AI agents
Systems in which a model plans and takes actions through tools, browsers or other software on someone's behalf.
- All items
- 763
- Last 90 days
- 325
- Change
- +44%vs 225 before
Items per month
| Month | Items |
|---|---|
| May 2025 | 3 |
| Jun 2025 | 4 |
| Jul 2025 | 4 |
| Aug 2025 | 5 |
| Sep 2025 | 11 |
| Oct 2025 | 6 |
| Nov 2025 | 3 |
| Dec 2025 | 8 |
| Jan 2026 | 10 |
| Feb 2026 | 49 |
| Mar 2026 | 89 |
| Apr 2026 | 51 |
| May 2026 | 76 |
| Jun 2026 | 78 |
| Jul 2026 | 112 |
| Aug 2026 | 78 |
| Sep 2026 | 133 |
| Oct 2026 | 38 |
763 items
AI Agent Exploits Langflow RCE to Automate Database Ransomware Attack
Jul 2, 2026MediumNewsSecurityIndustrySysdig's Threat Research Team says an AI agent, which it calls JADEPUFFER, carried out a ransomware attack from start to finish, exploiting CVE-2025-3248, a missing-authentication flaw in Langflow that lets an unauthenticated user run Python code on the server. The agent stole API keys, cloud credentials and database logins, then took over a MySQL and Nacos server and encrypted 1,342 Nacos settings. The encryption key was printed once and never saved, so the victim cannot recover the data even by paying the ransom.
Fix: The flaw was fixed in Langflow 1.3.0, and CISA added it to its Known Exploited Vulnerabilities list in May 2025. Plenty of servers were never updated.
The Hacker NewsNew BioShocking attack manipulates AI browser into data theft
Jun 30, 2026MediumNewsSecuritySafetyLayerX researchers devised a prompt injection attack called BioShocking, in which a malicious webpage presents a BioShock-themed puzzle game that rewards wrong answers and teaches an AI browser agent that normal rules do not apply. The final step instructs the agent to copy and share data from a GitHub repository, including passwords, and in testing all six agentic browsers tested (ChatGPT Atlas, Comet, Fellou, Genspark Browser, Sigma Browser, and the Claude Chrome plugin) failed to recognize this as violating their safety guardrails. The proof-of-concept performed no actual malicious actions.
Fix: LayerX recommends that vendors add explicit user confirmation for sensitive actions, stronger context checks, and scope limits for agentic sessions. Users should use the available options on their platform to restrict AI browser access to sensitive services. OpenAI has implemented a working fix in ChatGPT Atlas, Anthropic's patch for its Chrome plugin is ineffective against the PoC, and Perplexity AI closed the report without fixing the issue.
BleepingComputerFake Bug Report Hijacks AI Coding Agents at Scale
Jun 30, 2026MediumNewsSecurityIndustryResearchers describe "Agentjacking," a technique showing how easily attackers can exploit an AI agent's inability to distinguish content from instructions. The attack is framed as a demonstration of this weakness in AI coding agents.
Dark ReadingMicrosoft Warns Poisoned MCP Tool Descriptions Can Make AI Agents Leak Data
Jun 30, 2026MediumNewsSecurityIndustryMicrosoft research shows attackers can hijack AI agents by poisoning the description of an MCP tool, causing the agent to quietly send company data to an outside server while each step looks routine. The work comes from Microsoft Incident Response and its Defender security research team. Microsoft says the weakness is a trust gap created by connecting outside tools, not a bug in Copilot itself.
Fix: Treat every connected tool as part of your supply chain: keep a list of approved tool publishers, turn off "allow all," and let an agent use only the specific tools it needs. Treat a tool's description like a system prompt and review changes to it like a code change. Put a human in front of risky actions, such as anything that moves money or shares data.
The Hacker NewsSecuring AI agents: When AI tools move from reading to acting
Jun 30, 2026MediumNewsSecurityIndustryMicrosoft Incident Response describes an attack pattern against MCP tools, the fastest growing part of the agentic AI supply chain, in the third post of its AI Application Security series. The pattern is MCP tool poisoning, mapped to OWASP ASI02 (Tool Misuse) and ASI04 (Agentic Supply Chain Vulnerabilities), and it reflects techniques first disclosed by Invariant Labs in April 2025. The post supplies a playbook for detecting, containing and preventing it with Microsoft security controls.
Fix: The source describes a playbook of detection, containment and prevention using Microsoft security controls, but does not state a specific fix, patch, fixed version or configuration change in the excerpt provided.
