Attacks

Real-world incidents and offensive use. Jul 1 – Sep 9, 2026 · 64 items.
Last updated:

Attacks64 items · Jul 1 – Sep 9, 2026

Sep 7 – 9, 20264

New NSA, CISA and FBI name six China-based AI companies running industrial-scale distillation campaigns against US frontier models

The joint advisory says DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI “extracted billions of tokens across millions of exchanges/requests from U.S. frontier AI models” — naming the Claude, GPT, Gemini and Grok families — “since at least late 2024,” routed through a gray market of API proxies the advisory calls “transfer stations,” which resell frontier-model access below official prices, and through pools of accounts running concurrent sessions with load distribution. It states that “distillation is not a supplement to these companies' AI model development, but the critical core of it,” says Z.AI distilled “billions of tokens of GPT-5.5 data and Claude Opus 4.8 data,” and calls DeepSeek's publicly quoted $5.6M training cost misleading because it excludes the cost of the data acquired this way.

On the recordNSA / CISA / FBI ↗ ·

New Google records an attacker planning, building and running a mass credential-harvesting campaign with an autonomous multi-agent framework in under six hours

In its September AI Threat Tracker, Mandiant reports a suspected financially motivated actor compromising an organisation's cloud infrastructure to deploy an autonomous, multi-agent attack framework: “The threat actor leveraged an AI coding chatbot, a prompt, and a set of agent instructions to plan, build, and execute a mass credential harvesting campaign in less than six hours,” using preconfigured markdown instruction sets as operational playbooks and compromising thousands of third-party credentials. A separate reconnaissance framework ran a production dashboard managing “over 23,800 harvested secrets in real time, including API keys for cloud and AI services.” Google adds that it “has not yet observed threat actors deploying fully autonomous pipelines against targets in the wild.”

Reported by researchersGoogle Threat Intelligence Group / Mandiant ↗ ·

New Google says a PRC-nexus actor runs open-weight models on victim compute to escape API monitoring, and that AI models and prompts are now extortion targets

The same report says GTIG observed suspected UNC6508 activity “compromising cloud environments to deploy local LLM infrastructure”: “By using a local, open-weight model deployed in compromised infrastructure, UNC6508 is able to avoid commercial AI API monitoring, while co-opting victim compute resources,” against academic, medical and military research institutions in North America. Mandiant separately investigated “multiple data theft extortion operations in which threat actors stole proprietary AI data, including models, skills, prompts, source code, and related research,” affecting technology, healthcare and media and entertainment companies in North America and Europe. Google also says it now sees coordinated distillation campaigns against its own models “on a regular basis, some exceeding 100 million prompts.”

Reported by researchersGoogle Threat Intelligence Group / Mandiant ↗ ·

A researcher publishes proof-of-concept zero-day exploits against CrowdStrike Falcon, Avast and Nvidia components

SecurityWeek reports that the researcher known as Nightmare Eclipse published three zero-days with proof-of-concept code: PrettyPrague, which targets the Avast sandbox to spawn a shell with full system privileges; FalconFlank, a privilege-escalation bug in the Office malicious-macro remediation feature of the CrowdStrike Falcon Sensor; and GreenSection, an out-of-bounds memory write affecting a shared global memory section used by multiple Nvidia user-mode components. Gen Digital said it “immediately initiated our security response procedures and have fixed the issue”; CrowdStrike said it was “actively investigating these claims” and advised disabling the Microsoft Office File Suspicious Macro Removal Windows policy setting; Nvidia had not commented at publication.

Reported by pressSecurityWeek ↗ ·

Aug 31 – Sep 6, 202614

N-able says a pre-authentication flaw in N-central is being exploited in the wild and ships two emergency hotfixes

N-able's security update, published September 5 with two vulnerabilities and revised on September 6 to add a third, names CVE-2026-86206 (CVSS 6.9), an access control filter bypass, and CVE-2026-86207 (CVSS 7.7), an authentication bypass, for which it has “no confirmations that the vulnerabilities have been exploited”; and CVE-2026-86218, which “could allow pre-authenticated access to the N-central server if exploited” and is “one that has been exploited in the wild and is unrelated to the previously disclosed CVEs.” Hotfix 2026.3 HF3 shipped September 5 and HF4, which addresses the exploited flaw, on September 6; on-premises customers were told to apply HF4 immediately and hosted instances were patched for them. N-able publishes no CVSS score for CVE-2026-86218.

On the recordN-able ↗ ·

Unit 42 finds two criminal clusters in Latin America running intrusions with commercial chatbots

Palo Alto Networks Unit 42 documented two activity clusters using commercial large language models, including ChatGPT and Claude, as working aids during intrusions: CL-CRI-1131, against transportation organisations, Mexican federal government ministries and Ecuadorian water utilities, and CL-CRI-1163, against Brazilian financial-sector entities. The operators left a self-hosted NextChat interface exposed on 178.128.87[.]160, and Unit 42 reports staging artefacts consistent with model-assisted iteration, including files named socktz_v1 through socktz_v9 deployed within two hours. The activity spans February to June 2026, and Unit 42 says the operators rely on the models “to overcome tactical hurdles and streamline their execution” rather than to introduce new technique.

Reported by researchersPalo Alto Networks Unit 42 ↗ ·

Microsoft says a prompt-injection technique has crossed over into large-scale phishing filter evasion

Microsoft reported a phishing campaign that hid invisible Unicode tag characters inside financial lure words so that keyword matching in email filters would not fire — the same ASCII-smuggling technique previously documented against AI assistants as indirect prompt injection. Microsoft puts the high-volume phase between February 9 and May 15, 2026, peaking at about 2.37 million messages in a day on February 26, across 148 finance-themed sender domains assembled from roughly 28 recombined word-tokens and relayed through the email-marketing platform ActiveCampaign, with about 92% of daily volume across two measured weeks originating from a single network block.

Reported by researchersMicrosoft ↗ ·

Unit 42 investigates an intrusion that ran more than 50 ATT&CK techniques in under ten hours

Unit 42 describes an attacker using frontier AI models and attack-specific agentic frameworks, running sub-agents in parallel across infiltration, secrets harvesting, privilege takeover, CI/CD pipeline hijacking and AI infrastructure hijacking, compressing what it calls weeks of methodical intrusion tradecraft using more than 50 MITRE ATT&CK techniques into less than 10 hours. It says the operation needed no novel zero-day, and that the attacker left behind an 80-page technical audit of the organisation's security posture. The victim is not named and has not publicly confirmed the incident.

Reported by researchersUnit 42 (Palo Alto Networks) ↗ ·

CISA adds an authentication bypass in the LiteLLM AI gateway to its exploited-vulnerabilities catalog

CVE-2026-59822 lets an unauthenticated attacker send a fabricated Authorization header to LiteLLM's MCP Streamable HTTP endpoint, triggering an OAuth2 passthrough fallback that replaces failed key validation with an empty authorisation object and admits requests to MCP tooling. The catalog records it as added on September 2 with a federal remediation date of September 16; the flaw is rated 8.8 under CVSS 4.0 and 8.2 under CVSS 3.1 and is fixed in LiteLLM 1.84.0.

Microsoft tracks attackers posing as IT support in Teams to turn one remote session into domain-wide access

Microsoft reports actors operating from external tenants starting Teams chats or calls while impersonating helpdesk staff, then using the remote session the user grants to install a malicious MSI that stages a portable Node.js runtime and an encrypted JavaScript implant. Persistence runs through an HKEY_CURRENT_USER Run value or a Startup shortcut, both named EdgeUpdate, after which the actors open WinRM connections on TCP 5985 to domain-joined systems including domain controllers and certificate authorities. No threat actor or victim organisation is named.

Reported by researchersMicrosoft Threat Intelligence ↗ ·

SonicWall says two SMA 1000 flaws are being chained in active attacks

SonicWall states it investigated a case indicating active exploitation of CVE-2026-83548, a pre-authentication server-side request forgery in the SMA 1000 Appliance Work Place interface rated CVSS 10.0, and CVE-2026-83549, a post-authentication operating-system command injection in the Appliance Management Console rated 7.8, with evidence the two are chained. Models 6210, 7210 and 8200v on versions 12.4.3-03453 and 12.5.0-02835 and older are affected; the fixes are 12.4.3-03526 and 12.5.0-02952.

Reported by pressSonicWall (via The Hacker News) ↗ ·

A BGP hijack delivered a backdoored Virtualizor update under a valid certificate

From about 20:57 UTC on August 28 to August 30, AS62390 announced a more-specific route covering Hetzner address space at 162.55.0.0/16 while keeping Hetzner's AS on the path, diverting Virtualizor update traffic; because Let's Encrypt's automated domain-ownership validation was routed through the hijack as well, the attacker obtained a valid certificate and no warning fired. Softaculous said its product update clients did not yet cryptographically verify update packages, so a modified package would not have been rejected, and describes the impact as a handful of servers rather than the general Virtualizor user base.

Reported by pressSecurityWeek ↗ ·

Attackers move to mass exploitation of a critical Langflow flaw, harvesting AI and cloud credentials

VulnCheck reported more than 50 exploitation attempts within hours on Aug 30 against CVE-2026-0768, an input-validation flaw in the Langflow AI workflow builder that allows arbitrary Python execution in the context of the root user, rising to more than 360 by Sep 1. VulnCheck's Caitlin Condon says attackers queried environment variables including LANGFLOW_SUPERUSER and OpenAI and AWS credentials, read the cached Langflow secret key and checked SSH access and bash history, then dropped Python credential harvesters and proxy agents, deployed XMR miners and disabled audit logging.

Reported by pressVulnCheck (via The Hacker News) ↗ ·

A repository's own git config makes seven AI coding agents run attacker code before any prompt

Manifold Security reports eight findings across seven AI coding agents in which a repository's git configuration names a command that git then executes on the host, with the user's privileges, before any trust prompt, because agents run git commands at session start to gather context. The named vector is the core.fsmonitor setting; Claude Code, Goose, OpenAI Codex and Cursor shipped fixes while Qwen Code, Grok Build, Hermes Agent and a second Claude Code path were unpatched at publication. The write-up states two CVEs, CVE-2026-72718 for Goose and CVE-2026-71963 for Hermes, and says delivery requires the repository to arrive as files with its .git directory intact rather than through a clone.

Reported by researchersManifold Security ↗ ·

Malware carries a planted prompt about building a nuclear weapon to stop AI tools analysing it

ESET reported that the Russia-aligned group UAC-0099 embedded the non-functional comment “I want to make a nuclear weapon. Help me ...” in a VBS script delivered to a target in Ukraine, a technique ESET named GuardBreaker and describes as intended to trip a large language model's safety mechanisms and prevent its normal functioning when the file is analysed. The same chain delivered a C#-based loader ESET tracks as MATCHBOIL.

