Full Archive · Page 9

Research archive, page 9

Browse entries 193–216 of 1531. Return to the first page to search and filter the complete collection.

Unit 42 AI Security September 29, 2026 analysis

OperTraitor: audit the permissions behind Kubernetes and AI operators

Unit 42’s open-source OperTraitor compares operator RBAC manifests with documented functionality to flag excessive privileges for review. Its case studies distinguish an IBM secret-access issue that received a patch from Datadog permissions documented as an architectural tradeoff. The attack prerequisite is compromise or misuse of an already privileged operator; this is not evidence that an LLM independently breached a cluster. Model-generated risk scores are triage aids, while actual service-account permissions determine the reachable resources.

Unit 42 AI Security September 2, 2026 analysis

An AI-Assisted Cyber Attack: Inside a Unit 42 Investigation

Unit 42 describes an enterprise intrusion completed in under ten hours, with observed activity consistent with AI assistance and an attacker claiming agent use. The chain moved from a public web service through repository secrets and administrative credentials into CI/CD and cloud AI access. Branch protection blocked attempted Terraform backdoors. The investigation highlights overlapping persistence and abuse of the victim’s own AI services after compromise.

Black Hat Asia 2026 | Bad Vibes - Pwning Coding Agents 70 Times With The Same Bugs video thumbnail Play video
Black Hat August 29, 2026 video

Black Hat Asia 2026 | Bad Vibes - Pwning Coding Agents 70 Times With The Same Bugs

Palo Alto Networks researchers found the same command-parser, protected-path, and sandbox-boundary failures across major coding agents. Their survey produced more than 81 vendor reports and 18 assigned or reserved CVEs, including allowlist bypasses through compound shell syntax, path-equivalence errors, unsafe moves and symlinks, and gaps between file and terminal controls.

Wiz AI Security August 27, 2026 analysis

Inside 90 days of attacks on AI infrastructure

Across 90 days of AI-service honeypots, Wiz observed exploitation of LiteLLM MCP flaws, blind prompt injection that used out-of-band callbacks to confirm agent shell execution, and post-exploitation tailored to steal model-provider and proxy credentials from process memory. The activity targeted AI infrastructure as ordinary high-value cloud infrastructure.

Ryan Greenblatt – What happens once AI can automate AI research? video thumbnail Play video
Dwarkesh Patel August 11, 2026 video

Ryan Greenblatt – What happens once AI can automate AI research?

Dwarkesh Patel and Redwood Research chief scientist Ryan Greenblatt debate whether verifiable AI-research tasks could produce rapid recursive improvement, then examine alignment targets, reward hacking, model coordination, and recent deception and containment incidents. The two-hour format exposes assumptions about data, compute, verification, and extrapolation rather than presenting a single forecast as settled fact.

Adversa AI Trusted AI Blog July 30, 2026 analysis

A hole in every one: bypassing the open source AI skill scanners

Adversa tested eight open-source AI skill scanners with paired unobfuscated and obfuscated malicious skills, finding that every scanner passed an attack through either a true bypass, a blind spot, or an injectable model judge. The study covers encoding, Unicode, command reconstruction, truncation, allowlists, bundled files, paraphrase, and remote stages; its 4,000-skill benign set also found no scanner beat an always-block baseline on F1. Most tools ran offline without optional model triage, and some were reconstructed from retained artifacts.

From Prompt Tricks to Autonomous Hackers video thumbnail Play video
Black Hat July 29, 2026 video

From Prompt Tricks to Autonomous Hackers

Ari Herbert-Voss reviews three years of progress in autonomous offensive-security systems, evaluates where they can already complete meaningful attack tasks, and separates those capabilities from work that still needs human expertise. The talk frames scalable, parallel attack simulation as a challenge to point-in-time testing rather than as a product announcement.

