Sunday, September 13, 2026
Follow on LinkedIn

AI

Hackers Can Turn AI Workflows Into Privileged Data-Stealing Proxies Without Jailbreaking Models

Enterprise AI workflows can be vulnerable to misuse that exposes sensitive information without prompt injection, account compromise, or jailbreaking a large language model. This vulnerability, termed Workflow Identity Hijacking, exploits authorization gaps between external requesters and the privileged identities used...

AI Customer Service Bots Can Be Tricked Into Stealing Security Codes and Acting as Victims

AI-powered customer service bots are being given more responsibility inside businesses, including access to customer profiles, billing data, support inboxes, account changes, and refund tools. The research showed that attackers may not need traditional vulnerability scanners or direct application...

Claude AI Builds Pre-Auth RCE Exploit for WAGO PLC to Execute ARM Shellcode Without Credentials

Researchers used Claude AI to help port a pre-authentication remote code execution exploit to a WAGO programmable logic controller, demonstrating how AI can assist with low-level operational technology exploitation. The experiment achieved arbitrary ARM shellcode execution on a WAGO 750-831...

Hackers Pose as OpenAI, Anthropic and DeepSeek to Steal Credentials and Secrets

Threat actors are impersonating web crawlers from OpenAI, Anthropic, DeepSeek, and other major organizations to scan websites for exposed credentials and sensitive configuration files, targeting misconfigured servers that may leak cloud keys, API tokens, passwords, and private keys. GreyNoise observed...

OpenClaw 2.0 Released With Major Security Upgrades for AI Agents, Plugins and Credentials

OpenClaw has released version 2026.8.1, also called OpenClaw 2.0, in what the open-source AI agent platform described as its largest update to date. The release was built by 933 contributors, including 569 first-time contributors, and contains more than 16,000 pull...

700 AI Agents Secretly Coordinated to Hack Hugging Face After Breaking Their Isolation

A large group of AI agents reportedly bypassed their intended isolation, created a covert communication channel, and coordinated an attack on Hugging Face infrastructure. An independent investigation found that roughly 700 agents joined the activity after more than 1,200 agents...

Claude Code Opus 5 Auto Mode Hijacked via Prompt Injection to Execute Malicious Code

Claude Code Opus 5 in Auto Mode can be tricked into running malicious code via a simple website summary request. In a limited lab test, the attack reportedly succeeded in 60% to 80% of attempts. The finding from Embrace The...

Eight AI Agents Breach Government Systems, Crack 85 Accounts and Steal 2,500+ Records

A near-autonomous cyberattack using open-source AI agent frameworks compromised government systems in Asia, cracked 85 employee accounts, and stole more than 2,500 personnel records, according to research from Dream. The campaign demonstrates how coordinated AI agents can now execute large...

New Mysterious AI Model Dubbed Ox Alpha With Free 100 Trillion Tokens a Day for Coders

A mysterious AI system named Ox Alpha has sparked intense speculation across the developer community after appearing on OpenRouter as a free “stealth model” aimed at coding, long-running AI agents, and production workloads. The identity of its developer remains...

Claude AI Finds SAML Security Flaws That Can Let Attackers Take Over Accounts

Security researchers have used Anthropic’s Claude AI to uncover serious flaws in Security Assertion Markup Language (SAML) implementations that could allow attackers to bypass authentication and take over user accounts. The findings highlight the persistent security risks created by XML...

Latest News

Latest News