#LLM security
17 stories taggedLLM security.

OWASP Updates Its AI Security Danger List, and the Biggest Threats May Surprise You
The security industry's most-watched ranking of AI software risks has been refreshed with real incident data for the first time. Prompt injection stays at the top, but a newer danger tied to AI agents acting on their own is climbing fast.

A Simple Network Misconfiguration Lets Hackers Quietly Reprogram AI Agents
A flaw in Nvidia's NemoClaw tool means visiting one bad website could hand a stranger permanent control over your AI assistant's instructions, with no warning and no download required.

UAC-0099 Hides a Fake Nuclear Threat in Malware to Break AI Analysis Tools
A Russia-aligned group is stuffing malware with a shock prompt designed to make security analysts' AI assistants refuse to look at the code.

When AI Agents Go Rogue: What the Hugging Face Incident Tells Us About Securing AI Systems
Threat modelling expert Adam Shostack sat down with Dark Reading at Black Hat USA 2026 to discuss OpenAI's findings on AI models that began secretly passing messages during training. His verdict: the real problem isn't the AI. It's the missing guardrails around it.

Your AI Safety Certificate Is Worthless the Moment the Agent Goes Live
Compliance badges on AI products look reassuring. They don't protect you once an autonomous agent starts reading your files, calling your internal systems, and making decisions faster than any human can watch.

Five Major AI Coding Tools Keep Inventing the Same Fake Software Packages
A researcher found 127 made-up package names shared across ChatGPT, Claude, Gemini, and DeepSeek, and 53 of those names are still free for criminals to register today.

Fake Files That Stop Hackers: How 'Context Bombs' Crash AI Attack Agents
A security firm has found a way to halt automated AI attacks by planting decoy text that triggers the safety rules built into AI systems. In tests, AI-driven attack success rates dropped by up to 90%.

A Russian-speaking hacker turned Google's Gemini CLI into his botnet co-pilot
For roughly a year, an attacker chatted with Google's open-source AI tool to run malware on eight computers inside a dental clinic, migrate his servers, and troubleshoot bugs in six minutes flat.

One Poisoned Email Can Rewrite What Your AI Assistant 'Remembers' About You
Researchers show how a single message can plant a false memory in an AI agent's long-term store, quietly steering its answers in every future chat.

AI Agents Can Be Tricked Into Sending Money. Zscaler Has the Data.
A new study shows that some expensive, enterprise-grade AI assistants fall for hidden instructions that most humans would ignore, and the real danger is far bigger than a fake three-dollar fee.

Context Manipulation Attack 'BioShocking' Turns Agentic Browsers Into Credential Thieves
Researchers show how poisoned context fed to AI-driven browser agents causes them to drop safety guardrails and quietly exfiltrate stored credentials.

North Korean Malware Tells AI Analyzers to Look Away
A macOS sample attributed to Pyongyang-linked actors contains prompts designed to make LLM-assisted security tools abandon their analysis. Defenders are starting to notice the pattern.

AI Agents Are Being Manipulated Through the Data They Trust
Hidden content injections and context poisoning are turning autonomous AI pipelines into attack surfaces. What defenders need to understand before deploying agents at scale.

AI-SPM Is Now a Real Category. Here's Why Your Organization Probably Needs It.
More than half of enterprise AI agents run without security oversight or logging. A maturing class of AI security posture management tools exists to fix that, if you know what to look for.

AI Web Agents Have No Reliable Prompt Injection Defenses, Benchmark Finds
Researchers ran 3,168 adversarial tests against GPT-5 and Gemini-powered agents. The 'Robust Behavior' outcome, agent completes task, attacker gets nothing, never appeared.