Secure Bulletin Navigating the cyber sea with knowledge
Home > Tag > AI security
#AI security

Ransomware Affiliate Used AI Coding Tool Cursor to Plan Attacks on 20+ Companies Across 9 Countries

28 August 2026  |  dark6  |  Ransomware

An exposed staging server has given researchers an unusually detailed look at how a Russian-speaking Aurora ransomware affiliate used the AI coding assistant Cursor to help plan and...

>> read more

Grok AI Chatbot Tricked Into Leaking Private Chats Through Encrypted Prompt Injection

22 August 2026  |  dark6  |  AI

Security researchers at Adversa AI found a zero-click flaw in xAI's Grok that hides malicious instructions inside encrypted text to steal names, locations, and chat history. The attack...

>> read more

Critical MLflow Flaw Lets Attackers Steal Cloud Credentials via Webhook Redirects

19 August 2026  |  dark6  |  Vulnerability

A critical server-side request forgery flaw in MLflow, tracked as CVE-2026-64849 with a 9.3 CVSS score, lets unauthenticated attackers abuse the platform's webhook-testing endpoint to reach cloud metadata...

>> read more

Security Leaders Warn the ‘Agentic Attacker’ Has Arrived After AI Models Reportedly Breached Hugging Face on Their Own

17 August 2026  |  dark6  |  AI

An incident in which autonomous OpenAI models allegedly broke out of a sandboxed test environment and gained remote code execution on Hugging Face's infrastructure — carrying out more...

>> read more

How a Rogue Prompt Could Turn Microsoft Copilot Into a $250,000 Wire Fraud Accomplice

5 August 2026  |  dark6  |  Cybercrime

A proof-of-concept from Barracuda researchers shows how attackers could weaponize Microsoft Copilot itself to escalate a single compromised inbox into full CEO account takeover and a quarter-million-dollar wire...

>> read more

Claude Broke Out of a Sandboxed Security Test and Hit Three Real Companies, Anthropic Admits

31 July 2026  |  dark6  |  AI

Anthropic says a review of 141,000 evaluation transcripts turned up three cases where Claude models, told they were operating in an isolated capture-the-flag simulation, instead reached the live...

>> read more

Hugging Face Breach Reveals a New Front: AI Agents Attacking, AI Agents Defending

19 July 2026  |  dark6  |  Databreach

Hugging Face has confirmed a production infrastructure intrusion driven by an autonomous AI agent, exploiting two flaws in its dataset processing pipeline. The company's own AI-based forensic analysis...

>> read more

Inside NadMesh: The Shodan-Powered Botnet Hunting Exposed AI Servers

19 July 2026  |  dark6  |  Malware

Researchers at XLab have identified NadMesh, a Go-based botnet that uses Shodan to hunt down exposed AI and MCP infrastructure before hijacking it with more than 20 exploitation...

>> read more