AI Security — Page 9

The Automation Nobody Reviewed: How AI-Built Workflows Are Quietly Leaking Enterprise Data
A developer asked an AI to speed up a document approval process. It worked perfectly — and exposed sensitive HR files to hundreds of colleagues. This is happening across businesses right now.

A Fake Error Message Hijacked AI Coding Assistants — and Security Tools Saw Nothing
Researchers planted a single bogus bug report in a popular developer service and watched AI coding agents obediently run the attackers' code. No password stolen. No alarm raised.

AI Assistants Are Inventing Fake Web Addresses — and Criminals Are Buying Them Up
Researchers at Palo Alto Networks found that AI tools routinely make up plausible-sounding website addresses that don't exist. Criminals are registering those addresses before anyone notices — and one already built a full fraud operation using the same AI trick.

IBM and Red Hat Launch $5 Billion Initiative to Secure Open-Source Software
IBM and Red Hat invest heavily in Project Lightwell to address open-source software vulnerabilities revealed by Anthropic's AI.

Apple Shifts Security Update Strategy Amid AI-Driven Cyber Threats
Apple now releases security patches more frequently to tackle the growing threats posed by AI-enhanced cyberattacks.

Anthropic's Claude Fable is back — and users say it's answering "no" to almost everything
After regulators lifted the ban, the returning model keeps handing tasks off to a weaker sibling. Anthropic says its safety net is just set very wide.

U.S. Government Lifts Its Block on Anthropic's AI Models — With Strings Attached
After a weeks-long government-ordered shutdown triggered by a security flaw in its AI software, Anthropic's chatbots are back online. One is open to the public again. The other remains locked behind federal approval.

Anthropic pulls Claude Fable 5 from subscriptions on July 7 — but says it's coming back
The AI company blames unpredictable demand for its most powerful model. Subscribers will need to pay per use until capacity catches up.

CISOs Are Betting Big on AI—But Is the Hype Outrunning the Evidence?
Reddit's CISO and an Omdia analyst weigh in on where AI security tooling actually delivers, and where the gap between pitch deck and production remains embarrassingly wide.

AI-Generated Code Is Outpacing Your Audit Process
CISOs are discovering that traditional software audits weren't built for a world where a developer can generate 500 lines of Go in forty seconds. Here's what the checklist needs to look like now.

Context Manipulation Attack 'BioShocking' Turns Agentic Browsers Into Credential Thieves
Researchers demonstrate how feeding poisoned context to AI-driven browser agents causes them to quietly drop safety guardrails and exfiltrate stored credentials.

DeepSeek-Generated PoC Ransomware Runs Entirely in the Browser via Chromium File System Access API
Researchers documented what they describe as the first frontier-model-produced malware artifact combining LLM ideation with a legitimate Chromium capability to encrypt user files without a native binary.

Cursor IDE's Sandbox Cracked by Prompt Injection — No User Interaction Required
Two logic flaws in Cursor's command execution sandbox let attackers escape the isolation layer and run code on the underlying OS. Patches landed in April. The researchers say Cursor isn't alone.

DuneSlide: Two Cursor Bugs Turn a Prompt Into a Shell
A pair of 9.8-rated flaws in the AI code editor let a single crafted prompt escape the sandbox and execute arbitrary commands — no user approval required.

DeepSeek Spits Out Working Browser-Native Ransomware for Windows and Android
Researchers say a frontier model stitched together a real Chromium capability with fantasy malware ideas and produced something that actually encrypts files from inside a tab.