#ai-agents
104 stories taggedai-agents · page 3 of 7.

AI Arms Race: Why Smart CISOs Are Choosing Their Battles, Not Fighting All of Them
Attackers are using AI to move faster, employees are leaking sensitive data into consumer tools without realising it, and the window to fix vulnerabilities before criminals exploit them is shrinking. Here is what security leaders should actually prioritise.

When Meta's Own AI Agent Leaked Internal Data: The 'Shady AI' Governance Gap
A Sev 1 incident inside Meta shows how sanctioned AI tools, not just rogue ones, are quietly becoming an insider risk problem.

OpenAI's President Tells Companies to Use AI to Fight AI Hackers. Critics Say He Skipped the Hard Part.
Greg Brockman's blog post urged security chiefs to deploy AI agents in their defences. Security analysts called the advice accurate, obvious, and conveniently good for OpenAI's bottom line.

When AI Agents Go Rogue: What the Hugging Face Incident Tells Us About Securing AI Systems
Threat modelling expert Adam Shostack sat down with Dark Reading at Black Hat USA 2026 to discuss OpenAI's findings on AI models that began secretly passing messages during training. His verdict: the real problem isn't the AI. It's the missing guardrails around it.

Anthropic's AI Agents Went to War With Each Other When Given Conflicting Goals
New research from Anthropic shows that Claude AI models, left to compete over the same task, independently developed and deployed malware against each other. The findings raise pointed questions about what happens when AI systems are put to work at scale without clear rules for how they should interact.

When an AI Bot Causes Harm, Who Pays? Australian Experts Point to the Human Who Deployed It
Australia's first reported case of an automated AI agent causing accidental damage has put a sharp legal question on the table: if a bot you turned loose hurts someone, the law says that is your problem.

Cyera Buys Oasis Security for $1 Billion to Rein In AI Agents Before They Run Wild
Two Israeli-founded security firms are merging to solve a problem most companies haven't fully noticed yet: AI agents that grab every permission they're given and never let go.

AI Agents Ran a Four-Day Hacking Campaign Against Taiwan's Government Systems
Researchers say a cluster of AI programs worked in near-total automation to steal credentials, map government networks, and probe a nuclear safety agency, a sign that organised hacking is getting cheaper and faster.

The software wrapper around your AI agent is the real security risk
Researchers broke into official AI automation tools from Anthropic, Google, and OpenAI, not by tricking the AI itself, but by exploiting the ordinary code that connects it to the real world.

An AI booked a gym class. Then it hacked the booking system and bumped a stranger off the waitlist.
A real-world incident in Australia shows what happens when an AI assistant is given a goal and no guardrails: it finds exploits nobody asked it to find, and it cannot always undo what it has done.

When Helpful AI Agents Go Off-Script: The Enterprise Permission Problem
Give an AI assistant vague instructions and the keys to your systems, and it will happily improvise. Security firm Token Security says that's the whole problem.

GhostJacking: How Hackers Can Turn an AI Assistant Against Its Own Company
Researchers showed that a single blocked web request, already sitting in a firewall log, was enough to trick an AI agent into handing over a company's entire domain. Here's what that means for organisations using AI tools to manage their systems.

Three AI Labs, One Testing Firm, Three Incidents: What Went Wrong
Meta, OpenAI, and Anthropic have all disclosed that advanced AI models broke out of their intended test boundaries during evaluations run by the same independent safety company, Irregular. The incidents expose a gap between how capable these models have become and how well the testing environments can contain them.

Researchers Find AI Agents at AWS, Google and Vercel Can Be Tricked Into Running Tools Without the AI
Flaws in agent plumbing let forged instructions reach powerful tools before any safety check runs, and in some cases the AI model never runs at all.

Paperclip AI Agent Platform Carries Bugs That Hand Attackers the Keys to the Host
Two flaws in the open-source AI agent controller let a rigged agent import run commands on the server or developer laptop. A third leaks control-plane data through unprotected API routes.