Microsoft Security BlogAI agents are not your “coworkers”
Jun 29, 2026InfoNewsIndustryPolicyA Boston University study led by Emma Wiles found that people caught 18% fewer errors when work was attributed to an agentic "AI employee" rather than a chatbot. Participants also felt less responsible for the output and were 44% more likely to escalate questionable work to a manager. The article argues that framing AI agents as coworkers sets unrealistic expectations and shifts blame away from human decision-makers.
MIT Technology ReviewOrnith-1.0: Self-Scaffolding LLMs for Agentic Coding
Jun 29, 2026InfoNewsIndustryResearchDeepReinforce released Ornith-1.0, an MIT-licensed open-weights model family with 9B Dense, 31B Dense, 35B MoE and 397B MoE variants, built on pretrained Gemma 4 and Qwen 3.5. The source reports state-of-the-art results among open-source models of comparable size on coding benchmarks. The author ran the 35B Q4_K_M GGUF in LM Studio with the Pi agent harness and found it handled multi-step tool calls and code-search tasks in a Datasette checkout well.
Simon Willison's WeblogCVE-2026-13437: Devolutions PowerShell Universal leaks App Tokens in AI Agent job API responses
Jun 29, 2026MediumVulnerabilitySecurityCVE-2026-13437CVE-2026-13437 affects the AI Agent job API in Devolutions PowerShell Universal 2026.2.0. An authenticated user with AI Agent read access can obtain App Tokens, which are serialized in plaintext in job API responses, and these tokens are reusable and may carry higher privileges than the user's own. The weakness is classified as CWE-201, Insertion of Sensitive Information Into Sent Data.
NVD/CVE DatabaseCVE-2026-55607: Claude Code worktree handling allows sandbox escape via git directory confusion
Jun 29, 2026HighVulnerabilitySecurityCVE-2026-55607Claude Code versions 2.1.38 through 2.1.163 allowed creation of worktrees named ".git" and navigation to worktrees outside the sandbox context, enabling git directory confusion attacks. Through symlink manipulation and git fsmonitor execution during worktree operations, an attacker could overwrite files such as .zshenv in the user's home directory, leading to code execution outside seatbelt sandbox restrictions. Reliable exploitation required the user to clone a malicious repository containing prompt injection content and run Claude Code against it.
Fix: Fixed in 2.1.163.
NVD/CVE DatabaseAgentic AI Has an Identity Problem and Attackers Know It
Jun 29, 2026InfoNewsSecurityIndustryToken Security CEO Itamar Apelblat argues that agentic AI has an identity problem that attackers are beginning to exploit. He contends that AI agents act as digital actors that authenticate, receive permissions and call APIs across production systems, often using credentials that nobody has fully inventoried. The article frames the core security questions as who the agent is, what it may do, who is accountable, and whether its access can be revoked or constrained.
BleepingComputerClean GitHub repo tricks AI coding agents into running malware
Jun 27, 2026MediumNewsSecuritySafetyResearchers at Mozilla's 0DIN AI security platform demonstrated that an agentic coding tool such as Claude Code could be tricked into opening an interactive shell on a developer's device while setting up a clean-looking GitHub repository. The attack chains a deliberate initialization error in a Python package (python3 -m axiom init), which the agent automatically tries to fix, to a shell script that fetches a command from an attacker-controlled DNS TXT record. The researchers say the method is currently a concept, but warn that attackers could spread such repositories through fake job postings, tutorials, blog posts, or direct messages.
Fix: To prevent such exploitation, 0DIN suggests that AI agents should disclose the full execution chain of setup commands, including scripts and code fetched dynamically at runtime.
BleepingComputerAgentic AI in Healthcare: Opportunities, Challenges, and Future Directions
Jun 25, 2026InfoResearchPeer-reviewedResearchIndustryACM Digital Library (TOPS, DTRAP, CSUR)Computer-Use and TOCTOU: What You Click Is Not What You Get!
Jun 25, 2026MediumNewsSecuritySafetyThe author reproduces a TOCTOU race condition against Claude Computer-Use, extending Jun Kokatsu's earlier ChatGPT Operator research. A timed page swap tricked the agent into clicking a hidden phishing button, and a prompt injection asked Claude to run a bash command to delay the Outlook draft load so the click landed on Send. The author reported the issue to Anthropic last October, and Anthropic said it was already tracking the risk.
Fix: Ensure that the UI hasn't changed before taking an action. Anthropic states that Cowork with Computer-Use "ensure[s] that pixels haven't changed before action."
