Tag

#ai-security

325 stories taggedai-security · page 16 of 22.

AI Security

DeepSeek Spits Out Working Browser-Native Ransomware for Windows and Android

Researchers say a frontier model stitched together a real Chromium capability with fantasy malware ideas and produced something that actually encrypts files from inside a tab.

3 min read
AI Security

Cutting Through the AI Noise: What Enterprises Should Actually Be Asking Security Vendors

Marketing copy is cheap. Measurable detection capability is not. Here's how to stress-test an AI security pitch before you sign anything.

2 min read
Threat Intelligence

Phantom Squatting: When Attackers Camp on the Domains LLMs Hallucinate

Unit 42 documents a pre-positioning tactic where actors register non-existent domains that chatbots keep suggesting, then wait for the traffic to arrive.

2 min read
AI Security

Poisoned Tool Descriptions Turn Helpful AI Agents Into Quiet Exfiltration Channels

Microsoft Incident Response demonstrates how a single malicious MCP-style tool description can coax an agent into leaking corporate data — without tripping a single policy check.

3 min read
Vulnerabilities

Langflow RCE Is Back on the Menu — This Time for a Monero Miner

Attackers are still pillaging exposed Langflow instances through CVE-2026-33017, turning forgotten AI workflow servers into XMR mining rigs.

3 min read
AI Security

Two-Thirds of iPhone AI Chatbot Apps Are Bleeding API Keys

A study of 444 iOS chatbot apps found 282 exposing paid model access in plaintext network traffic — sometimes with no authentication at all.

3 min read
AI Security

The Hidden Cost of Agentic AI in Security: Token Budgets Are Now a Defense Problem

Cybersecurity platforms are racing to embed agentic AI, but the economics of token consumption, AI credits, and deployment architecture may undercut the value before defenders see a return.

2 min read
AI Security

BioShocking: Prompt-Game Trick Pries Credentials From AI Browsers

Researchers at LayerX got six AI browsers and assistants — including ChatGPT Atlas, Perplexity's Comet, and Anthropic's Claude extension — to exfiltrate user logins by framing the attack as a game.

3 min read
Vulnerabilities

Amazon Patches CVE-2026-12957 in Q Developer: Malicious Repo Could Drain AWS Credentials via MCP

A workspace-trust prompt was all that stood between a developer and credential theft. Amazon has shipped a fix for the high-severity flaw in its AI coding assistant.

2 min read
AI Security

Frontier AI Is a Pressure Test, Not a New Threat Model

The arrival of capable AI models like Mythos changes attacker economics. It doesn't change which controls actually matter — and most organizations are still failing the old ones.

3 min read
AI Security

MCP's Enterprise Overhaul Hands Security Problems to Developers

A major revision to the Model Context Protocol repositions itself as enterprise-ready — then quietly offloads the hard security work onto the teams building on top of it.

3 min read
AI Security

Gaslight: A Rust macOS Stealer That Tries to Talk Your AI Analyst Out of Looking

The implant ships with an embedded prompt injection payload aimed at LLM-assisted reverse engineering tools — a small but telling escalation in adversarial UX.

3 min read
AI Security

CIOs Are Running AI Governance Without a Playbook — and the Clock Is Running

Boards want AI returns. Employees want access. Compliance teams want guardrails. The CIO is stuck in the middle of all three.

3 min read
AI Security

AIVEX Triage Model Targets Software Supply Chain Risk in AI Environments

A new framework aims to help security teams prioritize which supply chain vulnerabilities carry the highest operational, safety, and business risk where AI systems are in play.

2 min read
AI Security

Fake AI Agent Skill Exploits Security Gaps, Reaches 26,000 Users

A malicious AI agent skill bypassed security checks, exposing potential risks in enterprise environments.

2 min read
© 2026 Threat Vectr