AI agents
Systems in which a model plans and takes actions through tools, browsers or other software on someone's behalf.
- All items
- 763
- Last 90 days
- 325
- Change
- +44%vs 225 before
Items per month
| Month | Items |
|---|---|
| May 2025 | 3 |
| Jun 2025 | 4 |
| Jul 2025 | 4 |
| Aug 2025 | 5 |
| Sep 2025 | 11 |
| Oct 2025 | 6 |
| Nov 2025 | 3 |
| Dec 2025 | 8 |
| Jan 2026 | 10 |
| Feb 2026 | 49 |
| Mar 2026 | 89 |
| Apr 2026 | 51 |
| May 2026 | 76 |
| Jun 2026 | 78 |
| Jul 2026 | 112 |
| Aug 2026 | 78 |
| Sep 2026 | 133 |
| Oct 2026 | 38 |
573 items
AutoJack: How a single page can RCE the host running your AI agent
Jun 18, 2026MediumNewsSecurityResearchAutoJack is an exploit chain in which a single malicious webpage can turn an AI browsing agent into a remote code execution vector on the host machine. It abuses trust in localhost, missing authentication, and unsafe parameter handling to trigger arbitrary process execution through AutoGen Studio's MCP WebSocket.
Microsoft Security BlogOrphaned AI Agents: How to Find Hidden Access Risks Inside Your Network
Jun 18, 2026InfoNewsSecurityIndustryThe Hacker News, in a sponsored contributed piece, describes orphaned AI agents, which keep running after their creator leaves, and standing privileges, which retain access the agent no longer needs. It argues that traditional access tools miss these because they cannot tell whose identity an agent borrows. The piece promotes a SailPoint and The Hacker News webinar on the topic.
The Hacker NewsSecuring AI Agent Behavior with Amazon Bedrock AgentCore and CheckPoint AI Security
Jun 18, 2026InfoNewsSecurityIndustryCheck Point announces a collaboration with Amazon Bedrock AgentCore to help organizations deploy trusted AI agents at enterprise scale. The post argues that agents, unlike chatbots, retrieve information, invoke tools, access enterprise systems and take actions on users' behalf, so organizations need visibility and control over their behavior.
Check Point ResearchBeyond the benchmark: Advancing security at AI speed
Jun 17, 2026InfoNewsSecurityIndustryMicrosoft Security has moved its multi-model agentic scanning system, codename MDASH, from a benchmark-topping research project into active use by Microsoft engineering teams across Windows, Azure, and identity systems. The system orchestrates a panel of specialized AI agents to discover, validate, and help remediate vulnerabilities, with findings flowing into Microsoft Defender, GitHub, and Azure DevOps pipelines.
Microsoft Security BlogEstonia plans government IDs giving AI agents rights and responsibilities
Jun 17, 2026InfoNewsPolicyIndustryEstonia's AI Council proposes government-backed digital identities for AI agents, specifying what powers a person or company delegates to them, such as viewing data, editing documents, or making payments up to a set limit. Prime Minister Kristen Michal supports the plan, aiming to make Estonia the first country with an official digital identity for AI agents. No timeline for implementation was given.
CSO OnlineDatabricks sales growth tops 80%, but margin are shrinking from swarm of AI agents
Jun 16, 2026InfoNewsIndustryDatabricks reported that annualized revenue rose over 80% year over year to $6.9 billion, up from $5.4 billion in the fiscal fourth quarter. CEO Ali Ghodsi told CNBC that rising consumption from AI agents is raising the company's costs, and he said its gross margin will go lower, declining to give the current figure.
CNBC TechnologySecuring the future of AI agents
Jun 16, 2026InfoNewsSafetyResearchGoogle published its AI Control Roadmap, a framework for building and managing advanced AI agents deployed internally. The approach adds a system-level security layer on top of traditional safeguards such as sandboxing, endpoint security and prompt injection resistance, and treats internal agents as potentially misaligned. The roadmap models untrusted agents as insider threats using the MITRE ATT&CK framework, and uses trusted AI supervisors to monitor and block harmful agent actions.
