Skip to main content

Tag: ai security

144 articles

Cluttered tech workspace with laptop and development tools on a desk.

Mini Shai-Hulud Worm Targets Multiple AI, Dev Packages

Meet the Mini Shai-Hulud worm, a sneaky new malware that's infiltrating AI and development packages through a clever supply-chain attack. This malicious code can steal sensitive data from cloud providers, cryptocurrency wallets, and even popular dev tools like GitHub Actions.

Analyst 207
A text document on a laptop screen with a nearly imperceptible line of white text blending into the white background.

Steganography Exploits LLMs with Hidden Text Techniques

Want to hide text in plain sight? Try using white text on a white background or black text on a black background - simple yet effective visual tricks that can evade human eyes while remaining readable by machines.

Analyst 207
Developer workstation with laptop screen showing a trust prompt and blurred software development environment in the…

Anthropic's AI Tool Exposes to One-Click Remote Code Execution Risk

A single click on Claude Code's generic dialog can unleash a major security risk, allowing an unsandboxed Node.js process to spawn with full user privileges. This vulnerability can be exploited using just two common JSON files, putting developers at risk of one-click remote code execution.

Analyst 207
Professionals gather in front of a futuristic data center at a tech company headquarters.

Legacy Security Tools Hinder Data Protection Efforts

With data constantly moving across cloud and AI environments, traditional security tools are holding you back from truly protecting your data - it's time for a modern approach. A staggering 72% of security professionals agree that data security is more critical than ever, making an evolution in strategy urgent.

Analyst 207
Person typing on laptop keyboard in modern office setting with blurred screen.

AI Exploits Emerge as New Security Threat

As AI use grows, a hidden risk is emerging: malicious inputs can alter model behavior, bypassing safeguards and putting enterprises at risk. This "prompt injection" tactic is like phishing, targeting the link between user and system to wreak havoc.

Analyst 207
Server room with rows of computer servers and a single workstation featuring a blank AI system interface.

AI-BOMs Emerge to Secure Enterprise AI Supply Chains

Imagine biting into a mysterious birthday cake without knowing its ingredients or who baked it - that's what it's like for enterprises trying to secure their AI supply chains without visibility into the components used to build their AI systems. Traditional software bills of materials just aren't cutting it in this new landscape.

Analyst 207
Modern technology command center with sleek console and multiple laptop screens.

ServiceNow Unveils AI Command Center to Tame Enterprise AI Assets

ServiceNow's AI Command Center brings order to enterprise AI assets, ensuring every system is secure, compliant, and aligned with your business strategy. This powerful tool tackles AI agent sprawl by offering a unified control tower across five key areas: discovery, observation, governance, security, and measurement.

Analyst 207
Laptop screen shows GitHub repository with blurred section, symbolizing restricted access to source code.

NHS Moves to Close-Source GitHub Repos Citing AI Security Risks

The NHS is taking steps to boost security by moving its public GitHub repositories to private access by May 11, amid concerns that AI-powered code analysis could be exploited to uncover sensitive information. This temporary measure aims to prevent unintended disclosure of source code and other critical details.

Analyst 207
Modern tech facility interior with AI device prototype on display.

Palo Alto Networks Bolsters AI Security With Portkey Acquisition

Palo Alto Networks is taking a major leap in AI security with its acquisition of Portkey, a cutting-edge startup that offers an AI agent gateway to streamline and secure communications among autonomous agents. This move will enable centralized control and oversight, ensuring safer interactions between AI agents.

Analyst 207
Speaker at podium in conference setting with blurred audience and gradient visuals on screen.

Open Source Models Challenge Dominance in Automated Bug Finding

The impressive performance of Anthropic's Mythos in automated bug finding, which uncovered 271 Firefox flaws, has been called into question by Ari Herbert-Voss, who argues that open-source models can be just as effective. Herbert-Voss suggests that Mythos's success can be attributed to its ability to detect both simple and complex vulnerabilities, thanks to a phenomenon he terms "supralinear scaling".

Analyst 207
Large computer screen displays complex network diagram in modern lab setting.

Frontier AI Exposes Gaps in Traditional Security Programs

Imagine having the power to replicate a full year’s worth of manual penetration testing in just three weeks - that's the reality with frontier AI, which has exposed significant gaps in traditional security programs. Palo Alto Networks and Unit 42 have revealed that advanced models like Anthropic Mythos can autonomously identify software vulnerabilities and adapt to defensive controls in near-real-time.

Analyst 207
Security team works at a workstation with multiple monitors in a brightly-lit operations center overlooking a cityscape.

Anthropic's Claude Mythos Exposes AI Vulnerability Risks

The recent exposure of Anthropic's Claude Mythos highlights a chilling reality: AI tools designed to improve software quality can be easily repurposed to accelerate vulnerability discovery for malicious ends. This underscores the growing threat of AI-powered attacks, as malicious actors exploit commercial tools with minimal friction.

Analyst 207
Cluttered office workspace with computer and browser on desk, cityscape outside window.

Researchers Expose AI Agents to Malicious Prompt Injection Payloads

Imagine a browser AI that can summarize web pages, but with a hidden vulnerability that allows malicious instructions to be embedded and executed - a newly discovered threat that security researchers are warning deserves our attention. Forcepoint researchers have uncovered 10 real-world examples of indirect prompt injection payloads designed to subvert AI agents and wreak havoc.

