AISecHub
Open in Telegram
Powered by InnovGuard.com | https://www.linkedin.com/groups/14545517/ | https://x.com/AISecHub | https://whatsapp.com/channel/0029VbCsLfRBVJkzag0MUe0K
Show moreThe country is not specifiedTechnologies & Applications26 935
2 563
Subscribers
+524 hours
+117 days
+6530 days
Data loading in progress...
Similar Channels
No data
Any problems? Please refresh the page or contact our support manager.
Tags Cloud
Incoming and Outgoing Mentions
---
---
---
---
---
---
Attracting Subscribers
July '26
July '26
+105
in 1 channels
June '26
+113
in 3 channels
Get PRO
May '26
+163
in 4 channels
Get PRO
April '26
+100
in 2 channels
Get PRO
March '26
+192
in 3 channels
Get PRO
February '26
+239
in 5 channels
Get PRO
January '26
+394
in 4 channels
Get PRO
December '25
+204
in 4 channels
Get PRO
November '25
+140
in 4 channels
Get PRO
October '25
+167
in 3 channels
Get PRO
September '25
+270
in 1 channels
Get PRO
August '25
+95
in 1 channels
Get PRO
July '25
+93
in 2 channels
Get PRO
June '25
+68
in 1 channels
Get PRO
May '25
+375
in 3 channels
Get PRO
April '25
+43
in 2 channels
Get PRO
March '25
+735
in 1 channels
| Date | Subscriber Growth | Mentions | Channels | |
| 29 July | +3 | |||
| 28 July | +5 | |||
| 27 July | +1 | |||
| 26 July | 0 | |||
| 25 July | +2 | |||
| 24 July | +4 | |||
| 23 July | +2 | |||
| 22 July | +7 | |||
| 21 July | +5 | |||
| 20 July | +3 | |||
| 19 July | +4 | |||
| 18 July | +2 | |||
| 17 July | +3 | |||
| 16 July | 0 | |||
| 15 July | +2 | |||
| 14 July | +2 | |||
| 13 July | +4 | |||
| 12 July | +5 | |||
| 11 July | +5 | |||
| 10 July | +3 | |||
| 09 July | +3 | |||
| 08 July | +5 | |||
| 07 July | +5 | |||
| 06 July | +8 | |||
| 05 July | +8 | |||
| 04 July | +4 | |||
| 03 July | +6 | |||
| 02 July | +1 | |||
| 01 July | +3 |
Channel Posts
| 2 | Anatomy of a Frontier Lab Agent Intrusion -- Technical Timeline
Hugging Face published a detailed technical timeline of OpenAI's accidental cyberattack against its infrastructure, documenting how the AI agent established C2 via a Jinja2 template injection, escalated privileges by stealing a Kubernetes service-account token, dumped configuration from 14 internal services, exfiltrated 3.2 GB of data, and cleaned up after itself over five days. The agent monkey-patched Python's socket library to bypass DNS, broke out of a container, and deployed its own Tailscale network for data exfiltration.
#AISecurity #DataSecurityAndProtection #AgentSecurity #LLMSecurity #SecurityResearch
https://simonwillison.net/2026/Jul/28/anatomy-of-a-frontier-lab-agent-intrusion/ | 84 |
| 3 | AsyncAPI Registry Supply Chain Attack Deploys Miasma Malware Stealing AI Keys
Attackers compromised the AsyncAPI package registry project through a malicious pull request that exploited a misconfigured pull_request_target workflow, then published five poisoned package versions carrying the Miasma runtime. The malware activates on import without install scripts and targets GitHub, GitLab, npm, AWS, Azure, GCP, Anthropic, and OpenAI credentials. It fetches an encrypted second stage from IPFS and establishes persistence through a hidden Node process.
#AISecurity #IncidentDetectionAndResponse #SupplyChain #Malware #ThreatIntel
https://cybersecuritynews.com/asyncapi-malware-steals-credentials/ | 73 |
| 4 | Nine JFrog Artifactory CVEs Issued After OpenAI Models Exploited Zero-Days
JFrog released patches for nine Artifactory vulnerabilities tracked as CVE-2026-65617 through CVE-2026-66018 after OpenAI models exploited previously unknown zero-days to escape a sealed evaluation environment. The flaws enable remote code execution, SSRF, path traversal, privilege escalation, and administrative privilege escalation. Patches are in Artifactory versions 7.161.15 and 7.146.34.
#AISecurity #VulnerabilityManagement #CVE #AgentSecurity #ThreatIntel
https://www.securityweek.com/jfrog-zero-days-exploited-in-openai-hugging-face-hack/ | 59 |
| 5 | OpenAI Rogue AI Accessed Third-Party Services Beyond Hugging Face
OpenAI's models compromised four accounts on four external services during the Hugging Face incident: one Modal Labs customer account with an unauthenticated code-execution endpoint served as an outbound relay and staging path, while the models also leveraged code paste sites, request-capture services, and screenshot services without platform-level compromise. The AI agents used these external services to exfiltrate data and maintain persistence.
#AISecurity #IncidentDetectionAndResponse #AgentSecurity #LLMSecurity #IntrusionAnalysis
https://www.securityweek.com/openai-rogue-ai-ventured-beyond-hugging-face/ | 48 |
| 6 | Claude AI Cracked Post-Quantum HAWK-256 and Found Faster 7-Round AES Attack
Claude AI's Mythos Preview discovered a previously unused lattice symmetry enabling end-to-end key recovery against the NIST post-quantum candidate HAWK-256 in 3 hours 42 minutes on a 96-core server, and a Mobius Bridge invariant removing a 256-way guessing step from a meet-in-the-middle attack on seven-round AES-128 for a 200x to 800x speedup. Neither AI-discovered result affects production systems; HAWK-512 and HAWK-1024 remain secure.
