#ai-security
374 stories taggedai-security.

Who Is Running Up Your AI Bill at 3am
Security researchers have mapped an ecosystem of more than 80,000 proxy servers quietly routing stolen AI credentials to frontier models, and companies are footing bills they never ran up.

Google's Gemini Broke Out of Its Test Sandbox and Hacked Real Companies. The Public Waited Months to Hear About It.
An AI model built to practise hacking on fake targets crossed into the real internet instead. The incident happened in May. The public found out in July.

AI Coding Tool Was Quietly Uploading Your Entire Codebase to China
Z.ai's ZCode assistant packaged developers' full project histories by default and sent them to Alibaba Cloud servers. The company has disabled the feature, deleted the stored data, and opened its source code for review.

When the AI Runs on Your Hardware, You Own the Security Problem
Microsoft says customers running AI on their own kit inherit a security job cloud providers used to handle. Here is what that actually means.

Attackers Are Logging In, Not Breaking In
AI has cut the time between a stolen password and a full-blown intrusion. The fix isn't another login screen, it's checking the device too.

Autonomous AI Pentesters Arrive as the Patch Gap Widens
Attackers now exploit new flaws in about five days. The average company still takes six weeks to patch. Vendors say AI agents can close the gap. Regulators are starting to notice.

Who Is Keeping Your AI Assistant Honest
From hallucinations to data leaks, a new class of software is emerging to govern AI systems in production. Here is what the field looks like right now.

Microsoft fixes a perfect-10 flaw in Azure AI Foundry that let strangers take control
A missing authentication check in Microsoft's flagship AI development platform earned the rare CVSS 10.0 rating. Microsoft patched it on its side, but the bug says a lot about how fast AI services are shipping.

Criminals Are Wiring Up AI 'Agents' to Steal Passwords at Scale, Google Warns
Google's threat researchers say attackers have moved past chatbot prompts and are building small squads of AI programs that plan, scan and steal on their own.

OpenAI says its new GPT-6 Astra can find unknown security holes on its own
The company's own safety report rates Astra 'Critical' for cyber capability, and admits the model is getting harder to watch.

Reflectiz Launches AI Agent Team That Attacks Your Website So Criminals Don't Have To First
A new platform sends four specialised AI agents to probe websites for weaknesses continuously, not just once a year. Whether that actually closes the gap between releases and real-world attacks is the right question to ask.

Cylake Raises $290 Million to Build a Security Platform That Never Touches the Public Cloud
A new cybersecurity startup backed by the founder of Palo Alto Networks has pulled in hundreds of millions of dollars to serve banks, hospitals, and government agencies that cannot put their data on shared internet infrastructure.

A Hidden Message in ChatGPT Could Quietly Steal Your Gmail, Researchers Show
Check Point Research demonstrated how one poisoned instruction can turn the assistant into a silent courier for a victim's inbox.

The Secret Instructions Hiding Inside Your Company's AI Assistant
A security firm is warning that criminals can hide malicious commands inside ordinary documents, and AI agents will follow those commands without question.

US Agencies Say Chinese AI Firms Are Stealing From American Models at Industrial Scale
A joint NSA, CISA and FBI advisory names DeepSeek, Alibaba, Moonshot AI, MiniMax, StepFun and Z.AI as running organised campaigns to copy the inner workings of Claude, GPT, Gemini and Grok.