Tag: LLM
-
Six Flowise Vulnerabilities Enable Remote Code Execution on AI Workflow Servers
Six newly disclosed vulnerabilities in Flowise, a popular open”‘source platform for building AI agents and LLM workflows, allow unauthenticated and low”‘privileged attackers to achieve remote code execution (RCE) on self”‘hosted and cloud AI workflow servers running vulnerable versions. These flaws collectively expose organizations to full server compromise, data exfiltration, and AI pipeline manipulation if instances…
-
AI Agent Guardrails: How to Set Boundaries Before You Give an LLM Access to Your Systems
AI agents are crossing a line that traditional chatbots never crossed. A chatbot produces text. An AI agent can retrieve customer records, query financial data,…Read More First seen on securityboulevard.com Jump to article: https://securityboulevard.com/2026/08/ai-agent-guardrails-how-to-set-boundaries-before-you-give-an-llm-access-to-your-systems/
-
Chinese hacker used DeepSeek to launch autonomous cyberattacks on vulnerable servers
A Chinese threat actor operating under the aliases >>knaithe<>KnYuan<< used multiple LLMs to automate cyberattacks against internet-facing systems … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/03/deepseek-ai-autonomous-cyberattacks-hermes-agent/
-
30 days with Claude Mythos Preview: How Tenable adapted our security program, and why yours is next
Tags: ai, api, attack, business, control, cybersecurity, data, data-breach, endpoint, exploit, flaw, injection, LLM, remote-code-execution, risk, service, threat, tool, update, vulnerabilityTenable spent 30 days running frontier AI models against our own code. It didn’t just find bugs, it proved they’re real, with reproducible exploits. That fundamentally changes code security from ranking potential code defects to a much higher signal focused on the findings that matter. Read on to learn how it reshaped our security team’s…
-
Klassische Firewalls sind blind für Angriffe in natürlicher Sprache – Warum LLM-Guards allein die KI-Sicherheit nicht retten
First seen on security-insider.de Jump to article: www.security-insider.de/llm-guards-ki-sicherheit-a-2fbccecb3c2d06bb933157bbaadd9970/
-
What an LLM Can Find: A Practical, Cheap Path to Code-level Threat Discovery
An AI-assisted audit found 29 flaws in GlobaLeaks, showing LLMs make large-scale code reviews faster, cheaper, and accessible. GlobaLeaks, a mature whistleblowing platform that had already undergone six independent professional audits over the past thirteen years, was subjected to an LLM-assisted security review that cost roughly USD 3,140 in API calls. The review identified 29…
-
(g+) Agentgateway: Ein Kontrollpunkt für LLMs, Tools und KI-Agenten
Je mehr Werkzeuge KI-Agenten nutzen, desto schwieriger wird es nachzuvollziehen, wer worauf zugreift. Agentgateway soll genau dieses Problem lösen. First seen on golem.de Jump to article: www.golem.de/news/agentgateway-ein-kontrollpunkt-fuer-llms-tools-und-ki-agenten-2607-211089.html
-
Google says it fixed more Chrome bugs in June than over the past two years, thanks to AI
As experts have warned for the last two years, some companies, like Microsoft and now Google, are finding and patching an exponential number of bugs in their products, thanks to the use of LLMs and AI tools. First seen on techcrunch.com Jump to article: techcrunch.com/2026/07/30/google-says-it-fixed-more-chrome-bugs-in-june-than-over-the-past-two-years-thanks-to-ai/
-
Stronger AI Safety Requires Peeking Inside the ‘Black Box’
Researchers propose focusing on identification of certain cognitive elements in LLMs that indicate when AI systems may take an unwanted action. First seen on darkreading.com Jump to article: www.darkreading.com/cybersecurity-analytics/stronger-ai-safety-requires-peeking-inside-black-box
-
Using LLMs to Find & Prioritize Vulnerabilities Is No Easy Task
