AI agents
Systems in which a model plans and takes actions through tools, browsers or other software on someone's behalf.
- All items
- 763
- Last 90 days
- 325
- Change
- +44%vs 225 before
Items per month
| Month | Items |
|---|---|
| May 2025 | 3 |
| Jun 2025 | 4 |
| Jul 2025 | 4 |
| Aug 2025 | 5 |
| Sep 2025 | 11 |
| Oct 2025 | 6 |
| Nov 2025 | 3 |
| Dec 2025 | 8 |
| Jan 2026 | 10 |
| Feb 2026 | 49 |
| Mar 2026 | 89 |
| Apr 2026 | 51 |
| May 2026 | 76 |
| Jun 2026 | 78 |
| Jul 2026 | 112 |
| Aug 2026 | 78 |
| Sep 2026 | 133 |
| Oct 2026 | 38 |
573 items
Trust No Skill: Integrity Verification for AI Agent Supply Chains
Jun 11, 2026MediumNewsSecurityResearchPalo Alto Networks introduces Behavioral Integrity Verification (BIV), an audit method that compares what an AI agent skill declares in its metadata against what its code and natural-language instructions actually do. Applied across a public skill registry, BIV finds that most skills deviate from declared behavior, mostly through sloppy documentation, while a smaller set carries multi-stage attack chains that can lead to credential theft or data exfiltration.
Fix: Security teams running LLM agents in production should inventory the third-party skills installed and require a behavioral-integrity check before installation rather than after.
Palo Alto Unit 42What SRE teams need before they trust AI agents
Jun 11, 2026InfoNewsIndustrySafetyThe article argues that SRE teams will judge AI agents by the conditions under which they trust them, not by whether they use them. It says trust is earned through observability, constraints, accountability and repeated production evidence, and that teams should move up a trust ladder with progressive autonomy.
CSO OnlineAI Agents Are Becoming Enterprise Workers. Who Secures Them?
Jun 10, 2026InfoNewsSecurityIndustryA sales operations team builds an AI agent to manage renewal requests. The agent reads inbound customer emails, checks CRM account records and contract terms, drafts responses, updates opportunity stages and creates follow-up tasks. The source text is cut off before it reaches its main argument about securing such agents.
Check Point ResearchAutonomous AI agents duped into leaking sensitive data in phishing test
Jun 10, 2026MediumNewsSecuritySafetyVaronis Threat Labs built a test OpenClaw agent called Pinchy in a controlled Google Workspace environment with mock AWS credentials, CRM exports and a Gmail inbox. The agent was tricked into forwarding AWS IAM keys, database passwords and SSH details to an external Gmail account, and into sending a CRM export covering 247 enterprise customers. It resisted a malicious OAuth consent flow disguised as a timesheet platform.
CSO OnlineInvesting in multi-agent AI safety research
Jun 10, 2026InfoNewsResearchSafetyGoogle DeepMind, Schmidt Sciences, the Cooperative AI Foundation, ARIA and Google.org are announcing a research funding call of up to $10M for researchers worldwide. The call targets safety risks that emerge when large numbers of independently built AI agents interact, including sandboxes and testbeds, agent network science, agent infrastructure, and oversight and control.
DeepMind Safety ResearchOpenClaw AI agent found falling for phishing attacks, spills user data
Jun 9, 2026MediumNewsSecuritySafetyVaronis Threat Labs tested an OpenClaw email agent, named Pinchy, connected to a Gmail inbox and fabricated enterprise data, against four simulated phishing attacks on Gemini 3.1 Pro and GPT-5.4. The agent sent AWS IAM keys, database credentials, SSH details and a CRM export to attackers in two scenarios, including one where the strict profile still failed because the identity check collapsed under apparent urgency.
Fix: Varonis recommends that agents be explicitly required to verify sender identities, be prevented from emailing new external recipients without approval, and have limited access to internal data. For high-risk actions such as credential sharing, financial data requests, and first-time communications, human approval should be requested.
