Skip to content
HiveSecurity
  • Home
  • Blog
  • Tags
  • Vulnerabilities
    • Tools
    • Cheat Sheet
    • Security Guides
  • Contact
  • About
Esc
Type to search...
  • Home
  • Blog
  • Tags
  • Vulnerabilities
  • Resources
  • Tools
  • Cheat Sheet
  • Security Guides
  • Contact
  • About
← All tags Tag

AI Security

33 articles

Langflow CVE-2026-9198: Auto-Login Was a Server Shell

Default Langflow deployments exposed a two-step path from no account to remote code execution. Learn how to patch, isolate, hunt, and rotate secrets.

11 August 2026
AI Security Vulnerability Management Application Security

DEF CON 34: The Hacker Party That Became the World's Biggest Hacking Conference

DEF CON started as a farewell party for a BBS sysop who never showed up. 33 years later it draws more than 30,000 people, shapes election security policy, and lets autonomous AI agents hunt flags.

7 August 2026
Cybersecurity DEF CON Hacker Culture

AI Voice Cloning: The $25.6 Million Phone Call That Wasn't Real

A finance employee wired $25.6 million after a video call with the CFO and colleagues — all AI-generated deepfakes. Short public audio clips can now seed convincing voice clones. Here's how vishing changed and what actually stops it.

30 July 2026
Social Engineering Deepfake Blue Team

DuneSlide: How a Prompt Injection Became Full RCE in Cursor IDE

Cato AI Labs found two 9.8 CVSS flaws in Cursor's terminal sandbox — CVE-2026-50548 and CVE-2026-50549 — that let a poisoned MCP response or search result silently escape to full remote code execution. Neither requires a click.

27 July 2026
AI Security Prompt Injection Vulnerability Research

JADEPUFFER: Inside the First Documented Agentic Ransomware Attack

Sysdig caught an LLM agent breaking into a Langflow server, pivoting to a production database, and extorting the victim — with no human at the keyboard between steps. Here's what actually happened, and what's still unproven.

25 July 2026
AI Security Ransomware Threat Intelligence

Grok Build Uploaded Entire Git Repositories: What the Wire Capture Proved

A wire-level analysis found Grok Build 0.2.93 uploading tracked source code and full Git history independently of what the agent read. Here is what was proven, what changed, and how developers should respond.

14 July 2026
AI Security Developer Security Data Privacy

Instagram @-Mentions Are Now an AI Impersonation Surface

Meta's Muse Image turns public Instagram content into promptable visual context. The security issue is not novelty; it is lower-friction impersonation at social-media scale.

9 July 2026
AI Security Social Engineering Phishing

Prompt Injection in 2026: From Research Toy to Real CVEs, Agent Hijacking, and Zero-Click Exfiltration

CVE-2025-32711 (EchoLeak) exfiltrated M365 data with zero user interaction. The Anthropic MCP server had three exploitable injection CVEs. OpenAI says AI browsers may never be fully fixed. Here's the full attack chain — and how to detect it.

Updated 8 July 2026
AI Security Red Team Blue Team

AI-Built Browser Ransomware Abuses Chrome File Access

Check Point analyzed a DeepSeek-attributed ransomware sample that should not work from a browser tab. Most of it was fiction — except for one detail that mapped to a real Chromium API. No malware install required.

5 July 2026
Ransomware AI Security Web Security

The Clean Repo Trap: AI Coding Agents and the Trust Boundary Problem

A 0DIN proof of concept against Claude Code demonstrates how a clean-looking repository can lead to runtime command execution. The structural risk behind the attack applies to any AI coding agent with shell access.

30 June 2026
AI Security Supply Chain Developer Security

Trump Died of Rabies — And What That Means for Your Package Manager

When DuckDuckGo's AI killed Trump with rabies, the world laughed. When AI coding assistants invent package names, attackers register them. Nobody's laughing then.

27 June 2026
Supply Chain AI Security Malware

AI Cyber Sovereignty: What Happens When Your Best Defender Can Be Switched Off?

Frontier cyber AI is becoming controlled infrastructure. The security risk is not only that attackers get stronger models, but that defenders become dependent on capabilities a vendor or government can withdraw.

25 June 2026
AI Security Threat Intelligence Blue Team

When AI Insiders Walk Away: Google's Moral Compass Problem Is a User Trust Problem

A Google Android security director resigned over Pentagon AI work. The deeper question is what users should believe when people close to powerful AI systems start walking away.

15 June 2026
AI Security Cloud Security Governance

Your AI Assistant Has Tools. Audit Them Before They Audit You.

A practical home-user checklist for auditing MCP servers, AI assistant tools, local permissions, and supply-chain risk before a trusted setup turns into an exposed one.

13 June 2026
AI Security Cybersecurity Hardening

N-days Are Becoming N-hours

Anthropic's June 2026 N-day research shows how frontier models can turn public patches into working exploits in hours. Here's what defenders should change now.

9 June 2026
AI Security Vulnerability Management Blue Team

Meta's Hidden NameTag: Facial Recognition Code for Smart Glasses Is Already in a 50M-Download App

Wired found dormant facial recognition code in Meta's AI app. It has not been activated for consumers, but researchers manually triggered a 2,048-dimensional faceprint pipeline.

6 June 2026
Cybersecurity AI Security Privacy

Miasma and Mini Shai-Hulud: When npm Malware Learned to Persist in AI Coding Agents

Mini Shai-Hulud and Miasma show how supply chain malware can move from npm install-time execution into Claude Code hooks, VS Code tasks, and CI/CD persistence.

