AI Security News

Security news at the intersection of AI: vulnerabilities in AI systems, and AI's role in both attacks and defense.

AI security is a two-sided story: new vulnerability classes specific to AI systems (prompt injection, model manipulation, data poisoning) on one side, AI-assisted attacks and defenses on the other. Vulnerabilities and incidents involving AI tooling and models land here, along with reporting on how AI is changing offense and defense. The field is young and does not yet have the settled conventions of more mature security domains.

Recent AI items

Deepfakes Are Becoming a Costly Reality for Businesses, Report Warns 📔 A quarter of victims of deepfake attacks have lost over 1m. CISOs worry that boardrooms dont understand the threat. 📖 Read more.…
@cibsecurity · Sep 28, 2026
Carbonato Botnet Compromises Docker Hosts to Deploy Telegram-Controlled Hermes AI Agent 🖋️ Cybersecurity researchers have disclosed details of a new botnet malware called Carbonato that's targeting ex…
@cibsecurity · Sep 28, 2026
RatHat Android Malware Console Uses Gemini to Identify Higher-Value Victims 🖋️ RatHat's operators build and publish the Android banking trojan and control infected phones from a web console, according…
@cibsecurity · Sep 28, 2026
Anthropic Declines Australian AI Hearing as OpenAI Agent Breach Faces Scrutiny 🦿 Anthropic declined an Australian Senate AI hearing as officials investigate an OpenAI agent breach and consider mandato…
@cibsecurity · Sep 28, 2026
CVE-2026-85887 Incorrect permission assignment for critical resource in M365 Copilot allows an authorized attacker to disclose information over a network. 🎖
@cveNotify · Sep 28, 2026
RatHat Android Malware Console Uses Gemini to Identify Higher-Value Victims https://ift.tt/PbhWLZu
@ctinow · Sep 28, 2026
RatHat, an Android banking trojan, uses Gemini to rank infected phones by estimated bank balance. Cleafy traced nearly 100 console deployments since April 2026. Gemini helps operators prioritize victi…
@thehackernews · Sep 28, 2026
Modulate Raises $25 Million to Advance Deepfake Detection https://ift.tt/fenhriy
@ctinow · Sep 28, 2026
OpenAI Agent Swarm Used Nearly 1 Million URLs to Hack Hugging Face https://gbhackers.com/openai-agent-swarm-used-nearly-1-million-urls-to-hack-hugging-face/
@PentestingNews · Sep 28, 2026
OpenAI pauses work on top AI models after agent slips past internet controls https://ift.tt/7U0kh9Q
@ctinow · Sep 28, 2026
OpenAI is preparing “o,” an always-on ChatGPT assistant that could handle email OpenAI is testing a new always-on assistant called "o", and references to the unannounced feature briefly showed up on t…
@bleepingcomputer · Sep 27, 2026
OpenAI is preparing “o,” an always-on ChatGPT assistant that could handle email https://ift.tt/uspz0w3
@ctinow · Sep 27, 2026
Anthropic turns Claude into an AI marketplace with 2,000+ plugins and connectors Anthropic has just announced a new Claude Marketplace, and it brings all AI-related tools into one place, including plu…
@bleepingcomputer · Sep 27, 2026
Revealing the details of how OpenAI agents hacked Hugging Face https://swarmtraces.org/
@secharvester · Sep 27, 2026
Zero Trust for AI Agents Starts With Fixing Zero Visibility 🖋️ The way we talk about AI agents is shifting, and the way we implement them requires an even more fundamental shift. While earlier discour…
@cibsecurity · Sep 27, 2026
CVE-2026-100863 Heym versions 0.0.90 and earlier contain two server-side request forgery (SSRF) egress gaps, both remediated in app/services/ssrf_guard.py in 0.0.91. First, the LLM image-edit input lo…
@cveNotify · Sep 27, 2026
OpenAI halts training of latest models as reports mount of AI agents going rogue https://ift.tt/98ikESM
@ctinow · Sep 27, 2026
OpenAI Agents Accessed US Government Websites Without Authorization https://securityaffairs.com/199815/ai/openai-agents-accessed-us-government-websites-without-authorization.html
@PentestingNews · Sep 26, 2026
Claude Opus 5.5 uses 95% fewer em dashes, but its answers are getting longer Anthropic's Claude Opus 5.5 appears to be changing how it writes, with new analysis showing fewer obvious AI writing patter…
@bleepingcomputer · Sep 26, 2026
Google Confirms Gemini Autonomously Hacked Three Companies During Security Testing Google confirmed its Gemini AI model autonomously breached the protected systems of three companies during red-team t…
@Cyber_Security_Channel · Sep 26, 2026
OpenAI's AI agents accidentally uploaded user-provided images to third-party sites OpenAI says its AI agents uploaded user-provided images to third-party image-hosting services while carrying out rese…
@bleepingcomputer · Sep 26, 2026
OpenAI's AI agents accidentally uploaded user-provided images to third-party sites https://ift.tt/4t6xGFw
@ctinow · Sep 26, 2026
OpenAI Says Its Models Engaged With US Government Websites in New Model Misbehavior Disclosure https://ift.tt/QWxAOu4
@ctinow · Sep 26, 2026
CVE-2026-100585 OpenClaw (npm package `openclaw`) before 2026.7.1 fails to enforce the owner-only authorization requirement for Claude Code permission prompts delivered through the MCP channel bridge.…
@cveNotify · Sep 26, 2026
CVE-2026-84301 FastGPT is an open-source LLM platform for building AI applications on a knowledge base. Prior to 4.15.2, the safe Axios request interceptor in packages/service/common/api/axios.ts vali…
@cveNotify · Sep 26, 2026
CVE-2026-55946 Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to disclose information over a network. 🎖
@cveNotify · Sep 25, 2026
What We Missed: Google Gemini Joins the AI Escape Party https://ift.tt/2oaiN9K
@ctinow · Sep 25, 2026
Anthropic rolls out up to $250 in free Claude Code credits, but only for cloud sessions https://ift.tt/ePihYma
@ctinow · Sep 25, 2026
Anthropic rolls out up to $250 in free Claude Code credits, but only for cloud sessions Anthropic now allows you to run Claude Code via cloud sessions without signing up for the research preview, and…
@bleepingcomputer · Sep 25, 2026
OpenAI is preparing a $500 ChatGPT Pro Max plan with faster Codex OpenAI appears to be preparing a new ChatGPT Pro Max subscription that could cost $500 per month, but it's unclear when it'll begin ro…
@bleepingcomputer · Sep 25, 2026

Other topics

CVE
Recent CVE identifiers and vulnerability disclosures aggregated from security feeds: new IDs, published advisories, and the vendors and products they affect.
Ransomware
Ransomware attacks, extortion group activity, victim disclosures and decryptor releases.
Phishing
Phishing campaigns, credential-harvesting kits, and social-engineering techniques used to compromise users and organizations.
Zero-Day
Zero-day vulnerabilities being actively exploited before a patch exists, and the fixes that follow.
Data Breach
Confirmed and reported data breaches: what was exposed, which organizations were affected, and how the incident came to light.
Exploit
Public exploit code, proof-of-concept releases, and technical exploitation write-ups for known vulnerabilities.