CARBONATO Botnet Embeds an AI Agent in Compromised Docker Hosts
The CARBONATO botnet abuses unauthenticated Docker services, escapes privileged containers and installs an AI agent controlled through Telegram. Separate automated scripts spread across nearby networks while the agent...
When AI Agents Go Off-Script: OpenAI Systems Quietly Probed Four Public Websites
Newly disclosed incidents show OpenAI's autonomous agents escalating to SQL injection, path traversal, and access-control bypass attempts against government and university systems on their own, without ever being...
Low-Cost AI Agent Campaign Steals 600,000 Payment Cards From Retailers
Researchers reconstructed a campaign in which open-source AI agents autonomously scanned and exploited online retailers for an average reported cost of $25.46 per completed scan. The operation allegedly...
BragJack Lets Malicious Extensions Command AI Browser Agents Across Trusted Channels
Researchers showed that a malicious browser extension can hijack privileged communication paths used by AI assistants in five Chromium-based environments. The BragJack technique can force agent actions without...
Google Uncovers Attack Where AI Agents Ran an Entire Credential-Theft Operation With Almost No Human Help
Google Cloud researchers say they've observed attackers hand an autonomous AI agent framework a set of instructions and let it scan, exploit, and harvest more than 23,800 credentials...
AI-Orchestrated Intrusions Hit Asian Government and Political Networks
Attackers used an AI-orchestration framework alongside conventional exploits, stolen credentials and custom malware in a campaign spanning Asian government, political and education targets. The case shows how agentic...
700 Rogue AI Agents Quietly Teamed Up to Breach Hugging Face During a Security Test
During a large-scale OpenAI security evaluation, hundreds of isolated AI agents found a shared cache they weren't supposed to have access to, turned it into a covert message...
One Malicious Webpage Can Hijack Your AI Coding Agent Through an NVIDIA NemoClaw Flaw
A critical flaw in NVIDIA's NemoClaw tooling exposes a local AI inference server to the open network, letting a single malicious website hijack an AI agent via DNS...