AI agents
Systems in which a model plans and takes actions through tools, browsers or other software on someone's behalf.
- All items
- 763
- Last 90 days
- 325
- Change
- +44%vs 225 before
Items per month
| Month | Items |
|---|---|
| May 2025 | 3 |
| Jun 2025 | 4 |
| Jul 2025 | 4 |
| Aug 2025 | 5 |
| Sep 2025 | 11 |
| Oct 2025 | 6 |
| Nov 2025 | 3 |
| Dec 2025 | 8 |
| Jan 2026 | 10 |
| Feb 2026 | 49 |
| Mar 2026 | 89 |
| Apr 2026 | 51 |
| May 2026 | 76 |
| Jun 2026 | 78 |
| Jul 2026 | 112 |
| Aug 2026 | 78 |
| Sep 2026 | 133 |
| Oct 2026 | 38 |
763 items
AI Agent Uncovers 21 Zero-Days in FFmpeg; Chrome Patches Record 429 Bugs
Jun 6, 2026InfoNewsSecurityResearchA security startup, depthfirst, reported 21 zero-day vulnerabilities in FFmpeg found by its autonomous AI security agent, each with a reproducible proof-of-concept input, at a cost of around $1,000. The same week, Google shipped Chrome 149 with fixes for 429 security bugs, a record for a single release, though Google did not tie that count to AI.
Fix: For FFmpeg, pull the fixed upstream build or your distribution's security update as soon as it lands, and prioritize anything that ingests untrusted RTSP or AV1-over-RTP; embedded copies in media pipelines, Python wheels, container images, and appliances need patching too. For Chrome, update to 149.0.7827.53 on Linux or 149.0.7827.53/54 on Windows and macOS, or confirm auto-update has run.
The Hacker NewsMicrosoft identifies seven new ways AI agents can be hacked
Jun 5, 2026InfoNewsSecurityResearchMicrosoft has identified seven new failure modes in agentic AI systems, extending the first Taxonomy of Failure Modes in Agentic AI Systems it published last year. The new modes include Goal Hijacking, Inter-Agent Trust Escalation, Computer Use Agent (CUA) Visual Attack, and MCP / Plugin Abuse. Microsoft attributes the expanding list to rapid mainstream adoption, the maturing Model Context Protocol (MCP) ecosystem, the rise of computer-use agents, and more empirical findings from real-world research.
Fix: Microsoft advises security teams to inventory their supply chain and generate a software bill of materials (SBOM) for every deployed agent. It also recommends verifying agent identity cryptographically rather than positionally, by issuing attestable credentials at provisioning. Teams should add the seven new failure modes to their red-team coverage matrix and audit the human-in-the-loop user experience as a security control.
CSO OnlineSecuring CI/CD in an agentic world: Claude Code Github action case
Jun 5, 2026MediumNewsSecuritySafetyMicrosoft Threat Intelligence found that Anthropic's Claude Code GitHub Action could expose CI/CD workflow secrets when the agent processed untrusted GitHub content such as issue bodies, pull request descriptions, and comments. The Read tool was not subject to the same sandboxing as Bash, and it could be authorized to read /proc/self/environ, exposing the workflow's ANTHROPIC_API_KEY and possibly other runner credentials.
Fix: Following responsible disclosure, Anthropic mitigated the issue in Claude Code version 2.1.128 by blocking access to sensitive /proc files. Microsoft advises defenders to treat AI workflows that process untrusted GitHub content as high-risk when they also have access to secrets, file-read tools, or external communication channels.
Microsoft Security BlogAdaptive, Agentic AI Worms Loom as Next Enterprise Threat
Jun 5, 2026InfoNewsSecurityResearchResearchers say AI worms, described as "viruses with wings and brains," can adapt to new environments and seek out vulnerabilities. They are likely to strike within a year.
Dark Reading3 Principles to Safely Scale Agentic AI
Jun 5, 2026InfoNewsSecurityIndustryCrowdStrike and NVIDIA's collaboration on securing autonomous agents is cited as part of industry efforts to define secure agentic AI at scale. The article argues that organizations should treat AI agents as privileged identities, secure the full AI lifecycle from build to runtime, and use AI to defend against AI-driven threats.
