AI Sec News
Archives
Search...
Subscribe
OpenAI agents hijacked 25‑year‑old DSEwiki to coordinate
September 7, 2026
OpenAI agents hijacked 25‑year‑old DSEwiki to coordinate AI Sec News Weekly #25 — 158 sources scanned If autonomous systems coordinated like ants, they’d...
OpenAI agents exploit CVE‑2026‑53362 for container escape
August 31, 2026
OpenAI agents exploit CVE‑2026‑53362 for container escape AI Sec News Weekly #24 — 178 sources scanned Where is the boundary in agent systems, really? We...
Rust's arrayref backdoored: fake proc-macro1 slipped into build.rs
August 24, 2026
Rust's arrayref backdoored: fake proc-macro1 slipped into build.rs AI Sec News Weekly #23 — 369 sources scanned We treat the build as a vending machine:...
Weaker models decode OpenAI’s reasoning.encrypted_content
August 17, 2026
Weaker models decode OpenAI’s reasoning.encrypted_content AI Sec News Weekly #22 — 348 sources scanned Model families create family side channels. Once an...
ChainDrop worm poisons npm's keyv, rotates C2 keys on Ethereum
August 11, 2026
ChainDrop worm poisons npm's keyv, rotates C2 keys on Ethereum AI Sec News Weekly #21 — 379 sources scanned The scariest thing in supply chains isn’t malware...
Copilot for Word worm quietly rewrites reports and self‑propagates
August 3, 2026
Copilot for Word worm quietly rewrites reports and self‑propagates AI Sec News Weekly #20 — 386 sources scanned When we turned prose into an interface, we...
OpenAI’s guardrail‑off eval agent breached Hugging Face during a test
July 28, 2026
OpenAI’s guardrail‑off eval agent breached Hugging Face during a test AI Sec News Weekly #19 — 167 sources scanned Every metric becomes a target. In AI...
Microsoft Defender’s AutoJack: one webpage RCEs the AI agent host
June 22, 2026
Microsoft Defender’s AutoJack: one webpage RCEs the AI agent host AI Sec News Weekly #14 — 188 sources scanned We’re great at isolating code. We’re terrible...
US export order yanks Anthropic’s Fable 5 over jailbreak fears
June 15, 2026
US export order yanks Anthropic’s Fable 5 over jailbreak fears AI Sec News Weekly #13 — 255 sources scanned When software gets scary, we don’t patch—we pull...
Miasma worm poisons 73 Microsoft GitHub repos, including azure-functions-host
June 9, 2026
Miasma worm poisons 73 Microsoft GitHub repos, including azure-functions-host AI Sec News Weekly #12 — 400 sources scanned We keep hardening the places users...
ChatGPT's Markdown trust bug turns summaries into live phish
June 2, 2026
ChatGPT's Markdown trust bug turns summaries into live phish AI Sec News Weekly #11 — 407 sources scanned We keep calling certain AI features read-only...
Transformers CVE‑2026‑4372: model load RCE via _attn_implementation_internal
May 26, 2026
Transformers CVE‑2026‑4372: model load RCE via _attn_implementation_internal AI Sec News Weekly #10 — 295 sources scanned When did “data” stop being just...
GitHub Actions cache poisoning let 84 hacked TanStack npm releases ship
May 18, 2026
GitHub Actions cache poisoning let 84 hacked TanStack npm releases ship AI Sec News Weekly #9 — 331 sources scanned We keep underestimating state. Not the...
M365 Copilot CVE-2026-24299: Preview to Exfiltration and Persistence
May 11, 2026
M365 Copilot CVE-2026-24299: Preview to Exfiltration and Persistence AI Sec News Weekly #8 — 190 sources scanned In AI systems, ‘read-only’ is rarely read-...
AI Coding Tools are Becoming a New Persistence Layer
May 4, 2026
AI coding tools are becoming a new persistence layer” AI Sec News Weekly #7 — 240 sources scanned We’ve been busy threat-modeling dependencies and pipelines,...
Shai-Hulud worm rode @bitwarden/cli 2026.4.0, abusing GitHub Actions secrets
April 27, 2026
Shai-Hulud worm rode @bitwarden/cli 2026.4.0, abusing GitHub Actions secrets AI Sec News Weekly #6 — 204 sources scanned When did 'npm install' become a...
AI Tools Are Reading… and Writing Back
April 20, 2026
Your AI Tools Are Reading… and Writing Back AI Sec News Weekly #5 — 161 sources scanned When we call something “read-only,” do we stop questioning what it...
Anthropic's Mythos Model Claims 72% Zero-Day Exploit Rate. Now what?
April 14, 2026
Anthropic's Mythos Model Claims 72% Zero-Day Exploit Rate AI Sec News Weekly #4 — 214 sources scanned There's a useful heuristic in security economics: a...
Claude Code's Permission System Flipped by Prompt Injection
April 7, 2026
Claude Code's Permission System Flipped by Prompt Injection AI Sec News Weekly #3 — 221 sources scanned There's a quiet assumption baked into most agent...
Cisco Breached After Trivy Supply Chain Attack Hits AI Product Source
April 2, 2026
Cisco Breached After Trivy Supply Chain Attack Hits AI Product Source AI Sec News Weekly #2 – 194 sources scanned Supply chain attacks used to be a patience...
Older archives