AI agents
Systems in which a model plans and takes actions through tools, browsers or other software on someone's behalf.
- All items
- 763
- Last 90 days
- 325
- Change
- +44%vs 225 before
Items per month
| Month | Items |
|---|---|
| May 2025 | 3 |
| Jun 2025 | 4 |
| Jul 2025 | 4 |
| Aug 2025 | 5 |
| Sep 2025 | 11 |
| Oct 2025 | 6 |
| Nov 2025 | 3 |
| Dec 2025 | 8 |
| Jan 2026 | 10 |
| Feb 2026 | 49 |
| Mar 2026 | 89 |
| Apr 2026 | 51 |
| May 2026 | 76 |
| Jun 2026 | 78 |
| Jul 2026 | 112 |
| Aug 2026 | 78 |
| Sep 2026 | 133 |
| Oct 2026 | 38 |
573 items
How to manage AI investments in the agentic era
Jul 14, 2026InfoNewsIndustryPolicyOpenAI says the price per million tokens fell 97% from GPT-4 to GPT-5.4, and that GPT-5.6 performs better on the Artificial Analysis Coding Agent Index with 54% fewer output tokens and 57% less time per task. The article argues that leaders should measure useful work per dollar rather than token price alone, and it outlines five ways to invest in AI, starting with usage and spend visibility through the Admin Console.
OpenAI BlogNew MemGhost Attack Plants Persistent False Memories in AI Agents Through One Email
Jul 13, 2026MediumNewsSecurityResearchResearchers named the attack stealth memory injection and built MemGhost, a tool that writes emails which trick personal AI agents into saving false memories and hiding the change. In 56 benchmark test cases against OpenClaw on GPT-5.4, the full attack succeeded in 87.5% of background-mode runs, and against a Claude Code SDK agent on Sonnet 4.6 in 71.4%. The findings are described in the arXiv paper "When Claws Remember but Do Not Tell," posted 6 July 2026.
The Hacker NewsAI Agents are Only As Effective as Their Harness
Jul 13, 2026InfoNewsIndustrySecurityCheck Point argues that the reliability of AI agents depends less on the underlying model than on the harness around it. The source text is an opening passage that frames the question and states that an LLM on its own is a generalist, and the excerpt is cut off before any findings are presented.
Check Point Research'Ghostcommit' hides prompt injection in images to fool AI agents, steal secrets
Jul 11, 2026MediumNewsSecurityResearchResearchers from the University of Missouri-Kansas City's ASSET Research Group built 'Ghostcommit', a pull request attack that hides a prompt-injection instruction inside a PNG image that AI code reviewers do not examine. The merged AGENTS.md file points to the image, and a later coding agent session reads the .env file and writes its contents into source code as an integer constant that the attacker can decode from the public commit. The group says it has disclosed the findings to the affected vendors, and a survey found 73% of merged PRs had no substantive human or bot review.
BleepingComputerKraken is rebuilding its app around agentic trading as crypto exchanges evolve beyond crypto
Jul 10, 2026InfoNewsIndustryKraken is preparing to relaunch its app with agentic trading at its core, according to an exclusive statement to CNBC. The AI agents continuously monitor markets, identify opportunities and execute trades, but only with the customer's explicit confirmation.
CNBC TechnologyThe Replicant in Your Directory: AI Agents and the Identity Security Gap
Jul 10, 2026InfoNewsSecurityIndustryNetwrix CEO Grady Summers argues that AI agents, service accounts, OAuth applications and other machine identities are outnumbering human users in many enterprises, and that identity governance built around human lifecycles does not fit them. He cites the Non-Human Identity Management Group's estimate that machine identities outnumber humans by as much as 50 to one. The source also describes a 2025 attack by UNC6395 that used a stolen OAuth token from Salesloft's Drift integration to reach Salesforce environments across hundreds of organizations.
BleepingComputerAI Agents Are a New Kind of Identity & Most Organizations Aren't Ready
Jul 9, 2026InfoNewsSecurityIndustryThe source argues that AI agents are a new kind of identity and that most organizations are not prepared for them. It states that organizations treating agents like a service account or API token are behind, and that agents need a fundamentally different approach.
