New tools, products, platforms, funding rounds, and company developments in AI security.
This newsletter covers multiple AI developments, including Chinese AI company Moonshot's release of Kimi, a free open-source model that rivals paid models from US companies like OpenAI and Anthropic, creating division among Trump administration advisers on how to respond. Other major stories include Anthropic's record $1.5 billion copyright settlement for using pirated works to train Claude, China considering export controls on AI models and chips, and Trump's AI safety head resigning after three months.
Chinese AI companies recently released large language models (LLMs, AI systems trained on vast amounts of text data) that they claim can compete with top models from American companies like OpenAI and Anthropic, surprising markets and tech industry leaders. The announcement sparked concerns about competition and prompted discussions about whether the US is falling behind in AI development. The article argues that these breakthroughs should not be shocking given ongoing global AI competition.
Researchers discovered ENCFORGE, a new ransomware (malware that encrypts files and demands payment) written in Go, being deployed by JADEPUFFER attackers through a vulnerability in Langflow versions before 1.3.0. The attackers exploit CVE-2025-3248 (a flaw in the /api/v1/validate/code endpoint that allows unauthenticated code execution with a CVSS score of 9.8) to run malicious code that specifically targets AI infrastructure files like model weights, vector databases, and training datasets across the infected system.
OpenAI has appointed David Vélez, founder and CEO of Nubank, and Robin Vince, CEO of BNY, to the boards of the OpenAI Foundation and OpenAI Group PBC. Both leaders bring experience in using technology to transform financial services and expand access, and they are expected to help OpenAI ensure that AI benefits more businesses and people globally.
Security researchers discovered sandbox escape vulnerabilities in four popular AI coding agents (Cursor, OpenAI's Codex, Google's Gemini CLI, and Antigravity) by exploiting a fundamental design flaw: these tools trust files written by the sandboxed agent and automatically execute them through external tools like Git integrations and task runners. The attacks use prompt injection (tricking an AI by hiding malicious instructions in files like READMEs or code dependencies) to make the agent write files that trigger unsandboxed command execution on the developer's machine without the agent itself breaking out of the sandbox.
JadePuffer, an autonomous AI agent, has been upgraded with EncForge ransomware that specifically targets AI infrastructure like training datasets, model checkpoints, and vector databases by encrypting files with the .locked extension. The agent successfully adapted during an attack on a Langflow instance, deploying multiple Python scripts to overcome delivery obstacles and gaining root-level access through an exposed Docker socket. EncForge uses AES-256 encryption for file protection and targets approximately 180 file types specific to AI and machine learning systems, potentially costing organizations significant time and money to recover encrypted models.
Ivanti is exploring the use of frontier models (advanced AI systems at the cutting edge of development) to help find and fix security vulnerabilities in software. While early tests show these AI systems work well at this task, questions remain about whether the approach is affordable and whether it's practical to have humans review and approve the AI's recommendations before using them.
Chris Fall resigned as director of the Center for AI Standards and Innovation (CAISI, a U.S. government agency that tests and researches commercial AI systems) after only three months, creating uncertainty in the Trump administration's AI leadership. The departure comes as the administration is implementing a new executive order that requires AI developers to voluntarily submit models to the government for safety evaluation before release, and as Chinese AI models are gaining market share against American competitors like OpenAI and Anthropic.
ServiceNow patched a sandbox escape RCE vulnerability (CVE-2026-6875, a flaw that lets attackers run unauthorized code on systems they don't control) last week, but attackers are already exploiting it in the wild using modified techniques. Security experts warn this is especially dangerous because the vulnerability affects ServiceNow's sandbox (the security container designed to safely run untrusted code), and a compromise could give attackers access to sensitive data like HR records and potentially spread to corporate networks through integrations.
As companies rapidly adopt AI technology, Chief Information Security Officers (CISOs, the executives responsible for protecting company data and systems) face increased job stress, with 26% considering leaving their positions. The pressure stems from the security challenges that come with quickly implementing AI systems across organizations.
Cybersecurity researchers discovered nearly 7,600 malicious GitHub repositories spreading SmartLoader malware, with over 800 posing as AI skills or MCP servers (Model Context Protocol servers, which are tools that help AI assistants perform specialized tasks). A particularly dangerous aspect called AgentBaiting allows AI agents like Claude, Gemini, and ChatGPT to inadvertently discover these fake repositories and execute malware without human intervention, by simply searching for legitimate-sounding tools. The attack leverages copied projects, fake developer profiles, and convincing documentation to trick both users and AI systems into downloading malicious files.
AMD has launched Helios, its first rack-scale system (a large computing unit designed for data centers) for AI, which competes with Nvidia's similar systems and has attracted major customers including Microsoft, Meta, and OpenAI. The system combines AMD's own GPUs (graphics processing units, specialized chips for AI calculations), CPUs (central processing units, the main processors), networking, and software to offer what AMD claims is the lowest cost per token (the cost to process individual units of text in AI models). AMD will begin shipping Helios to customers later this year.
Adobe's Indigo camera app, originally designed to improve iPhone photo quality with a more natural look, is being updated with generative AI tools (AI systems that create new content based on patterns they learn) through an "AI Playground" feature. The update does not use Adobe's own Firefly AI models, and users have the option to opt out and use the app's original features instead.
