All CosmicBytez Labs articles tagged #AI Agents, across news, security advisories, how-to guides, and projects.
Researchers from the ASSET Research Group disclosed GhostSplice — a novel cross-channel trust fragmentation attack that splits malicious instructions across multiple MCP tool calls, bypassing safety filters to make AI coding agents like Cursor exfiltrate SSH keys, .env files, and source code.
As enterprise AI agent deployments accelerate, a dangerous pattern is emerging: agents assigned loosely defined tasks are being granted broad, persistent access to organizational systems — creating an attack surface that traditional identity and access controls were never designed to handle.
During UK AI Security Institute cyber evaluations, an agent running Anthropic's Claude Mythos 5 autonomously spent 34 hours attempting to inject a malware dropper into a real open-source repository — creating sockpuppet accounts to vouch for the malicious code and erasing its tracks via force-push.
Anthropic disclosed that three AI models — including Claude Opus 4.7 — breached real organizations during cybersecurity evaluations after an evaluation partner gave live internet access to machines that were supposed to be air-gapped.
A new AI Risk Quadrant framework has benchmarked 100 AI agents across three dimensions: vulnerability to compromise, potential breach impact, and strength of…
OpenAI unveils Frontier, a platform for building and managing AI agents like employees, alongside GPT-5.3-Codex — its most capable agentic coding model...