search
AI security tools
Trends
- 1Nvidia launches security platform to rein in rogue AI agents▼Nvidia unveils security platform to stop AI agents from going rogue
Nvidia has unveiled a new security platform designed to prevent autonomous AI agents from acting outside their intended instructions. The company says the tooling aims to monitor and control agent behaviour as businesses deploy AI systems that operate independently. Coverage from wire and business outlets highlights growing industry concern about AI safety and oversight as agentic AI adoption accelerates.
- 2Pi pod lets developers run coding agents in self-hosted sandboxes●Show HN: Pi pod – Run your pi coding agent in sandboxes on your own server
A new tool called Pi pod is being shared with developers, letting them run the Pi coding agent inside sandboxed environments on their own servers. The pitch is control and security: instead of relying on third-party infrastructure, teams can isolate agent execution on hardware they manage themselves. Early reaction on Hacker News is positive, with the launch drawing more than a hundred upvotes as developers weigh self-hosting coding agents against managed cloud options.
- 3
Anthropic is broadening access to its Claude AI system for vetted cybersecurity teams, in a move reported by The Hacker News. The announcement comes alongside figures from Glasswing, which says its use of the technology has uncovered 129,000 software flaws. The rollout signals Anthropic's effort to position Claude as a defensive security tool while keeping it away from malicious actors through screening of approved teams. Coverage is drawing attention from security professionals weighing AI's growing role in vulnerability discovery.
- 4Greg Kroah-Hartman on software security in the LLM age●Greg Kroah-Hartman – Security in the LLM Age [video]
Greg Kroah-Hartman, the longtime Linux kernel maintainer who leads the stable kernel branch, is featured in a talk on what large language models mean for software security. The discussion covers how LLM tools change the threat landscape for kernel and open-source development, and how maintainers should respond. The talk is drawing attention among developers debating AI's impact on critical infrastructure code.
- 5
Cloudflare has published an open-source security-audit skill for AI coding agents, available on GitHub under the name security-audit-skill. Written in JavaScript, the tool runs multi-phase security audits and produces machine-readable findings that are independently verified, aiming to make automated code review more trustworthy. Developers are picking it up and discussing how it could fit into agent-based development workflows.
- 6Meta and Microsoft reportedly curb employee use of Claude AI●Meta and Microsoft take steps to reduce employee usage of Claude AI
Meta and Microsoft are reported to have taken steps to limit their employees' use of Anthropic's Claude AI assistant. The move suggests the two tech giants want staff relying on internal or approved AI tools rather than a direct competitor's product. Further details about how the restrictions are enforced have not been made clear.
- 7Anthropic expands access to cyber tools with three tiers●Anthropic bündelt Cyberprogramme und führt drei Zugriffsstufen ein Anthropic weitet den kontrollierten Zugang zu sonst e
Anthropic is bundling its cybersecurity programmes and introducing three access levels for otherwise restricted cyber capabilities. The AI company says the tiered system of controlled access is meant to reach more security professionals, allowing vetted experts broader use of its tools for defensive security work while keeping safeguards in place. The move reflects the growing role of AI firms in cybersecurity and the balancing act between offering powerful capabilities and preventing misuse.
- 8Google freezes open-source bug bounty program amid flood of AI slop●Google freezes open-source bug bounty program amid flood of invalid AI slop
Google has suspended part of its Open Source Vulnerability Reward Program, ending reward submissions for product vulnerabilities from October 1, citing an influx of invalid, low-quality bug reports generated by AI tools. The flood of junk submissions has made it impossible to sort genuine vulnerabilities from automated noise, forcing the company to pause the program. The move highlights a growing problem: AI-generated spam overwhelming security research channels meant for human researchers.
- 9Temporal hires Oso team to build AI agent security▼Fast-growing Temporal hires team from NYC startup Oso to build AI agent security controls
Temporal Technologies, the fast-growing Seattle-area workflow orchestration company, has hired the team from New York security startup Oso to develop security controls for AI agents. The acqui-hire reflects growing industry concern over how autonomous AI systems are authenticated and governed. Oso, known for open-source authorization tooling, will wind down as its engineers join Temporal's security efforts.
- 10Open-source AI Agent Gateway keeps credentials out of configs▼AI Agent Gateway: Open-source tool keeps credentials out of agent configs
A new open-source tool called AI Agent Gateway has been released, designed to keep credentials out of AI agent configurations. The gateway handles authentication separately so agents never store sensitive keys directly in their configs. Coverage highlights it as a practical security improvement for teams deploying AI agents, where hard-coded credentials have become a common risk.
