AI Security — Page 15

Claude Mythos Preview Reportedly Breached Within Hours, Renewing Agentic AI Risk Questions
An unverified claim of unauthorized access to Anthropic's limited technical preview has defense-sector buyers asking whether agentic models belong on production networks at all.

One GitHub Issue Was Enough to Pwn Repos Running Claude Code Action
A bug in Anthropic's Claude Code GitHub Action turned issue triage into arbitrary code execution — including, briefly, against the action's own repo.

Silent RCE in Hugging Face Transformers Hides Behind a Single Config Field
CVE-2026-4372 lets an attacker own any machine that loads a poisoned model — no warnings, no prompts, no trace. The trust_remote_code flag didn't help.

Unpacking the 'Son of Mythos': AI's Role in Vulnerability Discovery
As Anthropic and OpenAI expand AI tool access, organizations face both risks and opportunities.

A Single Notification Could Hijack Gemini on Android
Researchers showed how a poisoned WhatsApp, Slack or SMS alert could weaponize Google's voice assistant — no malicious app required.

Microsoft Cages the Agent: MXC, MDASH, and the Push to Govern Autonomous AI at Runtime
Microsoft is shipping a dedicated containment environment for agentic AI workloads, alongside open-source governance frameworks and expanded vulnerability-scanning capabilities — all aimed at reining in what autonomous coding agents can actually do.

Someone Finally Tested 100 AI Agents for Security. Here's the Framework They Used.
A new evaluation methodology ranks AI agents by vulnerability, blast radius, and defensive posture. The results are a useful corrective to vendor claims.

Agentic AI Is Doing What a Thousand Breach Reports Couldn't: Getting Boards to Open the Checkbook
Autonomous agents, AI-generated code, and frontier models capable of offensive cyber ops are finally making cybersecurity a board-level business conversation — not just an IT line item.

Project Glasswing Expands: 150 More Companies Join AI Vulnerability Initiative
Anthropic's AI-driven bug-hunting project adds critical infrastructure partners, but the patching bottleneck looms.

Diverging Paths to Cybersecurity: Tools vs. Operational Control
New reports debate whether inadequate tools or operational lapses are to blame for cybersecurity issues.

AI Has Minted a New Kind of Attacker — One Who Knows Nothing
Generative AI closes the skill gap between vague criminal intent and working malware. Responsible disclosure norms weren't built for that world.

Meta's AI Support Bot Handed Out Password Resets to Anyone Who Asked Nicely
A pro-Iran Telegram channel published a walkthrough showing how Instagram's conversational recovery assistant could be talked into linking attacker-controlled email addresses to target accounts. The Obama White House and a senior U.S. Space Force account were briefly defaced.

One Click, Full Shell: Flowise MCP Flaw Scores 9.9 CVSS
A sandboxing failure in Flowise's MCP stdio implementation lets an attacker execute arbitrary OS commands with process-level privileges — and the patches so far don't close the hole.

The Pentagon Wants Battlefield AI. Not Everyone With Stars on Their Collar Agrees.
The White House sees AI as a defining American military edge. Some of the generals and admirals who would actually deploy it aren't so sure.

AI in Cyber Operations: From Scripts to Autonomous Systems
AI's role in cyber operations is not just about speed anymore. It's about scale and autonomy, reshaping offensive capabilities.