Topic: ai agent vulnerabilities
-
Tech Giants Paid Bounties for AI Agent Bugs, Kept Flaws Quiet
A researcher executed successful indirect prompt injection attacks against AI agent integrations from Anthropic, Google, and Microsoft, stealing API keys and tokens by embedding malicious instructions in trusted data sources like pull requests and issues. The affected companies paid bug bounties ...
Read More » -
Claude, Codex, Hermes found in corporate networks
AI coding agents like Claude and Codex are automatically executing malicious code by processing links found in `llms.txt` files on corporate websites, exposing over 100 sites including Fortune 500 companies. Researchers demonstrated this vulnerability by identifying references to unregistered dom...
Read More » -
AI skills turned agents into credential thieves at scale
Zenity Labs researchers exposed a credential-theft operation in the AI agent add-on marketplace skills.sh, where attackers used typosquatted clones of legitimate tools; one malicious skill family alone accumulated over 1.7 million downloads. The counterfeit skills initially behaved normally to bu...
Read More » -
Sage Shields AI Agents from OS Vulnerabilities
A new open-source security tool called Sage introduces Agent Detection and Response (ADR) to intercept and inspect the actions of autonomous AI agents, preventing them from becoming vectors for malware or system compromise. Sage operates by analyzing agent actions in real-time, using methods like...
Read More » -
Anthropic AI finds thousands of zero-day bugs as Fed, Treasury meet bank CEOs
Anthropic's Claude Mythos Preview AI model identified thousands of previously unknown zero-day vulnerabilities across major operating systems and web browsers, including a 27-year-old flaw in OpenBSD and 271 bugs in Mozilla Firefox in a single evaluation pass. The discovery prompted Federal Reser...
Read More » -
OpenAI Browser Flaw Could Spam Your WhatsApp Contacts
Zenity researchers at Black Hat demonstrated that OpenAI's Atlas browser, despite having the strongest security of tested AI browsers, can be tricked into sending spam messages to all WhatsApp contacts or adding items to an Amazon cart via prompt-injection attacks. The research uncovered roughly ...
Read More » -
New ChatGPT Data Breach Exposes AI's Vicious Cycle
AI safety often relies on reactive patches for specific exploits, rather than addressing underlying systemic vulnerabilities, creating a cycle of temporary fixes. The "ZombieAgent" exploit against ChatGPT demonstrated a severe flaw, covertly extracting private data from servers and persisting acr...
Read More »