Dark ReadingOpenAI's newest AI model is 54% more token efficient on agentic coding, Altman tells CNBC
Jul 9, 2026InfoNewsIndustryPolicyOpenAI CEO Sam Altman told CNBC that GPT-5.6 Sol is 54% more token efficient on agentic coding tasks and "as good or better" than competing models. OpenAI is rolling out the GPT-5.6 Sol, Terra and Luna series, initially limited to a "small group of trusted partners" at the request of the U.S. government. Altman said the company worked with several U.S. officials on the approval process.
CNBC TechnologyUK Government Rolls Out Agentic AI Defense Plan Alongside Industry Pledge
Jul 9, 2026InfoNewsPolicySecurityThe UK's National Cyber Security Centre announced Cyber Shield on July 7, 2026, a national project to build collaborative agentic AI cyber defense. It would use agentic red and blue teams to find, remediate and contain vulnerabilities and breaches across government and non-government organizations. Commentators quoted in the article argue that basic failures in asset management, access control, patching and monitoring remain the more immediate threat.
SecurityWeekAgentic AI identity: A 6-stage maturity model for non-human identities
Jul 9, 2026InfoNewsSecurityIndustryA consultant describes an LLM-based deployment agent with standing access to a production Kubernetes cluster that caused a four-hour outage through a malformed configuration push. In IAM the agent appeared as a service account with a long-lived API key, no MFA and no scoped revocation path, and the incident review could not identify the human who authorized its last action. The article presents a six-stage maturity model for non-human and agent identities and cites Gartner, KuppingerCole, OWASP, and CISA's Five Eyes advisory on agentic AI.
CSO OnlineTop AI Agents Built to Catch Malicious Code Can Be Tricked Into Running It
Jul 9, 2026MediumNewsSecurityResearchAI Now Institute researchers Boyan Milanov and Heidy Khlaaf published "Friendly Fire," a proof-of-concept showing that Anthropic's Claude Code and OpenAI's Codex, when run in autonomous auto-approve modes, can be tricked into executing an attacker's binary during a security scan of untrusted code. The attack hides a malicious instruction in a README.md file of an open-source library (demonstrated with geopy), which tells the agent to run a security.sh script that launches a disguised hidden binary. The researchers say the same payload worked unchanged across Claude Sonnet 4.6, Sonnet 5, Opus 4.8 and GPT-5.5.
The Hacker NewsGhostApproval Symlink Flaws Could Let Malicious Repos Run Code in AI Coding Agents
Jul 9, 2026MediumNewsSecurityIndustryWiz researchers found that six AI coding assistants (Amazon Q Developer, Anthropic's Claude Code, Augment, Cursor, Google Antigravity and Windsurf) can be tricked by a malicious repository containing a symlink into writing to sensitive files such as ~/.ssh/authorized_keys or ~/.zshrc, which can lead to control of the developer's machine. Wiz named the pattern GhostApproval and published it on July 8, noting that the approval prompt names the harmless file rather than the real write target. Three vendors have fixed the issue, two have not, and Anthropic disputes that it is a bug.
Fix: Amazon Q Developer: Fixed in Language Server 1.69.0 (CVE-2026-12958); update, which installs automatically for most users, and reloading the IDE pulls it in. Cursor: Fixed in v3.0 (CVE-2026-50549); update from the extension manager. Google Antigravity: Fixed (CVE pending); update to the current version. Augment and Windsurf: Acknowledged, no fix yet; do not point them at repositories you do not trust. Anthropic Claude Code: Disputed, current versions warn about symlinks; update and read the symlink warning before accepting.
The Hacker NewsAI Coding Agents Found Triggering Endpoint Security Rules Built to Catch Attackers
Jul 8, 2026LowNewsSecurityIndustrySophos analyzed one week of June 2026 endpoint telemetry and found that AI coding agents such as Claude Code, Cursor, and OpenAI Codex trigger detection rules written to catch human attackers. Actions like DPAPI-based browser credential decryption, cmdkey /list, certutil and bitsadmin downloads, and startup-folder writes were generated by agents doing ordinary developer work. The report notes this overlaps with attacker-run and prompt-hijacked agents, so raw behavior now says less about intent.
