Security news
Latest security news
Wed, 2 Sept 2026
- Malicious .git Configs Can Make Claude, Codex, Cursor, and Other AI Agents Run Attacker Code
Manifold Security has disclosed eight security flaws across seven command-line AI coding agents in which a repository's own Git configuration names a command that the agent runs on the developer's machine, four of them still unpatched at publication. The command executes as the user, outside the agent's sandbox and without an approval prompt, and exploitation requires the repository to arrive
The Hacker News - I’ve been deepfaked: What do I do?
Don’t panic if you spot an illegally created image or video of you online – there are ways to request its removal
WeLiveSecurity
Tue, 1 Sept 2026
- Anthropic pledges to try harder to keep models under control, asks partners to chip in
Security ... this time it will be different
The Register
Mon, 31 Aug 2026
- Anthropic Users Hit by Infostealer Attacks, Session Thefts
A threat actor used a variety of infostealers to collect session information and access Claude accounts belonging to an unknown number of users.
Dark Reading - The Coding-Agent Trap: When a "Free" LLM Endpoint Is the Adversary, (Mon, Aug 31st)
One of my internet-exposed inference honeypots was discovered, relabeled with sought-after model names, and incorporated into infrastructure apparently used to provide "free" LLM backends. It then received a real coding-agent session — history, filesystem output, working paths, and the agent's local tool manifest. The honeypot did not request or cause any tool execution; what the request exposed is what a malicious operator in that position could do.
SANS Internet Storm Center - AI Model Rules Are Not Security Controls
OpenAI's Hugging Face attack postmortem shows agents don't care about rules — they need strong controls.
Dark Reading - Anthropic cracks down on hijacked user accounts mining AI tokens
Commodity malware steals authenticated sessions, letting thieves freeload on victims' paid usage
The Register
Sat, 29 Aug 2026
Fri, 28 Aug 2026
- Perturbation Probing: A New Diagnostic for the Fragility of LLM Safety
New research reveals that AI safety refusal lives in a thin neural layer, highlighting the critical need for external, multi-layered security.
Unit 42 - Researcher shows how Claude Code can be tricked simply by asking it to summarize a website
More prompt-injection hijinks from wunderwuzzi
The Register
About this news
- 1,263
- Stories
- 35
- Added in the last 24 hours
- 16
- Critical in the last 7 days
- 4
- Reported by several outlets