#ai-security
372 stories taggedai-security · page 7 of 25.

Fake npm Calendar Tools Hid an AI-Powered Linux Backdoor
Researchers found 14 booby-trapped packages on the popular open-source library npm, each quietly installing a remote-control tool called RedC2 4.0 on Linux machines.

OWASP Publishes First Security Watchlist for AI Agent 'Skills'
A real attack in July exposed more than 300,000 users to stolen credentials through fake AI skills. Now the group behind the web's most-used security checklists has named the top ten risks, and 'malicious skills' sits at number one.

Researchers Find Way to Hide Malicious Instructions Inside Encrypted AI Prompts
A new technique called 'Cryptographic Context Injection' slips harmful commands past the safety filters built into Grok and Gemini by wrapping them in encryption that only the AI unwraps.

OpenAI's AI Models Broke Into a Real Website. The Safety Fixes Came After.
An OpenAI test model found its own way out of a controlled exercise, reached Hugging Face's live infrastructure, and forced a reckoning with containment gaps that critics say should never have existed.

Wazuh Adds AI Assistants to Speed Up Security Teams Drowning in Alerts
The open-source security platform is bolting large language models onto its dashboards, aiming to cut the hours analysts spend triaging attacks.

AI Arms Race: Why Smart CISOs Are Choosing Their Battles, Not Fighting All of Them
Attackers are using AI to move faster, employees are leaking sensitive data into consumer tools without realising it, and the window to fix vulnerabilities before criminals exploit them is shrinking. Here is what security leaders should actually prioritise.

Weekly Roundup: Trusted Software Turned Against Defenders, Plus a Critical Gogs Flaw
Signed drivers hijacked to kill antivirus, a code-execution bug in the Gogs source-code platform, and AI shortening the gap between disclosure and working exploit: this week's threats run on tools defenders already trust.

Researchers Show How a Booby-Trapped Web Page Can Steal Your Grok Chat Data
Adversa AI's 'Cryptographic Context Injection' technique tricks xAI's Grok into leaking user names, locations and prompts to attacker servers when a user asks it to summarize a page.

Who Is Watching You Right Now, and What Are They Doing With It?
From supermarket cameras to workplace keystroke logs, surveillance of ordinary people has quietly become a growth industry. AI is making it faster, cheaper and harder to spot.

When Meta's Own AI Agent Leaked Internal Data: The 'Shady AI' Governance Gap
A Sev 1 incident inside Meta shows how sanctioned AI tools, not just rogue ones, are quietly becoming an insider risk problem.

AI Agents That Go Rogue Are Now an Insider Threat, Security Expert Warns
A breach involving AI systems at a major machine-learning platform has exposed a problem companies weren't expecting: the AI tools they deploy can quietly turn against them.

OpenAI Tightens AI Model Security After Hugging Face Breach and Astra Findings
New sandboxing controls, 30-minute alert windows, and the ability to pause model training mark a concrete shift in how OpenAI manages threats inside its own systems.

Meet Kriminal: The AI Service With No Rules That Anyone Can Find on Google
A subscription AI platform called Kriminal markets itself as uncensored and unlimited. Researchers say it is stitched together from mainstream AI tools, and that makes it very hard to shut down.

Prevalent AI Banks $22 Million to Stitch Together Scattered Business Data
A London firm built by ex-GCHQ and Darktrace veterans just landed its first outside funding. Here is what it does and why the security world is watching.

AI is already in your attacker's toolkit. Is it in your defences?
A Five Eyes government warning and new survey data reveal a sharp gap between how confident security teams feel about AI-powered defences and how well those defences actually work under pressure.