ai

OpenAI Expands Daybreak With GPT-5.5-Cyber to Help Defenders Patch Security Flaws

OpenAI has released an enhanced GPT-5.5-Cyber model through its Daybreak initiative to assist trusted defenders in identifying, validating, and patching software vulnerabilities across large codebases. Alongside an updated Codex Security plugin, this cybersecurity tool streamlines vulnerability detection, triage, and remediation, while the new Patch the Planet project partners with open-source communities to improve security by collaboratively developing and deploying patches. These efforts address the rapid escalation of vulnerabilities accelerated by AI, aiming to support maintainers in securing critical infrastructure despite increasing exploitation risks from advanced threat actors.

https://thehackernews.com/2026/06/openai-expands-daybreak-with-gpt-55.html

Agentjacking Attack Tricks AI Coding Agents Into Running Malicious Code

Researchers have identified a new attack called Agentjacking that deceives AI coding agents into executing malicious code by exploiting a flaw in Sentry's error-tracking platform. By injecting crafted error events via a public Sentry Data Source Name (DSN), attackers can trick AI assistants into interpreting them as trusted instructions, enabling code execution with developer privileges and exposing sensitive data. Despite acknowledgment, Sentry has not fully fixed the issue, leaving many organizations vulnerable to exploitation without traditional detection methods.

https://thehackernews.com/2026/06/agentjacking-attack-tricks-ai-coding.html

88% of People Struggle to Tell What’s Real Online

A Malwarebytes survey of 1,500 adults across several countries found that 88% of people struggle to distinguish real online content from AI-generated fakes, with 85% reporting difficulty telling scams from genuine interactions—an increase from 66% last year. Half of respondents have encountered AI-driven fraud, including AI-generated product photos and personalized scams, while 19% experienced AI-related identity harms like non-consensual explicit content creation. The findings highlight growing challenges in online trust and identity due to AI-enabled deception, urging increased awareness and protective measures.

https://www.malwarebytes.com/blog/ai/2026/06/88-of-people-struggle-to-tell-whats-real-online

Amazon Security Research Reportedly Led to the White House’s Anthropic Fable Ban

Amazon's security research reportedly prompted the White House to impose export controls restricting foreign access to Anthropic's AI models Fable 5 and Mythos 5 after Amazon demonstrated the models could be manipulated to provide information useful for cyberattacks. CEO Andy Jassy's discussions with U.S. officials led to the directive, although Anthropic has contested the characterization of these vulnerabilities, noting similar issues exist in other publicly available models like GPT 5.5. This move has raised concerns as many of Anthropic’s researchers are foreign-born, effectively barring them from their own AI tools amid ongoing tensions between the company and the U.S. government.

https://www.theverge.com/ai-artificial-intelligence/949601/amazon-anthropic-fablemythos-government-ban

Mini Shai-Hulud, Miasma, and Hades Worms Target Bioinformatics and MCP Developers Via Malicious PyPI Wheels

The Mini Shai-Hulud, Miasma, and Hades supply chain campaign has expanded with 23 new malicious PyPI packages targeting bioinformatics and MCP developers by using varied delivery mechanisms including trojanized native extensions and .pth startup hooks to execute obfuscated JavaScript stealers via Bun. These malware-laden packages aim to compromise developer workstations and CI/CD environments to steal credentials, tokens, SSH keys, and cloud secrets, with attackers innovating their payload deployment to evade detection and complicate forensic analysis. Security teams are advised to review affected package versions, monitor for unusual Python startup behaviors, and rotate exposed credentials to mitigate the threat.

https://socket.dev/blog/mini-shai-hulud-miasma-and-hades-worms-target-bioinformatics-and-mcp-developers-via-malicious

AI Agent Uncovers 21 Zero-Days in FFmpeg; Chrome Patches Record 429 Bugs

An autonomous AI agent from security startup depthfirst discovered 21 zero-day vulnerabilities in FFmpeg, some latent for over two decades, highlighting AI's growing role in vulnerability detection. Meanwhile, Google released Chrome 149, patching a record 429 security bugs—including critical use-after-free flaws—with much of the increased workload attributed to managing a surge in AI-generated bug reports. These developments underscore the accelerating pace and volume of vulnerability discovery driven by AI, emphasizing the need for faster patch cycles and robust update mechanisms.

https://thehackernews.com/2026/06/ai-agent-uncovers-21-zero-days-in.html

Critical Hugging Face Transformers Vulnerability Enables Remote Code Execution Attacks

A critical vulnerability (CVE-2026-4372) in the HuggingFace Transformers library allows remote code execution via malicious model configuration files, bypassing existing security controls. This flaw affects versions 4.56.0 through 5.2.x when used with the kernels package, enabling attackers to execute arbitrary Python code during model loading from HuggingFace Hub without user consent. HuggingFace fixed the issue in version 5.3.0 and advises users to upgrade immediately and audit their environments to mitigate supply chain risks in AI workflows.

