Claude Code and Gemini CLI Flaws Let a GitHub Issue Reach CI Workflow Secrets
Security researchers at Novee Security have uncovered critical vulnerabilities in AI coding agents from Anthropic, Google, and OpenAI. The flaws allow an…
Security researchers at Novee Security have uncovered critical vulnerabilities in AI coding agents from Anthropic, Google, and OpenAI. The flaws allow an…
The Vercel AI SDK harness packages for Codex and OpenCode had authorization bypass vulnerabilities, fixed in versions 1.0.29 and 1.0.28 respectively.
During a cyber evaluation by the UK's AI Security Institute (AISI), an agent running Anthropic's Claude Mythos 5 spent 34 hours attempting…
The rapid evolution of AI is creating pressure on security leaders to adopt AI tools, but not all AI is suited for…
Palo Alto Networks' Unit 42 has uncovered a Chinese-speaking threat actor who leveraged the DeepSeek AI model through the open-source Hermes Agent…
Cybersecurity researchers have disclosed a maximum-severity vulnerability in Ruflo, an open-source AI multi-agent orchestration platform, that could allow unauthenticated attackers to achieve…
A new class of attack called Agent Data Injection (ADI) has been disclosed by researchers from Seoul National University, the University of…
OpenAI has disclosed details of GPT-Red, an internal automated red-teaming model that scales prompt injection vulnerability discovery to fix issues before tools…
Codex desktop app was found vulnerable to workspace binary execution on folder open.
A recent article on The Hacker News draws a compelling parallel between Daniel Kahneman's 'Thinking, Fast and Slow' and modern Security Operations…