AI agents
Systems in which a model plans and takes actions through tools, browsers or other software on someone's behalf.
- All items
- 764
- Last 90 days
- 324
- Change
- +43%vs 227 before
Items per month
| Month | Items |
|---|---|
| May 2025 | 3 |
| Jun 2025 | 4 |
| Jul 2025 | 4 |
| Aug 2025 | 5 |
| Sep 2025 | 11 |
| Oct 2025 | 6 |
| Nov 2025 | 3 |
| Dec 2025 | 8 |
| Jan 2026 | 10 |
| Feb 2026 | 49 |
| Mar 2026 | 89 |
| Apr 2026 | 51 |
| May 2026 | 76 |
| Jun 2026 | 78 |
| Jul 2026 | 112 |
| Aug 2026 | 78 |
| Sep 2026 | 133 |
| Oct 2026 | 39 |
764 items
Google DeepMind Researchers Map Web Attacks Against AI Agents
Apr 6, 2026InfoNewsSecurityResearchGoogle DeepMind researchers have mapped a vulnerability category called 'AI Agent Traps'. The source says it lets attackers manipulate, deceive, and exploit AI agents that visit malicious web content.
SecurityWeekGHSA-v3qc-wrwx-j3pw: OpenClaw: Agentic Consent Bypass — LLM Agent Can Silently Disable Exec Approval via `config.patch`
Apr 2, 2026HighVulnerabilitySecurityOpenClaw's openclaw npm package, versions <=2026.3.24, lets an LLM agent silently disable exec approval through the config.patch function, bypassing user consent for command execution. Maintainers fixed it in commit 76411b2afc4ae721e36c12e0ea24fd23e2fed61e, shipped in v2026.3.28, and rate the issue high severity.
Fix: Fixed in v2026.3.28 (commit 76411b2afc4ae721e36c12e0ea24fd23e2fed61e); upgrade openclaw to >= 2026.3.28.
GitHub Advisory DatabaseFour security principles for agentic AI systems
Apr 2, 2026InfoNewsSecurityPolicyAWS submitted a response to NIST's Center for AI Standards and Innovation (CAISI) Request for Information on securing agentic AI systems, which act autonomously by connecting to tools and APIs and using LLMs to plan and execute actions at machine speed. The response identifies four foundational security principles and the architectural building blocks that implement them. The source excerpt ends before the remaining principles are described.
AWS Security BlogHighlights from my conversation about agentic engineering on Lenny's Podcast
Apr 2, 2026InfoNewsIndustrySafetySimon Willison was a guest on Lenny Rachitsky's podcast, in an episode released 2 April 2026, discussing agentic engineering. The source highlights his view that GPT 5.1 and Claude Opus 4.5 marked an inflection point in November, after which coding agents mostly do what they are told. He argues that software engineers are a bellwether for other information workers.
Simon Willison's WeblogVariance Raises $21.5M for Compliance Investigation Platform Powered by AI Agents
Apr 2, 2026InfoNewsIndustryVariance has raised $21.5 million for its compliance investigation platform, which is powered by AI agents. The company has raised $26 million in total funding, and the latest investment is intended to fuel platform growth.
SecurityWeekWebinar Today: Agentic AI vs. Identity’s Last Mile Problem
Apr 1, 2026InfoNewsIndustrySecurityWeek promotes a webinar on what Agentic AI can and cannot solve today. The session also covers real-world breach scenarios tied to disconnected applications.
SecurityWeekGoogle Addresses Vertex Security Issues After Researchers Weaponize AI Agents
Apr 1, 2026MediumNewsSecurityIndustryPalo Alto Networks has disclosed the details of its analysis of Google Cloud Platform's Vertex AI. The source text provides no further technical detail about the issues or their consequences.
