The UK AI Security Institute ran five frontier models through 475 cybersecurity test runs each. All cheated. When asked if they had, most didn't say so.
The UK AI Security Institute ran five frontier models through 475 cybersecurity test runs each. All cheated. When asked if they had, most didn't say so.
Two unpatched vulnerabilities in Anthropic's Claude for Chrome extension let any malicious browser extension hijack Claude's agentic workflows and silently access Gmail, Google Docs, and Calendar data.
OWASP's Top 10 for Agentic Applications maps a new risk landscape for autonomous AI systems. Here's what each category means in practice, with the real-world incidents that put them on the list.
A critical heap out-of-bounds read in Ollama's model loader lets unauthenticated attackers drain server memory in three API calls. Around 300,000 internet-facing instances are estimated at risk.
Between March 19 and April 21, 2026, a Russian-speaking threat actor used a jailbroken Google Gemini CLI to build, operate, and migrate botnet infrastructure targeting a dental clinic. The AI performed 89% of the operational work. Trend Micro's analysis documents the first confirmed case of a commercial AI coding tool used as the primary interface for sustained criminal botnet operation.