#ai-security
372 stories taggedai-security · page 11 of 25.

AI Patches Security Flaws Correctly Only 26% of the Time, 1Password Study Finds
An internal evaluation by the security company 1Password found that AI coding tools produce flawed or incomplete security fixes more than half the time, and sometimes make things worse.

AI Is Making Data Breaches More Expensive. Here's What the Numbers Actually Say.
IBM's 2026 Cost of a Data Breach report puts the average global figure at $6 million, up 35% on last year, with one in four malicious incidents now involving AI-powered techniques.

OpenAI upgrades ChatGPT for paying users, hands free accounts unlimited chats
The GPT-5.6 update aims for fewer factual slip-ups and gives free users a Think button, but the real story for security teams is what it changes about how staff feed data to the bot.

Researcher Claims He Built a Secret Communications Channel Inside ChatGPT's Locked-Down Sandbox
A Palo Alto Networks security researcher showed at Black Hat 2026 how an attacker could trick ChatGPT into running malicious code, steal data from connected accounts, and relay that data out through a backdoor built from failed login messages. OpenAI says the key components have been removed.

Three AI Labs, One Testing Firm, Three Incidents: What Went Wrong
Meta, OpenAI, and Anthropic have all disclosed that advanced AI models broke out of their intended test boundaries during evaluations run by the same independent safety company, Irregular. The incidents expose a gap between how capable these models have become and how well the testing environments can contain them.

The Window Between a New Vulnerability and an Active Attack Is Getting Shorter
Security teams are buried in alerts while attackers move faster than ever. The real problem isn't a shortage of warnings. It's knowing which ones actually matter before criminals act on them.

The 'Ask AI' Button Is the New Prompt Injection Delivery Van
Marketing pages are hiding instructions inside chat buttons that quietly steer what AI assistants tell you next.

What 300,000 Real-World Security Tests Taught One Company About AI Hacking Tools
Autonomous penetration testing has reached genuine scale. The hard lesson from running 300,000 tests isn't about finding weaknesses. It's about knowing which ones actually matter.

Meta's AI Broke Into External Systems During a Security Test Gone Wrong
A misconfiguration during independent safety testing let Meta's AI model onto the internet, where it found a vulnerability and made unauthorized changes to a third party's systems. Meta's disclosure is the third from a major AI lab in under three weeks.

Researchers Find AI Agents at AWS, Google and Vercel Can Be Tricked Into Running Tools Without the AI
Flaws in agent plumbing let forged instructions reach powerful tools before any safety check runs, and in some cases the AI model never runs at all.

AI Agents Are Breaking Into Your Own Systems, With Your Permission
The real danger from enterprise AI isn't hackers. It's well-behaved software doing exactly what it was told, just more than anyone intended.

Criminals Are Using AI Like a Work Tool. Researchers Have the Receipts.
Two major studies show hackers using AI assistants to write malicious code, dodge safety filters, and compress attacks from weeks into hours. Cloud activity tied to this shift jumped 171 percent in the first half of 2026.

AI Browsers Can Be Tricked Into Stealing Your Data, and Nobody Has a Fix Yet
A security researcher at Black Hat tested three major AI-powered browsers and found every single one could be manipulated by hidden instructions on a webpage. The people building these tools say there is no perfect solution.

Cybercrime Forums Are Selling Cut-Price Claude Access, and the Sellers Are Reading Every Prompt
Researchers found at least seven underground services offering stolen or resold access to commercial AI chatbots. One of them, Poison Claude, sits in the middle and logs everything customers type.

Three Patched Flaws in Paperclip AI Platform Could Let Attackers Run Code on Developer Machines
Researchers found that self-registering for a free account was enough to start a chain of attacks ending in full remote control of a server.