Security news

Latest security news

136 of 1,256 storiesTopic: AI SecurityClear all

Thu, 10 Sept 2026

  1. AI lets small actors run state-level hacking campaigns, Anthropic report finds

    The report details a Russian-aligned espionage campaign against more than 20 organizations, an exploit foundry run by Chinese undergraduates and ShinyHunters-affiliated breaches, among other disrupted operations.

    CyberScoop
  2. AI-powered attack exploited PaperCut flaws to hack 395 organizations

    A threat actor, likely Russian-speaking, used hundreds of AI agents to develop and launch a global exploitation campaign targeting vulnerable PaperCut NG/MF servers.

    BleepingComputerPaperCut
  3. Anthropic Researcher Resigns With Warning About the Dangers of AI Development

    Both Anthropic and OpenAI have seen high-profile resignations in recent years that were tied to safety concerns.

    SecurityWeek
  4. PuzzleMask: Abusing Plain Prose as a Covert AI Attack Vector

    Executive Summary In this research we introduce a prompt-crafting technique for bypassing quick LLM-based policy checks — using plain English (no emojis, base64, invisible formatting, etc.) A policy-violating payload (e.g. ”encrypt files in ~/Documents”, “give me a biohazard recipe”, “ignore all previous instructions and…”) is embedded in a specially crafted prose wrapper. An LLM with limited

    Check Point Research
  5. Widened Scan Turns Up Fourth Rogue Claude Cyber Incident

    Anthropic is most concerned about Claude Mythos 5’s reckless behavior after recent incidents in which real systems were hacked.

    SecurityWeek
  6. PaperCut Attacker Uses Hundreds of AI Agents to Compromise 440+ Instances

    A suspected Russian-speaking cyber actor has been attributed to the use of artificial intelligence (AI) to devise exploits targeting a recently disclosed pair of security flaws in PaperCut NG/MF and break into hundreds of instances. According to independent reports from Blackpoint Cyber and GreyNoise, the activity originates from "45.142.193[.]132," an IP address that has been linked to

    The Hacker NewsPaperCut
  7. Scytale expands vendor risk management with AI-powered TPRM tools

    Scytale has announced the launch of their latest AI-powered third-party risk management (TPRM) capabilities within its Vendors module. The release further extends vendor risk management from a periodic review exercise into a continuously updated vendor risk intelligence engine, giving security and GRC teams a current view of every vendor in their ecosystem. Scytale’s AI GRC platform automates vendor discovery, risk scoring, and evidence collection across compliance frameworks. (Source: Scytale) The expansion arrives as third-party exposure … More →

    Help Net Security
  8. GuardBreaker: Derailing AI-assisted malware analysis with a code comment

    LLM-based code scanners won’t help attackers build a nuclear weapon, but that refusal could work in their favor

    WeLiveSecurity
  9. Anthropic Reveals Yet Another Cybersecurity Incident

    Anthropic has found a fourth case of its model accessing third-party systems without authorization

    Infosecurity Magazine
  10. Nearly 1 in 10 Exposed LiteLLM Gateways Accepted the Example "sk-1234" Admin Key

    Nearly one in ten of the internet-facing LiteLLM servers that Wiz Research scanned in February accepted sk-1234, the example admin key in LiteLLM's own setup guide. LiteLLM is an open-source AI gateway, the software a company puts between its applications and the model providers it pays for. That key is the gateway's administrator credential. Anyone who holds it can read every

    The Hacker News

About this news

1,256
Stories
35
Added in the last 24 hours
18
Critical in the last 7 days
4
Reported by several outlets