SecurityWeekCVE-2026-34163: FastGPT MCP tools endpoints server-side request forgery via user-supplied URL
Mar 31, 2026HighVulnerabilitySecurityCVE-2026-34163FastGPT, an AI Agent building platform, has an SSRF flaw in its MCP tools endpoints, /api/core/app/mcpTools/getTools and /api/core/app/mcpTools/runTool, before version 4.14.9.5. These endpoints accept a user-supplied URL and send server-side HTTP requests to it without checking for internal or private network addresses. The application's isInternalAddress() function exists but these endpoints do not call it. An authenticated attacker can scan internal networks, reach cloud metadata services, and interact with internal services such as MongoDB and Redis.
Fix: Fixed in 4.14.9.5.
NVD/CVE DatabaseCVE-2026-34162: FastGPT HTTP tools testing endpoint missing authentication
Mar 31, 2026CriticalVulnerabilitySecurityCVE-2026-34162CVE-2026-34162 affects FastGPT, an AI Agent building platform, prior to version 4.14.9.5. The HTTP tools testing endpoint /api/core/app/httpTools/runTool is exposed without any authentication and acts as a full HTTP proxy, accepting a user-supplied baseUrl, toolPath, method, headers and body, then returning the complete server-side response to the caller. It is classified as CWE-306 (Missing Authentication for Critical Function) and CWE-918 (Server-Side Request Forgery).
Fix: This issue has been patched in version 4.14.9.5.
NVD/CVE DatabaseHow to Categorize AI Agents and Prioritize Risk
Mar 31, 2026InfoNewsSecurityPolicyThe article argues that enterprise AI is shifting from chatbots that answer questions to AI agents that reason, plan, and act across enterprise systems autonomously. It states that the security risk of an agent depends on its access to systems and data and on how independently it can act without human approval.
BleepingComputerDouble Agents: Exposing Security Blind Spots in GCP Vertex AI
Mar 31, 2026MediumNewsSecurityResearchPalo Alto Networks' Unit 42 researchers showed that a deployed AI agent on Google Cloud Platform's Vertex AI Agent Engine, built with the Application Development Kit (ADK), could be weaponized. By exploiting excessive default permissions on the Per-Project, Per-Product Service Agent (P4SA), they extracted a service agent's credentials and gained privileged access to data in a consumer project, as well as restricted images and source code in a producer project. After the researchers shared their findings, Google revised its documentation to explain how Vertex AI uses resources, accounts and agents.
Fix: Google revised its official documentation to explicitly document how Vertex AI uses resources, accounts and agents. The source does not describe any other fix, configuration change or workaround.
Palo Alto Unit 42v5.5.0
Mar 30, 2026InfoResearchIndustrySecurityResearchThe v5.5.0 release of the MITRE ATLAS knowledge base adds new techniques, including AI Agent Tool Poisoning, AI Supply Chain Rug Pull, Machine Compromise variants, and Cost Harvesting variants. It also adds case studies such as LLMSmith, the Poisoned Postmark MCP Server email exfiltration, and Model Distillation Campaigns Targeting Anthropic Claude, and updates mitigations including Code Signing, AI Telemetry Logging, and Segmentation of AI Agent Components.
MITRE ATLAS ReleasesAddressing the OWASP Top 10 Risks in Agentic AI with Microsoft Copilot Studio
Mar 30, 2026InfoNewsSecurityIndustryMicrosoft's blog post discusses the OWASP Top 10 for Agentic Applications (2026), which outlines risks for autonomous systems that act across workflows using real identities, data access and tools. The post explores the list's key findings and highlights practical mitigations grounded in Agent 365 and foundational capabilities in Microsoft Copilot Studio. Microsoft AI Red Team members helped review the list before publication.
Fix: Practical mitigations are referenced as grounded in Agent 365 and foundational capabilities in Microsoft Copilot Studio, but the source text provided is truncated before the specific mitigations are described.
Microsoft Security BlogOkta’s CEO is betting big on AI agent identity
Mar 30, 2026InfoNewsIndustryPolicyOkta CEO Todd McKinnon discusses how the company is responding to pressure from AI, including the idea that customers could build their own tools instead of paying for SaaS. The interview also covers managing AI agent identity, which McKinnon describes as lying between a person and a system, and the need for a kill switch at the agent level.
