Security researchers have used Anthropic’s Claude AI to uncover serious flaws in Security Assertion Markup Language (SAML) implementations that could allow attackers to bypass authentication and take over user accounts.
The findings highlight the persistent security risks created by XML...
Irregular has detailed an investigation into an AI cyber-evaluation incident in which internet access unintentionally allowed models to interact with real-world systems.
The company said the issue was contained and fixed before the first public disclosure on July 30, with...
Anthropic has introduced a new /design skill for Claude Code, expanding its developer-focused AI platform into user interface design workflows. The feature is currently available as a research preview.
It brings Claude Design’s artboard-based experience to both the Claude Code...
Z.ai has released GLM-5.3, a new AI model built to handle complex coding, long-running agent tasks, and cybersecurity analysis. The company says the model uses the same base model as GLM-5.2, with improvements coming entirely from larger-scale post-training.
The release...
A criminal AI service called MessiahGPT is being marketed on BreachForums as an uncensored platform for creating ransomware, phishing kits, stealers, crypters, rootkits, and social-engineering content.
Trellix researchers describe it as part of a growing underground market that turns offensive...
Microsoft is moving closer to a unified Copilot experience by merging key elements of its consumer AI assistant with the Microsoft 365 productivity environment.
The change positions Copilot as a single application for personal tasks, workplace productivity, files, collaboration, and...
SpecterOps has released Blacklight, an open-source toolkit that identifies local artifacts from AI coding agents like Codex, Claude Code, Cursor, and Antigravity CLI, which can expose authentication data, session history, project details, and connected services.
AI agents are increasingly used...
A new AI-agent attack technique called “Ghostjacking,” can trick coding agents into running attacker-controlled commands, changing cloud settings, stealing credentials, and creating persistent backdoors.
The research was presented by Tenet Security at DEF CON 34 in Las Vegas on August...
Anthropic has announced plans to add invisible watermarks and signed metadata to content created by Claude AI. The move follows the company’s decision to sign the European Union AI Act’s Article 50(2) Code of Practice on Transparency of AI-Generated...
Anthropic’s Claude Opus 5 has recorded the lowest indirect prompt injection attack success rate in Gray Swan’s latest benchmark, according to results provided in its system card.
The model reduced an attacker’s chance of success within 15 attempts to 2.0%....