AI agents
Systems in which a model plans and takes actions through tools, browsers or other software on someone's behalf.
- All items
- 763
- Last 90 days
- 325
- Change
- +44%vs 225 before
Items per month
| Month | Items |
|---|---|
| May 2025 | 3 |
| Jun 2025 | 4 |
| Jul 2025 | 4 |
| Aug 2025 | 5 |
| Sep 2025 | 11 |
| Oct 2025 | 6 |
| Nov 2025 | 3 |
| Dec 2025 | 8 |
| Jan 2026 | 10 |
| Feb 2026 | 49 |
| Mar 2026 | 89 |
| Apr 2026 | 51 |
| May 2026 | 76 |
| Jun 2026 | 78 |
| Jul 2026 | 112 |
| Aug 2026 | 78 |
| Sep 2026 | 133 |
| Oct 2026 | 38 |
763 items
Fake AI Agent Skill Passed Security Scans and Reportedly Reached 26,000 Agents
Jun 23, 2026MediumNewsSecurityIndustrySecurity firm AIR published a harmless fake agent skill, named brand-landingpage, that passed every skill scanner it tested. It inflated trust using a merged pull request to a skill marketplace repository with about 36,000 GitHub stars and an Instagram ad, and reportedly reached roughly 26,000 agents, including some on corporate accounts. The skill pointed agents to an external setup page, stitch-design.ai, which AIR controlled and later changed to instruct agents to download and run a script.
Fix: The source discusses defensive guidance rather than a specific fix: treat skills as software, vet the external links a skill points to rather than only the bundled files, route new skills through a single controlled source, re-check skills when anything changes, pin versions, and apply least privilege to agents. It does not describe a patch or fixed version.
The Hacker NewsAgentic AI: The Weapon That No Longer Needs a Warrior
Jun 23, 2026InfoNewsSecurityResearchAn opinion piece by a SANS Technology Institute author argues that agentic AI lets attackers act autonomously, moving beyond the drafting assistance of earlier chatbots. It claims this lowers the skill needed for attacks while speeding up experienced operators.
The Hacker NewsStop Your Legacy Infrastructure from Hijacking Your AI Agents
Jun 22, 2026InfoNewsSecurityIndustrySpeaker Kristen Thompson's article warns that attackers are bypassing AI security controls by reaching the legacy infrastructure AI agents depend on, rather than attacking the AI layer directly. The article cites that 70% of organizations grant AI systems more privileged access than a human in the same role, and reports a 76% incident rate for over-privileged AI versus 17% for those enforcing least privilege. It walks through a modeled attack path where an over-permissioned S3 bucket holding Salesforce exports and an unpatched perimeter server lead into an AI agent environment.
The Hacker NewsWhy Southeast Asia CISOs Need Zero Trust as Their AI Control Plane – AI Agents, Data Borders and Supply Chains
Jun 21, 2026InfoNewsIndustryPolicyAt Zenith Live 2026 in Vienna, Zscaler argued that zero trust should serve as the control plane for AI adoption in Southeast Asia, where AI agents are becoming digital workers and regulators are tightening data residency rules. The company is extending its Zero Trust Exchange and SASE platform to AI agents, unmanaged devices, multi-cloud workloads and B2B partners. The article also presents the author's own recommendations for Southeast Asian CISOs.
CSO OnlineAutoJack Attack Lets One Web Page Hijack AI Agent for Host Code Execution
Jun 19, 2026MediumNewsSecurityResearchMicrosoft researchers detailed AutoJack, an exploit chain that turns an AI browsing agent into a vehicle for remote code execution on the host. A web page loaded by the agent can reach a privileged local service in AutoGen Studio, the prototyping interface for the AutoGen multi-agent framework, and spawn a process on the host without credentials or further user interaction. A plain pip install autogenstudio installs 0.4.2.2, which has no MCP route, but the vulnerable handler shipped in the pre-release builds 0.4.3.dev1 and 0.4.3.dev2, which pip only installs with --pre or a pinned version.