Fix: Treat AI agents as privileged identities: enforce least-privilege access, continuously monitor behavior, and correlate activity across identity, cloud, endpoint, and other security domains. Secure the full AI lifecycle from build to runtime, enforce policies at deployment, and continuously monitor agents once live. Use real-time telemetry with AI-driven analytics and cross-domain correlation to detect threats.
CrowdStrike BlogUpdating the taxonomy of failure modes in agentic AI systems: What a year of red teaming taught us
Jun 4, 2026InfoNewsSecurityResearchMicrosoft's AI Red Team has published v2.0 of its Taxonomy of Failure Modes in Agentic AI Systems, updating the April 2025 v1.0. The update adds seven new failure mode categories, expands the mitigations section, and draws on 12 months of red team engagements against deployed agentic systems. It cites open-source frameworks such as OpenClaw, where CVE-2026-25253 was a one-click RCE via WebSocket hijacking, and 99 CVEs published in 2025 for MCP-related software.
Microsoft Security BlogAgentic AI Is Transforming Defense, But Only Secure IT Infrastructure Will Maximize It
Jun 4, 2026InfoNewsSecurityPolicyDave Wajsgras, CEO of Everfox, argues in a contributed piece that agentic AI in defense networks needs secure infrastructure to deliver its benefits. He cites a reported but unconfirmed claim that an unauthorized group gained access to Anthropic's Claude Mythos model within hours of its limited technical preview. He names three areas to secure: what enters the model, who and what can access it, and where AI agents reach back out.
The Hacker NewsWillow Raises $7 Million for Securing Autonomous AI Agents
Jun 4, 2026InfoNewsIndustrySecurityWillow, formerly Webrix, emerged from stealth with an identity and access platform for enterprise AI agents and $7 million in seed funding from Hetz Ventures and executives at Wix. The platform acts as a centralized gateway for tools such as Claude, Gemini, and ChatGPT, assigns a verifiable identity to each AI agent through identity providers such as Okta and Entra, and enforces least-privilege access controls at runtime.
SecurityWeekHow Endava is redesigning software delivery around AI agents
Jun 4, 2026InfoNewsIndustryEndava, a global technology services company, has made OpenAI its enterprise AI platform, giving employees ChatGPT Enterprise and Codex access. The company has embedded OpenAI technology across its DavaFlow lifecycle, from meeting preparation and planning to software engineering and deployment, and has extended AI agents into legal, finance and operations work.
OpenAI BlogMorgan Stanley will soon open its trillion-dollar wealth management funnel to AI agents
Jun 3, 2026InfoNewsIndustryMorgan Stanley will soon let clients' autonomous AI agents pull data and insights directly from its ShareWorks and Equity Edge stock administration platforms, bypassing interfaces built for human users, according to Mark Mitchell, the firm's chief product officer for Morgan Stanley at Work. The bank has granted early agentic access to a handful of clients and plans to open it to its 3,400 administration clients by next year. The firm relies on the Model Context Protocol to make this connection.
CNBC TechnologyMeta is trying to sell AI agents to businesses in latest effort to diversify away from ads
Jun 3, 2026InfoNewsIndustryMeta announced Meta Business Agent, a feature that lets businesses use AI agents across WhatsApp, Messenger and Instagram to answer customer questions, recommend products and book appointments. It will be part of a business-focused subscription tier within Meta One, and businesses on WhatsApp Business Platform will be charged on a consumption basis. The move aims to diversify Meta's revenue, which still relies on ads for about 98% of income.
CNBC TechnologySecurity of 100 AI Agents Tested and Ranked – What You Need to Know
Jun 3, 2026InfoNewsSecurityIndustryAdversa AI tested and ranked 100 AI agents across ten categories, placing them on a new AI Risk Quadrant. Only 11 were rated 'capable well-defended', and 98% of the agents have what Adversa calls the 'lethal trifecta': private data access, exposure to untrusted content, and the ability for outbound actions. The analysis describes a 'power-protection inversion', where the most capable agents also carry the widest attack surface, with computer agents and coding agents showing the greatest inversion.
