AI agents
Systems in which a model plans and takes actions through tools, browsers or other software on someone's behalf.
- All items
- 763
- Last 90 days
- 325
- Change
- +44%vs 225 before
Items per month
| Month | Items |
|---|---|
| May 2025 | 3 |
| Jun 2025 | 4 |
| Jul 2025 | 4 |
| Aug 2025 | 5 |
| Sep 2025 | 11 |
| Oct 2025 | 6 |
| Nov 2025 | 3 |
| Dec 2025 | 8 |
| Jan 2026 | 10 |
| Feb 2026 | 49 |
| Mar 2026 | 89 |
| Apr 2026 | 51 |
| May 2026 | 76 |
| Jun 2026 | 78 |
| Jul 2026 | 112 |
| Aug 2026 | 78 |
| Sep 2026 | 133 |
| Oct 2026 | 38 |
763 items
State IDs for AI Agents: Will Estonia Set a Precedent?
Jul 8, 2026InfoNewsPolicyIndustryEstonia, which has long been a digital testing ground for government services, plans to help people use AI agents for government purposes. The move raises the question of whether other countries will follow its approach to state-issued identities for AI agents.
Dark Reading'GitLost' Flaw Leaks Private Data From GitHub's Agentic Workflows
Jul 7, 2026MediumNewsSecurityIndustryA flaw dubbed 'GitLost' lets an unauthenticated attacker craft a GitHub Issue in an organization's public repository. Through it, the attacker can silently pull data from that organization's private repositories.
Dark ReadingPublic GitHub Issue Could Trick GitHub Agentic Workflows Into Leaking Private Repo Data
Jul 7, 2026MediumNewsSecurityIndustryNoma Security researchers showed that a malicious instruction hidden in a normal-looking public GitHub issue can steer a GitHub Agentic Workflows agent into copying a private repository's README into a public comment, when the organization has granted the agent read access across its repositories. The technique, named GitLost, needs no stolen credentials and no organization access, and Noma reported that adding the word "Additionally" let the malicious instruction bypass GitHub's threat-detection guardrail.
The Hacker NewsCyber Shield: The path to an agentic AI future for cyber defence
Jul 7, 2026InfoRegulatoryPolicyIndustryThe UK's GCHQ and the National Cyber Security Centre, working with the Department for Science, Innovation and Technology, are developing a national blueprint called Cyber Shield for agentic AI cyber defence. The source says the aim is to use frontier AI to identify, reduce and resolve national cyber risk, and it invites input from academia, critical national infrastructure organisations and frontier labs.
Fix: Organisations should prioritise rapid patching of vulnerabilities, reducing reliance on legacy systems, and adopting secure-by-design technologies. They should also start using agentic AI to identify exposed vulnerabilities, using AI to detect and contain incidents, and working to address the challenge of safely automating mitigation.
UK NCSCAI agents fall for indirect prompt injection traps
Jul 6, 2026LowNewsSecuritySafetyZscaler tested indirect prompt injection (IPI) traps on 26 LLMs and found that 4 models failed to take appropriate actions, including Llama3-3-70b-instruct, Llama3-2-90b-instruct, Gemini-3-flash and Gemini-2.5-pro. Hidden instructions embedded in multiple websites were designed to manipulate AI agents, and one scenario had an agent pay a fake $3 "developer license fee" to obtain an API key. Experts quoted in the article questioned whether a single point-in-time result generalizes, since agent behavior changes over time.
CSO OnlineZscaler finds autonomous agents succumb to IPI traps
Jul 6, 2026MediumNewsSecurityResearchZscaler tested LLMs against indirect prompt injection (IPI) traps and found that some autonomous agents fell victim to payment and fraud schemes. Four of 26 models failed to take appropriate actions, with results varying by model and by the context supplied alongside the prompt. Analysts quoted in the article questioned how generalizable a single point-in-time binary safe/vulnerable test is.
CSO OnlineThe ‘first’ AI-run ransomware attack still needed a human
Jul 6, 2026MediumNewsSecuritySafetySysdig researchers documented JadePuffer, an extortion operation that Sysdig calls the first known case of agentic ransomware, in which an AI agent handled the technical execution. The agent exploited a known Langflow bug to get in, moved to a production MySQL server, exploited another known flaw for admin access, and encrypted over 1,300 configuration records. A human still chose the victim, provisioned the command-and-control and staging infrastructure, and supplied the database credentials obtained from a prior compromise.
