AI Security — Page 3

A single fake review can trick an AI agent into buying the wrong product
Researchers describe a new class of attack where planted content on trusted pages steers AI assistants into harmful actions without ever hijacking the task itself.

AI Finds Bugs Fast. Proving They're Real Still Takes a Human.
AI tools can scan code and spit out vulnerabilities at speed, but a finding is worthless until someone shows it actually works. Here's why that gap matters for anyone worried about software security.

AI Can Build a Dossier on Your CEO in Ten Minutes. Most Companies Have No Answer for That.
Artificial intelligence tools have turned the slow, skilled work of researching a target executive into a task anyone with a browser can do. Security teams have not caught up.

Give an AI a Body and You Give It an Attack Surface
Warehouses and factories are buying humanoid robots before security teams have a single audit standard to work from. Here is what that means for the people on the floor.

A Russian-speaking hacker turned Google's Gemini CLI into his botnet co-pilot
For roughly a year, an attacker chatted with Google's open-source AI tool to run malware on eight computers inside a dental clinic, migrate his servers, and troubleshoot bugs in six minutes flat.

One Click Was All It Took to Hijack Anthropic's Claude AI
A flaw in the Claude Desktop app let attackers silently feed malicious instructions to the AI and steal private files. The bug is fixed, but the attack method points to a new category of risk.

Intruder's AI 'vulnerability vending machine' finds a WordPress zero-day on its own
A security firm wired large language models into code-analysis tools and produced a working exploit for an unknown plugin flaw. It says more disclosures are on the way.

Two Clicks to Own a Developer's Machine: The Cursor AI Flaw You Should Know About
Researchers found they could smuggle a malicious installation command into the most popular AI code editor by hiding it inside what looked like a routine code-review link.

White House Launches AI-Powered Clearinghouse to Fix Software Flaws Faster
A new federal program called Gold Eagle will use artificial intelligence to sort and prioritise software vulnerabilities across government agencies and critical industries. Whether it delivers depends almost entirely on execution.

The AI Blind Spot in Corporate Security: Why Old Traffic Inspection Is Falling Behind
Employees are pasting company secrets into ChatGPT and installing rogue browser add-ons. The security tools most firms rely on can't see any of it.

Cribl Buys CardinalOps to Close the Gap Between Collecting Security Data and Acting on It
The $3.5 billion data-pipeline company moves beyond simply gathering security information, adding AI-powered tools that tell defenders where their defences are actually failing.

Bugs in Claude's Chrome Extension Let Other Add-Ons Read Your Gmail and Docs
Security researchers say two unpatched flaws in Anthropic's browser assistant can be exploited to silently pull private data from Google services, and a simple one-line fix has gone unshipped for months.

What separates a good security engineer from a great one in 2025
New research and industry voices spell out exactly what companies should demand when hiring the people who keep their systems safe, and why the old checklist of certifications no longer cuts it.

Pentera Pitches Validation as the Missing Layer in AI Security Workflows
The vendor argues AI security agents making real decisions need proof, not just risk scores, before they act.

A Bug in the Claude for Chrome Extension Has Survived Eight Fixes and Still Leaks Your Gmail
A flaw nicknamed 'ClaudeBleed' lets other browser extensions quietly read your email and calendar. After eight attempted patches, it apparently still works.