Related Threat Clusters
-
Critical Ruflo Vulnerability Allows Full Control of AI Agent Platforms
Noma Labs has disclosed a critical vulnerability (CVE-2026-59726) in the Ruflo AI hosting platform, allowing unauthenticated attackers to execute arbitrary commands and take full control of AI agent environments. The…
11 articles · Updated July 29, 2026 -
New Cryptographic Context Injection Attack Targets AI Coding Agents
A novel attack technique named Cryptographic Context Injection has been identified, allowing attackers to inject malicious instructions into AI models like Grok and Gemini. This method involves shipping encrypted…
11 articles · Updated August 20, 2026 -
AI-Generated Security Patches Fail 74% of the Time, Study Reveals
A recent study by 1Password's Off-by-1 Labs found that AI-generated patches for software vulnerabilities succeeded only 26% of the time. The research analyzed 6,080 patches created by AI models ChatGPT 5.5 and Claude…
13 articles · Updated August 6, 2026 -
OpenAI Codex Fails to Mitigate Linux Threats During Cyber Incident
A Linux user attempted to use OpenAI's Codex AI agent for incident response during a cyberattack but faced significant challenges. The user was unaware that at least two threat actors had compromised their system,…
2 articles · Updated April 22, 2026 -
Vulnerabilities in AI Coding Tools Expose GitHub Secrets to Attackers
AI coding tools from Anthropic, Google, and OpenAI were found vulnerable to malicious GitHub issues. Researchers at Novee Security identified flaws in Claude Code, Gemini CLI, and Codex that could allow remote code…
2 articles · Updated August 7, 2026 -
Critical ChatGPT Data Leak Exploited via DNS Channel
A recently discovered vulnerability in ChatGPT allowed attackers to exfiltrate sensitive user data through a covert DNS channel. Researchers from Check Point found that a single malicious prompt could activate this…
13 articles · Updated March 30, 2026 -
GitHub Agentic Workflows Vulnerability Exposes Private Repositories
In July 2026, Noma Labs discovered a prompt injection vulnerability in GitHub's Agentic Workflows, named GitLost, allowing unauthenticated attackers to access private repositories by crafting a GitHub Issue in a public…
2 articles · Updated August 25, 2026 -
AI-Driven Cybercrime: Botnets, Crypto Theft, and Surveillance Exploits Unveiled
Cybercriminals are increasingly leveraging artificial intelligence (AI) to conduct sophisticated attacks, including building botnets, stealing cryptocurrency, and hijacking live camera feeds. A report by Cisco Talos…
2 articles · Updated August 5, 2026 -
Sandbox Escapes Discovered in Major AI Coding Tools
Pillar Security has identified vulnerabilities in four AI coding agents—Cursor, Codex, Gemini CLI, and Antigravity—that allow for sandbox escapes without direct attacks on the sandbox itself. These vulnerabilities stem…
6 articles · Updated July 20, 2026 -
AI Codex Exploits Samsung TV Vulnerability for Root Access
An AI coding assistant, Codex, has demonstrated the ability to gain root access on Samsung Smart TVs by exploiting vulnerabilities in the KantS2 Tizen firmware. The attack leveraged world-writable kernel drivers,…
4 articles · Updated April 14, 2026
Recent Intelligence Reports
- Agentic AI Security: Credentials and Permissions Define the Blast Radius — Blog.Gitguardian · August 25, 2026
- SymJack attack — adversa.ai · August 20, 2026
- IBM Partners with OpenAI to Accelerate Secure AI Deployment for Enterprises Across Core ... — Newsroom.Ibm · August 13, 2026
- PentestGPT turns Claude Code and Codex into an autonomous pentester — Feeds.4Sysops · August 12, 2026
- PentestGPT: Open — Feeds2.Feedburner · August 12, 2026
- AI coding tools vulnerable to malicious GitHub issues | brief — Scworld · August 7, 2026
- AI failed to properly patch software flaws 74% of the time, 1Password's study warns — Zdnet · August 6, 2026
- Keep Going Bro Youve Got This A Data Driven Look At How Adversaries Are Weaponizing Ai — blog.talosintelligence.com · August 6, 2026