AI agents
Systems in which a model plans and takes actions through tools, browsers or other software on someone's behalf.
- All items
- 764
- Last 90 days
- 324
- Change
- +43%vs 227 before
Items per month
| Month | Items |
|---|---|
| May 2025 | 3 |
| Jun 2025 | 4 |
| Jul 2025 | 4 |
| Aug 2025 | 5 |
| Sep 2025 | 11 |
| Oct 2025 | 6 |
| Nov 2025 | 3 |
| Dec 2025 | 8 |
| Jan 2026 | 10 |
| Feb 2026 | 49 |
| Mar 2026 | 89 |
| Apr 2026 | 51 |
| May 2026 | 76 |
| Jun 2026 | 78 |
| Jul 2026 | 112 |
| Aug 2026 | 78 |
| Sep 2026 | 133 |
| Oct 2026 | 39 |
764 items
CVE-2026-33620: PinchTab accepts API token in URL query parameter
Mar 26, 2026MediumVulnerabilitySecurityCVE-2026-33620PinchTab, a standalone HTTP server giving AI agents direct control over a Chrome browser, versions v0.7.8 through v0.8.3 accepted the API token from a `token` URL query parameter as well as the `Authorization` header. A valid credential sent in the URL can be exposed through URIs recorded by reverse proxy access logs, browser and shell history, clipboard history, and tracing systems. The issue is an unsafe credential transport pattern rather than an authentication bypass, and it affects only deployments with a configured token where a client uses the query-parameter form.
Fix: Fixed in v0.8.4, which removes query-string token authentication and requires safer header- or session-based authentication flows.
NVD/CVE DatabaseCVE-2026-33619: PinchTab server-side request forgery in scheduler webhook delivery
Mar 26, 2026MediumVulnerabilitySecurityCVE-2026-33619PinchTab v0.8.3 contains a server-side request forgery issue in the optional scheduler's webhook delivery path. When a task submitted to POST /tasks has a user-controlled callbackUrl, the server sends an outbound POST to that URL without rejecting loopback or private destinations, and it follows redirects, enabling blind SSRF toward attacker-chosen targets reachable from the server. The scheduler is off by default, and in token-protected deployments the attacker must already hold the master API token.
Fix: Fixed in v0.8.4, which validates callback targets before dispatch, rejects non-public IP ranges, pins delivery to validated IPs, disables redirect following, and validates callbackUrl during task submission.
NVD/CVE DatabaseThe Kill Chain Is Obsolete When Your AI Agent Is the Threat
Mar 25, 2026InfoNewsSecurityIndustryA compromised AI agent that already holds access, permissions and a routine need to move data across systems can skip the traditional kill chain entirely, since the agent itself becomes the attack path. The article cites the OpenClaw crisis as evidence, noting that roughly 12% of skills in its public marketplace were malicious, a critical RCE vulnerability allowed one-click compromise, and over 21,000 instances were publicly exposed. Because the attacker's activity mirrors the agent's normal workflow, standard detection tools that look for abnormal behavior may not flag it.
The Hacker NewsAgentic commerce runs on truth and context
Mar 25, 2026InfoNewsIndustryPolicyThe article argues that agentic commerce, where AI agents discover, compare and execute purchases on a user's behalf, requires near-perfect data and trust at machine speed. It says master data management (MDM), which creates a single master record, must serve as the exchange layer that tracks who an agent represents, what it can do, and where responsibility lies.
MIT Technology ReviewHow Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem
Mar 25, 2026InfoNewsIndustryCrowdStrike introduced Charlotte AI AgentWorks, a hub for building and scaling security agents on the Falcon platform, and Charlotte Agentic SOAR, an orchestration layer that coordinates CrowdStrike-native, AgentWorks-built, and third-party agents. The announcement cites eCrime breakout times as short as 27 seconds and a 89% year-over-year rise in attacks from AI-powered adversaries as reasons for an agentic SOC model.
CrowdStrike BlogWhy Agentic AI Systems Need Better Governance – Lessons from OpenClaw
Mar 24, 2026InfoNewsSecurityPolicyAgentic AI platforms are shifting from passive recommendation tools to autonomous action-takers with real system access. The source text is a truncated excerpt from a SecurityWeek article titled "Why Agentic AI Systems Need Better Governance – Lessons from OpenClaw."
SecurityWeekExclusive eBook: Are we ready to hand AI agents the keys?
Mar 24, 2026InfoNewsSafetyIndustryMIT Technology ReviewGoverning AI agent behavior: Aligning user, developer, role, and organizational intent
Mar 24, 2026InfoNewsSafetyResearchMicrosoft researchers Fady Copty, Neta Haiby, and Idan Hen argue that trustworthy AI agents must align four layers of intent: user, developer, role-based, and organizational. The article explains that agents should satisfy the user's objective while staying within what the developer, deploying role, and organization intended. It illustrates this with an email-sorting agent that may classify messages but must not send replies or delete mail without explicit authorization.
Microsoft Security BlogMicrosoft Proposes Better Identity, Guardrails for AI Agents
Mar 24, 2026InfoNewsSecurityIndustryMicrosoft has proposed new identity and guardrail features for AI agents, which it presents as a starting point for companies facing growing threats from agentic AI. The source text gives no further detail on the features themselves.
Dark ReadingAnthropic says Claude can now use your computer to finish tasks for you in AI agent push
Mar 24, 2026InfoNewsIndustrySafetyAnthropic announced that Claude can now use a person's computer to complete tasks, such as opening apps, navigating a web browser and filling in spreadsheets, after a user sends a request from a phone. Anthropic said computer use is still early, that Claude can make mistakes, and that Claude will always request permission before accessing new apps.
