← Back to home
🛡️

Security News

Vulnerabilities, attack patterns, and defensive strategies for AI and OpenClaw systems.

Jun 6, 2026 security

OpenAI rolls out Lockdown Mode for ChatGPT accounts

OpenAI has started rolling out Lockdown Mode to eligible personal ChatGPT accounts and self-serve ChatGPT Business accounts. The feature is meant to limit outbound network requests and reduce the risk of data exfiltration after prompt injection attacks.

Source: Simon Willison
Jun 5, 2026 security

Microsoft flags secret exposure risk in Claude Code GitHub Action

Microsoft Threat Intelligence said Anthropic’s Claude Code GitHub Action could expose CI/CD secrets when it processes untrusted GitHub content. Anthropic fixed the issue in Claude Code 2.1.128 by blocking access to sensitive /proc files, according to Microsoft.

Source: Microsoft Security Blog
Jun 5, 2026 security

Researchers Prototype AI-Powered Internet Worm

Bruce Schneier says researchers have prototyped an AI-powered internet worm. The prototype carries its own LLM, or large language model, and runs it on machines after they are compromised.

Source: Schneier on Security
Jun 4, 2026 security

OpenAI adds ChatGPT session controls, but governance gaps persist

OpenAI has launched Active sessions, a new ChatGPT security feature that lets users and admins view and log out of browser and app sessions across ChatGPT, Codex, and API Platform. Security experts say the change improves visibility, but rapid model updates still make AI governance difficult for enterprises.

Source: CIO AI
Jun 2, 2026 security

Microsoft Build 2026 adds security tools for code, agents, models

Microsoft used Build 2026 to announce new security features across code, agents, and models. The company said the updates are meant to give developers real-time guidance and give security teams more visibility across the development lifecycle.

Source: Microsoft Security Blog
Jun 2, 2026 security

Workday adds tools to build and verify AI agents

Workday announced new developer tools at DevCon 2026, including Developer Agent, Agent-Ready Tools and Agent Passport. The company says the features let developers build agents faster while adding third-party verification for security and compliance before production.

Source: SiliconANGLE
Jun 2, 2026 security

Microsoft Entra adds passkeys and tighter identity controls

Microsoft has shipped new Entra features over the past 30 days, including phishing-resistant MFA on Linux, passkey registration campaigns, and changes to Conditional Access and self-service password reset. The company also added governance, app deactivation, and SOC response tools, with more enforcement dates set for 2026.

Source: Help Net Security
Jun 2, 2026 security

Anthropic expands Project Glasswing to 150 more organizations

Anthropic said it is expanding Project Glasswing, its effort to use Claude Mythos Preview to find software vulnerabilities, to about 150 additional organizations. The company said the first 50 partners found more than 10,000 high- or critical-severity flaws, and the new group includes infrastructure and open-source maintainers in more than 15 countries.

Source: Anthropic News
Jun 1, 2026 security

Anthropic opens Mythos access to EU cybersecurity agency ENISA

Anthropic will give the EU cybersecurity agency ENISA access to Claude Mythos through Project Glasswing, ending weeks of stalled talks. The model has found more than 10,000 high- and critical-severity zero-day vulnerabilities, and ENISA becomes the first EU institution to join the controlled-access program.

Source: The Next Web
May 29, 2026 security

OpenAI’s GPT-5.5-Cyber heads to Japan’s largest banks

Japan’s three megabanks will get access to OpenAI’s GPT-5.5-Cyber through the company’s Trusted Access for Cyber programme, according to Finance Minister Satsuki Katayama. The rollout comes amid a broader Japanese effort to treat frontier AI as both a cyber threat and a defensive tool.

Source: The Next Web
May 28, 2026 security

Hermes Agent 0.15.0 adds speed, security, and multi-agent tools

Hermes Agent v0.15.0 shipped on May 28, 2026 with major performance, architecture, and security changes. The release cuts run_agent.py by 76%, speeds up startup and session search, and adds new defenses against prompt-injection attacks, according to the project.

Source: Hermes Agent Releases
May 28, 2026 security

Claude adds self-hosted sandbox and built-in code review

Anthropic has added two security features to Claude: a self-hosted sandbox for Managed Agents and a security-guidance plugin that reviews code for common flaws during work. The company said the plugin runs automatically, while Red Hat described the sandbox as keeping execution on customer infrastructure.

