AI Worming through Word
A new prompt injection variant turns Microsoft Word documents into self-replicating AI worms via Copilot.
A new prompt injection variant turns Microsoft Word documents into self-replicating AI worms via Copilot.
Explains why AI agents with shell access and credentials must be secured using zero-trust architecture, treating them as privileged insiders.
A daily curated reading list covering AI tools, developer burnout, security, and tech trends for IT professionals.
A fireside chat with Anthropic's Claude Code team discussing coding agents, tool design, and their internal development practices.
Unicode tag characters can hide instructions in AI agent skill files, demonstrated by hijacking Gemini CLI to execute hidden commands.
A security researcher tricks Claude's web_fetch tool into leaking user data via a honeypot attack, bypassing Anthropic's protections.
Explores the concept of a 'vulnpocalypse' where new tech like AI finds massive vulnerabilities, arguing systemic fixes beat patching one-by-one.
Overview of the OWASP Top 10 security risks for agentic AI applications, including attack vectors and mitigations.
Guide to scanning AI skill repositories for security risks using NVIDIA SkillSpector integrated with GitHub Actions CI/CD.
Analysis of Microsoft's AI Prompt Defense Stack, including Prompt Shields, Spotlighting, and Defender for Cloud, to protect against prompt injection attacks.
Hackers exploited Meta's AI support bot to take over high-profile Instagram accounts by simply asking it to change linked emails.
Hackers exploited Meta's AI chatbot to hijack high-profile Instagram accounts by simply asking it to change account recovery details.
Analysis of UK government guidance on AI, open code, and vulnerability risk in the public sector, emphasizing remediation over code visibility.
A software developer reflects on balancing writing a book on effective writing for developers with AI-assisted bug bounty hunting.
Explores whether prompt injection in AI systems is an unsolvable structural problem or just an unfixed vulnerability.
Analysis of Anthropic Mythos's impact on cybersecurity, debunking hype and examining real LLM capabilities in vulnerability detection.
Explains why running AI locally on your own hardware is the best way to maintain HIPAA compliance, avoiding costly and restrictive cloud options.
Anthropic researcher uses Claude Code to discover multiple Linux kernel vulnerabilities, including one hidden for 23 years.
Report on a prompt injection attack in Snowflake's Cortex AI agent that allowed malware execution, now fixed.
Report on a prompt injection attack that allowed Snowflake's Cortex AI agent to escape its sandbox and execute malware.