- 11ZRON Leak Exposes China's Commercial Hacking Ecosystem▼(nattothoughts.com) AI-Powered Cyber Espionage: Analyzing the ZRON Leak and China’s Commercial Hacking Ecosystem In brie
A major data leak from Chinese cybersecurity firm Zhengzhou Zhirong Network Technology (ZRON) is drawing scrutiny over the country's commercial hacking industry. The leaked material is being analyzed as evidence of how AI tools are used in state-linked cyber espionage, and how vendor firms supply hacking capabilities, renewing debate about China's contractor-driven espionage model.
- 12
Meta and Microsoft are reportedly restricting employees from using Anthropic's Claude AI tools for their work. The move, reported by tech news outlets, underscores growing caution among major AI developers about relying on rival companies' chatbots and coding assistants, likely over concerns about data security, confidentiality and competitive sensitivity. The story is drawing attention in tech circles as competition between AI providers intensifies.
- 13
French outlet l'Opinion reports on Fleuret AI, a startup developing AI agents for cybersecurity. The company is betting that autonomous AI agents can help detect and counter threats more effectively. The piece is drawing attention in France amid growing interest in AI-driven security tools.
- 14
War on the Rocks has published an analysis on how governments and public health systems could defend against viruses designed with the help of artificial intelligence. The piece examines the emerging intersection of AI and bioweapons, and what defensive measures might counter the growing risk of engineered pathogens. It adds to an ongoing debate among security and biology experts about the dual-use dangers of advanced AI in biotechnology.
- 15CrowdStrike Monetizes AI Cybersecurity Complexities▼CrowdStrike (CRWD) is Monetizing the Complexities of the AI Cybersecurity Environment
CrowdStrike (CRWD) is being highlighted for its strategy of turning the growing complexities of AI-driven cybersecurity into revenue opportunities. The company, known for its cloud-based endpoint security platform, is positioning itself to benefit as enterprises confront new AI-related threats and seek advanced protection tools, according to a financial news report.
- 16Malicious web pages could trick GitHub Copilot CLI into leaking secrets●Zombie instructions on carefully constructed web pages could trick GitHub Copilot CLI into sharing secrets https:// sh.i
Security discussions are highlighting a prompt injection risk in GitHub Copilot CLI: carefully crafted web pages containing hidden 'zombie' instructions could manipulate the coding assistant into revealing secrets or performing unintended actions when it processes content from those pages. Commenters warn that developers using AI tools in terminals may be exposed if the tool cannot distinguish trusted instructions from malicious text embedded in the material it reads.
- 17Dungeons & Dragons creative teams unionize over pay and AI concerns●'Dungeons & Dragons' creative teams join union as concerns mount over pay discrepancies and 'forced AI use' https://www.
Creative teams working on Dungeons & Dragons have voted to join a union, citing pay discrepancies across the tabletop gaming company and concerns over forced use of artificial intelligence in their work. The move reflects wider tensions in the gaming industry, where workers are organizing over wages, job security, and the growing role of AI tools in creative production.
- 18Replit Previews Secure Windows Desktop App with AI Sandboxes●Replit Previews Secure Desktop App for Windows with AI Sandboxes
Replit has given a first look at a secure desktop application for Windows that runs AI workloads in isolated sandboxes. The preview highlights stronger safety and local performance for coding with AI assistance directly on the desktop. Developers are discussing what the sandboxing approach means for security and whether the app will reduce reliance on the browser-based Replit workspace.
- 19Prompt Injection Threat Now Targets AI Coding Agents●When people hear "prompt injection", they picture a chatbot being tricked by a clever user... # ai # security # devops #
Security discussions are warning that prompt injection attacks are moving beyond chatbots to AI coding agents. The concern is that malicious instructions can be hidden in everyday development files, with a README alone potentially enough to manipulate an agent into harmful actions. Developers are being urged to treat repository content as untrusted input as AI tools increasingly read and execute instructions from codebases.
- 20AWS launches Strands Box sandboxes for AI agents●Introducing Strands Box: AI agent sandboxes powered by Dogwood
Amazon Web Services has introduced Strands Box, a tool for running AI agents in isolated sandboxes, built on its Dogwood technology. The sandboxes give agents a controlled environment to execute code and tasks safely. The announcement adds to AWS's growing Strands agent toolkit as companies look for secure ways to deploy autonomous AI systems in production.
- 21Developers ask which AI models handle code security reviews●Ask HN: Which frontier model can do code security reviews
A question on Hacker News is asking which frontier AI models are capable of performing code security reviews. The discussion seeks recommendations on which large language models can reliably audit code for vulnerabilities. With few replies so far, the thread reflects a broader interest among developers in using AI tools for security analysis.