The latest large language models have high false-positive rates and fail to take into account the context of scans, leading to more work for AppSec professionals. First seen on darkreading.com Jump to article: www.darkreading.com/application-security/finding-and-prioritizing-vulnerabilities-no-easy-task
-
Using LLMs to Find & Prioritize Vulnerabilities Is No Easy Task
The latest large language models have high false-positive rates and fail to take into account the context of scans, leading to more work for AppSec professionals. First seen on darkreading.com Jump to article: www.darkreading.com/application-security/finding-and-prioritizing-vulnerabilities-no-easy-task
-
Die neue Risiken durch agentische KI im Fokus – Warum LLM-Observability zum Sicherheitsfaktor für KI-Systeme wird
First seen on security-insider.de Jump to article: www.security-insider.de/warum-llm-observability-zum-sicherheitsfaktor-fuer-ki-systeme-wird-a-bd9def5d1852e535db0558409c91e25f/
-
When AI Attacks: OpenAI Models Autonomously Hack Hugging Face
Advanced LLMs escaped their sandboxes while attempting to achieve a non-malicious benchmark test objective. First seen on darkreading.com Jump to article: www.darkreading.com/cyber-risk/openai-models-autonomously-hack-hugging-face
-
OpenAI says model test was behind Hugging Face hack
At the time, Hugging Face said it wasn’t clear which LLM was used in the attack. OpenAI confirmed it was one of their models being tested for “maximal” cyber capabilities. First seen on cyberscoop.com Jump to article: cyberscoop.com/openai-chatgpt-hugging-face-cyberattack-data-poisoning/
-
Using LLMs to Find and Prioritize Vulnerabilities Is No Easy Task
The latest large language models have high false-positive rates and fail to take into account the context of scans, leading to more work for AppSec professionals. First seen on darkreading.com Jump to article: www.darkreading.com/application-security/finding-and-prioritizing-vulnerabilities-no-easy-task
-
Remediating Vulnerabilities With LLMs: Inside Ivanti’s Automation Push
Ivanti CSO Daniel Spicer says frontier models have shown surprising effectiveness in early stages; but cost and human-in-the-loop viability remain open questions. First seen on darkreading.com Jump to article: www.darkreading.com/cybersecurity-operations/remediating-vulnerabilities-llms-ivanti-automation
-
F5 CEO On Massive AI Security Opportunity: LLMs Are ‘A Vulnerable Technology Today’
F5 is doubling down on enabling solution and service providers to capitalize on surging AI adoption through the recent launch of its unified platform for discovering, testing and securing AI models, according to F5 CEO François Locoh-Donou. First seen on crn.com Jump to article: www.crn.com/news/security/2026/f5-ceo-on-massive-ai-security-opportunity-llms-are-a-vulnerable-technology-today
-
PENTDEM AI Pentesting Daemon Uses 34 Security Tools to Automate WAF Bypass and Attack Chains
Tags: ai, attack, bug-bounty, cyber, firewall, LLM, open-source, penetration-testing, tool, vulnerability, wafPENTDEM is an open-source autonomous AI pentesting daemon that integrates 34 security tools with LLM-directed analysis to automate various tasks, including reconnaissance, vulnerability discovery, evidence validation, Web Application Firewall (WAF) fingerprinting, and multi-stage attack-path modeling. This Python-based project is designed for authorized security testing and bug-bounty workflows, offering both an autonomous agent mode and a…
-
Linux Creator Linus Torvalds Rejects Anti-AI Push and Defends LLM Tools
Linux creator and top-level kernel maintainer Linus Torvalds has made it clear that the Linux kernel project will not adopt an anti-AI stance. He believes that large language models and related tools should be assessed based on their technical value rather than dismissed outright. His comments were part of a discussion on the Linux Media…
-
1M+ Emails Use Hidden Text to Dupe AI Security Filters
Artificial intelligence and LLMs can be surprisingly ineffective against text salting, allowing phishing emails to slide right into your inbox. First seen on darkreading.com Jump to article: www.darkreading.com/threat-intelligence/1m-emails-hidden-text-dupe-ai-security-filters
