Chrome Fixed 1,072 Bugs, Then Changed How Updates Reach Users
Chrome fixed more security bugs in two milestones than in the previous 23 while using AI across discovery, triage and fix preparation.
Read article →Reader view
Choose the default article length.
AI systems, model security, agent abuse, and attacks that use generative tools.
Chrome fixed more security bugs in two milestones than in the previous 23 while using AI across discovery, triage and fix preparation.
Read article →A misconfigured evaluation harness let three Claude models reach production systems, exposing a control gap that prompts and model safeguards could not contain.
Read article →Five recovered task logs record service discovery, privilege checks and file enumeration after an operator enabled Hermes's unattended mode.
Read article →Hugging Face traced 17,600 actions from an Artifactory escape through two malicious-dataset vectors and into its clusters, network and source control.
Read article →Zenity found URL parameters that preselected a template and auto-submitted instructions inside a logged-in user's Workspace Agents builder.
Read article →Any authenticated proxy-key holder could make two MCP preview endpoints run an arbitrary command on the LiteLLM host.
Read article →Push Security traced paid search ads to shared ChatGPT and Claude pages that handed visitors to fake desktop-app downloads.
Read article →A civil lawsuit targets a Telegram-based phishing-kit operation that Google links to 2.5 million texts and more than one million fraudulent URLs.
Read article →Researchers put instructions to read .env and encode it into source inside a PNG that text-only pull-request reviewers ignored but vision-capable coding agents later followed.
Read article →AIR says its brand-landingpage experiment reached 26,000 agents after scanners missed a remote instruction source that changed after approval.
Read article →CVE-2026-12957 allowed project configuration to start MCP processes with a developer's environment. AWS fixed the flaw in Language Servers for AWS 1.65.0.
Read article →Island found more than 800 fake skills and MCP servers using credible READMEs and ZIP files to turn capability searches into malware installs.
Read article →Trend Micro found a Russian-speaking actor using Gemini CLI to rebuild command-and-control infrastructure and operate eight infected computers.
Read article →