Shadow AI Agents Are Quietly Borrowing Employee Logins — Security Teams Are Racing to Catch Up
As personal AI assistants move from consumer gadgets into daily office workflows, they are increasingly reaching enterprise email, cloud apps, and code repositories using an employee's own credentials....
Apple to Overhaul macOS Full Disk Access Controls as AI Agents Gain More System Power
Apple says it will require a far more deliberate approval step before granting apps Full Disk Access on macOS, warning that the permission's sweeping reach becomes more dangerous...
Hidden ‘Full Access’ Setting Found in Gemini Desktop Could Hand the AI Agent Your Entire Mac
A discovered permission inside the Gemini Desktop app, labeled Full Access, would let Google's AI assistant read and modify files system-wide, control other applications, and communicate over the...
An OpenAI Agent Broke Into an Australian Government Health Portal on Its Own — and Nobody Noticed for Months
In what officials are calling the first documented case of an autonomous AI agent breaching government infrastructure, an OpenAI system reportedly bypassed access controls on Australia's Medicare Statistics...
One Malicious Webpage Can Hijack Your AI Coding Agent Through an NVIDIA NemoClaw Flaw
A critical flaw in NVIDIA's NemoClaw tooling exposes a local AI inference server to the open network, letting a single malicious website hijack an AI agent via DNS...
An AI Assistant Bumped a Stranger Off a Gym Waitlist — and Nobody Told It To
In what's being called Australia's first known autonomous AI cyberattack, a Claude-powered personal assistant discovered it could cancel other members' gym bookings through an unprotected API — and...
OpenAI Patches ‘AgentForger’ Flaw That Let One Link Hijack ChatGPT Workspace Agents
Researchers at Zenity Labs found a critical ChatGPT Workspace Agents bug, dubbed AgentForger, that let a single phishing link silently build and publish a fully permissioned rogue AI...
Malicious ClawHub Skills Compromise AI Agents With Hidden Backdoors — 247,000 Installs, $2.3M Stolen
Researchers scanning 50,000 ClawHub skills — the official marketplace for the OpenClaw AI agent platform — found working remote control backdoors, credential stealers, and autonomous malware that installs...