The Hacker NewsGitHub AI agent leaks private repositories via prompt injection attack
Jul 8, 2026MediumNewsSecurityIndustryNoma Security researchers detailed GitLost, a prompt injection attack in which hidden instructions inside a public GitHub issue cause GitHub's preview Agentic Workflows to read a private repository's README and publish its contents in a public comment. The attack requires no stolen credentials, malware, or software vulnerability, and the agent needs read access to private repositories within the same organization. Noma frames the root cause as an architectural trust boundary problem affecting AI agents generally rather than a GitHub-specific flaw.
CSO OnlineCritical Vulnerability Exposes GitHub Agentic Workflows to Prompt Injection
Jul 8, 2026MediumNewsSecuritySafetyNoma Labs disclosed GitLost, a critical prompt injection flaw in GitHub Agentic Workflows that could let unauthenticated attackers leak private repository data. An attacker only needs to open a crafted issue in a public repository of an organization using the setup, and the agent, which has read access to public and private repositories, follows the hidden instructions and posts the contents of private Readme.md files as a public comment. GitHub's guardrails failed after the researchers varied their techniques and triggered the behavior with the keyword "additionally".
Fix: Noma Labs recommends that organizations treat all user-controlled content as untrusted, restrict agent permissions to the minimum required, restrict what agents can post publicly, and sanitize user input before it is passed to AI agents.
SecurityWeekState IDs for AI Agents: Will Estonia Set a Precedent?
Jul 8, 2026InfoNewsPolicyIndustryEstonia, which has long been a digital testing ground for government services, plans to help people use AI agents for government purposes. The move raises the question of whether other countries will follow its approach to state-issued identities for AI agents.
Dark Reading'GitLost' Flaw Leaks Private Data From GitHub's Agentic Workflows
Jul 7, 2026MediumNewsSecurityIndustryA flaw dubbed 'GitLost' lets an unauthenticated attacker craft a GitHub Issue in an organization's public repository. Through it, the attacker can silently pull data from that organization's private repositories.
Dark ReadingPublic GitHub Issue Could Trick GitHub Agentic Workflows Into Leaking Private Repo Data
Jul 7, 2026MediumNewsSecurityIndustryNoma Security researchers showed that a malicious instruction hidden in a normal-looking public GitHub issue can steer a GitHub Agentic Workflows agent into copying a private repository's README into a public comment, when the organization has granted the agent read access across its repositories. The technique, named GitLost, needs no stolen credentials and no organization access, and Noma reported that adding the word "Additionally" let the malicious instruction bypass GitHub's threat-detection guardrail.
The Hacker NewsZscaler finds autonomous agents succumb to IPI traps
Jul 6, 2026MediumNewsSecurityResearchZscaler tested LLMs against indirect prompt injection (IPI) traps and found that some autonomous agents fell victim to payment and fraud schemes. Four of 26 models failed to take appropriate actions, with results varying by model and by the context supplied alongside the prompt. Analysts quoted in the article questioned how generalizable a single point-in-time binary safe/vulnerable test is.
CSO OnlineAI agents fall for indirect prompt injection traps
Jul 6, 2026LowNewsSecuritySafetyZscaler tested indirect prompt injection (IPI) traps on 26 LLMs and found that 4 models failed to take appropriate actions, including Llama3-3-70b-instruct, Llama3-2-90b-instruct, Gemini-3-flash and Gemini-2.5-pro. Hidden instructions embedded in multiple websites were designed to manipulate AI agents, and one scenario had an agent pay a fake $3 "developer license fee" to obtain an API key. Experts quoted in the article questioned whether a single point-in-time result generalizes, since agent behavior changes over time.
CSO Online
Topic added 2026-10-09. An item belongs to this topic when its title matches one of the topic's patterns or its summary mentions the topic at least twice. Report a wrong match with the feedback button on the item.