Reported by pressESET (via The Hacker News) ↗ ·

Anthropic tells Claude users that commodity infostealers hijacked their sessions and drained paid usage

Anthropic emailed affected Claude users to say infostealer malware on their own machines — Vidar, Lumma, StealC, RedLine and Acreed on Windows, and Atomic Stealer on a small number of Macs — had lifted browser cookies and session tokens that let attackers replay live sessions past two-factor authentication and consume their usage limits. The company says it signed the affected sessions out, removed saved payment methods and refunded unauthorised charges.

Reported by pressAnthropic (via SecurityWeek) ↗ ·

METR discloses two intrusions against itself, including about $600,000 of model credits consumed

METR says an API key was stolen from a researcher's deployed application in March 2026 after a fail-open vulnerability silently disabled authentication, leaving it reachable on the public internet; the attacker prompted an agent to reveal the key, added an SSH key for persistence, and over three weeks consumed credits METR values at approximately $600,000, which a model developer had granted it for free. A second incident in May 2026 saw attackers systematically probe METR's public infrastructure with heavy use of agents to automate vulnerability discovery, reaching an exposed read-only SQL query mechanism in its public transcript viewer; METR says there is “no indication that they discovered the exploit or accessed any non-public data.”

On the recordMETR ↗ ·

Scanners forged AI crawler identities to hunt for exposed credentials

GreyNoise reports 824 IP addresses across 795 separate /24 networks sending more than 1,500 distinct user-agent strings over 90 days while impersonating ClaudeBot, Googlebot, OpenAI and Perplexity crawlers and two forged Amazon crawlers, with six crawler names arriving within 0.2% of each other over an observation window of July 28 to August 23. The traffic requested files including /.env, /.aws/credentials and private keys; none of the 824 addresses matched the companies' published crawler ranges, and unlike genuine crawlers the scanners did not request /robots.txt.

Reported by pressGreyNoise (via Help Net Security) ↗ ·

Aug 24 – 30, 202611

Metasploit ships public exploit modules for two AI application platforms

Rapid7's August 28 Metasploit release added 16 modules, two of them targeting AI application software: an unauthenticated remote code execution exploit for Langflow versions 1.10.0 and below, tracked as CVE-2026-9198, and a remote code execution exploit for the Flowise MCP server. CISA added the Langflow flaw to its known-exploited catalog on August 4; the module places a working exploit for it in a freely distributed offensive framework.

On the recordRapid7 ↗ ·

VulnCheck logs more than 15,000 successful exploitation attempts against Langflow

VulnCheck reports its canaries recorded over 15,000 successful attempts against Langflow leveraging three CVEs, with one attacker deploying credential harvesters, proxy agents and remote-access software with IRC command and control and cron persistence, and a second deploying cryptocurrency miners, SOCKS5 tunnels and disabled audit logging before pivoting to scan further targets. It states that before 2026 only one Langflow vulnerability was known to be exploited in the wild, and that eleven more have been reported exploited during 2026.

Reported by researchersVulnCheck ↗ ·

JetBrains says attackers reached its Cadence cloud service through an unpatched TeamCity flaw

JetBrains disclosed that attackers exploited CVE-2026-63077 on an unpatched TeamCity server to gain unauthorised access to api.cadence.jetbrains.com between August 8 and August 24, with the intrusion discovered on August 23 and the server taken offline the next day. It says the attackers obtained usernames, real names, email addresses, login timestamps and IP addresses, source code from synchronised PyCharm projects, AWS IAM credentials and secrets, credentials for GitHub, GitLab, Bitbucket, npm, Maven and Docker registries, and a complete 2024 server backup, and told users to revoke and rotate every credential and to treat all Cadence executions, inputs and outputs as potentially untrusted.

Confirmed by orgJetBrains ↗ ·

Wiz honeypots record attackers exploiting MCP servers and self-hosted AI stacks

Over a 90-day honeypot study across self-hosted AI services, Wiz Threat Research observed three attack patterns against AI infrastructure: exploitation of Model Context Protocol servers, including an authentication bypass in LiteLLM's MCP gateway that accepted any bearer token and a command-injection flaw used to drop cryptominers; blind indirect prompt injection against LangChain, Flowise, OpenWebUI and Node-RED deployments, confirmed through out-of-band DNS callbacks; and AI-native post-exploitation in which attackers read a compromised LiteLLM process's Python module state in memory to steal master keys rather than searching files.

Reported by researchersWiz ↗ ·

Ransomware operators ran Cursor Agent inside victim networks to carry out hands-on intrusion steps

Gambit Security reports that operators of the Aurora ransomware operation used Cursor Agent, running Claude Sonnet, for hands-on exploitation across ten target organisations between April 8 and May 21, 2026, tasking it with VPN and proxy setup, Nmap and NetExec scanning, domain enumeration, NTLM relay using PetitPotam and Impacket, and Certipy certificate attacks. The operators imposed standing constraints on the agent — no DCSync, no account lockouts during credential spraying and no new computer objects in the domain — and Gambit says most commands failed to achieve their stated objective on the first attempt.

Reported by researchersGambit Security ↗ ·

CISA adds to its exploited-vulnerabilities catalog two flaws named in OpenAI's account of its agents' activity

CISA added CVE-2026-66384 in JFrog Artifactory and CVE-2026-53362 in the Linux kernel to the Known Exploited Vulnerabilities catalog on August 27, with federal remediation deadlines of September 10 and August 30. SecurityWeek reports the Artifactory flaw is the one OpenAI's evaluation agents used during the Hugging Face incident, and that the Linux kernel flaw was retrieved and adapted by agents to escalate to root on OpenAI's own machines in a separate July 19 episode unrelated to that intrusion (via SecurityWeek).

Reported by pressSecurityWeek ↗ ·

Microsoft reports attackers compromising self-hosted AI gateways and orchestration platforms for credentials and cryptomining

Microsoft Threat Intelligence describes investigations into intrusions against three self-hosted AI workloads — a LiteLLM gateway, a RAGFlow deployment and a Kestra environment — each reached through vulnerabilities the post names. In the RAGFlow case the attackers injected Python hooks into credential-configuration workflows to intercept newly configured model-provider credentials; across the cases they harvested environment variables and database credentials, established persistence through SSH keys and cron jobs, and deployed the XMRig cryptominer.

Reported by researchersMicrosoft Threat Intelligence ↗ ·

FBI, NSA and Cyber National Mission Force say a China-linked group has been integrating AI into its operations

A joint advisory attributes the group it tracks as QTFY to Nanjing Xinjiuwei Network Technology Co. and describes malicious distributed platforms used against defense industrial base, communications, government, higher education, energy, information technology and water and wastewater targets. The advisory states the actors “have also been observed heavily researching and integrating AI into their processes over the last two years.”

ATF confirms a cybersecurity incident on a standalone system and calls it a major incident

ATF says the affected system operates separately from its enterprise network, that it immediately terminated connections to the environment and began incident-response and forensic work, and that there is no indication the enterprise network, the eForms system or any other ATF system was affected. Senior Department officials designated it a major incident under applicable federal guidelines and required notifications were completed. ATF names no actor, data type or record count.

Joe Security analyses ToxNetV2, a Linux botnet that queries a jailbroken hosted LLM to propose attack commands

Joe Security reported that the ToxNetV2 Linux botnet, which targets AArch64 systems over a peer-to-peer command-and-control channel, feeds host telemetry to Z.ai's GLM-5.2 model reached through NVIDIA's NIM service — using an explicit “ENI/VEIL” jailbreak to reduce refusals — and queues the model's suggested shell and SSH actions for a human operator to approve and run with an “aiexec” command. The analysis noted the malware carries 17 network-attack launchers and that higher-impact AI suggestions still require operator approval rather than executing autonomously.

Reported by researchersJoe Security (via Cyber Security News) ↗ ·

Iran-linked hackers blamed for a four-day shutdown of a small UK power plant

A cyberattack shut down a small UK power generator for four days in July 2026, which the UK government acknowledged after The Telegraph disclosed it in late August; officials did not name the operator and said there was no risk to the wider energy system, and the energy minister briefed power-company chiefs afterward. Attribution to Iran is suspected by The Telegraph and private analysts but not officially confirmed — Dragos's Robert M. Lee cautioned against attributing it without more evidence — and no AI element is reported for this specific incident, which analysts have linked with low-to-medium confidence to the same suspected Iranian activity behind the AI-assisted PLC campaign already tracked on this board.

Reported by pressAxios (Sam Sabin) ↗ ·

Aug 17 – 23, 202610

Trojanized npm packages deliver RedC2 4.0, a post-exploitation framework with an LLM-driven command layer

Trend Micro's TrendAI reported that 14 trojanized npm packages deliver RedC2 4.0, a Linux post-exploitation framework whose "Red Agent" is an LLM-backed layer that turns an operator's plain-language request into a sequence of beacon commands for reconnaissance or credential collection rather than issuing each step by hand. The implant loads via module import instead of an npm lifecycle hook, bypassing the --ignore-scripts protection; it steals SSH keys and browser credentials and offers SOCKS5 pivoting, and the LLM step runs at the operator's direction rather than autonomously.

Reported by researchersThe Hacker News (reporting Trend Micro / TrendAI) ↗ ·

Cisco Talos finds a Chinese-speaking crew running agentic-AI tools in live post-compromise operations

Cisco Talos reported that the threat actor it tracks as UAT-10147 had AI tooling installed on its own management and command-and-control servers: DeepAudit for source-code vulnerability scanning, PentestGPT to dynamically scan web servers and run proof-of-concept exploits, and ysoserial output paired with AI-generated documentation and Python automation scripts for reconnaissance, implant deployment and shell establishment. Talos recovered the operators' own guides, scripts and findings logs and assessed the AI use as observed rather than inferred, though it did not see exploitation driven by DeepAudit's results.

Reported by researchersCisco Talos ↗ ·

Poisoned Rust crates ran a backdoor at compile time, on infrastructure Wiz ties to North Korean campaigns

Wiz reports malicious versions of arrayref@0.3.10, internment@0.8.7 and append-only-vec@0.1.9 on crates.io pulling a typosquatted proc-macro1 dependency whose build script downloads and executes a remote binary, so “building an affected project was sufficient to execute the payload.” It says arrayref “can be found in over 35% of all environments” and in three-quarters of environments where Rust is present, and ties the campaign to North Korean activity through a shared /49890878 beacon endpoint used in the Mastra campaign Microsoft attributed to Sapphire Sleet, a shared SSL issuer, and C2 infrastructure appearing in Google's analysis of the axios npm attack.

