CrowdStrike has shared five new ways to inject prompts, showing the rising danger to AI agents as more organizations use autonomous AI systems. Early risks were mainly about simple chatbot misuse. Now, AI agents can look at websites, access internal data, and carry out commands. This has greatly increased the areas …
Read More »Thousands of MCP Servers Exposed to File Access and Injection Attacks
Thousands of Model Context Protocol (MCP) servers have serious security flaws like file access issues, command injection, server-side request forgery (SSRF), and SQL injection. This raises big worries about the safety of AI supply chain security. A big study of 9,695 MCP servers from well-known sites like GitHub, Glama, Lobehub, …
Read More »An AI performed a cyber attack without any human help for the first time
Security experts found what they think is the first time an AI carried out a cyber attack all by itself. The complete automated campaign used an AI to carry out a ransomware attack. Victims have to pay money to get their data back. A team from the cloud security company …
Read More »Alibaba Reportedly Bans Claude Code for Suspected AI Tool Backdoor
Alibaba is said to be getting ready to ban the use of Anthropic’s Claude Code in its own systems starting July 10. This choice follows claims that the AI coding helper has a hidden detection method that acts like a backdoor. The news, first reported by the Chinese financial outlet …
Read More »India asks WhatsApp not to roll out ‘username’ feature over fraud concerns
The Indian government issued a notice WhatsApp planned to roll out its new ‘username’ feature. They are worried about fake accounts and fraud. The company must discuss the issue before moving forward. This week, WhatsApp said it will let users pick a username and hide their phone numbers when they …
Read More »Asian Two AI startups launch Mythos-like Model
Two Asian AI companies have released new models this week that compete with Anthropic’s recently limited Mythos and Fable models, as a U.S. export ban on those technologies reaches its third week. These actions show an increasing effort in the region to cover gaps left by U.S. export ban. New …
Read More »OpenAI unveils its first custom chip, Named Jalapeño
On Wednesday, OpenAI introduced its first special AI chip. This is aimed at growing from just consumer products to being involved in AI infrastructure. The chip, called Jalapeño, was made with Broadcom to handle the computing for ChatGPT and Codex efficiently. OpenAI says it’s also built for future AI projects. …
Read More »Anthropic’s Mythos reportedly broke NSA classified systems in hours
The recent finding shows how powerful Mythos is: the AI can access the US government’s secret networks in just a few hours. The Mythos model created by Anthropic was able to breach “almost all” of the US National Security Agency’s classified systems in a matter of hours rather than weeks, …
Read More »CyberSentinel AI features 33 security tools like Nmap, SQLMap, and ZAP, utilizing Claude and GPT
A new open-source cybersecurity tool named CyberSentinel AI v3.0 has come out. It is an important step in self-operated security tools. It combines 33 tools for testing and understanding threats with an AI system that works with Claude, GPT-4o, and OpenRouter, and it can work offline using Ollama. CyberSentinel AI …
Read More »FortiBleed: 70,000 Fortinet Firewalls Compromised Globally
A vast cyber spying operation called “FortiBleed” has quietly compromised more than 73,932 different Fortinet firewall URLs in 194 countries. Originally discovered by security researcher Volodymyr “Bob” Diachenko, with more study from Hudson Rock and cyber expert Kevin Beaumont, this dataset shows a huge, automated scheme. Bad actors managed to …
Read More »
InfoSecBulletin Cybersecurity for mankind