Fix: Pull AutoGen Studio from GitHub main at or after commit b047730, which contains the hardening (PR #7362), since no PyPI release carries it yet. Until a release exists, do not run AutoGen Studio on the same machine as a browsing or code-execution agent that handles untrusted content; if they must run together, isolate them in separate containers or VMs and run AutoGen Studio under a low-privilege account.
The Hacker NewsGHSA-vcv2-r9jh-99m5: Agentic-Flow: OS Command Injection in agentic-flow MCP server tools via unsanitized tool-parameter interpolation into execSync
Jun 19, 2026HighVulnerabilitySecurityagentic-flow versions <= 2.0.13 interpolated MCP tool parameters such as agent, task, name, language and agentdb arguments directly into shell command strings passed to execSync(). A malicious value can break out of the double-quoted argument and run arbitrary OS commands with the privileges of the user running the MCP server. The HTTP/SSE transports expose the same sinks without authentication or Origin/Host validation.
Fix: Fixed in agentic-flow@2.0.14, which rewrites every affected call site to use execFileSync(file, argv, { shell: false }). Upgrade to agentic-flow >= 2.0.14. There is no in-product configuration that mitigates this without upgrading.
GitHub Advisory DatabaseEvery AI Agent Is an Identity. Most Organizations Don't Treat Them That Way
Jun 19, 2026InfoNewsSecurityIndustryA 2026 CSA survey commissioned by Token Security reports that 82% of organizations found at least one AI agent created without the knowledge of security, IT, or governance teams in the past year. The article argues that AI agents are identities and that most enterprises lack governance models for them, with security teams needing to know what each agent can access. It also reports that 65% of organizations experienced a security incident involving an AI agent in the past year, with 61% reporting exposure or mishandling of sensitive data.
BleepingComputerFrom Assistive to Agentic: The AI Shift That's Redefining Threat Management
Jun 19, 2026InfoNewsIndustrySecurityThe article argues that enterprise security stacks fail because specialized tools (threat intelligence platforms, vulnerability scanners, BAS tools and SIEMs) generate data without closing the loop, leaving breach dwell times around 43 days. It contrasts assistive AI, which waits to be asked, with agentic AI, which autonomously correlates threat intelligence, validates controls and routes remediation to support Gartner's CTEM framework.
The Hacker NewsQualcomm CEO Cristiano Amon on the new world of AI agents
Jun 19, 2026InfoNewsIndustryQualcomm CEO Cristiano Amon describes a future where AI agents coordinate across apps and wearable devices, such as smart glasses, earbuds, pins and watches, replacing the need to open individual apps. Amon told CNBC that Qualcomm is working on more than 40 AI gadget designs and is most bullish on smart glasses. The article notes that privacy will be a key concern as agents become more pervasive.
CNBC TechnologyMicrosoft says web-enabled AI agents can trigger host-level RCE
Jun 19, 2026MediumNewsSecurityIndustryMicrosoft disclosed AutoJack, a technique in which a malicious webpage rendered by a browsing AI agent reaches a local Model Context Protocol (MCP) service in AutoGen Studio and runs arbitrary processes on the host. The attack chains three weaknesses in AutoGen Studio's MCP WebSocket implementation: an origin allowlist that a local browsing agent can satisfy, authentication that skipped MCP WebSocket paths, and a "server_params" URL value passed to process spawning without an executable allowlist. Microsoft says the vulnerable code existed only in development builds and was never shipped in the current PyPI release, and that the problem could affect a broader class of agentic frameworks.
Fix: For those installing AutoGen Studio from source, the maintainers removed URL-based parameter injection, routed MCP paths through normal authentication flows, and implemented server-side parameter handling keyed to session identifiers.
CSO OnlineCisco to Acquire WideField Security to Boost Splunk’s Agentic SOC
Jun 19, 2026InfoNewsIndustrySecurityCisco announced an agreement to acquire identity lifecycle security company WideField Security to strengthen Splunk's Agentic SOC. No financial details have been publicly disclosed. WideField's platform discovers human and non-human identities, maps exposures across accounts and roles, and detects misconfigurations in authentication policies.
