Agentic AI Forces Enterprises to Replace Standing Access With Task-Level Control
Rapid adoption of autonomous workplace agents is exposing the limits of broad, long-lived permissions designed for people and predictable software. Enterprises need short-lived credentials, task-specific authorization and clear...
Hugging Face Intrusion Shows Autonomous AI Can Break In—but Struggles to Stay Quiet
An AI security evaluation reportedly escaped its intended environment and spent days inside Hugging Face systems, leaving an unusually detailed record of autonomous offensive behavior. The case shows...
Gemini Security Test Escaped Its Sandbox and Reached Three Real Companies
Google confirmed that Gemini accessed systems at three real companies after a cybersecurity evaluation mistakenly left internet access enabled and used a fictional company name that matched a...
OpenAI Caught Its Own Models Stealing API Keys and Faking Data During Training Runs
OpenAI has disclosed six internal incidents in which models under reinforcement-learning training went looking for ways around blocked tasks — one located and used an exposed API key...
BragJack Lets Malicious Extensions Command AI Browser Agents Across Trusted Channels
Researchers showed that a malicious browser extension can hijack privileged communication paths used by AI assistants in five Chromium-based environments. The BragJack technique can force agent actions without...
Google Uncovers Attack Where AI Agents Ran an Entire Credential-Theft Operation With Almost No Human Help
Google Cloud researchers say they've observed attackers hand an autonomous AI agent framework a set of instructions and let it scan, exploit, and harvest more than 23,800 credentials...
AI Infrastructure Needs Automatic Containment as Attacks Accelerate Beyond Human Response
AI-connected environments can let autonomous attacks progress faster than analyst-led response processes can contain them. Security leaders should redesign controls around isolation, short-lived identities, behavioral sequences and tested...
Russia-Aligned Group Tests Prompt Injection to Blind AI Malware Scanners
A Russia-aligned campaign used a malicious script comment designed to trigger an AI model’s safety refusal and interrupt malware analysis. The GuardBreaker technique, found in a MATCHBOIL delivery...