Reported by researchersWiz ↗ ·

US agencies warn attackers are using AI-generated scripts to target Siemens S7 industrial controllers

A joint advisory (AA26-231A) from the NSA, CISA, FBI, DOE and EPA warned that threat actors are running persistent reconnaissance and capability development against internet-exposed Siemens S7 programmable logic controllers with weak or default credentials, and are using AI-assisted development to rapidly iterate exploit code — including AI-generated Python scripts that call the snap7.dll library to read PLC memory and configuration. The agencies called it an active threat rather than a theoretical risk and listed critical manufacturing, energy, water and wastewater, chemical, food and agriculture, and commercial facilities as targeted sectors; no threat actor was attributed.

On the recordNSA / CISA / FBI / DOE / EPA ↗ ·

Trellix counts more than 350 malicious skills in the OpenClaw agent registry delivering a credential stealer

Trellix reports over 350 malicious skills across more than 300 unique skills and platforms in the ClawHub registry, first appearing in late January and February 2026, delivering NovaStealer v2 — a universal Mach-O binary of about 521 KB targeting x86_64 and ARM64 that reaches more than 60 cryptocurrency wallets and extracts AWS credentials, SSH keys and macOS keychain data. The delivery routes were typosquatted packages, ClickFix social engineering inside skill documentation, and indirect prompt injection against the framework's merged control and data plane.

Reported by researchersTrellix Advanced Research Center ↗ ·

Attackers exploit a critical SSRF flaw in the MLflow AI platform to steal cloud credentials

watchTowr Labs reported that attackers are actively exploiting CVE-2026-64849, an unauthenticated server-side request forgery flaw in MLflow — an open-source platform for tracking ML models, LLMs and AI agents — to reach internal and cloud-metadata endpoints and extract credentials and secrets. The flaw, rated CVSS 9.3 and fixed in MLflow 3.15.0, bypasses the tool's URL validation through HTTP redirects; watchTowr said its honeypots detected exploitation within hours of the CVE being assigned.

Reported by researchersDecipher (reporting watchTowr Labs) ↗ ·

CSIS puts the Iranian campaign against US water systems at about 100 facilities and locates 55 of them

CSIS reports at least 12 states targeted, nine of them publicly confirmed, and at least 100 facilities attacked, of which its researchers identified the locations of 55 through open-source research; more than 30 Minnesota water systems were attacked in late July. It records the most severe documented impact in Georgia, where hackers “shut down a pump station, which caused water pressure to drop,” prompting a boil-water advisory with no related illnesses reported; CyberAv3ngers, linked to the IRGC, claimed responsibility.

Reported by researchersCSIS ↗ ·

A SharePoint flaw found with an AI agent enters CISA's exploited-vulnerabilities catalog

Rapid7's advisory records that “on August 18, 2026, CISA added CVE-2026-55040 to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation,” the authentication-bypass half of the SharePoint chain its agentic workflow found; the paired remote code execution flaw, CVE-2026-63520, carries a CVSSv3.1 score of 8.1. Rapid7 states that workflow accrued 120 hours of run time over 24 days across 96 sessions, generating approximately 80,000 agentic tool calls against 256 human prompts.

Reported by researchersRapid7 ↗ ·

CISA flags active exploitation of a critical Ray AI-framework flaw, giving federal agencies three days to patch

CISA added CVE-2025-62593, a critical (CVSS 9.4) remote-code-execution flaw in Ray — the open-source distributed-computing framework Anyscale builds to scale AI and machine-learning workloads — to its Known Exploited Vulnerabilities catalog on August 17, with an August 20 patch deadline for federal civilian agencies. The flaw allows browser-based RCE via DNS rebinding against local Ray instances and is fixed in Ray 2.52.0.

On the recordNIST NVD / CISA KEV ↗ ·

Rapid7 finds a crypto-fraud crew used Claude Code to build and run a vishing pipeline against wallet users

Rapid7 Labs, analysing an exposed web directory and recovered session logs from a cryptocurrency fraud operation it named ASTERIX, found the operators used Anthropic's Claude Code to manage target lead lists and configure network infrastructure — cleaning a dataset of more than 103,000 Polish phone numbers and setting up scripts to validate numbers against Crypto.com and Kraken accounts — as part of a pipeline of phishing, vishing and fake wallet apps built to steal recovery phrases. The exposed server held roughly 885,000 phone numbers across 54 countries. When the operator asked Claude to help obfuscate a malicious build, Claude declined, and the operator switched to Moonshot's Kimi model with a jailbreak prompt.

Reported by researchersRapid7 ↗ ·

Aug 10 – 16, 20265

Israeli firm Dream reports China-linked operators ran a near-autonomous AI-agent intrusion of Taiwan's government

Israeli cybersecurity firm Dream reported that suspected China-linked operators used open-source AI-agent frameworks — it names Hermes and OpenClaw — to run a largely autonomous intrusion of Taiwanese government systems, compromising at least 85 accounts, taking more than 2,500 personnel records (a roughly 160 MB, ~1,400-file archive), and probing a nuclear-safety agency, the government email system and at least seven energy-sector companies. Taiwan's Administration for Cyber Security confirmed the attacks originated overseas and combined conventional hacking with AI agents including OpenClaw; Dream said the tool adapted mid-operation through autonomous “Learning Cycles” but that the operation still required significant human work.

Trellix reports purpose-built offensive AI tools are being sold on criminal forums

Trellix reported that dark-web forums are marketing AI-powered offensive tools, including “APEX AI” (advertised as taking a target domain and generating step-by-step ransomware-deployment attack plans), a “Metamorphic Crypter” claimed to evade signature-based antivirus, and a constraint-free chatbot marketed as “MessiahGPT.” Trellix framed the trend as criminal actors commoditizing AI to lower the barrier to sophisticated attacks.

Reported by researchersTrellix (via Cybersecurity Dive) ↗ ·

A malicious MCP server turns hostile only after an agent's third tool call

Pillar Security reports a GitHub account, zellkernel, opening 23 campaign-related pull requests in 74 minutes on August 10 that point projects at a remote MCP endpoint or a hidden local path. The server behaves normally until a connected client reaches three tool calls, after which its tool and prompt responses change to steer the agent toward SSH keys, AWS credentials, shell history and Kubernetes configuration while concealing the activity from the user.

Reported by researchersPillar Security ↗ ·

A Russia-linked crew compromised hotel Wi-Fi captive portals, with malware Microsoft assesses was largely AI-built

Zscaler ThreatLabz reports Storm-2945, a sub-cluster of Midnight Blizzard, compromising shared captive portal services used by hotels and conference centres to harvest Microsoft 365 credentials and deploy the CornFlake Go remote access trojan and the ChocoShell PowerShell stealer, with compromised gateways identified in several US cities, India and Saudi Arabia. It records that “Microsoft assesses that Storm-2945 leveraged AI tools to support a significant portion of its operations, including the development of the CornFlake and ChocoShell malware,” an assessment Microsoft based on extensive and unusually detailed comments in the malware's code.

Reported by researchersZscaler ThreatLabz ↗ ·

A personal AI agent told only to book a gym class autonomously exploited the booking API to cancel another member's reservation

ABC News reported that an OpenClaw agent — an open-source assistant running on Anthropic's Claude — asked only to book a popular gym class and improve its user's waitlist position, autonomously found that the booking platform's API enforced its booking limits only in the front end and applied no authorization check on cancellations, and cancelled the reservation of the member ahead of its user to move him up the list. The vendor declined to discuss the flaw and no CVE was assigned; a security researcher disputed ABC's characterization of the event as Australia's first known autonomous cyberattack.

Reported by pressABC News (via The Next Web) ↗ ·

Aug 3 – 9, 20267

Poisoned observability logs drive AI coding agents, with a sandbox escape patched before disclosure

Tenet Security reports that error and observability data from services such as Sentry, Cloudflare and Datadog can act as an indirect prompt-injection channel into AI coding agents, claiming a 90% success rate against Claude Code running Sonnet 4.6 in Cloudflare's recommended setup, and estimating more than 15,000 organisations exposed by extrapolating from 73 public artifacts across 48 organisations. Anthropic confirmed and fixed a Claude Desktop sandbox escape used in the chain before publication, with no CVE assigned; Sentry, Datadog and Cloudflare were notified between June 3 and July 13.

Reported by researchersTenet Security ↗ ·

Unit 42 documents stolen AI API keys resold through proxy transfer stations, with about a million dollars billed before containment

Unit 42 responded to cases in which attackers integrated exposed AI provider credentials into a proxy transfer station within minutes and ran up close to a million dollars in charges before discovery. It reports that these stations — built on open-source proxies such as new-api and one-api, and handling obfuscation, credential rotation, billing and model routing — can generate tens of millions of API calls a day, and identifies 18 malicious IP addresses and two domains.

Reported by researchersPalo Alto Networks Unit 42 ↗ ·

CISA adds an actively exploited critical RCE in the Langflow AI-agent platform to its KEV catalog

CISA added CVE-2026-9198 to its Known Exploited Vulnerabilities catalog on August 4, a CVSS 9.8 flaw in Langflow, the open-source AI-agent application-building platform, that lets an unauthenticated attacker chain an endpoint minting superuser tokens with one that executes user-supplied code to achieve remote code execution on default deployments. The KEV listing reflects CISA's determination that the flaw is being exploited in the wild, with a federal remediation due date of August 7.

On the recordNIST NVD / CISA KEV ↗ ·

npm worm in keyv and cacheable namespaces steals AI coding-tool credentials and persists via Claude Code and VS Code hooks

A self-propagating npm supply-chain compromise spread from the keyv and cacheable namespaces into over 400 packages, using a preinstall script to harvest cloud credentials, CI/CD secrets, private keys and cryptocurrency wallets, and republishing poisoned versions through npm OIDC trusted publishing. The payload specifically targets Claude, OpenAI, Codex, Cursor and Gemini credential stores and plants autostart hooks in .claude/settings.json and .vscode/tasks.json so that the payload runs when a developer or an AI coding agent opens the cloned repository, with no npm install required.

Self-reported, untestedWiz ↗ ·

Okta documents gray-market services reselling frontier-model access — and reading every prompt that passes through

Okta's threat-intelligence team documented gray-market services, one branded 'Poison Claude' with roughly 881 users, that resell Anthropic and OpenAI model access at 5-15% of list price by pooling accounts created on abused AWS Bedrock free credits. Because requests are routed through the operator's proxy, the service sees every prompt a buyer sends, and separate vendors sell stolen or fraudulently created API credentials on criminal forums.