6 June 2026
Supply Chain Malware Analysis AI Security

The AI Evasion Lab

Sophos X-Ops uncovered a threat actor using Claude Opus 4.5 and Cursor IDE to build an automated, modular EDR evasion framework — 80 modules, 70+ techniques, tested against Sophos, CrowdStrike, and Defender.

3 June 2026
Malware Analysis Red Team Blue Team

No One in the Loop: The Autonomous Weapons Race

China's so-called 'kill them all' drone algorithm made headlines. But the real story is bigger: major militaries are racing to reduce human involvement in lethal decisions, and the window to regulate them is narrowing.

1 June 2026
AI Security Threat Intelligence Nation-State

AI Bug Hunting in Browsers: Discovery Is Becoming the Easy Part

Mozilla used Claude Mythos Preview to identify and fix 271 Firefox security bugs, while Chrome shipped a separate 151-fix security update. The lesson is not that AI replaces security teams. It is that patching, triage, and verification are becoming the bottleneck.

29 May 2026
AI Security Cybersecurity Vulnerability Research

Poisoned AI: How Hugging Face Became a Malware Distribution Platform

A fake OpenAI repo hit #1 trending on Hugging Face with 244K downloads in 18 hours. Here's every attack vector targeting AI model repositories — and how to defend against them.

29 May 2026
Supply Chain AI Security Malware Analysis

When the Weapon Learns: How Nation-States Weaponized AI Across the Full Attack Chain

Google GTIG's May 2026 report documents a turning point: state actors now use AI to write zero-day exploits, build self-navigating backdoors, and poison the AI supply chain itself.

11 May 2026
Threat Intelligence Malware Analysis Red Team

Agentic AI: The Enterprise Blind Spot That Attackers Already Found

Autonomous AI agents are already inside enterprise environments — and most security teams have no idea what they're doing. Here's what attackers exploit and how to defend against it.

7 May 2026
AI Security Cybersecurity Supply Chain

AI Agent Traps: Six Ways Attackers Manipulate Autonomous AI — With Real Examples

Google DeepMind published the first systematic taxonomy of AI agent manipulation techniques. Here's what each attack looks like in practice — and why most AI deployments are already vulnerable.

7 May 2026
AI Security Cybersecurity Red Team

Claude Mythos: The AI That Rewrites the Rules of Cybersecurity — For Everyone

Anthropic built an AI that autonomously discovered a 27-year-old vulnerability in widely-used code. It can build working exploits from scratch. It's too dangerous to release publicly. Here's what that means for your bank, your government, your code — and the future of digital security.

7 May 2026
AI Security Cybersecurity Vulnerability Research

Your Local AI Is Listening — And So Is Everyone Else on Your Network

Ollama, LM Studio, Jupyter Notebook — you installed them for privacy, but they may be broadcasting your data to your entire network. Here's what's actually happening and how to fix it.

7 May 2026
AI Security Cybersecurity Network Security

MCP Servers Through an Attacker's Eyes: What Happens When You Plug In Without Thinking

MCP servers let AI assistants control your tools — but most users install them without understanding the attack surface. Here's what attackers already know.

7 May 2026
AI Security Cybersecurity Supply Chain

OpenClaw: How the Viral AI Agent Became 2026's First Major Security Crisis

OpenClaw went from 0 to 180,000 GitHub stars in weeks — and then came the RCE, 30,000 exposed instances, and a supply chain attack poisoning its entire skill marketplace.

7 May 2026
Cybersecurity Malware Analysis Supply Chain

Project Glasswing: Anthropic's AI That Finds Zero-Days Better Than Humans

Anthropic just unveiled Claude Mythos Preview — an AI model too dangerous to release publicly, but powerful enough to find vulnerabilities that evaded detection for decades. Here's what it means and how to get involved.

7 May 2026
Cybersecurity AI Security Vulnerability Research

When Trusted Agents Turn Rogue: The Rise of the Double Agent in Modern AI Systems

AI agents are trusted to act on your behalf — but that trust is exactly what attackers exploit. Here's how AI agents get turned against you, and why you won't see it coming.

7 May 2026
AI Security Cybersecurity Red Team

Xanthorox AI: When the Attacker's AI Goes Dark

Xanthorox is an offline, modular AI attack platform with five specialized models — and it needs no cloud, no API, and leaves no traditional IoCs. Here's what defenders need to know.

7 May 2026
Cybersecurity Malware Analysis AI Security

The Human Remains the Weakest Link – But Now It's AI-Assisted

AI has transformed social engineering into an automated, scalable threat. Learn how attackers leverage AI-powered phishing, deepfakes, and voice cloning—and what defenders can do about it.

27 December 2025
AI Security Social Engineering Threat Intelligence

Cybersecurity in 2025: Holiday Season Security Guide and Year-End Threats

Cybersecurity threats heading into 2025: AI-powered attacks, ransomware trends, and quantum threats — with practical security measures for the holiday season and beyond.

19 December 2025
Cybersecurity Ransomware Threat Intelligence
HiveSecurity

Offensive thinking. Defensive expertise.

Content
  • Home
  • Blog
  • Tags
  • Vulnerabilities
Resources
  • Tools
  • Cheat Sheet
  • Security Guides
Company
  • Contact
  • About
  • RSS
  • Privacy
  • Security Policy

© 2026 Hive Security. All rights reserved.

Built with zero trust & least privilege