2026-09-28 10:27 UTC
Security Journalism
Security Week · Eduard Kovacs · indexed 2026-09-28 10:40 UTC
The platform combines open source software and a reference system design to keep AI agents within set boundaries. The post Nvidia Unveils AI Agent Safety Platform With Hardware-Based Watchdog appeared first on SecurityWeek.
P0
2026-09-27 15:26 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-27 15:35 UTC
Security Affairs AI-CYBERSECURITY newsletter includes a collection of the best articles and research on AI in the international landscape Artificial intelligence is rapidly changing cybersecurity, reshaping both the techniques used by attackers and the tools available to defenders. AI agents can automate tasks, analyze large amounts of data, discover vulnerabilities and accelerate offensive operations. At […]
P0
2026-09-27 13:40 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-27 14:40 UTC
A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including international press. OpenAI Agents Accessed US Government Websites Without Authorization Exploit.in Database Reveals the Roots of Today’s Ransomware Ecosystem […]
P15
2026-09-26 18:09 UTC
Security Journalism
Security Week · Associated Press · indexed 2026-09-26 18:20 UTC
The US and China agreed to set up a communication mechanism for artificial intelligence-related incidents. The post China and US Agree to Establish AI Safety Channel and Continue Trade and Military Talks appeared first on SecurityWeek.
P0
2026-09-26 15:41 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-26 17:00 UTC
OpenAI is investigating AI agents that accessed US gov websites without authorization, including an attempted Education Department hack. OpenAI disclosed on Friday that its AI agents had interacted with US government websites in ways nobody planned or authorized, as part of what the company is calling an ongoing review of unexpected model behavior. The affected […]
P0
2026-09-26 12:28 UTC
Security Journalism
BleepingComputer · Mayank Parmar · indexed 2026-09-26 12:40 UTC
OpenAI says its AI agents uploaded user-provided images to third-party image-hosting services while carrying out research and evaluation tasks. [...]
P0
2026-09-26 10:30 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-26 14:20 UTC
The way we talk about AI agents is shifting, and the way we implement them requires an even more fundamental shift. While earlier discourse focused on how quickly organizations could stand up agents and how much productivity they could promise, a string of recent incidents, including a widely discussed intrusion at Hugging Face during an evaluation of OpenAI agents, has spurred organizations to
P0
2026-09-25 18:39 UTC
Security Journalism
Dark Reading · Jerry Bui · indexed 2026-09-25 19:00 UTC
When autonomous AI agents "escape the sandbox," the real story isn't rogue machines — it's the same access-control failures we've seen for decades.
P0
2026-09-25 14:51 UTC
Security Journalism
BleepingComputer · Sponsored by Token Security · indexed 2026-09-25 14:55 UTC
AI agents can operate through human credentials and take actions that existing SOC 2 controls may not distinguish from human activity. Token Security explains why SOC 2 needs to adapt to address the security gaps created by agent identities. [...]
P0
2026-09-25 12:00 UTC
Security Journalism
The Record · indexed 2026-09-25 12:15 UTC
Researchers are questioning whether an OpenAI agent needed to hack an Australian government health portal to access it, after a review of the website’s archived code found it explicitly directed visitors to an unauthenticated endpoint.
P0
2026-09-25 09:55 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-25 10:40 UTC
CARBONATO exploits exposed Docker daemons, installs an AI agent, steals API keys and spreads across networks with autonomous command execution. CARBONATO is a Docker-based botnet that has been active since at least October 2024. ThreatDown discovered the operation after finding an unauthenticated container registry exposed to the internet. The registry contained the attackers’ entire toolchain […]
P0
2026-09-24 20:10 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-09-24 20:25 UTC
A new botnet malware called Carbonato is targeting insecure hosts running Docker daemons to install the Hermes Agent AI framework and take control. [...]
P0
2026-09-24 16:00 UTC
Vendor Research
Microsoft Security Blog · Alym Rayani · indexed 2026-09-24 18:00 UTC
This month's updates help you discover and control local AI agents, extend Zero Trust to agent traffic, and strengthen SOC foundations. The post What’s new in Microsoft Security: September 2026 appeared first on Microsoft Security Blog.
P0
2026-09-24 15:52 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-09-24 16:00 UTC
The startup’s runtime enforcement platform evaluates AI agents in real time to provide visibility and control over their actions. The post Kontext Security Emerges With $4 Million for AI Agent Runtime Controls appeared first on SecurityWeek.
P0
2026-09-24 14:44 UTC
Security Journalism
Dark Reading · Arielle Waldman · indexed 2026-09-24 15:45 UTC
This installment of the Reporters' Notebook video series discusses the impact of AI agents breaching Hugging Face, Fairlife's ransomware attack, and Iranian-linked threat actors compromising a dozen US water systems. It was a busy summer.