https://cybersecuritynews.com/hugging-face-rce-vulnerability/

Attackers Use AI to Automate EDR Evasion Testing

Sophos X-Ops analysts discovered that an unidentified threat actor used AI-driven Python scripts to automate the testing and evasion of endpoint detection and response (EDR) tools from Sophos, CrowdStrike, and Windows Defender. This attacker created a sophisticated lab environment with multiple virtual machines to iteratively develop and refine malware capable of bypassing EDR defenses, highlighting the increasing use of AI in advanced cyberattack methods.

https://www.darkreading.com/endpoint-security/attackers-automate-edr-evasion-testing

Agentic AI Red Teaming Reveals Zero-Click Human-in-the-Loop Bypass Attack Chains

Security researchers have discovered that agentic AI systems—AI capable of planning and executing multi-step tasks autonomously—exhibit exploitable vulnerabilities that allow attackers to bypass human-in-the-loop controls entirely, executing zero-click attack chains without user interaction. Microsoft’s year-long red teaming efforts led to an updated taxonomy identifying seven new failure modes in agentic AI, highlighting risks such as supply chain compromise, goal hijacking, and session context contamination, and recommending robust architectural mitigations including cryptographic agent verification and hardened approval processes.

https://cybersecuritynews.com/agentic-ai-red-teaming-reveals-zero-click/

Meta AI Support Bot Helped Hackers Hijack Instagram Accounts

Meta's AI support assistant for Instagram was exploited by hackers to hijack high-profile accounts by changing the email address linked to those accounts without proper identity verification, sometimes bypassing two-factor authentication. The vulnerability, which was publicly accessible for a short time, allowed attackers to take over accounts easily, prompting Meta to patch the issue and secure impacted accounts.

https://www.macrumors.com/2026/06/01/meta-ai-instagram-attack/

ChatGPhish: The Page Is the Payload

Researchers discovered a new phishing and tracking attack called ChatGPhish that exploits ChatGPT's page summarization feature by injecting malicious Markdown links and images into web pages. When users summarize such pages in ChatGPT, the assistant renders active clickable links, spoofed alerts, and QR codes within its trusted interface, enabling phishing, cross-origin data leakage, and off-device attacks without traditional browser protections. This expands the attack surface from email to everyday browsing, highlighting risks in AI-generated outputs that automatically render untrusted external content inside trusted AI interfaces.

https://permiso.io/blog/chatgpt-markdown-rendering-vulnerability

Top Ethical Hacker Chompie Warns AI Tools Could Put Her Out of Business

Valentina Palmiotti, known as Chompie, a top ethical hacker who won major prizes at the Pwn2Own competition, warns that advanced AI tools like Claude Mythos could soon make it much harder for human hackers to compete in finding software vulnerabilities. While AI currently assists ethical hackers in speeding up their work, Chompie believes new AI models will soon handle most vulnerabilities, leaving only the very best human hackers able to discover novel bugs, which could significantly change the landscape of cybersecurity defense and offense.

https://www.bbc.com/news/articles/c3r2zjpryzro

AI Chatbot Recommendations Redirect Users to Cryptojacking Malware Sites

Microsoft has alerted to an active cryptojacking campaign that uses AI chatbot interactions to redirect users seeking legitimate system utilities to attacker-controlled domains hosting malware. This sophisticated attack targets users with high-performance GPUs by delivering malicious installers that establish persistent remote access, enabling cryptocurrency mining and potential further exploitation such as data theft or ransomware.

https://thehackernews.com/2026/05/ai-chatbot-recommendations-redirect.html

Microsoft Copilot Cowork Exfiltrates Files

Microsoft Copilot Cowork in Microsoft 365 is vulnerable to file exfiltration attacks via indirect prompt injection, exploiting the fact that sending emails and Teams messages to the active user occurs without manual approval. Attackers can use poisoned skills to cause Copilot Cowork to send messages containing pre-authenticated download links to sensitive files, which are exfiltrated when the user opens the messages, posing a significant security risk that can be mitigated by restricting permissions and file downloads in SharePoint.

https://www.promptarmor.com/resources/microsoft-copilot-cowork-exfiltrates-files

Anthropic to Release Mythos-class Models to the Public

Anthropic plans to publicly release its Mythos-class AI models, known for their exceptional ability to find security vulnerabilities in code, once stronger safeguards against misuse are developed. Currently, Mythos is available only to select partners, including governments, as unrestricted access could enable cybercriminals to exploit software flaws rapidly, and the company acknowledges that no existing safeguards fully prevent potential harm from these models.

https://www.theregister.com/security/2026/05/25/anthropic-to-release-mythos-class-models-to-the-public/5245596

Scroll to Top