Secure Bulletin Navigating the cyber sea with knowledge
Home > Tag > AI agent security
#AI agent security

Shadow AI Agents Are Quietly Borrowing Employee Logins — Security Teams Are Racing to Catch Up

7 October 2026  |  dark6  |  AI

As personal AI assistants move from consumer gadgets into daily office workflows, they are increasingly reaching enterprise email, cloud apps, and code repositories using an employee's own credentials....

>> read more

Apple to Overhaul macOS Full Disk Access Controls as AI Agents Gain More System Power

6 October 2026  |  dark6  |  Privacy

Apple says it will require a far more deliberate approval step before granting apps Full Disk Access on macOS, warning that the permission's sweeping reach becomes more dangerous...

>> read more

Hidden ‘Full Access’ Setting Found in Gemini Desktop Could Hand the AI Agent Your Entire Mac

6 October 2026  |  dark6  |  AI

A discovered permission inside the Gemini Desktop app, labeled Full Access, would let Google's AI assistant read and modify files system-wide, control other applications, and communicate over the...

>> read more

An OpenAI Agent Broke Into an Australian Government Health Portal on Its Own — and Nobody Noticed for Months

25 September 2026  |  dark6  |  AI

In what officials are calling the first documented case of an autonomous AI agent breaching government infrastructure, an OpenAI system reportedly bypassed access controls on Australia's Medicare Statistics...

>> read more

One Malicious Webpage Can Hijack Your AI Coding Agent Through an NVIDIA NemoClaw Flaw

27 August 2026  |  dark6  |  AI

A critical flaw in NVIDIA's NemoClaw tooling exposes a local AI inference server to the open network, letting a single malicious website hijack an AI agent via DNS...

>> read more

An AI Assistant Bumped a Stranger Off a Gym Waitlist — and Nobody Told It To

10 August 2026  |  dark6  |  AI

In what's being called Australia's first known autonomous AI cyberattack, a Claude-powered personal assistant discovered it could cancel other members' gym bookings through an unprotected API — and...

>> read more

OpenAI Patches ‘AgentForger’ Flaw That Let One Link Hijack ChatGPT Workspace Agents

27 July 2026  |  dark6  |  AI

Researchers at Zenity Labs found a critical ChatGPT Workspace Agents bug, dubbed AgentForger, that let a single phishing link silently build and publish a fully permissioned rogue AI...

>> read more

Malicious ClawHub Skills Compromise AI Agents With Hidden Backdoors — 247,000 Installs, $2.3M Stolen

30 June 2026  |  dark6  |  Malware

Researchers scanning 50,000 ClawHub skills — the official marketplace for the OpenClaw AI agent platform — found working remote control backdoors, credential stealers, and autonomous malware that installs...

>> read more