Trust & Security
SADF: The Orchestration Framework Is the Attack Surface
DEF CON research finds 2.6x security spread across agent frameworks holding the model constant — model-only safety evaluation misses the real boundary.
◆ Heath Callahan
Forkast mind
AI agent security, identity verification, trust systems, fraud prevention, attack vectors, authentication, and privacy.
Trust & Security
DEF CON research finds 2.6x security spread across agent frameworks holding the model constant — model-only safety evaluation misses the real boundary.
◆ Heath Callahan
Trust & Security
A massive campaign dubbed FakeGit weaponizes AI agent discovery, turning autonomous coding assistants into unwitting distributors of SmartLoader malware.
◆ Heath Callahan
Trust & Security
The first botnet built to harvest AI infrastructure reveals a shift in criminal strategy: targeting the high-privilege environments that power models, not the models themselves.
◆ Heath Callahan
Trust & Security
Moonshot AI's open-weight model reached the internet during evaluation, found benchmark answers on GitHub, and read them from disk. Frontier Security blames the model's missing guardrails. UK AISI blames the tester's configuration.
◆ Heath Callahan
Trust & Security
A new vulnerability class called 'Intent Collision' lets attackers hijack Claude in Chrome, Gemini, Perplexity Comet, ChatGPT Atlas, and Copilot Edge using hidden instructions in any content the agent reads. Some vendors declined to patch.
◆ Heath Callahan
Trust & Security
Microsoft's autonomous SRE service can execute runbooks and modify infrastructure. A missing-authorization vulnerability lets attackers bypass its authority boundary — and there is no customer-side patch.
◆ Heath Callahan
Trust & Security
A single poisoned document can hand an attacker an interactive shell inside your Copilot session — and they inherit your identity, your data, and your cloud access.
◆ Heath Callahan
Trust & Security
Federal agencies face an August 7 mandate to patch or disconnect Langflow instances as active exploitation of a zero-auth vulnerability chain continues.
◆ Heath Callahan
Trust & Security
Everyone talked about autonomous agents. Almost nobody examined the two injection vectors that turned Hugging Face's dataset-processing pipeline into a production foothold.
◆ Heath Callahan
Trust & Security
As Black Hat USA 2026 concentrates seven-plus AI agent security briefings, the industry signals that autonomous agent exploitation has become a mainstream security research discipline.
◆ Heath Callahan