Full Archive · Page 7

Research archive, page 7

Browse entries 145–168 of 1346. Return to the first page to search and filter the complete collection.

Wiz AI Security August 27, 2026 analysis

Inside 90 days of attacks on AI infrastructure

Across 90 days of AI-service honeypots, Wiz observed exploitation of LiteLLM MCP flaws, blind prompt injection that used out-of-band callbacks to confirm agent shell execution, and post-exploitation tailored to steal model-provider and proxy credentials from process memory. The activity targeted AI infrastructure as ordinary high-value cloud infrastructure.

Black Hat Asia 2026 | Cache Me, Catch You: Exploiting LLM Caching Layers in vLLM, GPTCache & Friends video thumbnail Play video
Black Hat August 21, 2026 video

Black Hat Asia 2026 | Cache Me, Catch You: Exploiting LLM Caching Layers in vLLM, GPTCache & Friends

The NDSS-backed research identifies six inference-time cache attacks across vLLM, SGLang, GPTCache, and related stacks. Weak prefix and image cache keys plus semantic near-match errors can make distinct inputs share cached state, enabling poisoned responses, information leakage, and moderation bypass; the authors provide experimental artifacts and vendor disclosures.

Adversa AI Trusted AI Blog August 18, 2026 analysis

Top 10 zero-click attacks against AI agents

Adversa compares ten shipped or research-stage zero-click agent compromises, including EchoLeak, DuneSlide, TrustFall, ShadowLeak, GeminiJack, and Morris II. The recurring chain is untrusted retrieved content entering model context, an agent applying inherited privileges, and data or code escaping through images, cloud requests, browser navigation, email, or a developer shell.

The Hacker News AI Security August 18, 2026 analysis

AI "Mind Viruses" Can Spread Between Agents Through Persistent Prompt Files

An Anthropic and EPFL preprint tests self-propagating instructions in sandboxed agent chains whose MEMORY.md and SOUL.md files persist across sessions. Writes to the system-loaded soul file produced most propagation attempts and infected the next agent 55% of the time; all four action payloads survived some 20-hop trials. A one-paragraph warning reduced tested spread to near zero, and the researchers found no successful wild propagation in archived Moltbook data.

The Hacker News AI Security August 18, 2026 analysis

Microsoft Copilot Personal Flaws Could Let One Click Exfiltrate Data From Connected Apps

Varonis' CoSnitch research combines Copilot Personal's q parameter with an undocumented autorun parameter so one crafted link executes an attacker prompt inside a signed-in session. The prompt can read already authorized mail, calendars, Drive metadata, chat history, and memory, then exfiltrate data through Copilot's URL fetch. A separate web-summarization path could persist attacker instructions in memory. Microsoft patched CVE-2026-24301 on August 18.

Why Great Models Fail: Lessons From 9 Years of Deploying ML Models - Megan Robertson video thumbnail Play video
NDC Conferences YouTube August 13, 2026 video

Why Great Models Fail: Lessons From 9 Years of Deploying ML Models - Megan Robertson

Drawing on nine years of cross-industry ML deployments, Megan Robertson explains why a statistically accurate model can still fail to deliver in production. The session moves beyond offline performance to scoping, organizational failure modes, monitoring, maintainability, and the operational conditions required for a model to keep producing useful results.

Adversa AI Trusted AI Blog July 30, 2026 analysis

A hole in every one: bypassing the open source AI skill scanners

Adversa tested eight open-source AI skill scanners with paired unobfuscated and obfuscated malicious skills, finding that every scanner passed an attack through either a true bypass, a blind spot, or an injectable model judge. The study covers encoding, Unicode, command reconstruction, truncation, allowlists, bundled files, paraphrase, and remote stages; its 4,000-skill benign set also found no scanner beat an always-block baseline on F1. Most tools ran offline without optional model triage, and some were reconstructed from retained artifacts.

From Prompt Tricks to Autonomous Hackers video thumbnail Play video
Black Hat July 29, 2026 video

From Prompt Tricks to Autonomous Hackers

Ari Herbert-Voss reviews three years of progress in autonomous offensive-security systems, evaluates where they can already complete meaningful attack tasks, and separates those capabilities from work that still needs human expertise. The talk frames scalable, parallel attack simulation as a challenge to point-in-time testing rather than as a product announcement.

