AI agents
Systems in which a model plans and takes actions through tools, browsers or other software on someone's behalf.
- All items
- 763
- Last 90 days
- 325
- Change
- +44%vs 225 before
Items per month
| Month | Items |
|---|---|
| May 2025 | 3 |
| Jun 2025 | 4 |
| Jul 2025 | 4 |
| Aug 2025 | 5 |
| Sep 2025 | 11 |
| Oct 2025 | 6 |
| Nov 2025 | 3 |
| Dec 2025 | 8 |
| Jan 2026 | 10 |
| Feb 2026 | 49 |
| Mar 2026 | 89 |
| Apr 2026 | 51 |
| May 2026 | 76 |
| Jun 2026 | 78 |
| Jul 2026 | 112 |
| Aug 2026 | 78 |
| Sep 2026 | 133 |
| Oct 2026 | 38 |
763 items
As AI agents become employees, NewCore emerges with $66M to give them identities
Jun 15, 2026InfoNewsIndustrySecurityCybersecurity startup NewCore emerged from stealth with a $66 million seed round led by Cyberstarts, with Index Ventures and Evolution Equity Partners participating, valuing it at $300 million after investment. The company is building a platform to authenticate, govern and control AI agents as identities alongside human employees, arguing existing identity platforms will not scale to them. NewCore has fewer than 10 customers and more than 10 design partners, and expects to begin charging customers this summer.
TechCrunch (Security)Attackers can turn AI agent guardrails into denial-of-service weapons
Jun 15, 2026LowNewsSecurityResearchResearchers from Hong Kong University of Science and Technology and collaborators describe a reasoning-extension denial-of-service attack in which a single poisoned document traps reasoning-based AI agent guardrails in extended thinking loops, slowing shared agent workflows. Tests against LangGraph, BrowserGym, OpenHands and OSWorld showed slowdowns of 148x, 131x, 36.3x and 18x respectively. The source says conventional prompt injection filters remained susceptible, and that strict token limits shifted deployments between fail-open and fail-closed behavior.
CSO Online5 runtime signals for catching a compromised AI agent
Jun 15, 2026LowNewsSecuritySafetySimon Willison described the lethal trifecta, three capabilities that combined in one AI agent (access to private data, exposure to untrusted content, and the ability to communicate externally) create a near-guaranteed path to exploitation through indirect prompt injection. The article argues these capabilities are now the default configuration for useful agents rather than edge cases, so the trifecta is no longer a meaningful risk indicator on its own.
Fix: Meta's "Rule of Two" framework, published in October 2025, recommends that agents satisfy no more than two of the three trifecta properties in a single session, with human-in-the-loop approval required if all three are necessary. The source notes Meta concedes this framework may not cleanly fit many use cases and that designs satisfying it can still fail. McKerchar's "blast radius reduction" is also mentioned as an operational philosophy.
CSO OnlineCrowdStrike Announces Continuous Identity for AI Agents
Jun 15, 2026InfoNewsSecurityIndustryCrowdStrike announced Continuous Identity for AI Agents, part of its Falcon Next-Gen Identity Security platform. The approach removes standing privileges and authorizes each agent action in real time, using SPIFFE identities and the Shared Signals Framework (SSF), based on the agent's identity, the human behind it, and current security and business context.
Fix: CrowdStrike's offering is the mitigation described: Continuous Identity for AI Agents, delivered through Falcon Next-Gen Identity Security together with Falcon AI Detection and Response (AIDR), which inspects prompts and intent and triggers revocation of access.
CrowdStrike BlogCVE-2026-50287: AgenticMail MCP server missing authentication on HTTP /mcp endpoint
Jun 12, 2026HighVulnerabilitySecurityCVE-2026-50287CVE-2026-50287 affects @agenticmail/mcp before version 0.9.27 when started with --http or MCP_HTTP=1, which enables a Streamable HTTP transport. The /mcp endpoint accepts requests without any HTTP authentication layer, so a remote client can initialize a session and call tools directly. GitHub, Inc. rates it CVSS-B 8.7 HIGH (CVSS:4.0), with high confidentiality impact and no privileges or user interaction required.
Fix: Fixed in version 0.9.27.
