AI Security — Page 14

AI Red Teaming Grew Up. The Job Description Is Still Being Written.
The tools broke when LLMs arrived. Now the discipline is rebuilding itself in real time — and the threat model includes teenagers with too much free time.

Anthropic Ships Claude Fable 5 as Two Products, One With the Cyber Guardrails Off
The public gets Fable 5. A vetted cyber cohort gets Mythos 5 — the same model with safety classifiers lifted.

Knowingly Shipping Vulnerable Code Has Become Standard Practice, Survey Finds
A Checkmarx survey of 2,350 security leaders finds nearly half of production code is AI-generated — and enterprises are deploying it despite knowing it carries unresolved flaws.

Anthropic Opens Mythos-Class Intelligence to the Public — With a Classifier Standing Guard
Claude Fable 5 ships with AI-powered routing that quietly downgrades sensitive requests to Opus 4.8. Early tests suggest the net is wider than Anthropic's marketing implies.

Anthropic's Mythos Preview Goes Bug-Hunting: What XBOW's Red Team Found
An offensive-security shop put Anthropic's unreleased Mythos model through exploit discovery, reverse engineering, and live-site validation. The source-code review results were the standout.

Attackers Are Wrapping Old Phishing Tricks in AI Branding. It's Working.
Microsoft and Google both dropped advisories this week documenting how threat actors are dressing up familiar credential theft and malware campaigns as ChatGPT, Copilot, and DeepSeek experiences. The technique is not new. The success rate is.

Cryptographic Invisibility: Atsign’s Approach to Securing AI Applications
Atsign’s AI Architect aims to shield agentic software from attackers by rendering application identities invisible.

AI Worm Exploits Networks Using Local Models
University researchers create AI worm that crafts unique attacks without external AI services.

Anthropic's Mythos Shows AI Can Find Bugs Faster Than Humans. The Bug Bounty Model May Not Survive It.
Machine-speed vulnerability discovery is no longer theoretical. The question now is whether the bounty ecosystem — and the offensive security teams inside it — are priced and structured for a world where finding flaws is the easy part.

A Free LLM, a Custom Harness, and 27 Compromised VMs: The AI Worm You Don't Need a Lab to Build
University of Toronto researchers built a self-replicating AI worm using only locally-hosted open models. It spread to 82% of its targets. The threat model here isn't frontier AI — it's the misconfigured server you forgot about.

LiteLLM Command Injection Hits CISA KEV as Attackers Chain to RCE
CVE-2026-42271 lets any authenticated user run shell commands on the LiteLLM proxy. CISA says it's already being exploited.

The Hades Campaign: Malware That Deceives AI Security Systems
A sophisticated supply chain attack exploits AI analysis, targeting Python environments with silent payloads.

OpenAI's Lockdown Mode Admits the Problem It Can't Quite Fix
The new containment feature reduces AI-enabled data exfiltration — it doesn't stop it. Experts are divided on whether enterprises should even trust a vendor to police itself.

12 Questions That Expose Whether Your Security Program Is Actually Working
A roundup of hard questions CISOs should already be asking — about blast radius, nonhuman identities, and whether 'vibe coding' has eaten your attack surface.

OpenAI Ships ChatGPT 'Lockdown Mode' to Blunt Prompt-Injection Data Theft
The opt-in setting strips connectors and browsing tools that attackers have used to siphon data from logged-in sessions.