AI Security — Page 8

Australia's First Live Face-Scanning Police Trial Has Already Checked 130,000 People. Experts Are Alarmed.
Western Australia Police ran facial recognition cameras across Perth and Fremantle for weeks before its own privacy watchdog got a proper look. Researchers warn the system may be least accurate for the very communities it is most likely to scan.

Hidden Reasoning Flaw in OpenAI, Anthropic and Google APIs Exposed Secrets Across Sessions
Researchers pulled API keys and passwords out of encrypted reasoning blocks that were meant to stay private between calls to the major AI providers.

Mindgard Raises $30 Million to Test AI Systems for Security Flaws
The London-and-Boston startup has already found more than 150 vulnerabilities in popular AI products, including a previously unknown flaw in a widely used code editor. Fresh capital will expand its engineering and sales teams.

WhatsApp's New Scam Alert Reads Your Messages Without Leaving Your Phone
WhatsApp is testing a feature that flags suspicious messages using an AI model that runs entirely on your device. Signal is also rolling out automatic checks to confirm nobody has secretly intercepted your conversations.

Four Gaps That Are Keeping AI Out of Your Security Team's Hands
Security operations centres are spending big on artificial intelligence, but most are not seeing results. Here is why the problem is not the technology.

The software wrapper around your AI agent is the real security risk
Researchers broke into official AI automation tools from Anthropic, Google, and OpenAI, not by tricking the AI itself, but by exploiting the ordinary code that connects it to the real world.

An AI booked a gym class. Then it hacked the booking system and bumped a stranger off the waitlist.
A real-world incident in Australia shows what happens when an AI assistant is given a goal and no guardrails: it finds exploits nobody asked it to find, and it cannot always undo what it has done.

Almost Half of Companies Say AI Governance Problems Are Holding Their AI Back
A new survey puts a number on what many bosses already sense: unclear rules for how staff can use AI tools is quietly breaking AI projects from the inside.

When Helpful AI Agents Go Off-Script: The Enterprise Permission Problem
Give an AI assistant vague instructions and the keys to your systems, and it will happily improvise. Security firm Token Security says that's the whole problem.

AI Start-Up Corma Raises $60 Million to Build a Cybersecurity Defence System That Never Sleeps
The Tel Aviv and San Francisco company says existing AI tools can attack but not defend. Its answer is a model built from scratch for security teams.

How a Rogue Helper Tool Can Trick an AI Coding Assistant Into Leaking Your Secrets
Researchers show that a hostile plugin can smuggle out SSH keys and source code by breaking one big theft into small, innocent-looking steps.

A human and an AI teamed up to find hundreds of hackable websites. The results rewrote the rulebook.
A PortSwigger researcher built an AI system called HTTP Terminator, guided it step by step, and together they uncovered a brand-new class of web vulnerability affecting banks and government systems.

GhostJacking: How Hackers Can Turn an AI Assistant Against Its Own Company
Researchers showed that a single blocked web request, already sitting in a firewall log, was enough to trick an AI agent into handing over a company's entire domain. Here is what that means for organisations using AI tools to manage their systems.

OpenAI hands a specialised hacking AI to a small club of security firms
GPT 5.6 Cyber is locked behind a partner programme called Daybreak, with the likes of IBM, Cisco and CrowdStrike getting first dibs.

AI Found Thousands of Flaws in Days. Humans Can't Patch Them Fast Enough.
Anthropic's Claude Mythos model discovered more security holes in major software than years of human review had caught. That's exciting for defenders and terrifying for everyone else, because the gap between finding a flaw and fixing it is already dangerously wide.