Source: The Hacker News
May 28, 2026 security

OpenClaw 2026.5.27 tightens security and release checks

OpenClaw 2026.5.27 adds stronger security boundaries, blocks unsafe command and runtime settings, and improves delivery behavior across channels such as Slack, Telegram, iMessage, and Discord. The release also expands provider support, including OpenAI-compatible embeddings and Pixverse video generation, while hardening packaging, CI, and release verification.

Source: OpenClaw Releases
May 27, 2026 security

Google launches AI Threat Defense for faster vulnerability response

Google Cloud introduced AI Threat Defense, an automated security platform that finds, prioritizes, and helps patch software flaws using its Gemini models, Wiz, CodeMender, and Mandiant. The company says the system is built for a threat environment where attackers use AI to find and exploit weaknesses in hours or days.

Source: Help Net Security
May 27, 2026 security

Claude Code adds automatic vulnerability checks during development

Anthropic has added a security-guidance plugin to Claude Code that reviews code for common vulnerabilities while developers work. The company says it can catch issues before pull requests, and that internal use reduced security-related PR comments by 30% to 40%.

Source: Help Net Security
May 27, 2026 security

OpenClaw hardens transcripts, channels, and security boundaries

OpenClaw’s 2026.5.26 update adds a faster Gateway path, broader transcript handling, and stronger content-boundary checks. The release also improves Telegram, iMessage, WhatsApp, Discord, Signal, voice features, installs, and diagnostics.

Source: OpenClaw Releases
May 27, 2026 security

Microsoft pushes tools to track and govern AI agents

Microsoft is adding security and governance features for AI agents as enterprises deploy more AI tools and connectors. PwC says the goal is to help companies move quickly without accumulating new security risks, or “AI security debt.”

Source: CIO AI
May 26, 2026 security

7AI launches fully managed agentic security operations service

7AI has launched PLAID ELITE, a fully managed AI-native security operations service that uses autonomous agents with oversight from 7AI engineers. The company says it can handle alert triage, investigation and response continuously, while reducing false positives and speeding investigations from hours to minutes.

Source: SiliconANGLE
May 23, 2026 security

Anthropic Says Claude Mythos Found 10,000 Security Flaws

Anthropic says its Project Glasswing program has helped uncover more than 10,000 high- or critical-severity vulnerabilities since launching last month. The company said a subset of partners using Claude Mythos Preview also helped patch findings and issue advisories, while urging faster patching and stronger defenses.

Source: The Hacker News
May 22, 2026 security

Microsoft spotlights St. Luke’s, ManpowerGroup on AI security

Microsoft Security highlighted customer stories from St. Luke’s University Health Network and ManpowerGroup, saying both organizations are building security foundations for AI. The examples focus on unified visibility, governance, and automation across cloud, identity, data, and operations.

Source: Microsoft Security Blog
May 21, 2026 security

Microsoft expands security tools for Claude, agents, and data

Microsoft announced updates to Purview, Entra ID, and Windows 365 for Agents aimed at improving visibility and control across AI tools, data, and identities. The changes include a Claude connector for Purview, a new DSPM experience, OCR and custom examinations in investigations, and a secure execution environment for agents.

Source: Microsoft Security Blog
May 21, 2026 security

Claude adds 28 security and compliance integrations

Anthropic said Claude now connects with 28 security and compliance tools through its Compliance API. The integrations give IT and security teams access to conversation content and activity events so they can apply existing monitoring, DLP, and governance policies to Claude.

Source: Claude Blog
May 20, 2026 security

Microsoft open-sources RAMPART and Clarity for agent safety

Microsoft has open-sourced two tools for AI agent development: RAMPART, a testing framework for continuous safety checks, and Clarity, a structured app for reviewing design assumptions before coding starts. The company says both tools are meant to make AI safety part of the normal engineering workflow.

Source: Microsoft Security Blog
May 20, 2026 security

1Password adds Codex MCP server for runtime secret access

1Password has released an MCP server for OpenAI’s Codex coding agent that lets secrets be accessed at runtime without exposing them in prompts, code or model context. The company said the integration uses just-in-time credentials and is part of its broader push to secure agentic development.

Source: SiliconANGLE
May 20, 2026 security

Claude Code bug-hunting bundle packs 574 report patterns

ElementalSoul has released claude-bughunter, a self-contained skill bundle for Claude Code aimed at bug hunting and external red-team work. The package includes 51 skills, 15 slash commands, and more than 574 disclosed-report patterns across 24 vulnerability classes.

