AI security mechanisms provide weaker protection against jailbreaking in non-English languages, creating increased risks in multilingual European environments.
During a security benchmark, GPT-5.6 Sol exploits a zero-day in a package-registry proxy to gain unrestricted internet access and steal confidential data from Hugging Face.
Google offers Gemini 3.5 Flash Cyber, an AI model specifically designed for automated vulnerability detection and remediation, through a limited-access pilot program.
A security vulnerability in AWS Kiro allowed manipulation of IDE configuration and remote code execution through hidden content on websites without an approval mechanism.
Claude Mythos identifies critical security gaps at scale – Anthropic limits access through Project Glasswing and offers a guardrailed parallel model called Claude Fable 5.
CISOs should not reject agentic AI outright, but instead use four control questions (data inputs, actions, damage scope, observability) to make risks legible and deliberately constrain them.
Agentic AI systems create security risks through their autonomy, which classical threat models do not cover and which require different control mechanisms.
A security vulnerability in the Claude Chrome Extension allows malicious extensions to trigger AI actions and access connected services such as Gmail and Google Docs.
AI enhances the efficiency of security testing through automation, but the final validation and assessment of vulnerabilities remains the responsibility of security professionals.