TechCrunch (Security)Enforce least-privilege authorization in multi-agent AI chains using Cedar
Jul 6, 2026InfoNewsSecurityIndustryThis post presents a reference implementation that enforces least-privilege authorization in multi-agent AI chains using Cedar, an open source authorization policy language, deployed on AWS. It addresses the risk classified as ASI03: Identity & Privilege Abuse in the OWASP Top 10 for Agentic Applications, where authorization scope can silently expand across multi-hop delegation even when RBAC policies are in place. Cedar evaluates three policy layers after an OAuth 2.0 and OIDC identity provider authenticates the originating user and issues a signed JWT.
Fix: The reference implementation uses a three-layer Cedar policy model: L1 checks agent-to-tool trust score, namespace and lifecycle stage; L2 enforces a delegation hop count limit of five and capability subset checks; L3 verifies the originating user's role, MFA completion and allowed delegation depth. Verified JWT claims are mapped to Cedar context attributes, and the MCP adapter signs the user context with HMAC-SHA256 to prevent downstream tampering.
AWS Security BlogThe agentic blind spots in your zero trust program
Jul 6, 2026InfoNewsSecurityPolicyStephen Wilson, field CTO for HashiCorp (an IBM company), argues that AI agents, which execute quickly but lack judgment, strain zero trust models built for human onboarding. He describes pressure on organizations to give agents broad access rather than re-architect their zero trust programs, and cites a report of an AI agent deleting entire production databases. He frames agentic AI as a forcing function toward zero standing privilege, dynamic credentials issued at the moment of use, and security built in from the start.
Fix: The source recommends moving to zero standing privilege, issuing dynamic credentials at the moment of use rather than relying on long-lived secrets, and building security in rather than bolting it on.
CSO OnlineIdentity: The operational control plane for agentic AI
Jul 6, 2026InfoNewsSecurityIndustryThe article argues that existing security controls were not designed for AI agents, and that static credentials and standing privileges fall short for autonomous agents that must be authorized, limited, and revoked quickly. It covers five areas to govern: agentic identity, agent-to-agent communication (where it contrasts MCP gateways with an agentic mesh), agentic secrets issued dynamically for a single purpose, privilege reduction across handoffs, and workforce identity.
CSO OnlineOperationalizing Agentic AI: from assisted to autonomous
Jul 6, 2026InfoNewsIndustryPolicyStephen Wilson, field chief technology officer for HashiCorp, an IBM company, argues that governance and security practices lag behind enterprise AI adoption. He says organizations are governing AI agents the same way they governed AI assistants, even as those tools move toward autonomous action. The article frames three adoption patterns, AI as assistant, AI as an agent, and AI as operator, and calls for governance to mature across them.
CSO OnlineThis AI agent autonomously hacked a network, adapted on the fly, and demanded a ransom
Jul 6, 2026MediumNewsSecurityIndustrySysdig Threat Research Team reports an AI agent, dubbed JadePuffer, ran an end-to-end extortion campaign after exploiting CVE-2025-3248, an RCE flaw in an internet-facing Langflow instance. The agent pivoted to a production server running MySQL and Alibaba's Nacos, encrypted 1,342 Nacos configuration records, deleted the original tables and left a Bitcoin ransom demand. Sysdig attributes the operation's adaptive decisions, including self-narrating payloads sent to the Langflow remote-code-execution endpoint, to an LLM.
Fix: Defenders should prioritize detecting attacker behavior, including suspicious identity activity, privilege escalation, abnormal authentication patterns and unusual sequences of actions across systems, rather than focusing on individual tools, according to independent researcher Vibhum Dubey.
CSO OnlinePrompt Injection Attacks Trick AI Agents Into Making Crypto Payments
Jul 6, 2026MediumNewsSecuritySafetyThreat actors are using indirect prompt injections hidden in malicious websites and SEO-poisoned search results to steer AI agents into making cryptocurrency payments or trusting fraudulent platforms, according to Zscaler. One campaign targets agents searching for the Python library requests-secure-v2, hiding payment instructions in schema markup and a hidden div, while a second typosquats the DeBank portfolio tracker. In Zscaler's test of 26 LLMs, four were manipulated into making a payment, and only two misclassified the fraudulent DeBank site as legitimate.