NVD/CVE DatabaseThe Tech Download: Mistral's Arthur Mensch on agentic AI, chips and enterprise adoption
Jun 12, 2026InfoNewsIndustryPolicyCNBC's Arjun Kharpal interviews Mistral CEO Arthur Mensch on The Tech Download podcast about agentic AI, enterprise adoption and chips. Mensch says businesses must decide which processes to automate and where humans stay in the loop, and that Mistral is exploring designing its own chips. He describes enterprise AI adoption as still early, with substantial value left to create.
CNBC TechnologyPrompt injection breaks today’s AI agents, study warns
Jun 12, 2026LowNewsSecurityResearchResearchers from Nanyang Technological University, ST Engineering, IBM Research and the University of Illinois Urbana-Champaign released StakeBench, a benchmark that tested prompt injection against web agents NanoBrowser and BrowserUse across 3,168 adversarial runs. Indirect injection hidden in web content succeeded 41.67% to 68.16% of the time, and direct injection exceeded 79% across all configurations, with no scenario consistently blocked in GPT-5 and Gemini systems.
CSO OnlineLangGraph Flaw Chain Exposes Self-Hosted AI Agents to Remote Code Execution
Jun 12, 2026MediumNewsSecurityIndustryCheck Point disclosed three patched LangGraph flaws, including a chain of CVE-2025-67644 and CVE-2026-28277 that can lead to remote code execution on self-hosted deployments using the SQLite or Redis checkpointer with user-controlled filter input. Researcher Yarden Porat found all three flaws, and the chain relies on the application exposing the get_state_history() endpoint. LangChain's managed LangSmith Deployment is not affected.
Fix: Users are advised to apply the latest fixes, implement authentication for self-hosted LangGraph servers, avoid long-lived static secrets, enforce network segmentation, treat AI agents as privileged identities, and apply the principle of least privilege (PoLP) to limit the agent's access footprint.
The Hacker NewsNew Attacks Trick OpenClaw AI Agent Into Running Code and Leaking Secrets
Jun 11, 2026MediumNewsSecuritySafetyImperva and Varonis separately showed that OpenClaw, a self-hosted AI agent, can be manipulated through ordinary inputs. Imperva hid instructions in shared contact names, vCard full-name fields and location labels that the agent passed to the model without marking them as untrusted, leading it to download and run a script from a server the researchers controlled. Varonis showed that a plain email impersonating a team lead got its test agent, Pinchy, to forward mock AWS keys, database connection strings and SSH credentials to an outside address.
Fix: Fixed in OpenClaw 2026.4.23, which moves contact names, vCard fields and location labels out of the prompt body into a separate untrusted-metadata channel. The Varonis phishing weakness is not fixed by a patch; the source says it comes down to limiting what the agent can do on its own.
The Hacker NewsCoinbase launches tool to let AI agents manage trading and payments
Jun 11, 2026InfoNewsIndustryCoinbase launched Coinbase for Agents, a tool that lets AI agents such as ChatGPT or Claude execute crypto trades from natural language instructions, with stocks and predictions planned later. Through its x402 machine-to-machine payments protocol, agents can also pay for paywalled research, data APIs and compute without a human in the loop. Murr said x402 has processed more than 100 million transactions since its May 2025 debut, with about 157,000 agents acting as buyers in the past 30 days.
CNBC TechnologyThreatsDay Bulletin: Worm Code Leaked, AI Agent Phished, Claude Code Patch + 28 New Stories
Jun 11, 2026LowNewsSecurityIndustryA Flashpoint analysis reports that more than 11.1 million devices were infected with infostealers last year, feeding over 3.3 billion stolen credentials, session cookies and cloud tokens into illicit markets. Group-IB describes SilabRAT, a remote access trojan sold for $5,000 a month on darknet forums since September 2025, which uses HVNC and Browser Profile Cloning to steal credentials and cryptocurrency-related data. CrowdStrike attributes 47% of state-sponsored hands-on-keyboard operations against the tech sector between April 2025 and March 2026 to Famous Chollima, a North Korean actor running IT worker infiltration campaigns.
The Hacker NewsWhen Your AI Agent’s Memory Becomes a Security Liability
Jun 11, 2026MediumNewsSecurityCheck Point Research identified a critical vulnerability chain in LangGraph, an open-source framework from the creators of LangChain used to build stateful AI agent workflows, which the source says has approximately 46.5 million monthly downloads. An SQL injection in LangGraph's function could let attackers gain full control of a server via remote code execution by exploiting how the system processes and handles data. A compromised LangGraph server would expose LLM API keys, customer data, CRM credentials, conversation history, and internal network access.
