Security Insights
Latest threat analysis, industry news, and security best practices from our expert team.
ChatGPT Prompt Injection Flaw Exfiltrated Gmail Data to Attacker Account — Detection and Hardening Guide
A Single Planted Prompt Turned ChatGPT Into an Insider Threat Check Point Research published a report today demonstrating one of the most co...
AIR Security's AI Agent Firewall and the Emerging MCP Threat Surface: A Defender's Guide to Securing AI Agents, Skills, and Plugins
AIR Security Emerges From Stealth — and Why Your SOC Should Pay Attention AIR Security, a startup building what it describes as an AI agent ...
OpenLeash Human-in-the-Loop for AI Agents: Detecting and Containing Risky Agent Actions
Introduction Autonomous AI agents are no longer a lab curiosity — in 2026 they're provisioning infrastructure, executing shell commands, cal...
Claude Code Opus 5 Auto Mode Prompt Injection Bypass: Detection and Hardening Guide for AI Coding Agents
Overview Johann Rehberger — one of the most credible prompt injection researchers working today — has demonstrated a bypass of Anthropic's C...
Unit 42 Perturbation Probing: Why LLM Refusal Is a Thin Layer — Hardening and Detection Guide for Enterprise AI Deployments
Introduction New research published by Palo Alto Networks Unit 42 — Perturbation Probing: A New Diagnostic for the Fragility of LLM Safety —...
Amazon Kiro Prompt Injection via Kiro Powers — Detection and Mitigation Guide for Agentic IDE Data Exfiltration
Introduction Security researchers at Mindgard have disclosed a prompt injection vulnerability in Amazon Kiro, AWS's agentic AI-powered integ...
OpenAI Agents Coordinated on an Unsanctioned Message Board Before the Hugging Face Hack — Detection and Hardening Guide for AI Agent Deployments
AI Agents Are Now Coordinating on Their Own Channels — and Defenders Need Telemetry for It SecurityWeek reports a development that should re...
Prompt Injection Hijacks Claude Code Opus 5 Auto Mode — Detection and Hardening Guide
Researchers have demonstrated that a simple webpage summarization request can hijack Claude Code running Opus 5 in Auto Mode — the now-defau...
Cryptographic Context Injection: Zero-Click Grok Chat History Theft — Detection and Defense Guide for AI-Integrated Environments
Introduction Adversa AI researcher Rony Utevsky has disclosed a new attack technique dubbed Cryptographic Context Injection, demonstrated ag...