P15
2026-09-24 14:43 UTC
Security Journalism
Security Week · Eduard Kovacs · indexed 2026-09-24 14:45 UTC
Australia disclosed that an OpenAI agent gained unauthorized access to non-public government information. The post OpenAI Agents Probed Websites for Vulnerabilities While Fetching Public Data appeared first on SecurityWeek.
P0
2026-09-24 14:00 UTC
Vendor Research
Google Threat Intelligence / Mandiant · Mandiant · indexed 2026-09-24 15:25 UTC
Introduction The landscape of software supply chain security has undergone a significant shift. Recent campaigns demonstrate that sophisticated threat actors are systematically targeting the engineering lifecycle by compromising trusted security and programming tools. These intrusions reveal three key tactics: Attackers target trusted security scanners, utility libraries, and AI developer tools to exploit the elevated privileges granted to these systems within build pipelines. Adversaries targe…
P0
2026-09-24 12:30 UTC
Security Journalism
The Record · indexed 2026-09-24 12:35 UTC
An OpenAI agent gained “unauthorized access” to “non-public files” from an Australian government health website in June, Prime Minister Anthony Albanese said.
P0
2026-09-24 10:31 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-24 11:45 UTC
OpenAI’s AI agent bypassed controls on an Australian health portal, accessed non-public files and triggered a government investigation. An OpenAI AI agent bypassed access controls on an Australian government health statistics portal in June, accessing both public and non-public files in what Australian authorities are treating as a serious AI-related cyber incident. The case was […]
P0
2026-09-24 09:38 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-09-24 09:45 UTC
OpenAI agents targeted public data providers in multiple countries, probing some for vulnerabilities and exploiting a security weakness in an Australian government portal while performing information-retrieval tasks as part of a research project. [...]
P0
2026-09-24 07:07 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-24 08:35 UTC
An AI agent on an internal OpenAI research task bypassed access controls on an Australian government Medicare statistics portal in June, Prime Minister Anthony Albanese said. The portal publishes aggregate figures, such as spending, and is separate from the systems that handle Medicare claims and personal records. The agent reached files on it that were not public, but no personal
P0
2026-09-23 16:20 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-09-23 16:30 UTC
A financially motivated threat actor is using open-source AI agent frameworks to attack hundreds of online retailers at scale, stealing more than 600,000 credit card records. [...]
P0
2026-09-23 11:47 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-23 12:40 UTC
Anthropic and OpenAI on Tuesday announced new models, with both artificial intelligence (AI) companies noting that they are continuing to invest in improving alignment to combat risky behavior. Opus 5.5, per Anthropic, is a "major step up from Opus 5," and "achieves the best scores of any model to date on our automated behavioral audit, our alignment suite that tests Claude across thousands
P0
2026-09-23 10:00 UTC
Security Journalism
Security Week · Kevin Townsend · indexed 2026-09-23 10:10 UTC
Emerging from stealth with $16 million in pre-seed funding, Outerlimit offers a decentralized authorization layer designed to discover, observe, and block harmful autonomous AI actions. The post Outerlimit Raises $16 Million to Stop Rogue AI Agents From Causing Harm appeared first on SecurityWeek.
P0
2026-09-22 19:48 UTC
Vendor Research
AWS Security Bulletins · aws@amazon.com · indexed 2026-08-15 18:58 UTC
P5
2026-09-22 17:03 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-22 17:55 UTC
Microsoft on Tuesday announced the takedown of the EvilTokens device code phishing service that it said used artificial intelligence (AI) "at every step of the attack chain." The action, carried out with authorization from the U.S. District Court for the Eastern District of Virginia, involved the efforts of Health-ISAC, alongside Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, The Shadowserver
P0
2026-09-22 16:41 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-22 17:55 UTC
A critical vulnerability in Bifrost, an open-source AI gateway that routes requests to more than 20 LLM providers, allows an unauthenticated attacker to run arbitrary commands on the gateway server with a single HTTP request. The flaw, tracked as CVE-2026-90898 (CVSS score: 9.8), affects all versions of the Bifrost HTTP transport before 2.1.0 when management authentication is
P15
2026-09-22 15:51 UTC
Security Journalism
The Record · indexed 2026-09-22 16:00 UTC
Available on Telegram for a $1,500 initiation fee and a recurring monthly $500 subscription, EvilTokens provided cybercriminals with artificial intelligence tools enabling them to compromise accounts, analyze breached inboxes and find the best methods for monetizing their access through fraud.
P0
2026-09-22 12:30 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-22 13:40 UTC
Security teams have spent decades asking whether an identity has too much access. AI agents raise a harder question: how can we determine which paths an autonomous system can discover, given the access it already has? A person may try several ways to complete a task. A deterministic application follows the flow its developer wrote. But an AI agent is relentless in its pursuit of done. In May
P0
2026-09-22 11:00 UTC
Other
Proofpoint Threat Insight · indexed 2026-09-22 18:05 UTC
P0