GreyNoise: AI Agents Hit 395 Orgs, 1 Entry-to-Admin in 7 Minutes
GreyNoise says AI agents exploited two PaperCut flaws to breach 395 organizations, schools the hardest hit, and hit at least 11 in 26 seconds. Timeline and fixes inside.
AI-powered threats, deepfakes, adversarial attacks, AI safety research, and defensive AI
GreyNoise says AI agents exploited two PaperCut flaws to breach 395 organizations, schools the hardest hit, and hit at least 11 in 26 seconds. Timeline and fixes inside.
AI incident response shifted after Hugging Face logged more than 17,000 attacker actions and, it says, hosted models’ safety filters refused its forensic team. A field guide.
Wiz found six AI coding agents could be steered outside the workspace by a symlink, some behind approval prompts naming the link, not the file it reaches.
OX Security found 7,000 MCP servers on public IPs and estimates about 200,000 vulnerable. Anthropic calls the STDIO behavior expected; OX calls it the problem.
Sysdig captured its first AI-agent-driven intrusion: an LLM agent turned a Marimo RCE foothold into the theft of an internal database in 4 pivots. The evidence chain, analyzed.