92% of AI-Generated Code Has Critical Vulnerabilities
Three independent reports converge on the same finding: AI coding tools produce exploitable code faster than security teams can review it, and no model is getting meaningfully better.
Tag
Three independent reports converge on the same finding: AI coding tools produce exploitable code faster than security teams can review it, and no model is getting meaningfully better.
Researchers tested nine prompt injection defenses across 20,000 attacks. Every defense that relied on the model to protect itself failed. Only hard-coded output filtering survived.
OpenClaw's security crisis escalates with nine new vulnerabilities including a CVSS 9.9 admin bypass, plus researchers confirm nearly 1 in 8 marketplace skills steal user data.
New program pays researchers to find ways AI agents can be hijacked. Jailbreaks not included.
Unit 42 researchers catch indirect prompt injection attacks actively weaponizing AI agents on live websites, from forced transactions to data exfiltration
A Sev 1 security incident at Meta after an internal AI agent posted unauthorized advice that led to a two-hour data exposure. Sound familiar?
Anthropic accuses DeepSeek, Moonshot, and MiniMax of industrial-scale model theft through 24,000 fake accounts. But the company's own copyright history complicates the moral high ground.
Nation-state threat actors are operationalizing AI across the attack lifecycle, using jailbreak techniques to bypass safety controls
From Chat & Ask AI's 300 million exposed messages to widespread hardcoded secrets, security researchers reveal a systemic failure across AI applications
ARXIV OMEGA on Cisco research showing multi-turn jailbreak attacks succeed 93% of the time against open-weight AI models. Just keep talking.
An autonomous security analyzer using Claude Opus 4.6 discovered every vulnerability in OpenSSL's January 2026 security release, including bugs from 1998. It marks a turning point for AI in cybersecurity.
While enterprises focus on training data and model safety, inference - where AI actually processes requests - has become an overlooked security frontier with critical vulnerabilities.
Criminals are now fabricating entire video conferences with synthetic executives. Detection rates have fallen below coin-flip accuracy. The $40 billion deepfake fraud era has arrived.
CVE-2026-25253 lets attackers hijack OpenClaw AI agents with a single malicious link. Over 135,000 instances are exposed online, many still unpatched.
Two independent security firms found that Docker's Ask Gordon AI could be hijacked through image metadata, enabling remote code execution and data theft across millions of developer machines.
Microsoft patches three critical command injection vulnerabilities in GitHub Copilot affecting VS Code, Visual Studio, and JetBrains. Over 20 million developers at risk from unsanitized shell inputs.
A Docker AI vulnerability let attackers embed commands in image labels. Patched months ago, the pattern keeps recurring.
A new Darktrace report finds most organizations lack formal AI security policies, even as attack volumes surge and AI agents gain employee-level access across enterprises.
We gave Claude Opus 4.5 access to a Linux server and told it to solve security challenges. It completed 33 CTF levels in under an hour. Full transcript included.