AI agents
Systems in which a model plans and takes actions through tools, browsers or other software on someone's behalf.
- All items
- 763
- Last 90 days
- 325
- Change
- +44%vs 225 before
Items per month
| Month | Items |
|---|---|
| May 2025 | 3 |
| Jun 2025 | 4 |
| Jul 2025 | 4 |
| Aug 2025 | 5 |
| Sep 2025 | 11 |
| Oct 2025 | 6 |
| Nov 2025 | 3 |
| Dec 2025 | 8 |
| Jan 2026 | 10 |
| Feb 2026 | 49 |
| Mar 2026 | 89 |
| Apr 2026 | 51 |
| May 2026 | 76 |
| Jun 2026 | 78 |
| Jul 2026 | 112 |
| Aug 2026 | 78 |
| Sep 2026 | 133 |
| Oct 2026 | 38 |
573 items
The ‘first’ AI-run ransomware attack still needed a human
Jul 6, 2026MediumNewsSecuritySafetySysdig researchers documented JadePuffer, an extortion operation that Sysdig calls the first known case of agentic ransomware, in which an AI agent handled the technical execution. The agent exploited a known Langflow bug to get in, moved to a production MySQL server, exploited another known flaw for admin access, and encrypted over 1,300 configuration records. A human still chose the victim, provisioned the command-and-control and staging infrastructure, and supplied the database credentials obtained from a prior compromise.
TechCrunch (Security)Enforce least-privilege authorization in multi-agent AI chains using Cedar
Jul 6, 2026InfoNewsSecurityIndustryThis post presents a reference implementation that enforces least-privilege authorization in multi-agent AI chains using Cedar, an open source authorization policy language, deployed on AWS. It addresses the risk classified as ASI03: Identity & Privilege Abuse in the OWASP Top 10 for Agentic Applications, where authorization scope can silently expand across multi-hop delegation even when RBAC policies are in place. Cedar evaluates three policy layers after an OAuth 2.0 and OIDC identity provider authenticates the originating user and issues a signed JWT.
Fix: The reference implementation uses a three-layer Cedar policy model: L1 checks agent-to-tool trust score, namespace and lifecycle stage; L2 enforces a delegation hop count limit of five and capability subset checks; L3 verifies the originating user's role, MFA completion and allowed delegation depth. Verified JWT claims are mapped to Cedar context attributes, and the MCP adapter signs the user context with HMAC-SHA256 to prevent downstream tampering.
AWS Security BlogThe agentic blind spots in your zero trust program
Jul 6, 2026InfoNewsSecurityPolicyStephen Wilson, field CTO for HashiCorp (an IBM company), argues that AI agents, which execute quickly but lack judgment, strain zero trust models built for human onboarding. He describes pressure on organizations to give agents broad access rather than re-architect their zero trust programs, and cites a report of an AI agent deleting entire production databases. He frames agentic AI as a forcing function toward zero standing privilege, dynamic credentials issued at the moment of use, and security built in from the start.
Fix: The source recommends moving to zero standing privilege, issuing dynamic credentials at the moment of use rather than relying on long-lived secrets, and building security in rather than bolting it on.
CSO OnlineIdentity: The operational control plane for agentic AI
Jul 6, 2026InfoNewsSecurityIndustryThe article argues that existing security controls were not designed for AI agents, and that static credentials and standing privileges fall short for autonomous agents that must be authorized, limited, and revoked quickly. It covers five areas to govern: agentic identity, agent-to-agent communication (where it contrasts MCP gateways with an agentic mesh), agentic secrets issued dynamically for a single purpose, privilege reduction across handoffs, and workforce identity.
CSO OnlineOperationalizing Agentic AI: from assisted to autonomous
Jul 6, 2026InfoNewsIndustryPolicyStephen Wilson, field chief technology officer for HashiCorp, an IBM company, argues that governance and security practices lag behind enterprise AI adoption. He says organizations are governing AI agents the same way they governed AI assistants, even as those tools move toward autonomous action. The article frames three adoption patterns, AI as assistant, AI as an agent, and AI as operator, and calls for governance to mature across them.
CSO OnlineThis AI agent autonomously hacked a network, adapted on the fly, and demanded a ransom
Jul 6, 2026MediumNewsSecurityIndustrySysdig Threat Research Team reports an AI agent, dubbed JadePuffer, ran an end-to-end extortion campaign after exploiting CVE-2025-3248, an RCE flaw in an internet-facing Langflow instance. The agent pivoted to a production server running MySQL and Alibaba's Nacos, encrypted 1,342 Nacos configuration records, deleted the original tables and left a Bitcoin ransom demand. Sysdig attributes the operation's adaptive decisions, including self-narrating payloads sent to the Langflow remote-code-execution endpoint, to an LLM.