-
Single Prompt Enables ChatGPT to Execute Full Cyber-Attack Chain, Researchers Claim
Cybersecurity researchers tested Open AI GPT 5.5’s offensive cyber capabilities and the results showed how effective a frontier LLM can be for hackers First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/chatgpt55-to-execute-full/
-
TuxBot v3: The IoT Botnet Built With AI Bugs, Disclaimers and All
TuxBot v3, an AI-built IoT botnet for 17 architectures, shipped with LLM bugs and safety disclaimers the developer never removed. Palo Alto Networks’ Unit 42 identified a previously undocumented modular IoT botnet framework called TuxBot v3 Evolution, and it comes with an unusual detail: the developer used a large language model to write significant portions…
-
ThreatLocker CEO: ‘Fighting AI With AI’ Is Not A Winning Security Strategy
The idea of ‘fighting AI with AI’ is fundamentally the wrong approach for protecting against intensifying LLM-powered attacks, ThreatLocker CEO Danny Jenkins says in the inaugural episode of CRN’s new Security or Else! video series. First seen on crn.com Jump to article: www.crn.com/news/security/2026/threatlocker-ceo-fighting-ai-with-ai-is-not-a-winning-security-strategy
-
Attackers Combine MCP Recon With Cloud Metadata SSRF to Steal Service Account Tokens
Internet-wide reconnaissance is expanding beyond conventional application targets to include Model Context Protocol (MCP) services, AI assistant configuration files, and locally exposed LLM endpoints. A 14-day review of Apache and ModSecurity logs from a small, low-traffic shared host found roughly 200 requests tied to AI-agent reconnaissance, alongside routine WordPress, .env, Git, and Spring Boot Actuator…
-
New Relic startet kostenloses Observability-Programm für Startups bis Series A
Da Startups zunehmend auf LLMs, Agenten und KI-generierten Code setzen, liefern sie neue Funktionen und Änderungen oft in rasantem Tempo über ihren gesamten Tech-Stack hinweg aus. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/new-relic-startet-kostenloses-observability-programm-fuer-startups-bis-series-a/a45727/
-
Hackers can use 9 of the most popular AI tools to assemble massive botnets
“HalluSquatting” weaponizes LLMs’ inability to say “I don’t know.” First seen on arstechnica.com Jump to article: arstechnica.com/security/2026/07/hackers-can-use-9-of-the-most-popular-ai-tools-to-assemble-massive-botnets/
-
JadePuffer: The First Complete LLM-Driven Ransomware Attack
An agentic threat actor successfully exploited a Langflow flaw to steal data from a production database server and encrypt other systems. First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/jadepuffer-first-complete-llm-driven-ransomware-attack
-
SSH Attackers Use Single Exec Commands to Bypass Interactive Honeypot Analysis
SSH attackers are increasingly abusing single non-interactive exec commands over SSH to bypass traditional honeypot analysis, effectively turning post-authentication activity into short, automated probes rather than interactive shell sessions that deception systems were designed to study. Recent measurements on eleven LLM-backed SSH honeypots show that 99.23% of authenticated sessions consist of a single non-interactive exec…
-
Chinese LLMs Broaden the Gap Between Attackers & Defenders
Two new models from Chinese firms compete with top US mainstream and frontier models. Should cyber-defenders be worried? First seen on darkreading.com Jump to article: www.darkreading.com/cyber-risk/chinese-llms-broaden-gap-between-attackers-and-defenders
-
Sysdig Details JADEPUFFER, the First Documented Agentic Ransomware Operation
A new Sysdig report traces how an LLM agent abused a Langflow flaw, stole credentials, reached production MySQL, and destroyed Nacos config data in minutes flat. First seen on hackread.com Jump to article: hackread.com/sysdig-jadepuffer-first-agentic-ransomware-operation/

