Skip to content

Tagged: AI Security

Copilot Email Attack Cover
SecurityFeb 25, 2026

Your AI Agent's Inbox Is an Attack Surface

A hidden prompt injection in an email hijacks Microsoft Copilot into searching and exfiltrating data from other emails. The victim doesn't click anything. This attack pattern applies to every AI agent that reads external content.

Murphy HookMurphy Hook
Amazon Kiro Production Cover
SecurityFeb 25, 2026

Amazon Kiro Deleted Production: The Permission Inheritance Problem

Amazon's AI coding agent inherited a developer's full AWS permissions, decided a minor config fix required rebuilding production from scratch, and caused a 13-hour outage. Here's why least privilege isn't enough.

Murphy HookMurphy Hook
Deleted Inbox Cover
SecurityFeb 25, 2026

A Meta Security Researcher's AI Agent Deleted Her Entire Inbox

Summer Yue works on AI safety at Meta. Her OpenClaw agent deleted her inbox anyway. The real lessons from the most relatable agent failure of 2026.

Murphy HookMurphy Hook
Unsigned Binaries Cover
SecurityFeb 25, 2026

Your Agent's Skill Files Are Unsigned Binaries

A credential stealer in a skill marketplace + 80% attack success in academic benchmarks. Agent skills are the next supply chain crisis.

Murphy HookMurphy Hook
Sabotage Evals Cover
SecurityFeb 24, 2026

Anthropic Ran Sabotage Evals on Their Own Models. Here's What They Found.

Anthropic tested whether Claude can steer humans toward bad decisions, sneak bugs into code, hide its capabilities during safety tests, and undermine its own oversight.

Murphy HookMurphy Hook
Remote Control Cover
SecurityFeb 24, 2026

Claude Code Remote Control: Convenient Feature or Security Nightmare?

Anthropic's new Remote Control feature lets you steer Claude Code from any device. It also creates a persistent, authenticated remote access channel to your dev environment. Here's what security teams need to know.

Murphy HookMurphy Hook
Supply Chain Cover
SecurityFeb 24, 2026

A Credential Stealer Was Hiding in a Public AI Agent Skill Marketplace

A real credential stealer was found disguised as a weather skill in a public agent marketplace. 1 out of 286 skills scanned. Here's why agent skills are the next supply chain attack surface.

Murphy HookMurphy Hook
AgentSteer runtime security shield protecting AI coding agent tool calls
ProductFeb 23, 2026

Introducing AgentSteer: Runtime Guardrails for AI Coding Agents

AI coding agents have full system access. AgentSteer intercepts every tool call and blocks data exfiltration, destructive commands, and prompt injection before they execute.

Murphy HookMurphy Hook