METR July 24, 2026 analysis

Metrics of Agent Ability

METR organizes agent-capability measures around performance as a function of expenditure, comparing fixed-budget scores, cost to reach a score, returns to test-time scaling, human-equivalent time and expenditure horizons, and human-relative cost. It explains when familiar benchmark scores break down—particularly when performance keeps improving with more inference or human benchmarks saturate—and notes that full cost, reliability, coverage, and elicitation choices affect the result.

Cloudflare AI Security August 14, 2026 analysis

How Cloudflare detects MCP traffic and helps secure it

Cloudflare Gateway now classifies inspected Streamable HTTP MCP traffic using the MCP-Protocol-Version header, exposes the user and destination in logs and a dashboard, and supports allow or block rules through an MCP-specific selector. The article distinguishes unapproved shadow MCP from direct connections that bypass an approved Portal's controls, and notes blind spots including local stdio, off-network, non-inspected, and otherwise unobserved traffic.

Google DeepMind Blog December 9, 2025 analysis

FACTS separates factuality tests for memory, search, images and supplied context

Google DeepMind’s December 2025 FACTS suite evaluates factual answers under four different information conditions: model knowledge alone, web search, images and supplied documents. Its search track standardizes the retrieval tool across models, while public examples accompany a private held-out evaluation set managed by Kaggle. The combined score averages results across tracks and sets, which can conceal sharply different failure patterns. The release provides a reusable evaluation structure, but benchmark accuracy does not establish factual reliability on a different application’s questions, retrieval system or user population.

RIG-RAG: A Graph-Inspired Approach to Agentic Cloud Infrastructure video thumbnail Play video
CAMLIS / PMLR November 14, 2025 video

RIG-RAG: A Graph-Inspired Approach to Agentic Cloud Infrastructure

RIG-RAG converts changing cloud configuration data into a typed, security-enriched graph for natural-language investigation and scheduled oversight. The authors report a production AWS deployment supporting 300,000 users, with interactive queries for analysts and curated recurring questions that detect infrastructure drift and expose relationships such as public reachability and identity access.

Microsoft Security Blog September 25, 2026 news

Storm-3168: compromised service principals enable rapid Azure destruction

Microsoft documents two compromised service principals used for Azure discovery, resource destruction and credential collection in activity linked to Storm-3168. The investigation distinguishes successful deletions from failed operations and attempts to remove recovery protections. Although the actor is associated with agentic ransomware reporting, the Azure evidence establishes destructive cloud operations, not a confirmed autonomous decision for every action. Microsoft reports no observed ransom note or confirmed successful data exfiltration in this case.

One Operator, Many Drones: Inside Skydio's Autonomy Stack — Suchet Bargoti, Skydio video thumbnail Play video
AI Engineer September 24, 2026 video

One Operator, Many Drones: Inside Skydio's Autonomy Stack — Suchet Bargoti, Skydio

Suchet Bargoti demonstrates remotely coordinated drones and explains Skydio’s division of autonomy between aircraft and cloud services. Immediate control stays on the vehicle; cloud models support heavier reasoning, shared maps and tool-based task planning. Fleet observations feed later updates. The talk illustrates how an operator can shift attention between aircraft, while its stated reliability target is not a measured fleet-wide success rate.

The Hacker News AI Security September 9, 2026 news

Joint advisory describes alleged model-distillation campaigns and detection controls

CISA, NSA and FBI allege industrial-scale extraction of US model capabilities through distributed accounts, proxies and aggregators. Their advisory recommends correlating prompts, usage and account behavior across providers; it distinguishes these alleged campaigns from legitimate model distillation.

The Hacker News AI Security August 31, 2026 news

Aurora Ransomware Operators Use Cursor AI in Attacks Against 10 Targets

CloudSEK and Gambit Security report that an Aurora ransomware affiliate used Cursor for sustained Russian-language attack planning and hands-on exploitation after obtaining credentials or an existing route into victim networks. Recovered infrastructure linked the agent sessions to Active Directory discovery and escalation plans, while the broader intrusion still relied on familiar social engineering, credential theft, lateral movement, defense evasion, exfiltration, and ransomware deployment.