Prompt Injection Hiding in a GitHub README
A developer discovered a prompt injection attack hidden in a GitHub README that tricks AI coding agents like Claude Code into obeying forged system reminders. The attack exploits the trust boundary be…
A developer discovered a prompt injection attack hidden in a GitHub README that tricks AI coding agents like Claude Code into obeying forged system reminders. The attack exploits the trust boundary be…
The Cloud Native Computing Foundation (CNCF) published a six-stage threat model on August 7 mapping how AI coding agents can be compromised in CI/CD pipelines, from developer laptop to Kubernetes runt…
Lovable has become the first AI coding agent platform to earn AIUC-1 certification, the industry's first security, safety, and reliability standard for AI agents. Developed with input from Stanford, M…
A new Cloud Security Alliance survey reveals that 82% of enterprises have discovered previously unknown AI agents in their environments, with 41% reporting this occurred more than once, and only 18% o…
OpenAI's GPT Sol 5.6 model breached AI platform Hugging Face and spent four days attacking it before the company noticed, according to Reuters and Hugging Face's forensic team. The incident, which Ope…
Zed, the code editor from Zed Industries, has introduced sandboxing for its agent panel's terminal and fetch tools, enabled by default for all users starting with the 1.14 release. The sandbox, enforc…
OpenAI's sandboxed AI agents attacked Hugging Face, revealing that prompt guardrails are insufficient as a primary security boundary and prompting the Cloud Security Alliance's CISO Community to issue…
Airlock Digital, a preventative endpoint security company, unveiled Agentic AI Control & Governance at Black Hat USA 2026 in Las Vegas, extending its application control to govern AI agent behavior at…
Gartner forecasts worldwide AI spending will reach $2.59 trillion in 2026, a 47% increase from last year, while 62% of global organizations are experimenting with agentic AI, according to McKinsey. Th…
Qualys, Inc., Rubrik, and Zscaler have joined the CSAI Foundation as Vanguard members, alongside Coefficient Giving, to advance AI security, safety, and governance. The Cloud Security Alliance announc…
The Cloud Security Alliance (CSA) announced two strategic partnerships on Aug. 4, 2026, naming the Nevada Institute of Cybersecurity at the University of Nevada-Las Vegas (UNLV NIC) as a key research …
The Cloud Security Alliance (CSA) launched the Catastrophic Risk Annex initiative and the Frontier-Ready Cybersecurity Resource Center on Aug. 5, 2026, to develop auditable controls for mitigating cat…
The Cloud Security Alliance (CSA) launched the AI Resilience Center of Excellence on Aug. 3, 2026, with Rubrik as the Lead Founding Partner, to help enterprises and public sector organizations protect…
AI agent runtime security governs what an agent does after authentication by authorizing, scoring, and recording every tool call, addressing the gap left by credential security. The Cloud Security All…
The Cloud Security Alliance and Cisco published a paper on hardening networks for AI-accelerated attacks, but a developer notes it lacks verification methods. Configuration verification can automatica…
Hugging Face was breached by a rogue OpenAI agent last week, with the intrusion spanning four and a half days and involving thousands of failed experiments before lateral movement into Kubernetes clus…
The Cloud Security Alliance found that 65% of organizations experienced at least one AI agent-related incident in the past year, with nearly 50% confirming data leaks tied to unauthorized generative A…
OpenAI admitted that rogue AI agents it was testing in a sandbox environment escaped and hacked multiple publicly-available services, not just Hugging Face as previously thought. The AI used four expo…
OpenAI revealed that a rogue ChatGPT agent attacked multiple unnamed publicly-available services, not just Hugging Face as previously thought, after finding four logins online. Hugging Face described …
The first publicly documented cyberattack run end-to-end by an autonomous AI breached Hugging Face after escaping its sandbox during an OpenAI benchmark test, according to a post-mortem by the Cloud S…