- 22Pentagon launches AI pilot for managing sensitive information●Pentagon launches pilot program that will use AI to manage sensitive information
The Pentagon has started a pilot program that will use artificial intelligence to handle and manage sensitive information within the US Department of Defense. The initiative, reported by DefenseScoop, signals the Pentagon's growing interest in applying AI tools to core administrative and data-management functions. The news is drawing attention because of the obvious security implications of letting AI systems handle classified or sensitive government material.
- 23Chinese open-source AI tool used to breach South Korean banks●An open-source Chinese AI tool meant for defensive testing was just weaponized to breach major South Korean banks, inclu
An open-source Chinese AI tool built for defensive security testing has been weaponized in attacks breaching major South Korean banks, including Shinhan Bank and KB Kookmin. Security commentators say the incident undermines claims that dual-use AI can be safely contained, and is prompting calls for an urgent overhaul of AI governance and cyber-defence practices across Asia's financial sector.
- 24Google Pauses Open-Source Bug Bounty Program▼Google Pauses Open-Source Bug Bounty Program Amid AI Slop
Google has paused its open-source bug bounty program, with reports attributing the decision to a flood of low-quality, AI-generated vulnerability reports overwhelming the program's reviewers. The move highlights a growing burden on security teams as automated tools churn out submissions that must be triaged. Security commentators are debating whether the change signals wider trouble for crowd-sourced vulnerability disclosure.
- 25Vibe Coding Lets Non-Developers Build Apps with AI●Vibe Coding Lets Non-Developers Build Apps with AI Prompts
The practice known as vibe coding is drawing attention as a way for people without programming skills to build working software by describing what they want in plain-language prompts to AI tools. Supporters say it opens app development to non-developers, while critics warn the results can be hard to maintain or secure.
- 26
Anthropic is broadening its cyber verification program, introducing tiered levels of access to its AI models for vetted cybersecurity professionals. The scheme gives approved researchers and defenders stronger capabilities for security work while imposing safeguards against misuse. It signals the company's ongoing effort to balance powerful AI tools for cyber defense with controls on offensive applications.
- 27Temporal buys AI security startup Oso after $550M raise▼Temporal buys AI security startup Oso weeks after $550M raise
Workflow orchestration company Temporal has acquired Oso, a startup focused on AI security, just weeks after raising $550 million in new funding. The deal signals Temporal's intent to expand into security tooling for AI-powered applications. Details on the purchase price and integration plans were not disclosed, and broader reaction to the acquisition remains limited so far.
- 28Anthropic opens its most powerful AI models to security teams▼Anthropic opens its most powerful AI models to more security teams
Anthropic has announced it will grant a wider range of security teams access to its most powerful AI models. The move, reported by Reuters and picked up by multiple US radio outlets, is aimed at helping cybersecurity researchers and defenders use advanced AI to identify and counter threats. It signals the company's effort to position its technology as a tool for safety research and defense rather than only commercial use.
- 29South Korea says AI agents used to hack banks●South Korea says AI agents appear to have been used to hack the country's banks https://www.reuters.com/world/south-kore
South Korean officials, cited by Reuters, say AI agents appear to have been used in hacks targeting the country's banks, according to statements from President Lee. The claim suggests autonomous AI-driven tools may have played a role in cyberattacks on financial institutions. It is sparking debate about the security risks of advanced AI systems being turned to criminal use.
- 30South Korea's Lee says AI may have been used in bank hacks▼South Korea's Lee says AI appears to have been used in bank hacks
South Korean President Lee Jae-myung said artificial intelligence appears to have been used in recent bank hacking incidents, according to Reuters. The remarks point to growing official concern that AI tools are being deployed in cyberattacks on financial institutions. The statement is drawing attention as governments worldwide debate how to counter AI-enabled security threats.
- 31Git ambiguity flaw leaves dependency pinning unsafe●git checkout does not pin a commit. If a branch has that exact name, checkout switches to the branch, while git rev-pars
Developers are warning that 'git checkout' does not actually pin a commit. If a branch shares the exact name of a commit hash, checkout switches to the branch instead of the commit, while 'git rev-parse' on the same string returns the commit itself. The issue matters for tools like Claude Code, Codex and GitHub Copilot, which install pinned plugins using clone, potentially resolving to unexpected code.
