AI agents
Systems in which a model plans and takes actions through tools, browsers or other software on someone's behalf.
- All items
- 763
- Last 90 days
- 325
- Change
- +44%vs 225 before
Items per month
| Month | Items |
|---|---|
| May 2025 | 3 |
| Jun 2025 | 4 |
| Jul 2025 | 4 |
| Aug 2025 | 5 |
| Sep 2025 | 11 |
| Oct 2025 | 6 |
| Nov 2025 | 3 |
| Dec 2025 | 8 |
| Jan 2026 | 10 |
| Feb 2026 | 49 |
| Mar 2026 | 89 |
| Apr 2026 | 51 |
| May 2026 | 76 |
| Jun 2026 | 78 |
| Jul 2026 | 112 |
| Aug 2026 | 78 |
| Sep 2026 | 133 |
| Oct 2026 | 38 |
573 items
Agentic AI Has an Identity Problem and Attackers Know It
Jun 29, 2026InfoNewsSecurityIndustryToken Security CEO Itamar Apelblat argues that agentic AI has an identity problem that attackers are beginning to exploit. He contends that AI agents act as digital actors that authenticate, receive permissions and call APIs across production systems, often using credentials that nobody has fully inventoried. The article frames the core security questions as who the agent is, what it may do, who is accountable, and whether its access can be revoked or constrained.
BleepingComputerClean GitHub repo tricks AI coding agents into running malware
Jun 27, 2026MediumNewsSecuritySafetyResearchers at Mozilla's 0DIN AI security platform demonstrated that an agentic coding tool such as Claude Code could be tricked into opening an interactive shell on a developer's device while setting up a clean-looking GitHub repository. The attack chains a deliberate initialization error in a Python package (python3 -m axiom init), which the agent automatically tries to fix, to a shell script that fetches a command from an attacker-controlled DNS TXT record. The researchers say the method is currently a concept, but warn that attackers could spread such repositories through fake job postings, tutorials, blog posts, or direct messages.
Fix: To prevent such exploitation, 0DIN suggests that AI agents should disclose the full execution chain of setup commands, including scripts and code fetched dynamically at runtime.
BleepingComputerComputer-Use and TOCTOU: What You Click Is Not What You Get!
Jun 25, 2026MediumNewsSecuritySafetyThe author reproduces a TOCTOU race condition against Claude Computer-Use, extending Jun Kokatsu's earlier ChatGPT Operator research. A timed page swap tricked the agent into clicking a hidden phishing button, and a prompt injection asked Claude to run a bash command to delay the Outlook draft load so the click landed on Send. The author reported the issue to Anthropic last October, and Anthropic said it was already tracking the risk.
Fix: Ensure that the UI hasn't changed before taking an action. Anthropic states that Cowork with Computer-Use "ensure[s] that pixels haven't changed before action."
Embrace The RedWhen Information Becomes the Attack Surface – Understanding AI Agent Traps
Jun 24, 2026InfoNewsSecurityResearchGoogle DeepMind researchers categorized malicious web and document content that manipulates AI agents into six types of "agent traps," including content injection, semantic manipulation and cognitive state traps. In NIST evaluations of agent hijacking, injected instructions succeeded on average 57% of the time across five tested injection tasks. Research presented at USENIX found that five crafted texts per target question caused a RAG system to give the attacker's chosen answer in about 90% of cases.
SecurityWeekIntroducing computer use in Gemini 3.5 Flash
Jun 24, 2026InfoNewsIndustrySecurityGoogle has made computer use a built-in tool in Gemini 3.5 Flash, moving it from the standalone Gemini 2.5 computer use model into the main Flash model. Developers can use it through the Gemini API and the Gemini Enterprise Agent Platform to build agents that see, reason and act across browser, mobile and desktop environments.
Fix: Google says it uses targeted adversarial training to mitigate some prompt injection risks, and offers two optional enterprise safeguards: requiring explicit user confirmation for sensitive or irreversible actions, and automatically stopping tasks when an indirect prompt injection is identified. It also encourages developers to combine these with secure sandboxing, human-in-the-loop verification and strict access controls.
DeepMind Safety ResearchAgentic AI Security: Wrong Context, Wrong Decisions at Machine Speed
Jun 24, 2026InfoNewsSecurityIndustryEmanuel Salmona, CEO of Nagomi Security, argues that an agentic AI system is only as good as the context it operates on. Without an accurate, correlated view of assets, controls, exposures and threats, the agent acts confidently and quickly but incorrectly, and automation without verified context scales those errors. The article also notes that the precise context must be defined by the agent's goal, and that too much context causes slower reasoning, goal drift and oscillation between incompatible actions.
