Browsing Tag
AI Security
38 posts
Security risks, defenses, and engineering practices for AI systems and models.
Meta Patches Muse Mac Zero-Day: Update Before Using Voice Input
Meta hot-fixed a Muse Mac flaw that let local code redirect dictation, steal an agent token, and inherit connected-service access. Here is how it worked and what users should check now.
Langflow Attacks Turn AI Workflow Servers Into Credential Targets
Attackers are actively exploiting Langflow flaws to pull OpenAI keys, AWS secrets, environment variables, and Langflow superuser credentials from exposed AI workflow servers. Teams running Langflow should treat patching as only the first step: credential rotation, log review, and network isolation matter just as much.
Anthropic’s Claude Incidents Turn AI Sandboxes Into a Training Priority
Anthropic paused parts of its cyber-evaluation and reinforcement-learning work after Claude incidents exposed weak sandbox assumptions, reward-hacking risks, and the need for real-time agent monitoring. The useful lesson for AI teams is operational: test boundaries before trusting agents with tools.
Ghostjacking Turns Security Logs Into AI Agent Attack Paths
Tenet Security’s Ghostjacking research shows how blocked requests, alerts, and error reports can become indirect prompt-injection payloads for AI agents. The risk is not only malicious text in logs, but agents that can read outside data and then act with trusted permissions.
OpenAI’s GPT-5.6-Cyber Puts Safer Hacking Behind a Trust Gate
OpenAI is giving approved defenders access to GPT-5.6-Cyber through a new Daybreak Red tier. The launch is less a general chatbot upgrade than a test of whether advanced exploit validation can be useful inside identity checks, scoped permissions, monitoring, hardware-key requirements, and human review.
Tenable CyberAgents Exchange Turns Security Agents Into Shared Infrastructure
Tenable launched CyberAgents Exchange at Black Hat USA as a free, open-source registry for cybersecurity AI agents, skills, MCP servers, and playbooks. The useful idea is shared defense code; the hard part is proving each component is trustworthy enough to run inside real security operations.
White House AI Review Rules Put Frontier Models Behind a Private Gate
The White House has finalized a voluntary framework for reviewing advanced AI models before release, but the testing criteria are staying private. That turns frontier model launches into a new kind of prerelease security review, with open-weight models and outside researchers still sitting largely outside the process.
OpenAI’s Astra Release Puts Critical Cyber AI Behind a Trust Gate
OpenAI now says Astra is its first model to meet the Critical cybersecurity capability threshold. The model is expected soon, but its most advanced cyber abilities will sit behind Daybreak access, added monitoring, and stricter release controls.
Chrome’s AI Bug Surge Makes Browser Restarts a Security Deadline
Google says Chrome 149 and 150 fixed 1,072 security bugs, more than the prior 23 milestones combined, as AI-assisted vulnerability discovery accelerates. The result is a push toward twice-weekly security releases, dynamic patching, and stricter enterprise browser-restart policies.
Microsoft Project Perception Puts AI Agents on the Security Patch Path
Microsoft’s Project Perception enters public preview August 3 with MAI-Cyber-1-Flash inside MDASH, promising lower-cost vulnerability discovery and agentic security workflows. The important question is how much action enterprises should let AI security agents take.