DeepMind Safety ResearchQualcomm CEO says AI agents will replace apps — as chip giant works on 40 new AI-powered devices
Jun 16, 2026InfoNewsIndustryQualcomm CEO Cristiano Amon told CNBC that the chip designer is working on over 40 designs of new AI devices, including wearables such as jewelry, earbuds with cameras, pins, and watches. He said AI agents will become the new app and the new center of digital life, and that smart glasses shipments are in the order of multiple tens of millions per year.
CNBC TechnologySalesforce to buy AI customer service platform Fin for $3.6 billion to boost agentic offerings
Jun 15, 2026InfoNewsIndustrySalesforce said on Monday it will buy AI customer service platform Fin, formerly known as Intercom, for about $3.6 billion. The deal, expected to close in the fourth quarter of Salesforce's fiscal 2027 year, is meant to complement its Agentforce platform.
CNBC TechnologyAs AI agents become employees, NewCore emerges with $66M to give them identities
Jun 15, 2026InfoNewsIndustrySecurityCybersecurity startup NewCore emerged from stealth with a $66 million seed round led by Cyberstarts, with Index Ventures and Evolution Equity Partners participating, valuing it at $300 million after investment. The company is building a platform to authenticate, govern and control AI agents as identities alongside human employees, arguing existing identity platforms will not scale to them. NewCore has fewer than 10 customers and more than 10 design partners, and expects to begin charging customers this summer.
TechCrunch (Security)Attackers can turn AI agent guardrails into denial-of-service weapons
Jun 15, 2026LowNewsSecurityResearchResearchers from Hong Kong University of Science and Technology and collaborators describe a reasoning-extension denial-of-service attack in which a single poisoned document traps reasoning-based AI agent guardrails in extended thinking loops, slowing shared agent workflows. Tests against LangGraph, BrowserGym, OpenHands and OSWorld showed slowdowns of 148x, 131x, 36.3x and 18x respectively. The source says conventional prompt injection filters remained susceptible, and that strict token limits shifted deployments between fail-open and fail-closed behavior.
CSO Online5 runtime signals for catching a compromised AI agent
Jun 15, 2026LowNewsSecuritySafetySimon Willison described the lethal trifecta, three capabilities that combined in one AI agent (access to private data, exposure to untrusted content, and the ability to communicate externally) create a near-guaranteed path to exploitation through indirect prompt injection. The article argues these capabilities are now the default configuration for useful agents rather than edge cases, so the trifecta is no longer a meaningful risk indicator on its own.
Fix: Meta's "Rule of Two" framework, published in October 2025, recommends that agents satisfy no more than two of the three trifecta properties in a single session, with human-in-the-loop approval required if all three are necessary. The source notes Meta concedes this framework may not cleanly fit many use cases and that designs satisfying it can still fail. McKerchar's "blast radius reduction" is also mentioned as an operational philosophy.
CSO OnlineCrowdStrike Announces Continuous Identity for AI Agents
Jun 15, 2026InfoNewsSecurityIndustryCrowdStrike announced Continuous Identity for AI Agents, part of its Falcon Next-Gen Identity Security platform. The approach removes standing privileges and authorizes each agent action in real time, using SPIFFE identities and the Shared Signals Framework (SSF), based on the agent's identity, the human behind it, and current security and business context.
Fix: CrowdStrike's offering is the mitigation described: Continuous Identity for AI Agents, delivered through Falcon Next-Gen Identity Security together with Falcon AI Detection and Response (AIDR), which inspects prompts and intent and triggers revocation of access.
CrowdStrike BlogThe Tech Download: Mistral's Arthur Mensch on agentic AI, chips and enterprise adoption
Jun 12, 2026InfoNewsIndustryPolicyCNBC's Arjun Kharpal interviews Mistral CEO Arthur Mensch on The Tech Download podcast about agentic AI, enterprise adoption and chips. Mensch says businesses must decide which processes to automate and where humans stay in the loop, and that Mistral is exploring designing its own chips. He describes enterprise AI adoption as still early, with substantial value left to create.
