#ai-security
324 stories taggedai-security · page 20 of 22.

Weekly Recap: Old Tricks, New Victims — Poisoned Packages, a Chatbot Bypass, and a GitHub Worm
A week of loud incidents masked quieter intrusions. The common thread: failures that should have been caught at code review.

Corporate Cyber Readiness Is a Compliance Exercise. The Military Treats It as Combat.
Enterprise incident response still runs on annual tabletops and audit checkboxes. That gap between posture and practice is exactly what attackers count on.

12 Questions That Expose Whether Your Security Program Is Actually Working
A roundup of hard questions CISOs should already be asking — about blast radius, nonhuman identities, and whether 'vibe coding' has eaten your attack surface.

OpenAI Ships ChatGPT 'Lockdown Mode' to Blunt Prompt-Injection Data Theft
The opt-in setting strips connectors and browsing tools that attackers have used to siphon data from logged-in sessions.

Microsoft Expands Its Agentic AI Failure Taxonomy With Seven New Attack Classes
From inter-agent trust escalation to MCP plugin abuse, the updated taxonomy surfaces threat categories that didn't exist — or weren't well-understood — when Microsoft published its first version.

Voluntary AI Security Rules: The Industry Already Knows What That Means
Trump's AI cybersecurity executive order drew polite applause from vendors and quiet skepticism from practitioners. The gap between those two reactions is where the real story lives.

Claude Mythos Preview Reportedly Breached Within Hours, Renewing Agentic AI Risk Questions
An unverified claim of unauthorized access to Anthropic's limited technical preview has defense-sector buyers asking whether agentic models belong on production networks at all.

The Week the Tape Came Off: Old Bugs, Cheap C2, and AI That Breaks Things
A roundup of the criminal-economy churn driving this week's intrusions, from plugin holes to agentic AI gone feral.

Agentic AI Is Doing What a Thousand Breach Reports Couldn't: Getting Boards to Open the Checkbook
Autonomous agents, AI-generated code, and frontier models capable of offensive cyber ops are finally making cybersecurity a board-level business conversation — not just an IT line item.

Trump Signs AI Cybersecurity Order, Reviving the Pre-Release Review Provisions His Team Killed Two Weeks Ago
The new directive creates a voluntary framework for government review of frontier AI models and spins up a Treasury-led vulnerability clearinghouse — while going out of its way to say none of this is mandatory.

AI Has Minted a New Kind of Attacker — One Who Knows Nothing
Generative AI closes the skill gap between vague criminal intent and working malware. Responsible disclosure norms weren't built for that world.

The Patch Window Is Now Measured in Hours
AI-assisted exploit development has collapsed the time between disclosure and mass exploitation. Traditional vulnerability management workflows weren't built for this pace.

Meta's AI Support Bot Handed Out Password Resets to Anyone Who Asked Nicely
A pro-Iran Telegram channel published a walkthrough showing how Instagram's conversational recovery assistant could be talked into linking attacker-controlled email addresses to target accounts. The Obama White House and a senior U.S. Space Force account were briefly defaced.

One Click, Full Shell: Flowise MCP Flaw Scores 9.9 CVSS
A sandboxing failure in Flowise's MCP stdio implementation lets an attacker execute arbitrary OS commands with process-level privileges — and the patches so far don't close the hole.

The Pentagon Wants Battlefield AI. Not Everyone With Stars on Their Collar Agrees.
The White House sees AI as a defining American military edge. Some of the generals and admirals who would actually deploy it aren't so sure.