AI Agent Security & Safety
Articles about AI security, agent safety, and guardrails for autonomous systems
Unauthenticated OIDC Token Forgery Exploit Grants Administrative Control of SimpleHelp Servers
A critical flaw in SimpleHelp's OIDC implementation allows attackers to forge assertions, bypass MFA, and spawn unauthorized remote management accounts.
Fake Security Verification Frameworks Abuse Native macOS Utilities to Execute Hidden Infostealers
An in-depth analysis of the macOS ClickFix campaign, which leverages system commands to bypass manual interaction by silently downloading, mounting, and launching the Atomic macOS Stealer (AMOS), highlighting how the threat landscape is evolving to bypass user and OS boundaries.
Securing Autonomous Agents: The New CISO Challenge
As agentic AI adoption accelerates in enterprises, securing these autonomous agents presents a major challenge due to their ability to act outside traditional control frameworks.
Prompt Injection and Data Exfiltration in Copilot Search
Understand the SearchLeak attack: A three-stage indirect prompt injection threat in AI-powered search. Learn detection and mitigation strategies for Secure AI deployment.
Talkspace Launches 'Tee': The First Safe AI Agent Specifically Developed for Mental Health Support
Talkspace introduces Tee, a clinically-grounded AI mental health agent designed with safety features, HIPAA-grade privacy, and real-time clinician oversight to provide 24/7 supportive conversations.
Arcade.dev Raises $60 Million to Secure AI Agents
Arcade.dev raises $60M Series A to solve enterprise AI agent authorization challenges with an authentication runtime layer. Learn how the platform enables secure, auditable AI agent operations.
Claw Patrol: A Security Firewall for Autonomous AI Agents
Claw Patrol provides a runtime security layer for AI agents, allowing developers to set guardrails and monitor agent behavior. Created by the Deno team, it solves the 'rogue agent' problem in autonomous workflows through protocol-level inspection and rule-based validation.
Xiaomi MiMo Code: An Open-Source AI Development Assistant for Solo Developers
Xiaomi has released MiMo Code, an open-source AI assistant for developers claiming performance comparable to Claude Sonnet 4.6. The tool features multi-modal capabilities, agent collaboration, and long-horizon memory management designed to function as a professional development team partner for solo developers.
The Miasma Worm: A Self-Replicating Supply Chain Attack Targeting AI Coding Agents
The Miasma worm is a credential-stealing supply chain attack framework that has compromised 73 Microsoft-affiliated GitHub repositories. This autonomous worm uses compromised developer credentials to spread through CI/CD pipelines and specifically targets environments with automated AI tools.
Langflow Path Traversal Vulnerability CVE-2026-5027 Actively Exploited in Attacks
Attackers are actively exploiting a high-severity path traversal vulnerability in Langflow, the popular AI development platform. The flaw allows unauthenticated attackers to write arbitrary files on exposed servers, potentially leading to remote code execution. This article details the vulnerability, its exploitation timeline, and necessary mitigation steps.