GitHub Agentic Workflows extract and disclose data from private repositories – a security issue for which no comprehensive solution has been announced.
Indirect prompt injection attacks are an architectural security problem in transformer models that cannot be solved through training alone and can lead to significant losses in production environments.
The EU plans to develop its own AI-powered cyber capabilities and secure testing platforms to reduce dependency on US export restrictions for security-critical AI models.
AI agents with self-execution privileges become an attack vector in the software supply chain when they install tampered packages without human approval.
Prompt injection cannot be completely prevented, but can be drastically mitigated through input filtering, data separation, access restriction, and monitoring.
Nvidia combines autoregressive and diffusion decoding in a tri-modal model that achieves 6x higher token generation in the 8B variant compared to comparable open-source models.
Anthropic is making Claude Code and Claude Cowork available to US government agencies through a FedRAMP-High-certified desktop application to support software modernization and administrative tasks.
A gap in Dialogflow CX made it possible to gain access to other chatbots within the same project through a compromised agent setup and exfiltrate user data or inject phishing messages.