped Anthropic’s Claude from exec...

SentinelOne's AI-EDR detected trojanized LiteLLM targeting Anthropic's Claude in supply chain attack.

Rb. Amsterdam - C/13/783613 / KG ZA 26-120

Dutch court bans X's Grok from generating non-consensual intimate and CSAM imagery in Netherlands.

CrewAI Vulnerabilities Expose Devices to Hacking

Four chained vulnerabilities in CrewAI allow sandbox escape and arbitrary code execution via prompt injection.

Vertex AI Vulnerability Exposes Google Cloud Data and Private Artifacts

Vertex AI permission model flaw exposes GCP data and private container artifacts.

Rb. Amsterdam - C/13/783613 / KG ZA 26-120

Dutch court bans X's Grok from generating non-consensual intimate and child sexual abuse material.

Rb. Amsterdam - C/13/783613 / KG ZA 26-120

Dutch court bans X's Grok from generating non-consensual intimate and CSAM imagery.

Rb. Amsterdam - C/13/783613 / KG ZA 26-120

Dutch court bans X's Grok from generating non-consensual intimate and CSAM imagery.

Critical Vulnerability in OpenAI Codex Allowed GitHub Token Compromise

OpenAI Codex vulnerability allowed extraction of GitHub OAuth tokens via branch name injection.

AI-Powered 'DeepLoad' Malware Steals Credentials, Evades Detection

AI-generated obfuscation in 'DeepLoad' malware enables credential theft and detection evasion.

OpenAI Codex Vulnerability Allowed Attackers to Steal GitHub Tokens

OpenAI Codex vulnerability allowed attackers to steal GitHub tokens via hidden Unicode in branch names.

Researchers say credential-stealing campaign used AI to build evasion ‘at every stage’

DeepLoad malware campaign uses AI to generate obfuscated code and steal credentials via QuickFix social engineering.

‼️🇺🇸 LAPSUS$ Group is allegedly selling a massive dataset of https://t.co/Q6UlD72i8v, an AI rec...

LAPSUS$ group allegedly selling 4TB dataset stolen from AI recruiting platform.

‼️🇺🇸 LAPSUS$ Group is allegedly selling a massive dataset of https://t.co/Q6UlD72PY3, an AI rec...

LAPSUS$ group allegedly selling 4TB dataset from AI recruiting platform HireVue.

OpenAI Patches ChatGPT Data Exfiltration Flaw and Codex GitHub Token Vulnerability

OpenAI patches ChatGPT data exfiltration and Codex GitHub token theft vulnerabilities.

The State of Secrets Sprawl 2026: 9 Takeaways for CISOs

GitGuardian 2026 report reveals 29M hardcoded secrets leaked in 2025, up 34% YoY; AI integration drives 81% increase in

Hacked Hospitals, Hidden Spyware: Iran Conflict Shows How Digital Fight Is Ingrained in Warfare

Iran-linked hackers deploy spyware via fake bomb-shelter alerts during missile strikes on Israel.

Tips & tricks