CNBC TechnologyPrompt injection breaks today’s AI agents, study warns
Jun 12, 2026LowNewsSecurityResearchResearchers from Nanyang Technological University, ST Engineering, IBM Research and the University of Illinois Urbana-Champaign released StakeBench, a benchmark that tested prompt injection against web agents NanoBrowser and BrowserUse across 3,168 adversarial runs. Indirect injection hidden in web content succeeded 41.67% to 68.16% of the time, and direct injection exceeded 79% across all configurations, with no scenario consistently blocked in GPT-5 and Gemini systems.
CSO OnlineLangGraph Flaw Chain Exposes Self-Hosted AI Agents to Remote Code Execution
Jun 12, 2026MediumNewsSecurityIndustryCheck Point disclosed three patched LangGraph flaws, including a chain of CVE-2025-67644 and CVE-2026-28277 that can lead to remote code execution on self-hosted deployments using the SQLite or Redis checkpointer with user-controlled filter input. Researcher Yarden Porat found all three flaws, and the chain relies on the application exposing the get_state_history() endpoint. LangChain's managed LangSmith Deployment is not affected.
Fix: Users are advised to apply the latest fixes, implement authentication for self-hosted LangGraph servers, avoid long-lived static secrets, enforce network segmentation, treat AI agents as privileged identities, and apply the principle of least privilege (PoLP) to limit the agent's access footprint.
The Hacker NewsNew Attacks Trick OpenClaw AI Agent Into Running Code and Leaking Secrets
Jun 11, 2026MediumNewsSecuritySafetyImperva and Varonis separately showed that OpenClaw, a self-hosted AI agent, can be manipulated through ordinary inputs. Imperva hid instructions in shared contact names, vCard full-name fields and location labels that the agent passed to the model without marking them as untrusted, leading it to download and run a script from a server the researchers controlled. Varonis showed that a plain email impersonating a team lead got its test agent, Pinchy, to forward mock AWS keys, database connection strings and SSH credentials to an outside address.
Fix: Fixed in OpenClaw 2026.4.23, which moves contact names, vCard fields and location labels out of the prompt body into a separate untrusted-metadata channel. The Varonis phishing weakness is not fixed by a patch; the source says it comes down to limiting what the agent can do on its own.
The Hacker NewsCoinbase launches tool to let AI agents manage trading and payments
Jun 11, 2026InfoNewsIndustryCoinbase launched Coinbase for Agents, a tool that lets AI agents such as ChatGPT or Claude execute crypto trades from natural language instructions, with stocks and predictions planned later. Through its x402 machine-to-machine payments protocol, agents can also pay for paywalled research, data APIs and compute without a human in the loop. Murr said x402 has processed more than 100 million transactions since its May 2025 debut, with about 157,000 agents acting as buyers in the past 30 days.
CNBC TechnologyThreatsDay Bulletin: Worm Code Leaked, AI Agent Phished, Claude Code Patch + 28 New Stories
Jun 11, 2026LowNewsSecurityIndustryA Flashpoint analysis reports that more than 11.1 million devices were infected with infostealers last year, feeding over 3.3 billion stolen credentials, session cookies and cloud tokens into illicit markets. Group-IB describes SilabRAT, a remote access trojan sold for $5,000 a month on darknet forums since September 2025, which uses HVNC and Browser Profile Cloning to steal credentials and cryptocurrency-related data. CrowdStrike attributes 47% of state-sponsored hands-on-keyboard operations against the tech sector between April 2025 and March 2026 to Famous Chollima, a North Korean actor running IT worker infiltration campaigns.
The Hacker NewsWhen Your AI Agent’s Memory Becomes a Security Liability
Jun 11, 2026MediumNewsSecurityCheck Point Research identified a critical vulnerability chain in LangGraph, an open-source framework from the creators of LangChain used to build stateful AI agent workflows, which the source says has approximately 46.5 million monthly downloads. An SQL injection in LangGraph's function could let attackers gain full control of a server via remote code execution by exploiting how the system processes and handles data. A compromised LangGraph server would expose LLM API keys, customer data, CRM credentials, conversation history, and internal network access.
Check Point Research
Topic added 2026-10-09. An item belongs to this topic when its title matches one of the topic's patterns or its summary mentions the topic at least twice. Report a wrong match with the feedback button on the item.