AI Security — Page 10

Cutting Through the AI Noise: What Enterprises Should Actually Be Asking Security Vendors
Marketing copy is cheap. Measurable detection capability is not. Here's how to stress-test an AI security pitch before you sign anything.

Poisoned Tool Descriptions Turn Helpful AI Agents Into Quiet Exfiltration Channels
Microsoft Incident Response demonstrates how a single malicious MCP-style tool description can coax an agent into leaking corporate data — without tripping a single policy check.

GuardFall: A 1970s Shell Trick Walks Past AI Coding Agent Safety Checks
Adversa AI says ten of eleven open-source coding agents fall to a command-substitution bypass that any sysadmin would recognize on sight.

Two-Thirds of iPhone AI Chatbot Apps Are Bleeding API Keys
A study of 444 iOS chatbot apps found 282 exposing paid model access in plaintext network traffic — sometimes with no authentication at all.

Bash Shell Tricks From the '90s Are Breaking AI Coding Agents Wide Open
Old-school shell injection techniques can bypass safeguards in most open-source AI coding agents — and a poisoned repo is all it takes to start the chain.

Malicious Extension Spoofs AI Platform to Intercept Searches
A fake browser extension impersonating Perplexity AI intercepted search queries, highlighting governance gaps in enterprise security.

The Hidden Cost of Agentic AI in Security: Token Budgets Are Now a Defense Problem
Cybersecurity platforms are racing to embed agentic AI, but the economics of token consumption, AI credits, and deployment architecture may undercut the value before defenders see a return.

BioShocking: Prompt-Game Trick Pries Credentials From AI Browsers
Researchers at LayerX got six AI browsers and assistants — including ChatGPT Atlas, Perplexity's Comet, and Anthropic's Claude extension — to exfiltrate user logins by framing the attack as a game.

Poisoned Repos Can Trick Claude Code Into Opening a Reverse Shell
Researchers show that prompt injection hidden inside a repository's files is enough to turn Anthropic's agentic coding tool against the developer running it.

Prompt Injection in Git Repos Can Turn Claude Code Into a Reverse Shell Launcher
Malicious instructions buried in a repository's files can hijack Anthropic's Claude Code agent and open a backdoor on the developer's own machine — no obvious malware required.

White House Puts OpenAI and Anthropic Models on a Short Leash Pending Cybersecurity Review
The Trump administration is vetting frontier AI releases before they reach the public — and both major labs are complying.

OpenAI Hands GPT-5.6 to a Closed Circle, Citing Cyber and National Security Hooks
Three variants — Sol, Terra, and Luna — ship to a small slate of enterprise partners and U.S. government workstreams under a limited preview.

Frontier AI Is a Pressure Test, Not a New Threat Model
The arrival of capable AI models like Mythos changes attacker economics. It doesn't change which controls actually matter — and most organizations are still failing the old ones.

MCP's Enterprise Overhaul Hands Security Problems to Developers
A major revision to the Model Context Protocol repositions itself as enterprise-ready — then quietly offloads the hard security work onto the teams building on top of it.

Gaslight: A Rust macOS Stealer That Tries to Talk Your AI Analyst Out of Looking
The implant ships with an embedded prompt injection payload aimed at LLM-assisted reverse engineering tools — a small but telling escalation in adversarial UX.