ThreatDown researchers found that Kriminal.ai, a clearnet cybercrime storefront selling 'uncensored' AI access, isn't running its own model at all: it's a jailbreak prompt layered over rented Grok and Claude capacity.
The latest AI security developments, threats, and industry updates.
ThreatDown researchers found that Kriminal.ai, a clearnet cybercrime storefront selling 'uncensored' AI access, isn't running its own model at all: it's a jailbreak prompt layered over rented Grok and Claude capacity.
OpenAI is previewing Private Safety Processing, a system that flags patterns of AI misuse across sessions without OpenAI staff ever seeing customer prompts, aiming to close the gap between zero-retention privacy and abuse monitoring.
CVE-2026-55253 lets attackers inject MongoDB operators into LangGraph's checkpoint filters, letting one tenant's agent read another tenant's session memory.
Trend Micro found 14 npm packages hiding a Linux backdoor that connects to RedC2 4.0, a commercial C2 kit whose 'Red Agent' turns plain-English commands into post-exploitation actions.
A researcher found a path traversal flaw in the boot process of Apple's Private Cloud Compute, letting them redirect AI inference telemetry to a server they controlled. Apple fixed it and paid out its top bounty tier.