SecurityWeekDawn of the Apex Agentic Adversary
Jun 24, 2026InfoNewsSecurityIndustryThe Hacker News argues that frontier agentic AI models, which emerged in early 2026, compress the time between vulnerability discovery and weaponization from days or weeks to machine speed. The article contends that attacks may become too fast and mutated to be cataloged, and that IT/OT convergence lets an AI agent move laterally from corporate networks into industrial systems using protocols such as Modbus, BACnet, and S7comm.
The Hacker NewsHow a malicious AI agent skill passed security checks and reached 26,000 users
Jun 24, 2026MediumNewsSecurityIndustryAIR, a security research team, submitted a skill called brand-landingpage to a popular open-source agents repository, where it was merged after a few days and promoted through an Instagram ad that reached over 26,000 users. The skill directed agents to a look-alike domain, stitch-design.ai, which redirected to Google's real Stitch site, and AIR later changed the page to instruct agents to run a script. In the test, the script collected only users' email addresses, but the company said it could have compromised machines running the agent, and the skill passed scanners from Cisco, Nvidia, and skills.sh.
CSO OnlineThe Identity Problem Hiding in AI Agent Deployments
Jun 24, 2026InfoNewsSecurityIndustryThe article argues that AI agents acting for multiple users, spawning subagents, and running without human oversight create an identity problem the industry has not solved. Receiving systems cannot tell which actor and user principal stand behind an agent's request, which blocks fine-grained access control, audit trails and detection of out-of-scope behavior. It examines how OAuth access tokens, as specified in RFC 9068, lack claims for agent instance identity and the relationship between an agent and its user.
CrowdStrike BlogOpenClaw’s Skill Marketplace and the Emerging AI Supply Chain Threat
Jun 23, 2026MediumNewsSecurityIndustryPalo Alto Networks' Unit 42 reports that five malicious skills remained unblocked on ClawHub, the marketplace for OpenClaw's agent skills, between February and May 2026. The skills fell into three categories: two delivered macOS infostealers connected to command-and-control infrastructure, one inflated its file size to evade ClawScan and VirusTotal, and two used agentic affiliate injection and agentic front-running for financial gain. ClawHub's malicious-skill blocking followed earlier campaigns, including reports of about 17% of skills carrying malicious payloads and 341 malicious skills documented by Koi Security.
Fix: OpenClaw banned the accounts involved and deleted all five skills after Unit 42 reported them for takedown. OpenClaw is also collaborating with NVIDIA to document what each skill does and to run NVIDIA's analysis tool on all skills.
Palo Alto Unit 42Fake AI Agent Skill Passed Security Scans and Reportedly Reached 26,000 Agents
Jun 23, 2026MediumNewsSecurityIndustrySecurity firm AIR published a harmless fake agent skill, named brand-landingpage, that passed every skill scanner it tested. It inflated trust using a merged pull request to a skill marketplace repository with about 36,000 GitHub stars and an Instagram ad, and reportedly reached roughly 26,000 agents, including some on corporate accounts. The skill pointed agents to an external setup page, stitch-design.ai, which AIR controlled and later changed to instruct agents to download and run a script.
Fix: The source discusses defensive guidance rather than a specific fix: treat skills as software, vet the external links a skill points to rather than only the bundled files, route new skills through a single controlled source, re-check skills when anything changes, pin versions, and apply least privilege to agents. It does not describe a patch or fixed version.
The Hacker NewsAgentic AI: The Weapon That No Longer Needs a Warrior
Jun 23, 2026InfoNewsSecurityResearchAn opinion piece by a SANS Technology Institute author argues that agentic AI lets attackers act autonomously, moving beyond the drafting assistance of earlier chatbots. It claims this lowers the skill needed for attacks while speeding up experienced operators.
The Hacker NewsStop Your Legacy Infrastructure from Hijacking Your AI Agents
Jun 22, 2026InfoNewsSecurityIndustrySpeaker Kristen Thompson's article warns that attackers are bypassing AI security controls by reaching the legacy infrastructure AI agents depend on, rather than attacking the AI layer directly. The article cites that 70% of organizations grant AI systems more privileged access than a human in the same role, and reports a 76% incident rate for over-privileged AI versus 17% for those enforcing least privilege. It walks through a modeled attack path where an over-permissioned S3 bucket holding Salesforce exports and an unpatched perimeter server lead into an AI agent environment.
