Reading view
OpenAIโs Upcoming Astra Model Raises Autonomous Cyberattack Concerns
The current GPT-5.6-Sol has been assigned a โhighโ cybersecurity threshold, but Astra could reach the maximum โcriticalโ threshold.ย
The post OpenAIโs Upcoming Astra Model Raises Autonomous Cyberattack Concerns appeared first on SecurityWeek.
โGhostjackingโ Attack Uses Poisoned Logs to Turn AI Agents Bad
An AI agent executes instructions that an attacker has planted in the log or alert that records a blocked request word for word.
The post โGhostjackingโ Attack Uses Poisoned Logs to Turn AI Agents Bad appeared first on SecurityWeek.
Critical One-Click Vulnerability in Atlassianโs Rovo AI Exposed Enterprise Data
The RovoBlast attack method identified by Varonis researchers could have been exploited to steal Confluence, Jira and SharePoint data.
The post Critical One-Click Vulnerability in Atlassianโs Rovo AI Exposed Enterprise Data appeared first on SecurityWeek.
What Canvas learned from a massive cyberattack
In Other News: AI Slop Limits Apple Bounties, North Carolina Port Attacks, Hackers Target Wall Street
Noteworthy stories that might have slipped under the radar: ban on Chinese data center tech, QuickFox VPN supply chain attack, IEH Corporation mailbox breached via phishing.
The post In Other News: AI Slop Limits Apple Bounties, North Carolina Port Attacks, Hackers Target Wall Street appeared first on SecurityWeek.
OpenAI rolls out a major ChatGPT upgrade, even if you donโt pay for it
Zero-Click AI Browser Hacking: Claude and ChatGPT Atlas Hijacked via Emails, X Posts
Zenity researchers reported the findings to Anthropic and OpenAI in late 2025 and early 2026, but they remain unpatched.
The post Zero-Click AI Browser Hacking: Claude and ChatGPT Atlas Hijacked via Emails, X Posts appeared first on SecurityWeek.
Critical Paperclip Flaw Allowed Admin Access, Code Execution
An attacker could self-register, sign in for board-level API access, and import a new company for code execution.
The post Critical Paperclip Flaw Allowed Admin Access, Code Execution appeared first on SecurityWeek.
Meta AI Hacked External Systems During Cybersecurity Testing
The incident involved a testing environment set up by Irregular, similar to what Anthropic reported last week.
The post Meta AI Hacked External Systems During Cybersecurity Testing appeared first on SecurityWeek.
Cybersecurity Alliance Drafts SAFE Guidelines for Sharing AI Incident Dataย
The guidelines are the work of the recently launched Open Secure AI Alliance, which now includes 120 organizations.
The post Cybersecurity Alliance Drafts SAFE Guidelines for Sharing AI Incident Dataย appeared first on SecurityWeek.
AI Agents Targeted Real People and Projects During Cybersecurity Tests
AI Security Institute reports Anthropic and OpenAI models going rogue against real people, organizations, and open source projects.
The post AI Agents Targeted Real People and Projects During Cybersecurity Tests appeared first on SecurityWeek.
Republican attorneys general urge OpenAI to preserve records on Hugging Face breach
Rethinking AI Security: Why CASB and DLP Need an Interaction-Aware Layer
Build your strategy around answering these questions to ensure employees use AI productively while keeping sensitive data, IP, and agent behavior within the boundaries set for safe AI use.
The post Rethinking AI Security: Why CASB and DLP Need an Interaction-Aware Layer appeared first on SecurityWeek.
Zenity Raises $125 Million in Series C Funding
The AI security company will invest in product innovation, global expansion, and customer experience.
The post Zenity Raises $125 Million in Series C Funding appeared first on SecurityWeek.
Obsidian Security Raises $85 Million at $1.1 Billion Valuation
Obsidian Security has developed a platform for governing AI agents across third-party applications.
The post Obsidian Security Raises $85 Million at $1.1 Billion Valuation appeared first on SecurityWeek.
Gemini Agent-to-Agent Attack Method Exposed Secrets, Enabled Pull Request Tampering
A crafted prompt to a low-privilege Google ADK agent could be used to pass a malicious hand-off comment to a privileged agent.
The post Gemini Agent-to-Agent Attack Method Exposed Secrets, Enabled Pull Request Tampering appeared first on SecurityWeek.
OpenAI, Anthropic AI agents targeted real people and systems in cyber tests
Black Hat USA 2026 โ Summary of Vendor Announcements (Part 1)
Many companies are showcasing their products and services this week at the 2026 edition of the Black Hat conference in Las Vegas.
The post Black Hat USA 2026 โ Summary of Vendor Announcements (Part 1) appeared first on SecurityWeek.