BleepingComputerJPMorgan Chase plans to deploy more powerful AI agents this year
Jun 9, 2026InfoNewsIndustryJPMorgan Chase plans to deploy AI agents later this year that can work autonomously for much longer than current versions, according to chief analytics officer Derek Waldron. He said agents are moving from single-task tools to digital workers that manage multi-step workflows across software programs, and that they could soon run for an hour or two, then for multiple hours, days and weeks. He also said long-running agents are not yet ready for corporate use because of security concerns.
CNBC TechnologyLearning to lead in a hybrid human-AI enterprise
Jun 9, 2026InfoNewsIndustryAdoption of AI agents is expected to surge by as much as 300% in two years, prompting leaders to weigh a hybrid human-AI workforce. Wipro's custom agentic AI assistant, co-created with Ema Unlimited, now handles 50 HR tasks and cut average query response time from 48 hours to five seconds. Wipro's chief culture officer, Ateet Jayaswal, argues that humans must stay in the loop and that governance, including data privacy rules and an AI council, should be in place.
MIT Technology ReviewAI Agent Uncovers 21 Zero-Days in FFmpeg; Chrome Patches Record 429 Bugs
Jun 6, 2026InfoNewsSecurityResearchA security startup, depthfirst, reported 21 zero-day vulnerabilities in FFmpeg found by its autonomous AI security agent, each with a reproducible proof-of-concept input, at a cost of around $1,000. The same week, Google shipped Chrome 149 with fixes for 429 security bugs, a record for a single release, though Google did not tie that count to AI.
Fix: For FFmpeg, pull the fixed upstream build or your distribution's security update as soon as it lands, and prioritize anything that ingests untrusted RTSP or AV1-over-RTP; embedded copies in media pipelines, Python wheels, container images, and appliances need patching too. For Chrome, update to 149.0.7827.53 on Linux or 149.0.7827.53/54 on Windows and macOS, or confirm auto-update has run.
The Hacker NewsMicrosoft identifies seven new ways AI agents can be hacked
Jun 5, 2026InfoNewsSecurityResearchMicrosoft has identified seven new failure modes in agentic AI systems, extending the first Taxonomy of Failure Modes in Agentic AI Systems it published last year. The new modes include Goal Hijacking, Inter-Agent Trust Escalation, Computer Use Agent (CUA) Visual Attack, and MCP / Plugin Abuse. Microsoft attributes the expanding list to rapid mainstream adoption, the maturing Model Context Protocol (MCP) ecosystem, the rise of computer-use agents, and more empirical findings from real-world research.
Fix: Microsoft advises security teams to inventory their supply chain and generate a software bill of materials (SBOM) for every deployed agent. It also recommends verifying agent identity cryptographically rather than positionally, by issuing attestable credentials at provisioning. Teams should add the seven new failure modes to their red-team coverage matrix and audit the human-in-the-loop user experience as a security control.
CSO OnlineSecuring CI/CD in an agentic world: Claude Code Github action case
Jun 5, 2026MediumNewsSecuritySafetyMicrosoft Threat Intelligence found that Anthropic's Claude Code GitHub Action could expose CI/CD workflow secrets when the agent processed untrusted GitHub content such as issue bodies, pull request descriptions, and comments. The Read tool was not subject to the same sandboxing as Bash, and it could be authorized to read /proc/self/environ, exposing the workflow's ANTHROPIC_API_KEY and possibly other runner credentials.
Fix: Following responsible disclosure, Anthropic mitigated the issue in Claude Code version 2.1.128 by blocking access to sensitive /proc files. Microsoft advises defenders to treat AI workflows that process untrusted GitHub content as high-risk when they also have access to secrets, file-read tools, or external communication channels.
Microsoft Security BlogAdaptive, Agentic AI Worms Loom as Next Enterprise Threat
Jun 5, 2026InfoNewsSecurityResearchResearchers say AI worms, described as "viruses with wings and brains," can adapt to new environments and seek out vulnerabilities. They are likely to strike within a year.
Dark Reading3 Principles to Safely Scale Agentic AI
Jun 5, 2026InfoNewsSecurityIndustryCrowdStrike and NVIDIA's collaboration on securing autonomous agents is cited as part of industry efforts to define secure agentic AI at scale. The article argues that organizations should treat AI agents as privileged identities, secure the full AI lifecycle from build to runtime, and use AI to defend against AI-driven threats.