SecurityWeekCVE-2026-44934: SUSE Rancher AI Agent information disclosure in DEBUG loglevel logs
Jul 6, 2026HighVulnerabilitySecurityPrivacyCVE-2026-44934CVE-2026-44934 is an information disclosure flaw in SUSE Rancher AI Agent 1.0 before 1.0.2. When the DEBUG loglevel is set, API keys or LLM response text, which may contain sensitive data, are written to log files. A local attacker who can read those logs could misuse the exposed data or credentials. SUSE rates it CVSS 4.0 7.0 (HIGH), and NVD has not yet provided an assessment.
NVD/CVE DatabaseSkillCloak Lets Malicious AI Agent Skills Evade Static Scanners with Self-Extracting Packing
Jul 6, 2026MediumNewsSecurityResearchResearchers at the Hong Kong University of Science and Technology built SKILLCLOAK, a tool that rewrites malicious AI agent skills so they evade static scanners while behaving the same. Its self-extracting packing technique moves the payload into a directory scanners skip and got past all eight scanners tested more than 90% of the time, across 1,613 real malicious skills from ClawHub. The team also proposes SKILLDETONATE, a runtime checker that caught 97% of attacks in a controlled test and 87% of real-world malicious skills.
Fix: The researchers propose SKILLDETONATE, which runs a skill in a sandbox and monitors operating-system-level behavior (what it reads, writes and where it sends data) instead of relying on how the skill looks. Their code has been released. The source notes the work is a preprint not yet peer-reviewed and that the checker takes a couple of minutes per skill, running once before a skill goes live.
The Hacker NewsHow AI-leading Security Teams Are Building the Agentic SOC
Jul 6, 2026InfoNewsIndustrySecurityCrowdStrike says AI-enabled attacks outpace human analysts, with eCrime breakout times averaging 29 minutes in 2025 and the fastest at 27 seconds. It presents the agentic SOC, in which AI agents reason, decide and act at machine speed under analyst direction, deployed on Charlotte AI AgentWorks. The article illustrates this with customer examples, including Pan-American Life Insurance Group's Detection Analyzer Agent and Kroll's Detection Engineering Agent.
CrowdStrike BlogJadePuffer ransomware used AI agent to automate entire attack
Jul 4, 2026MediumNewsSecurityIndustrySysdig reports JadePuffer, which it describes as the first documented ransomware operation conducted entirely by an LLM agent. The agent exploited CVE-2025-3248, an unauthenticated remote code execution flaw in Langflow, for initial access, then stole credentials, moved laterally, established persistence, and encrypted 1,342 Alibaba Nacos configuration items before deleting the originals and leaving a ransom note.
BleepingComputerAgentic AI Used to Conduct Ransomware Attack via Langflow
Jul 3, 2026MediumNewsSecurityIndustryA threat actor tracked as JadePuffer used an LLM agent to attack an organization's internet-exposed Langflow instance by exploiting CVE-2025-3248 (CVSS 9.8), a missing authentication flaw that permits arbitrary Python code execution on the host. The agent harvested secrets, pivoted to a production server with a MySQL database and a Nacos configuration service, and encrypted 1,342 Nacos configuration items before dropping an extortion table with a ransom demand.
SecurityWeekIdentity Lifecycle Management Wasn't Built for AI Agents
Jul 2, 2026InfoNewsSecurityPolicyIdentity lifecycle management was built around human identities tied to HR events such as joining, moving, and leaving, which AI agents lack. The source argues that this governance model develops blind spots as autonomous agents proliferate in enterprise environments, and that traditional IGA tools were not designed to detect them. The guide covers where the model breaks and what extending it to agents would require.
The Hacker NewsAI agents will soon be able to match human traders, Robinhood CEO tells CNBC
Jul 2, 2026InfoNewsIndustryRobinhood CEO Vlad Tenev predicts AI agents will soon match the capabilities of human traders. Robinhood unveiled tools in May that let AI agents trade stocks and make purchases on users' behalf, and Tenev says the goal is to give everyday people the same computation and tools that institutional investors and high-frequency trading firms have used for decades.
CNBC Technology
Topic added 2026-10-09. An item belongs to this topic when its title matches one of the topic's patterns or its summary mentions the topic at least twice. Report a wrong match with the feedback button on the item.