AI Security — Page 25

Anthropic's Claude Fable is back — and users say it's answering "no" to almost everything
After regulators lifted the ban, the returning model keeps handing tasks off to a weaker sibling. Anthropic says its safety net is just set very wide.

U.S. Government Lifts Its Block on Anthropic's AI Models — With Strings Attached
After a weeks-long government-ordered shutdown triggered by a security flaw in its AI software, Anthropic's chatbots are back online. One is open to the public again. The other remains locked behind federal approval.

Anthropic pulls Claude Fable 5 from subscriptions on July 7 — but says it's coming back
The AI company blames unpredictable demand for its most powerful model. Subscribers will need to pay per use until capacity catches up.

CISOs Are Betting Big on AI—But Is the Hype Outrunning the Evidence?
Reddit's CISO and an Omdia analyst weigh in on where AI security tooling actually delivers, and where the gap between pitch deck and production remains embarrassingly wide.

AI-Generated Code Is Outpacing Your Audit Process
CISOs are discovering that traditional software audits weren't built for a world where a developer can generate 500 lines of Go in forty seconds. Here's what the checklist needs to look like now.

Context Manipulation Attack 'BioShocking' Turns Agentic Browsers Into Credential Thieves
Researchers demonstrate how feeding poisoned context to AI-driven browser agents causes them to quietly drop safety guardrails and exfiltrate stored credentials.

DeepSeek-Generated PoC Ransomware Runs Entirely in the Browser via Chromium File System Access API
Researchers documented what they describe as the first frontier-model-produced malware artifact combining LLM ideation with a legitimate Chromium capability to encrypt user files without a native binary.

Cursor IDE's Sandbox Cracked by Prompt Injection — No User Interaction Required
Two logic flaws in Cursor's command execution sandbox let attackers escape the isolation layer and run code on the underlying OS. Patches landed in April. The researchers say Cursor isn't alone.

DuneSlide: Two Cursor Bugs Turn a Prompt Into a Shell
A pair of 9.8-rated flaws in the AI code editor let a single crafted prompt escape the sandbox and execute arbitrary commands — no user approval required.

DeepSeek Spits Out Working Browser-Native Ransomware for Windows and Android
Researchers say a frontier model stitched together a real Chromium capability with fantasy malware ideas and produced something that actually encrypts files from inside a tab.

Cutting Through the AI Noise: What Enterprises Should Actually Be Asking Security Vendors
Marketing copy is cheap. Measurable detection capability is not. Here's how to stress-test an AI security pitch before you sign anything.

Poisoned Tool Descriptions Turn Helpful AI Agents Into Quiet Exfiltration Channels
Microsoft Incident Response demonstrates how a single malicious MCP-style tool description can coax an agent into leaking corporate data — without tripping a single policy check.

GuardFall: A 1970s Shell Trick Walks Past AI Coding Agent Safety Checks
Adversa AI says ten of eleven open-source coding agents fall to a command-substitution bypass that any sysadmin would recognize on sight.

Two-Thirds of iPhone AI Chatbot Apps Are Bleeding API Keys
A study of 444 iOS chatbot apps found 282 exposing paid model access in plaintext network traffic — sometimes with no authentication at all.

Bash Shell Tricks From the '90s Are Breaking AI Coding Agents Wide Open
Old-school shell injection techniques can bypass safeguards in most open-source AI coding agents — and a poisoned repo is all it takes to start the chain.