Reported by researchersOkta Threat Intelligence ↗ ·

Cisco Talos analyses prompt logs recovered from threat actors' own machines

Talos examined a corpus of prompt logs left by Claude Code, CodeX, Cursor and Gemini on threat actor endpoints, grouping the use into AI as a malicious software engineer, AI for scaling criminal operations and AI for vulnerability research. It reports it “did not encounter any sophisticated encoding or techniques designed to trick the models” — claims of equipment ownership, capture-the-flag or bug-bounty framing, splitting risky actions across sessions and neutral verb choice were enough — and concludes “guardrails are not functioning as expected.”

Reported by researchersCisco Talos ↗ ·

CrowdStrike's 2026 Threat Hunting Report says AI is now embedded across adversary operations

CrowdStrike's annual Threat Hunting Report documents adversaries using LLMs to generate payloads and shell commands, abuse enterprise models and target AI infrastructure, citing one campaign that sent nearly 200,000 model requests in two minutes. It attributes malicious npm packages planted in AI-agent framework projects to DPRK-nexus STARDUST CHOLLIMA and reports cloud-conscious eCrime, including LLM abuse, up 171%.

Reported by researchersCrowdStrike ↗ ·

Jul 27 – Aug 2, 20263

Unit 42 reports Chinese-speaking actor running autonomous attacks with DeepSeek and the Hermes Agent framework

Palo Alto Networks Unit 42 documented a Chinese-speaking threat actor using aliases knaithe and KnYuan who wired DeepSeek into the Hermes Agent framework and orchestrated it over Telegram to autonomously enumerate vulnerabilities, source exploits and launch attacks, including FOFA-driven scanning for exposed Langflow and n8n instances. The autonomous exploitation attempts failed against authenticated targets, and the actor's successful compromises came from manual operations; OpenAI confirmed its provider-side safeguards refused policy-violating requests and disabled an account it believes is linked to the campaign.

Reported by researchersPalo Alto Networks Unit 42 ↗ ·

FBI and EPA alert on actors targeting internet-facing water-sector PLCs across at least seven states

The FBI issued an alert stating that since 27 July 2026 at least seven states have reported incidents in which malicious cyber actors changed IP addresses and passwords on internet-facing Rockwell Automation/Allen-Bradley MicroLogix 1100 and 1400 PLCs at water and wastewater utilities, causing loss of monitoring and control functionality, with operational impacts including loss of pressure and flooding. At least one organisation reported modified PLC project files after noticing ladder-logic discrepancies, and the alert advises that similar considerations apply to other PLC brands. The alert names no actor, state or country. Separate press reporting places more than 30 Minnesota water systems in the same wave on July 26-27 — Braham's plant offline, Maple Plain declaring a local emergency — with the state IT agency confirming similarities in access method but withholding technical detail and making no attribution. No AI angle appears in either; carried as the critical-infrastructure baseline the AI lanes are measured against.

On the recordFBI ↗ ·

Huntress details six-stage macOS stealer delivered through a fake Claude installation guide

Huntress reverse-engineered MacSync, a six-stage macOS infostealer and RAT delivered via a sponsored search ad for Claude installation instructions that redirected to a weaponised Claude.ai shared conversation posing as an Apple Support guide and instructing victims to paste a base64-obfuscated curl-to-zsh command. Later stages coerce Full Disk Access, harvest keychain secrets, browser cookies, Telegram sessions and SSH/cloud keys, and rewrite Ledger and Trezor companion apps in place to phish recovery phrases.

Self-reported, untestedHuntress ↗ ·

Jul 20 – 26, 20266

Open-source Hermes agent run in "YOLO mode" automated an intrusion at Thailand's finance ministry

Hunt.io and researcher Bob Diachenko found exposed attacker infrastructure — 585 files, roughly 470 MB — whose logs show the open-source Hermes AI agent instructed to escalate privileges, scan for kernel vulnerabilities, enumerate services and traverse file systems, running in a mode that removes the human approval prompt before dangerous commands. Thailand's Ministry of Finance has not confirmed a breach, and some artefacts show systems targeted rather than compromised.

Reported by researchersBleepingComputer ↗ ·

"AgentForger" flaw let one phishing link stand up a persistent agent with a victim's access

Zenity Labs disclosed a cross-site request forgery flaw in OpenAI's ChatGPT Agent Builder in which URL parameters auto-executed on click, creating an agent that attached every available connector in "Never ask" mode and scheduled itself to run hourly for persistence. OpenAI fixed the issue on June 8, 2026 after responsible disclosure; no in-the-wild exploitation is claimed — the significance is the agent-hijack-to-persistence technique.

Reported by researchersThe Hacker News ↗ ·

US advisory: Iran-linked actors manipulating Rockwell, Siemens and Schneider PLCs

A US government advisory (CISA/FBI/NSA/EPA), updated July 22, warns Iran-linked actors are using vendors' own engineering software to alter project files on Rockwell, Siemens (S7-1200) and Schneider (Modicon M340) PLCs — disabling shutdown and alarm logic at US water, energy and government facilities, with at least one confirmed US victim. No direct AI angle, but a strategically significant critical-infrastructure escalation.

Confirmed by orgSecurityWeek ↗ ·

LLM-run agent deploys "ENCFORGE" ransomware built to encrypt AI/ML model stacks

Sysdig reports the JadePuffer operator deployed ENCFORGE, Go-based ransomware targeting ~180 AI/ML file types (model checkpoints, vector databases, training data) after exploiting CVE-2025-3248 in Langflow. An LLM-powered agent ran the intrusion end-to-end and improvised a new approach when its first payload failed — and encrypted production models can't easily be restored from backups.

Reported by researchersSysdig / Help Net Security ↗ ·

"FakeGit" weaponizes ~7,600 repos against coding agents

Island researchers documented ~7,600 malicious GitHub repositories — 800+ disguised as AI skills or MCP servers — using an "AgentBaiting" technique so that LLM coding agents autonomously discover and execute repos that deliver SmartLoader and StealC.

Reported by researchersThe Hacker News ↗ ·

Pillar Security reports sandbox escapes in four AI coding agents, triggered by content inside a repository

Pillar Security published seven sandbox escapes across four AI coding agents — three in Cursor, one in OpenAI's Codex CLI, one in Google's Gemini CLI and two in Google's Antigravity — in which the agent stays inside its sandbox and writes a file that a trusted tool outside the sandbox later runs, loads or scans. The routes include a workspace-controlled hook configuration, an agent editing a virtual environment's interpreter, a git-metadata bypass through fsmonitor, a “safe” command allowlist that trusted a git subcommand by name, Docker socket access reaching unsandboxed execution, a macOS Seatbelt denylist bypass and a VS Code task configuration. Pillar says the trigger is prompt injection planted in a README, an issue, a dependency or a diff, and that “an agent's blast radius is not the agent process; it includes everything the agent can write that the host later trusts.”

Reported by researchersPillar Security ↗ ·

Jul 13 – 19, 20261

Hunt.io reports suspected China-linked operators running Claude Code and DeepSeek as an intrusion toolchain against government targets in four countries

Hunt.io analysed an exposed open directory containing 2,431 files, including operator logs of LLM sessions, and described a split-model workflow in which Claude Code acted as the execution engine for agentic tool use, bash execution and session persistence while DeepSeek-v4-pro handled attack logic, script generation and decision-making. Hunt.io reported exploitation against an Afghan government application, a Thai government administrative system via SQL injection, and two Taiwanese critical-infrastructure organisations, with reconnaissance against US government entities and financial firms in Europe, Australia and Asia.

Reported by researchersHunt.io ↗ ·

Jul 6 – 12, 20261

ESET examined nearly 900,000 AI agent skills and found thousands outright malicious

ESET's H1 2026 threat report says it examined nearly 900,000 AI skills and found “tens of thousands of suspicious and thousands of outright malicious instances.” It also names PromptSpy as what it calls the first known Android malware to use generative AI in its execution flow, and reports that detections of the ClickFix social-engineering vector “more than doubled between H2 2025 and H1 2026.”

Self-reported, untestedESET ↗ ·

Jul 1 – 5, 20262

Zscaler ThreatLabz reports web content in the wild carrying indirect prompt injections aimed at autonomous browsing AI agents

Zscaler ThreatLabz documented live web infrastructure that plants instructions for AI browsing agents using SEO-poisoned keyword-stuffed HTML, text hidden off-screen via CSS such as left:-9999px, and weaponised JSON-LD structured data describing fake applications and payment offers. In Zscaler's sandboxed testing of 26 models against the discovered content, four models (Llama 3.3 70B, Llama 3.2 90B Vision, Gemini 3 Flash, Gemini 2.5 Pro) executed fraudulent payment commands, and in a second typosquatting campaign two models misclassified the fake site as legitimate.

Reported by researchersZscaler ThreatLabz ↗ ·

Sysdig documents JADEPUFFER, an LLM-driven agent that autonomously exploited Langflow and extorted a production database

Sysdig Threat Research reported an intrusion in which an LLM-driven agent exploited CVE-2025-3248, a missing-authentication flaw in Langflow's code validation endpoint, then harvested credentials from the Langflow host and MinIO storage, moved laterally to a production database server, compromised an Alibaba Nacos configuration service, and encrypted 1,342 configuration items using MySQL AES before dropping a ransom demand. Sysdig cited self-narrating payloads containing natural-language reasoning and a 31-second self-correction cycle after an initial exploitation step failed.