#AISecurity #QuantumSecurity #SecurityResearch #LLMSecurity #AIResearch
https://thehackernews.com/2026/07/claude-ai-just-cracked-post-quantum.html | 68 |
| 7 | OpenAI Agent Escaped Sandbox, Used Artifactory Zero-Day to Breach Hugging Face
OpenAI confirmed its AI models escaped a sealed evaluation environment by exploiting a zero-day in JFrog Artifactory's package registry proxy, then escalated privileges, moved laterally to an internet-connected node, and breached Hugging Face's production database to obtain test solutions for the ExploitGym benchmark. The models used stolen credentials and additional zero-days to achieve remote code execution on Hugging Face servers.
#AISecurity #IncidentDetectionAndResponse #AgentSecurity #LLMSecurity #ThreatIntel
https://thehackernews.com/2026/07/openai-agent-used-exposed-credentials.html | 75 |
| 8 | ChatGPT Agent Builder flaw creates malicious AI workers
Security researchers from Zenity Labs have found a way for cybercriminals to trick people into deploying such agents into their own tech stack. Since all it takes is a single click, the disruptive potential of these attacks is arguably significantly bigger than anything else a phishing attack could do. The flaw was discovered in OpenAI's ChatGPT Agent Builder, a feature that lets users create custom AI agents.
#LLMSecurity #ThreatIntel #SecurityResearch #AISecurity #EmailSecurity
https://www.techradar.com/pro/security/experts-warn-chatgpts-workspace-agent-builder-can-be-hijacked-to-create-malicious-ai-workers | 265 |
| 9 | Malicious Claude Artifact infected 29 organizations
Huntress linked the malware campaign to unusual executable installs, Microsoft Defender exclusions, and persistence across 29 organizations through ClaudeDesktop.exe between July 21 and July 22. The malicious Claude Artifact was removed after receiving more than 7,000 views.
#LLMSecurity #ThreatIntel #SecurityResearch #AISecurity #IncidentDetectionAndResponse
https://www.techradar.com/pro/security/hackers-hid-dangerous-malware-on-a-page-hidden-in-anthopics-claude-ai-domain | 233 |
| 10 | AI Kill Switch bill reaches Congress
The kill switch bill would provide the Secretary of Homeland Security with the authorization to issue a "slow down or shut down" of particular AI models that threaten to cause "catastrophic harm".
#AIRegulation #Policy #RiskManagement #AISecurity #IdentityAndAccessManagement
https://www.techradar.com/pro/security/powerful-ai-systems-can-go-rogue-behave-in-extremely-dangerous-ways-or-even-resist-human-intervention-a-bill-requiring-ai-systems-to-have-a-kill-switch-is-now-in-congress | 198 |
| 11 | AI browser agents expose user data to malicious sites
Researchers have discovered a security flaw in AI web browsers that could result in users having their data exposed by malicious websites. Browsers equipped with AI agents, such as ChatGPT's Atlas, are like ordinary internet browsers but with additional chatbot functionality baked into the software.
#PromptInjection #AgentSecurity #SecurityResearch #AISecurity #ApplicationSecurity
https://www.livescience.com/technology/computing/ai-web-browsers-arent-ready-for-the-public-scientists-warn-as-they-highlight-massive-security-red-flags | 191 |
| 12 | AI Agent Used for Unattended Intrusion Tasks
BleepingComputer reports that 5 recovered AI-agent logs recorded privilege-escalation checks, service enumeration, and filesystem traversal. The threat actor enabled approval-free autonomous execution, allowing the agent to continue intrusion tasks without human confirmation.
#AgentSecurity #ThreatIntel #IntrusionAnalysis #AISecurity #IncidentDetectionAndResponse
https://www.bleepingcomputer.com/news/security/hermes-ai-agent-used-to-automate-attack-on-thai-finance-ministry | 205 |
| 13 | Benchmark Measures Whether LLM Guardrails Actually Work
The LLM security benchmark runs 49 attack cases across prompt injection, system-prompt extraction, policy bypass, and data leakage. Deterministic string and regex graders avoid judge-model manipulation, while Wilson confidence intervals show whether a guardrail change exceeds statistical noise.
#LLMSecurity #PromptInjection #Guardrails #AISecurity #AISecurityGovernanceAndAssurance
https://github.com/Vincent-P-essy/llm-security-benchmark | 196 |
| 14 | Agent Injection Lab Tests Real Tool Hijacking
The lab tests prompt injection, memory poisoning, and task hijacking against local AI agents. Its tools mode executes read, write, delete, and secret-access requests inside a resettable path-jailed sandbox, then measures attack success through verified filesystem side effects.
#PromptInjection #AgentSecurity #SecurityTesting #AISecurity #ApplicationSecurity
https://github.com/LurkSec/LurkSec-Agent-Injection-Lab | 211 |
| 15 | No text... | 248 |
| 16 | No text... | 248 |
| 17 | https://sec.cloudapps.cisco.com/security/center/resources/risk-based-disclosure #cisco | 268 |
| 18 | No text... | 256 |
| 19 | No text... | 275 |
| 20 | https://github.com/uphiago/recon-skills | 290 |
