News
Updates and announcements from FM CyberSecurity: partner certifications, hires, and milestones.
Looking for vulnerability news? →
New research examines what agents did when ordinary data retrieval failed.
A lab test shows why an email assistant's model and its surrounding automation must be understood together. The results differed between Gmail's sidebar and a custom workflow.
Zimperium describes Android malware that asks an AI assistant where to tap and scroll. The model helps navigate a phone the malware has already compromised.
Plugin4Shell exposed a gap between approving an AI coding plugin and checking the code delivered. A published Codex fix explains the missing verification.
Hacktron describes Claude-assisted research linking a forum image-upload flaw to OpenAI account access. Here is how the chain worked.
CrowdStrike's new PhantomRaven report connects likely AI-written malware, npm packages and bug bounty activity. Here is what the findings establish.
Falcon Data Security aims to recognise confidential information in ordinary text. Here is how classification on the PC works.
CrowdStrike's Fal.Con 2026 announcements connect AI activity, agent identities and AI-powered defence. Here is what Guardian, SafeMind and Agentic IdP each add.
RubyGems removed more than 500 malicious packages in May. New research attributes the campaign to AI agents and highlights risks in automated documentation builds.
The September report describes AI-assisted intrusions with varying human involvement. The response should focus on access and observable behaviour.
An agent-assisted campaign moved from planning to credential theft in hours. Check how quickly your cloud response can contain unauthorised activity.
Check Point demonstrated a cross-account channel combined with prompt injection. The channel was closed, but connector permissions still deserve review.
Researchers reconstructed about 18,000 agent posts on DSEwiki. The findings raise practical questions about writable websites and agent network controls.
ESET describes malware comments intended to derail AI-assisted analysis. Your pipeline needs an explicit path for incomplete or refused results.
Researchers describe an Aurora operator using Cursor during attacks. Focus on the actions and access, rather than treating the tool's name as a verdict.
The industry calls for faster cyber defense. For business leaders, the next step is to turn that commitment into funded, accountable work.
OpenAI's investigation describes unauthorised agent communication and uneven safeguards. Shared storage and test environments need explicit security boundaries.
Aikido's lab recreation shows an agent bypassing a booking restriction. The result is a reminder to enforce permissions on the server.
Only 12 of 405 samples appeared in Unit 42's endpoint dataset. That is useful evidence, but not a measure of every AI-assisted attack.
An NSA-led advisory describes reconnaissance against Siemens PLCs. Review exposure and remote access with the people responsible for the process.
Adversa demonstrated a Grok attack using encrypted webpage content. Transforming external data must not turn it into trusted instructions.
OpenAI reported a training pause and stricter controls after signs of critical cyber capability. The announcement also makes the cost of agent oversight visible.
A preprint shows instructions propagating between agents. Its warning-prompt result is promising, but should not replace access controls.
OpenAI's cyber model responds to more advanced security requests. Its 95 percent completion figure measures refusals, not a universal exploit success rate.
Dream's research describes a four-day intrusion using AI agents. The findings show why weak authentication and exposed APIs still matter.
Researchers recovered sensitive data from published reasoning blocks. Treat agent traces as potentially confidential before sharing them.
JFrog describes malicious hooks and editor tasks in the August campaign. Review executable project settings as well as package dependencies.
Tenet's research shows how attacker-controlled log content can steer an agent. Reading an event should not give that event authority to change systems.
Three incidents reached real systems from an evaluation setup with unintended internet access. A prompt describing a sandbox cannot enforce its boundaries.
Agents left the intended boundaries of an OpenAI evaluation and compromised Hugging Face. The incident puts shared infrastructure and agent permissions in focus.
Johan Vorgaard, Kenny Le, Maximilian Sharoyan and Fredrik Standahl represented FM CyberSecurity at Arrow ECS Norway's Summer Cloud Festival in Oslo.
Tenable visited FM CyberSecurity's Oslo office in May. Guy March also took a turn in the racing simulator, recording 1:36.052 at Silverstone.