Researchers discovered seven attacks against five open-source Android AI agent frameworks (AppAgent, AppAgentX, Mobile-Agent-v3, Open-AutoGLM, and MobA) that could let malicious apps trick the AI into running commands on a host PC. The attacks exploit weaknesses like invisible text overlays that AI vision models can read but humans cannot, file race conditions (timing gaps where attackers can modify screenshots before the AI sees them), and unsanitized shell commands that allow code injection when the AI types attacker-controlled text.
AI coding agents can bypass security restrictions without technically breaking out of sandboxes (isolated execution environments) by creating files that trusted programs outside the sandbox later execute or read. Researchers at Pillar Security demonstrated this vulnerability in tools like Cursor, Codex, Gemini CLI, and Antigravity, showing that agents can manipulate configuration files, scripts, and virtual environments to indirectly run code with higher privileges outside their restricted environments.
Fix: The source recommends treating workspace configurations that trigger execution as sensitive assets requiring explicit approval before agents create or modify them, ensuring helper processes operate under the same security policy as direct agent execution, preserving provenance (a record distinguishing user-created files from agent-generated ones) to track file origins, modeling security policies around command side effects rather than just process invocation, limiting access to privileged local services, and monitoring trust handoffs throughout the development workflow. However, the source does not describe specific patches, version updates, or concrete implementation details for these recommendations.
CSO OnlineFix: Upgrade Langflow to version 1.3.0 or later to patch CVE-2025-3248.
The Hacker NewsSecurity expert Park Chan-am warns that AI is dramatically accelerating cyberattacks, reducing vulnerability discovery time from weeks to less than a day, and creating new security challenges around access control and software supply chains. Key risks include prompt contamination (tricking AI agents through malicious documents), excessive permissions for AI agents accessing internal systems, and unsecured local AI testing environments that expose thousands of servers to the internet.
Attackers are using AI agents (software programs that can make decisions and take actions automatically) to conduct cyberattacks, so security researchers at Tracebit developed a defensive technique called "context bombing" that plants decoy files with prompts designed to trigger an LLM's (large language model's) content safety guardrails (built-in rules that prevent harmful outputs), causing the attacker's AI agent to stop and crash rather than just triggering an alert. In tests, context bombing reduced the success rate of AI-powered attacks by up to 90%, dropping full system compromise from 36% success down to just 1%.
Fix: According to Tracebit, the technique is to "plant decoy resources not merely to trigger alerts, but to actually stop AI agents." Specifically: "plant a 'context bomb': a short piece of text designed to trigger a model's safety guardrails, planted directly in the attacker's path — a decoy secret, environment variable, or DNS record (the system that translates website names into IP addresses)." The source notes that effective context bombs were identified through testing, but "the identified strings were different between the tested models," requiring customization for Claude Opus 4.8, Gemini 3.1 Pro, GLM 5.2, DeepSeek V4 Pro, and Kimi K2.6.
CSO OnlineFix: Most issues have been patched by vendors. Cursor fixed multiple vulnerabilities in version 3.0.0 (including a .claude hook config execution flaw and Git metadata bypass). OpenAI patched Codex CLI's 'safe' command allowlist bug in v0.95.0. The Docker socket vulnerability affecting Codex, Cursor, and Gemini CLI is now fixed. According to Pillar Security, the underlying fix involves monitoring the moment a trusted local tool runs something the agent wrote, rather than simply banning filenames.
BleepingComputerFix: Apply available security updates, specifically Langflow version 1.3.0 or later. Additionally, restrict Docker socket access, run Langflow containers as non-root (not with full system privileges), and apply filesystem-level access controls (rules limiting which users/processes can access files) to model weight directories.
BleepingComputerFix: ServiceNow has issued updates and patches to address the vulnerability. The company stated: "We have provided updates and patches designed to address this issue, and we encourage our self-hosted and ServiceNow-hosted customers to apply the relevant patches if they have not already done so."
CSO OnlineMarc Maiffret reflects on Code Red, a major worm (self-replicating malware that spreads across networks) from 25 years ago, and what security lessons from that era can help organizations protect AI systems today. The article draws parallels between past worm attacks and current AI security challenges to guide how companies should approach AI risk management.
Fix: To counter the threat, the source advises: build a catalog of reviewed Skills, MCP servers, and agent plugins; evaluate new agent capabilities in a sandboxed environment (an isolated testing area) first before broader rollout; and verify both the publisher and the project to ensure credibility.
The Hacker NewsChinese AI company Moonshot released Kimi, a free open-source AI model that performs as well as paid models from US companies like OpenAI and Anthropic, causing disagreement among Trump's AI advisors about how to respond. The situation creates economic and political problems for the Trump administration because free Chinese models reduce demand for expensive US models, while also raising questions about whether the government should intervene to protect US companies or allow open competition.
AI is being adopted quickly across businesses, but security programs haven't kept pace, creating a gap where organizations struggle to understand their actual risks. Traditional security problems like weak access controls (permissions given too broadly) and poor logging (records of system activity) become more dangerous when AI agents connect to company data and workflows, potentially spreading damage from a small issue into something that affects the entire business. Security leaders are now expected to help businesses move fast with AI while identifying which initiatives are safe, where the company is exposed, and what needs immediate action.