#ai-security
371 stories taggedai-security · page 21 of 25.

A trick in six AI coding helpers lets a poisoned project hijack your laptop
Researchers at Wiz found that popular AI coding assistants, including Amazon Q Developer and Claude Code, can be fooled into writing to sensitive files while asking permission for a harmless one.

When your AI coder looks exactly like a hacker to the security software
Sophos found that popular AI coding assistants keep tripping the same alarms designed to spot break-ins, and the false alerts are piling up.

HalluSquatting: When AI Coding Helpers Invent Fake Software, Criminals Register It First
Researchers show how attackers can predict the fake package names AI assistants make up, then publish real malware under those names, waiting for developers to install the trap.

When the Help Desk Becomes the Front Door: AI-Assisted Social Engineering Hits Onboarding
IBM's 2025 breach data puts AI-assisted attacks at 16% of cases studied. A growing share of those start with a phone call to the service desk, and new-hire onboarding is where defences are thinnest.

US cyber agency gives federal staff four days to patch Langflow AI tool being actively hacked
CISA added an authorisation bypass in the popular AI-agent builder Langflow to its must-patch list after Sysdig spotted attackers stealing cloud keys and hijacking servers.

A Hidden Command in a GitHub Issue Can Silently Steal a Company's Private Code
Researchers found a flaw in GitHub's AI automation tool that lets an outsider read an organisation's private repositories by hiding plain-English instructions inside a public bug report.

Federal Cyber Agency Reportedly Turning to AI to Hunt for Weaknesses in Government Software
CISA's specialist team is said to be using Anthropic's Mythos tool to scan federal systems for security flaws, in what could become a significant shift in how the U.S. government checks its own digital defenses.

When AI writes your code, your supply chain just got a new stranger in it
For years, defenders worried about which open-source parts sat inside their software. Now an AI assistant is quietly adding parts of its own, and nobody is quite sure who owns the risk.

Keyfactor Raises Over $1 Billion to Tackle AI and Post-Quantum Security
The investment backs technology that manages digital certificates and cryptographic keys, as companies race to prepare for a generation of threats that today's encryption may not survive.

AI Agents Need Passports, Not Passwords
Companies are handing more decisions to autonomous AI agents, and the old rules about who gets access to what are breaking down. Here is what needs to change.

AI Is Making Decisions at Work. Most Companies Have No Rules for That.
Stephen Wilson, field CTO at HashiCorp, says businesses are giving AI tools real operational independence while still applying the loose oversight they used when AI only answered questions.

AI Writes Code Faster Than Anyone Can Check It. That's the Problem.
Machine-generated code is flooding into production with fewer human eyes on it. Defenders are being asked to catch what nobody wrote by hand.

The Weak Link This Week Wasn't Code. It Was Trust.
From home streaming boxes turned into criminal relays to AI assistants tricked by hidden instructions, this week's incidents share one root cause: systems trusting the wrong thing.

Hackers Are Hiding Instructions Inside Websites to Make AI Assistants Send Crypto Payments
Two newly discovered attack campaigns show how criminals can secretly hijack AI browsing agents by planting hidden commands in ordinary-looking web pages.

The Cybersecurity Skills Gap Is Real. But We're Measuring the Wrong Thing.
Companies keep buying courses and certifications. Breaches keep happening anyway. The problem is not a shortage of trained people. It is a shortage of people who have actually practised under fire.