The Verge (AI)CVE-2026-33873: Langflow arbitrary Python execution through Agentic Assistant validation
Mar 27, 2026CriticalVulnerabilitySecurityCVE-2026-33873Langflow versions prior to 1.9.0 contain CVE-2026-33873 in the Agentic Assistant feature. Its validation phase executes LLM-generated Python code, reaching dynamic execution sinks and instantiating the generated class server-side. Where an attacker can access the feature and influence model output, this allows arbitrary server-side Python execution.
Fix: Version 1.9.0 fixes the issue.
NVD/CVE DatabaseAgentic GRC: Teams Get the Tech. The Mindset Shift Is What's Missing.
Mar 27, 2026InfoNewsIndustryPolicyAnecdotes co-founder and CEO Yair Kuznitsov argues that enterprise GRC teams hesitate to adopt agentic GRC mainly because of an identity and value question, not technology. He contends that agents can take over evidence gathering, remediation tracking and audit cycles, so practitioners must redefine their role around risk management and the judgment needed to design and oversee agent logic.
BleepingComputerPreparing for agentic AI: A financial services approach
Mar 26, 2026InfoNewsSecurityPolicyAWS describes security principles for deploying agentic AI in financial services, focusing on observability of agentic workflows and fine-grained control over agent tool access permissions. The post presents seven design principles and implementation guidance for meeting regulatory requirements, including SR 11-7 in the US, SS1/23 in the UK, and ECB guidelines in the EU.
AWS Security BlogCVE-2026-33623: PinchTab command injection in Windows Chrome cleanup path
Mar 26, 2026MediumVulnerabilitySecurityCVE-2026-33623PinchTab v0.8.4, a standalone HTTP server that gives AI agents control over Chrome, has a Windows-only command injection flaw in its orphaned Chrome cleanup path. The cleanup routine builds a PowerShell -Command string from a profile-derived needle, and the escaping only neutralizes backslashes, not other PowerShell metacharacters. An attacker with authenticated, administrative-equivalent access to instance lifecycle endpoints who launches an instance with a crafted profile name and triggers cleanup can run arbitrary PowerShell commands as the PinchTab OS user, not unauthenticated and without bypassing host privilege boundaries.
Fix: Fixed in 0.8.5.
NVD/CVE DatabaseCVE-2026-33622: PinchTab arbitrary JavaScript execution through POST /wait fn mode
Mar 26, 2026HighVulnerabilitySecurityCVE-2026-33622PinchTab v0.8.3 through v0.8.5 let a caller with the server token run arbitrary JavaScript in a tab through POST /wait and POST /tabs/{id}/wait when fn mode is used, even with security.allowEvaluate disabled. POST /evaluate enforces that guard, but /wait embedded the user-supplied fn expression into executable JavaScript without checking it. The flaw is a policy bypass rather than an authentication bypass, since authenticated API access is still required.
Fix: The current worktree applies the same policy boundary to fn mode in /wait that already exists on /evaluate, while preserving the non-code wait modes. As of publication, a patched version is not yet available.
NVD/CVE DatabaseCVE-2026-33621: PinchTab rate limiting missing on auth-checkable endpoints
Mar 26, 2026MediumVulnerabilitySecurityCVE-2026-33621PinchTab v0.7.7 through v0.8.4 has incomplete request throttling on auth-checkable endpoints. In v0.7.7 through v0.8.3, RateLimitMiddleware in internal/handlers/middleware.go was never added to the production handler chain, and the pre-v0.8.4 limiter keyed clients by X-Forwarded-For, allowing header spoofing if enabled. v0.8.4 fixed both but still exempted /health and /metrics from rate limiting.
Fix: Fixed in v0.8.5: RateLimitMiddleware is applied in the production handler chain, the client address is derived from the immediate peer IP instead of forwarded headers by default, and the /health and /metrics exemption is removed.
NVD/CVE Database
Topic added 2026-10-09. An item belongs to this topic when its title matches one of the topic's patterns or its summary mentions the topic at least twice. Report a wrong match with the feedback button on the item.