#LLM
12 stories taggedLLM.

Browsing a Model Was Enough. The 'trust_remote_code' Flaw That Won't Go Away
A bug in Unsloth Studio ran malicious code before a model ever loaded. It's the fourth time this year the same one-line AI setting has opened the door.

CLOSEDQUORUM Runs Its Own Attack Without Asking Anyone
Cisco Talos has identified what it calls the first fully autonomous command-and-control implant: malware that polls a panel of AI models to decide its next move and never checks back with its operator.

Hidden Text in Emails Can Trick AI Assistants Into Showing You Fake Numbers
Researchers planted invisible instructions inside ordinary emails and watched an AI summariser rewrite invoice amounts and meeting dates without any warning to the reader.

Your AI email assistant can be fed a fake message while you read a real one
Researchers hid nearly 500 characters of secret instructions inside an ordinary-looking email. The AI summariser obeyed them every single time.

A 15-Minute Framework for Spotting What AI Systems Can Do Wrong
Security expert Adam Shostack built PHANTOM-B to help organisations find the risks hiding inside AI-powered software before those risks find them.

AI is getting better at breaking software than fixing it
Multiple studies show AI tools write insecure code nearly as often as they did a year ago, even as those same tools grow sharper at finding and exploiting the very flaws they leave behind.

AI Patches Security Flaws Correctly Only 26% of the Time, 1Password Study Finds
An internal evaluation by the security company 1Password found that AI coding tools produce flawed or incomplete security fixes more than half the time, and sometimes make things worse.

The 'Ask AI' Button Is the New Prompt Injection Delivery Van
Marketing pages are hiding instructions inside chat buttons that quietly steer what AI assistants tell you next.

AI Security Bots Are Great at Hacking. Terrible at Defence. Researchers Are Trying to Fix That.
A cybersecurity startup found that AI agents built to stop attacks were, in their own words, 'sh*t' at the job. Here is why that gap exists, and what they are doing about it.

AI Coding Tools Carry Real Security Risks, and the Danger Depends on What You're Building With
A new study tested 16 major AI coding assistants and found an average of 15 security flaws per project. The safest choice for one type of software can be one of the worst for another.

Intruder's AI 'vulnerability vending machine' finds a WordPress zero-day on its own
A security firm wired large language models into code-analysis tools and produced a working exploit for an unknown plugin flaw. It says more disclosures are on the way.

An AI Agent Broke Into a Server, Taught Itself to Adapt, and Left a Ransom Note
Security firm Sysdig says it has documented the first fully autonomous AI-driven ransomware attack, where a program called JadePuffer broke into a database, encrypted thousands of records, and demanded Bitcoin payment without a human criminal directing any step.