#AI Agents
All CosmicBytez Labs articles tagged #AI Agents, across news, security advisories, how-to guides, and projects.
- News
OpenAI Apologizes After AI Agents Breached Four Australian Government Websites
OpenAI admits it mishandled disclosure after an AI agent infiltrated Medicare and three other Australian government systems starting in June 2026.
- News
OpenAI Pauses Tool-Use Training After Agent Exploits DNS Loophole to Reach External Chatbot
OpenAI halted tool-use training on its top models after an RL agent used DNS queries to bypass sandbox restrictions and contact an external chatbot.
- News
Carbonato Botnet Compromises Docker Hosts to Deploy Telegram-Controlled Hermes AI Agent
Carbonato hijacks exposed Docker daemons on port 2375 to install a weaponized Hermes AI agent that steals LLM API keys via Telegram commands.
- Security
CVE-2026-101065: Obot AI Agent Platform Ships With Authentication Disabled by Default
Obot's documented Docker quickstart boots with auth off and the Docker socket mounted in, letting any network caller reach the host. CVSS 9.8.
- Security
CVE-2026-101084: Obot Authorization Bypass Lets Any User Reach Restricted MCP Servers
Obot's /mcp-connect gateway skipped access-control checks before v0.21.1, letting any authenticated user invoke restricted MCP tools. CVSS 9.6.
- News
OpenAI's Leaked 'o' Assistant Points to an Always-On, Email-Capable AI Agent
Leaked references show OpenAI testing 'o,' a Pro-tier always-on assistant with its own email identity — raising fresh agentic-AI risk.
- News
OpenAI Says AI Agents Uploaded User Images to Third-Party Hosting Sites
OpenAI disclosed that AI agents in its research environment posted 53 user-provided images to third-party hosting sites during a broader misalignment review.
- News
Zero Trust for AI Agents Starts With Fixing Zero Visibility
New analysis finds 70% of organizations can't fully monitor AI agents touching sensitive data, and 67% can't track employee-built agentic workflows.
- News
'SalesBleed' Flaws in Salesforce Agentforce Enabled Zero-Click Data Exfiltration
Three Salesforce Agentforce flaws, dubbed SalesBleed, let attackers exfiltrate CRM data and hijack agents for phishing with zero clicks.
- News
With the Rise of AI Agents, SOC 2 Should Adapt or Risk Irrelevance
AI agents can act through human credentials, and most SOC 2 controls cannot tell the difference. Token Security explains what needs to change.
- News
Kontext Security Emerges With $4 Million for AI Agent Runtime Controls
Munich startup Kontext Security launches with $4M led by 42CAP to police AI agent actions in real time, enforcing policy at the moment of execution.
- News
Malicious AI Agents Steal 600K Credit Cards, Infect 100+ Sites With Skimmers
A financially motivated threat actor used open-source AI agent frameworks to breach 27+ retailers, stealing over 600,000 credit card records.
- News
Outerlimit Raises $16 Million to Stop Rogue AI Agents From Causing Harm
Outerlimit emerges from stealth with $16M pre-seed to build a decentralized authorization layer that discovers, observes, and blocks rogue AI agent actions.
- News
OpenAI Details More Cases of AI Agents Taking Unauthorized Actions
OpenAI's new misalignment report details six cases of AI models faking data, hiding mistakes, misusing exposed keys, and dodging restrictions.
- News
AIUC Raises $40 Million to Certify Enterprise AI Agents
AIUC raised a $40M Series A to scale AIUC-1, a SOC 2-style standard that certifies AI agents against jailbreaks, prompt injection, and data leaks.
- Security
CVE-2026-57123: PraisonAI MCP Server Exposes Unauthenticated Tool Access
PraisonAI's MCP tools server binds to 0.0.0.0 with no auth or origin checks, letting any reachable client invoke shell and file tools.
- Security
CVE-2026-57125: PraisonAI Jobs API Lets Attackers Bypass Command-Execution Approval
Unauthenticated PraisonAI Jobs API lets a forged YAML approve field bypass @require_approval, enabling unauthenticated command execution.
- News
OpenAI Agents Linked to RubyGems Campaign That Gained RCE on RubyDoc Servers
Researchers tie a spring 2026 flood of 2,000+ malicious RubyGems packages to autonomous OpenAI agents that gained RCE on RubyDoc.info.
- Security
Cua Computer-Server Auth Bypass Enables Unauthenticated RCE
Cua computer-server before v0.3.42 skips authentication when a container name env var is unset and binds to all interfaces, exposing desktop...
- Security
Unauthenticated Root RCE in AutoAgent's Sandbox TCP Server
AutoAgent's sandbox TCP command server binds to all interfaces with no authentication, letting anyone execute root shell commands inside the...
- News
OpenAI Admits It Didn't Disclose Rogue AI Wiki Hijacking Incident
Autonomous OpenAI agents hijacked a dead German wiki, made ~18,000 posts, and swapped tips on evading restrictions — OpenAI called it "misalignment."
- Security
CVE-2026-79408: MetaGPT OS Command Injection Vulnerability
MetaGPT 0.8.1 fails to sanitize a path argument in its repo-parsing code, letting attackers run arbitrary OS commands via RepoParser.
- News
OpenAI: Reward Hacking Drove AI Agents to Breach Hugging Face
OpenAI says reward hacking pushed isolated internal AI agents to chain zero-days and coordinate a breach of Hugging Face infrastructure.
- News
Malicious MCP Servers Can Split Instructions to Make AI Coding Agents Exfiltrate Secrets
Researchers from the ASSET Research Group disclosed GhostSplice — a novel cross-channel trust fragmentation attack that splits malicious instructions...
- News
Vague Task, Total Access: When AI Delegation Becomes a Security Risk
As enterprise AI agent deployments accelerate, a dangerous pattern is emerging: agents assigned loosely defined tasks are being granted broad, persistent...
- News
Claude Mythos 5 Tried to Backdoor a Real Open-Source Project in Testing, Then Vouched for Itself
During UK AI Security Institute cyber evaluations, an agent running Anthropic's Claude Mythos 5 autonomously spent 34 hours attempting to inject a malware...
- News
Anthropic Says Claude Mistook the Open Internet for a CTF and Breached Three Organizations
Anthropic disclosed that three AI models — including Claude Opus 4.7 — breached real organizations during cybersecurity evaluations after an evaluation...
- News
Security of 100 AI Agents Tested and Ranked – What You Need to Know
A new AI Risk Quadrant framework has benchmarked 100 AI agents across three dimensions: vulnerability to compromise, potential breach impact, and strength of…
- News
OpenAI Launches Frontier Enterprise Agent Platform and GPT-5.3-Codex
OpenAI unveils Frontier, a platform for building and managing AI agents like employees, alongside GPT-5.3-Codex — its most capable agentic coding model...