CNBC TechnologyCrowdStrike Services and Agentic MDR Put the Agentic SOC in Reach
Mar 24, 2026InfoNewsIndustryCrowdStrike has announced agentic MDR, delivered by CrowdStrike Falcon Complete, and new SOC Transformation Services aimed at helping organizations move toward an agentic SOC. Agentic MDR combines deterministic automation within expert-defined guardrails, adaptive AI agents, and human analysts, and is now generally available, with a 1-minute median time to contain (MTTC) cited. The SOC Transformation Services focus on modernizing SIEM, data pipelines, workflows, and talent models.
CrowdStrike BlogPalo Alto updates security platform to discover AI agents
Mar 23, 2026InfoNewsSecurityIndustryPalo Alto Networks has announced an update to its Prisma AIRS security platform and enterprise browser that adds the ability to discover AI agents, models, and connections across an IT environment, scan agents for vulnerabilities, and let admins simulate red team tests for agents. The company also said that, assuming its planned acquisition of Koi Security completes, Prisma AIRS 3.0 will offer an AI Agent Gateway providing a central control plane for agent runtime and identity security.
CSO OnlineVaronis Atlas: Securing AI and the Data That Powers It
Mar 23, 2026InfoNewsIndustrySecurityVaronis announced general availability of Varonis Atlas, an AI security platform that discovers, posture-manages, tests and protects AI systems, including hosted AI platforms, custom LLMs, agentic frameworks, chatbots and embedded AI. Atlas is built on the Varonis Data Security Platform and offers AI inventory, AI-SPM, security testing, runtime guardrails and compliance reporting. The announcement is promotional, citing Gartner analysis that over 50% of organizations have begun or plan to deploy AI agents.
BleepingComputerNew CrowdStrike Innovations Secure AI Agents and Govern Shadow AI Across Endpoints, SaaS, and Cloud
Mar 23, 2026InfoNewsSecurityIndustryCrowdStrike announced new Falcon platform capabilities that extend AI detection and response (AIDR) to endpoints, SaaS and cloud environments. On endpoints, Falcon AIDR will extend runtime threat detection beyond the browser to desktop AI applications such as ChatGPT, Gemini, Claude, DeepSeek, Microsoft Copilot, GitHub Copilot and Cursor, and is currently in pre-beta with general availability planned for Q2.
CrowdStrike BlogWho’s Really Shopping? Retail Fraud in the Age of Agentic AI
Mar 20, 2026InfoNewsSecurityIndustryPalo Alto Networks researchers describe how agentic AI could enable retail fraud, citing Google's Universal Commerce Protocol (UCP), announced at the January 2026 NRF Big Show, which provides tokenized payments and verifiable credentials for communication between agents and business backends. They cite Bain and Company's estimate that agentic AI could handle 15-25% of e-commerce volume by 2030, and an estimate that one in four data breaches could result from AI agent exploitation by 2028. The article also notes that Organized Retail Crime costs retailers on average $700,000 per $1 billion in sales, and that criminals already use AI-generated images to facilitate returns fraud.
Palo Alto Unit 42CTI-REALM: A new benchmark for end-to-end detection rule generation with AI agents
Mar 20, 2026InfoNewsResearchSecurityMicrosoft has open-sourced CTI-REALM, a benchmark that tests AI agents on end-to-end detection engineering, from reading threat intelligence reports to producing validated Sigma and KQL detection rules. The benchmark uses 37 CTI reports from Microsoft Security, Datadog Security Labs, Palo Alto Networks, and Splunk, spanning Linux endpoints, Azure Kubernetes Service, and Azure cloud infrastructure. It scores intermediate steps such as report selection, MITRE technique mapping, and query refinement, not only the final rule.
Microsoft Security BlogSecure agentic AI end-to-end
Mar 20, 2026InfoNewsSecurityIndustryMicrosoft's RSAC 2026 announcement presents security as the core primitive of the AI stack for agentic AI. It introduces Agent 365, the control plane for agents, which becomes generally available on May 1, and new capabilities for visibility, identity, data protection and threat defense across AI workflows.
Microsoft Security BlogCVE-2026-33081: PinchTab blind SSRF through the /download endpoint
Mar 20, 2026MediumVulnerabilitySecurityCVE-2026-33081PinchTab, a standalone HTTP server giving AI agents control of a Chrome browser, versions 0.8.2 and below, has a blind SSRF flaw in its /download endpoint. validateDownloadURL() checks only the initial user-supplied URL, so the embedded Chromium browser can follow attacker-controlled redirects or navigations to internal network addresses after validation. Exploitation requires security.allowDownload=true, which is disabled by default.
Fix: Fixed in 0.8.3.
NVD/CVE DatabaseCVE-2026-33075: FastGPT workflow code execution and secret exfiltration by external contributors
Mar 20, 2026HighVulnerabilitySecurityCVE-2026-33075FastGPT versions 4.14.8.3 and below have a flaw in the fastgpt-preview-image.yml workflow. It uses pull_request_target, which runs with access to repository secrets, yet checks out code from the pull request author's fork, so any external contributor can achieve arbitrary code execution and secret exfiltration. The workflow also builds and pushes Docker images from attacker-controlled Dockerfiles, which enables a supply chain attack via the production container registry.
Fix: A patch was not available at the time of publication.
NVD/CVE DatabaseMeta AI agent’s instruction causes large sensitive data leak to employees
Mar 20, 2026LowNewsSecurityPrivacyAn AI agent at Meta gave an engineer a solution to an engineering question posted on an internal forum, and the engineer implemented it. The resulting exposure made a large amount of sensitive user and company data visible to engineers for two hours, which Meta confirmed.
The Guardian Technology
Topic added 2026-10-09. An item belongs to this topic when its title matches one of the topic's patterns or its summary mentions the topic at least twice. Report a wrong match with the feedback button on the item.