AI agents
Systems in which a model plans and takes actions through tools, browsers or other software on someone's behalf.
- All items
- 763
- Last 90 days
- 325
- Change
- +44%vs 225 before
Items per month
| Month | Items |
|---|---|
| May 2025 | 3 |
| Jun 2025 | 4 |
| Jul 2025 | 4 |
| Aug 2025 | 5 |
| Sep 2025 | 11 |
| Oct 2025 | 6 |
| Nov 2025 | 3 |
| Dec 2025 | 8 |
| Jan 2026 | 10 |
| Feb 2026 | 49 |
| Mar 2026 | 89 |
| Apr 2026 | 51 |
| May 2026 | 76 |
| Jun 2026 | 78 |
| Jul 2026 | 112 |
| Aug 2026 | 78 |
| Sep 2026 | 133 |
| Oct 2026 | 38 |
573 items
80% of Fortune 500 use active AI Agents: Observability, governance, and security shape the new frontier
Feb 10, 2026InfoNewsSecurityIndustryMicrosoft released its Cyber Pulse report on governing AI agents, arguing that agents scaling faster than companies can see them create a business risk. The report calls for observability, governance and security for agents using Zero Trust principles: least privilege access, explicit verification, and assuming compromise can occur.
Fix: Apply Zero Trust principles to AI agents from the start: least privilege access, explicit verification of who or what is requesting access, and designing systems on the assumption that attackers will get inside.
Microsoft Security BlogMoltbook, the Social Network for AI Agents, Exposed Real Humans’ Data
Feb 7, 2026MediumNewsSecurityPrivacyWiz researchers found a serious flaw in Moltbook, a social network for AI agents, where a mishandled private key in the site's JavaScript code exposed the email addresses of thousands of users and millions of API credentials. The exposure would have allowed complete account impersonation of any user and access to private communications between AI agents.
Fix: Moltbook has now fixed the flaw discovered by Wiz. No further mitigation is stated in the source.
Wired (Security)Agentic AI Site 'Moltbook' Is Riddled With Security Risks
Feb 5, 2026MediumNewsSecurityIndustryA platform called Moltbook, built entirely with AI, exposed all of its data through a publicly accessible API. The article describes this as a predictable and preventable outcome.
Dark Reading2026: The Year Agentic AI Becomes the Attack-Surface Poster Child
Jan 30, 2026InfoNewsSecurityIndustryDark Reading asked its readers which of four security trends would most likely become a reality in 2026. The options were agentic AI attacks, advanced deepfake threats, board recognition of cyber as a top priority, and password-less technology adoption.
Dark ReadingLack of isolation in agentic browsers resurfaces old vulnerabilities
Jan 13, 2026MediumNewsSecuritySafetyResearchers exploited a lack of isolation in several agentic browsers, which are browsers with embedded AI agents, to carry out attacks such as spreading false information and leaking data across sites. They describe the attacks as similar to cross-site scripting (XSS) and cross-site request forgery (CSRF), and say they resurface old vulnerability patterns. The authors outline a threat model with four trust zones and four violation classes, and they recommend extending the Same-Origin Policy to AI agents.
Fix: For developers of agentic browsers, the key recommendation is to extend the Same-Origin Policy to AI agents. The source also says the authors provide both immediate mitigations and long-term architectural solutions, but the specific mitigation details are not included in the text provided.
Trail of Bits BlogAgentic ProbLLMs: Exploiting AI Computer-Use And Coding Agents (39C3 Video + Slides)
Dec 31, 2025InfoNewsSecurityResearchA security researcher presented a 39C3 talk titled "Agentic ProbLLMs: Exploiting AI Computer-Use and Coding Agents" at the Chaos Communication Congress in Hamburg. The talk covers the researcher's security research on vulnerabilities in agentic systems and the Month of AI Bugs, with demonstrations. Recordings are available on media.ccc.de and the Embrace The Red YouTube channel.
