Topic: ai security vulnerabilities

  • Microsoft Copilot's hidden prompt exposed in hack

    Microsoft Copilot's hidden prompt exposed in hack

    Researchers at Varonis exploited Microsoft 365 Copilot Enterprise by simply asking the AI to reveal its own safety mechanisms, eventually extracting an undocumented prompt parameter (`?autorun=1`) that enabled silent, one-click data exfiltration without user consent. Copilot's repeated refusals d...

    Read More »
  • Meta’s Muse AI Launches With Critical Security Flaw

    Meta’s Muse AI Launches With Critical Security Flaw

    Meta’s new AI assistant, Muse, faces intense scrutiny after a critical zero-day vulnerability was discovered that allows locally run applications to seize complete control of the agent. The flaw exploits cloud-based dictation by redirecting authentication tokens to malicious servers, enabling att...

    Read More »
  • Meta’s AI Muse Has Critical 0-Day Vulnerability

    Meta’s AI Muse Has Critical 0-Day Vulnerability

    Meta’s AI assistant Muse contains a critical zero-day vulnerability that allows unauthorized access to user accounts and device resources, prompting Amazon to block the tool over safety concerns. The macOS-exclusive application requires extensive permissions to function, bypassing Apple’s securit...

    Read More »
  • Claude Code Vulnerability: Researcher Hijacks AI via Web Summary

    Claude Code Vulnerability: Researcher Hijacks AI via Web Summary

    A critical security flaw in Claude Code’s Auto Mode allows attackers to execute arbitrary code on user machines by manipulating the AI into summarizing malicious webpages, succeeding in up to 80% of attempts. The exploit leverages the model's safety guardrails by forcing it to write a custom Pyth...

    Read More »
  • GrafanaGhost Bypasses AI Security for Data Theft

    GrafanaGhost Bypasses AI Security for Data Theft

    A critical vulnerability named GrafanaGhost allows attackers to covertly steal sensitive enterprise data from Grafana platforms, bypassing client-side security and AI guardrails without user interaction or stolen credentials. The attack exploits application logic flaws and AI behavior, using indi...

    Read More »
  • New Method Reveals How AI Models Think

    New Method Reveals How AI Models Think

    Researchers have discovered a technique that reveals the hidden reasoning steps of advanced AI models, exposing both how they solve problems and a security vulnerability affecting major providers like OpenAI, Anthropic, and Google. The method provides suggestive but not conclusive evidence that C...

    Read More »
  • Anthropic's Mythos crisis deepens further

    Anthropic's Mythos crisis deepens further

    Anthropic's Mythos-class AI models remain offline two weeks after a Trump administration export control order, with no clear timeline for their return and uncertainty about whether the order will expand to other companies. The impasse stems from the lack of a clear framework for AI export control...

    Read More »
  • Utah Approves AI for Medical Prescriptions

    Utah Approves AI for Medical Prescriptions

    Utah has approved a pilot program for an AI system to autonomously renew prescriptions, operating within a regulatory sandbox that reduces physician oversight, which has drawn objections from major medical associations. The AI aims to address medication non-adherence by improving access, especial...

    Read More »
  • Apple Hide My Email Service Fails to Keep Email Private

    Apple Hide My Email Service Fails to Keep Email Private

    A vulnerability in Apple's Hide My Email feature has been discovered that can expose users' real email addresses; the flaw was reported to Apple over a year ago but remains unresolved despite claims it had been addressed. A 19-year-old Estonian-U.S. dual citizen, Peter Stokes, has been arrested a...

    Read More »
  • Jeffrey Epstein's 'Personal Hacker' Revealed, Informant Says

    Jeffrey Epstein's 'Personal Hacker' Revealed, Informant Says

    A federal judge has delayed a ruling on armed DHS raids in Minnesota, amid scrutiny of ICE's use of AI surveillance tools and military-style tactics in immigration enforcement. Global security concerns include a human trafficking investigation in Laos, the rise of accessible deepfake abuse techno...

    Read More »