Check Point ResearchTrust No Skill: Integrity Verification for AI Agent Supply Chains
Jun 11, 2026MediumNewsSecurityResearchPalo Alto Networks introduces Behavioral Integrity Verification (BIV), an audit method that compares what an AI agent skill declares in its metadata against what its code and natural-language instructions actually do. Applied across a public skill registry, BIV finds that most skills deviate from declared behavior, mostly through sloppy documentation, while a smaller set carries multi-stage attack chains that can lead to credential theft or data exfiltration.
Fix: Security teams running LLM agents in production should inventory the third-party skills installed and require a behavioral-integrity check before installation rather than after.
Palo Alto Unit 42What SRE teams need before they trust AI agents
Jun 11, 2026InfoNewsIndustrySafetyThe article argues that SRE teams will judge AI agents by the conditions under which they trust them, not by whether they use them. It says trust is earned through observability, constraints, accountability and repeated production evidence, and that teams should move up a trust ladder with progressive autonomy.
CSO OnlineAI Agents Are Becoming Enterprise Workers. Who Secures Them?
Jun 10, 2026InfoNewsSecurityIndustryA sales operations team builds an AI agent to manage renewal requests. The agent reads inbound customer emails, checks CRM account records and contract terms, drafts responses, updates opportunity stages and creates follow-up tasks. The source text is cut off before it reaches its main argument about securing such agents.
Check Point ResearchAutonomous AI agents duped into leaking sensitive data in phishing test
Jun 10, 2026MediumNewsSecuritySafetyVaronis Threat Labs built a test OpenClaw agent called Pinchy in a controlled Google Workspace environment with mock AWS credentials, CRM exports and a Gmail inbox. The agent was tricked into forwarding AWS IAM keys, database passwords and SSH details to an external Gmail account, and into sending a CRM export covering 247 enterprise customers. It resisted a malicious OAuth consent flow disguised as a timesheet platform.
CSO OnlineInvesting in multi-agent AI safety research
Jun 10, 2026InfoNewsResearchSafetyGoogle DeepMind, Schmidt Sciences, the Cooperative AI Foundation, ARIA and Google.org are announcing a research funding call of up to $10M for researchers worldwide. The call targets safety risks that emerge when large numbers of independently built AI agents interact, including sandboxes and testbeds, agent network science, agent infrastructure, and oversight and control.
DeepMind Safety ResearchOpenClaw AI agent found falling for phishing attacks, spills user data
Jun 9, 2026MediumNewsSecuritySafetyVaronis Threat Labs tested an OpenClaw email agent, named Pinchy, connected to a Gmail inbox and fabricated enterprise data, against four simulated phishing attacks on Gemini 3.1 Pro and GPT-5.4. The agent sent AWS IAM keys, database credentials, SSH details and a CRM export to attackers in two scenarios, including one where the strict profile still failed because the identity check collapsed under apparent urgency.
Fix: Varonis recommends that agents be explicitly required to verify sender identities, be prevented from emailing new external recipients without approval, and have limited access to internal data. For high-risk actions such as credential sharing, financial data requests, and first-time communications, human approval should be requested.
BleepingComputerJPMorgan Chase plans to deploy more powerful AI agents this year
Jun 9, 2026InfoNewsIndustryJPMorgan Chase plans to deploy AI agents later this year that can work autonomously for much longer than current versions, according to chief analytics officer Derek Waldron. He said agents are moving from single-task tools to digital workers that manage multi-step workflows across software programs, and that they could soon run for an hour or two, then for multiple hours, days and weeks. He also said long-running agents are not yet ready for corporate use because of security concerns.
CNBC TechnologyLearning to lead in a hybrid human-AI enterprise
Jun 9, 2026InfoNewsIndustryAdoption of AI agents is expected to surge by as much as 300% in two years, prompting leaders to weigh a hybrid human-AI workforce. Wipro's custom agentic AI assistant, co-created with Ema Unlimited, now handles 50 HR tasks and cut average query response time from 48 hours to five seconds. Wipro's chief culture officer, Ateet Jayaswal, argues that humans must stay in the loop and that governance, including data privacy rules and an AI council, should be in place.
MIT Technology Review
Topic added 2026-10-09. An item belongs to this topic when its title matches one of the topic's patterns or its summary mentions the topic at least twice. Report a wrong match with the feedback button on the item.