$ tail -f ./news/ai-security

AI Security News Feed

34 latest AI Sec News · built Apr 27, 2026
Incident // 2026-03-26

LiteLLM TeamPCP Supply Chain Attack: Malicious PyPI Packages

The article discusses a supply chain attack involving malicious packages on PyPI that target the LiteLLM project. This incident highlights the ongoing risks associated with software supply chains and the importance of securing dependencies in AI/ML development.

Wiz Blog open_link()
Threat Actor // 2026-03-24

Deepfakes and Cybersecurity: The Next Frontier in AI-Driven Threats

The article discusses the rise of AI-generated deepfakes as tools for cybercriminals, focusing on their usage in sophisticated social engineering attacks. It highlights the significant implications for cybersecurity as these tactics become more prevalent.

lynxtechnologypartners.com open_link()
Vulnerability // 2026-03-22

Three High-Risk AI Vulnerabilities Discovered in Claude.ai

The article discusses three significant vulnerabilities found in Claude.ai that could allow attackers to exfiltrate sensitive information without user awareness. This highlights the critical need for enhanced security measures in AI applications to protect user data.

TechRadar open_link()
Research // 2026-03-22

Beyond Jailbreaks: Why Agentic AI Needs Contextual Red Teaming

The article discusses the importance of contextual red teaming in evaluating the security of agentic AI systems. It highlights how traditional security measures may fall short in addressing the unique challenges posed by AI, emphasizing the need for tailored approaches to ensure robust security.

Palo Alto Networks Blog open_link()
Research // 2026-03-22

From Spark to Fire: Modeling and Mitigating Error Cascades in LLM-Based Multi-Agent Collaboration

This article discusses the potential for error cascades in multi-agent systems utilizing large language models (LLMs) and proposes methods for mitigation. Understanding these error dynamics is crucial for enhancing the reliability and security of AI systems in collaborative environments.

arXiv open_link()
Vulnerability // 2026-03-22

GitHub Actions Shell Injection via Unsanitized Issue Metadata in Workflow Templates

This article discusses a vulnerability in GitHub Actions that allows shell injection through unsanitized issue metadata in workflow templates. The findings highlight the importance of input validation in CI/CD pipelines to prevent potential exploitation by threat actors.

Sebastion open_link()
Vulnerability // 2026-03-21

Critical Langflow Flaw CVE-2026-33017 Triggers Attacks within 20 Hours of Disclosure

A critical vulnerability in Langflow, identified as CVE-2026-33017, has been disclosed and is reportedly being exploited within hours of its announcement. This incident highlights the urgent need for timely patching and awareness in the AI/ML security landscape.

The Hacker News open_link()
Vulnerability // 2026-03-21

Three high-risk AI vulnerabilities discovered in Claude.ai - end-to-end attack chain exfiltrates sensitive info without user knowing

Researchers have identified three critical vulnerabilities in Claude.ai that could facilitate an end-to-end attack chain. These vulnerabilities allow sensitive information to be exfiltrated without the user's awareness, posing serious privacy and security risks.

techradar.com open_link()
Tool // 2026-03-21

How Ceros Gives Security Teams Visibility and Control in Claude Code

The article discusses how Ceros enhances security teams' capabilities by providing visibility and control over Claude code. This is particularly relevant as organizations increasingly rely on AI systems, necessitating robust security measures to protect against potential vulnerabilities.

The Hacker News open_link()
Policy // 2026-03-19

NIST Trustworthy and Responsible AI

NIST has published guidelines focused on building trustworthy and responsible AI systems. This document outlines best practices and standards essential for ethical AI development.

nvlpubs.nist.gov open_link()
Threat Actor // 2026-03-19

ThreatsDay Bulletin: FortiGate RaaS, Citrix Exploits, MCP Abuse, LiveChat Phish & More

The article discusses various security threats including ransomware-as-a-service targeting FortiGate devices and exploits affecting Citrix products. It highlights the importance of staying informed about these vulnerabilities and the evolving tactics used by threat actors in the cybersecurity landscape.

The Hacker News open_link()
Research // 2026-03-19

Protecting Context and Prompts: Deterministic Security for Non-Deterministic AI

This paper discusses the challenges of ensuring deterministic security in non-deterministic AI systems. It explores novel methods to protect context and prompts that are critical to the AI’s performance.

arxiv.org open_link()