» Tag
security
518 postsAI Agent Runtime Policy: Stop Dangerous Tool Calls Before They Execute
A runtime policy layer stops AI agents from calling dangerous tools in production: risk tiers, delegation scopes, and argument validation explained.
ALIBI: Adversarial Comments Bypass LLM Vulnerability Detectors
ALIBI framework shows LLM-based vulnerability detectors can be bypassed over 90% of the time using adversarial source-code comments.
Rethinking MCP Security: A Large-Scale Study of 64K Runtime Servers
MCPZoo tests 64,611 MCP servers, revealing that most security scanner alerts are false positives and scanners disagree widely.
CommitBrief — AI code reviews, right in your terminal
A provider-agnostic, local-first CLI that reviews your staged changes, a historic range, or a whole GitHub pull request. Zero telemetry, no server. Free and open source.
commitbrief.comAI Jailbreak Benchmark Reveals 100x Safety Gap Between Models
New benchmark shows up to 100x safety gaps among frontier AI models against jailbreak attacks; some models yield zero jailbreaks.
AI Agent XBOW Finds and Exploits a Linux Kernel Bug (CVE-2026-72018)
XBOW's AI security agent found and exploited a Linux kernel bug (CVE-2026-72018) via SMC-D, achieving full root privilege escalation.
Fake Express Packages on NPM Spread Linux Worm
Fake Express packages on NPM spread a Linux worm, posing a significant security risk for engineers.
Fake AI Crawler User-Agents Are Probing Cloud Metadata Endpoints
HoneyLabs uncovered a single client spoofing thousands of AI crawler user-agents to run SSRF attacks against cloud instance metadata endpoints.
Rust crate arrayref 0.3.10 pulls in malware via proc-macro1 dependency
crates.io package arrayref 0.3.10 pulls in malicious proc-macro1, executing remote payloads and affecting Rust GUI projects like egui and iced.
221,000 Live Secrets Found in 7.6PB of Hugging Face Training Data
Researchers scanned 7.6PB of Hugging Face training data and found 221,303 live secrets — GitHub, GCP, database, and AI provider credentials.
ButterClaw: Self-Hosted Runtime Security for AI Agents, No Cloud
ButterClaw enforces AI agent security locally with regex signatures, a local LLM verdict pipeline, and SIGKILL/credential shredding — no cloud, no telemetry.