METR July 24, 2026 analysis

Metrics of Agent Ability

METR organizes agent-capability measures around performance as a function of expenditure, comparing fixed-budget scores, cost to reach a score, returns to test-time scaling, human-equivalent time and expenditure horizons, and human-relative cost. It explains when familiar benchmark scores break down—particularly when performance keeps improving with more inference or human benchmarks saturate—and notes that full cost, reliability, coverage, and elicitation choices affect the result.

OpenAI News June 1, 2026 analysis

“Tech and Tariffs” Campaign: Influence activity targeting US tech policy

OpenAI describes a likely PRC-origin cluster that used ChatGPT to generate political comments and cartoons, edit work reports, and plan social-media monitoring. The report distinguishes observed prompts and account links from attribution judgments and rates the operation Category One: activity on one platform with little authentic engagement and no evidence of breakout.

RIG-RAG: A Graph-Inspired Approach to Agentic Cloud Infrastructure video thumbnail Play video
CAMLIS / PMLR November 14, 2025 video

RIG-RAG: A Graph-Inspired Approach to Agentic Cloud Infrastructure

RIG-RAG converts changing cloud configuration data into a typed, security-enriched graph for natural-language investigation and scheduled oversight. The authors report a production AWS deployment supporting 300,000 users, with interactive queries for analysts and curated recurring questions that detect infrastructure drift and expose relationships such as public reachability and identity access.

The Hacker News AI Security August 31, 2026 news

Aurora Ransomware Operators Use Cursor AI in Attacks Against 10 Targets

CloudSEK and Gambit Security report that an Aurora ransomware affiliate used Cursor for sustained Russian-language attack planning and hands-on exploitation after obtaining credentials or an existing route into victim networks. Recovered infrastructure linked the agent sessions to Active Directory discovery and escalation plans, while the broader intrusion still relied on familiar social engineering, credential theft, lateral movement, defense evasion, exfiltration, and ransomware deployment.

The Hacker News AI Security August 20, 2026 news

AI-Generated Exploit Scripts Target Siemens S7 PLCs in U.S. Critical Infrastructure

A joint U.S. government advisory describes threat actors using AI-assisted Python scripts and public automation libraries to find and interact with exposed Siemens S7 and other PLCs. The activity relies on known vulnerabilities and weak segmentation for reconnaissance, credential access, denial of service, and capability development rather than a novel model-specific exploit.

The Hacker News AI Security August 5, 2026 news

Paperclip AI Flaws Let Attackers Run Host Commands via Malicious Agent Imports

Paperclip vulnerabilities let malicious agent imports reach host command execution through an authorization gap in network deployments and DNS rebinding against local-trusted deployments; additional routes missed expected access checks. The reviewed code in v2026.416.0 contains the import and hostname-validation fixes, although public advisory metadata was not fully aligned and no in-the-wild exploitation was reported.

Noma Labs July 29, 2026 analysis

RufRoot: unauthenticated Ruflo MCP bridge enabled RCE and memory poisoning

Before Ruflo 3.16.3, its default Docker Compose deployment bound the MCP bridge to all interfaces without authentication. A reachable attacker could invoke the terminal tool, read model-provider keys and conversations, spawn agents, and poison persistent AgentDB patterns. Noma Labs verified the chain; the patch adds loopback binding, bearer authentication for public exposure, an opt-in terminal tool, authenticated MongoDB, tighter CORS and container defaults, and regression tests.

Hunt.io July 23, 2026 analysis

Thailand's Ministry of Finance Targeted With Hermes AI Agent Running Unattended

Hunt.io recovered 585 files and Hermes logs from an exposed staging server used against Thailand's Ministry of Finance. The evidence shows an operator who already had target knowledge and access running Hermes in unattended “YOLO” mode for repetitive post-exploitation enumeration, while also staging Hadoop exploitation scripts and a custom Hades implant; it does not show the agent finding the initial entry point or novel vulnerabilities.