Hacking AI customer service agents
Security researcher Inti De Ceukelaire, a founding member of Intigriti, demonstrated at Bug Bounty Village during DEF CON 34 how attackers can abuse AI customer service agents through email spoofing a…
Security researcher Inti De Ceukelaire, a founding member of Intigriti, demonstrated at Bug Bounty Village during DEF CON 34 how attackers can abuse AI customer service agents through email spoofing a…
Nearly 1 in 10 publicly accessible LiteLLM instances accept a default master key or require no authentication, exposing cloud AI infrastructure to root-level remote code execution and IAM theft, accor…
Sentry's AI security research team, led by Armend Gashi and Redon Gashi, presented at DEF CON 34 a new tool called infreerence that demonstrates how adversaries exploit exposed self-hosted inference s…
Security researchers Ayoub and Inti De Ceukelaire demonstrated at DEF CON 34 that AI customer service agents can be manipulated to bypass multi-factor authentication, leak one-time passwords, and take…
Intigriti was named the new provider for Adobe's Bug Bounty Program effective September 1, 2026, with Intigriti Founder and CEO Stijn Jans calling it "the start of a long and rewarding partnership." T…
Tenet Security researchers demonstrated at DEF CON 34 a new attack called 'Ghostjacking' that tricks AI coding agents into proposing DNS changes by planting malicious instructions in error logs, achie…
Cloudflare introduced beta-stage MCP detection in its Cloudflare One platform on August 14, 2026, using a Gateway selector (experimental.is_mcp == true) to identify and block Shadow MCP traffic at the…
At DEF CON 34, Tenet Security demonstrated Ghostjacking, an indirect prompt injection attack that succeeds 90% of the time against Claude Code under Cloudflare's default recommended configuration, all…
PortSwigger researcher James Kettle unveiled the HTTP Terminator, an autonomous AI system that invented novel HTTP desync attack techniques and compromised banks, security solutions, and government in…
Security firm Tenet presented research at DEF CON 34 showing that a new attack called GhostJacking exploits AI agents by hiding malicious instructions in data they analyze, such as firewall logs, allo…
Researchers at Varonis demonstrated a one-click prompt injection attack against Atlassian's Rovo AI assistant at DEF CON 34, exploiting the rovoChatPrompt parameter to leak sensitive data across conne…
Cyera disclosed 10 memory-safety vulnerabilities in llama.cpp, the inference engine embedded in many local AI tools, after presenting the research at DEF CON 34. VulnCheck assigned 10 CVEs, and Cyera …
VicOne Inc. released the free VicOne Radeis Extension for NVIDIA Isaac Sim, enabling developers to test cyberattack scenarios on robot models in simulation, based on research from DEF CON 34. The exte…
At DEF CON 34, Varonis researchers demonstrated a one-click prompt injection attack, dubbed RovoBlast, against Atlassian's enterprise AI assistant Rovo, which could expose sensitive data across connec…
A single click on a crafted link could have let attackers hijack Atlassian's Rovo AI assistant and steal sensitive enterprise data across Jira, Confluence, SharePoint, and more, according to Varonis T…