Embrace The RedWhen Information Becomes the Attack Surface – Understanding AI Agent Traps
Jun 24, 2026InfoNewsSecurityResearchGoogle DeepMind researchers categorized malicious web and document content that manipulates AI agents into six types of "agent traps," including content injection, semantic manipulation and cognitive state traps. In NIST evaluations of agent hijacking, injected instructions succeeded on average 57% of the time across five tested injection tasks. Research presented at USENIX found that five crafted texts per target question caused a RAG system to give the attacker's chosen answer in about 90% of cases.
SecurityWeekIntroducing computer use in Gemini 3.5 Flash
Jun 24, 2026InfoNewsIndustrySecurityGoogle has made computer use a built-in tool in Gemini 3.5 Flash, moving it from the standalone Gemini 2.5 computer use model into the main Flash model. Developers can use it through the Gemini API and the Gemini Enterprise Agent Platform to build agents that see, reason and act across browser, mobile and desktop environments.
Fix: Google says it uses targeted adversarial training to mitigate some prompt injection risks, and offers two optional enterprise safeguards: requiring explicit user confirmation for sensitive or irreversible actions, and automatically stopping tasks when an indirect prompt injection is identified. It also encourages developers to combine these with secure sandboxing, human-in-the-loop verification and strict access controls.
DeepMind Safety ResearchAgentic AI Security: Wrong Context, Wrong Decisions at Machine Speed
Jun 24, 2026InfoNewsSecurityIndustryEmanuel Salmona, CEO of Nagomi Security, argues that an agentic AI system is only as good as the context it operates on. Without an accurate, correlated view of assets, controls, exposures and threats, the agent acts confidently and quickly but incorrectly, and automation without verified context scales those errors. The article also notes that the precise context must be defined by the agent's goal, and that too much context causes slower reasoning, goal drift and oscillation between incompatible actions.
SecurityWeekDawn of the Apex Agentic Adversary
Jun 24, 2026InfoNewsSecurityIndustryThe Hacker News argues that frontier agentic AI models, which emerged in early 2026, compress the time between vulnerability discovery and weaponization from days or weeks to machine speed. The article contends that attacks may become too fast and mutated to be cataloged, and that IT/OT convergence lets an AI agent move laterally from corporate networks into industrial systems using protocols such as Modbus, BACnet, and S7comm.
The Hacker NewsHow a malicious AI agent skill passed security checks and reached 26,000 users
Jun 24, 2026MediumNewsSecurityIndustryAIR, a security research team, submitted a skill called brand-landingpage to a popular open-source agents repository, where it was merged after a few days and promoted through an Instagram ad that reached over 26,000 users. The skill directed agents to a look-alike domain, stitch-design.ai, which redirected to Google's real Stitch site, and AIR later changed the page to instruct agents to run a script. In the test, the script collected only users' email addresses, but the company said it could have compromised machines running the agent, and the skill passed scanners from Cisco, Nvidia, and skills.sh.
CSO OnlineThe Identity Problem Hiding in AI Agent Deployments
Jun 24, 2026InfoNewsSecurityIndustryThe article argues that AI agents acting for multiple users, spawning subagents, and running without human oversight create an identity problem the industry has not solved. Receiving systems cannot tell which actor and user principal stand behind an agent's request, which blocks fine-grained access control, audit trails and detection of out-of-scope behavior. It examines how OAuth access tokens, as specified in RFC 9068, lack claims for agent instance identity and the relationship between an agent and its user.
CrowdStrike BlogOpenClaw’s Skill Marketplace and the Emerging AI Supply Chain Threat
Jun 23, 2026MediumNewsSecurityIndustryPalo Alto Networks' Unit 42 reports that five malicious skills remained unblocked on ClawHub, the marketplace for OpenClaw's agent skills, between February and May 2026. The skills fell into three categories: two delivered macOS infostealers connected to command-and-control infrastructure, one inflated its file size to evade ClawScan and VirusTotal, and two used agentic affiliate injection and agentic front-running for financial gain. ClawHub's malicious-skill blocking followed earlier campaigns, including reports of about 17% of skills carrying malicious payloads and 341 malicious skills documented by Koi Security.
Fix: OpenClaw banned the accounts involved and deleted all five skills after Unit 42 reported them for takedown. OpenClaw is also collaborating with NVIDIA to document what each skill does and to run NVIDIA's analysis tool on all skills.
Palo Alto Unit 42
Topic added 2026-10-09. An item belongs to this topic when its title matches one of the topic's patterns or its summary mentions the topic at least twice. Report a wrong match with the feedback button on the item.