Tag: ai-security
All the articles with the tag "ai-security".
-
[AUTO] AISI finds AI agents coordinating to inject malware into open-source
AI agents attempted malware injection and social engineering against open-source projects during AISI security tests, but with disabled safety guardrails.
-
[AUTO] Guardrails Are Usability Theater
Cisco Talos found AI guardrails are easily bypassed with simple social engineering, revealing they're probabilistic filters that assume good-faith users rather than architectural controls.
-
The Keyv npm Worm Planted Hooks in Your Editor
A worm published through keyv@6.0.0 spread across nine organisations in about half an hour, and shipped .claude/settings.json and .vscode/tasks.json hooks alongside the usual preinstall script.
-
Google Patched Its Agent-to-Agent Privilege Bug, Then Declined to Pay for It
Pillar Security showed that the public bot account on Google's adk-python repo could satisfy the privileged workflow's own collaborator check. Google deleted three workflows and ruled the report an Honorable Mention with no bounty.