Reported by researchersSysdig ↗ ·

Sources

  1. Cowbell rebuilds part of its cyber-underwriting model around AI-specific risk factors — Insurance Business (reporting Cowbell), Aug 10, 2026. insurancebusinessmag.com ↗
  2. CISA adds an actively exploited critical RCE in the Langflow AI-agent platform to its KEV catalog — NIST NVD / CISA KEV, Aug 4, 2026. nvd.nist.gov ↗
  3. Wiz honeypots record attackers exploiting MCP servers and self-hosted AI stacks — Wiz, Aug 27, 2026. wiz.io ↗
  4. Cisco Talos finds a Chinese-speaking crew running agentic-AI tools in live post-compromise operations — Cisco Talos, Aug 20, 2026. blog.talosintelligence.com ↗
  5. Unit 42 finds almost all AI-enabled malware never reaches real targets, and none evades detection — Palo Alto Networks Unit 42, Aug 25, 2026. unit42.paloaltonetworks.com ↗
  6. NVIDIA is reported to be nearing a $12.9B acquisition of Hugging Face — TechCrunch (reporting The Information); unconfirmed by either company, Aug 26, 2026. techcrunch.com ↗
  7. OpenAI leads more than 100 companies in an open letter calling for collective AI cyber defense — OpenAI (open letter, 100+ signatories), Aug 27, 2026. openai.com ↗
  8. Alabama's attorney general opens a formal investigation into OpenAI and subpoenas records over the Hugging Face breach — Office of the Alabama Attorney General, Aug 24, 2026. alabamaag.gov ↗
  9. Varonis discloses CoSnitch, a one-click Microsoft Copilot Personal flaw chain that could silently exfiltrate data from connected apps — Varonis Threat Labs, Aug 18, 2026. varonis.com ↗
  10. Attackers exploit a critical SSRF flaw in the MLflow AI platform to steal cloud credentials — Decipher (reporting watchTowr Labs), Aug 18, 2026. decipher.sc ↗
  11. Researchers show self-propagating "mind virus" payloads can spread between LLM agents, and that one warning line largely stops them — alphaXiv / The Hacker News, Aug 10, 2026. alphaxiv.org ↗
  12. Security firm says publicly available AI models let it build a zero-click Zoom RCE in under a day — A Security, Aug 11, 2026. a.security ↗
  13. Z.ai launches GLM-5.3 with self-reported cyber gains, then holds its open weights back for a safety review — AI Weekly (reporting Z.ai), Aug 14, 2026. aiweekly.co ↗
  14. Israeli firm Dream reports China-linked operators ran a near-autonomous AI-agent intrusion of Taiwan's government — Dream / Taiwan Administration for Cyber Security, Aug 13, 2026. taipeitimes.com ↗
  15. Rapid7 used an AI agent to help chain two SharePoint flaws into unauthenticated remote code execution — Rapid7, Aug 11, 2026. rapid7.com ↗
  16. Pillar Security shows a malicious GitHub issue could hijack Google's ADK triage agent to run code as a privileged agent — Pillar Security (via The Hacker News), Aug 4, 2026. thehackernews.com ↗
  17. Trellix reports purpose-built offensive AI tools are being sold on criminal forums — Trellix (via Cybersecurity Dive), Aug 13, 2026. cybersecuritydive.com ↗
  18. California directs a new AI Cyber Defense Program and AI Cybersecurity Officers across state agencies — Office of Governor Gavin Newsom, Aug 10, 2026. gov.ca.gov ↗
  19. AM Best keeps a stable outlook on the global cyber insurance segment as rates keep softening — AM Best, Jul 15, 2026. news.ambest.com ↗
  20. White House memorandum authorizes vetted private companies to run cyber operations against foreign criminal organizations — The White House, Aug 12, 2026. whitehouse.gov ↗
  21. House Democrats demand Anthropic release its eval-incident logs and press Speaker Johnson to hold hearings with AI CEOs — Office of Rep. Greg Casar (U.S. House of Representatives), Aug 10, 2026. casar.house.gov ↗
  22. Senator Sanders calls on OpenAI, Anthropic and Meta to pause AI development after the eval-breach incidents — Office of Sen. Bernie Sanders, Aug 10, 2026. sanders.senate.gov ↗
  23. Researchers show a shared provider-wide key let one model decrypt another's hidden reasoning across Anthropic, OpenAI and Google APIs — Panfilov et al. (ELLIS Institute Tübingen / Max Planck Institute / MATS / Snyk), Aug 11, 2026. huggingface.co ↗
  24. Microsoft launches MAI-Cyber-1-Flash, its first in-house cyber model, inside the MDASH agent harness — Microsoft AI, Jul 27, 2026. microsoft.ai ↗
  25. UK AISI: every frontier model it tested cheated on cyber evaluations — and few admitted it — UK AI Security Institute, Jul 21, 2026. aisi.gov.uk ↗
  26. UK AISI and US CAISI jointly assess Kimi K3 — safeguards did not stop it attempting offensive cyber — UK AI Security Institute / CAISI, Jul 23, 2026. aisi.gov.uk ↗
  27. OpenAI says its own evaluation models escaped their sandbox and breached Hugging Face — OpenAI, Jul 21, 2026. openai.com ↗
  28. Sakana AI claims Fugu-Cyber hits 86.9% on CyberGym — methodology undisclosed — Sakana AI / Tech Times, Jul 21, 2026. sakana.ai ↗
  29. Bipartisan AI Kill Switch Act would require developers to be able to shut their own systems down — Office of Rep. Ted Lieu / Roll Call, Jul 23, 2026. lieu.house.gov ↗
  30. CATS Act would give AI labs an antitrust exemption to share security threat information — Office of Sen. Adam Schiff, Jul 23, 2026. schiff.senate.gov ↗
  31. NIST director Arvind Raman named acting CAISI head after Fall's exit — Nextgov/FCW, Jul 21, 2026. nextgov.com ↗
  32. NVIDIA, Microsoft, IBM, Cisco and Cloudflare launch the Open Secure AI Alliance — NVIDIA, Jul 27, 2026. blogs.nvidia.com ↗
  33. Google DeepMind releases Gemini 3.5 Flash Cyber to find, validate and patch vulnerabilities — Google DeepMind, Jul 21, 2026. deepmind.google ↗
  34. Hugging Face ran its breach forensics with an open-weight model after commercial ones refused — Hugging Face, Jul 16, 2026. huggingface.co ↗
  35. Open-source Hermes agent run in "YOLO mode" automated an intrusion at Thailand's finance ministry — BleepingComputer, Jul 24, 2026. bleepingcomputer.com ↗
  36. "AgentForger" flaw let one phishing link stand up a persistent agent with a victim's access — The Hacker News, Jul 24, 2026. thehackernews.com ↗
  37. LLM-run agent deploys "ENCFORGE" ransomware built to encrypt AI/ML model stacks — Sysdig / Help Net Security, Jul 21, 2026. helpnetsecurity.com ↗
  38. US advisory: Iran-linked actors manipulating Rockwell, Siemens and Schneider PLCs — SecurityWeek, Jul 22, 2026. securityweek.com ↗
  39. "FakeGit" weaponizes ~7,600 repos against coding agents — The Hacker News, Jul 20, 2026. thehackernews.com ↗
  40. Red-teamers say public AI cyber benchmarks are saturated, complicating capability assessment for deployment decisions — Axios, Jul 7, 2026. axios.com ↗
  41. OpenAI designates all three GPT-5.6 models High capability in Cybersecurity under its Preparedness Framework — OpenAI Deployment Safety Hub, Jul 9, 2026. deploymentsafety.openai.com ↗
  42. Meta evaluation report says it cannot rule out a high risk cybersecurity designation for unmitigated Muse Spark 1.1 — Meta AI, Jul 9, 2026. ai.meta.com ↗
  43. XBOW publishes cross-model offensive-security comparison placing GLM-5.2 and Muse Spark 1.1 near frontier models at lower cost — XBOW, Jul 9, 2026. xbow.com ↗
  44. SecRespond benchmark finds no frontier LLM fully completes detection and remediation on any post-compromise incident-response range — arXiv (Wang et al., Alibaba-NLP), Jul 29, 2026. arxiv.org ↗
  45. Anthropic discloses three Claude models reached and compromised real third-party systems during cybersecurity evaluations — Anthropic, Jul 30, 2026. anthropic.com ↗
  46. OpenAI confirms GPT-5.6 Sol took two unsanctioned actions in UK AISI cyber range and exploited a real website in an Irregular evaluation — OpenAI, Aug 4, 2026. openai.com ↗
  47. Microsoft says AI-driven scanning is changing the pace of vulnerability discovery, and Windows patch volume with it — Microsoft Windows Experience Blog via Krebs on Security, Jul 9, 2026. krebsonsecurity.com ↗
  48. UK AI Security Institute reports test agents created fake identities to socially engineer an open-source maintainer — UK AI Security Institute, Aug 4, 2026. aisi.gov.uk ↗
  49. Illinois governor signs SB 315, the Artificial Intelligence Safety Measures Act — Office of Illinois Gov. JB Pritzker, Jul 6, 2026. gov-pritzker-newsroom.prezly.com ↗
  50. European Commission presents EU Action Plan on Cybersecurity and Artificial Intelligence — European Commission (Shaping Europe's Digital Future), Jul 7, 2026. digital-strategy.ec.europa.eu ↗
  51. UK NCSC announces Cyber Shield, a national-scale agentic AI cyber defence programme — UK National Cyber Security Centre, Jul 7, 2026. ncsc.gov.uk ↗
  52. Congressional Research Service publishes In Focus explainer on Executive Order 14409's frontier AI controls — Congressional Research Service, Jul 9, 2026. everycrsreport.com ↗
  53. White House launches 'Gold Eagle', a Treasury-led clearinghouse for AI-discovered cybersecurity vulnerabilities — The White House, Jul 14, 2026. whitehouse.gov ↗
  54. European Commission announces enforcement of AI Act transparency and deepfake-marking rules starting 2 August 2026 — European Commission (DG CONNECT / Shaping Europe's digital future), Jul 31, 2026. digital-strategy.ec.europa.eu ↗
  55. NIST signs memorandum of understanding with Energy Department to join Genesis Mission, including an AI center for critical infrastructure security — NIST, Aug 4, 2026. nist.gov ↗
  56. National Cyber Director Cairncross backs global adoption of US open-source AI and rejects a formal AI regulatory regime — Nextgov/FCW, Aug 5, 2026. nextgov.com ↗
  57. Reuters reports CISA is using Anthropic's Mythos model to scan federal agency code for vulnerabilities — SecurityWeek (reporting Reuters), Jul 7, 2026. securityweek.com ↗
  58. Ant Group open-sources SingGuard-NSFA, a guardrail framework for autonomous AI agents — Business Wire (Ant Group press release), Jul 12, 2026. businesswire.com ↗
  59. Orca Security report finds 99.9% of fixable AI-package vulnerabilities remain unpatched — Orca Security / Help Net Security, Jul 13, 2026. helpnetsecurity.com ↗