SecurityWeekMicrosoft wants to put AI agents on a short leash
Jun 3, 2026InfoNewsSecurityIndustryAt Microsoft Build, Microsoft announced Microsoft Execution Container (MXC), a runtime containment offering for agentic AI workloads, and updates to its multi-agent vulnerability research system MDASH. MXC is a policy-driven execution workflow that lets developers specify what an AI agent can access, such as files, networks, resources and credentials, and enforces those boundaries at runtime. OpenClaw and NVIDIA's OpenShell are already adopting MXC.
CSO OnlineSecuring AI Agents Before They Go Rogue Is Next to Impossible
Jun 2, 2026InfoNewsSecurityIndustryThe source argues that high-autonomy AI agents with broad permissions and unfettered access create serious risk. It urges enterprises to act now before such agents cause a damaging incident.
Dark ReadingMicrosoft’s Project Solara is an OS for AI agent gadgets
Jun 2, 2026InfoNewsIndustryMicrosoft announced Project Solara at Build 2026, a new operating system built on Android rather than Windows, designed for gadgets that run AI agents. The company demonstrated two concept devices: a desk device resembling an Amazon Echo Show that unlocks with facial recognition, and a wearable badge with a camera and fingerprint scanner that can wake an AI agent.
The Verge (AI)Secure multi-tenant AI agents with Amazon Bedrock AgentCore resource-based policies
Jun 2, 2026InfoNewsIndustrySecurityAWS describes how SaaS providers can use resource-based policies on Amazon Bedrock AgentCore to control access to a shared AgentCore Runtime and its endpoint per tenant. The post walks through a multi-tenant customer service platform where one tenant gets cross-account access from its own AWS account, while another is restricted to invocations from a private VPC for regulatory compliance.
AWS Security BlogGemini Spark is the most impressive and terrifying AI experience I’ve had yet
Jun 2, 2026InfoNewsIndustryGoogle has launched Spark, a new always-on AI agent positioned as its agentic answer to general-purpose assistance. The source text is an excerpt from a Verge review that describes the reviewer's trip-planning experience with the product, but the excerpt cuts off before the full assessment.
The Verge (AI)Rehumanizing global health care with agentic AI
Jun 2, 2026InfoNewsIndustryPolicyKPMG reports that 68% of health-care providers have adopted AI agents into their workforce. At Hospital for Special Surgery, AI agents process insurance claims at 1,100 per month, cutting the appeals stage from 45 minutes to five and raising the appeal success rate from 65% to 100% in nine months. HSS is also deploying an AI scheduling and triage service, built with Ema Unlimited, that escalates sensitive or uncertain cases to human specialists.
MIT Technology ReviewGemini’s new AI agent is about as good as Google’s demo
Jun 1, 2026InfoNewsIndustryGoogle's Gemini Spark, an AI agent that Google says can run multi-step tasks in the background, was tested by a reviewer who found it impressively capable. The reviewer questions whether it is worth its financial cost and potential privacy tradeoffs.
The Verge (AI)CVE-2026-44287: FastGPT JavaScript sandbox code execution via dynamic import bypass
May 29, 2026MediumVulnerabilitySecurityCVE-2026-44287CVE-2026-44287 affects FastGPT, an AI Agent building platform, before 4.15.0-beta1. The JavaScript sandbox worker at projects/code-sandbox/src/pool/worker.ts:356 blocks dynamic import() with the regex /\bimport\s*\(/.test(code), which misses a block comment placed between import and (, such as import/**/("child_process"). Because import() is not wrapped by the safeRequire Proxy, which only proxies require, an attacker can load child_process and call execSync to run arbitrary commands as uid=100(sandbox) inside the sandbox container.
Fix: Fixed in 4.15.0-beta1.
NVD/CVE Database
Topic added 2026-10-09. An item belongs to this topic when its title matches one of the topic's patterns or its summary mentions the topic at least twice. Report a wrong match with the feedback button on the item.