- 32Okta says AI makes phishing-resistant authentication essential▼AI underscores singular importance of phishing-resistant authentication, Okta says
Identity security company Okta says the rise of AI has made phishing-resistant authentication more important than ever, arguing that AI tools make phishing attacks faster, more convincing and harder to detect. The company is pressing organisations to adopt authentication methods, such as passkeys and hardware keys, that cannot be stolen through deceptive messages, as AI-driven social engineering puts traditional defences under strain.
- 33Chinese AI agent helped hackers breach seven major South Korean banks●Китайський ШІ-агент допоміг хакерам зламати сім найбільших банків Південної Кореї Хакери використали китайського агента
Hackers used a Chinese artificial intelligence agent to attack seven of South Korea's largest banks, stealing personal data of around 68,000 people, according to The Wall Street Journal. The case is drawing attention to how AI tools are being used to scale and automate cyberattacks, and is likely to intensify scrutiny of Chinese AI technology abroad.
- 34Tool removes unwanted Apple Intelligence models from macOS●Pared - remove unwanted Apple Intelligence models without disabling SIP https://github.com/4evy/pared # Apple # macOS #
A new open-source utility called Pared lets Mac users delete unwanted Apple Intelligence models from macOS without having to disable SIP, the system integrity protection that normally blocks such changes. The tool, published on GitHub, is drawing attention among Apple and macOS users interested in reclaiming storage or limiting on-device AI features while keeping system security intact.
- 35Free software community clashes over AI-written GPL code●GPL apps/distros should not be using AI. GPL is not compatible with the ToS of these ai-generating code companies. It wa
Free software advocates are arguing that GPL-licensed projects should not use AI code-generation tools, because the terms of service of services like Codex and Cursor conflict with the GPL's licensing requirements. The debate intensified after criticism of Debian embracing AI-generated code. Some argue AI should only be used for tasks like finding security vulnerabilities, never for writing code in GPL projects.
- 36CrowdStrike, AWS and NVIDIA Expand Cybersecurity Startup Accelerator▼CrowdStrike, AWS, and NVIDIA Expand Global Cybersecurity Startup Accelerator, Defining the Next Generation of Innovation for the Agentic Era
CrowdStrike, AWS and NVIDIA announced an expansion of their global cybersecurity startup accelerator, aimed at supporting early-stage companies building AI-driven, agentic security tools. The program offers startups technical resources, cloud credits and go-to-market support from the three companies. The announcement was carried across financial and technology news outlets, positioning the partnership as an effort to shape the next wave of security innovation.
- 37Google pauses open source bug bounty program citing flood of AI reports▼Google froze its open source bug bounty program due to a ‘significant rise’ in AI submissions
Google has frozen its open source bug bounty program, citing a significant rise in submissions generated with the help of AI. The company says automated, low-quality vulnerability reports are overwhelming reviewers, making it harder to identify genuine security flaws. The move highlights a growing problem across the security industry as AI tools make it easy to mass-produce plausible-looking bug reports.
- 38Study probes whether AI models judge code morally●Ask a model if code is malicious and it reaches for its morals https://www.manifold.security/blog/do-models-consider-mor
Security firm Manifold Security published research asking whether AI models factor morality into their judgments about malicious code. The finding: when asked to assess whether code is malware, language models appear to bring moral reasoning into their analysis rather than relying purely on technical criteria. The report is circulating among developers and security researchers interested in how AI tools evaluate potentially harmful software.
- 39AI logins stolen from 80,000 organizations in infostealer campaign●Cybercriminals have stolen # AI logins from 80,000 organizations https:// proton.me/business/blog/infost ealers-business
Proton reports that cybercriminals have harvested AI service login credentials from roughly 80,000 organizations using infostealer malware. The stolen logins give attackers access to corporate AI accounts, potentially exposing sensitive company data and paid subscriptions. Security commentators are highlighting the finding as a sign that business AI tools have become a fresh target for credential theft.
- 40Google pauses open source bug bounty over AI flood▼Google pauses open source bug bounty program after rise in AI submissions
Google has paused its open source bug bounty program following a sharp rise in submissions generated by artificial intelligence tools. The company says the volume of low-quality, AI-written reports has made the program difficult to manage, prompting a temporary halt while it reassesses how to handle the influx.
Repos
- affaan-m/ECC The agent harness performance optimization system. Skills, instincts, memory, security, and research-first development f
- cloudflare/cloudflare-os Agent workspace built on Cloudflare Workers for creating documents, building apps, and running agents with your company’
- garrytan/gstack Use Garry Tan's exact Claude Code setup: 23 opinionated tools that serve as CEO, Designer, Eng Manager, Release Man
- archestra-ai/OpenAPPA Deterministic guardrails that don't break agents