
Topic
AI Risk & Security
Threats to models and systems, AI misuse, red teaming, and security posture
Featured

All Stories
Google Bans AI Manipulation in Search Spam Policy
Google has expanded its spam policy to explicitly prohibit attempts to manipulate its AI systems in search results,…

Agent Authorization Gaps Widen as Deployment Accelerates
Cisco's chief security officer confirmed that rogue AI agent incidents are reaching enterprise customers, but the core…

Bedrock AgentCore adds Chrome policies for controlled agent browsing
Amazon Bedrock AgentCore now supports Chrome enterprise policies and custom root CA certificates, enabling…

Anthropic's Mythos AI Shows Sharper Hacking Skills, U.K. Researchers Find
Researchers at the U.K.'s AI Security Institute reported Wednesday that Anthropic's latest version of Mythos AI…
Meta Launches Encrypted AI Chat with No Server Logs
Meta has launched Incognito Chat, a new AI conversation mode that Meta CEO Mark Zuckerberg claims offers end-to-end…

Supply Chain Attack Poisons 172 Packages with Valid Provenance
A supply chain attack dubbed Shai-Hulud compromised 172 npm and PyPI packages across 403 malicious versions starting…

Claude's Confused Deputy Flaw Spans Water Utilities, Extensions, and Code
Between May 6 and 7, security researchers disclosed three separate attacks exploiting the same architectural flaw in…
Google Stops First AI-Developed Zero-Day Before Mass Attack
Google's Threat Intelligence Group detected and blocked a zero-day exploit that was developed with AI assistance,…

Identity Governance, Not AI Capability, Is Blocking Agent Production
Enterprise deployments of AI agents are stalled at the pilot stage, with 85% of companies running pilots but only 5% in…

Finance's AI Paradox: Adoption Outpaces Governance
Finance departments are adopting AI tools faster than leadership can establish governance frameworks, creating a…

Valid Credentials Aren't Enough: Why AI Agents Break Identity Systems
A Fortune 50 CEO's AI agent rewrote the company's security policy without being compromised, exposing a fundamental gap…

Tool Registry Poisoning Exposes Gap in Agent Security
AI agents select tools from shared registries by matching natural-language descriptions, but no verification ensures…

OpenAI Details Safety Controls for Codex Deployment
OpenAI has published guidance on running Codex, its code generation model, with security controls including sandboxing,…
ChatGPT Adds User Controls for Training Data Privacy
OpenAI has published details on how ChatGPT protects user privacy while learning from interactions, including…

SAP Unifies API Governance for AI Agents, Not Gatekeeping
SAP has unified API governance policies across its product portfolio to enforce rate limits, usage controls, and…
Canvas LMS Restored After ShinyHunters Breach and Extortion Threat
Canvas, the Instructure-owned learning management platform used by schools, went offline after the hacking group…

Anthropic's Mythos uncovers high-severity Firefox bugs
Mozilla security researchers have identified a significant number of high-severity bugs in Firefox using Anthropic's…

AI Agent Supply Chain Has a Blind Spot, and Attackers Know It
Researchers have demonstrated that CLI-Anything, a popular tool for generating command-line interfaces for AI agents,…
Chrome's 4GB AI Model Download Raises Storage and Transparency Issues
Google Chrome is automatically downloading a 4GB weights.bin file containing the Gemini Nano AI model to users' system…
How AI Agents Could Reshape Democracy
AI is becoming the primary interface through which people form political beliefs and participate in democratic…

SUDP: A Protocol to Keep Agent Secrets Secret
Researchers propose SUDP, a three-role protocol that lets AI agents perform secret-backed operations (API calls, cloud…

MCP's Command Execution Flaw Exposes 200,000 AI Servers
OX Security researchers discovered that MCP's default STDIO transport executes arbitrary operating system commands…

Health Care AI Needs Deep Clinical Roots, Not Just Algorithms
Health care AI adoption is accelerating, with over 1,300 FDA-approved AI-enabled medical devices and rapid growth in…
GPT-5.5 matches Mythos Preview on cybersecurity tests
OpenAI's newly released GPT-5.5 performs at parity with Anthropic's restricted Mythos Preview model on cybersecurity…
Google Brings Gemini to Connected Vehicles via Software Update
Google is rolling out its Gemini AI assistant to vehicles equipped with Google built-in, replacing the current Google…