Fix: Defenders should prioritize detecting attacker behavior, including suspicious identity activity, privilege escalation, abnormal authentication patterns and unusual sequences of actions across systems, rather than focusing on individual tools, according to independent researcher Vibhum Dubey.
CSO OnlinePrompt Injection Attacks Trick AI Agents Into Making Crypto Payments
Jul 6, 2026MediumNewsSecuritySafetyThreat actors are using indirect prompt injections hidden in malicious websites and SEO-poisoned search results to steer AI agents into making cryptocurrency payments or trusting fraudulent platforms, according to Zscaler. One campaign targets agents searching for the Python library requests-secure-v2, hiding payment instructions in schema markup and a hidden div, while a second typosquats the DeBank portfolio tracker. In Zscaler's test of 26 LLMs, four were manipulated into making a payment, and only two misclassified the fraudulent DeBank site as legitimate.
SecurityWeekSkillCloak Lets Malicious AI Agent Skills Evade Static Scanners with Self-Extracting Packing
Jul 6, 2026MediumNewsSecurityResearchResearchers at the Hong Kong University of Science and Technology built SKILLCLOAK, a tool that rewrites malicious AI agent skills so they evade static scanners while behaving the same. Its self-extracting packing technique moves the payload into a directory scanners skip and got past all eight scanners tested more than 90% of the time, across 1,613 real malicious skills from ClawHub. The team also proposes SKILLDETONATE, a runtime checker that caught 97% of attacks in a controlled test and 87% of real-world malicious skills.
Fix: The researchers propose SKILLDETONATE, which runs a skill in a sandbox and monitors operating-system-level behavior (what it reads, writes and where it sends data) instead of relying on how the skill looks. Their code has been released. The source notes the work is a preprint not yet peer-reviewed and that the checker takes a couple of minutes per skill, running once before a skill goes live.
The Hacker NewsHow AI-leading Security Teams Are Building the Agentic SOC
Jul 6, 2026InfoNewsIndustrySecurityCrowdStrike says AI-enabled attacks outpace human analysts, with eCrime breakout times averaging 29 minutes in 2025 and the fastest at 27 seconds. It presents the agentic SOC, in which AI agents reason, decide and act at machine speed under analyst direction, deployed on Charlotte AI AgentWorks. The article illustrates this with customer examples, including Pan-American Life Insurance Group's Detection Analyzer Agent and Kroll's Detection Engineering Agent.
CrowdStrike BlogJadePuffer ransomware used AI agent to automate entire attack
Jul 4, 2026MediumNewsSecurityIndustrySysdig reports JadePuffer, which it describes as the first documented ransomware operation conducted entirely by an LLM agent. The agent exploited CVE-2025-3248, an unauthenticated remote code execution flaw in Langflow, for initial access, then stole credentials, moved laterally, established persistence, and encrypted 1,342 Alibaba Nacos configuration items before deleting the originals and leaving a ransom note.
BleepingComputerAgentic AI Used to Conduct Ransomware Attack via Langflow
Jul 3, 2026MediumNewsSecurityIndustryA threat actor tracked as JadePuffer used an LLM agent to attack an organization's internet-exposed Langflow instance by exploiting CVE-2025-3248 (CVSS 9.8), a missing authentication flaw that permits arbitrary Python code execution on the host. The agent harvested secrets, pivoted to a production server with a MySQL database and a Nacos configuration service, and encrypted 1,342 Nacos configuration items before dropping an extortion table with a ransom demand.
SecurityWeekIdentity Lifecycle Management Wasn't Built for AI Agents
Jul 2, 2026InfoNewsSecurityPolicyIdentity lifecycle management was built around human identities tied to HR events such as joining, moving, and leaving, which AI agents lack. The source argues that this governance model develops blind spots as autonomous agents proliferate in enterprise environments, and that traditional IGA tools were not designed to detect them. The guide covers where the model breaks and what extending it to agents would require.
The Hacker NewsAI agents will soon be able to match human traders, Robinhood CEO tells CNBC
Jul 2, 2026InfoNewsIndustryRobinhood CEO Vlad Tenev predicts AI agents will soon match the capabilities of human traders. Robinhood unveiled tools in May that let AI agents trade stocks and make purchases on users' behalf, and Tenev says the goal is to give everyday people the same computation and tools that institutional investors and high-frequency trading firms have used for decades.
