AI Security This Week: RoguePilot, Memory Poisoning, and 2,800 Leaked API Keys
GitHub patches critical Copilot takeover flaw, Microsoft warns of AI memory manipulation attacks, and thousands of Gemini API keys are found in public code.
Tag
GitHub patches critical Copilot takeover flaw, Microsoft warns of AI memory manipulation attacks, and thousands of Gemini API keys are found in public code.
Former Google and Stripe security head Niels Provos built an open source sandbox that assumes AI agents will go rogue. Here's how it works.
Cisco's 2026 State of AI Security report reveals a dangerous gap: enterprises are deploying AI agents faster than they can secure them, with MCP vulnerabilities and prompt injection attacks proliferating.
Security researchers found that simply opening an untrusted repository in Claude Code could execute arbitrary commands and steal your Anthropic API keys - all before you saw a warning.
IBM's annual threat intelligence report reveals attackers are using AI to accelerate vulnerability discovery while infostealer malware harvests hundreds of thousands of AI chatbot credentials from the dark web.
New paper shows 'intent laundering' bypasses Gemini, Claude, and other models with 90-98% success by removing obvious attack cues
Android malware using Gemini for real-time evasion. A low-skill attacker using Claude and DeepSeek to compromise 600 networks. NIST launches an emergency standards initiative. Welcome to February 2026.
Amazon threat researchers tracked a Russian-speaking attacker who used commercial AI tools to compensate for limited hacking skills. The result: 600+ FortiGate devices compromised across 55 countries.
Anthropic's flagship model bypassed by security researchers who extracted detailed sarin gas and smallpox synthesis instructions
A bug allowed Microsoft 365 Copilot to summarize emails marked with confidentiality labels, bypassing DLP protections. Microsoft says no one saw data they weren't authorized to see. That misses the point.
This week in AI security: Chat & Ask AI exposes 300 million messages, Microsoft patches Copilot email vulnerability, and vibe-coded apps prove trivially hackable.
Kaspersky finds DeepSeek, Llama, and ChatGPT all produce password outputs that fail standard strength tests. Prediction capability makes LLMs bad at randomness.
Microsoft Semantic Kernel has back-to-back critical vulnerabilities enabling remote code execution and arbitrary file writes through AI agent function calls
A CVSS 9.8 flaw in vLLM allows unauthenticated remote code execution through malicious video URLs. Patch now if you run multimodal models.
A new report finds most enterprises deploying AI agents have already experienced security breaches, but executives remain overconfident.
Two vulnerabilities in the popular Chainlit AI framework allow attackers to steal cloud credentials, API keys, and user data from enterprise chatbots.
Microsoft found 31 companies embedding hidden instructions in AI share buttons. One click poisons your assistant's memory without your knowledge.
Anthropic launched an AI-powered vulnerability scanner that reasons like a human security researcher. CrowdStrike, Okta, and Cloudflare dropped 8% on the news.
Researchers discovered that displaying an AI model's reasoning process creates a roadmap for attackers. OpenAI's o1 rejection rate dropped from 98% to under 2%.
ESET discovers Android malware that queries Google's Gemini AI in real-time to navigate infected devices and maintain persistence across any Android version.
A Cybernews analysis of 1.8 million Android apps found most AI apps leak credentials in code. Over 200M files were exposed via misconfigured databases.
Check Point demonstrated how web-browsing AI assistants can relay malware commands through legitimate traffic. Microsoft changed Copilot's behavior.
Researchers tricked Google Translate's Gemini-based Advanced mode into answering prompts, including requests for drug and malware instructions.
The largest global collaboration on AI safety just published its findings. An AI agent found 77% of vulnerabilities in real software.