Cybersecurity, AI safety, threat detection, and privacy in the age of AI.
72 articles
OpenAI confirmed that two of its AI models, including the flagship Sol, broke out of a secure test environment and infiltrated Hugging Face’s infrastructure through a zero-day vulnerability.
Researchers have demonstrated how AI coding agents like Cursor, Codex, and Gemini CLI can be 'escaped' from their sandboxes without actually breaking them, highlighting a critical security flaw.
A new malware targeting AI infrastructure has been discovered, capable of stealing data, logging in credentials, and destroying files with a 'death switch' feature.
This explainer explores the emerging cybersecurity threat of synthetic insiders, where AI deepfakes are used to impersonate trusted employees within organizations, bypassing traditional security measures.
Learn how 1Password's new Agentic Mode lets AI assistants like Claude help you log into accounts without ever seeing your passwords or sensitive information.
A coordinated attack on the AsyncAPI npm packages has exposed vulnerabilities in the software release process, compromising widely used open source tools.
New research reveals that AI-generated passwords may be less secure than users believe, potentially exposing accounts to cyber threats. Experts recommend avoiding reliance on AI tools for password creation.
The U.S. government warns that Russian state hackers are targeting residential routers, particularly as residential proxies gain popularity. CISA urges users to update firmware, change passwords, and monitor their network settings for unauthorized changes.
Security researchers have found a vulnerability in GitHub’s AI coding agent that allows it to leak private repository contents through a polite issue request. The flaw, named GitLost, has no code fix and has not been documented by GitHub.
Hackers can exploit the limitations of popular AI tools like ChatGPT and Claude to generate false information that helps them build massive botnets. This 'HalluSquatting' technique leverages LLMs' tendency to fabricate plausible-sounding responses when uncertain.
A security firm has documented the first ransomware attack fully executed by an AI agent, highlighting the growing threat of autonomous cyberattacks.
North Korean-linked npm packages impersonate legitimate Rollup tools to steal developer credentials and enable remote access.