Analyst 207
Secure computer workstation with multiple monitors displaying code and system dashboard in a neutral-colored setting.

Anthropic's Mythos Model Exposes Limited Capabilities

Anthropic's highly anticipated Mythos model, designed to proactively identify vulnerabilities, has been compromised - with a small group of individuals reportedly gaining unauthorized access to the preview through a third-party vendor environment. The incident has raised concerns about the model's limited capabilities to protect itself from exploitation.

Analyst 207
A hovering laptop screen glows amidst scattered code and cables, surrounded by swirling particles, with shattered circuit…

Google's Antigravity AI Flaw Exposes Remote Code Risk

Google's top-of-the-line Antigravity AI safeguard can be surprisingly easily tricked into letting its guard down, leaving the door open for attackers to execute remote code. Even with its highest security setting, the AI agent manager's weaknesses can be exploited, putting users at risk.

Analyst 207
Abandoned server room with flickering light, broken lock, and eerie shadows.

Misconfiguration Exposes Azure AI Agent to Unauthorized Access

A single misconfiguration in Microsoft's Azure SRE Agent turned a troubleshooting tool into a live wiretap, potentially allowing outsiders to intercept sensitive conversations, commands, and credentials from other companies in real time. This alarming security flaw may have left organizations vulnerable to unauthorized access, with no digital trail to detect the breach.

Analyst 207
Shattered robotic arm on modern desk with scattered papers and broken devices amidst cityscape at dusk.

Vercel Breach Traced to Compromised AI Tool

A recent Vercel breach highlights a growing concern: what happens when AI tools, meant to boost efficiency, become the weakest link in our security chain? The breach was traced back to a third-party AI tool used by an employee, blurring the lines between human error and machine vulnerability.

Analyst 207
Shadowy figure looms over laptop with chatbot interface as syringe hovers above, surrounded by shattered glass and torn…

Prompt Injection Attacks Target AI Systems with Alarming Frequency

Imagine a simple question that can outsmart a secret-keeping system - it's happening more often than you'd think, as prompt injection attacks use cleverly crafted language to trick AI models into spilling their secrets. By manipulating conversational inputs, these attacks can get supposedly secure AI bots to reveal sensitive information.

Analyst 207
Dark cityscape with cracked shield in foreground and ghostly code streams in background, lone figure walking away.

AI Vendors Downplay Role in Security Vulnerabilities

AI vendors are caught in a contradictory spin cycle, urging companies to rely on AI to combat threats while downplaying security flaws, leaving customers wondering who's truly responsible for safeguarding their systems. When vulnerabilities arise, these vendors often claim it's simply their AI working as intended - a response that only fuels concerns about their maturity and accountability.

Analyst 207
Futuristic pipeline system with glowing blue circuits and a massive gate, set against a dark misty background with an…

AI Cybersecurity Pipelines Unlock Mythos' Full Potential

Mythos can dazzle with its ability to uncover vulnerabilities and chain exploits, but the real challenge lies in harnessing its power through robust AI cybersecurity pipelines that deliver lasting value across an organization. It's time to shift from showcasing AI capabilities to building the engineering and governance scaffolding that turns promise into practical utility.

Analyst 207
Dimly lit server room with eerie shadows, smoke, and a shattered laptop screen.

Anthropic's MCP Flaw Exposes 200K Servers to Takeover Risk

A security flaw in Anthropic's Model Context Protocol (MCP) could put a staggering 200,000 servers at risk of complete takeover, leaving thousands of machines vulnerable to attack. This design flaw, described as a vulnerability by security researchers, highlights a potentially disastrous weakness in a protocol meant to manage AI model context.

Analyst 207
A lone figure in a hoodie stands on a rooftop, gazing out over a dark cityscape with a grid pattern of code and circuitry…

OpenAI Unveils GPT-5.4-Cyber Model to Bolster Defensive Cybersecurity Measures

OpenAI's new GPT-5.4-Cyber model is a game-changer in defensive cybersecurity measures, offering a powerful tool to help organizations outsmart cyber threats. By harnessing AI to defend networks, OpenAI is challenging the status quo and raising important questions about the future of cyber risk management.

Analyst 207
Masked figure in hoodie sits before laptop with Git repository, surrounded by distorted identity symbols.

AI Code Reviewer Vulnerable to Git Identity Spoofing

Imagine a security system that can be tricked into trusting a foe as a friend with just two lines of code - that's what happened with Anthropic's AI code reviewer, Claude, which was vulnerable to Git identity spoofing. This simple hack allowed researchers to forge a trusted developer's identity and get hostile code approved in no time.

Analyst 207
Darkened hospital corridor with spotlight on laptop showing 3D brain with gap, surrounded by puzzle pieces and broken…

Healthcare Sector Tackles Third-Party AI Security Gaps with New Guidance

The healthcare sector is taking a major step towards securing its AI-powered tools with new guidance from the Health Sector Coordinating Council (HSCC) that helps tackle the growing threat of third-party AI security gaps. This playbook is a timely response to the explosion of AI-related cyber risks from vendors, and aims to safeguard the industry's increasing reliance on externally developed artificial intelligence.

Analyst 207