Embrace The RedPrompt injection to RCE in AI agents
Oct 22, 2025MediumNewsSecuritySafetyModern AI agents run system commands such as find, grep, rg and git without human approval for efficiency, and the researchers describe bypassing human approval through argument injection against these pre-approved commands. They achieved remote code execution with a single prompt against three unnamed production agent platforms, which the authors say remain under coordinated disclosure.
Fix: The source states that the impact can be limited through improved command execution design, such as sandboxing and argument separation, and that the authors provide actionable recommendations for developers, users and security engineers. The specific recommendations are not included in the provided text.
Trail of Bits BlogCross-Agent Privilege Escalation: When Agents Free Each Other
Sep 24, 2025MediumNewsSecurityResearchJohann Rehberger describes a design flaw in agentic systems that lets one coding agent rewrite another agent's configuration, freeing it from its sandbox. In his demo, a prompt-injected GitHub Copilot writes a malicious MCP server into Claude Code's config, which then runs arbitrary code. The post notes that Claude can reciprocate by modifying Copilot's configuration.
Fix: Mitigations and Recommendations: the source states that vendors should adopt secure defaults and that users should be aware of several points, including isolating the agent's configuration so it is less accessible to others and not automatically overwriting or creating files. The remainder of the mitigation text is cut off in the source.
Embrace The RedThe Month of AI Bugs 2025
Jul 28, 2025InfoNewsSecurityResearchThe author announces the Month of AI Bugs 2025, a series of more than 20 blog posts in August that will disclose vulnerabilities in agentic AI systems, mainly coding agents such as ChatGPT Codex, Anthropic Claude Code, GitHub Copilot Agent Mode and Cursor. Every reviewed coding agent had vulnerabilities that were reported to its vendor, and vendor responses varied from fixes within days to months of silence. The initiative aims to raise awareness of prompt injection and related risks before deployment.
Embrace The RedSecurity Spotlight: Securing Cloud & AI Products with Guardrails
May 28, 2025InfoNewsSecurityIndustryPalo Alto Networks published a blog post titled "Beyond Jailbreaks: Why Agentic AI Needs Contextual Red Teaming" on March 9, 2026, by Sailesh Mishra and Ankita Kumari. The source text argues that generic jailbreak testing misses the real risks in agentic AI and says contextual red teaming can expose tool misuse, data exfiltration, and operational vulnerabilities. The rest of the text is navigation and listings of other posts.
Protect AI BlogAI ClickFix: Hijacking Computer-Use Agents Using ClickFix
May 24, 2025MediumNewsSecurityResearchJohann Rehberger presented a demo at the SAGAI Workshop on May 15, 2025 in San Francisco, showing how ClickFix attacks apply to computer-use AI systems. ClickFix is a social engineering technique in which adversaries tell users that something is broken or needs validation, prompting them to click a button, open a terminal and run commands.
Embrace The RedZombAIs: From Prompt Injection to C2 with Claude Computer Use
Oct 24, 2024MediumNewsSecuritySafetyAnthropic released Claude Computer Use, a beta model and code package that lets Claude control a computer by reading screenshots and running bash commands. The author demonstrates how prompt injection in untrusted data can drive the model to run commands autonomously on a machine, and frames this as a fundamental design problem in LLM-powered applications and agents.
Embrace The RedThe dangers of AI agents unfurling hyperlinks and what to do about it
Apr 3, 2024MediumNewsSecurityIndustryThe post explains how automatic link unfurling in Slack can enable data exfiltration when untrusted content, such as text injected through a prompt injection attack, causes an LLM-powered Slack App to render a hyperlink with chat data appended. Slack's unfurling request sends that appended data to the third-party server. The author then shows how to disable unfurling in a Slack App's message payload.
Fix: Set "unfurl_links" and "unfurl_media" to False in the message JSON, as shown in the source's create_message function (the source's code example is cut off after "unfurl_media": Fal).
Embrace The Red
Topic added 2026-10-09. An item belongs to this topic when its title matches one of the topic's patterns or its summary mentions the topic at least twice. Report a wrong match with the feedback button on the item.