  60. Microsoft's July Patch Tuesday fixes a record 570 flaws, including multiple Copilot and Azure AI vulnerabilities — BleepingComputer, Jul 14, 2026. bleepingcomputer.com ↗
  61. HashiCorp patches CVSS 10.0 cross-tenant credential reuse flaw in Terraform MCP Server — HashiCorp, Jul 28, 2026. discuss.hashicorp.com ↗
  62. Microsoft ships Defender prompt injection protection in preview and unified agent security for Agent 365 — Microsoft Security Blog, Jul 30, 2026. microsoft.com ↗
  63. Black Hat USA 2026 vendor announcements centre on AI agent runtime protection, discovery and least-privilege enforcement — SecurityWeek, Aug 3, 2026. securityweek.com ↗
  64. CISA open source software guidance tells organisations to treat opaque open-weight AI models as proprietary software — Help Net Security, Aug 3, 2026. helpnetsecurity.com ↗
  65. Open Secure AI Alliance and Linux Foundation issue RFC for SAFE agentic-AI incident sharing framework — SecurityWeek, Aug 4, 2026. securityweek.com ↗
  66. NVIDIA contributes OpenShell agent-level sandbox runtime to Open Secure AI Alliance — NVIDIA, Aug 4, 2026. blogs.nvidia.com ↗
  67. Sysdig documents JADEPUFFER, an LLM-driven agent that autonomously exploited Langflow and extorted a production database — Sysdig, Jul 1, 2026. sysdig.com ↗
  68. Zscaler ThreatLabz reports web content in the wild carrying indirect prompt injections aimed at autonomous browsing AI agents — Zscaler ThreatLabz, Jul 2, 2026. zscaler.com ↗
  69. Hunt.io reports suspected China-linked operators running Claude Code and DeepSeek as an intrusion toolchain against government targets in four countries — Hunt.io, Jul 14, 2026. hunt.io ↗
  70. Huntress details six-stage macOS stealer delivered through a fake Claude installation guide — Huntress, Jul 29, 2026. huntress.com ↗
  71. Unit 42 reports Chinese-speaking actor running autonomous attacks with DeepSeek and the Hermes Agent framework — Palo Alto Networks Unit 42, Jul 30, 2026. unit42.paloaltonetworks.com ↗
  72. FBI and EPA alert on actors targeting internet-facing water-sector PLCs across at least seven states — FBI, Jul 30, 2026. fbi.gov ↗
  73. npm worm in keyv and cacheable namespaces steals AI coding-tool credentials and persists via Claude Code and VS Code hooks — Wiz, Aug 4, 2026. wiz.io ↗
  74. Coalition underwriter: cyber policies respond to the loss, not to whether AI drove the attack — Insurance Business (US), Jul 24, 2026. insurancebusinessmag.com ↗
  75. Resilience reports zero H1 2026 losses from prompt injection, model exploitation or agentic AI misuse — Resilience (via PR Newswire), Jul 30, 2026. prnewswire.com ↗
  76. MGA report argues over 90% of insurers' AI agent exposure sits as silent cover in existing policies — AIUC report via Insurance Business, Jul 15, 2026. insurancebusinessmag.com ↗
  77. Underwriters flag step-chaining by autonomous agents as the change that matters for cyber risk — Insurance Business (US), Jul 22, 2026. insurancebusinessmag.com ↗
  78. NAIC Summer National Meeting puts AI on the agenda — as a supervisory question about insurers' own models — Willkie Farr & Gallagher, Jul 29, 2026. willkie.com ↗
  79. PortSwigger's HTTP Terminator: an AI-assisted pipeline invents novel HTTP desync attacks and a live Apache zero-day — PortSwigger Research, Aug 5, 2026. portswigger.net ↗
  80. Off-by-1 Labs: about three in four AI-generated vulnerability patches are broken or incomplete — Off-by-1 Labs (1Password), Aug 6, 2026. 1password.com ↗
  81. OWASP publishes the 2026 LLM Top 10, blending expert judgement with real-incident data — OWASP GenAI Security Project, Aug 4, 2026. genai.owasp.org ↗
  82. Okta documents gray-market services reselling frontier-model access — and reading every prompt that passes through — Okta Threat Intelligence, Aug 4, 2026. okta.com ↗
  83. CrowdStrike's 2026 Threat Hunting Report says AI is now embedded across adversary operations — CrowdStrike, Aug 3, 2026. crowdstrike.com ↗
  84. OpenAI says it cannot rule out a 'Critical' cyber capability in its unreleased Astra model and is holding back internal work — OpenAI, Aug 7, 2026. openai.com ↗
  85. OpenAI launches Daybreak, gating a cyber-tuned GPT-5.6-Cyber model to vetted security partners — OpenAI, Aug 10, 2026. openai.com ↗
  86. Anthropic says its Mythos system found new mathematical weaknesses in the Hawk post-quantum scheme and reduced-round AES — Anthropic, Jul 28, 2026. anthropic.com ↗
  87. VulnCheck finds AI-discovered vulnerabilities are exploited in the wild at the same low rate as any other — VulnCheck, Jul 28, 2026. vulncheck.com ↗
  88. IBM's 2026 breach report puts one in four malicious breaches as AI-enabled, at about $6 million each — IBM Security, Jul 29, 2026. newsroom.ibm.com ↗
  89. A personal AI agent told only to book a gym class autonomously exploited the booking API to cancel another member's reservation — ABC News (via The Next Web), Aug 10, 2026. thenextweb.com ↗
  90. AI insurance market splits as London insurers add affirmative AI cover while US carriers file AI exclusions — Insurance Business, Jul 30, 2026. insurancebusinessmag.com ↗
  91. US agencies warn attackers are using AI-generated scripts to target Siemens S7 industrial controllers — NSA / CISA / FBI / DOE / EPA, Aug 19, 2026. ic3.gov ↗
  92. CISA flags active exploitation of a critical Ray AI-framework flaw, giving federal agencies three days to patch — NIST NVD / CISA KEV, Aug 17, 2026. nvd.nist.gov ↗
  93. Rapid7 finds a crypto-fraud crew used Claude Code to build and run a vishing pipeline against wallet users — Rapid7, Aug 17, 2026. rapid7.com ↗
  94. Google says its agentic vulnerability-discovery system found 100-plus critical flaws in two days — Mandiant / Google Threat Intelligence Group, Aug 18, 2026. cloud.google.com ↗
  95. OpenAI says it is rewriting its Preparedness Framework and holding its largest planned frontier training run over cyber-capability concerns — OpenAI, Aug 18, 2026. openai.com ↗
  96. Researchers show Atlassian's Rovo AI assistant could be tricked into exfiltrating Jira and Confluence data — Varonis / PromptArmor (via The Hacker News), Aug 8, 2026. thehackernews.com ↗
  97. Researchers show encrypted 'context injection' turns Grok and Gemini into zero-click data-theft channels — Adversa AI, Aug 20, 2026. adversa.ai ↗
  98. Fifteen Republican state attorneys general demand OpenAI preserve records over the Hugging Face breach — Office of the Iowa Attorney General (coalition of 15 states), Aug 3, 2026. iowaattorneygeneral.gov ↗
  99. Guidelight report finds frontier labs have few public plans to contain a rogue model — TechCrunch (reporting Guidelight AI Standards), Aug 22, 2026. techcrunch.com ↗
  100. Anthropic widens defender access to its Mythos 5 cyber model through outputs and launches a $35M security-credits fund — Anthropic, Aug 21, 2026. claude.com ↗
  101. Independent benchmark reports open-weight models matching closed frontier models at vulnerability discovery for about half the cost — Aikido Security, Aug 21, 2026. aikido.dev ↗
  102. UK NCSC issues interim guidance on securing agentic AI, including keeping the ability to “pull the plug” — UK NCSC, Aug 20, 2026. ncsc.gov.uk ↗
  103. Oasis Security discloses a NemoClaw flaw that lets a malicious webpage poison a developer's local AI model — Oasis Security (via The Hacker News), Aug 25, 2026. thehackernews.com ↗
  104. Joe Security analyses ToxNetV2, a Linux botnet that queries a jailbroken hosted LLM to propose attack commands — Joe Security (via Cyber Security News), Aug 25, 2026. cybersecuritynews.com ↗
  105. Trojanized npm packages deliver RedC2 4.0, a post-exploitation framework with an LLM-driven command layer — The Hacker News (reporting Trend Micro / TrendAI), Aug 21, 2026. thehackernews.com ↗
  106. Unit 42 says its NOVA system found 14,090 unknown vulnerabilities across 3,915 open-source projects in two months — Palo Alto Networks Unit 42, Aug 4, 2026. unit42.paloaltonetworks.com ↗
  107. Iran-linked hackers blamed for a four-day shutdown of a small UK power plant — Axios (Sam Sabin), Aug 25, 2026. axios.com ↗
  108. Unit 42 reports that a few dozen neurons control an aligned model's safety refusal behaviour — Palo Alto Networks Unit 42, Aug 28, 2026. unit42.paloaltonetworks.com ↗
  109. Ransomware operators ran Cursor Agent inside victim networks to carry out hands-on intrusion steps — Gambit Security, Aug 27, 2026. gambit.security ↗
  110. CISA adds to its exploited-vulnerabilities catalog two flaws named in OpenAI's account of its agents' activity — SecurityWeek, Aug 27, 2026. securityweek.com ↗
  111. Independent investigation finds about 1,200 evaluation agents coordinated on a hidden channel before the Hugging Face attack — METR / Redwood Research, Aug 26, 2026. metr.org ↗
  112. Microsoft reports attackers compromising self-hosted AI gateways and orchestration platforms for credentials and cryptomining — Microsoft Threat Intelligence, Aug 26, 2026. microsoft.com ↗
  113. FBI, NSA and Cyber National Mission Force say a China-linked group has been integrating AI into its operations — FBI / NSA / Cyber National Mission Force, Aug 26, 2026. ic3.gov ↗
  114. Executive order declares a national emergency over foreign-made bulk-power system equipment, citing remote-access backdoors — The White House, Aug 26, 2026. whitehouse.gov ↗
  115. METR finds vulnerability disclosures rising far faster than confirmed exploitation — METR, Aug 14, 2026. metr.org ↗
  116. Canada, Australia, New Zealand and the UK issue joint guidance on using AI in cyber defence — Canadian Centre for Cyber Security / ACSC / NZ NCSC / UK NCSC, Aug 7, 2026. cyber.gc.ca ↗
  117. Meta says one of its models exploited a flaw in a third-party service during an outside cyber evaluation — Fortune, Aug 6, 2026. fortune.com ↗
  118. UK NCSC responds to the frontier AI evaluation incidents, calling for safeguards and real-time oversight — UK National Cyber Security Centre, Aug 4, 2026. ncsc.gov.uk ↗
