Mandiant's enterprise AI report finds runaway agents, prompt injection, and weak access controls already costing real money.
Check Point shows a planted instruction can make ChatGPT exfiltrate Gmail data through a covert channel between accounts.
ESET says Russia-aligned UAC-0099 hides a nuclear weapon request in malware comments to stall AI-powered triage.
A prompt injection flaw in Amazon's Kiro IDE can push sensitive local data to attackers when a poisoned project is…
Adversa AI shows how ciphertext hidden in a page can make xAI's Grok hand over chat details with no warning.
Varonis shows how one click on a crafted link can drain data from connected apps in Microsoft Copilot Personal.
Tenet Security's Ghostjacking demo shows attackers planting instructions in logs that AI agents read and execute, targeting Cloudflare, Datadog, and…
Two firms found independent ways to turn Atlassian's Rovo assistant into a one-click data leak.