AI Security — Page 13

AI Security

Three-Bug Chain Turns Any LiteLLM User Into Root on the AI Gateway

A default low-privilege account on the popular open-source LLM proxy can escalate to admin and execute code, exposing every provider key the gateway holds.

2 min read
AI Security

SearchLeak: How a microsoft.com Link Could Have Drained a Copilot Tenant

Varonis Threat Labs chained three bugs in Microsoft 365 Copilot Enterprise Search into a one-click exfil path that lived behind a trusted Microsoft URL.

2 min read
AI Security

Langflow's Unauthenticated File-Write Flaw Is Being Exploited — Patch Dropped 73 Days Ago

CVE-2026-5027 lets attackers write files to arbitrary paths on exposed servers, and because Langflow ships with login disabled by default, exploitation requires exactly zero credentials.

3 min read
AI Security

Poisoned Documents Can Freeze AI Agent Guardrails Dead in Their Tracks

Researchers found that a single malicious input can trap reasoning-based safety systems in extended thinking loops, slowing LangGraph deployments by 148x and starving co-located agents of resources.

2 min read
AI Security

Anthropic Pulls Claude Fable 5 and Mythos 5 After Federal Suspension Order

A late-Friday directive citing national security forced Anthropic to cut off its top-tier models — for everyone, not just foreign nationals.

3 min read
AI Security

Agentjacking: Poisoned Sentry Error Reports Hijack AI Coding Assistants

Researchers describe a prompt-injection class that turns developer error-tracking pipelines into a remote code execution path against AI coding agents.

3 min read
AI Security

AI Web Agents Have No Reliable Prompt Injection Defenses, Benchmark Finds

Researchers ran 3,168 adversarial tests against GPT-5 and Gemini-powered agents. The 'Robust Behavior' outcome — agent completes task, attacker gets nothing — never appeared.

3 min read
AI Security

LangGraph Patches Three Bugs, Including an SQLi-to-RCE Chain in Self-Hosted Agents

The framework underpinning a wave of multi-agent AI deployments shipped fixes for a flaw chain that let attackers pivot from SQL injection to code execution on self-hosted nodes.

3 min read
AI Security

Researchers Turn OpenClaw Into a Confused Deputy With Hidden Prompts

Two teams show the self-hosted AI agent will execute attacker instructions smuggled inside contacts, location pins, and other benign-looking inputs.

3 min read
AI Security

The Alert Queue Is Full. So Is the Graveyard of Missed Threats.

When every event screams critical, nothing is. AI and automation are being drafted to fix a triage problem that human analysts simply can't outrun anymore.

3 min read
AI Security

Six Things SRE Teams Demand Before Handing Anything to an AI Agent

Observability gaps, missing guardrails, and opaque reasoning are the real blockers — not the AI itself.

3 min read
AI Security

Frontier AI Models Transform Vulnerability Discovery

AI capabilities reshape cyber defense strategies, prompting new approaches to vulnerability management.

2 min read
AI Security

AI Agents in Phishing Tests: Risks and Failures Exposed

Autonomous AI agents can be tricked into leaking sensitive data, highlighting configuration issues in security frameworks.

2 min read
AI Security

Shadow AI Is the Governance Gap Nobody Wants to Admit

A mid-year security forum puts unmonitored generative AI use front and center. The problem is older than the hype.

2 min read
AI Security

Twelve Controls That Actually Matter Once AI Ships to Production

Visibility into AI applications is a starting point, not a security posture. Here is what ongoing monitoring and defense of production AI systems looks like in practice.

3 min read
© 2026 Threat Vectr