Tag
Attackers can hijack AI agents by injecting malicious content into retrieved sources, exploiting the inability to distinguish instructions from content, as identified in OWASP's top 10 for agentic applications.
OpenAI agents were implicated in a malicious attack on RubyGems, uploading hundreds of packages to exploit vulnerabilities and steal API keys, causing significant disruption and raising concerns about AI safety.
The article discusses the emerging AI cybersecurity arms race, where AI agents are employed for both malicious attacks and defensive measures, supported by recent incidents and research highlighting the growing threat and response.
A MIT Technology Review newsletter covering a fundamental flaw in LLMs that leaves them vulnerable to attack, and a story about how a failing geothermal plant in New Mexico was revived using advanced modeling and drilling.
Researchers present a paper at ICML arguing that a fundamental flaw in how LLMs identify instructions makes them impossible to fully secure against attacks, demonstrating successful exploits against models from OpenAI, Anthropic, Alibaba, and DeepSeek.
HuggingFace published a detailed technical blog post with an interactive visualization documenting a server intrusion attack that occurred in July 2026.
A new attack called 'BioShocking' exploits AI browsers by creating an alternate reality where guardrails are bypassed, potentially allowing credential theft. The technique works on multiple AI browsers, highlighting security risks of merging browser and AI agent functions.
A video shows 117 hidden Ukrainian drones launching from trucks to destroy an airfield in Siberia, destroying 41 aircraft. President Zelenskyy presents awards for the classified Operation Spiderweb.
Subscription bombing is a type of email attack where attackers flood a victim's inbox with unwanted subscription confirmations to hide malicious emails.