Artificial Intelligence
Curated coverage and analysis in this editorial area.

HTTP Terminator Proves AI Can Autonomously Discover Attack Techniques
James Kettle demonstrates that PortSwigger's HTTP Terminator AI system independently generates HTTP desynchronization techniques. The…

Autonomous AI vs. a Water Network: How Claude Mapped an OT Environment Without a Manual
An unknown threat actor used Anthropic's Claude and OpenAI's GPT to autonomously conduct discovery, enumeration, and password spraying…

Iran Weaponizes Its Asymmetric Playbook With Commercial AI
Recorded Future documents how generative AI has become a force multiplier across Iranian cyber and influence operations — compressing…

Google Sues 'Outsider Enterprise': Gemini Weaponized as PhaaS Engine
Google has filed a civil lawsuit against a China-based cybercrime network that abused Gemini to generate phishing code at scale. The c…

In Internal Test, OpenAI AI Agent Breaches Hugging Face to Obtain ExploitGym Solutions
During a controlled offensive cyber evaluation, OpenAI models with reduced cyber refusals escaped a sandbox and compromised Hugging Fa…

FakeGit: 800 AI Repositories on GitHub Turn Agents Into Malware Vectors
Island uncovered 800 malicious GitHub repositories masquerading as AI Skills and MCP servers. AI agents autonomously recommended the m…

Friendly Fire: Defensive AI Agents Turn into RCE Attack Vectors
The AI Now Institute's Friendly Fire report, published July 8, 2026, demonstrates that Anthropic's Claude Code and OpenAI's Codex — to…

Ollama Zero-Day DoS: downloadBlob Bug Puts Local AI Servers at Risk
ZDI has disclosed a zero-day vulnerability in Ollama enabling unauthenticated remote denial-of-service attacks via the downloadBlob fu…

HalluSquatting Turns AI Assistants' Predictable Hallucinations into a Botnet Installation Vector
Researchers from Tel Aviv University, Technion, and Intuit demonstrated that nine AI coding tools install botnet malware when asked fo…

Elastic Automates CVE Advisory Writing with RAG on MITRE Data
Elastic Security Labs has put into production an AI pipeline that generates complete CVE advisory drafts with CWE, CAPEC, and CVSS, gr…

SkillCloak: 90% of AI Agent Skill Scanners Fail Against Obfuscated Skills
HKUST researchers demonstrate that static scanners on AI skill marketplaces systematically fail against active evasion techniques. The…

BioShocking: How a Game Tricks Agentic AI into Stealing Credentials
LayerX researchers demonstrated BioShocking, a prompt injection attack that manipulates agentic AI browsers into exfiltrating sensitiv…