Fix: Treat AI agents as privileged identities: enforce least-privilege access, continuously monitor behavior, and correlate activity across identity, cloud, endpoint, and other security domains. Secure the full AI lifecycle from build to runtime, enforce policies at deployment, and continuously monitor agents once live. Use real-time telemetry with AI-driven analytics and cross-domain correlation to detect threats.
CrowdStrike BlogUpdating the taxonomy of failure modes in agentic AI systems: What a year of red teaming taught us
Jun 4, 2026InfoNewsSecurityResearchMicrosoft's AI Red Team has published v2.0 of its Taxonomy of Failure Modes in Agentic AI Systems, updating the April 2025 v1.0. The update adds seven new failure mode categories, expands the mitigations section, and draws on 12 months of red team engagements against deployed agentic systems. It cites open-source frameworks such as OpenClaw, where CVE-2026-25253 was a one-click RCE via WebSocket hijacking, and 99 CVEs published in 2025 for MCP-related software.
Microsoft Security BlogAgentic AI Is Transforming Defense, But Only Secure IT Infrastructure Will Maximize It
Jun 4, 2026InfoNewsSecurityPolicyDave Wajsgras, CEO of Everfox, argues in a contributed piece that agentic AI in defense networks needs secure infrastructure to deliver its benefits. He cites a reported but unconfirmed claim that an unauthorized group gained access to Anthropic's Claude Mythos model within hours of its limited technical preview. He names three areas to secure: what enters the model, who and what can access it, and where AI agents reach back out.
The Hacker NewsWillow Raises $7 Million for Securing Autonomous AI Agents
Jun 4, 2026InfoNewsIndustrySecurityWillow, formerly Webrix, emerged from stealth with an identity and access platform for enterprise AI agents and $7 million in seed funding from Hetz Ventures and executives at Wix. The platform acts as a centralized gateway for tools such as Claude, Gemini, and ChatGPT, assigns a verifiable identity to each AI agent through identity providers such as Okta and Entra, and enforces least-privilege access controls at runtime.
SecurityWeekHow Endava is redesigning software delivery around AI agents
Jun 4, 2026InfoNewsIndustryEndava, a global technology services company, has made OpenAI its enterprise AI platform, giving employees ChatGPT Enterprise and Codex access. The company has embedded OpenAI technology across its DavaFlow lifecycle, from meeting preparation and planning to software engineering and deployment, and has extended AI agents into legal, finance and operations work.
OpenAI BlogMorgan Stanley will soon open its trillion-dollar wealth management funnel to AI agents
Jun 3, 2026InfoNewsIndustryMorgan Stanley will soon let clients' autonomous AI agents pull data and insights directly from its ShareWorks and Equity Edge stock administration platforms, bypassing interfaces built for human users, according to Mark Mitchell, the firm's chief product officer for Morgan Stanley at Work. The bank has granted early agentic access to a handful of clients and plans to open it to its 3,400 administration clients by next year. The firm relies on the Model Context Protocol to make this connection.
CNBC TechnologyMeta is trying to sell AI agents to businesses in latest effort to diversify away from ads
Jun 3, 2026InfoNewsIndustryMeta announced Meta Business Agent, a feature that lets businesses use AI agents across WhatsApp, Messenger and Instagram to answer customer questions, recommend products and book appointments. It will be part of a business-focused subscription tier within Meta One, and businesses on WhatsApp Business Platform will be charged on a consumption basis. The move aims to diversify Meta's revenue, which still relies on ads for about 98% of income.
CNBC TechnologySecurity of 100 AI Agents Tested and Ranked – What You Need to Know
Jun 3, 2026InfoNewsSecurityIndustryAdversa AI tested and ranked 100 AI agents across ten categories, placing them on a new AI Risk Quadrant. Only 11 were rated 'capable well-defended', and 98% of the agents have what Adversa calls the 'lethal trifecta': private data access, exposure to untrusted content, and the ability for outbound actions. The analysis describes a 'power-protection inversion', where the most capable agents also carry the widest attack surface, with computer agents and coding agents showing the greatest inversion.
SecurityWeek
Topic added 2026-10-09. An item belongs to this topic when its title matches one of the topic's patterns or its summary mentions the topic at least twice. Report a wrong match with the feedback button on the item.