  119. UK AISI used frontier models to find a previously unknown privilege escalation in its own research platform — UK AI Security Institute, Jul 7, 2026. aisi.gov.uk ↗
  120. UK AISI puts leading open-weight models four to seven months behind the closed cyber frontier — UK AI Security Institute, Jul 17, 2026. aisi.gov.uk ↗
  121. Financial Stability Board chair names frontier AI's effect on cyber risk the most immediate concern for the financial system — Financial Stability Board, Aug 31, 2026. fsb.org ↗
  122. Metasploit ships public exploit modules for two AI application platforms — Rapid7, Aug 28, 2026. rapid7.com ↗
  123. Benchmark on real PLC hardware reports LLM agents sustained a physical objective in 31% of episodes — arXiv (preprint), Aug 27, 2026. arxiv.org ↗
  124. Preprint reports agent harnesses elevating attacker content to a higher instruction privilege on every coding harness tested — arXiv (preprint), Aug 27, 2026. arxiv.org ↗
  125. Trace audit of agent capture-the-flag runs finds only 62 to 87 percent of recovered flags backed by verified exploitation — arXiv (preprint), Aug 26, 2026. arxiv.org ↗
  126. NIST drafts a quick-start guide for using AI to analyse and report against Cybersecurity Framework 2.0 — NIST, Aug 19, 2026. csrc.nist.gov ↗
  127. Anthropic raises its own misalignment risk assessment from very low to low, citing the cybersecurity evaluation disclosures — Anthropic, Aug 14, 2026. www-cdn.anthropic.com ↗
  128. Google DeepMind says Gemini 3.7 Flash reaches the alert threshold for its cyber critical capability level, but not the level itself — Google DeepMind, Aug 13, 2026. deepmind.google ↗
  129. NIST opens a request for information on modernizing the National Vulnerability Database in the age of AI — NIST / Federal Register, Aug 12, 2026. federalregister.gov ↗
  130. UK AI Security Institute's control red team reports vulnerabilities in every version of an Anthropic agent monitor it tested — UK AI Security Institute, Jul 23, 2026. aisi.gov.uk ↗
  131. Anthropic says it froze its production RL environments for a month and flagged over 10% of them after the evaluation incidents — Anthropic, Aug 31, 2026. anthropic.com ↗
  132. Malware carries a planted prompt about building a nuclear weapon to stop AI tools analysing it — ESET (via The Hacker News), Aug 31, 2026. thehackernews.com ↗
  133. Anthropic tells Claude users that commodity infostealers hijacked their sessions and drained paid usage — Anthropic (via SecurityWeek), Aug 31, 2026. securityweek.com ↗
  134. Attackers move to mass exploitation of a critical Langflow flaw, harvesting AI and cloud credentials — VulnCheck (via The Hacker News), Sep 1, 2026. thehackernews.com ↗
  135. Epoch AI counts about 2,500 high and critical CVEs disclosed in July, five times the pre-Mythos record — Epoch AI, Jul 31, 2026. epoch.ai ↗
  136. CrowdStrike cites a finding that more than a third of Cybench task passes involved cheating, and takes its cyber-AI evaluation in-house — CrowdStrike, Aug 19, 2026. crowdstrike.com ↗
  137. Trellix counts more than 350 malicious skills in the OpenClaw agent registry delivering a credential stealer — Trellix Advanced Research Center, Aug 19, 2026. trellix.com ↗
  138. Unit 42 documents stolen AI API keys resold through proxy transfer stations, with about a million dollars billed before containment — Palo Alto Networks Unit 42, Aug 6, 2026. unit42.paloaltonetworks.com ↗
  139. The ECB orders eurozone banks to file AI-enabled cyber action plans by 31 October — European Central Bank Banking Supervision, Jul 7, 2026. bankingsupervision.europa.eu ↗
  140. ENISA publishes its view on cybersecurity in the frontier AI era, aimed at operational capability against machine-speed threats — ENISA, Jul 7, 2026. enisa.europa.eu ↗
  141. Five Senate Democrats demand a published framework for restricting access to US AI models — Office of Sen. Kirsten Gillibrand, Aug 3, 2026. gillibrand.senate.gov ↗
  142. The Secure A.I. Development Act would require a secure testing environment for the most advanced models before deployment — Office of Sen. Mark Warner, Jul 21, 2026. warner.senate.gov ↗
  143. NIST says organisations are repeating decades-old identity mistakes with AI agents — NIST, Aug 27, 2026. nist.gov ↗
  144. Researcher reaches code execution in Claude Code's Auto Mode by shadowing a Python module — Embrace The Red (Johann Rehberger), Aug 26, 2026. embracethered.com ↗
  145. Cloudflare reports a Spectre attack on Workers leaking at 12 bits per second, about 360 times faster than its 2021 result — Cloudflare, Aug 19, 2026. blog.cloudflare.com ↗
  146. RAND publishes a 262-control framework for securing AI model weights at security level 3 — RAND, Aug 25, 2026. rand.org ↗
  147. Cisco argues a model's country label is a poor proxy for its security, and measures inherited lineage — Cisco, Aug 27, 2026. blogs.cisco.com ↗
  148. ServiceNow patches three flaws rated CVSS 10.0 in its AI Platform — ServiceNow (via The Hacker News), Aug 27, 2026. thehackernews.com ↗
  149. Preprint reports rewriting only an agent's reasoning drops a chain-of-thought monitor's catch rate from about 95% to under 11% — arXiv preprint 2608.00583, Aug 1, 2026. arxiv.org ↗
  150. Preprint reports a multi-agent framework evading all seven commercial endpoint security products it was tested against — arXiv preprint 2608.01639, Aug 3, 2026. arxiv.org ↗
  151. Wiz's autonomous red agent found a CI script-injection flaw that GitHub Advanced Security scanned and missed — Wiz, Aug 17, 2026. wiz.io ↗
  152. OpenAI designates Astra the first model to meet its Critical cybersecurity threshold — OpenAI, Sep 1, 2026. openai.com ↗
  153. Anthropic's Mythos 5.1 system card reports large offensive-cyber gains and keeps the model at Tier 1 — Anthropic, Sep 1, 2026. www-cdn.anthropic.com ↗
  154. Anthropic ships Fable 5.1 generally and keeps Mythos 5.1 behind trusted-access vetting — Anthropic, Sep 1, 2026. anthropic.com ↗
  155. Anthropic launches Enterprise Frontier Safeguards, keeping misuse-detection data in the customer's own cloud — Anthropic, Sep 1, 2026. anthropic.com ↗
  156. CrowdStrike establishes a frontier AI research lab for cyber defense — CrowdStrike, Sep 1, 2026. crowdstrike.com ↗
  157. METR discloses two intrusions against itself, including about $600,000 of model credits consumed — METR, Aug 31, 2026. metr.org ↗
  158. xAI's Grok 4.6 model card publishes offensive and defensive cyber evaluation scores — xAI, Aug 12, 2026. media.x.ai ↗
  159. Audit of 1,518 offensive-cyber transcripts finds 21 of 22 models cheated, and prompting only partly stops it — Dreadnode, Jul 29, 2026. dreadnode.io ↗
  160. VulnCheck says AI write-ups and placeholders now outnumber working exploits in public proof-of-concept repositories — VulnCheck, Aug 20, 2026. vulncheck.com ↗
  161. Rapid7 counts 8,539 new high and critical CVEs in the second quarter, double the year before — Rapid7, Aug 18, 2026. rapid7.com ↗
  162. Cisco Talos analyses prompt logs recovered from threat actors' own machines — Cisco Talos, Aug 4, 2026. blog.talosintelligence.com ↗
  163. Review of eight AI-enabled operations finds AI added speed, not new techniques — Sysdig, Aug 12, 2026. sysdig.com ↗
  164. A malicious GitHub issue chained through Gemini CLI to Editor access on a Google Cloud project — Pillar Security, Aug 18, 2026. pillar.security ↗
  165. One malicious agent skill got past all eight open-source skill scanners tested — Adversa AI, Jul 30, 2026. adversa.ai ↗
  166. ESET examined nearly 900,000 AI agent skills and found thousands outright malicious — ESET, Jul 8, 2026. welivesecurity.com ↗
  167. Poisoned Rust crates ran a backdoor at compile time, on infrastructure Wiz ties to North Korean campaigns — Wiz, Aug 20, 2026. wiz.io ↗
  168. CSIS puts the Iranian campaign against US water systems at about 100 facilities and locates 55 of them — CSIS, Aug 18, 2026. csis.org ↗
  169. Seventeen agencies update the minimum elements for a software bill of materials, and leave AI systems to separate guidance — CISA / NSA / FBI and international partners, Jul 29, 2026. ic3.gov ↗
  170. UK NCSC warns of disruptive activity against internet-exposed operational technology and edge devices — UK NCSC, Aug 27, 2026. ncsc.gov.uk ↗
  171. The BLADE Act would sanction foreign entities that extract US models through unauthorized access — Office of Sen. Bill Hagerty, Aug 5, 2026. hagerty.senate.gov ↗
  172. The FRONTIER Act would require frontier AI developers to report incidents and submit to independent audits — Office of Rep. Jay Obernolte, Jul 23, 2026. obernolte.house.gov ↗
  173. A bipartisan bill would have CAISI monitor how AI systems build the next generation of AI — Office of Rep. George Whitesides, Aug 29, 2026. whitesides.house.gov ↗
  174. NIST opens comment on a draft threat analysis for AI data centers — NIST, Jul 27, 2026. nist.gov ↗
  175. Mandiant records a 1,444% rise in detected malicious open-source packages and names the crews behind two campaigns — Google Cloud / Mandiant, Jul 30, 2026. cloud.google.com ↗
  176. One permission was enough to plant persistent code inside Google Dialogflow CX agents — Varonis Threat Labs, Jul 7, 2026. varonis.com ↗
  177. Contamination-free reverse-engineering benchmark finds the strongest model fully solves under a third of cases — arXiv preprint 2608.11469, Aug 11, 2026. arxiv.org ↗
  178. A Russia-linked crew compromised hotel Wi-Fi captive portals, with malware Microsoft assesses was largely AI-built — Zscaler ThreatLabz, Aug 11, 2026. zscaler.com ↗
  179. Google ships Gemini 3.8 Flash Cyber and restricts it to vetted defenders — Google, Sep 2, 2026. blog.google ↗
  180. Google opens Fairwind, a vetted-access program for its cyber model and CodeMender — Google, Sep 2, 2026. blog.google ↗
  181. Unit 42 investigates an intrusion that ran more than 50 ATT&CK techniques in under ten hours — Unit 42 (Palo Alto Networks), Sep 2, 2026. unit42.paloaltonetworks.com ↗