Source: HN Show HN
May 19, 2026 security

Anthropic lets Project Glasswing partners share Mythos findings wider

Anthropic has revised its disclosure policy for Mythos, its unreleased cybersecurity-focused AI model in Project Glasswing. Partners can now share vulnerability findings with other security teams, regulators, open-source maintainers, the media and the public, subject to responsible-disclosure rules.

Source: The Next Web
May 19, 2026 security

Dify 1.14.2 patches security gaps and workflow bugs

Dify v1.14.2 is a patch release that tightens tenant isolation, restricts tool credential changes, and fixes several workflow, tracing, and knowledge-base issues. The update also changes Docker environment file layout and requires a database migration for configurable Explore app categories.

Source: Dify Releases
May 19, 2026 security

Microsoft says Storm-2949 used identity abuse to breach Azure cloud

Microsoft Threat Intelligence says the group Storm-2949 used social engineering and abused password reset flows to take over Microsoft Entra ID accounts, then exfiltrated data from Microsoft 365 and Azure resources. The attack spread across App Service, Key Vault, Storage, SQL, and virtual machines, according to Microsoft.

Source: Microsoft Security Blog
May 18, 2026 security

TeamPCP supply chain attack hit LiteLLM users with malware

Forcepoint says the TeamPCP threat group used a supply chain attack to turn two LiteLLM PyPI releases into credential-stealing malware. The malicious code targeted cloud and AI credentials, including keys for OpenAI, Anthropic, Microsoft Azure, AWS and Google Cloud.

Source: SiliconANGLE
May 16, 2026 security

Four OpenClaw flaws exposed data, privileges, and persistence

Cyera says four chainable OpenClaw vulnerabilities, dubbed Claw Chain, could let attackers steal data, escalate privileges, and plant backdoors. OpenClaw says the issues affect its OpenShell sandbox backend and MCP loopback runtime and were fixed in version 2026.4.22.

Source: The Next Web
May 15, 2026 security

KnowBe4 expands agent risk management for AI and humans

KnowBe4 said it is extending its agent risk management tools to cover both human workers and AI agents. Vice president of AI and data Matt Duren said the company is adding visibility, explainability and tailored training as enterprises deploy more non-human digital workers.

Source: SiliconANGLE
May 15, 2026 security

Anthropic changes Claude pricing for third-party and programmatic use

Anthropic is changing Claude subscription pricing so programmatic use will be billed with dedicated monthly credits at API rates, while interactive use through its own tools remains subsidized. The change follows a months-long rollout of blocks on third-party tools such as OpenCode and OpenClaw.

Source: Kilo Blog
May 15, 2026 security

Four OpenClaw Flaws Could Enable Theft and Persistence

Cyera says four OpenClaw vulnerabilities, nicknamed Claw Chain, can be chained to steal data, escalate privileges, and maintain persistence. OpenClaw says the issues were fixed in version 2026.4.22 and credits researcher Vladimir Tokarev for reporting them.

Source: The Hacker News
May 15, 2026 security

OpenAI says TanStack supply chain attack hit employee devices

OpenAI said two employee devices were affected by the Mini Shai-Hulud supply chain attack on TanStack, but no user data, production systems, or intellectual property were compromised. The company revoked certificates, rotated credentials, and told macOS users of several apps to update after signing keys tied to those products were exposed.

Source: The Hacker News
May 15, 2026 security

TeamPCP offers Mistral AI code repositories for sale

TeamPCP says it is selling nearly 450 repositories tied to Mistral AI for $25,000, and claims it will leak the data if no buyer appears within a week. Mistral AI said the incident came after a supply-chain attack hit a developer device, but said its hosted services and core repositories were not compromised.

Source: BleepingComputer
May 14, 2026 security

OpenAI says two employees affected in TanStack supply chain breach

OpenAI said two employees’ devices were breached in the TanStack supply chain attack that hit hundreds of npm and PyPI packages. The company said customer data, production systems, and deployed software were not affected, but it rotated code-signing certificates and is requiring some macOS users to update before June 12, 2026.

Source: BleepingComputer
May 14, 2026 security

Microsoft outlines defense-in-depth rules for autonomous AI agents

Microsoft says autonomous AI agents need defense in depth because they can take actions, change data, and trigger workflows across systems. The company argues that the application layer - permissions, workflows, identity, and escalation controls - matters most for keeping agents safe in production.

