AI Security

LLM & AI-agent attack research plus the AI-security news cycle — prompt injection, jailbreaks, agent abuse, model attacks — last 90 days.

Spotlight · past 30 days

TypeSource

103 items · last 90 days

  • 2026-08-26 · SecurityWeek
    Palo Alto Networks Unit 42 analyzed 405 AI-linked malware samples and found only 12 reached production endpoints. The post AI Speeds Up Malware Development, Not Its Success Rate: Analysis appeared first on SecurityWeek.
    news
  • 2026-08-26 · Cyber Security News
    Cybercriminals are using a counterfeit Claude desktop application to compromise Windows systems, disable key security checks, and install remote-access malware. The campaign turns a familiar AI software search into a route for credential theft and long-term access. It also shows how trusted-looking download pages can make a dangerous file appear routine. For organizations, the campaign […] The post Hackers Use Fake Claude Desktop App to Disable Defender and Install Remote Access Malware appeared
    news
  • 2026-08-26 · The Hacker News
    Aikido Security has published research that recreates the Australian gym-booking incident in a synthetic environment, finding that Claude Opus 4.6, running on the OpenClaw agent harness, exploited a client-side-only booking restriction in 9 of 10 runs. The original incident was first reported by ABC News on August 10, based on chat logs and screenshots the user supplied. He had asked an
    news
  • 2026-08-26 · SecurityWeek
    Most of the flaws were discovered by Google using AI, but researchers are still discovering high-value Chrome vulnerabilities. The post Chrome 152 Patches Over 300 Vulnerabilities appeared first on SecurityWeek.
    news
  • 2026-08-26 · SecurityOnline
    Operation CameraSwarm compromised 14,500+ Dahua cameras in 35 days. Hunt.io traced the camera hacking campaign to an exposed operator directory. Related Posts: Core Werewolf Deploys New CoreRAT Malware Against Russian Targets Balonx Sistema: Mexican PhaaS Adds AI Vishing and RAT StopAndProtect Malware Turns Hacked WordPress Sites Into a Botnet The post Operation CameraSwarm: 14,500 Dahua Cameras Compromised Across Ukraine and Russia appeared first on Daily CyberSecurity.
    news
  • 2026-08-25 · Dark Reading
    With some simple HTML that's invisible to users, attackers can manipulate AI-powered email summarizers into producing malicious information.
    news
  • 2026-08-25 · Dark Reading
    Attackers can exploit a security bug in Nvidia's tool to gain unauthenticated access to the local model server through the Ollama API, paving the way for persistent AI agent corruption.
    agent-abusenews
  • 2026-08-25 · OpenSourceMalware
    The package is published as 'chai-as-testkit' with a description referencing vulnerability management, but the tarball ships pino's README, docs/, index.d.ts, and lib/ tree (proto, levels, transport, worker, redaction) under an unrelated author (Robert King <[email protected]>, bugs.url jsonspack.com) rather than the real pinojs publisher. The shipped index.js is a synthetic stub whose only effect is `const config = require('./lib/config')`, and lib/config.js is a 4,083,409-byte single-line obfuscator.io-style bundle: a rotated hex-escaped string array of ~23,953 entries with control-flow flattening and dead-code layers (webcrack inlines 40,105 decoded strings across the decoder layers before failing to serialize). This blob runs immediately when any consumer imports the package, executing attacker-controlled code inside the developer or CI Node.js process. The pino impersonation is the social-engineering wrapper around an on-import loader; the shape (name/description/author mismatch + hollow main entry that delegates to a multi-megabyte obfuscated module at require time) is a typosquat-delivered install/import-time RCE vehicle rather than a logging library.
    malwarenpmpoisoningsupply-chain
  • 2026-08-25 · The Hacker News
    Vulnerability management has been a staple of security programs since the dawn of the cybersecurity discipline. The symbiotic relationship between vulnerability and patch management teams has also existed for that time and has gone through waves of contention and thankfulness. While this relationship required thoughtful care and feeding from both sides, both sides were aiming to work toward a
    news
  • 2026-08-25 · Adversa AI
    OWASP's newest Top 10 covers the skill layer: prose files agents load and act on. What all ten risks mean, and the order to fix them.
    adversaagent-abuse
  • 2026-08-25 · AI Incident DB
    Two class action lawsuits are in the works against two major AI companies, Udio and Suno, on behalf of independent artists. Lawyers at Delgado Entertainment Law and Hagens Berman have urged indie artists to get involved in the lawsuits. Thi ... (https://incidentdatabase.ai/cite/1655#7811)
    ai-incident
  • 2026-08-25 · AI Incident DB
    The American Federation of Musicians has filed an amended complaint in its lawsuit against Universal Music Group and Warner Music Group, accusing the majors of breaching their union contract by failing to pay musicians for recordings licens ... (https://incidentdatabase.ai/cite/1655#7828)
    ai-incident
  • 2026-08-25 · AI Incident DB
    Law firm's high tech and intellectual property teams come together with Delgado Entertainment Law PLLC to represent "the music community's most vulnerable and valuable creators" SEATTLE -- Attorneys at Hagens Berman have joined forces with ... (https://incidentdatabase.ai/cite/1655#7819)
    ai-incident
  • 2026-08-25 · AI Incident DB
    The AI music generation tool Suno scraped millions of songs and lyrics from YouTube Music, Deezer, and Genius, as well as from the stock music libraries Pond5, Jamendo, Freesound, the International Music Score Library Project, and podcasts ... (https://incidentdatabase.ai/cite/1655#7803)
    ai-incident
  • 2026-08-25 · AI Incident DB
    In a "landmark victory" for musicians globally, AI music company Suno has lost a major copyright lawsuit brought by Germany's music rights organisation GEMA. The Munich Regional Court has found that the US-based company has breached copyri ... (https://incidentdatabase.ai/cite/1655#7809)
    ai-incident
115 of 103
Page/ 7