SecurityWeekAutoJack: How a single page can RCE the host running your AI agent
Jun 18, 2026MediumNewsSecurityResearchAutoJack is an exploit chain in which a single malicious webpage can turn an AI browsing agent into a remote code execution vector on the host machine. It abuses trust in localhost, missing authentication, and unsafe parameter handling to trigger arbitrary process execution through AutoGen Studio's MCP WebSocket.
Microsoft Security BlogOrphaned AI Agents: How to Find Hidden Access Risks Inside Your Network
Jun 18, 2026InfoNewsSecurityIndustryThe Hacker News, in a sponsored contributed piece, describes orphaned AI agents, which keep running after their creator leaves, and standing privileges, which retain access the agent no longer needs. It argues that traditional access tools miss these because they cannot tell whose identity an agent borrows. The piece promotes a SailPoint and The Hacker News webinar on the topic.
The Hacker NewsSecuring AI Agent Behavior with Amazon Bedrock AgentCore and CheckPoint AI Security
Jun 18, 2026InfoNewsSecurityIndustryCheck Point announces a collaboration with Amazon Bedrock AgentCore to help organizations deploy trusted AI agents at enterprise scale. The post argues that agents, unlike chatbots, retrieve information, invoke tools, access enterprise systems and take actions on users' behalf, so organizations need visibility and control over their behavior.
Check Point ResearchBeyond the benchmark: Advancing security at AI speed
Jun 17, 2026InfoNewsSecurityIndustryMicrosoft Security has moved its multi-model agentic scanning system, codename MDASH, from a benchmark-topping research project into active use by Microsoft engineering teams across Windows, Azure, and identity systems. The system orchestrates a panel of specialized AI agents to discover, validate, and help remediate vulnerabilities, with findings flowing into Microsoft Defender, GitHub, and Azure DevOps pipelines.
Microsoft Security BlogEstonia plans government IDs giving AI agents rights and responsibilities
Jun 17, 2026InfoNewsPolicyIndustryEstonia's AI Council proposes government-backed digital identities for AI agents, specifying what powers a person or company delegates to them, such as viewing data, editing documents, or making payments up to a set limit. Prime Minister Kristen Michal supports the plan, aiming to make Estonia the first country with an official digital identity for AI agents. No timeline for implementation was given.
CSO OnlineDatabricks sales growth tops 80%, but margin are shrinking from swarm of AI agents
Jun 16, 2026InfoNewsIndustryDatabricks reported that annualized revenue rose over 80% year over year to $6.9 billion, up from $5.4 billion in the fiscal fourth quarter. CEO Ali Ghodsi told CNBC that rising consumption from AI agents is raising the company's costs, and he said its gross margin will go lower, declining to give the current figure.
CNBC TechnologySecuring the future of AI agents
Jun 16, 2026InfoNewsSafetyResearchGoogle published its AI Control Roadmap, a framework for building and managing advanced AI agents deployed internally. The approach adds a system-level security layer on top of traditional safeguards such as sandboxing, endpoint security and prompt injection resistance, and treats internal agents as potentially misaligned. The roadmap models untrusted agents as insider threats using the MITRE ATT&CK framework, and uses trusted AI supervisors to monitor and block harmful agent actions.
DeepMind Safety ResearchQualcomm CEO says AI agents will replace apps — as chip giant works on 40 new AI-powered devices
Jun 16, 2026InfoNewsIndustryQualcomm CEO Cristiano Amon told CNBC that the chip designer is working on over 40 designs of new AI devices, including wearables such as jewelry, earbuds with cameras, pins, and watches. He said AI agents will become the new app and the new center of digital life, and that smart glasses shipments are in the order of multiple tens of millions per year.
CNBC TechnologySalesforce to buy AI customer service platform Fin for $3.6 billion to boost agentic offerings
Jun 15, 2026InfoNewsIndustrySalesforce said on Monday it will buy AI customer service platform Fin, formerly known as Intercom, for about $3.6 billion. The deal, expected to close in the fourth quarter of Salesforce's fiscal 2027 year, is meant to complement its Agentforce platform.
CNBC Technology
Topic added 2026-10-09. An item belongs to this topic when its title matches one of the topic's patterns or its summary mentions the topic at least twice. Report a wrong match with the feedback button on the item.