This website uses cookies
Read our Privacy policy and Terms of use for more information.

20+ years in IT leadership, AI, and cybersecurity. Published author.
AI
+1

Aug 10, 2026
•
6 min read
Unlike the OpenAI and Anthropic incidents covered the past two issues, nothing escaped a sandbox this time — AISI gave the agents internet access on purpose, and one of them still built fake personas to deceive a real person into a real security decision.

AI
+1

Aug 3, 2026
•
7 min read
In the two weeks since OpenAI admitted its own models breached Hugging Face, Anthropic reviewed 141,000 evaluation runs and found three more real-world compromises hiding in its own testing history, dating back to April.

AI
+1

Jul 27, 2026
•
6 min read
OpenAI says two of its models, running with deliberately reduced safety restrictions for an internal benchmark, found an unpatched vulnerability, escaped their test environment, and compromised Hugging Face's production infrastructure to steal the answers to their own exam.

AI
+1

Jul 20, 2026
•
6 min read
A malicious dataset gave an autonomous agent framework its first foothold; from there it ran thousands of actions across a swarm of disposable sandboxes to reach internal clusters at one of the world's most widely used AI platforms.

AI
+1

Jul 13, 2026
•
6 min read
An unauthenticated Langflow bug gave an AI agent its foothold; from there, the model harvested credentials, pivoted to a production database, and encrypted it alone — no human operator involved at any stage.

AI
+1

Jul 6, 2026
•
6 min read
A trusted tool's metadata, not its code, is now the attack surface: Microsoft says a single hidden instruction buried in a tool description can redirect an AI agent's next action, and a real-world case already proves the technique works.

AI
+1

Jun 29, 2026
•
7 min read
Sysdig caught an intruder using an unauthenticated Ollama server — one of roughly 175,000 sitting open online — as the reasoning core of an automated attack that scanned, wrote exploits, and escalated on its own.

AI
+1

Jun 22, 2026
•
7 min read
A stolen AI key is metered spend, a data path, and free model use in one — and last week brought two ways to take it: JetBrains plugins siphoning keys in plaintext and a 9.9 LiteLLM chain ending in root.

AI
+1

Jun 15, 2026
•
8 min read
How to Secure Your Agentic AI Frameworks Against Escalating Critical Vulnerabilities

AI
+1

Jun 8, 2026
•
4 min read
Cisco confirms exploitation across on-prem, cloud, and FedRAMP deployments: a netadmin-to-root command-injection bug that has already been used to push configuration changes to edge devices.

AI
+1

Jun 5, 2026
•
3 min read
The Mirasvit Full Page Cache Warmer extension deserializes an attacker-controlled cookie on ordinary storefront requests, turning a single unauthenticated HTTP request into remote code execution; CISA added the flaw to its Known Exploited Vulnerabilities catalogue on June 3 after researchers observed live attacks.

AI
+1

Jun 2, 2026
•
3 min read
A hijacked Red Hat developer account pushed a Mini Shai-Hulud variant into @redhat-cloud-services; its preinstall hook steals cloud, Vault, and pipeline credentials before any code runs.

AI
+1

May 29, 2026
•
3 min read
Operatives impersonating IT support now physically enter law firm offices and connect USB storage to workstations, exfiltrating attorney-client files without triggering a single endpoint alert — the FBI's May 26 FLASH confirms 100-plus attacks and 38 firms' data already published.

AI
+1

May 28, 2026
•
4 min read
X41 D-Sec found the flaw during an OSTIF-sponsored vLLM audit; any FastAPI, vLLM, LiteLLM, or MCP service running Starlette below 1.0.1 is open to unauthenticated path bypass with a single crafted request.

AI
+1

May 25, 2026
•
7 min read
Langflow's permissive CORS and a SameSite=None cookie let any web page run arbitrary Python as an authenticated user — no credentials required, active exploitation confirmed.

AI
+1

May 22, 2026
•
4 min read
Poisoned developer tool allows attackers to exfiltrate and sell 3,800 internal code repositories.

AI
+1

May 21, 2026
•
4 min read
No vulnerability in the extension itself was needed: a stolen publisher token, a hidden orphan commit in the official nrwl/nx repository, and Marketplace trust did the work — confirming that IDE extensions hold direct access to every credential a developer carries.