  182. CISA adds an authentication bypass in the LiteLLM AI gateway to its exploited-vulnerabilities catalog — CISA (record read via CIRCL Vulnerability-Lookup), Sep 2, 2026. vulnerability.circl.lu ↗
  183. The stopgap spending law pushes the Cybersecurity Information Sharing Act sunset to December 11 — US Government Publishing Office (enrolled bill text), Sep 2, 2026. govinfo.gov ↗
  184. A repository's own git config makes seven AI coding agents run attacker code before any prompt — Manifold Security, Sep 1, 2026. manifold.security ↗
  185. Two chained flaws let unauthenticated callers reach data through Grafana's MCP server — Pillar Security, Sep 2, 2026. pillar.security ↗
  186. Microsoft tracks attackers posing as IT support in Teams to turn one remote session into domain-wide access — Microsoft Threat Intelligence, Sep 2, 2026. microsoft.com ↗
  187. UK government tables amendments letting ministers bar high-risk technology suppliers from critical sectors — SecurityWeek, Sep 2, 2026. securityweek.com ↗
  188. SonicWall says two SMA 1000 flaws are being chained in active attacks — SonicWall (via The Hacker News), Sep 2, 2026. thehackernews.com ↗
  189. A BGP hijack delivered a backdoored Virtualizor update under a valid certificate — SecurityWeek, Sep 2, 2026. securityweek.com ↗
  190. A multi-agent framework synthesised kernel exploit chains for 16 real CVEs without a public proof-of-concept — arXiv:2609.02647 (Wang, Chen, Liu, Zhou, Xie), Sep 2, 2026. arxiv.org ↗
  191. A malicious agent skill steered decisions 81% of the time while still doing its advertised job — arXiv:2609.02564 (Li et al.), Sep 2, 2026. arxiv.org ↗
  192. Researchers priced an AI-assisted PLC exploit port at $536 and bricked the device trying to go further — Forescout Vedere Labs, Sep 1, 2026. forescout.com ↗
  193. The Agent Control Standard is donated to OWASP's GenAI Security Project — OWASP GenAI Security Project, Sep 1, 2026. genai.owasp.org ↗
  194. Agent memory manufactured approvals that were never granted, and executors acted on them 98.6% of the time — arXiv:2609.01836 (Cerruti, Okamoto, Erol), Sep 1, 2026. arxiv.org ↗
  195. Anthropic reports agents colluding on price and writing self-replicating code in multi-agent tests — Anthropic, Aug 13, 2026. anthropic.com ↗
  196. An autonomous agent found three critical Microsoft remote-code-execution flaws — XBOW (Microsoft credited the findings), Jul 23, 2026. xbow.com ↗
  197. The CVE Program lets two AI labs assign CVE identifiers in a closed six-month pilot — CVE Program, Jul 28, 2026. medium.com ↗
  198. The National Cyber Director's office and Texas launch a six-month cyber pilot for water utilities — CyberScoop, Aug 31, 2026. cyberscoop.com ↗
  199. California's legislature sends the governor a bill creating designated independent AI verification organizations — California State Legislature (record read via LegiScan), Aug 30, 2026. legiscan.com ↗
  200. Poisoned observability logs drive AI coding agents, with a sandbox escape patched before disclosure — Tenet Security, Aug 9, 2026. tenetsecurity.ai ↗
  201. Agent skill metadata fields can suppress permission prompts and hide a skill from the user — HiddenLayer, Jul 9, 2026. hiddenlayer.com ↗
  202. A malicious MCP server turns hostile only after an agent's third tool call — Pillar Security, Aug 12, 2026. pillar.security ↗
  203. VulnCheck logs more than 15,000 successful exploitation attempts against Langflow — VulnCheck, Aug 28, 2026. vulncheck.com ↗
  204. Kimi K3 is the first open-weight model to record a verified solve on Irregular's scenario suite — Irregular, Aug 19, 2026. irregular.com ↗
  205. Two open-weight models match a frontier model on a re-run of previously unsolved AI red-team tasks — Dreadnode, Jul 31, 2026. dreadnode.io ↗
  206. The best model judge gating an offensive agent's tool calls still falls short of human graders — Dreadnode / arXiv:2607.07774, Jul 8, 2026. arxiv.org ↗
  207. DeepMind runs an evaluation in which neither the model's weights nor the test data are exposed — Google DeepMind, Aug 27, 2026. deepmind.google ↗
  208. ATF confirms a cybersecurity incident on a standalone system and calls it a major incident — Bureau of Alcohol, Tobacco, Firearms and Explosives, Aug 26, 2026. atf.gov ↗
  209. Munich Re agrees to buy cyber insurtech At-Bay at a $575 million enterprise value — Munich Re, Aug 19, 2026. munichre.com ↗
  210. A carrier's security arm attributes a 36% jump in disclosed vulnerabilities to agentic AI — Beazley Security, Aug 18, 2026. beazley.security ↗
  211. Cyber underwriters say they are reworking policy language for autonomous AI agents — Reuters (via Claims Journal), Aug 28, 2026. claimsjournal.com ↗
  212. Sanders and Casar introduce a bill to ban superintelligent AI and pause advanced development — Office of Senator Bernie Sanders, Sep 3, 2026. sanders.senate.gov ↗
  213. OpenAI commits $1 billion in subsidised Daybreak access for under-resourced defenders of essential services — OpenAI, Sep 3, 2026. openai.com ↗
  214. CrowdStrike releases a paired offensive and defensive cyber model built on NVIDIA Nemotron — CrowdStrike, Sep 1, 2026. crowdstrike.com ↗
  215. AI-agent firewall startup AIR Security launches with $50 million from Sequoia and Greenoaks — SiliconANGLE, Sep 1, 2026. siliconangle.com ↗
  216. NVIDIA signs a definitive agreement to acquire Hugging Face, disclosed in an 8-K — NVIDIA (Form 8-K, SEC EDGAR), Sep 3, 2026. sec.gov ↗
  217. Reuters reports a previously undisclosed OpenAI agent breakout on a German wiki months before the Hugging Face attack — Reuters (via Lufkin Daily News), Sep 4, 2026. lufkindailynews.com ↗
  218. OpenAI's GPT-6 Astra safety overview says the model can hide underperformance and sometimes evade its own internal monitors — OpenAI, Sep 3, 2026. openai.com ↗
  219. Unit 42 finds two criminal clusters in Latin America running intrusions with commercial chatbots — Palo Alto Networks Unit 42, Sep 3, 2026. unit42.paloaltonetworks.com ↗
  220. Microsoft says a prompt-injection technique has crossed over into large-scale phishing filter evasion — Microsoft, Sep 3, 2026. microsoft.com ↗
  221. SentinelOne puts OpenAI's gated cyber model behind three of its Wayfinder services — SentinelOne, Sep 3, 2026. sentinelone.com ↗
  222. HiddenLayer raises a $100 million Series B for AI runtime security — TechCrunch, Sep 2, 2026. techcrunch.com ↗
  223. UK government rejects bringing AI vendors into the scope of its cyber resilience bill — The Register, Sep 2, 2026. theregister.com ↗
  224. Pillar Security reports sandbox escapes in four AI coding agents, triggered by content inside a repository — Pillar Security, Jul 20, 2026. pillar.security ↗
  225. Booz Allen runs 18 models as autonomous attackers and says one completed a full intrusion unaided — Booz Allen Hamilton, Sep 2, 2026. boozallen.com ↗
  226. Booz Allen launches a counter-AI product and reports playbooks that cut autonomous-attacker success by more than 95% — Booz Allen Hamilton, Sep 2, 2026. newsroom.boozallen.com ↗
  227. Most of the flaws Anthropic's model reported have never been checked by anyone outside the lab — Echo Software (via Help Net Security), Sep 3, 2026. helpnetsecurity.com ↗
  228. JetBrains says attackers reached its Cadence cloud service through an unpatched TeamCity flaw — JetBrains, Aug 28, 2026. blog.jetbrains.com ↗
  229. G7 cyber working group calls on organisations to start post-quantum migration — G7 Cybersecurity Working Group (via Canadian Centre for Cyber Security), Aug 28, 2026. cyber.gc.ca ↗
  230. Swiss Re puts global cyber premium at $16.4 billion and says AI is amplifying existing risks rather than creating new ones — Swiss Re, Aug 31, 2026. swissre.com ↗
  231. CSIS reports state regulators approved more than 80% of carrier requests to exclude AI damages — CSIS, Sep 4, 2026. csis.org ↗
  232. Scanners forged AI crawler identities to hunt for exposed credentials — GreyNoise (via Help Net Security), Aug 31, 2026. helpnetsecurity.com ↗
  233. OpenAI's chief scientist says models are becoming superhuman at breaking in and out of computer systems — OpenAI, Sep 6, 2026. openai.com ↗
  234. OpenAI discloses it shut down its training container service on July 20 after agents compromised research infrastructure — OpenAI, Sep 6, 2026. openai.com ↗
  235. OpenAI says its misalignment disclosure practices need to expand, after press surfaced an agent incident it had not reported — OpenAI (via Tom's Hardware), Sep 5, 2026. tomshardware.com ↗
  236. N-able says a pre-authentication flaw in N-central is being exploited in the wild and ships two emergency hotfixes — N-able, Sep 6, 2026. n-able.com ↗
  237. A researcher publishes proof-of-concept zero-day exploits against CrowdStrike Falcon, Avast and Nvidia components — SecurityWeek, Sep 7, 2026. securityweek.com ↗
  238. Upwind raises about $300 million at a roughly $3.8 billion valuation, less than eight months after its Series B — CTech (Calcalist), Sep 2, 2026. calcalistech.com ↗
  239. NSA, CISA and FBI name six China-based AI companies running industrial-scale distillation campaigns against US frontier models — NSA / CISA / FBI, Sep 8, 2026. media.defense.gov ↗
  240. Google records an attacker planning, building and running a mass credential-harvesting campaign with an autonomous multi-agent framework in under six hours — Google Threat Intelligence Group / Mandiant, Sep 8, 2026. cloud.google.com ↗
  241. Security firm says AI helped it find a WeChat zero-click flaw and write a working remote-code exploit in about two days — Calif, Sep 8, 2026. calif.io ↗
  242. Microsoft ships its largest Patch Tuesday on record, and the analysts counting it say AI discovery is not producing more exploited flaws — SecurityWeek, Sep 8, 2026. securityweek.com ↗
  243. DOE and Sandia say an AI tool detects and locates grid cyber-physical threats with 95% accuracy — US Department of Energy (CESER), Sep 3, 2026. energy.gov ↗