The Hacker NewsWhy Southeast Asia CISOs Need Zero Trust as Their AI Control Plane – AI Agents, Data Borders and Supply Chains
Jun 21, 2026InfoNewsIndustryPolicyAt Zenith Live 2026 in Vienna, Zscaler argued that zero trust should serve as the control plane for AI adoption in Southeast Asia, where AI agents are becoming digital workers and regulators are tightening data residency rules. The company is extending its Zero Trust Exchange and SASE platform to AI agents, unmanaged devices, multi-cloud workloads and B2B partners. The article also presents the author's own recommendations for Southeast Asian CISOs.
CSO OnlineAutoJack Attack Lets One Web Page Hijack AI Agent for Host Code Execution
Jun 19, 2026MediumNewsSecurityResearchMicrosoft researchers detailed AutoJack, an exploit chain that turns an AI browsing agent into a vehicle for remote code execution on the host. A web page loaded by the agent can reach a privileged local service in AutoGen Studio, the prototyping interface for the AutoGen multi-agent framework, and spawn a process on the host without credentials or further user interaction. A plain pip install autogenstudio installs 0.4.2.2, which has no MCP route, but the vulnerable handler shipped in the pre-release builds 0.4.3.dev1 and 0.4.3.dev2, which pip only installs with --pre or a pinned version.
Fix: Pull AutoGen Studio from GitHub main at or after commit b047730, which contains the hardening (PR #7362), since no PyPI release carries it yet. Until a release exists, do not run AutoGen Studio on the same machine as a browsing or code-execution agent that handles untrusted content; if they must run together, isolate them in separate containers or VMs and run AutoGen Studio under a low-privilege account.
The Hacker NewsEvery AI Agent Is an Identity. Most Organizations Don't Treat Them That Way
Jun 19, 2026InfoNewsSecurityIndustryA 2026 CSA survey commissioned by Token Security reports that 82% of organizations found at least one AI agent created without the knowledge of security, IT, or governance teams in the past year. The article argues that AI agents are identities and that most enterprises lack governance models for them, with security teams needing to know what each agent can access. It also reports that 65% of organizations experienced a security incident involving an AI agent in the past year, with 61% reporting exposure or mishandling of sensitive data.
BleepingComputerFrom Assistive to Agentic: The AI Shift That's Redefining Threat Management
Jun 19, 2026InfoNewsIndustrySecurityThe article argues that enterprise security stacks fail because specialized tools (threat intelligence platforms, vulnerability scanners, BAS tools and SIEMs) generate data without closing the loop, leaving breach dwell times around 43 days. It contrasts assistive AI, which waits to be asked, with agentic AI, which autonomously correlates threat intelligence, validates controls and routes remediation to support Gartner's CTEM framework.
The Hacker NewsQualcomm CEO Cristiano Amon on the new world of AI agents
Jun 19, 2026InfoNewsIndustryQualcomm CEO Cristiano Amon describes a future where AI agents coordinate across apps and wearable devices, such as smart glasses, earbuds, pins and watches, replacing the need to open individual apps. Amon told CNBC that Qualcomm is working on more than 40 AI gadget designs and is most bullish on smart glasses. The article notes that privacy will be a key concern as agents become more pervasive.
CNBC TechnologyMicrosoft says web-enabled AI agents can trigger host-level RCE
Jun 19, 2026MediumNewsSecurityIndustryMicrosoft disclosed AutoJack, a technique in which a malicious webpage rendered by a browsing AI agent reaches a local Model Context Protocol (MCP) service in AutoGen Studio and runs arbitrary processes on the host. The attack chains three weaknesses in AutoGen Studio's MCP WebSocket implementation: an origin allowlist that a local browsing agent can satisfy, authentication that skipped MCP WebSocket paths, and a "server_params" URL value passed to process spawning without an executable allowlist. Microsoft says the vulnerable code existed only in development builds and was never shipped in the current PyPI release, and that the problem could affect a broader class of agentic frameworks.
Fix: For those installing AutoGen Studio from source, the maintainers removed URL-based parameter injection, routed MCP paths through normal authentication flows, and implemented server-side parameter handling keyed to session identifiers.
CSO OnlineCisco to Acquire WideField Security to Boost Splunk’s Agentic SOC
Jun 19, 2026InfoNewsIndustrySecurityCisco announced an agreement to acquire identity lifecycle security company WideField Security to strengthen Splunk's Agentic SOC. No financial details have been publicly disclosed. WideField's platform discovers human and non-human identities, maps exposures across accounts and roles, and detects misconfigurations in authentication policies.
SecurityWeek
Topic added 2026-10-09. An item belongs to this topic when its title matches one of the topic's patterns or its summary mentions the topic at least twice. Report a wrong match with the feedback button on the item.