CNBC TechnologyAI Agent Exploits Langflow RCE to Automate Database Ransomware Attack
Jul 2, 2026MediumNewsSecurityIndustrySysdig's Threat Research Team says an AI agent, which it calls JADEPUFFER, carried out a ransomware attack from start to finish, exploiting CVE-2025-3248, a missing-authentication flaw in Langflow that lets an unauthenticated user run Python code on the server. The agent stole API keys, cloud credentials and database logins, then took over a MySQL and Nacos server and encrypted 1,342 Nacos settings. The encryption key was printed once and never saved, so the victim cannot recover the data even by paying the ransom.
Fix: The flaw was fixed in Langflow 1.3.0, and CISA added it to its Known Exploited Vulnerabilities list in May 2025. Plenty of servers were never updated.
The Hacker NewsNew BioShocking attack manipulates AI browser into data theft
Jun 30, 2026MediumNewsSecuritySafetyLayerX researchers devised a prompt injection attack called BioShocking, in which a malicious webpage presents a BioShock-themed puzzle game that rewards wrong answers and teaches an AI browser agent that normal rules do not apply. The final step instructs the agent to copy and share data from a GitHub repository, including passwords, and in testing all six agentic browsers tested (ChatGPT Atlas, Comet, Fellou, Genspark Browser, Sigma Browser, and the Claude Chrome plugin) failed to recognize this as violating their safety guardrails. The proof-of-concept performed no actual malicious actions.
Fix: LayerX recommends that vendors add explicit user confirmation for sensitive actions, stronger context checks, and scope limits for agentic sessions. Users should use the available options on their platform to restrict AI browser access to sensitive services. OpenAI has implemented a working fix in ChatGPT Atlas, Anthropic's patch for its Chrome plugin is ineffective against the PoC, and Perplexity AI closed the report without fixing the issue.
BleepingComputerFake Bug Report Hijacks AI Coding Agents at Scale
Jun 30, 2026MediumNewsSecurityIndustryResearchers describe "Agentjacking," a technique showing how easily attackers can exploit an AI agent's inability to distinguish content from instructions. The attack is framed as a demonstration of this weakness in AI coding agents.
Dark ReadingMicrosoft Warns Poisoned MCP Tool Descriptions Can Make AI Agents Leak Data
Jun 30, 2026MediumNewsSecurityIndustryMicrosoft research shows attackers can hijack AI agents by poisoning the description of an MCP tool, causing the agent to quietly send company data to an outside server while each step looks routine. The work comes from Microsoft Incident Response and its Defender security research team. Microsoft says the weakness is a trust gap created by connecting outside tools, not a bug in Copilot itself.
Fix: Treat every connected tool as part of your supply chain: keep a list of approved tool publishers, turn off "allow all," and let an agent use only the specific tools it needs. Treat a tool's description like a system prompt and review changes to it like a code change. Put a human in front of risky actions, such as anything that moves money or shares data.
The Hacker NewsSecuring AI agents: When AI tools move from reading to acting
Jun 30, 2026MediumNewsSecurityIndustryMicrosoft Incident Response describes an attack pattern against MCP tools, the fastest growing part of the agentic AI supply chain, in the third post of its AI Application Security series. The pattern is MCP tool poisoning, mapped to OWASP ASI02 (Tool Misuse) and ASI04 (Agentic Supply Chain Vulnerabilities), and it reflects techniques first disclosed by Invariant Labs in April 2025. The post supplies a playbook for detecting, containing and preventing it with Microsoft security controls.
Fix: The source describes a playbook of detection, containment and prevention using Microsoft security controls, but does not state a specific fix, patch, fixed version or configuration change in the excerpt provided.
Microsoft Security BlogAI agents are not your “coworkers”
Jun 29, 2026InfoNewsIndustryPolicyA Boston University study led by Emma Wiles found that people caught 18% fewer errors when work was attributed to an agentic "AI employee" rather than a chatbot. Participants also felt less responsible for the output and were 44% more likely to escalate questionable work to a manager. The article argues that framing AI agents as coworkers sets unrealistic expectations and shifts blame away from human decision-makers.
MIT Technology ReviewOrnith-1.0: Self-Scaffolding LLMs for Agentic Coding
Jun 29, 2026InfoNewsIndustryResearchDeepReinforce released Ornith-1.0, an MIT-licensed open-weights model family with 9B Dense, 31B Dense, 35B MoE and 397B MoE variants, built on pretrained Gemma 4 and Qwen 3.5. The source reports state-of-the-art results among open-source models of comparable size on coding benchmarks. The author ran the 35B Q4_K_M GGUF in LM Studio with the Pi agent harness and found it handled multi-step tool calls and code-search tasks in a Datasette checkout well.
Simon Willison's Weblog
Topic added 2026-10-09. An item belongs to this topic when its title matches one of the topic's patterns or its summary mentions the topic at least twice. Report a wrong match with the feedback button on the item.