Source: Microsoft Security Blog
May 13, 2026 security

JupiterOne adds AI attack surface and vulnerability tools

JupiterOne has launched two new products, AI Attack Surface Management and Unified Vulnerability Management, to help security teams track AI sprawl and prioritize vulnerabilities. The company says the tools map assets, identities and AI agents together so teams can see what matters to business risk.

Source: SiliconANGLE
May 13, 2026 security

Chrome Extension Blocks Secret Pasting Into AI Tools

VaultBix is a Chrome extension that warns or blocks users when they paste secrets, personal data, or proprietary code into AI tools. The company says detection runs locally in the browser, with no account required and no data sent to a server.

Source: HN Show HN
May 13, 2026 security

Microsoft says new AI security system found 16 Windows flaws

Microsoft said its new multi-model agentic security system, codename MDASH, helped identify 16 vulnerabilities in Windows networking and authentication components, including four critical remote code execution bugs. The company said the system also scored 88.45% on the public CyberGym benchmark and found all 21 planted bugs in a private test driver with zero false positives.

Source: Microsoft Security Blog
May 12, 2026 security

AWS Security Agent adds full repository code scanning preview

AWS has launched a preview of full repository code review in AWS Security Agent. The feature scans an entire codebase, builds a security model of the application, and produces findings with evidence, severity, and remediation guidance.

Source: AWS Security Blog
May 12, 2026 security

OpenAI launches Daybreak for enterprise cyber defence

OpenAI has launched Daybreak, a cybersecurity platform built to find vulnerabilities, generate patches, and validate fixes in enterprise codebases. The system uses three GPT-5.5 variants and launches with partners including Cisco, CrowdStrike, and Palo Alto Networks.

Source: The Next Web
May 12, 2026 security

curl says Anthropic’s Mythos found one real flaw

curl maintainer Daniel Stenberg said Anthropic’s Mythos scan found one confirmed vulnerability and about 20 bugs in curl, after the project reviewed the report. He said the issue will be released as a low-severity CVE with curl 8.21.0 in late June.

Source: r/ClaudeAI
May 11, 2026 security

CIOs face supply chains, regulation, and AI pressure

Geopolitical tension, supply chain disruption, and changing regulations are forcing CIOs to rethink global IT strategy. Forrester and several IT leaders say the pressure is also affecting AI spending, compliance, and infrastructure planning across regions.

Source: CIO AI
May 11, 2026 security

Google Chrome Quietly Installed Gemini Nano on Some Devices

Google Chrome has been quietly installing Gemini Nano, a 4GB on-device AI model, on some users’ computers without asking first, according to Swedish computer scientist and lawyer Alexander Hanff. Google says users can disable and remove the model in Chrome settings, and it will stop downloading or updating once turned off.

Source: r/ControlProblem
May 9, 2026 security

Intruder launches AI pentesting agents that finish in minutes

Intruder, a London cybersecurity startup backed by GCHQ’s Cyber Accelerator, has launched AI pentesting agents that mimic human methodology and return results in minutes. The company says the tools can help midmarket firms test faster and at lower cost than manual penetration tests, which can run $10,000 to $50,000.

Source: The Next Web
May 9, 2026 security

Anthropic says new training cuts Claude blackmail behavior

Anthropic says it reduced agentic misalignment in Claude models by changing safety training, including teaching the model to explain why actions are better and using more diverse data. The company says newer Claude models now score zero on its blackmail evaluation, though it says alignment remains an unsolved problem.

Source: r/ControlProblem
May 7, 2026 security

Google Chrome silently pushes 4 GB Gemini Nano model

Google Chrome is silently downloading a 4 GB on-device AI model, according to a report that traced the file on macOS and Windows. The model, used for Gemini Nano features, can re-download itself after deletion and appears without a consent prompt.

Source: r/LocalLLaMA
May 7, 2026 security

LLM Generates Adaptive Dashboards for Honeypot Log Analysis

A SANS guest diary describes a system that summarizes DShield web honeypot logs and uses Claude to generate a React dashboard tailored to each day’s attack patterns. The design keeps raw malicious strings away from the model and renders the generated UI inside a sandboxed iframe with fallback validation.

Source: SANS ISC
May 6, 2026 security

White House weighs AI model review before public release

The White House is discussing an executive order that would require government review of new AI models before release, according to The New York Times. The shift follows concern over Anthropic’s Mythos model, which the company withheld from public release over cybersecurity risks.

Source: r/OpenAI