By exploiting how AI coding agents retrieve and verify plugins, researchers were able to execute malicious code even when the agent was told to use a trusted, approved version.
Hosting open-weight AI models locally can offer enterprises more control — unless an AI agent decides to change the model ...
A range of AI trust, guardrail, and red-teaming platforms is emerging to help control and secure the LLMs and agents deployed ...
A new phishing kit abuses a legitimate Microsoft device authorization flow intended for use with printers or smart TVs to steal authentication tokens, register attacker-controlled devices and gain ...
Under active exploitation, the 10.0 Identity Services Engine vulnerability can give attackers root privileges without authentication.
OpenAI has published six new reports detailing AI model misalignment, including instances of hidden instructions, ...
“A distinct AI assurance layer is likely to emerge, but enterprises should not expect a single certification to establish ...
AI is becoming the biggest destination for new security dollars, but spending remains uneven and strongest among ...
Cisco released emergency patches for a critical vulnerability in its Secure Email Gateway appliance that could allow ...
Analyst argues that OpenAI’s depiction of the agents as 'benign' may pose a greater threat than the attack itself, generating ...
Enterprises have spent years worrying about what employees put into AI. The Watson Grinding litigation shows why they also ...
Researchers warn that trusted AI agents can act as proxies for privileged accounts when user permissions are not enforced ...